مع فائق احترامي وتقديري لك اختي خلود وبالنسبة للأداتين حملتها وبالنسبة للأداة الأولى هذا هو التقرير
ComboFix 08-11-13.02 - Administrator 11/15/2008 21:52:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.201 [GMT 3:00]
Running from: c:\documents and settings\Administrator\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Application Data\addon.dat
c:\program files\Bifrost
c:\program files\bifrost\klog.dat
.
((((((((((((((((((((((((( Files Created from 2008-10-15 to 2008-11-15 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-15 19:06 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-15 18:56 4,436 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-15 18:56 368,672 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-15 18:56 16,740 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-15 18:56 1,602,080 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-12 21:59 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-10 18:36 --------- d-----w c:\windows\system32\config\systemprofile\Application Data\FreeHotBabesScreensaver
2008-11-03 21:05 --------- d-----w c:\program files\TuneUp Utilities 2008
2008-11-03 11:41 --------- d-----w c:\program files\HP
2008-11-03 11:41 --------- d-----w c:\program files\Hewlett-Packard
2008-11-03 10:17 --------- d-----w c:\documents and settings\Administrator\Application Data\Skype
2008-11-03 10:07 --------- d-----w c:\documents and settings\Administrator\Application Data\skypePM
2008-11-01 19:59 --------- d-----w c:\program files\Skype
2008-11-01 19:59 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-11-01 19:58 --------- d-----w c:\program files\Common Files\Skype
2008-10-31 19:42 65,385 ----a-w c:\windows\BricoPackUninst.cmd
2008-10-31 19:42 6,112 ----a-w c:\windows\BricoPackFoldersDelete.cmd
2008-10-31 13:09 --------- d-----w c:\program files\Axialis
2008-10-31 12:17 --------- d-----w c:\program files\MSN Messenger
2008-10-31 12:17 --------- d-----w c:\program files\Messenger Plus! Live
2008-10-31 12:17 --------- d-----w c:\program files\Circle Developement
2008-10-31 07:09 --------- d-----w c:\documents and settings\Administrator\Application Data\Thinking Minds Budiling Bytes
2008-10-26 21:24 --------- d-----w c:\documents and settings\All Users\Application Data\FreeHotBabesScreensaver
2008-10-26 21:23 --------- d-----w c:\documents and settings\Administrator\Application Data\FreeHotBabesScreensaver
2008-10-25 20:49 --------- d-----w c:\documents and settings\Administrator\Application Data\Image Zone Express
2008-10-25 17:02 --------- d-----w c:\documents and settings\Administrator\Application Data\HP
2008-10-25 16:05 --------- d-----w c:\documents and settings\All Users\Application Data\HP
2008-10-25 15:54 --------- d-----w c:\program files\Common Files\Hewlett-Packard
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 20:22 --------- d-----w c:\program files\MSN Pictures Displayer
2008-10-16 20:22 --------- d-----w c:\documents and settings\Administrator\Application Data\MSN Pictures Displayer
2008-10-15 16:06 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-10-15 14:09 --------- d-----w c:\program files\Adverts
2008-10-07 06:22 --------- d-----w c:\documents and settings\Administrator\Application Data\Orbit
2008-10-06 23:57 --------- d-----w c:\documents and settings\Administrator\Application Data\GrabPro
2008-10-06 15:48 --------- d-----w c:\program files\Evil Msn
2008-10-05 05:11 --------- d-----w c:\program files\Hanami
2008-10-04 22:05 --------- d-----w c:\program files\MouseAround
.
------- Sigcheck -------
04/21/2008 09:56 AM 665088 5e6599f286dca71723cae03c388770c5 c:\windows\$hf_mig$\KB950759\SP2QFE\wininet.dll
04/21/2008 09:42 AM 664576 908b749bc0864b68b5be77bc530b63bd c:\windows\$hf_mig$\KB950759\SP3GDR\wininet.dll
04/21/2008 09:24 AM 665088 5d9314f5fad444882b68d49b23429d75 c:\windows\$hf_mig$\KB950759\SP3QFE\wininet.dll
04/23/2008 07:19 AM 827392 154282ae8e63d03a7add87e50d061836 c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
06/23/2008 06:38 PM 827904 bd4be2824bc805da1f29385519b865f9 c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
08/26/2008 12:08 PM 827904 bceb6d8a6bea74628db977215081652a c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
04/21/2008 10:01 AM 657920 087391c34ae510d222ea2b4753bb8f5d c:\windows\$NtServicePackUninstall$\wininet.dll
04/14/2008 09:29 PM 664576 699b4dbfba7d4201d67c521e5df0670d c:\windows\$NtUninstallKB950759$\wininet.dll
08/04/2004 12:55 AM 654848 1e1cef80a11bdab92b2a83f885d214d5 c:\windows\$NtUninstallKB950759_0$\wininet.dll
04/21/2008 09:42 AM 664576 908b749bc0864b68b5be77bc530b63bd c:\windows\ie7\wininet.dll
08/13/2007 06:54 PM 818688 a4a0fc92358f39538a6494c42ef99fe9 c:\windows\ie7updates\KB950759-IE7\wininet.dll
04/23/2008 07:16 AM 826368 565098f166f21e24874ebc8cf89c623c c:\windows\ie7updates\KB953838-IE7\wininet.dll
06/23/2008 07:15 PM 826368 3f4bca25f29394995161e8e85d925c1a c:\windows\ie7updates\KB956390-IE7\wininet.dll
08/26/2008 10:57 AM 817152 931f9e64c1054d8418fb6719f157713c c:\windows\ServicePackFiles\i386\wininet.dll
08/26/2008 10:57 AM 817152 931f9e64c1054d8418fb6719f157713c c:\windows\system32\wininet.dll
08/26/2008 10:57 AM 826368 8d2003bbfffd5ff95ea66350e4d1e4c7 c:\windows\system32\dllcache\wininet.dll
04/14/2008 09:29 PM 974848 5320ea6507cfa8abc92caf91cd2fc8a5 c:\windows\explorer.exe
08/04/2004 12:56 AM 1029632 932f97b77f2625f7ff7dfc97552548f8 c:\windows\$NtServicePackUninstall$\explorer.exe
04/14/2008 09:29 PM 974848 5320ea6507cfa8abc92caf91cd2fc8a5 c:\windows\ServicePackFiles\i386\explorer.exe
07/18/2008 10:10 PM 68808 136896c2cdc3f689876e0d44485153ea c:\windows\ServicePackFiles\i386\wuauclt.exe
07/18/2008 10:10 PM 68808 136896c2cdc3f689876e0d44485153ea c:\windows\system32\wuauclt.exe
