وهذا التقرير بعد مانزلت الاداه
ComboFix 09-06-18.02 - user 06/19/2009 21:55.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1256.974.1033.18.2037.1022 [GMT 3:00]
Running from: c:\users\user\Documents\My Completed Downloads\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Kaspersky Anti-Virus *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2347180839-3205931739-3509662-500
c:\$recycle.bin\S-1-5-21-658016502-570071951-3739974579-500
c:\$recycle.bin\S-1-5-21-2347180839-3205931739-3509662-500\desktop.ini
c:\$recycle.bin\S-1-5-21-658016502-570071951-3739974579-500\desktop.ini
.
((((((((((((((((((((((((( Files Created from 2009-05-19 to 2009-06-19 )))))))))))))))))))))))))))))))
.
2009-06-19 18:18 . 2009-06-19 18:18 -------- d-----w- c:\program files\Trend Micro
2009-06-19 12:09 . 2009-06-19 12:09 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-06-19 09:19 . 2008-03-17 08:57 103680 ----a-w- c:\windows\system32\drivers\ewusbfake.sys
2009-06-19 09:19 . 2008-03-17 08:05 101632 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2009-06-19 09:19 . 2008-03-16 11:47 872192 ----a-w- c:\windows\system32\drivers\mod7700.sys
2009-06-19 09:19 . 2008-01-22 12:10 100864 ----a-w- c:\windows\system32\drivers\ewusbnet.sys
2009-06-19 09:19 . 2007-08-09 01:06 23424 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2009-06-19 08:02 . 2009-06-19 08:02 3584 ----a-r- c:\users\user\AppData\Roaming\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2009-06-19 08:02 . 2009-06-19 08:02 -------- d-----w- c:\program files\Windows Installer Clean Up
2009-06-19 07:58 . 2009-06-19 08:01 -------- d-----w- c:\program files\MSECACHE
2009-06-19 07:37 . 2009-06-19 07:37 83248 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-06-10 18:15 . 2009-04-21 11:39 2034688 ----a-w- c:\windows\system32\win32k.sys
2009-06-10 18:15 . 2009-04-23 12:14 623616 ----a-w- c:\windows\system32\localspl.dll
2009-06-10 18:15 . 2009-04-23 12:15 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-06-10 18:14 . 2009-04-24 16:02 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-10 18:14 . 2009-04-23 12:15 828416 ----a-w- c:\windows\system32\wininet.dll
2009-06-08 20:28 . 2009-06-19 08:14 -------- d-----w- c:\program files\Qtel Mobile Broadband E180
2009-05-27 19:01 . 2009-05-27 19:01 -------- d-----w- c:\users\user\AppData\Local\Mozilla
2009-05-27 18:49 . 2009-05-27 19:10 -------- d-----w- c:\program files\VS Revo Group
2009-05-26 23:20 . 2009-05-26 23:20 -------- d-----w- C:\inetpub
2009-05-26 22:49 . 2009-06-19 09:19 -------- d-----w- c:\program files\Mobile Partner
2009-05-26 21:43 . 2009-05-26 21:46 -------- d-----w- c:\windows\system32\ca-ES
2009-05-26 21:43 . 2009-05-26 21:46 -------- d-----w- c:\windows\system32\eu-ES
2009-05-26 21:43 . 2009-05-26 21:46 -------- d-----w- c:\windows\system32\vi-VN
2009-05-26 21:28 . 2009-05-26 21:28 -------- d-----w- c:\windows\system32\EventProviders
2009-05-26 21:25 . 2009-04-11 06:28 190464 ----a-w- c:\windows\system32\sperror.dll
2009-05-26 21:24 . 2009-04-11 06:28 222720 ----a-w- c:\windows\system32\umpnpmgr.dll
2009-05-26 21:23 . 2009-04-11 06:28 155136 ----a-w- c:\windows\system32\rasmontr.dll
2009-05-26 20:52 . 2009-05-26 20:52 -------- d-----w- C:\f99199caf4f82c3753e1
2009-05-26 20:38 . 2009-05-26 20:38 -------- d-----w- c:\users\user\AppData\Local\Apps
2009-05-26 20:29 . 2009-05-26 20:29 -------- d-----w- c:\users\user\AppData\Local\Powercinema
2009-05-26 20:28 . 2009-05-26 20:29 -------- d-----w- c:\users\user\AppData\Roaming\CyberLink
2009-05-26 19:36 . 2009-05-27 21:31 -------- d-----w- c:\users\user\AppData\Local\MigWiz
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-19 18:56 . 2009-03-10 22:29 291124768 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-19 17:45 . 2009-03-10 22:29 -------- d-----w- c:\programdata\Kaspersky Lab
2009-06-19 17:44 . 2009-03-10 22:29 3895736 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-19 17:44 . 2008-09-25 21:56 3204 ----a-w- c:\windows\bthservsdp.dat
2009-06-16 15:15 . 2009-02-21 11:40 83456 ----a-w- c:\programdata\SpeedBit\DAP\SDCondition.dll
