التقرير الأول من برنامج الكومبو فيكس وعلى فكرة لم يعمل ريستارت للجهاز
ComboFix 08-06-12.2 - Alftoh 06/15/2008 2:02:00.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.149 [GMT 3:00]
Running from: D:\Documents and Settings\Alftoh\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\WINDOWS\system32\MabryObj.dll
D:\WINDOWS\v10neformatic.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-14 to 2008-06-14 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-14 10:24 --------- d-----w D:\Program Files\AviSynth 2.5
2008-06-13 22:23 2,079 ----a-w D:\WINDOWS\system32\M1achardks.dll
2008-06-12 14:06 32 --sha-w D:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-12 14:06 32 --sha-w D:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-12 14:06 32 --sha-w D:\WINDOWS\system32\drivers\fidbox.idx
2008-06-12 14:06 32 --sha-w D:\WINDOWS\system32\drivers\fidbox.dat
2008-06-11 15:04 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\Nokia Multimedia Player
2008-06-09 20:14 0 ---ha-w D:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-09 20:14 0 ---ha-w D:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-06-09 20:07 --------- d-----w D:\Program Files\Common Files\PCSuite
2008-06-09 20:07 --------- d-----w D:\Program Files\Common Files\Nokia
2008-06-09 20:03 --------- d-----w D:\Program Files\PC Connectivity Solution
2008-06-06 13:35 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\LimeWire
2008-05-31 11:48 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\Media Player Classic
2008-05-29 20:14 --------- d-----w D:\Program Files\Cryptomathic
2008-05-29 18:11 88,774 ----a-w D:\WINDOWS\system32\drivers\klick.dat
2008-05-29 17:44 --------- d-----w D:\Documents and Settings\All Users\Application Data\TEMP
2008-05-28 23:23 96,966 ----a-w D:\WINDOWS\system32\drivers\klin.dat
2008-05-28 23:23 112,144 ----a-w D:\WINDOWS\system32\drivers\kl1.sys
2008-05-24 03:55 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\Thinstall
2008-05-23 13:03 --------- d-----w D:\Program Files\BuddyCheck
2008-05-23 13:03 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\Nuotex
2008-05-23 12:26 --------- d-----w D:\Program Files\Common Files\Ahead
2008-05-19 22:34 --------- d--h--w D:\Program Files\InstallShield Installation Information
2008-05-19 22:33 --------- d-----w D:\Program Files\Common Files\InstallShield
2008-05-18 00:02 --------- d-----w D:\Documents and Settings\All Users\Application Data\TechSmith
2008-05-17 13:36 4,608 ----a-w D:\WINDOWS\system32\w95inf32.dll
2008-05-17 13:36 2,272 ----a-w D:\WINDOWS\system32\w95inf16.dll
2008-05-17 08:55 --------- d-----w D:\Program Files\TelecomEgypt
2008-05-16 11:12 --------- d-----w D:\Program Files\ExtraTools
2008-05-12 22:21 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\IDM
2008-05-12 22:21 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\DMCache
2008-05-10 22:01 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\Gracebyte Software
2008-05-10 17:39 32 ----a-w D:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-05-10 17:39 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\skypePM
2008-05-10 17:03 160,107 ----a-w D:\WINDOWS\رفيق الأزواج Uninstaller.exe
2008-05-10 16:13 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\DAEMON Tools Pro
2008-05-10 15:14 4,100 ----a-w D:\WINDOWS\system32\hdvirffo.dll
2008-05-10 15:03 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\DAEMON Tools
2008-05-10 14:39 --------- d-----w D:\Program Files\Microsoft.NET
2008-05-10 14:39 --------- d-----w D:\Program Files\Microsoft ActiveSync
2008-05-10 14:39 --------- d-----w D:\Program Files\Common Files\L&H
2008-05-10 14:35 715,248 ----a-w D:\WINDOWS\system32\drivers\sptd.sys
2008-05-10 13:59 --------- d-----w D:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-05-10 13:52 --------- d-----w D:\Program Files\MessengerPlus! 3
2008-05-09 13:54 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\TuneUp Software
2008-05-09 13:53 --------- d-----w D:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-05-09 13:51 --------- d-----w D:\Program Files\Kaspersky Lab
