راااااااااائع أنتهت مشكلة المتصفح وهذا التقرير :
ComboFix 08-10-25.01 - homoudsh 10/27/2008 1:51:16.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.600 [GMT 3:00]
Running from: C:\Documents and Settings\homoudsh\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\x64
E:\Autorun.inf
E:\EXPLORER.EXE
.
((((((((((((((((((((((((( Files Created from 2008-09-26 to 2008-10-26 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-26 22:55 4,784 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-26 22:55 38,876 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-26 22:55 28,448 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-26 22:55 2,512,416 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-26 22:55 18,030 ----a-w C:\WINDOWS\system32\drivers\DeskLock.sys
2008-10-26 18:57 --------- d-----w C:\Program Files\Open
2008-10-24 23:23 --------- d-----w C:\Program Files\Launch Manager
2008-10-24 23:18 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-10-24 04:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Raxco
2008-10-24 04:27 --------- d-----w C:\Program Files\Raxco
2008-10-24 04:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Protexis
2008-10-24 03:55 --------- d-----w C:\Program Files\Systerac XP Tools 4
2008-10-24 01:09 --------- d-----w C:\Program Files\Talisman 2
2008-10-24 00:25 --------- d-----w C:\Program Files\Desktop Lock
2008-10-24 00:25 --------- d-----w C:\Documents and Settings\homoudsh\Application Data\TopLang
2008-10-23 18:26 --------- d-----w C:\Program Files\Your Uninstaller 2008
2008-10-23 18:26 --------- d-----w C:\Documents and Settings\homoudsh\Application Data\URSoft
2008-10-23 17:46 --------- d-----w C:\Program Files\TechSmith
2008-10-23 17:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\TechSmith
2008-10-23 12:44 262,144 ----a-w C:\ntuser.dat
2008-10-23 12:44 --------- d-----w C:\Documents and Settings\homoudsh\Application Data\Yahoo!
2008-10-23 05:22 --------- d-----w C:\Program Files\CONEXANT
2008-10-23 03:48 --------- d-----w C:\Program Files\War Chess
2008-10-23 03:48 --------- d-----w C:\Program Files\ReflexiveArcade
2008-10-23 03:28 --------- d-----w C:\Program Files\EASIS
2008-10-20 22:41 155,995 ----a-w C:\WINDOWS\java\Packages\B35F5RTF.ZIP
2008-10-19 23:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-10-19 22:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-10-19 22:01 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-10-19 22:01 --------- d-----w C:\Program Files\Circle Developement
2008-10-19 06:54 --------- d-----w C:\Program Files\MessengerPlus! 3
2008-10-19 06:54 --------- d-----w C:\Program Files\Adverts
2008-10-19 06:33 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-10-19 06:33 172,032 ------w C:\WINDOWS\Setup1.exe
2008-10-19 05:36 --------- d-----w C:\Program Files\Hotspot Shield
2008-10-19 03:33 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE
2008-10-19 00:26 --------- d-----w C:\Documents and Settings\homoudsh\Application Data\SlipStream
2008-10-19 00:23 --------- d-----w C:\Program Files\Capture Professional v6 Trial
2008-10-19 00:06 --------- d-----w C:\Program Files\Registry Compressor
2008-10-16 08:38 --------- d-----w C:\Documents and Settings\homoudsh\Application Data\ErrorSmart
2008-10-16 08:37 --------- d-----w C:\Program Files\ErrorSmart
2008-10-16 06:37 --------- d-----w C:\Program Files\RegistryCleanerPro
2008-10-15 16:35 337,408 ------w C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-13 18:38 --------- d-----w C:\Program Files\Giganology
2008-10-13 10:22 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-10-13 07:43 --------- d-----w C:\Program Files\Adobe Media Player
2008-10-13 07:42 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-10-13 03:03 --------- d-----w C:\Documents and Settings\homoudsh\Application Data\DivX
2008-10-12 23:41 --------- d-----w C:\Program Files\Common Files\Ahead
2008-10-12 23:41 --------- d-----w C:\Program Files\Ahead
2008-10-12 23:27 --------- d-----w C:\Documents and Settings\homoudsh\Application Data\Search Settings
2008-10-12 23:26 --------- d-----w C:\Program Files\Dealio
2008-10-12 23:26 --------- d-----w C:\Documents and Settings\homoudsh\Application Data\Dealio
2008-10-12 23:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-10-12 23:23 --------- d-----w C:\Program Files\Yahoo!
