اخوي اعتز بك ... هذا هو التقرير اللي طلع عندي بعد الفحص من قبل الاداة
ComboFix 09-05-16.03 - FS user 05/16/2009 23:24.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.985.629 [GMT 3:00]
Running from: c:\documents and settings\FS user\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\kakle.dll
c:\windows\system32\winitn.dll
c:\windows\twain_16.dll
.
((((((((((((((((((((((((( Files Created from 2009-04-16 to 2009-05-16 )))))))))))))))))))))))))))))))
.
2009-05-16 20:17 . 2009-05-16 20:19 -------- d-----w c:\documents and settings\FS user\Application Data\cleaner
2009-05-15 21:30 . 2009-05-15 21:30 -------- d-----w c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-05-15 21:30 . 2009-05-15 21:30 -------- d-----w c:\documents and settings\FS user\Application Data\Recordpad
2009-05-14 16:22 . 2009-05-14 16:22 -------- d-----w c:\program files\ma-config.com
2009-05-14 16:22 . 2009-05-14 16:22 -------- d-----w c:\documents and settings\All Users\Application Data\ma-config.com
2009-05-13 18:21 . 2009-05-13 18:21 -------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-05-11 18:02 . 2008-10-16 11:06 208744 ----a-w c:\windows\system32\muweb.dll
2009-05-11 18:02 . 2008-10-16 11:06 268648 ----a-w c:\windows\system32\mucltui.dll
2009-05-10 22:51 . 2009-05-16 17:00 -------- d-----w c:\documents and settings\FS user\Tracing
2009-05-10 22:50 . 2009-05-12 00:25 -------- d-----w c:\program files\Microsoft Silverlight
2009-05-10 22:50 . 2009-05-10 22:50 -------- d-----w c:\program files\Microsoft Office Outlook Connector
2009-05-10 22:49 . 2009-02-06 15:08 55152 ----a-w c:\windows\system32\drivers\fssfltr_tdi.sys
2009-05-10 22:47 . 2009-05-10 22:47 -------- d-----w c:\program files\Microsoft Sync Framework
2009-05-10 22:46 . 2006-11-29 10:06 3426072 ----a-w c:\windows\system32\d3dx9_32.dll
2009-05-10 22:46 . 2009-05-10 22:46 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-05-10 22:44 . 2009-05-10 22:50 -------- d-----w c:\program files\Microsoft
2009-05-10 22:44 . 2009-05-10 22:44 -------- d-----w c:\program files\Windows Live SkyDrive
2009-05-10 21:44 . 2009-05-10 21:44 -------- d-----w c:\program files\Common Files\Windows Live
2009-05-08 23:10 . 2009-05-08 23:10 -------- d-----w c:\windows\system32\scripting
2009-05-08 23:10 . 2009-05-08 23:10 -------- d-----w c:\windows\l2schemas
2009-05-08 23:10 . 2009-05-08 23:10 -------- d-----w c:\windows\system32\en
2009-05-08 23:10 . 2009-05-08 23:10 -------- d-----w c:\windows\system32\bits
2009-05-08 23:08 . 2009-05-08 23:11 -------- d-----w c:\windows\ServicePackFiles
2009-05-06 17:04 . 2009-05-06 17:04 -------- d-----w c:\documents and settings\FS user\Local Settings\Application Data\Apple Computer
2009-05-04 20:53 . 2009-05-15 21:30 -------- d-----w c:\documents and settings\FS user\Application Data\NCH Swift Sound
2009-05-04 20:52 . 2009-05-04 20:52 -------- d-----w c:\program files\NCH Software
2009-05-04 20:50 . 2009-05-04 20:56 -------- d-----w c:\program files\NCH Swift Sound
2009-05-02 00:40 . 2009-05-02 00:40 -------- d-----w c:\documents and settings\FS user\Application Data\vlc
2009-05-01 23:41 . 2007-10-18 11:25 41856 ----a-w c:\windows\system32\drivers\tosrfusb.sys
2009-05-01 23:41 . 2008-03-25 13:24 131712 ----a-w c:\windows\system32\drivers\tosrfbd.sys
2009-05-01 23:41 . 2008-03-19 08:38 74112 ----a-w c:\windows\system32\drivers\Tosrfhid.sys
2009-05-01 23:41 . 2007-11-29 06:45 36608 ----a-w c:\windows\system32\drivers\tosrfbnp.sys
2009-05-01 23:41 . 2005-01-07 02:42 18612 ----a-w c:\windows\system32\drivers\tosrfnds.sys
2009-05-01 23:41 . 2008-01-22 17:57 54144 ----a-w c:\windows\system32\drivers\TosRfSnd.sys
2009-05-01 23:41 . 2007-10-02 08:43 64128 ----a-w c:\windows\system32\drivers\tosrfcom.sys
2009-05-01 23:41 . 2008-03-25 10:54 41472 ----a-w c:\windows\system32\drivers\tosporte.sys
2009-05-01 23:41 . 2009-05-01 23:41 -------- d-----w c:\program files\Toshiba
2009-05-01 17:16 . 2004-08-03 19:29 52224 ------w c:\windows\system32\drivers\atinraxx.sys
