الغالي .. kong
تسلم حبيبي .. رجعنا لك بالتقارير:q:
التقرير الاول
ComboFix 08-09-10.02 - TOSHIBA 09/11/2008 3:10:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.171 [GMT 3:00]
Running from: C:\Documents and Settings\TOSHIBA\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\Guest\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\TOSHIBA\s\toshiba@www.iproxblock[2].txt
C:\Documents and Settings\TOSHIBA\err.log
C:\Documents and Settings\TOSHIBA\Start Menu\Programs\Uninstall.lnk
C:\WINDOWS\services.exe
C:\WINDOWS\system\oeminfo.ini
C:\WINDOWS\system\sservice.exe
C:\WINDOWS\system32\fservice.exe
C:\WINDOWS\system32\reginv.dll
C:\WINDOWS\system32\winkey.dll
.
((((((((((((((((((((((((( Files Created from 2008-08-11 to 2008-09-11 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-11 00:15 852,000 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-11 00:15 6,440,480 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-11 00:15 52,444 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-11 00:15 5,040 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-10 22:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-09 02:23 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-09 01:37 --------- d-----w C:\Program Files\Your Uninstaller 2008
2008-09-08 23:55 --------- d-----w C:\Program Files\MSBuild
2008-09-08 23:46 --------- d-----w C:\Program Files\Reference Assemblies
2008-09-08 07:41 --------- d-----w C:\Documents and Settings\TOSHIBA\Application Data\Free Download Manager
2008-08-31 21:13 --------- d-----w C:\Documents and Settings\Guest\Application Data\Free Download Manager
2008-08-31 02:43 --------- d-----w C:\Documents and Settings\TOSHIBA\Application Data\toshiba
2008-08-30 06:52 --------- d-----w C:\Program Files\Teorex
2008-08-28 22:19 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-08-28 22:19 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-08-28 22:10 --------- d-----w C:\Program Files\Kaspersky Lab
2008-08-28 21:43 --------- d-----w C:\Documents and Settings\TOSHIBA\Application Data\Avira
2008-08-28 21:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-08-27 18:13 --------- d-----w C:\Program Files\Nokia
2008-08-27 18:12 --------- d-----w C:\Program Files\Common Files\Nokia
2008-08-27 18:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-08-27 17:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nokia
2008-08-27 15:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-08-27 14:47 --------- d-----w C:\Program Files\SOFTplus
2008-08-22 14:11 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-21 03:19 --------- d-----w C:\Program Files\WinPcap
2008-08-15 22:09 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-08-13 05:19 --------- d-----w C:\Program Files\Unlocker
2008-08-13 05:17 --------- d-----w C:\Program Files\UltraISO
2008-08-13 03:59 --------- d-----w C:\Program Files\Common Files\EZB Systems
2008-08-10 23:15 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-08-09 00:05 --------- d-----w C:\Program Files\XoftSpySE
2008-08-02 22:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-31 14:25 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-07-28 02:16 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-27 21:08 --------- d-----w C:\Program Files\Opera 9
2008-07-25 04:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-25 03:54 --------- d-----w C:\Program Files\QuickTime
2008-07-25 03:54 --------- d-----w C:\Program Files\ImTOO
2008-07-22 21:02 --------- d-----w C:\Documents and Settings\TOSHIBA\Application Data\Ashampoo
2008-07-22 21:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\ashampoo
2008-07-22 21:00 --------- d-----w C:\Program Files\Ashampoo
2008-07-22 20:20 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-07-22 03:24 --------- d-----w C:\Program Files\Active GIF Creator 3.2
2008-07-21 07:41 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Windows Desktop Search
2008-07-21 07:41 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Symantec
2008-07-21 07:14 --------- d-----w C:\Documents and Settings\TOSHIBA\Application Data\ESET
2008-07-21 07:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-07-19 06:48 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2008-07-17 21:43 --------- d-----w C:\Documents and Settings\Guest\Application Data\URSoft
2008-07-17 02:12 --------- d-----w C:\Program Files\VisualRoute Lite Edition
2008-07-17 01:06 --------- d-----w C:\Program Files\Registry Fast
2008-07-16 13:05 --------- d-----w C:\Program Files\MSXML 6.0
2008-07-14 10:15 --------- d-----w C:\Documents and Settings\TOSHIBA\Application Data\cleaner
2008-07-14 09:59 --------- d-----w C:\Documents and Settings\TOSHIBA\Application Data\Desktopicon
2008-07-13 21:12 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-07-13 21:06 --------- d-----w C:\Documents and Settings\TOSHIBA\Application Data\TuneUp Software
2008-07-13 21:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-07-13 21:03 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-12 08:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Downloaded Installations
