اخوي AbOdy
هادا تقرير الفحص اللي طلع معي
ComboFix 09-04-24.01 - Administrator 04/24/2009 15:23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.20.1033.18.1983.1597 [GMT 2:00]
Running from: e:\برامج\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\autorun.inf
c:\windows\IE4 Error Log.txt
D:\Autorun.inf
E:\Autorun.inf
F:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-05-24 to 2009-4-24 )))))))))))))))))))))))))))))))
.
2009-04-24 12:17 . 2009-04-24 12:21 -------- d-----w c:\documents and settings\Administrator\DoctorWeb
2009-04-24 12:01 . 2009-04-24 12:01 -------- d-----w c:\documents and settings\Administrator\Application Data\CyberScrub
2009-04-24 03:56 . 2009-04-24 03:57 7168 ----a-w c:\windows\system32\drivers\utmymjk3.sys
2009-04-24 03:53 . 2009-04-24 12:35 5184 ----a-w c:\windows\system32\winxp
2009-04-24 00:58 . 2009-04-24 03:19 -------- d-----w c:\windows\BDOSCAN8
2009-04-24 00:17 . 2009-04-24 11:53 -------- d-----w c:\documents and settings\Administrator\Application Data\cleaner
2009-04-24 00:00 . 2009-04-24 00:00 -------- d--h--w c:\windows\system32\GroupPolicy
2009-04-23 23:40 . 2009-04-23 23:40 8601 ----a-w c:\windows\system32\%LocalXml%
2009-04-23 23:32 . 2009-04-23 23:32 -------- d-----w c:\documents and settings\Administrator\Application Data\Internet Saving Optimizer
2009-04-23 23:32 . 2009-04-23 23:32 -------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-04-23 23:28 . 2009-04-23 23:28 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\DoubleD
2009-04-23 23:25 . 2009-04-24 13:09 -------- d-----w c:\documents and settings\Administrator\Tracing
2009-04-23 21:05 . 2009-04-23 21:05 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-04-23 21:05 . 2009-04-23 21:05 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-04-23 19:06 . 2001-11-08 00:27 237568 ----a-w c:\windows\system\glut32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-24 13:26 . 2009-04-23 15:54 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-24 13:26 . 2009-04-23 15:59 294944 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-24 13:26 . 2009-04-23 15:59 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-24 13:24 . 2009-04-23 15:59 5204 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-24 13:24 . 2009-04-23 15:59 15928 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-24 13:24 . 2009-04-23 15:59 1498144 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-24 12:05 . 2009-04-24 12:04 768 ----a-w C:\20090424-140454.968.log
2009-04-24 05:09 . 2009-04-24 05:09 627 ----a-w C:\20090424-070921.375.log
2009-04-24 05:09 . 2009-04-24 05:08 487 ----a-w C:\20090424-070852.859.log
2009-04-24 00:57 . 2009-04-23 23:26 -------- d-----w c:\program files\Messenger Plus! Live
2009-04-23 23:43 . 2009-04-23 23:41 775 ----a-w C:\20090424-014135.468.log
2009-04-23 23:38 . 2009-04-23 23:38 -------- d-----w c:\program files\Nice Prosper
2009-04-23 23:32 . 2009-04-23 22:44 -------- d-----w c:\program files\MSECACHE
2009-04-23 23:31 . 2009-04-23 23:31 -------- d-----w c:\program files\Internet Saving Optimizer
2009-04-23 23:29 . 2009-04-23 23:29 -------- d-----w c:\program files\System Search Dispatcher
2009-04-23 23:29 . 2009-04-23 23:29 -------- d-----w c:\program files\DoubleD
2009-04-23 23:26 . 2009-04-23 23:26 -------- d-----w c:\program files\Circle Developemet
2009-04-23 23:23 . 2009-04-23 23:23 -------- d-----w c:\program files\Microsoft
2009-04-23 23:23 . 2009-04-23 23:23 -------- d-----w c:\program files\Windows Live
2009-04-23 23:23 . 2009-04-23 23:23 -------- d-----w c:\program files\Windows Live SkyDrive
2009-04-23 22:44 . 2009-04-23 22:44 -------- d-----w c:\program files\Windows Installer Clean Up
2009-04-23 22:10 . 2008-01-29 15:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-04-23 22:10 . 2009-04-23 16:00 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-04-23 22:10 . 2009-04-23 16:00 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-04-23 21:25 . 2009-04-23 15:47 132312 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-23 21:05 . 2009-04-23 21:05 -------- d-----w c:\program files\Common Files\xing shared
2009-04-23 21:05 . 2009-04-23 20:29 -------- d-----w c:\program files\Common Files\Real
2009-04-23 21:05 . 2009-04-23 20:29 -------- d-----w c:\program files\Real
2009-04-23 20:26 . 2009-04-23 20:15 -------- d-----w c:\program files\The KMPlayer
2009-04-23 18:18 . 2009-04-23 18:10 -------- d-----w c:\program files\Web Publish
2009-04-23 18:05 . 2009-04-23 18:05 2678 ----a-w c:\windows\java\Packages\Data\SA6J1V93.DAT
