اخويا انتهت اات الكمبوفاس وهذا هوا لتقرير
ComboFix 09-05-07.A01 - خالد khalid 05/08/2009 19:15.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.238.96 [GMT 3:00]
Running from: C:\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated)
AV: McAfee VirusScan *On-access scanning enabled* (Updated)
FW: Kaspersky Internet Security *enabled*
FW: McAfee Personal Firewall *enabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ATI64SI
-------\Legacy_FIPS32CUP
-------\Legacy_KSI32SK
-------\Legacy_NETSIK
-------\Legacy_NICSK32
-------\Legacy_PORT135SIK
-------\Legacy_SECURENTM
-------\Legacy_SYSTEMNTMI
((((((((((((((((((((((((( Files Created from 2009-04-08 to 2009-05-08 )))))))))))))))))))))))))))))))
.
2009-05-08 16:11 . 2009-05-08 16:11 3019252 ----a-r C:\ComboFix.exe
2009-05-08 15:48 . 2009-05-08 15:48 -------- d-----w c:\documents and settings\خالد khalid\Application Data\CyberScrub
2009-05-08 15:47 . 2009-05-08 15:47 -------- d-----w c:\documents and settings\خالد khalid\Application Data\cleaner
2009-05-08 15:44 . 2009-05-08 15:44 3550880 ----a-w C:\Zyzoom_CyberScrub_Privacy_Suite_2.exe
2009-05-08 03:54 . 2002-02-18 07:22 139536 ----a-w c:\windows\system32\javaee.dll
2009-05-08 03:24 . 2009-05-08 03:24 -------- d-----w c:\documents and settings\خالد khalid\Application Data\Malwarebytes
2009-05-08 03:24 . 2009-05-08 03:24 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-08 03:22 . 2009-05-08 03:22 2351120 ----a-w C:\mbam-setup.exe
2009-05-07 23:18 . 2009-05-06 03:27 394267 ----a-w C:\نسخ من UltraSurf 9.2.zip
2009-05-07 21:04 . 2009-05-07 21:07 -------- d-----w C:\moon abudabi
2009-05-07 18:02 . 2009-05-07 18:02 39072864 ----a-w C:\setup_7.0.0.290_07.05.2009_20-52.exe
2009-05-07 16:29 . 2009-05-07 18:31 396288 ----a-w C:\HiJackThis.exe
2009-05-07 16:00 . 2009-05-07 16:00 74299 ----a-w C:\اقوى اداة لاازالة فيروس Autorun.zip
2009-05-07 15:58 . 2009-05-07 15:58 -------- d--h--w c:\windows\system32\GroupPolicy
2009-05-07 15:37 . 2009-05-07 15:37 217 ----a-w C:\disablerollback.zip
2009-05-06 03:27 . 2009-05-06 03:27 394267 ----a-w C:\UltraSurf 9.2.zip
2009-05-05 22:18 . 2009-05-05 22:18 -------- d-----w c:\documents and settings\All Users\Application Data\SWiSHMax2WorkFolder
2009-04-29 21:05 . 2009-04-30 01:04 -------- d-----w C:\عليان
2009-04-27 03:21 . 2009-04-27 03:21 -------- d-----w c:\documents and settings\خالد khalid\Local Settings\Application Data\Identities
2009-04-27 01:04 . 2009-04-27 01:04 -------- d-----w c:\documents and settings\خالد khalid\Application Data\Thinstall
2009-04-23 00:01 . 2009-04-23 00:01 -------- d-----w c:\program files\ColorSoft
2009-04-18 23:15 . 2009-04-18 23:40 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-04-18 23:15 . 2009-04-18 23:40 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-04-18 23:10 . 2009-04-30 14:42 557088 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-18 23:10 . 2009-04-18 23:10 -------- d-----w c:\program files\Kaspersky Lab
2009-04-18 23:10 . 2009-05-07 18:12 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-18 22:29 . 2009-04-18 22:29 -------- d-----w c:\windows\Sun
2009-04-18 11:19 . 2009-05-08 16:21 423454752 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-18 11:18 . 2008-07-08 11:54 148496 ----a-w c:\windows\system32\drivers\98747588.sys
2009-04-18 11:17 . 2009-04-18 11:14 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-17 23:14 . 2009-04-17 23:14 0 ----a-w c:\windows\nsreg.dat
2009-04-17 23:13 . 2009-04-17 23:13 -------- d-----w c:\documents and settings\خالد khalid\Local Settings\Application Data\Mozilla
2009-04-17 22:30 . 2009-04-17 22:30 -------- d-----w c:\documents and settings\خالد khalid\Local Settings\Application Data\ESET
2009-04-17 22:13 . 2009-04-17 22:13 -------- d-----w c:\program files\Enigma Software Group
