تفضل
ComboFix 09-07-29.04 - PC User 01/08/2009 0:29.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.44.1033.18.2038.1468 [GMT 3:00]
Running from: c:\documents and settings\PC User\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\desktop.ini
c:\documents and settings\PC User\My Documents\الله اكبر\صامدون\Desktop_.ini
c:\documents and settings\PC User\My Documents\ الله اكبر\عمليات المقاومة\Desktop_.ini
c:\documents and settings\PC User\My Documents\ الله اكبر\ الله\Desktop_.ini
c:\documents and settings\PC User\My Documents\الله اكبر\الوحدة الوطنية\اخرى\Desktop_.ini
c:\documents and settings\PC User\My Documents\ الله\الوحدة الوطنية\Desktop_.ini
c:\documents and settings\PC User\My Documents\ الله اكبر\اناشيد\Desktop_.ini
c:\documents and settings\PC User\My Documents\ الله اكبر\تضامن\Desktop_.ini
c:\documents and settings\PC User\My Documents\منوعات\Desktop_.ini
c:\documents and settings\PC User\My Documents\منوعات\jgff\Desktop_.ini
c:\recycler\S-1-5-21-9269302697-1744559286-345803494-5363
c:\windows\Installer\151c7a.msi
c:\windows\Installer\1fe6f.msi
c:\windows\Installer\9cfa51.msi
c:\windows\Installer\d8a168.msi
c:\windows\system32\kakle.dll
c:\windows\system32\UTSCSI.EXE
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
c:\windows\system32\winitn.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_AVPsys
-------\Legacy_UTSCSI
-------\Service_UTSCSI
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-31 )))))))))))))))))))))))))))))))
.
2009-07-31 13:00 . 2009-07-31 13:00 -------- d-----w- c:\program files\Trend Micro
2009-07-31 11:00 . 2009-07-31 11:00 198064 ----a-w- c:\documents and settings\PC User\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-07-30 09:57 . 2009-07-31 13:19 2320640 ----a-w- c:\windows\system32\TUKernel.exe
2009-07-30 09:46 . 2009-07-30 09:46 -------- d-----w- c:\documents and settings\PC User\Application Data\TuneUp Software
2009-07-30 09:46 . 2009-07-30 09:46 306432 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-07-30 09:46 . 2007-12-20 07:41 29440 ----a-w- c:\windows\system32\uxtuneup.dll
2009-07-30 09:45 . 2009-07-30 09:45 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-07-30 09:45 . 2009-07-30 09:46 -------- d-----w- c:\program files\TuneUp Utilities 2008
2009-07-29 15:52 . 2009-07-29 15:52 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\update\rollback\AutoPatches\kav8exec\8.0.0.506\avp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-31 21:41 . 2007-03-08 10:13 -------- d-----w- c:\documents and settings\PC User\Application Data\DMCache
2009-07-31 21:41 . 2008-12-03 12:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-07-31 21:39 . 2008-12-03 12:30 491552 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-07-31 21:39 . 2008-12-03 12:30 2760 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-07-31 21:39 . 2008-12-03 12:30 1999904 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-31 21:39 . 2008-12-03 12:30 16704 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-31 12:06 . 2009-07-31 12:06 -------- d-----w- c:\documents and settings\PC User\Application Data\CyberScrub
2009-07-31 12:06 . 2009-07-31 12:06 -------- d-----w- c:\documents and settings\PC User\Application Data\cleaner
2009-07-31 11:41 . 2008-05-22 07:42 -------- d-----w- c:\program files\The KMPlayer
2009-07-31 11:00 . 2007-03-08 10:13 -------- d-----w- c:\documents and settings\PC User\Application Data\IDM
2009-07-31 11:00 . 2007-03-08 10:13 -------- d-----w- c:\program files\Internet Download Manager
2009-07-31 10:57 . 2004-08-03 22:56 3970048 ----a-w- c:\windows\system32\logonuiX.exe
2009-07-30 09:11 . 2008-12-04 18:27 -------- d-----w- c:\documents and settings\PC User\Application Data\Thinstall
2009-07-29 15:52 . 2009-02-17 10:19 208616 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
2009-07-20 10:53 . 2009-04-29 05:45 -------- d-----w- c:\documents and settings\PC User\Application Data\Skype
2009-07-20 10:52 . 2009-04-29 05:57 -------- d-----w- c:\documents and settings\PC User\Application Data\skypePM
2009-07-11 12:06 . 2008-11-06 09:45 -------- d-----w- c:\documents and settings\PC User\Application Data\uTorrent
2009-06-18 10:39 . 2007-10-11 12:22 -------- d-----w- c:\program files\Avant Browser
2009-06-18 10:35 . 2007-02-04 06:27 -------- d-----w- c:\program files\CCleaner
2009-05-27 15:10 . 2008-12-03 12:32 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-27 15:10 . 2008-12-03 12:32 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-27 15:04 . 2009-05-27 15:04 81920 ----a-w- c:\documents and settings\PC User\Application Data\PLAux\URT2119.dll
2009-05-27 15:04 . 2009-05-27 15:04 49152 ----a-w- c:\documents and settings\PC User\Application Data\PLAux\URTProdLic.dll
2009-05-27 15:04 . 2009-05-27 15:04 389120 ----a-w- c:\documents and settings\PC User\Application Data\PLAux\URTDevLic.dll
2009-05-27 15:04 . 2009-05-27 15:04 315392 ----a-w- c:\documents and settings\PC User\Application Data\PLAux\URTUSBest.dll
2008-12-09 21:57 . 2008-12-09 21:57 771072 ----a-w- c:\program files\FLV PlayerRCSetup.exe
