خلصنا الخطوة الاولى والثانية ( وحبيت اعرف كيف ارفقلك التقرير لاني ماعرف )
وهذا التقرير
ComboFix 08-09-05.02 - User 2008-09-07 0:24:42.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.971.1033.18.1595 [GMT 4:00]
Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\systeminfo.dll
.
((((((((((((((((((((((((( Files Created from 2008-08-06 to 2008-09-06 )))))))))))))))))))))))))))))))
.
2008-09-06 21:44 . 2008-09-07 00:17 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-09-06 20:07 . 2008-09-05 19:32 165,888 --a------ C:\WINDOWS\system32\sav.cpl
2008-09-06 20:07 . 2008-09-06 20:07 116,228 --a------ C:\WINDOWS\system32\msxml71.dll
2008-09-05 07:44 . 2008-09-06 07:17 2,359,350 --a------ C:\WINDOWS\User.bmp
2008-08-30 02:24 . 2008-08-30 02:24 <DIR> d-------- C:\Program Files\Ashampoo
2008-08-28 16:23 . 2008-08-28 16:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DFX
2008-08-28 15:13 . 2008-08-28 15:39 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-08-26 04:55 . 2008-08-27 22:14 <DIR> d-------- C:\Program Files\VstPlugins
2008-08-26 04:55 . 2006-06-20 12:56 225,280 --a------ C:\WINDOWS\system32\rewire.dll
2008-08-26 04:54 . 2002-07-08 02:14 1,294,336 --a------ C:\WINDOWS\system32\vorbis.acm
2008-08-26 04:52 . 2008-08-27 22:14 <DIR> d-------- C:\Program Files\Image-Line
2008-08-25 01:23 . 2008-08-25 01:23 <DIR> d--h----- C:\WINDOWS\PIF
2008-08-25 01:23 . 2008-08-25 01:47 <DIR> d-------- C:\Program Files\ClubDJ Pro
2008-08-25 01:23 . 1999-03-24 00:06 1,046,288 --a------ C:\WINDOWS\system32\msjet35.dll
2008-08-25 01:23 . 1997-01-12 23:00 37,136 --a------ C:\WINDOWS\system32\MSJINT35.DLL
2008-08-25 01:23 . 1996-12-02 17:44 24,336 --a------ C:\WINDOWS\system32\MSJTER35.DLL
2008-08-24 22:54 . 2008-06-27 19:32 211 --ahs---- C:\BOOT.BKK
2008-08-24 22:41 . 2008-08-24 22:41 <DIR> d-------- C:\Program Files\TGTSoft
2008-08-24 22:36 . 2008-09-06 21:46 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-08-24 22:36 . 2008-09-06 21:46 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-08-24 22:08 . 2008-08-24 22:08 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-08-24 22:06 . 2008-08-24 22:06 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-08-24 22:06 . 2008-08-26 02:23 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-08-24 22:06 . 2006-09-16 03:02 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-08-20 15:56 . 2008-09-05 07:30 <DIR> d-------- C:\Documents and Settings\User\Application Data\IDM
2008-08-20 15:56 . 2008-09-07 00:24 <DIR> d-------- C:\Documents and Settings\User\Application Data\DMCache
2008-08-20 15:55 . 2008-08-26 02:23 <DIR> d-------- C:\Program Files\Internet Download Manager
2008-08-18 06:47 . 2008-08-18 06:48 <DIR> d-------- C:\Program Files\BitSpirit
2008-08-18 06:40 . 2008-08-22 11:25 <DIR> d-------- C:\Downloads
2008-08-18 06:31 . 2008-08-18 06:31 <DIR> d-------- C:\Documents and Settings\User\Application Data\BitSpirit
2008-08-17 07:32 . 2008-08-17 07:40 <DIR> d-------- C:\Program Files\TorrentMan
2008-08-17 07:32 . 2008-08-17 07:40 <DIR> d-------- C:\Program Files\Conduit
2008-08-16 20:46 . 2008-08-16 20:46 <DIR> d-------- C:\Program Files\Winamp Toolbar
2008-08-16 20:46 . 2008-08-16 20:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2008-08-16 20:45 . 2008-08-16 20:46 <DIR> d-------- C:\Program Files\Winamp Remote
2008-08-16 20:45 . 2008-08-16 20:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-08-16 20:36 . 2008-08-28 17:01 <DIR> d-------- C:\Program Files\Winamp
2008-08-16 20:36 . 2008-08-17 00:25 <DIR> d-------- C:\Documents and Settings\User\Application Data\Winamp
2008-08-16 12:29 . 2008-08-16 12:29 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\PC Suite
2008-08-16 12:28 . 2004-08-04 03:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-08-16 01:57 . 2008-08-16 01:58 <DIR> d-------- C:\Documents and Settings\User\Application Data\Media Player Classic
2008-08-16 00:14 . 2008-08-16 00:14 244 --ah----- C:\sqmnoopt04.sqm
