عفوا نسيت تقرير ComboFix
----------------
ComboFix 08-08-14.05 - xp 2008-08-16 4:50:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.643 [GMT 3:00]
Running from: C:\Documents and Settings\xp\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\xp\Application Data\macromedia\Flash Player\#Shareds\ME7WDJGZ\interclick.com
C:\Documents and Settings\xp\Application Data\macromedia\Flash Player\#Shareds\ME7WDJGZ\interclick.com\ud.sol
C:\Documents and Settings\xp\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\xp\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\xp\s\xp@2o7[1].txt
C:\Documents and Settings\xp\s\xp@ad.yieldmanager[1].txt
C:\Documents and Settings\xp\s\xp@delicious[1].txt
C:\Documents and Settings\xp\s\xp@deviantart[2].txt
C:\Documents and Settings\xp\s\xp@mybrandcentral[1].txt
C:\Documents and Settings\xp\s\xp@network.adsmarket[2].txt
C:\Documents and Settings\xp\s\xp@specificclick[2].txt
C:\Documents and Settings\xp\s\xp@statcounter[1].txt
C:\Documents and Settings\xp\s\xp@www.3mints[1].txt
C:\Documents and Settings\xp\s\xp@www.amman-dj[1].txt
C:\Documents and Settings\xp\s\xp@www.fanansoft[2].txt
C:\Documents and Settings\xp\s\xp@www.hymarkets[1].txt
C:\Documents and Settings\xp\Local Settings\Temporary Internet Files\AlxRes_dll_IMAGE_bg_popup.gif
C:\Documents and Settings\xp\Local Settings\Temporary Internet Files\AlxRes_dll_IMAGE_window_sliver.gif
C:\Program Files\alexa toolbar
C:\Program Files\alexa toolbar\uninstall.exe
C:\WINDOWS\system32\wsnpoem
C:\WINDOWS\system32\wsnpoem\audio.dll
C:\WINDOWS\system32\wsnpoem\video.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-16 to 2008-08-16 )))))))))))))))))))))))))))))))
.
2008-08-16 04:07 . 2008-08-16 04:07 <DIR> d-------- C:\Documents and Settings\Administrator
2008-08-15 22:26 . 2008-06-13 16:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-08-15 22:26 . 2008-06-13 16:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-08-15 22:04 . 2008-08-16 02:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-08-15 21:50 . 2008-08-16 03:03 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-08-15 21:50 . 2005-02-25 06:35 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-08-15 21:28 . 2008-08-15 21:28 <DIR> d-------- C:\Program Files\XviD
2008-08-15 21:28 . 2008-08-15 21:28 <DIR> d-------- C:\Program Files\Apex
2008-08-15 21:28 . 2001-08-23 17:00 1,700,352 --a------ C:\WINDOWS\system32\gdiplus.dll
2008-08-15 21:02 . 2008-08-15 21:02 27,648 --a------ C:\WINDOWS\system32\sysani.dll
2008-08-15 15:23 . 2008-08-15 15:23 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\CyberLink
2008-08-15 15:00 . 2008-08-15 15:00 <DIR> d-------- C:\Documents and Settings\All Users\CyberLink
2008-08-15 14:49 . 2008-08-15 14:49 279,126 --a------ C:\_MaskResult.bmp
2008-08-15 14:45 . 2008-08-15 14:45 0 --a------ C:\WINDOWS\PhotoNow.INI
2008-08-15 14:37 . 2008-08-15 14:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-08-15 14:35 . 2008-08-15 14:36 <DIR> d-------- C:\Documents and Settings\xp\Application Data\CyberLink
2008-08-15 14:25 . 2008-08-15 14:28 <DIR> d-------- C:\Program Files\CyberLink
2008-08-14 12:39 . 2008-08-14 12:55 <DIR> d-------- C:\Documents and Settings\xp\Application Data\IDM
2008-08-14 12:39 . 2008-08-16 04:49 <DIR> d-------- C:\Documents and Settings\xp\Application Data\DMCache
2008-08-13 06:19 . 2008-08-13 07:02 <DIR> d-------- C:\Program Files\phpDesigner 2008
2008-08-13 05:35 . 2008-08-13 05:36 <DIR> d-------- C:\Documents and Settings\xp\Application Data\phpDesigner 2008
2008-08-13 05:32 . 2003-04-17 22:57 207 --------- C:\WINDOWS\zend_encoder.dat
