تفضل عملت كما قلت لي بالظبط
وهاذا التقرير
ComboFix 09-07-09.02 - ابو عزام 07/09/2009 23:13.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.1525.908 [GMT 3:00]
Running from: e:\documents and settings\ابو عزام\سطح المكتب\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - system32: deleted 12 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\documents and settings\ابو عزام\Application Data\addon.dat
e:\documents and settings\ابو عزام\Application Data\addons.dat
e:\documents and settings\ابو ريان\Application Data\addons.dat
e:\program files\bifrost
e:\program files\bifrost\logg.dat
e:\windows\system32\d3d10core.dll
e:\windows\system32\dxgi.dll
e:\windows\system32\kakle.dll
e:\windows\system32\systeminfo.dll
e:\windows\system32\videocore.dll
e:\windows\system32\videoformat.dll
e:\windows\system32\WgaLogon.dll
e:\windows\system32\winitn.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2009-06-09 to 2009-07-09 )))))))))))))))))))))))))))))))
.
2009-07-09 20:20 . 2009-07-09 20:20 53248 ----a-w- e:\temp\catchme.dll
2009-07-09 20:20 . 2009-07-09 20:20 -------- d-----w- e:\temp\WPDNSE
2009-07-09 20:19 . 2009-07-09 20:19 16384 ----atw- e:\temp\Perflib_Perfdata_258.dat
2009-07-09 20:17 . 2009-07-09 20:17 60416 ----a-w- e:\temp\Perflib_Perfdata__755.dat
2009-07-08 22:21 . 2006-06-29 10:07 14048 ------w- e:\windows\system32\spmsg2.dll
2009-07-08 22:18 . 2009-07-08 22:18 251616 ----a-w- e:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-07-08 22:17 . 2009-07-08 22:17 -------- d-----w- e:\windows\system32\XPSViewer
2009-07-08 22:17 . 2009-07-08 22:17 -------- d-----w- e:\program files\MSBuild
2009-07-08 22:17 . 2009-07-08 22:17 -------- d-----w- e:\program files\Reference Assemblies
2009-07-08 22:16 . 2008-07-06 12:06 89088 -c----w- e:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-07-08 22:16 . 2008-07-06 12:06 575488 -c----w- e:\windows\system32\dllcache\xpsshhdr.dll
2009-07-08 22:16 . 2008-07-06 12:06 575488 ------w- e:\windows\system32\xpsshhdr.dll
2009-07-08 22:16 . 2008-07-06 12:06 117760 ------w- e:\windows\system32\prntvpt.dll
2009-07-08 22:16 . 2008-07-06 10:50 597504 -c----w- e:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-07-08 22:16 . 2008-07-06 12:06 1676288 -c----w- e:\windows\system32\dllcache\xpssvcs.dll
2009-07-08 22:16 . 2008-07-06 12:06 1676288 ------w- e:\windows\system32\xpssvcs.dll
2009-07-08 18:29 . 2008-09-16 19:23 168448 ----a-w- e:\windows\system32\unrar.dll
2009-07-08 18:29 . 2004-05-18 18:16 39936 ----a-w- e:\windows\system32\huffyuv.dll
2009-07-08 18:29 . 2004-01-25 16:18 217088 ----a-w- e:\windows\system32\yv12vfw.dll
2009-07-08 18:29 . 2006-04-02 12:47 630784 ----a-w- e:\windows\system32\vp7vfw.dll
2009-07-08 18:29 . 2004-12-10 08:03 438272 ----a-w- e:\windows\system32\vp6vfw.dll
2009-07-08 18:29 . 2009-05-29 21:37 205824 ----a-w- e:\windows\system32\xvidvfw.dll
2009-07-08 18:29 . 2009-05-29 21:31 881664 ----a-w- e:\windows\system32\xvidcore.dll
2009-07-08 18:29 . 2008-11-06 16:37 3596288 ----a-w- e:\windows\system32\qt-dx331.dll
2009-07-08 18:29 . 2009-05-01 21:02 90112 ----a-w- e:\windows\system32\dpl100.dll
2009-07-08 18:29 . 2009-05-01 21:02 685056 ----a-w- e:\windows\system32\divx.dll
2009-07-08 18:29 . 2009-06-02 16:11 85504 ----a-w- e:\windows\system32\ff_vfw.dll
2009-07-07 18:59 . 2009-07-07 18:59 -------- d-sh--r- e:\windows\system32\x.exe
2009-07-07 18:59 . 2009-07-07 18:59 -------- d-sh--r- e:\windows\system32\x
2009-07-07 18:59 . 2009-07-07 18:59 -------- d-sh--r- e:\windows\system32\Winlog.exe
