اخوي الغالي مافيه زر بالفلاش
سويت المطلوب اخواني
وهذا التقرير
ComboFix 09-06-23.01 - saad 06/25/2009 1:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.1015.647 [GMT 3:00]
Running from: c:\documents and settings\saad\سطح المكتب\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\kl1.sys
.
((((((((((((((((((((((((( Files Created from 2009-05-24 to 2009-06-24 )))))))))))))))))))))))))))))))
.
2009-06-24 20:04 . 2009-06-24 20:04 -------- d-----w- c:\documents and settings\Administrator
2009-06-24 19:59 . 2008-07-08 11:54 148496 ----a-w- c:\windows\system32\drivers\34907869.sys
2009-06-24 16:28 . 2009-06-24 16:28 -------- dc----w- c:\windows\system32\dllcache\cache
2009-06-24 16:08 . 2009-06-24 16:08 -------- d-----w- c:\program files\MP3 Player Utilities 3.68
2009-06-24 15:25 . 2009-06-24 15:25 -------- d-----w- c:\program files\Trend Micro
2009-06-24 14:56 . 2009-06-24 14:56 -------- d-----w- C:\DriveKey
2009-06-24 10:40 . 2009-06-24 10:40 -------- d-----w- C:\1f80cf26acbfe278d3c6454c7f478755
2009-06-23 07:20 . 2009-06-24 08:18 -------- d-----w- c:\program files\Autorun Eater
2009-06-21 07:46 . 2009-06-21 07:46 -------- d-----w- c:\docume~1\saad\APPLIC~1\CyberScrub
2009-06-21 07:46 . 2009-06-24 17:46 -------- d-----w- c:\docume~1\saad\APPLIC~1\cleaner
2009-06-19 17:14 . 2009-06-23 07:59 -------- d-----w- c:\program files\Unlocker
2009-06-19 16:50 . 2009-06-24 14:52 -------- d-----w- c:\windows\system32\NtmsData
2009-06-19 16:09 . 2009-06-24 11:47 63 ----a-w- c:\windows\AlfaStart.CMD
2009-06-19 16:09 . 2009-06-24 11:47 74 ----a-w- c:\windows\StartClean.cmd
2009-06-19 16:09 . 2009-06-24 11:47 1410 ----a-w- c:\windows\AlfaRun.cmd
2009-06-19 16:09 . 2009-06-19 16:09 -------- d-----w- c:\program files\Alfa Autorun Killer 2
2009-06-19 16:07 . 2009-06-19 16:07 -------- d--h--w- c:\windows\PIF
2009-06-19 15:58 . 2009-06-24 13:13 -------- d-----w- c:\program files\AutorunRemover
2009-06-19 15:25 . 2008-10-16 11:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-06-19 15:25 . 2008-10-16 11:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-06-19 15:15 . 2009-06-19 15:16 -------- d-----w- c:\docume~1\saad\APPLIC~1\ooVoo Details
2009-06-19 15:15 . 2009-06-19 15:15 -------- d-----w- c:\program files\ooVoo
2009-06-18 14:32 . 2009-06-18 14:34 -------- dcsh--w- c:\program files\Common Files\WindowsLiveInstaller
2009-06-18 14:31 . 2009-06-19 15:09 -------- d-----w- c:\documents and settings\All Users\Application Data\WLInstaller
2009-06-18 02:08 . 2009-06-18 02:08 -------- d-----w- c:\program files\Paltalk Messenger
2009-06-17 01:16 . 2009-06-17 01:16 -------- d-----w- c:\windows\system32\LogFiles
2009-06-16 23:50 . 2009-06-16 23:50 -------- d-----w- c:\documents and settings\saad\Local Settings\Application Data\Yahoo
2009-06-16 23:49 . 2009-06-16 23:49 -------- d-----w- c:\docume~1\saad\APPLIC~1\Yahoo!
