من اضافة وازاله البرامج احذف
Software Informer
لأنه ماله داعي
حدد القيم واحذفها
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Proc Deaf Delete Peak] C:\Documents and Settings\All Users\Application Data\file joy proc deaf\Great inside.exe
O4 - HKCU\..\Run: [JUGS SURF] C:\DOCUME~1\ADMINI~1\APPLIC~1\MOREOP~1\bitscastfil m.exe
طريقه الحذف
بعدها اذهب الى اضافة وازالة البرامج واحذف التولبار الموجود عندك (toolbar)>> ممكن ما يكون موجود
ثم نزل هذه الاداة واتبع الشرح التالي
التوافق : ويندوز اكسبيفقط
شرح الاستخدام ,,,,,,
دبل كلك على الاداة واصبر حتى تنتهي جميع النوافذ وتقف عند هذه النافذة
وعند ظهور هذه الشاشه ,, اضغط على Close ليتم اعادة تشغيل جهازك (( لتكملة عملية التنظيف ))
وبعد عمل المطلوب اعمل التالي
عطل برامج الحماية عن العمل
ثم
حمل الاداة التالية واحفظها على سطح المكتب
عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
لا تقم بتشغيل اي برنامج ،، ومهما طالت عملية الفحص انتظر حتى تنتهي
انتظر حتى يظهر لك تقرير ،،انسخه والصقه بمشاركتك القادمة
هذا التقرير الاخير
ComboFix 09-08-02.04 - Administrator 08/03/2009 18:41.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.1270.844 [GMT 3:00]
Running from: c:\documents and settings\Administrator\سطح المكتب\22055\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\tmp.reg
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_AVPsys
((((((((((((((((((((((((( Files Created from 2009-07-03 to 2009-08-03 )))))))))))))))))))))))))))))))
.
2009-08-03 15:04 . 2009-08-03 15:04 -------- d-----w- c:\program files\Trend Micro
2009-08-03 10:36 . 2009-08-03 10:36 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-03 10:36 . 2008-10-16 17:25 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-03 10:36 . 2008-10-16 17:25 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 10:36 . 2009-08-03 10:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-03 10:36 . 2009-08-03 10:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-31 22:58 . 2009-07-03 16:55 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-31 22:58 . 2009-07-03 16:55 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-07-31 22:37 . 2009-08-03 15:36 741376 ----a-w- c:\documents and settings\All Users\Application Data\file joy proc deaf\Great inside.exe
2009-07-31 22:37 . 2009-07-31 22:37 741376 ----a-w- c:\documents and settings\Administrator\Application Data\moreoptionsoap\ttqrpftx.exe
2009-07-31 22:35 . 2009-07-31 22:35 -------- d-----w- c:\program files\moreoptionsoap
2009-07-16 14:17 . 2009-07-31 22:39 286720 ----a-w- c:\documents and settings\Administrator\Application Data\moreoptionsoap\find tray bold.exe
2009-07-16 14:16 . 2009-07-31 22:38 499712 ----a-w- c:\documents and settings\Administrator\Application Data\moreoptionsoap\Log Mix Audio Locks.exe
2009-07-16 14:15 . 2009-07-31 22:37 -------- d-----w- c:\documents and settings\All Users\Application Data\file joy proc deaf
2009-07-16 14:15 . 2009-07-16 14:15 798720 ----a-w- c:\documents and settings\Administrator\Application Data\moreoptionsoap\lfynluee.exe
2009-07-16 14:15 . 2009-07-31 22:39 -------- d-----w- c:\documents and settings\Administrator\Application Data\moreoptionsoap
2009-07-16 14:15 . 2009-07-31 22:34 589824 ----a-w- c:\documents and settings\Administrator\Application Data\moreoptionsoap\bitscastfilm.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-03 15:39 . 2009-03-04 21:30 -------- d-----w- c:\documents and settings\Administrator\Application Data\Software Informer
2009-08-03 15:34 . 2009-03-20 07:32 -------- d-----w- c:\documents and settings\Administrator\Application Data\cleaner
2009-08-02 21:17 . 2009-02-12 18:53 -------- d-----w- c:\program files\Google
2009-08-02 09:41 . 2009-04-05 16:20 -------- d-----w- c:\documents and settings\Administrator\Application Data\dvdcss
2009-07-17 15:03 . 2009-02-14 16:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-16 14:14 . 2009-02-12 11:33 -------- d-----w- c:\program files\Messenger Plus! Live
2009-07-16 14:13 . 2009-02-12 04:52 104976 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-05 21:59 . 2009-07-03 19:33 -------- d-----w- c:\program files\HP
2009-07-03 19:40 . 2009-07-03 19:40 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-07-03 19:40 . 2009-07-03 19:20 112372 ----a-w- c:\windows\hpoins07.dat
2009-07-03 19:39 . 2009-07-03 19:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Sonic
2009-07-03 19:39 . 2009-07-03 19:39 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-07-03 19:39 . 2009-07-03 19:38 -------- d-----w- c:\program files\Common Files\HP
2009-07-03 19:35 . 2009-07-03 19:35 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-07-03 19:19 . 2009-07-03 19:19 -------- d-----w- c:\documents and settings\Administrator\Application Data\HP
2009-07-03 16:55 . 2008-04-14 17:29 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-03 00:14 . 2009-07-03 00:15 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-03 00:14 . 2009-07-03 00:14 -------- d-----w- c:\program files\Java
2009-07-03 00:14 . 2009-03-26 06:47 152576 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-07-02 23:51 . 2009-07-02 23:51 2678 ----a-w- c:\windows\Java\Packages\Data\5FFTV17Z.DAT
2009-07-02 23:51 . 2009-07-02 23:51 2678 ----a-w- c:\windows\Java\Packages\Data\YTBH33NB.DAT
2009-07-02 23:51 . 2009-07-02 23:51 2678 ----a-w- c:\windows\Java\Packages\Data\NXFLNNJH.DAT
2009-07-02 23:51 . 2009-07-02 23:51 2678 ----a-w- c:\windows\Java\Packages\Data\GLVRF9FJ.DAT
2009-07-02 23:51 . 2009-07-02 23:51 2678 ----a-w- c:\windows\Java\Packages\Data\B5R3R13N.DAT
2009-07-02 23:25 . 2009-05-13 19:40 -------- d-----w- c:\program files\Uniblue
2009-07-02 23:08 . 2009-05-13 19:40 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverScanner
