thanks so much again.i think my pc is clean!!!
here`s is the combofix log
ComboFix 08-02-25.2 - sales 2008-02-26 14:20:24.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1253.1.1032.18.442 [GMT 2:00]
Running from: C:\Documents and Settings\sales\Επιφάνεια εργασίας\ComboFix.exe
Command switches used :: C:\Documents and Settings\sales\Επιφάνεια εργασίας\CFScript.txt
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
FILE ::
C:\Program Files\xInsIDE\xInsIDE.exe
C:\WINDOWS\mrofinu572.exe.tmp
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\dqhwgrpy.dll
C:\WINDOWS\system32\gopdibna.dll
C:\WINDOWS\system32\qaevvjuk.ini
C:\WINDOWS\system32\sgccvtft.dll
C:\WINDOWS\system32\sstqo.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\JavaCore
C:\Program Files\JavaCore\JavaCore.exe
C:\Program Files\JavaCore\UnInstall.exe
C:\Program Files\xInsIDE
C:\Program Files\xInsIDE\xInsIDE.exe
C:\VundoFix Backups
C:\VundoFix Backups\dqhwgrpy.dll.bad
C:\VundoFix Backups\gopdibna.dll.bad
C:\VundoFix Backups\jddptnpf.dll.bad
C:\VundoFix Backups\oojhhsgy.dll.bad
C:\VundoFix Backups\oqtss.ini.bad
C:\VundoFix Backups\oqtss.ini2.bad
C:\VundoFix Backups\sgccvtft.dll.bad
C:\VundoFix Backups\sstqo.dll.bad
C:\VundoFix Backups\yprgwhqd.ini.bad
C:\WINDOWS\mrofinu572.exe.tmp
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\qaevvjuk.ini
.
((((((((((((((((((((((((( Files Created from 2008-01-26 to 2008-02-26 )))))))))))))))))))))))))))))))
.
2008-02-25 12:02 . 2008-02-25 12:03 1,158 --a------ C:\WINDOWS\mozver.dat
2008-02-25 12:01 . 2008-02-25 12:01 0 --a------ C:\WINDOWS\nsreg.dat
2008-02-23 11:26 . 2008-02-23 11:26 132,608 --a------ C:\Program Files\VundoFix.exe
2008-02-23 11:17 . 2008-02-23 11:17 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-23 10:32 . 2008-02-23 10:32 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avg7
2008-02-22 14:07 . 2008-02-22 14:07 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-02-22 08:42 . 2008-02-23 10:52 70,896 --a------ C:\WINDOWS\BMdf404e2b.xml
2008-02-21 17:41 . 2008-02-25 14:05 <DIR> d-------- C:\Temp
2008-02-20 10:36 . 2008-02-20 13:34 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-02-20 10:29 . 2008-02-20 10:36 <DIR> d-------- C:\Documents and Settings\sales\Application Data\Ahead
2008-02-20 10:29 . 2008-02-20 10:29 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Ahead
