ComboFix 09-06-01.03 - ahmad 06/04/2009 13:34.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.963.1025.18.503.212 [GMT 3:00]
Running from: c:\documents and settings\ahmad\سطح المكتب\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-05-04 to 2009-06-04 )))))))))))))))))))))))))))))))
.
2009-06-01 13:36 . 2009-06-01 13:36 -------- d-----w- c:\program files\Ozone
2009-06-01 13:02 . 2009-06-01 13:02 -------- d-----w- c:\program files\Trend Micro
2009-06-01 09:15 . 1998-09-02 08:28 38160 ----a-w- c:\windows\system32\LMRTREND.dll
2009-06-01 09:15 . 1998-08-27 04:51 182032 ----a-w- c:\windows\system32\dxtmsft3.dll
2009-06-01 09:15 . 1998-09-02 08:28 63488 ----a-w- c:\windows\system32\unam4ie.exe
2009-06-01 09:14 . 1998-08-17 09:21 10240 ----a-w- c:\windows\system32\vidx16.dll
2009-06-01 09:14 . 1998-08-17 09:21 11776 ----a-w- c:\windows\system32\mciqtz.drv
2009-06-01 09:14 . 1998-09-02 08:02 194320 ----a-w- c:\windows\system32\qcut.dll
2009-06-01 09:14 . 2009-06-01 09:14 4608 ----a-w- c:\windows\system32\w95inf32.dll
2009-06-01 09:14 . 2009-06-01 09:14 2272 ----a-w- c:\windows\system32\w95inf16.dll
2009-06-01 09:13 . 2009-06-01 09:13 -------- d-----w- c:\program files\Auralog
2009-05-28 12:00 . 2009-06-01 13:37 18628608 ----a-w- c:\windows\system32\viscomavi.dll
2009-05-28 11:59 . 2009-06-01 13:37 237568 ----a-w- c:\windows\system32\lame_enc.dll
2009-05-13 12:49 . 2009-05-13 12:49 -------- d-----w- c:\program files\CequenzeTech
2009-05-11 11:08 . 2009-05-11 11:08 -------- d-----w- c:\documents and settings\ahmad\Library
2009-05-11 11:08 . 2009-05-11 11:08 -------- d-----w- c:\documents and settings\ahmad\Application Data\com.adobe.ExMan
2009-05-10 12:11 . 2009-05-10 12:11 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\FLEXnet
2009-05-10 11:56 . 2009-05-10 11:56 -------- d-----w- c:\program files\Adobe Media Player
2009-05-10 11:51 . 2009-05-10 11:51 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-05-10 11:43 . 2009-05-10 11:43 -------- d-----w- c:\program files\Common Files\Macrovision Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-04 10:37 . 2001-09-19 14:00 391262 ----a-w- c:\windows\system32\perfh001.dat
2009-06-04 10:37 . 2001-09-19 14:00 75896 ----a-w- c:\windows\system32\perfc001.dat
2009-06-04 10:32 . 2009-04-20 16:35 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2009-06-04 10:30 . 2009-04-20 16:35 565280 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-04 10:30 . 2009-04-20 16:35 4060 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-04 10:30 . 2009-04-20 16:35 2928160 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-04 10:30 . 2009-04-20 16:35 25004 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-03 11:41 . 2009-01-18 15:45 -------- d-----w- c:\documents and settings\ahmad\Application Data\DMCache
2009-06-03 11:12 . 2009-02-03 12:13 -------- d-----w- c:\program files\NetTimer 2000
2009-05-28 10:20 . 2009-01-18 15:31 -------- d---a-w- c:\docume~1\ALLUSE~1\APPLIC~1\TEMP
2009-05-26 12:04 . 2009-04-20 16:36 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-26 12:04 . 2009-04-20 16:36 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-24 12:44 . 2009-02-13 12:02 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Apple Computer
2009-05-23 13:03 . 2009-01-18 16:09 -------- d-----w- c:\documents and settings\ahmad\Application Data\PC Suite
2009-05-19 11:40 . 2009-01-18 16:05 -------- d-----w- c:\program files\AnMing
2009-05-11 10:35 . 2009-01-18 14:17 -------- d-----w- c:\program files\Quick Button NT
2009-05-10 12:15 . 2009-01-20 13:09 136848 ----a-w- c:\documents and settings\ahmad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-10 11:59 . 2009-02-19 13:19 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-03 10:51 . 2009-05-01 19:35 -------- d-----w- c:\program files\AlbaniV2
2009-05-02 11:16 . 2009-03-15 15:47 -------- d-----w- c:\documents and settings\ahmad\Application Data\Ulead Systems
2009-05-02 11:05 . 2009-05-02 11:05 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\InterVideo
