اشكرك اخي نور على حسن متاعبتك معي واسف للتاخير
وهذا هو التقرير
ComboFix 09-03-04.01 - دريم 03/05/2009 10:45:10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.2039.1472 [GMT 3:00]
Running from: e:\برامج جديده 1-1-2009\أدوات حمايه زيزوم\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Implode.dll
c:\windows\system32\MabryObj.dll
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\nmdfgds1.dll
.
((((((((((((((((((((((((( Files Created from 2009-02-05 to 2009-03-05 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-05 07:49 8,917,024 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-05 07:48 226,336 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-03-05 07:47 25,376 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-03-05 07:47 126,572 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-05 07:42 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-03-04 13:34 --------- d-----w c:\program files\AutoPlay Menu Builder
2009-03-01 09:09 --------- d-----w c:\documents and settings\دريم\Application Data\cleaner
2009-02-28 18:52 --------- d-----w c:\documents and settings\All Users\Application Data\SlySoft
2009-02-25 17:38 --------- d-----w c:\program files\Google
2009-02-25 17:34 --------- d-----w c:\program files\Common Files\xing shared
2009-02-25 17:34 --------- d-----w c:\program files\Common Files\Real
2009-02-24 15:00 --------- d-----w c:\program files\أروع ما قيل في الهجاء
2009-02-24 14:59 286,720 ----a-w c:\windows\iun506.exe
2009-02-24 14:33 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-24 14:33 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-02-24 13:52 --------- d-----w c:\program files\Kaspersky Lab
2009-02-24 13:52 --------- d-----w c:\documents and settings\All Users\Application Data\zyz Kaspersky Lab setup files
2009-02-24 07:58 --------- d-----w c:\documents and settings\دريم\Application Data\HP
2009-02-24 07:01 --------- d-----w c:\documents and settings\دريم\Application Data\CyberScrub
2009-02-23 20:15 --------- d-----w c:\program files\MSXML 4.0
2009-02-23 18:30 --------- d-----w c:\program files\Fahess_Activation
2009-02-23 18:30 --------- d-----w c:\program files\Common Files\Motive
2009-02-23 18:30 --------- d-----w c:\documents and settings\دريم\Application Data\Motive
2009-02-23 18:29 --------- d-----w c:\documents and settings\All Users\Application Data\Motive
2009-02-20 09:46 --------- d-----w c:\program files\CubedLabs YouTube Download & Convert
2009-02-20 09:25 --------- d-----w c:\program files\Messenger Plus! Live
2009-02-20 09:25 --------- d-----w c:\program files\Adverts
2009-02-19 21:33 --------- d-----w c:\program files\Real
2009-02-19 11:04 --------- d-----w c:\documents and settings\دريم\Application Data\Media Player Classic
2009-02-19 09:38 --------- d-----w c:\documents and settings\دريم\Application Data\COWON
2009-02-19 07:27 --------- d-----w c:\documents and settings\دريم\Application Data\Ahead
2009-02-19 05:32 --------- d-----w c:\documents and settings\دريم\Application Data\Talkback
2009-02-18 23:40 --------- d-----w c:\documents and settings\دريم\Application Data\1burn
2009-02-18 23:39 --------- d-----w c:\documents and settings\All Users\Application Data\That Face Camp Shim
2009-02-18 23:38 --------- d-----w c:\program files\Circle Developement
2009-02-18 23:38 --------- d-----w c:\program files\1burn
2009-02-18 22:52 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-02-18 22:10 --------- d-----w c:\program files\Windows Media Connect 2
2009-02-18 22:08 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-18 22:08 --------- d-----w c:\program files\JetAudio
2009-02-18 22:08 --------- d-----w c:\program files\Common Files\COWON
2009-02-18 22:07 --------- d-----w c:\documents and settings\دريم\Application Data\InstallShield
2009-02-18 22:05 --------- d-----w c:\program files\Common Files\ACD Systems
2009-02-18 22:05 --------- d-----w c:\program files\ACD Systems
2009-02-18 22:05 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2009-02-18 22:05 --------- d-----w c:\documents and settings\All Users\Application Data\ACD Systems
2009-02-18 22:04 --------- d-----w c:\program files\Yahoo!
