هذا الي طلعلي
ComboFix 09-07-09.08 - أسامة الحربي 07/12/2009 0:58.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1256.966.1033.18.3061.1929 [GMT 3:00]
Running from: c:\users\أسامة الحربي\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Kaspersky Internet Security *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2331656841-495014813-4142818907-500
c:\$recycle.bin\S-1-5-21-918531171-1958856377-3773996760-500
c:\program files\RelevantKnowledge
c:\program files\RelevantKnowledge\rloci.bin
c:\program files\RelevantKnowledge\rlservice.exe
c:\windows\Installer\64053.msi
c:\windows\system32\KBL.LOG
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_RelevantKnowledge
((((((((((((((((((((((((( Files Created from 2009-06-11 to 2009-07-11 )))))))))))))))))))))))))))))))
.
2009-07-10 06:17 . 2009-07-10 06:17 -------- d-----w- c:\program files\Common Files\Skype
2009-07-10 06:17 . 2009-07-10 06:17 -------- d-----r- c:\program files\Skype
2009-07-10 01:42 . 2009-07-10 01:42 385024 ----a-w- c:\programdata\Bodybitsdata\Draw One Date Media.exe
2009-07-10 01:42 . 2009-07-11 22:10 765952 ----a-w- c:\programdata\comp two long internet\01 Keep.exe
2009-07-10 01:42 . 2009-07-10 01:42 -------- d-----w- c:\programdata\comp two long internet
2009-07-10 01:41 . 2009-07-10 01:41 765952 ----a-w- c:\programdata\Bodybitsdata\icgcavfp.exe
2009-07-10 01:41 . 2009-07-10 01:42 -------- d-----w- c:\programdata\Bodybitsdata
2009-07-10 01:41 . 2009-07-10 01:40 548864 ----a-w- c:\programdata\Bodybitsdata\Bore The Rdr.exe
2009-07-09 23:18 . 2009-07-09 23:19 -------- d-----w- C:\OutputFolder
2009-07-09 22:53 . 2009-07-09 22:53 -------- d-----w- c:\program files\Common Files\PCSuite
2009-07-09 22:53 . 2009-07-09 22:53 -------- d-----w- c:\program files\Common Files\Nokia
2009-07-09 22:52 . 2009-07-09 22:49 34008688 ----a-w- c:\programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_ara.exe
2009-07-09 22:51 . 2009-07-09 22:51 95232 ----a-w- c:\programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-07-09 22:51 . 2009-07-09 22:51 8192 ----a-w- c:\programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-07-09 22:51 . 2009-07-09 22:51 61440 ----a-w- c:\programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-07-09 22:51 . 2009-07-09 22:51 10240 ----a-w- c:\programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-07-09 21:48 . 2009-07-09 21:48 7680 ----a-w- c:\users\أسامة الحربي\AppData\Roaming\Thinstall\BvT Live Tv 3.0\4000002e00002i\BvtUtility.exe
2009-07-09 21:48 . 2009-07-09 21:48 7680 ----a-w- c:\users\أسامة الحربي\AppData\Roaming\Thinstall\BvT Live Tv 3.0\4000008000002i\Splash Screen.exe
2009-07-09 21:47 . 2009-07-09 21:47 -------- d-----w- c:\users\أسامة الحربي\AppData\Roaming\Thinstall
2009-07-09 21:47 . 2009-07-09 21:47 -------- d-----w- c:\users\أسامة الحربي\AppData\Local\Thinstall
2009-07-04 23:42 . 2009-07-04 23:42 -------- d-----w- c:\program files\Common Files\COWON
2009-07-04 23:42 . 2009-07-04 23:42 -------- d-----w- c:\program files\JetAudio
2009-07-02 23:46 . 2009-07-02 23:48 -------- d-----w- c:\program files\Fake Webcam
2009-07-02 14:37 . 2009-07-02 14:37 -------- d-----w- c:\users\أسامة الحربي\AppData\Roaming\Media Player Classic
2009-07-02 12:37 . 2009-07-02 12:38 -------- d-----w- c:\program files\URUSoft
2009-06-24 11:02 . 2009-06-24 11:03 -------- d-----w- c:\users\أسامة الحربي\AppData\Roaming\ooVoo Details
2009-06-24 11:02 . 2009-06-24 11:02 -------- d-----w- c:\programdata\EmailNotifier
2009-06-21 21:06 . 2009-06-21 21:06 -------- d-----w- c:\program files\Freewire
2009-06-18 12:20 . 2008-08-26 07:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-06-18 12:20 . 2009-06-18 12:20 -------- d-----w- c:\program files\PC Connectivity Solution
2009-06-18 12:14 . 2009-06-18 12:12 33856936 ----a-w- c:\programdata\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Nokia_PC_Suite_7_1_30_8_ara.exe
2009-06-18 12:14 . 2009-06-18 12:14 95232 ----a-w- c:\programdata\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\pcswpcsi.exe
2009-06-18 12:14 . 2009-06-18 12:14 8192 ----a-w- c:\programdata\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstCCD.exe
