هلا بذيب الليل
تفضل
ComboFix 08-03-14.4 - user 2008-03-15 10:14:46.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.566 [GMT -7:00]
Running from: C:\Documents and Settings\user\Desktop\down loud\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\kakle.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-15 to 2008-03-15 )))))))))))))))))))))))))))))))
.
2008-03-15 08:57 . 2008-03-15 09:07 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-03-15 05:01 . 2008-03-15 05:07 749 --a------ C:\is.html
2008-03-15 02:45 . 2008-03-15 02:45 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-03-15 02:45 . 2008-03-15 10:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-15 02:45 . 2008-03-15 10:20 3,834,912 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-15 02:45 . 2008-03-15 10:20 110,624 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-03-15 02:45 . 2008-03-15 02:45 91,700 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-03-15 02:45 . 2008-03-15 02:45 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-03-15 02:45 . 2008-03-15 10:20 56,156 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-15 02:45 . 2008-03-15 10:20 11,108 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-03-14 12:48 . 2008-03-14 12:48 <DIR> d-------- C:\Program Files\Webroot
2008-03-14 12:48 . 2008-03-14 12:48 <DIR> d-------- C:\Program Files\Common Files\Webroot Shared
2008-03-14 12:48 . 2008-03-14 12:48 <DIR> d-------- C:\Documents and Settings\user\Application Data\Webroot
2008-03-14 12:38 . 2005-04-20 10:34 487,936 --a------ C:\WINDOWS\system32\wwSecure.exe
2008-03-14 12:38 . 2005-04-18 13:49 57,344 --a------ C:\WINDOWS\Unwash6.exe
2008-03-14 00:15 . 2008-03-14 00:15 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-03-14 00:13 . 2008-03-14 00:13 <DIR> d-------- C:\WINDOWS\system32\URTTEMP
2008-03-13 19:00 . 2008-03-13 19:00 <DIR> d-------- C:\WINDOWS\naevius_yt_1
2008-03-13 19:00 . 2008-03-13 19:26 <DIR> d-------- C:\Program Files\Naevius YouTube Converter
2008-03-13 19:00 . 2008-03-13 19:25 <DIR> d-------- C:\naevius_temp_folder
2008-03-13 18:00 . 2008-03-13 18:00 <DIR> d-------- C:\VProRecovery
2008-03-13 16:10 . 2008-03-13 17:59 <DIR> d-------- C:\WINDOWS\KingoOo
2008-03-13 16:10 . 2008-03-13 16:10 <DIR> d-------- C:\Program Files\System
2008-03-13 16:10 . 2004-07-29 12:56 208,896 --a------ C:\WINDOWS\system32\cttune.cpl
2008-03-13 16:10 . 2004-09-30 11:17 122,880 --a------ C:\WINDOWS\system32\directx.cpl
2008-03-13 16:10 . 2002-12-29 01:14 110,592 --a------ C:\WINDOWS\system32\Startup.cpl
2008-03-13 13:55 . 2008-03-13 17:59 <DIR> d-------- C:\Program Files\Kasparov Chessmate
2008-03-13 13:54 . 2008-03-13 14:04 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-03-13 11:44 . 2008-03-13 11:44 <DIR> d-------- C:\Program Files\Ashampoo
2008-03-11 20:46 . 2008-03-11 20:48 <DIR> d-------- C:\Documents and Settings\user\Application Data\IDM
2008-03-11 20:45 . 2008-03-14 09:34 <DIR> d-------- C:\Program Files\Internet Download Manager
2008-03-10 19:38 . 2008-03-10 20:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-03-10 10:13 . 2008-03-10 10:13 <DIR> d-------- C:\Program Files\eq show bows
2008-03-10 10:13 . 2008-03-10 10:13 <DIR> d-------- C:\Documents and Settings\user\Application Data\eq show bows
2008-03-10 10:09 . 2008-03-10 10:09 <DIR> d-------- C:\Program Files\Messenger Plus! Live
2008-03-10 10:09 . 2008-03-10 10:09 <DIR> d-------- C:\Program Files\Circle Developement
2008-03-09 21:19 . 2008-03-09 21:19 <DIR> d-------- C:\Documents and Settings\user\Application Data\vlc
2008-03-09 16:58 . 2008-03-09 16:58 0 --a------ C:\WINDOWS\nsreg.dat