2009-02-18 21:33 --------- d-----w c:\program files\NCC Education
2009-02-18 21:28 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-02-18 21:22 --------- d-----w c:\program files\Microsoft.NET
2009-02-18 21:21 --------- d-----w c:\program files\Microsoft Works
2009-02-18 21:21 --------- d-----w c:\program files\Common Files\Adobe
2009-02-18 20:58 --------- d-----w c:\program files\Common Files\Ahead
2009-02-18 20:58 --------- d-----w c:\documents and settings\All Users\Application Data\Ahead
2009-02-18 20:55 --------- d-----w c:\documents and settings\دريم\Application Data\Skype
2009-02-18 20:51 73,216 ----a-w c:\windows\ST6UNST.EXE
2009-02-18 20:51 172,032 ------w c:\windows\Setup1.exe
2009-02-18 20:51 --------- d-----w c:\program files\SlySoft
2009-02-18 20:51 --------- d-----w c:\program files\Golden Al-Wafi Translator
2009-02-18 20:50 --------- d-----w c:\program files\Total Video Converter
2009-02-18 20:50 --------- d-----w c:\program files\Nero
2009-02-18 20:50 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2009-02-18 20:48 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2009-02-18 20:46 --------- d-----w c:\documents and settings\All Users\Application Data\HP
2009-02-18 20:45 --------- d-----w c:\program files\Nokia
2009-02-18 20:45 --------- d-----w c:\program files\CyberLink
2009-02-18 20:45 --------- d-----w c:\program files\Common Files\Nokia
2009-02-18 20:45 --------- d-----w c:\program files\Common Files\InstallShield
2009-02-18 20:44 47,104 ------w c:\windows\AKDeInstall.exe
2009-02-18 20:44 --------- d-----w c:\program files\mpegable
2009-02-18 20:44 --------- d-----w c:\program files\K-Lite Codec Pack
2009-02-18 20:44 --------- d-----w c:\program files\HP
2009-02-18 20:44 --------- d-----w c:\program files\GRETECH
2009-02-18 20:44 --------- d-----w c:\program files\Common Files\HP
2009-02-18 20:43 --------- d-----w c:\program files\Paltalk Messenger
2009-02-18 20:43 --------- d-----w c:\program files\ooVoo
2009-02-18 20:43 --------- d-----w c:\program files\Hewlett-Packard
2009-02-18 20:43 --------- d-----w c:\documents and settings\دريم\Application Data\ooVoo Details
2009-02-18 20:42 --------- d-----w c:\program files\Skype
2009-02-18 20:42 --------- d-----w c:\documents and settings\دريم\Application Data\Paltalk
2009-02-18 20:41 155,995 ----a-w c:\windows\java\Packages\w31b37jb.zip
2009-02-18 20:41 --------- d-----w c:\program files\Common Files\Skype
2009-02-18 20:41 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-02-18 20:40 --------- d-----w c:\program files\Windows Live
2009-02-18 20:34 --------- d-----w c:\program files\Realtek
2009-02-18 20:27 315,392 ----a-w c:\windows\HideWin.exe
2009-02-18 20:25 --------- d-----w c:\program files\Intel
2009-02-18 20:19 --------- d-----w c:\program files\microsoft frontpage
2008-12-20 22:31 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\dllcache\srv.sys
2007-03-12 09:04 66,672 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2007-03-12 09:04 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2007-03-12 09:04 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2007-03-12 09:04 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2007-03-12 09:04 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [08/17/2007 07:19 AM 5728112]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [11/07/2007 10:51 AM 3810544]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [06/28/2007 09:03 AM 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [11/03/2005 10:25 AM 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [11/03/2005 10:22 AM 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [11/03/2005 10:26 AM 118784]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [02/19/2006 05:41 PM 49152]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [11/03/2004 11:24 AM 32768]
"CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [09/28/2006 10:21 PM 57344]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [02/28/2008 04:03 AM 570664]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [02/19/2008 05:36 AM 1629480]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [02/19/2008 05:36 AM 1057064]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [02/25/2009 08:33 PM 185872]
"MotiveReportAgent"="c:\program files\Fahess_Activation\McciBrowser.exe" [03/17/2008 10:16 AM 1020928]
"SkyTel"="SkyTel.EXE" [05/16/2006 01:04 PM 2879488 c:\windows\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [01/30/2007 01:54 PM 16116224 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-02-19 113664]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-02-18 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"msacm.divxa32"= DivXa32.acm
"VIDC.ACDV"= ACDV.dll
"vidc.DIV3"= DIVXc32.dll
"vidc.DIV4"= DIVXc32f.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\PalTalk.lnk
backup=c:\windows\pss\PalTalk.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\oovoo.exe]
--a------ 05/26/2008 08:56 AM 13268784 c:\program files\ooVoo\ooVoo.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 11/13/2007 06:48 AM 21760296 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\ooVoo\\ooVoo.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2009-02-24 24592]
S2 gupdate1c9976f2cea81e0;Google Update Service (gupdate1c9976f2cea81e0);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-25 133104]
S3 AVPsys;AVPsys;\??\c:\windows\system32\drivers\cdaudio.sys --> c:\windows\system32\drivers\cdaudio.sys [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06667eda-fec2-11dd-9a49-0019dba5c04a}]
\Shell\AutoRun\command - H:\cv22.cmd
\Shell\open\Command - H:\cv22.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{126bfd2e-fe02-11dd-9a45-0019dba5c04a}]
\Shell\AutoRun\command - w2.com
\Shell\open\Command - w2.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{375ba4f6-0248-11de-9a5a-0019dba5c04a}]
\Shell\AutoRun\command - H:\f9cvum.exe
\Shell\open\Command - H:\f9cvum.exe
.
*******s of the 'Scheduled Tasks' folder
2009-03-05 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [02/25/2009 08:33 PM]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
HKLM-Run-Device Detector - DevDetect.exe
.
------- Supplementary Scan -------
.
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
FF - ProfilePath - c:\documents and settings\دريم\Application Data\Mozilla\Firefox\Profiles\8kg85wbn.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:ar

fficial
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-03-05 10:49:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\docume~1\DDAE~1\LOCALS~1\Temp\STS6.tmp 113 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1048)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(1104)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
- - - - - - - > 'explorer.exe'(188)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\program files\Common Files\ACD Systems\EN\DevDetect.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\windows\system32\msiexec.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 03/05/2009 10:52:52 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-05 07:52:47
Pre-Run: 25,871,257,600 bytes free
Post-Run: 26,643,156,992 bytes free
246 --- E O F --- 2009-02-28 08:50:58