2009-06-14 17:51 . 2009-02-26 21:27 -------- d-----w- c:\programdata\lockslitedog
2009-06-14 17:51 . 2009-02-26 21:27 -------- d-----w- c:\program files\Cicle Developement
2009-06-10 21:09 . 2008-09-25 20:29 -------- d-----w- c:\program files\Microsoft Works
2009-05-27 22:14 . 2009-05-27 22:14 2678 ----a-w- c:\windows\Java\Packages\Data\R3JBL7PB.DAT
2009-05-27 22:14 . 2009-05-27 22:14 2678 ----a-w- c:\windows\Java\Packages\Data\AE797ZJD.DAT
2009-05-27 22:14 . 2009-05-27 22:14 2678 ----a-w- c:\windows\Java\Packages\Data\W400BJHZ.DAT
2009-05-27 22:14 . 2009-05-27 22:14 2678 ----a-w- c:\windows\Java\Packages\Data\NBRZ57DB.DAT
2009-05-27 22:14 . 2009-05-27 22:14 2678 ----a-w- c:\windows\Java\Packages\Data\FV9VTBH3.DAT
2009-05-26 21:46 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-05-26 21:46 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-26 21:46 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-05-26 21:46 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2009-05-26 21:46 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2009-05-26 21:46 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-05-26 21:43 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-05-26 21:14 . 2009-02-23 19:16 -------- d-----w- c:\program files\AviSynth 2.5
2009-05-26 20:28 . 2008-09-25 20:26 -------- d-----w- c:\programdata\CyberLink
2009-05-20 19:07 . 2009-03-10 22:30 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-20 19:07 . 2009-03-10 22:30 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-02 11:33 . 2009-02-26 21:27 -------- d-----w- c:\programdata\Poke admin tons bike
2009-04-24 11:40 . 2009-02-19 16:22 -------- d-----w- c:\program files\Messenger Plus! Live
2009-04-17 15:33 . 2009-03-23 21:32 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-11 06:33 . 2009-05-26 21:25 986600 ----a-w- c:\windows\system32\winload.exe
2009-04-11 06:33 . 2009-05-26 21:25 926184 ----a-w- c:\windows\system32\winresume.exe
2009-04-11 06:33 . 2009-05-26 21:24 292840 ----a-w- c:\windows\system32\drivers\volmgrx.sys
2009-04-11 06:33 . 2009-05-26 21:25 897000 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-04-11 06:33 . 2009-05-26 21:25 614376 ----a-w- c:\windows\system32\ci.dll
2009-04-11 06:28 . 2009-05-26 21:25 56320 ----a-w- c:\windows\system32\xmlfilter.dll
2009-04-11 06:27 . 2009-05-26 21:26 441344 ----a-w- c:\windows\system32\SearchIndexer.exe
2009-04-11 06:22 . 2009-05-26 21:23 7168 ----a-w- c:\windows\system32\f3ahvoas.dll
2009-04-11 06:21 . 2009-05-26 21:23 37376 ----a-w- c:\windows\system32\cdd.dll
2009-04-11 05:42 . 2009-05-26 21:23 93696 ----a-w- c:\windows\system32\drivers\bridge.sys
2009-04-11 05:03 . 2009-05-26 21:26 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-04-11 05:03 . 2009-05-26 21:26 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2009-04-11 04:57 . 2009-05-26 21:23 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-04-11 04:54 . 2009-05-26 21:23 2048 ----a-w- c:\windows\system32\mferror.dll
2009-04-11 04:51 . 2009-05-26 21:23 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2009-04-11 04:47 . 2009-05-26 21:24 273920 ----a-w- c:\windows\system32\drivers\afd.sys
2009-04-11 04:46 . 2009-05-26 21:23 69120 ----a-w- c:\windows\system32\drivers\rassstp.sys
2009-04-11 04:46 . 2009-05-26 21:23 121344 ----a-w- c:\windows\system32\drivers\ndiswan.sys
2009-04-11 04:46 . 2009-05-26 21:23 41472 ----a-w- c:\windows\system32\drivers\raspppoe.sys
2009-04-11 04:46 . 2009-05-26 21:23 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2009-04-11 04:46 . 2009-05-26 21:23 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2009-04-11 04:46 . 2009-05-26 21:24 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-04-11 04:45 . 2009-05-26 21:23 72192 ----a-w- c:\windows\system32\drivers\tdx.sys
2009-04-11 04:45 . 2009-05-26 21:23 72192 ----a-w- c:\windows\system32\drivers\pacer.sys
2009-04-11 04:45 . 2009-05-26 21:24 185856 ----a-w- c:\windows\system32\drivers\netbt.sys
2009-04-11 04:45 . 2009-05-26 21:24 401408 ----a-w- c:\windows\system32\drivers\http.sys
2009-04-11 04:45 . 2009-05-26 21:23 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2009-04-11 04:45 . 2009-05-26 21:23 66560 ----a-w- c:\windows\system32\drivers\smb.sys
