تفضل ياغالي ...
--------------------------------
ComboFix 08-06-20.4 - Administrator 07/01/2008 0:29:10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.670 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\Documents and Settings\Administrator\Application Data\tazebama
C:\Documents and Settings\Administrator\Application Data\tazebama\zPharaoh.dat
C:\WINDOWS\system32\pskill.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-30 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-30 21:31 --------- d-----w C:\Program Files\microsoft frontpage
2008-06-30 21:30 245,792 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-30 21:30 2,968 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-30 21:30 11,312 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-30 21:30 1,175,584 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-30 21:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-30 21:18 --------- d-----w C:\Program Files\ma-config.com
2008-06-30 21:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-06-30 21:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-30 21:00 --------- d-----w C:\Program Files\Realtek
2008-06-30 21:00 --------- d-----w C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-06-30 20:57 --------- d-----w C:\Program Files\Realtek AC97
2008-06-30 20:57 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-30 20:54 --------- d-----w C:\Program Files\Intel
2008-06-30 14:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Long slow road itch
2008-06-28 12:15 --------- d-----w C:\Program Files\Hotspot Shield
2008-06-27 01:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-24 10:09 --------- d-----w C:\Program Files\MSN Messenger
2008-06-24 10:08 --------- d-----w C:\Program Files\Windows Live
2008-06-24 07:41 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Styler
2008-06-24 05:17 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-06-24 04:22 --------- d-----w C:\Documents and Settings\Administrator\Application Data\HiYo
2008-06-24 04:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-23 16:46 --------- d-----w C:\Program Files\MSXML 6.0
2008-06-23 16:45 --------- d-----w C:\Program Files\MSXML 4.0
2008-06-23 11:09 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Screenshot Sender
2008-06-23 08:02 --------- d-----w C:\Program Files\MSBuild
2008-06-23 08:02 --------- d-----w C:\Program Files\Microsoft Works
2008-06-23 08:01 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-23 08:00 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-06-23 07:24 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-06-23 03:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-06-23 03:47 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-06-23 03:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-06-23 03:30 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-06-23 03:18 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-06-23 03:17 --------- d-----w C:\Documents and Settings\Administrator\Application Data\trustreal
2008-06-23 03:16 --------- d-----w C:\Program Files\trustreal
2008-06-23 03:16 --------- d-----w C:\Program Files\Circle Developement
2008-06-23 03:13 --------- d---a-w C:\Program Files\SnagIt 8.0.2
2008-06-23 03:10 --------- d-----w C:\Program Files\MessengerPlus! 3
2008-06-23 03:10 --------- d-----w C:\Program Files\Adverts
2008-06-23 03:08 --------- d-----w C:\Program Files\IObit
2008-06-23 03:06 --------- d-----w C:\Program Files\Cryptomathic
2008-06-23 03:02 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-06-23 03:02 --------- d-----w C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2008-06-23 03:01 306,432 ----a-w C:\WINDOWS\system32\TuneUpDefragService.exe
2008-06-23 03:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-06-23 02:59 --------- d-----w C:\Program Files\Kaspersky Lab
2008-06-23 02:49 96,966 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-06-23 02:49 88,774 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-06-23 02:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-06-23 02:34 --------- d-----w C:\Program Files\SLD Codec Pack
2008-06-23 02:34 --------- d-----w C:\Program Files\Real Alternative
2008-06-23 02:34 --------- d-----w C:\Program Files\Media Player Classic
2008-06-23 02:33 10,368 ----a-w C:\WINDOWS\system32\drivers\pfc.sys
2008-06-23 02:33 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-06-23 02:33 --------- d-----w C:\Program Files\Java
2008-06-23 02:33 --------- d-----w C:\Program Files\Foxit Software
2008-06-23 02:33 --------- d-----w C:\Program Files\Common Files\Java
2008-06-23 02:33 --------- d-----w C:\Program Files\ADSoft
2008-06-23 02:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\ADSoft
2008-06-23 02:32 --------- d-----w C:\Program Files\Nero
2008-06-23 02:32 --------- d-----w C:\Program Files\My Company Name
2008-06-23 02:32 --------- d-----w C:\Program Files\Common Files\Nero
2008-06-23 02:26 --------- d-----w C:\Program Files\STYLER
2008-06-23 02:26 --------- d-----w C:\Program Files\RocketDock
2008-06-23 02:25 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Notepad++
