أوكي هذا التقرير
ComboFix 08-11-21.02 - owner 2008-11-21 22:25:08.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.652 [GMT -8:00]
Running from: c:\documents and settings\owner\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-10-22 to 2008-11-22 )))))))))))))))))))))))))))))))
.
2008-11-21 21:14 . 2008-11-21 21:30 <DIR> d-------- c:\program files\Common Files\Adobe
2008-11-21 20:55 . 2008-11-21 20:55 <DIR> d-------- c:\program files\IEPro
2008-11-21 19:20 . 2008-11-21 22:02 <DIR> d-------- C:\kasper_update
2008-11-21 18:50 . 2008-07-18 22:07 270,880 --a------ c:\windows\system32\mucltui.dll
2008-11-21 18:50 . 2008-07-18 22:07 210,976 --a------ c:\windows\system32\muweb.dll
2008-11-21 18:50 . 2008-07-18 22:07 29,728 --a------ c:\windows\system32\mucltui.dll.mui
2008-11-21 18:25 . 2008-11-21 18:28 <DIR> d-------- c:\program files\AviSynth 2.5
2008-11-21 18:25 . 2008-11-21 18:29 <DIR> d-------- c:\program files\Aegisub
2008-11-21 03:50 . 2008-11-21 03:50 <DIR> d-------- c:\program files\Kaspersky Lab
2008-11-21 03:50 . 2008-11-21 21:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-21 03:50 . 2008-11-21 22:25 1,680,928 --ahs---- c:\windows\system32\drivers\fidbox.dat
2008-11-21 03:50 . 2008-11-21 04:19 96,976 --a------ c:\windows\system32\drivers\klin.dat
2008-11-21 03:50 . 2008-11-21 04:19 87,855 --a------ c:\windows\system32\drivers\klick.dat
2008-11-21 03:50 . 2008-11-21 22:26 83,488 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2008-11-21 03:50 . 2008-11-21 21:36 24,716 --ahs---- c:\windows\system32\drivers\fidbox.idx
2008-11-21 03:50 . 2008-11-21 21:36 9,440 --ahs---- c:\windows\system32\drivers\fidbox2.idx
2008-11-21 03:46 . 2008-11-21 03:46 <DIR> d-------- c:\documents and settings\owner\Application Data\IEPro
2008-11-21 03:38 . 2008-11-21 03:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-21 02:36 . 2008-10-03 09:41 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2008-11-21 02:36 . 2007-04-17 01:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2008-11-21 02:36 . 2007-03-07 21:10 991,232 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2008-11-21 02:36 . 2008-08-25 23:24 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2008-11-21 02:36 . 2008-08-25 23:24 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2008-11-21 02:36 . 2008-08-25 23:24 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2008-11-21 02:36 . 2008-08-25 23:24 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2008-11-21 02:36 . 2008-08-25 23:24 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2008-11-21 02:36 . 2008-08-25 00:38 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2008-11-21 01:46 . 2008-11-21 01:46 <DIR> d-------- c:\program files\x264
2008-11-21 01:46 . 2008-11-21 01:46 580,114 --a------ c:\windows\system32\x264vfw.dll
2008-11-21 01:25 . 2008-11-21 03:19 <DIR> d-------- c:\program files\NOS
2008-11-21 01:25 . 2008-11-21 01:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS
2008-11-21 01:22 . 2008-11-21 01:22 <DIR> d-------- c:\program files\fileflyer
2008-11-21 01:22 . 2008-11-21 01:22 <DIR> d-------- c:\program files\Conduit
2008-11-21 01:21 . 2008-11-21 21:47 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-11-21 01:20 . 2008-11-21 01:20 <DIR> d-------- c:\program files\uTorrent
2008-11-21 01:20 . 2008-11-21 01:20 <DIR> d-------- c:\program files\Google
2008-11-21 01:20 . 2008-11-21 03:09 <DIR> d-------- c:\program files\DAP
2008-11-21 01:20 . 2008-11-21 02:44 <DIR> d-------- c:\documents and settings\owner\Application Data\uTorrent
2008-11-21 01:20 . 2008-11-21 01:20 479,298 --a------ c:\windows\system32\wbocx.ocx
2008-11-21 01:20 . 2008-11-21 01:20 172,032 --a------ c:\windows\system32\AniGIF.ocx
2008-11-21 01:20 . 2008-11-21 01:20 50,688 --a------ c:\windows\system32\wbhelp2.dll
2008-11-21 00:38 . 2008-11-21 00:38 <DIR> d-------- c:\documents and settings\owner\Application Data\Thinstall
2008-11-21 00:29 . 2008-11-21 00:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-11-21 00:17 . 2008-11-21 00:17 <DIR> d-------- c:\program files\Messenger Plus! Live