2008-08-16 00:14 . 2008-08-16 00:14 232 --ah----- C:\sqmdata04.sqm
2008-08-15 22:31 . 2008-08-15 22:31 <DIR> d-------- C:\Documents and Settings\User\Application Data\Thinstall
2008-08-15 22:31 . 2008-08-15 22:31 <DIR> d-------- C:\Documents and Settings\User\Application Data\Avant Profiles
2008-08-15 22:20 . 2008-08-15 22:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BlazeVideo
2008-08-15 22:19 . 2004-08-04 00:56 363,520 --a------ C:\WINDOWS\system32\psisdecd.dll
2008-08-15 22:19 . 2004-08-04 00:56 363,520 --a--c--- C:\WINDOWS\system32\dllcache\psisdecd.dll
2008-08-15 22:19 . 2004-08-04 00:56 56,832 --a------ C:\WINDOWS\system32\msdvbnp.ax
2008-08-15 22:19 . 2004-08-04 00:56 56,832 --a--c--- C:\WINDOWS\system32\dllcache\msdvbnp.ax
2008-08-15 22:19 . 2004-08-04 00:56 33,280 --a------ C:\WINDOWS\system32\psisrndr.ax
2008-08-15 22:19 . 2004-08-04 00:56 33,280 --a--c--- C:\WINDOWS\system32\dllcache\psisrndr.ax
2008-08-15 22:02 . 2008-08-15 22:28 <DIR> d-------- C:\Program Files\MJ Studio 2008
2008-08-15 21:59 . 2008-08-15 21:59 <DIR> d-------- C:\Program Files\Real Alternative
2008-08-15 21:58 . 2008-08-15 22:01 <DIR> d-------- C:\Program Files\The KMPlayer
2008-08-15 21:44 . 2008-08-15 21:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-08-09 19:16 . 2008-08-09 19:25 <DIR> d-------- C:\Program Files\Your Uninstaller 2008
2008-08-09 19:16 . 2008-08-09 19:16 <DIR> d-------- C:\Documents and Settings\User\Application Data\URSoft
2008-08-09 19:16 . 2008-09-06 21:13 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-09 03:04 . 2008-08-30 02:27 <DIR> d-------- C:\Program Files\radio program
2008-08-09 01:37 . 2008-08-09 01:37 <DIR> d-------- C:\WINDOWS\Sun
2008-08-09 01:37 . 2008-09-07 00:23 <DIR> d-------- C:\Documents and Settings\User\Application Data\LimeWire
2008-08-09 01:36 . 2008-08-09 01:36 <DIR> d-------- C:\Program Files\Sun
2008-08-09 01:36 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-09 01:35 . 2008-08-09 01:36 <DIR> d-------- C:\Program Files\Java
2008-08-09 01:28 . 2008-08-09 01:28 <DIR> d-------- C:\Program Files\Common Files\Java
2008-08-09 01:20 . 2008-08-19 13:05 <DIR> d-------- C:\Program Files\LimeWire
2008-08-08 01:32 . 2008-08-08 01:41 <DIR> d-------- C:\Program Files\Unlocker
2008-08-08 01:32 . 2008-08-08 01:36 <DIR> d-------- C:\Documents and Settings\User\Application Data\Desktopicon
2008-08-07 22:45 . 2008-08-07 22:45 <DIR> d-------- C:\Documents and Settings\User\Application Data\Ahead
2008-08-07 19:50 . 2008-08-07 19:50 <DIR> d-------- C:\Program Files\Acoustica MP3 Audio Mixer
2008-08-07 19:50 . 2004-02-12 14:44 352,256 --a------ C:\WINDOWS\system32\eSellerateEngine.dll
2008-08-07 02:28 . 2008-08-07 02:28 <DIR> d-------- C:\Documents and Settings\User\Application Data\Nokia Multimedia Player
2008-08-06 14:11 . 2008-08-06 14:11 <DIR> d-------- C:\Documents and Settings\User\Phone Browser
2008-08-06 14:09 . 2008-08-06 14:11 <DIR> d-------- C:\Documents and Settings\User\Application Data\Nokia
2008-08-06 14:09 . 2008-08-26 02:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Suite
2008-08-06 14:08 . 2008-08-06 14:08 <DIR> d-------- C:\Program Files\DIFX
2008-08-06 14:08 . 2008-08-06 14:08 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-08-06 14:08 . 2008-08-06 14:08 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-08-06 14:08 . 2008-08-06 14:08 <DIR> d-------- C:\Documents and Settings\User\Application Data\PC Suite
2008-08-06 14:07 . 2008-08-06 14:09 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-08-06 14:07 . 2008-08-06 14:07 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-08-06 14:07 . 2008-08-06 14:08 <DIR> d-------- C:\Program Files\Nokia
2008-08-06 14:07 . 2007-02-22 11:15 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2008-08-06 14:07 . 2007-02-22 11:15 90,624 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2008-08-06 14:07 . 2007-02-22 11:15 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2008-08-06 14:07 . 2007-02-22 11:15 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2008-08-06 14:07 . 2007-02-22 11:15 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys
2008-08-06 14:07 . 2007-02-22 11:15 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
2008-08-06 00:07 . 2008-08-06 00:07 <DIR> d-------- C:\Documents and Settings\User\Application Data\Leadertech
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-06 20:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-06 20:13 56,564 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-06 20:13 549,920 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-06 20:13 178,268 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-06 20:13 12,363,040 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-05 22:28 --------- d-----w C:\Documents and Settings\User\Application Data\iMesh
2008-08-09 15:22 --------- d-----w C:\Program Files\Common Files\Real
2008-08-08 00:13 --------- d-----w C:\Program Files\AtomixMP3
2008-08-06 22:24 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-08-02 21:27 --------- d-----w C:\Documents and Settings\User\Application Data\AdobeUM
2008-08-02 21:27 --------- d-----w C:\Documents and Settings\User\Application Data\AdobeAUM
2008-08-02 21:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-07-31 21:20 --------- d-----w C:\Program Files\Traduce Gratis
2008-07-24 11:31 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-07-22 13:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-07-19 20:47 --------- d-----w C:\Program Files\iMesh Applications
2008-07-19 20:09 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-07-09 14:34 206,256 ----a-w C:\WINDOWS\system32\idmmbc.dll
2008-06-27 18:48 155,995 ----a-w C:\WINDOWS\java\Packages\SR73NPZB.ZIP
2008-06-27 18:37 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-06-27 18:37 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-06-27 18:35 90,112 ----a-w C:\WINDOWS\system32\agsaami.dll
2008-06-27 18:35 610,304 ----a-w C:\WINDOWS\system32\agsaamg.dll
2008-06-27 18:35 372,736 ----a-w C:\WINDOWS\system32\agsaamc.dll
2008-06-27 18:35 2,535,424 ----a-w C:\WINDOWS\system32\agsaamj.dll
2008-06-27 18:35 196,608 ----a-w C:\WINDOWS\system32\maag.dll
2008-06-27 18:35 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-06-27 18:35 1,245,184 ----a-w C:\WINDOWS\system32\bkll.dll
2008-06-27 18:35 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2008-06-27 16:47 155,995 ----a-w C:\WINDOWS\java\Packages\M06Q1JJ1.ZIP
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2008-07-17 1266992]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{474597C5-AB09-49d6-A4D5-2E8D7341384E}]
2008-07-07 13:21 398768 --a------ C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshIEHelper.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-08-23 932864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-06-27 98304]
"CTSysVol"="C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 90112]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-07-10 36352]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 271360]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-03-01 15872]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]
C:\Documents and Settings\User\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-06-18 147456]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\BitSpirit\\BitSpirit.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 24344]
.
- - - - ORPHANS REMOVED - - - -
BHO-{140BD8E3-C167-11D4-B4A3-080000180323} - (no file)
HKLM-Run-Antivirus - C:\Program Files\SAV\sav.exe
Notify-WgaLogon - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\tn91lfak.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-07 00:26:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-07 0:28:13
ComboFix-quarantined-files.txt 2008-09-06 20:27:56
Pre-Run: 30,104,576,000 bytes free
Post-Run: 30,092,984,320 bytes free
217