مشكووور اخوي على مساعدتك لي واعذرني مارديت عليك بدري
تفضل التقرير :
ComboFix 09-06-07.05 - SPARK PLUGS 06/08/2009 20:16.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1256.966.1025.18.3070.2309 [GMT 3:00]
Running from: c:\users\SPARK PLUGS\Downloads\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE}
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
SP: AntiVir Desktop *enabled* (Updated) {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE}
SP: Kaspersky Internet Security *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\SPARKP~1\AppData\Local\Temp\install_flash_player.exe
c:\windows\system32\WgaLogon.dll
.
((((((((((((((((((((((((( Files Created from 2009-05-08 to 2009-06-08 )))))))))))))))))))))))))))))))
.
2009-06-08 17:20 . 2009-06-08 17:21 -------- d-----w- c:\users\SPARK PLUGS\AppData\Local\temp
2009-06-08 17:14 . 2009-06-08 17:21 -------- d-s---w- \ComboFix
2009-06-08 17:14 . 2009-06-08 17:14 -------- d-----w- \Qoobox
2009-06-07 23:01 . 2009-06-07 23:02 -------- d-----w- c:\program files\Quranzu1
2009-06-05 21:40 . 2008-07-12 05:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2009-06-04 13:32 . 2009-06-08 07:21 12 ----a-w- c:\windows\bthservsdp.dat
2009-06-02 14:34 . 2009-06-02 14:34 667976 ----a-w- c:\windows\system32\360x180° Mekan.scr
2009-06-02 14:34 . 2009-06-02 14:34 -------- d-----w- c:\windows\system32\mekanlar
2009-06-02 14:33 . 2009-06-02 14:33 4096 ----a-w- c:\windows\d3dx.dat
2009-05-31 19:52 . 2009-05-31 20:01 -------- d-----w- c:\programdata\HP
2009-05-29 01:46 . 2009-05-29 01:46 -------- d-----w- c:\programdata\MumboJumbo
2009-05-29 01:45 . 2009-06-06 17:40 -------- d-----w- c:\program files\Luxor Quest For The Afterlife
2009-05-14 21:56 . 2009-05-21 22:22 -------- d-----w- c:\users\SPARK PLUGS\AppData\Roaming\Desktopicon
2009-05-14 21:56 . 2009-05-14 21:56 -------- d-----w- c:\program files\FormatFactory
2009-05-14 21:34 . 2009-05-25 20:15 -------- d-----w- c:\program files\Microsoft Works
2009-05-14 21:32 . 2009-05-14 21:32 -------- d-----w- c:\program files\Microsoft.NET
2009-05-14 21:30 . 2009-05-14 21:30 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-05-14 21:28 . 2009-05-14 21:28 -------- d--h--r- C:\MSOCache
2009-05-14 21:28 . 2009-05-14 21:28 -------- d--h--r- \MSOCache
2009-05-10 22:12 . 2009-05-10 22:12 -------- d-----w- c:\users\SPARK PLUGS\AppData\Roaming\VitySoft
2009-05-10 02:09 . 2009-05-10 02:10 198064 ----a-w- c:\users\SPARK PLUGS\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
2009-05-09 18:02 . 2008-09-28 19:00 439440 ----a-w- c:\program files\un_Internet Download Manager_16575.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-08 17:21 . 2009-04-23 02:51 -------- d-----w- c:\users\SPARK PLUGS\AppData\Roaming\DMCache
2009-06-08 11:06 . 2009-04-23 13:37 -------- d-----w- c:\programdata\Kaspersky Lab
2009-06-08 11:05 . 2009-04-22 18:37 3219644416 --sha-w- \hiberfil.sys
2009-06-08 11:05 . 2009-04-22 18:33 3533258752 --sha-w- \pagefile.sys
2009-06-08 07:21 . 2009-04-23 13:37 540704 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-08 07:21 . 2009-04-23 13:37 2928 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-08 07:21 . 2009-04-23 13:37 2802720 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-08 07:21 . 2009-04-23 13:37 24024 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-07 05:20 . 2006-12-05 05:25 79198 ----a-w- c:\windows\system32\perfc001.dat
2009-06-07 05:20 . 2006-12-05 05:25 441596 ----a-w- c:\windows\system32\perfh001.dat
2009-06-05 21:40 . 2006-11-02 12:35 -------- d-----w- c:\program files\Microsoft Games
2009-05-31 20:03 . 2009-05-31 20:03 -------- d-----w- c:\users\SPARK PLUGS\AppData\Roaming\HP
2009-05-31 20:03 . 2009-05-31 19:52 173358 ----a-w- c:\windows\hphins25.dat
2009-05-31 20:03 . 2009-05-31 20:03 -------- d-----w- c:\programdata\WEBREG
2009-05-31 20:00 . 2009-05-31 20:00 -------- d-----w- c:\programdata\Hewlett-Packard
