أخي ماكس تفضل التقرير
ComboFix 09-06-04.09 - osama&renas 06/05/2009 18:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.2038.1427 [GMT 3:00]
Running from: c:\documents and settings\osama&renas\سطح المكتب\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\OSAMA&~1\LOCALS~1\Temp\mProjector1162230337\File.3.0.9.mfx
c:\docume~1\OSAMA&~1\LOCALS~1\Temp\mProjector1162230337\Flash6MovieV2.3.0.9.mvx
c:\docume~1\OSAMA&~1\LOCALS~1\Temp\mProjector1162230337\FlashPlayer.3.0.9.ocx
c:\docume~1\OSAMA&~1\LOCALS~1\Temp\mProjector1162230337\mPlayer.3.0.9.dll
c:\docume~1\OSAMA&~1\LOCALS~1\Temp\mProjector1162230337\Registry.3.0.9.mfx
c:\docume~1\OSAMA&~1\LOCALS~1\Temp\mProjector1162230337\System.3.0.9.mfx
c:\documents and settings\osama&renas\Favorites\Translator.url
c:\documents and settings\osama&renas\Local Settings\Temp\mProjector1162230337\File.3.0.9.mfx
c:\documents and settings\osama&renas\Local Settings\Temp\mProjector1162230337\Flash6MovieV2.3.0.9.mvx
c:\documents and settings\osama&renas\Local Settings\Temp\mProjector1162230337\FlashPlayer.3.0.9.ocx
c:\documents and settings\osama&renas\Local Settings\Temp\mProjector1162230337\mPlayer.3.0.9.dll
c:\documents and settings\osama&renas\Local Settings\Temp\mProjector1162230337\Registry.3.0.9.mfx
c:\documents and settings\osama&renas\Local Settings\Temp\mProjector1162230337\System.3.0.9.mfx
c:\windows\system32\Cache
c:\windows\system32\kakle.dll
.
((((((((((((((((((((((((( Files Created from 2009-05-05 to 2009-06-05 )))))))))))))))))))))))))))))))
.
2009-06-05 14:53 . 2009-06-05 14:53 -------- d-----w- c:\program files\Trend Micro
2009-06-05 14:11 . 2009-06-05 14:11 -------- d-s---w- c:\documents and settings\osama&renas\UserData
2009-06-05 13:40 . 2009-06-05 13:40 -------- d-----w- c:\documents and settings\LocalService\سطح المكتب
2009-06-05 13:37 . 2009-06-05 13:37 -------- d-----w- c:\windows\IIS Temporary Compressed Files
2009-06-05 13:35 . 2008-04-15 12:00 9216 -c--a-w- c:\windows\system32\dllcache\wamps51.dll
2009-06-05 13:10 . 2008-04-15 12:00 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-06-05 13:09 . 2008-04-15 12:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-06-05 13:09 . 2009-06-05 13:09 -------- d-----w- c:\program files\Windows Media Connect 2
2009-06-05 13:08 . 2009-06-05 13:08 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-06-05 13:06 . 2009-06-05 13:06 23558 ----a-r- c:\documents and settings\osama&renas\Application Data\Microsoft\Installer\{57430A5A-0F17-49B9-B192-C6301260E93C}\_18be6784.exe
2009-06-05 13:06 . 2009-06-05 13:06 23558 ----a-r- c:\documents and settings\osama&renas\Application Data\Microsoft\Installer\{57430A5A-0F17-49B9-B192-C6301260E93C}\_294823.exe
2009-06-05 13:06 . 2009-06-05 13:06 -------- d-----w- c:\program files\الحاسبة المتطورة لـ Microsoft
2009-06-05 12:57 . 2009-06-05 12:57 -------- d-----w- c:\documents and settings\osama&renas\Application Data\InstallShield
2009-06-05 12:33 . 2009-02-20 16:50 52224 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-06-05 12:33 . 2009-02-20 16:50 459264 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-06-05 12:33 . 2009-02-20 16:50 268288 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-06-05 12:33 . 2009-02-20 16:50 63488 -c----w- c:\windows\system32\dllcache\icardie.dll
2009-06-05 12:33 . 2009-02-20 10:20 13824 -c----w- c:\windows\system32\dllcache\ieudinit.exe
2009-06-05 12:33 . 2009-02-20 16:50 383488 -c----w- c:\windows\system32\dllcache\ieapfltr.dll
2009-06-05 12:33 . 2008-07-09 14:25 2455488 -c----w- c:\windows\system32\dllcache\ieapfltr.dat
2009-06-05 12:33 . 2009-02-20 16:50 6066176 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-06-05 12:24 . 2009-06-05 12:24 -------- d-----w- c:\program files\Ask Search Assistant
2009-06-05 12:01 . 2009-06-05 12:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-06-05 01:31 . 2009-06-05 01:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Ascentive
2009-06-05 01:31 . 2009-06-05 01:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Sunbelt Software
