ComboFix 09-09-13.04 - الشبكه 09/14/2009 0:22.1.2 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1256.966.1025.18.1919.1295 [GMT 3:00]
Running from: c:\users\الشبكه\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-51003140-4199384537-3980697693-500
c:\windows\system32\kakle.dll
c:\windows\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2009-08-13 to 2009-09-13 )))))))))))))))))))))))))))))))
.
2009-09-13 21:28 . 2009-09-13 21:29 -------- d-----w- c:\users\الشبكه\AppData\Local\temp
2009-09-13 21:28 . 2009-09-13 21:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-13 18:54 . 2009-09-13 18:54 -------- d-----w- c:\users\الشبكه\AppData\Roaming\Malwarebytes
2009-09-13 18:53 . 2009-09-10 11:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-13 18:53 . 2009-09-10 11:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-13 18:53 . 2009-09-13 20:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-13 18:53 . 2009-09-13 18:53 -------- d-----w- c:\programdata\Malwarebytes
2009-09-13 06:18 . 2009-09-13 06:18 -------- d-----w- c:\programdata\avp
2009-09-13 04:13 . 2009-09-13 04:13 -------- d-----w- c:\program files\Trend Micro
2009-09-12 23:04 . 2009-09-12 23:49 -------- d-----w- c:\users\الشبكه\AppData\Roaming\MessengerDiscovery 2
2009-09-12 23:03 . 2009-09-12 23:03 -------- d-----w- c:\program files\MessengerDiscovery 2
2009-09-09 16:26 . 2009-06-10 12:07 98816 ----a-w- c:\windows\system32\mfps.dll
2009-09-09 16:26 . 2009-06-10 12:07 2855424 ----a-w- c:\windows\system32\mf.dll
2009-09-09 16:26 . 2009-06-10 10:14 52736 ----a-w- c:\windows\system32\rrinstaller.exe
2009-09-09 16:26 . 2009-06-10 10:15 24576 ----a-w- c:\windows\system32\mfpmp.exe
2009-09-09 16:26 . 2009-06-10 08:50 2048 ----a-w- c:\windows\system32\mferror.dll
2009-09-09 16:22 . 2009-07-11 19:32 502272 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-09 16:22 . 2009-07-11 19:32 297984 ----a-w- c:\windows\system32\wlansec.dll
2009-09-09 16:22 . 2009-07-11 19:32 290816 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-09 16:22 . 2009-07-11 19:26 123904 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-09 16:22 . 2009-07-11 19:32 67584 ----a-w- c:\windows\system32\wlanhlp.dll
2009-09-09 16:22 . 2009-07-11 19:32 47104 ----a-w- c:\windows\system32\wlanapi.dll
2009-09-02 22:20 . 2009-08-29 03:41 1686528 ----a-w- c:\windows\system32\gameux.dll
2009-09-02 22:20 . 2009-08-29 03:40 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-02 22:20 . 2009-08-28 23:31 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-01 06:16 . 2009-09-01 06:16 -------- d-----w- c:\program files\Teorex
2009-08-26 22:18 . 2009-06-15 15:25 216576 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-26 22:18 . 2009-06-15 15:23 494592 ----a-w- c:\windows\system32\kerberos.dll
2009-08-26 22:18 . 2009-06-15 15:29 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-08-26 22:18 . 2009-06-15 15:23 1233920 ----a-w- c:\windows\system32\lsasrv.dll
2009-08-26 22:18 . 2009-06-15 18:12 408136 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-26 22:18 . 2009-06-15 15:28 272384 ----a-w- c:\windows\system32\schannel.dll
2009-08-26 22:18 . 2009-06-15 15:28 72704 ----a-w- c:\windows\system32\secur32.dll
2009-08-26 22:18 . 2009-06-15 13:10 7680 ----a-w- c:\windows\system32\lsass.exe
2009-08-26 00:02 . 2009-06-22 08:44 2048 ----a-w- c:\windows\system32\tzres.dll
2009-08-21 00:15 . 2008-06-20 01:17 97800 ----a-w- c:\windows\system32\infocardapi.dll
2009-08-21 00:15 . 2008-06-20 01:18 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-08-21 00:15 . 2008-06-20 01:18 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-08-21 00:15 . 2008-06-20 01:17 622080 ----a-w- c:\windows\system32\icardagt.exe
2009-08-21 00:15 . 2008-06-20 01:17 11264 ----a-w- c:\windows\system32\icardres.dll
2009-08-21 00:15 . 2008-06-20 01:18 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-08-21 00:15 . 2008-06-20 01:18 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2009-08-21 00:01 . 2008-07-27 18:00 96760 ----a-w- c:\windows\system32\dfshim.dll
2009-08-21 00:01 . 2008-07-27 18:00 282112 ----a-w- c:\windows\system32\mscoree.dll
2009-08-21 00:01 . 2008-07-27 18:00 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-08-21 00:01 . 2008-07-27 18:00 158720 ----a-w- c:\windows\system32\mscorier.dll
2009-08-21 00:01 . 2008-07-27 18:00 83968 ----a-w- c:\windows\system32\mscories.dll
2009-08-16 03:47 . 2007-06-27 02:21 1984512 ----a-w- c:\windows\system32\authui.dll
2009-08-16 03:47 . 2007-06-26 02:51 220160 ----a-w- c:\windows\system32\ntprint.dll
