للاسف المشكلة ما زالت
ComboFix 09-02-24.02 - BVX-Messi 02/25/2009 20:28:09.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.254.34 [GMT 2:00]
Running from: c:\documents and settings\BVX-Messi\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\BVX-Messi\Application Data\dach100.dll
c:\windows\sqlite3.dll
c:\windows\system32\autorun.ini
c:\windows\system32\dp1.fne
c:\windows\system32\eAPI.fne
c:\windows\system32\explorer.exe
c:\windows\system32\internet.fne
c:\windows\system32\krnln.fnr
c:\windows\system32\og.dll
c:\windows\system32\og.edt
c:\windows\system32\RegEx.fnr
c:\windows\system32\setting.ini
c:\windows\system32\shell.fne
c:\windows\system32\spec.fne
c:\windows\system32\ssvichosst.exe
c:\windows\system32\ul.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2009-01-25 to 2009-02-25 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-25 18:35 26,857,504 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-02-25 18:33 315,500 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-02-25 18:33 --------- d-----w c:\program files\microsoft frontpage
2009-02-25 17:17 --------- d-----w c:\program files\HDD Regenerator
2009-02-25 17:09 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-25 11:20 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-02-24 19:40 --------- d-----w c:\program files\DAP
2009-02-24 19:20 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\cleaner
2009-02-23 17:39 --------- d-----w c:\program files\On Screen Display
2009-02-23 17:39 --------- d-----w c:\program files\MSN Messenger
2009-02-23 17:34 224,256 ----a-w c:\windows\regedit.exe
2009-02-22 08:08 --------- d-----w c:\program files\Unlocker
2009-02-21 18:19 --------- d-----w c:\program files\Internet Download Manager
2009-02-21 18:18 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\DMCache
2009-02-21 16:02 --------- d-----w c:\program files\ThreatFire
2009-02-20 16:41 --------- d-----w c:\documents and settings\All Users\Application Data\SpeedBit
2009-02-20 14:58 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\CyberScrub
2009-02-20 10:05 --------- d-----w c:\documents and settings\All Users\Application Data\PC Tools
2009-02-19 09:50 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\IDM
2009-02-18 13:49 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\uTorrent
2009-02-17 19:18 --------- d-----w c:\program files\nLite
2009-02-17 18:09 --------- d-----w c:\documents and settings\All Users\Application Data\Bluetooth
2009-02-17 17:53 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-17 17:53 --------- d-----w c:\program files\IVT Corporation
2009-02-16 18:54 --------- d-----w c:\program files\Registry Fast
2009-02-16 17:05 --------- d-----w c:\program files\lg_swupdate
2009-02-16 16:54 --------- d-----w c:\program files\CCleaner
2009-02-16 13:34 --------- d-----w c:\program files\Codemonster
2009-02-16 13:34 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\Codemonster
2009-02-15 03:04 27,242,765 ----a-w c:\windows\msapps\msinfo\all files\AIO Kodak DIGITAL Professional PlugIn.exe
2009-02-11 21:16 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\MessengerDiscovery 2
2009-02-11 17:06 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\MMToolz
2009-02-11 17:04 --------- d-----w c:\program files\MMToolz
2009-02-05 19:00 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\Skype
2009-02-05 15:47 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\skypePM
2009-02-05 15:44 --------- d-----w c:\program files\Common Files\Skype
2009-02-05 15:44 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-02-05 15:44 --------- d-----r c:\program files\Skype
2009-02-05 15:27 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\ooVoo Details
2009-02-05 15:22 --------- d-----w c:\program files\ooVoo
2009-02-04 18:18 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\PenProtect
2009-02-02 10:38 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-02-02 10:32 --------- d-----w c:\program files\Windows Live
2009-02-02 10:32 --------- d-----w c:\program files\Messenger Plus! Live
2009-01-29 09:14 --------- d-----w c:\program files\uTorrent
2009-01-27 12:15 --------- d-----w c:\program files\VideoLAN
2009-01-26 11:54 --------- d-----w c:\program files\The KMPlayer
2009-01-21 09:26 --------- d-----w c:\program files\AVG
2009-01-19 17:12 --------- d-----w c:\program files\iriver
2009-01-19 11:26 --------- d-----w c:\program files\EzManual
2009-01-18 11:25 --------- d-----w c:\program files\Dachshund Software
2009-01-17 15:40 4,096 ----a-w c:\windows\msapps\msinfo\all files\prb\all files\Tools\مفاتيح لاضافة بعض الخيارات وحل بعض المشاكل +ادوات مفيدة جدااا\showthread.php_files\showthread.php_files.exe
2009-01-15 12:08 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\Winamp
2009-01-14 12:48 --------- d-----w c:\program files\Driver-Soft
2009-01-13 16:03 --------- d-----w c:\program files\Marvell
2009-01-13 11:15 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\Media Player Classic
2009-01-13 05:11 --------- d-----w c:\program files\LG Software
