سويتها
وهذا هو تقرير
عسه خير إن شاءالله
ComboFix 08-09-20.04 - khalid 09/21/2008 0:41:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.1488 [GMT 3:00]
Running from: D:\برامج\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
E:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-08-20 to 2008-09-20 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-20 21:49 491,552 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-20 21:49 --------- d-----w C:\Documents and Settings\khalid\Application Data\Orbit
2008-09-20 21:46 5,876 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-20 21:46 22,520 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-20 21:46 2,207,776 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-20 08:02 --------- d-----w C:\Program Files\CubedLabs YouTube Download & Convert
2008-09-20 06:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-20 04:23 --------- d-----w C:\Program Files\Common Files\xing shared
2008-09-20 04:23 --------- d-----w C:\Program Files\Common Files\Real
2008-09-19 22:08 66,144 ----a-w C:\WINDOWS\system32\drivers\snapman.sys
2008-09-19 22:08 371,200 ----a-w C:\WINDOWS\system32\autoprnt.exe
2008-09-19 22:08 37,888 ----a-w C:\WINDOWS\system32\setupnt.dll
2008-09-19 22:08 102,400 ----a-w C:\WINDOWS\system32\snapapi.dll
2008-09-17 11:24 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-09-17 05:01 --------- d-----w C:\Program Files\iVocalize Web Conference 4
2008-09-17 04:57 --------- d-----w C:\Program Files\LtUcx
2008-09-17 04:56 155,995 ----a-w C:\WINDOWS\java\Packages\9BNN3PJ9.ZIP
2008-09-16 22:03 --------- d-----w C:\Program Files\LeapFTP
2008-09-16 19:07 --------- d-----w C:\Program Files\Common Files\Acronis
2008-09-16 19:07 --------- d-----w C:\Program Files\Acronis
2008-09-15 22:41 --------- d-----w C:\Program Files\DVB-S PowerInstall
2008-09-15 22:41 --------- d-----w C:\Program Files\Common Files\Elecard
2008-09-15 19:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-09-15 19:21 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-15 19:21 --------- d-----w C:\Program Files\Circle Developement
2008-09-15 09:16 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-09-15 08:59 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-09-15 08:59 --------- d-----w C:\Documents and Settings\khalid\Application Data\Media Player Classic
2008-09-15 08:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-15 08:55 --------- d-----w C:\Program Files\vPlug Files Center
2008-09-15 08:28 --------- d-----w C:\Program Files\Orbitdownloader
2008-09-15 08:01 --------- d-----w C:\Program Files\MSXML 4.0
2008-09-15 07:59 --------- d-----w C:\Program Files\Microsoft Works
2008-09-15 07:23 --------- d-----w C:\Program Files\Windows Live
2008-09-15 07:07 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-09-15 07:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-09-15 06:40 --------- d-----w C:\Program Files\Real
2008-09-15 06:34 --------- d-----w C:\Program Files\Valve
2008-09-15 06:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-15 06:02 --------- d-----w C:\Program Files\TechniSat DVB
2008-09-15 06:02 --------- d-----w C:\Program Files\MainConcept
2008-09-15 06:02 --------- d-----w C:\Program Files\DVBViewerTE
2008-09-15 06:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Technisat
2008-09-15 06:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\CMUV
2008-09-15 05:55 --------- d-----w C:\Program Files\Microsoft.NET
2008-09-15 05:42 --------- d-----w C:\Program Files\Common Files\Ahead
2008-09-15 05:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-09-15 05:38 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-09-15 05:31 --------- d-----w C:\Documents and Settings\khalid\Application Data\ATI
2008-09-15 05:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\ATI
2008-09-15 05:16 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-09-15 05:16 --------- d-----w C:\Program Files\Kaspersky Lab
2008-09-15 05:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-15 05:11 --------- d-----w C:\Program Files\CyberLink
2008-09-15 05:08 --------- d-----w C:\Documents and Settings\khalid\Application Data\Ahead
2008-09-15 05:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-09-15 05:06 --------- d-----w C:\Program Files\Nero
2008-09-15 05:03 --------- d-----w C:\Program Files\ATI Technologies
2008-09-15 05:00 --------- d-----w C:\Program Files\Common Files\ATI Technologies
2008-09-15 04:55 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-15 04:52 16,608 ----a-w C:\WINDOWS\gdrv.sys
2008-09-15 03:45 --------- d-----w C:\Program Files\Realtek
2008-09-15 03:42 --------- d-----w C:\Program Files\AMD
2008-09-15 03:42 --------- d-----w C:\Documents and Settings\khalid\Application Data\InstallShield
2008-09-15 03:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-09-15 03:35 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-05 21:29 8,818,856 ----a-w C:\everestultimate460.zip
2008-07-29 17:21 218,376 ----a-w C:\WINDOWS\system32\klogon.dll
2008-07-29 17:20 24,774 ----a-w C:\WINDOWS\system32\drivers\klopp.dat
2008-07-21 15:34 121,872 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-07-18 19:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 19:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 19:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 19:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 19:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 19:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 19:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 19:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 19:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 19:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:27 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 15:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
2008-06-23 16:15 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:47 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"Steam"="C:\Program Files\Valve\Steam\Steam.exe" [09/15/2008 09:41 AM 1271032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="m–|\ü" [X]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [11/10/2006 12:35 PM 90112]
"NBKeyScan"="C:\Program Files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe" [09/17/2007 09:36 AM 1377576]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [03/14/2007 09:01 PM 71216]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [01/08/2007 10:17 PM 52256]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [03/01/2007 02:57 PM 153136]
"SecurDisc"="C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [11/26/2007 02:54 PM 1629480]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [11/26/2007 02:54 PM 1057064]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [09/20/2008 07:23 AM 185896]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [07/29/2008 08:20 PM 206088]
"RTHDCPL"="RTHDCPL.EXE" [12/20/2007 11:47 AM 16860672 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 06:59 PM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
07/22/2006 11:49 PM 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"C:\\Program Files\\LeapFTP\\LeapFTP.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/30/2008 06:06 PM 24592]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;C:\WINDOWS\system32\DRIVERS\SkyNET.SYS [06/09/2008 03:57 PM 418832]
.
- - - - ORPHANS REMOVED - - - -
Notify-WgaLogon - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.1tesh.com/vb
O8 -: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 -: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 -: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/202
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-21 00:48:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Program Files\TechniSat DVB\bin\Server4PC.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\TechniSat DVB\bin\Server4PC.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 09/21/2008 0:50:48 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-20 21:50:46
Pre-Run: 83,190,919,168 bytes free
Post-Run: 84,208,054,272 bytes free
185 --- E O F --- 2008-09-15 08:09:06