مشكور أخي الجنرال
وهذا هو نص التقرير تفضل
ComboFix 09-09-18.02 - zero one 09/20/2009 0:03.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1256.966.1025.18.1915.1129 [GMT 3:00]
Running from: c:\users\zero one\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Kaspersky Anti-Virus *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2365545147-1999384947-2466353664-500
c:\program files\SpeedBit Video Downloader\Toolbar\tbhelper.dll
c:\windows\system32\kakle.dll
.
((((((((((((((((((((((((( Files Created from 2009-08-19 to 2009-09-19 )))))))))))))))))))))))))))))))
.
2009-09-19 20:18 . 2009-09-19 20:18 -------- d-----w- c:\program files\Trend Micro
2009-09-16 13:58 . 2009-09-19 19:17 -------- d-----w- c:\users\zero one\Tracing
2009-09-16 13:05 . 2009-08-05 19:48 54632 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2009-09-16 13:05 . 2009-09-16 13:05 -------- dc----w- c:\windows\system32\DRVSTORE
2009-09-16 13:04 . 2009-09-16 13:04 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-09-16 13:03 . 2006-11-29 10:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-09-16 13:02 . 2009-09-16 13:02 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-09-16 12:59 . 2009-09-16 12:59 -------- d-----w- c:\program files\Microsoft
2009-09-16 12:59 . 2009-09-16 12:59 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-16 12:19 . 2009-09-16 12:19 -------- d-----w- c:\program files\Common Files\Windows Live
2009-09-10 18:58 . 2009-09-10 18:58 -------- d-----w- c:\program files\ImageBadger
2009-09-10 18:58 . 2009-09-10 18:58 -------- d-----w- c:\users\zero one\AppData\Roaming\ImageBadger
2009-09-09 12:47 . 2009-07-11 19:32 502272 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-09 12:47 . 2009-07-11 19:32 297984 ----a-w- c:\windows\system32\wlansec.dll
2009-09-09 12:47 . 2009-07-11 19:32 290816 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-09 12:47 . 2009-07-11 19:32 67584 ----a-w- c:\windows\system32\wlanhlp.dll
2009-09-09 12:47 . 2009-07-11 19:32 47104 ----a-w- c:\windows\system32\wlanapi.dll
2009-09-09 12:47 . 2009-07-11 19:26 123904 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-09 01:09 . 2009-09-09 01:09 -------- d-----w- c:\users\zero one\AppData\Roaming\Uniblue
2009-09-09 01:09 . 2009-09-09 01:09 -------- d-----w- c:\program files\Uniblue
2009-09-02 23:47 . 2009-09-02 23:49 -------- d-----w- c:\users\zero one\AppData\Local\MediaMonkey
2009-09-02 23:47 . 2009-09-02 23:49 -------- d-----w- c:\program files\MediaMonkey
2009-09-02 01:05 . 2009-08-29 03:41 1686528 ----a-w- c:\windows\system32\gameux.dll
2009-09-02 01:05 . 2009-08-29 03:40 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-02 01:05 . 2009-08-28 23:31 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-31 00:37 . 2009-09-02 23:26 -------- d-----w- c:\program files\mpegjoin
2009-08-26 23:27 . 2009-06-22 08:44 2048 ----a-w- c:\windows\system32\tzres.dll
2009-08-24 02:01 . 2009-06-15 15:25 216576 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-24 02:01 . 2009-06-15 15:23 494592 ----a-w- c:\windows\system32\kerberos.dll
2009-08-24 02:01 . 2009-06-15 18:12 408136 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-24 02:01 . 2009-06-15 15:29 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-08-24 02:01 . 2009-06-15 15:28 72704 ----a-w- c:\windows\system32\secur32.dll
2009-08-24 02:01 . 2009-06-15 15:28 272384 ----a-w- c:\windows\system32\schannel.dll
2009-08-24 02:01 . 2009-06-15 15:23 1233920 ----a-w- c:\windows\system32\lsasrv.dll
2009-08-24 02:01 . 2009-06-15 13:10 7680 ----a-w- c:\windows\system32\lsass.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-19 19:17 . 2009-07-07 08:29 -------- d-----w- c:\programdata\Kaspersky Lab
2009-09-19 19:17 . 2009-07-07 07:11 1356 ----a-w- c:\users\zero one\AppData\Local\d3d9caps.dat
