ComboFix 09-06-17.04 - solda 06/19/2009 7:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.953.536 [GMT 3:00]
Running from: c:\downloads\Software\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Desktop_.ini
c:\windows\system32\kakle.dll
c:\windows\system32\MabryObj.dll
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
c:\windows\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2009-05-19 to 2009-06-19 )))))))))))))))))))))))))))))))
.
2009-06-17 18:26 . 2009-06-17 18:26 -------- d-----w- c:\program files\Real_SC
2009-06-17 18:20 . 2009-06-17 18:20 -------- d-----w- c:\documents and settings\solda\Application Data\Ahead
2009-06-17 18:14 . 2007-04-19 23:29 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-06-17 18:14 . 2007-04-19 23:27 364544 ----a-w- c:\windows\system32\TwnLib4.dll
2009-06-17 18:14 . 2007-04-19 23:29 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-06-17 18:14 . 2007-04-19 23:28 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-06-17 18:14 . 2007-04-19 23:28 1047552 ----a-w- c:\windows\system32\mfc71u.dll
2009-06-17 18:14 . 2007-04-19 23:27 476320 ----a-w- c:\windows\system32\imagXpr7.dll
2009-06-17 18:14 . 2007-04-19 23:27 471040 ----a-w- c:\windows\system32\imagXRA7.dll
2009-06-17 18:14 . 2007-04-19 23:27 262144 ----a-w- c:\windows\system32\imagXR7.dll
2009-06-17 18:14 . 2007-04-19 23:27 1568768 ----a-w- c:\windows\system32\imagX7.dll
2009-06-17 18:14 . 2009-06-17 18:14 -------- d-----w- c:\program files\Common Files\Ahead
2009-06-17 18:13 . 2009-06-17 18:13 -------- d-----w- c:\program files\Nero
2009-06-17 04:53 . 2009-06-17 04:53 -------- d-----w- c:\program files\Trend Micro
2009-06-17 03:21 . 2006-06-13 13:57 1872 ----a-w- C:\ATS.reg
2009-06-17 03:21 . 2009-06-17 15:32 -------- d---a-w- C:\PrimerDB
2009-06-17 00:47 . 2009-06-17 00:47 -------- d-----w- c:\program files\uTorrent
2009-06-17 00:47 . 2009-06-17 03:03 -------- d-----w- c:\documents and settings\solda\Application Data\uTorrent
2009-06-16 20:47 . 2009-06-16 20:47 0 ----a-w- c:\windows\system32\cd.dat
2009-06-15 21:10 . 2009-06-16 22:56 -------- d-----w- c:\program files\Hotspot Shield
2009-06-15 20:11 . 2009-06-15 20:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-06-15 19:58 . 2009-06-15 19:58 -------- d-----w- c:\program files\Yahoo!
2009-06-15 16:32 . 2009-06-16 20:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-06-15 16:12 . 2009-06-15 16:13 -------- dcsh--w- c:\program files\Common Files\WindowsLiveInstaller
2009-06-15 16:12 . 2009-06-15 16:23 -------- d-----w- c:\program files\Windows Live
2009-06-15 16:12 . 2009-06-15 16:12 -------- d-----w- c:\documents and settings\All Users\Application Data\WLInstaller
2009-06-15 15:56 . 2009-06-15 15:56 -------- d-----w- c:\documents and settings\solda\Application Data\URSoft
2009-06-15 15:56 . 2009-06-17 18:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-15 15:56 . 2009-06-15 15:56 -------- d-----w- c:\program files\Your Uninstaller 2008
2009-06-15 04:19 . 2003-06-18 14:31 17920 ----a-w- c:\windows\system32\mdimon.dll
2009-06-15 04:17 . 2009-06-15 04:17 -------- d-----w- c:\program files\Microsoft Works
2009-06-15 04:17 . 2009-06-15 04:18 -------- d-----w- c:\windows\SHELLNEW
2009-06-15 04:15 . 2009-06-15 04:15 -------- d-----w- c:\program files\Microsoft.NET
2009-06-15 04:15 . 2009-06-15 04:15 -------- d--h--r- C:\MSOCache
2009-06-15 02:15 . 2006-06-29 10:07 14048 ------w- c:\windows\system32\spmsg2.dll
2009-06-15 02:15 . 2009-06-15 02:15 -------- d-----w- c:\windows\system32\ar-SA
2009-06-15 02:14 . 2009-06-15 02:14 83160 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-15 02:13 . 2009-06-15 02:15 -------- d-----w- c:\windows\system32\XPSViewer
2009-06-15 02:13 . 2009-06-15 02:13 -------- d-----w- c:\program files\MSBuild
