وهذا تقرير الأداة الثالثة من الوضع الآمين
ComboFix 08-08-28.04 - Administrator 2008-08-29 3:17:29.3 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1256.966.1033.18.371 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-29 )))))))))))))))))))))))))))))))
.
2008-08-29 02:07 . 2008-08-29 02:51 <DIR> d-------- C:\QUARANTINE
2008-08-29 02:07 . 2008-08-29 02:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-29 02:03 . 2008-08-29 02:03 3,506 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-28 02:03 . 2008-03-05 11:41 148,496 --a------ C:\WINDOWS\system32\drivers\92736188.sys
2008-08-28 01:55 . 2008-07-06 07:01 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-08-28 01:55 . 2008-07-06 07:01 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2008-08-28 01:55 . 2008-07-06 07:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
2008-08-28 01:55 . 2008-07-06 07:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\toshiba
2008-08-28 01:55 . 2008-07-06 07:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2008-08-28 01:55 . 2008-07-05 23:47 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intel
2008-08-28 01:55 . 2008-07-06 07:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\ATI
2008-08-28 01:55 . 2008-08-28 01:56 <DIR> d-------- C:\Documents and Settings\Administrator
2008-08-27 23:44 . 2008-08-27 23:44 <DIR> d-------- C:\WINDOWS\McAfee.com
2008-08-26 01:24 . 2008-08-26 01:28 <DIR> d-------- C:\Program Files\Proxifier
2008-08-26 01:24 . 1997-06-06 15:52 11,264 --a------ C:\WINDOWS\system32\SPORDER.DLL
2008-08-24 19:43 . 2008-08-24 19:44 <DIR> d-------- C:\Program Files\Hotspot Shield
2008-08-22 02:14 . 2008-08-22 02:14 <DIR> d-------- C:\Program Files\CCleaner
2008-08-20 20:45 . 2008-08-20 20:46 <DIR> d-------- C:\Documents and Settings\Dhawi\Application Data\ArtOfPing
2008-08-20 20:34 . 2008-08-20 20:34 <DIR> d-------- C:\TEMP
2008-08-20 20:34 . 2008-08-20 20:34 <DIR> d-------- C:\Documents and Settings\Dhawi\Application Data\GPass-3
2008-08-20 20:08 . 2008-08-20 20:08 <DIR> d-------- C:\Documents and Settings\Dhawi\Application Data\GPass
2008-08-20 15:25 . 2008-08-20 15:25 <DIR> d-------- C:\Program Files\4arabnetwork
2008-08-19 21:06 . 2008-08-19 21:06 <DIR> d-------- C:\Program Files\TeamViewer3
2008-08-19 21:06 . 2008-08-19 22:30 <DIR> d-------- C:\Documents and Settings\Dhawi\Application Data\TeamViewer
2008-08-19 20:48 . 2008-08-19 20:48 <DIR> d-------- C:\Documents and Settings\Dhawi\temp
2008-08-18 23:26 . 2008-08-18 23:30 <DIR> d-------- C:\s2h
2008-08-18 20:59 . 2008-08-28 02:33 <DIR> d-------- C:\Program Files\HTTP-Tunnel
2008-08-15 22:43 . 2008-08-15 22:43 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-08-06 22:10 . 2008-08-06 22:10 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-08-06 05:52 . 2008-08-09 11:46 <DIR> d-------- C:\Program Files\Ares
2008-08-03 19:16 . 2008-08-03 19:16 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-08-03 19:16 . 2008-08-03 19:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-08-03 03:26 . 2008-08-03 03:26 <DIR> d-------- C:\Program Files\Microsoft Firewall Client 2004
2008-07-29 22:07 . 2008-08-28 23:55 <DIR> d-------- C:\Documents and Settings\Dhawi\Tracing
2008-07-29 21:54 . 2008-08-01 04:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-29 00:15 401,440 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-08-29 00:15 2,452 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-08-29 00:15 16,172 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-29 00:15 1,931,808 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-29 00:09 --------- d-----w C:\Documents and Settings\Dhawi\Application Data\DMCache
2008-08-29 00:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-26 00:59 --------- d-----w C:\Program Files\InterVideo
2008-08-24 16:38 --------- d-----w C:\Documents and Settings\Dhawi\Application Data\uTorrent
2008-08-23 17:58 --------- d-----w C:\Program Files\Internet Download Manager
2008-08-22 23:35 --------- d-----w C:\Documents and Settings\Dhawi\Application Data\IDM
2008-08-20 17:26 --------- d-----w C:\Program Files\uTorrent
2008-08-19 21:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Babylon
