عطلت برامج الحماية
وهذا التقرير
ComboFix 09-05-02.4 - Administrator 05/04/2009 23:57.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.1526.1089 [GMT 3:00]
Running from: c:\documents and settings\Administrator\My Documents\Downloads\Programs\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
FW: ESET Personal firewall *disabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Application Data\BITS
c:\documents and settings\Administrator\Application Data\BITS\BITS.ini
c:\documents and settings\Administrator\Application Data\BITS\DHTTable.dat
c:\documents and settings\Administrator\Application Data\BITS\ProxyList.ini
c:\program files\FlashGet Network
c:\program files\FlashGet Network\FlashGet universal\dbtrans_verbose.log
c:\program files\FlashGet Network\FlashGet universal\fgoption.ini
c:\program files\FlashGet Network\FlashGet universal\P2PCfg.ini
c:\program files\FlashGet Network\FlashGet universal\p2spmgr.ini
c:\program files\FlashGet Network\FlashGet universal\p4spmgr.ini
c:\program files\FlashGet Network\FlashGet universal\Profiles\config.dat
c:\program files\FlashGet Network\FlashGet universal\Profiles\tasks.dat
c:\program files\FlashGet Network\FlashGet universal\transaction.log
.
((((((((((((((((((((((((( Files Created from 2009-04-04 to 2009-05-04 )))))))))))))))))))))))))))))))
.
2009-05-04 07:48 . 2001-09-18 10:38 12160 ----a-w c:\windows\system32\drivers\mouhid.sys
2009-05-04 07:48 . 2001-08-17 11:02 9600 ----a-w c:\windows\system32\drivers\hidusb.sys
2009-05-04 07:25 . 2009-05-04 07:25 -------- d-----w c:\documents and settings\Administrator\Application Data\SolidWorks 2008
2009-05-04 02:33 . 2009-05-04 02:33 -------- d-----w c:\documents and settings\Administrator\Application Data\Thinstall
2009-05-04 02:29 . 2009-05-04 02:29 -------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-05-04 02:25 . 2009-05-04 02:25 -------- d-----w c:\program files\Windows Live
2009-05-04 02:25 . 2009-05-04 02:25 -------- d-----w c:\program files\Messenger Plus! Live
2009-05-04 02:03 . 2009-05-04 02:25 -------- d-----w c:\program files\MSN Messenger
2009-05-03 22:09 . 2009-05-03 22:09 -------- d-----w c:\program files\Cicle Developement
2009-05-02 08:51 . 2009-05-02 08:51 -------- d-----w c:\documents and settings\Administrator\Application Data\SolidWorks
2009-05-02 08:42 . 2009-05-02 08:46 -------- d-----w c:\program files\Common Files\SolidWorks Shared
2009-05-02 08:41 . 2009-05-02 08:41 -------- d-----w c:\program files\Common Files\eDrawings2008
2009-05-02 08:41 . 2009-05-02 08:41 -------- d-----w c:\program files\AGEIA Technologies
2009-05-02 08:41 . 2009-05-02 08:47 -------- d-----w c:\program files\SolidWorks
2009-05-02 08:41 . 2009-05-02 08:41 -------- d-----w c:\documents and settings\All Users\Application Data\SolidWorks
2009-05-02 08:38 . 2009-05-02 08:38 182168 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-02 08:34 . 2009-05-02 08:34 -------- d-----w c:\windows\system32\XPSViewer
2009-05-02 08:34 . 2009-05-02 08:34 -------- d-----w c:\program files\Reference Assemblies
2009-05-02 08:33 . 2006-06-29 10:07 14048 ------w c:\windows\system32\spmsg2.dll
2009-05-02 07:36 . 2009-05-04 01:50 -------- d-----w c:\documents and settings\Administrator\Tracing
2009-05-02 07:34 . 2009-05-02 07:34 -------- d-----w c:\program files\Microsoft
2009-05-02 07:21 . 2009-05-02 07:21 -------- d-----w c:\program files\Common Files\Windows Live
