شكرا لك اخي زيزووم وشسويلة بعد و جميع الاعضاء للتفاعل
على العموم هذي التقرير
ComboFix 08-03-30.1 - bajaman 03/30/2008 13:08:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.551 [GMT 3:00]
Running from: C:\Documents and Settings\------\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
/wow section - STAGE 41
يتعذر على العملية الوصول إلى الملف لأنه قيد الاستخدام من قبل عملية أخرى.
يتعذر على العملية الوصول إلى الملف لأنه قيد الاستخدام من قبل عملية أخرى.
يتعذر على العملية الوصول إلى الملف لأنه قيد الاستخدام من قبل عملية أخرى.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-30 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-30 10:31 6,048,032 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-30 10:29 165,408 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-03-30 10:12 22,820 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-03-30 10:12 109,148 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-30 09:52 --------- d-----w C:\Documents and Settings\bajaman\Application Data\DMCache
2008-03-29 22:44 --------- d-----w C:\Program Files\CEDP Stealer 6.0 for Messenger
2008-03-29 16:14 --------- d-----w C:\Documents and Settings\bajaman\Application Data\IDM
2008-03-29 11:41 --------- d-----w C:\Program Files\VIA
2008-03-28 17:30 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-28 17:30 --------- d-----w C:\Program Files\Stellar Phoenix Recovery Suite
2008-03-28 17:23 --------- d-----w C:\Program Files\GetData
2008-03-28 00:52 --------- d-----w C:\Documents and Settings\bajaman\Application Data\rule soft load
2008-03-28 00:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\aim rect help creative
2008-03-28 00:51 --------- d-----w C:\Program Files\rule soft load
2008-03-28 00:50 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-03-27 23:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-03-27 23:32 --------- d-----w C:\Program Files\Circle Developement
2008-03-27 22:26 --------- d-----w C:\Program Files\ma-config.com
2008-03-27 22:26 --------- d-----w C:\Documents and Settings\bajaman\Application Data\ma-config.com
2008-03-27 22:19 --------- d-----w C:\Program Files\Common Files\SWF Studio
2008-03-27 22:18 --------- d-----w C:\Program Files\GDivX Zenith Player
2008-03-27 21:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-26 21:40 23,600 ----a-w C:\WINDOWS\system32\drivers\TVICHW32.SYS
2008-03-26 12:25 --------- d-----w C:\Program Files\S3
2008-03-26 12:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-26 12:09 --------- d-----w C:\Program Files\IDETOOL
2008-03-26 05:55 --------- d-----w C:\Program Files\Common Files\delet
2008-03-25 15:08 --------- d-----w C:\Program Files\Windows Live
2008-03-25 15:07 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-03-25 14:33 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-25 13:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\WindowsLiveInstaller
2008-03-23 20:27 --------- d-----w C:\Documents and Settings\bajaman\Application Data\MiniDm
2008-03-23 20:01 --------- d-----w C:\Program Files\ooVoo
2008-03-23 19:21 --------- d-----w C:\Documents and Settings\bajaman\Application Data\ooVoo Details
2008-03-23 07:10 --------- d-----w C:\Program Files\Google
2008-03-22 23:23 --------- d-----w C:\Documents and Settings\bajaman\Application Data\IEPro
2008-03-22 23:22 --------- d-----w C:\Program Files\IEPro
2008-03-22 23:17 --------- d-----w C:\Program Files\Common Files\xing shared
2008-03-22 23:16 --------- d-----w C:\Program Files\Common Files\Real
2008-03-22 17:54 --------- d-----w C:\Documents and Settings\bajaman\Application Data\Media Player Classic
2008-03-22 17:44 --------- d-----w C:\Program Files\Free RM to MP3 Converter
2008-03-22 17:38 --------- d-----w C:\Program Files\Streambox
2008-03-22 17:31 --------- d-----w C:\Documents and Settings\bajaman\Application Data\AccurateRip
2008-03-22 17:29 --------- d-----w C:\Program Files\Real Alternative
2008-03-22 17:26 426,872 ----a-w C:\WINDOWS\system32\SpoonUninstall.exe
2008-03-22 17:25 --------- d-----w C:\Program Files\Illustrate
2008-03-22 17:00 --------- d-----w C:\Program Files\FOX Video Converter
2008-03-22 16:59 81,920 ----a-w C:\Documents and Settings\bajaman\Application Data\ezpinst.exe
2008-03-22 16:59 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-03-22 16:59 47,360 ----a-w C:\Documents and Settings\bajaman\Application Data\pcouffin.sys
2008-03-22 16:59 --------- d-----w C:\Documents and Settings\bajaman\Application Data\Vso
2008-03-22 16:42 --------- d-----w C:\Program Files\Xilisoft
2008-03-22 15:30 344,064 ----a-w C:\WINDOWS\system32\dkll.dll
2008-03-22 15:30 196,608 ----a-w C:\WINDOWS\system32\maag.dll
2008-03-22 15:30 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-03-22 15:30 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2008-03-22 15:30 --------- d-----w C:\Program Files\Ozone
2008-03-22 11:59 --------- d-----w C:\Documents and Settings\bajaman\Application Data\Thinstall
2008-03-22 11:14 --------- d-----w C:\Documents and Settings\bajaman\Application Data\Ahead
2008-03-22 11:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-03-22 11:01 --------- d-----w C:\Program Files\Common Files\Ahead
2008-03-22 10:57 --------- d-----w C:\Program Files\Nero
2008-03-22 10:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-03-22 05:38 --------- d-----w C:\Documents and Settings\bajaman\Application Data\DivX
2008-03-22 04:49 --------- d-----w C:\Documents and Settings\bajaman\Application Data\vlc
2008-03-21 23:42 --------- d-----w C:\Program Files\Kaspersky Lab
2008-03-21 23:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-21 22:33 --------- d-----w C:\Program Files\Internet Download Manager
2008-03-21 21:31 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-03-21 21:31 172,032 ------w C:\WINDOWS\Setup1.exe
2008-03-21 21:31 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-03-21 21:30 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-21 21:29 --------- d-----w C:\Program Files\DIFX
2008-03-21 21:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-03-21 21:28 --------- d-----w C:\Program Files\Nokia
2008-03-21 21:28 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-03-21 21:28 --------- d-----w C:\Program Files\Common Files\Nokia
2008-03-21 21:28 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-21 21:28 --------- d-----w C:\Documents and Settings\bajaman\Application Data\PC Suite
2008-03-21 21:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-21 21:08 --------- d-----w C:\Program Files\MSBuild
2008-03-21 21:08 --------- d-----w C:\Program Files\Microsoft Works
2008-03-21 21:07 --------- d-----w C:\Program Files\Microsoft.NET
2008-03-21 21:05 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-03-21 20:56 --------- d-----w C:\Program Files\DivX
2008-03-21 20:56 --------- d-----w C:\Documents and Settings\bajaman\Application Data\Talkback
2008-03-21 20:37 --------- d-----w C:\Program Files\easySms
2008-03-21 20:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-03-21 20:36 --------- d-----w C:\Program Files\iTunes
2008-03-21 20:36 --------- d-----w C:\Program Files\iPod
2008-03-21 20:36 --------- d-----w C:\Documents and Settings\bajaman\Application Data\Apple Computer
2008-03-21 20:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-21 20:35 --------- d-----w C:\Program Files\QuickTime
2008-03-21 20:35 --------- d-----w C:\Program Files\Common Files\Apple
2008-03-21 20:35 --------- d-----w C:\Program Files\Apple Software Update
2008-03-21 20:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-03-21 20:34 --------- d-----w C:\Program Files\The KMPlayer
2008-03-21 20:33 --------- d-----w C:\Program Files\Riva
2008-03-21 20:32 --------- d-----w C:\Program Files\VideoLAN
2008-03-21 20:32 --------- d-----w C:\Program Files\Paltalk Messenger
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [07/27/2007 05:56 PM 2536880]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [06/27/2006 04:21 PM 1449984]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [10/18/2007 11:34 AM 5724184]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [08/30/2007 05:43 PM 4670704]
"ooVoo.exe"="C:\Program Files\ooVoo\ooVoo.exe" [03/20/2008 04:18 PM 12408624]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"Internet more"="C:\DOCUME~1\bajaman\APPLIC~1\RULESO~1\Byte Bows Dash.exe" [03/28/2008 03:51 AM 410112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [06/29/2007 06:24 AM 286720]
"iTune****per"="C:\Program Files\iTunes\iTune****per.exe" [09/26/2007 02:42 PM 267064]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [08/09/2004 06:03 AM 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [08/09/2004 06:03 AM 81920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 03:06 AM 40048]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM 31016]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [06/15/2006 12:36 PM 229376]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [11/08/2006 06:28 PM 155751]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [03/01/2007 03:57 PM 153136]
"SecurDisc"="C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [05/15/2007 03:55 PM 1628208]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [05/15/2007 03:55 PM 1057328]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [03/23/2008 02:15 AM 185896]
"MsgCenterExe"="C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" [03/23/2008 02:15 AM 69632]
"VTTimer"="VTTimer.exe" [12/20/2007 05:05 PM 77824 C:\WINDOWS\system32\VTTimer.exe]
"S3Trayp"="S3trayp.exe" [09/30/2007 03:50 PM 200704 C:\WINDOWS\system32\S3Trayp.exe]
"Help Creative Meow City"="C:\Documents and Settings\All Users\Application Data\aim rect help creative\Second bits.exe" [03/30/2008 01:32 PM 476160]
"HDAudDeck"="C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe" [02/01/2007 06:30 PM 778240]
"zyz1"="c:\zyz_auto_killer\run2.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 01:56 AM 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuMorePrograms"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 10/03/2007 05:42 PM 21260584 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 08/30/2007 05:43 PM 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\IEPro\\MiniDM.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP

oVoo TCP المنفذ 443
"443:UDP"= 443:UDP

oVoo UDP المنفذ 443
"37674:TCP"= 37674:TCP

oVoo TCP المنفذ 37674
"37674:UDP"= 37674:UDP

oVoo UDP المنفذ 37674
"37675:UDP"= 37675:UDP

oVoo UDP المنفذ 37675
R0 viadsk;viadsk;C:\WINDOWS\system32\DRIVERS\viadsk.sys [06/19/2003 06:00 PM]
R0 ViBus;ViBus;C:\WINDOWS\system32\DRIVERS\ViBus.sys [12/07/2007 11:13 AM]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [09/21/2007 05:49 PM]
R0 ViPrt;VIA SATA IDE Device Driver;C:\WINDOWS\system32\DRIVERS\ViPrt.sys [12/07/2007 11:10 AM]
R3 S3GIGP;S3GIGP;C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [02/18/2008 05:47 PM]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\WINDOWS\system32\drivers\viahduaa.sys [01/16/2007 09:15 AM]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-03-30 13:31:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 03/30/2008 13:34:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-30 10:34:22
Pre-Run: 21,493,035,008 bytes free
Post-Run: 21,347,696,640 bytes free
اتمنى تلاقي لي حل لانو الهاردسك بية شقى عمر والله
وشاكر لك مرة اخرى