2009-05-01 16:04 . 2009-05-01 16:04 -------- d-----w c:\program files\MSXML 4.0
2009-05-01 16:02 . 2008-06-13 11:05 272128 -c----w c:\windows\system32\dllcache\bthport.sys
2009-05-01 15:54 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-05-01 15:54 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-05-01 15:54 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-05-01 15:54 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-05-01 15:54 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-05-01 15:54 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-05-01 15:54 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-05-01 15:54 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-05-01 15:54 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-05-01 15:54 . 2009-02-06 11:06 2145280 -c----w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-05-01 15:54 . 2009-02-06 11:08 2189056 -c----w c:\windows\system32\dllcache\ntoskrnl.exe
2009-05-01 15:54 . 2009-02-06 10:32 2023936 -c----w c:\windows\system32\dllcache\ntkrpamp.exe
2009-05-01 15:40 . 2008-05-08 14:02 203136 -c----w c:\windows\system32\dllcache\rmcast.sys
2009-05-01 15:39 . 2008-10-24 11:21 455296 -c----w c:\windows\system32\dllcache\mrxsmb.sys
2009-05-01 15:39 . 2008-12-11 10:57 333952 -c----w c:\windows\system32\dllcache\srv.sys
2009-05-01 15:37 . 2008-04-11 19:04 691712 -c----w c:\windows\system32\dllcache\inetcomm.dll
2009-05-01 15:32 . 2008-10-15 16:34 337408 -c----w c:\windows\system32\dllcache\netapi32.dll
2009-05-01 15:23 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-05-01 15:23 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-05-01 15:22 . 2009-05-11 18:18 -------- d--h--w c:\windows\$hf_mig$
2009-04-30 19:29 . 2009-04-30 19:29 -------- d-----w c:\documents and settings\FS user\Local Settings\Application Data\Identities
2009-04-30 16:27 . 2009-04-30 16:27 -------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-04-30 14:34 . 2007-01-22 21:43 277504 ----a-w c:\windows\system32\oestore.dll
2009-04-30 14:34 . 2009-04-30 14:34 -------- d-----w c:\program files\Acesoft
2009-04-30 13:47 . 2009-04-30 13:47 -------- d-----w c:\program files\Ask Search Assistant
2009-04-30 13:44 . 2009-05-10 22:45 -------- d-----w c:\program files\MSN Messenger
2009-04-30 11:21 . 2009-04-30 13:47 -------- d-----w c:\program files\Messenger Plus! Live
2009-04-29 17:22 . 2009-04-29 17:22 -------- d-s---w c:\documents and settings\FS user\UserData
2009-04-29 15:56 . 2009-05-07 23:30 -------- d-----w c:\documents and settings\FS user\Contacts
2009-04-27 14:47 . 2009-04-29 16:30 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-04-27 14:47 . 2009-04-29 16:30 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-04-27 14:47 . 2009-05-16 20:26 1835040 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-27 14:47 . 2009-05-16 20:26 368672 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-27 14:47 . 2009-04-27 14:47 -------- d-----w c:\program files\Kaspersky Lab
2009-04-27 14:47 . 2009-05-16 19:18 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-27 14:45 . 2009-04-27 14:45 286720 ----a-w c:\windows\iun503.exe
2009-04-27 14:45 . 2009-04-27 14:45 -------- d-----w c:\program files\Dictionary (Arabic)
2009-04-27 14:44 . 2009-04-27 14:44 -------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2009-04-27 14:44 . 2009-04-27 14:44 -------- d-----w c:\documents and settings\FS user\Application Data\CyberLink
2009-04-27 14:44 . 2009-05-04 23:33 -------- d-----w c:\program files\Windows Media Connect 2
2009-04-27 14:43 . 2009-04-27 14:43 -------- d-----w c:\windows\system32\drivers\UMDF
2009-04-27 14:43 . 2009-04-27 14:43 -------- d-----w c:\windows\system32\LogFiles
2009-04-27 14:42 . 2009-05-10 22:49 -------- d-----w c:\program files\Windows Live
2009-04-27 14:40 . 2009-04-27 14:40 -------- d-----w c:\documents and settings\FS user\Application Data\Apple Computer