2009-05-02 06:35 . 2009-05-02 06:35 -------- d-----w c:\program files\Windows Installer Clean Up
2009-05-02 06:35 . 2009-05-02 08:32 -------- d-----w c:\program files\MSECACHE
2009-05-01 21:42 . 2009-05-01 21:42 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\PCHealth
2009-04-29 03:45 . 2009-04-29 03:47 -------- d-----w c:\program files\Power Mp3 Cutter(Mp3 Sound Cutter)
2009-04-27 15:37 . 2009-04-27 15:38 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-04-27 00:51 . 2008-06-21 15:54 11779 ----a-w c:\windows\REGTWEAK.REG
2009-04-25 18:56 . 2009-04-25 18:56 -------- d-----w c:\documents and settings\Administrator\Application Data\URSoft
2009-04-25 18:55 . 2009-05-04 01:44 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-25 18:55 . 2009-04-25 19:00 -------- d-----w c:\program files\Your Uninstaller 2008
2009-04-25 18:48 . 2009-04-25 18:48 -------- d--h--w c:\windows\system32\GroupPolicy
2009-04-24 13:05 . 2009-04-24 13:05 603904 ----a-w c:\windows\system32\TUProgSt.exe
2009-04-24 13:05 . 2008-11-24 11:19 27904 ----a-w c:\windows\system32\uxtuneup.dll
2009-04-24 13:05 . 2009-04-24 13:05 362240 ----a-w c:\windows\system32\TuneUpDefragService.exe
2009-04-24 13:00 . 2009-04-24 13:00 -------- d-----w c:\documents and settings\Administrator\Application Data\TuneUp Software
2009-04-24 12:59 . 2009-04-24 12:59 -------- d-----w c:\documents and settings\All Users\Application Data\TuneUp Software
2009-04-24 12:59 . 2009-04-24 13:45 -------- d-----w c:\program files\TuneUp Utilities 2009
2009-04-24 12:59 . 2009-04-24 12:59 -------- d-sh--w c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-04-24 10:04 . 2009-04-24 10:05 -------- d-----w c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-04-23 23:11 . 2009-04-23 23:11 -------- d-----w c:\documents and settings\Administrator\Application Data\Desktopicon
2009-04-23 23:10 . 2009-04-23 23:11 -------- d-----w c:\program files\FormatFactory
2009-04-23 22:55 . 2009-04-23 22:55 -------- d-----w c:\windows\Sun
2009-04-23 22:21 . 2009-04-23 22:21 -------- d-----w c:\program files\CCleaner
2009-04-23 18:36 . 2009-04-23 22:42 -------- d-----w c:\documents and settings\Administrator\Contacts
2009-04-23 18:18 . 2009-04-25 19:04 -------- d-----w c:\documents and settings\Administrator\Application Data\IDM
2009-04-23 18:18 . 2009-05-04 20:57 -------- d-----w c:\documents and settings\Administrator\Application Data\DMCache
2009-04-23 18:18 . 2009-04-25 19:00 -------- d-----w c:\program files\Internet Download Manager
2009-04-23 18:11 . 2009-04-23 18:11 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\ESET
2009-04-23 18:11 . 2009-04-23 18:11 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2009-04-23 17:58 . 2009-04-23 17:58 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-04-23 17:58 . 2009-04-23 17:58 -------- d-sh--w c:\documents and settings\Administrator\IECompatCache
2009-04-23 17:57 . 2009-04-23 17:57 -------- d-sh--w c:\documents and settings\Administrator\PrivacIE
2009-04-23 17:57 . 2009-04-23 17:57 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Google
2009-04-21 15:01 . 2009-05-02 08:46 -------- dc----w c:\windows\system32\DRVSTORE
2009-04-21 14:05 . 2009-04-27 15:36 -------- d-----w c:\program files\Common Files\Adobe
2009-04-21 14:01 . 2006-10-26 16:56 32592 ----a-w c:\windows\system32\msonpmon.dll
2009-04-21 14:00 . 2009-04-21 14:00 -------- d-----w c:\program files\Microsoft Works