07/18/2008 10:10 PM 53448 d316e28958873859b88d72cf47ad1ea5 c:\windows\system32\dllcache\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [03/27/2008 02:12 PM 173368]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{215fa32b-b0f7-6d7f-002a-fbebadf0d30c}]
08/07/2008 02:54 PM 97792 --a------ c:\windows\system32\rfqibozfmswe.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{e795e28a-af8a-d108-f8bd-880759b738cb}]
11/06/2008 07:41 PM 573952 --a------ c:\windows\system32\nsn2D.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{EEE6C35C-6118-11DC-9C72-001320C79847}]
03/27/2008 02:12 PM 1164600 --a------ c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{FC740608-B791-515F-27AC-5BAC2DEACFDB}]
11/01/2008 12:46 PM 178176 --a------ c:\windows\system32\nzxdnekgaugofrxc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [03/27/2008 02:12 PM 1164600]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [03/27/2008 02:12 PM 1164600]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [04/14/2008 09:29 PM 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [11/01/2008 07:42 PM 68856]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [01/19/2007 12:55 PM 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [08/16/2008 08:59 AM 185896]
"pxwlpxaqgwcb"="c:\windows\system32\nzxdnekgaugofrxc.dll" [11/01/2008 12:46 PM 178176]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [05/08/2007 04:24 PM 54840]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [04/25/2008 06:21 PM 201992]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/14/2008 09:29 PM 15360]
c:\documents and settings\Administrator\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
MSN Pictures Displayer.lnk - c:\program files\MSN Pictures Displayer\MSN Pictures Displayer.exe [2008-10-16 4561920]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-19 630784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
09/07/2004 04:08 PM 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^قائمة ابدأ^البرامج^بدء التشغيل^Ela-Salaty.lnk]
path=c:\documents and settings\Administrator\قائمة ابدأ\البرامج\بدء التشغيل\Ela-Salaty.lnk
backup=c:\windows\pss\Ela-Salaty.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^قائمة ابدأ^البرامج^بدء التشغيل^Shortcut to Hanami.exe.lnk]
path=c:\documents and settings\Administrator\قائمة ابدأ\البرامج\بدء التشغيل\Shortcut to Hanami.exe.lnk
backup=c:\windows\pss\Shortcut to Hanami.exe.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
-ra------ 10/07/2005 02:13 PM 176128 c:\program files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 04/14/2008 09:29 PM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
--a------ 09/01/2005 05:24 PM 684032 c:\program files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HiYo]
--a------ 06/24/2008 02:26 PM 148784 c:\program files\HiYo\Bin\HiYo.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 09/20/2005 10:32 AM 77824 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 09/20/2005 10:36 AM 114688 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 09/20/2005 10:35 AM 94208 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 10/30/2004 02:59 PM 385024 c:\program files\Intel\Wireless\Bin\iFrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
--a------ 08/01/2008 02:54 AM 190024 c:\program files\MessengerPlus! 3\MsgPlus.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MouseAround]
--a------ 12/11/2001 11:34 PM 151552 c:\program files\MouseAround\MouseAround.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 06/10/2008 04:27 AM 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
-ra------ 03/27/2008 07:31 PM 111928 c:\program files\SweetIM\Messenger\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 08/16/2008 08:59 AM 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R2 UxTuneUp;TuneUp Theme Extension;c:\windows\System32\svchost.exe -k netsvcs [2004-08-04 14336]
R3 GTICARD;GTICARD;c:\windows\system32\DRIVERS\gticard.sys [2003-02-06 59328]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;c:\windows\System32\TuneUpDefragService.exe [2008-11-04 355584]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
s of the 'Scheduled Tasks' folder
2008-10-31 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [06/20/2008 09:09 AM]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-msnmsgr - ~c:\program files\MSN Messenger\MsnMsgr.Exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R0 -: HKLM-Main,Start Page = hxxp://home.sweetim.com
R1 -: HKCU-Internet Settings,ProxyOverride = local
O8 -: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-15 22:07:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\docume~1\ADMINI~1\LOCALS~1\Temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\LC.gif 379 bytes
c:\docume~1\ADMINI~1\LOCALS~1\Temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\LK.gif 377 bytes
c:\docume~1\ADMINI~1\LOCALS~1\Temp\__SkypeIEToolbar_Cache\e70d95847a8f5723cfca6b3fd9946506\static\famfamfam\ME.gif 330 bytes
scan completed successfully
hidden files: 3
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: c:\windows\explorer.exe
-> c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\windows\system32\scardsvr.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Dell\NicConfigSvc\NicConfigSvc.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\windows\system32\regsvr32.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
.
**************************************************************************
.
Completion time: 11/15/2008 22:10:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-15 19:10:17
Pre-Run: 23,604,228,096 bytes free
Post-Run: 23,781,466,112 bytes free
237 --- E O F --- 2008-11-12 22:06:34