2009-06-05 01:14 . 2009-04-08 14:52 32768 ----a-w- c:\windows\system32\Password.dll
2009-06-05 01:08 . 2009-04-08 14:52 223232 ----a-w- c:\windows\system32\sqlite3.dll
2009-06-05 01:08 . 2008-11-07 14:58 20480 ----a-w- c:\windows\system32\SysRestore.dll
2009-06-05 01:08 . 2008-11-06 13:04 36864 ----a-w- c:\windows\system32\ascbalon.dll
2009-06-05 01:08 . 2009-04-08 14:52 86016 ----a-w- c:\windows\system32\SQLiteWrapper.dll
2009-06-05 00:39 . 2009-06-05 00:39 -------- d-----w- c:\documents and settings\osama&renas\Application Data\Avant Profiles
2009-06-05 00:38 . 2009-06-05 01:13 -------- d-----w- c:\program files\Avant Browser
2009-06-05 00:36 . 2009-06-05 00:36 8704 ----a-w- c:\documents and settings\osama&renas\Application Data\Thinstall\Avant Browser (remove only)\40000041a00002h\avant.exe
2009-06-05 00:36 . 2009-06-05 00:36 -------- d-----w- c:\documents and settings\osama&renas\Application Data\Thinstall
2009-06-05 00:33 . 2009-06-05 00:34 -------- d-----w- c:\program files\Circle Developement
2009-06-05 00:33 . 2009-06-05 12:24 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-05 00:33 . 2009-06-05 00:33 -------- d-----w- c:\program files\Windows Live
2009-06-04 23:24 . 2009-06-04 23:24 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-06-04 23:23 . 2009-06-04 23:23 -------- d-sh--w- c:\documents and settings\osama&renas\IETldCache
2009-06-04 23:08 . 2009-06-05 00:27 -------- d-----w- c:\windows\ie8updates
2009-06-04 23:08 . 2009-05-12 05:11 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-06-04 23:04 . 2009-02-20 16:50 78336 -c--a-w- c:\windows\system32\dllcache\ieencode.dll
2009-06-04 23:04 . 2009-02-20 16:50 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-04 22:48 . 2009-06-04 22:48 -------- d-----w- c:\program files\MSXML 4.0
2009-06-04 22:27 . 2009-06-04 22:27 932368 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\profiles-1-6.dll
2009-06-04 22:27 . 2009-06-04 22:27 678416 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\content_interpreter-1-1.dll
2009-06-04 22:27 . 2009-06-04 22:27 604688 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\gsg-3-9.dll
2009-06-04 22:27 . 2009-06-04 22:27 1096208 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\filtration-4-6.dll
2009-06-04 22:27 . 2009-06-04 22:27 522768 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\database-1-5.dll
2009-06-04 22:18 . 2009-06-04 22:18 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-06-04 22:15 . 2009-06-04 22:15 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-06-04 22:15 . 2009-06-04 22:15 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-06-04 22:14 . 2009-06-05 15:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-04 21:44 . 2009-06-04 21:44 -------- d-----w- c:\documents and settings\osama&renas\Contacts
2009-06-04 21:25 . 2008-06-14 17:31 271616 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-06-04 21:25 . 2008-06-14 17:31 271616 ------w- c:\windows\system32\drivers\bthport.sys
2009-06-04 21:25 . 2009-02-09 11:22 2190592 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-06-04 21:25 . 2009-02-09 11:22 2146816 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-06-04 21:25 . 2009-02-09 11:22 2025472 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-06-04 21:25 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-06-04 19:01 . 2009-01-07 15:20 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2009-06-04 19:00 . 2009-06-05 12:38 -------- d--h--w- c:\windows\$hf_mig$
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-05 15:44 . 2009-06-04 13:13 -------- d-----w- c:\documents and settings\osama&renas\Application Data\DMCache
2009-06-05 14:47 . 2008-04-15 12:00 62722 ----a-w- c:\windows\system32\perfc001.dat
2009-06-05 14:47 . 2008-04-15 12:00 309458 ----a-w- c:\windows\system32\perfh001.dat
2009-06-05 13:14 . 2009-06-04 12:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-05 12:56 . 2009-06-04 12:24 -------- d-----w- c:\program files\Ascentive
2009-06-05 12:24 . 2009-06-04 13:19 -------- d-----w- c:\program files\MSN Messenger
