ComboFix 09-11-09.02 - Administrator 11/11/2009 16:14.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.1014.375 [GMT 3:00]
Running from: c:\documents and settings\Administrator\سطح المكتب\ComboFix.exe
AV: برنامج Kaspersky لأمان الإنترنت *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: برنامج Kaspersky لأمان الإنترنت *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-10-11 to 2009-11-11 )))))))))))))))))))))))))))))))
.
2009-11-11 11:05 . 2009-11-11 11:05 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-11 10:25 . 2009-11-11 10:25 -------- d-----w- c:\program files\Doblon
2009-11-11 09:37 . 2003-03-19 02:05 89088 ----a-w- c:\windows\system32\ATL71.DLL
2009-11-11 09:37 . 2009-11-11 09:59 -------- d-----w- c:\program files\Dart Karaoke Studio CDG
2009-11-11 08:48 . 2009-11-11 08:48 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AVNEX_Ltd._(CY)
2009-11-09 22:16 . 2009-11-09 22:16 13824 ----a-w- c:\windows\system32\drivers\splitcam.sys
2009-11-09 22:16 . 2009-11-09 22:21 -------- d-----w- c:\program files\SplitCam
2009-11-09 21:53 . 2009-11-09 21:53 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\RcIncidents
2009-11-09 21:16 . 2009-11-09 22:55 -------- d-----w- c:\documents and settings\Administrator\Application Data\Paltalk
2009-11-09 18:05 . 2009-11-09 18:05 -------- d-----w- c:\documents and settings\Administrator\AVTmpDir
2009-11-08 14:37 . 2009-11-08 14:37 -------- d-----w- c:\program files\Boilsoft Video Splitter
2009-11-08 11:25 . 2009-11-08 11:34 -------- d-----w- c:\program files\Orbitdownloader
2009-11-08 04:57 . 2009-11-08 04:57 371 ----a-w- C:\temp.dat
2009-11-08 04:19 . 2009-11-08 04:19 16 ----a-w- c:\windows\system32\RgsData.dat
2009-11-05 00:50 . 2009-11-05 00:50 62464 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\16\7ed2ca50-297be5b9-n\avutil-49.dll
2009-11-05 00:50 . 2009-11-05 00:50 516096 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\16\7ed2ca50-297be5b9-n\ivjni.dll
2009-11-05 00:50 . 2009-11-05 00:50 288361 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\16\7ed2ca50-297be5b9-n\libmp3lame-0.dll
2009-11-05 00:50 . 2009-11-05 00:50 1941504 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\16\7ed2ca50-297be5b9-n\avcodec-51.dll
2009-11-05 00:50 . 2009-11-05 00:50 107520 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\16\7ed2ca50-297be5b9-n\avformat-52.dll
2009-11-03 21:46 . 2009-11-03 21:46 152576 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-03 02:19 . 2009-11-06 16:22 -------- d-----w- c:\program files\FreeTime
2009-11-01 13:45 . 2009-11-01 13:45 7168 ----a-w- c:\documents and settings\Administrator\Application Data\Thinstall\{03DB79AE-7B40-44AA-81B2-FDEB7FA8C805}\4000001800002i\kasbr.exe
2009-10-31 20:57 . 2009-10-31 20:57 932368 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\profiles-1-6.dll
2009-10-31 20:57 . 2009-10-31 20:57 678416 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\content_interpreter-1-1.dll
2009-10-31 20:57 . 2009-10-31 20:57 604688 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\gsg-3-9.dll
2009-10-31 20:57 . 2009-10-31 20:57 522768 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\database-1-5.dll
2009-10-31 20:57 . 2009-10-31 20:57 1096208 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\filtration-4-6.dll
2009-10-31 20:56 . 2009-10-31 20:56 80400 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.459\mzvkbd3.dll
2009-10-31 20:56 . 2009-10-31 20:56 80400 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.459\mzvkbd.dll
2009-10-31 20:56 . 2009-10-31 20:56 264720 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.459\klwtbbho.dll
2009-10-31 20:56 . 2009-10-31 20:56 109072 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\mzvkbd3.dll
2009-10-31 20:56 . 2009-10-31 20:56 59920 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\mzvkbd.dll
2009-10-31 20:56 . 2009-10-31 20:56 264720 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\klwtbbho.dll
2009-10-31 20:31 . 2009-10-31 20:31 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-10-31 02:44 . 2009-10-31 02:44 28 ----a-w- c:\windows\kmcdfa2200.dat
2009-10-31 02:22 . 2009-10-31 02:22 7168 ----a-w- c:\documents and settings\Administrator\Application Data\Thinstall\{03DB79AE-7B40-44AA-81B2-FDEB7FA8C805}\4000008900002i\NOTEPAD.EXE
2009-10-23 22:17 . 2009-10-23 22:17 -------- d-----w- c:\windows\system32\wbem\Repository
2009-10-23 06:38 . 2009-10-23 06:40 -------- d-----w- c:\program files\Anyplace Control
2009-10-23 04:57 . 2009-10-23 05:59 -------- d-----w- c:\windows\Icon_Patcher
2009-10-16 17:56 . 2009-08-04 19:56 2190720 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-10-16 17:56 . 2009-08-04 17:26 2067584 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-10-16 17:56 . 2009-08-04 17:25 2025472 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-10-16 17:56 . 2009-08-04 17:26 2146816 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
1601-01-01 00:00 . 1601-01-01 00:00 -------- d-----w- c:\windows\LastGood.Tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-11 13:23 . 2009-02-24 19:03 -------- d-----w- c:\documents and settings\Administrator\Application Data\Orbit
2009-11-11 13:14 . 2009-08-22 18:25 -------- d-----w- c:\program files\Mobily Connect Card
2009-11-11 11:13 . 2009-02-24 19:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-11-11 11:09 . 2009-03-01 13:23 -------- d-----w- c:\program files\Windows Live
2009-11-11 08:41 . 2003-01-27 17:31 67636 ----a-w- c:\windows\system32\perfc001.dat
2009-11-11 08:41 . 2003-01-27 17:31 367146 ----a-w- c:\windows\system32\perfh001.dat