2009-04-11 04:43 . 2009-05-26 21:23 148480 ----a-w- c:\windows\system32\drivers\nwifi.sys
2009-04-11 04:43 . 2009-05-26 21:25 196096 ----a-w- c:\windows\system32\drivers\usbhub.sys
2009-04-11 04:43 . 2009-05-26 21:25 148992 ----a-w- c:\windows\system32\drivers\rfcomm.sys
2009-04-11 04:43 . 2009-05-26 21:26 507904 ----a-w- c:\windows\system32\drivers\bthport.sys
2009-04-11 04:43 . 2009-05-26 21:24 22528 ----a-w- c:\windows\system32\drivers\bthenum.sys
2009-04-11 04:43 . 2009-05-26 21:23 41472 ----a-w- c:\windows\system32\drivers\bthmodem.sys
2009-04-11 04:43 . 2009-05-26 21:24 29696 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2009-04-11 04:43 . 2009-05-26 21:23 62208 ----a-w- c:\windows\system32\drivers\ohci1394.sys
2009-04-11 04:42 . 2009-05-26 21:24 226304 ----a-w- c:\windows\system32\drivers\usbport.sys
2009-04-11 04:42 . 2009-05-26 21:24 25856 ----a-w- c:\windows\system32\drivers\USBCAMD2.sys
2009-04-11 04:42 . 2009-05-26 21:24 25856 ----a-w- c:\windows\system32\drivers\USBCAMD.sys
2009-04-11 04:42 . 2009-05-26 21:24 39936 ----a-w- c:\windows\system32\drivers\usbehci.sys
2009-04-11 04:42 . 2009-05-26 21:24 167936 ----a-w- c:\windows\system32\drivers\portcls.sys
2009-04-11 04:42 . 2009-05-26 21:23 12800 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-04-11 04:42 . 2009-05-26 21:23 39424 ----a-w- c:\windows\system32\drivers\hidclass.sys
2009-04-11 04:42 . 2009-05-26 21:23 52992 ----a-w- c:\windows\system32\drivers\stream.sys
2009-04-11 04:42 . 2009-05-26 21:26 561152 ----a-w- c:\windows\system32\drivers\hdaudbus.sys
2009-04-11 04:39 . 2009-05-26 21:23 16384 ----a-w- c:\windows\system32\iscsilog.dll
2009-04-11 04:39 . 2009-05-26 21:23 67072 ----a-w- c:\windows\system32\drivers\cdrom.sys
2009-04-11 04:39 . 2009-05-26 21:23 19456 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2009-04-11 04:38 . 2009-05-26 21:24 149504 ----a-w- c:\windows\system32\drivers\ks.sys
2009-04-11 04:38 . 2009-05-26 21:24 17408 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2009-04-11 04:27 . 2009-05-26 21:23 2560 ----a-w- c:\windows\system32\msimsg.dll
2009-04-11 04:23 . 2009-05-26 21:25 626176 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-04-11 04:23 . 2009-05-26 21:23 76288 ----a-w- c:\windows\system32\drivers\dxg.sys
2009-04-11 04:23 . 2009-05-26 21:23 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-04-11 04:22 . 2009-05-26 21:23 33280 ----a-w- c:\windows\system32\drivers\watchdog.sys
2009-04-11 04:19 . 2009-05-26 21:24 89088 ----a-w- c:\windows\system32\drivers\sdbus.sys
2009-04-11 04:15 . 2009-05-26 21:24 288768 ----a-w- c:\windows\system32\drivers\srv.sys
2009-04-11 04:15 . 2009-05-26 21:24 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-04-11 04:15 . 2009-05-26 21:24 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2009-04-11 04:14 . 2009-05-26 21:25 114688 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2009-04-11 04:14 . 2009-05-26 21:24 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-04-11 04:14 . 2009-05-26 21:25 225280 ----a-w- c:\windows\system32\drivers\rdbss.sys
2009-04-11 04:14 . 2009-05-26 21:24 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2009-04-11 04:14 . 2009-05-26 21:24 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-04-11 04:14 . 2009-05-26 21:23 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2009-04-11 04:14 . 2009-05-26 21:24 35328 ----a-w- c:\windows\system32\drivers\npfs.sys
2009-04-11 04:13 . 2009-05-26 21:23 226816 ----a-w- c:\windows\system32\drivers\udfs.sys
2009-04-11 04:13 . 2009-05-26 21:24 136704 ----a-w- c:\windows\system32\drivers\exfat.sys
2009-04-11 04:13 . 2009-05-26 21:23 142848 ----a-w- c:\windows\system32\drivers\fastfat.sys
2009-04-11 04:12 . 2009-05-26 21:25 617984 ----a-w- c:\windows\system32\adtschema.dll
2009-04-11 02:52 . 2009-05-26 21:26 684032 ----a-w- c:\windows\system32\drivers\spsys.sys
2009-04-11 01:59 . 2009-05-26 21:25 107612 ----a-w- c:\windows\system32\StructuredQuerySchema.bin
2009-03-30 04:42 . 2009-05-26 21:26 278848 ----a-w- c:\windows\system32\mscoree.dll