2009-05-31 19:56 . 2009-05-31 19:56 -------- d-----w- c:\programdata\HP Product Assistant
2009-05-31 19:56 . 2009-05-31 19:53 -------- d-----w- c:\program files\HP
2009-05-31 19:55 . 2009-05-31 19:55 -------- d-----w- c:\program files\Common Files\HP
2009-05-29 16:42 . 2009-04-22 18:44 115576 ----a-w- c:\users\SPARK PLUGS\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-29 01:06 . 2009-04-23 02:51 -------- d-----w- c:\users\SPARK PLUGS\AppData\Roaming\IDM
2009-05-26 17:49 . 2009-05-05 02:55 -------- d-----w- c:\programdata\Microsoft Help
2009-05-25 20:45 . 2009-04-23 01:12 -------- d-----w- c:\programdata\NVIDIA
2009-05-24 19:09 . 2009-04-23 01:02 -------- d-----w- c:\program files\Common Files\InstallShield
2009-05-22 21:40 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-20 13:50 . 2009-04-23 13:38 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-20 13:50 . 2009-04-23 13:38 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-14 21:33 . 2006-11-02 12:35 -------- d-----w- c:\program files\MSBuild
2009-05-10 02:09 . 2009-04-23 02:51 -------- d-----w- c:\program files\Internet Download Manager
2009-05-09 18:02 . 2009-05-09 18:02 6066 ----a-w- c:\program files\un_Internet Download Manager_16575.txt
2009-05-08 16:56 . 2009-05-08 16:56 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-05-07 12:57 . 2009-05-07 12:58 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-07 12:57 . 2009-05-07 12:57 -------- d-----w- c:\program files\Java
2009-05-06 17:13 . 2009-04-23 12:23 -------- d-----w- c:\programdata\Messenger Plus!
2009-05-05 18:20 . 2009-04-23 01:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-05 17:25 . 2009-05-05 17:25 -------- d-----w- c:\program files\Enlight
2009-05-05 11:58 . 2009-05-05 11:58 -------- d-----w- c:\program files\BitLocker
2009-05-05 11:44 . 2009-04-23 01:19 -------- d-----w- c:\program files\CONEXANT
2009-05-04 00:34 . 2009-05-04 00:34 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-05-03 23:22 . 2009-05-03 23:22 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-05-03 20:56 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-05-03 20:56 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-05-03 20:56 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Journal
2009-05-03 20:56 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2009-05-03 20:56 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2009-05-03 20:55 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-05-03 20:54 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-05-03 20:21 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2009-05-03 20:21 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2009-05-01 23:27 . 2009-05-01 23:27 -------- d-----w- c:\users\SPARK PLUGS\AppData\Roaming\Ahead
2009-04-30 21:03 . 2009-04-23 13:48 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-04-30 21:03 . 2009-04-23 13:48 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-04-23 23:24 . 2009-04-23 23:24 269312 ----a-w- c:\windows\system32\es.dll
2009-04-23 23:20 . 2009-04-23 23:20 6656 ----a-w- c:\windows\system32\kbd106n.dll
2009-04-23 23:20 . 2009-04-23 23:20 988216 ----a-w- c:\windows\system32\winload.exe
2009-04-23 23:20 . 2009-04-23 23:20 927288 ----a-w- c:\windows\system32\winresume.exe
2009-04-23 23:20 . 2009-04-23 23:20 40960 ----a-w- c:\windows\system32\srclient.dll
2009-04-23 23:20 . 2009-04-23 23:20 378368 ----a-w- c:\windows\system32\srcore.dll
2009-04-23 23:20 . 2009-04-23 23:20 318464 ----a-w- c:\windows\system32\rstrui.exe
2009-04-23 23:20 . 2009-04-23 23:20 19000 ----a-w- c:\windows\system32\kd1394.dll
2009-04-23 23:20 . 2009-04-23 23:20 14848 ----a-w- c:\windows\system32\srdelayed.exe
2009-04-23 23:20 . 2009-04-23 23:20 615992 ----a-w- c:\windows\system32\ci.dll
2009-04-23 23:20 . 2009-04-23 23:20 46592 ----a-w- c:\windows\system32\setbcdlocale.dll