2009-11-09 22:16 . 2009-02-24 17:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-03 21:47 . 2009-08-15 21:26 -------- d-----w- c:\program files\Java
2009-10-31 20:56 . 2009-02-24 19:27 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-31 20:56 . 2009-02-24 19:27 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-31 20:28 . 2009-02-24 19:27 6408 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-10-31 20:28 . 2009-02-24 19:27 639008 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-10-31 20:28 . 2009-02-24 19:27 2451488 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-31 20:28 . 2009-02-24 19:27 23376 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-31 20:26 . 2009-02-24 18:22 -------- d-----w- c:\program files\Kaspersky Lab
2009-10-31 20:19 . 2009-02-24 18:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-10-31 17:38 . 2009-04-29 19:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nokia
2009-10-31 02:22 . 2009-07-18 03:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\Thinstall
2009-10-29 15:03 . 2009-02-24 19:03 -------- d-----w- c:\program files\mpegable
2009-10-23 17:28 . 2009-10-09 16:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\Hide IP NG
2009-10-11 01:17 . 2009-08-15 22:55 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-11 14:17 . 2004-08-03 21:55 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-03 21:55 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:55 . 2004-08-03 21:55 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-03 21:55 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-15 22:54 . 2009-08-15 22:54 152576 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-14 15:11 . 2004-08-03 21:46 1850496 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-12 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-12 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-12 138008]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-19 198160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"avp"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-07-03 303376]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-05-28 16132608]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2009-11-8 1719568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideFastUserSwitching"= 0 (0x0)
"HideShutdownScripts"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoVisualStyleChoice"= 0 (0x0)
"NoColorChoice"= 0 (0x0)
"NoSizeChoice"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeAnimation"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"RestrictRun"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"HideSCAVolume"= 0 (0x0)
"HideSCANetwork"= 0 (0x0)
"HideSCAPower"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoThemesTab"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"RestrictRun"= 0 (0x0)
"DisallowRun"= 0 (0x0)
"NoRecycleFiles"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"HideClock"= 0 (0x0)
"HideSCAVolume"= 0 (0x0)
"HideSCANetwork"= 0 (0x0)
"HideSCAPower"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= c:\documents and settings\Administrator\My Documents\My Pictures\الصور\جاهز من برنامج دمج الاصوات\ros55.gif
FriendlyName=
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= c:\documents and settings\Administrator\My Documents\My Pictures\389544298.jpg
FriendlyName=
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
Source= c:\documents and settings\Administrator\سطح المكتب\فيصل\هكر.JPG
FriendlyName=
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\3]
Source= c:\documents and settings\Administrator\My Documents\My Pictures\GeAs4ever.gif
FriendlyName=
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\4]
Source= c:\documents and settings\Administrator\My Documents\My Pictures\الصور\صور ورود\08111910443136305e42.gif
FriendlyName=
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^قائمة ابدأ^البرامج^بدء التشغيل^AMSN.lnk]
path=c:\documents and settings\Administrator\قائمة ابدأ\البرامج\بدء التشغيل\AMSN.lnk
backup=c:\windows\pss\AMSN.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Bluetooth.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\Program Files
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\program files\dfjdkjfdkjfldjf
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\program files\dfjdkjfdkjfldjf\dfjdkjfdkjfldjf
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*

isabled

xpsp2res.dll,-22009
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 05:29 م 33808]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 05:06 م 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16/05/2009 08:59 م 19472]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [13/12/2006 12:00 م 19072]
S3 SliceDisk5;SliceDisk5;\??\c:\program files\A-FF Find and Mount\slicedisk.sys --> c:\program files\A-FF Find and Mount\slicedisk.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-11-11 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-11-11 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-11-11 c:\windows\Tasks\User_Feed_Synchronization-{D8A38463-0283-4887-8881-1372BE7C5C01}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 01:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = about:blank
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: Microsoft XML Parser for Java -
DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} - hxxp://98.126.42.42/ReadUid.CAB
DPF: {C171FF59-8C55-4796-A398-4F5D02B4C763} - hxxp://76.76.24.112/saudi1999/talks3n.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs7h2w57.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sa/
FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - component: c:\program files\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
.