2008-02-20 10:28 . 2008-02-20 10:28 <DIR> d-------- C:\Program Files\Nero
2008-02-20 10:28 . 2008-02-20 10:29 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-02-20 10:28 . 2008-02-20 10:28 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Nero
2008-02-20 09:10 . 2007-07-09 15:09 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-02-19 19:01 . 2008-02-22 14:21 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-02-19 12:51 . 2008-02-19 12:51 0 --a------ C:\WINDOWS\VPC32.INI
2008-02-19 11:22 . 2007-09-28 09:17 73,728 --a------ C:\WINDOWS\system32\TCDraftMon.dll
2008-02-19 11:18 . 2008-02-19 11:25 <DIR> d-------- C:\TAXIS
2008-02-19 11:18 . 2008-02-19 11:18 <DIR> d-------- C:\Φάκελος
2008-02-19 11:13 . 2008-02-19 11:13 <DIR> d-------- C:\Documents and Settings\sales\Application Data\AdobeUM
2008-02-19 11:07 . 2008-02-19 11:07 <DIR> d-------- C:\Program Files\TaxCode
2008-02-19 11:03 . 2008-02-18 10:25 2,585,872 --a------ C:\Program Files\WindowsInstaller-KB893803-v2-x86.exe
2008-02-19 11:00 . 2008-02-18 10:14 23,510,720 --a------ C:\Program Files\dotnetfx.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-07 01:06 665,088 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:40 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-11-29 15:58 3,778,560 ----a-w C:\Program Files\SetupTaxSoft_V2-8.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-04 06:45 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="sm56hlpr.exe" [2004-12-29 00:01 544768 C:\WINDOWS\sm56hlpr.exe]
"SiSPower"="SiSPower.dll" [2007-04-10 21:06 53248 C:\WINDOWS\system32\SiSPower.dll]
"SkyTel"="SkyTel.EXE" [2006-05-16 12:04 2879488 C:\WINDOWS\SkyTel.exe]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2002-07-30 11:35 77824]
"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 09:03 16125440 C:\WINDOWS\RTHDCPL.exe]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-09-04 06:45 15360]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\¨¦¨α££«\„΅΅ε¤©\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
Shortcut to Taxline2.lnk - C:\Program Files\TaxCode\TaxSoft\Taxline2.exe [2007-11-29 17:54:00 915968]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
Contents of the 'Scheduled Tasks' folder
"2008-02-26 06:36:56 C:\WINDOWS\Tasks\updater.exe.job"
- C:\Program Files\TaxCode\TaxSoft\updater.ex
