اخواني الكرام حاليا لايوجـد بجهازي برنامج حماية كنت منصب الكاسبر ثم قمت بازالتـه حتي اجد حل لهذا المشكله
ثانياً اخي ugugx
لا اعرف كيف اقوم بعملية الحذف
اما بالنسبه لا اخي ماكس قمت بتحميل الاداة ثم عملت الطريقة التي وضعتها والتقرير كالتالي :
ComboFix 09-06-11.05 - CT 06/11/2009 14:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.1526.990 [GMT -7:00]
Running from: c:\documents and settings\CT\Desktop\ComboFix.exe
AV: Total Security 10.00 *On-access scanning disabled* (Outdated) {05C1329D-F0E0-4B19-9D15-54F9BC3ADE87}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
c:\windows\system32\kakle.dll
.
((((((((((((((((((((((((( Files Created from 2009-05-11 to 2009-06-11 )))))))))))))))))))))))))))))))
.
2009-06-11 17:43 . 2009-06-11 17:43 -------- d-----w- c:\program files\Trend Micro
2009-06-11 14:32 . 2009-06-11 14:32 -------- d-----w- c:\program files\Common Files\xing shared
2009-06-10 23:38 . 2009-06-10 23:38 -------- d-----w- c:\windows\system32\wbem\Repository
2009-06-10 23:37 . 2009-06-10 23:37 -------- d-----w- c:\program files\Quick Heal
2009-06-09 16:10 . 2009-06-09 17:07 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-06-09 16:10 . 2009-06-09 17:07 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-06-09 16:09 . 2009-06-10 22:29 270368 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-09 16:09 . 2009-06-10 22:29 2580512 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-09 16:09 . 2009-06-10 16:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-09 16:09 . 2009-06-09 16:09 -------- d-----w- c:\program files\Kaspersky Lab
2009-06-05 12:46 . 2009-06-10 23:37 -------- d-----w- c:\program files\Quick Heal(2)
2009-05-19 04:02 . 2004-08-04 06:08 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-05-19 04:02 . 2004-08-04 06:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-05-19 04:02 . 2009-05-19 04:02 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-05-19 04:02 . 2008-01-24 00:08 99456 ----a-w- c:\windows\system32\drivers\bsusbser.sys
2009-05-19 04:02 . 2009-05-19 04:02 -------- d-----w- c:\program files\Promate
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-11 21:57 . 2009-04-24 06:10 -------- d-----w- c:\documents and settings\CT\Application Data\Orbit
2009-06-11 15:10 . 2009-05-02 16:32 -------- d-----w- c:\documents and settings\CT\Application Data\skypePM
2009-06-11 14:31 . 2009-04-24 05:49 -------- d-----w- c:\program files\Common Files\Real
2009-06-11 14:31 . 2006-07-12 01:35 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-06-11 02:58 . 2009-04-24 06:13 -------- d-----w- c:\documents and settings\CT\Application Data\Skype
2009-06-10 23:37 . 2009-04-24 06:13 -------- d-----w- c:\program files\Google
2009-06-10 22:29 . 2009-06-09 16:09 23336 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-10 22:29 . 2009-06-09 16:09 2004 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-05-29 01:40 . 2009-04-24 05:33 -------- d-----w- c:\program files\AutorunRemover
2009-05-26 18:42 . 2009-04-24 06:10 -------- d-----w- c:\program files\Orbitdownloader
2009-05-22 13:38 . 2009-05-01 12:14 -------- d-----w- c:\program files\Messenger Plus! Live
2009-05-19 04:02 . 2009-04-24 04:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-19 04:02 . 2009-04-24 04:51 -------- d-----w- c:\program files\Common Files\InstallShield
2009-05-16 19:37 . 2009-04-24 14:21 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-05-16 19:15 . 2009-04-24 11:39 -------- d-----w- c:\documents and settings\CT\Application Data\Nokia
2009-05-16 16:56 . 2009-04-24 05:59 65144 ----a-w- c:\windows\system32\drivers\catflt.sys
2009-05-12 20:46 . 2009-04-27 18:18 -------- d-----w- c:\program files\JetAudio
