وهذا التقرير بس مازالت به شاشه مفتوحه
ComboFix 09-05-06.02 - khaleed 05/07/2009 4:09.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.1014.532 [GMT 3:00]
Running from: c:\documents and settings\khaleed\سطح المكتب\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Mozilla Firefox\components\iamfamous.dll
c:\windows\IE4 Error Log.txt
c:\windows\system32\kakle.dll
c:\windows\system32\ogacheckcontrol.dll
c:\windows\system32\tmp.reg
c:\windows\system32\winitn.dll
D:\resycled
d:\resycled\boot.com
E:\resycled
e:\resycled\boot.com
.
((((((((((((((((((((((((( Files Created from 2009-04-07 to 2009-05-07 )))))))))))))))))))))))))))))))
.
2009-05-06 21:52 . 2009-05-06 21:52 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-05-06 16:11 . 2009-05-06 16:11 -------- d-----w c:\documents and settings\khaleed\Application Data\CyberScrub
2009-05-06 16:06 . 2009-05-06 16:06 -------- d-----w c:\documents and settings\khaleed\Application Data\cleaner
2009-05-04 19:54 . 2009-05-04 19:54 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-05-03 19:36 . 2009-05-03 19:36 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-05-03 19:30 . 2009-05-06 02:18 -------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-05-01 19:21 . 2009-05-01 19:22 147456 ----a-w c:\windows\AVUNTOOL.EXE
2009-05-01 19:16 . 2009-05-01 19:19 -------- d-----w c:\program files\Photoshop
2009-04-27 00:53 . 2008-04-14 15:59 116224 -c--a-w c:\windows\system32\dllcache\xrxwiadr.dll
2009-04-27 00:53 . 2001-09-18 11:05 23040 -c--a-w c:\windows\system32\dllcache\xrxwbtmp.dll
2009-04-27 00:53 . 2008-04-14 15:59 18944 -c--a-w c:\windows\system32\dllcache\xrxscnui.dll
2009-04-27 00:53 . 2001-09-18 11:06 27648 -c--a-w c:\windows\system32\dllcache\xrxftplt.exe
2009-04-27 00:53 . 2001-09-18 11:06 4608 -c--a-w c:\windows\system32\dllcache\xrxflnch.exe
2009-04-27 00:53 . 2001-09-18 11:06 99865 -c--a-w c:\windows\system32\dllcache\xlog.exe
2009-04-27 00:53 . 2001-08-17 09:11 16970 -c--a-w c:\windows\system32\dllcache\xem336n5.sys
2009-04-27 00:53 . 2004-08-03 19:29 19455 -c--a-w c:\windows\system32\dllcache\wvchntxx.sys
2009-04-27 00:53 . 2008-04-13 18:46 19200 -c--a-w c:\windows\system32\dllcache\wstcodec.sys
2009-04-27 00:53 . 2004-08-03 19:29 12063 -c--a-w c:\windows\system32\dllcache\wsiintxx.sys
2009-04-27 00:53 . 2004-08-03 19:31 154624 -c--a-w c:\windows\system32\dllcache\wlluc48.sys
2009-04-27 00:51 . 2001-08-17 10:28 64605 -c--a-w c:\windows\system32\dllcache\vvoice.sys
2009-04-27 00:50 . 2008-04-13 18:45 17152 -c--a-w c:\windows\system32\dllcache\usbohci.sys
2009-04-27 00:49 . 2001-08-17 09:51 159232 -c--a-w c:\windows\system32\dllcache\tridkbm.sys
2009-04-27 00:48 . 2001-08-17 09:13 37961 -c--a-w c:\windows\system32\dllcache\tdk100b.sys
2009-04-27 00:47 . 2008-04-13 18:46 15232 -c--a-w c:\windows\system32\dllcache\streamip.sys
2009-04-27 00:46 . 2001-08-17 10:53 7040 -c--a-w c:\windows\system32\dllcache\snyaitmc.sys
2009-04-27 00:45 . 2004-08-03 19:31 32768 -c--a-w c:\windows\system32\dllcache\sisnic.sys
2009-04-27 00:44 . 2001-09-18 10:27 17280 -c--a-w c:\windows\system32\dllcache\scr111.sys
2009-04-27 00:43 . 2001-09-18 11:05 82432 -c--a-w c:\windows\system32\dllcache\rwia450.dll
2009-04-27 00:42 . 2001-08-17 10:52 49024 -c--a-w c:\windows\system32\dllcache\ql1280.sys
2009-04-27 00:41 . 2001-08-17 11:04 173696 -c--a-w c:\windows\system32\dllcache\philcam2.sys
2009-04-27 00:40 . 2001-08-17 11:05 25216 -c--a-w c:\windows\system32\dllcache\ovsound2.sys
2009-04-27 00:39 . 2008-04-13 18:54 28672 -c--a-w c:\windows\system32\dllcache\nscirda.sys
2009-04-27 00:38 . 2001-09-18 10:44 75520 -c--a-w c:\windows\system32\dllcache\mxport.sys
2009-04-27 00:37 . 2001-08-17 10:57 16128 -c--a-w c:\windows\system32\dllcache\modemcsa.sys
2009-04-27 00:36 . 2001-08-17 10:53 4992 -c--a-w c:\windows\system32\dllcache\loop.sys
2009-04-27 00:35 . 2001-08-17 10:49 26624 -c--a-w c:\windows\system32\dllcache\irstusb.sys
2009-04-27 00:34 . 2001-09-18 11:04 91648 -c--a-w c:\windows\system32\dllcache\icam4com.dll
2009-04-27 00:33 . 2001-08-17 10:28 44863 -c--a-w c:\windows\system32\dllcache\hsf_soar.sys
