هذا التقرير الثاني ،،، وجزاك الله خير على تعاونك
ComboFix 08-08-17.01 - SSC1 08/17/2008 22:03:32.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.521 [GMT 3:00]
Running from: F:\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\SSC1\UserData
C:\Documents and Settings\SSC1\UserData\index.dat
C:\Documents and Settings\SSC1\UserData\OHENS1A7\oWindowsUpdate[1].xml
C:\Documents and Settings\SSC1\UserData\WXYFCDQN\userDataXmlIsland[1].xml
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\url(2).dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2008-07-17 to 2008-08-17 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-17 19:05 720,928 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-08-17 19:05 4,592 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-08-17 19:05 288,104 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-17 19:05 24,404,000 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-17 18:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-17 18:56 --------- d-----w C:\Documents and Settings\SSC1\Application Data\cleaner
2008-08-17 10:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-16 21:53 --------- d-----w C:\Program Files\Nokia
2008-08-16 21:53 --------- d-----w C:\Documents and Settings\SSC1\Application Data\Nokia
2008-08-16 21:51 --------- d-----w C:\Documents and Settings\SSC1\Application Data\PC Suite
2008-08-16 21:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-08-16 21:42 --------- d-----w C:\Program Files\DIFX
2008-08-16 21:41 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-08-16 21:41 --------- d-----w C:\Program Files\Common Files\Nokia
2008-08-16 21:12 --------- d-----w C:\Program Files\Uniblue
2008-08-12 23:33 --------- d-----w C:\Program Files\Hide IP Platinum
2008-08-12 14:14 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-08-10 21:08 --------- d-----w C:\Program Files\The KMPlayer
2008-08-09 11:30 --------- d-----w C:\Program Files\Common Files\DirectX
2008-08-09 10:41 --------- d-----w C:\Program Files\GVR
2008-08-08 14:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-07 13:22 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-07 13:13 --------- d-----w C:\Program Files\Google
2008-08-07 12:15 --------- d-----w C:\Program Files\CCleaner
2008-08-07 11:17 --------- d-----w C:\Program Files\Samy Soft
2008-08-06 16:41 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-08-03 16:21 --------- d-----w C:\Program Files\Registry Compressor
2008-08-03 12:06 --------- d-----w C:\Program Files\Ashampoo
2008-08-03 11:57 --------- d-----w C:\Documents and Settings\SSC1\Application Data\Uniblue
2008-08-01 15:11 --------- d-----w C:\Program Files\Windows Live
2008-07-31 19:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-29 09:06 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-27 19:23 --------- d-----w C:\Program Files\Kaspersky Lab
2008-07-27 08:34 --------- d-----w C:\Program Files\Hotspot Shield
2008-07-27 08:23 --------- d-----w C:\Program Files\Java
2008-07-27 05:29 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-07-25 10:29 --------- d-----w C:\Program Files\Windows Desktop Search
2008-07-24 11:48 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-07-24 02:12 --------- d-----w C:\Program Files\Error Repair Professional
2008-07-23 12:25 --------- d-----w C:\Program Files\XoftSpySE
2008-07-23 11:28 --------- d-----w C:\Program Files\NoAdware5.0
2008-07-22 22:52 --------- d-----w C:\Documents and Settings\SSC1\Application Data\Windows Search
2008-07-15 09:20 --------- d-----w C:\Documents and Settings\SSC1\Application Data\Hide IP NG
2008-07-13 08:51 --------- d-----w C:\Program Files\IObit
2008-07-11 02:50 --------- d-----w C:\Program Files\Windows Defender
2008-07-10 23:35 --------- d-----w C:\Documents and Settings\SSC1\Application Data\Grisoft
2008-07-10 15:14 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-09 22:06 --------- d-----w C:\Program Files\VS Revo Group
2008-07-09 19:26 --------- d-----w C:\Program Files\Real_SC
2008-07-09 19:26 --------- d-----w C:\Program Files\QuickTime
2008-07-09 19:26 --------- d-----w C:\Program Files\mpegable
2008-07-09 19:26 --------- d-----w C:\Program Files\Fantasy Moon 3D Screensaver
2008-07-09 19:26 --------- d-----w C:\Program Files\FairStars Audio Converter
2008-07-09 19:26 --------- d-----w C:\Program Files\Drawing for Children
2008-07-09 19:26 --------- d-----w C:\Program Files\DivX
2008-07-09 19:26 --------- d-----w C:\Program Files\Ancient Castle 3D Screensaver
2008-07-09 19:26 --------- d-----w C:\Program Files\Abrosoft FantaMorph
2008-07-09 19:26 --------- d-----w C:\Program Files\3Planesoft Screensaver Manager
2008-07-09 16:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-07-08 22:18 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-07-07 23:19 --------- d-----w C:\Documents and Settings\SSC1\Application Data\Media Player Classic
2008-07-07 23:16 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-07-07 19:26 --------- d-----w C:\Program Files\Common Files\xing shared
2008-07-07 19:26 --------- d-----w C:\Program Files\Common Files\Real
2008-07-07 19:25 --------- d-----w C:\Program Files\Real
2008-07-04 23:11 --------- d-----w C:\Documents and Settings\SSC1\Application Data\Desktop Mechanic
2008-07-04 20:52 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-07-04 20:35 --------- d-----w C:\Program Files\MSBuild
2008-07-04 20:32 --------- d-----w C:\Program Files\Reference Assemblies
2008-07-04 16:26 --------- d-----w C:\Program Files\MSXML 4.0
2008-07-04 14:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-07-03 15:40 --------- d-----w C:\Documents and Settings\SSC1\Application Data\Apple Computer
2008-07-03 10:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-03 10:37 --------- d-----w C:\Program Files\Apple Software Update
