تقرير الأداة الثانية
وجزاك الله خيرا عنى
ComboFix 09-03-04.01 - XPPRESP3 2009-03-06 21:57:32.1 - NTFSx86
Running from: c:\documents and settings\XPPRESP3\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\XPPRESP3\Application Data\addon.dat
c:\documents and settings\XPPRESP3\Application Data\addons.dat
c:\program files\Bifrost
c:\program files\bifrost\klog.dat
c:\program files\Bifrost\logg.dat
c:\windows\system32\drivers\npf.sys
c:\windows\system32\packet.dll
c:\windows\system32\pthreadGC2.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
D:\resycled
E:\resycled
F:\resycled
G:\resycled
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-02-06 to 2009-03-06 )))))))))))))))))))))))))))))))
.
2009-03-04 21:34 . 2009-03-04 21:34 <DIR> d--h----- c:\windows\system32\GroupPolicy
2009-03-04 18:52 . 2009-03-05 06:39 101,287 --a------ c:\windows\system32\drivers\klin.dat
2009-03-04 18:52 . 2009-03-05 06:39 89,601 --a------ c:\windows\system32\drivers\klick.dat
2009-03-04 18:50 . 2009-03-04 18:50 <DIR> d-------- c:\program files\Kaspersky Lab
2009-03-04 18:50 . 2009-03-06 22:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-03-04 17:57 . 2009-03-06 21:27 <DIR> d-------- c:\windows\system32\CatRoot2
2009-03-02 19:52 . 2009-03-02 19:52 <DIR> d-------- c:\program files\ffdshow
2009-03-02 19:52 . 2008-02-15 19:13 7,680 --a------ c:\windows\system32\ff_vfw.dll
2009-03-02 19:52 . 2008-02-15 19:13 547 --a------ c:\windows\system32\ff_vfw.dll.manifest
2009-03-02 19:49 . 2009-03-02 19:49 <DIR> d-------- c:\documents and settings\XPPRESP3\Application Data\Media Player Classic
2009-03-02 19:46 . 2009-03-02 19:46 <DIR> d-------- c:\program files\Common Files\Real
2009-03-02 19:46 . 2009-03-02 19:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2009-03-01 19:35 . 2009-03-01 19:35 54,156 --ah----- c:\windows\QTFont.qfn
2009-03-01 19:35 . 2009-03-01 19:35 1,409 --a------ c:\windows\QTFont.for
2009-03-01 09:34 . 2009-03-01 09:34 <DIR> d-------- c:\windows\Sun
2009-02-28 20:47 . 2009-02-28 20:47 <DIR> d-------- c:\documents and settings\XPPRESP3\Application Data\Nero
2009-02-28 20:46 . 2009-02-28 20:46 <DIR> d-------- c:\program files\Nero
2009-02-28 14:16 . 2009-03-02 14:04 <DIR> d-------- c:\program files\VVSN
2009-02-28 14:16 . 2009-02-28 14:18 <DIR> d-------- c:\program files\Bit Lord 1.1
2009-02-27 12:18 . 2002-02-18 10:22 139,536 --a------ c:\windows\system32\javaee.dll
2009-02-27 10:17 . 2009-03-02 20:31 <DIR> d-------- C:\Downloads
2009-02-14 19:30 . 2009-02-14 19:30 2,560 --a------ c:\windows\_MSRSTRT.EXE
2009-02-14 12:32 . 2009-02-14 19:29 1,442 --a------ c:\windows\EXTRADNS.INI
2009-02-12 20:02 . 2009-03-04 18:02 23,392 --a------ c:\windows\system32\nscompat.tlb
2009-02-12 20:02 . 2009-03-04 18:02 16,832 --a------ c:\windows\system32\amcompat.tlb
2009-02-11 20:45 . 2009-02-11 20:45 <DIR> d--hs---- c:\documents and settings\XPPRESP3\IECompatCache
2009-02-11 20:44 . 2009-02-11 20:44 <DIR> d--hs---- c:\documents and settings\XPPRESP3\PrivacIE
2009-02-11 20:44 . 2009-02-11 20:44 <DIR> d--hs---- c:\documents and settings\XPPRESP3\IETldCache
2009-02-11 20:44 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-02-11 20:44 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-02-09 22:10 . 2009-03-02 16:40 <DIR> d-------- c:\windows\ie8updates
2009-02-09 22:10 . 2009-02-09 22:10 <DIR> d--h----- c:\windows\$hf_mig$
2009-02-09 22:08 . 2008-10-13 13:55 26,144 --a------ c:\windows\system32\spupdsvc.exe
2009-02-09 22:07 . 2004-08-04 18:00 81,920 --a------ c:\windows\system32\ieencode.dll
2009-02-09 22:07 . 2004-08-04 18:00 72,704 --a------ c:\windows\system32\plugin.ocx
2009-02-09 22:01 . 2009-01-11 07:00 79,360 -----c--- c:\windows\system32\dllcache\iecompat.dll
