تفضل عزيزي هذا التقرير
وجاري الفحص بالوضع الامن
ComboFix 09-05-07.A01 - user 05/08/2009 18:15.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.502.293 [GMT 3:00]
Running from: c:\documents and settings\user\Desktop\التحميلات\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-04-08 to 2009-05-08 )))))))))))))))))))))))))))))))
.
2009-05-01 07:54 . 2009-05-01 07:54 -------- d--h--r C:\MSOCache
2009-05-01 07:44 . 2009-05-01 07:47 -------- d-----w c:\program files\Quran_in_Word
2009-04-22 13:46 . 2009-04-22 13:46 -------- d-----w c:\program files\Windows Media Connect 2
2009-04-16 19:43 . 2009-04-16 20:04 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-04-16 19:43 . 2009-04-16 20:04 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-04-16 19:41 . 2009-05-08 15:18 2408480 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-16 19:41 . 2009-05-08 15:21 475168 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-16 19:41 . 2009-04-16 19:41 -------- d-----w c:\program files\Kaspersky Lab
2009-04-16 19:41 . 2009-05-08 15:22 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-13 14:47 . 2009-04-13 14:47 -------- d-----w c:\windows\system32\hr-hr
2009-04-13 14:47 . 2009-04-13 14:47 -------- d-----w c:\windows\system32\he-il
2009-04-13 14:47 . 2009-04-13 14:47 -------- d-----w c:\windows\system32\fr-fr
2009-04-13 14:47 . 2009-04-13 14:47 -------- d-----w c:\windows\system32\fi-fi
2009-04-13 14:47 . 2009-04-13 14:47 -------- d-----w c:\windows\system32\et-ee
2009-04-13 14:47 . 2009-04-13 14:47 -------- d-----w c:\windows\system32\es-es
2009-04-13 14:47 . 2009-04-13 14:47 -------- d-----w c:\windows\system32\el-gr
2009-04-13 14:47 . 2009-04-13 14:47 -------- d-----w c:\windows\system32\de-de
2009-04-13 14:47 . 2009-04-13 14:47 -------- d-----w c:\windows\system32\da-dk
2009-04-08 19:16 . 2009-04-08 19:16 191656 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-04-08 19:15 . 2009-04-08 19:15 -------- d-----w c:\program files\MSBuild
2009-04-08 19:15 . 2009-04-08 19:20 -------- d-----w c:\windows\system32\XPSViewer
2009-04-08 19:14 . 2009-04-08 19:14 -------- d-----w c:\program files\Reference Assemblies
2009-04-08 19:13 . 2006-06-29 10:07 14048 ------w c:\windows\system32\spmsg2.dll
2009-04-08 16:56 . 2009-04-08 17:02 -------- d-----w C:\3dfed16209b503314ec660e4b20d
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-08 15:21 . 2009-04-16 19:41 2704 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-08 15:18 . 2009-04-16 19:41 19896 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-08 11:47 . 2009-04-06 12:41 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-05-01 12:21 . 2009-04-08 19:22 -------- d-----w c:\program files\TuneUp Utilities 2007
2009-05-01 12:02 . 2009-03-30 06:29 97520 ----a-w c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-22 16:18 . 2009-03-31 08:36 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-17 10:30 . 2009-03-31 08:24 -------- d-----w c:\program files\ScanSpyware v3.8.0.4
2009-04-16 20:04 . 2008-01-29 14:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-04-09 16:52 . 2009-03-31 17:23 -------- d-----w c:\program files\Internet Download Manager
2009-04-09 16:45 . 2009-04-09 16:16 7168 ----a-w c:\windows\system32\drivers\utezmzaz.sys
2009-04-06 19:20 . 2009-03-31 08:01 -------- d-----w c:\program files\Your Uninstaller 2008
2009-04-06 19:17 . 2009-04-06 17:12 -------- d-----w c:\program files\TuneUp Utilities 2009
2009-04-06 15:12 . 2009-03-31 17:03 -------- d-----w c:\program files\Windows Live
2009-04-06 15:11 . 2009-04-06 15:11 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-04-06 15:09 . 2009-03-30 07:15 -------- d-----w c:\program files\MSN Messenger
2009-04-06 15:08 . 2009-04-06 15:08 -------- d-----w c:\program files\Microsoft
2009-04-04 11:40 . 2009-03-30 07:01 -------- d-----w c:\program files\Microsoft Works
2009-04-03 18:15 . 2009-04-03 18:15 -------- d-----w c:\program files\Common Files\Windows Live
2009-04-02 15:24 . 2009-03-30 06:46 -------- d-----w c:\program files\Yahoo!