2008-05-09 13:51 --------- d-----w D:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-09 13:50 --------- d-----w D:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-05-09 13:48 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\EditPlus 2
2008-05-09 13:46 --------- d-----w D:\Program Files\Java
2008-05-09 13:46 --------- d-----w D:\Program Files\Common Files\Java
2008-05-09 13:45 --------- d-----w D:\Program Files\Teletext
2008-05-09 13:44 --------- d-----w D:\Program Files\LifeView TVR
2008-05-09 13:39 --------- d-----w D:\Documents and Settings\All Users\Application Data\PC Suite
2008-05-09 13:39 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\Nokia
2008-05-09 13:37 --------- d-----w D:\Program Files\DIFX
2008-05-09 13:37 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\PC Suite
2008-05-09 13:35 --------- d-----w D:\Documents and Settings\All Users\Application Data\Installations
2008-05-09 13:35 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\Nero
2008-05-09 13:28 499,712 ----a-w D:\WINDOWS\system32\msvcp71.dll
2008-05-09 13:28 348,160 ----a-w D:\WINDOWS\system32\msvcr71.dll
2008-05-09 13:28 --------- d-----w D:\Program Files\Real
2008-05-09 13:28 --------- d-----w D:\Program Files\Common Files\xing shared
2008-05-09 13:28 --------- d-----w D:\Program Files\Common Files\Real
2008-05-09 13:26 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\WeatherWatcher
2008-05-09 13:21 --------- d-----w D:\Program Files\FilGoal.com
2008-05-09 13:21 --------- d-----w D:\Program Files\Conduit
2008-05-09 13:19 --------- d-----w D:\Program Files\Skype
2008-05-09 13:19 --------- d-----w D:\Program Files\Common Files\Skype
2008-05-09 13:19 --------- d-----w D:\Documents and Settings\All Users\Application Data\Yahoo!
2008-05-09 13:19 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\Skype
2008-05-09 13:18 --------- d-----w D:\Program Files\Yahoo!
2008-05-09 13:18 --------- d-----w D:\Documents and Settings\All Users\Application Data\Skype
2008-05-09 13:17 --------- d-----w D:\Program Files\MSN Messenger
2008-05-09 13:11 --------- d-----w D:\Program Files\Common Files\Wise Installation Wizard
2008-05-09 13:01 --------- d-----w D:\Documents and Settings\Alftoh\Application Data\Talkback
2008-04-14 02:55 1,804 ----a-w D:\WINDOWS\system32\Dcache.bin
2008-04-14 02:46 329,728 ----a-w D:\WINDOWS\system32\netsetup.exe
2008-04-14 02:43 92,424 ----a-w D:\WINDOWS\system32\rdpdd.dll
2008-04-14 02:43 87,176 ----a-w D:\WINDOWS\system32\rdpwsx.dll
2008-04-14 02:43 40,840 ----a-w D:\WINDOWS\system32\drivers\termdd.sys
2008-04-14 02:43 299,520 ----a-w D:\WINDOWS\system32\drmclien.dll
2008-04-14 02:43 299,520 ----a-w D:\WINDOWS\system32\dllcache\drmclien.dll
2008-04-14 02:43 21,896 ----a-w D:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-14 02:43 2,109,440 ----a-w D:\WINDOWS\system32\dllcache\wmvcore.dll
2008-04-14 02:43 139,656 ----a-w D:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-14 02:43 12,168 ----a-w D:\WINDOWS\system32\tsddd.dll
2008-04-14 02:43 12,040 ----a-w D:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-14 02:41 98,304 ----a-w D:\WINDOWS\system32\actxprxy.dll
2008-04-14 02:40 67,584 ----a-w D:\WINDOWS\system32\dllcache\pmigrate.dll
2008-04-14 02:40 53,760 ----a-w D:\WINDOWS\system32\dllcache\pintlcsd.dll
2008-04-14 02:40 53,279 ------w D:\WINDOWS\system32\odbcji32.dll
2008-04-14 02:40 4,126 ----a-w D:\WINDOWS\system32\msdxmlc.dll
2008-04-14 02:40 4,126 ----a-w D:\WINDOWS\system32\dllcache\msdxmlc.dll
2008-04-14 02:40 3,584 ----a-w D:\WINDOWS\system32\msafd.dll
2008-04-14 02:40 175,104 ----a-w D:\WINDOWS\system32\dllcache\pintlcsa.dll
2008-04-14 02:40 15,872 ----a-w D:\WINDOWS\system32\dllcache\padrs404.dll
2008-04-14 02:40 15,360 ----a-w D:\WINDOWS\system32\dllcache\padrs804.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{dae6f2e0-1d7b-4928-8a26-84e69271d804}]
03/13/2008 10:30 AM 1524248 --a------ D:\Program Files\FilGoal.com\tbFilG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{DAE6F2E0-1D7B-4928-8A26-84E69271D804}"= "D:\Program Files\FilGoal.com\tbFilG.dll" [03/13/2008 10:30 AM 1524248]
