جــزإأكـ الله خــيــر آخــوي MAAX
وهــذآآ تــقــريــر الــكــمــبــو
ComboFix 09-06-19.01 - welcome 06/20/2009 16:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.1270.795 [GMT 3:00]
Running from: c:\documents and settings\welcome\سطح المكتب\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Bifrost
c:\windows\system32\Bifrost\logg.dat
c:\windows\system32\kakle.dll
.
((((((((((((((((((((((((( Files Created from 2009-05-20 to 2009-06-20 )))))))))))))))))))))))))))))))
.
2009-06-20 13:01 . 2009-06-20 13:01 -------- d-----w- C:\Temp
2009-06-19 13:59 . 2008-09-26 15:00 24448 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2009-06-19 13:59 . 2009-06-19 14:05 -------- d-----w- c:\program files\Mobily Connect Card
2009-06-19 07:13 . 2009-06-19 07:13 -------- d-----w- c:\program files\Trend Micro
2009-06-17 07:10 . 2009-06-20 12:57 -------- d-----w- c:\program files\GTA San Andreas
2009-06-16 07:08 . 2009-06-16 07:08 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\klbg.sys
2009-06-16 07:08 . 2009-06-16 07:08 213520 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\XP\klif.sys
2009-06-15 19:16 . 2009-06-15 19:16 -------- d-----w- c:\windows\system32\wbem\Repository
2009-06-15 14:05 . 2009-06-15 14:19 -------- d-----w- c:\documents and settings\welcome\amsn
2009-06-15 14:05 . 2009-06-15 14:53 -------- d-----w- c:\program files\aMSN
2009-06-13 14:32 . 2009-06-13 14:32 -------- d-----w- c:\program files\MTA San Andreas
2009-06-01 21:57 . 2009-06-01 21:57 -------- d-----w- c:\documents and settings\welcome\Application Data\COWON
2009-06-01 17:52 . 2009-06-01 17:54 -------- d-----w- c:\documents and settings\welcome\Application Data\Motive
2009-06-01 17:51 . 2009-06-01 17:51 -------- d-----w- c:\program files\Fahess_Activation
2009-06-01 17:51 . 2009-06-01 17:51 -------- d-----w- c:\program files\Common Files\Motive
2009-06-01 17:12 . 2009-06-01 17:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Motive
2009-06-01 13:42 . 2001-09-18 10:38 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-05-31 22:10 . 2001-08-17 11:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-05-31 15:52 . 2007-03-22 10:46 126976 ----a-w- c:\documents and settings\welcome\Application Data\GRETECH\GomPlayer\GrLauncher.exe
2009-05-31 15:51 . 2009-05-31 15:51 -------- d-----w- c:\documents and settings\welcome\Application Data\GRETECH
2009-05-27 15:42 . 2004-08-03 21:58 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2009-05-27 15:42 . 2004-08-03 22:10 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2009-05-27 15:42 . 2004-08-03 22:10 15360 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2009-05-27 15:42 . 2004-08-03 22:10 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2009-05-27 15:42 . 2004-08-03 22:10 19328 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2009-05-27 15:42 . 2004-08-03 22:10 85376 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2009-05-27 15:42 . 2004-08-03 22:10 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2009-05-27 15:42 . 2004-08-03 21:55 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2009-05-27 15:42 . 2009-05-28 23:02 13824 ----a-w- c:\windows\system32\drivers\splitcam.sys
2009-05-27 15:41 . 2009-05-27 15:41 -------- d-----w- c:\program files\SplitCam
2009-05-27 15:38 . 2002-12-10 08:11 6852 ----a-w- c:\windows\system32\drivers\Vcs.sys
2009-05-27 12:41 . 2009-05-27 12:41 -------- d-----w- c:\program files\iVocalize Web Conference 4
2009-05-27 01:41 . 2004-08-03 23:07 59264 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2009-05-27 01:41 . 2004-08-03 23:10 78464 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2009-05-26 21:52 . 2009-06-16 17:35 -------- d-----w- c:\program files\LtUcx
2009-05-26 15:20 . 2009-05-26 15:20 62464 ----a-w- c:\documents and settings\welcome\Application Data\Sun\Java\Deployment\cache\6.0\38\37c7a6a6-19ed9719-n\avutil-49.dll
2009-05-26 15:20 . 2009-05-26 15:20 516096 ----a-w- c:\documents and settings\welcome\Application Data\Sun\Java\Deployment\cache\6.0\38\37c7a6a6-19ed9719-n\ivjni.dll
2009-05-26 15:20 . 2009-05-26 15:20 288361 ----a-w- c:\documents and settings\welcome\Application Data\Sun\Java\Deployment\cache\6.0\38\37c7a6a6-19ed9719-n\libmp3lame-0.dll