2009-07-07 18:59 . 2009-07-07 18:59 -------- d-sh--r- e:\windows\system32\wdmfmc32.dll
2009-07-07 18:59 . 2009-07-07 18:59 -------- d-sh--r- e:\windows\system32\vcmgcd32.dll
2009-07-07 18:59 . 2009-07-07 18:59 -------- d-sh--r- e:\windows\system32\flcss.exe
2009-07-07 18:59 . 2009-07-07 18:59 -------- d-sh--r- e:\windows\system32\csrsc.exe
2009-07-07 18:59 . 2009-07-07 18:59 -------- d-sh--r- e:\windows\hmn.exe
2009-07-07 18:59 . 2009-07-07 18:59 -------- d-sh--r- e:\windows\dnmee.33.exe
2009-07-07 18:59 . 2009-07-07 18:59 -------- d-----w- e:\windows\system32\o.exe
2009-07-07 18:59 . 2009-07-07 18:59 -------- d-sh--r- e:\windows\flcss.exe
2009-07-07 11:58 . 2009-07-07 12:41 -------- d-----w- e:\documents and settings\ابو عزام\Contacts
2009-07-07 08:52 . 2009-07-07 08:52 35840 ----a-w- e:\documents and settings\ابو عزام\Application Data\Thinstall\KB884016\4000001300002h\ymsgr_tray.exe
2009-07-07 00:00 . 2009-07-07 00:00 -------- d-----w- e:\documents and settings\ابو ريان\Local Settings\Application Data\Mozilla
2009-07-06 23:19 . 2009-07-09 03:47 139936 ----a-w- e:\documents and settings\ابو ريان\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-06 22:02 . 2009-07-06 22:02 367104 ----a-w- e:\windows\system32\autoprnt.exe
2009-07-06 21:14 . 2004-02-26 21:00 962612 ----a-w- e:\windows\system32\MFC42D.DLL
2009-07-06 21:14 . 2004-02-26 21:00 61493 ----a-w- e:\windows\system32\MFCN42D.DLL
2009-07-06 21:14 . 2004-02-16 21:00 434252 ----a-w- e:\windows\system32\MSVCRTD.DLL
2009-07-06 21:14 . 2006-06-23 18:38 192 ----a-w- e:\windows\system32\nmap_performance.reg
2009-07-06 21:14 . 2002-11-20 16:44 77824 ----a-w- e:\windows\system32\nmapwin.exe
2009-07-06 21:14 . 2002-11-20 15:06 290816 ----a-w- e:\windows\system32\nmapserv.exe
2009-07-06 21:14 . 2006-06-23 18:38 452096 ----a-w- e:\windows\system32\nmap.exe
2009-07-06 21:14 . 2001-11-26 21:13 114688 ----a-w- e:\windows\system32\CCGNU32.dll
2009-07-06 21:14 . 2003-03-18 23:03 544768 ----a-w- e:\windows\system32\msvcr71d.dll
2009-07-06 21:13 . 1999-04-16 21:06 10752 ----a-w- e:\windows\system32\aamd532.dll
2009-07-06 21:13 . 2004-03-01 17:55 561179 ----a-w- e:\windows\system32\dao360.dll
2009-07-06 21:13 . 1998-06-17 21:00 299008 ----a-w- e:\windows\system32\MSDBRPTR.DLL
2009-07-06 21:13 . 1998-06-08 21:00 137216 ----a-w- e:\windows\system32\MSDERUN.DLL
2009-07-06 21:13 . 1999-03-26 00:00 101888 ----a-w- e:\windows\system32\VB6STKIT.DLL
2009-07-06 21:13 . 2009-07-06 22:33 -------- d-----w- e:\program files\Net Tools
2009-07-06 16:19 . 2009-07-06 16:19 -------- d-----w- e:\documents and settings\All Users\Application Data\InterVideo
2009-07-06 16:19 . 2007-03-06 08:58 210456 ----a-w- e:\windows\system32\IVIresizeW7.dll
2009-07-06 16:19 . 2007-03-06 08:58 194072 ----a-w- e:\windows\system32\IVIresizePX.dll
2009-07-06 16:19 . 2007-03-06 08:58 198168 ----a-w- e:\windows\system32\IVIresizeP6.dll
2009-07-06 16:19 . 2007-03-06 08:58 198168 ----a-w- e:\windows\system32\IVIresizeM6.dll
2009-07-06 16:19 . 2007-03-06 08:58 206360 ----a-w- e:\windows\system32\IVIresizeA6.dll
2009-07-06 16:19 . 2007-03-06 08:58 26136 ----a-w- e:\windows\system32\IVIresize.dll
2009-07-06 16:18 . 2009-07-06 16:19 -------- d-----w- e:\program files\Common Files\Ulead Systems
2009-07-06 16:18 . 2009-07-06 16:18 -------- d-----w- e:\program files\Ulead Systems
2009-07-06 16:08 . 2009-07-06 16:08 -------- d-----w- e:\documents and settings\ابو عزام\Application Data\Aleo Software
