وانا خوك ذا التقرير طلع من نفسع بدون برنامجhijack
ComboFix 08-06-20.4 - Administrator 06/24/2008 14:40:36.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.226 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\system32\kakle.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-24 to 2008-06-24 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-24 11:44 7,064,096 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-24 11:29 --------- d-----w C:\Documents and Settings\Administrator\Application Data\TeraCopy
2008-06-24 11:08 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-23 23:40 596 ----a-w C:\WINDOWS\system32\drivers\اختصار إلى ftdisk.sys.lnk
2008-06-23 23:29 25,388 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-23 23:29 228,640 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-23 23:29 101,000 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-23 21:47 --------- d-----w C:\Program Files\Debugging Tools for Windows
2008-06-23 08:46 --------- d-----w C:\Program Files\MSXML 6.0
2008-06-18 14:22 --------- d-----w C:\Program Files\ma-config.com
2008-06-18 14:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-06-18 14:19 --------- d-----w C:\Program Files\Intel
2008-06-17 11:10 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Ahead
2008-06-16 19:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-16 18:25 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-06-16 08:10 --------- d-----w C:\Program Files\QuickTime
2008-06-16 08:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-16 08:09 --------- d-----w C:\Program Files\Apple Software Update
2008-06-16 08:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-06-16 08:08 --------- d-----w C:\Program Files\Java
2008-06-16 08:07 --------- d-----w C:\Program Files\Common Files\Java
2008-06-13 00:22 --------- d-----w C:\Program Files\Magellass
2008-06-12 23:47 --------- d-----w C:\Program Files\MessengerLog Pro
2008-06-12 22:19 --------- d-----w C:\Program Files\Panda Security
2008-06-12 22:13 --------- d-----w C:\Documents and Settings\Administrator\Application Data\MessengerLog6
2008-06-12 21:55 --------- d-----w C:\Program Files\MSN Messenger
2008-06-12 21:51 --------- d-----w C:\Program Files\MessengerLog
2008-06-10 22:07 --------- d-----w C:\Program Files\Sun
2008-06-10 22:06 --------- d-----w C:\Program Files\Realtek AC97
2008-06-10 22:05 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-06-10 22:04 --------- d-----w C:\Program Files\Google
2008-06-10 22:04 --------- d-----w C:\Program Files\Ace Utilities
2008-06-05 03:08 --------- d-----w C:\Program Files\Microsoft Windows OneCare Live
2008-06-02 10:12 --------- d-----w C:\Program Files\Mohsoft
2008-06-02 10:11 720,896 ----a-w C:\WINDOWS\iun6002.exe
2008-05-26 08:26 --------- d-----w C:\Program Files\Kaspersky Lab
2008-05-25 13:37 --------- d-----w C:\Program Files\ASUS
2008-05-25 11:29 376,832 ----a-w C:\WINDOWS\system32\AegisI5Installer.exe
2008-05-25 11:29 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Intel
2008-05-25 11:29 --------- d-----w C:\Documents and Settings\NetworkService\Application Data\Intel
2008-05-25 11:29 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Intel
2008-05-25 11:29 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Intel
2008-05-25 11:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intel
2008-05-25 11:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-25 11:13 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-25 11:12 --------- d-----w C:\Program Files\VIA
2008-05-25 10:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-05-25 10:37 --------- d-----w C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-05-25 08:40 --------- d-----w C:\Program Files\Star Downloader
2008-05-25 07:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-05-25 07:58 45,568 ----a-w C:\WINDOWS\system32\avgfwdx.dll
2008-05-25 07:58 22,528 ----a-w C:\WINDOWS\system32\drivers\avgfwdx.sys
2008-05-25 07:23 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-05-16 02:08 --------- d-----w C:\Program Files\TeraCopy
2008-05-11 02:55 --------- d-----w C:\Program Files\HDD Regenerator
2008-05-11 02:40 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-05-11 01:14 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-11 01:10 --------- d-----w C:\Program Files\Common Files\Ahead
2008-05-11 01:10 --------- d-----w C:\Program Files\Ahead
2008-05-11 01:07 --------- d-----w C:\Program Files\Real
2008-05-11 01:07 --------- d-----w C:\Program Files\Common Files\xing shared
2008-05-11 01:07 --------- d-----w C:\Program Files\Common Files\Real
2008-05-11 01:06 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-05-11 01:06 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-05-11 01:05 --------- d-----w C:\Program Files\Yahoo!
