يعطيك العافيه اخوي وهذا هو التقرير
بس حبيبت استفسر وش المشكله مع تول بار قوقل احسه عملي كثير هل استطيع ارجاعه مره اخرى او لا
ComboFix 09-05-07.06 - alyami 05/08/2009 3:13.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1256.966.1033.18.2045.1026 [GMT 3:00]
Running from: c:\users\alyami\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\kakle.dll
c:\windows\system32\winitn.dll
D:\Autorun.inf
d:\recycler\S-2-9-76-100029284-100029568-100028152-1714.com
.
((((((((((((((((((((((((( Files Created from 2009-04-08 to 2009-05-08 )))))))))))))))))))))))))))))))
.
2009-05-07 23:55 . 2009-05-07 23:55 -------- d-----w c:\program files\Trend Micro
2009-05-07 17:41 . 2009-05-07 17:40 410984 ----a-w c:\windows\system32\deploytk.dll
2009-05-06 15:45 . 2009-05-06 15:45 -------- d-----w c:\program files\CyberLat
2009-05-06 10:59 . 2009-05-06 10:59 -------- d-----w c:\users\alyami\AppData\Local\Cooliris
2009-05-05 17:48 . 2009-05-05 17:48 -------- d-----w c:\users\alyami\AppData\Roaming\ESET
2009-05-05 17:24 . 2009-05-05 17:24 -------- d-----w c:\program files\ESET(5)
2009-05-05 14:02 . 2009-05-05 14:02 -------- d-----w c:\programdata\Avira
2009-05-05 14:02 . 2009-05-05 14:02 -------- d-----w c:\users\All Users\Avira
2009-05-02 00:18 . 2009-05-02 00:18 -------- d-----w c:\users\alyami\AppData\Local\Apple
2009-04-30 15:15 . 2009-04-30 15:15 -------- d-----w c:\program files\Java
2009-04-29 23:34 . 2009-04-29 23:34 -------- d-----w c:\users\alyami\AppData\Local\Apps
2009-04-29 23:34 . 2009-04-30 16:16 -------- d-----w c:\users\alyami\AppData\Local\Deployment
2009-04-28 18:25 . 2009-04-30 15:30 -------- d-----w c:\program files\Bug Doctor
2009-04-27 23:04 . 2009-05-08 00:09 -------- d-----w c:\users\alyami\AppData\Local\Google
2009-04-27 23:03 . 2009-05-08 00:09 -------- d-----w c:\program files\Google
2009-04-27 01:53 . 2009-04-27 01:53 -------- d-----w c:\users\alyami\AppData\Local\Apple Computer
2009-04-26 22:50 . 2009-04-29 01:30 -------- d-----w c:\users\alyami\AppData\Local\Adobe
2009-04-26 20:47 . 2009-04-26 20:47 -------- d-----w c:\program files\Windows Installer Clean Up
2009-04-26 20:41 . 2009-04-26 20:46 -------- d-----w c:\program files\MSECACHE
2009-04-24 21:27 . 2009-04-24 21:27 53760 ----a-w c:\windows\system\ppacklib.dll
2009-04-24 21:27 . 2009-04-24 21:41 -------- d-----w c:\windows\system32\RMBin
2009-04-19 18:09 . 2009-04-19 18:09 -------- d-----w c:\program files\Common Files\xing shared
2009-04-19 18:08 . 2009-04-19 18:09 -------- d-----w c:\program files\Real
2009-04-18 00:43 . 2009-04-18 00:43 -------- d-----w c:\users\alyami\AppData\Local\Mozilla
2009-04-15 00:15 . 2009-04-15 00:15 -------- d-----w c:\users\alyami\AppData\Local\ESET
2009-04-09 23:53 . 2008-04-17 09:12 107368 ----a-w c:\windows\system32\GEARAspi.dll
2009-04-09 23:53 . 2009-03-19 13:32 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-04-09 23:53 . 2009-04-09 23:53 -------- d-----w c:\program files\iPod
2009-04-09 23:53 . 2009-04-09 23:53 -------- d-----w c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-09 23:53 . 2009-04-09 23:53 -------- d-----w c:\users\All Users\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-09 23:53 . 2009-04-09 23:53 -------- d-----w c:\program files\iTunes
2009-04-09 12:21 . 2009-04-09 12:21 38240 ----a-w c:\windows\system32\drivers\epfwwfp.sys
2009-04-09 12:21 . 2009-04-09 12:21 33096 ----a-w c:\windows\system32\drivers\epfwndis.sys
2009-04-09 12:21 . 2009-04-09 12:21 133000 ----a-w c:\windows\system32\drivers\epfw.sys
2009-04-09 12:18 . 2009-04-09 12:18 107256 ----a-w c:\windows\system32\drivers\ehdrv.sys
2009-04-09 12:10 . 2009-04-09 12:10 113960 ----a-w c:\windows\system32\drivers\eamon.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-07 17:45 . 2009-02-07 19:53 12 ----a-w c:\windows\bthservsdp.dat
2009-05-05 17:57 . 2006-11-02 10:25 86016 ----a-w c:\windows\inf\infstrng.dat
2009-05-05 17:57 . 2006-11-02 10:25 51200 ----a-w c:\windows\inf\infpub.dat
2009-05-05 17:57 . 2006-11-02 10:25 86016 ----a-w c:\windows\inf\infstor.dat