2008-11-21 00:17 . 2008-11-21 00:17 <DIR> d-------- c:\program files\Circle Developement
2008-11-21 00:15 . 2008-11-21 00:35 <DIR> d-------- c:\documents and settings\owner\Contacts
2008-11-21 00:14 . 2008-11-21 00:14 <DIR> d----c--- c:\windows\system32\DRVSTORE
2008-11-21 00:14 . 2008-11-21 00:15 <DIR> d-------- c:\program files\Windows Live Toolbar
2008-11-21 00:14 . 2008-11-21 00:14 <DIR> d-------- c:\program files\Windows Live Favorites
2008-11-21 00:11 . 2008-11-21 01:56 <DIR> d-------- c:\documents and settings\owner\Application Data\Aegisub
2008-11-21 00:06 . 2008-11-21 00:13 <DIR> d--hsc--- c:\program files\Common Files\WindowsLiveInstaller
2008-11-21 00:05 . 2008-11-21 00:14 <DIR> d-------- c:\program files\Windows Live
2008-11-21 00:05 . 2008-11-21 00:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-20 23:48 . 2008-10-16 14:09 43,544 --a------ c:\windows\system32\wups2.dll
2008-11-20 23:48 . 2008-10-16 14:09 31,768 --a------ c:\windows\system32\wucltui.dll.mui
2008-11-20 23:48 . 2008-10-16 14:07 23,576 --a------ c:\windows\system32\wuaucpl.cpl.mui
2008-11-20 23:48 . 2008-10-16 14:07 23,576 --a------ c:\windows\system32\wuapi.dll.mui
2008-11-20 23:48 . 2008-10-16 14:07 18,456 --a------ c:\windows\system32\wuaueng.dll.mui
2008-11-20 23:46 . 2008-11-21 20:39 <DIR> d--h----- c:\windows\$hf_mig$
2008-11-20 23:37 . 2008-11-20 23:37 <DIR> d---s---- c:\documents and settings\owner\UserData
2008-11-20 23:26 . 2004-08-03 23:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-11-20 22:02 . 2008-11-20 22:02 <DIR> d-------- c:\program files\Yahoo!
2008-11-20 22:02 . 2008-11-20 22:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-22 05:20 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-21 12:20 112,144 ----a-w c:\windows\system32\drivers\kl1.sys
2008-11-21 05:58 155,995 ----a-w c:\windows\java\Packages\61ZTJ7D3.ZIP
2008-11-21 05:58 --------- d-----w c:\program files\Opera
2008-11-21 05:57 --------- d-----w c:\program files\K-Lite Codec Pack
2008-11-21 05:56 --------- d-----w c:\program files\Total Video Converter
2008-11-21 05:55 --------- d-----w c:\program files\Common Files\Ahead
2008-11-21 05:55 --------- d-----w c:\documents and settings\owner\Application Data\Ahead
2008-11-21 05:54 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-11-21 05:54 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-11-21 05:54 --------- d-----w c:\program files\Nero
2008-11-21 05:54 --------- d-----w c:\program files\Common Files\xing shared
2008-11-21 05:54 --------- d-----w c:\program files\Common Files\Real
2008-11-21 05:52 --------- d-----w c:\program files\Real
2008-11-21 05:52 --------- d-----w c:\documents and settings\owner\Application Data\BSplayer PRO
2008-11-21 05:51 47,104 ------w c:\windows\AKDeInstall.exe
2008-11-21 05:51 --------- d-----w c:\program files\mpegable
2008-11-21 05:51 --------- d-----w c:\program files\GRETECH
2008-11-21 05:48 --------- d-----w c:\program files\Webteh
2008-11-21 05:45 --------- d-----w c:\program files\Microsoft.NET
2008-11-21 05:45 --------- d-----w c:\program files\Microsoft ActiveSync
2008-11-21 05:31 --------- d-----w c:\program files\CONEXANT
2008-11-21 05:29 16,608 ----a-w c:\windows\gdrv.sys
2008-11-21 05:29 --------- d-----w c:\program files\Realtek
2008-11-21 05:29 --------- d-----w c:\documents and settings\owner\Application Data\InstallShield
2008-11-21 05:27 315,392 ----a-w c:\windows\HideWin.exe
2008-11-21 05:27 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-21 05:25 --------- d-----w c:\program files\Intel
2008-11-21 05:09 --------- d-----w c:\program files\microsoft frontpage
2008-10-16 22:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 22:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 22:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 22:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 22:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 22:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-08-26 07:24 826,368 ----a-w c:\windows\system32\wininet.dll
2008-11-21 09:20 251,392 ----a-w c:\program files\opera\program\plugins\dapop.dll
.