2009-05-06 07:23 . 2009-05-06 07:23 -------- d-----w- c:\documents and settings\All Users\Application Data\WLInstaller
2009-05-02 16:32 . 2009-05-02 16:32 32 ----a-w- c:\documents and settings\All Users\Application Data\ezsid.dat
2009-05-01 14:11 . 2009-05-01 14:11 2678 ----a-w- c:\windows\java\Packages\Data\5VZHZ53R.DAT
2009-05-01 14:11 . 2009-05-01 14:11 2678 ----a-w- c:\windows\java\Packages\Data\53PJLVNJ.DAT
2009-05-01 14:11 . 2009-05-01 14:11 2678 ----a-w- c:\windows\java\Packages\Data\7LNXBJF3.DAT
2009-05-01 14:11 . 2009-05-01 14:11 2678 ----a-w- c:\windows\java\Packages\Data\4C63BJ7H.DAT
2009-05-01 14:11 . 2009-05-01 14:11 2678 ----a-w- c:\windows\java\Packages\Data\3FT3HNTR.DAT
2009-05-01 13:56 . 2009-05-01 13:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-05-01 12:14 . 2009-05-01 12:14 -------- d-----w- c:\program files\Cirle Developement
2009-05-01 09:43 . 2009-04-24 05:55 -------- d-----w- c:\program files\Windows Live
2009-05-01 09:42 . 2009-05-01 09:42 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-04-30 20:52 . 2009-04-30 20:52 -------- d-----w- c:\program files\BaroufaSoft
2009-04-27 23:42 . 2009-04-27 23:42 390664 ----a-w- c:\documents and settings\CT\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-04-27 18:31 . 2009-04-27 18:31 -------- d-----w- c:\documents and settings\CT\Application Data\COWON
2009-04-27 18:20 . 2009-04-24 05:49 -------- d-----w- c:\program files\Real
2009-04-27 18:18 . 2009-04-27 18:18 -------- d-----w- c:\program files\Common Files\COWON
2009-04-27 03:49 . 2009-04-27 03:49 -------- d-----w- c:\documents and settings\CT\Application Data\CyberLink
2009-04-26 05:54 . 2009-04-26 05:54 -------- d-----w- c:\program files\Ask Search Assistant
2009-04-26 04:17 . 2009-04-24 04:34 95216 ----a-w- c:\documents and settings\CT\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-26 04:05 . 2009-04-26 04:05 -------- d-----w- c:\program files\Microsoft
2009-04-26 04:04 . 2009-04-26 04:04 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-04-26 03:10 . 2009-04-24 05:36 -------- d-----w- c:\program files\eTeSoft Video Converter
2009-04-26 03:10 . 2009-04-24 05:52 -------- d-----w- c:\program files\Real_SC
2009-04-25 15:18 . 2009-04-25 15:17 -------- d-----w- c:\program files\hp deskjet 845c series
2009-04-25 15:17 . 2009-04-25 15:17 376 ----a-w- c:\windows\mozregistry.dat
2009-04-25 15:17 . 2009-04-25 15:16 -------- d-----w- c:\program files\Hewlett-Packard
2009-04-25 01:55 . 2009-04-24 14:21 -------- d-----w- c:\documents and settings\CT\Application Data\PC Suite
2009-04-25 01:55 . 2009-04-25 01:55 -------- d-----w- c:\documents and settings\CT\Application Data\Media Player Classic
2009-04-25 01:55 . 2009-04-25 01:55 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-04-25 01:55 . 2009-04-25 01:55 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-04-25 01:48 . 2009-04-25 01:48 -------- d-----w- c:\program files\Common Files\PCSuite
2009-04-25 01:48 . 2009-04-25 01:48 -------- d-----w- c:\program files\Common Files\Nokia
2009-04-25 01:48 . 2009-04-25 01:47 -------- d-----w- c:\program files\Nokia
2009-04-25 01:48 . 2009-04-25 01:48 -------- d-----w- c:\program files\PC Connectivity Solution
2009-04-25 01:43 . 2009-04-25 01:43 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-04-25 01:43 . 2009-04-25 01:43 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-04-25 01:43 . 2009-04-25 01:43 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-04-25 01:42 . 2009-04-24 11:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-04-25 00:21 . 2009-04-25 00:21 -------- d-----w- c:\program files\Common Files\Windows Live