2009-05-05 17:45 . 2009-02-07 19:39 -------- d-----w c:\program files\ESET
2009-05-02 04:07 . 2009-02-08 04:42 131024 ----a-w c:\users\alyami\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-02 03:57 . 2009-02-10 21:04 -------- d-----w c:\program files\Microsoft Works
2009-04-25 22:24 . 2009-02-07 19:48 -------- d-----w c:\program files\Messenger Plus! Live
2009-04-24 21:46 . 2009-04-24 21:27 90112 ----a-w c:\windows\system32\agsaami.dll
2009-04-24 21:46 . 2009-04-24 21:27 610304 ----a-w c:\windows\system32\agsaamg.dll
2009-04-24 21:46 . 2009-04-24 21:27 2535424 ----a-w c:\windows\system32\agsaamj.dll
2009-04-24 21:46 . 2009-04-24 21:27 372736 ----a-w c:\windows\system32\agsaamc.dll
2009-04-24 21:46 . 2003-08-07 12:01 237568 ----a-w c:\windows\system32\lame_enc.dll
2009-04-24 21:46 . 2009-04-24 21:46 -------- d-----w c:\program files\AML Products
2009-04-24 21:40 . 2009-04-24 21:27 196608 ----a-w c:\windows\system32\maag.dll
2009-04-24 21:40 . 2009-04-24 21:27 1212416 ----a-w c:\windows\system32\ckll.dll
2009-04-24 21:40 . 2009-04-24 21:40 823296 ----a-w c:\windows\system32\agsaamh.dll
2009-04-24 21:40 . 2009-04-24 21:40 680061 ----a-w c:\windows\system32\agsaame.dll
2009-04-24 21:40 . 2009-04-24 21:40 655360 ----a-w c:\windows\system32\agsaamd.dll
2009-04-24 21:40 . 2009-04-24 21:40 638976 ----a-w c:\windows\system32\agsaamb.dll
2009-04-24 21:40 . 2009-04-24 21:40 315392 ----a-w c:\windows\system32\agsaama.dll
2009-04-24 21:40 . 2009-04-24 21:27 1986560 ----a-w c:\windows\system32\akll.dll
2009-04-24 21:40 . 2009-04-24 21:27 1245184 ----a-w c:\windows\system32\bkll.dll
2009-04-19 18:09 . 2009-02-16 01:47 -------- d-----w c:\program files\Common Files\Real
2009-04-16 16:03 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-04-11 23:30 . 2009-02-08 04:42 680 ----a-w c:\users\alyami\AppData\Local\d3d9caps.dat
2009-04-09 23:53 . 2009-02-21 00:54 -------- d-----w c:\program files\Common Files\Apple
2009-04-07 22:41 . 2009-03-21 13:35 -------- d-----w c:\program files\Common Files\Adobe
2009-04-07 01:37 . 2009-04-06 21:34 -------- d-----w c:\program files\AviSynth 2.5
2009-04-06 21:33 . 2009-04-06 21:33 -------- d-----w c:\program files\Red Kawa
2009-03-22 16:51 . 2009-03-22 16:51 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-03-21 12:52 . 2009-03-21 12:52 -------- d-----w c:\program files\NOS
2009-03-20 01:56 . 2009-02-17 18:47 -------- d-----w c:\program files\ooVoo
2009-03-18 00:19 . 2009-03-18 00:19 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-03-17 03:38 . 2009-04-16 15:32 13824 ----a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-16 15:32 24064 ----a-w c:\windows\system32\amxread.dll
2009-03-08 11:34 . 2009-05-07 16:23 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-05-07 16:23 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-05-07 16:23 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-05-07 16:23 109056 ----a-w c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-05-07 16:23 109568 ----a-w c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-05-07 16:23 132608 ----a-w c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-05-07 16:23 107520 ----a-w c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-05-07 16:23 107008 ----a-w c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-05-07 16:23 103936 ----a-w c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-05-07 16:23 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-05-07 16:23 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-05-07 16:23 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-05-07 16:23 66560 ----a-w c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-05-07 16:23 169472 ----a-w c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-05-07 16:23 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-05-07 16:23 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2009-05-07 16:23 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2009-05-07 16:23 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-05 20:59 . 2009-03-05 20:59 36864 ----a-w c:\windows\system32\drivers\usbaapl.sys