2008-07-03 10:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-07-03 01:21 --------- d-----w C:\Program Files\Ozone
2008-07-03 00:08 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-07-03 00:08 172,032 ------w C:\WINDOWS\Setup1.exe
2008-07-01 16:50 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE
2008-07-01 16:50 --------- d-----w C:\Program Files\speed-bit
2008-07-01 16:30 --------- d-----w C:\Program Files\DAP
2008-06-23 14:55 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-23 14:55 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-06-23 14:53 --------- d-----w C:\Program Files\MSXML 6.0
2008-06-23 14:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nokia
2008-06-23 14:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-06-20 19:33 --------- d-----w C:\Program Files\IDA
2008-06-20 14:20 --------- d-----w C:\Documents and Settings\SSC1\Application Data\Internet Download Accelerator
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 23:51 --------- d-----w C:\Program Files\Paltalk Messenger
2008-06-19 23:51 --------- d-----w C:\Documents and Settings\SSC1\Application Data\Paltalk
2008-06-17 18:42 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-06-17 14:31 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-13 17:29 0 ----a-w C:\osy3.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 03:12 AM 15360]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [06/27/2006 04:21 PM 1449984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" [11/03/2007 04:50 AM 6731312]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [08/24/2007 07:00 AM 33648]
"NSLauncher"="C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe" [11/28/2006 01:12 AM 2658304]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 03:12 AM 15360]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [08/24/2007 03:18 AM 437160]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoFileAssociate"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
"NoFind"= 0 (0x0)
"NoRun"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^SSC1^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
--a------ 11/03/2007 04:50 AM 6731312 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 01/11/2008 10:16 PM 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
--a------ 03/16/2007 06:10 PM 1392640 C:\WINDOWS\system32\WLTRAY.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 04/14/2008 03:12 AM 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 12/13/2005 05:41 PM 77824 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 12/13/2005 05:45 PM 118784 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 12/13/2005 05:44 PM 98304 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
--a------ 12/28/2005 11:55 AM 667718 C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 04/14/2008 03:12 AM 1695232 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 10/18/2007 11:34 AM 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
--a------ 10/13/2006 11:31 AM 184320 C:\Program Files\Dell\MediaDirect\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 11/12/2007 05:24 PM 77824 C:\Program Files\Java\jre1.6.0\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 03/08/2006 12:48 PM 761947 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 07/07/2008 10:25 PM 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wcmdmgr]
--a------ 09/15/2000 09:13 AM 20480 C:\WINDOWS\wt\wcmdmgrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--a------ 03/24/2006 05:30 PM 282624 C:\WINDOWS\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\english\\setup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"C:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\WINDOWS\\system32\\dxdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP

eer Name Resolution Protocol (PNRP)
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [03/13/2008 05:38 AM]
S3 HssTrayService;Hotspot Shield Tray Service;C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE [07/24/2008 05:35 AM]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;C:\WINDOWS\system32\drivers\nmwcdnsu.sys [02/01/2008 03:17 PM]
S3 nmwcdnsuc;Nokia USB Flashing Generic;C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [02/01/2008 03:17 PM]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [04/14/2008 03:12 AM]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [04/14/2008 03:12 AM]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [04/14/2008 03:12 AM]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [04/14/2008 03:12 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
s of the 'Scheduled Tasks' folder
2008-08-17 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [11/03/2006 07:20 PM]
2008-08-03 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
2008-08-03 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\SSC1\Application Data\Mozilla\Firefox\Profiles\zr14mo9w.default\
FF -: plugin - C:\Program Files\DivX\DivX Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava11.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava12.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava13.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava14.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava32.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npoji610.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-17 22:07:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Common Files\PCSuite\Services\NclBTHandler.exe
.
**************************************************************************
.
Completion time: 08/17/2008 22:11:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-17 19:11:27
ComboFix2.txt 2008-07-10 23:56:21
Pre-Run: 41,302,417,408 bytes free
Post-Run: 41,224,572,928 bytes free
303 --- E O F --- 2008-08-17 10:27:29