2009-04-23 23:03 . 2009-04-23 23:03 96760 ----a-w- c:\windows\system32\dfshim.dll
2009-04-23 23:03 . 2009-04-23 23:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-04-23 23:03 . 2009-04-23 23:03 282112 ----a-w- c:\windows\system32\mscoree.dll
2009-04-23 23:03 . 2009-04-23 23:03 83968 ----a-w- c:\windows\system32\mscories.dll
2009-04-23 23:03 . 2009-04-23 23:03 158720 ----a-w- c:\windows\system32\mscorier.dll
2009-04-23 21:59 . 2009-04-23 21:59 -------- d-----w- c:\users\SPARK PLUGS\AppData\Roaming\Media Player Classic
2009-04-23 20:42 . 2009-04-23 20:42 -------- d-----w- c:\program files\CCleaner
2009-04-23 20:35 . 2009-04-23 20:35 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-04-23 20:25 . 2009-04-23 20:08 -------- d-----w- c:\program files\ma-config.com
2009-04-23 20:25 . 2009-04-23 20:08 -------- d-----w- c:\programdata\ma-config.com
2009-04-23 14:32 . 2008-01-29 14:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-04-23 14:32 . 2009-04-23 14:32 206088 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
2009-04-23 14:32 . 2009-04-23 14:32 33808 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
2009-04-23 14:32 . 2009-04-23 14:32 239120 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\Vista\klif.sys
2009-04-23 13:58 . 2009-04-23 13:54 -------- d-----w- c:\programdata\Comodo
2009-04-23 13:55 . 2009-04-23 13:55 253688 ----a-w- c:\windows\system32\cssdll32.dll
2009-04-23 13:55 . 2009-04-23 13:53 -------- d-----w- c:\program files\COMODO
2009-04-23 13:55 . 2009-04-23 13:55 -------- d-----w- c:\program files\AskBarDis
2009-04-23 13:53 . 2009-04-23 13:54 68112 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-04-23 13:53 . 2009-04-23 13:54 28688 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-04-23 13:53 . 2009-04-23 13:54 155384 ----a-w- c:\windows\system32\guard32.dll
2009-04-23 13:53 . 2009-04-23 13:54 108560 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-04-23 13:48 . 2009-04-23 13:48 -------- d-----w- c:\programdata\Avira
2009-04-23 13:48 . 2009-04-23 13:48 -------- d-----w- c:\program files\Avira
2009-04-23 13:37 . 2009-04-23 13:37 -------- d-----w- c:\program files\Kaspersky Lab
2009-04-23 13:33 . 2009-04-23 13:33 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2009-04-23 13:32 . 2009-04-23 11:48 -------- d-----w- c:\program files\Messenger Plus! Live
2009-04-23 11:44 . 2009-04-23 02:37 -------- d-----w- c:\program files\Windows Live
2009-04-23 03:19 . 2009-04-23 03:19 61440 ----a-w- c:\windows\system32\winipsec.dll
2009-04-23 03:19 . 2009-04-23 03:19 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2009-04-23 03:19 . 2009-04-23 03:19 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2009-04-23 03:19 . 2009-04-23 03:19 272896 ----a-w- c:\windows\system32\polstore.dll
2009-04-23 03:17 . 2009-04-23 03:17 376832 ----a-w- c:\windows\system32\winhttp.dll
2009-04-23 03:16 . 2009-04-23 03:16 296960 ----a-w- c:\windows\system32\gdi32.dll
2009-04-23 03:16 . 2009-04-23 03:16 212480 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-04-23 03:15 . 2009-04-23 03:15 562176 ----a-w- c:\windows\system32\msdtcprx.dll
2009-04-23 03:15 . 2009-04-23 03:15 38912 ----a-w- c:\windows\system32\xolehlp.dll
2009-04-23 03:15 . 2009-04-23 03:15 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-08-06 12:20 279944 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-05-07 2807216]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Google Update"="c:\users\SPARK PLUGS\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-04-23 133104]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-04-23 206088]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"COMODO SafeSurf"="c:\program files\COMODO\SafeSurf\cssurf.exe" [2009-04-23 278264]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-04-23 1851128]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-07 148888]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 92704]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-02-13 4915200]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\adialhk.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll c:\windows\System32\cssdll32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2438606203-3547274495-2573177203-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2A2506DA-60CA-4209-AF92-C2CD8694FB3D}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