2009-06-04 22:19 . 2009-06-04 13:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-06-04 22:14 . 2009-06-04 13:02 -------- d-----w- c:\program files\Kaspersky Lab
2009-06-04 21:23 . 2009-06-04 12:39 -------- d-----w- c:\documents and settings\osama&renas\Application Data\toshiba
2009-06-04 15:11 . 2009-06-04 14:09 -------- d-----w- c:\program files\iColorFolder
2009-06-04 14:36 . 2009-06-04 14:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-04 14:30 . 2009-06-04 12:13 118856 ----a-w- c:\documents and settings\osama&renas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-04 14:17 . 2009-06-04 14:17 -------- d-----w- c:\program files\Microsoft Works
2009-06-04 14:17 . 2009-06-04 14:17 -------- d-----w- c:\program files\MSBuild
2009-06-04 14:08 . 2009-06-04 14:08 -------- d-----w- c:\program files\ClocX
2009-06-04 14:06 . 2009-06-04 14:06 -------- d-----w- c:\documents and settings\osama&renas\Application Data\dvdcss
2009-06-04 13:56 . 2009-06-04 13:56 -------- d-----w- c:\program files\Microsoft.NET
2009-06-04 13:49 . 2009-06-04 13:46 -------- d-----w- c:\program files\Total Video Converter
2009-06-04 13:47 . 2009-06-04 13:47 -------- d-----w- c:\documents and settings\osama&renas\Application Data\ACD Systems
2009-06-04 13:46 . 2009-06-04 13:46 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-06-04 13:46 . 2009-06-04 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\ACD Systems
2009-06-04 13:46 . 2009-06-04 13:46 -------- d-----w- c:\program files\ACD Systems
2009-06-04 13:45 . 2009-06-04 12:36 10368 ----a-w- c:\windows\system32\drivers\pfc.sys
2009-06-04 13:36 . 2009-06-04 12:28 21361 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-06-04 13:32 . 2009-06-04 13:32 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-04 13:32 . 2009-06-04 13:32 -------- d-----w- c:\program files\Java
2009-06-04 13:30 . 2008-04-15 12:00 862720 ----a-w- c:\windows\system32\shdoclc.dll
2009-06-04 13:26 . 2008-04-15 12:00 131072 ----a-w- c:\windows\system32\mycomput.dll
2009-06-04 13:21 . 2009-06-04 13:21 -------- d-----w- c:\program files\DSL Speed
2009-06-04 13:20 . 2008-04-15 12:00 1949184 ----a-w- c:\windows\system32\logonui.exe
2009-06-04 13:16 . 2009-06-04 13:16 -------- d-----w- c:\documents and settings\osama&renas\Application Data\Ahead
2009-06-04 13:14 . 2009-06-04 13:13 -------- d-----w- c:\program files\Internet Download Manager
2009-06-04 13:13 . 2009-06-04 13:13 95928 ----a-w- c:\documents and settings\osama&renas\Application Data\IDM\idmmzcc\components\idmmzcc.dll
2009-06-04 13:13 . 2009-06-04 13:13 -------- d-----w- c:\documents and settings\osama&renas\Application Data\IDM
2009-06-04 13:12 . 2009-06-04 13:12 -------- d-----w- c:\documents and settings\osama&renas\Application Data\vlc
2009-06-04 13:12 . 2009-06-04 13:12 -------- d-----w- c:\program files\CyberLat
2009-06-04 13:09 . 2009-06-04 13:09 -------- d-----w- c:\program files\GlobFX
2009-06-04 13:09 . 2009-06-04 13:09 -------- d-----w- c:\documents and settings\osama&renas\Application Data\Intel
2009-06-04 13:09 . 2009-06-04 13:09 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Intel
2009-06-04 13:09 . 2009-06-04 13:09 -------- d-----w- c:\documents and settings\LocalService\Application Data\Intel
2009-06-04 13:09 . 2009-06-04 13:09 -------- d-----w- c:\documents and settings\Default User\Application Data\Intel
2009-06-04 13:08 . 2009-06-04 13:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel
2009-06-04 13:08 . 2009-06-04 12:29 -------- d-----w- c:\program files\Intel
2009-06-04 13:06 . 2009-06-04 13:06 -------- d-----w- c:\program files\Google
2009-06-04 13:06 . 2009-06-04 13:06 196608 ----a-w- c:\windows\system32\maag.dll
2009-06-04 13:06 . 2009-06-04 13:06 1245184 ----a-w- c:\windows\system32\bkll.dll
2009-06-04 13:06 . 2009-06-04 13:06 1212416 ----a-w- c:\windows\system32\ckll.dll
2009-06-04 13:06 . 2009-06-04 13:06 1986560 ----a-w- c:\windows\system32\akll.dll
2009-06-04 13:06 . 2009-06-04 13:06 90112 ----a-w- c:\windows\system32\agsaami.dll
