من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
السلام عليكم والرحمة ..
اخواني انا عندي مشكلة في الاتصال .. ولازم كل شوي استخدم الكومبوفيكس عشان يرجع الاتصال
ويرجع ينقطع من جديد .. وهكذا ...
( علاوة على ذلك .. اكتشفت اني عندما اعطل برنامج الكاسبر سكاي .. يشتغل النت ولا ادري ان كان بينهما علاقة )
ويرجع ينقطع من جديد .. وهكذا ...
( علاوة على ذلك .. اكتشفت اني عندما اعطل برنامج الكاسبر سكاي .. يشتغل النت ولا ادري ان كان بينهما علاقة )
سويت التقارير وهذا تقرير الـComboFix
ComboFix 09-07-14.08 - MAS 07/16/2009 18:49.8.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.2037.1542 [GMT 3:00]
Running from: d:\documents and settings\MAS\My Documents\Downloads\Programs\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-06-16 to 2009-07-16 )))))))))))))))))))))))))))))))
.
2009-07-16 15:03 . 2009-07-16 15:48 -------- d-----w- D:\[090710] ?????? ?? 1
2009-07-16 09:39 . 2009-07-16 09:39 -------- d-----w- d:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-07-15 20:00 . 2009-07-16 00:04 -------- d-----w- D:\Pokemon Season 2
2009-07-12 01:08 . 2000-08-10 18:21 86016 ----a-w- d:\windows\unvise32.exe
2009-07-12 01:08 . 2009-04-02 12:21 84480 ----a-w- d:\windows\system32\ff_vfw.dll
2009-07-12 01:08 . 2008-06-08 20:58 60273 ----a-w- d:\windows\system32\pthreadGC2.dll
2009-07-12 01:08 . 2009-07-12 01:08 -------- d-----w- d:\program files\ffdshow
2009-07-12 01:08 . 2009-07-12 01:08 81920 ----a-w- d:\documents and settings\MAS\Application Data\ezpinst.exe
2009-07-12 01:08 . 2009-07-12 01:08 47360 ----a-w- d:\windows\system32\drivers\pcouffin.sys
2009-07-12 01:08 . 2009-07-12 01:08 47360 ----a-w- d:\documents and settings\MAS\Application Data\pcouffin.sys
2009-07-12 01:08 . 2009-07-12 01:08 -------- d-----w- d:\documents and settings\MAS\Application Data\Vso
2009-07-12 01:08 . 2004-02-21 22:11 719872 ----a-w- d:\windows\system32\devil.dll
2009-07-12 01:08 . 2005-10-28 06:44 308224 ----a-w- d:\windows\system32\avisynth.dll
2009-07-12 01:08 . 2009-07-12 01:08 -------- d-----w- d:\program files\Video Convert Master
2009-07-11 23:47 . 2009-03-19 13:32 23400 ----a-w- d:\windows\system32\drivers\GEARAspiWDM.sys
2009-07-11 23:47 . 2008-04-17 09:12 107368 ----a-w- d:\windows\system32\GEARAspi.dll
2009-07-11 23:47 . 2009-07-11 23:47 -------- d-----w- d:\program files\iPod
2009-07-11 23:47 . 2009-07-11 23:47 -------- d-----w- d:\program files\iTunes
2009-07-11 23:47 . 2009-07-11 23:47 -------- d-----w- d:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-11 23:47 . 2009-07-11 23:47 -------- d-----w- d:\program files\Bonjour
2009-07-11 23:46 . 2009-07-11 23:46 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\Apple
2009-07-11 23:46 . 2009-07-11 23:46 -------- d-----w- d:\program files\Apple Software Update
2009-07-11 23:46 . 2009-06-05 08:42 39424 ----a-w- d:\windows\system32\drivers\usbaapl.sys
2009-07-11 23:46 . 2009-06-05 08:42 2060288 ----a-w- d:\windows\system32\usbaaplrc.dll
2009-07-11 23:45 . 2009-07-11 23:48 -------- d-----w- d:\documents and settings\All Users\Application Data\Apple
2009-07-11 23:45 . 2009-07-11 23:47 -------- d-----w- d:\program files\Common Files\Apple
2009-07-11 23:45 . 2009-07-11 23:48 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\Apple Computer
2009-07-11 23:19 . 2001-08-17 19:36 5632 ----a-w- d:\windows\system32\ptpusb.dll
2009-07-11 23:19 . 2004-08-03 21:56 159232 ----a-w- d:\windows\system32\ptpusd.dll
2009-07-11 23:19 . 2004-08-03 19:58 15104 -c--a-w- d:\windows\system32\dllcache\usbscan.sys
2009-07-11 23:19 . 2004-08-03 19:58 15104 ----a-w- d:\windows\system32\drivers\usbscan.sys
2009-07-11 12:17 . 2009-07-15 19:59 -------- d-----w- D:\Pokemon Season 1
2009-07-09 12:40 . 2009-07-09 12:44 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\WMTools Downloaded Files
2009-07-07 11:52 . 2009-07-07 11:52 -------- d-----w- d:\program files\danny_kay1710
2009-07-06 13:17 . 2007-07-23 18:25 -------- d-----w- d:\program files\Languages
2009-06-28 09:28 . 2009-07-05 13:32 -------- d-----w- d:\program files\Heroes
2009-06-28 08:40 . 2004-04-30 06:37 160640 ----a-w- d:\windows\system32\drivers\a347bus.sys
2009-06-28 08:40 . 2004-04-30 06:33 5248 ----a-w- d:\windows\system32\drivers\a347scsi.sys
2009-06-28 08:40 . 2009-06-28 08:40 -------- d-----w- d:\program files\Alcohol Soft
2009-06-28 08:36 . 2009-06-28 08:36 -------- d-----w- d:\program files\Okoker ISO Maker
2009-06-28 07:46 . 2004-05-04 11:53 1645320 ----a-w- d:\windows\system32\gdiplus.dll
2009-06-28 07:28 . 1994-09-21 03:00 12800 ----a-w- d:\windows\system32\WING32.DLL
2009-06-28 07:19 . 1997-04-08 17:08 299520 ----a-w- d:\windows\uninst.exe
2009-06-28 07:19 . 2009-06-28 07:19 -------- d-----w- d:\documents and settings\MAS\WINDOWS
2009-06-28 07:00 . 2009-06-28 07:00 98304 ----a-w- d:\windows\system32\CmdLineExt.dll
2009-06-28 06:58 . 2009-06-28 07:57 -------- d-----w- d:\program files\Ubisoft
2009-06-28 06:38 . 2005-05-26 12:34 2297552 ----a-w- d:\windows\system32\d3dx9_26.dll
2009-06-28 06:15 . 2009-06-28 06:15 -------- d--h--w- d:\windows\PIF
2009-06-28 06:09 . 2009-06-28 06:09 -------- d-----w- d:\program files\MagicISO
2009-06-26 16:28 . 2009-06-26 16:28 8854 ----a-r- d:\documents and settings\MAS\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\Uninstall_Project64__9559F7CA5E344237A2D9D856464AD727.exe