2009-04-17 20:18 . 2009-05-08 15:34 -------- d-----w c:\documents and settings\خالد khalid\Local Settings\Application Data\Google
2009-04-17 16:52 . 2009-04-17 16:52 -------- d-----w c:\documents and settings\خالد khalid\Application Data\INAC
2009-04-17 16:52 . 2009-04-17 16:52 -------- d-----w c:\documents and settings\All Users\Application Data\INAC
2009-04-17 16:22 . 2009-04-17 16:22 78440 ----a-w c:\documents and settings\خالد khalid\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-17 16:11 . 2009-04-17 19:02 67645 ----a-w c:\windows\system32\drivers\pshook11.sys
2009-04-17 16:11 . 2009-04-18 00:26 -------- d-----w c:\program files\INAC
2009-04-17 15:03 . 2009-04-17 15:10 -------- d-----w c:\documents and settings\خالد khalid\Application Data\MYweb4net
2009-04-17 14:58 . 2009-04-17 16:51 -------- d-----w c:\program files\MYweb4net
2009-04-17 14:10 . 2009-04-17 14:10 -------- d-----w c:\windows\PaltalkScene
2009-04-17 14:10 . 2009-04-17 14:13 -------- d-----w c:\program files\Paltalk Messenger
2009-04-16 12:54 . 2009-04-16 12:54 -------- d-----w c:\documents and settings\خالد khalid\Application Data\Ipswitch
2009-04-16 12:48 . 2009-04-16 12:48 -------- d-----w c:\documents and settings\All Users\Application Data\Ipswitch
2009-04-16 11:46 . 2009-04-16 14:22 -------- d-----w c:\documents and settings\خالد khalid\Tracing
2009-04-16 11:46 . 2009-04-16 14:22 -------- d-----w c:\documents and settings\خالد khalid\Tracing
2009-04-16 11:40 . 2009-04-17 10:09 -------- d-----w c:\windows\SxsCaPendDel
2009-04-16 11:13 . 2009-04-16 11:13 -------- d-----w c:\program files\Common Files\Windows Live
2009-04-16 04:18 . 2009-04-17 14:10 -------- d-----w c:\documents and settings\خالد khalid\Application Data\Paltalk
2009-04-16 03:57 . 2009-04-16 16:18 -------- d-----w c:\program files\security
2009-04-15 19:21 . 2009-04-15 19:21 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-04-15 16:44 . 2009-04-27 16:38 -------- d-----w C:\اضافات لمنصور
2009-04-14 21:48 . 2009-04-14 21:48 53248 ----a-w C:\u94.zip
2009-04-13 21:50 . 2002-10-25 02:17 65536 ----a-w c:\windows\system32\Crypserv.exe
2009-04-13 21:50 . 1999-06-18 21:49 165888 ----a-w c:\windows\Ckconfig.exe
2009-04-13 21:50 . 1995-07-04 18:33 11776 ----a-w c:\windows\Ckrfresh.exe
2009-04-13 21:50 . 1996-05-03 15:36 18432 ----a-w c:\windows\Setup_ck.dll
2009-04-13 21:50 . 1996-05-03 17:21 27648 ----a-r c:\windows\Setup_ck.exe
2009-04-13 21:44 . 2009-04-24 17:11 -------- d-----w c:\program files\Kelk 2000
2009-04-13 21:41 . 2009-04-14 21:55 -------- d-----w C:\تحميلات
2009-04-09 19:16 . 2009-04-09 19:42 -------- d-----w c:\program files\Online TV Player 4
2009-04-09 18:18 . 2009-04-09 18:18 -------- d-----w c:\documents and settings\خالد khalid\Application Data\FDRLab
2009-04-09 16:10 . 2009-04-09 16:10 -------- d-----w c:\documents and settings\All Users\Application Data\PrevxCSI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-08 16:21 . 2009-04-18 11:19 4898588 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-08 15:34 . 2009-03-15 06:07 -------- d-----w c:\program files\Google
2009-05-08 03:54 . 2009-05-08 03:54 2678 ----a-w c:\windows\java\Packages\Data\PRT3X7Z1.DAT
2009-05-08 03:54 . 2009-05-08 03:54 2678 ----a-w c:\windows\java\Packages\Data\4YM3DRR9.DAT
2009-05-08 03:54 . 2009-05-08 03:54 2678 ----a-w c:\windows\java\Packages\Data\PJH73PV7.DAT
2009-05-08 03:54 . 2009-05-08 03:54 2678 ----a-w c:\windows\java\Packages\Data\AJ1VDBLJ.DAT
2009-05-08 03:54 . 2009-05-08 03:54 2678 ----a-w c:\windows\java\Packages\Data\C5Z9V1Z1.DAT
2009-05-08 03:39 . 2009-03-10 06:31 -------- d-----w c:\program files\K-Lite Codec Pack
2009-05-08 00:53 . 2009-04-02 05:50 50176 ----a-w c:\windows\uninstyler.exe
2009-05-07 18:42 . 2009-04-06 22:22 262144 ----a-w C:\u94.exe
2009-05-07 18:30 . 2004-08-03 20:56 337920 ----a-w c:\windows\system32\zipfldr.dll
2009-05-07 18:29 . 2004-08-03 20:56 65024 ----a-w c:\windows\system32\msiexec.exe