2009-03-05 20:59 . 2009-03-05 20:59 1900544 ----a-w c:\windows\system32\usbaaplrc.dll
2009-03-03 04:46 . 2009-04-16 15:32 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-16 15:32 3547632 ----a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:39 . 2009-04-16 15:32 183296 ----a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-16 15:32 551424 ----a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-16 15:32 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-16 15:32 98304 ----a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-16 15:32 54784 ----a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-16 15:32 44032 ----a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-16 15:32 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-16 15:32 17408 ----a-w c:\windows\system32\iashost.exe
2009-02-13 08:49 . 2009-04-16 15:32 72704 ----a-w c:\windows\system32\secur32.dll
2009-02-13 08:49 . 2009-04-16 15:32 1255936 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 03:10 . 2009-03-11 21:38 2033152 ----a-w c:\windows\system32\win32k.sys
2009-02-08 04:47 . 2009-02-08 04:47 76 --sh--r c:\windows\CT4CET.bin
2009-02-08 04:26 . 2009-02-08 04:26 2232 ----a-w c:\windows\Java\Packages\Data\NLZXFVHF.DAT
2009-02-08 04:26 . 2009-02-08 04:26 155995 ----a-w c:\windows\Java\Packages\CSPJFPF7.ZIP
2009-02-08 04:26 . 2009-02-08 04:26 2678 ----a-w c:\windows\Java\Packages\Data\SXRRBXJZ.DAT
2009-02-08 04:26 . 2009-02-08 04:26 2678 ----a-w c:\windows\Java\Packages\Data\Y7BH3PBP.DAT
2009-02-08 04:26 . 2009-02-08 04:26 2678 ----a-w c:\windows\Java\Packages\Data\QXJPJPRD.DAT
2009-02-08 04:26 . 2009-02-08 04:26 2678 ----a-w c:\windows\Java\Packages\Data\H73Z3RZV.DAT
2009-02-08 04:25 . 2009-02-08 04:25 2678 ----a-w c:\windows\Java\Packages\Data\CUNFV3RF.DAT
2009-02-08 03:21 . 2009-02-08 03:21 56 ---ha-w c:\users\All Users\ezsidmv.dat
2009-02-08 03:21 . 2009-02-08 03:21 56 ---ha-w c:\programdata\ezsidmv.dat
2009-02-08 02:53 . 2006-11-02 10:25 665600 ----a-w c:\windows\inf\drvindex.dat
2009-02-07 19:22 . 2006-11-02 12:50 174 --sha-w c:\program files\desktop.ini
2009-02-07 19:02 . 2006-11-02 10:32 101888 ----a-w c:\windows\system32\ifxcardm.dll
2009-02-07 19:02 . 2006-11-02 10:32 82432 ----a-w c:\windows\system32\axaltocm.dll
2009-02-07 18:40 . 2009-02-07 18:55 47560 ----a-w c:\windows\system32\SPReview.exe
2009-02-07 18:40 . 2009-02-07 18:55 152576 ----a-w c:\windows\system32\SPWizUI.dll
2009-02-07 18:37 . 2009-02-08 05:16 27430 ----a-w c:\users\alyami\AppData\Roaming\nvModes.dat
2007-02-21 19:49 . 2007-02-21 19:49 8192 --sha-w c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"DELL Webcam Manager"="c:\program files\DELL\DELL Webcam Manager\DellWMgr.exe" [2007-06-07 118784]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-19 2153472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-05-07 405504]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-09 36864]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-27 857648]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-10-04 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-04 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-10-04 81920]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2007-10-04 86016]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-04-09 2029640]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{6631BC37-E1BF-4BA0-8BD5-2F4E717FFCDD}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{D57D890F-6B57-4FF1-80C8-3CFA10424EAA}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{E9682A5C-087B-4C17-84F3-A81F946075F6}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{309FB0A3-56D8-4648-862C-B6AFFA143FBA}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{5180B20B-301F-42EC-9F84-225E33D6FC56}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4A986B01-40D2-4EF2-BEF8-3D8A086B12EB}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{6B40CD25-4CBA-4E8B-9959-986F01056FE1}"= UDP:443