2008-08-13 04:35 . 2008-08-13 05:16 <DIR> d-------- C:\Documents and Settings\xp\ZDE
2008-08-13 04:32 . 2008-08-13 04:34 <DIR> d--h----- C:\Program Files\Zero G Registry
2008-08-13 04:30 . 2008-08-13 04:30 <DIR> d--h----- C:\Documents and Settings\xp\InstallAnywhere
2008-08-12 13:53 . 2008-08-13 05:32 <DIR> d-------- C:\Program Files\Zend
2008-08-10 03:54 . 2008-08-10 03:54 <DIR> d-------- C:\spoolerlogs
2008-08-09 03:46 . 2008-08-09 03:46 <DIR> d-------- C:\Program Files\LtUcx
2008-08-06 05:00 . 2008-08-06 05:00 <DIR> d-------- C:\Program Files\Save Flash
2008-08-04 01:13 . 2008-08-04 01:13 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-07-26 09:13 . 2008-07-26 09:13 <DIR> d-------- C:\Program Files\Nokia
2008-07-17 01:50 . 2008-08-12 03:08 15,607 --a------ C:\is.html
2008-07-16 20:26 . 2008-07-16 20:26 <DIR> d-------- C:\Documents and Settings\xp\Application Data\Media Player Classic
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-16 01:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-15 23:27 --------- d-----w C:\Program Files\PowerArchiver
2008-08-15 11:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 13:10 --------- d-----w C:\Documents and Settings\xp\Application Data\Alien Skin
2008-07-07 13:08 --------- d-----w C:\Program Files\Alien Skin
2008-06-29 22:53 --------- d-----w C:\Program Files\MSN Messenger
2008-06-29 22:53 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-06-24 18:25 --------- d-----w C:\Documents and Settings\xp\Application Data\ACD Systems
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:38 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-23 09:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
2008-06-23 09:29 --------- d-----w C:\Program Files\GlobalSCAPE
2008-06-23 09:29 --------- d-----w C:\Documents and Settings\xp\Application Data\GlobalSCAPE
2008-06-23 09:28 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-23 07:54 --------- d-----w C:\Program Files\Ipswitch
2008-06-23 04:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-06-23 04:43 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-23 04:43 --------- d-----w C:\Program Files\Bonjour
2008-06-23 04:35 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-06-22 23:10 --------- d-----w C:\Program Files\WIDCOMM
2008-06-22 23:07 --------- d-----w C:\Program Files\Broadcom
2008-06-22 22:34 --------- d-----w C:\Program Files\Creative
2008-06-22 22:34 --------- d-----w C:\Program Files\Common Files\Reallusion
2008-06-22 22:33 --------- d-----w C:\Program Files\Dell
2008-06-22 22:33 --------- d-----w C:\Program Files\Creative Live! Cam
2008-06-22 22:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-06-22 21:48 --------- d-----w C:\Program Files\Kaspersky Lab
2008-06-22 21:45 --------- d-----w C:\Program Files\Windows Live
2008-06-22 21:41 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-06-22 21:40 10,368 ----a-w C:\WINDOWS\system32\drivers\pfc.sys
2008-06-22 21:40 --------- d-----w C:\Program Files\ACD Systems
2008-06-22 21:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-06-22 21:36 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-06-22 21:36 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-06-22 21:36 --------- d-----w C:\Program Files\Common Files\xing shared
2008-06-22 21:36 --------- d-----w C:\Program Files\Common Files\Real
2008-06-22 21:35 --------- d-----w C:\Program Files\Real
2008-06-22 21:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\ConeXware
2008-06-22 19:59 --------- d-----w C:\Documents and Settings\xp\Application Data\Creative
2008-06-22 19:56 --------- d-----w C:\Documents and Settings\xp\Application Data\Reallusion
