االف الف شكر لسرعه ردك
انا عملت فحص بالاداه الاولى بس الجهاز ماعملش ريستارت. والتقرير كالتالي:ComboFix 08-09-13.03 - Administrator 09/14/2008 8:26:27.2 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.874.1.1033.18.278 [GMT 7:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-08-14 to 2008-09-14 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-14 00:34 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-14 00:34 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-14 00:34 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-14 00:34 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-13 00:00 --------- d-----w C:\Program Files\AnMing
2008-09-11 18:51 --------- d-----w C:\Program Files\Java
2008-09-11 18:51 --------- d-----w C:\Program Files\Common Files\Java
2008-09-11 09:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-09-11 01:46 --------- d-----w C:\Program Files\CCleaner
2008-09-09 16:14 716 ----a-w C:\BOWLDA.DAT
2008-09-08 03:36 --------- d-----w C:\Program Files\Yahoo!
2008-09-08 03:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-09-08 03:34 --------- d-----w C:\Program Files\Windows Live
2008-09-08 03:32 --------- d-----w C:\Documents and Settings\Administrator\Application Data\vlc
2008-09-08 03:31 --------- d-----w C:\Program Files\VideoLAN
2008-09-08 03:31 --------- d-----w C:\Program Files\Real Alternative
2008-09-08 03:30 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-09-08 01:08 --------- d-----w C:\Program Files\Common Files\DirectX
2008-09-08 01:02 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-07 23:32 --------- d-----w C:\Program Files\ExtraTools
2008-09-07 22:19 --------- d-----w C:\Program Files\Google
2008-09-07 21:50 --------- d-----w C:\Program Files\Winamp
2008-09-07 21:50 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Winamp
2008-09-07 20:36 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-09-07 20:33 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-07 20:33 --------- d-----w C:\Program Files\Analog Devices
2008-09-07 19:08 --------- d-----w C:\Program Files\Kaspersky Lab
2008-09-07 19:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-07 18:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-07 18:15 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-09-07 18:15 --------- d-----w C:\Program Files\Unlocker
2008-09-07 18:15 --------- d-----w C:\Program Files\Microsoft PowerToys
2008-09-07 18:15 --------- d-----w C:\Program Files\LClock
2008-09-07 18:15 --------- d-----w C:\Program Files\HashTab Shell Extension
2008-09-07 18:15 --------- d-----w C:\Program Files\Drive Space Indicator
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:28 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:28 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 11:12 295,936 ----a-w C:\WINDOWS\system32\wmpeffects.dll
2008-06-24 03:57 3,592,192 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:20 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:20 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-21 05:23 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:36 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:36 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:36 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:44 360,960 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:32 225,920 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-03-08 23:25 236 ---ha-w C:\Program Files\Common Files\dx.reg
.
------- Sigcheck -------
11/13/2007 09:00 PM 577536 7a540726ca75e1e988d56ab69925ba79 C:\WINDOWS\system32\user32.dll
11/13/2007 09:00 PM 2223616 95e8b55443bd91dab5632924d2616a1e C:\WINDOWS\system32\ntkrnlpa.exe
11/13/2007 09:00 PM 2346752 24fcd8fb0c6bd0e5f3b1203769948336 C:\WINDOWS\system32\ntoskrnl.exe
11/13/2007 09:00 PM 1647616 3d8a3ba32663082a2256f0eb986c3025 C:\WINDOWS\explorer.exe
11/13/2007 09:00 PM 40448 e00dfa816fa5521eb44c5d63109de2a9 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [11/13/2007 09:00 PM 40448]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [11/07/2007 03:34 PM 3739672]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [08/30/2007 05:43 PM 4670704]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [09/08/2008 05:49 AM 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [04/02/2008 01:49 AM 36352]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [09/12/2008 01:51 AM 77824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [11/13/2007 09:00 PM 40448]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [06/23/2008 11:57 PM 124928 C:\WINDOWS\system32\advpack.dll]
"RunNarrator"="Narrator.exe" [11/13/2007 09:00 PM 55808 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ExtraDNS.lnk - C:\Program Files\ExtraTools\ExtraDNS\ExtraDNS.exe [2008-09-08 594460]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 11/13/2007 09:00 PM 40448 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveSpace]
--a------ 11/10/2007 06:44 PM 247949 C:\Program Files\Drive Space Indicator\DrvSpace.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 07/01/2004 11:58 AM 118784 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 07/01/2004 12:02 PM 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LClock]
--a------ 09/19/2004 12:27 PM 65536 C:\Program Files\LClock\LClock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
--a------ 09/07/2006 01:19 PM 15872 C:\Program Files\Unlocker\UnlockerAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\ExtraTools\\ExtraDNS\\ExtraDNS.dll"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
S2 cdralw;NVIDIA Compatible Windows Miniport Driver;C:\WINDOWS\system32\DRIVERS\nvmini.sys [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WudfServiceGroup REG_SZ hex(7):57,00,55,00,44,00,46,00,53,00,76,00,63,00,00,00,00,00
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xr6piah2.default\
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava11.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava12.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava13.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava14.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjava32.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0\bin\npoji610.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-14 08:28:44
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
.
Completion time: 09/14/2008 8:29:41
ComboFix-quarantined-files.txt 2008-09-14 01:29:38
ComboFix2.txt 2008-09-14 01:20:58
Pre-Run: 1,292,550,144 bytes free
Post-Run: 1,284,124,672 bytes free
171 --- E O F --- 2008-09-10 20:10:40