2009-06-15 02:13 . 2009-06-15 02:13 -------- d-----w- c:\program files\Reference Assemblies
2009-06-15 02:12 . 2009-06-15 02:13 -------- d-----w- C:\bf859b609802d2dd7ccf3fdaf342a927
2009-06-15 02:12 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-06-15 02:12 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-06-15 02:12 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-06-15 02:12 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-06-15 02:12 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-06-15 02:12 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-06-15 02:12 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-06-15 02:11 . 2009-06-15 02:11 -------- d-----w- c:\program files\MSXML 6.0
2009-06-14 15:47 . 2009-06-14 15:47 -------- d-----w- c:\program files\CEDP Stealer 6.0 for Messenger
2009-06-14 10:27 . 2009-06-14 10:27 -------- d--h--w- c:\windows\PIF
2009-06-14 02:33 . 2009-06-16 19:06 -------- d-----w- c:\program files\Common Files\delet
2009-06-13 18:23 . 2009-06-13 20:09 -------- d-s---w- c:\program files\WinPersonalizer
2009-06-13 16:36 . 2009-06-13 16:36 -------- d-----w- c:\program files\Avant Browser
2009-06-12 22:54 . 2009-06-17 05:19 -------- d-----w- C:\Downloads
2009-06-12 22:53 . 2009-06-19 05:03 -------- d-----w- c:\documents and settings\solda\Application Data\Software Informer
2009-06-12 22:53 . 2009-06-19 05:01 -------- d-----w- c:\documents and settings\solda\Application Data\Free Download Manager
2009-06-12 22:53 . 2009-06-12 22:53 -------- d-----w- c:\program files\Software Informer
2009-06-12 22:53 . 2009-06-12 22:53 -------- d-----w- c:\program files\Free Download Manager
2009-06-12 22:53 . 2009-06-12 22:53 -------- d-----w- c:\documents and settings\All Users\Application Data\FreeDownloadManager.ORG
2009-06-12 22:52 . 2009-06-12 22:52 -------- d-----w- c:\documents and settings\solda\Application Data\Avant Profiles
2009-06-12 22:06 . 2009-06-15 16:30 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-12 20:07 . 2000-05-17 06:52 187392 ----a-w- c:\windows\system32\JPGUtils.dll
2009-06-12 20:07 . 2009-06-12 20:07 -------- d-----w- c:\program files\WinCustomize
2009-06-12 20:07 . 2009-06-12 20:07 -------- d-----w- c:\program files\Common Files\Stardock
2009-06-12 18:09 . 2009-06-15 16:05 -------- d-----w- c:\program files\MSN Messenger
2009-06-12 10:27 . 2009-06-12 10:27 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
2009-06-12 10:27 . 2009-06-12 10:27 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
2009-06-12 10:27 . 2009-06-12 10:27 226832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
2009-06-12 10:12 . 2009-06-12 10:27 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-06-12 10:12 . 2009-06-12 10:27 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-06-12 10:11 . 2009-06-19 05:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-12 10:11 . 2009-06-19 05:01 253984 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-12 10:11 . 2009-06-19 05:01 1620000 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-12 10:11 . 2009-06-12 10:11 -------- d-----w- c:\program files\Kaspersky Lab
2009-06-12 10:08 . 2009-06-12 10:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-06-12 10:04 . 2009-06-12 10:04 -------- d-----w- c:\program files\Launch Manager
2009-06-12 10:03 . 2008-03-18 18:36 54824 ----a-r- c:\windows\agrsmdel.exe
2009-06-12 10:03 . 2008-03-18 18:27 13312 ----a-r- c:\windows\system32\agrsmsvc.exe
2009-06-12 10:03 . 2008-02-29 22:13 1202560 ----a-r- c:\windows\system32\drivers\AGRSM.sys
2009-06-12 10:03 . 2007-12-11 18:40 13312 ----a-r- c:\windows\system32\agrscoin.dll