2009-06-26 16:28 . 2009-06-26 16:28 40960 ----a-r- d:\documents and settings\MAS\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
2009-06-26 16:28 . 2009-06-26 16:28 40960 ----a-r- d:\documents and settings\MAS\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
2009-06-26 16:28 . 2009-06-26 19:37 -------- d-----w- d:\program files\Project64 1.6
2009-06-26 16:25 . 2009-06-26 16:25 416256 ----a-w- d:\windows\system32\glide3x.dll
2009-06-25 03:58 . 2009-06-25 03:58 112144 ----a-w- d:\windows\system32\drivers\kl1.sys
2009-06-25 00:09 . 2009-06-25 00:10 3561743 ----a-w- d:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-25 00:08 . 2009-06-25 00:08 -------- d-----w- d:\documents and settings\MAS\Application Data\Malwarebytes
2009-06-25 00:08 . 2009-06-17 08:27 19096 ----a-w- d:\windows\system32\drivers\mbam.sys
2009-06-25 00:08 . 2009-06-17 08:27 38160 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2009-06-25 00:08 . 2009-06-25 00:10 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2009-06-25 00:08 . 2009-06-25 00:08 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-24 20:11 . 2009-06-24 20:11 -------- d-----w- d:\documents and settings\MAS\Application Data\CyberScrub
2009-06-24 08:18 . 2009-06-24 08:18 -------- d-----w- d:\documents and settings\MAS\Application Data\QuickScan
2009-06-24 08:15 . 2009-06-24 08:15 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\Runscanner.net
2009-06-24 07:52 . 2009-06-24 07:52 -------- d-----w- d:\program files\Trend Micro
2009-06-22 06:15 . 2009-06-22 06:15 0 ----a-w- d:\windows\nsreg.dat
2009-06-22 06:11 . 2009-06-22 06:11 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\Mozilla
2009-06-21 08:47 . 2009-06-21 08:47 -------- d-----w- d:\program files\URUSoft
2009-06-20 18:00 . 2009-06-20 18:00 -------- d-----w- d:\documents and settings\MAS\Application Data\ImgBurn
2009-06-20 17:59 . 2009-06-20 17:59 -------- d-----w- d:\program files\ImgBurn
2009-06-19 19:42 . 2009-06-19 19:42 -------- d-----w- d:\program files\Pokemon PC 2.0
2009-06-18 23:51 . 2009-06-19 00:01 -------- d-----w- d:\program files\blueMSX
2009-06-18 22:51 . 2009-06-18 22:51 -------- d-----w- d:\program files\Gabest
2009-06-18 22:47 . 2009-06-18 22:47 -------- d-----w- d:\program files\DirectVobSub
2009-06-17 21:01 . 2009-06-17 21:01 -------- d-----w- d:\program files\Ask Search Assistant
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-16 15:53 . 2009-06-11 15:01 -------- d-----w- d:\documents and settings\MAS\Application Data\DMCache
2009-07-16 15:53 . 2009-06-13 11:45 16859168 --sha-w- d:\windows\system32\drivers\fidbox.dat
2009-07-16 15:50 . 2009-06-16 12:10 -------- d-----w- d:\documents and settings\MAS\Application Data\uTorrent
2009-07-16 15:45 . 2009-06-13 11:45 -------- d-----w- d:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-07-16 15:29 . 2009-06-11 15:02 117760 ----a-w- d:\documents and settings\MAS\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-16 15:29 . 2009-06-14 20:42 -------- d-----w- d:\documents and settings\MAS\Application Data\skypePM
2009-07-16 15:27 . 2009-06-13 11:45 682016 --sha-w- d:\windows\system32\drivers\fidbox2.dat
2009-07-16 15:27 . 2009-06-13 11:45 66524 --sha-w- d:\windows\system32\drivers\fidbox2.idx
2009-07-16 15:27 . 2009-06-13 11:45 231008 --sha-w- d:\windows\system32\drivers\fidbox.idx
2009-07-16 07:39 . 2009-06-10 13:25 -------- d-----w- d:\program files\Common Files\Adobe
2009-07-16 00:28 . 2009-06-11 15:02 -------- d-----w- d:\program files\SUPERAntiSpyware
2009-07-15 19:56 . 2009-06-10 13:28 -------- d-----w- d:\program files\Messenger Plus! Live
2009-07-13 10:47 . 2009-06-10 13:42 -------- d-----w- d:\program files\Golden Al-Wafi Translator
2009-07-12 01:08 . 2009-07-12 01:08 752 ----a-w- d:\program files\Common Files\uninstal.log
2009-07-11 23:53 . 2009-06-10 13:30 -------- d-----w- d:\documents and settings\MAS\Application Data\Apple Computer
2009-07-11 23:47 . 2009-06-10 13:30 -------- d-----w- d:\documents and settings\All Users\Application Data\Apple Computer
2009-07-11 23:47 . 2009-06-10 13:30 -------- d-----w- d:\program files\QuickTime
2009-07-08 07:16 . 2009-06-11 15:06 -------- d-----w- d:\documents and settings\MAS\Application Data\Skype
2009-07-06 13:17 . 2009-06-11 15:01 -------- d-----w- d:\program files\Internet Download Manager
2009-06-28 07:47 . 2009-06-10 13:29 -------- d--h--w- d:\program files\InstallShield Installation Information
2009-06-28 07:14 . 2009-06-10 13:29 -------- d-----w- d:\program files\Common Files\InstallShield
2009-06-25 03:58 . 2009-06-13 12:24 112144 ----a-w- d:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\X86\kl1.sys
2009-06-24 20:10 . 2009-06-24 20:10 -------- d-----w- d:\documents and settings\MAS\Application Data\cleaner
2009-06-20 20:22 . 2009-06-11 15:01 -------- d-----w- d:\documents and settings\MAS\Application Data\IDM
2009-06-16 12:10 . 2009-06-16 12:10 -------- d-----w- d:\program files\uTorrent
2009-06-14 20:42 . 2009-06-14 20:42 56 ---ha-w- d:\windows\system32\ezsidmv.dat
2009-06-14 18:22 . 2009-06-14 18:22 165296 ----a-w- d:\documents and settings\MAS\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
2009-06-13 15:04 . 2009-06-11 14:57 -------- d-----w- d:\documents and settings\All Users\Application Data\Messenger Plus!