2009-05-26 15:20 . 2009-05-26 15:20 1941504 ----a-w- c:\documents and settings\welcome\Application Data\Sun\Java\Deployment\cache\6.0\38\37c7a6a6-19ed9719-n\avcodec-51.dll
2009-05-26 15:20 . 2009-05-26 15:20 107520 ----a-w- c:\documents and settings\welcome\Application Data\Sun\Java\Deployment\cache\6.0\38\37c7a6a6-19ed9719-n\avformat-52.dll
2009-05-24 18:16 . 2009-05-24 18:16 -------- d-----w- c:\documents and settings\welcome\.webrenderer
2009-05-24 16:23 . 2009-05-24 16:23 -------- d-----w- c:\windows\system32\ar-sa
2009-05-24 16:19 . 2009-05-24 16:19 -------- d--h--w- c:\windows\$hf_mig$
2009-05-24 15:14 . 2009-05-24 15:14 -------- d-----w- c:\windows\Sun
2009-05-24 12:43 . 2009-06-19 07:42 -------- d-----w- c:\documents and settings\welcome\Contacts
2009-05-23 21:11 . 2009-05-23 21:11 -------- d-----w- c:\program files\Kaspersky Lab
2009-05-23 21:08 . 2009-05-23 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-05-23 20:55 . 2009-06-20 13:38 -------- d-----w- c:\windows\system32\Lang
2009-05-23 20:42 . 2007-01-11 10:20 194304 ----a-r- c:\windows\system32\drivers\RTL8187.sys
2009-05-23 20:29 . 2004-08-03 22:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-05-23 20:27 . 2009-05-24 17:13 -------- d-----w- c:\windows\system32\SupportAppXL
2009-05-23 20:22 . 2009-05-23 20:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-05-23 20:21 . 2005-06-08 02:58 135168 ----a-r- c:\windows\system32\igfxres.dll
2009-05-23 20:19 . 2009-05-23 20:19 -------- d-----w- c:\documents and settings\welcome\Bluetooth Software
2009-05-23 20:15 . 2009-05-23 20:15 -------- d-----w- c:\program files\WIDCOMM
2009-05-23 20:12 . 2004-11-16 04:06 458752 ----a-r- c:\windows\system32\w29NCPA.dll
2009-05-23 20:12 . 2004-11-16 04:06 3222784 ----a-r- c:\windows\system32\drivers\w29n51.sys
2009-05-23 20:12 . 2009-05-23 20:12 -------- d-----w- c:\program files\Launch Manager
2009-05-23 20:10 . 2004-10-08 06:44 69722 ----a-w- c:\windows\system32\SynTPFcs.dll
2009-05-23 20:10 . 2004-10-08 06:46 81920 ----a-w- c:\windows\system32\SynTPCo2.dll
2009-05-23 20:10 . 2004-10-08 06:36 90202 ----a-w- c:\windows\system32\SynTPAPI.dll
2009-05-23 20:10 . 2004-10-08 06:33 185824 ----a-w- c:\windows\system32\drivers\SynTP.sys
2009-05-23 20:10 . 2004-10-08 06:36 114688 ----a-w- c:\windows\system32\SynCtrl.dll
2009-05-23 20:10 . 2004-10-08 06:35 77917 ----a-w- c:\windows\system32\SynCOM.dll
2009-05-23 20:10 . 2009-05-23 20:10 -------- d-----w- c:\program files\Synaptics
2009-05-23 20:03 . 2005-04-16 14:20 487424 ------r- c:\windows\RtlExUpd.dll
2009-05-23 19:55 . 2009-05-23 19:55 -------- d-----w- c:\documents and settings\welcome\Application Data\ESET
2009-05-23 19:54 . 2009-05-23 19:54 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-05-23 19:53 . 2009-05-27 08:05 -------- d-----w- c:\program files\Circle Developement
2009-05-23 19:53 . 2009-05-23 19:53 -------- d-----w- c:\program files\Messenger Plus! Live
2009-05-23 19:53 . 2009-05-23 19:53 -------- dc----w- c:\windows\system32\DRVSTORE
2009-05-23 19:52 . 2009-05-23 19:52 -------- d-----w- c:\program files\Windows Live
2009-05-23 19:51 . 2009-05-23 19:51 -------- d-----w- c:\program files\Webteh
2009-05-23 19:51 . 2007-10-26 07:05 33576 ----a-w- c:\windows\system32\BCGPOleAcc.dll
2009-05-23 19:51 . 2007-10-26 07:05 3036456 ----a-w- c:\windows\system32\BCGCBPRO860u80.dll
2009-05-23 19:51 . 2006-03-17 13:49 368640 ----a-w- c:\windows\system32\TwnLib4.dll
2009-05-23 19:51 . 2006-03-17 10:45 802816 ----a-w- c:\windows\system32\imagXRA7.dll
2009-05-23 19:51 . 2006-03-17 10:45 497296 ----a-w- c:\windows\system32\imagXpr7.dll
2009-05-23 19:51 . 2006-03-17 10:45 258048 ----a-w- c:\windows\system32\imagXR7.dll
2009-05-23 19:51 . 2006-03-17 10:45 1757184 ----a-w- c:\windows\system32\imagX7.dll
2009-05-23 19:50 . 2009-05-23 19:50 -------- d-----w- c:\program files\Common Files\Nero
2009-05-23 19:50 . 2009-05-23 19:50 -------- d-----w- c:\program files\Nero
2009-05-23 19:49 . 2009-05-23 19:49 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-05-23 19:48 . 2009-05-23 19:48 -------- d-----w- c:\program files\CyberLink
