طيب اخ maax ان طلعلي هاذا التقرير ComboFix 08-12-01.01 - dodo 12/02/2008 7:15:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.406 [GMT -8:00]
Running from: c:\documents and settings\dodo\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\wmdrtc32.dl_
c:\windows\system32\wmdrtc32.dll
G:\autorun.inf
G:\sxhkg.pif
.
((((((((((((((((((((((((( Files Created from 2008-11-02 to 2008-12-02 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 15:17 65,852 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-02 15:17 5,477 ----a-w c:\windows\system32\drivers\kshklr.sys
2008-12-02 15:17 4,524,832 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-02 15:17 341,792 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-12-02 15:17 141,668 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-12-02 15:15 --------- d-----w c:\documents and settings\dodo\Application Data\DMCache
2008-12-02 01:56 --------- d-----w c:\program files\Total Video Converter
2008-12-01 20:23 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-12-01 18:04 --------- d-----w c:\documents and settings\All Users\Application Data\Trymedia
2008-12-01 17:25 --------- d-----w c:\documents and settings\dodo\Application Data\IDM
2008-12-01 16:26 --------- d-----w c:\documents and settings\dodo\Application Data\GameHouse
2008-12-01 16:24 --------- d-----w c:\documents and settings\All Users\Application Data\MythPeople
2008-12-01 13:49 --------- d-----w c:\program files\WinAVI Video Capture
2008-12-01 13:11 --------- d-----w c:\program files\ESCV
2008-11-30 23:14 --------- d-----w c:\program files\Microsoft IntelliPoint
2008-11-30 23:11 --------- d-----w c:\program files\Realtek AC97
2008-11-30 18:59 --------- d-----w c:\documents and settings\All Users\Application Data\DriverScanner
2008-11-30 18:41 --------- dc-h--w c:\documents and settings\All Users\Application Data\{148D8B8A-8F96-4822-81EC-D510B626B7D5}
2008-11-30 18:41 --------- d-----w c:\program files\Uniblue
2008-11-30 18:41 --------- d-----w c:\documents and settings\dodo\Application Data\Uniblue
2008-11-29 17:05 --------- d-----w c:\documents and settings\dodo\Application Data\Nokia Multimedia Player
2008-11-29 17:05 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-29 16:44 --------- d-----w c:\program files\Collage Maker
2008-11-29 16:41 --------- d-----w c:\program files\Acoustica Mp3 To Wave Converter Plus
2008-11-29 09:54 --------- d-----w c:\documents and settings\dodo\Application Data\Thinstall
2008-11-29 09:54 --------- d-----w c:\documents and settings\dodo\Application Data\Megaupload
2008-11-28 23:02 --------- d-----w c:\program files\Acoustica MP3 Audio Mixer
2008-11-27 21:15 --------- d-----w c:\documents and settings\dodo\Application Data\Nuotex
2008-11-27 09:01 --------- d-----w c:\documents and settings\Guest\Application Data\PC Suite
2008-11-26 22:25 --------- d-----w c:\documents and settings\dodo\Application Data\PC Suite
2008-11-26 18:44 --------- d-----w c:\program files\WorldOfGoo
2008-11-26 18:44 --------- d-----w c:\documents and settings\All Users\Application Data\2DBoy
2008-11-26 17:44 --------- d-----w c:\program files\Common Files\Adobe
2008-11-26 16:26 --------- d-----w c:\program files\Reference Assemblies
2008-11-26 16:26 --------- d-----w c:\program files\MSBuild
2008-11-26 16:07 --------- d-----w c:\program files\Burger Shop
2008-11-26 16:05 --------- d-----w c:\program files\ReflexiveArcade
2008-11-26 15:13 --------- d-----w c:\program files\MSN Messenger
2008-11-26 03:14 --------- d-----w c:\program files\LtUcx
2008-11-26 01:02 --------- d-----w c:\program files\QuickTime
2008-11-26 01:02 --------- d-----w c:\program files\ImTOO
2008-11-26 00:48 --------- d-----w c:\program files\3gp Player
2008-11-26 00:45 --------- d-----w c:\program files\Internet Download Manager
2008-11-26 00:44 --------- d-----w c:\documents and settings\dodo\Application Data\Nokia
2008-11-25 20:12 --------- d-----w c:\documents and settings\All Users\Application Data\PC Suite
2008-11-25 20:11 --------- d-----w c:\program files\PC Connectivity Solution
2008-11-25 20:11 --------- d-----w c:\program files\Nokia
2008-11-25 20:11 --------- d-----w c:\program files\DIFX
