هذا التقرير حق الخطوه الاولي وجاري عمل الخطوه الثانيه
ComboFix 08-08-26.03 - moon 08/27/2008 15:49:48.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.107 [GMT 3:00]
Running from: C:\Documents and Settings\moon\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\kakle.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-27 to 2008-08-27 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-27 12:56 --------- d-----w C:\Documents and Settings\moon\Application Data\Skype
2008-08-27 12:54 352,800 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-08-27 12:54 21,853,472 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-27 12:53 37,208 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-08-27 12:53 301,988 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-27 12:48 --------- d-----w C:\Documents and Settings\moon\Application Data\DMCache
2008-08-27 12:12 --------- d-----w C:\Documents and Settings\moon\Application Data\IDM
2008-08-27 12:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-27 12:11 --------- d-----w C:\Documents and Settings\moon\Application Data\skypePM
2008-08-26 16:41 --------- d-----w C:\Program Files\Smart Virus Remover
2008-08-24 08:28 --------- d-----w C:\Documents and Settings\moon\Application Data\uTorrent
2008-08-24 01:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD X Studios
2008-08-19 23:12 --------- d-----w C:\Documents and Settings\moon\Application Data\TuneUp Software
2008-08-19 09:07 --------- d-----w C:\Program Files\MSN Messenger
2008-08-13 01:51 --------- d-----w C:\Program Files\iVocalize Web Conference 4
2008-08-07 19:14 --------- d-----w C:\Program Files\The KMPlayer
2008-08-06 16:26 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-08-05 15:52 --------- d-----w C:\Documents and Settings\moon\Application Data\Thinstall
2008-08-03 19:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-07-29 14:06 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-29 14:06 --------- d-----w C:\Program Files\AoA Audio Extractor
2008-07-29 13:58 90,112 ----a-w C:\WINDOWS\system32\agsaami.dll
2008-07-29 13:58 610,304 ----a-w C:\WINDOWS\system32\agsaamg.dll
2008-07-29 13:58 372,736 ----a-w C:\WINDOWS\system32\agsaamc.dll
2008-07-29 13:58 2,535,424 ----a-w C:\WINDOWS\system32\agsaamj.dll
2008-07-29 13:58 196,608 ----a-w C:\WINDOWS\system32\maag.dll
2008-07-29 13:58 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-07-29 13:58 1,245,184 ----a-w C:\WINDOWS\system32\bkll.dll
2008-07-29 13:58 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2008-07-29 13:58 --------- d-----w C:\Program Files\Real_SC
2008-07-29 13:54 --------- d-----w C:\Documents and Settings\moon\Application Data\Ashampoo
2008-07-27 15:32 --------- d-----w C:\Program Files\CONEXANT
2008-07-24 10:56 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-07-20 22:43 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-07-20 22:42 --------- d-----w C:\Program Files\Skype
2008-07-20 22:42 --------- d-----w C:\Program Files\Common Files\Skype
2008-07-20 22:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-07-19 22:22 155,995 ----a-w C:\WINDOWS\java\Packages\HBNTBPV5.ZIP
2008-07-19 02:15 --------- d-----w C:\Program Files\Hotspot Shield
2008-07-17 23:59 --------- d-----w C:\Documents and Settings\moon\Application Data\Talkback
2008-07-17 23:57 --------- d-----w C:\Program Files\Real
2008-07-17 23:57 --------- d-----w C:\Program Files\Common Files\xing shared
2008-07-17 23:56 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-07-17 23:56 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-07-17 23:56 --------- d-----w C:\Program Files\Common Files\Real
2008-07-17 23:51 --------- d-----w C:\Program Files\Paltalk Messenger
2008-07-17 23:51 --------- d-----w C:\Program Files\AskPBar
2008-07-17 23:41 --------- d-----w C:\Documents and Settings\moon\Application Data\Paltalk
2008-07-17 20:51 --------- d-----w C:\Program Files\Circle Developement
2008-07-17 20:50 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-07-17 19:56 --------- d-----w C:\Program Files\Opera
2008-07-17 19:38 --------- d-----w C:\Program Files\Windows Live
2008-07-17 19:24 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-07-17 19:05 --------- d-----w C:\Program Files\Kaspersky Lab
2008-07-17 19:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-17 18:20 --------- d-----w C:\Program Files\Realtek Sound Manager
2008-07-17 18:20 --------- d-----w C:\Program Files\Realtek AC97
2008-07-17 18:20 --------- d-----w C:\Program Files\AvRack
2008-07-17 18:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-17 18:17 --------- d-----w C:\Program Files\S3
2008-07-17 18:17 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-17 17:15 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-07 20:27 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:10 664,576 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:47 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0A94B116-4504-4e26-AB05-E61E474AA38B}"= "C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL" [07/18/2008 02:51 AM 61440]
[HKEY_CLASSES_ROOT\clsid\{0a94b116-4504-4e26-ab05-e61e474aa38b}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [01/19/2007 12:55 PM 5674352]
"AFProg"="C:\Program Files\Hotspot Shield\AnchorFree\ctrl\AFController.exe" [07/23/2006 12:44 PM 118784]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [12/07/2007 03:08 PM 21686568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [07/18/2008 02:56 AM 185896]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [02/08/2008 06:36 PM 227856]
"VTTimer"="VTTimer.exe" [03/07/2005 10:33 PM 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [04/11/2006 11:06 AM 176128 C:\WINDOWS\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [11/17/2006 12:42 AM 577536 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 06:59 PM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\English\\setup.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"C:\\Program Files\\Opera\\opera.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 7.0\\avp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Documents and Settings\\moon\\Application Data\\Thinstall\\{EEE54C34-08A8-46F3-929A-B9282DE2A31E}\\400000a500002i\\uTorrent.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [12/13/2007 01:28 PM]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [07/23/2006 12:44 PM]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\moon\Application Data\Mozilla\Firefox\Profiles\6bp94fxn.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-27 15:54:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Paltalk Messenger\paltalk.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 08/27/2008 16:01:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-27 13:01:20
Pre-Run: 73,281,323,008 bytes free
Post-Run: 73,628,913,664 bytes free
152 --- E O F --- 2008-08-19 19:45:14