اعمل الاتي
عطل جميع برامج الحمايه ,,
نزل هذه الاداة
عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
انتظر حتى يظهر لك تقرير ،، وبذلك يكون الفحص انتهى الصق التقرير بمشاركتك القادمة
وهذا النقرير . يا ليت تعطيني رابط النتيجه ابي اشوف
ComboFix 09-04-29.07 - bin mastor 04/30/2009 20:10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.3061.2537 [GMT 3:00]
Running from: c:\documents and settings\bin mastor\سطح المكتب\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
FW: ESET Personal firewall *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\BINMAS~1\LOCALS~1\Temp\install_flash_player.exe
c:\windows\system32\kakle.dll
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
c:\windows\system32\winitn.dll
c:\windows\system32\x64
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-30 )))))))))))))))))))))))))))))))
.
2009-04-30 17:02 . 2009-04-30 17:02 -------- d-----w c:\documents and settings\LocalService\Application Data\TeamViewer
2009-04-30 02:04 . 2009-04-30 03:14 -------- d-----w C:\camel
2009-04-29 23:27 . 2009-04-29 23:27 -------- d-----w c:\program files\Trend Micro
2009-04-29 23:21 . 2003-11-04 12:11 159744 ----a-w c:\windows\system32\lfpng13n.dll
2009-04-29 23:21 . 2003-11-04 12:10 69632 ----a-w c:\windows\system32\lfgif13n.dll
2009-04-29 23:21 . 2004-05-14 13:53 57344 ----a-w c:\windows\system32\lfbmp13n.dll
2009-04-29 23:21 . 2004-05-14 13:53 401408 ----a-w c:\windows\system32\lfcmp13n.dll
2009-04-29 23:21 . 2004-01-11 23:09 206336 ----a-w c:\windows\system32\ltefx13n.dll
2009-04-29 23:21 . 2004-05-14 13:53 299008 ----a-w c:\windows\system32\ltdis13n.dll
2009-04-29 23:21 . 2004-05-14 13:53 163840 ----a-w c:\windows\system32\ltfil13n.dll
2009-04-29 23:21 . 2004-05-14 13:53 450560 ----a-w c:\windows\system32\ltimg13n.dll
2009-04-29 23:21 . 2004-05-14 13:53 462848 ----a-w c:\windows\system32\ltkrn13n.dll
2009-04-29 22:33 . 2009-04-29 22:33 13824 ----a-w c:\windows\system32\drivers\splitcam.sys
2009-04-29 22:32 . 2009-04-29 22:32 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-29 18:47 . 2009-04-29 18:47 -------- d-----w c:\windows\system32\config\systemprofile\Application Data\TeamViewer
2009-04-28 07:02 . 2009-04-28 07:02 -------- d-----w c:\program files\Windows Live SkyDrive
2009-04-27 22:25 . 2009-04-30 17:04 -------- d-----w c:\documents and settings\bin mastor\Application Data\Skype
2009-04-27 22:25 . 2009-04-27 22:25 -------- d-----w c:\program files\Skype
2009-04-23 12:13 . 2009-04-26 22:12 -------- d-----w c:\program files\StartClock
2009-04-23 11:50 . 2009-04-29 03:09 -------- d-----w c:\program files\TeamViewer
2009-04-23 11:28 . 2009-04-23 17:14 -------- d-----w c:\documents and settings\bin mastor\Application Data\TeamViewer
2009-04-23 11:28 . 2009-04-23 11:28 -------- d-----w c:\documents and settings\bin mastor\temp
2009-04-23 10:55 . 2009-04-30 03:41 -------- d-----w c:\documents and settings\bin mastor\Local Settings\Application Data\Google
2009-04-22 02:26 . 2009-04-22 02:26 -------- d-----w C:\Temp
2009-04-22 01:46 . 2009-04-22 01:46 -------- d-----w c:\documents and settings\bin mastor\Application Data\Apple Computer
2009-04-21 21:20 . 2009-04-21 21:20 -------- d-----w c:\documents and settings\bin mastor\Local Settings\Application Data\TechSmith