2009-06-16 13:42 . 2009-06-16 13:44 -------- d-----w- c:\program files\ManyCam 2.3
2009-06-16 12:10 . 2009-06-16 12:10 -------- d-----w- c:\docume~1\saad\APPLIC~1\Nokia Multimedia Player
2009-06-16 12:07 . 2009-06-16 12:07 -------- d-----w- c:\docume~1\saad\APPLIC~1\GRETECH
2009-06-16 12:00 . 2009-06-16 12:00 -------- d-----w- c:\docume~1\saad\APPLIC~1\Datalayer
2009-06-16 12:00 . 2009-06-16 12:00 -------- d-----w- c:\documents and settings\saad\Phone Browser
2009-06-16 11:58 . 2009-06-16 11:58 -------- d-----w- c:\docume~1\saad\APPLIC~1\Nokia
2009-06-16 11:56 . 2009-06-16 11:56 -------- d-----w- c:\docume~1\saad\APPLIC~1\PC Suite
2009-06-16 11:55 . 2009-06-16 11:55 -------- d-----w- c:\program files\Common Files\PCSuite
2009-06-16 11:55 . 2009-06-16 11:55 -------- d-----w- c:\program files\Common Files\Nokia
2009-06-16 11:55 . 2009-06-16 11:56 -------- d-----w- c:\program files\Nokia
2009-06-16 11:55 . 2009-06-16 11:55 -------- d-----w- c:\docume~1\saad\APPLIC~1\vlc
2009-06-16 11:54 . 2009-06-16 11:54 -------- d-----w- c:\program files\VideoLAN
2009-06-16 11:45 . 2009-06-16 11:45 -------- d-----w- c:\program files\Common Files\xing shared
2009-06-15 00:22 . 2006-09-29 08:26 176165 ----a-w- c:\windows\system32\drv23260.dll
2009-06-15 00:22 . 2006-09-29 08:25 208935 ----a-w- c:\windows\system32\drv33260.dll
2009-06-15 00:22 . 2006-09-29 08:24 217127 ----a-w- c:\windows\system32\drv43260.dll
2009-06-15 00:21 . 2009-06-15 00:22 -------- d-----w- c:\program files\VSO
2009-06-15 00:19 . 2009-06-15 00:19 -------- d-----w- c:\program files\CamStudio
2009-06-15 00:18 . 2009-06-16 23:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-06-15 00:17 . 2009-06-19 01:31 -------- d-----w- c:\program files\Yahoo!
2009-06-15 00:16 . 2009-06-15 00:16 -------- d-----w- c:\program files\TGTSoft
2009-06-15 00:14 . 2009-06-15 00:15 -------- d-----w- c:\program files\AAAScreenCaptureV2.1
2009-06-15 00:11 . 2009-06-15 00:11 -------- d-----w- c:\program files\PConPoint
2009-06-15 00:10 . 2009-06-24 22:19 -------- d-----w- c:\docume~1\saad\APPLIC~1\DMCache
2009-06-15 00:10 . 2009-06-19 15:12 -------- d-----w- c:\docume~1\saad\APPLIC~1\IDM
2009-06-15 00:10 . 2009-06-20 22:18 -------- d-----w- c:\program files\Internet Download Manager
2009-06-15 00:09 . 2009-06-15 00:09 -------- d-----w- c:\documents and settings\saad\Local Settings\Application Data\Thinstall
2009-06-15 00:09 . 2009-06-15 00:09 -------- d-----w- c:\docume~1\saad\APPLIC~1\Thinstall
2009-06-14 21:19 . 2009-06-18 02:08 -------- d-----w- c:\docume~1\saad\APPLIC~1\Paltalk
2009-06-14 21:15 . 2009-06-20 00:39 -------- d-----w- c:\program files\Registry Winner
2009-06-14 21:12 . 2009-06-14 21:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-06-14 21:03 . 2009-06-14 21:13 -------- d-----w- c:\program files\The KMPlayer
2009-06-14 21:01 . 2009-06-14 21:02 -------- d-----w- c:\windows\system32\ar-sa
2009-06-14 20:54 . 2009-04-29 04:42 268288 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-06-14 20:54 . 2009-04-29 04:42 63488 -c----w- c:\windows\system32\dllcache\icardie.dll
2009-06-14 20:54 . 2009-04-29 04:42 383488 -c----w- c:\windows\system32\dllcache\ieapfltr.dll
2009-06-14 20:54 . 2009-04-28 09:05 13824 -c----w- c:\windows\system32\dllcache\ieudinit.exe
2009-06-14 20:54 . 2008-07-09 14:25 2455488 -c----w- c:\windows\system32\dllcache\ieapfltr.dat
2009-06-14 20:54 . 2009-04-29 04:42 459264 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-06-14 20:54 . 2009-04-29 04:42 52224 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-06-14 20:54 . 2009-04-29 04:42 6066176 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-06-14 20:52 . 2009-06-18 14:32 -------- d-----w- c:\program files\Windows Live
2009-06-14 20:52 . 2009-06-14 21:59 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-14 20:52 . 2009-06-14 20:52 27264 ----a-w- c:\documents and settings\saad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-14 20:50 . 2009-06-17 21:39 -------- d-----w- c:\documents and settings\saad\Contacts