2008-08-12 00:58 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-08-06 19:10 --------- d-----w C:\Program Files\Common Files\Real
2008-08-05 21:38 37,088 ----a-w C:\Documents and Settings\Dhawi\Application Data\GDIPFONTCACHEV1.DAT
2008-08-03 16:17 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-03 09:00 --------- d-----w C:\Documents and Settings\Dhawi\Application Data\Babylon
2008-07-29 18:15 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-07-26 19:09 --------- d-----w C:\Program Files\Windows Live
2008-07-26 19:09 --------- d-----w C:\Program Files\MSN Messenger
2008-07-25 12:56 96,559 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-07-25 12:56 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-07-25 12:28 --------- d-----w C:\Program Files\Kaspersky Lab
2008-07-25 12:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-25 08:34 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-07-25 08:34 683,520 ----a-w C:\WINDOWS\system32\divx.dll
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 13:47 --------- d-----w C:\Program Files\TechSmith
2008-07-23 13:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\TechSmith
2008-07-23 13:45 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-19 02:26 --------- d--h--w C:\Program Files\Zenographics
2008-07-19 02:26 --------- d-----w C:\Program Files\Hewlett-Packard
2008-07-15 13:25 --------- d-----w C:\Program Files\Babylon
2008-07-14 03:55 --------- d-----w C:\Documents and Settings\Dhawi\Application Data\AdobeUM
2008-07-12 18:58 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-07-12 18:58 172,032 ------w C:\WINDOWS\Setup1.exe
2008-07-12 13:44 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-07-11 20:58 --------- d-----w C:\Program Files\MessengerPlus! 3
2008-07-06 22:16 --------- d-----w C:\Program Files\Real
2008-07-06 21:52 --------- d-----w C:\Documents and Settings\Dhawi\Application Data\Media Player Classic
2008-07-06 14:53 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-06 14:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-06 07:33 --------- d-----w C:\Program Files\Symantec
2008-07-06 07:33 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-07-06 07:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-07-06 04:12 --------- d-----w C:\Program Files\Windows Desktop Search
2008-07-06 04:12 --------- d-----w C:\Program Files\Toshiba
2008-07-06 04:11 --------- d-----w C:\Program Files\Synaptics
2008-07-06 04:11 --------- d-----w C:\Program Files\Sonic
2008-07-06 04:11 --------- d-----w C:\Program Files\Realtek
2008-07-06 04:10 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-06 04:10 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-06 04:10 --------- d-----w C:\Program Files\ltmoh
2008-07-06 04:10 --------- d-----w C:\Program Files\Java
2008-07-06 04:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-06 04:08 --------- d-----w C:\Program Files\Common Files\Java
2008-07-06 04:08 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-06 04:08 --------- d-----w C:\Program Files\ATI Technologies
2008-07-06 04:00 --------- d-----w C:\Documents and Settings\Dhawi\Application Data\Windows Desktop Search
2008-07-06 04:00 --------- d-----w C:\Documents and Settings\Dhawi\Application Data\toshiba
2008-07-06 04:00 --------- d-----w C:\Documents and Settings\Dhawi\Application Data\Sonic
2008-07-06 04:00 --------- d-----w C:\Documents and Settings\Dhawi\Application Data\ATI
2008-07-06 04:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\SBSI
2008-07-05 20:51 --------- d-----w C:\Documents and Settings\Dhawi\Application Data\Protector Suite
2008-07-05 20:49 --------- d-----w C:\Program Files\Protector Suite QL
2008-07-05 20:48 --------- d-----w C:\Program Files\Common Files\Protector Suite QL
2008-07-05 20:47 21,275 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-07-05 20:47 --------- d-----w C:\Program Files\Intel
2008-07-05 20:47 --------- d-----w C:\Documents and Settings\Dhawi\Application Data\Intel
2008-07-05 20:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intel
2008-07-05 20:44 0 --sha-r C:\WINDOWS\system32\drivers\TOSHIBA_SATELLITE A100_04705-AR_PSAA9E-0R101.MRK
