ComboFix 08-07-04.2 - Fahd 07/05/2008 0:39:16.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.221 [GMT 3:00]
Running from: C:\Documents and Settings\Fahd\My Documents\Downloads\Programs\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Fahd\Application Data\macromedia\Flash Player\#Shareds\AS8S8GCQ\iforex.com
C:\Documents and Settings\Fahd\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\wanpacket.dll
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\v10neformatic.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-06-04 to 2008-07-04 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-04 21:42 96,544 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-04 21:42 9,812 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-04 21:42 51,992 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-04 21:42 3,587,616 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-04 21:38 --------- d-----w C:\Documents and Settings\Fahd\Application Data\DMCache
2008-07-04 15:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-03 08:48 --------- d-----w C:\Documents and Settings\Fahd\Application Data\CyberScrub
2008-07-03 08:47 --------- d-----w C:\Documents and Settings\Fahd\Application Data\cleaner
2008-07-03 00:26 --------- d-----w C:\Program Files\MSN Messenger
2008-06-30 11:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-30 11:51 --------- d-----w C:\Program Files\Mubasher
2008-06-29 14:21 --------- d-----w C:\Program Files\Real
2008-06-29 14:21 --------- d-----w C:\Program Files\Common Files\xing shared
2008-06-29 14:21 --------- d-----w C:\Program Files\Common Files\Real
2008-06-28 13:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-28 02:08 --------- d-----w C:\Program Files\LimeWire
2008-06-28 02:07 --------- d-----w C:\Program Files\Internet Download Manager
2008-06-28 02:07 --------- d-----w C:\Documents and Settings\Fahd\Application Data\LimeWire
2008-06-27 01:37 --------- d-----w C:\Program Files\Browster
2008-06-26 22:19 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-06-26 22:18 96,966 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-06-26 22:18 88,774 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-06-26 18:42 --------- d-----w C:\Program Files\Kaspersky Lab
2008-06-26 17:54 --------- d-----w C:\Program Files\FALCOM
2008-06-26 17:43 --------- d-----w C:\Program Files\Lucky Broker
2008-06-26 17:41 --------- d-----w C:\Program Files\HP
2008-06-26 17:37 --------- d-----w C:\Program Files\Color7 Video Studio
2008-06-26 17:37 --------- d-----w C:\Program Files\Avant Browser
2008-06-26 06:55 --------- d-----w C:\Program Files\AVI ReComp
2008-06-19 10:28 --------- d-----w C:\Program Files\SRS Labs
2008-06-19 10:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\SRS Labs
2008-06-14 17:31 271,616 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-17 20:54 --------- d-----w C:\Program Files\Nero
2008-05-12 05:01 --------- d-----w C:\Program Files\Java
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-14 16:00 32,866 ------w C:\WINDOWS\slrundll.exe
2008-04-14 16:00 284,160 ----a-w C:\WINDOWS\winhlp32.exe
2008-04-14 16:00 146,944 ----a-w C:\WINDOWS\regedit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [01/08/2008 01:25 PM 2124088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [11/23/2006 02:52 PM 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [11/23/2006 02:52 PM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [11/23/2006 02:52 PM 118784]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM 31016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [03/25/2008 04:28 AM 144784]
"TempClean"="C:\Program Files\TempClean\TempClean.exe" [03/19/2001 07:51 AM 507904]
"DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [11/27/2006 03:19 PM 1582616]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [11/02/2004 08:24 PM 32768]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [02/02/2006 12:11 PM 73728]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/29/2008 05:20 PM 185896]
"RTHDCPL"="RTHDCPL.EXE" [11/23/2006 02:52 PM 15691264 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 06:59 PM 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
12/20/2001 11:34 PM 24576 C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
07/22/2006 11:49 PM 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Avant Browser\\avant.exe"=
"C:\\Program Files\\Toshiba\\ConfigFree\\CFXFER.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\WINDOWS\\system32\\CNAB4RPK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15399:TCP"= 15399:TCP:BitComet 15399 TCP
"15399:UDP"= 15399:UDP:BitComet 15399 UDP
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/04/2007 02:58 PM]
S3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [12/16/2006 11:37 PM]
.
s of the 'Scheduled Tasks' folder
"2008-07-04 21:43:51 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-NDSTray.exe - NDSTray.exe
HKLM-Run-CFSServ.exe - CFSServ.exe
Notify-WgaLogon - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-05 00:47:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\CNAB4RPK.EXE
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\ConfigFree\CFSServ.exe
.
**************************************************************************
.
Completion time: 07/05/2008 0:53:23 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-04 21:53:14
Pre-Run: 30,073,847,808 bytes free
Post-Run: 29,980,647,424 bytes free
155 --- E O F --- 2008-06-20 07:33:02
هذا التقرير بالنسبة للأداء الاولى
هذا التقرير كامل
لايكون كبير او انت تبي جزء معين
نبي رأيك اخوي
المانسي
وابغاك تشرح هذي الكلمة شوي
"""واعمل تقرير للهايجاك"""
شكرا اخوي المانسي
النهاااااااااااااااااااااية