إليك التقرير .. أخي ..
.......................... التقرير ....................
ComboFix 08-12-16.03 - Harley 12/18/2008 10:55:46.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.3062.2506 [GMT 3:00]
Running from: f:\my prog\new\لفحص الجهاز مثل هايجاك\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\_000124_.tmp.dll
c:\windows\system32\BReWErS.dll
c:\windows\system32\DivXc32.dll
c:\windows\system32\DivXc32f.dll
c:\windows\system32\drivers\downld
c:\windows\system32\lphccs3j0e7b5.exe
c:\windows\system32\msmpeg4.dll
c:\windows\system32\phccs3j0e7b5.bmp
c:\windows\system32\systeminfo3.dll
c:\windows\system32\tmp47.tmp
c:\windows\system32\tmp48.tmp
.
((((((((((((((((((((((((( Files Created from 2008-11-18 to 2008-12-18 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-18 08:03 --------- d-----w c:\documents and settings\Harley\Application Data\IDM
2008-12-18 08:03 --------- d-----w c:\documents and settings\Harley\Application Data\DMCache
2008-12-18 08:02 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-12-18 08:00 9,180 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-12-18 08:00 7,153,696 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-18 08:00 61,160 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-18 08:00 1,450,016 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-12-18 07:43 --------- d-----w c:\program files\SpeedFan
2008-12-18 07:19 --------- d-----w c:\documents and settings\Harley\Application Data\uTorrent
2008-12-17 23:02 --------- d-----w c:\program files\Zoom Player
2008-12-17 22:54 --------- d-----w c:\program files\Restaurant Rush
2008-12-17 22:50 --------- d-----w c:\program files\eMule
2008-12-17 03:59 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-16 22:18 --------- d-----w c:\program files\Smarty Uninstaller Pro
2008-12-07 13:28 440 ----a-w c:\documents and settings\Mastool\Application Data\mindhabits.dat
2008-12-07 05:25 4,876 ----a-w c:\documents and settings\Harley\Application Data\mindhabits.dat
2008-12-07 05:07 --------- d-----w c:\program files\MindHabits
2008-11-29 00:23 --------- d-----w c:\program files\TuneUp Utilities 2009
2008-11-25 13:46 3,532 ----a-w C:\drmHeader.bin
2008-11-24 15:55 --------- d-----w c:\program files\plentyoftorrents.com
2008-11-24 15:55 --------- d-----w c:\program files\Conduit
2008-11-23 20:14 --------- d-----w c:\program files\Eidos
2008-11-21 10:21 --------- d-sh--w c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2008-11-21 10:21 --------- d-----w c:\documents and settings\All Users\Application Data\TuneUp Software
2008-11-21 10:19 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-15 21:21 --------- d-----w c:\program files\K-Lite Codec Pack
2008-11-15 21:21 --------- d-----w c:\documents and settings\Harley\Application Data\Media Player Classic
2008-11-15 21:21 --------- d-----w c:\documents and settings\Harley\Application Data\bsplayer
2008-11-10 21:49 --------- d-----w c:\program files\Brain Workout
2008-11-06 17:14 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-06 17:09 --------- d-----w c:\program files\Team JPN
2008-11-04 15:40 22,328 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-11-04 15:40 22,328 ----a-w c:\documents and settings\Harley\Application Data\PnkBstrK.sys
2008-11-04 15:18 --------- d-----w c:\program files\Electronic Arts
2008-10-31 23:18 --------- d-----w c:\program files\Reference Assemblies
2008-10-31 23:18 --------- d-----w c:\program files\MSBuild
2008-10-31 23:12 --------- d-----w c:\program files\MSXML 6.0
2008-10-30 15:48 --------- d-----w c:\program files\MagicISO
2008-10-27 16:22 --------- d-----w c:\program files\Ubisoft
2008-10-27 15:44 --------- d-----w c:\program files\SystemRequirementsLab
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 19:37 --------- d-----w c:\documents and settings\Harley\Application Data\Uniblue
2008-10-21 13:29 --------- d-----w c:\program files\Internet Download Manager
2008-10-19 19:37 --------- d-----w c:\program files\Uniblue
2008-10-18 21:04 --------- d-----w c:\program files\Microsoft.NET
2008-10-18 21:01 --------- d-----w c:\program files\Microsoft ActiveSync
2008-10-18 18:18 --------- d-----w c:\program files\Golden Al-Wafi Translator
2008-10-18 18:18 --------- d-----w c:\program files\Crystal Player
2008-10-18 18:18 --------- d-----w c:\program files\CloneDVD
2008-10-18 18:18 --------- d-----w c:\documents and settings\Mastool\Application Data\TeraCopy
2008-10-18 18:18 --------- d-----w c:\documents and settings\Harley\Application Data\TeraCopy
2008-10-18 18:18 --------- d-----w c:\documents and settings\Harley\Application Data\iolo
2008-10-18 18:18 --------- d-----w c:\documents and settings\Guest\Application Data\iolo
2008-10-18 18:18 --------- d-----w c:\documents and settings\Guest\Application Data\DMCache
2008-10-18 18:18 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-09-29 22:57 81,920 ----a-w c:\documents and settings\Harley\Application Data\ezpinst.exe
2008-09-29 22:57 47,360 ----a-w c:\documents and settings\Harley\Application Data\pcouffin.sys