2009-07-06 12:20 . 2009-07-06 13:38 -------- d-----w- e:\windows\SxsCaPendDel
2009-07-06 11:25 . 2009-07-06 11:25 -------- d-----w- e:\windows\USB Vibration
2009-07-06 11:24 . 2009-07-06 11:24 -------- d-----w- e:\program files\USB Vibration Joystick
2009-07-05 19:43 . 2009-07-06 22:01 37888 ----a-w- e:\windows\system32\setupnt.dll
2009-07-05 19:43 . 2009-07-05 19:43 65856 ----a-w- e:\windows\system32\drivers\snapman.sys
2009-07-05 19:43 . 2009-07-05 19:43 102400 ----a-w- e:\windows\system32\snapapi.dll
2009-07-05 19:43 . 2009-07-06 22:01 -------- d-----w- e:\program files\Acronis
2009-07-05 19:43 . 2009-07-05 19:43 -------- d-----w- e:\program files\Common Files\Acronis
2009-07-03 12:41 . 2008-06-27 06:39 332928 ----a-w- e:\windows\system\rtl8187.sys
2009-07-03 05:10 . 2009-07-03 05:10 -------- d-----w- e:\windows\system32\%DataFolder%
2009-07-02 21:01 . 2009-07-02 21:01 -------- d-----w- e:\program files\CreativePainter
2009-07-02 19:03 . 2008-04-14 15:29 363520 -c--a-w- e:\windows\system32\dllcache\psisdecd.dll
2009-07-02 19:03 . 2008-04-14 15:29 363520 ----a-w- e:\windows\system32\psisdecd.dll
2009-07-02 17:49 . 2009-07-02 17:49 -------- d-----w- e:\documents and settings\ابو عزام\Local Settings\Application Data\PowerDVDCox
2009-07-02 17:49 . 2009-07-02 17:49 -------- d-----w- e:\documents and settings\All Users\Application Data\CyberLink
2009-07-02 17:49 . 2009-07-02 17:49 -------- d-----w- e:\documents and settings\ابو عزام\Local Settings\Application Data\PowerDVDCinema
2009-07-02 17:45 . 2009-07-02 17:45 -------- d-----w- e:\documents and settings\ابو عزام\Application Data\CyberLink
2009-07-02 17:43 . 2009-07-02 17:43 -------- d-----w- e:\program files\Common Files\CyberLink
2009-07-02 17:42 . 2009-07-02 17:42 -------- d-----w- e:\program files\CyberLink
2009-07-02 17:41 . 2009-07-02 17:40 29480 ----a-w- e:\windows\system32\msxml3a.dll
2009-07-02 17:41 . 2009-07-02 19:00 53319 ----a-w- e:\documents and settings\All Users\Application Data\TEMP\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe
2009-07-02 13:00 . 2009-07-02 13:00 702976 ----a-w- e:\windows\is-4OK5C.exe
2009-07-02 13:00 . 2009-01-09 09:46 39776 ----a-w- e:\windows\system32\DfSdkBt64.exe
2009-07-02 13:00 . 2009-01-09 09:46 33632 ----a-w- e:\windows\system32\DfSdkBt.exe
2009-07-02 12:15 . 2009-07-02 12:58 -------- d-----w- e:\documents and settings\All Users\Application Data\page
2009-07-02 12:15 . 2009-07-02 12:24 -------- d-----w- e:\program files\Ashampoo
2009-07-02 11:45 . 2009-07-08 21:12 -------- d-----w- e:\program files\K-Lite Codec Pack
2009-07-02 06:16 . 2009-07-02 06:16 -------- d-----w- e:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-07-02 06:01 . 2009-07-02 06:01 76800 ----a-w- e:\documents and settings\ابو عزام\Application Data\Thinstall\CCleaner (remove only)\1000000b00002i\RunDll32.exe
2009-07-02 04:00 . 2009-04-30 21:13 12800 -c----w- e:\windows\system32\dllcache\xpshims.dll
2009-07-02 04:00 . 2009-04-30 21:13 246272 -c----w- e:\windows\system32\dllcache\ieproxy.dll
2009-07-01 13:11 . 2009-07-05 09:06 -------- d-----w- e:\program files\ChickenInvadersROTYXmas
2009-07-01 08:42 . 2009-07-01 08:42 -------- d-----w- e:\windows\Sun
2009-07-01 01:27 . 2008-06-27 06:39 332928 ----a-w- e:\windows\system32\drivers\RTL8187.sys
2009-06-30 16:45 . 2009-06-30 16:45 -------- d-----w- e:\documents and settings\ابو عزام\Application Data\Media Player Classic
2009-06-30 09:00 . 2009-06-30 09:08 -------- d-----w- e:\windows\system32\drivers\UMDF