((((((((((((((((((((((((((((( snapshot_2008-11-21_19.50.56.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-22 05:14:33 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A80000000002}\SC_Reader.exe
- 2004-08-03 22:56:46 1,281,536 -c--a-w c:\windows\system32\dllcache\ole32.dll
+ 2005-04-28 19:31:11 1,285,120 -c--a-w c:\windows\system32\dllcache\ole32.dll
- 2001-08-23 15:00:00 68,608 -c--a-w c:\windows\system32\dllcache\olecli32.dll
+ 2005-04-28 19:31:11 74,752 -c--a-w c:\windows\system32\dllcache\olecli32.dll
- 2001-08-23 15:00:00 34,304 -c--a-w c:\windows\system32\dllcache\olecnv32.dll
+ 2005-04-28 19:31:11 37,888 -c--a-w c:\windows\system32\dllcache\olecnv32.dll
- 2004-08-03 22:56:46 395,776 -c--a-w c:\windows\system32\dllcache\rpcss.dll
+ 2005-04-28 19:31:11 395,776 -c--a-w c:\windows\system32\dllcache\rpcss.dll
- 2004-08-03 22:56:46 1,281,536 ----a-w c:\windows\system32\ole32.dll
+ 2005-04-28 19:31:11 1,285,120 ----a-w c:\windows\system32\ole32.dll
- 2001-08-23 15:00:00 68,608 ----a-w c:\windows\system32\olecli32.dll
+ 2005-04-28 19:31:11 74,752 ----a-w c:\windows\system32\olecli32.dll
- 2001-08-23 15:00:00 34,304 ----a-w c:\windows\system32\olecnv32.dll
+ 2005-04-28 19:31:11 37,888 ----a-w c:\windows\system32\olecnv32.dll
- 2004-08-03 22:56:46 395,776 ----a-w c:\windows\system32\rpcss.dll
+ 2005-04-28 19:31:11 395,776 ----a-w c:\windows\system32\rpcss.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-11-21 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2008-11-21 3057152]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-11-21 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
"vidc.X264"= x264vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-10-28 16:25 94208 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
-ra------ 2005-11-27 21:52 77824 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
-ra------ 2005-11-27 21:55 118784 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
-ra------ 2005-11-27 21:55 98304 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-11-20 21:54 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-03-01 18:11 4670968 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-03 02:43 69632 c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 2008-02-12 22:31 16857600 c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\English\\setup.exe"=
"c:\\Program Files\\IEPro\\MiniDM.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-12-13 24592]
.
s of the 'Scheduled Tasks' folder
2008-11-22 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{72C9B60B-F700-472C-B960-5D37C8C46DB9} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.ie7pro.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
IE: Add to Windows &Live Favorites -
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {000002a3-84fe-43f1-b958-f2c3ca804f1a} - {CD275D4E-791A-4993-9D4D-6A071EDD2709} - c:\program files\IEPro\iepro.dll
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
O16 -: Microsoft XML Parser for Java -
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-21 22:26:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-21 22:26:46
ComboFix-quarantined-files.txt 2008-11-22 06:26:44
ComboFix2.txt 2008-11-22 03:51:15
ComboFix3.txt 2008-11-21 20:39:32
ComboFix4.txt 2008-11-21 11:33:24
Pre-Run: 33,231,790,080 bytes free
Post-Run: 33,242,411,008 bytes free
231