2009-06-13 13:06 . 2009-06-13 13:06 -------- d-----w- d:\program files\mpegable
2009-06-13 13:06 . 2009-06-13 13:06 47104 ------w- d:\windows\AKDeInstall.exe
2009-06-13 12:24 . 2009-06-13 11:46 94643 ----a-w- d:\windows\system32\drivers\klick.dat
2009-06-13 12:24 . 2009-06-13 11:46 105395 ----a-w- d:\windows\system32\drivers\klin.dat
2009-06-13 12:24 . 2009-06-13 12:24 25104 ----a-w- d:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\ushata.dll
2009-06-13 12:24 . 2009-06-13 12:24 772624 ----a-w- d:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\updater.dll
2009-06-13 12:24 . 2009-06-13 12:24 150032 ----a-w- d:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\diffs.dll
2009-06-13 12:24 . 2009-06-13 12:23 354832 ----a-w- d:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\ckahum.dll
2009-06-13 11:45 . 2009-06-13 11:45 -------- d-----w- d:\program files\Kaspersky Lab
2009-06-13 11:43 . 2009-06-10 14:10 -------- d-----w- d:\program files\ESET
2009-06-12 10:07 . 2009-06-12 10:07 -------- d-----w- d:\documents and settings\MAS\Application Data\GRETECH
2009-06-12 10:07 . 2009-06-12 10:07 112 ----a-w- d:\windows\mbuff.sys
2009-06-11 23:37 . 2009-06-11 23:37 -------- d-----w- d:\documents and settings\MAS\Application Data\Ahead
2009-06-11 23:14 . 2009-06-11 23:14 -------- d-----w- d:\documents and settings\MAS\Application Data\vlc
2009-06-11 15:29 . 2009-06-11 15:29 -------- d-----w- d:\documents and settings\MAS\Application Data\Media Player Classic
2009-06-11 15:02 . 2009-06-11 15:02 -------- d-----w- d:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-11 15:02 . 2009-06-11 15:02 -------- d-----w- d:\documents and settings\MAS\Application Data\SUPERAntiSpyware.com
2009-06-11 15:02 . 2009-06-11 15:02 -------- d-----w- d:\program files\Common Files\Wise Installation Wizard
2009-06-11 14:59 . 2009-06-11 14:59 -------- d-----w- d:\program files\Common Files\Skype
2009-06-11 14:59 . 2009-06-11 14:59 -------- d-----r- d:\program files\Skype
2009-06-11 14:59 . 2009-06-11 14:59 -------- d-----w- d:\documents and settings\All Users\Application Data\Skype
2009-06-10 14:05 . 2009-06-10 14:05 -------- d-----w- d:\program files\CONEXANT
2009-06-10 13:52 . 2009-06-10 13:49 -------- d-----w- d:\program files\Realtek
2009-06-10 13:52 . 2009-06-10 13:52 -------- d-----w- d:\documents and settings\MAS\Application Data\InstallShield
2009-06-10 13:52 . 2009-06-10 13:45 16608 ----a-w- d:\windows\gdrv.sys
2009-06-10 13:49 . 2009-06-10 13:49 315392 ----a-w- d:\windows\HideWin.exe
2009-06-10 13:46 . 2009-06-10 13:46 -------- d-----w- d:\program files\Intel
2009-06-10 13:46 . 2009-06-10 13:46 -------- d-----w- d:\program files\Browser Configuration Utility
2009-06-10 13:41 . 2009-06-10 13:41 73216 ----a-w- d:\windows\ST6UNST.EXE
2009-06-10 13:41 . 2009-06-10 13:41 172032 ------w- d:\windows\Setup1.exe
2009-06-10 13:39 . 2009-06-10 13:39 2232 ----a-w- d:\windows\java\Packages\Data\DN7TBB7D.DAT
2009-06-10 13:39 . 2009-06-10 13:39 155995 ----a-w- d:\windows\java\Packages\375BHVLN.ZIP
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\8QTVTBVZ.DAT
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\8J97ZVRR.DAT
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\NPJ9J31R.DAT
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\I3TJJBL3.DAT
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\9VJ5RR31.DAT
2009-06-10 13:38 . 2009-06-10 13:38 1023035 ----a-w- d:\windows\system32\Setup.scr
2009-06-10 13:37 . 2009-06-10 13:37 -------- d-----w- d:\program files\Windows Media Connect 2
2009-06-10 13:35 . 2009-06-10 13:35 -------- d-----w- d:\program files\Common Files\xing shared
2009-06-10 13:35 . 2009-06-10 13:35 -------- d-----w- d:\program files\Common Files\Real
2009-06-10 13:35 . 2009-06-10 13:29 348160 ----a-w- d:\windows\system32\msvcr71.dll
2009-06-10 13:35 . 2009-06-10 13:29 499712 ----a-w- d:\windows\system32\msvcp71.dll
2009-06-10 13:35 . 2009-06-10 13:35 -------- d-----w- d:\program files\Real
2009-06-10 13:34 . 2009-06-10 13:34 -------- d-----w- d:\documents and settings\All Users\Application Data\CyberLink
2009-06-10 13:31 . 2009-06-10 13:31 -------- d-----w- d:\program files\CyberLink
2009-06-10 13:30 . 2009-06-10 13:30 -------- d-----w- d:\program files\VideoLAN
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\Nokia
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\Common Files\Nokia
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\GRETECH
