أخي زيزووم
قمت بتحميل البرنامج وظهر هذا التقرير وآسف على التأخير
ComboFix 08-05-01.1 - Administrator 05/02/2008 14:17:59.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.220 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-04-02 to 2008-05-02 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-02 11:20 2,222,112 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-02 11:20 114,976 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-02 10:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-02 10:46 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DMCache
2008-05-02 04:34 29,780 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-02 04:34 13,508 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-01 23:06 --------- d-----w C:\Program Files\Google
2008-05-01 22:53 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CyberScrub
2008-05-01 22:51 --------- d-----w C:\Documents and Settings\Administrator\Application Data\cleaner
2008-05-01 16:30 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-05-01 16:30 --------- d-----w C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2008-05-01 16:29 306,432 ----a-w C:\WINDOWS\system32\TuneUpDefragService.exe
2008-05-01 16:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-05-01 16:28 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-01 04:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-05-01 03:57 502,784 ----a-w C:\WINDOWS\system32\winlogon.exe
2008-05-01 03:40 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-05-01 00:52 96,645 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-05-01 00:52 87,941 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-05-01 00:41 --------- d-----w C:\Program Files\Internet Download Manager
2008-05-01 00:27 --------- d-----w C:\Program Files\Kaspersky Lab
2008-05-01 00:26 78,415 ----a-w C:\WINDOWS\system32\drivers\klif.cab
2008-05-01 00:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-04-30 21:25 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Regrun
2008-04-30 21:18 31,170 ----a-w C:\WINDOWS\system32\drivers\Partizan.sys
2008-04-30 21:18 22,528 ----a-w C:\WINDOWS\system32\Partizan.exe
2008-04-30 21:18 --------- d-----w C:\Program Files\Greatis
2008-04-30 19:51 --------- d-----w C:\Program Files\NoAdware5.0
2008-04-30 17:23 --------- d-----w C:\Documents and Settings\Administrator\Application Data\IDM
2008-04-30 16:30 --------- d-----w C:\Documents and Settings\Administrator\Application Data\MiniDm
2008-04-30 15:05 --------- d-----w C:\Documents and Settings\Administrator\Application Data\IEPro
2008-04-30 15:04 --------- d-----w C:\Program Files\IEPro
2008-04-30 15:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\GRETECH
2008-04-30 15:04 --------- d-----w C:\Documents and Settings\Administrator\Application Data\GRETECH
2008-04-30 15:03 --------- d-----w C:\Program Files\GRETECH
2008-04-30 15:02 --------- d-----w C:\Program Files\Webteh
2008-04-30 15:02 --------- d-----w C:\Program Files\bsplay086.501
2008-04-30 15:02 --------- d-----w C:\Documents and Settings\Administrator\Application Data\BSplayer Pro
2008-04-30 15:00 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-04-29 20:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-04-29 12:41 --------- d-----w C:\Program Files\VIA Technologies, Inc
2008-04-29 12:39 --------- d-----w C:\Program Files\Winbond
2008-04-29 12:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-29 12:36 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-29 12:36 --------- d-----w C:\Program Files\AvRack
2008-04-29 12:36 --------- d-----w C:\Program Files\Avance Sound Manager
2008-04-29 12:01 76,192 ----a-w C:\WINDOWS\system32\drivers\snapman.sys
2008-04-29 12:01 37,888 ----a-w C:\WINDOWS\system32\setupnt.dll
2008-04-29 12:01 118,784 ----a-w C:\WINDOWS\system32\snapapi.dll
2008-04-29 12:01 --------- d-----w C:\Program Files\Acronis
2008-04-29 12:01 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Acronis
2008-04-29 12:00 373,248 ----a-w C:\WINDOWS\system32\autoprnt.exe
2008-04-29 12:00 --------- d-----w C:\Program Files\Common Files\Acronis
2008-04-29 11:46 --------- d-----w C:\Program Files\Microsoft.NET
2008-04-29 11:45 --------- d-----w C:\Program Files\Microsoft Works
2008-04-29 11:24 --------- d-----w C:\Program Files\microsoft frontpage
2008-03-19 09:40 1,845,888 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 18:49 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 06:52 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-15 15:12 206,256 ----a-w C:\WINDOWS\system32\idmmbc.dll
.
------- Sigcheck -------
08/04/2004 12:56 AM 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe
08/04/2004 12:56 AM 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll
05/01/2008 06:57 AM 502784 cde7b5c3ba6118ff1c3aa45d9de46ffc C:\WINDOWS\system32\winlogon.exe
08/03/2004 11:14 PM 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys
08/03/2004 11:00 PM 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys
08/04/2004 12:56 AM 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [04/30/2008 08:07 PM 932864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [04/29/2008 03:01 PM 65536]
"Acronis Popup Blocker"="C:\PROGRA~1\Acronis\PRIVAC~1\Blocker.dll" [ ]
"SoundMan"="SOUNDMAN.EXE" [02/05/2002 09:05 AM 46592 C:\WINDOWS\SOUNDMAN.EXE]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [06/28/2007 12:51 PM 218376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [08/04/2004 12:56 AM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/04/2007 02:58 PM]
S3 Partizan;Partizan;C:\WINDOWS\system32\drivers\Partizan.sys [05/01/2008 12:18 AM]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [05/01/2008 07:29 PM]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
.
s of the 'Scheduled Tasks' folder
"2008-05-01 16:30:22 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-05-02 14:20:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 05/02/2008 14:21:58
ComboFix-quarantined-files.txt 2008-05-02 11:21:46
ComboFix2.txt 2008-05-02 11:12:15
ComboFix3.txt 2008-05-02 11:02:01
Pre-Run: 9,085,841,408 bytes free
Post-Run: 9,076,666,368 bytes free
134 --- E O F --- 2008-05-02 04:33:34
في انتظار الحل ..