هذا بالنسبة للبرنامج الأول
ComboFix 08-11-11.01 - ALA 11/12/2008 17:22:43.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.596 [GMT 3:00]
Running from: c:\documents and settings\ALA\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\ALA\Application Data\addon.dat
c:\documents and settings\ALA\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
c:\program files\IEToolbar
c:\windows\system32\logon.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-12 to 2008-11-12 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-12 14:24 --------- d-----w c:\documents and settings\ALA\Application Data\DMCache
2008-11-12 11:54 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-11 16:40 573,472 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-11 16:40 5,136 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-11 16:40 24,792 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-11 16:40 2,766,880 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-09 17:10 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-18 23:53 96,976 ----a-w c:\windows\system32\drivers\klin.dat
2008-10-18 23:53 87,855 ----a-w c:\windows\system32\drivers\klick.dat
2008-10-17 14:36 --------- d-----w c:\program files\TeamViewer3
2008-10-10 10:12 --------- d-----w c:\documents and settings\ALA\Application Data\IDM
2008-10-10 09:46 --------- d-----w c:\program files\Internet Download Manager
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\win32k.sys
2008-09-14 17:10 --------- d-----w c:\program files\PCPitstop
2008-09-14 16:43 --------- d-----w c:\program files\DiskTrix
2008-09-14 11:21 --------- d-----w c:\program files\DM NetVu ObserVer
2008-09-14 11:01 --------- d-----w c:\program files\Java
2008-08-26 07:24 826,368 ----a-w c:\windows\system32\wininet.dll
2008-08-14 09:58 2,136,064 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:22 2,015,744 ----a-w c:\windows\system32\ntkrnlpa.exe
2008-06-05 01:25 1,126 --sha-w c:\windows\Bifrost\klog.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
08/19/2008 09:20 AM 66912 --a------ c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [06/16/2008 02:55 AM 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [09/28/2007 04:48 PM 282624]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [08/24/2007 07:00 AM 33648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [08/24/2007 03:18 AM 437160]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [11/09/2006 05:15 PM 1634304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codec"= l3codecp.acm
"msacm.speex32"= speex32.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
backup=c:\windows\pss\PalTalk.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdVantage
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PURE UPLOAD
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegDoctor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Regscan
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 08/03/2007 12:51 PM 202024 c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 08/04/2004 01:56 AM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 09/05/2008 03:13 AM 133104 c:\documents and settings\ALA\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 08/24/2007 07:00 AM 33648 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
-ra------ 12/13/2005 05:41 PM 77824 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
-ra------ 12/13/2005 05:45 PM 118784 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
-ra------ 12/13/2005 05:44 PM 98304 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsgCenterExe]
--a------ 06/16/2008 02:55 AM 69632 c:\program files\Common Files\Real\Update_OB\RealOneMessageCenter.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 10/18/2007 11:34 AM 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 08/08/2007 09:25 AM 1828136 c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nero PhotoShow Media Manager]
--a------ 04/27/2007 09:22 PM 312848 c:\progra~1\Nero\PHOTOS~1\data\Xtras\mssysmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 03/01/2007 03:57 PM 153136 c:\program files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder]
-ra------ 01/30/2006 07:00 PM 98304 c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 01/23/2007 11:19 AM 223232 c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 09/28/2007 04:48 PM 282624 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RocketDock]
--a------ 03/19/2007 01:05 AM 630784 c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 05/30/2008 03:54 PM 21718312 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 11/10/2005 01:03 PM 36975 c:\program files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 10/10/2007 02:59 AM 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 06/16/2008 02:55 AM 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
--a------ 07/23/2008 01:16 PM 1927448 c:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC]
--a------ 05/02/2008 03:15 PM 9442584 c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VisualTaskTips]
--a------ 08/16/2007 06:33 AM 36352 c:\program files\VisualTaskTips\VisualTaskTips.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 11/03/2006 07:20 PM 866584 c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"c:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\ALA\\Desktop\\دريم\\WinGrabZ.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\english\\setup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\ALA\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\DM NetVu ObserVer\\DM NetVu ObserVer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13758:TCP"= 13758:TCP:BitComet 13758 TCP
"13758:UDP"= 13758:UDP:BitComet 13758 UDP
"24455:TCP"= 24455:TCP

ORT_24455
"30511:TCP"= 30511:TCP

ORT_30511
"9273:TCP"= 9273:TCP

ORT_9273
"21950:TCP"= 21950:TCP

ORT_21950
"44297:TCP"= 44297:TCP

ORT_44297
"35789:TCP"= 35789:TCP

ORT_35789
"34117:TCP"= 34117:TCP

ORT_34117
"5196:TCP"= 5196:TCP

ORT_5196
"45856:TCP"= 45856:TCP

ORT_45856
"30192:TCP"= 30192:TCP

ORT_30192
"20883:TCP"= 20883:TCP

ORT_20883
"61996:TCP"= 61996:TCP

ORT_61996
"62457:TCP"= 62457:TCP

ORT_62457
"46445:TCP"= 46445:TCP

ORT_46445
"35129:TCP"= 35129:TCP

ORT_35129
"42332:TCP"= 42332:TCP

ORT_42332
"28570:TCP"= 28570:TCP

ORT_28570
"29117:TCP"= 29117:TCP

ORT_29117
"26539:TCP"= 26539:TCP

ORT_26539
"52623:TCP"= 52623:TCP

ORT_52623
"50102:TCP"= 50102:TCP

ORT_50102
"11890:TCP"= 11890:TCP

ORT_11890
"21426:TCP"= 21426:TCP

ORT_21426
"9055:TCP"= 9055:TCP

ORT_9055
"5895:TCP"= 5895:TCP

ORT_5895
"10848:TCP"= 10848:TCP

ORT_10848
"46968:TCP"= 46968:TCP

ORT_46968
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM 26640]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187.sys [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9a7df9c0-ee6f-11dc-ac56-00c0ca19d4b4}]
\Shell\AutoRun\command - G:\oufddh.exe
\Shell\explore\Command - G:\oufddh.exe
\Shell\open\Command - G:\oufddh.exe
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-11-12 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\ALA\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [09/05/2008 03:13 AM]
2008-11-12 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [11/03/2006 07:20 PM]
2008-10-15 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [05/02/2008 03:15 PM]
2008-08-06 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [05/02/2008 03:15 PM]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{1A295E8E-E51B-42CE-81B2-B73614F0FCD2} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\ALA\Application Data\Mozilla\Firefox\Profiles\fddzbg1z.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_03\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_03\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_03\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_03\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_03\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_03\bin\NPJPI150_03.dll
FF -: plugin - c:\program files\Java\jre1.5.0_03\bin\NPOJI610.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-12 17:24:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 11/12/2008 17:26:01
ComboFix-quarantined-files.txt 2008-11-12 14:25:06
Pre-Run: 8,158,535,680 bytes free
Post-Run: 8,187,088,896 bytes free
221 --- E O F --- 2008-11-08 06:42:32