وهذا تقرير الكومبو اخي الكريم
ComboFix 09-05-19.08 - wk.h 05/21/2009 0:01.4 - NTFSx86
Running from: c:\documents and settings\wk.h\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-04-21 to 2009-05-21 )))))))))))))))))))))))))))))))
.
2009-05-22 03:06 . 2009-05-21 05:47 94643 ----a-w c:\windows\system32\drivers\klick.dat
2009-05-22 03:06 . 2009-05-21 05:47 105395 ----a-w c:\windows\system32\drivers\klin.dat
2009-05-22 03:05 . 2009-05-21 06:53 928288 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-22 03:05 . 2009-05-21 06:53 188448 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-22 03:05 . 2009-05-22 03:05 -------- d-----w c:\program files\Kaspersky Lab
2009-05-22 03:05 . 2009-05-21 06:54 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-05-22 03:04 . 2009-05-22 03:04 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-05-22 02:12 . 2009-05-22 02:12 253688 ----a-w c:\windows\system32\cssdll32.dll
2009-05-22 02:11 . 2009-05-22 02:28 -------- d-----w c:\program files\COMODO
2009-05-22 01:52 . 2009-05-22 01:52 -------- d-----w c:\documents and settings\wk.h\Application Data\COWON
2009-05-22 01:28 . 2009-03-24 23:08 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-22 01:28 . 2009-05-22 03:03 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-05-22 01:25 . 2009-05-22 01:25 -------- d-----w c:\windows\SxsCaPendDel
2009-05-21 05:24 . 2009-05-21 05:24 -------- d-----w c:\documents and settings\wk.h\Application Data\Media Player Classic
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-22 01:24 . 2009-05-17 21:10 -------- d-----w c:\program files\Common Files\BitDefender
2009-05-22 01:24 . 2009-05-17 21:26 81984 ----a-w c:\windows\system32\bdod.bin
2009-05-21 06:53 . 2009-05-22 03:05 3820 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-21 06:53 . 2009-05-22 03:05 11476 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-21 05:47 . 2008-01-30 00:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-05-18 06:46 . 2009-05-18 06:46 -------- d-----w c:\program files\microsoft frontpage
2009-05-18 06:44 . 2009-05-18 06:44 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-05-17 22:20 . 2009-05-17 22:20 -------- d-----w c:\program files\FastStone Image Viewer
2009-05-17 22:19 . 2009-05-17 22:19 -------- d-----w c:\program files\Ashampoo
2009-05-17 22:14 . 2009-05-17 22:14 -------- d-----w c:\program files\Common Files\TechSmith Shared
2009-05-17 22:14 . 2009-05-17 22:14 -------- d-----w c:\program files\TechSmith
2009-05-17 22:04 . 2009-05-17 21:58 -------- d-----w c:\program files\Your Uninstaller 2008
2009-05-17 21:55 . 2009-05-17 21:55 -------- d-----w c:\program files\TuneUp Utilities 2009
2009-05-17 21:55 . 2009-05-17 21:55 604416 ----a-w c:\windows\system32\TUProgSt.exe
2009-05-17 21:55 . 2009-05-17 21:55 361216 ----a-w c:\windows\system32\TuneUpDefragService.exe
2009-05-17 21:54 . 2009-05-17 21:54 -------- d-----w c:\program files\CCleaner
2009-05-17 21:50 . 2009-05-17 21:49 -------- d-----w c:\program files\Allok 3GP PSP MP4 iPod Video Converter
2009-05-17 21:49 . 2009-05-17 21:49 -------- d-----w c:\program files\JetAudio
2009-05-17 21:49 . 2009-05-17 21:49 -------- d-----w c:\program files\Common Files\COWON
2009-05-17 21:49 . 2009-05-17 21:49 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-17 21:49 . 2009-05-17 21:48 -------- d-----w c:\program files\K-Lite Codec Pack
2009-05-17 21:48 . 2009-05-17 21:46 -------- d-----w c:\program files\Internet Download Manager
2009-05-17 21:44 . 2009-05-17 21:44 -------- d-----w c:\program files\Windows Live
2009-05-17 21:44 . 2009-05-17 21:44 -------- d-----w c:\program files\Messenger Plus! Live
2009-05-17 21:44 . 2009-05-17 21:40 -------- d-----w c:\program files\MSN Messenger
2009-05-17 21:18 . 2009-05-17 21:18 27264 ----a-w c:\documents and settings\wk.h\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-17 21:11 . 2009-05-17 21:11 -------- d-----w c:\program files\BitDefender