2009-05-23 19:47 . 2009-05-23 19:47 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-23 19:45 . 2009-05-23 19:45 -------- d-----w- c:\program files\Common Files\xing shared
2009-05-23 19:45 . 2009-05-23 19:45 -------- d-----w- c:\program files\Common Files\Real
2009-05-23 19:45 . 2009-05-23 19:45 -------- d-----w- c:\program files\Real
2009-05-23 19:42 . 2009-05-23 19:42 -------- d-----w- c:\program files\DivX
2009-05-23 19:42 . 2009-05-23 19:42 -------- d-----w- c:\program files\GRETECH
2009-05-23 19:41 . 2009-05-23 19:41 410976 ----a-w- c:\windows\system32\deploytk.dll
2009-05-23 19:41 . 2009-05-23 19:41 -------- d-----w- c:\program files\Java
2009-05-23 19:40 . 2009-05-23 19:40 -------- d-----w- c:\program files\Common Files\COWON
2009-05-23 19:40 . 2009-06-01 21:57 -------- d-----w- c:\program files\JetAudio
2009-05-23 19:39 . 2009-05-23 19:39 -------- d-----w- c:\documents and settings\welcome\Local Settings\Application Data\Real
2009-05-23 19:36 . 2004-08-03 21:55 25600 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-05-23 19:26 . 2009-05-23 19:26 -------- d-sh--w- c:\documents and settings\welcome\UserData
2009-05-23 19:07 . 2009-05-23 19:07 -------- d-----w- c:\program files\Windows Media Connect 2
2009-05-23 19:06 . 2009-05-23 19:06 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-05-23 19:06 . 2009-05-23 19:06 -------- d-----w- c:\windows\system32\LogFiles
2009-05-23 19:06 . 2006-09-25 16:58 23856 ----a-w- c:\windows\system32\spupdsvc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-20 13:38 . 2009-06-16 06:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-20 13:36 . 2009-06-16 06:19 303136 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-20 13:36 . 2009-06-16 06:19 2116 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-20 13:36 . 2009-06-16 06:19 1533984 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-20 13:36 . 2009-06-16 06:19 14112 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-20 09:40 . 2001-09-19 15:00 40316 ----a-w- c:\windows\system32\perfc001.dat
2009-06-20 09:40 . 2001-09-19 15:00 251946 ----a-w- c:\windows\system32\perfh001.dat
2009-06-16 07:08 . 2008-01-29 15:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-06-16 07:08 . 2009-06-16 06:20 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-06-16 07:08 . 2009-06-16 06:20 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-06-16 07:08 . 2009-06-16 07:08 21256 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\vkbd.dll
2009-06-16 07:08 . 2009-06-16 07:07 861448 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\updater.dll
2009-06-16 07:07 . 2009-06-16 07:07 83208 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\mzvkbd.dll
2009-06-16 07:07 . 2009-06-16 07:07 62728 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\ievkbd.dll
2009-06-16 07:07 . 2009-06-16 07:07 43784 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\fssync.dll
2009-06-16 07:07 . 2009-06-16 07:07 365832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\ckahum.dll
2009-06-16 07:07 . 2009-06-16 07:07 201992 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\avp.exe
2009-05-27 15:41 . 2009-05-23 19:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-23 20:11 . 2009-05-23 20:11 -------- d-----w- c:\program files\CONEXANT
2009-05-23 20:09 . 2009-05-23 20:09 294912 ----a-w- c:\windows\HideWin.exe
2009-05-23 20:09 . 2009-05-23 20:09 -------- d-----w- c:\program files\Realtek
2009-05-23 19:59 . 2009-05-23 19:59 -------- d-----w- c:\program files\Intel
2009-05-23 19:53 . 2009-05-23 18:44 94632 ----a-w- c:\documents and settings\welcome\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-23 19:48 . 2009-05-23 19:39 -------- d-----w- c:\program files\Common Files\InstallShield
2009-05-23 19:45 . 2009-05-23 19:39 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-05-23 19:45 . 2009-05-23 19:39 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-05-23 19:43 . 2009-05-23 19:43 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-05-23 19:43 . 2009-05-23 19:43 90112 ----a-w- c:\windows\system32\agsaami.dll
2009-05-23 19:43 . 2009-05-23 19:43 610304 ----a-w- c:\windows\system32\agsaamg.dll