"{23DA19AB-5633-482E-BC58-DACACBD50D50}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
"{1B3173E5-3433-4BF1-BD84-523EE6713546}"= UDP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
"{FCB7DCB7-1641-4D0A-A32A-D31AF1724277}"= TCP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
"TCP Query User{827A0558-17B3-497E-BFDB-38619674E4EE}c:\\program files\\java\\jre6\\launch4j-tmp\\frd.exe"= UDP:c:\program files\java\jre6\launch4j-tmp\frd.exe:Java(TM) Platform SE binary
"UDP Query User{B06B3AA5-9CAB-476C-B3A8-A73AC3D7E089}c:\\program files\\java\\jre6\\launch4j-tmp\\frd.exe"= TCP:c:\program files\java\jre6\launch4j-tmp\frd.exe:Java(TM) Platform SE binary
"{B89912E8-4CA4-48AE-AC5C-6ACA9ACFA44F}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{E0C4ABF1-283A-4948-9CAF-F7C048FC51BE}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{C4A56EC9-8F7B-4F39-90F0-B963780492BF}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{C0D69E89-7D07-46DE-8045-EA8134404EFE}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{83837748-1C66-423A-8391-3A2A97D6D868}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{6804F96C-0EAB-486D-B11E-E874DC44F909}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{F830B74A-54A7-4FD8-86EE-D8C97DAF9278}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{E803D6AE-9345-4B31-9042-5F2037D25D15}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{467E40C9-B564-43C4-8150-FF3E5BD43724}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{A661D3A8-7F11-4B6A-B4A3-65FECB55548A}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{9116FD01-582C-4893-A9E1-D26E784CC8A8}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [29/01/08 05:29 م 33808]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\System32\drivers\cmdguard.sys [23/04/09 04:54 م 108560]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\System32\drivers\cmdhlp.sys [23/04/09 04:54 م 28688]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [09/07/08 05:28 م 20496]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [23/04/09 04:48 م 108289]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\System32\drivers\klfltdev.sys [13/03/08 06:02 م 26640]
S4 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [23/04/09 04:48 م 194817]
S4 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [23/04/09 04:48 م 432897]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24}]
%SystemRoot%\system32\soundschemes2.exe /AddRegistration
.
Contents of the 'Scheduled Tasks' folder
2009-06-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2438606203-3547274495-2573177203-1000.job
- c:\users\SPARK PLUGS\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-23 18:49]
2009-06-08 c:\windows\Tasks\User_Feed_Synchronization-{424EA959-503D-402A-AD0B-82BB2883C3AB}.job
- c:\windows\system32\msfeedssync.exe [2009-05-05 11:31]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-08 20:21
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(884)
c:\windows\system32\cssdll32.dll
- - - - - - - > 'lsass.exe'(760)
c:\windows\system32\cssdll32.dll
.
Completion time: 2009-06-08 20:22
ComboFix-quarantined-files.txt 2009-06-08 17:22
Pre-Run: 261,142,241,280 bytes free
Post-Run: 261,242,056,704 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=15 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15
269 --- E O F --- 2009-06-05 21:40