2009-04-21 20:57 . 2008-01-07 11:29 352 ---ha-w c:\windows\nod32fixtemdono.reg
2009-04-21 20:13 . 2008-07-10 10:56 107864 ----a-w c:\windows\system32\tsccvid.dll
2009-04-21 20:13 . 2009-04-21 20:13 -------- d-----w c:\program files\Common Files\TechSmith Shared
2009-04-21 19:13 . 2009-04-21 19:13 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-04-21 18:23 . 2009-04-21 18:25 -------- d-----w c:\program files\Video-AVI to GIF Converter
2009-04-21 18:07 . 2009-04-30 17:02 -------- d-----w c:\documents and settings\LocalService\Application Data\VMware
2009-04-21 18:06 . 2005-12-15 17:42 5120 ----a-r c:\windows\system32\vnetinst.dll
2009-04-21 18:06 . 2005-12-15 17:42 9600 ----a-r c:\windows\system32\drivers\vmnetadapter.sys
2009-04-21 18:06 . 2005-12-15 17:42 106496 ----a-w c:\windows\system32\vmnetdhcp.exe
2009-04-21 18:06 . 2005-12-15 17:42 135168 ----a-w c:\windows\system32\vmnat.exe
2009-04-21 18:06 . 2005-12-15 17:42 15616 ----a-w c:\windows\system32\drivers\vmnetuserif.sys
2009-04-21 18:06 . 2005-12-15 17:42 10240 ----a-r c:\windows\system32\drivers\vmnet.sys
2009-04-21 18:06 . 2005-12-15 17:42 385024 ----a-w c:\windows\system32\vnetlib.dll
2009-04-21 18:01 . 2009-04-21 18:01 -------- d-----w c:\program files\Common Files\VMware
2009-04-21 18:01 . 2009-04-21 18:01 -------- d-----w c:\program files\VMware
2009-04-21 11:09 . 2009-04-21 11:10 -------- d-----w c:\documents and settings\bin mastor\Local Settings\Application Data\Digsby
2009-04-21 11:09 . 2009-04-21 11:10 -------- d-----w c:\documents and settings\bin mastor\Application Data\Digsby
2009-04-21 11:07 . 2009-04-21 11:07 -------- d-----w c:\documents and settings\All Users\Application Data\Winferno
2009-04-21 11:03 . 2009-04-21 11:03 -------- d-----w c:\documents and settings\bin mastor\Application Data\Jenkat
2009-04-21 11:02 . 2009-04-24 23:55 -------- d-----w c:\program files\Winferno
2009-04-21 11:00 . 2009-04-28 19:06 -------- d-----w c:\program files\Wyyo
2009-04-21 11:00 . 2009-04-28 06:24 -------- d-----w c:\documents and settings\All Users\Application Data\Wyyo
2009-04-21 10:38 . 2009-04-21 10:38 -------- d-----w c:\documents and settings\LocalService\سطح المكتب
2009-04-21 09:44 . 2009-04-21 09:44 -------- d-----w c:\documents and settings\bin mastor\Local Settings\Application Data\ESET
2009-04-21 08:40 . 2009-04-21 08:40 -------- d-----w c:\program files\TuneUp Utilities 2009
2009-04-21 08:29 . 2009-04-21 08:38 -------- d-s---w c:\documents and settings\Administrator
2009-04-18 12:51 . 2009-04-21 08:38 -------- d-----w c:\documents and settings\bin mastor\Local Settings\Application Data\TechSmith(2)
2009-04-18 12:40 . 2009-04-22 01:05 -------- d-----w c:\program files\Video GIF Converter
2009-04-18 05:33 . 2009-04-24 18:43 -------- d-----w c:\program files\Hotspot Shield
2009-04-18 04:49 . 2009-04-21 08:39 -------- d-----w c:\program files\TuneUp Utilities 2009(2)
2009-04-18 02:19 . 2009-04-18 02:19 -------- d-----w c:\documents and settings\bin mastor\Application Data\Media Player Classic
2009-04-17 08:43 . 2009-04-17 08:43 -------- d-----w c:\documents and settings\bin mastor\Application Data\TechSmith