2009-01-12 17:21 239,905 ----a-w c:\windows\msapps\msinfo\all files\prb\all files\لأغلب مشاكل وحلول الوندوز والريجستري\حلول اغلب مشاكل الوندوز والريجستري\لإصلاح محرر الريجستري\لإصلاح محرر الريجستري.exe
2009-01-12 16:30 --------- d-----w c:\program files\Synaptics
2009-01-12 16:27 --------- d-----w c:\program files\ATI Technologies
2009-01-12 16:22 --------- d-----w c:\program files\Intel
2009-01-12 16:17 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-12 15:43 --------- d-----w c:\program files\Java
2009-01-12 15:42 --------- d-----w c:\program files\Common Files\Java
2009-01-12 15:38 --------- d-----w c:\program files\Winamp
2009-01-12 15:37 --------- d-----w c:\program files\Windows Media Connect 2
2009-01-12 15:35 --------- d-----w c:\program files\K-Lite Codec Pack
2009-01-12 15:33 --------- d-----w c:\documents and settings\BVX-Messi\Application Data\Nero
2009-01-12 15:32 --------- d-----w c:\program files\Nero
2009-01-12 15:31 --------- d-----w c:\program files\Common Files\Nero
2009-01-12 15:31 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2008-12-31 04:48 281,600 ----a-w c:\windows\msapps\msinfo\all files\photoshop\AMS.Software.Framing.Studio.v2.55\Crack\crd.exe
2008-12-31 04:48 1,600,073 ----a-w c:\windows\msapps\msinfo\all files\Autorun_Virus_Remover_2.3\Autorun_Virus_Remover_2.3.exe
2008-12-31 04:48 1,358,032 ----a-w c:\windows\msapps\msinfo\all files\photoshop\Andromeda Prespective Filter\fo-apf11.exe
2008-12-31 04:20 750,080 ----a-w c:\windows\msapps\msinfo\all files\prb\all files\Tools\BOOB77.7\Avast Virus Cleaner Tool.tmp
2008-12-27 20:48 214,016 ----a-w c:\windows\msapps\msinfo\all files\حل مسكلة task manager and register\RRT.exe
2008-12-27 20:48 118,784 ----a-w c:\windows\msapps\msinfo\all files\حل مسكلة task manager and register\775a2ca50d.exe
2008-12-27 20:48 110,592 ----a-w c:\windows\msapps\msinfo\all files\حل مسكلة task manager and register\f48c643ae2.exe
2008-12-11 10:13 44,983,341 ----a-w c:\windows\msapps\msinfo\all files\photoshop\اصدار جديدPicture Collage Maker افضل برامج لدمج الصور واضافة التاثيرات بشرح للدلوعة\PictureCollageMaker.exe
2004-04-21 08:38 516,096 ----a-w c:\program files\HPUSBFW.EXE
2003-11-13 10:00 532,480 ----a-w c:\program files\HPUSBF.EXE
2003-10-24 13:50 17,730 ----a-w c:\program files\EULA.doc
2006-11-25 20:11 2,560 --sh--r c:\windows\system32\fooool.exe
.
------- Sigcheck -------
05/30/2008 09:56 AM 2343424 9a64fdd5bd8ce0018af03e31b4beaa71 c:\windows\system32\ntoskrnl.exe
01/27/2008 04:04 PM 1602048 ba10afed11feefd8a5c659c1c783ccfd c:\windows\explorer.exe
04/14/2008 07:42 PM 84992 c6f25ca5288999ce492f8393bc930805 c:\windows\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [04/14/2008 07:42 PM 84992]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [02/23/2009 07:29 PM 5743984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KeybdUtility"="c:\program files\On Screen Display\Hotkey.exe" [02/23/2009 07:29 PM 151552]
"C2K"="c:\windows\Cyb2k.exe" [01/21/2007 01:28 AM 3342336]
"Barsaka"="explorer.exe" [01/27/2008 04:04 PM 1602048 c:\windows\explorer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/14/2008 07:42 PM 84992]
c:\documents and settings\BVX-Messi\Start Menu\Programs\Startup\
is-DDI2T.lnk - c:\documents and settings\BVX-Messi\Desktop\Virus Removal Tool\is-DDI2T\startup.exe [2/23/2009 7:23:47 PM 65536]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2/17/2009 7:53:45 PM 1253376]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{26F5978F-6493-4ee3-B114-C0C3ACCF9D4D}"= "c:\windows\system32\bmpsap.dll" [06/01/2006 05:54 PM 114688]
[HKLM\~\startupfolder\C:^Documents and Settings^BVX-Messi^Start Menu^Programs^Startup^AntiCrash.lnk]
backup=c:\windows\pss\AntiCrash.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 01/30/2009 03:01 PM 421888 c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\batterymiser]
--a------ 02/23/2009 07:36 PM 405504 c:\program files\LG Software\Battery Miser 2005\batterymiser.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 01/22/2009 05:16 PM 2823600 c:\program files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPO3]
--a------ 06/22/2005 12:00 PM 1097728 c:\program files\LG Software\IP Operator 2005\IP Operator 2005.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\oovoo.exe]
--a------ 02/01/2009 11:51 PM 14612272 c:\program files\ooVoo\ooVoo.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 10/29/2004 03:01 AM 761946 c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
--a------ 10/29/2004 03:02 AM 172122 c:\program files\Synaptics\SynTP\SynTPLpr.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Nero\\Nero Burning ROM\\nero.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\ooVoo\\ooVoo.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\Cyb2k.exe"=
"c:\\WINDOWS\\system32\\Ati2evxx.exe"=
"c:\\WINDOWS\\system32\\cmd.exe"= c:\\WINDOWS\\System32\\cmd.exe
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\WINDOWS\\system32\\dumprep.exe"=
"c:\\Program Files\\MSN Messenger\\usnsvc.exe"=
"c:\\Program Files\\On Screen Display\\Hotkey.exe"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
"c:\\WINDOWS\\system32\\CF17563.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:*

