جزاك الله خير وكتب لك الاجر
هذا هو التقرير بعد تعطيل الكاسبر
ComboFix 09-06-23.01 - user 06/24/2009 20:04.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.1015.635 [GMT 3:00]
Running from: c:\documents and settings\user\My Documents\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\kl1.sys
.
((((((((((((((((((((((((( Files Created from 2009-05-24 to 2009-06-24 )))))))))))))))))))))))))))))))
.
2009-06-24 16:43 . 2009-06-24 16:43 -------- dc----w- c:\windows\system32\dllcache\cache
2009-06-24 16:19 . 2009-06-24 16:19 -------- d-----w- c:\program files\Trend Micro
2009-06-22 13:03 . 2009-06-22 13:03 -------- d-----w- c:\windows\system32\apigidsys
2009-06-22 13:03 . 2009-06-22 13:03 -------- d-----w- c:\program files\Zabaware
2009-06-22 13:03 . 2009-06-22 13:03 -------- d-----w- c:\program files\Haptek
2009-06-22 13:03 . 2003-02-20 07:59 413696 ----a-w- c:\windows\system32\hapapi2.dll
2009-06-22 13:02 . 2009-06-22 13:02 -------- d-----w- c:\windows\lhsp
2009-06-20 13:19 . 2009-06-20 13:19 -------- d-----w- c:\program files\QuickTime
2009-06-13 21:59 . 2009-06-13 21:59 390664 ----a-w- c:\documents and settings\user\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
2009-06-10 20:37 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-10 20:37 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-10 02:34 . 2009-06-10 02:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-06-06 15:22 . 2009-06-06 15:22 -------- d-----w- c:\program files\Common Files\Java
2009-05-31 15:15 . 2009-05-31 15:15 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
2009-05-31 15:15 . 2009-05-31 15:15 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
2009-05-31 15:15 . 2009-05-31 15:15 226832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
2009-05-31 14:57 . 2009-06-24 16:56 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-31 14:57 . 2009-06-24 16:56 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-31 14:56 . 2009-06-24 17:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-05-31 14:56 . 2009-06-24 17:07 401440 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-05-31 14:56 . 2009-06-24 17:07 1989152 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-05-26 02:19 . 2006-08-29 14:56 32377 ----a-w- c:\windows\system32\drivers\prodigy.sys
2009-05-26 02:19 . 2009-05-26 02:19 -------- d-----w- c:\program files\NSS
2009-05-26 01:30 . 2009-05-26 01:30 -------- d-----w- c:\documents and settings\user\Application Data\Datalayer
2009-05-26 01:28 . 2009-05-26 01:31 -------- d-sh--w- c:\documents and settings\user\Phone Browser
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-24 17:07 . 2009-05-31 14:56 3500 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-24 17:07 . 2009-05-31 14:56 17668 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-24 15:47 . 2009-05-02 21:31 -------- d-----w- c:\documents and settings\user\Application Data\Skype
2009-06-24 13:59 . 2009-04-28 20:19 -------- d-----w- c:\documents and settings\user\Application Data\skypePM
2009-06-19 18:12 . 2009-05-06 04:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-14 18:56 . 2009-03-15 17:46 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-14 18:56 . 2009-03-08 08:14 -------- d-----w- c:\program files\MSN Messenger
2009-06-08 01:10 . 2009-04-17 15:53 -------- d-----w- c:\program files\eLecta Live
2009-06-06 15:24 . 2009-05-07 21:41 -------- d-----w- c:\program files\iVocalize Web Conference 4
2009-06-06 15:23 . 2009-03-18 23:18 -------- d-----w- c:\program files\Java
2009-05-31 15:16 . 2008-01-29 14:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-05-31 14:56 . 2009-05-09 14:35 -------- d-----w- c:\program files\Kaspersky Lab
2009-05-31 14:54 . 2009-05-09 14:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-05-26 01:28 . 2009-05-09 22:40 -------- d-----w- c:\documents and settings\user\Application Data\PC Suite
2009-05-24 14:26 . 2009-05-24 14:26 32256 ----a-w- c:\documents and settings\user\Application Data\Thinstall\TeamViewer 4\4000009c00002i\IEXPLORE.EXE
2009-05-24 14:26 . 2009-05-24 14:26 32256 ----a-w- c:\documents and settings\user\Application Data\Thinstall\TeamViewer 4\1000000e00002i\mshta.exe
2009-05-24 14:13 . 2009-05-14 21:44 -------- d-----w- c:\documents and settings\user\Application Data\Thinstall