2009-04-17 08:33 . 2009-04-21 09:40 -------- d-----w c:\documents and settings\bin mastor\Application Data\DivX
2009-04-16 22:34 . 2009-04-21 20:13 -------- d-----w c:\windows\system32\QuickTime
2009-04-16 22:13 . 2009-04-21 20:13 -------- d-----w c:\documents and settings\All Users\Application Data\TechSmith
2009-04-16 22:13 . 2009-04-21 18:29 -------- d-----w c:\program files\TechSmith
2009-04-15 23:09 . 2009-04-21 08:41 -------- d-----w c:\program files\Common Files\VMware(2)
2009-04-15 23:09 . 2009-04-21 08:41 -------- d-----w c:\program files\VMware(2)
2009-04-15 22:33 . 2009-04-29 02:16 -------- d-----w c:\documents and settings\bin mastor\Application Data\VMware
2009-04-15 22:08 . 2009-04-30 17:02 -------- d-----w c:\documents and settings\All Users\Application Data\VMware
2009-04-14 21:09 . 2009-04-15 22:11 -------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-04-14 21:03 . 2009-04-21 08:43 -------- d-----w c:\documents and settings\All Users\Application Data\Lies shim upload curb
2009-04-14 21:02 . 2009-04-21 08:43 -------- d-----w c:\documents and settings\bin mastor\Application Data\internet fast
2009-04-14 21:02 . 2009-04-21 08:43 -------- d-----w c:\program files\MessengerPlus! 3(2)
2009-04-14 20:40 . 2009-04-24 20:41 -------- d-----w c:\documents and settings\bin mastor\Contacts
2009-04-14 20:37 . 2009-04-21 09:51 -------- d-----w c:\program files\MSN Messenger
2009-04-14 20:35 . 2009-04-14 20:35 -------- d-----w c:\program files\ESET
2009-04-14 20:09 . 2009-04-14 20:09 -------- d-----w c:\documents and settings\bin mastor\Application Data\ESET
2009-04-14 20:08 . 2009-04-14 20:08 -------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-04-14 19:46 . 2009-04-14 19:46 -------- d-----w c:\windows\Sun
2009-04-14 19:37 . 2001-08-17 11:02 9600 -c--a-w c:\windows\system32\dllcache\hidusb.sys
2009-04-14 19:37 . 2001-08-17 11:02 9600 ----a-w c:\windows\system32\drivers\hidusb.sys
2009-04-14 19:37 . 2004-08-03 20:08 31616 -c--a-w c:\windows\system32\dllcache\usbccgp.sys
2009-04-14 19:37 . 2004-08-03 20:08 31616 ----a-w c:\windows\system32\drivers\usbccgp.sys
2009-04-14 16:19 . 2005-06-20 01:57 110592 ----a-w c:\windows\system32\uci32100.dll
2009-04-14 16:19 . 2009-04-14 16:19 -------- d-----w c:\program files\CONEXANT
2009-04-14 16:03 . 2009-04-14 16:03 -------- d-----w c:\windows\speech
2009-04-14 16:01 . 2009-04-14 16:02 -------- d-----w c:\program files\Golden Al-Wafi Translator
2009-04-14 16:01 . 2009-04-14 16:01 172032 ------w c:\windows\Setup1.exe
2009-04-14 16:01 . 2009-04-14 16:01 73216 ----a-w c:\windows\ST6UNST.EXE
2009-04-14 15:59 . 2009-04-14 15:59 -------- d-----w c:\program files\MumboJumbo
2009-04-14 15:58 . 2009-04-27 04:39 -------- d-----w c:\program files\Quranzu1
2009-04-14 15:07 . 2001-08-17 13:59 3072 ----a-w c:\windows\system32\drivers\audstub.sys
2009-04-14 15:06 . 2004-08-04 00:41 57216 ----a-w c:\windows\system32\drivers\redbook.sys
2009-04-14 15:05 . 2004-08-04 00:55 73728 ----a-w c:\windows\system32\usbui.dll
2009-04-14 15:05 . 2009-04-28 07:02 -------- d-sh--w c:\windows\Installer
2009-04-14 15:05 . 2001-09-19 11:00 61440 -c--a-w c:\windows\system32\dllcache\spcplui.dll
2009-04-14 15:05 . 2001-09-19 11:00 77824 -c--a-w c:\windows\system32\dllcache\spcommon.dll