2008-03-09 15:57 . 2008-03-09 15:57 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-03-09 07:23 . 2008-03-09 07:23 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-03-09 02:34 . 2008-03-09 22:24 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-09 02:23 . 2008-03-09 02:23 <DIR> d-------- C:\Program Files\RegDoctor
2008-03-09 02:23 . 2005-02-12 16:43 245,760 --a------ C:\WINDOWS\system32\vbalColumnTreeView6.ocx
2008-03-09 02:23 . 1999-08-02 17:11 57,344 --a------ C:\WINDOWS\system32\CGZipLibrary.DLL
2008-03-09 02:23 . 2003-01-26 14:41 40,960 --a------ C:\WINDOWS\system32\SSubTmr6.dll
2008-03-09 02:23 . 1999-03-12 02:20 18,728 --a------ C:\WINDOWS\system32\ISHF_Ex.tlb
2008-03-09 02:23 . 1998-03-18 17:45 8,096 --a------ C:\WINDOWS\system32\OLEGUIDS.TLB
2008-03-09 01:43 . 2008-03-09 01:43 <DIR> d-------- C:\Documents and Settings\user\Application Data\Media Player Classic
2008-03-09 00:36 . 2008-03-09 00:36 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-03-08 23:28 . 2008-03-15 03:00 <DIR> d-------- C:\Program Files\Common Files\delet
2008-03-08 23:05 . 2008-03-09 00:03 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-08 23:05 . 2008-03-08 23:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-08 15:39 . 2008-03-08 15:39 <DIR> d-------- C:\Documents and Settings\user\Bluetooth Software
2008-03-08 02:52 . 2008-03-14 00:43 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-03-08 02:04 . 2007-07-30 20:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-03-08 01:59 . 2008-03-08 15:51 <DIR> d-------- C:\Documents and Settings\user\Contacts
2008-03-08 01:48 . 2001-08-17 14:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-03-08 01:48 . 2001-08-17 14:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-03-08 01:48 . 2007-10-30 19:47 10,368 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-03-08 01:48 . 2007-10-30 19:47 10,368 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-03-07 22:43 . 2008-03-07 22:43 <DIR> d-------- C:\Program Files\PowerQuest
2008-03-07 22:32 . 2008-03-15 02:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-03-07 21:59 . 2008-03-07 21:59 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2008-03-07 21:59 . 2008-03-07 21:59 <DIR> d-------- C:\Program Files\QuickTime
2008-03-07 21:59 . 2008-03-07 21:59 <DIR> d-------- C:\Program Files\iTunes
2008-03-07 21:59 . 2008-03-07 21:59 <DIR> d-------- C:\Program Files\iPod
2008-03-07 21:59 . 2008-03-07 21:59 <DIR> d-------- C:\Documents and Settings\user\Application Data\Apple Computer
2008-03-07 21:59 . 2008-03-14 00:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2008-03-07 21:59 . 2008-03-07 21:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-07 21:59 . 1999-11-10 13:05 86,016 --a------ C:\WINDOWS\unvise32qt.exe
2008-03-07 21:58 . 2008-03-07 21:58 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-03-07 21:50 . 2008-03-15 10:22 <DIR> d-------- C:\Documents and Settings\user\Application Data\DMCache
2008-03-07 21:49 . 2008-03-07 21:49 <DIR> d-------- C:\WINDOWS\system32\ar-sa
2008-03-07 21:23 . 2008-03-13 22:08 <DIR> d-------- C:\Program Files\Windows Live
2008-03-07 21:22 . 2008-03-07 21:22 <DIR> d-------- C:\WINDOWS\PaltalkScene
2008-03-07 21:22 . 2008-03-08 01:56 <DIR> d-------- C:\Program Files\Paltalk Messenger
2008-03-07 21:22 . 2008-03-08 01:56 <DIR> d-------- C:\Documents and Settings\user\Application Data\Paltalk
2008-03-07 21:18 . 2008-03-07 22:02 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-03-07 21:18 . 2008-03-07 21:18 2,535,424 --a------ C:\WINDOWS\system32\agsaamj.dll
2008-03-07 21:18 . 2008-03-07 21:18 1,986,560 --a------ C:\WINDOWS\system32\akll.dll
2008-03-07 21:18 . 2008-03-07 21:18 1,245,184 --a------ C:\WINDOWS\system32\bkll.dll
2008-03-07 21:18 . 2008-03-07 21:18 1,212,416 --a------ C:\WINDOWS\system32\ckll.dll
2008-03-07 21:18 . 2008-03-07 21:18 610,304 --a------ C:\WINDOWS\system32\agsaamg.dll