2009-06-12 08:02 . 2004-08-03 22:58 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2009-06-12 08:02 . 2004-08-03 23:10 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2009-06-12 08:02 . 2004-08-03 23:10 85376 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2009-06-12 08:02 . 2004-08-03 23:10 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2009-06-12 08:02 . 2004-08-03 23:10 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2009-06-12 08:02 . 2004-08-03 23:10 19328 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2009-06-12 08:02 . 2004-08-03 22:58 7552 ----a-w- c:\windows\system32\drivers\MSKSSRV.sys
2009-06-12 08:02 . 2004-08-03 22:58 5376 ----a-w- c:\windows\system32\drivers\MSPCLOCK.sys
2009-06-12 08:02 . 2004-08-03 23:10 15360 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2009-06-12 08:02 . 2004-08-03 22:58 4992 ----a-w- c:\windows\system32\drivers\MSPQM.sys
2009-06-12 08:02 . 2001-08-17 13:59 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2009-06-12 08:01 . 2004-08-04 00:55 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2009-06-12 08:01 . 2004-08-03 23:10 78464 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2009-06-12 08:01 . 2004-08-03 21:55 4096 -c--a-w- c:\windows\system32\dllcache\ksuser.dll
2009-06-12 08:01 . 2004-08-03 21:55 4096 ----a-w- c:\windows\system32\ksuser.dll
2009-06-12 08:01 . 2004-08-04 00:41 57216 ----a-w- c:\windows\system32\drivers\redbook.sys
2009-06-12 08:01 . 2001-08-17 13:58 9344 ----a-w- c:\windows\system32\drivers\compbatt.sys
2009-06-12 08:01 . 2001-09-18 13:30 16256 ----a-w- c:\windows\system32\drivers\battc.sys
2009-06-12 08:01 . 2004-08-03 23:07 14080 ----a-w- c:\windows\system32\drivers\CmBatt.sys
2009-06-12 08:00 . 2004-08-03 21:55 73728 -c--a-w- c:\windows\system32\dllcache\usbui.dll
2009-06-12 08:00 . 2004-08-03 21:55 73728 ----a-w- c:\windows\system32\usbui.dll
2009-06-12 08:00 . 2004-08-03 23:07 8832 ----a-w- c:\windows\system32\drivers\wmiacpi.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-19 05:01 . 2009-06-12 10:11 2996 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-19 05:01 . 2009-06-12 10:11 15832 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-19 04:38 . 2001-09-19 11:00 68594 ----a-w- c:\windows\system32\perfc001.dat
2009-06-19 04:38 . 2001-09-19 11:00 369798 ----a-w- c:\windows\system32\perfh001.dat
2009-06-17 18:26 . 2009-06-16 23:02 2535424 ----a-w- c:\windows\system32\agsaamj.dll
2009-06-17 18:26 . 2009-06-16 23:02 1986560 ----a-w- c:\windows\system32\akll.dll
2009-06-17 18:26 . 2009-06-16 23:02 196608 ----a-w- c:\windows\system32\maag.dll
2009-06-17 18:26 . 2009-06-16 23:02 1245184 ----a-w- c:\windows\system32\bkll.dll
2009-06-17 18:26 . 2009-06-16 23:02 1212416 ----a-w- c:\windows\system32\ckll.dll
2009-06-17 18:26 . 2009-06-16 23:02 90112 ----a-w- c:\windows\system32\agsaami.dll
2009-06-17 18:26 . 2009-06-16 23:02 610304 ----a-w- c:\windows\system32\agsaamg.dll
2009-06-17 18:26 . 2009-06-16 23:02 372736 ----a-w- c:\windows\system32\agsaamc.dll
2009-06-17 03:20 . 2009-06-17 03:20 -------- d-----w- c:\program files\NCC Education
2009-06-17 03:20 . 2009-06-12 06:29 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-15 06:22 . 2009-06-12 06:42 94632 ----a-w- c:\documents and settings\solda\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-13 08:49 . 2009-06-12 06:17 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-12 20:42 . 2004-08-03 21:56 515584 ----a-w- c:\windows\system32\logonuiX.exe
2009-06-12 10:27 . 2008-01-29 14:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-06-12 06:36 . 2009-06-12 06:36 -------- d-----w- c:\program files\WIDCOMM
2009-06-12 06:34 . 2009-06-12 06:34 -------- d-----w- c:\program files\Synaptics
2009-06-12 06:33 . 2009-06-12 06:29 -------- d-----w- c:\program files\Common Files\InstallShield
2009-06-12 06:32 . 2009-06-12 06:32 -------- d-----w- c:\program files\Atheros
2009-06-12 06:32 . 2009-06-12 06:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Atheros