2009-08-16 03:47 . 2007-07-13 02:20 8138240 ----a-w- c:\windows\system32\ssBranded.scr
2009-08-16 03:47 . 2007-06-19 02:09 105984 ----a-w- c:\windows\system32\CscMig.dll
2009-08-16 03:47 . 2007-06-19 00:48 320000 ----a-w- c:\windows\system32\drivers\csc.sys
2009-08-16 03:47 . 2007-05-24 02:25 69632 ----a-w- c:\windows\system32\sendmail.dll
2009-08-16 03:47 . 2007-06-26 02:49 120320 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2009-08-16 03:47 . 2007-06-26 02:49 10240 ----a-w- c:\windows\system32\dhcpcmonitor.dll
2009-08-16 03:47 . 2007-06-26 02:21 61440 ----a-w- c:\windows\system32\ntprint.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-13 21:18 . 2006-12-05 05:25 81136 ----a-w- c:\windows\system32\perfc001.dat
2009-09-13 21:18 . 2006-12-05 05:25 460662 ----a-w- c:\windows\system32\perfh001.dat
2009-09-13 21:12 . 2009-08-02 19:37 12 ----a-w- c:\windows\bthservsdp.dat
2009-09-13 05:48 . 2009-08-02 20:22 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2009-09-11 03:38 . 2009-08-02 20:25 107547 ----a-w- c:\windows\system32\drivers\klin.dat
2009-09-11 03:38 . 2009-08-02 20:25 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-09-10 00:08 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-10 00:01 . 2009-08-02 19:53 -------- d-----w- c:\programdata\Microsoft Help
2009-08-14 23:49 . 2009-08-03 21:19 -------- d-----w- c:\programdata\Messenger Plus!
2009-08-14 17:16 . 2009-09-09 16:28 213592 ----a-w- c:\windows\system32\drivers\netio.sys
2009-08-14 16:42 . 2009-09-09 16:28 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-08-14 16:40 . 2009-09-09 16:28 103936 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:40 . 2009-09-09 16:28 15360 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:25 . 2009-09-09 16:28 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:25 . 2009-09-09 16:28 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:25 . 2009-09-09 16:28 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:25 . 2009-09-09 16:28 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:25 . 2009-09-09 16:28 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:25 . 2009-09-09 16:28 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:25 . 2009-09-09 16:28 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 14:24 . 2009-09-09 16:28 813568 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 14:23 . 2009-09-09 16:28 22016 ----a-w- c:\windows\system32\netiougc.exe
2009-08-14 00:04 . 2009-08-14 00:04 1585664 ----a-w- c:\windows\system32\setupapi.dll
2009-08-13 00:07 . 2009-08-13 00:07 71680 ----a-w- c:\windows\system32\atl.dll
2009-08-13 00:06 . 2009-08-13 00:06 156160 ----a-w- c:\windows\system32\wkssvc.dll
2009-08-13 00:06 . 2009-08-13 00:06 36352 ----a-w- c:\windows\system32\tsgqec.dll
2009-08-13 00:06 . 2009-08-13 00:06 1871872 ----a-w- c:\windows\system32\mstscax.dll
2009-08-13 00:06 . 2009-08-13 00:06 116736 ----a-w- c:\windows\system32\aaclient.dll
2009-08-13 00:05 . 2009-08-13 00:05 268800 ----a-w- c:\windows\system32\es.dll
2009-08-13 00:05 . 2009-08-13 00:05 88576 ----a-w- c:\windows\system32\avifil32.dll
2009-08-13 00:05 . 2009-08-13 00:05 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-08-13 00:05 . 2009-08-13 00:05 65024 ----a-w- c:\windows\system32\avicap32.dll
2009-08-13 00:05 . 2009-08-13 00:05 31232 ----a-w- c:\windows\system32\msvidc32.dll
2009-08-13 00:05 . 2009-08-13 00:05 12800 ----a-w- c:\windows\system32\msrle32.dll
2009-08-13 00:05 . 2009-08-13 00:05 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-08-13 00:04 . 2009-08-13 00:04 33280 ----a-w- c:\windows\system32\slwmi.dll
2009-08-13 00:04 . 2009-08-13 00:04 268288 ----a-w- c:\windows\system32\mcbuilder.exe
2009-08-13 00:04 . 2009-08-13 00:04 223232 ----a-w- c:\windows\system32\SLC.dll
2009-08-13 00:04 . 2009-08-13 00:04 57856 ----a-w- c:\windows\system32\SLUINotify.dll
2009-08-13 00:04 . 2009-08-13 00:04 566784 ----a-w- c:\windows\system32\SLCommDlg.dll
2009-08-13 00:04 . 2009-08-13 00:04 351232 ----a-w- c:\windows\system32\SLUI.exe
2009-08-13 00:04 . 2009-08-13 00:04 186368 ----a-w- c:\windows\system32\SLLUA.exe
2009-08-13 00:04 . 2009-08-13 00:04 39936 ----a-w- c:\windows\system32\slcinst.dll
2009-08-13 00:04 . 2009-08-13 00:04 2605568 ----a-w- c:\windows\system32\SLsvc.exe
2009-08-13 00:03 . 2009-08-13 00:03 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2009-08-13 00:03 . 2009-08-13 00:03 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-08-13 00:03 . 2009-08-13 00:03 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-08-13 00:02 . 2009-08-13 00:02 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-08-11 20:25 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-08-11 20:25 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-08-11 20:25 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-08-11 19:15 . 2009-08-11 19:15 61440 ----a-w- c:\windows\system32\winipsec.dll
