هذا التقرير الاول
ComboFix 08-05-01.3 - Atheer 2 05/03/2008 9:52:18.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.85 [GMT 3:00]
Running from: C:\Documents and Settings\Atheer 2\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\kakle.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-03 to 2008-05-03 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-02 17:07 43,040 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-02 17:07 339,152 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-02 17:07 154,160 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-02 17:07 11,133,728 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-29 14:07 --------- d-----w C:\Documents and Settings\Atheer 2\Application Data\CyberScrub
2008-04-29 14:07 --------- d-----w C:\Documents and Settings\Atheer 2\Application Data\cleaner
2008-04-21 20:24 --------- d-----w C:\Program Files\NoAdware5.0
2008-04-21 19:05 --------- d-----w C:\Program Files\Error Repair Professional
2008-04-17 00:13 --------- d-----w C:\Program Files\iColorFolder
2008-04-12 19:25 --------- d-----w C:\Program Files\Hide IP Platinum
2008-04-05 23:15 --------- d-----w C:\Program Files\Common Files\xing shared
2008-04-05 23:13 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-04-05 23:13 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-04-04 14:13 --------- d-----w C:\Documents and Settings\Atheer 2\Application Data\Orbit
2008-04-03 20:20 --------- d-----w C:\Documents and Settings\Atheer 2\Application Data\Sony Setup
2008-03-21 03:15 --------- d-----w C:\Program Files\Common Files\Kaspersky Lab
2008-03-19 07:58 --------- d-----w C:\Documents and Settings\Atheer 2\Application Data\Hide IP NG
2008-03-17 16:10 --------- d-----w C:\Program Files\XoftSpySE
2008-03-03 18:43 --------- d-----w C:\Documents and Settings\Atheer 2\Application Data\Super-Cow
2008-03-03 18:37 --------- d-----w C:\Program Files\ReflexiveArcade
2008-03-02 02:29 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-03-02 02:29 172,032 ------w C:\WINDOWS\Setup1.exe
2008-02-10 14:53 90,112 ----a-w C:\WINDOWS\system32\agsaami.dll
2008-02-10 14:53 610,304 ----a-w C:\WINDOWS\system32\agsaamg.dll
2008-02-10 14:53 372,736 ----a-w C:\WINDOWS\system32\agsaamc.dll
2008-02-10 14:53 2,535,424 ----a-w C:\WINDOWS\system32\agsaamj.dll
2008-02-10 14:53 196,608 ----a-w C:\WINDOWS\system32\maag.dll
2008-02-10 14:53 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-02-10 14:53 1,245,184 ----a-w C:\WINDOWS\system32\bkll.dll
2008-02-10 14:53 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2007-02-20 14:07 5,473,872 ----a-w C:\Program Files\java.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Hide IP Platinum"="C:\Program Files\Hide IP Platinum\hideippla.exe" [08/01/2007 03:50 PM 1572864]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [01/19/2007 12:55 PM 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kav"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [03/24/2006 06:09 PM 139367]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [04/06/2008 02:13 AM 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [11/24/2005 01:14 PM 1947872]
C:\Documents and Settings\Atheer 2\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Kaspersky Anti-Virus 6.0.lnk - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe [2006-03-24 18:09:22 139367]
C:\Documents and Settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Kaspersky Anti-Hacker.lnk - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe [2006-05-11 17:05:33 2195583]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoFavoritesMenu"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoInstrumentation"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFavoritesMenu"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoUserNameInStartMenu"= 1 (0x1)
"NoInstrumentation"= 0 (0x0)
"NoStartMenuPinnedList"= 0 (0x0)
"ForceStartMenuLogoff"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
antiwpa.dll 08/12/2005 05:25 AM 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
"STYLEXP"=C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe
"PadTouch"=C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
"AGRSMMSG"=AGRSMMSG.exe
"TPSMain"=TPSMain.exe
"CeEKEY"=C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
"<NO NAME>"=
"TPNF"=C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
"TCtryIOHook"=TCtrlIOHook.exe
"Zooming"=ZoomingHook.exe
"SmoothView"=C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
"Tvs"=C:\Program Files\Toshiba\Tvs\TvsTray.exe
"NDSTray.exe"=NDSTray.exe
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
"HWSetup"=C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
"SVPWUTIL"=C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"HPDJ Taskbar Utility"=C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
"rfagent"="C:\Program Files\RFA Platinum\rfagent.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiHacker]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
R0 Klpf;Klpf;C:\WINDOWS\system32\drivers\Klpf.sys [05/11/2006 05:05 PM]
R0 Klpid;Klpid;C:\WINDOWS\system32\drivers\Klpid.sys [05/11/2006 05:06 PM]
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [08/04/2004 12:56 AM]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
.
s of the 'Scheduled Tasks' folder
"2008-05-02 14:15:02 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2008-05-02 09:57:02 C:\WINDOWS\Tasks\WebReg 20080211125744.job"
- C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe_/TaskName 20080211125744 /N
"2008-04-19 00:00:02 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2008-05-03 06:16:14 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-05-03 09:53:55
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 05/03/2008 9:54:21
ComboFix-quarantined-files.txt 2008-05-03 06:54:20
Pre-Run: 9,224,560,640 bytes free
Post-Run: 9,297,641,472 bytes free
158