2009-05-02 11:04 . 2009-01-18 14:06 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-02 11:04 . 2009-05-02 11:02 -------- d-----w- c:\program files\Common Files\Ulead Systems
2009-05-02 11:02 . 2009-03-15 14:41 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Ulead Systems
2009-05-02 11:02 . 2009-05-02 10:59 -------- d-----w- c:\program files\Corel
2009-05-02 10:59 . 2009-05-02 10:59 -------- d-----w- c:\documents and settings\ahmad\Application Data\InstallShield
2009-05-01 21:15 . 2009-03-06 18:20 -------- d-----w- c:\program files\Ashampoo
2009-05-01 19:58 . 2009-05-01 19:22 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-05-01 19:51 . 2009-03-15 14:35 -------- d-----w- c:\program files\Ulead Systems
2009-05-01 19:34 . 2009-05-01 19:34 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-01 12:33 . 2009-01-18 15:45 -------- d-----w- c:\documents and settings\ahmad\Application Data\IDM
2009-05-01 12:32 . 2009-01-18 15:45 -------- d-----w- c:\program files\Internet Download Manager
2009-04-21 11:17 . 2008-01-29 14:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-04-20 17:10 . 2009-04-20 17:10 -------- d-----w- c:\documents and settings\ahmad\Application Data\Windows Live Writer
2009-04-20 17:02 . 2009-01-18 16:20 -------- d-----w- c:\program files\Kaspersky Lab
2009-04-20 16:18 . 2009-04-01 11:38 -------- d-----w- c:\program files\Windows Live
2009-04-20 16:17 . 2009-04-20 16:17 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-04-20 16:16 . 2009-04-20 16:16 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-04-18 11:13 . 2009-01-18 15:57 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-04-15 13:13 . 2009-04-15 13:13 -------- d-----w- c:\program files\Common Files\xing shared
2009-04-15 13:12 . 2009-01-18 16:03 -------- d-----w- c:\program files\Common Files\Real
2009-04-15 13:12 . 2009-01-18 15:21 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-04-13 14:16 . 2009-01-18 14:48 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Microsoft Help
2009-04-07 11:07 . 2009-04-07 11:07 -------- d-----w- c:\documents and settings\ahmad\Application Data\Transcend
2009-03-26 15:35 . 2009-04-29 12:20 210352 ----a-w- c:\windows\system32\idmmbc.dll
2009-03-24 13:55 . 2009-01-18 15:55 29480 ----a-w- c:\windows\system32\msxml3a.dll
2009-03-24 13:55 . 2009-01-18 15:21 353576 ----a-w- c:\windows\system32\msvcr71.dll
2009-03-14 11:52 . 2009-03-14 11:52 63488 ----a-w- c:\windows\xobglu16.dll
2009-03-14 11:52 . 2009-03-14 11:52 23552 ----a-w- c:\windows\xobglu32.dll
2009-03-12 13:15 . 2009-02-25 15:58 450560 ----a-w- c:\windows\system32\maai.dll
2009-03-12 13:15 . 2009-02-25 15:58 1040384 ----a-w- c:\windows\system32\maah.dll
2009-03-12 13:15 . 2009-02-25 15:58 835584 ----a-w- c:\windows\system32\maae.dll
2009-03-12 13:15 . 2009-02-25 15:58 729088 ----a-w- c:\windows\system32\maad.dll
2009-03-12 13:15 . 2009-02-25 15:58 335872 ----a-w- c:\windows\system32\maac.dll
2009-03-12 13:15 . 2009-02-25 15:58 315392 ----a-w- c:\windows\system32\maab.dll
2009-03-12 13:15 . 2009-02-25 15:58 311296 ----a-w- c:\windows\system32\maaf.dll
2009-03-08 01:34 . 2008-04-14 10:29 914944 ----a-w- c:\windows\system32\wininet.dll
2009-03-08 01:34 . 2008-04-14 10:29 43008 ----a-w- c:\windows\system32\licmgr10.dll
2009-03-08 01:33 . 2008-04-14 10:29 18944 ----a-w- c:\windows\system32\corpol.dll
2009-03-08 01:33 . 2008-04-14 10:29 420352 ----a-w- c:\windows\system32\vbscript.dll
2009-03-08 01:32 . 2008-04-14 10:29 72704 ----a-w- c:\windows\system32\admparse.dll
2009-03-08 01:32 . 2008-04-14 10:29 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-03-08 01:31 . 2008-04-14 10:29 34816 ----a-w- c:\windows\system32\imgutil.dll
2009-03-08 01:31 . 2008-04-14 10:05 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-03-08 01:31 . 2008-04-14 10:29 45568 ----a-w- c:\windows\system32\mshta.exe
2009-03-08 01:22 . 2001-09-19 14:00 156160 ----a-w- c:\windows\system32\msls31.dll
2009-03-06 14:20 . 2008-04-14 10:29 283136 ----a-w- c:\windows\system32\pdh.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-06-04_10.17.38 )))))))))))))))))))))))))))))))))))))))))
.
