.
وع ـليكم السلام ..,
شرفت وانرت اخي عدنان معنا في منتديات زيزوم .,
اعمل الاتي ..:
مودتي .,
.
ComboFix 08-09-05.02 - yu 09/07/2008 19:40:59.2 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.352 [GMT 4:00]
Running from: C:\Documents and Settings\yu\My Documents\Downloads\Programs\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-08-07 to 2008-09-07 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-06 21:00 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-06 21:00 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-06 21:00 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-06 21:00 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-03 18:26 --------- d-----w C:\Program Files\Nuclear Coffee
2008-08-30 06:22 --------- d-----w C:\Program Files\AutorunRemover
2008-08-28 14:41 98,304 ----a-w C:\WINDOWS\DUMPcbdb.tmp
2008-08-21 20:33 --------- d-----w C:\Program Files\Steganos Internet Trace Destructor 7
2008-08-21 20:09 --------- d-----w C:\Documents and Settings\yu\Application Data\URSoft
2008-08-21 20:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-21 19:34 --------- d-----w C:\Program Files\MSConfig CleanUp
2008-08-21 19:10 --------- d-----w C:\Documents and Settings\yu\Application Data\IDM
2008-08-21 19:10 --------- d-----w C:\Documents and Settings\yu\Application Data\DMCache
2008-08-20 18:18 --------- d-----w C:\Documents and Settings\yu\Application Data\Media Player Classic
2008-08-20 18:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-20 18:16 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-20 17:08 --------- d-----w C:\Documents and Settings\yu\Application Data\Internet Download Accelerator
2008-08-20 16:32 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-08-20 16:32 --------- d-----w C:\Program Files\Athan
2008-08-19 18:49 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-08-19 18:49 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-08-19 18:49 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-08-17 20:01 --------- d-----w C:\Program Files\D-Link
2008-08-17 20:01 --------- d-----w C:\Program Files\ANI
2008-08-17 19:55 --------- d-----w C:\Program Files\Realtek Sound Manager
2008-08-17 19:55 --------- d-----w C:\Program Files\AvRack
2008-08-17 19:52 --------- d-----w C:\Program Files\Intel
2008-08-17 19:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-17 19:49 --------- d-----w C:\Program Files\Kaspersky Lab
2008-08-17 19:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-17 19:46 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-17 19:32 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ITD7"="C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" [09/03/2004 04:02 PM 241664]
"NvMediaCenter"="C:\WINDOWS\system32\NVMCTRAY.DLL" [05/02/2003 03:19 PM 49152]
"IDMan"="E:\البرامج\Internet Download Manager\IDMan.exe" [03/31/2008 09:06 AM 887040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [05/02/2003 03:19 PM 4640768]
"nwiz"="nwiz.exe" [05/02/2003 03:19 PM 323584 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/03/2004 08:56 PM 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ITD7"="C:\Program Files\Steganos Internet Trace Destructor 7\itd7.exe" [09/03/2004 04:02 PM 241664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yv12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [05/11/2006 01:11 PM 472096]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [08/03/2004 10:31 PM 36224]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/04/2007 02:58 PM 24344]
.
.
------- Supplementary Scan -------
.
O8 -: Download All Links with IDM - E:\البرامج\Internet Download Manager\IEGetAll.htm
O8 -: Download with IDM - E:\البرامج\Internet Download Manager\IEExt.htm
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-07 19:43:51
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 09/07/2008 19:46:49
ComboFix-quarantined-files.txt 2008-09-07 15:46:44
ComboFix2.txt 2008-09-06 20:53:06
Pre-Run: 2,387,746,816 bytes free
Post-Run: 2,379,239,424 bytes free
94