2008-11-25 20:11 --------- d-----w c:\program files\Common Files\PCSuite
2008-11-25 20:11 --------- d-----w c:\program files\Common Files\Nokia
2008-11-25 20:11 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2008-11-25 20:03 --------- d-----w c:\documents and settings\dodo\Application Data\COWON
2008-11-25 18:52 --------- d-----w c:\program files\Java
2008-11-25 18:40 --------- d-----w c:\documents and settings\All Users\Application Data\SpeakyChat
2008-11-25 17:56 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-25 17:56 --------- d-----w c:\program files\JetAudio
2008-11-25 17:56 --------- d-----w c:\program files\Common Files\COWON
2008-11-25 17:56 --------- d-----w c:\documents and settings\dodo\Application Data\InstallShield
2008-11-25 17:41 --------- d-----w c:\program files\Real
2008-11-25 17:41 --------- d-----w c:\program files\Common Files\xing shared
2008-11-25 17:41 --------- d-----w c:\program files\Common Files\Real
2008-11-25 17:38 --------- d-----w c:\documents and settings\dodo\Application Data\globalford
2008-11-25 17:37 --------- d-----w c:\documents and settings\All Users\Application Data\third lies itch ford
2008-11-25 17:35 --------- d-----w c:\program files\Windows Live
2008-11-25 17:35 --------- d-----w c:\program files\Messenger Plus! Live
2008-11-25 17:35 --------- d-----w c:\program files\globalford
2008-11-25 17:35 --------- d-----w c:\program files\Circle Developement
2008-11-25 16:12 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-11-25 16:01 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-25 15:55 --------- d-----w c:\program files\Kaspersky Lab
2008-11-25 15:55 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-25 15:46 --------- d-----w c:\program files\Yahoo!
2008-11-25 15:45 --------- d-----w c:\documents and settings\dodo\Application Data\Yahoo!
2008-11-25 12:09 --------- d-----w c:\program files\NOS
2008-11-25 12:09 --------- d-----w c:\documents and settings\All Users\Application Data\NOS
2008-11-25 11:44 --------- d-----w c:\program files\SiS VGA Utilities V3.73
2008-11-25 11:43 --------- d-----w c:\program files\sisagp
2008-11-25 11:42 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-25 11:31 --------- d-----w c:\program files\microsoft frontpage
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/13/2008 04:12 PM 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [06/19/2007 10:17 AM 1241088]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2008-11-25 262144]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Nokia\\Nokia PC Suite 6\\LaunchApplication.exe"=
S3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\lnhnji.sys []
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-11-25 33752]
.
s of the 'Scheduled Tasks' folder
2008-12-02 c:\windows\Tasks\A4FD60AB91DF12C3.job
- c:\docume~1\dodo\applic~1\global~1\internetkeepjump.exe [11/25/2008 09:38 AM]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.jo/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
TCP: {1655645C-8450-4466-B79B-97883A063A0F} = 196.27.0.35 196.27.0.230
c:\windows\system32\msvcrt.dll - c:\windows\system32\mfc42.dll
c:\windows\system32\olepro32.dll
c:\windows\Downloaded Program Files\SysInfo.ocx
c:\windows\Downloaded Program Files\Authenticatedll.dll
c:\windows\Downloaded Program Files\imcv1.dll
c:\program files\LtUcx\1003\imcv1.dll
O16 -: {6924091F-CD97-41E1-B1D4-D9079409D413}
hxxp://67.198.192.146/talk.cab
c:\windows\Downloaded Program Files\talk.inf
c:\windows\Downloaded Program Files\ReadUid.ocx - O16 -: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA}
hxxp://67.198.192.146/ReadUid.CAB
c:\windows\Downloaded Program Files\ReadUid.INF
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-02 07:18:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(688)
c:\windows\system32\klogon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
.
**************************************************************************
.
Completion time: 12/02/2008 7:20:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-02 15:20:49
Pre-Run: 33,276,133,376 bytes free
Post-Run: 33,237,135,360 bytes free
191 --- E O F --- 2008-11-28 04:18:50