2008-09-25 20:10 . 2008-09-25 20:10 76 --sha-r- c:\windows\CT4CET.bin
2008-09-26 05:43 . 2008-09-26 05:42 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{72ae8426-3b8d-4ead-b191-8d0ad1c62158}]
2009-02-19 13:58 2081304 ----a-w- c:\program files\P2P_Max\tbP2P_.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnhancedStorageShell]
@="{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}"
[HKEY_CLASSES_ROOT\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}]
2009-04-11 06:28 114176 ----a-w- c:\windows\System32\EhStorShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2009-02-21 2807296]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 405504]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-21 185872]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-06 133656]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-06 166424]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-06 141848]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2008-03-04 36864]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-05-04 167936]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-2-19 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-9-25 50688]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"BindDirectlyToPropertySetStorage"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-09-25 20:30 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1.0\r3hook.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):0a,bb,ee,3b,4c,de,c9,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D9701C99-5694-49E0-82AE-E2B7577A4678}"= c:\program files\Dell\MediaDirect\MediaDirect.exe

ell MediaDirect
"{66A71BA3-7F3D-4A09-A1D9-ABB51E29B9B1}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{5FC933C3-CE29-4C54-B116-FC7EF1581C6A}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{CE912A2F-AC79-4A7F-8580-BE1CAE18C391}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"TCP Query User{E3DE220D-0E7F-4A0C-8CB6-4AFC0632EAD3}c:\\programdata\\kaspersky lab setup files\\kaspersky anti-virus 7.0.1.325\\english\\setup.exe"= UDP:c:\programdata\kaspersky lab setup files\kaspersky anti-virus 7.0.1.325\english\setup.exe:Kaspersky Anti-Virus 7.0 Setup
"UDP Query User{9A26CDDA-483E-43ED-806D-1084CFFE446C}c:\\programdata\\kaspersky lab setup files\\kaspersky anti-virus 7.0.1.325\\english\\setup.exe"= TCP:c:\programdata\kaspersky lab setup files\kaspersky anti-virus 7.0.1.325\english\setup.exe:Kaspersky Anti-Virus 7.0 Setup
"{C432BE87-DA94-43A4-8C38-EC0B2E88090D}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{37FF8AD4-5431-4348-A1D2-DBD5FF4A69CD}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{AF94E711-DC53-4DD7-900E-414D72EFD937}"= UDP:c:\users\user\LimeWire\LimeWire.exe:LimeWire
"{84ABBE2E-D368-460F-A0B8-8E13F47DC70A}"= TCP:c:\users\user\LimeWire\LimeWire.exe:LimeWire
"{47A815F5-03C5-4656-84BF-9B4850D1AC0C}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [16/10/2007 11:05 AM 20496]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [26/09/2008 12:54 AM 73728]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [02/05/2008 03:09 PM 161048]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\System32\drivers\IntcHdmi.sys [26/09/2008 08:49 AM 111616]
S3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [26/09/2008 08:49 AM 235648]
S3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [26/09/2008 08:49 AM 7424]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder
2009-06-18 c:\windows\Tasks\User_Feed_Synchronization-{346023D5-582E-4252-9FF2-CECB3DECB3D8}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
TCP: {EB8DFF41-CC37-463A-A6F9-030963A31729} = 212.77.192.59 212.77.192.60
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-19 22:02
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(776)
c:\progra~1\KASPER~1\KASPER~1.0\r3hook.dll
c:\windows\system32\NSI.dll
- - - - - - - > 'lsass.exe'(692)
c:\progra~1\KASPER~1\KASPER~1.0\r3hook.dll
.
Completion time: 2009-06-19 22:04
ComboFix-quarantined-files.txt 2009-06-19 19:04
Pre-Run: 176,306,561,024 bytes free
Post-Run: 176,476,483,584 bytes free
302 --- E O F --- 2009-06-18 20:39
ا