2009-05-23 19:43 . 2009-05-23 19:43 372736 ----a-w- c:\windows\system32\agsaamc.dll
2009-05-23 19:43 . 2009-05-23 19:43 2535424 ----a-w- c:\windows\system32\agsaamj.dll
2009-05-23 19:43 . 2009-05-23 19:43 1986560 ----a-w- c:\windows\system32\akll.dll
2009-05-23 19:43 . 2009-05-23 19:43 196608 ----a-w- c:\windows\system32\maag.dll
2009-05-23 19:43 . 2009-05-23 19:43 1245184 ----a-w- c:\windows\system32\bkll.dll
2009-05-23 19:43 . 2009-05-23 19:43 1212416 ----a-w- c:\windows\system32\ckll.dll
2009-05-23 19:43 . 2009-05-23 19:42 -------- d-----w- c:\program files\Real_SC
2009-05-23 19:40 . 2009-05-23 19:39 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-05-23 19:39 . 2009-05-23 19:39 -------- d-----w- c:\program files\mpegable
2009-05-23 19:39 . 2009-05-23 19:39 47104 ------w- c:\windows\AKDeInstall.exe
2009-05-23 19:39 . 2009-05-23 19:39 2232 ----a-w- c:\windows\java\Packages\Data\5RDFJX7B.DAT
2009-05-23 19:39 . 2009-05-23 19:39 155995 ----a-w- c:\windows\java\Packages\B1VTNRTZ.ZIP
2009-05-23 19:39 . 2009-05-23 19:39 2678 ----a-w- c:\windows\java\Packages\Data\6RJZ97N5.DAT
2009-05-23 19:39 . 2009-05-23 19:39 2678 ----a-w- c:\windows\java\Packages\Data\4BB3RJ1J.DAT
2009-05-23 19:39 . 2009-05-23 19:39 2678 ----a-w- c:\windows\java\Packages\Data\UW4WRDBL.DAT
2009-05-23 19:39 . 2009-05-23 19:39 2678 ----a-w- c:\windows\java\Packages\Data\R9ZRFTVZ.DAT
2009-05-23 19:39 . 2009-05-23 19:39 2678 ----a-w- c:\windows\java\Packages\Data\LNT79ZZD.DAT
2009-05-23 19:39 . 2009-05-23 19:39 -------- d-----w- c:\program files\Common Files\Nokia
2009-05-23 19:39 . 2009-05-23 19:39 -------- d-----w- c:\program files\Nokia
2009-05-23 19:24 . 2009-05-23 17:19 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-23 18:50 . 2009-05-23 18:50 -------- d-----w- c:\program files\Microsoft.NET
2009-05-23 18:50 . 2009-05-23 18:50 -------- d-----w- c:\program files\Microsoft Works
2009-05-23 17:20 . 2009-05-23 17:20 -------- d-----w- c:\program files\microsoft frontpage
2009-05-23 17:16 . 2009-05-23 17:16 22144 ----a-w- c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-08-16 5728112]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-23 136600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-23 198160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-08 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-08 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-08 114688]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 53248]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 688218]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2005-08-18 462848]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-06-16 201992]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2005-08-09 14743552]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-8-16 577597]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-9-8 525664]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\english\\setup.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [1/29/2008 6:29 م 33808]
R2 Vcs;Vcs support;c:\windows\system32\drivers\Vcs.sys [5/27/2009 6:38 م 6852]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [3/25/2008 8:07 م 24592]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [5/23/2009 11:42 م 194304]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: Microsoft XML Parser for Java -
DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} - hxxp://174.36.94.118:1999/ReadUid.CAB
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-20 16:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Hints\9@@E@@1 *'D9@J@Q@"A ]
@Allowed: (2) (S-1-5-21-2025429265-1580436667-682003330-1005)
@=""
"PictureSource"="c:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\User Account Pictures\\Default Pictures\\خيول.bmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(960)
c:\windows\system32\klogon.dll
- - - - - - - > 'explorer.exe'(2776)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
.
**************************************************************************
.
Completion time: 2009-06-20 16:40 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-20 13:40
Pre-Run: 17,310,683,136 bytes free
Post-Run: 17,295,327,232 bytes free
263