- C:\Program Files\TaxCode\TaxSoft\.SYSTEM
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 14:21:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
Completion time: 2008-02-26 14:21:34
ComboFix-quarantined-files.txt 2008-02-26 12:21:32
ComboFix2.txt 2008-02-25 12:08:25
.
2008-02-22 12:26:46 --- E O F ---
and her`s the report from sdfix
[b]SDFix: Version 1.147 [/b]
Run by sales on Τρι 26/02/2008 at 03:01 μμ
Microsoft Windows XP [Έκδοση 5.1.2600]
Running From: C:\SDFix
[b]Checking Services [/b]:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
[b]Checking Files [/b]:
No Trojan Files Found
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 15:05:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions]
"\x2018\3\x393\3\x39d\3\xb3\3\x397\3\x391\3\x38f\3\xbd\3\x38f\3\x392\3 ?\x390\3\x391\3\x38f\3\x393\3\xb1\3\x391\3\x38c\3\x38f\3\xb3\3\xad\3\xb1\3\x392\3 ?R?A?S?"=str(7):"1\0"
"\x2018\3\x390\3\xb5\3\x395\3\x388\3\xb5\3\x2015\3\xb1\3\x392\3 ?\x390\3\xb1\3\x391\3\xac\3\xbb\3\xbb\3\xb7\3\xbb\3\xb7\3"=str(7):"1\0"
"\xa0\3\xb1\3\x38a\3\xad\3\x394\3\x38f\3 ?\x397\3\x391\3\x38f\3\xbd\3\x38f\3\x384\3\x389\3\xb1\3\xb3\3\x391\3\xac\3\x38c\3\x38c\3\xb1\3\x394\3\x38f\3\x392\3 ?M?i?n?i?p?o?r?t?"=str(7):"1\0002\0"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\\x201d\3\x389\3\xb1\3\x397\3\xb5\3\x2015\3\x391\3\x389\3\x393\3\xb7\3 ]
"EventMessageFile"="C:\WINDOWS\system32\sessmgr.exe"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\\xa5\3\x390\3\xb7\3\x391\3\xb5\3\x393\3\x2015\3\xb1\3 ]
"EventMessageFile"=str(2):"%SystemRoot%\System32\NTMSEVT.DLL"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions]
"\x2018\3\x393\3\x39d\3\xb3\3\x397\3\x391\3\x38f\3\xbd\3\x38f\3\x392\3 ?\x390\3\x391\3\x38f\3\x393\3\xb1\3\x391\3\x38c\3\x38f\3\xb3\3\xad\3\xb1\3\x392\3 ?R?A?S?"=str(7):"1\0"
"\x2018\3\x390\3\xb5\3\x395\3\x388\3\xb5\3\x2015\3\xb1\3\x392\3 ?\x390\3\xb1\3\x391\3\xac\3\xbb\3\xbb\3\xb7\3\xbb\3\xb7\3"=str(7):"1\0"
"\xa0\3\xb1\3\x38a\3\xad\3\x394\3\x38f\3 ?\x397\3\x391\3\x38f\3\xbd\3\x38f\3\x384\3\x389\3\xb1\3\xb3\3\x391\3\xac\3\x38c\3\x38c\3\xb1\3\x394\3\x38f\3\x392\3 ?M?i?n?i?p?o?r?t?"=str(7):"1\0002\0"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\System\\x201d\3\x389\3\xb1\3\x397\3\xb5\3\x2015\3\x391\3\x389\3\x393\3\xb7\3 ]
"EventMessageFile"="C:\WINDOWS\system32\sessmgr.exe"