2009-06-14 20:48 . 2009-06-18 14:45 -------- d-----w- c:\program files\MSN Messenger
2009-06-13 22:59 . 2009-06-14 21:01 -------- d--h--w- c:\windows\$hf_mig$
2009-06-13 22:42 . 2009-06-24 14:22 -------- d-----w- c:\docume~1\saad\APPLIC~1\TeamViewer
2009-06-13 22:34 . 2004-08-03 19:58 100992 -c--a-w- c:\windows\system32\dllcache\bthpan.sys
2009-06-13 22:34 . 2004-08-03 19:58 100992 ----a-w- c:\windows\system32\drivers\bthpan.sys
2009-06-13 20:07 . 2009-06-24 13:10 -------- d-----w- c:\docume~1\saad\APPLIC~1\skypePM
2009-06-13 20:07 . 2009-06-13 20:07 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-06-13 20:07 . 2009-06-24 21:16 -------- d-----w- c:\docume~1\saad\APPLIC~1\Skype
2009-06-13 20:06 . 2009-06-13 20:07 -------- d-----w- c:\program files\Skype
2009-06-13 20:06 . 2009-06-13 20:06 -------- d-----w- c:\program files\Common Files\Skype
2009-06-13 20:06 . 2009-06-13 20:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-06-13 20:03 . 2009-06-24 13:16 -------- d-----w- c:\program files\USB Disk Security
2009-06-13 19:26 . 2009-06-13 19:26 -------- d-----w- c:\documents and settings\saad\DoctorWeb
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-24 22:19 . 2009-06-15 00:25 -------- d-----w- c:\program files\DNA
2009-06-24 22:19 . 2009-06-15 00:25 -------- d-----w- c:\docume~1\saad\APPLIC~1\DNA
2009-06-24 22:19 . 2004-06-13 18:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-24 22:17 . 2004-06-13 18:59 3024 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-24 22:17 . 2004-06-13 18:59 262176 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-24 22:17 . 2004-06-13 18:59 1483808 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-24 22:17 . 2004-06-13 18:59 13720 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-24 22:17 . 2001-09-19 11:00 40316 ----a-w- c:\windows\system32\perfc001.dat
2009-06-24 22:17 . 2001-09-19 11:00 251946 ----a-w- c:\windows\system32\perfh001.dat
2009-06-24 20:03 . 2009-06-15 00:25 -------- d-----w- c:\docume~1\saad\APPLIC~1\BitTorrent
2009-06-24 18:01 . 2004-06-13 19:00 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-06-24 18:01 . 2004-06-13 19:00 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-06-24 14:56 . 2004-06-13 18:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-24 14:56 . 2004-06-13 18:52 -------- d-----w- c:\program files\Common Files\InstallShield
2009-06-16 11:51 . 2009-06-16 11:51 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-06-16 11:45 . 2009-06-16 11:45 -------- d-----w- c:\program files\Common Files\Real
2009-06-16 11:44 . 2009-06-16 11:44 -------- d-----w- c:\program files\Real
2009-06-16 11:39 . 2009-06-16 11:39 -------- d-----w- c:\program files\GRETECH
2009-06-15 00:28 . 2009-06-15 00:22 -------- d-----w- c:\docume~1\saad\APPLIC~1\Vso
2009-06-15 00:25 . 2009-06-15 00:25 -------- d-----w- c:\program files\BitTorrent
2009-06-15 00:22 . 2009-06-15 00:22 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-06-15 00:22 . 2009-06-15 00:22 47360 ----a-w- c:\docume~1\saad\APPLIC~1\pcouffin.sys
2009-06-14 21:34 . 2009-06-14 21:34 2232 ----a-w- c:\windows\java\Packages\Data\FPJL7NFN.DAT
2009-06-14 21:34 . 2009-06-14 21:34 155995 ----a-w- c:\windows\java\Packages\ZFP7F5RD.ZIP
2009-06-14 21:34 . 2009-06-14 21:34 2678 ----a-w- c:\windows\java\Packages\Data\8VJ1RD3H.DAT
2009-06-14 21:34 . 2009-06-14 21:34 2678 ----a-w- c:\windows\java\Packages\Data\ZZ7FL3DR.DAT
2009-06-14 21:34 . 2009-06-14 21:34 2678 ----a-w- c:\windows\java\Packages\Data\XRPJTB7J.DAT
2009-06-14 21:34 . 2009-06-14 21:34 2678 ----a-w- c:\windows\java\Packages\Data\WMTRZDBJ.DAT
2009-06-14 21:34 . 2009-06-14 21:34 2678 ----a-w- c:\windows\java\Packages\Data\BLBDJ7R5.DAT
2009-06-13 22:11 . 2008-01-29 14:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-06-13 20:56 . 2004-06-13 18:35 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-29 04:43 . 2004-08-03 21:55 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:42 . 2004-08-03 21:55 78336 ------w- c:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-24_16.27.32 )))))))))))))))))))))))))))))))))))))))))
.
