هذا التقرير بعد الفحص بهذه الاداة التي اعطيتني اياها :
ComboFix 09-06-09.01 - samer 06/10/2009 9:35.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.964.1033.18.2047.1603 [GMT 4:00]
Running from: c:\documents and settings\samer\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
F:\install.exe
.
((((((((((((((((((((((((( Files Created from 2009-05-10 to 2009-06-10 )))))))))))))))))))))))))))))))
.
2009-06-08 09:00 . 2009-06-08 09:00 -------- d-----w- c:\program files\Trend Micro
2009-06-07 18:13 . 2009-06-07 18:17 -------- d-----w- c:\windows\NV15084016.TMP
2009-06-07 18:12 . 2007-11-06 15:59 356352 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-06-07 17:58 . 2006-12-08 07:02 67072 ----a-r- c:\windows\system32\drivers\Rtlh86.sys
2009-06-06 12:30 . 2009-06-06 12:30 -------- d-----w- c:\documents and settings\samer\Application Data\GlarySoft
2009-06-06 12:29 . 2009-06-06 12:29 -------- d-----w- c:\program files\Absolute Uninstaller
2009-06-06 12:22 . 2009-06-06 12:22 -------- d-----w- c:\documents and settings\samer\Application Data\URSoft
2009-06-06 12:22 . 2009-06-06 12:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-05 22:11 . 2009-06-05 22:11 -------- d-----w- c:\documents and settings\samer\Application Data\ABBYY
2009-06-05 22:09 . 2009-06-05 22:09 -------- d-----w- c:\program files\Common Files\ABBYY
2009-06-05 22:07 . 2009-06-05 22:11 -------- d-----w- c:\program files\ABBYY FineReader 9.0
2009-06-05 22:07 . 2009-06-05 22:07 -------- d-----w- c:\documents and settings\samer\Local Settings\Application Data\ABBYY
2009-06-05 22:07 . 2009-06-05 22:07 -------- d-----w- c:\documents and settings\All Users\Application Data\ABBYY
2009-06-05 12:36 . 2003-04-18 13:46 1233920 ----a-w- c:\windows\system32\msxml4.dll
2009-06-05 12:36 . 2003-04-18 13:29 82432 ----a-w- c:\windows\system32\msxml4r.dll
2009-06-05 12:36 . 2003-04-18 13:29 44544 ----a-w- c:\windows\system32\msxml4a.dll
2009-06-05 12:36 . 2009-06-05 12:37 -------- d-----w- c:\program files\File Recover
2009-06-04 21:36 . 2009-06-04 21:36 -------- d-----w- c:\documents and settings\samer\Application Data\Datalayer
2009-06-04 21:36 . 2009-06-04 21:36 -------- d-----w- c:\documents and settings\samer\Phone Browser
2009-06-04 21:36 . 2009-06-04 21:36 -------- d-----w- c:\documents and settings\samer\Application Data\Nokia
2009-06-03 08:17 . 2009-06-03 08:17 -------- d-----w- c:\program files\DIFX
2009-06-03 07:48 . 2009-06-03 07:48 -------- d-----w- c:\program files\Common Files\xing shared
2009-06-03 07:40 . 2009-06-03 07:40 -------- d-----w- c:\program files\Xing
2009-06-03 07:32 . 2009-06-03 07:32 -------- d-----w- c:\program files\Elaborate Bytes
2009-06-03 00:23 . 2009-06-03 00:23 -------- d-----w- c:\documents and settings\samer\Application Data\COWON
2009-06-03 00:21 . 2009-06-03 00:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-06-02 11:51 . 2009-06-06 20:35 -------- d-----w- c:\program files\Yahoo!