2009-09-19 19:08 . 2009-07-07 08:29 4744 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-09-19 19:08 . 2009-07-07 08:29 458784 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-09-19 19:08 . 2009-07-07 08:29 3395552 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-09-19 19:08 . 2009-07-07 08:29 30768 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-09-19 19:08 . 2009-07-07 14:53 4132 ----a-w- c:\windows\bthservsdp.dat
2009-09-16 13:05 . 2009-07-07 09:02 -------- d-----w- c:\program files\Windows Live
2009-09-16 12:59 . 2009-07-07 09:03 -------- d-----w- c:\programdata\WindowsLiveInstaller
2009-09-11 01:35 . 2009-07-07 08:29 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-09-11 01:35 . 2009-07-07 08:29 107547 ----a-w- c:\windows\system32\drivers\klin.dat
2009-09-10 00:01 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-10 00:00 . 2009-07-07 07:39 -------- d-----w- c:\programdata\Microsoft Help
2009-08-14 17:16 . 2009-09-09 12:52 213592 ----a-w- c:\windows\system32\drivers\netio.sys
2009-08-14 16:42 . 2009-09-09 12:52 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-08-14 16:40 . 2009-09-09 12:52 103936 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:40 . 2009-09-09 12:52 15360 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:25 . 2009-09-09 12:52 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:25 . 2009-09-09 12:52 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:25 . 2009-09-09 12:52 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:25 . 2009-09-09 12:52 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:25 . 2009-09-09 12:52 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:25 . 2009-09-09 12:52 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:25 . 2009-09-09 12:52 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 14:24 . 2009-09-09 12:52 813568 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 14:23 . 2009-09-09 12:52 22016 ----a-w- c:\windows\system32\netiougc.exe
2009-08-02 01:34 . 2009-08-02 01:34 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-08-02 01:34 . 2009-07-07 07:12 115576 ----a-w- c:\users\zero one\AppData\Local\GDIPFONTCACHEV1.DAT
2009-08-02 01:22 . 2009-07-07 07:42 -------- d-----w- c:\program files\Microsoft Works
2009-08-01 19:27 . 2009-07-19 21:31 -------- d-----w- c:\program files\DivX
2009-08-01 04:13 . 2009-08-01 04:13 -------- d-----w- c:\users\zero one\AppData\Roaming\Media Player Classic
2009-08-01 03:56 . 2009-07-19 21:32 -------- d-----w- c:\program files\Google
2009-07-31 23:50 . 2009-07-31 23:47 -------- d-----w- c:\program files\IDA
2009-07-31 23:47 . 2009-07-31 23:47 -------- d-----w- c:\users\zero one\AppData\Roaming\Internet Download Accelerator
2009-07-31 22:41 . 2009-07-15 20:36 -------- d-----w- c:\program files\DAP
2009-07-31 22:40 . 2009-07-15 23:19 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2009-07-31 22:39 . 2009-07-15 20:36 -------- d-----w- c:\programdata\SpeedBit
2009-07-31 22:33 . 2009-07-31 22:33 -------- d-----w- c:\program files\Ask.com
2009-07-30 11:38 . 2009-07-30 11:38 -------- d-----w- c:\program files\Common Files\xing shared
2009-07-30 11:38 . 2009-07-07 15:49 -------- d-----w- c:\program files\Common Files\Real
2009-07-30 11:38 . 2009-07-30 11:38 -------- d-----w- c:\program files\Real
2009-07-30 11:15 . 2009-07-30 11:14 482336 ----a-w- c:\users\zero one\RealPlayer11GOLD.exe
2009-07-26 13:44 . 2009-07-26 13:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-21 21:52 . 2009-08-02 01:13 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-08-02 01:13 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-08-02 01:13 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-08-02 01:13 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-19 21:32 . 2009-07-19 21:32 56 --sh--r- c:\windows\system32\B542134524.sys