"TypesSupported"=dword:00000007
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\System\\xa5\3\x390\3\xb7\3\x391\3\xb5\3\x393\3\x2015\3\xb1\3 ]
"EventMessageFile"=str(2):"%SystemRoot%\System32\NTMSEVT.DLL"
"TypesSupported"=dword:00000007
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes]
"\xa0\3\x391\3\x38f\3\xb5\3\x390\3\x389\3\xbb\3\xb5\3\xb3\3\x38c\3\xad\3\xbd\3\xb1\3 ?W?i?n?d?o?w?s?"="",,,,,,,,,,,,,""
"\x9a\3\x389\3\xbd\3\x38f\3\x39d\3\x38c\3\xb5\3\xbd\3\xb1\3 ?W?i?n?d?o?w?s?"=""C:\WINDOWS\Cursors\rainbow.ani,,C:\WINDOWS\Cursors\appstart.ani,C:\WINDOWS\Cursors\hourglas.ani,C:\WINDOWS\Cursors\cross.cur,,,,C:\WINDOWS\Cursors\sizens.ani,C:\WINDOWS\Cursors\sizewe.ani,C:\WINDOWS\Cursors\sizenwse.ani,C:\WINDOWS\Cursors\sizenesw.ani,,""
"\x2020\3\x393\3\x390\3\x391\3\x38f\3 ?3?\x201d\3"=""C:\WINDOWS\Cursors\3dwarro.cur,,C:\WINDOWS\Cursors\appstar3.ani,C:\WINDOWS\Cursors\hourgla3.ani,C:\WINDOWS\Cursors\cross.cur,,,C:\WINDOWS\Cursors\3dwno.cur,C:\WINDOWS\Cursors\3dwns.cur,C:\WINDOWS\Cursors\3dwwe.cur,C:\WINDOWS\Cursors\3dwnwse.cur,C:\WINDOWS\Cursors\3dwnesw.cur,C:\WINDOWS\Cursors\3dwmove.cur,""
"\xa7\3\xad\3\x391\3\x389\3\xb1\3 ?1?"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\handapst.ani,C:\WINDOWS\Cursors\hand.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\hnodrop.cur,C:\WINDOWS\Cursors\hns.cur,C:\WINDOWS\Cursors\hwe.cur,C:\WINDOWS\Cursors\hnwse.cur,C:\WINDOWS\Cursors\hnesw.cur,C:\WINDOWS\Cursors\hmove.cur,""
"\xa7\3\xad\3\x391\3\x389\3\xb1\3 ?2?"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\handapst.ani,C:\WINDOWS\Cursors\handwait.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\handno.ani,C:\WINDOWS\Cursors\handns.ani,C:\WINDOWS\Cursors\handwe.ani,C:\WINDOWS\Cursors\handnwse.ani,C:\WINDOWS\Cursors\handnesw.ani,C:\WINDOWS\Cursors\hmove.cur,""
"\x201d\3\xb5\3\x389\3\xbd\3\x39c\3\x393\3\xb1\3\x395\3\x391\3\x38f\3\x392\3"=""C:\WINDOWS\Cursors\3dgarro.cur,,C:\WINDOWS\Cursors\dinosaur.ani,C:\WINDOWS\Cursors\dinosau2.ani,C:\WINDOWS\Cursors\cross.cur,,,C:\WINDOWS\Cursors\banana.ani,C:\WINDOWS\Cursors\3dsns.cur,C:\WINDOWS\Cursors\3dgwe.cur,C:\WINDOWS\Cursors\3dsnwse.cur,C:\WINDOWS\Cursors\3dgnesw.cur,C:\WINDOWS\Cursors\3dsmove.cur,""