2009-06-18 12:14 . 2009-06-18 12:14 61440 ----a-w- c:\programdata\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-06-18 12:14 . 2009-06-18 12:14 10240 ----a-w- c:\programdata\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstPCS.exe
2009-06-17 19:04 . 2009-06-17 19:04 -------- d-----w- c:\users\أسامة الحربي\AppData\Local\TVU Networks
2009-06-17 19:04 . 2009-06-17 19:04 -------- d-----w- c:\programdata\TVU Networks
2009-06-17 11:59 . 2009-06-17 11:59 -------- d-----w- c:\program files\Common Files\xing shared
2009-06-15 06:38 . 2009-06-15 10:31 -------- d-----w- c:\program files\aod
2009-06-12 21:50 . 2009-06-12 21:50 456304 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb7041.tmp.exe
2009-06-12 04:43 . 2009-06-12 04:43 -------- d-----w- c:\program files\Easiestutils
2009-06-12 04:30 . 2009-06-12 04:30 81920 ----a-w- c:\users\أسامة الحربي\AppData\Roaming\ezpinst.exe
2009-06-12 04:30 . 2009-06-12 04:30 47360 ----a-w- c:\users\أسامة الحربي\AppData\Roaming\pcouffin.sys
2009-06-12 04:30 . 2009-06-12 04:31 -------- d-----w- c:\users\أسامة الحربي\AppData\Roaming\Vso
2009-06-12 04:00 . 2009-06-12 04:00 -------- d-----w- C:\Mp3 Output
2009-06-12 04:00 . 2007-02-25 12:36 383238 ----a-w- c:\windows\system32\libmp3lame-0.dll
2009-06-11 22:33 . 2009-06-11 22:33 -------- d-----w- c:\users\أسامة الحربي\AppData\Local\TubeTilla
2009-06-11 22:32 . 2009-06-11 22:32 -------- d-----w- c:\program files\TubeTilla
2009-06-11 22:26 . 2009-07-09 21:00 -------- d-----w- c:\program files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-11 22:12 . 2009-06-11 21:13 -------- d-----w- c:\users\أسامة الحربي\AppData\Roaming\Skype
2009-07-11 22:11 . 2009-06-11 21:16 -------- d-----w- c:\users\أسامة الحربي\AppData\Roaming\skypePM
2009-07-11 22:11 . 2008-11-15 10:39 -------- d-----w- c:\programdata\Kaspersky Lab
2009-07-11 22:07 . 2008-11-15 10:39 6160928 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-11 22:07 . 2008-11-15 10:39 50260 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-11 22:07 . 2008-11-15 10:39 4916 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-07-11 22:07 . 2008-11-15 10:39 1122336 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-07-11 22:07 . 2008-12-16 17:26 5332 ----a-w- c:\windows\bthservsdp.dat
2009-07-10 06:17 . 2009-06-11 21:12 -------- d-----w- c:\programdata\Skype
2009-07-10 01:43 . 2008-12-04 22:39 -------- d-----w- c:\program files\Windows Live
2009-07-10 01:40 . 2008-12-04 22:39 -------- d-----w- c:\program files\Circle Developement
2009-07-10 01:40 . 2008-12-04 22:39 -------- d-----w- c:\program files\Messenger Plus! Live
2009-07-09 22:52 . 2009-02-21 15:34 -------- d-----w- c:\programdata\Installations
2009-07-06 23:09 . 2009-01-16 14:39 680 ----a-w- c:\users\أسامة الحربي\AppData\Local\d3d9caps.dat
2009-07-06 19:32 . 2009-03-27 22:33 -------- d-----w- c:\programdata\Microsoft Help
2009-07-05 18:24 . 2008-11-16 11:13 -------- d-----w- c:\users\أسامة الحربي\AppData\Roaming\COWON
2009-07-04 23:42 . 2008-03-06 09:01 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-22 08:07 . 2008-11-15 09:36 123568 ----a-w- c:\users\أسامة الحربي\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-18 12:22 . 2009-04-20 14:43 -------- d-----w- c:\program files\Nokia
2009-06-18 12:20 . 2009-02-21 15:38 -------- d-----w- c:\program files\DIFX
2009-06-17 11:59 . 2008-11-24 18:11 -------- d-----w- c:\program files\Common Files\Real
2009-06-15 10:30 . 2008-11-24 18:11 -------- d-----w- c:\program files\Real
2009-06-11 21:16 . 2009-06-11 21:16 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-06-11 16:44 . 2009-06-11 16:44 456304 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbB720.tmp.exe
2009-06-11 00:09 . 2008-03-06 09:32 -------- d-----w- c:\program files\Microsoft Works
2009-06-06 20:14 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-06-06 20:14 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-06-06 20:14 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-06-06 20:14 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2009-06-06 20:14 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-06-06 20:14 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2009-06-06 20:13 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-06-06 19:51 . 2009-06-04 18:03 -------- d-----w- c:\program files\MyVideoConverter
2009-06-05 13:57 . 2009-06-05 13:56 -------- d-----w- c:\program files\Ask Search Assistant