2009-05-07 18:28 . 2009-03-10 05:57 114688 ----a-w c:\windows\system32\hkcmd.exe
2009-05-07 18:28 . 2009-03-10 05:57 155648 ----a-w c:\windows\system32\igfxtray.exe
2009-05-07 18:27 . 2004-08-03 20:55 438272 ----a-w c:\windows\system32\shimgvw.dll
2009-04-30 14:42 . 2009-04-18 23:10 2984 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-27 14:42 . 2009-03-19 12:47 -------- d-----w c:\program files\SWiSH Max2
2009-04-23 21:35 . 2009-03-23 04:06 -------- d-----w c:\program files\SWiSHmax
2009-04-21 05:19 . 2009-03-10 07:10 -------- d-----w c:\program files\Microsoft ActiveSync
2009-04-18 23:41 . 2008-01-29 14:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-04-18 01:29 . 2009-03-11 11:23 -------- d-----w c:\program files\Messenger Plus! Live
2009-04-18 01:29 . 2009-03-10 14:18 -------- d-----w c:\program files\MSN Messenger
2009-04-18 00:46 . 2009-04-06 02:50 -------- d-----w c:\program files\SiteMap Generator
2009-04-17 19:28 . 2001-09-19 11:00 58784 ----a-w c:\windows\system32\perfc001.dat
2009-04-17 19:28 . 2001-09-19 11:00 328494 ----a-w c:\windows\system32\perfh001.dat
2009-04-16 16:05 . 2009-03-11 11:23 -------- d-----w c:\program files\Windows Live
2009-04-08 16:37 . 2009-04-02 06:54 -------- d-----w c:\program files\MassSender
2009-04-06 22:48 . 2009-04-06 22:48 -------- d-----w c:\program files\Invisible Detector
2009-04-06 02:11 . 2009-04-06 02:11 -------- d-----w c:\program files\Micro-Sys Software
2009-04-02 20:14 . 2009-04-02 20:14 -------- d-----w c:\program files\Common Files\xing shared
2009-04-02 20:14 . 2009-03-10 06:17 -------- d-----w c:\program files\Common Files\Real
2009-03-30 21:45 . 2009-03-30 21:44 -------- d-----w c:\program files\Replay Converter 3
2009-03-30 21:42 . 2009-03-30 21:42 21319232 ----a-w C:\RCSetup.exe
2009-03-30 21:40 . 2009-03-30 21:40 -------- d-----w c:\program files\Magicbit
2009-03-30 21:36 . 2009-03-30 21:36 -------- d-----w c:\program files\Common Files\SWF Studio
2009-03-30 21:35 . 2009-03-30 21:35 -------- d-----w c:\program files\Riva
2009-03-30 05:56 . 2009-03-30 05:45 -------- d-----w c:\program files\YoutubeGet
2009-03-30 05:23 . 2009-03-29 05:52 -------- d-----w c:\program files\Total Video Converter
2009-03-30 05:21 . 2009-03-30 05:21 5353452 ----a-w C:\Total_Video_Converter_v3[1].10.zip
2009-03-27 16:34 . 2009-03-27 16:32 -------- d-----w c:\program files\Propel Accelerator
2009-03-24 17:13 . 2009-03-24 17:13 -------- d-----w c:\program files\aMSN
2009-03-20 23:49 . 2009-03-20 23:49 -------- d-----w c:\program files\مشغل الفلاش العربي
2009-03-19 12:51 . 2009-03-19 12:51 -------- d-----w c:\program files\Common Files\SWiSHzone.com
2009-03-19 05:28 . 2009-03-17 20:08 -------- d-----w c:\program files\REALTEK RTL8187 Wireless LAN Driver and Utility
2009-03-18 23:15 . 2009-03-18 23:15 -------- d-----w c:\program files\Ipswitch
2009-03-18 23:15 . 2009-03-10 05:57 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-18 04:21 . 2009-03-17 20:07 21035 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-03-17 20:07 . 2009-03-17 20:07 -------- d-----w c:\program files\Atheros
2009-03-17 01:29 . 2009-03-17 01:29 -------- d-----w c:\program files\Microsoft Works
2009-03-16 03:06 . 2009-03-13 17:27 -------- d-----w c:\program files\McAfee
2009-03-16 02:48 . 2009-03-11 11:23 -------- d-----w c:\program files\Circle Developement
2009-03-15 13:48 . 2009-03-12 04:39 -------- d-----w c:\program files\Orbitdownloader
2009-03-15 07:18 . 2009-03-15 07:18 2232 ----a-w c:\windows\java\Packages\Data\V357DBN1.DAT
2009-03-15 07:18 . 2009-03-15 07:18 155995 ----a-w c:\windows\java\Packages\BLFRNFFV.ZIP
2009-03-13 15:24 . 2009-03-13 15:21 -------- d-----w c:\program files\Common Files\Adobe
2009-03-13 10:32 . 2009-03-10 05:22 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-10 07:09 . 2009-03-10 07:09 -------- d-----w c:\program files\winbond