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\Common Files\Ahead
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\Nero
2009-06-10 13:28 . 2009-06-10 08:31 94632 ----a-w- d:\documents and settings\MAS\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-10 13:25 . 2009-06-10 13:25 -------- d-----w- d:\program files\Windows Live
2009-06-10 13:23 . 2009-06-10 13:22 -------- d-----w- d:\documents and settings\All Users\Application Data\WinZip
2009-06-10 13:19 . 2009-06-10 13:19 -------- d-----w- d:\program files\Common Files\L&H
2009-06-10 13:19 . 2009-06-10 13:19 -------- d-----w- d:\program files\Microsoft.NET
2009-06-10 13:19 . 2009-06-10 13:19 -------- d-----w- d:\program files\Microsoft ActiveSync
2009-06-10 13:19 . 2009-06-10 13:19 -------- d-----w- d:\program files\Microsoft Works
2009-06-10 08:32 . 2009-06-10 08:23 166455 ----a-w- d:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-10 08:24 . 2009-06-10 08:24 -------- d-----w- d:\program files\microsoft frontpage
2009-06-10 08:20 . 2009-06-10 08:20 21640 ----a-w- d:\windows\system32\emptyregdb.dat
2009-06-05 10:57 . 2009-06-05 10:57 75048 ----a-w- d:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
.
((((((((((((((((((((((((((((( SnapShot_2009-07-14_20.11.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-27 10:32 . 2009-06-27 10:32 37766656 d:\windows\Installer\130de.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Skype"="d:\program files\Skype\Phone\Skype.exe" [2009-04-21 24264488]
"SUPERAntiSpyware"="d:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-07-16 1830128]
"IDMan"="d:\program files\Internet Download Manager\IDMan.exe" [2007-07-23 800768]
"µTorrent"="d:\program files\uTorrent\utorrent.exe" [2007-02-15 177152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="d:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-02-07 71216]
"LanguageShortcut"="d:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 54832]
"TkBellExe"="d:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-10 185896]
"IgfxTray"="d:\windows\system32\igfxtray.exe" [2007-09-05 141848]
"HotKeysCmds"="d:\windows\system32\hkcmd.exe" [2007-09-05 166424]
"Persistence"="d:\windows\system32\igfxpers.exe" [2007-09-05 137752]
"QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"RTHDCPL"="RTHDCPL.EXE" - d:\windows\RTHDCPL.exe [2008-02-13 16857600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
d:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-6-10 113664]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 09:05 356352 ----a-w- d:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"d:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"d:\\Program Files\\uTorrent\\utorrent.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\Windows Live Messenger.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [14/05/2009 02:22 م 9968]
R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [14/05/2009 02:22 م 72944]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;d:\windows\system32\drivers\klim5.sys [13/12/2007 01:28 م 24592]
R3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [14/05/2009 02:22 م 7408]
.
Contents of the 'Scheduled Tasks' folder
2009-07-16 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-AdobeUpdater - d:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.2037.1542 [GMT 3:00]
Running from: d:\documents and settings\MAS\My Documents\Downloads\Programs\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-06-16 to 2009-07-16 )))))))))))))))))))))))))))))))
.
2009-07-16 15:03 . 2009-07-16 15:48 -------- d-----w- D:\[090710] ?????? ?? 1
2009-07-16 09:39 . 2009-07-16 09:39 -------- d-----w- d:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-07-15 20:00 . 2009-07-16 00:04 -------- d-----w- D:\Pokemon Season 2
2009-07-12 01:08 . 2000-08-10 18:21 86016 ----a-w- d:\windows\unvise32.exe
2009-07-12 01:08 . 2009-04-02 12:21 84480 ----a-w- d:\windows\system32\ff_vfw.dll
2009-07-12 01:08 . 2008-06-08 20:58 60273 ----a-w- d:\windows\system32\pthreadGC2.dll
2009-07-12 01:08 . 2009-07-12 01:08 -------- d-----w- d:\program files\ffdshow
2009-07-12 01:08 . 2009-07-12 01:08 81920 ----a-w- d:\documents and settings\MAS\Application Data\ezpinst.exe
2009-07-12 01:08 . 2009-07-12 01:08 47360 ----a-w- d:\windows\system32\drivers\pcouffin.sys
2009-07-12 01:08 . 2009-07-12 01:08 47360 ----a-w- d:\documents and settings\MAS\Application Data\pcouffin.sys