2009-04-14 15:05 . 2001-09-19 11:00 774144 -c--a-w c:\windows\system32\dllcache\spttseng.dll
2009-04-14 15:05 . 2001-09-19 11:00 36864 -c--a-w c:\windows\system32\dllcache\sapisvr.exe
2009-04-14 15:05 . 2004-08-03 21:55 741376 -c--a-w c:\windows\system32\dllcache\sapi.dll
2009-04-14 15:05 . 2009-04-29 23:27 -------- d-----r C:\Program Files
2009-04-14 15:03 . 2009-04-21 08:29 -------- d-----w C:\Documents and Settings
2009-04-14 15:03 . 2009-04-14 12:12 -------- d-----w c:\documents and settings\All Users
2009-04-14 15:03 . 2009-04-14 12:13 -------- d--h--w c:\documents and settings\Default User
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-30 17:06 . 2001-09-19 11:00 44696 ----a-w c:\windows\system32\perfc001.dat
2009-04-30 17:06 . 2001-09-19 11:00 262804 ----a-w c:\windows\system32\perfh001.dat
2009-04-29 22:32 . 2009-04-26 14:31 -------- d-----w c:\program files\SplitCam
2009-04-27 22:25 . 2009-04-27 22:25 -------- d-----w c:\program files\Common Files\Skype
2009-04-27 13:18 . 2009-04-27 13:18 -------- d-----w c:\program files\Multiskype
2009-04-27 03:21 . 2009-04-27 03:21 -------- d-----w c:\program files\WinWatermark 2.2
2009-04-26 14:02 . 2009-04-26 14:02 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-24 21:51 . 2009-04-24 21:51 56 ---ha-w c:\windows\system32\ezsidmv.dat
2009-04-24 21:51 . 2009-04-24 21:50 -------- d-----w c:\program files\Google
2009-04-23 15:00 . 2009-04-14 14:15 -------- d-----w c:\program files\Internet Download Manager
2009-04-23 15:00 . 2009-04-14 14:13 -------- d-----w c:\program files\Crcle Developement
2009-04-21 09:51 . 2009-04-14 14:12 -------- d-----w c:\program files\Messenger Plus! Live
2009-04-14 19:57 . 2009-04-14 12:12 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-14 19:53 . 2009-04-14 19:53 2232 ----a-w c:\windows\java\Packages\Data\PZLBZNZR.DAT
2009-04-14 19:53 . 2009-04-14 19:53 155995 ----a-w c:\windows\java\Packages\4J53B537.ZIP
2009-04-14 19:53 . 2009-04-14 19:53 2678 ----a-w c:\windows\java\Packages\Data\93TZPRP7.DAT
2009-04-14 19:53 . 2009-04-14 19:53 2678 ----a-w c:\windows\java\Packages\Data\ZLBX7JH7.DAT
2009-04-14 19:53 . 2009-04-14 19:53 2678 ----a-w c:\windows\java\Packages\Data\NXFLZTRX.DAT
2009-04-14 19:53 . 2009-04-14 19:53 2678 ----a-w c:\windows\java\Packages\Data\BPV575B1.DAT
2009-04-14 19:53 . 2009-04-14 19:53 2678 ----a-w c:\windows\java\Packages\Data\444GOE8P.DAT
2009-04-14 14:14 . 2009-04-14 14:14 603904 ----a-w c:\windows\system32\TUProgSt.exe
2009-04-14 14:14 . 2009-04-14 14:14 362240 ----a-w c:\windows\system32\TuneUpDefragService.exe
2009-04-14 14:12 . 2009-04-14 14:12 99496 ----a-w c:\documents and settings\bin mastor\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-14 14:11 . 2009-04-14 14:11 -------- d-----w c:\program files\Windows Live
2009-04-14 14:07 . 2009-04-14 14:07 -------- d-----w c:\program files\Ozone
2009-04-14 13:56 . 2009-04-14 13:56 -------- d-----w c:\program files\Common Files\xing shared
2009-04-14 13:56 . 2009-04-14 13:55 -------- d-----w c:\program files\Common Files\Real
2009-04-14 13:56 . 2009-04-14 13:56 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-04-14 13:56 . 2009-04-14 13:55 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-04-14 13:55 . 2009-04-14 13:55 -------- d-----w c:\program files\Real