2008-06-22 19:53 --------- d-----w C:\Program Files\Microsoft Works
2008-06-22 19:48 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-22 18:07 --------- d-----w C:\Program Files\Marvell
2008-06-22 18:05 --------- d-----w C:\Documents and Settings\xp\Application Data\TMP
2008-06-22 18:02 --------- d-----w C:\Documents and Settings\xp\Application Data\InstallShield
2008-06-22 17:59 --------- d-----w C:\Program Files\CONEXANT
2008-06-22 17:55 --------- d-----w C:\Program Files\SigmaTel
2008-06-22 17:50 --------- d-----w C:\Program Files\Intel
2008-06-22 17:36 --------- d-----w C:\Program Files\DIFX
2008-06-22 16:50 --------- d-----w C:\Program Files\microsoft frontpage
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-12 18:36 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\divx.dll
2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{3F1CEB16-3615-47ED-B153-3E98A4B9F3F5}]
2008-08-15 21:02 27648 --a------ C:\WINDOWS\system32\sysani.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"PowerArchiver Tray"="C:\Program Files\PowerArchiver\PASTARTER.EXE" [2007-11-30 18:08 140328]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:55 5674352]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 11:06 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-11-16 00:33 141848]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-11-16 00:32 166424]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-11-16 00:33 137752]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2007-10-10 05:17 2183168]
"DELL Webcam Manager"="C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-28 02:43 118784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-23 00:36 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 01:56 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-25 04:28:28 622653]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"VIDC.XVID"= xvid.dll
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\GlobalSCAPE\\CuteFTP 8 Professional\\ftpte.exe"=
"E:\\برامج\\برنامج قوي لبرمجة وتحرير الـPHP باخر اصدار له PHP Designer 2008 Professional v6.0\\phpDesigner2008.exe"=
"C:\\Program Files\\phpDesigner 2008\\phpDesigner2008.exe"=
"C:\\Program Files\\CyberLink\\PowerDirector\\PDR.exe"=
"E:\\E?C??\\E??C?? ??? ?E???E ?E???? C?UPHP ECI? C?IC? ?? PHP Designer 2008 Professional v6.0\\phpDesigner2008.exe"=
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Device Detector - DevDetect.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.sa/
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: Download all links with IDM - C:\DOCUME~1\xp\LOCALS~1\Temp\RarSFX1\IEGetAll.htm
O8 -: Download FLV video with IDM - C:\DOCUME~1\xp\LOCALS~1\Temp\RarSFX1\IEGetVL.htm
O8 -: Download with IDM - C:\DOCUME~1\xp\LOCALS~1\Temp\RarSFX1\IEExt.htm
O8 -: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 -: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 -: {6924091F-CD97-41E1-B1D4-D9079409D413} - hxxp://ghalaa.digivoice.net:1999/talk.cab
C:\WINDOWS\Downloaded Program Files\talk.inf
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\mfc42.dll
C:\WINDOWS\system32\olepro32.dll
C:\WINDOWS\Downloaded Program Files\imcv1.dll
O16 -: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} - hxxp://ghalaa.digivoice.net:1999/ReadUid.CAB
C:\WINDOWS\Downloaded Program Files\ReadUid.INF
C:\WINDOWS\Downloaded Program Files\ReadUid.ocx
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-16 04:54:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-16 4:56:08
ComboFix-quarantined-files.txt 2008-08-16 01:55:20
Pre-Run: 24,832,888,832 bytes free
Post-Run: 25,884,917,760 bytes free
210 --- E O F --- 2008-08-16 00:03:06