2007-09-16 06:35 66,408 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2007-09-16 06:35 54,112 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2007-09-16 06:35 34,688 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2007-09-16 06:35 46,456 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2007-09-16 06:35 171,880 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{34e460f4-5d42-49ef-bfbc-9a55f34e9a45}"= "c:\program files\plentyoftorrents.com\tbplen.dll" [07/27/2008 09:11 PM 1606680]
[HKEY_CLASSES_ROOT\clsid\{34e460f4-5d42-49ef-bfbc-9a55f34e9a45}]
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{34e460f4-5d42-49ef-bfbc-9a55f34e9a45}]
07/27/2008 09:11 PM 1606680 --a------ c:\program files\plentyoftorrents.com\tbplen.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{34e460f4-5d42-49ef-bfbc-9a55f34e9a45}"= "c:\program files\plentyoftorrents.com\tbplen.dll" [07/27/2008 09:11 PM 1606680]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{34E460F4-5D42-49EF-BFBC-9A55F34E9A45}"= "c:\program files\plentyoftorrents.com\tbplen.dll" [07/27/2008 09:11 PM 1606680]
[HKEY_CLASSES_ROOT\clsid\{34e460f4-5d42-49ef-bfbc-9a55f34e9a45}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [08/16/2007 04:19 PM 5728112]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [06/22/2008 09:49 PM 2566656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" [11/03/2007 04:50 AM 6731312]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [10/07/2008 01:33 PM 13574144]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [08/04/2004 10:56 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
"VIDC.DIV3"= DivXc32.dll
"VIDC.DIV4"= DivXc32f.dll
"VIDC.MPG4"= msmpeg4.dll
"VIDC.MP42"= msmpeg4.dll
"VIDC.MP43"= msmpeg4.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Harley^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
--a------ 11/03/2007 04:50 AM 6731312 c:\program files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 05/11/2007 03:06 AM 40048 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 08/04/2004 10:56 AM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
--a------ 09/24/2008 07:22 AM 5256776 c:\program files\eMule\emule.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 06/22/2008 09:49 PM 2566656 c:\program files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 10/06/2005 06:03 PM 278528 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 10/13/2004 07:24 PM 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 08/16/2007 04:19 PM 5728112 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 10/07/2008 01:33 PM 13574144 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 10/07/2008 01:33 PM 86016 c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD8LanguageShortcut]
--------- 12/14/2007 11:36 AM 50472 c:\program files\CyberLink\PowerDVD8\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 07/07/2008 10:34 AM 167936 c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 08/15/2008 02:20 AM 155648 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl8]
--------- 03/20/2008 08:23 PM 83240 c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STYLEXP]
--a------ 04/04/2006 08:01 PM 1368064 c:\program files\TGTSoft\StyleXP\StyleXP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 06/10/2008 04:27 AM 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 06/13/2008 06:28 AM 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 06/15/2007 07:03 AM 69632 c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 10/07/2008 01:33 PM 1630208 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 06/15/2007 07:03 AM 16132608 c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 2009\\avp.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\Program Files\\JetAudio\\JetAudio.exe"=
"c:\\Program Files\\Team JPN\\SpiderMan Web of Shadows\\image\\pc\\Spider-Man Web of Shadows.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2008-05-30 566120]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2008-05-30 566120]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2008-11-21 603904]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd7e98dc-5295-11dd-888d-0019d1b073af}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe AngAntiVirus.vbs
.
- - - - ORPHANS REMOVED - - - -
Notify-WgaLogon - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://VeryCD.265.com
uInternet Settings,ProxyOverride = local
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
c:\windows\Downloaded Program Files\sysreqlab3.dll - c:\windows\Downloaded Program Files\sysreqlab_srl.dll
O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
hxxp://www.srtest.com/srl_bin/sysreqlab_srl.cab
c:\windows\Downloaded Program Files\sysreqlab.osd
FF - ProfilePath - c:\documents and settings\Harley\Application Data\Mozilla\Firefox\Profiles\s71c8krx.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-18 11:01:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1188)
c:\windows\system32\klogon.dll
- - - - - - - > 'explorer.exe'(3404)
c:\progra~1\WINDOW~2\wmpband.dll
c:\program files\Internet Download Manager\idmmkb.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\TGTSoft\StyleXP\StyleXPService.exe
c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 12/18/2008 11:06:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-18 08:05:50
Pre-Run: 80,923,590,656 bytes free
Post-Run: 81,554,964,480 bytes free
250 --- E O F --- 2008-12-18 07:46:48
........................ إنتهى التقرير ......................