2008-06-23 02:25 --------- d-----w C:\Program Files\System
2008-06-23 02:25 --------- d-----w C:\Program Files\Notepad2
2008-06-23 02:25 --------- d-----w C:\Program Files\Notepad++
2008-06-23 02:25 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Notepad++
2008-06-23 02:22 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-05-08 12:14 203,008 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-08 12:14 203,008 ------w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 04:55 1,288,192 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-25 15:22 206,088 ----a-w C:\WINDOWS\system32\klogon.dll
2008-04-22 08:02 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 08:02 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-22 08:02 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-20 05:07 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-04-02 07:52 2,276,352 ----a-w C:\WINDOWS\system32\logonui.exe
2008-04-01 18:41 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-04-01 18:41 140,288 ----a-w C:\WINDOWS\system32\sfc_os.dll
2008-04-01 18:40 984,576 ----a-w C:\WINDOWS\system32\syssetup.dll
2008-03-29 09:12 7,579,136 ----a-w C:\WINDOWS\system32\wmploc.dll
2008-03-29 09:12 3,368,960 ----a-w C:\WINDOWS\system32\xpsp2res.dll
2008-03-29 09:12 279,552 ----a-w C:\WINDOWS\system32\upnpui.dll
2008-03-29 09:12 2,237,952 ----a-w C:\WINDOWS\system32\netshell.dll
2008-03-29 09:12 166,912 ----a-w C:\WINDOWS\system32\sndvol32.exe
2008-03-28 19:13 74,240 ----a-w C:\WINDOWS\system32\notepad.exe
2008-03-28 19:13 74,240 ----a-w C:\WINDOWS\NOTEPAD.EXE
2008-03-28 19:13 517,120 ----a-w C:\WINDOWS\system32\wiaacmgr.exe
2008-03-28 19:13 367,616 ----a-w C:\WINDOWS\system32\mspaint.exe
2008-03-28 19:13 315,864 ----a-w C:\WINDOWS\system32\wuauclt1.exe
2008-03-28 19:13 186,880 ----a-w C:\WINDOWS\system32\sysocmgr.exe
2008-03-28 19:13 121,344 ----a-w C:\WINDOWS\system32\calc.exe
.
------- Sigcheck -------
02/28/2007 01:15 AM 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
02/28/2007 11:38 AM 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
02/28/2007 11:38 AM 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\SoftwareDistribution\Download\10e16e65c532d077de7c89a212bd8df8\SP2GDR\ntkrnlpa.exe
02/28/2007 01:15 AM 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\SoftwareDistribution\Download\10e16e65c532d077de7c89a212bd8df8\SP2QFE\ntkrnlpa.exe
04/02/2008 12:07 PM 2183680 a149c9c44c4fbd2705c9a1737928c028 C:\WINDOWS\system32\ntkrnlpa.exe
02/28/2007 11:38 AM 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
06/30/2008 02:32 PM 62728 --a------ C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [06/29/2008 02:40 AM 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaDrive"="C:\WINDOWS\VistaDrive\VistaDrive.exe" [10/05/2006 08:56 PM 280779]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM 144784]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 12:25 PM 6731312]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [09/20/2005 05:35 AM 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [09/20/2005 05:32 AM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [09/20/2005 05:36 AM 114688]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM 31016]
"SoundMan"="SOUNDMAN.EXE" [04/16/2007 03:28 PM 577536 C:\WINDOWS\soundman.exe]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 01:56 AM 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [04/23/2008 06:35 AM 124928 C:\WINDOWS\system32\advpack.dll]
"ShowDeskFix"="regsvr32" []
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
RocketDock.lnk - C:\Program Files\RocketDock\RocketDock.exe [2008-06-23 05:26:04 495616]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
TrueTransparency.lnk - C:\Program Files\TrueTransparency\TrueTransparency.exe [2008-06-23 05:26:10 133120]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"LockTaskbar"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"LockTaskbar"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"VIDC.YV12"= yv12vfw.dll
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
--a------ 06/23/2008 06:09 AM 190024 C:\Program Files\MessengerPlus! 3\MsgPlus.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 06/29/2008 02:40 AM 5724184 C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [08/04/2004 01:56 AM]
R3 Cap713x;Philips Cap713x Video Capture;C:\WINDOWS\system32\DRIVERS\Cap713x.sys [05/04/2005 11:32 AM]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [03/25/2008 08:07 PM]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [06/08/2007 09:52 AM]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [06/23/2008 06:01 AM]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
s of the 'Scheduled Tasks' folder
"2008-06-27 14:16:10 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-01 00:32:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
.
**************************************************************************
.
Completion time: 07/01/2008 0:35:40 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-30 21:35:37
Pre-Run: 24,961,302,528 bytes free
Post-Run: 25,013,153,792 bytes free
231 --- E O F --- 2008-06-25 02:57:23