2009-05-22 20:57 . 2009-05-22 20:57 8704 ----a-w- c:\documents and settings\user\Application Data\Thinstall\PHOTOSHOP\1000000b00002h\verclsid.exe
2009-05-14 21:44 . 2009-05-14 21:44 8704 ----a-w- c:\documents and settings\user\Application Data\Thinstall\PHOTOSHOP\1000000b00002h\rundll32.exe
2009-05-13 21:50 . 2009-05-13 21:50 -------- d-----w- c:\program files\MSXML 4.0
2009-05-13 16:01 . 2009-03-08 06:50 166455 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-13 15:45 . 2009-05-13 15:45 -------- d-----w- c:\program files\Driver-Soft
2009-05-13 05:15 . 2007-12-28 21:04 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-12 19:47 . 2009-05-12 19:47 -------- d-----w- c:\documents and settings\user\Application Data\Ashampoo
2009-05-12 19:34 . 2009-05-12 19:34 -------- d-----w- c:\documents and settings\All Users\Application Data\ashampoo
2009-05-12 19:34 . 2009-05-12 19:34 -------- d-----w- c:\program files\Ashampoo
2009-05-12 06:39 . 2009-05-12 06:38 -------- d-----w- c:\documents and settings\Guest\Application Data\PC Suite
2009-05-11 19:25 . 2009-05-11 19:25 -------- d-----w- c:\program files\Common Files\xing shared
2009-05-11 19:25 . 2009-03-08 08:11 -------- d-----w- c:\program files\Common Files\Real
2009-05-09 22:43 . 2009-05-09 22:43 -------- d-----w- c:\documents and settings\user\Application Data\Nokia Multimedia Player
2009-05-09 22:42 . 2009-05-09 22:41 -------- d-----w- c:\documents and settings\user\Application Data\Nokia
2009-05-09 22:42 . 2009-05-09 22:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-05-09 22:40 . 2009-05-09 22:40 -------- d-----w- c:\program files\Common Files\PCSuite
2009-05-09 22:40 . 2009-05-09 22:40 -------- d-----w- c:\program files\Common Files\Nokia
2009-05-09 22:40 . 2009-05-09 22:39 -------- d-----w- c:\program files\Nokia
2009-05-09 22:40 . 2009-05-09 22:40 -------- d-----w- c:\program files\PC Connectivity Solution
2009-05-09 15:38 . 2009-03-15 17:46 -------- d-----w- c:\program files\Circle Developement
2009-05-09 15:29 . 2009-03-15 17:48 -------- d-----w- c:\documents and settings\user\Application Data\loginfoping
2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 10:12 . 2009-05-06 10:12 -------- d-----w- c:\documents and settings\user\Application Data\Apple Computer
2009-05-06 04:48 . 2009-05-06 04:47 -------- d-----w- c:\program files\Apple Software Update
2009-05-06 04:47 . 2009-05-06 04:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-05-05 20:47 . 2009-05-05 20:47 -------- d-----w- c:\program files\Windows Media Connect 2
2009-05-05 00:01 . 2009-04-15 12:17 -------- d-----w- c:\documents and settings\user\Application Data\HP
2009-05-05 00:01 . 2009-05-04 23:49 -------- d-----w- c:\documents and settings\user\Application Data\Image Zone Express
2009-05-02 21:31 . 2009-05-02 21:31 -------- d-----w- c:\program files\Skype
2009-05-02 21:31 . 2009-04-28 20:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-05-02 21:31 . 2009-05-02 21:31 -------- d-----w- c:\program files\Common Files\Skype
2009-04-30 04:42 . 2009-04-30 04:42 -------- d-----w- c:\documents and settings\user\Application Data\Media Player Classic
2009-04-28 20:19 . 2009-04-28 20:19 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-04-25 00:50 . 2009-04-25 00:50 57104 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-17 12:26 . 2004-08-04 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-14 13:11 . 2009-04-14 13:11 152576 ----a-w- c:\documents and settings\user\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-07 23:10 . 2009-04-07 22:54 110030 ----a-w- c:\windows\hpoins08.dat
2009-03-27 17:29 . 2009-03-08 08:11 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-03-27 17:29 . 2009-03-08 08:11 348160 ----a-w- c:\windows\system32\msvcr71.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-06-24_16.42.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-24 17:08 . 2009-06-24 17:08 16384 c:\windows\Temp\Perflib_Perfdata_404.dat
+ 2004-08-04 12:00 . 2009-06-24 17:13 41170 c:\windows\system32\perfc009.dat
- 2004-08-04 12:00 . 2009-06-24 13:42 41170 c:\windows\system32\perfc009.dat