2009-05-29 15:55 . 2009-05-29 15:55 -------- d-----w- c:\program files\HooTech
2009-05-26 20:58 . 2009-05-26 20:55 -------- d-----w- c:\program files\AV Vcs 7.0
2009-05-20 20:06 . 2008-11-15 10:39 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-20 20:06 . 2008-11-15 10:39 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-09 05:50 . 2009-06-10 12:53 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-10 12:53 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-04-26 10:13 . 2009-03-26 15:11 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2009-04-23 12:15 . 2009-06-10 12:53 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:14 . 2009-06-10 12:53 623616 ----a-w- c:\windows\system32\localspl.dll
2009-04-21 11:39 . 2009-06-10 12:53 2034688 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Loud Gram"="c:\programdata\boltuseruser.j8h69z2" [X]
"Long Internet Team Stupid"="c:\programdata\Save Inside Film.uy9i0b5" [X]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"CollaborationHost"="c:\windows\system32\p2phost.exe" [2008-01-21 192000]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-05 39408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-06-26 25604904]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-08-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-08-28 154136]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-08-28 137752]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-06-30 159744]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-12-20 468264]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-12-06 202032]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-09-13 222504]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-10-03 480560]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-15 136600]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-10 201992]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"Flashget"="c:\program files\FlashGet\FlashGet.exe" [2007-09-25 2007088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-17 198160]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Snagit 9.lnk - c:\program files\TechSmith\Snagit 9\Snagit32.exe [2009-1-22 7225672]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll c:\progra~1\KASPER~1\KASPER~1\adialhk.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):23,f4,61,44,e4,e6,c9,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C1AF4571-704D-4276-A86A-E048884E805C}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{500F29D7-F117-4D49-ABD4-B392F6221F6D}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{DDEC682C-B37A-4F28-B9CF-7504D8EC17DE}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{73C7A8F8-130D-490B-9F99-49EECA207461}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{7F5C8250-51FD-46A0-A185-0E5FC8AD8E27}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{8AC9C1C0-6B7A-4470-8CA8-8B04A290EC86}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{06665FCB-F8F9-4A9B-8856-2C45E59AC213}c:\\program files\\flashget\\flashget.exe"= UDP:c:\program files\flashget\flashget.exe:Flashget
"UDP Query User{355A1E4F-A682-41B7-A0C7-C1747A351215}c:\\program files\\flashget\\flashget.exe"= TCP:c:\program files\flashget\flashget.exe:Flashget
"TCP Query User{B83C9770-DB85-4C43-8C60-E9EB13F27F01}c:\\program files\\java\\jre1.6.0_02\\bin\\javaw.exe"= UDP:c:\program files\java\jre1.6.0_02\bin\javaw.exe:Java(TM) Platform SE binary
"UDP Query User{698056F9-D497-402E-8EE6-B9457E64C5E1}c:\\program files\\java\\jre1.6.0_02\\bin\\javaw.exe"= TCP:c:\program files\java\jre1.6.0_02\bin\javaw.exe:Java(TM) Platform SE binary
"{4420FA56-DF17-46A3-98FD-A63CD39F7ED2}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{D53E164C-CE70-41CB-BF6B-6DBC7579DEE8}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{65BA4A6A-BBD9-460D-A1FC-6AFD50F042AB}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{665195D8-486C-469D-8C99-440B22447607}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"UDP Query User{653B1DF9-F090-4E08-9095-4D0DE6D5D80F}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"TCP Query User{7EA19FDA-2953-4C00-BAA5-1D23BEBB3E80}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{8C171C13-7220-4DDF-97D6-7F1F938F8EC3}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"{D33475FF-11D6-40C1-91DC-6C1ADCBDDB87}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{21D9F85F-3FB4-4E46-AAD0-16F774AC755B}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{48922580-0D32-4907-83A2-EE7C0B6F1C25}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{0464DFB9-EF6A-4FDF-9C24-D613CBE1CC17}c:\\program files\\freewire\\freewire television\\freewire television.exe"= Disabled:UDP:c:\program files\freewire\freewire television\freewire television.exe:Freewire Television
