هذا التقرير الاخير بعد الفحص لكن ماجربت الفلاش
ComboFix 09-10-28.08 - admin 10/31/2009 0:47.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.511.244 [GMT 3:00]
Running from: c:\documents and settings\admin\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\clrviddc.dll
.
((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-30 )))))))))))))))))))))))))))))))
.
2009-10-29 21:58 . 2009-10-29 21:58 -------- d-----w- c:\windows\system32\XPSViewer
2009-10-29 21:58 . 2009-10-29 21:58 -------- d-----w- c:\program files\MSBuild
2009-10-29 21:58 . 2009-10-29 21:58 -------- d-----w- c:\program files\Reference Assemblies
2009-10-29 20:56 . 2009-10-29 20:56 -------- d-----w- c:\windows\ServicePackFiles
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-30 22:03 . 2008-07-03 00:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-10-30 22:01 . 2008-07-03 00:16 573472 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-10-30 22:01 . 2008-07-03 00:16 3040 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-10-30 22:01 . 2008-07-03 00:16 2480160 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-30 22:01 . 2008-07-03 00:16 20456 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-30 08:53 . 2006-10-03 09:59 96600 ----a-w- c:\documents and settings\admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-29 20:20 . 2008-04-09 22:22 -------- d-----w- c:\program files\Real_SC
2009-10-29 18:32 . 2008-01-29 15:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-10-29 18:32 . 2008-07-03 00:18 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-29 18:32 . 2008-07-03 00:18 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-08-24 18:17 . 2006-10-07 22:22 1956 ----a-w- c:\windows\system32\d3d8caps.dat
2009-08-04 14:00 . 2004-08-03 23:20 2180352 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 13:13 . 2004-08-03 22:59 2057728 ----a-w- c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-29 32768]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 144784]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-15 196608]
"BigDogPath"="c:\windows\VM_STI.EXE" [2004-12-15 40960]
"NeroCheck"="c:\windows\system32\\NeroCheck.exe" [2001-07-09 155648]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-08-03 201992]
"SMSERIAL"="sm56hlpr.exe" - c:\windows\sm56hlpr.exe [2005-06-06 544768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-6-22 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk
backup=c:\windows\pss\BlueSoleil.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\english\\setup.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:*

isabled

oVoo TCP المنفذ 443
"443:UDP"= 443:UDP:*

isabled

oVoo UDP المنفذ 443
"37674:TCP"= 37674:TCP:*

isabled

oVoo TCP المنفذ 37674
"37674:UDP"= 37674:UDP:*

isabled

oVoo UDP المنفذ 37674
"37675:UDP"= 37675:UDP:*

isabled

oVoo UDP المنفذ 37675
"37676:TCP"= 37676:TCP:*

isabled

oVoo TCP المنفذ 37676
"37676:UDP"= 37676:UDP:*

isabled

oVoo UDP المنفذ 37676
"37677:UDP"= 37677:UDP:*

isabled

oVoo UDP المنفذ 37677
"37680:TCP"= 37680:TCP:*

isabled

oVoo TCP المنفذ 37680
"37680:UDP"= 37680:UDP:*

isabled

oVoo UDP المنفذ 37680
"37681:UDP"= 37681:UDP:*

isabled

oVoo UDP المنفذ 37681
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 06:29 م 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 07:02 م 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [25/03/2008 08:07 م 24592]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\drivers\br3gmdm.sys [04/05/2008 07:32 م 100096]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [17/06/2008 01:37 ص 194304]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - CLASSPNP_2
*NewlyCreated* - MBR
*NewlyCreated* - PCIIDEX_2
*Deregistered* - CLASSPNP_2
*Deregistered* - mbr
*Deregistered* - PCIIDEX_2
.
Contents of the 'Scheduled Tasks' folder
2008-08-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 12:42]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 212.93.193.78:8080
uInternet Settings,ProxyOverride = <local>
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
DPF: Microsoft XML Parser for Java -
.
- - - - ORPHANS REMOVED - - - -
Notify-WgaLogon - (no file)
AddRemove-HijackThis - c:\documents and settings\admin\Desktop\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-10-31 01:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(848)
c:\windows\system32\klogon.dll
- - - - - - - > 'explorer.exe'(3976)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
.
**************************************************************************
.
Completion time: 2009-10-30 1:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-30 22:09
Pre-Run: 7,767,183,360 bytes free
Post-Run: 8,087,367,680 bytes free
- - End Of File - - F933E9B2054864AFBC2FF894CF5C811B