2009-02-08 19:14 . 2009-02-08 19:14 <DIR> d-------- c:\documents and settings\XPPRESP3\Application Data\VitySoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-06 20:09 3,429,920 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-06 20:06 49,028 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-06 20:06 114,208 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-03-06 20:06 11,780 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-03-06 19:59 --------- d-----w c:\documents and settings\XPPRESP3\Application Data\DMCache
2009-03-05 05:02 112,144 ----a-w c:\windows\system32\drivers\kl1.sys
2009-03-02 17:46 --------- d-----w c:\program files\Ringz Studio
2009-03-02 12:46 --------- d-----w c:\documents and settings\XPPRESP3\Application Data\AIMP
2009-02-17 11:51 --------- d-----w c:\program files\Internet Download Manager
2009-02-04 07:36 --------- d-----w c:\program files\Java
2009-01-30 22:14 --------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-01-30 20:39 --------- d-----w c:\program files\Microsoft Silverlight
2009-01-29 13:29 --------- d-----w c:\documents and settings\All Users\Application Data\TEMP
2009-01-29 13:28 --------- d-----w c:\documents and settings\XPPRESP3\Application Data\ImageBadger
2009-01-26 10:47 --------- d-----w c:\documents and settings\XPPRESP3\Application Data\IDM
2009-01-11 18:43 --------- d-----w c:\program files\USB Disk Security
2009-01-10 10:16 --------- d-----w c:\documents and settings\XPPRESP3\Application Data\TuneUp Software
2009-01-10 10:15 --------- d-----w c:\documents and settings\All Users\Application Data\TuneUp Software
2009-01-07 16:43 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-12-19 12:39 704 ----a-w C:\Dionakra.DAT
2008-12-08 11:41 499,712 -c--a-w c:\windows\system32\msvcp71.dll
2006-06-01 17:16 60,526 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2006-06-01 17:16 49,256 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2006-06-01 17:16 166,000 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
------- Sigcheck -------
2006-06-17 22:43 673792 296f36ff783ea520ff1c1acfacfb07f2 c:\windows\system32\wininet.dll
2006-06-17 22:43 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\XPize\Backup\wininet.dll
2008-06-20 12:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\SP2GDR\tcpip.sys
2008-06-20 12:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\SP2QFE\tcpip.sys
2008-06-20 13:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\SP3GDR\tcpip.sys
2008-06-20 13:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\SP3QFE\tcpip.sys
2005-07-13 03:07 360448 0601f83f6784c220ee302f03f702316e c:\windows\system32\drivers\tcpip.sys
2005-10-15 13:07 949760 17e3c975c6fe3e94cf760f10d91c2af3 c:\windows\explorer.exe
2007-06-13 12:23 1033216 97bd6515465659ff8f3b7be375b2ea87 c:\windows\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\SP2GDR\explorer.exe
2007-06-13 13:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 c:\windows\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\SP2QFE\explorer.exe
2005-10-15 13:07 1032192 45757077a47c68a603a79b03a1a836ab c:\windows\XPize\Backup\explorer.exe
2004-08-04 18:00 30208 de8fa9cf18f95341079c7e6a215c226a c:\windows\system32\ctfmon.exe
2004-08-04 18:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\XPize\Backup\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 30208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,32,\
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AntiArp 26_06_2006 By ابراهيم عادل]
--a------ 2007-04-07 15:09 32768 c:\documents and settings\XPPRESP3\Desktop\AntiArp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a--c--- 2004-08-04 18:00 30208 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NoCut]
--a------ 2007-09-15 01:16 95 c:\documents and settings\XPPRESP3\Desktop\NoCut.bat