"UDP Query User{386704E5-CF0A-4708-BA1E-7A59258DA1ED}c:\\program files\\freewire\\freewire television\\freewire television.exe"= Disabled:TCP:c:\program files\freewire\freewire television\freewire television.exe:Freewire Television
"TCP Query User{E4E2D51E-1611-40FD-893B-EA9BF0B6E7AF}c:\\program files\\java\\jre6\\bin\\javaw.exe"= UDP:c:\program files\java\jre6\bin\javaw.exe:Java(TM) Platform SE binary
"UDP Query User{A52A5C5E-52D0-47D6-BB14-EBAA9F447F50}c:\\program files\\java\\jre6\\bin\\javaw.exe"= TCP:c:\program files\java\jre6\bin\javaw.exe:Java(TM) Platform SE binary
"{1817A72A-030C-46B2-B441-F2E36957E1EE}"= Disabled:UDP:443

oVoo TCP المنفذ 443
"{365C8A40-7132-4BEB-8DE1-4739E11D6257}"= Disabled:TCP:443

oVoo UDP المنفذ 443
"{E463A5EF-E9F7-46B6-B6E1-E1A94D542426}"= Disabled:UDP:37674

oVoo TCP المنفذ 37674
"{0087AAC1-A137-421C-8BE5-DB73B6DB90D7}"= Disabled:TCP:37674

oVoo UDP المنفذ 37674
"{3FAA45C9-9EC3-448B-A0E1-E70D553BBB24}"= Disabled:TCP:37675

oVoo UDP المنفذ 37675
"{9498B9DC-73FB-4329-9F1F-F5405F182790}"= UDP:c:\program files\RelevantKnowledge\rlvknlg.exe:rlvknlg.exe
"{F7FB1A33-1CEE-4AF2-8212-21E00A4F1DD7}"= TCP:c:\program files\RelevantKnowledge\rlvknlg.exe:rlvknlg.exe
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [29/01/08 08:29 م 33808]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [26/03/08 03:10 م 20496]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\System32\drivers\klfltdev.sys [13/03/08 09:02 م 26640]
S3 HssTrayService;Hotspot Shield Tray Service;c:\program files\Hotspot Shield\bin\HssTrayService.EXE --> c:\program files\Hotspot Shield\bin\HssTrayService.EXE [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-07-11 c:\windows\Tasks\User_Feed_Synchronization-{2536B282-B972-43B8-9825-9604C991C5D6}.job
- c:\windows\system32\msfeedssync.exe [2009-05-03 11:31]
.
- - - - ORPHANS REMOVED - - - -
BHO-{c95a4e8e-816d-4655-8c79-d736da1adb6d} - (no file)
HKCU-Run-ares - c:\program files\Ares\Ares.exe
HKCU-RunOnce-Shockwave Updater - c:\windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103472 -Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6; Avant Browser; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET
HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
HKLM-Run-Propel Accelerator - c:\program files\Propel Accelerator - Free Trial\trayctl.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_sa&c=81&bd=Presario&pf=laptop
uInternet Settings,ProxyServer = http=localhost:4001
uInternet Settings,ProxyOverride = <local>
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
**************************************************************************
scanning hidden processes ...
[0] 0x00090000
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(4044)
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ara.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Common Files\InstallShield Shared\Service\InstallShield Licensing Service.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\System32\drivers\XAudio.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\System32\conime.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\windows\System32\igfxsrvc.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\program files\TechSmith\Snagit 9\TscHelp.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\TechSmith\Snagit 9\SnagPriv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
c:\program files\TechSmith\Snagit 9\SnagitEditor.exe
.
**************************************************************************
.
Completion time: 2009-07-11 1:18 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-11 22:17
Pre-Run: 121,966,768,128 bytes free
Post-Run: 121,737,252,864 bytes free
293 --- E O F --- 2009-07-09 18:05