2009-06-30 09:00 . 2009-06-30 09:00 -------- d-----w- e:\windows\NLDRV
2009-06-30 06:56 . 2009-06-30 06:56 -------- d-----w- e:\documents and settings\ابو عزام\Local Settings\Application Data\TechSmith
2009-06-30 06:55 . 2007-08-24 03:03 159744 ----a-r- e:\windows\system32\igfxres.dll
2009-06-30 06:37 . 2008-04-15 21:00 101376 -c--a-w- e:\windows\system32\dllcache\srusbusd.dll
2009-06-30 06:36 . 2008-04-15 21:00 32256 -c--a-w- e:\windows\system32\dllcache\gzip.dll
2009-06-30 06:35 . 2009-06-30 06:35 -------- d-----w- e:\documents and settings\All Users\Application Data\TechSmith
2009-06-30 06:35 . 2009-06-30 06:35 -------- d-----w- e:\windows\system32\config\systemprofile\Local Settings\Application Data\TechSmith
2009-06-30 06:35 . 2009-07-09 20:21 -------- d-----w- E:\TEMP
2009-06-30 06:35 . 2009-06-30 06:35 -------- d-----w- e:\program files\TechSmith
2009-06-30 06:34 . 2009-06-30 06:34 -------- d-----w- e:\documents and settings\Default User\7zSBC6.tmp
2009-06-30 06:29 . 2009-04-30 21:13 1985024 -c--a-w- e:\windows\system32\dllcache\iertutil.dll
2009-06-30 06:29 . 2009-03-08 01:32 594432 -c--a-w- e:\windows\system32\dllcache\msfeeds.dll
2009-06-30 06:29 . 2009-03-08 01:31 55296 -c--a-w- e:\windows\system32\dllcache\msfeedsbs.dll
2009-06-30 06:29 . 2008-06-23 09:20 13824 -c----w- e:\windows\system32\dllcache\ieudinit.exe
2009-06-30 06:29 . 2009-02-06 18:07 3698584 -c--a-w- e:\windows\system32\dllcache\ieapfltr.dat
2009-06-30 06:29 . 2009-04-30 21:13 11064832 -c--a-w- e:\windows\system32\dllcache\ieframe.dll
2009-06-30 06:29 . 2009-03-08 01:31 59904 -c--a-w- e:\windows\system32\dllcache\icardie.dll
2009-06-30 06:29 . 2009-03-08 01:11 445952 -c--a-w- e:\windows\system32\dllcache\ieapfltr.dll
2009-06-30 06:28 . 2008-04-15 21:00 221184 ----a-w- e:\windows\system32\wmpns.dll
2009-06-30 06:26 . 2008-04-15 21:00 23552 -c--a-w- e:\windows\system32\dllcache\mssoapr.dll
2009-06-30 06:26 . 2008-04-15 21:00 16384 -c--a-w- e:\windows\system32\dllcache\isignup.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-09 20:21 . 2009-06-15 08:02 18296352 --sha-w- e:\windows\system32\drivers\fidbox.dat
2009-07-09 20:20 . 2009-06-15 08:02 1124896 --sha-w- e:\windows\system32\drivers\fidbox2.dat
2009-07-09 20:18 . 2009-06-15 08:02 257504 --sha-w- e:\windows\system32\drivers\fidbox.idx
2009-07-09 20:18 . 2009-06-15 08:02 114812 --sha-w- e:\windows\system32\drivers\fidbox2.idx
2009-07-09 20:14 . 2001-09-19 12:00 65206 ----a-w- e:\windows\system32\perfc001.dat
2009-07-09 20:14 . 2001-09-19 12:00 361718 ----a-w- e:\windows\system32\perfh001.dat
2009-07-09 20:10 . 2009-06-15 08:02 -------- d-----w- e:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-07-09 20:03 . 2009-07-09 20:03 -------- d-----w- e:\documents and settings\ابو عزام\Application Data\CyberScrub
2009-07-09 20:03 . 2009-07-09 20:03 -------- d-----w- e:\documents and settings\ابو عزام\Application Data\cleaner
2009-07-09 12:35 . 2009-07-01 11:25 403968 ----a-w- e:\windows\system32\ALOWMAFile2.dll
2009-07-07 09:40 . 2009-06-15 07:59 -------- d-----w- e:\program files\Circle Dvelopement
2009-07-06 16:17 . 2009-06-15 07:36 -------- d--h--w- e:\program files\InstallShield Installation Information
2009-07-03 12:41 . 2009-06-15 07:36 -------- d-----w- e:\program files\Realtek
2009-07-02 17:40 . 2009-06-15 08:06 505128 ----a-w- e:\windows\system32\msvcp71.dll
2009-07-02 17:40 . 2009-06-15 08:06 353576 ----a-w- e:\windows\system32\msvcr71.dll
2009-07-01 11:25 . 2009-07-01 11:25 344064 ----a-w- e:\windows\system32\dkll.dll
