وأنا اسوي الفحص طلع لي هالكلام
ComboFix 08-05-01.3 - user 2008-05-07 18:17:57.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.974.1033.18.1134 [GMT 3:00]
Running from: C:\Documents and Settings\user\My Documents\My Completed Downloads\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-04-07 to 2008-05-07 )))))))))))))))))))))))))))))))
.
2008-05-06 18:28 . 2008-05-06 18:47 <DIR> d-------- C:\Documents and Settings\user\SmitfraudFix
2008-05-06 18:27 . 2008-05-06 18:29 2,680 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-05 20:59 . 2008-05-05 21:00 5,206 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-05-04 19:35 . 2008-05-04 19:35 <DIR> d-------- C:\WINDOWS\system32\athan
2008-05-04 19:35 . 2008-05-04 19:35 <DIR> d-------- C:\Program Files\Athan
2008-05-04 19:35 . 2008-05-04 19:35 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-04-19 00:13 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-19 00:07 . 2008-04-19 00:07 <DIR> d-------- C:\Program Files\Common Files\Java
2008-04-17 22:38 . 2008-05-07 14:51 <DIR> d-------- C:\Documents and Settings\user\Application Data\LimeWire
2008-04-12 21:35 . 2008-04-12 21:35 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-04-12 21:35 . 2008-04-12 21:35 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-04-12 21:35 . 2008-04-12 21:35 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-04-07 15:05 . 2008-04-07 15:05 <DIR> d-------- C:\Program Files\sect play love
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-07 15:18 9,603,360 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-07 15:18 309,280 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-07 14:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-07 14:55 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-07 14:36 30,800 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-07 14:36 131,252 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-06 20:08 --------- d-----w C:\Documents and Settings\user\Application Data\cleaner
2008-05-06 15:03 --------- d-----w C:\Program Files\Windows Live
2008-05-05 18:00 70,541 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-04-21 18:19 --------- d-----w C:\Program Files\learn computer
2008-04-18 21:13 --------- d-----w C:\Program Files\Java
2008-04-12 18:35 --------- d-----w C:\Program Files\Common Files\Real
2008-04-07 12:05 --------- d-----w C:\Documents and Settings\user\Application Data\sect play love
2008-04-07 12:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\live 64 math does
2008-04-07 12:04 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-03-29 15:30 --------- d-----w C:\Program Files\ScanSpyware v3.8.0.4
2008-03-27 18:06 --------- d-----w C:\Program Files\DAP
2008-03-27 16:29 --------- d-----w C:\Program Files\Kaspersky Lab
2008-03-27 16:00 --------- d-----w C:\Documents and Settings\user\Application Data\FastStone
2008-03-27 00:17 2,136,064 ----a-w C:\WINDOWS\system32\kernel1.exe
2008-03-27 00:15 2,137,088 ----a-w C:\WINDOWS\system32\KERNEL.TMP
2008-03-26 17:18 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-03-26 13:57 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-03-25 21:05 --------- d-----w C:\Documents and Settings\user\Application Data\CyberScrub
2008-03-25 20:57 --------- d-----w C:\Documents and Settings\user\Application Data\MegauploadToolbar
2008-03-25 16:15 --------- d-----w C:\Program Files\Nufsoft
2008-03-25 14:31 --------- d-----w C:\Program Files\TGTSoft
2008-03-25 11:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware
2008-03-23 20:23 50,688 ----a-w C:\WINDOWS\system32\wbhelp2.dll
2008-03-23 19:41 --------- d-----w C:\Program Files\DSL Speed
2008-03-23 18:20 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-23 17:34 --------- d-----w C:\Program Files\ScanSpyware v3.8
2008-03-23 17:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-23 16:35 --------- d-----w C:\Program Files\MegauploadToolbar
2008-03-23 16:06 --------- d-----w C:\Documents and Settings\user\Application Data\SUPERAntiSpyware.com
2008-03-23 16:05 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-03-23 15:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-18 11:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-17 09:41 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-03-05 12:02 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-03-05 12:02 172,032 ------w C:\WINDOWS\Setup1.exe
2008-02-20 13:24 583,311,360 ----a-w C:\WINDOWS\system32\Mpg4c32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-17 07:28 90,112 ----a-w C:\WINDOWS\system32\agsaami.dll
2008-02-17 07:28 610,304 ----a-w C:\WINDOWS\system32\agsaamg.dll
2008-02-17 07:28 372,736 ----a-w C:\WINDOWS\system32\agsaamc.dll
2008-02-17 07:28 2,535,424 ----a-w C:\WINDOWS\system32\agsaamj.dll
2008-02-17 07:28 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-02-17 07:28 1,245,184 ----a-w C:\WINDOWS\system32\bkll.dll
2008-02-17 07:28 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2008-02-17 07:05 155,995 ----a-w C:\WINDOWS\java\Packages\1J5B57X3.ZIP
2008-02-16 08:59 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-08 15:37 219,664 ----a-w C:\WINDOWS\system32\klogon.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{2ba521ac-b9b9-4433-ba45-dba2f02cba5a}]
2008-02-19 01:10 1555480 --a------ C:\Program Files\speed-bit\tbspe1.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2BA521AC-B9B9-4433-BA45-DBA2F02CBA5A}"= C:\Program Files\speed-bit\tbspe1.dll [2008-02-19 01:10 1555480]
[HKEY_CLASSES_ROOT\clsid\{2ba521ac-b9b9-4433-ba45-dba2f02cba5a}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-02-18 21:28 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-08-14 14:39 98304]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-08-14 14:41 114688]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-08-14 14:38 94208]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-28 02:36 155648]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.exe" [2008-03-25 21:25 3057152]
"Pareto_Update"="C:\PROGRA~1\COMMON~1\PARETO~1\UUS\Pareto_Update.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-12 21:35 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"Athan"="C:\Program Files\Athan\Athan.exe" [2005-09-12 03:02 937984]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2008-02-08 18:36 227856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 01:56 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\DAP\\DAP.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Documents and Settings\\user\\Desktop\\تحميلات سارونهـ\\Ares\\Ares.exe"=
"D:\\LimeWire\\LimeWire.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
.
s of the 'Scheduled Tasks' folder
"2008-05-07 15:00:00 C:\WINDOWS\Tasks\AE4DD49791864B0F.job"
- c:\docume~1\user\applic~1\sectpl~1\Jugs Jump Save.exe
"2008-05-06 15:00:00 C:\WINDOWS\Tasks\Pareto UNS.job"
- C:\Program Files\Common Files\ParetoLogic\UUS\UUS.dll\Pareto_Update.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-05-07 18:18:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-07 18:19:31
ComboFix-quarantined-files.txt 2008-05-07 15:19:26
ComboFix2.txt 2008-05-07 15:16:52
ComboFix3.txt 2008-05-06 20:18:37
Pre-Run: 25,434,243,072 bytes free
Post-Run: 25,424,232,448 bytes free
151 --- E O F --- 2008-04-10 12:00:11