2008-10-12 23:22 --------- d-----w C:\Program Files\DivX
2008-10-12 23:06 --------- d-----w C:\Program Files\Red Kawa
2008-10-12 22:23 --------- d-----w C:\Program Files\AVI Movie Player
2008-10-12 22:22 --------- d-----w C:\Program Files\GRETECH
2008-10-12 22:21 --------- d-----w C:\Documents and Settings\homoudsh\Application Data\Talkback
2008-10-12 22:06 --------- d-----w C:\Program Files\Real
2008-10-12 22:06 --------- d-----w C:\Program Files\Common Files\Real
2008-10-12 20:13 --------- d-----w C:\Program Files\Reference Assemblies
2008-10-12 20:13 --------- d-----w C:\Program Files\MSBuild
2008-10-12 16:17 --------- d-----w C:\Documents and Settings\homoudsh\Application Data\Uniblue
2008-10-12 16:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2008-10-12 14:49 --------- d-----w C:\Program Files\PC Drivers HeadQuarters
2008-10-12 14:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-10-11 23:51 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-10-11 23:41 --------- d-sh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-10-11 23:41 --------- d-----w C:\Program Files\Windows Live
2008-10-11 23:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-10-11 09:13 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-10-11 00:21 --------- d-----w C:\Program Files\MSXML 6.0
2008-10-10 10:26 --------- d-----w C:\Program Files\Error Repair Professional
2008-10-10 09:43 --------- d-----w C:\Documents and Settings\homoudsh\Application Data\MyProxy
2008-10-10 09:39 --------- d-----w C:\Program Files\IP Address Shield
2008-10-10 09:36 --------- d-----w C:\Program Files\IEHistoryX
2008-10-10 09:36 --------- d-----w C:\Documents and Settings\homoudsh\Application Data\585Soft
2008-10-10 09:33 --------- d-----w C:\Program Files\Hotspot_Shield
2008-10-10 09:33 --------- d-----w C:\Program Files\Conduit
2008-10-10 08:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-10-10 07:38 355,584 ----a-w C:\WINDOWS\system32\TuneUpDefragService.exe
2008-10-10 07:38 --------- d-----w C:\Documents and Settings\homoudsh\Application Data\TuneUp Software
2008-10-10 07:37 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-10-10 07:37 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-10-10 07:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-10-10 07:03 --------- d-----w C:\Program Files\Spyware Doctor
2008-10-10 05:27 --------- d-----w C:\Program Files\InTouchLock
2008-10-10 02:48 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-10-10 02:48 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-10-10 02:48 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-10-10 02:30 --------- d-----w C:\Program Files\GetData
2008-10-10 02:30 --------- d-----w C:\Program Files\Flash File Recovery
2008-10-10 02:29 --------- d-----w C:\Program Files\Flash Recovery Toolbox
2008-10-10 02:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-10 01:42 --------- d-----w C:\Program Files\Kaspersky Lab
2008-10-10 01:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-10-10 01:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-10 00:25 --------- d-----w C:\Program Files\Google
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{c95a4e8e-816d-4655-8c79-d736da1adb6d}"= "C:\Program Files\Hotspot_Shield\tbHot0.dll" [06/24/2008 11:17 PM 1569304]
[HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
06/24/2008 11:17 PM 1569304 --a------ C:\Program Files\Hotspot_Shield\tbHot0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{c95a4e8e-816d-4655-8c79-d736da1adb6d}"= "C:\Program Files\Hotspot_Shield\tbHot0.dll" [06/24/2008 11:17 PM 1569304]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}"= "C:\Program Files\Hotspot_Shield\tbHot0.dll" [06/24/2008 11:17 PM 1569304]
[HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 09:29 PM 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [10/19/2008 02:15 AM 171448]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [10/19/2008 09:54 AM 190024]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [10/18/2007 11:34 AM 5724184]
"Messenger (Yahoo!)"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [09/19/2008 05:34 PM 4347120]
"Search Protection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [06/26/2008 02:01 PM 111856]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [06/26/2008 02:01 PM 111856]