2009-04-27 00:32 . 2001-09-18 11:04 119296 -c--a-w c:\windows\system32\dllcache\hpdigwia.dll
2009-04-27 00:31 . 2001-08-17 09:10 22090 -c--a-w c:\windows\system32\dllcache\fem556n5.sys
2009-04-27 00:30 . 2001-08-17 09:19 283904 -c--a-w c:\windows\system32\dllcache\emu10k1m.sys
2009-04-27 00:29 . 2001-09-18 11:04 38985 -c--a-w c:\windows\system32\dllcache\disrvsu.dll
2009-04-27 00:28 . 2001-08-17 09:19 6912 -c--a-w c:\windows\system32\dllcache\ctlfacem.sys
2009-04-27 00:27 . 2001-09-18 10:31 13824 -c--a-w c:\windows\system32\dllcache\bulltlp3.sys
2009-04-27 00:26 . 2001-08-17 11:07 101888 -c--a-w c:\windows\system32\dllcache\adpu160m.sys
2009-04-25 20:48 . 2009-05-06 22:39 -------- d-----w c:\program files\Password Protect USB
2009-04-24 04:34 . 2009-04-24 04:34 44544 ------w c:\windows\AWuninstall.exe
2009-04-22 17:51 . 2009-05-03 19:37 -------- d-----w c:\program files\Google
2009-04-21 22:58 . 2009-04-21 23:48 -------- d-----w c:\windows\SxsCaPendDel
2009-04-21 22:56 . 2009-04-21 22:56 -------- d-----w c:\windows\__SkypeIEToolbar_Cache
2009-04-20 23:38 . 2009-04-20 23:39 -------- d-----w c:\program files\WMV9_VCM
2009-04-20 23:38 . 2009-04-20 23:43 -------- d-----w c:\documents and settings\khaleed\Local Settings\Application Data\Xara
2009-04-20 23:38 . 2009-04-21 01:22 -------- d-----w c:\program files\Xara
2009-04-19 23:09 . 2009-04-22 00:51 -------- d-----w c:\documents and settings\khaleed\Application Data\Skype
2009-04-19 23:08 . 2009-04-19 23:08 -------- d-----r c:\program files\Skype
2009-04-19 23:07 . 2009-04-19 23:08 -------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-04-17 23:26 . 2009-04-17 23:26 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2009-04-17 16:13 . 2009-04-17 16:13 -------- d-----w c:\program files\MSECache
2009-04-14 03:09 . 2009-04-14 03:09 -------- d--h--w c:\windows\PIF
2009-04-13 20:54 . 2009-04-13 20:54 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-04-13 01:16 . 2009-04-13 01:19 -------- dc-h--w c:\windows\ie8
2009-04-10 00:09 . 2009-04-10 00:09 -------- d-----w c:\documents and settings\khaleed\Local Settings\Application Data\Downloaded Installations
2009-04-08 00:48 . 2009-04-08 00:48 344064 ----a-w c:\windows\system32\dkll.dll
2009-04-08 00:48 . 2009-04-08 00:48 196608 ----a-w c:\windows\system32\maag.dll
2009-04-08 00:48 . 2009-04-08 00:48 1212416 ----a-w c:\windows\system32\ckll.dll
2009-04-08 00:48 . 2009-04-08 00:51 1245184 ----a-w c:\windows\system32\bkll.dll
2009-04-08 00:48 . 2009-04-08 00:48 1986560 ----a-w c:\windows\system32\akll.dll
2009-04-08 00:48 . 2009-04-08 00:51 90112 ----a-w c:\windows\system32\agsaami.dll
2009-04-08 00:48 . 2009-04-08 00:51 2846720 ----a-w c:\windows\system32\agsaamj.dll
2009-04-08 00:48 . 2009-04-08 00:51 753664 ----a-w c:\windows\system32\agsaamg.dll
2009-04-08 00:48 . 2009-04-08 00:51 372736 ----a-w c:\windows\system32\agsaamc.dll
2009-04-08 00:48 . 2009-04-08 00:48 53760 ----a-w c:\windows\system\ppacklib.dll
2009-04-08 00:48 . 2006-07-28 22:22 51712 ----a-w c:\windows\system32\coodest.dll
2009-04-08 00:48 . 2003-08-07 12:01 237568 ----a-w c:\windows\system32\lame_enc.dll
2009-04-08 00:48 . 2005-05-19 00:17 40960 ----a-w c:\windows\system32\osenxpsuite2005.dll
2009-04-08 00:47 . 2002-01-05 08:37 344064 ----a-w c:\windows\system32\msvcr70.dll
2009-04-08 00:47 . 2002-01-05 02:40 487424 ----a-w c:\windows\system32\msvcp70.dll
2009-04-08 00:47 . 2002-01-05 03:48 974848 ----a-w c:\windows\system32\mfc70.dll
2009-04-08 00:47 . 2009-04-08 00:47 -------- d-----w c:\windows\system32\RMBin
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-07 01:13 . 2008-10-14 16:33 909344 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-07 01:13 . 2008-10-14 16:33 6284 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-07 01:13 . 2008-10-14 16:33 3766816 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-07 01:13 . 2008-10-14 16:33 33652 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-06 21:57 . 2007-10-29 12:00 443412 ----a-w c:\windows\system32\perfh001.dat
2009-05-06 21:57 . 2007-10-29 12:00 109752 ----a-w c:\windows\system32\perfc001.dat