2009-04-27 14:39 . 2009-04-27 14:39 -------- d-----w c:\program files\Common Files\xing shared
2009-04-27 14:39 . 2009-04-27 14:40 -------- d-----w c:\program files\QuickTime
2009-04-27 14:39 . 2009-04-27 14:39 -------- d-----w c:\program files\Real
2009-04-27 14:39 . 2009-04-27 14:39 -------- d-----w c:\program files\Common Files\Real
2009-04-27 14:39 . 2009-04-27 14:39 -------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-04-27 14:38 . 2009-04-27 14:38 47104 ------w c:\windows\AKDeInstall.exe
2009-04-27 14:38 . 2009-04-27 14:38 -------- d-----w c:\program files\mpegable
2009-04-27 14:38 . 2009-04-27 14:38 -------- d-----w c:\documents and settings\FS user\Application Data\Skype
2009-04-27 14:37 . 2009-04-27 14:37 -------- d-----w c:\program files\Common Files\Skype
2009-04-27 14:37 . 2009-04-27 14:37 -------- d-----r c:\program files\Skype
2009-04-27 14:37 . 2009-04-27 14:37 -------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-04-27 14:28 . 2009-04-27 14:28 -------- d-----w c:\documents and settings\All Users\Application Data\GRETECH
2009-04-27 14:28 . 2009-04-27 14:28 -------- d-----w c:\documents and settings\FS user\Application Data\GRETECH
2009-04-27 14:28 . 2009-04-27 14:28 -------- d-----w c:\program files\GRETECH
2009-04-27 14:28 . 2006-05-13 18:29 843 ----a-w C:\ChangeWinXPKey.vbs
2009-04-27 14:27 . 2009-04-27 14:27 -------- d-----w c:\windows\speech
2009-04-27 14:27 . 2009-04-27 14:27 -------- d-----w c:\program files\Golden Al-Wafi Translator
2009-04-27 14:27 . 2009-04-27 14:27 172032 ------w c:\windows\Setup1.exe
2009-04-27 14:27 . 2009-04-27 14:27 73216 ----a-w c:\windows\ST6UNST.EXE
2009-04-27 14:27 . 2001-08-17 10:48 12160 -c--a-w c:\windows\system32\dllcache\mouhid.sys
2009-04-27 14:27 . 2001-08-17 10:48 12160 ----a-w c:\windows\system32\drivers\mouhid.sys
2009-04-27 14:27 . 2008-04-13 18:45 10368 ----a-w c:\windows\system32\drivers\hidusb.sys
2009-04-27 14:27 . 2009-05-04 23:45 -------- d-----w c:\documents and settings\FS user\Local Settings\Application Data\ACD Systems
2009-04-27 14:26 . 2009-04-27 14:26 -------- d-----w c:\documents and settings\FS user\Application Data\ACD Systems
2009-04-27 14:26 . 2009-04-27 14:44 -------- d-----w c:\program files\Common Files\Adobe
2009-04-27 14:26 . 2009-04-27 14:26 -------- d-----w c:\windows\Cache
2009-04-27 14:26 . 2009-04-27 14:26 -------- d-----w c:\documents and settings\All Users\Application Data\ACD Systems
2009-04-27 14:26 . 2009-04-27 14:26 -------- d-----w c:\program files\Common Files\ACD Systems
2009-04-27 14:26 . 2009-04-27 14:26 -------- d-----w c:\program files\ACD Systems
2009-04-27 14:25 . 2009-04-27 14:25 -------- d-----w c:\documents and settings\FS user\Local Settings\Application Data\Downloaded Installations
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-16 20:26 . 2009-04-27 14:47 3388 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-16 20:26 . 2009-04-27 14:47 17512 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-30 11:20 . 2009-04-27 10:08 99496 ----a-w c:\documents and settings\FS user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-29 20:21 . 2009-04-27 14:36 -------- d-----w c:\program files\The KMPlayer
2009-04-29 16:30 . 2008-01-29 14:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-04-27 14:46 . 2009-04-27 14:46 344064 ----a-w c:\windows\system32\dkll.dll
2009-04-27 14:46 . 2009-04-27 14:46 1986560 ----a-w c:\windows\system32\akll.dll
2009-04-27 14:46 . 2009-04-27 14:46 196608 ----a-w c:\windows\system32\maag.dll
2009-04-27 14:46 . 2009-04-27 14:46 1212416 ----a-w c:\windows\system32\ckll.dll
2009-04-27 14:46 . 2009-04-27 14:46 -------- d-----w c:\program files\Ozone
2009-04-27 14:39 . 2009-04-27 10:24 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-04-27 14:39 . 2009-04-27 10:24 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-04-27 14:39 . 2009-04-27 10:23 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-27 14:36 . 2009-04-27 14:36 -------- d-----w c:\program files\VideoLAN
