هذا تقرير ال combo fix
ComboFix 08-10-09.06 - hcc 10/10/2008 13:15:11.2 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.44 [GMT 3:00]
Running from: C:\Documents and Settings\hcc\سطح المكتب\برامج حذف فايروس المكافح الكذاب\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-09-10 to 2008-10-10 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-10 10:24 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-10 10:24 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-10 10:24 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-10 10:24 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-10 08:26 --------- d-----w C:\Program Files\Folder Lock 6
2008-10-09 09:44 --------- d-----w C:\Documents and Settings\hcc\Application Data\URSoft
2008-10-09 09:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-09 03:34 --------- d-----w C:\Documents and Settings\hcc\Application Data\Malwarebytes
2008-10-07 07:53 --------- d-----w C:\Program Files\a-squared Anti-Malware
2008-10-07 06:41 --------- d-----w C:\Program Files\anoooos
2008-10-07 06:41 --------- d-----w C:\Documents and Settings\hcc\Application Data\DMCache
2008-10-05 10:58 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-10-05 10:15 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-10-05 06:16 --------- d-----w C:\Documents and Settings\hcc\Application Data\SlipStream
2008-10-02 11:52 --------- d-----w C:\Program Files\Sidebar
2008-10-01 20:07 --------- d-----w C:\Program Files\Thoosje Vista Sidebar
2008-09-28 04:21 --------- d-----w C:\Documents and Settings\hcc\Application Data\IDM
2008-09-28 03:13 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-27 23:22 --------- d-----w C:\Program Files\Registry Compressor
2008-09-27 22:58 --------- d-----w C:\Program Files\Registry Fast
2008-09-27 16:08 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-09-27 16:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-27 07:18 --------- d-----w C:\Program Files\The KMPlayer
2008-09-26 00:03 355,584 ----a-w C:\WINDOWS\system32\TuneUpDefragService.exe
2008-09-26 00:03 --------- d-----w C:\Documents and Settings\hcc\Application Data\TuneUp Software
2008-09-26 00:01 --------- d-----w C:\Program Files\Data
2008-09-25 23:32 --------- d-----w C:\Program Files\Common Files\xing shared
2008-09-25 10:15 --------- d-----w C:\Documents and Settings\hcc\Application Data\CyberScrub
2008-09-25 10:15 --------- d-----w C:\Documents and Settings\hcc\Application Data\cleaner
2008-09-17 22:43 --------- d-----w C:\Program Files\ACD Systems
2008-09-16 13:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg8
2008-09-11 13:56 --------- d-----w C:\Program Files\CCleaner
2008-09-09 21:07 38,528 ----a-w C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-09 21:07 17,200 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-09-05 20:30 266,792 ------w C:\WINDOWS\system32\dllcache\wgaLogon.dll
2008-09-05 20:29 942,632 ------w C:\WINDOWS\system32\dllcache\WgaTray.exe
2008-09-04 00:12 --------- d-----w C:\Program Files\Alwil Software
2008-09-03 23:03 --------- d-----w C:\Program Files\Avira
2008-09-03 23:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-09-03 22:29 --------- d-----w C:\Program Files\AVG
2008-09-02 06:00 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-09-01 09:23 --------- d-----w C:\Program Files\Common Files\Panda Software
2008-09-01 06:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Winferno
2008-08-12 12:32 --------- d-----w C:\Program Files\Hotspot Shield
2008-08-12 06:52 10,368 ----a-w C:\WINDOWS\system32\drivers\pfc.sys
2008-08-09 18:26 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-08-09 18:26 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-07-29 17:21 218,376 ----a-w C:\WINDOWS\system32\klogon.dll
2008-07-18 19:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 19:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 19:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 19:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 19:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 19:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 19:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 19:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 19:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 19:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 19:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 19:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 19:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 19:08 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 19:08 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 19:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 19:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-06-20 06:09 177,920 ----a-w C:\Program Files\UninstallManager.exe
2008-06-19 14:13 563,200 ----a-w C:\Program Files\GR32_D6.bpl
2008-06-19 14:12 644,608 ----a-w C:\Program Files\MSI_D6.bpl
2008-06-19 14:12 643,072 ----a-w C:\Program Files\MainControls.bpl
2008-06-19 14:12 54,272 ----a-w C:\Program Files\ehs_d6.bpl
2008-06-19 14:12 282,112 ----a-w C:\Program Files\VisControls.bpl
2008-06-19 14:12 279,040 ----a-w C:\Program Files\SysInfo.bpl
2008-06-19 14:12 131,584 ----a-w C:\Program Files\CommonForms.bpl
2008-06-19 14:12 129,536 ----a-w C:\Program Files\AppInitialization.bpl
2008-06-19 14:12 127,488 ----a-w C:\Program Files\TUIcoEngineerDirTree.bpl
2008-04-01 13:17 2,293,848 ----a-w C:\Program Files\FLV PlayerFCSetup.exe
2008-04-01 05:12 4,265,560 ----a-w C:\Program Files\FLV PlayerRCATSetup.exe
2008-04-01 05:02 411,248 ----a-w C:\Program Files\FLV PlayerRCSetup.exe
2008-03-07 12:23 111,872 ----a-w C:\Program Files\NtfsLib.dll
2007-09-10 10:35 198,656 ----a-w C:\Program Files\vclx100.bpl
2007-09-05 13:19 97,792 ----a-w C:\Program Files\vcljpg100.bpl
2007-09-05 13:18 852,992 ----a-w C:\Program Files\rtl100.bpl
2007-09-05 13:18 1,868,800 ----a-w C:\Program Files\vcl100.bpl
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"IDMan"="C:\Program Files\anoooos\Internet Download Manager\IDMan.exe" [09/01/2008 07:04 PM 2606512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [09/26/2008 02:31 AM 185872]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [07/29/2008 08:20 PM 206088]
"BluetoothAuthenticationAgent"="bthprops.cpl" [04/14/2008 07:00 PM 110592 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 06:59 PM 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"DisableLockWorkstation"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuPinnedList"= 0 (0x0)
"NoStartMenuMFUprogramsList"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinterTabs"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChange"= 0 (0x0)
"NoChangeKeyboardNavigationIndicators"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.speex32"= speex32.acm
"VIDC.ACDV"= ACDV.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
???? [?]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]
???? [?]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\a-squared]
--a------ 10/04/2008 12:24 PM 2776720 C:\Program Files\a-squared Anti-Malware\a2guard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDog305]
--------- 08/05/2005 10:15 AM 61440 C:\WINDOWS\VM305_STI.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
--a------ 06/07/2005 11:31 AM 819712 C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando]
--a------ 07/01/2008 04:18 PM 6587720 C:\Program Files\Pando Networks\Pando\pando.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 04/14/2008 07:00 PM 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mssadv.exe]
-ra------ 12/29/2004 01:01 AM 544768 C:\WINDOWS\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
-ra------ 12/29/2004 01:01 AM 544768 C:\WINDOWS\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\English\\setup.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=
"C:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP