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StormCodec_Helper]
--a------ 2006-11-26 20:30 97357 c:\program files\Ringz Studio\Storm Codec\StormSet.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
R2 Stormser;Stormser; [x]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-12-13 24592]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - HELPSVC
*Deregistered* - AFD
*Deregistered* - Alerter
*Deregistered* - ALG
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - AVP
*Deregistered* - Beep
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - Cdfs
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - Fastfat
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - FolderSize
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - ImapiService
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - kl1
*Deregistered* - KLIF
*Deregistered* - klim5
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RDPWD
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - Secdrv
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - swenum
*Deregistered* - Tcpip
*Deregistered* - TDTCP
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WudfServiceGroup REG_SZ hex(7):57,00,55,00,44,00,46,00,53,00,76,00,63,00,00,00,00,00
.
*******s of the 'Scheduled Tasks' folder
2009-02-27 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe []
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-Nokia.PCSync - c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe
MSConfigStartUp-TuneUp MemOptimizer - c:\program files\TuneUp Utilities 2007\MemOptimizer.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.eg/
mWindow Title = Microsoft Internet Explorer
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Download All Links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\docume~1\XPPRESP3\LOCALS~1\Temp\RarSFX0\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\docume~1\XPPRESP3\LOCALS~1\Temp\RarSFX0\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\docume~1\XPPRESP3\LOCALS~1\Temp\RarSFX0\IEGetVL.htm
TCP: {AE5B6B1E-4890-4698-BB9D-C398F8DC01ED} = 192.168.1.10,192.168.1.1
TCP: {AE842B84-4E3E-47A5-A15A-B92A20D083FB} = 192.168.1.10,192.168.1.1,127.0.0.1
DPF: Microsoft XML Parser for Java -
FF - ProfilePath - c:\documents and settings\XPPRESP3\Application Data\Mozilla\Firefox\Profiles\k6mvk2yr.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.eg/
FF - component: c:\documents and settings\XPPRESP3\Application Data\IDM\idmmzcc\components\idmmzcc.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{31513E58-F253-47ad-86DB-D5F21E905429}\components\mintray-9178506d-2005072516-trunk.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.******.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/*******/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/*******/searchconfig.properties");
.
.
------- File Associations -------
.
txtfile=c:\windows\notepad.exe %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-03-06 22:08:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{70e9c9b1-f15a-43d6-945e-7ce313a4713b}]
@Denied: (Full) (Everyone)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):b0,c9,24,8b,39,41,10,94,b4,56,1b,c8,25,00,b8,f3,a9,28,92,11,1d,
d3,7b,5d,05,cb,ca,6c,0d,be,2f,c9,b2,66,b1,ec,0d,35,14,18,00,00,00,00,00,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1012)
c:\windows\system32\klogon.dll
c:\windows\system32\cscui.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
c:\program files\FolderSize\FolderSizeSvc.exe
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
.
**************************************************************************
.
Completion time: 2009-03-06 22:13:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-06 20:13:40
Pre-Run: 1,517,719,552 bytes free
Post-Run: 2,496,729,088 bytes free
343