2009-07-01 11:25 . 2009-07-01 11:25 196608 ----a-w- e:\windows\system32\maag.dll
2009-07-01 11:25 . 2009-07-01 11:25 1212416 ----a-w- e:\windows\system32\ckll.dll
2009-07-01 11:25 . 2009-07-01 11:25 1986560 ----a-w- e:\windows\system32\akll.dll
2009-06-30 06:23 . 2009-06-15 07:17 23380 ----a-w- e:\windows\system32\emptyregdb.dat
2009-06-27 08:47 . 2009-06-17 08:19 -------- d-----w- e:\documents and settings\ابو عزام\Application Data\TeamViewer
2009-06-19 00:16 . 2009-06-17 08:46 -------- d-----w- e:\program files\DynDNS Updater
2009-06-18 01:26 . 2009-06-15 07:32 16608 ----a-w- e:\windows\gdrv.sys
2009-06-17 21:29 . 2009-06-17 21:29 1078 ----a-r- e:\documents and settings\ابو عزام\Application Data\Microsoft\Installer\{26A373DB-162B-4B6E-A488-0BED0F0FB227}\_2cd672ae.exe
2009-06-17 21:29 . 2009-06-17 21:29 1078 ----a-r- e:\documents and settings\ابو عزام\Application Data\Microsoft\Installer\{26A373DB-162B-4B6E-A488-0BED0F0FB227}\_294823.exe
2009-06-17 21:29 . 2009-06-17 21:29 1078 ----a-r- e:\documents and settings\ابو عزام\Application Data\Microsoft\Installer\{26A373DB-162B-4B6E-A488-0BED0F0FB227}\_26e91eb.exe
2009-06-17 21:29 . 2009-06-17 21:29 1078 ----a-r- e:\documents and settings\ابو عزام\Application Data\Microsoft\Installer\{26A373DB-162B-4B6E-A488-0BED0F0FB227}\_18be6784.exe
2009-06-17 21:29 . 2009-06-17 21:29 1078 ----a-r- e:\documents and settings\ابو عزام\Application Data\Microsoft\Installer\{26A373DB-162B-4B6E-A488-0BED0F0FB227}\_16496df1.exe
2009-06-17 21:29 . 2009-06-17 06:28 -------- d-----w- e:\program files\BreakPoint Software
2009-06-17 08:47 . 2009-06-17 08:47 -------- d-----w- e:\documents and settings\ابو عزام\Application Data\Kana Solution
2009-06-17 06:59 . 2009-06-17 06:59 -------- d-----w- e:\program files\No-IP
2009-06-16 16:24 . 2009-06-15 07:43 -------- d-----w- e:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-15 23:32 . 2009-06-15 23:32 2478 ----a-w- e:\program files\Common Files\unins000.dat
2009-06-15 23:32 . 2009-06-15 23:32 728858 ----a-w- e:\program files\Common Files\unins000.exe
2009-06-15 20:54 . 2009-06-15 07:20 86327 ----a-w- e:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-15 19:39 . 2007-04-28 13:51 112144 ----a-w- e:\windows\system32\drivers\kl1.sys
2009-06-15 19:39 . 2009-06-15 08:02 94643 ----a-w- e:\windows\system32\drivers\klick.dat
2009-06-15 19:39 . 2009-06-15 08:02 105395 ----a-w- e:\windows\system32\drivers\klin.dat
2009-06-15 08:07 . 2009-06-15 08:06 -------- d-----w- e:\program files\Common Files\Adobe
2009-06-15 08:06 . 2009-06-15 08:06 -------- d-----w- e:\program files\Common Files\xing shared
2009-06-15 08:06 . 2009-06-15 08:06 -------- d-----w- e:\program files\Common Files\Real
2009-06-15 08:06 . 2009-06-15 08:06 -------- d-----w- e:\program files\Real
2009-06-15 08:04 . 2009-06-15 08:04 2232 ----a-w- e:\windows\java\Packages\Data\V5ZXRPJ3.DAT
2009-06-15 08:04 . 2009-06-15 08:04 155995 ----a-w- e:\windows\java\Packages\MMHJJPR3.ZIP
2009-06-15 08:04 . 2009-06-15 08:04 2678 ----a-w- e:\windows\java\Packages\Data\PJ3PZ7ZV.DAT
2009-06-15 08:04 . 2009-06-15 08:04 2678 ----a-w- e:\windows\java\Packages\Data\O3VJBDFZ.DAT
2009-06-15 08:04 . 2009-06-15 08:04 2678 ----a-w- e:\windows\java\Packages\Data\P73PFRDN.DAT
2009-06-15 08:04 . 2009-06-15 08:04 2678 ----a-w- e:\windows\java\Packages\Data\JF3ZPV13.DAT
2009-06-15 08:04 . 2009-06-15 08:04 2678 ----a-w- e:\windows\java\Packages\Data\GQUA2HB1.DAT
2009-06-15 08:02 . 2009-06-15 08:02 -------- d-----w- e:\program files\Kaspersky Lab