2009-07-19 21:32 . 2009-07-19 21:32 1890 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-07-17 14:52 . 2009-08-13 05:12 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-14 17:27 . 2009-07-14 17:26 4708336 ----a-w- c:\users\zero one\ikey.exe
2009-07-14 13:02 . 2009-08-13 05:12 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 13:01 . 2009-08-13 05:12 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-14 13:00 . 2009-08-13 05:12 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-14 11:11 . 2009-08-13 05:12 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-10 10:07 . 2009-07-10 10:07 306544 ----a-w- c:\windows\WLXPGSS.SCR
2009-07-09 00:19 . 2009-07-09 00:19 268800 ----a-w- c:\windows\system32\es.dll
2009-07-08 02:13 . 2009-07-08 02:13 61440 ----a-w- c:\windows\system32\winipsec.dll
2009-07-08 02:13 . 2009-07-08 02:13 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2009-07-08 02:13 . 2009-07-08 02:13 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2009-07-08 02:13 . 2009-07-08 02:13 272896 ----a-w- c:\windows\system32\polstore.dll
2009-07-08 02:11 . 2009-07-08 02:11 95232 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-07-08 02:11 . 2009-07-08 02:11 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-07-08 02:11 . 2009-07-08 02:11 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-07-08 02:11 . 2009-07-08 02:11 39424 ----a-w- c:\windows\system32\ACCTRES.dll
2009-07-08 02:11 . 2009-07-08 02:11 87040 ----a-w- c:\windows\system32\msoert2.dll
2009-07-08 02:11 . 2009-07-08 02:11 205824 ----a-w- c:\windows\system32\msoeacct.dll
2009-07-08 02:10 . 2009-07-08 02:10 704000 ----a-w- c:\windows\system32\PhotoScreensaver.scr
2009-07-08 02:10 . 2009-07-08 02:10 356352 ----a-w- c:\windows\system32\wbem\wbemcomn.dll
2009-07-08 02:10 . 2009-07-08 02:10 24064 ----a-w- c:\windows\system32\wtsapi32.dll
2009-07-08 02:10 . 2009-07-08 02:10 20920 ----a-w- c:\windows\system32\drivers\compbatt.sys
2009-07-08 02:10 . 2009-07-08 02:10 28344 ----a-w- c:\windows\system32\drivers\battc.sys
2009-07-08 02:10 . 2009-07-08 02:10 258232 ----a-w- c:\windows\system32\drivers\acpi.sys
2009-07-08 02:10 . 2009-07-08 02:10 14208 ----a-w- c:\windows\system32\drivers\CmBatt.sys
2009-07-08 02:09 . 2009-07-08 02:09 542720 ----a-w- c:\windows\system32\sysmain.dll
2009-07-08 02:09 . 2009-07-08 02:09 194560 ----a-w- c:\windows\system32\WebClnt.dll
2009-07-08 02:09 . 2009-07-08 02:09 110080 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2009-07-08 00:54 . 2009-07-08 00:54 2028032 ----a-w- c:\windows\system32\win32k.sys
2009-07-08 00:53 . 2009-07-08 00:53 49664 ----a-w- c:\windows\system32\csrsrv.dll
2009-07-08 00:53 . 2009-07-08 00:53 376320 ----a-w- c:\windows\system32\winsrv.dll
2009-07-08 00:51 . 2009-07-08 00:51 376832 ----a-w- c:\windows\system32\winhttp.dll
2009-07-08 00:50 . 2009-07-08 00:50 297472 ----a-w- c:\windows\system32\gdi32.dll
2009-07-08 00:49 . 2009-07-08 00:49 41984 ----a-w- c:\windows\system32\drivers\monitor.sys
2009-07-08 00:49 . 2009-07-08 00:49 1060920 ----a-w- c:\windows\system32\drivers\ntfs.sys
2009-07-08 00:48 . 2009-07-08 00:48 211456 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-07-08 00:48 . 2009-07-08 00:48 374456 ----a-w- c:\windows\system32\mcupdate_GenuineIntel.dll
2009-07-08 00:47 . 2009-07-08 00:47 500736 ----a-w- c:\windows\system32\msdtcprx.dll
2009-07-08 00:47 . 2009-07-08 00:47 30208 ----a-w- c:\windows\system32\xolehlp.dll
2009-07-08 00:45 . 2009-07-08 00:45 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2009-07-08 00:45 . 2009-07-08 00:45 1194496 ----a-w- c:\windows\system32\msxml3.dll