2009-08-11 19:15 . 2009-08-11 19:15 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2009-08-11 19:15 . 2009-08-11 19:15 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2009-08-11 19:15 . 2009-08-11 19:15 272896 ----a-w- c:\windows\system32\polstore.dll
2009-08-11 19:11 . 2009-08-11 19:11 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-08-11 19:11 . 2009-08-11 19:11 95232 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-08-11 19:11 . 2009-08-11 19:11 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-08-11 19:09 . 2009-08-11 19:09 1244672 ----a-w- c:\windows\system32\mcmde.dll
2009-08-11 19:09 . 2009-08-11 19:09 428032 ----a-w- c:\windows\system32\EncDec.dll
2009-08-11 19:09 . 2009-08-11 19:09 292352 ----a-w- c:\windows\system32\psisdecd.dll
2009-08-11 19:06 . 2009-08-11 19:06 87040 ----a-w- c:\windows\system32\msoert2.dll
2009-08-11 19:06 . 2009-08-11 19:06 39424 ----a-w- c:\windows\system32\ACCTRES.dll
2009-08-11 19:06 . 2009-08-11 19:06 205824 ----a-w- c:\windows\system32\msoeacct.dll
2009-08-11 19:04 . 2009-08-11 19:04 704000 ----a-w- c:\windows\system32\PhotoScreensaver.scr
2009-08-11 19:04 . 2009-08-11 19:04 356352 ----a-w- c:\windows\system32\wbem\wbemcomn.dll
2009-08-11 19:04 . 2009-08-11 19:04 24064 ----a-w- c:\windows\system32\wtsapi32.dll
2009-08-11 19:04 . 2009-08-11 19:04 20920 ----a-w- c:\windows\system32\drivers\compbatt.sys
2009-08-11 19:04 . 2009-08-11 19:04 258232 ----a-w- c:\windows\system32\drivers\acpi.sys
2009-08-11 19:04 . 2009-08-11 19:04 28344 ----a-w- c:\windows\system32\drivers\battc.sys
2009-08-11 19:04 . 2009-08-11 19:04 14208 ----a-w- c:\windows\system32\drivers\CmBatt.sys
2009-08-11 19:04 . 2009-08-11 19:04 542720 ----a-w- c:\windows\system32\sysmain.dll
2009-08-11 19:02 . 2009-08-11 19:02 194560 ----a-w- c:\windows\system32\WebClnt.dll
2009-08-11 19:02 . 2009-08-11 19:02 110080 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2009-08-11 19:01 . 2009-08-11 19:01 2028032 ----a-w- c:\windows\system32\win32k.sys
2009-08-11 18:59 . 2009-08-11 18:59 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-08-11 18:59 . 2009-08-11 18:59 156160 ----a-w- c:\windows\system32\t2embed.dll
2009-08-11 18:59 . 2009-08-11 18:59 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-08-11 18:59 . 2009-08-11 18:59 34304 ----a-w- c:\windows\system32\atmlib.dll
2009-08-11 18:59 . 2009-08-11 18:59 24064 ----a-w- c:\windows\system32\lpk.dll
2009-08-11 18:59 . 2009-08-11 18:59 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-08-11 18:56 . 2009-08-11 18:56 49664 ----a-w- c:\windows\system32\csrsrv.dll
2009-08-11 18:56 . 2009-08-11 18:56 376320 ----a-w- c:\windows\system32\winsrv.dll
2009-08-11 18:52 . 2009-08-11 18:52 376832 ----a-w- c:\windows\system32\winhttp.dll
2009-08-11 18:49 . 2009-08-11 18:49 297472 ----a-w- c:\windows\system32\gdi32.dll
2009-08-11 18:48 . 2009-08-11 18:48 1060920 ----a-w- c:\windows\system32\drivers\ntfs.sys
2009-08-11 18:48 . 2009-08-11 18:48 41984 ----a-w- c:\windows\system32\drivers\monitor.sys
2009-08-11 18:47 . 2009-08-11 18:47 211456 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-08-11 18:45 . 2009-08-11 18:45 374456 ----a-w- c:\windows\system32\mcupdate_GenuineIntel.dll
2009-08-11 18:44 . 2009-08-11 18:44 500736 ----a-w- c:\windows\system32\msdtcprx.dll
2009-08-11 18:44 . 2009-08-11 18:44 30208 ----a-w- c:\windows\system32\xolehlp.dll
2009-08-11 18:43 . 2009-08-11 18:43 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2009-08-11 18:41 . 2009-08-11 18:41 1194496 ----a-w- c:\windows\system32\msxml3.dll
2009-08-11 18:41 . 2009-08-11 18:41 2048 ----a-w- c:\windows\system32\msxml3r.dll
2009-08-11 18:40 . 2009-08-11 18:40 414208 ----a-w- c:\windows\system32\msscp.dll
2009-08-11 18:38 . 2009-08-11 18:38 356864 ----a-w- c:\windows\system32\MediaMetadataHandler.dll
2009-08-11 18:37 . 2009-08-11 18:37 392192 ----a-w- c:\windows\system32\FirewallAPI.dll
2009-08-11 18:37 . 2009-08-11 18:37 63488 ----a-w- c:\windows\system32\drivers\mpsdrv.sys
2009-08-11 18:37 . 2009-08-11 18:37 86016 ----a-w- c:\windows\system32\icfupgd.dll
2009-08-11 18:37 . 2009-08-11 18:37 396800 ----a-w- c:\windows\system32\MPSSVC.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-08-11 1232896]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-03 148888]
