وهذا التقرير
ComboFix 09-06-01.03 - faisoly 06/03/2009 16:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.1021.630 [GMT 3:00]
Running from: c:\documents and settings\faisoly\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-05-03 to 2009-06-03 )))))))))))))))))))))))))))))))
.
2009-06-03 12:26 . 2009-06-03 12:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Atelier Web
2009-06-03 09:23 . 2009-06-03 09:23 -------- d-s---w- c:\documents and settings\faisoly\UserData
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-03 13:26 . 2009-06-02 17:42 2555424 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-03 13:26 . 2009-06-02 17:42 86560 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-03 11:55 . 2009-06-02 17:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-03 11:41 . 2009-06-02 17:42 39920 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-03 11:41 . 2009-06-02 17:42 11768 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-02 19:51 . 2007-04-28 13:51 112144 ----a-w- c:\windows\system32\drivers\kl1.sys
2009-06-02 19:51 . 2009-06-02 17:42 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-06-02 19:51 . 2009-06-02 17:42 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-06-02 19:51 . 2009-06-02 19:51 112144 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.0.119\X86\kl1.sys
2009-06-02 19:51 . 2009-06-02 19:50 682512 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.0.119\updater.dll
2009-06-02 19:50 . 2009-06-02 19:50 194320 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.0.119\klif.sys
2009-06-02 19:50 . 2009-06-02 19:50 150032 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.0.119\diffs.dll
2009-06-02 19:49 . 2009-06-02 19:49 342544 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.0.119\ckahum.dll
2009-06-02 19:37 . 2009-06-02 19:37 -------- d-----w- c:\documents and settings\faisoly\Application Data\COWON
2009-06-02 18:26 . 2009-06-02 18:26 390664 ----a-w- c:\documents and settings\faisoly\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-06-02 18:24 . 2009-06-02 18:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-06-02 18:23 . 2009-06-02 18:23 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-02 18:22 . 2009-06-02 18:22 -------- d-----w- c:\program files\Windows Live
2009-06-02 18:21 . 2009-06-02 18:17 -------- d-----w- c:\program files\TuneUp Utilities 2008
2009-06-02 18:17 . 2009-06-02 18:17 355584 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-06-02 18:17 . 2009-06-02 18:17 -------- d-----w- c:\documents and settings\faisoly\Application Data\TuneUp Software
2009-06-02 18:17 . 2009-06-02 18:17 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-06-02 18:17 . 2009-06-02 18:17 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-02 18:15 . 2009-06-02 18:15 -------- d-----w- c:\program files\Common Files\xing shared
2009-06-02 18:15 . 2009-06-02 18:15 -------- d-----w- c:\program files\Common Files\Real
2009-06-02 18:15 . 2009-06-02 17:08 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-06-02 18:15 . 2007-03-11 18:24 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-06-02 18:15 . 2009-06-02 18:15 -------- d-----w- c:\program files\Real
2009-06-02 18:13 . 2009-06-02 18:13 -------- d-----w- c:\program files\JetAudio
2009-06-02 18:13 . 2009-06-02 18:13 -------- d-----w- c:\program files\Common Files\COWON
2009-06-02 18:13 . 2009-06-02 16:57 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-02 18:06 . 2009-06-02 16:38 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-02 17:47 . 2009-06-02 17:47 -------- d-----w- c:\program files\Opera
2009-06-02 17:42 . 2009-06-02 17:42 -------- d-----w- c:\program files\Kaspersky Lab
2009-06-02 17:41 . 2009-06-02 17:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-06-02 17:40 . 2009-06-02 17:25 127823 ----a-w- c:\windows\hpgins24.dat
2009-06-02 17:28 . 2009-06-02 17:28 -------- d-----w- c:\program files\Common Files\HP
2009-06-02 17:28 . 2009-06-02 17:25 -------- d-----w- c:\program files\HP
2009-06-02 17:26 . 2009-06-02 17:26 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-06-02 17:26 . 2009-06-02 17:26 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-06-02 17:26 . 2009-06-02 17:26 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-06-02 17:26 . 2009-06-02 17:26 -------- d-----w- c:\program files\Hewlett-Packard
2009-06-02 17:20 . 2009-06-02 17:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Bluetooth
2009-06-02 17:11 . 2009-06-02 17:11 -------- d-----w- c:\program files\IVT Corporation
2009-06-02 17:08 . 2009-06-02 17:08 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-06-02 17:08 . 2009-06-02 16:59 -------- d-----w- c:\program files\Common Files\InstallShield
2009-06-02 17:05 . 2009-06-02 17:05 34232 ----a-w- c:\documents and settings\faisoly\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-02 16:59 . 2009-06-02 16:57 -------- d-----w- c:\program files\Realtek
2009-06-02 16:59 . 2009-06-02 16:59 315392 ----a-w- c:\windows\HideWin.exe
2009-06-02 16:57 . 2009-06-02 16:57 -------- d-----w- c:\documents and settings\faisoly\Application Data\InstallShield
2009-06-02 16:51 . 2009-06-02 16:51 -------- d-----w- c:\program files\Intel
2009-06-02 16:51 . 2009-06-02 16:51 -------- d-----w- c:\program files\MSXML 4.0
2009-06-02 16:39 . 2009-06-02 16:39 -------- d-----w- c:\program files\microsoft frontpage
2009-06-02 16:35 . 2009-06-02 16:35 21640 ----a-w- c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2007-10-30 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-06-02 5728112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-01-16 16384512]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-06-28 1626112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-10-30 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2009-6-2 1183744]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"BlueSoleil Hid Service"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [04/04/2007 02:58 م 24344]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [02/06/2009 08:08 م 194304]
S3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [02/06/2009 08:08 م 13532]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - USNJSVC
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-06-03 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 06:09]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-03 16:26
Windows 5.1.2600 Service Pack 3, v.3244 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1060)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(1116)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
- - - - - - - > 'explorer.exe'(3448)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll
.
Completion time: 2009-06-03 16:27
ComboFix-quarantined-files.txt 2009-06-03 13:27
Pre-Run: 44,960,821,248 bytes free
Post-Run: 44,981,100,544 bytes free
142