"\xa0\3\x391\3\x38f\3\xb7\3\xb3\3\x38f\3\x39d\3\x38c\3\xb5\3\xbd\3\x38f\3 ?\x38c\3\x38f\3\xbd\3\x394\3\xad\3\xbb\3\x38f\3"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\horse.ani,C:\WINDOWS\Cursors\barber.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\coin.ani,C:\WINDOWS\Cursors\3dgns.cur,C:\WINDOWS\Cursors\3dgwe.cur,C:\WINDOWS\Cursors\3dgnwse.cur,C:\WINDOWS\Cursors\3dgnesw.cur,C:\WINDOWS\Cursors\3dgmove.cur,""
"\xa3\3\x39d\3\xbd\3\x388\3\xb5\3\x393\3\xb7\3"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\drum.ani,C:\WINDOWS\Cursors\metronom.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\piano.ani,C:\WINDOWS\Cursors\hns.cur,C:\WINDOWS\Cursors\hwe.cur,C:\WINDOWS\Cursors\hnwse.cur,C:\WINDOWS\Cursors\hnesw.cur,C:\WINDOWS\Cursors\hmove.cur,""
"\x9c\3\xb5\3\xb3\3\xad\3\x388\3\x395\3\xbd\3\x393\3\xb7\3"=""C:\WINDOWS\Cursors\larrow.cur,,C:\WINDOWS\Cursors\lappstrt.cur,C:\WINDOWS\Cursors\lwait.cur,C:\WINDOWS\Cursors\lcross.cur,C:\WINDOWS\Cursors\libeam.cur,,C:\WINDOWS\Cursors\lnodrop.cur,C:\WINDOWS\Cursors\lns.cur,C:\WINDOWS\Cursors\lwe.cur,C:\WINDOWS\Cursors\lnwse.cur,C:\WINDOWS\Cursors\lnesw.cur,C:\WINDOWS\Cursors\lmove.cur,""
"\xa0\3\xb1\3\x391\3\xb1\3\xbb\3\xbb\3\xb1\3\xb3\3\xad\3\x392\3"=""C:\WINDOWS\Cursors\fillitup.ani,,C:\WINDOWS\Cursors\raindrop.ani,C:\WINDOWS\Cursors\counter.ani,C:\WINDOWS\Cursors\cross.cur,,,C:\WINDOWS\Cursors\wagtail.ani,C:\WINDOWS\Cursors\sizens.ani,C:\WINDOWS\Cursors\sizewe.ani,C:\WINDOWS\Cursors\sizenwse.ani,C:\WINDOWS\Cursors\sizenesw.ani,""
"\x9c\3\x390\3\x391\3\x38f\3\x39d\3\x394\3\xb6\3\x389\3\xbd\3\x38f\3 ?3?\x201d\3"=""C:\WINDOWS\Cursors\3dgarro.cur,,C:\WINDOWS\Cursors\appstar2.ani,C:\WINDOWS\Cursors\hourgla2.ani,C:\WINDOWS\Cursors\cross.cur,,,C:\WINDOWS\Cursors\3dgno.cur,C:\WINDOWS\Cursors\3dgns.cur,C:\WINDOWS\Cursors\3dgwe.cur,C:\WINDOWS\Cursors\3dgnwse.cur,C:\WINDOWS\Cursors\3dgnesw.cur,C:\WINDOWS\Cursors\3dgmove.cur,""
"\x9c\3\xb1\3\x39d\3\x391\3\xb1\3 ?W?i?n?d?o?w?s? ?"="C:\WINDOWS\cursors\arrow_r.cur,C:\WINDOWS\cursors\help_r.cur,C:\WINDOWS\cursors\wait_r.cur,C:\WINDOWS\cursors\busy_r.cur,C:\WINDOWS\cursors\cross_r.cur,C:\WINDOWS\cursors\beam_r.cur,C:\WINDOWS\cursors\pen_r.cur,C:\WINDOWS\cursors\no_r.cur,C:\WINDOWS\cursors\size4_r.cur,C:\WINDOWS\cursors\size3_r.cur,C:\WINDOWS\cursors\size2_r.cur,C:\WINDOWS\cursors\size1_r.cur,C:\WINDOWS\cursors\move_r.cur,C:\WINDOWS\cursors\up_r.cur"