[HKEY_CLASSES_ROOT\clsid\{dae6f2e0-1d7b-4928-8a26-84e69271d804}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{DAE6F2E0-1D7B-4928-8A26-84E69271D804}"= D:\Program Files\FilGoal.com\tbFilG.dll [03/13/2008 10:30 AM 1524248]
[HKEY_CLASSES_ROOT\clsid\{dae6f2e0-1d7b-4928-8a26-84e69271d804}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MessengerPlus3"="D:\Program Files\MessengerPlus! 3\MsgPlus.exe" [05/10/2008 04:53 PM 190024]
"Nokia.PCSync"="G:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" [03/26/2008 06:41 PM 1232896]
"PC Suite Tray"="G:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [04/16/2008 12:53 PM 1079808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="D:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [09/01/2004 10:00 AM 208952]
"PHIME2002ASync"="D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [09/01/2004 10:00 AM 455168]
"PHIME2002A"="D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [09/01/2004 10:00 AM 455168]
"SunJavaUpdateSched"="D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [07/12/2007 04:00 AM 132496]
"TkBellExe"="D:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05/09/2008 04:28 PM 185896]
"MessengerPlus3"="D:\Program Files\MessengerPlus! 3\MsgPlus.exe" [05/10/2008 04:53 PM 190024]
"NeroFilterCheck"="D:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 10:50 AM 155648]
"RRT-Auto"="D:\Documents and Settings\Alftoh\Desktop\RRT.exe" [ ]
"SystemInit"="" []
"Karen"="" []
"raVe"="" []
"Win32BaseServiceMOD"="" []
"startIE"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"raVe"="" []
"Driver32"="" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 05:42 AM 15360]
D:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - G:\Program Files\MSI\Bluetooth Software\BTTray.exe [3/31/2004 5:13:32 PM 507965]
Microtek Scanner Finder.lnk - G:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe [3/24/2008 8:22:37 PM 335872]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
"NoFind"= 0 (0x0)
"NoRun"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=D:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
G:\Program Files\DAEMON Tools Pro\DTProAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DaemonTools_WhenUSave_Installer]
D:\Program Files\DaemonTools_WhenUSave_Installer\DaemonTools_WhenUSave_Installer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecSche]
--a------ 05/10/2004 05:34 AM 454656 D:\Program Files\LifeView TVR\RecSche.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ScanRegistry]
D:\W
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 02/01/2008 05:22 PM 21898024 D:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 10/02/2001 02:42 AM 10752 g:\Program Files\Winamp\Winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinDVRCtrl]
D:\WINDOWS\WDVRCtrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"G:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"G:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"D:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"G:\\النسخ الإحتياطية\\الهـــــامة\\Shear 5400\\السيرفرات العاملة\\waelbob\\ShareMax.exe"=
"G:\\النسخ الإحتياطية\\الهـــــامة\\Shear 5400\\السيرفرات العاملة\\hatch\\ShareMax.exe"=
"G:\\النسخ الإحتياطية\\الهـــــامة\\Shear 5400\\السيرفرات العاملة\\طبيب الحق\\ShareMax.exe"=
"D:\\Program Files\\Skype\\Phone\\Skype.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;D:\WINDOWS\system32\DRIVERS\klim5.sys [12/13/2007 01:28 PM]
*Newly Created Service* - CATCHME
.
s of the 'Scheduled Tasks' folder
"2008-06-06 14:15:04 D:\WINDOWS\Tasks\1-Click Maintenance.job"
- G:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-06-15 02:18:57
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\OMSCAN]
"ImagePath"="\Sys"
.
Completion time: 06/15/2008 2:22:22
ComboFix-quarantined-files.txt 2008-06-14 23:22:08
Pre-Run: 720,326,656 bytes free
Post-Run: 712,110,080 bytes free
237 --- E O F --- 2008-05-09 13:42:49