2009-06-04 13:06 . 2009-06-04 13:06 610304 ----a-w- c:\windows\system32\agsaamg.dll
2009-06-04 13:06 . 2009-06-04 13:06 372736 ----a-w- c:\windows\system32\agsaamc.dll
2009-06-04 13:06 . 2009-06-04 13:06 2535424 ----a-w- c:\windows\system32\agsaamj.dll
2009-06-04 13:06 . 2009-06-04 13:05 -------- d-----w- c:\program files\Real_SC
2009-06-04 13:04 . 2009-06-04 13:04 40960 ----a-r- c:\documents and settings\osama&renas\Application Data\Microsoft\Installer\{0568801A-94CE-448B-A9FB-093C2ECB2132}\NewShortcut2_0568801A94CE448BA9FB093C2ECB2132.exe
2009-06-04 13:04 . 2009-06-04 13:04 40960 ----a-r- c:\documents and settings\osama&renas\Application Data\Microsoft\Installer\{0568801A-94CE-448B-A9FB-093C2ECB2132}\NewShortcut1_0568801A94CE448BA9FB093C2ECB2132.exe
2009-06-04 13:04 . 2009-06-04 13:04 10134 ----a-r- c:\documents and settings\osama&renas\Application Data\Microsoft\Installer\{0568801A-94CE-448B-A9FB-093C2ECB2132}\ARPPRODUCTICON.exe
2009-06-04 13:04 . 2009-06-04 13:04 -------- d-----w- c:\program files\Samy Soft
2009-06-04 12:58 . 2009-06-04 12:58 12846 ----a-r- c:\documents and settings\osama&renas\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_D3DD076B988600E59BFD1E.exe
2009-06-04 12:58 . 2009-06-04 12:58 12846 ----a-r- c:\documents and settings\osama&renas\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_CA1D36A8BD7C6E8B327132.exe
2009-06-04 12:58 . 2009-06-04 12:58 12846 ----a-r- c:\documents and settings\osama&renas\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_A17D378A7C093FF2005726.exe
2009-06-04 12:58 . 2009-06-04 12:58 12846 ----a-r- c:\documents and settings\osama&renas\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_6FEFF9B68218417F98F549.exe
2009-06-04 12:58 . 2009-06-04 12:58 12846 ----a-r- c:\documents and settings\osama&renas\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_67DB1B8F6A28368D658316.exe
2009-06-04 12:58 . 2009-06-04 12:58 12846 ----a-r- c:\documents and settings\osama&renas\Application Data\Microsoft\Installer\{EA5A0CD7-C894-4FA8-88A5-0887E8257E4A}\_64E749EF31745C29AAF314.exe
2009-06-04 12:58 . 2009-06-04 12:58 -------- d-----w- c:\program files\FriendFinder
2009-06-04 12:57 . 2009-06-04 12:57 -------- d-----w- c:\program files\VideoLAN
2009-06-04 12:40 . 2009-06-04 12:40 -------- d-----w- c:\program files\ltmoh
2009-06-04 12:40 . 2009-06-04 12:40 -------- d-----w- c:\program files\DVD-RAM
2009-06-04 12:39 . 2009-06-04 12:26 -------- d-----w- c:\program files\TOSHIBA
2009-06-04 12:38 . 2009-06-04 12:38 10134 ----a-r- c:\documents and settings\osama&renas\Application Data\Microsoft\Installer\{C45F4811-31D5-4786-801D-F79CD06EDD85}\ARPPRODUCTICON.exe
2009-06-04 12:37 . 2009-06-04 12:37 -------- d-----w- c:\program files\Realtek AC97
2009-06-04 12:36 . 2009-06-04 12:36 -------- d-----w- c:\program files\Apoint2K
2009-06-04 12:35 . 2009-06-04 12:33 -------- d-----w- c:\program files\InterVideo
2009-06-04 12:32 . 2009-06-04 12:32 -------- d-----w- c:\program files\Sonic
2009-06-04 12:28 . 2009-06-04 12:28 -------- d-----w- c:\program files\Atheros
2009-06-04 12:27 . 2009-06-04 12:27 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-04 12:26 . 2009-06-04 12:24 -------- d-----w- c:\program files\Common Files\InstallShield
2009-06-04 12:24 . 2009-06-04 12:22 102259 ----a-w- c:\windows\hpoins05.dat
2009-06-04 12:23 . 2009-06-04 12:23 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-06-04 12:23 . 2009-06-04 12:23 -------- d-----w- c:\program files\HP
2009-06-04 12:23 . 2009-06-04 12:23 -------- d-----w- c:\program files\Common Files\xing shared
2009-06-04 12:23 . 2009-06-04 12:23 -------- d-----w- c:\program files\Common Files\Real
2009-06-04 12:23 . 2009-06-04 12:23 -------- d-----w- c:\program files\Real
2009-06-04 12:05 . 2009-06-04 12:05 -------- d-----w- c:\program files\microsoft frontpage
2009-06-04 12:04 . 2009-06-04 12:04 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-04 12:01 . 2009-06-04 12:01 22144 ----a-w- c:\windows\system32\emptyregdb.dat
2009-05-25 02:21 . 2009-05-25 02:21 219664 ----a-w- c:\windows\system32\klogon.dll