"\x9c\3\xb1\3\x39d\3\x391\3\xb1\3 ?W?i?n?d?o?w?s? ?(?\x38c\3\xb5\3\xb3\3\xac\3\xbb\3\xb1\3)?"="C:\WINDOWS\cursors\arrow_rm.cur,C:\WINDOWS\cursors\help_rm.cur,C:\WINDOWS\cursors\wait_rm.cur,C:\WINDOWS\cursors\busy_rm.cur,C:\WINDOWS\cursors\cross_rm.cur,C:\WINDOWS\cursors\beam_rm.cur,C:\WINDOWS\cursors\pen_rm.cur,C:\WINDOWS\cursors\no_rm.cur,C:\WINDOWS\cursors\size4_rm.cur,C:\WINDOWS\cursors\size3_rm.cur,C:\WINDOWS\cursors\size2_rm.cur,C:\WINDOWS\cursors\size1_rm.cur,C:\WINDOWS\cursors\move_rm.cur,C:\WINDOWS\cursors\up_rm.cur"
"\x9c\3\xb1\3\x39d\3\x391\3\xb1\3 ?W?i?n?d?o?w?s? ?(?\x390\3\x38f\3\xbb\3\x39d\3 ?\x38c\3\xb5\3\xb3\3\xac\3\xbb\3\xb1\3)?"="C:\WINDOWS\cursors\arrow_rl.cur,C:\WINDOWS\cursors\help_rl.cur,C:\WINDOWS\cursors\wait_rl.cur,C:\WINDOWS\cursors\busy_rl.cur,C:\WINDOWS\cursors\cross_rl.cur,C:\WINDOWS\cursors\beam_rl.cur,C:\WINDOWS\cursors\pen_rl.cur,C:\WINDOWS\cursors\no_rl.cur,C:\WINDOWS\cursors\size4_rl.cur,C:\WINDOWS\cursors\size3_rl.cur,C:\WINDOWS\cursors\size2_rl.cur,C:\WINDOWS\cursors\size1_rl.cur,C:\WINDOWS\cursors\move_rl.cur,C:\WINDOWS\cursors\up_rl.cur"
"\x2018\3\xbd\3\x394\3\xb5\3\x393\3\x394\3\x391\3\xb1\3\x38c\3\x38c\3\xad\3\xbd\3\xb1\3 ?W?i?n?d?o?w?s?"="C:\WINDOWS\cursors\arrow_i.cur,C:\WINDOWS\cursors\help_i.cur,C:\WINDOWS\cursors\wait_i.cur,C:\WINDOWS\cursors\busy_i.cur,C:\WINDOWS\cursors\cross_i.cur,C:\WINDOWS\cursors\beam_i.cur,C:\WINDOWS\cursors\pen_i.cur,C:\WINDOWS\cursors\no_i.cur,C:\WINDOWS\cursors\size4_i.cur,C:\WINDOWS\cursors\size3_i.cur,C:\WINDOWS\cursors\size2_i.cur,C:\WINDOWS\cursors\size1_i.cur,C:\WINDOWS\cursors\move_i.cur,C:\WINDOWS\cursors\up_i.cur"
"\x2018\3\xbd\3\x394\3\xb5\3\x393\3\x394\3\x391\3\xb1\3\x38c\3\x38c\3\xad\3\xbd\3\xb1\3 ?W?i?n?d?o?w?s? ?(?\x38c\3\xb5\3\xb3\3\xac\3\xbb\3\xb1\3)?"="C:\WINDOWS\cursors\arrow_im.cur,C:\WINDOWS\cursors\help_im.cur,C:\WINDOWS\cursors\wait_im.cur,C:\WINDOWS\cursors\busy_im.cur,C:\WINDOWS\cursors\cross_im.cur,C:\WINDOWS\cursors\beam_im.cur,C:\WINDOWS\cursors\pen_im.cur,C:\WINDOWS\cursors\no_im.cur,C:\WINDOWS\cursors\size4_im.cur,C:\WINDOWS\cursors\size3_im.cur,C:\WINDOWS\cursors\size2_im.cur,C:\WINDOWS\cursors\size1_im.cur,C:\WINDOWS\cursors\move_im.cur,C:\WINDOWS\cursors\up_im.cur"