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [12/01/2006 12:03 PM 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [08/12/2007 01:48 AM 292152]
"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [02/02/2006 02:11 PM 73728]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [01/05/2006 05:02 PM 352256]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [03/17/2007 11:31 AM 77824]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [05/12/2005 01:31 PM 118784]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 11:50 AM 155648]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [11/28/2005 11:55 PM 98304]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [11/28/2005 11:55 PM 118784]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [11/28/2005 11:52 PM 77824]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [10/06/2005 08:20 AM 122940]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [07/04/2008 10:36 PM 185896]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [05/02/2008 07:15 AM 15872]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [06/06/2005 11:46 PM 57344]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"TDispVol"="TDispVol.exe" [03/11/2005 06:03 PM 73728 C:\WINDOWS\system32\TDispVol.exe]
"RTHDCPL"="RTHDCPL.EXE" [12/10/2005 01:49 AM 15691264 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-02-03 1753088]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
"NoSecCpl"= 0 (0x0)
"DisableLockWorkstation"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuPinnedList"= 0 (0x0)
"NoStartMenuMFUprogramsList"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinterTabs"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChange"= 0 (0x0)
"NoChangeKeyboardNavigationIndicators"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
"NoFind"= 0 (0x0)
"NoRun"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [03/13/2006 03:11 PM 233472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalStart.lnk]
backup=C:\WINDOWS\pss\PalStart.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
-ra--c--- 03/01/2007 10:37 AM 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a--c--- 07/23/2007 12:43 PM 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"C:\\Program Files\\Mobily Connect Card\\Mobily Connect Card.exe"=
"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\javaw.exe"=
"C:\\WINDOWS\\system32\\java.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\AppServ\\Apache2.2\\bin\\httpd.exe"=
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"C:\\Program Files\\GlobalSCAPE\\CuteFTP 8 Professional\\ftpte.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\
000.fcl [11/02/2006 04:51 PM 13560]
R2 Apache2.2;Apache2.2;C:\AppServ\Apache2.2\bin\httpd.exe [01/09/2007 07:17 PM 20539]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [08/04/2004 01:56 AM 14336]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [03/25/2008 08:07 PM 24592]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [01/25/2007 08:31 PM 42000]
S3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [06/08/2007 09:52 AM 27136]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [07/14/2008 12:06 AM 306432]
S4 NetFxUpdate_v1.1.4322;Microsoft .NET Framework v1.1.4322 Update;C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe [01/15/2007 04:11 PM 73728]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e3a36f9-34b9-11dc-b478-0019d21aa6b9}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{449b00d2-868a-11da-a583-00a0d1df1b4d}]
\Shell\AutoRun\command - browser.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{600a21c3-38f8-11dc-b490-0019d21aa6b9}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8545b048-da6b-11dc-b5d0-0019d21aa6b9}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e86f6fd-da01-11db-b3cd-00037ae330dd}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL exiplorer.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{942038e9-c422-11dc-b5b4-0019d21aa6b9}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL exiplorer.exe
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\TOSHIBA\Application Data\Mozilla\Firefox\Profiles\vpyp2qs1.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://french.eazel.com/index.php?rvs=hompag
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.
.
------- File Associations (Beta) -------
.
txtfile=NotePad.exe "%1" %*
vbefile\shell\edit\command=C:\WINDOWS\Notepad.exe %1
vbsfile\shell\edit\command=C:\WINDOWS\Notepad.exe %1
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-11 03:17:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\
000.fcl"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Documents and Settings\TOSHIBA\Desktop\C:\AppServ\Apache2.2\bin\httpd.exe
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
.
**************************************************************************
.
Completion time: 09/11/2008 3:25:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-11 00:25:14
Pre-Run: 4,356,001,792 bytes free
Post-Run: 4,297,469,952 bytes free
273 --- E O F --- 2008-09-10 00:59:45