2008-05-11 01:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-05-11 01:02 90,112 ----a-w C:\WINDOWS\system32\agsaami.dll
2008-05-11 01:02 610,304 ----a-w C:\WINDOWS\system32\agsaamg.dll
2008-05-11 01:02 372,736 ----a-w C:\WINDOWS\system32\agsaamc.dll
2008-05-11 01:02 2,535,424 ----a-w C:\WINDOWS\system32\agsaamj.dll
2008-05-11 01:02 196,608 ----a-w C:\WINDOWS\system32\maag.dll
2008-05-11 01:02 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-05-11 01:02 1,245,184 ----a-w C:\WINDOWS\system32\bkll.dll
2008-05-11 01:02 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2008-05-11 01:02 --------- d-----w C:\Program Files\Real_SC
2008-05-11 00:59 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-05-11 00:58 --------- d-----w C:\Program Files\WinDriver Ghost
2008-05-11 00:52 --------- d-----w C:\Program Files\CONEXANT
2008-05-11 00:51 --------- d-----w C:\Program Files\Sigmatel
2008-05-11 00:33 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:14 1,285,632 ----a-w C:\WINDOWS\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [01/19/2007 12:55 PM 5674352]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [02/10/2005 05:00 PM 1937408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/18/2008 11:37 PM 6731312]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05/11/2008 04:06 AM 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [03/25/2008 04:28 AM 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [05/27/2008 10:50 AM 413696]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [06/06/2006 07:09 PM 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [06/06/2006 07:06 PM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [06/06/2006 07:10 PM 118784]
"BluetoothAuthenticationAgent"="bthprops.cpl,,BluetoothAuthenticationAgent" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
--a------ 06/18/2008 11:37 PM 6731312 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioDeck]
-ra------ 08/09/2007 03:48 PM 528384 C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 08/04/2004 12:56 AM 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 06/06/2006 07:06 PM 77824 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 06/06/2006 07:10 PM 118784 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 06/06/2006 07:09 PM 94208 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 03/04/2008 02:41 PM 1101824 C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
--a------ 03/04/2008 02:46 PM 999424 C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kav]
--a------ 03/07/2006 05:48 PM 139367 C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 08/04/2004 01:09 AM 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 01/19/2007 12:55 PM 5674352 C:\Program Files\MSN Messenger\MsnMsgr.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 07/09/2001 10:50 AM 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 05/11/2008 04:06 AM 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 08/20/2007 04:30 PM 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
R1 is-6HU7Qdrv;is-6HU7Qdrv;C:\WINDOWS\system32\drivers\86931805.sys [03/05/2008 11:41 AM]
S2 is-6HU7Q;is-6HU7Q;"C:\Documents and Settings\All Users\سطح المكتب\Kaspersky Lab Tool\is-6HU7Q\is-6HU7Q.exe" -r []
S3 Avgfwdx;Avgfwdx;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [05/25/2008 10:58 AM]
S3 Avgfwfd;AVG network filter service;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [05/25/2008 10:58 AM]
.
s of the 'Scheduled Tasks' folder
"2008-06-16 08:09:45 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-24 14:44:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 06/24/2008 14:46:05
ComboFix-quarantined-files.txt 2008-06-24 11:45:59
Pre-Run: 36,186,243,072 bytes free
Post-Run: 36,200,996,864 bytes free
190