2009-06-15 08:01 . 2009-06-15 07:59 -------- d-----w- e:\program files\MSN Messenger
2009-06-15 08:00 . 2009-06-15 08:00 -------- d-----w- e:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-06-15 07:59 . 2009-06-15 07:36 -------- d-----w- e:\program files\Common Files\InstallShield
2009-06-15 07:59 . 2009-06-15 07:59 -------- d-----w- e:\program files\Messenger Plus! Live
2009-06-15 07:59 . 2009-06-15 07:59 -------- d-----w- e:\program files\Windows Live
2009-06-15 07:48 . 2009-06-15 07:48 -------- d-----w- e:\program files\Microsoft Works
2009-06-15 07:36 . 2009-06-15 07:36 315392 ----a-w- e:\windows\HideWin.exe
2009-06-15 07:21 . 2009-06-15 07:21 -------- d-----w- e:\program files\microsoft frontpage
2009-06-06 23:12 . 2009-06-06 23:12 1571328 ----a-w- e:\windows\system32\sfcfiles.dll
2009-05-31 06:46 . 2001-09-18 11:06 77891 ----a-w- e:\windows\system32\usrmlnka.exe
2009-05-31 06:17 . 2009-05-31 06:17 938496 ----a-w- e:\windows\system32\wmnetmgr.dll
2009-05-31 06:17 . 2009-05-31 06:17 100864 ----a-w- e:\windows\system32\logagent.exe
2009-05-31 06:16 . 2009-05-31 06:16 1286144 ----a-w- e:\windows\system32\quartz.dll
2009-05-31 06:16 . 2009-05-31 06:16 354304 ----a-w- e:\windows\system32\winhttp.dll
2009-05-31 06:16 . 2009-05-31 06:16 144896 ----a-w- e:\windows\system32\schannel.dll
2009-05-31 06:16 . 2009-05-31 06:16 56832 ----a-w- e:\windows\system32\secur32.dll
2009-05-31 06:15 . 2009-05-31 06:15 333952 ----a-w- e:\windows\system32\drivers\srv.sys
2009-05-31 06:15 . 2009-05-31 06:15 455936 ----a-w- e:\windows\system32\drivers\mrxsmb.sys
2009-05-31 06:15 . 2009-05-31 06:15 138496 ----a-w- e:\windows\system32\drivers\afd.sys
2009-05-31 06:15 . 2009-05-31 06:15 286720 ----a-w- e:\windows\system32\gdi32.dll
2009-05-31 06:15 . 2009-06-15 07:16 227840 ----a-w- e:\windows\system32\wbem\wmiprvse.exe
2009-05-31 06:15 . 2009-06-15 07:16 453120 ----a-w- e:\windows\system32\wbem\wmiprvsd.dll
2009-05-31 06:15 . 2009-05-31 06:15 35328 ----a-w- e:\windows\system32\sc.exe
2009-05-31 06:15 . 2009-05-31 06:15 110592 ----a-w- e:\windows\system32\services.exe
2009-05-31 06:15 . 2009-05-31 06:15 401408 ----a-w- e:\windows\system32\rpcss.dll
2009-05-31 06:15 . 2009-05-31 06:15 283136 ----a-w- e:\windows\system32\pdh.dll
2009-05-31 06:15 . 2009-05-31 06:15 2146816 ----a-w- e:\windows\system32\ntoskrnl.exe
2009-05-31 06:14 . 2009-05-31 06:14 723456 ----a-w- e:\windows\system32\lsasrv.dll
2009-05-31 06:14 . 2009-06-15 07:16 473600 ----a-w- e:\windows\system32\wbem\fastprox.dll
2009-05-31 06:14 . 2009-05-31 06:14 681472 ----a-w- e:\windows\system32\advapi32.dll
2009-05-31 06:14 . 2009-05-31 06:14 1106944 ----a-w- e:\windows\system32\msxml3.dll
2009-05-31 06:14 . 2009-05-31 06:14 247326 ----a-w- e:\windows\system32\strmdll.dll
2009-05-31 06:14 . 2009-05-31 06:14 1379840 ----a-w- e:\windows\system32\msxml6.dll
2009-05-31 06:14 . 2009-05-31 06:14 104960 ----a-w- e:\windows\system32\win32spl.dll
2009-05-31 06:14 . 2009-05-31 06:14 74752 ----a-w- e:\windows\system32\msw3prt.dll
2009-05-31 06:14 . 2009-05-31 06:14 74240 ----a-w- e:\windows\system32\mscms.dll
2009-05-31 06:13 . 2009-06-15 07:16 91648 ----a-w- e:\windows\system32\mtxoci.dll
2009-05-31 06:13 . 2009-06-15 07:16 161792 ----a-w- e:\windows\system32\msdtcuiu.dll
2009-05-31 06:13 . 2009-05-31 06:13 66560 ----a-w- e:\windows\system32\mtxclu.dll
2009-05-31 06:13 . 2009-06-15 07:16 956928 ----a-w- e:\windows\system32\msdtctm.dll
