هلا اخوي بالعذاب اشتغلت الاداة الا لين طيفت الكاسبر
طبعا حذفت البرنامج حق الثيمات
هذا التقرير بعد
ComboFix 09-04-21.A8 - Administrator 04/21/2009 20:19.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.759.531 [GMT 3:00]
Running from: c:\documents and settings\Administrator\سطح المكتب\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\JNoOoNY
c:\windows\Mylist.dll
c:\windows\system32\logondll.dll
c:\windows\system32\MabryObj.dll
c:\windows\system32\plugin.dat
c:\windows\tmp.tmp.tmp1
.
((((((((((((((((((((((((( Files Created from 2009-03-21 to 2009-04-21 )))))))))))))))))))))))))))))))
.
2009-04-04 21:00 . 2009-04-04 21:00 268 ---ha-w C:\sqmdata03.sqm
2009-04-04 21:00 . 2009-04-04 21:00 244 ---ha-w C:\sqmnoopt03.sqm
2009-04-01 12:44 . 2009-04-01 12:44 268 ---ha-w C:\sqmdata02.sqm
2009-04-01 12:44 . 2009-04-01 12:44 244 ---ha-w C:\sqmnoopt02.sqm
2009-03-28 14:26 . 2009-03-28 14:26 268 ---ha-w C:\sqmdata01.sqm
2009-03-28 14:26 . 2009-03-28 14:26 244 ---ha-w C:\sqmnoopt01.sqm
2009-03-28 13:59 . 2009-03-28 13:59 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Conduit
2009-03-28 13:59 . 2009-03-28 13:59 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Eazel-FR
2009-03-25 15:27 . 2009-03-25 15:27 268 ---ha-w C:\sqmdata00.sqm
2009-03-25 15:27 . 2009-03-25 15:27 244 ---ha-w C:\sqmnoopt00.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-21 17:24 . 2009-01-18 19:58 311328 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-21 17:23 . 2009-01-18 19:58 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-21 17:22 . 2009-01-18 19:58 4212 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-21 17:22 . 2009-01-18 19:58 4032032 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-21 17:22 . 2009-01-18 19:58 34676 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-21 16:51 . 2009-01-18 19:51 -------- d-----w c:\program files\Circle Developement
2009-04-21 15:59 . 2001-09-19 12:00 39982 ----a-w c:\windows\system32\perfc001.dat
2009-04-21 15:59 . 2001-09-19 12:00 251478 ----a-w c:\windows\system32\perfh001.dat
2009-03-30 12:02 . 2009-01-20 17:55 -------- d-----w c:\program files\BreakPoint Software
2009-03-30 11:57 . 2009-01-21 09:37 -------- d-----w c:\program files\No-IP
2009-03-28 13:59 . 2009-03-28 13:59 -------- d-----w c:\program files\Eazel-FR
2009-03-28 13:59 . 2009-03-28 13:59 -------- d-----w c:\program files\Conduit
2009-03-28 13:37 . 2009-03-28 13:37 -------- d-----w c:\program files\TGTSoft
2009-03-17 20:15 . 2009-03-17 20:15 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-17 20:15 . 2009-03-17 20:15 -------- d-----w c:\program files\Java
2009-03-15 20:26 . 2009-03-15 20:26 -------- d-----w c:\documents and settings\Administrator\Application Data\GRETECH
2009-03-08 12:27 . 2009-03-08 12:27 2232 ----a-w c:\windows\java\Packages\Data\PNRTV9VB.DAT
2009-03-08 12:27 . 2009-03-08 12:27 155995 ----a-w c:\windows\java\Packages\SGJLNZPJ.ZIP
2009-03-08 12:27 . 2009-03-08 12:27 2678 ----a-w c:\windows\java\Packages\Data\SFL3V1R9.DAT
2009-03-08 12:27 . 2009-03-08 12:27 2678 ----a-w c:\windows\java\Packages\Data\CN7DZFPZ.DAT
2009-03-08 12:27 . 2009-03-08 12:27 2678 ----a-w c:\windows\java\Packages\Data\O64KUJZP.DAT
2009-03-08 12:27 . 2009-03-08 12:27 2678 ----a-w c:\windows\java\Packages\Data\CW75ZRX7.DAT
2009-03-08 12:27 . 2009-03-08 12:27 2678 ----a-w c:\windows\java\Packages\Data\53J1FXRR.DAT
2009-03-08 12:18 . 2009-03-08 12:11 -------- d-----w c:\program files\CamStudio
2009-03-07 16:45 . 2009-03-07 16:45 -------- d-----w c:\program files\Trend Micro
2009-03-01 15:02 . 2009-02-17 12:01 -------- d-----w c:\program files\CCleaner
2009-01-30 11:58 . 2009-01-18 18:42 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-01-21 23:56 . 2009-01-21 23:56 12104143 ------w C:\$Persi0.sys
2009-01-21 23:47 . 2009-01-18 18:46 2048 --s-a-w c:\windows\bootstet.dat
2009-01-18 19:51 . 2009-01-18 19:51 73208 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
------- Sigcheck -------
[-] 2008-05-27 16:54 1547776 D74083DCEC51D5291EF24D8D055D133A c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-08-16 5728112]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-03 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2003-03-11 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2003-03-11 114688]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-18 185896]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-02-10 206088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-17 148888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /k:C /k

*
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"81:TCP"= 81:TCP:Bifrost_u 1.2.1d
"81:UDP"= 81:UDP:Bifrost_u 1.2.1d
"85:TCP"= 85:TCP:Spy-Net
"85:UDP"= 85:UDP:Spy-Net
S0 DeepFrz;DeepFrz; [x]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-02-10 33808]
S3 ip100xp;IC Plus IP100 10/100 Fast Ethernet Adapter NT Driver;c:\windows\system32\DRIVERS\ipfnd51.sys [2005-02-02 26752]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
.
Contents of the 'Scheduled Tasks' folder
2009-04-21 c:\windows\Tasks\AE836FF49184E09C.job
- c:\docume~1\admini~1\applic~1\uplocks\SafeTestOkay.exe [2009-02-17 11:45]
.
- - - - ORPHANS REMOVED - - - -
Notify-DfLogon - LogonDll.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext =
uInternet Settings,ProxyOverride = local
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\kgd7xnui.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sa/
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-21 20:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-21 20:26 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-21 17:26
Pre-Run: 11,296,129,024 bytes free
Post-Run: 11,257,012,224 bytes free
144