2009-04-27 14:36 . 2009-04-27 14:36 -------- d-----w c:\program files\Typing Arabic
2009-04-27 10:42 . 2009-04-27 10:42 -------- d-----w c:\program files\Atheros
2009-04-27 10:42 . 2009-04-27 10:24 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-27 10:41 . 2009-04-27 10:41 251 ----a-w c:\windows\xUninstall.bat
2009-04-27 10:40 . 2009-04-27 10:40 -------- d-----w c:\program files\Synaptics
2009-04-27 10:39 . 2009-04-27 10:39 -------- d-----w c:\program files\Motorola
2009-04-27 10:37 . 2009-04-27 10:37 -------- d-----w c:\program files\Realtek
2009-04-27 10:37 . 2009-04-27 10:37 315392 ----a-w c:\windows\HideWin.exe
2009-04-27 10:34 . 2009-04-27 10:34 -------- d-----w c:\program files\Intel
2009-04-27 10:30 . 2009-04-27 10:30 -------- d-----w c:\program files\Common Files\Ahead
2009-04-27 10:30 . 2009-04-27 10:30 -------- d-----w c:\program files\Nero
2009-04-27 10:24 . 2009-04-27 10:24 -------- d-----w c:\program files\CyberLink
2009-04-27 10:18 . 2009-04-27 10:18 -------- d-----w c:\program files\Microsoft Works
2009-04-27 10:17 . 2009-04-27 10:17 -------- d-----w c:\program files\MSBuild
2009-04-27 10:00 . 2009-04-27 10:00 -------- d-----w c:\program files\microsoft frontpage
2009-04-27 09:57 . 2009-04-27 09:57 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-06 14:22 . 2004-08-03 22:56 284160 ----a-w c:\windows\system32\pdh.dll
2009-02-20 08:10 . 2004-08-03 22:56 666112 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2004-08-03 22:56 81920 ----a-w c:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Tracks Eraser Pro"="c:\program files\Acesoft\Tracks Eraser Pro\te.exe" [2007-05-23 1327104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-07-14 570664]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-17 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-17 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-17 150040]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-10-26 671744]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-05-08 1105920]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-27 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-04-27 155648]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-28 75136]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-04-29 206088]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-03-26 16859136]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SoundMan.exe [2006-07-21 86016]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\alcwzrd.exe [2006-05-04 2808832]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2007-11-1 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPCS.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 05:29 م 33808]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [11/05/2009 01:49 ص 55152]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [14/01/2009 05:53 م 226656]
R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [11/04/2008 05:55 م 84240]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 05:06 م 24592]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 06:08 م 533360]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [13/05/2009 02:37 م 234864]
.
Contents of the 'Scheduled Tasks' folder
2009-05-16 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-05-16 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
.
.
------- Supplementary Scan -------
.
mWindow Title =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-16 23:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2020)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\rundll32.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Windows Live\Toolbar\wltuser.exe
.
**************************************************************************
.
Completion time: 2009-05-16 23:31 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-16 20:31
Pre-Run: 41,252,372,480 bytes free
Post-Run: 41,115,492,352 bytes free
270 --- E O F --- 2009-05-13 18:20