اخوي kong جربت الطريقة الاولى وجاني ملف بـ Text File
هذا الكلام
ComboFix 08-08-29.02 - user1 2008-08-30 17:40:10.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.1485 [GMT 3:00]
Running from: C:\Documents and Settings\user1\Desktop\طلال\خطوط عربية\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\user1\Application Data\macromedia\Flash Player\#Shareds\M3THHRQX\iforex.com
C:\Documents and Settings\user1\Application Data\macromedia\Flash Player\#Shareds\M3THHRQX\iforex.com\Emerp\Events\flash_.swf\user_data.sol
C:\Documents and Settings\user1\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\user1\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\Documents and Settings\user1\s\user1@ad.yieldmanager[1].txt
C:\WINDOWS\artools.dll
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-30 )))))))))))))))))))))))))))))))
.
2008-08-30 12:55 . 2008-08-30 12:55 <DIR> d-------- C:\Program Files\Samehsoft
2008-08-30 12:55 . 1998-06-17 23:00 299,008 --a------ C:\WINDOWS\system32\MSDBRPTR.DLL
2008-08-21 11:21 . 2008-06-13 16:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-08-21 11:21 . 2008-06-13 16:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-08-21 11:12 . 2008-06-23 19:57 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-08-21 11:12 . 2007-04-17 12:32 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-08-21 11:12 . 2007-03-08 08:10 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-08-21 11:12 . 2008-06-23 19:57 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-08-21 11:12 . 2008-06-23 19:57 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-08-21 11:12 . 2008-06-23 19:57 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-08-21 11:12 . 2008-06-23 19:57 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-08-21 11:12 . 2008-06-23 19:57 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-08-21 11:12 . 2008-06-23 12:20 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-20 18:51 . 2008-08-20 18:51 268 --ah----- C:\sqmdata01.sqm
2008-08-20 18:51 . 2008-08-20 18:51 244 --ah----- C:\sqmnoopt01.sqm
2008-08-19 14:09 . 2008-08-19 14:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-08-19 14:04 . 2008-08-19 14:04 <DIR> d-------- C:\Program Files\Bonjour
2008-08-19 13:59 . 2008-08-19 14:00 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-08-16 13:03 . 2008-08-16 13:03 203,776 --a------ C:\WINDOWS\system32\clrviddc.dll
2008-08-12 18:27 . 2008-08-12 18:27 <DIR> d-------- C:\Documents and Settings\user1\Application Data\Talkback
2008-08-12 18:27 . 2008-08-12 18:27 0 --a------ C:\WINDOWS\nsreg.dat
2008-08-12 18:26 . 2008-08-12 18:26 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-08-12 18:26 . 2008-08-12 18:26 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-08-12 18:26 . 2008-08-12 18:26 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-08-10 12:10 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-08-10 12:10 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\dllcache\usbprint.sys
2008-08-10 12:09 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-08-10 12:09 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-08-10 11:38 . 2008-08-10 11:38 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-08-10 11:35 . 2008-08-10 11:35 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-08-09 13:33 . 2008-08-09 13:33 <DIR> d-------- C:\Program Files\Hotspot_Shield
2008-08-09 13:33 . 2008-08-09 13:33 <DIR> d-------- C:\Program Files\Conduit
2008-08-09 11:53 . 2008-08-09 11:53 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-08-09 11:19 . 2008-08-09 11:19 <DIR> d-------- C:\Program Files\BitComet
2008-08-07 11:24 . 2008-08-07 11:24 <DIR> d-------- C:\Program Files\DAP
2008-08-07 11:24 . 2008-08-07 11:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-07 11:24 . 2008-08-07 11:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SpeedBit
2008-08-07 11:24 . 2008-08-07 11:24 479,298 --a------ C:\WINDOWS\system32\wbocx.ocx
2008-08-07 11:24 . 2008-08-07 11:24 172,032 --a------ C:\WINDOWS\system32\AniGIF.ocx
2008-08-07 11:24 . 2008-08-07 11:24 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll
2008-08-06 17:40 . 2008-08-06 17:40 <DIR> d--hs---- C:\Documents and Settings\user1\UserData
2008-08-06 12:29 . 2008-08-06 12:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-08-06 11:19 . 2008-08-06 11:19 <DIR> d-------- C:\Documents and Settings\user1\Contacts
2008-08-06 11:19 . 2008-08-06 11:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Dead info sign cdrom
2008-08-06 11:18 . 2008-08-06 11:18 <DIR> d-------- C:\Program Files\Windows Live
2008-08-06 11:18 . 2008-08-06 11:18 <DIR> d-------- C:\Program Files\Messenger Plus! Live
2008-08-06 11:18 . 2008-08-06 11:18 <DIR> d-------- C:\Program Files\Circle Developement
2008-08-06 11:18 . 2008-08-06 11:18 <DIR> d-------- C:\Program Files\Build four time
2008-08-06 11:18 . 2008-08-06 11:18 <DIR> d-------- C:\Documents and Settings\user1\Application Data\Build four time
2008-08-06 11:18 . 2008-08-06 11:18 268 --ah----- C:\sqmdata00.sqm
2008-08-06 11:18 . 2008-08-06 11:18 244 --ah----- C:\sqmnoopt00.sqm
2008-08-06 11:15 . 2008-08-06 11:15 <DIR> d-------- C:\WINDOWS\system32\DRVSTORE
2008-08-06 11:15 . 2008-08-06 11:15 <DIR> d-------- C:\Program Files\MSN Messenger