2008-03-07 21:18 . 2008-03-07 21:18 372,736 --a------ C:\WINDOWS\system32\agsaamc.dll
2008-03-07 21:18 . 2008-03-07 21:18 196,608 --a------ C:\WINDOWS\system32\maag.dll
2008-03-07 21:18 . 2008-03-07 21:18 90,112 --a------ C:\WINDOWS\system32\agsaami.dll
2008-03-07 21:18 . 2008-03-07 21:18 53,760 --a------ C:\WINDOWS\system\ppacklib.dll
2008-03-07 21:17 . 2008-03-07 21:18 <DIR> d-------- C:\WINDOWS\system32\RMBin
2008-03-07 21:17 . 2008-03-07 21:18 <DIR> d-------- C:\Program Files\Real_SC
2008-03-07 21:16 . 2008-03-07 21:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-03-07 21:15 . 2008-03-07 21:16 <DIR> d-------- C:\Program Files\CyberLink
2008-03-07 21:15 . 2001-03-08 19:30 24,064 --------- C:\WINDOWS\system32\msxml3a.dll
2008-03-07 21:14 . 2008-03-07 21:14 <DIR> d-------- C:\Program Files\Real
2008-03-07 21:14 . 2008-03-09 07:21 <DIR> d-------- C:\Program Files\Common Files\Real
2008-03-07 21:13 . 2008-03-07 21:13 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-03-07 21:12 . 2008-03-07 21:12 <DIR> d-------- C:\Program Files\mpegable
2008-03-07 21:12 . 2008-03-07 21:12 47,104 --------- C:\WINDOWS\AKDeInstall.exe
2008-03-07 20:57 . 2004-11-15 21:06 3,222,784 -ra------ C:\WINDOWS\system32\drivers\w29n51.sys
2008-03-07 20:57 . 2004-11-15 21:06 458,752 -ra------ C:\WINDOWS\system32\w29NCPA.dll
2008-03-07 20:56 . 2008-03-07 20:56 <DIR> d-------- C:\Documents and Settings\user\Application Data\Symantec
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-08 04:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-08 03:48 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-08 03:40 155,995 ----a-w C:\WINDOWS\java\Packages\WQJ1ZXR1.ZIP
2008-03-08 00:56 --------- d-----w C:\Program Files\Intel
2008-03-08 00:42 --------- d-----w C:\Program Files\microsoft frontpage
2008-03-08 00:35 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-02-01 18:17 586,240 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-01-08 12:13 202,160 -c--a-w C:\WINDOWS\system32\idmmbc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-10-31 01:32 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 19:05 143360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-03-11 20:49 2577840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2007-07-22 04:14 61952 C:\WINDOWS\system32\HDAShCut.exe]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-07 20:02 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-07 19:59 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-06-07 20:03 114688]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 04:51 53248]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 08:00 33648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 23:57 30208]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 12:09 49152]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-09 07:20 185896]
"AntiSpyWare2Guard"="C:\Program Files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWare2Guard.exe" [2007-08-14 08:29 2334040]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2008-02-27 20:04 199184]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2007-10-31 01:32 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="regsvr32 /s /n /i:u l32" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R2 AASW2_Service;Ashampoo AntiSpyWare 2 Service;C:\Program Files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWareService.exe [2007-08-14 08:28]
R3 genmcmnUSB;USB Scroll Mouse Driver;C:\WINDOWS\system32\DRIVERS\gflmouhid.sys [2003-08-07 16:42]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-03-15 10:22:36
Windows 5.1.2600 Service Pack 3, v.3244 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\wwSecure.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-03-15 10:25:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-15 17:24:52