2009-07-12 01:08 . 2009-07-12 01:08 -------- d-----w- d:\documents and settings\MAS\Application Data\Vso
2009-07-12 01:08 . 2004-02-21 22:11 719872 ----a-w- d:\windows\system32\devil.dll
2009-07-12 01:08 . 2005-10-28 06:44 308224 ----a-w- d:\windows\system32\avisynth.dll
2009-07-12 01:08 . 2009-07-12 01:08 -------- d-----w- d:\program files\Video Convert Master
2009-07-11 23:47 . 2009-03-19 13:32 23400 ----a-w- d:\windows\system32\drivers\GEARAspiWDM.sys
2009-07-11 23:47 . 2008-04-17 09:12 107368 ----a-w- d:\windows\system32\GEARAspi.dll
2009-07-11 23:47 . 2009-07-11 23:47 -------- d-----w- d:\program files\iPod
2009-07-11 23:47 . 2009-07-11 23:47 -------- d-----w- d:\program files\iTunes
2009-07-11 23:47 . 2009-07-11 23:47 -------- d-----w- d:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-11 23:47 . 2009-07-11 23:47 -------- d-----w- d:\program files\Bonjour
2009-07-11 23:46 . 2009-07-11 23:46 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\Apple
2009-07-11 23:46 . 2009-07-11 23:46 -------- d-----w- d:\program files\Apple Software Update
2009-07-11 23:46 . 2009-06-05 08:42 39424 ----a-w- d:\windows\system32\drivers\usbaapl.sys
2009-07-11 23:46 . 2009-06-05 08:42 2060288 ----a-w- d:\windows\system32\usbaaplrc.dll
2009-07-11 23:45 . 2009-07-11 23:48 -------- d-----w- d:\documents and settings\All Users\Application Data\Apple
2009-07-11 23:45 . 2009-07-11 23:47 -------- d-----w- d:\program files\Common Files\Apple
2009-07-11 23:45 . 2009-07-11 23:48 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\Apple Computer
2009-07-11 23:19 . 2001-08-17 19:36 5632 ----a-w- d:\windows\system32\ptpusb.dll
2009-07-11 23:19 . 2004-08-03 21:56 159232 ----a-w- d:\windows\system32\ptpusd.dll
2009-07-11 23:19 . 2004-08-03 19:58 15104 -c--a-w- d:\windows\system32\dllcache\usbscan.sys
2009-07-11 23:19 . 2004-08-03 19:58 15104 ----a-w- d:\windows\system32\drivers\usbscan.sys
2009-07-11 12:17 . 2009-07-15 19:59 -------- d-----w- D:\Pokemon Season 1
2009-07-09 12:40 . 2009-07-09 12:44 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\WMTools Downloaded Files
2009-07-07 11:52 . 2009-07-07 11:52 -------- d-----w- d:\program files\danny_kay1710
2009-07-06 13:17 . 2007-07-23 18:25 -------- d-----w- d:\program files\Languages
2009-06-28 09:28 . 2009-07-05 13:32 -------- d-----w- d:\program files\Heroes
2009-06-28 08:40 . 2004-04-30 06:37 160640 ----a-w- d:\windows\system32\drivers\a347bus.sys
2009-06-28 08:40 . 2004-04-30 06:33 5248 ----a-w- d:\windows\system32\drivers\a347scsi.sys
2009-06-28 08:40 . 2009-06-28 08:40 -------- d-----w- d:\program files\Alcohol Soft
2009-06-28 08:36 . 2009-06-28 08:36 -------- d-----w- d:\program files\Okoker ISO Maker
2009-06-28 07:46 . 2004-05-04 11:53 1645320 ----a-w- d:\windows\system32\gdiplus.dll
2009-06-28 07:28 . 1994-09-21 03:00 12800 ----a-w- d:\windows\system32\WING32.DLL
2009-06-28 07:19 . 1997-04-08 17:08 299520 ----a-w- d:\windows\uninst.exe
2009-06-28 07:19 . 2009-06-28 07:19 -------- d-----w- d:\documents and settings\MAS\WINDOWS
2009-06-28 07:00 . 2009-06-28 07:00 98304 ----a-w- d:\windows\system32\CmdLineExt.dll
2009-06-28 06:58 . 2009-06-28 07:57 -------- d-----w- d:\program files\Ubisoft
2009-06-28 06:38 . 2005-05-26 12:34 2297552 ----a-w- d:\windows\system32\d3dx9_26.dll
2009-06-28 06:15 . 2009-06-28 06:15 -------- d--h--w- d:\windows\PIF
2009-06-28 06:09 . 2009-06-28 06:09 -------- d-----w- d:\program files\MagicISO
2009-06-26 16:28 . 2009-06-26 16:28 8854 ----a-r- d:\documents and settings\MAS\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\Uninstall_Project64__9559F7CA5E344237A2D9D856464AD727.exe
2009-06-26 16:28 . 2009-06-26 16:28 40960 ----a-r- d:\documents and settings\MAS\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
2009-06-26 16:28 . 2009-06-26 16:28 40960 ----a-r- d:\documents and settings\MAS\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
2009-06-26 16:28 . 2009-06-26 19:37 -------- d-----w- d:\program files\Project64 1.6
2009-06-26 16:25 . 2009-06-26 16:25 416256 ----a-w- d:\windows\system32\glide3x.dll
2009-06-25 03:58 . 2009-06-25 03:58 112144 ----a-w- d:\windows\system32\drivers\kl1.sys
2009-06-25 00:09 . 2009-06-25 00:10 3561743 ----a-w- d:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-25 00:08 . 2009-06-25 00:08 -------- d-----w- d:\documents and settings\MAS\Application Data\Malwarebytes
2009-06-25 00:08 . 2009-06-17 08:27 19096 ----a-w- d:\windows\system32\drivers\mbam.sys
