لا شنت يا أستاذي
هذا أول تقرير :
ComboFix 08-08-27.05 - USER 08/28/2008 13:05:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.671 [GMT 3:00]
Running from: C:\Documents and Settings\USER\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-28 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-28 10:13 63,386,656 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-28 10:12 --------- d-----w C:\Documents and Settings\USER\Application Data\Skype
2008-08-28 10:11 --------- d-----w C:\Documents and Settings\USER\Application Data\DMCache
2008-08-28 10:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-28 10:10 1,135,648 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-08-28 10:09 857,192 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-28 10:09 110,624 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-08-28 09:37 --------- d-----w C:\Program Files\Minefield
2008-08-28 09:33 --------- d-----w C:\Documents and Settings\USER\Application Data\CyberScrub
2008-08-28 09:33 --------- d-----w C:\Documents and Settings\USER\Application Data\cleaner
2008-08-28 00:37 --------- d-----w C:\Program Files\المكتبة الشاملة
2008-08-26 12:37 --------- d-----w C:\Program Files\Internet Download Manager
2008-08-25 20:35 --------- d-----w C:\Documents and Settings\USER\Application Data\IDM
2008-08-16 05:46 355,584 ----a-w C:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-16 05:46 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-08-15 06:12 --------- d-----w C:\Program Files\Zoom Player
2008-08-15 06:07 --------- d-----w C:\Program Files\RealMedia
2008-08-15 06:07 --------- d-----w C:\Program Files\OpenSource Flash Video Splitter
2008-08-15 06:07 --------- d-----w C:\Program Files\DScaler5
2008-08-15 06:07 --------- d-----w C:\Program Files\CD Audio Reader Filter
2008-08-15 06:06 --------- d-----w C:\Program Files\SHOUTcast Source
2008-08-15 06:06 --------- d-----w C:\Program Files\Haali
2008-08-15 06:06 --------- d-----w C:\Program Files\DSP-worx
2008-08-15 06:05 691,717 ----a-w C:\WINDOWS\system32\unins000.exe
2008-08-15 06:04 --------- d-----w C:\Program Files\DirectVobSub
2008-08-13 04:23 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-08-06 17:22 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-07-30 00:09 --------- d-----w C:\Program Files\Foxit Software
2008-07-26 01:26 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-07-23 13:55 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE
2008-07-23 13:52 --------- d-----w C:\Program Files\InCode Solutions
2008-07-23 13:16 97,784 ----a-w C:\Documents and Settings\USER\Application Data\GDIPFONTCACHEV1.DAT
2008-07-23 10:10 --------- d-----w C:\Documents and Settings\USER\Application Data\skypePM
2008-07-20 10:12 --------- d-----w C:\Program Files\Common Files\Skype
2008-07-18 03:21 --------- d-----w C:\Program Files\Unlocker
2008-07-12 01:45 --------- d-----w C:\Program Files\PhotoWatermark Professional 7
2008-07-09 14:34 206,256 ----a-w C:\WINDOWS\system32\idmmbc.dll
2008-06-11 20:06 98,304 ----a-w C:\WINDOWS\system32\viscomtran.dll
2008-06-08 01:15 203,776 ----a-w C:\WINDOWS\system32\clrviddc.dll
2008-06-08 01:05 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-06-07 20:37 81,920 ----a-w C:\Documents and Settings\USER\Application Data\ezpinst.exe
2008-06-07 20:37 47,360 ----a-w C:\Documents and Settings\USER\Application Data\pcouffin.sys
2008-05-29 06:28 28,416 ----a-w C:\WINDOWS\system32\uxtuneup.dll
2008-04-29 21:04 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [08/16/2007 04:19 PM 5728112]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [08/25/2008 11:37 PM 2606512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/08/2008 04:05 AM 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
C:\Documents and Settings\USER\Start Menu\Programs\Startup\
TempClean.lnk - C:\Program Files\TempClean\TempClean.exe [2008-04-29 18:01:16 356352]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 04/13/2006 11:09 AM 49152 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 08/16/2007 04:19 PM 5728112 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 07/09/2001 10:50 AM 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 12/07/2005 10:57 PM 30208 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--------- 06/08/2008 04:05 AM 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"diagnostics"="C:\Program Files/Thomson SpeedTouch/ST330/diagnostics/diagnostics.exe" /icon -l:en
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Thomson SpeedTouch\\ST330\\service\\st330service.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [08/04/2004 12:56 AM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/04/2007 02:58 PM]
R3 ST330;ST330;C:\WINDOWS\system32\drivers\st330.sys [11/17/2005 04:17 PM]
R3 STBUS;STBUS;C:\WINDOWS\system32\drivers\stbus.sys [11/17/2005 04:17 PM]
R3 stppp;Speedtouch PPP Adapter Adapter;C:\WINDOWS\system32\DRIVERS\stppp.sys [04/29/2008 09:51 PM]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [08/16/2008 08:46 AM]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{071183ad-2118-11dd-a7a4-54484d000031}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{071183af-2118-11dd-a7a4-54484d000031}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{afda6d22-6f8e-11dd-a857-54484d000031}]
\Shell\AutoRun\command - explorer .
\Shell\mobile\command - H:\MobileLaunch.exe
.
s of the 'Scheduled Tasks' folder
2008-08-28 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe [06/20/2008 09:09 AM]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Skype - C:\Documents and Settings\USER\Desktop\خدمية\Skype.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\479xsza0.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/intl/ar/
FF -: plugin - C:\Program Files\ma-config.com\nphardwaredetection.dll
FF -: plugin - C:\Program Files\Minefield\plugins\npnul32.dll
FF -: plugin - C:\Program Files\Minefield\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\Minefield\plugins\nprjplug.dll
FF -: plugin - C:\Program Files\Minefield\plugins\nprpjplug.dll
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-28 13:11:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt\" --defaults-file=\"C:\Program Files\MySQL\MySQL Server 4.1\my.ini\" MySQL"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\st330service]
"ImagePath"="C:\Program Files/Thomson SpeedTouch/ST330/service/st330service.exe -service"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Thomson SpeedTouch\ST330\service\st330service.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 08/28/2008 13:16:05 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-28 10:15:57
Pre-Run: 21,142,016,000 bytes free
Post-Run: 21,069,459,456 bytes free
175