2009-05-04 19:35 . 2008-10-14 19:03 350480 ----a-w c:\documents and settings\khaleed\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-27 19:15 . 2008-12-06 09:49 -------- d-----w c:\program files\Kelk 2000
2009-04-22 17:24 . 2008-10-17 21:34 -------- d-----w c:\program files\No-IP
2009-04-20 23:38 . 2008-10-14 16:20 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-08 00:55 . 2008-10-14 11:41 -------- d-----w c:\program files\Dell
2009-04-07 00:53 . 2009-04-07 00:53 34 ---ha-w c:\windows\system32\DVDRippper_sysquict.dat
2009-04-07 00:49 . 2009-04-07 00:49 -------- d-----w c:\program files\K-Lite Codec Pack
2009-04-06 17:30 . 2009-04-06 17:30 -------- d-----w c:\program files\SplashData
2009-04-04 20:46 . 2009-04-04 20:46 -------- d-----w c:\program files\Addition
2009-04-01 01:35 . 2009-04-01 01:34 -------- d-----w c:\program files\iTunes
2009-04-01 01:34 . 2009-04-01 01:34 -------- d-----w c:\program files\iPod
2009-04-01 01:34 . 2009-03-17 17:39 -------- d-----w c:\program files\Common Files\Apple
2009-04-01 00:36 . 2009-03-25 17:21 -------- d-----w c:\program files\WinSCP
2009-03-30 15:50 . 2009-03-30 15:50 -------- d-----w c:\program files\Selteco
2009-03-29 23:25 . 2008-10-14 16:34 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-03-29 23:25 . 2008-10-14 16:34 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-03-29 15:57 . 2009-03-25 18:54 -------- d-----w c:\program files\iPhone Tunnel Suite 2.7 BETA
2009-03-25 00:13 . 2008-10-14 19:03 -------- d-----w c:\program files\Messenger Plus! Live
2009-03-17 17:40 . 2009-03-17 17:40 -------- d-----w c:\program files\QuickTime
2009-03-17 17:39 . 2009-03-17 17:39 -------- d-----w c:\program files\Apple Software Update
2009-03-16 17:00 . 2009-03-16 17:00 -------- d-----w c:\program files\Studio V5
2009-03-08 01:34 . 2007-10-29 12:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 01:34 . 2007-10-29 12:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 01:33 . 2007-10-29 12:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 01:33 . 2007-10-29 12:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 01:32 . 2007-10-29 12:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 01:32 . 2007-10-29 12:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 01:31 . 2007-10-29 12:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 01:31 . 2007-10-29 12:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 01:31 . 2007-10-29 12:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 01:22 . 2007-10-29 12:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:20 . 2007-10-29 12:00 283136 ----a-w c:\windows\system32\pdh.dll
2009-03-05 20:59 . 2009-03-17 17:39 36864 ----a-w c:\windows\system32\drivers\usbaapl.sys
2009-03-05 20:59 . 2009-03-17 17:39 1900544 ----a-w c:\windows\system32\usbaaplrc.dll
2009-02-10 17:05 . 2008-01-29 15:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-09 14:04 . 2007-10-29 12:00 1846656 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:22 . 2004-08-04 00:48 2025472 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:22 . 2007-10-29 12:00 2146816 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:21 . 2007-10-29 12:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-09 10:51 . 2007-10-29 12:00 723456 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:51 . 2007-10-29 12:00 681472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:51 . 2007-10-29 12:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:51 . 2007-10-29 12:00 693760 ----a-w c:\windows\system32\ntdll.dll
2009-02-06 16:43 . 2009-02-06 16:43 307576 ----a-w c:\windows\WLXPGSS.SCR
2009-02-06 15:52 . 2009-02-06 15:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-06 10:39 . 2007-10-29 12:00 35328 ----a-w c:\windows\system32\sc.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-01 1392640]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-10 206088]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-30 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-30 162584]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-03 1032192]
