التقرير الاداة ComboFix
ComboFix 08-04-28.2 - مشاري 04/30/2008 16:51:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.128 [GMT 3:00]
Running from: C:\Documents and Settings\مشاري\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-30 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-30 13:54 824,352 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-30 13:54 25,632 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-04-30 13:53 4,472 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-04-30 13:53 19,376 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-30 13:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-30 13:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-04-30 13:32 96,645 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-04-30 13:32 87,941 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-04-30 13:11 --------- d-----w C:\Program Files\Internet Download Manager
2008-04-30 12:56 --------- d-----w C:\Program Files\Kaspersky Lab
2008-04-30 11:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-04-30 10:09 155,995 ----a-w C:\WINDOWS\java\Packages\RZ5335VN.ZIP
2008-04-30 09:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Cast ping base frag
2008-04-30 09:33 --------- d-----w C:\Program Files\interfirstdumb
2008-04-30 09:32 --------- d-----w C:\Program Files\Windows Live
2008-04-30 09:32 --------- d-----w C:\Program Files\MSN Messenger
2008-04-30 09:32 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-30 09:32 --------- d-----w C:\Program Files\Adverts
2008-04-30 09:24 --------- d-----w C:\Program Files\Real
2008-04-30 09:09 --------- d-----w C:\Program Files\PC Camer@
2008-04-30 09:09 --------- d-----w C:\Program Files\InstallShield Installation Information
2008-04-30 09:09 --------- d-----w C:\Program Files\Common Files\PCCamera
2008-04-30 09:09 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-30 07:53 --------- d-----w C:\Program Files\Paltalk Messenger
2008-04-30 07:05 --------- d-----w C:\Program Files\Common Files\xing shared
2008-04-30 07:05 --------- d-----w C:\Program Files\Common Files\Real
2008-04-30 07:04 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-04-30 07:04 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-04-30 06:57 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [01/19/2007 12:55 PM 5674352]
"Jugs book"="C:\DOCUME~1\563F~1\APPLIC~1\INTERF~1\FIVELITESITE.exe" [04/30/2008 12:32 PM 450560]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [04/30/2008 04:11 PM 2573744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [04/30/2008 10:04 AM 185896]
"VTTimer"="VTTimer.exe" [03/07/2005 10:33 PM 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [04/11/2006 11:06 AM 176128 C:\WINDOWS\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [11/19/2002 09:01 PM 46592 C:\WINDOWS\SOUNDMAN.EXE]
"Base frag grid bows"="C:\Documents and Settings\All Users\Application Data\Cast ping base frag\Tray type.exe" [04/30/2008 04:54 PM 657920]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [12/18/2007 12:43 AM 227856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.321\\English\\setup.exe"=
R3 PAC207;SoC
PC-Camer@;C:\WINDOWS\system32\DRIVERS\PFC027.SYS [05/05/2006 03:59 PM]
.
s of the 'Scheduled Tasks' folder
"2008-04-30 13:00:02 C:\WINDOWS\Tasks\ADBB8A11919800C1.job"
- c:\docume~1\563f~1\applic~1\interf~1\download locks free.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-04-30 16:54:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\PAStiSvc.exe
C:\Program Files\Paltalk Messenger\paltalk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 04/30/2008 16:57:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-30 13:56:55
Pre-Run: 28,339,453,952 bytes free
Post-Run: 28,466,540,544 bytes free
107 --- E O F --- 2008-04-30 12:56:53