2008-08-06 10:34 . 2008-08-06 10:34 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-08-06 10:34 . 2008-08-06 10:34 <DIR> d-------- C:\Program Files\Adobe Media Player
2008-08-06 10:23 . 2008-08-06 10:23 <DIR> d-------- C:\Program Files\Google
2008-08-02 18:09 . 2008-08-02 18:09 <DIR> d-------- C:\Program Files\Real_SC
2008-08-02 17:57 . 2001-09-19 15:00 66,082 --a------ C:\WINDOWS\system32\dllcache\c_20420.nls
2008-08-02 17:57 . 2001-09-19 15:00 66,082 --a------ C:\WINDOWS\system32\c_20420.nls
2008-07-29 12:41 . 2008-07-29 12:42 <DIR> d-------- C:\Documents and Settings\user1\Application Data\COWON
2008-07-28 17:38 . 2008-07-28 17:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-07-27 16:43 . 2008-07-27 16:43 <DIR> d--hs---- C:\FOUND.001
2008-07-27 00:57 . 2008-07-27 00:57 123 --a------ C:\WINDOWS\hpntwksetup.ini
2008-07-27 00:54 . 2008-07-27 00:54 <DIR> d--h----- C:\Program Files\Zenographics
2008-07-27 00:54 . 2008-07-27 00:54 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-07-27 00:51 . 2005-12-21 05:16 470,048 -ra------ C:\WINDOWS\system32\drivers\ar5211.sys
2008-07-25 00:06 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-07-25 00:05 . 2008-07-25 00:05 <DIR> d-------- C:\Program Files\MSBuild
2008-07-25 00:05 . 2008-07-25 00:05 <DIR> d-------- C:\Program Files\Microsoft Works
2008-07-25 00:03 . 2008-07-25 00:03 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-07-25 00:03 . 2008-07-25 00:03 <DIR> dr-h----- C:\MSOCache
2008-07-25 00:03 . 2008-07-25 00:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-11 07:09 155,995 ----a-w C:\WINDOWS\java\Packages\N9ZXRVPF.ZIP
2008-07-18 19:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 19:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 19:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 19:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 19:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 19:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 19:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 19:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 19:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 19:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 19:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 19:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 19:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 19:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 19:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 07:57 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:20 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:20 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-21 05:23 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2008-05-01 14:30 331,776 ----a-w C:\WINDOWS\system32\dllcache\msadce.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{F4F10C1D-87C7-404A-B4B3-000000000000}"= "C:\PROGRA~1\DAP\SBSearch.dll" [2008-08-07 11:24 32768]
[HKEY_CLASSES_ROOT\clsid\{f4f10c1d-87c7-404a-b4b3-000000000000}]
[HKEY_CLASSES_ROOT\SearchHook.SrchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}]
[HKEY_CLASSES_ROOT\SearchHook.SrchHook]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-08-06 10:23 171448]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.EXE" [2008-08-07 11:24 3065344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-28 08:55 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-28 08:52 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-28 08:55 118784]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-03-13 17:20 949376]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-08-12 18:26 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SkyTel"="SkyTel.EXE" [2006-05-16 13:04 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 12:21 16270848 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56 15360]
C:\Documents and Settings\user1\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]
Adobe Media Player.lnk - C:\Program Files\Adobe Media Player\Adobe Media Player.exe [2008-08-06 10:34:22 260096]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10261:TCP"= 10261:TCP:BitComet 10261 TCP
"10261:UDP"= 10261:UDP:BitComet 10261 UDP
S3 HssTrayService;Hotspot Shield Tray Service;C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE []
S3 SF-620;SF-620 USB Infrared Adapter;C:\WINDOWS\system32\DRIVERS\SF-620.sys [2004-08-12 05:18]
S3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2008-03-13 05:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9157438-ec01-11db-b351-806d6172696f}]
\Shell\AutoRun\command - E:\AUTORUN.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d93ec8e7-5cdd-11dd-9e5f-001d0fc694fc}]
\Shell\AutoRun\command - kongxsg.exe
\Shell\explore\Command - kongxsg.exe
\Shell\open\Command - kongxsg.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-filetype - C:\DOCUME~1\user1\APPLIC~1\BUILDF~1\Bin software heck.exe
HKLM-Run-Device Detector - DevDetect.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\ttttkydv.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-30 17:41:22
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-30 17:41:40
ComboFix-quarantined-files.txt 2008-08-30 14:41:40
Pre-Run: 34,660,122,624 bytes free
Post-Run: 36,738,891,776 bytes free
213 --- E O F --- 2008-08-21 11:46:50
والان حنزلك الطريقة الثانية
في الرد الذي يليه