"pdfFactory Pro Dispatcher v2"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" [2003-11-10 385024]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-15 185872]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
c:\documents and settings\khaleed\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Ela-Salaty.lnk - c:\program files\Ela-Salaty\Salaty.exe [2007-3-5 5349888]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-16 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=c:\windows\pss\Microsoft Office OneNote 2003 Quick Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iPhone Tunnel Suite 2.7 BETA\\iTunnel\\iTunnel.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\SplashData\\File Magic for iPhone\\File Magic.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 06:29 م 33808]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [14/01/2009 05:53 م 226656]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 07:02 م 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 06:06 م 24592]
S2 gupdate1c9cc267b3c819a;خدمة تحديث Google (gupdate1c9cc267b3c819a);c:\program files\Google\Update\GoogleUpdate.exe [03/05/2009 10:36 م 133104]
S3 ADM851X;Infineon ADM851X USB To Fast Ethernet MII Adapter Driver;c:\windows\system32\drivers\ADM851X.SYS [26/11/2008 06:22 م 25856]
S3 Ndisprot;ArcNet NDIS Protocol Driver;c:\windows\system32\drivers\ndisprot.sys [26/11/2008 01:57 ص 27904]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5451f9a5-ebf5-11dd-8f0a-001c262c8695}]
\Shell\AutoRun\command - H:\WDSetup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A8B23B20-1300-02B2-996B-91A5548059F3}]
c:\docume~1\khaleed\LOCALS~1\Temp\Rar$EX00.281\ar 1.2.exe
.
Contents of the 'Scheduled Tasks' folder
2009-03-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
2009-05-07 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-03 19:30]
2009-05-07 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-03 19:36]
2009-05-06 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-05-07 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-05-06 c:\windows\Tasks\User_Feed_Synchronization-{5275A366-9829-4CA4-9A7A-B93C6887C964}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 01:31]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKLM-Run-SystemInit - (no file)
HKLM-Run-Karen - (no file)
HKLM-Run-raVe - (no file)
HKLM-Run-Win32BaseServiceMOD - (no file)
HKLM-Run-startIE - (no file)
HKU-Default-Run-Nokia.PCSync - c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = local
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: Download All Links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath -
.
.
------- File Associations -------
.
txtfile=NOTEPAD %1
vbefile\shell\edit\command=c:\windows\Notepad.exe %1
vbsfile\shell\edit\command=c:\windows\Notepad.exe %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-07 04:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1520ea69-9f5f-4615-a6db-aff76f87d115}]
@Denied: (Full) (Everyone)
"Model"=dword:00000016
"Therad"=dword:00000013
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{34a6d826-cc94-403a-83bb-ebf633bfc40b}]
@Denied: (Full) (Everyone)
"Model"=dword:00000143
"Therad"=dword:00000017
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):c2,a3,3a,fe,cb,59,f1,61,ca,53,f5,7b,f1,01,0a,85,37,0b,77,8a,b8,
01,15,0b,9a,e4,e3,b9,85,37,04,81,97,cc,58,4b,17,11,c3,55,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):16,a9,4a,4a,4f,7b,6b,fd,c7,0a,09,a8,99,b3,4f,45,b4,60,90,58,07,
3a,57,8f,93,c4,98,63,28,de,7c,4e,65,d7,b7,14,f5,f5,a7,f9,00,00,00,00,00,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(4072)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ara.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\program files\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\Crypserv.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\windows\system32\rundll32.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
.
**************************************************************************
.
Completion time: 2009-05-07 4:28 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-07 01:27
Pre-Run: 22,246,084,608 bytes free
Post-Run: 22,221,316,096 bytes free
321 --- E O F --- 2009-05-04 17:21