2009-04-23 18:05 . 2009-04-23 18:05 2678 ----a-w c:\windows\java\Packages\Data\VRX3F9JP.DAT
2009-04-23 18:05 . 2009-04-23 18:05 2678 ----a-w c:\windows\java\Packages\Data\9N7XJDJJ.DAT
2009-04-23 18:05 . 2009-04-23 18:05 2678 ----a-w c:\windows\java\Packages\Data\9ZXFTVBF.DAT
2009-04-23 18:00 . 2009-04-23 17:36 -------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-23 17:59 . 2009-04-23 17:59 -------- d-----w c:\program files\Microsoft Works
2009-04-23 17:59 . 2009-04-23 17:59 -------- d-----w c:\program files\MSBuild
2009-04-23 17:33 . 2009-04-23 17:33 -------- d-----w c:\program files\Common Files\Windows Live
2009-04-23 16:34 . 2009-04-23 16:30 -------- d-----w c:\program files\Vista Sidebar
2009-04-23 16:31 . 2009-04-23 16:30 -------- d-----w c:\program files\Styler
2009-04-23 16:30 . 2009-04-23 16:30 -------- d-----w c:\documents and settings\Administrator\Application Data\Styler
2009-04-23 16:30 . 2009-04-23 16:30 -------- d-----w c:\program files\VisualTooltip
2009-04-23 16:30 . 2009-04-23 16:30 -------- d-----w c:\documents and settings\Administrator\Application Data\Stardock
2009-04-23 16:30 . 2009-04-23 16:30 -------- d-----w c:\program files\LClock
2009-04-23 16:27 . 2009-04-23 16:27 -------- d-----w c:\program files\microsoft frontpage
2009-04-23 16:26 . 2009-04-23 16:26 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-23 16:24 . 2009-04-23 16:24 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-04-23 16:23 . 2009-04-23 16:23 -------- d-----w c:\program files\Windows Media Connect 2
2009-04-23 16:15 . 2009-04-23 16:30 -------- d-----w c:\program files\Blaero Start Orb
2009-04-23 15:59 . 2009-04-23 15:59 -------- d-----w c:\program files\Kaspersky Lab
2009-04-23 15:58 . 2009-04-23 15:48 -------- d-----w c:\program files\Google
2009-04-23 15:58 . 2009-04-23 15:58 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-04-23 15:58 . 2009-04-23 15:58 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-04-23 15:57 . 2009-04-23 15:57 -------- d-----w c:\program files\Common Files\Adobe
2009-04-23 15:55 . 2009-04-23 15:54 -------- d-----w c:\program files\DAP
2009-04-23 15:54 . 2009-04-23 15:54 -------- d-----w c:\documents and settings\All Users\Application Data\SpeedBit
2009-04-23 15:54 . 2009-04-23 15:54 50688 ----a-w c:\windows\system32\wbhelp2.dll
2009-02-06 16:52 . 2009-02-06 16:52 49504 ----a-w c:\windows\system32\sirenacm.dll
.
------- Sigcheck -------
[-] 2007-04-04 15:10 2172928 F1EE6BDF8DB7BFCBCAEF5850FB226F6B c:\windows\system32\ntkrnlpa.exe
[-] 2007-04-04 14:56 2293248 A0775CC94870AE6463F9455EDBD79762 c:\windows\system32\ntoskrnl.exe
[-] 2007-04-04 15:52 1536000 05A5486C41980838512AB3531901D58F c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2009-04-23 2807296]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-23 39408]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LClock"="c:\program files\LClock\LClock.exe" [2004-09-19 65536]
"Vista Sidebar"="c:\program files\Vista Sidebar\sidebar.exe" [2006-12-25 6083072]
"Styler"="c:\program files\Styler\Styler.exe" [2006-05-03 307200]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-24 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-10-24 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-04-23 206088]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-23 185872]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-10-24 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-03-26 16859136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"IE7-11"="advpack.dll" - c:\windows\system32\advpack.dll [2007-03-21 124928]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R3 utmymjk3;AVZ Kernel Driver;c:\windows\system32\Drivers\utmymjk3.sys [2009-04-24 7168]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-04-23 33808]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{58558779-3035-11de-95cb-0024211de0e3}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Wscript.exe /e:vbs winfile.jpg
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-24 15:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(976)
c:\windows\system32\cscui.dll
- - - - - - - > 'explorer.exe'(3396)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\NETSHELL.dll
c:\program files\LClock\LC.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
c:\windows\system32\nvcpl.dll
c:\windows\system32\NVRSAR.DLL
c:\windows\system32\nvapi.dll
c:\windows\system32\nvshell.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-24 15:29 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-24 13:29
Pre-Run: 35,075,821,568 bytes free
Post-Run: 35,051,069,440 bytes free
200