2009-06-25 00:08 . 2009-06-17 08:27 38160 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2009-06-25 00:08 . 2009-06-25 00:10 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2009-06-25 00:08 . 2009-06-25 00:08 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-24 20:11 . 2009-06-24 20:11 -------- d-----w- d:\documents and settings\MAS\Application Data\CyberScrub
2009-06-24 08:18 . 2009-06-24 08:18 -------- d-----w- d:\documents and settings\MAS\Application Data\QuickScan
2009-06-24 08:15 . 2009-06-24 08:15 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\Runscanner.net
2009-06-24 07:52 . 2009-06-24 07:52 -------- d-----w- d:\program files\Trend Micro
2009-06-22 06:15 . 2009-06-22 06:15 0 ----a-w- d:\windows\nsreg.dat
2009-06-22 06:11 . 2009-06-22 06:11 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\Mozilla
2009-06-21 08:47 . 2009-06-21 08:47 -------- d-----w- d:\program files\URUSoft
2009-06-20 18:00 . 2009-06-20 18:00 -------- d-----w- d:\documents and settings\MAS\Application Data\ImgBurn
2009-06-20 17:59 . 2009-06-20 17:59 -------- d-----w- d:\program files\ImgBurn
2009-06-19 19:42 . 2009-06-19 19:42 -------- d-----w- d:\program files\Pokemon PC 2.0
2009-06-18 23:51 . 2009-06-19 00:01 -------- d-----w- d:\program files\blueMSX
2009-06-18 22:51 . 2009-06-18 22:51 -------- d-----w- d:\program files\Gabest
2009-06-18 22:47 . 2009-06-18 22:47 -------- d-----w- d:\program files\DirectVobSub
2009-06-17 21:01 . 2009-06-17 21:01 -------- d-----w- d:\program files\Ask Search Assistant
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-16 15:53 . 2009-06-11 15:01 -------- d-----w- d:\documents and settings\MAS\Application Data\DMCache
2009-07-16 15:53 . 2009-06-13 11:45 16859168 --sha-w- d:\windows\system32\drivers\fidbox.dat
2009-07-16 15:50 . 2009-06-16 12:10 -------- d-----w- d:\documents and settings\MAS\Application Data\uTorrent
2009-07-16 15:45 . 2009-06-13 11:45 -------- d-----w- d:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-07-16 15:29 . 2009-06-11 15:02 117760 ----a-w- d:\documents and settings\MAS\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-16 15:29 . 2009-06-14 20:42 -------- d-----w- d:\documents and settings\MAS\Application Data\skypePM
2009-07-16 15:27 . 2009-06-13 11:45 682016 --sha-w- d:\windows\system32\drivers\fidbox2.dat
2009-07-16 15:27 . 2009-06-13 11:45 66524 --sha-w- d:\windows\system32\drivers\fidbox2.idx
2009-07-16 15:27 . 2009-06-13 11:45 231008 --sha-w- d:\windows\system32\drivers\fidbox.idx
2009-07-16 07:39 . 2009-06-10 13:25 -------- d-----w- d:\program files\Common Files\Adobe
2009-07-16 00:28 . 2009-06-11 15:02 -------- d-----w- d:\program files\SUPERAntiSpyware
2009-07-15 19:56 . 2009-06-10 13:28 -------- d-----w- d:\program files\Messenger Plus! Live
2009-07-13 10:47 . 2009-06-10 13:42 -------- d-----w- d:\program files\Golden Al-Wafi Translator
2009-07-12 01:08 . 2009-07-12 01:08 752 ----a-w- d:\program files\Common Files\uninstal.log
2009-07-11 23:53 . 2009-06-10 13:30 -------- d-----w- d:\documents and settings\MAS\Application Data\Apple Computer
2009-07-11 23:47 . 2009-06-10 13:30 -------- d-----w- d:\documents and settings\All Users\Application Data\Apple Computer
2009-07-11 23:47 . 2009-06-10 13:30 -------- d-----w- d:\program files\QuickTime
2009-07-08 07:16 . 2009-06-11 15:06 -------- d-----w- d:\documents and settings\MAS\Application Data\Skype
2009-07-06 13:17 . 2009-06-11 15:01 -------- d-----w- d:\program files\Internet Download Manager
2009-06-28 07:47 . 2009-06-10 13:29 -------- d--h--w- d:\program files\InstallShield Installation Information
2009-06-28 07:14 . 2009-06-10 13:29 -------- d-----w- d:\program files\Common Files\InstallShield
2009-06-25 03:58 . 2009-06-13 12:24 112144 ----a-w- d:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\X86\kl1.sys
2009-06-24 20:10 . 2009-06-24 20:10 -------- d-----w- d:\documents and settings\MAS\Application Data\cleaner
2009-06-20 20:22 . 2009-06-11 15:01 -------- d-----w- d:\documents and settings\MAS\Application Data\IDM
2009-06-16 12:10 . 2009-06-16 12:10 -------- d-----w- d:\program files\uTorrent
2009-06-14 20:42 . 2009-06-14 20:42 56 ---ha-w- d:\windows\system32\ezsidmv.dat
2009-06-14 18:22 . 2009-06-14 18:22 165296 ----a-w- d:\documents and settings\MAS\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
2009-06-13 15:04 . 2009-06-11 14:57 -------- d-----w- d:\documents and settings\All Users\Application Data\Messenger Plus!