"\x2018\3\xbd\3\x394\3\xb5\3\x393\3\x394\3\x391\3\xb1\3\x38c\3\x38c\3\xad\3\xbd\3\xb1\3 ?W?i?n?d?o?w?s? ?(?\x390\3\x38f\3\xbb\3\x39d\3 ?\x38c\3\xb5\3\xb3\3\xac\3\xbb\3\xb1\3)?"="C:\WINDOWS\cursors\arrow_il.cur,C:\WINDOWS\cursors\help_il.cur,C:\WINDOWS\cursors\wait_il.cur,C:\WINDOWS\cursors\busy_il.cur,C:\WINDOWS\cursors\cross_il.cur,C:\WINDOWS\cursors\beam_il.cur,C:\WINDOWS\cursors\pen_il.cur,C:\WINDOWS\cursors\no_il.cur,C:\WINDOWS\cursors\size4_il.cur,C:\WINDOWS\cursors\size3_il.cur,C:\WINDOWS\cursors\size2_il.cur,C:\WINDOWS\cursors\size1_il.cur,C:\WINDOWS\cursors\move_il.cur,C:\WINDOWS\cursors\up_il.cur"
"\xa4\3\x395\3\x390\3\x389\3\x38a\3\xac\3 ?W?i?n?d?o?w?s? ?(?\x38c\3\xb5\3\xb3\3\xac\3\xbb\3\xb1\3)?"="C:\WINDOWS\cursors\arrow_m.cur,C:\WINDOWS\cursors\help_m.cur,C:\WINDOWS\cursors\wait_m.cur,C:\WINDOWS\cursors\busy_m.cur,C:\WINDOWS\cursors\cross_m.cur,C:\WINDOWS\cursors\beam_m.cur,C:\WINDOWS\cursors\pen_m.cur,C:\WINDOWS\cursors\no_m.cur,C:\WINDOWS\cursors\size4_m.cur,C:\WINDOWS\cursors\size3_m.cur,C:\WINDOWS\cursors\size2_m.cur,C:\WINDOWS\cursors\size1_m.cur,C:\WINDOWS\cursors\move_m.cur,C:\WINDOWS\cursors\up_m.cur"
"\xa4\3\x395\3\x390\3\x389\3\x38a\3\xac\3 ?W?i?n?d?o?w?s? ?(?\x390\3\x38f\3\xbb\3\x39d\3 ?\x38c\3\xb5\3\xb3\3\xac\3\xbb\3\xb1\3)?"="C:\WINDOWS\cursors\arrow_l.cur,C:\WINDOWS\cursors\help_l.cur,C:\WINDOWS\cursors\wait_l.cur,C:\WINDOWS\cursors\busy_l.cur,C:\WINDOWS\cursors\cross_l.cur,C:\WINDOWS\cursors\beam_l.cur,C:\WINDOWS\cursors\pen_l.cur,C:\WINDOWS\cursors\no_l.cur,C:\WINDOWS\cursors\size4_l.cur,C:\WINDOWS\cursors\size3_l.cur,C:\WINDOWS\cursors\size2_l.cur,C:\WINDOWS\cursors\size1_l.cur,C:\WINDOWS\cursors\move_l.cur,C:\WINDOWS\cursors\up_l.cur"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\\x9a\3\xb1\3\x394\3\xac\3\x391\3\xb3\3\xb7\3\x393\3\xb7\3 ]
@="{67cf8cbd-e5c0-44f7-9de5-e1d599d626d8}"
"Description"="\x391\x3c5\x3c4\x3ac \x3c4\x3b1 \x3b1\x3c1\x3c7\x3b5\x3af\x3b1 \x3b5\x3af\x3bd\x3b1\x3b9 \x3b1\x3c0\x3b1\x3c1\x3b1\x3af\x3c4\x3b7\x3c4\x3b1, \x3b5\x3ac\x3bd \x3b8\x3ad\x3bb\x3b5\x3c4\x3b5 \x3bd\x3b1 \x3ba\x3b1\x3c4\x3b1\x3c1\x3b3\x3ae\x3c3\x3b5\x3c4\x3b5 \x3c4\x3b7\x3bd \x3b5\x3b3\x3ba\x3b1\x3c4\x3ac\x3c3\x3c4\x3b1\x3c3\x3b7 \x3b1\x3c5\x3c4\x3ae\x3c2 \x3c4\x3b7\x3c2 \x3ad\x3ba\x3b4\x3bf\x3c3\x3b7\x3c2 \x3c4\x3c9\x3bd Windows \x3ba\x3b1\x3b9 \x3bd\x3b1 \x3b5\x3c0\x3b9\x3c3\x3c4\x3c1\x3ad\x3c8\x3b5\x3c4\x3b5 \x3c3\x3c4\x3bf \x3c0\x3c1\x3bf\x3b7\x3b3\x3bf\x3cd\x3bc\x3b5\x3bd\x3bf \x3bb\x3b5\x3b9\x3c4\x3bf\x3c5\x3c1\x3b3\x3b9\x3ba\x3cc \x3c3\x3b1\x3c2 \x3c3\x3cd\x3c3\x3c4\x3b7\x3bc\x3b1."