2008-06-12 18:36 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 14:26 65536]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 03:12 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 03:12 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 17:02 352256]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-05-12 13:31 118784]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-10-06 08:20 122940]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-02 18:02 761948]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-01 15:04 7557120]
"NVRotateSysTray"="C:\WINDOWS\system32\nvsysrot.dll" [2006-05-01 15:04 49152]
"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [2006-02-02 14:11 73728]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 12:37 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 11:41 602182]
"PSQLLauncher"="C:\Program Files\Protector Suite QL\launcher.exe" [2006-05-05 17:36 30208]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-08-06 22:09 185896]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-10 01:49 15691264 C:\WINDOWS\RTHDCPL.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 16:29 88203 C:\WINDOWS\agrsmmsg.exe]
"TPSMain"="TPSMain.exe" [2005-08-03 17:26 266240 C:\WINDOWS\system32\TPSMain.exe]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" [2005-03-11 18:03 73728 C:\WINDOWS\system32\TDispVol.exe]
"nwiz"="nwiz.exe" [2006-05-01 15:04 1519616 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 03:12 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [4/23/2008 3:38:16 AM 29696]
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2/3/2006 12:19:10 AM 1753088]
Microsoft Firewall Client Management.lnk - C:\Program Files\Microsoft Firewall Client 2004\FwcMgmt.exe [12/9/2006 7:04:10 PM 117568]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 15:11 233472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2006-05-05 17:48 40448 C:\WINDOWS\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"D:\\CCProxy\\CCProxy.v6.60\\CCProxy.v6.60\\CCProxy.dat"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Documents and Settings\\Dhawi\\Desktop\\CCProxy\\CCProxy.dat"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 20:07]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2006-12-16 23:37]
S0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 18:29]
S1 is-UCIE8drv;is-UCIE8drv;C:\WINDOWS\system32\drivers\92736188.sys [2008-03-05 11:41]
S2 FdRedir;FdRedir;C:\Program Files\Common Files\Protector Suite QL\Drivers\FdRedir.sys [2006-05-05 18:00]
S2 FileDisk2;FileDisk Protector Kernel Driver;C:\Program Files\Common Files\Protector Suite QL\Drivers\filedisk.sys [2006-05-05 17:59]
S2 FwcAgent;Firewall Client Agent;C:\Program Files\Microsoft Firewall Client 2004\FwcAgent.exe [2006-12-09 19:04]
S2 is-UCIE8;is-UCIE8;C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-UCIE8\is-UCIE8.exe []
S2 smihlp;SMI helper driver;C:\Program Files\Protector Suite QL\smihlp.sys [2006-05-05 17:33]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [2008-03-13 19:02]
S3 NetHook_ControlCenter;ArtOfPing ControlCenter;C:\Program Files\PingFu Iris\ControlCenter.sys []
S3 NetHook_Interceptor;ArtOfPing TDI Interceptor;C:\Program Files\PingFu Iris\Interceptor.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{449b00d2-868a-11da-a583-00a0d1df1b4d}]
\Shell\AutoRun\command - browser.exe
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-is-UCIE8 - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-UCIE8\is-UCIE8.exe
.
------- Supplementary Scan -------
.
R1 -: HKCU-Internet Settings,ProxyServer = stuproxy.kfupm.edu.sa:80
R1 -: HKCU-Internet Settings,ProxyOverride = <local>
O8 -: &MSN Search - C:\Program Files\MSN Toolbar Suite\msntb.dll/search.htm
O8 -: Open in new background tab - C:\Program Files\MSN Toolbar Suite\en-gb\msntabres.dll.mui/229?5ffc62ad4625433481b64c2b04fe285
O8 -: Open in new foreground tab - C:\Program Files\MSN Toolbar Suite\en-gb\msntabres.dll.mui/230?5ffc62ad4625433481b64c2b04fe285
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-29 03:19:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-29 3:20:02
ComboFix-quarantined-files.txt 2008-08-29 00:20:00
ComboFix2.txt 2008-08-29 00:02:53
ComboFix3.txt 2008-08-27 22:15:59
Pre-Run: 59,801,964,544 bytes free
Post-Run: 59,801,038,848 bytes free
213