2009-05-31 06:13 . 2009-06-15 07:16 428032 ----a-w- e:\windows\system32\msdtcprx.dll
2009-05-31 06:13 . 2009-06-15 07:16 58880 ----a-w- e:\windows\system32\msdtclog.dll
2009-05-31 06:13 . 2009-05-31 06:13 225856 ----a-w- e:\windows\system32\drivers\tcpip6.sys
2009-05-31 06:13 . 2009-05-31 06:13 361600 ----a-w- e:\windows\system32\drivers\tcpip.sys
2009-05-31 06:13 . 2009-05-31 06:13 245248 ----a-w- e:\windows\system32\mswsock.dll
2009-05-31 06:13 . 2009-05-31 06:13 271616 ----a-w- e:\windows\system32\drivers\bthport.sys
2009-05-31 06:11 . 2009-06-15 07:18 691712 ----a-w- e:\windows\system32\inetcomm.dll
2009-05-31 06:11 . 2009-05-31 06:11 253952 ----a-w- e:\windows\system32\es.dll
2009-05-31 06:11 . 2009-05-31 06:11 203136 ----a-w- e:\windows\system32\drivers\RMCast.sys
2009-05-13 05:02 . 2008-06-23 22:15 915456 ----a-w- e:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="e:\windows\system32\ctfmon.exe" [2008-04-15 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="e:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-15 185896]
"AVP"="e:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 218376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" - e:\windows\system32\advpack.dll [2009-03-08 128512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoFileAssociate"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ComPlusSetup]
2008-04-15 21:00 625664 ----a-w- e:\windows\system32\catsrvut.dll
[HKLM\~\startupfolder\E:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^REALTEK RTL8187 Wireless LAN Utility.lnk]
path=e:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\REALTEK RTL8187 Wireless LAN Utility.lnk
backup=e:\windows\pss\REALTEK RTL8187 Wireless LAN Utility.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gupdate1c9f670a2dd145c"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"e:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\Program Files\\Valve\\hl.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"d:\\تــثـــــــــــبــتــات\\تـثـبـيـتـات البرامج\\برامج لا تحتاج الى تنصيب محموله\\TeamViewer.exe"=
"d:\\تــثـــــــــــبــتــات\\تـثـبـيـتـات الاعاب\\Counter Strike\\كونتر سورس\\Counter-Strike Source PORTABLE\\hl2.exe"=
"d:\\تــثـــــــــــبــتــات\\تـثـبـيـتـات الاعاب\\لعبة هجوله L.F.S\\LFS_S2_ALPHA_X\\LFS.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP

eer Name Resolution Protocol (PNRP)
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 ulsata2;ulsata2;e:\windows\system32\drivers\ulsata2.sys [18/09/2008 05:42 ص 124928]
R2 EAPPkt;Realtek EAPPkt Protocol;e:\windows\system32\drivers\EAPPkt.sys [21/06/2009 02:59 ص 38144]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;e:\windows\system32\drivers\klim5.sys [04/04/2007 02:58 م 24344]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;e:\windows\system32\drivers\RTL8187.sys [01/07/2009 04:27 ص 332928]
S3 DfSdkS;Defragmentation-Service;e:\program files\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe [02/07/2009 04:00 م 410976]
S3 NPF;NetGroup Packet Filter Driver;e:\windows\system32\drivers\npf.sys [21/06/2007 11:55 م 42512]
S3 PEEK5;PEEK5 Protocol Driver;\??\c:\تــثـــــــــــبــتــات\تـثـبـيـتـات البرامج\برامج وادوات وطرق تهكير\برامج وطرق اختراق الشبكات\الطريقة الثانية لختراق الشبكات\aircrack-ng-0.9.1-win\aircrack-ng-win-0.9.1\bin\PEEK5.SYS --> c:\تــثـــــــــــبــتــات\تـثـبـيـتـات البرامج\برامج وادوات وطرق تهكير\برامج وطرق اختراق الشبكات\الطريقة الثانية لختراق الشبكات\aircrack-ng-0.9.1-win\aircrack-ng-win-0.9.1\bin\PEEK5.SYS [?]
