مع شكري وتقديري لك
ComboFix 09-07-09.08 - mgholnet 07/12/2009 1:39.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1025.18.1913.1446 [GMT 3:00]
Running from: D:\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\mgholnet\LOCALS~1\Temp\install_flash_player.exe
c:\documents and settings\mgholnet\Application Data\.#
c:\windows\Installer\36d540.msi
.
((((((((((((((((((((((((( Files Created from 2009-06-11 to 2009-07-11 )))))))))))))))))))))))))))))))
.
2009-07-11 21:46 . 2009-07-11 21:46 -------- d-----w- c:\documents and settings\All Users\MPlayer for Windows
2009-07-11 21:09 . 2009-07-11 22:11 -------- d-----w- c:\program files\MPlayer for Windows
2009-07-10 22:54 . 2009-07-10 22:54 -------- d-----w- c:\windows\Start Menu
2009-07-10 22:48 . 2001-09-19 12:00 229439 -c--a-w- c:\windows\system32\dllcache\multibox.dll
2009-07-10 22:47 . 2001-09-19 12:00 57856 -c--a-w- c:\windows\system32\dllcache\esuimgd.dll
2009-07-10 22:46 . 2003-03-24 13:52 20540 -c--a-w- c:\windows\system32\dllcache\admin.dll
2009-07-10 22:08 . 2001-09-19 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-07-10 22:08 . 2001-09-19 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2009-07-10 22:08 . 2001-09-19 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2009-07-10 22:08 . 2001-09-19 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2009-07-10 21:25 . 2009-07-10 21:25 -------- d-----w- c:\documents and settings\mgholnet\Application Data\AVS4YOU
2009-07-10 21:25 . 2009-07-10 21:25 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-07-10 21:24 . 2009-07-11 15:38 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-07-10 21:22 . 2008-08-13 08:22 974848 ----a-w- c:\windows\system32\mfc70.dll
2009-07-10 21:22 . 2008-08-13 08:22 487424 ----a-w- c:\windows\system32\msvcp70.dll
2009-07-10 21:22 . 2008-08-13 08:22 344064 ----a-w- c:\windows\system32\msvcr70.dll
2009-07-10 21:22 . 2009-07-11 15:39 -------- d-----w- c:\program files\AVS4YOU
2009-07-10 21:22 . 2008-08-13 08:22 24576 ----a-w- c:\windows\system32\msxml3a.dll
2009-07-10 19:11 . 2009-07-11 16:25 -------- d-----w- c:\documents and settings\mgholnet\Application Data\Desktopicon
2009-07-10 19:10 . 2009-07-10 19:10 -------- d-----w- c:\program files\FreeTime
2009-07-10 10:34 . 2009-07-11 15:20 95744 ----a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\Updates\Condition.dll
2009-07-09 18:10 . 2009-07-11 15:37 -------- d-----w- c:\documents and settings\mgholnet\Application Data\Any Video Converter
2009-07-09 18:10 . 2009-07-11 15:37 -------- d-----w- c:\program files\Any Video Converter
2009-07-09 17:06 . 2009-07-09 17:06 -------- d-----w- c:\documents and settings\mgholnet\Application Data\Toshiba
2009-07-08 15:39 . 2009-07-08 15:39 -------- d-----w- c:\windows\system32\wbem\Repository
2009-07-08 15:32 . 2009-07-08 15:50 -------- d-----w- c:\program files\Total Video Converter
2009-07-08 15:28 . 2009-07-08 15:39 -------- d-----w- c:\program files\Allok RM RMVB to AVI MPEG DVD Converter
2009-07-01 16:49 . 2009-07-01 16:49 -------- d-----w- c:\program files\Dict
2009-06-17 11:36 . 2009-07-10 11:31 -------- d-----w- C:\Star Defender 4
2009-06-15 18:33 . 2009-06-15 18:33 390664 ----a-w- c:\documents and settings\mgholnet\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-11 22:45 . 2009-03-29 20:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-07-11 22:44 . 2009-03-29 20:02 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-11 22:43 . 2009-03-29 20:11 5960 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-07-11 22:43 . 2009-03-29 20:11 507936 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-07-11 22:43 . 2009-03-29 20:11 2573344 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-11 22:43 . 2009-03-29 20:11 25376 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-11 21:57 . 2001-09-19 12:00 42164 ----a-w- c:\windows\system32\perfc001.dat
2009-07-11 21:57 . 2001-09-19 12:00 255974 ----a-w- c:\windows\system32\perfh001.dat
2009-07-11 15:41 . 2009-06-01 10:19 -------- d-----w- c:\program files\FairStars MP3 Recorder
2009-07-10 22:55 . 2009-03-29 19:10 484392 ----a-w- c:\documents and settings\mgholnet\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-10 22:43 . 2009-03-28 16:46 23380 ----a-w- c:\windows\system32\emptyregdb.dat
2009-07-10 11:43 . 2009-03-29 20:21 83456 ----a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2009-06-30 21:01 . 2009-03-29 19:54 -------- d-----w- c:\documents and settings\mgholnet\Application Data\BASELICENSESIZE
2009-06-30 21:01 . 2009-03-29 19:53 -------- d-----w- c:\program files\Cirle Developement
2009-06-01 10:27 . 2009-06-01 10:19 -------- d-----w- c:\documents and settings\mgholnet\Application Data\FairStars MP3 Recorder
2009-05-23 20:58 . 2009-05-23 20:58 -------- d-----w- c:\program files\Common Files\xing shared
2009-05-23 20:58 . 2009-03-28 17:10 -------- d-----w- c:\program files\Common Files\Real
2009-05-23 19:53 . 2009-03-29 20:12 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-23 19:53 . 2009-03-29 20:12 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-04-17 15:40 . 2009-04-17 15:40 0 ----a-w- c:\windows\nsreg.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2009-03-29 3134976]
"Google Update"="c:\documents and settings\mgholnet\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-24 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Toshiba Controls Utility"="c:\program files\TOSHIBA\Controls\VolumeIndicator.exe" [2008-02-01 77824]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-09-09 1024000]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2008-04-29 417792]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2008-12-19 83336]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-03-29 206088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-23 198160]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-09-09 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-09-09 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-09-09 141848]
"MPlayerForWindows_UpdateReminder"="c:\program files\MPlayer for Windows\AutoUpdate.exe" [2009-06-12 80224]
"NDSTray.exe"="NDSTray.exe" [BU]
"CFSServ.exe"="CFSServ.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 1634304]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^????? ????^???????^??? ???????^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\????? ????\???????\??? ???????\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-03-29 33808]
S3 CnxtHdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDAud.sys [2008-09-09 732160]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2008-09-09 110080]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
S3 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [2008-09-09 51160]
S3 QIOMem;Generic IO & Memory Access;c:\windows\system32\DRIVERS\QIOMem.sys [2007-05-29 6912]
.
Contents of the 'Scheduled Tasks' folder
2009-07-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-796845957-790525478-725345543-1003Core.job
- c:\documents and settings\mgholnet\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-24 21:41]
2009-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-796845957-790525478-725345543-1003UA.job
- c:\documents and settings\mgholnet\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-24 21:41]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: ????? ??? ???? ????? ?????? - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: ?&???? ??? Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-12 01:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2320)
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\PC Connectivity Solution\ConnAPI.DLL
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe
c:\program files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\program files\O2Micro Flash Memory Card Driver\o2flash.exe
c:\program files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-11 1:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-11 22:46
Pre-Run: 17,195,061,248 bytes free
Post-Run: 20,266,860,544 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
180