2009-07-02 23:08 . 2009-02-13 11:03 -------- d-----w- c:\documents and settings\Administrator\Application Data\Uniblue
2009-06-29 17:15 . 2009-02-12 18:54 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-06-24 18:39 . 2009-06-24 18:39 2232 ----a-w- c:\windows\Java\Packages\Data\RDZ5FD7T.DAT
2009-06-24 18:39 . 2009-06-24 18:39 155995 ----a-w- c:\windows\Java\Packages\NHNTRZDB.ZIP
2009-06-16 14:36 . 2008-04-14 17:29 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2008-04-14 17:29 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:10 . 2008-04-14 17:29 1289216 ----a-w- c:\windows\system32\quartz.dll
2009-05-17 16:50 . 2009-05-17 16:50 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7169FA93-66C2-43BD-86E0-CD332A686B29}\Installer\CommonCustomActions\msxml6Exec.exe
2009-05-17 16:50 . 2009-05-17 16:50 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7169FA93-66C2-43BD-86E0-CD332A686B29}\Installer\CommonCustomActions\Sleep.exe
2009-05-17 16:50 . 2009-05-17 16:50 3181612 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7169FA93-66C2-43BD-86E0-CD332A686B29}\Installer\CommonCustomActions\vcredistExec.exe
2009-05-17 16:50 . 2009-05-17 16:51 24368104 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7169FA93-66C2-43BD-86E0-CD332A686B29}\NokiaSoftwareUpdaterSetup_ar[1].exe
2009-05-07 15:32 . 2008-04-14 17:29 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-28 12:20 . 2009-03-16 15:44 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2009-02-12 13:13 . 2009-02-12 13:13 8 --sh--r- c:\windows\system32\fgxp9.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Software Informer"="c:\program files\Software Informer\softinfo.exe" [2009-03-24 1785925]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-11-23 163840]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2004-09-07 213054]
"WatchDog"="c:\program files\InterVideo\DVD Check\DVDCheck.exe" [2004-12-08 184320]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-06-04 286720]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-02-12 98304]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-11-01 290816]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-18 110592]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2004-12-08 790528]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-12 185872]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2004-06-04 1400944]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-03 148888]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2005-11-16 88209]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-3-19 113664]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-11-29 569405]
DVD Check.lnk - c:\program files\InterVideo\DVD Check\DVDCheck.exe [2009-2-12 184320]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-5-12 73728]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [17/05/2009 07:52 م 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [17/05/2009 07:52 م 8320]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-03 c:\windows\Tasks\ABF600AF918DB5AF.job
- c:\docume~1\admini~1\applic~1\moreop~1\find tray bold.exe [2009-07-16 22:39]
2009-08-02 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 18:34]
2009-08-03 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 18:34]
2009-08-03 c:\windows\Tasks\User_Feed_Synchronization-{2655E4B6-771D-401C-B0B3-5DD3C8B70326}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 01:31]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Uniblue RegistryBooster 2 - c:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\gtpzis78.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2233703&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - 4shared Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sa/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2233703&SearchSource=2&q=
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\gtpzis78.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\FFExternalAlert.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-08-03 18:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????2?1?0?0??P???? ???B???????????????B? ??????
scanning hidden files ...
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1993962763-1275210071-1177238915-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,54,9a,ea,a7,81,43,e7,40,bc,ec,dd,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a4,8d,8f,00,05,71,6f,4d,84,03,a0,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,54,9a,ea,a7,81,43,e7,40,bc,ec,dd,\
[HKEY_USERS\S-1-5-21-1993962763-1275210071-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*]
@Class="Shell"
"Application"="vlc.exe"
[HKEY_USERS\S-1-5-21-1993962763-1275210071-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*\OpenWithList]
@Class="Shell"
"a"="realplay.exe"
"MRUList"="ba"
"b"="vlc.exe"
[HKEY_USERS\S-1-5-21-1993962763-1275210071-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*\OpenWithProgids]
"؟_auto_file"=hex(0):
[HKEY_LOCAL_MACHINE\software\Classes\.*]
@="؟_auto_file"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(620)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Ahead\InCD\InCDsrv.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\WIDCOMM\Bluetooth Software\BTStackServer.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\Apoint2K\ApntEx.exe
c:\program files\HPQ\shared\hpqwmi.exe
.
**************************************************************************
.
Completion time: 2009-08-03 18:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-03 15:54
Pre-Run: 9,791,938,560 bytes free
Post-Run: 9,689,165,824 bytes free
258 --- E O F --- 2009-07-31 23:09