2009-05-17 21:04 . 2009-05-17 21:04 -------- d-----w c:\program files\Common Files\InstallShield
2009-05-17 21:02 . 2009-05-17 21:02 -------- d-----w c:\program files\VDOTool
2009-04-27 21:21 . 2009-05-17 21:55 28928 ----a-w c:\windows\system32\uxtuneup.dll
2009-04-02 13:21 . 2009-05-17 21:48 84480 ----a-w c:\windows\system32\ff_vfw.dll
2009-03-26 15:35 . 2009-05-07 07:42 210352 ----a-w c:\windows\system32\idmmbc.dll
2009-03-08 11:34 . 2004-08-03 23:56 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2004-08-03 23:56 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2004-08-03 23:56 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2004-08-03 23:56 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2004-08-03 23:56 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2004-08-03 23:56 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 11:31 . 2004-08-03 23:56 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2004-08-03 23:56 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2004-08-03 23:56 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2001-08-23 04:00 156160 ----a-w c:\windows\system32\msls31.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-05-22_02.46.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-12 02:58 . 2008-11-12 02:58 25601 c:\windows\system32\drivers\klopp.dat
+ 2008-05-01 00:06 . 2008-05-01 00:06 24592 c:\windows\system32\drivers\klim5.sys
+ 2008-03-14 01:02 . 2008-03-14 01:02 26640 c:\windows\system32\drivers\klfltdev.sys
+ 2008-11-12 03:00 . 2008-11-12 03:00 218376 c:\windows\system32\klogon.dll
+ 2009-05-22 03:05 . 2009-05-21 05:47 226832 c:\windows\system32\drivers\klif.sys
+ 2008-07-22 00:34 . 2008-07-22 00:34 121872 c:\windows\system32\drivers\kl1.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-05-07 2807216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TBPanel"="c:\program files\VDOTool\TBPanel.exe" [2008-01-29 2157096]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-08 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-08 81920]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-05-21 206088]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-01-08 1626112]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"e:\\KONAMI\\Pro.Evolution.Soccer.2009\\pes2009.exe"=
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-05-21 33808]
S2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2009-05-17 604416]
S3 ECTIVA;ECTIVA Audio 5.1 (WDM);c:\windows\system32\drivers\ECTIVA.sys [2004-02-12 1124864]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-14 26640]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-05-01 24592]
--- Other Services/Drivers In Memory ---
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - AVP
*Deregistered* - Beep
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - Cdfs
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - ImapiService
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - kl1
*Deregistered* - klbg
*Deregistered* - KLIF
*Deregistered* - klim5
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - NVSvc
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - TBPanel
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - TuneUp.ProgramStatisticsSvc
*Deregistered* - Update
*Deregistered* - UxTuneUp
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-05-21 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 22:37]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = 192.168.2.19:3128
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
TCP: {46C3D9FB-29DA-48AA-8CD6-D9FF89C88A50} = 192.168.2.19,192.168.2.9
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-21 00:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3420)
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2009-05-21 0:02
ComboFix-quarantined-files.txt 2009-05-21 07:02
ComboFix2.txt 2009-05-21 06:36
ComboFix3.txt 2009-05-22 02:46
Pre-Run: 35,162,316,800 bytes free
Post-Run: 35,159,449,600 bytes free
249