2009-07-26 22:06 . 2008-12-03 14:51 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-01-02 365960]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"ClocX"="c:\program files\ClocX\ClocX.exe" [2005-01-26 270336]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-07-31 2815408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-08 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-08 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-08 114688]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 53248]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 688218]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 385024]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2004-10-15 356352]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-01-04 282624]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"DataLayer"="c:\program files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-09-06 820736]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-06-29 176128]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-12-26 185896]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-07-29 208616]
"LogonStudio"="c:\program files\WinCustomize\LogonStudio\logonstudio.exe" [2002-09-03 987187]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2005-08-09 14743552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\PC User\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-8-16 577597]
REALTEK RTL8187 Wireless LAN Utility.lnk - c:\program files\REALTEK RTL8187 Wireless LAN Driver and Utility\RtWLan.exe [2008-12-26 737280]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 08:27 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Avant Browser\\avant.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Documents and Settings\\PC User\\Desktop\\العاب\\3D Live Pool\\3D Live Pool.exe"=
"d:\\مكتبة البرامج\\برامج\\مجموعة برامج محمولة\\utorrent.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 17:29 33808]
R1 ShldDrv;Panda File Shield Driver;c:\windows\system32\drivers\ShldDrv.sys [25/02/2007 16:55 26752]
R2 PavProc;Panda Process Protection Driver;c:\windows\system32\drivers\PavProc.sys [25/02/2007 16:55 165120]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 17:06 24592]
S0 black;black;c:\windows\system32\drivers\BlackDrv.sys --> c:\windows\system32\drivers\BlackDrv.sys [?]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\DRIVERS\br3gmdm.sys --> c:\windows\system32\DRIVERS\br3gmdm.sys [?]
S3 PortRST;USB Flash Memory Controller Service

ortRST;c:\windows\system32\drivers\PortRST.sys [27/04/2007 19:46 15547]
S3 RapFile;RapFile;c:\windows\system32\drivers\RapFile.sys [12/03/2007 17:00 36644]
S3 RapNet;RapNet;c:\windows\system32\drivers\RapNet.sys [12/03/2007 17:00 24344]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [01/12/2008 14:38 194304]
S3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [26/12/2008 12:17 13532]
S3 USBFMC2;USB Flash Memory Controller Service2;c:\windows\system32\drivers\USBFMC2.sys [27/04/2007 20:07 10382]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-07-31 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 12:17]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{ce3e3947-a80e-4e82-919a-4923c3744b10} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Connection Wizard,ShellNext = hxxp://hosting.conduit.com/Uninstall?toolbarid=&version=4.5.190.24
uInternet Settings,ProxyOverride = local
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
LSP: c:\windows\system32\idmmbc.dll
TCP: {A26B79B2-87D0-4315-8517-0A12FCFC481C} = 10.4.144.1
FF - ProfilePath - c:\documents and settings\PC User\Application Data\Mozilla\Firefox\Profiles\xwpa89k7.default\
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10591&gct=&gc=1&q=
FF - component: c:\documents and settings\PC User\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJPI142.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPOJI610.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-08-01 00:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-796845957-152049171-839522115-1003\RemoteAccess\Profile\¼w*ک**z*°وبىنبJ*]
"EnableAutodisconnect"=dword:00000001
"EnableExitDisconnect"=dword:00000001
"DisconnectIdleTime"=dword:00000014
[HKEY_USERS\S-1-5-21-796845957-152049171-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{021e4ea8-9fd0-4aa5-84ab-529bae632693}]
@Denied: (Full) (Everyone)
"Model"=dword:00000064
"Therad"=dword:00000023
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,de,1a,92,62,91,09,2e,04,5e,7a,d7,21,f9,87,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):bb,12,b8,e9,51,b8,27,bc,ce,e5,56,c0,96,cc,88,99,a7,bb,6a,93,eb,
6b,d9,7d,6f,14,ed,30,a2,d9,f3,99,d7,1b,ee,78,8a,a8,98,b2,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):b8,55,11,4a,fd,6f,a6,2f,05,ed,55,7a,eb,41,0f,e5,60,07,46,0f,74,
38,76,5c,06,b8,0f,f5,90,38,df,f2,73,d0,1a,32,83,42,de,9e,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{85085a1d-d4f6-4ed6-a8e8-fbf454abc0ed}]
@Denied: (Full) (Everyone)
"Model"=dword:00000081
"Therad"=dword:0000001f
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\WPAEvents]
@Denied: (Full) (LocalSystem)
"OOBETimer"=hex:ff,d5,71,d6,8b,6a,8d,6f,d5,33,93,fd
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1732)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
- - - - - - - > 'lsass.exe'(1788)
c:\windows\system32\idmmbc.dll
- - - - - - - > 'explorer.exe'(3264)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Intel\Wireless\Bin\OProtSvc.exe
c:\program files\Common Files\Panda Software\PavShld\PavPrSrv.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\progra~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
.
**************************************************************************
.
Completion time: 2009-07-31 0:44 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-31 21:44
Pre-Run: 8,661,397,504 bytes free
Post-Run: 8,553,537,536 bytes free
252