2009-04-21 13:59 . 2009-05-02 08:38 -------- d-----w c:\program files\MSBuild
2009-04-21 13:58 . 2009-04-21 13:58 -------- d-----w c:\program files\Microsoft.NET
2009-04-21 13:56 . 2009-04-21 13:56 -------- d-----w c:\program files\Microsoft Visual Studio 8
2009-04-21 13:55 . 2009-04-21 13:59 -------- d-----w c:\windows\SHELLNEW
2009-04-21 13:55 . 2009-04-21 13:55 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft Help
2009-04-21 13:55 . 2009-04-21 14:01 -------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-21 13:55 . 2009-04-21 13:55 -------- d--h--r C:\MSOCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-04 20:56 . 2009-04-21 08:31 6 ---ha-w c:\windows\Tasks\SA.DAT
2009-05-04 20:37 . 2009-04-23 17:58 430 ---ha-w c:\windows\Tasks\User_Feed_Synchronization-{12BF4DFC-392D-47AA-BDA7-2B2B934E0899}.job
2009-05-04 20:36 . 2001-09-19 14:00 70448 ----a-w c:\windows\system32\perfc001.dat
2009-05-04 20:36 . 2001-09-19 14:00 370894 ----a-w c:\windows\system32\perfh001.dat
2009-05-04 20:33 . 2009-04-24 13:46 428 ----a-w c:\windows\Tasks\الصيانة بنقرة واحدة.job
2009-05-04 20:33 . 2009-04-24 13:05 502 ----a-w c:\windows\Tasks\1-Click Maintenance.job
2009-05-02 08:49 . 2009-04-21 08:34 96056 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-28 17:10 . 2009-04-21 08:23 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-25 19:11 . 2009-04-21 08:34 -------- d-----w c:\program files\Instant ThumbView
2009-04-23 18:05 . 2009-04-21 09:44 -------- d-----w c:\program files\Atheros
2009-04-23 18:03 . 2009-04-21 08:35 -------- d-----w c:\program files\Google
2009-04-21 14:05 . 2009-04-21 09:29 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-21 09:50 . 2009-04-21 09:50 -------- d-----w c:\program files\WIDCOMM
2009-04-21 09:47 . 2009-04-21 09:47 -------- d-----w c:\program files\Launch Manager
2009-04-21 09:43 . 2009-04-21 09:28 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-21 09:41 . 2009-04-21 09:41 17801 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-04-21 09:40 . 2009-04-21 09:40 -------- d-----w c:\program files\CONEXANT
2009-04-21 09:29 . 2009-04-21 09:29 -------- d-----w c:\program files\Intel
2009-04-21 08:40 . 2009-04-21 08:40 136 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2009-04-21 08:39 . 2009-04-21 08:34 -------- d-----w c:\program files\USB Disk Security
2009-04-21 08:39 . 2009-04-21 08:38 -------- d-----w c:\program files\Nero
2009-04-21 08:39 . 2009-04-21 08:38 -------- d-----w c:\program files\Common Files\Nero
2009-04-21 08:36 . 2009-04-21 08:36 -------- d-----w c:\program files\ESET
2009-04-21 08:35 . 2009-04-21 08:35 -------- d-----w c:\program files\Common Files\xing shared
2009-04-21 08:35 . 2009-04-21 08:35 -------- d-----w c:\program files\Common Files\Real
2009-04-21 08:35 . 2009-04-21 08:32 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-04-21 08:35 . 2009-04-21 08:32 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-04-21 08:35 . 2009-04-21 08:35 -------- d-----w c:\program files\Real
2009-04-21 08:34 . 2009-04-21 08:34 -------- d-----w c:\program files\Rainlendar
2009-04-21 08:34 . 2009-04-21 08:34 -------- d-----w c:\program files\Absolute Sound Recorder
2009-04-21 08:34 . 2009-04-21 08:34 -------- d-----w c:\program files\Super Fast Shutdown
2009-04-21 08:34 . 2009-04-21 08:34 -------- d-----w c:\program files\ClocX