2009-04-01 22:21 . 2009-04-01 20:27 -------- d-----w c:\program files\Common Files\BitCtrl
2009-04-01 20:42 . 2009-04-01 20:42 17119 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-04-01 20:40 . 2009-03-30 06:31 -------- d-----w c:\program files\Intel
2009-04-01 20:09 . 2009-04-01 20:09 -------- d-----w c:\program files\VideoLAN
2009-04-01 19:58 . 2009-04-01 19:57 73216 ----a-w c:\windows\ST6UNST.EXE
2009-04-01 18:33 . 2009-04-01 18:33 -------- d-----w c:\program files\Lavasoft
2009-04-01 11:18 . 2009-04-01 11:18 -------- d-----w c:\program files\MSXML 4.0
2009-03-31 23:07 . 2009-03-31 23:07 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-03-31 23:07 . 2009-03-31 23:07 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-03-31 22:56 . 2009-03-31 20:05 -------- d-----w c:\program files\Nokia
2009-03-31 22:54 . 2009-03-31 20:06 -------- d-----w c:\program files\Common Files\Nokia
2009-03-31 22:54 . 2009-03-31 22:54 -------- d-----w c:\program files\MSXML 6.0
2009-03-31 20:06 . 2009-03-31 20:06 -------- d-----w c:\program files\Common Files\PCSuite
2009-03-31 20:06 . 2009-03-31 20:06 -------- d-----w c:\program files\DIFX
2009-03-31 20:05 . 2009-03-31 20:05 -------- d-----w c:\program files\PC Connectivity Solution
2009-03-31 17:03 . 2009-03-31 17:03 -------- d-----w c:\program files\Messenger Plus! Live
2009-03-31 11:27 . 2009-03-30 06:41 -------- d-----w c:\program files\JetAudio
2009-03-31 08:37 . 2009-03-31 08:37 -------- d-----w c:\program files\TechSmith
2009-03-31 07:42 . 2009-03-31 07:42 0 ----a-w c:\windows\nsreg.dat
2009-03-31 07:32 . 2009-03-31 07:33 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-31 07:32 . 2009-03-30 07:22 -------- d-----w c:\program files\Java
2009-03-30 07:22 . 2009-03-30 07:22 -------- d-----w c:\program files\Common Files\Java
2009-03-30 07:14 . 2009-03-30 07:13 -------- d-----w c:\program files\QuickTime
2009-03-30 07:14 . 2009-03-30 07:14 -------- d-----w c:\program files\Common Files\xing shared
2009-03-30 07:13 . 2009-03-30 07:13 -------- d-----w c:\program files\Common Files\Real
2009-03-30 07:13 . 2009-03-30 07:13 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-03-30 07:13 . 2009-03-30 07:13 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-03-30 07:13 . 2009-03-30 07:13 -------- d-----w c:\program files\Google
2009-03-30 07:13 . 2009-03-30 07:13 -------- d-----w c:\program files\Real
2009-03-30 07:13 . 2009-03-30 07:13 -------- d-----w c:\program files\Apple Software Update
2009-03-30 07:01 . 2009-03-30 07:01 -------- d-----w c:\program files\Microsoft.NET
2009-03-30 06:57 . 2009-03-30 06:54 -------- d-----w c:\program files\Common Files\Ahead
2009-03-30 06:54 . 2009-03-30 06:52 -------- d-----w c:\program files\Common Files\Adobe
2009-03-30 06:54 . 2009-03-30 06:54 -------- d-----w c:\program files\Nero
2009-03-30 06:52 . 2009-03-30 06:30 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-30 06:49 . 2009-03-30 06:46 -------- d-----w c:\program files\Common Files\Macromedia
2009-03-30 06:47 . 2009-03-30 06:19 166455 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-30 06:47 . 2009-03-30 06:46 -------- d-----w c:\program files\Macromedia
2009-03-30 06:42 . 2009-03-30 06:42 -------- d-----w c:\program files\Common Files\ACD Systems
2009-03-30 06:42 . 2009-03-30 06:42 -------- d-----w c:\program files\ACD Systems
2009-03-30 06:41 . 2009-03-30 06:41 10368 ----a-w c:\windows\system32\drivers\pfc.sys
2009-03-30 06:41 . 2009-03-30 06:30 -------- d-----w c:\program files\Common Files\InstallShield
2009-03-30 06:36 . 2009-03-30 06:36 -------- d-----w c:\program files\WIDCOMM
2009-03-30 06:34 . 2009-03-30 06:34 -------- d-----w c:\program files\CONEXANT
2009-03-30 06:33 . 2009-03-30 06:33 -------- d-----w c:\program files\Synaptics
2009-03-30 06:20 . 2009-03-30 06:20 -------- d-----w c:\program files\microsoft frontpage
2009-03-30 06:19 . 2001-08-23 12:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-03-30 06:16 . 2009-03-30 06:16 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-26 15:35 . 2009-03-30 08:51 210352 ----a-w c:\windows\system32\idmmbc.dll
2009-03-06 14:44 . 2004-08-03 21:56 283648 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-03 21:56 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-08-03 21:56 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 10:20 . 2004-08-03 21:56 399360 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:20 . 2004-08-03 21:56 723456 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:20 . 2004-08-03 21:56 616960 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:20 . 2004-08-03 21:56 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 10:19 . 2004-08-03 20:17 1846272 ----a-w c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-03-31 2790832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-04-16 206088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 08:27 110592 ----a-w c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"IgfxTray"=c:\windows\system32\igfxtray.exe
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 05:29 م 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 06:02 م 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 05:06 م 24592]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [01/04/2009 01:56 ص 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [01/04/2009 01:56 ص 8320]
S3 utezmzaz;AVZ Kernel Driver;c:\windows\system32\drivers\utezmzaz.sys [09/04/2009 07:16 م 7168]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-05-08 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-08-02 16:35]
2009-04-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 14:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\i4eqhnwk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\documents and settings\user\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-08 18:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1484)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
- - - - - - - > 'explorer.exe'(3080)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ara.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Intel\Wireless\Bin\OProtSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-05-08 18:25 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-08 15:25
Pre-Run: 20,252,893,184 bytes free
Post-Run: 20,188,504,064 bytes free
236 --- E O F --- 2009-05-07 12:41