"Display"="\x391\x3bd\x3c4\x3af\x3b3\x3c1\x3b1\x3c6\x3b1 \x3b1\x3c3\x3c6\x3b1\x3bb\x3b5\x3af\x3b1\x3c2 \x3b3\x3b9\x3b1 \x3c0\x3c1\x3bf\x3b7\x3b3\x3bf\x3cd\x3bc\x3b5\x3bd\x3bf \x3bb\x3b5\x3b9\x3c4\x3bf\x3c5\x3c1\x3b3\x3b9\x3ba\x3cc \x3c3\x3cd\x3c3\x3c4\x3b7\x3bc\x3b1"
"IconPath"=str(2):"%SystemRoot%\system32\osuninst.EXE,0"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets\Volume Control\Realtek HD Audio output\\x9a\3\xb5\3\xbd\3\x394\3\x391\3\x389\3\x38a\3\xae\3 ]
"LineStates"=hex:00,00,00,00,9a,03,b5,03,bd,03,c4,03,c1,03,b9,03,ba,03,ae,03,20,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\\xa3\3\x395\3\xbd\3\x384\3\xad\3\x393\3\xb5\3\x389\3\x392\3]
"Order"=hex:08,00,00,00,02,00,00,00,9c,01,00,00,01,00,00,00,04,00,00,00,56,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x2019\3\x38f\3\xb7\3\x388\3\xae\3\x38c\3\xb1\3\x394\3\xb1\3]
"Order"=hex:08,00,00,00,02,00,00,00,3a,0a,00,00,01,00,00,00,0f,00,00,00,2c,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x2019\3\x38f\3\xb7\3\x388\3\xae\3\x38c\3\xb1\3\x394\3\xb1\3\\x201c\3\x389\3\xb1\3 ]
"Order"=hex:08,00,00,00,02,00,00,00,d0,02,00,00,01,00,00,00,04,00,00,00,c0,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x2019\3\x38f\3\xb7\3\x388\3\xae\3\x38c\3\xb1\3\x394\3\xb1\3\\x201d\3\x389\3\xb1\3\x393\3\x38a\3\xad\3\x384\3\xb1\3\x393\3\xb7\3]
"Order"=hex:08,00,00,00,02,00,00,00,c0,01,00,00,01,00,00,00,03,00,00,00,92,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x2019\3\x38f\3\xb7\3\x388\3\xae\3\x38c\3\xb1\3\x394\3\xb1\3\\x2022\3\x390\3\x389\3\x38a\3\x38f\3\x389\3\xbd\3\x399\3\xbd\3\x2015\3\xb5\3\x392\3]
"Order"=hex:08,00,00,00,02,00,00,00,a0,04,00,00,01,00,00,00,06,00,00,00,98,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x2019\3\x38f\3\xb7\3\x388\3\xae\3\x38c\3\xb1\3\x394\3\xb1\3\\x2022\3\x391\3\xb3\3\xb1\3\xbb\3\xb5\3\x2015\3\xb1\3 ]
"Order"=hex:08,00,00,00,02,00,00,00,92,05,00,00,01,00,00,00,08,00,00,00,a4,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\x2022\3\x38a\3\x38a\3\x2015\3\xbd\3\xb7\3\x393\3\xb7\3]
"Order"=hex:08,00,00,00,02,00,00,00,3a,01,00,00,01,00,00,00,02,00,00,00,9c,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\xa0\3\xb1\3\x389\3\x397\3\xbd\3\x2015\3\x384\3\x389\3\xb1\3]
"Order"=hex:08,00,00,00,02,00,00,00,4e,07,00,00,01,00,00,00,0b,00,00,00,c2,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\GrpConv\MapGroups]
"\xa0\3\xb1\3\x389\3\x397\3\xbd\3\x2015\3\x384\3\x389\3\xb1\3"="\x392\x3bf\x3b7\x3b8\x3ae\x3bc\x3b1\x3c4\x3b1\\x3a0\x3b1\x3b9\x3c7\x3bd\x3af\x3b4\x3b9\x3b1"
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[b]Remaining Files [/b]:
[b]Files with Hidden Attributes [/b]:
Thu 23 Aug 2007 205,312 A..H. --- "C:\Documents and Settings\sales\’ β¨α £¦¬\”α΅Ά¦\”‹„‘ €€‚‚„€‘\~WRL0002.tmp"
Tue 10 Aug 1999 263,184 A..H. --- "C:\Documents and Settings\sales\’ β¨α £¦¬\”α΅Ά¦\”‹„‘ €€‚‚„€‘\~WRL3806.tmp"
Tue 31 Oct 2006 826,880 A..H. --- "C:\Documents and Settings\sales\’ β¨α £¦¬\”α΅Ά¦\‘”„‘ ANA—‘‹—\~WRL1442.tmp"
Tue 8 Nov 2005 264,192 A..H. --- "C:\Documents and Settings\sales\’ β¨α £¦¬\”α΅Ά¦\‘”„‘ PC\~WRL0004.tmp"
[b]Finished![/b]