- 2001-09-19 14:00 . 2009-06-03 11:11 75792 c:\windows\system32\perfc009.dat
+ 2001-09-19 14:00 . 2009-06-04 10:37 75792 c:\windows\system32\perfc009.dat
+ 2001-09-19 14:00 . 2009-06-04 10:37 457138 c:\windows\system32\perfh009.dat
- 2001-09-19 14:00 . 2009-06-03 11:11 457138 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"NetTimer 2000"="c:\program files\NetTimer 2000\NetTimer.exe" [2001-09-08 788992]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2003-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2003-01-23 114688]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-03-20 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-03-20 634880]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-04-21 206088]
"UVS12 Preload"="c:\program files\Corel\Corel VideoStudio 12\uvPL.exe" [2009-04-10 393216]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-15 198160]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-11-15 77824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\ahmad\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
QuickPB.exe.lnk - c:\program files\Quick Button NT\QuickPB.exe [2009-1-18 802816]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ComPlusSetup]
2008-04-14 10:29 625664 ----a-w- c:\windows\system32\catsrvut.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"OPSE reminder"="c:\program files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "c:\program files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"BDRegion"=c:\program files\Cyberlink\Shared Files\brs.exe
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe"
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 05:29 م 33808]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\
000.fcl [27/06/2008 05:50 م 61424]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [18/01/2009 06:57 م 603904]
R3 {5C8B2B62-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-A;c:\windows\system32\drivers\a311.sys [18/01/2009 05:09 م 31799]
R3 {5C8B2B65-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-B;c:\windows\system32\drivers\a310.sys [18/01/2009 05:09 م 33335]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 06:02 م 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 05:06 م 24592]
S3 PortTalk;PortTalk; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/ig?hl=ar
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: إضافة إلى حاجب إعلان الشعار - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} - hxxp://www.qurancomplex.com/Downloads/FontSmooth.cab
FF - ProfilePath - c:\docume~1\ahmad\APPLIC~1\Mozilla\Firefox\Profiles\1lpwxvth.default\
FF - prefs.js: browser.startup.homepage - hxxp://scs-net.org/portal/
FF - prefs.js: network.proxy.ftp - proxy.scs-net.org
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - proxy.scs-net.org
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - proxy.scs-net.org
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - proxy.scs-net.org
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - proxy.scs-net.org
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 1
FF - component: c:\documents and settings\ahmad\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: content.notify.interval - 750000
FF - user.js: content.max.tokenizing.time - 2250000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-04 13:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\
000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-854245398-746137067-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*n*b*u*)* \OpenWithList]
@Class="Shell"
"a"="ContentCopier.exe"
"MRUList"="a"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):87,58,b1,b2,90,25,0a,55,ec,c9,da,77,8a,96,cf,6e,66,ae,3b,b8,1a,
79,70,75,4c,f2,72,aa,79,44,3d,ce,a4,31,d6,85,04,c8,9f,81,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{afa1dba9-bf73-4184-8cb8-4473cb37fead}]
@Denied: (Full) (Everyone)
"Model"=dword:00000092
"Therad"=dword:00000021
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,98,07,ff,fc,5d,
df,1c,2f,3b,8a,0a,32,11,89,01,b5,4c,21,de,81,97,76,b9,7c,3a,9a,63,c8,7b,43,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1308)
c:\windows\system32\msi.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(812)
c:\windows\system32\SynTPFcs.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2009-06-04 13:58
ComboFix-quarantined-files.txt 2009-06-04 10:57
Pre-Run: 2,993,778,688 bytes free
Post-Run: 2,971,512,832 bytes free
271 --- E O F --- 2009-05-27 11:14