2009-06-12 06:31 . 2009-06-12 06:31 -------- d-----w- c:\program files\Broadcom
2009-06-12 06:31 . 2009-06-12 06:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Broadcom
2009-06-12 06:31 . 2009-06-12 06:31 -------- d-----w- c:\documents and settings\solda\Application Data\InstallShield
2009-06-12 06:30 . 2009-06-12 06:30 -------- d-----w- c:\program files\Marvell
2009-06-12 06:29 . 2009-06-12 06:29 -------- d-----w- c:\program files\Realtek
2009-06-12 06:29 . 2009-06-12 06:29 315392 ----a-w- c:\windows\HideWin.exe
2009-06-12 06:24 . 2009-06-12 06:24 -------- d-----w- c:\program files\Intel
2009-06-12 06:18 . 2009-06-12 06:18 -------- d-----w- c:\program files\microsoft frontpage
2009-06-12 06:14 . 2009-06-12 06:14 22144 ----a-w- c:\windows\system32\emptyregdb.dat
2009-06-08 04:00 . 2009-06-08 04:00 1547776 ----a-w- c:\windows\system32\sfcfiles.dll
2009-06-08 04:00 . 2009-06-08 04:00 124928 ----a-w- c:\windows\system32\drivers\ulsata2.sys
2009-06-08 04:00 . 2009-06-08 04:00 982528 ----a-w- c:\windows\system32\syssetup.dll
.
------- Sigcheck -------
[-] 2009-06-08 04:00 1547776 6E932D21E116B51ED9D5157E31C48E33 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Software Informer"="c:\program files\Software Informer\softinfo.exe" [2009-01-01 1654853]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2006-07-26 4617720]
"AFProg"="c:\program files\Hotspot Shield\AnchorFree\ctrl\AFController.exe" [2006-06-26 118784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-17 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-17 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-17 141848]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-18 53248]
"ACU"="c:\program files\Atheros\ACU.exe" [2008-04-09 450648]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-02-22 1032192]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-06-09 805384]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-06-12 206088]
"LogonStudio"="c:\program files\WinCustomize\LogonStudio\logonstudio.exe" [2002-09-03 987187]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-07 16862208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-1 568176]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 05:29 م 33808]
R0 ulsata2;ulsata2;c:\windows\system32\drivers\ulsata2.sys [08/06/2009 07:00 ص 124928]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 06:02 م 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 05:06 م 24592]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [12/06/2009 09:41 ص 194304]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-fsm - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.hotspotshield.com/g/?c=h
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: تحميل الفيديو بواسطة Free Download Manager -
files\Free Download Manager\dlfvideo.htm
IE: تحميل الكل بواسطة Free Download Manager -
files\Free Download Manager\dlall.htm
IE: تحميل المحددة بواسطة Free Download Manager -
files\Free Download Manager\dlselected.htm
IE: تحميل بواسطة Free Download Manager -
files\Free Download Manager\dllink.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-19 08:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(796)
c:\windows\system32\msi.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\browselc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\acs.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\docume~1\solda\LOCALS~1\Temp\RtkBtMnt.exe
.
**************************************************************************
.
Completion time: 2009-06-19 8:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-19 05:05
Pre-Run: 73,304,182,784 bytes free
Post-Run: 73,329,516,544 bytes free
256
بس لما عاد التشغيل جلست الشاشة الزرقا ومكتوب كولد نوت فايند C :\windows\system32\driver\compo-Fix.sys