سلام عليكم
تفضل اخي التقرير الأول
ComboFix 08-08-16.01 - hp 08/17/2008 7:26:20.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1256.1.1025.18.203 [GMT 3:00]
Running from: C:\Documents and Settings\hp\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\hp\Application Data\rhcnj2j0er2p
C:\Documents and Settings\hp\s\hp@facebook[1].txt
C:\Documents and Settings\hp\s\hp@cafe[2].txt
C:\Documents and Settings\hp\s\hp@mybrandcentral[1].txt
C:\Documents and Settings\hp\s\hp@www.elhawy[1].txt
C:\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My
C:\Program Files\rhcnj2j0er2p
C:\WINDOWS\system32\blphcjj2j0er2p.scr
C:\WINDOWS\system32\lphcjj2j0er2p.exe
C:\WINDOWS\system32\phcjj2j0er2p.bmp
C:\WINDOWS\system32\pphcjj2j0er2p.exe
C:\WINDOWS\system32\SkypeComm.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-17 to 2008-08-17 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-17 04:32 109,150 ----a-w C:\WINDOWS\system32\drivers\f160315c.sys
2008-08-17 04:30 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-08-17 04:30 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-08-17 04:30 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-17 04:30 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-17 04:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-17 04:15 96,645 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-08-17 04:15 87,941 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-08-17 00:54 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-08-17 00:52 --------- d-----w C:\Program Files\XoftSpySE
2008-08-16 23:44 --------- d-----w C:\Documents and Settings\hp\Application Data\InterVideo
2008-08-16 23:28 --------- d-----w C:\Program Files\Kaspersky Lab
2008-08-16 23:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-08-16 23:03 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-16 23:01 --------- d-----w C:\Program Files\Symantec
2008-08-16 23:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-16 23:00 --------- d-----w C:\Program Files\Norton AntiVirus
2008-08-16 22:52 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-08-13 02:01 --------- d-----w C:\Documents and Settings\hp\Application Data\Symantec
2008-08-06 01:52 --------- d-----w C:\Program Files\DivX
2008-08-03 18:39 --------- d-----w C:\Documents and Settings\NetworkService\Application Data\Yahoo!
2008-08-03 18:12 --------- d-----w C:\Program Files\Real_SC
2008-07-18 18:34 586,240 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-07-06 17:09 --------- d-----w C:\Documents and Settings\hp\Application Data\Leadertech
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" [11/19/2007 09:31 PM 57344]
[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 03:00 PM 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [10/18/2007 11:34 AM 5724184]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 07:24 PM 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [01/22/2005 09:36 PM 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [01/22/2005 09:31 PM 126976]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0\bin\jusched.exe" [10/24/2007 11:23 AM 36972]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [02/16/2005 11:11 PM 49152]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [02/04/2008 06:18 PM 185896]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [11/04/2004 09:40 PM 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [11/04/2004 09:38 PM 688218]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [10/13/2004 04:04 PM 278528]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [12/03/2004 01:24 PM 290816]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [11/05/2004 01:52 PM 233534]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [10/24/2007 11:12 AM 98304]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 03:00 PM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"SENTINEL"= snti386.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fssui]
--a------ 12/17/2007 11:12 AM 243240 C:\Program Files\Windows Live\Family Safety\fssui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HUAWEI 3G Data Card MTS]
--a------ 03/31/2007 11:58 AM 335872 C:\PROGRA~1\MOBILY~1\Mobily Connect Card.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 10/24/2007 11:12 AM 98304 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
-ra------ 10/14/2007 06:09 PM 103712 C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 02/12/2008 01:52 AM 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\kasperskyantivirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Mobily Connect Card\\Mobily Connect Card.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\KAV\\kav7.0\\english\\setup.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\english\\setup.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM]
R2 fssfltr;FssFltr;C:\WINDOWS\system32\DRIVERS\fssfltr.sys [10/17/2007 01:53 PM]
R2 fsssvc;Windows Live OneCare Family Safety;C:\Program Files\Windows Live\Family Safety\fsssvc.exe [12/17/2007 11:13 AM]
R3 klfltdev;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [03/25/2008 08:07 PM]
S3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [06/08/2007 09:52 AM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{03f204b9-bf93-11dc-9d57-00163621ff8d}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{03f204bd-bf93-11dc-9d57-00163621ff8d}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0911a929-c37f-11dc-9d60-00163621ff8d}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0911a9c7-c37f-11dc-9d60-00163621ff8d}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e3b70c0-8b29-11dc-9cf0-0016411d9fcb}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e3b70c4-8b29-11dc-9cf0-0016411d9fcb}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e44df46-e15d-11dc-9dbd-00163621ff8d}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e44df56-e15d-11dc-9dbd-00163621ff8d}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e44df58-e15d-11dc-9dbd-00163621ff8d}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1fe0e554-d32d-11dc-9d81-0016411d9fcb}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1fe0e55f-d32d-11dc-9d81-0016411d9fcb}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c90e93e-e065-11dc-9db9-00163621ff8d}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52c44790-e064-11dc-9db8-00163621ff8d}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53d7a387-93dd-11dc-9d07-0016411d9fcb}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53d7a427-93dd-11dc-9d07-0016411d9fcb}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53d7a4b3-93dd-11dc-9d07-0016411d9fcb}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53d7a544-93dd-11dc-9d07-0016411d9fcb}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6d81e2d6-dfbe-11dc-9db4-0016411d9fcb}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{803cd373-e481-11dc-9dbe-00163621ff8d}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a466b0b3-98f5-11dc-9d14-00163621ff8d}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a466b14a-98f5-11dc-9d14-00163621ff8d}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b2c01fbf-8408-11dc-9cdb-0016411d9fcb}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b2c01fc5-8408-11dc-9cdb-0016411d9fcb}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b66e8150-c489-11dc-9d65-00163621ff8d}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b66e8156-c489-11dc-9d65-00163621ff8d}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bb94b845-8404-11dc-9cda-0016411d9fcb}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bb94bb99-8404-11dc-9cda-0016411d9fcb}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c60b3b7b-e063-11dc-9db7-0016411d9fcb}]
\Shell\AutoRun\command - F:\AutoRun.exe
.
s of the 'Scheduled Tasks' folder
2008-08-17 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [10/19/2007 11:20 AM]
2008-08-17 C:\WINDOWS\Tasks\XoftSpySE 2.job
- C:\Program Files\XoftSpySE\XoftSpy.exe [08/17/2008 03:46 AM]
2008-08-17 C:\WINDOWS\Tasks\XoftSpySE.job
- C:\Program Files\XoftSpySE\XoftSpy.exe [08/17/2008 03:46 AM]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-lphcjj2j0er2p - C:\WINDOWS\system32\lphcjj2j0er2p.exe
Notify-NavLogon - (no file)
MSConfigStartUp-Flashget - C:\Program Files\FlashGet\FlashGet.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\hp\Application Data\Mozilla\Firefox\Profiles\laowbtdq.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-17 07:31:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????3?1?6?1??????? ?,?B?????????????hLC? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\f160315c]
"ImagePath"="\SystemRoot\System32\drivers\f160315c.sys"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
.
**************************************************************************
.
Completion time: 08/17/2008 7:36:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-17 04:36:10
Pre-Run: 44,077,252,608 bytes free
Post-Run: 45,200,916,480 bytes free
222 --- E O F --- 2008-08-15 22:33:35