------- File Associations -------
.
txtfile=c:\windows\notepad.exe %1
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-webcammorpher - c:\program files\AV VCS 3.0\WebCamCore.exe
AddRemove-HijackThis - c:\documents and settings\Administrator\سطح المكتب\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-11-11 16:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1757981266-1606980848-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c2,d5,f0,43,ac,e3,18,4f,a3,41,80,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,66,ea,27,db,8c,04,45,4b,bb,52,dd,\
[HKEY_LOCAL_MACHINE\software\Classes\ *è(g**QL*ؤ)**P_*a*u*t*o*_*f*i*l*e*\shell]
@="open"
[HKEY_LOCAL_MACHINE\software\Classes\ *è(g**QL*ؤ)**P_*a*u*t*o*_*f*i*l*e*\shell\open]
@="&فتح"
[HKEY_LOCAL_MACHINE\software\Classes\ *è(g**QL*ؤ)**P_*a*u*t*o*_*f*i*l*e*\shell\open\command]
@="c:\\Program Files\\Windows Media Player\\wmplayer.exe /Open \"%L\""
[HKEY_LOCAL_MACHINE\software\Classes\ *è(g**QL*ؤ)**P_*a*u*t*o*_*f*i*l*e*\shell\play]
@="&تشغيل"
[HKEY_LOCAL_MACHINE\software\Classes\ *è(g**QL*ؤ)**P_*a*u*t*o*_*f*i*l*e*\shell\play\command]
@="c:\\Program Files\\Windows Media Player\\wmplayer.exe /Play \"%L\""
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5bdeef76-1688-42ad-98c8-7e73a5bd1067}]
@Denied: (Full) (Everyone)
"Model"=dword:00000087
"Therad"=dword:00000014
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):87,a2,dc,49,10,1d,f2,dc,36,67,2a,78,c7,a6,bc,70,74,10,5f,a6,43,
9e,3f,6f,88,ff,cb,81,d4,60,0e,9d,0a,8c,3f,0f,0e,f7,6a,27,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):ea,bb,f1,3e,01,37,77,bc,43,bf,01,f4,5d,ba,fd,ba,9b,3f,5d,37,dc,
ec,68,f0,97,77,56,22,e3,20,7e,fb,25,bc,00,e4,ca,c1,a5,d9,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{b98a3f9a-ef25-46d6-8f0f-f6565ccc4cb9}]
@Denied: (Full) (Everyone)
"Model"=dword:000000bd
"Therad"=dword:0000001a
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,98,07,ff,fc,5d,
df,1c,2f,3b,8a,0a,32,11,89,01,b5,99,1a,ae,a9,70,59,59,fd,5a,25,3d,54,a6,7c,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2504)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\agrsmsvc.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Orbitdownloader\orbitnet.exe
c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
c:\docume~1\ADMINI~1\LOCALS~1\Temp\RtkBtMnt.exe
c:\windows\system32\wscntfy.exe
c:\\?\c:\windows\system32\WBEM\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2009-11-11 16:26 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-11 13:26
Pre-Run: 27,868,553,216 bytes free
Post-Run: 27,957,542,912 bytes free
- - End Of File - - E2438E06919CBBBFBED19551368ED92E