2009-04-21 08:34 . 2009-04-21 08:34 -------- d-----w c:\program files\RocketDock
2009-04-21 08:33 . 2009-04-21 08:33 -------- d-----w c:\program files\Supercleaner
2009-04-21 08:33 . 2009-04-21 08:31 -------- d-----w c:\program files\العنبري
2009-04-21 08:33 . 2009-04-21 08:33 -------- d-----w c:\program files\Resize
2009-04-21 08:33 . 2009-04-21 08:33 -------- d-----w c:\program files\Flash Player
2009-04-21 08:33 . 2009-04-21 08:32 -------- d-----w c:\program files\K-Lite Codec Pack
2009-04-21 08:32 . 2009-04-21 08:32 -------- d-----w c:\program files\Ela-Salaty
2009-04-21 08:32 . 2009-04-21 08:32 -------- d-----w c:\program files\Traductor Global
2009-03-11 11:50 . 2009-03-11 11:50 2052096 ----a-w c:\windows\system32\msgina.dll
2009-03-09 08:58 . 2009-03-09 08:58 6217216 ----a-w c:\windows\system32\logonui.exe
2009-03-08 01:34 . 2004-08-04 00:55 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 01:34 . 2004-08-04 00:55 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 01:33 . 2004-08-04 00:55 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 01:33 . 2004-08-04 00:55 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 01:32 . 2004-08-04 00:55 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 01:32 . 2004-08-04 00:55 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 01:31 . 2004-08-04 00:55 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 01:31 . 2004-08-04 00:53 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 01:31 . 2004-08-04 00:56 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 01:22 . 2001-09-19 14:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-04 10:34 . 2009-03-04 10:34 330752 ----a-w c:\windows\system32\hnetwiz.dll
2009-03-03 11:26 . 2009-03-03 11:26 2249216 ----a-w c:\windows\system32\netshell.dll
2009-03-03 11:26 . 2009-03-03 11:26 144896 ----a-w c:\windows\system32\ntshrui.dll
2009-03-03 09:19 . 2009-03-03 09:19 445952 ----a-w c:\windows\system32\themeui.dll
2009-03-03 09:19 . 2009-04-21 08:20 139776 ----a-w c:\windows\system32\sndvol32.exe
2009-03-03 09:19 . 2009-03-03 09:19 872448 ----a-w c:\windows\system32\netplwiz.dll
2009-03-03 09:18 . 2009-03-03 09:18 136192 ----a-w c:\windows\system32\netid.dll
2009-03-02 11:33 . 2009-03-02 11:33 1538048 ----a-w c:\windows\explorer.exe
2009-03-02 10:08 . 2009-03-02 10:08 37376 ----a-w c:\windows\system32\wupdmgr.exe
2009-03-02 10:08 . 2009-04-21 08:22 115712 ----a-w c:\windows\system32\wuauclt.exe
2009-03-02 10:08 . 2009-03-02 10:08 1533952 ----a-w c:\windows\system32\wiaacmgr.exe
2009-03-02 10:08 . 2009-03-02 10:08 186880 ----a-w c:\windows\system32\taskmgr.exe
2009-03-02 10:08 . 2009-03-02 10:08 629760 ----a-w c:\windows\system32\sysocmgr.exe
2009-03-02 10:08 . 2009-03-02 10:08 276480 ----a-w c:\windows\regedit.exe
2009-03-02 10:08 . 2009-04-21 08:20 397824 ----a-w c:\windows\system32\mspaint.exe
2009-03-02 10:07 . 2009-04-21 08:22 182784 ----a-w c:\windows\pchealth\helpctr\binaries\msconfig.exe
2009-03-02 10:07 . 2009-03-02 10:07 390144 ----a-w c:\windows\system32\cmd.exe
2009-03-02 10:07 . 2009-04-21 08:20 116224 ----a-w c:\windows\system32\calc.exe
2009-03-02 10:04 . 2009-03-02 10:04 90112 ----a-w c:\windows\system32\mydocs.dll
2009-02-17 21:09 . 2009-02-17 21:09 3996672 ----a-w c:\windows\system32\winntbbu.dll
2009-02-09 18:56 . 2009-04-21 08:32 67584 ----a-w c:\windows\system32\ff_vfw.dll
2009-02-06 15:52 . 2009-02-06 15:52 49504 ----a-w c:\windows\system32\sirenacm.dll
.