2009-06-13 13:06 . 2009-06-13 13:06 -------- d-----w- d:\program files\mpegable
2009-06-13 13:06 . 2009-06-13 13:06 47104 ------w- d:\windows\AKDeInstall.exe
2009-06-13 12:24 . 2009-06-13 11:46 94643 ----a-w- d:\windows\system32\drivers\klick.dat
2009-06-13 12:24 . 2009-06-13 11:46 105395 ----a-w- d:\windows\system32\drivers\klin.dat
2009-06-13 12:24 . 2009-06-13 12:24 25104 ----a-w- d:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\ushata.dll
2009-06-13 12:24 . 2009-06-13 12:24 772624 ----a-w- d:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\updater.dll
2009-06-13 12:24 . 2009-06-13 12:24 150032 ----a-w- d:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\diffs.dll
2009-06-13 12:24 . 2009-06-13 12:23 354832 ----a-w- d:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\ckahum.dll
2009-06-13 11:45 . 2009-06-13 11:45 -------- d-----w- d:\program files\Kaspersky Lab
2009-06-13 11:43 . 2009-06-10 14:10 -------- d-----w- d:\program files\ESET
2009-06-12 10:07 . 2009-06-12 10:07 -------- d-----w- d:\documents and settings\MAS\Application Data\GRETECH
2009-06-12 10:07 . 2009-06-12 10:07 112 ----a-w- d:\windows\mbuff.sys
2009-06-11 23:37 . 2009-06-11 23:37 -------- d-----w- d:\documents and settings\MAS\Application Data\Ahead
2009-06-11 23:14 . 2009-06-11 23:14 -------- d-----w- d:\documents and settings\MAS\Application Data\vlc
2009-06-11 15:29 . 2009-06-11 15:29 -------- d-----w- d:\documents and settings\MAS\Application Data\Media Player Classic
2009-06-11 15:02 . 2009-06-11 15:02 -------- d-----w- d:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-11 15:02 . 2009-06-11 15:02 -------- d-----w- d:\documents and settings\MAS\Application Data\SUPERAntiSpyware.com
2009-06-11 15:02 . 2009-06-11 15:02 -------- d-----w- d:\program files\Common Files\Wise Installation Wizard
2009-06-11 14:59 . 2009-06-11 14:59 -------- d-----w- d:\program files\Common Files\Skype
2009-06-11 14:59 . 2009-06-11 14:59 -------- d-----r- d:\program files\Skype
2009-06-11 14:59 . 2009-06-11 14:59 -------- d-----w- d:\documents and settings\All Users\Application Data\Skype
2009-06-10 14:05 . 2009-06-10 14:05 -------- d-----w- d:\program files\CONEXANT
2009-06-10 13:52 . 2009-06-10 13:49 -------- d-----w- d:\program files\Realtek
2009-06-10 13:52 . 2009-06-10 13:52 -------- d-----w- d:\documents and settings\MAS\Application Data\InstallShield
2009-06-10 13:52 . 2009-06-10 13:45 16608 ----a-w- d:\windows\gdrv.sys
2009-06-10 13:49 . 2009-06-10 13:49 315392 ----a-w- d:\windows\HideWin.exe
2009-06-10 13:46 . 2009-06-10 13:46 -------- d-----w- d:\program files\Intel
2009-06-10 13:46 . 2009-06-10 13:46 -------- d-----w- d:\program files\Browser Configuration Utility
2009-06-10 13:41 . 2009-06-10 13:41 73216 ----a-w- d:\windows\ST6UNST.EXE
2009-06-10 13:41 . 2009-06-10 13:41 172032 ------w- d:\windows\Setup1.exe
2009-06-10 13:39 . 2009-06-10 13:39 2232 ----a-w- d:\windows\java\Packages\Data\DN7TBB7D.DAT
2009-06-10 13:39 . 2009-06-10 13:39 155995 ----a-w- d:\windows\java\Packages\375BHVLN.ZIP
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\8QTVTBVZ.DAT
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\8J97ZVRR.DAT
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\NPJ9J31R.DAT
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\I3TJJBL3.DAT
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\9VJ5RR31.DAT
2009-06-10 13:38 . 2009-06-10 13:38 1023035 ----a-w- d:\windows\system32\Setup.scr
2009-06-10 13:37 . 2009-06-10 13:37 -------- d-----w- d:\program files\Windows Media Connect 2
2009-06-10 13:35 . 2009-06-10 13:35 -------- d-----w- d:\program files\Common Files\xing shared
2009-06-10 13:35 . 2009-06-10 13:35 -------- d-----w- d:\program files\Common Files\Real
2009-06-10 13:35 . 2009-06-10 13:29 348160 ----a-w- d:\windows\system32\msvcr71.dll
2009-06-10 13:35 . 2009-06-10 13:29 499712 ----a-w- d:\windows\system32\msvcp71.dll
2009-06-10 13:35 . 2009-06-10 13:35 -------- d-----w- d:\program files\Real
2009-06-10 13:34 . 2009-06-10 13:34 -------- d-----w- d:\documents and settings\All Users\Application Data\CyberLink
2009-06-10 13:31 . 2009-06-10 13:31 -------- d-----w- d:\program files\CyberLink
2009-06-10 13:30 . 2009-06-10 13:30 -------- d-----w- d:\program files\VideoLAN
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\Nokia
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\Common Files\Nokia
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\GRETECH
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\Common Files\Ahead
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\Nero
2009-06-10 13:28 . 2009-06-10 08:31 94632 ----a-w- d:\documents and settings\MAS\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-10 13:25 . 2009-06-10 13:25 -------- d-----w- d:\program files\Windows Live
2009-06-10 13:23 . 2009-06-10 13:22 -------- d-----w- d:\documents and settings\All Users\Application Data\WinZip
2009-06-10 13:19 . 2009-06-10 13:19 -------- d-----w- d:\program files\Common Files\L&H
2009-06-10 13:19 . 2009-06-10 13:19 -------- d-----w- d:\program files\Microsoft.NET
2009-06-10 13:19 . 2009-06-10 13:19 -------- d-----w- d:\program files\Microsoft ActiveSync
2009-06-10 13:19 . 2009-06-10 13:19 -------- d-----w- d:\program files\Microsoft Works
2009-06-10 08:32 . 2009-06-10 08:23 166455 ----a-w- d:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-10 08:24 . 2009-06-10 08:24 -------- d-----w- d:\program files\microsoft frontpage
2009-06-10 08:20 . 2009-06-10 08:20 21640 ----a-w- d:\windows\system32\emptyregdb.dat
2009-06-05 10:57 . 2009-06-05 10:57 75048 ----a-w- d:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
.
((((((((((((((((((((((((((((( SnapShot_2009-07-14_20.11.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-27 10:32 . 2009-06-27 10:32 37766656 d:\windows\Installer\130de.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Skype"="d:\program files\Skype\Phone\Skype.exe" [2009-04-21 24264488]
"SUPERAntiSpyware"="d:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-07-16 1830128]
"IDMan"="d:\program files\Internet Download Manager\IDMan.exe" [2007-07-23 800768]
"µTorrent"="d:\program files\uTorrent\utorrent.exe" [2007-02-15 177152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="d:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-02-07 71216]
"LanguageShortcut"="d:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 54832]
"TkBellExe"="d:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-10 185896]
"IgfxTray"="d:\windows\system32\igfxtray.exe" [2007-09-05 141848]
"HotKeysCmds"="d:\windows\system32\hkcmd.exe" [2007-09-05 166424]
"Persistence"="d:\windows\system32\igfxpers.exe" [2007-09-05 137752]
"QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"RTHDCPL"="RTHDCPL.EXE" - d:\windows\RTHDCPL.exe [2008-02-13 16857600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
d:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-6-10 113664]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 09:05 356352 ----a-w- d:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"d:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"d:\\Program Files\\uTorrent\\utorrent.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\Windows Live Messenger.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [14/05/2009 02:22 م 9968]
R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [14/05/2009 02:22 م 72944]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;d:\windows\system32\drivers\klim5.sys [13/12/2007 01:28 م 24592]
R3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [14/05/2009 02:22 م 7408]
.