isabled

oVoo TCP المنفذ 443
"443:UDP"= 443:UDP:*

isabled

oVoo UDP المنفذ 443
"37674:TCP"= 37674:TCP:*

isabled

oVoo TCP المنفذ 37674
"37674:UDP"= 37674:UDP:*

isabled

oVoo UDP المنفذ 37674
"37675:UDP"= 37675:UDP:*

isabled

oVoo UDP المنفذ 37675
R1 is-DDI2Tdrv;is-DDI2Tdrv;c:\windows\system32\drivers\28054318.sys [2/23/2009 7:23:18 PM 148496]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [5/12/2005 2:39:00 PM 1287296]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ASC3360PR
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DownloadAccelerator - c:\program files\DAP\DAP.EXE
HKLM-Run-LG Intelligent Update - c:\program files\lg_swupdate\autoupdate.exe
HKLM-Run-UnlockerAssistant - c:\program files\Unlocker\UnlockerAssistant.exe
HKLM-Run-Cmaudio - cmicnfg.cpl
Notify-WgaLogon - (no file)
.
------- Supplementary Scan -------
.
LSP: c:\windows\system32\lspcs.dll
TCP: {59F78186-A7B9-4A01-B37D-D76222FA474F} = 172.10.0.1 91.142.48.48
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} -
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} -
FF - ProfilePath - c:\documents and settings\BVX-Messi\Application Data\Mozilla\Firefox\Profiles\y7mpwkfs.default\
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-02-25 20:34:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(780)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(836)
c:\windows\system32\lspcs.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 02/25/2009 20:40:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-25 18:40:10
ComboFix2.txt 2009-02-23 17:18:46
Pre-Run: 25,992,765,440 bytes free
Post-Run: 25,899,028,480 bytes free
241