+ 2009-06-24 16:43 . 2008-10-16 11:09 51224 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-06-24 16:43 . 2008-04-14 00:12 82432 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-06-24 16:43 . 2008-04-14 00:12 26112 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-06-24 16:43 . 2008-04-14 00:12 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-06-24 16:43 . 2008-04-14 00:12 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-06-24 16:43 . 2008-04-14 00:12 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-06-24 16:43 . 2008-04-14 00:12 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-06-24 16:43 . 2008-04-13 18:39 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-06-24 16:43 . 2008-04-13 18:53 36608 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-06-24 16:43 . 2008-04-14 00:12 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 2004-08-04 12:00 . 2009-06-24 17:13 314842 c:\windows\system32\perfh009.dat
- 2004-08-04 12:00 . 2009-06-24 13:42 314842 c:\windows\system32\perfh009.dat
+ 2009-06-24 16:43 . 2008-04-14 00:12 507904 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-06-24 16:43 . 2009-05-13 05:15 915456 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-06-24 16:43 . 2008-04-14 00:12 578560 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-06-24 16:43 . 2008-04-14 00:12 295424 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-06-24 16:43 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-06-24 16:43 . 2009-02-06 11:11 110592 c:\windows\system32\dllcache\cache\services.exe
+ 2009-06-24 16:43 . 2008-04-13 19:20 182656 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-06-24 16:43 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-06-24 16:43 . 2008-04-14 00:11 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-06-24 16:43 . 2008-04-14 00:11 167936 c:\windows\system32\dllcache\cache\appmgmts.dll
+ 2009-06-24 16:43 . 2008-04-14 00:12 1614848 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-06-24 16:43 . 2009-02-06 11:06 2145280 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-06-24 16:43 . 2009-02-06 10:32 2023936 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-06-24 16:43 . 2008-04-14 00:12 1033728 c:\windows\system32\dllcache\cache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-11 185896]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-05-31 206088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 1634304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 05:29 م 33808]
R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [08/03/2009 10:30 ص 39680]
R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [08/03/2009 10:30 ص 35712]
R2 NishService;SCM Driver Daemon;c:\program files\System Control Manager\edd.exe [08/03/2009 10:38 ص 40960]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 06:02 م 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 05:06 م 24592]
R3 MGHwCtrl;MGHwCtrl;c:\windows\system32\drivers\MGHwCtrl.sys [08/03/2009 10:38 ص 9088]
R3 WSIMD;wsimd Service;c:\windows\system32\drivers\wsimd.sys [08/03/2009 10:34 ص 57024]
S3 PRODIGY;PRODIGY;c:\windows\system32\drivers\prodigy.sys [26/05/2009 05:19 ص 32377]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-05-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: إضافة إلى حاجب إعلان الشعار - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
DPF: {3C8E8DD8-D86A-4E6D-AF37-AB3CA7FDF8CD} - hxxp://skaam.redirectme.net/imscp/talkc38.cab
DPF: {7253A666-804A-1107-A4DC-00E04C504780} - hxxp://208.101.21.192/bmc.cab
DPF: {9E45BE3C-DE06-4492-AB7D-E51447CF2ED0} - hxxp://skaam.redirectme.net/imscp/talka.cab
DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} - hxxp://67.198.202.138/ReadUid.CAB
DPF: {C171FF59-8C55-4796-A398-4F5D02B4C763} - hxxp://76.76.24.112/saudi1999/talks3n.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-24 20:17
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3080)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\PC Connectivity Solution\ConnAPI.DLL
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\MSVCR80.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_ara.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\acs.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\O2Micro Oz128 Driver\o2flash.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\wbem\wmiadap.exe
.
**************************************************************************
.
Completion time: 2009-06-24 20:18 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-24 17:18
ComboFix2.txt 2009-06-24 16:44
Pre-Run: 70,515,945,472 bytes free
Post-Run: 70,504,960,000 bytes free
258 --- E O F --- 2009-06-22 13:44