ابو ريما شكرا لتواصلك
حملت الاداة وسويت مثل ماقلت وهذا هو التقرير
ComboFix 09-06-13.09 - Administrator 06/14/2009 10:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.1535.1013 [GMT 3:00]
Running from: d:\برامج2\برنامج الاعصار قاتل التروجان والفيروسات\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\msconfig.exe
.
((((((((((((((((((((((((( Files Created from 2009-05-14 to 2009-06-14 )))))))))))))))))))))))))))))))
.
2009-06-13 14:41 . 2009-06-14 07:36 11264544 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-13 14:41 . 2009-06-14 07:36 17696 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-10 09:01 . 2009-04-30 21:13 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-06-10 09:01 . 2009-04-30 21:13 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-09 21:23 . 2009-06-09 21:23 0 ----a-w- C:\osy3.sys
2009-06-08 22:50 . 2009-06-08 22:50 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-06-08 20:46 . 2009-06-08 20:46 -------- d-----w- c:\program files\Lavasoft
2009-06-04 08:12 . 2009-06-04 08:12 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-06-04 08:12 . 2009-06-04 08:12 -------- d-sh--w- c:\documents and settings\Administrator\IECompatCache
2009-06-04 08:07 . 2009-06-04 08:07 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-06-04 07:59 . 2009-06-04 07:59 -------- d-----w- c:\windows\ie8updates
2009-06-04 07:58 . 2009-05-12 05:11 102912 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-06-04 07:55 . 2009-06-04 07:58 -------- dc-h--w- c:\windows\ie8
2009-05-30 06:19 . 2009-05-30 06:19 -------- d-----w- c:\documents and settings\Administrator\Application Data\URSoft
2009-05-30 06:19 . 2009-06-14 07:32 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-30 06:19 . 2009-05-30 06:19 -------- d-----w- c:\program files\Your Uninstaller 2008
2009-05-29 19:32 . 2009-05-29 19:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Ashampoo
2009-05-29 19:29 . 2009-05-29 19:29 -------- d-----w- c:\program files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-13 23:33 . 2001-09-19 12:00 39670 ----a-w- c:\windows\system32\perfc001.dat
2009-06-13 23:33 . 2001-09-19 12:00 251606 ----a-w- c:\windows\system32\perfh001.dat
2009-06-13 23:29 . 2009-02-06 19:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-13 22:26 . 2009-06-13 15:11 -------- d-----w- c:\program files\Spyware Doctor
2009-06-13 22:24 . 2009-06-13 14:41 2936 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-13 22:24 . 2009-06-13 14:41 172916 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-13 16:31 . 2008-06-02 12:19 66952 ----a-w- c:\windows\system32\drivers\iksysflt.sys
2009-06-13 16:30 . 2008-06-10 18:22 81288 ----a-w- c:\windows\system32\drivers\iksyssec.sys
2009-06-13 16:30 . 2008-06-02 12:19 40840 ----a-w- c:\windows\system32\drivers\ikfilesec.sys
2009-06-13 15:40 . 2007-10-31 10:41 112144 ----a-w- c:\windows\system32\drivers\kl1.sys
2009-06-13 15:40 . 2009-06-13 14:42 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-06-13 15:40 . 2009-06-13 14:42 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-06-13 15:40 . 2009-06-13 15:40 112144 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\X86\kl1.sys
2009-06-13 15:39 . 2009-06-13 15:39 25104 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\ushata.dll
2009-06-13 15:39 . 2009-06-13 15:38 772624 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\updater.dll
2009-06-13 15:37 . 2009-06-13 15:37 150032 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\diffs.dll
2009-06-13 15:37 . 2009-06-13 15:36 354832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.1.321\ckahum.dll
2009-06-13 15:11 . 2009-06-13 15:11 -------- d-----w- c:\program files\Common Files\PC Tools
2009-06-13 14:41 . 2009-02-06 19:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-06-13 14:37 . 2009-02-06 19:22 -------- d-----w- c:\program files\Kaspersky Lab
2009-06-08 20:47 . 2009-02-06 23:23 -------- d-----w- c:\documents and settings\Administrator\Application Data\Lavasoft
2009-06-06 15:49 . 2009-02-07 06:17 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-02 08:09 . 2009-02-07 05:36 -------- d-----w- c:\documents and settings\Administrator\Application Data\HPAppData
2009-05-30 06:24 . 2009-02-06 22:37 89512 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-29 15:59 . 2009-02-09 22:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-05-29 02:36 . 2009-02-25 10:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\cleaner
2009-05-26 07:04 . 2009-02-07 06:15 -------- d-----w- c:\documents and settings\All Users\Application Data\WLInstaller
2009-05-13 05:02 . 2008-04-07 18:47 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2004-08-03 22:55 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-30 09:39 . 2009-03-31 06:53 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-04-19 19:47 . 2004-08-03 22:46 1847040 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:52 . 2004-08-03 22:55 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Vista Rainbar"="c:\program files\Vista Rainbar\Rainmeter.exe" [2006-01-21 118784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DrvIcon"="c:\windows\VistaDrives\DrvIcon.exe" [2007-07-04 45056]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^قائمة ابدأ^البرامج^بدء التشغيل^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Administrator\قائمة ابدأ\البرامج\بدء التشغيل\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^قائمة ابدأ^البرامج^بدء التشغيل^RocketDock.lnk]
path=c:\documents and settings\Administrator\قائمة ابدأ\البرامج\بدء التشغيل\RocketDock.lnk
backup=c:\windows\pss\RocketDock.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\ooVoo\\ooVoo.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.321\\English\\setup.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\English\\setup.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:*

isabled

oVoo TCP المنفذ 443
"443:UDP"= 443:UDP:*

isabled

oVoo UDP المنفذ 443
"37674:TCP"= 37674:TCP:*

isabled

oVoo TCP المنفذ 37674
"37674:UDP"= 37674:UDP:*

isabled

oVoo UDP المنفذ 37674
"37675:UDP"= 37675:UDP:*

isabled

oVoo UDP المنفذ 37675
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13/12/2007 01:28 م 24592]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [17/02/2009 07:32 م 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [17/02/2009 07:32 م 8320]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [13/06/2008 03:29 م 356920]
S3 VF0470Vid;Live! Cam Notebook (VF0470);c:\windows\system32\drivers\V0470Vid.sys [08/02/2009 10:12 م 146368]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - IKFILESEC
*NewlyCreated* - IKSYSFLT
*NewlyCreated* - IKSYSSEC
*NewlyCreated* - MCHINJDRV
*NewlyCreated* - SDAUXSERVICE
*NewlyCreated* - SDCORESERVICE
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-14 c:\windows\Tasks\User_Feed_Synchronization-{5BFF9DE4-DB04-4A28-9430-1B69F682441A}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 01:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uInternet Settings,ProxyServer = proxy.jeel.com:8080
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-14 10:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-73586283-1078145449-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,0c,9b,3a,8e,ba,b2,9d,4e,ad,25,ea,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,0c,9b,3a,8e,ba,b2,9d,4e,ad,25,ea,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1204)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(1260)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll
.
Completion time: 2009-06-14 10:38
ComboFix-quarantined-files.txt 2009-06-14 07:38
Pre-Run: 13,081,366,528 bytes free
Post-Run: 13,570,211,840 bytes free
188 --- E O F --- 2009-06-12 15:50