S3 RAPIProtocol;Ralink RAPI Protocol Driver;e:\windows\system32\drivers\RAPIProtocol.sys [21/06/2009 01:35 م 16512]
S3 SjyPkt;SjyPkt;\??\e:\windows\System32\Drivers\SjyPkt.sys --> e:\windows\System32\Drivers\SjyPkt.sys [?]
S4 gupdate1c9f670a2dd145c;Google Update Service (gupdate1c9f670a2dd145c);e:\program files\Google\Update\GoogleUpdate.exe [26/06/2009 06:13 م 133104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"e:\windows\system32\rundll32.exe" "e:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-02 e:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- e:\program files\Google\Update\GoogleUpdate.exe [2009-06-26 15:13]
2009-07-08 e:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- e:\program files\Google\Update\GoogleUpdate.exe [2009-06-26 15:13]
2009-06-30 e:\windows\Tasks\OGADaily.job
- e:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-06-30 e:\windows\Tasks\OGALogon.job
- e:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-07-08 e:\windows\Tasks\User_Feed_Synchronization-{56BC1D4C-B19A-4653-A02A-66C3841AADE3}.job
- e:\windows\system32\msfeedssync.exe [2008-09-18 01:31]
2009-07-08 e:\windows\Tasks\User_Feed_Synchronization-{89392DF3-B50B-4B26-8031-EF3F25276EA3}.job
- e:\windows\system32\msfeedssync.exe [2008-09-18 01:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: تحميل الكل بواسطة Internet Download Manager - e:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - e:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - e:\program files\Internet Download Manager\IEGetVL.htm
IE: { - e:\program files\Messenger\msmsgs.exe
LSP: e:\windows\system32\idmmbc.dll
DPF: Microsoft XML Parser for Java
FF - ProfilePath - e:\documents and settings\ابو عزام\Application Data\Mozilla\Firefox\Profiles\cskxagy1.default\
FF - prefs.js: browser.startup.homepage -
FF - component: e:\documents and settings\ابو عزام\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - component: e:\documents and settings\ابو عزام\Application Data\Mozilla\Firefox\Profiles\cskxagy1.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: e:\program files\Google\Google Gears\Firefox\components\gears.dll
FF - plugin: e:\documents and settings\All Users\Application Data\NexonEU\NGM\npNxGameeu.dll
FF - plugin: e:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
FF - user.js: browser.blink_allowed - true
FF - user.js: network.prefetch-next - true
FF - user.js: layout.spellcheckDefault - 2
FF - user.js: browser.urlbar.autoFill - true
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.urlbar.hideGoButton - false
.
.
------- File Associations -------
.
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-09 23:20
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1123561945-287218729-1801674531-1005_Classes\CLSID\{CF614386-2529-7040-AEC6-82A7191EF47E}\InprocServer32]
@Denied: (A 4) (Everyone)
[HKEY_USERS\S-1-5-21-1123561945-287218729-1801674531-1005_Classes\CLSID\{CF614386-2529-7040-AEC6-82A7191EF47E}\InprocServer32\Misc]
"95430919"=hex:f4,6c,19,7d,6d,b4,14,63,2e,01,2f,bd,dc,5a,dd,75,98,16,c7,ad,ff,
c9,01,0b,88,0e,60,a9,20,5b,0f,ca,de,98,5f,77,3e,e8,60,66,0e,f4,41,3f,28,1e,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1332)
e:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
e:\windows\system32\msi.dll
e:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(1396)
e:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
e:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
e:\windows\system32\idmmbc.dll
- - - - - - - > 'explorer.exe'(3684)
e:\windows\system32\WININET.dll
e:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
e:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll
e:\progra~1\WINDOW~2\wmpband.dll
e:\windows\system32\msi.dll
e:\windows\system32\ieframe.dll
e:\windows\system32\webcheck.dll
e:\windows\system32\wpdshserviceobj.dll
e:\windows\system32\portabledevicetypes.dll
e:\windows\system32\portabledeviceapi.dll
.
------------------------ Other Running Processes ------------------------
.
e:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
e:\program files\Hotspot Shield\bin\openvpnas.exe
e:\program files\Java\jre6\bin\jqs.exe
e:\windows\system32\tcpsvcs.exe
e:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
e:\windows\system32\wbem\wmiadap.exe
.
**************************************************************************
.
Completion time: 2009-07-09 23:25 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-09 20:24
Pre-Run: 23,061,491,712 bytes free
Post-Run: 22,987,866,112 bytes free
428 --- E O F --- 2009-07-06 18:07