2009-05-25 02:18 . 2009-05-25 02:18 27507 ----a-w- c:\windows\system32\drivers\klopp.dat
2009-05-25 01:41 . 2009-05-25 01:41 59992 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 2010 9.0.0.459\English\setup.exe
2009-05-25 01:41 . 2009-05-25 01:41 59976 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2010 9.0.0.459\English\setup.exe
2009-05-24 12:30 . 2009-05-24 12:30 128016 ----a-w- c:\windows\system32\drivers\kl1.sys
2009-05-16 17:59 . 2009-05-16 17:59 19472 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2009-05-13 14:46 . 2009-05-13 14:46 31760 ----a-w- c:\windows\system32\drivers\klim5.sys
2009-04-08 14:52 . 2009-06-04 12:25 217088 ----a-w- c:\windows\system32\ConTest.dll
.
------- Sigcheck -------
[-] 2009-06-04 13:25 1656832 2DB37ABB69BDCAF7D2E7D8CD8F0E8164 c:\windows\explorer.exe
[-] 2009-06-04 13:25 1656832 2DB37ABB69BDCAF7D2E7D8CD8F0E8164 c:\windows\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 65536]
"IMC"="c:\program files\FriendFinder\FriendFinder Messenger 4\imc.exe" [2008-01-14 4053102]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2007-01-12 885944]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CyberLat Ram Cleaner"="c:\program files\CyberLat\CyberLat RAM Cleaner 2" [X]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-04 185896]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"Tvs"="c:\program files\TOSHIBA\Tvs\TvsTray.exe" [2005-04-05 73728]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-03-23 196608]
"HWSetup"="c:\program files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-05-01 28672]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 995328]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 1101824]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-04 136600]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"avp"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-05-25 303376]
"TFncKy"="TFncKy.exe" [BU]
"NDSTray.exe"="NDSTray.exe" [BU]
"TCtryIOHook"="TCtrlIOHook.exe" - c:\windows\system32\TCtrlIOHook.exe [2005-08-22 28672]
"Zooming"="ZoomingHook.exe" - c:\windows\system32\ZoomingHook.exe [2005-06-06 24576]
"TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-08-11 266240]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2004-12-21 88358]
"CFSServ.exe"="CFSServ.exe" [BU]
"MsmqIntCert"="mqrt.dll" - c:\windows\system32\mqrt.dll [2008-04-15 177152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
c:\documents and settings\osama&renas\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2009-6-4 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [15/12/2008 08:41 م 33808]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13/05/2009 05:46 م 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16/05/2009 08:59 م 19472]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Performance Center - c:\program files\Ascentive\Performance Center\ApcMain.exe
HKLM-Run-Device Detector - DevDetect.exe
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.plusnetwork.com/
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
IE: Download All Links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
IE: {{CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-05 18:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\acs.exe
c:\windows\system32\msdtc.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\snmp.exe
c:\windows\system32\mqsvc.exe
c:\windows\system32\mqtgsvc.exe
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\program files\CyberLat\CyberLat RAM Cleaner 2,0\CLRamCleaner.exe
c:\program files\Common Files\ACD Systems\EN\DevDetect.exe
c:\program files\Apoint2K\ApntEx.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\windows\system32\wbem\wmiadap.exe
.
**************************************************************************
.
Completion time: 2009-06-05 18:47 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-05 15:47
Pre-Run: 27,421,696,000 bytes free
Post-Run: 28,270,174,208 bytes free
303 --- E O F --- 2009-06-05 14:40