2009-04-14 13:52 . 2009-04-14 13:51 -------- d-----w c:\program files\QuickTime
2009-04-14 13:52 . 2009-04-14 13:52 -------- d-----w c:\program files\Common Files\Apple
2009-04-14 13:51 . 2009-04-14 13:51 -------- d-----w c:\program files\Apple Software Update
2009-04-14 13:49 . 2009-04-14 13:48 -------- d-----w c:\program files\DivX
2009-04-14 13:42 . 2009-04-14 13:42 -------- d-----w c:\program files\Java
2009-04-14 13:38 . 2009-04-14 13:38 -------- d-----w c:\program files\Common Files\Adobe
2009-04-14 13:36 . 2009-04-14 13:36 -------- d-----w c:\program files\Microsoft Works
2009-04-14 13:36 . 2009-04-14 13:36 -------- d-----w c:\program files\MSBuild
2009-04-14 12:24 . 2009-04-14 12:24 16608 ----a-w c:\windows\gdrv.sys
2009-04-14 12:13 . 2009-04-14 12:13 -------- d-----w c:\program files\microsoft frontpage
2009-04-14 12:12 . 2001-09-19 11:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-04-14 12:10 . 2009-04-14 12:10 22144 ----a-w c:\windows\system32\emptyregdb.dat
.
------- Sigcheck -------
[-] 2008-03-29 16:19 1547776 6E932D21E116B51ED9D5157E31C48E33 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-24 39408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-08-12 21741864]
"WINDOWS"="c:\windows\system32\WIND0WS.exe" [2008-04-14 147456]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-05 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-05 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-05 137752]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-14 198160]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]
"WINDOWS"="c:\windows\system32\WIND0WS.exe" [2008-04-14 147456]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-12-31 16132608]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2007-12-31 1826816]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R3 CamelMysql;CamelMysql;c:\camel\mysql\bin\mysqld-nt.exe [2008-01-18 5750784]
R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2008-01-25 25088]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
S2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [2009-04-27 185640]
S2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2009-04-14 603904]
S2 Wyyo Service;Wyyo Service;c:\documents and settings\All Users\Application Data\Wyyo\wyyo133.exe [2009-04-27 54760]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-04-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-30 20:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6a4245f9-f282-48c4-825f-b1258b703b4d}]
@Denied: (Full) (Everyone)
"Model"=dword:0000006e
"Therad"=dword:00000008
"MData"=hex(0):cb,9b,ad,ef,27,7d,29,69,f5,02,f0,76,aa,4a,f1,7c,d3,d9,67,7f,6a,
4b,7b,ad,04,7a,b1,b5,76,9b,27,47,99,98,1c,a1,85,8b,f7,07,5a,a1,62,96,51,bd,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):b2,60,91,e4,6e,7f,71,29,f8,7e,ea,d1,0e,24,47,5b,41,34,80,76,b7,
73,82,20,25,42,03,3f,dc,25,c2,db,3c,23,cf,3b,1e,40,33,40,00,00,00,00,00,00,\
.
Completion time: 2009-04-30 20:12
ComboFix-quarantined-files.txt 2009-04-30 17:12
Pre-Run: 16,414,224,384 bytes free
Post-Run: 17,377,050,624 bytes free
258