2009-03-10 06:50 . 2009-03-10 06:50 -------- d-----w c:\program files\Microsoft.NET
2009-03-10 06:19 . 2009-03-10 06:17 -------- d-----w c:\program files\Real
2009-03-10 05:57 . 2009-03-10 05:57 -------- d-----w c:\program files\Common Files\InstallShield
2009-03-10 05:31 . 2009-03-10 05:31 -------- d-----w c:\program files\Alwil Software
2009-03-10 05:23 . 2009-03-10 05:23 -------- d-----w c:\program files\microsoft frontpage
2009-03-10 05:22 . 2001-09-19 11:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-03-10 05:19 . 2009-03-10 05:19 22144 ----a-w c:\windows\system32\emptyregdb.dat
.
------- Sigcheck -------
[-] 2008-01-02 20:15 1547776 DABAD58A8BA625B241B90FB1A81154ED c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2009-05-07 188416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-05-07 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-05-07 114688]
"ACU"="c:\program files\Atheros\ACU.exe" [2009-05-07 303104]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-07 192512]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"RestrictRun"= 0 (0x0)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\PalTalk.lnk
backup=c:\windows\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^خالد khalid^قائمة ابدأ^البرامج^بدء التشغيل^is-GIE86.lnk]
path=c:\documents and settings\خالد khalid\قائمة ابدأ\البرامج\بدء التشغيل\is-GIE86.lnk
backup=c:\windows\pss\is-GIE86.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^خالد khalid^قائمة ابدأ^البرامج^بدء التشغيل^WWU.lnk]
path=c:\documents and settings\خالد khalid\قائمة ابدأ\البرامج\بدء التشغيل\WWU.lnk
backup=c:\windows\pss\WWU.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R2 0315291236965362mcinstcleanup;0315291236965362mcinstcleanup; [x]
R2 gupdate1c9ac6c1739d950;خدمة تحديث Google (gupdate1c9ac6c1739d950);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-24 133104]
R2 Vihyajyoq;Vihyajyoq;c:\windows\System32\svchost.exe [2004-08-03 14336]
R3 abp470n5;abp470n5;c:\windows\system32\drivers\kkhtnn.sys [x]
R3 W35UND;W89C35 802.11bg WLAN USB Adapter Driver;c:\windows\system32\DRIVERS\W35UND.SYS [2006-07-21 111232]
R3 xAntiArp;xAntiArpSpoof Service;c:\windows\system32\DRIVERS\xAntiArp.sys [x]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-04-18 33808]
S1 is-GIE86drv;is-GIE86drv;c:\windows\system32\DRIVERS\98747588.sys [2008-07-08 148496]
S1 wbsecdrv;wbsecdrv Protocol Driver;c:\windows\system32\DRIVERS\wbsecdrv.sys [2006-02-15 17952]
S2 Apache2.2;Apache2.2;c:\appserv\Apache2.2\bin\httpd.exe [2008-01-17 24635]
S2 wbsecsvc;wbsecsvc;c:\windows\system32\wbsecsvc.exe [2006-07-14 274432]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187.sys [2007-01-11 194304]
S3 SjyPkt;SjyPkt;c:\windows\System32\Drivers\SjyPkt.sys [2002-10-02 13532]
--- Other Services/Drivers In Memory ---
*Deregistered* - ACS
*Deregistered* - Alerter
*Deregistered* - Apache2.2
*Deregistered* - AudioSrv
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - Crypkey License
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmserver
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - gupdate1c9ac6c1739d950
*Deregistered* - helpsvc
*Deregistered* - HTTPFilter
*Deregistered* - ImapiService
*Deregistered* - Irmon
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - MDM
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - MySQL
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - NetworkX
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PCIIde
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasirda
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SjyPkt
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - Vihyajyoq
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - wbsecdrv
*Deregistered* - wbsecsvc
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Vihyajyoq
.