2009-04-24 14:19 . 2009-04-24 14:19 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2009-04-24 14:19 . 2009-04-24 14:19 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-04-24 12:41 . 2009-04-24 12:41 -------- d-----w- c:\documents and settings\CT\Application Data\ACD Systems
2009-04-24 12:22 . 2009-04-24 12:22 -------- d-----w- c:\documents and settings\All Users\Application Data\GRETECH
2009-04-24 12:22 . 2009-04-24 12:22 -------- d-----w- c:\documents and settings\CT\Application Data\GRETECH
2009-04-24 12:12 . 2009-04-24 04:52 -------- d-----w- c:\program files\Common Files\Adobe
2009-04-24 11:18 . 2009-04-24 11:18 -------- d-----w- c:\program files\DIFX
2009-04-24 11:12 . 2009-04-24 11:12 -------- d-----w- c:\program files\MSBuild
2009-04-24 11:12 . 2009-04-24 11:12 -------- d-----w- c:\program files\Reference Assemblies
2009-04-24 11:10 . 2009-04-24 11:10 -------- d-----w- c:\program files\MSXML 6.0
2009-04-24 11:07 . 2009-04-24 11:07 -------- d-----w- c:\documents and settings\CT\Application Data\Yahoo!
2009-04-24 10:45 . 2009-04-25 01:47 34649904 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Nokia_PC_Suite_7_1_26_0_ara_web.exe
2009-04-24 06:12 . 2009-04-24 06:12 -------- d-----w- c:\program files\Skype
2009-04-24 06:12 . 2009-04-24 06:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-04-24 06:12 . 2009-04-24 06:12 -------- d-----w- c:\program files\Common Files\Skype
2009-04-24 06:10 . 2009-04-24 06:10 -------- d-----w- c:\documents and settings\CT\Application Data\GrabPro
2009-04-24 06:06 . 2009-04-24 05:54 47104 ------w- c:\windows\AKDeInstall.exe
2009-04-24 05:59 . 2009-04-24 06:00 28664 ----a-w- c:\windows\system32\drivers\EMLTDI.SYS
2009-04-24 05:57 . 2009-04-24 05:57 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-04-24 05:54 . 2009-04-24 05:54 -------- d-----w- c:\program files\mpegable
2009-04-24 05:54 . 2009-04-24 05:54 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-04-24 05:52 . 2009-04-24 05:52 -------- d-----w- c:\program files\GRETECH
2009-04-24 05:52 . 2009-04-24 05:52 196608 ----a-w- c:\windows\system32\maag.dll
2009-04-24 05:52 . 2009-04-24 05:52 1245184 ----a-w- c:\windows\system32\bkll.dll
2009-04-24 05:52 . 2009-04-24 05:52 1212416 ----a-w- c:\windows\system32\ckll.dll
2009-04-24 05:52 . 2009-04-24 05:52 90112 ----a-w- c:\windows\system32\agsaami.dll
2009-04-24 05:52 . 2009-04-24 05:52 610304 ----a-w- c:\windows\system32\agsaamg.dll
2009-04-24 05:52 . 2009-04-24 05:52 372736 ----a-w- c:\windows\system32\agsaamc.dll
2009-04-24 05:52 . 2009-04-24 05:52 2535424 ----a-w- c:\windows\system32\agsaamj.dll
2009-04-24 05:52 . 2009-04-24 05:52 1986560 ----a-w- c:\windows\system32\akll.dll
2009-04-24 05:51 . 2009-04-24 05:51 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-24 05:51 . 2009-04-24 05:50 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-04-24 05:50 . 2009-04-24 05:48 -------- d-----w- c:\program files\CyberLink
2009-04-24 05:48 . 2009-04-24 05:48 -------- d-----w- c:\program files\Windows Media Connect 2
2009-04-24 05:47 . 2009-04-24 05:46 -------- d-----w- c:\program files\Ahead
2009-04-24 05:47 . 2009-04-24 05:47 -------- d-----w- c:\program files\Common Files\Ahead
2009-04-24 05:45 . 2009-04-24 05:45 -------- d-----w- c:\program files\Macromedia
2009-04-24 05:45 . 2009-04-24 05:45 720896 ----a-w- c:\windows\iun6002.exe
2009-04-24 05:37 . 2009-04-24 05:36 -------- d-----w- c:\program files\Golden Al-Wafi Translator
2009-04-24 05:36 . 2009-04-24 05:36 172032 ------w- c:\windows\Setup1.exe
2009-04-24 05:36 . 2009-04-24 05:36 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-04-24 05:35 . 2009-04-24 05:35 -------- d-----w- c:\program files\Common Files\stardock