oVoo TCP المنفذ 443
"{539162FF-F71D-401B-AD89-466D7A81431B}"= TCP:443

oVoo UDP المنفذ 443
"{69C7F0FF-68EF-409F-9C0F-C4B56F94DF5C}"= UDP:37674

oVoo TCP المنفذ 37674
"{31BEF810-1A6E-46BB-B6F5-FCB713BB4EEC}"= TCP:37674

oVoo UDP المنفذ 37674
"{8C829408-64FB-4E67-8980-4713E6B2B497}"= TCP:37675

oVoo UDP المنفذ 37675
"{98D4EB63-292B-4594-8940-BE7B4CCD5DD8}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{574EACC5-CEED-4B8D-9EF8-BC27D6980942}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{0A198678-A8AD-44A4-B680-A8A1F0369EBB}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{9236F5BC-5FA8-4EC5-A08E-E811E2DB2FB9}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{7FB4E480-23F0-4AD9-B1AE-1D65AD797CAC}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{E2BBD3B7-E5B2-4863-A0CA-39ED0E8CDE7F}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{4813BEF7-832B-4D56-8270-48C5F00BD493}"= Disabled:UDP:443

oVoo TCP المنفذ 443
"{145C7190-D7D4-490B-9755-F13BFBD4DEDD}"= Disabled:TCP:443

oVoo UDP المنفذ 443
"{1713B9EB-E748-41EF-9951-AC058BC0B515}"= Disabled:UDP:37674

oVoo TCP المنفذ 37674
"{5E6404CA-7EF2-42A4-A6EB-509B22D8528B}"= Disabled:TCP:37674

oVoo UDP المنفذ 37674
"{E138A01C-BA82-43FE-8EC1-BC63D83340C5}"= Disabled:TCP:37675

oVoo UDP المنفذ 37675
"{83663680-66DD-4A7F-AF5C-EB1227BC6830}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{AFDC54C5-0848-4ABD-BC6C-680CFB72DF83}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [4/9/2009 3:18 PM 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [4/9/2009 3:19 PM 731840]
R2 epfwwfp;epfwwfp;c:\windows\System32\drivers\epfwwfp.sys [4/9/2009 3:21 PM 38240]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [1/14/2009 5:53 PM 226656]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [10/10/2007 5:03 PM 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [3/5/2007 10:45 AM 7424]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [3/21/2009 3:52 PM 33176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26684b3d-00e7-11de-a9c8-001dd9e7bc0e}]
\shell\AutoRun\command - F:\PMB_P.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-05-07 c:\windows\Tasks\User_Feed_Synchronization-{87F33411-63F6-4C99-9421-10CF53315085}.job
- c:\windows\system32\msfeedssync.exe [2009-05-07 11:31]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
DPF: Microsoft XML Parser for Java -
FF - ProfilePath - c:\users\alyami\AppData\Roaming\Mozilla\Firefox\Profiles\acsq74ta.default\
FF - component: c:\users\alyami\AppData\Roaming\Mozilla\Firefox\Profiles\acsq74ta.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-08 03:18
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-05-08 3:20
ComboFix-quarantined-files.txt 2009-05-08 00:19
Pre-Run: 64,747,417,600 bytes free
Post-Run: 64,821,624,832 bytes free
255 --- E O F --- 2009-05-07 17:38