"MSConfig"="c:\windows\system32\msconfig.exe" [2006-11-02 222208]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-8-3 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DCADA4E1-9C28-41D8-B188-74B73C371425}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{FC2C6AC2-B250-4448-A838-48BAA13BB21F}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{85B9E947-B680-4A52-B185-1DCF35F60093}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{90F9F40B-E5E3-4704-8041-FE447A738D9F}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EC093C3E-CCB4-4C92-B379-B1F1764DD1A2}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [15/12/08 08:41 م 33808]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [15/05/09 06:50 م 21008]
R3 Atc002;NDIS Miniport Driver for Attansic L2 Fast Ethernet Controller;c:\windows\System32\drivers\L260x86.sys [02/08/09 10:49 م 25600]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\System32\drivers\klmouflt.sys [16/05/09 08:59 م 19472]
R3 RTL8187;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\System32\drivers\RTL8187.sys [03/08/09 05:59 م 205312]
S0 OemBiosDevice;Royalty OEM Bios Extension;c:\windows\System32\drivers\royal.sys [02/08/09 10:23 م 240128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-09-14 00:29
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\TEMP\TMP0000004ED64096DE551A713D 524288 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.032"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.arw"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.bay"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.bmp"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.cr2"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.crw"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.cs1"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.dcr"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.dcx"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.dib"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.dng"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.emf"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.erf"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.fff"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.gif"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.hdr"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jfif"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jif"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jpe"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jpeg"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.jpg"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.kdc"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.mef"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.mos"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.mrw"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.nef"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.orf"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pcx"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pef"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.pic"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.png"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.raf"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.raw"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.rle"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.sr2"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.srf"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.tga"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.thm"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.tif"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.tiff"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v11o\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.v11o"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v11p\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.v11p"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v11pf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.v11pf"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.wbm"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.wbmp"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.wmf"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.xif"
[HKEY_USERS\S-1-5-21-2556992916-553650739-4180413998-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Photo Manager 2009.xmp"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2009-09-13 0:30
ComboFix-quarantined-files.txt 2009-09-13 21:30
Pre-Run: 34,975,506,432 bytes free
Post-Run: 34,840,993,792 bytes free
394 --- E O F --- 2009-09-10 17:45