2009-07-08 00:45 . 2009-07-08 00:45 2048 ----a-w- c:\windows\system32\msxml3r.dll
2009-07-08 00:44 . 2009-07-08 00:44 414208 ----a-w- c:\windows\system32\msscp.dll
2009-07-08 00:43 . 2009-07-08 00:43 356864 ----a-w- c:\windows\system32\MediaMetadataHandler.dll
2009-07-08 00:43 . 2009-07-08 00:43 86016 ----a-w- c:\windows\system32\icfupgd.dll
2009-07-08 00:43 . 2009-07-08 00:43 63488 ----a-w- c:\windows\system32\drivers\mpsdrv.sys
2009-07-08 00:43 . 2009-07-08 00:43 396800 ----a-w- c:\windows\system32\MPSSVC.dll
2009-07-08 00:43 . 2009-07-08 00:43 392192 ----a-w- c:\windows\system32\FirewallAPI.dll
2009-07-08 00:43 . 2009-07-08 00:43 16896 ----a-w- c:\windows\system32\wfapigp.dll
2009-07-08 00:43 . 2009-07-08 00:43 61952 ----a-w- c:\windows\system32\cmifw.dll
2009-07-08 00:43 . 2009-07-08 00:43 23040 ----a-w- c:\windows\system32\drivers\tunnel.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-04-02 16:50 809864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-04-02 809864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-04-02 809864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-08 1232896]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-30 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2009-07-08 1006264]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-12-29 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-12-29 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-12-29 141848]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-07-21 208616]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-09-18 29696]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-09-29 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-07-30 198160]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-7-7 113664]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-7-7 118784]
«©م، ¢¬نïé Adobe Reader.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{7D92A1CB-2149-4E17-A5CB-306F36C73C9F}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{C7D9169B-9033-49CE-8EEC-779CD263DC90}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{422F0C29-EB6A-4B78-9145-34A4E7687A40}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{2C0D1B5C-132B-490F-9404-D9146AF774A2}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A4F6339E-3667-4C09-B46B-2244D712954E}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [29/01/08 05:29 م 33808]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [09/07/08 05:28 م 20496]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\System32\drivers\BthAvrcp.sys [24/08/07 07:34 م 15872]
S0 OemBiosDevice;Royalty OEM Bios Extension;c:\windows\System32\drivers\royal.sys [07/07/09 10:38 ص 240128]
S2 gupdate1ca125ce56413a;خدمة تحديث Google (gupdate1ca125ce56413a);c:\program files\Google\Update\GoogleUpdate.exe [01/08/09 06:56 ص 133104]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [16/09/09 04:05 م 54632]
S3 fsssvc;خدمة أمان العائلة في Windows Live;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/09 10:48 م 704864]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-01 03:56]
2009-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-01 03:56]
2009-09-19 c:\windows\Tasks\User_Feed_Synchronization-{EEE639EA-7F8C-4175-89FA-BA4688C5B426}.job
- c:\windows\system32\msfeedssync.exe [2009-08-02 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: Download ALL with IDA
IE: Download with IDA
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Internet Download Accelerator - c:\program files\IDA\ida.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-09-20 00:09
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-09-19 0:11
ComboFix-quarantined-files.txt 2009-09-19 21:10
Pre-Run: 112,448,303,104 bytes free
Post-Run: 112,738,074,624 bytes free
279 --- E O F --- 2009-09-18 00:26