"DaVinci"="C:\Program Files\Open\Da Vinci\DaVinci.exe" [07/12/2006 04:15 PM 2234880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [04/16/2007 11:24 AM 819200]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [04/16/2007 11:22 AM 970752]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 10:50 AM 155648]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [06/13/2007 07:56 AM 142104]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [06/13/2007 07:55 AM 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [06/13/2007 07:55 AM 138008]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [06/26/2008 02:01 PM 111856]
"Desktop Lock Loader"="C:\PROGRA~1\DESKTO~1\TLDL.EXE" [05/02/2008 01:05 PM 151552]
"Registry Compact"="C:\Program Files\Systerac XP Tools 4\regcomp.exe" [11/09/2006 04:20 PM 659456]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [10/17/2007 05:59 AM 858632]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [02/08/2008 06:36 PM 227856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 09:29 PM 15360]
C:\Documents and Settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-09-11 525664]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-04-01 568176]
SnagIt 8.lnk - C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe [2007-05-01 6395464]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableLockWorkstation"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"DisableLockWorkstation"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCloseDragDropBands"= 0 (0x0)
"NoLogOff"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoCloseDragDropBands"= 0 (0x0)
"NoLogOff"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\WINDOWS\\System32\\dpvsetup.exe"=
R1 DaVinciDr;DaVinciDr;C:\WINDOWS\system32\drivers\DaVinciDr.sys [06/29/2006 03:13 PM 7552]
R1 DeskLock;DeskLock;C:\WINDOWS\system32\drivers\DeskLock.sys [10/27/2008 01:55 AM 18030]
R2 PD91Agent;PD91Agent;C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe [01/16/2008 10:52 AM 664840]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [04/14/2008 09:30 PM 14336]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [01/24/2008 12:25 AM 27136]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [12/13/2007 01:28 PM 24592]
S3 PD91Engine;PD91Engine;C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe [01/16/2008 10:52 AM 894216]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [10/10/2008 10:38 AM 355584]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0f45eae6-a221-11dd-a37a-00197e6c0837}]
\Shell\AutoRun\command - G:\xih9.cmd
\Shell\explore\Command - G:\xih9.cmd
\Shell\open\Command - G:\xih9.cmd
.
s of the 'Scheduled Tasks' folder
2008-10-26 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe [06/23/2008 04:53 PM]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\homoudsh\Application Data\Mozilla\Firefox\Profiles\bsivjdny.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
.
.
------- File Associations -------
.
txtfile=NOTEPAD %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-27 01:57:40
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\catchme]
"ImagePath"="\??\C:\DOCUME~1\homoudsh\LOCALS~1\Temp\catchme.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\catchme]
"ImagePath"="\??\C:\DOCUME~1\homoudsh\LOCALS~1\Temp\catchme.sys"
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\WIDCOMM\BLUETOOTH SOFTWARE\BIN\BTWDINS.EXE
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\S24EVMON.EXE
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\EVTENG.EXE
C:\PROGRAM FILES\HOTSPOT SHIELD\BIN\OPENVPNAS.EXE
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\REGSRVC.EXE
C:\PROGRAM FILES\DESKTOP LOCK\TLDL.EXE
C:\PROGRAM FILES\LAUNCH MANAGER\LMANAGER.EXE
C:\WINDOWS\SYSTEM32\IGFXSRVC.EXE
C:\WINDOWS\SYSTEM32\IGFXEXT.EXE
C:\PROGRAM FILES\TECHSMITH\SNAGIT 8\TSCHELP.EXE
C:\PROGRAM FILES\TECHSMITH\SNAGIT 8\SNAGPRIV.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 10/27/2008 2:00:04 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-26 23:00:00
Pre-Run: 20,362,231,808 bytes free
Post-Run: 20,333,871,104 bytes free
274 --- E O F --- 2008-10-23 23:21:47