Contents of the 'Scheduled Tasks' folder
2009-07-16 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-AdobeUpdater - d:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com.sa/
uInternet Settings,ProxyOverride = local
IE: Download All Links with IDM - d:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - d:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - d:\program files\Internet Download Manager\IEExt.htm
IE: تحميل الكل بـ إنترنت داونلود مانيجر - d:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - d:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - d:\program files\Internet Download Manager\IEGetVL.htm
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-16 18:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\d:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):0b,00,7c,c0,c7,32,ff,fd,69,01,97,98,a0,2a,c3,1e,38,44,82,e6,7f,
9f,51,fa,20,e7,63,6e,73,62,35,b6,a8,c9,d0,1a,3b,e5,aa,dc,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8ca61fa3-62de-48ed-9a83-e6bb9774ff0b}]
@Denied: (Full) (Everyone)
"Model"=dword:000000b9
"Therad"=dword:00000019
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(572)
d:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
d:\program files\SUPERAntiSpyware\SASWINLO.dll
d:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(628)
d:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
d:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
d:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
- - - - - - - > 'explorer.exe'(2716)
d:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
d:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
d:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll
d:\windows\system32\msi.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-16 18:55
ComboFix-quarantined-files.txt 2009-07-16 15:55
ComboFix2.txt 2009-07-14 20:39
ComboFix3.txt 2009-07-14 20:12
ComboFix4.txt 2009-07-06 17:53
ComboFix5.txt 2009-07-16 15:44
Pre-Run: 22,340,927,488 bytes free
Post-Run: 22,326,116,352 bytes free
300
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com.sa/
uInternet Settings,ProxyOverride = local
IE: Download All Links with IDM - d:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - d:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - d:\program files\Internet Download Manager\IEExt.htm
IE: تحميل الكل بـ إنترنت داونلود مانيجر - d:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - d:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - d:\program files\Internet Download Manager\IEGetVL.htm
DPF: Microsoft XML Parser for Java -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
Rootkit scan 2009-07-16 18:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\d:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):0b,00,7c,c0,c7,32,ff,fd,69,01,97,98,a0,2a,c3,1e,38,44,82,e6,7f,
9f,51,fa,20,e7,63,6e,73,62,35,b6,a8,c9,d0,1a,3b,e5,aa,dc,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8ca61fa3-62de-48ed-9a83-e6bb9774ff0b}]
@Denied: (Full) (Everyone)
"Model"=dword:000000b9
"Therad"=dword:00000019
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(572)
d:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
d:\program files\SUPERAntiSpyware\SASWINLO.dll
d:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(628)
d:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
d:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
d:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
- - - - - - - > 'explorer.exe'(2716)
d:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
d:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
d:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll
d:\windows\system32\msi.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-16 18:55
ComboFix-quarantined-files.txt 2009-07-16 15:55
ComboFix2.txt 2009-07-14 20:39
ComboFix3.txt 2009-07-14 20:12
ComboFix4.txt 2009-07-06 17:53
ComboFix5.txt 2009-07-16 15:44
Pre-Run: 22,340,927,488 bytes free
Post-Run: 22,326,116,352 bytes free
300
وهذا تقرير الهايجاك
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:02:37, on 16/07/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\WINDOWS\system32\igfxtray.exe
D:\WINDOWS\system32\hkcmd.exe
D:\WINDOWS\system32\igfxpers.exe
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\system32\igfxsrvc.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\Program Files\uTorrent\utorrent.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Program Files\CyberLink\Shared files\RichVideo.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Skype\Plugin Manager\skypePM.exe
D:\WINDOWS\system32\wscntfy.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\Internet Download Manager\IDMan.exe
D:\WINDOWS\explorer.exe
D:\Program Files\internet explorer\iexplore.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O4 - HKLM\..\Run: [RemoteControl] "D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "D:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IgfxTray] D:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] D:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] D:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [IDMan] D:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [µTorrent] "D:\Program Files\uTorrent\utorrent.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Download All Links with IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - D:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - D:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O16 - DPF: {E001C731-5E37-4538-A5CB-8168736A2360} (ActiveQscan Control) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - D:\Program Files\CyberLink\Shared files\RichVideo.exe
--
End of file - 6354 bytes
Scan saved at 19:02:37, on 16/07/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\WINDOWS\system32\igfxtray.exe
D:\WINDOWS\system32\hkcmd.exe
D:\WINDOWS\system32\igfxpers.exe
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\system32\igfxsrvc.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\Program Files\uTorrent\utorrent.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Program Files\CyberLink\Shared files\RichVideo.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Skype\Plugin Manager\skypePM.exe
D:\WINDOWS\system32\wscntfy.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\Internet Download Manager\IDMan.exe
D:\WINDOWS\explorer.exe
D:\Program Files\internet explorer\iexplore.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O4 - HKLM\..\Run: [RemoteControl] "D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "D:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IgfxTray] D:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] D:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] D:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [IDMan] D:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [µTorrent] "D:\Program Files\uTorrent\utorrent.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Download All Links with IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - D:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - D:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O16 - DPF: {E001C731-5E37-4538-A5CB-8168736A2360} (ActiveQscan Control) -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - D:\Program Files\CyberLink\Shared files\RichVideo.exe
--
End of file - 6354 bytes
علماً بأنني استخدمت برنامج WinsockxpFix ومافي فايدة
فيدوني الله يجزاكم خير ؟؟؟؟