- 2001-09-19 11:00 . 2009-06-24 13:13 40326 c:\windows\system32\perfc009.dat
+ 2001-09-19 11:00 . 2009-06-24 22:17 40326 c:\windows\system32\perfc009.dat
+ 2009-06-24 16:28 . 2008-10-16 11:09 51224 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-06-24 16:28 . 2004-08-03 21:56 82944 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-06-24 16:28 . 2004-08-03 21:56 24576 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-06-24 16:28 . 2004-08-03 21:56 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-06-24 16:28 . 2004-08-03 21:56 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-06-24 16:28 . 2004-08-03 21:55 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-06-24 16:28 . 2004-08-03 21:56 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-06-24 16:28 . 2004-08-03 21:45 24448 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-06-24 16:28 . 2004-08-03 20:00 29056 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-06-24 16:28 . 2004-08-03 21:56 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
- 2009-06-24 16:27 . 2009-06-24 16:27 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-06-24 22:18 . 2009-06-24 22:18 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-06-13 18:40 . 2009-06-24 16:27 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2004-06-13 18:40 . 2009-06-24 22:18 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2004-06-13 18:40 . 2009-06-24 22:18 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2004-06-13 18:40 . 2009-06-24 16:27 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2001-09-19 11:00 . 2009-06-24 13:13 311938 c:\windows\system32\perfh009.dat
+ 2001-09-19 11:00 . 2009-06-24 22:17 311938 c:\windows\system32\perfh009.dat
+ 2009-06-24 16:28 . 2004-08-03 21:56 501248 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-06-24 16:28 . 2009-04-29 04:43 827392 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-06-24 16:28 . 2004-08-03 21:55 576512 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-06-24 16:28 . 2004-08-03 21:55 295424 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-06-24 16:28 . 2004-08-03 20:14 359040 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-06-24 16:28 . 2004-08-03 21:56 108032 c:\windows\system32\dllcache\cache\services.exe
+ 2009-06-24 16:28 . 2004-08-03 20:14 182912 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-06-24 16:28 . 2004-08-03 21:55 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-06-24 16:28 . 2004-08-03 21:55 162304 c:\windows\system32\dllcache\cache\appmgmts.dll
+ 2009-06-24 16:28 . 2004-08-03 21:55 1547776 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-06-24 16:28 . 2004-08-03 21:48 2149888 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-06-24 16:28 . 2004-08-03 22:08 2016768 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-06-24 16:28 . 2004-08-03 21:55 1351680 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-06-24 16:28 . 2004-08-03 21:56 1029632 c:\windows\system32\dllcache\cache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-29 21755688]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-06-16 318272]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-11-30 1306624]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-10-29 2606512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-05 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-05 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-05 138008]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-16 180269]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-06-13 206088]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-01-05 16384512]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2008-01-05 1826816]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
backup=c:\windows\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP

oVoo TCP المنفذ 443
"443:UDP"= 443:UDP

oVoo UDP المنفذ 443
"37674:TCP"= 37674:TCP

oVoo TCP المنفذ 37674
"37674:UDP"= 37674:UDP

oVoo UDP المنفذ 37674
"37675:UDP"= 37675:UDP

oVoo UDP المنفذ 37675
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [1/29/2008 05:29 م 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [3/13/2008 06:02 م 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [4/30/2008 05:06 م 24592]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [1/14/2008 01:06 م 21632]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [6/13/2004 09:51 م 264576]
S1 is-NVEN7drv;is-NVEN7drv;c:\windows\system32\drivers\34907869.sys [6/24/2009 10:59 م 148496]
.
Contents of the 'Scheduled Tasks' folder
2009-06-14 c:\windows\Tasks\Registry Winner Schedule.job
- c:\program files\Registry Winner\RegistryWinner.exe [2009-06-14 08:17]
.
.
------- Supplementary Scan -------
.
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
uInternet Settings,ProxyServer = proxy1.jawalnet.net.sa:8080
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-25 01:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2228)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\agrsmsvc.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\rundll32.exe
c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
c:\progra~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
c:\progra~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-06-24 1:21 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-24 22:21
ComboFix2.txt 2009-06-24 16:29
Pre-Run: 44,370,685,952 bytes free
Post-Run: 44,314,624,000 bytes free
277 --- E O F --- 2009-06-13 23:00