Contents of the 'Scheduled Tasks' folder
2009-05-06 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-24 10:33]
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-[system] - c:\windows\system32\drivers\services.exe
HKU-Default-Run-winlogon - c:\documents and settings\LocalService\svchost.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-08 19:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1606980848-1563985344-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*t*t* \OpenWithList]
@Class="Shell"
"a"="msnmsgr.exe"
"MRUList"="a"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4233ADD3-CD31-D295-804BA870321FDEF4}\{F4A8E5F3-7E68-2DD0-FA9D328203A7D1A7}\{07380252-9142-5EC5-94F639FC4AE64832}*]
"1D1OWFM6WKF6TLM3S2BGKKUUDG1"=hex:01,00,01,00,00,00,00,00,71,4a,e0,45,b7,4f,44,
fb,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74099617-91C0-6CB0-475BC8650FC6C929}\{C2CB2410-92BB-FC4E-376913EB15620FA4}\{B6CDFCFD-0A38-7380-A1288DE48E078F85}*]
"1D1OWFM6WKF6TLM3S2BGKKUUDG1"=hex:01,00,01,00,00,00,00,00,71,4a,e0,45,b7,4f,44,
fb,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9D7D745F-2DA2-E26E-67E2A61C92B5C873}\{869A1319-CB5B-72EF-32E86935B8210920}\{0F637A1B-C125-DB37-203685E7DE12B741}*]
"{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1"=hex:01,00,01,00,0c,00,00,00,28,56,85,
90,85,0f,ae,fb,7b,50,52,ff,71,85,ca,0f,6b,66,6c,55,3b,97,e1,d8,e7,4e,77,51,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A73A7B6D-D5C7-2D01-6A3ED58A203D5FEA}\{958FE6C0-B367-4AD6-C310294BFC5DB709}\{E2E9EAF6-387C-4947-07B2C800F4ACC9F3}*]
"{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1"=hex:01,00,01,00,0c,00,00,00,28,56,85,
90,85,0f,ae,fb,7b,50,52,ff,71,85,ca,0f,6b,66,6c,55,3b,97,e1,d8,e7,4e,77,51,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CE901474-3557-00BE-0B74D16C6C9B8223}\{8B1B0984-A0E2-36AE-AE0ABC7DD3EE1D9C}\{C1D3D6EB-516B-0CD4-D732D0B608CDF1EA}*]
"SE4K5INHHR1EDZYY15BVZC6TKG1"=hex:01,00,01,00,00,00,00,00,7e,c3,c3,8e,86,b4,21,
5e,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D96284CB-92E6-3E1E-196BB0273B005327}\{BCF0CDFC-4A0B-26E5-259182A4D665E8F2}\{6E248836-421D-F84C-CF6B8AC08EBF0D43}*]
"SE4K5INHHR1EDZYY15BVZC6TKG1"=hex:01,00,01,00,00,00,00,00,7e,c3,c3,8e,86,b4,21,
5e,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(996)
c:\windows\system32\athgina.dll
c:\windows\system32\athcfg11.dll
c:\windows\system32\athcfg11Res.dll
- - - - - - - > 'explorer.exe'(4024)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\acs.exe
c:\windows\system32\Crypserv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\appserv\MySQL\bin\mysqld-nt.exe
c:\windows\system32\wscntfy.exe
c:\program files\REALTEK RTL8187 Wireless LAN Driver and Utility\RtWLan.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
.
**************************************************************************
.
Completion time: 2009-05-08 19:33 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-08 16:33
ComboFix2.txt 2009-05-07 17:15
Pre-Run: 10,662,133,760 bytes free
Post-Run: 10,652,057,600 bytes free
408
اخويا االان بعيد تشغيل الجهاز وشغله على الوظع الامن ونزل المكافي وسوي له فحص