2009-04-24 05:35 . 2009-04-24 05:35 -------- d-----w- c:\program files\Stardock
2009-04-24 05:33 . 2009-04-24 05:33 -------- d-----w- c:\program files\Common Files\ACD Systems
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2007-12-07 21686568]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-07 3885408]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-03-20 1312256]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-24 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2008-07-10 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2008-07-10 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2008-07-10 114688]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2008-07-22 196608]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2005-09-06 671744]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-15 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 54832]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-15 196608]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-11 198160]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2008-07-10 88358]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-4-24 113664]
Matrix Screen Locker.lnk - c:\program files\BaroufaSoft\Matrix Screen Locker\matrix.exe [2006-1-29 539136]
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2009-4-23 1719496]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 21:13 49152 ----a-w- c:\progra~1\COMMON~1\stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 catflt;catflt;c:\windows\system32\drivers\catflt.sys [23/04/2009 10:59 م 65144]
R2 EMLSS;EMLSS;c:\windows\system32\drivers\EMLTDI.SYS [23/04/2009 11:00 م 28664]
R3 bsusbser;Basecom USB Device for Legacy Serial Communication;c:\windows\system32\drivers\bsusbser.sys [18/05/2009 09:02 م 99456]
S2 Online Protection System;Online Protection System;c:\progra~1\QUICKH~1\QUICKH~1\opssvc.exe --> c:\progra~1\QUICKH~1\QUICKH~1\opssvc.exe [?]
S2 Quick Heal Total Security Mail Protection;Quick Heal Total Security Mail Protection;c:\progra~1\QUICKH~1\QUICKH~1\EMLPROXY.EXE --> c:\progra~1\QUICKH~1\QUICKH~1\EMLPROXY.EXE [?]
S2 Quick Update Service;Quick Update Service;c:\progra~1\QUICKH~1\QUICKH~1\quhlpsvc.exe --> c:\progra~1\QUICKH~1\QUICKH~1\quhlpsvc.exe [?]
S2 Startup Handler;Quick Heal Total Security Startup Handler;c:\progra~1\QUICKH~1\QUICKH~1\strtsvc.exe --> c:\progra~1\QUICKH~1\QUICKH~1\strtsvc.exe [?]
S2 TwonkyMedia;TwonkyMedia;c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0 --> c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0 [?]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-MyWirelessCard - c:\program files\Promate\3.75G
HKLM-Run-Email Protection - c:\progra~1\QUICKH~1\QUICKH~1\EMLPROUI.EXE
HKLM-Run-On-Line Protection - c:\progra~1\QUICKH~1\QUICKH~1\CATEYE.EXE
HKLM-Run-Startup Scan - c:\progra~1\QUICKH~1\QUICKH~1\sensor.exe
HKLM-Run-ResumeQuickupDownload - c:\progra~1\QUICKH~1\QUICKH~1\acappaa.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-11 15:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\
000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1614895754-1060284298-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*t*t* \OpenWithList]
@Class="Shell"
"a"="msnmsgr.exe"
"MRUList"="ba"
"b"="iexplore.exe"
[HKEY_USERS\S-1-5-21-1614895754-1060284298-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*t*t* \OpenWithProgids]
"ctt_auto_file"=hex(0):
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(768)
c:\progra~1\COMMON~1\Stardock\mcpstub.dll
.
Completion time: 2009-06-11 15:03
ComboFix-quarantined-files.txt 2009-06-11 22:03
Pre-Run: 19,249,684,480 bytes free
Post-Run: 21,080,592,384 bytes free
239