هذا اول تقريري
ComboFix 08-11-29.03 - WIN XP 11/30/2008 17:31:07.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.117 [GMT 3:00]
Running from: c:\documents and settings\WIN XP\Desktop\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-30 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-30 14:31 --------- d-----w c:\documents and settings\WIN XP\Application Data\DMCache
2008-11-30 14:22 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-30 02:28 --------- d-----w c:\program files\GVR
2008-11-29 10:13 --------- d-----w c:\documents and settings\WIN XP\Application Data\TweakNow RegCleaner Professional
2008-11-26 11:20 --------- d-----w c:\documents and settings\WIN XP\Application Data\IBP
2008-11-26 11:01 --------- d-----w c:\program files\IBP 10
2008-11-26 09:38 --------- d-----w c:\program files\Hotspot Shield
2008-11-26 02:27 --------- d-----w c:\program files\Hotspot_Shield
2008-11-19 02:06 --------- d-----w c:\program files\Conduit
2008-10-26 17:09 --------- d-----w c:\program files\Capitan Tsubasa RPG 1
2008-10-23 23:38 --------- d-----w c:\program files\LtUcx
2008-10-20 20:13 --------- d-----w c:\program files\AnchorFree
2008-10-14 21:58 --------- d-----w c:\program files\Tarzan
2008-10-06 04:52 --------- d-----w c:\documents and settings\All Users\Application Data\TurboFTP
2008-10-06 02:45 --------- d-----w c:\program files\TurboFTP
2008-10-06 02:38 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-06 02:37 --------- d-----w c:\program files\PowerArchiver
2008-10-03 18:23 --------- d-----w c:\program files\Internet Download Manager
2008-10-03 03:45 --------- d-----w c:\documents and settings\WIN XP\Application Data\IDM
2008-09-30 00:40 --------- d-----w c:\program files\File Recover
2008-09-23 07:46 53,248 ----a-w c:\windows\system32\suppdll.dll
2008-09-23 07:46 35,363 ----a-w c:\windows\system32\windrvNT.sys
2008-09-12 10:44 206,256 ----a-w c:\windows\system32\idmmbc.dll
2008-08-31 05:11 1,245,184 ----a-w c:\windows\system32\bkll.dll
2008-08-09 12:42 2,588 ----a-w c:\windows\system32\tmp.reg
2008-08-06 20:06 99,965 ----a-w c:\windows\UninstallFirefox.exe
2008-08-06 19:43 344,064 ----a-w c:\windows\system32\dkll.dll
2008-08-06 19:43 196,608 ----a-w c:\windows\system32\maag.dll
2008-08-06 19:43 1,986,560 ----a-w c:\windows\system32\akll.dll
2008-08-06 19:43 1,212,416 ----a-w c:\windows\system32\ckll.dll
2008-08-06 19:39 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-08-06 19:39 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-08-06 19:28 155,995 ----a-w c:\windows\java\Packages\ZFZ7BJVP.ZIP
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{c95a4e8e-816d-4655-8c79-d736da1adb6d}"= "c:\program files\Hotspot_Shield\tbHot1.dll" [11/26/2008 05:27 AM 1784856]
[HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
11/26/2008 05:27 AM 1784856 --a------ c:\program files\Hotspot_Shield\tbHot1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
11/25/2008 11:23 PM 204248 --a------ c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{c95a4e8e-816d-4655-8c79-d736da1adb6d}"= "c:\program files\Hotspot_Shield\tbHot1.dll" [11/26/2008 05:27 AM 1784856]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}"= "c:\program files\Hotspot_Shield\tbHot1.dll" [11/26/2008 05:27 AM 1784856]
[HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [01/19/2007 10:55 PM 5674352]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [04/04/2006 08:01 PM 1368064]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [08/04/2004 11:06 AM 1667584]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [08/10/2008 03:04 AM 68856]
"AFProg"="c:\program files\AnchorFree\bin\ctrl\AFController.exe" [11/20/2006 11:19 AM 81920]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [10/12/2008 03:02 PM 2607616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [08/03/2004 11:32 PM 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [08/03/2004 11:32 PM 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [08/03/2004 11:32 PM 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [08/24/2007 09:01 PM 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [08/24/2007 09:01 PM 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [08/24/2007 09:00 PM 131072]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [07/09/2001 09:50 PM 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [08/06/2008 10:39 PM 185896]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [09/18/2006 09:08 PM 29696]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [09/30/2006 07:58 AM 49152]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [07/01/2008 07:01 PM 1447168]
"HiYo"="c:\program files\HiYo\bin\HiYo.exe" [08/05/2008 02:40 PM 320816]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM 144784]
"SigmatelSysTrayApp"="stsystra.exe" [01/27/2008 04:50 AM 405504 c:\windows\stsystra.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 01:56 AM 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-08-06 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-25 622653]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-08-06 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\english\\setup.exe"=
"c:\\Program Files\\IBP 10\\IBP.exe"=
R2 BandLuxe_Service;BandLuxe Service;"c:\program files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe" -e [2008-06-03 87264]
S2 TBFTPSyncService;TurboFTP Sync Service;c:\program files\TurboFTP\tftpsvc.exe [2008-09-16 1052672]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\DRIVERS\br3gmdm.sys [2008-08-07 100096]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\WIN XP\Application Data\Mozilla\Firefox\Profiles\o8n56rqj.default\
.
.
------- File Associations -------
.
txtfile=c:\windows\notepad.exe %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-30 17:35:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
Completion time: 11/30/2008 17:36:01
ComboFix-quarantined-files.txt 2008-11-30 14:35:57
ComboFix2.txt 2008-11-30 03:03:29
ComboFix3.txt 2008-08-09 12:38:36
Pre-Run: 26,220,367,872 bytes free
Post-Run: 26,220,601,344 bytes free
134