------- Sigcheck -------
[-] 2007-12-17 12:23 2342272 EC7B4B2C69D213DE58B3274B8FE67E9A c:\windows\system32\ntkrnlpa.exe
[-] 2007-12-17 12:23 2342272 EC7B4B2C69D213DE58B3274B8FE67E9A c:\windows\system32\ntoskrnl.exe
[-] 2009-03-02 11:33 1538048 F005666A47955CBD5E02FFCAD4DB1B0C c:\windows\explorer.exe
[-] 2009-03-02 10:08 115712 78D1C9C1378ECB5D443E098EA08226E8 c:\windows\system32\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-04-23 2794928]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-23 39408]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-05 280779]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-21 198160]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-10-24 1451264]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-08-24 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-08-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-08-24 114688]
"ACU"="c:\program files\Atheros\ACU.exe" [2005-01-31 253952]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
"PowerKey"="c:\program files\Launch Manager\PowerKey.exe" [2002-08-30 94208]
"LManager"="c:\program files\Launch Manager\HotkeyApp.exe" [2005-11-08 69632]
"CtrlVol"="c:\program files\Launch Manager\CtrlVol.exe" [2003-09-16 20480]
"LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2005-07-25 241664]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2005-11-08 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-04-15 77824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512]
c:\documents and settings\Administrator\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Rainlendar.lnk - c:\program files\Rainlendar\Rainlendar.exe [2005-10-23 118784]
RocketDock.lnk - c:\program files\RocketDock\RocketDock.exe [2009-4-21 630784]
SolidWorks Task Scheduler Engine.lnk - c:\program files\SolidWorks\swScheduler\swBOEngine.exe [2007-9-9 488728]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-9-19 581693]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R1 mailKmd;mailKmd; [x]
R1 Wbutton;Wbutton; [x]
S1 Hotkey;Hotkey; [x]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
S2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2009-04-24 603904]
S3 POWERKEY;POWERKEY;c:\program files\Launch Manager\POWERKEY.sys [2000-12-19 2343]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-05-04 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-04 14:46]
2009-05-04 c:\windows\Tasks\User_Feed_Synchronization-{12BF4DFC-392D-47AA-BDA7-2B2B934E0899}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 01:31]
2009-05-04 c:\windows\Tasks\الصيانة بنقرة واحدة.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-04 14:46]
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-RoboForm - c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/webhp?sourceid=navclient&ie=UTF-8
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = stuproxy.kfupm.edu.sa:80
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: ت&حميل بواسطة فلاش جيت - c:\program files\FlashGet Network\FlashGet universal\ComDlls\Bholink.htm
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: تحميل ال&كل بواسطة فلاش جيت - c:\program files\FlashGet Network\FlashGet universal\ComDlls\Bhoall.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-04 23:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-220523388-1897051121-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4d,6e,22,0b,a4,70,b4,4c,87,6d,45,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4d,6e,22,0b,a4,70,b4,4c,87,6d,45,\
.
Completion time: 2009-05-04 23:59
ComboFix-quarantined-files.txt 2009-05-04 20:59
Pre-Run: 49,757,499,392 bytes free
Post-Run: 49,818,992,640 bytes free
285