وهذا التقرير
ComboFix 09-07-29.04 - tom 07/31/2009 18:39.1.2 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.502.347 [GMT 3:00]
Running from: c:\documents and settings\tom\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\mdm.exe
c:\windows\system32\winio.vxd
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-31 )))))))))))))))))))))))))))))))
.
2009-07-30 23:26 . 2009-07-30 23:26 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-07-29 22:21 . 2009-07-29 22:21 -------- d-----w- c:\program files\Trend Micro
2009-07-27 02:58 . 2009-07-27 02:58 -------- d-----w- c:\documents and settings\tom\Application Data\QuickScan
2009-07-26 21:41 . 2009-07-26 23:16 -------- d-----w- c:\documents and settings\tom\Application Data\SWiSH Max2
2009-07-26 21:38 . 2009-07-26 21:38 -------- d-----w- c:\program files\LameACM
2009-07-26 21:38 . 2009-07-26 21:38 -------- d-----w- c:\program files\Common Files\SWiSHzone.com
2009-07-26 21:38 . 2009-07-26 21:40 -------- d-----w- c:\program files\SWiSH Max2
2009-07-26 14:37 . 2009-07-26 14:37 -------- d-----w- c:\program files\SWiSHE.NET
2009-07-22 07:02 . 2009-07-31 01:31 -------- d-sh--r- c:\windows\system32\Net
2009-07-16 11:48 . 2009-07-16 11:48 -------- d-sh--w- c:\documents and settings\tom\IECompatCache
2009-07-16 11:45 . 2009-07-16 11:45 -------- d-sh--w- c:\documents and settings\tom\PrivacIE
2009-07-16 11:41 . 2009-07-16 11:41 -------- d-sh--w- c:\documents and settings\tom\IETldCache
2009-07-16 11:34 . 2009-06-02 10:12 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-07-16 11:33 . 2009-07-29 00:01 -------- d-----w- c:\windows\ie8updates
2009-07-16 11:32 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-07-16 11:32 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-16 11:27 . 2009-07-16 11:32 -------- dc-h--w- c:\windows\ie8
2009-07-05 05:01 . 2009-07-05 05:01 -------- d-----w- c:\program files\Topaz Labs
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-31 00:48 . 2007-03-15 19:08 -------- d-----w- c:\program files\Real_SC
2009-07-31 00:34 . 2008-04-10 07:10 -------- d-----w- c:\program files\Circle Developement
2009-07-30 02:58 . 2007-03-16 03:28 154040 ----a-w- c:\documents and settings\tom\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-30 02:39 . 2008-10-13 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-07-29 12:27 . 2009-02-10 11:10 -------- d-----w- c:\documents and settings\tom\Application Data\DMCache
2009-07-29 04:14 . 2008-10-13 21:47 786464 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-07-29 04:14 . 2008-10-13 21:47 5864 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-07-29 04:14 . 2008-10-13 21:47 4225568 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-29 04:14 . 2008-10-13 21:47 36188 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-18 19:09 . 2008-10-24 15:49 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-17 23:29 . 2008-12-08 17:14 -------- d-----w- c:\program files\Save Flash
2009-07-16 00:06 . 2008-03-18 16:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-14 07:13 . 2007-05-02 16:54 -------- d-----w- c:\program files\Macromedia
2009-07-12 05:44 . 2009-06-29 12:56 -------- d-----w- c:\program files\Common Files\SourceTec
2009-07-03 17:09 . 2004-08-03 21:56 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 13:05 . 2009-06-29 12:55 -------- d-----w- c:\program files\SourceTec
2009-06-16 14:36 . 2004-08-03 21:56 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2001-08-23 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:09 . 2004-08-03 21:56 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-23 19:02 . 2009-05-23 19:02 59392 ----a-w- c:\documents and settings\tom\Application Data\Thinstall\Adobe Dreamweaver CS3\4000001300002i\GoogleToolbarNotifier.exe
2009-05-23 19:02 . 2009-05-23 19:02 59392 ----a-w- c:\documents and settings\tom\Application Data\Thinstall\Adobe Dreamweaver CS3\1000000b00002i\Rundll32.exe
2009-05-23 19:02 . 2009-05-23 19:02 59392 ----a-w- c:\documents and settings\tom\Application Data\Thinstall\Adobe Dreamweaver CS3\4000009c00002i\IEXPLORE.EXE