oVoo TCP port 443
"443:UDP"= 443:UDP

oVoo UDP port 443
"37674:TCP"= 37674:TCP

oVoo TCP port 37674
"37674:UDP"= 37674:UDP

oVoo UDP port 37674
"37675:UDP"= 37675:UDP

oVoo UDP port 37675
"57246:TCP"= 57246:TCP

ando P2P TCP Listening Port
"57246:UDP"= 57246:UDP

ando P2P UDP Listening Port
"56366:TCP"= 56366:TCP

ando P2P TCP Listening Port
"56366:UDP"= 56366:UDP

ando P2P UDP Listening Port
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/30/2008 06:06 PM 24592]
R3 MPNatDrv;Artera NAT Driver;C:\WINDOWS\system32\DRIVERS\mpnat2k.sys [03/15/2007 01:25 PM 215968]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [01/24/2008 12:25 AM 27136]
S2 WinFl32;WinFl32;C:\WINDOWS\system32\WinFl32.sys [ ]
S2 WinVd32;WinVd32;C:\WINDOWS\system32\WinVd32.sys [ ]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [09/26/2008 03:03 AM 355584]
S3 vvftav;vvftav;C:\WINDOWS\system32\drivers\vvftav.sys [02/02/2007 09:38 PM 474368]
S3 ZSMC0305;USB PC Camera VC305;C:\WINDOWS\system32\Drivers\usbVM305.sys [03/08/2007 07:05 PM 1466624]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{03a46314-630d-11dd-83f3-9ae51b75034e}]
\Shell\AutoRun\command - 096.bat
\Shell\explore\Command - 096.bat
\Shell\open\Command - 096.bat
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\hcc\Application Data\Mozilla\Firefox\Profiles\3p6miy3l.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com.sa/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-10 13:28:06
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\A-SQUARED ANTI-MALWARE\A2SERVICE.EXE
C:\PROGRAM FILES\HOTSPOT SHIELD\BIN\OPENVPNAS.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\anoooos\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 10/10/2008 13:31:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-10 10:30:36
ComboFix2.txt 2008-09-27 17:39:34
Pre-Run: 10,999,267,328 bytes free
Post-Run: 11,284,004,864 bytes free
226