2009-06-01 22:34 . 2009-06-01 22:34 390664 ----a-w- c:\documents and settings\samer\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-06-01 22:33 . 2009-06-01 22:33 -------- d-----w- c:\documents and settings\samer\Local Settings\Application Data\Ahead
2009-06-01 22:00 . 2003-06-18 14:31 17920 ----a-w- c:\windows\system32\mdimon.dll
2009-06-01 21:59 . 2009-06-01 21:59 -------- d-----w- c:\program files\Microsoft.NET
2009-06-01 21:59 . 2009-06-01 21:59 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-06-01 21:58 . 2009-06-01 21:59 -------- d-----w- c:\windows\SHELLNEW
2009-06-01 21:50 . 2009-06-01 21:50 44384 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2009-06-01 21:50 . 2009-06-01 21:50 441760 ----a-w- c:\windows\system32\drivers\timntr.sys
2009-06-01 21:50 . 2009-06-01 21:50 129248 ----a-w- c:\windows\system32\drivers\snapman.sys
2009-06-01 21:49 . 2009-06-01 21:49 368736 ----a-w- c:\windows\system32\drivers\tdrpman.sys
2009-06-01 21:49 . 2009-06-01 21:49 -------- d-----w- c:\program files\Common Files\Acronis
2009-06-01 21:49 . 2009-06-01 21:49 -------- d-----w- c:\program files\Acronis
2009-06-01 21:37 . 2009-06-01 21:37 165013 ----a-w- c:\windows\Audio Converter Pro Uninstaller.exe
2009-06-01 21:37 . 2009-06-01 21:38 -------- d-----w- c:\documents and settings\All Users\Application Data\River Past G5
2009-06-01 21:37 . 2009-06-01 21:37 -------- d-----w- c:\program files\Common Files\River Past
2009-06-01 21:37 . 2009-06-01 21:37 -------- d-----w- c:\documents and settings\samer\Application Data\River Past G5
2009-06-01 21:37 . 2009-06-01 21:37 -------- d-----w- c:\program files\River Past
2009-06-01 21:35 . 2009-06-01 21:35 120240 ----a-w- c:\documents and settings\samer\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
2009-06-01 21:35 . 2009-06-03 02:17 -------- d-----w- c:\documents and settings\samer\Application Data\IDM
2009-06-01 21:35 . 2009-06-10 03:59 -------- d-----w- c:\documents and settings\samer\Application Data\DMCache
2009-06-01 21:35 . 2009-06-04 21:36 -------- d-----w- c:\program files\Internet Download Manager
2009-06-01 21:27 . 2009-06-05 22:12 -------- d-----w- c:\documents and settings\samer\Local Settings\Application Data\Adobe
2009-06-01 21:26 . 2009-06-01 21:26 -------- d-----w- c:\program files\Common Files\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-10 05:38 . 2008-06-01 20:30 2062624 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-10 05:38 . 2008-06-01 20:30 75552 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-10 04:58 . 2008-06-01 20:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-10 04:21 . 2008-06-01 20:30 31820 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-10 04:21 . 2008-06-01 20:30 10856 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-07 18:00 . 2008-06-01 18:15 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-06 19:46 . 2009-06-06 19:46 -------- d-----w- c:\program files\Instant Photo Artist 2
2009-06-06 00:12 . 2008-06-01 18:30 57104 ----a-w- c:\documents and settings\samer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-05 21:17 . 2008-06-01 18:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-03 08:17 . 2009-06-03 08:16 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-06-03 08:16 . 2009-06-03 08:16 -------- d-----w- c:\program files\Common Files\Nokia
2009-06-03 08:16 . 2009-06-03 08:16 -------- d-----w- c:\program files\Common Files\PCSuite
2009-06-03 08:16 . 2009-06-03 08:16 -------- d-----w- c:\program files\Nokia
2009-06-03 08:16 . 2009-06-03 08:16 -------- d-----w- c:\documents and settings\samer\Application Data\PC Suite
2009-06-03 08:16 . 2009-06-03 08:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-06-03 07:48 . 2008-06-01 19:29 -------- d-----w- c:\program files\Common Files\Real
2009-06-03 07:48 . 2008-06-01 19:29 -------- d-----w- c:\program files\Real
2009-06-01 20:49 . 2007-10-31 10:41 112144 ----a-w- c:\windows\system32\drivers\kl1.sys
2009-06-01 20:49 . 2009-06-01 20:49 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-06-01 20:49 . 2009-06-01 20:49 112144 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\X86\kl1.sys
2009-06-01 20:49 . 2009-06-01 20:49 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-06-01 20:49 . 2009-06-01 20:49 25104 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\ushata.dll
2009-06-01 20:49 . 2009-06-01 20:47 772624 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\updater.dll
2009-06-01 20:47 . 2009-06-01 20:47 150032 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\diffs.dll
2009-06-01 20:46 . 2009-06-01 20:46 354832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\ckahum.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-05-23 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-06-01 2610608]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\ypager.exe" [2005-08-19 3084288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-06 8523776]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-02-07 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 54832]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"D-Link AirPlus XtremeG"="c:\program files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [2006-06-16 1323008]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2006-06-01 49152]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-09-13 2595480]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-09-14 905056]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-09-13 140568]
"CloneCDElbyCDFL"="c:\program files\Elaborate Bytes\CloneCD\ElbyCheck.exe" [2002-11-02 45056]
"CloneCDTray"="c:\program files\Elaborate Bytes\CloneCD\CloneCDTray.exe" [2002-12-02 73728]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-03 180269]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-06 81920]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-11-06 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-11-14 16270848]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-05-23 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-6-1 389120]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [12/6/2007 10:03 PM 660768]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [5/11/2006 2:11 PM 472096]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [12/13/2007 2:28 PM 24592]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2008-06-01 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:53]
2008-06-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 14:57]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {D5877D03-B871-45F8-97E9-EF212E7F59F4} = 10.5.51.12 4.2.2.2
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-10 09:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\
000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1008)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(1064)
c:\windows\system32\relog_ap.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll
.
Completion time: 2009-06-10 9:40
ComboFix-quarantined-files.txt 2009-06-10 05:40
Pre-Run: 11,013,300,224 bytes free
Post-Run: 11,173,941,248 bytes free
184 --- E O F --- 2009-06-06 00:00