2009-05-23 18:58 . 2009-05-23 18:58 59392 ----a-w- c:\documents and settings\tom\Application Data\Thinstall\Adobe Dreamweaver CS3\800000fbe00002i\Dreamweaver.exe
2009-05-22 08:47 . 2009-05-22 08:10 198064 ----a-w- c:\documents and settings\tom\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-05-22 05:04 . 2009-05-22 05:02 2925416 ----a-w- c:\documents and settings\tom\Application Data\IDM\idmupdt.exe
2009-05-21 02:19 . 2009-05-21 02:23 15120 ----a-w- c:\windows\system32\jdbgmgr.exe
2009-05-20 22:34 . 2008-10-13 21:48 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-20 22:34 . 2008-10-13 21:48 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-08 14:30 . 2009-05-08 14:30 0 ----a-w- c:\documents and settings\tom\Application Data\IDM\DwnlData\tom\SPSS12EVAL_624\SPSS12EVAL.exe
2009-05-07 15:32 . 2004-08-03 21:56 345600 ----a-w- c:\windows\system32\localspl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-04-02 09:47 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-30 68856]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-05-22 2811312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-03-15 180269]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-02 761948]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"STCWCM_McciTrayApp"="c:\program files\STCWCM\McciTrayApp.exe" [2008-04-03 543232]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2005-12-09 15691264]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2005-03-11 73728]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-2-2 1753088]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Visual Studio\\COMMON\\Tools\\VS-Ent98\\Vanalyzr\\VARPC.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 06:29 م 33808]
S2 31750BFA;31750BFA;c:\windows\system32\BC5C9FB2.EXE -k --> c:\windows\system32\BC5C9FB2.EXE -k [?]
S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [08/05/2009 05:46 م 234888]
S3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [24/10/2008 03:19 م 2944]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 07:02 م 26640]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 06:06 م 24592]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5878ED0Q-8UV0-F27U-F4LF-02A7H73RE1RN}]
c:\windows\system32\Net\dns.exe Restart
.
Contents of the 'Scheduled Tasks' folder
2009-07-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
2009-07-23 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-07-29 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-07-29 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-30 19:18]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-ClearAllHistory - c:\program files\ClearAllHistory\cah.exe
HKCU-Run-AdobeUpdater - c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
HKCU-Run-EleFunAnimatedWallpaper - (no file)
HKLM-Run-FAHESS_McciTrayApp - c:\program files\FAHESS\McciTrayApp.exe
HKLM-Run-Device Detector - DevDetect.exe
HKLM-Run-Amazing3DAquariumWallpaper - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-31 19:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{23f446ad-b175-49df-b73e-f0bcb988db0b}]
@Denied: (Full) (Everyone)
"Model"=dword:00000041
"Therad"=dword:0000001a
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):33,59,bb,e3,96,96,d3,b1,d0,fb,e2,51,75,53,28,1b,c1,1b,4b,d0,79,
f2,9e,9c,10,c9,52,f9,86,85,f8,0b,89,37,5f,6d,0b,c6,b3,0a,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):38,91,f2,bf,da,c6,82,65,93,f4,dd,7b,e9,8c,eb,b6,b2,62,c2,2d,0b,
3a,1d,84,0f,72,f8,51,e5,2a,00,05,a7,ed,9d,62,55,36,2e,cc,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{d11d192b-850d-4dff-9d50-3a046e905ce8}]
@Denied: (Full) (Everyone)
"Model"=dword:00000083
"Therad"=dword:00000015
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,98,07,ff,fc,5d,
df,1c,2f,3b,8a,0a,32,11,89,01,b5,0b,5b,53,37,fd,23,a1,74,26,f3,91,b7,4d,1d,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1600)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WgaTray.exe
.
**************************************************************************
.
Completion time: 2009-07-31 19:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-31 16:22
Pre-Run: 12,311,781,376 bytes free
Post-Run: 14,709,305,344 bytes free
205 --- E O F --- 2009-07-29 00:01