حياك الله اخوي انتر
الله يحفظك ومشكور على المساعدة
عملت الخطوات اللي قلتلي عليها وهذا التقرير
ComboFix 08-10-11.04 - omar 10/12/2008 21:53:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.214 [GMT 2:00]
Running from: C:\Documents and Settings\omar\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\PCHealthCenter
C:\Program Files\PCHealthCenter\
0.gif
C:\Program Files\PCHealthCenter\1.ico
C:\Program Files\PCHealthCenter\2.ico
C:\Program Files\PCHealthCenter\5.exe
C:\Program Files\PCHealthCenter\sc.html
C:\Program Files\PCHealthCenter\Thumbs.db
C:\Program Files\SAV
C:\Program Files\SAV\sav.cpl
C:\Program Files\SAV\sav.exe
C:\Program Files\SAV\sav0.dat
C:\Program Files\SAV\sav1.dat
C:\WINDOWS\system32\SAV.cpl
.
((((((((((((((((((((((((( Files Created from 2008-09-12 to 2008-10-12 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-12 19:56 269,588 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-12 19:56 20,048,928 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-12 19:56 104,636 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-12 19:56 1,104,672 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-12 19:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-10-06 18:14 --------- d-----w C:\Program Files\Safari
2008-10-05 19:28 --------- d-----w C:\Documents and Settings\omar\Application Data\Apple Computer
2008-10-05 19:23 --------- d-----w C:\Program Files\Apple Software Update
2008-10-05 19:18 --------- d-----w C:\Program Files\iTunes
2008-10-05 19:18 --------- d-----w C:\Program Files\iPod
2008-10-05 19:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-05 19:16 --------- d-----w C:\Program Files\QuickTime
2008-10-05 19:16 --------- d-----w C:\Program Files\Common Files\Apple
2008-10-05 18:56 --------- d-----w C:\Program Files\Bonjour
2008-09-21 10:30 --------- d-----w C:\Program Files\Cartoon Network
2008-09-17 16:03 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-11 22:12 --------- d-----w C:\Program Files\MoneyMania
2008-09-11 21:27 --------- d-----w C:\Program Files\Chroma-Ways
2008-09-11 21:27 --------- d-----w C:\Program Files\AirXonix
2008-09-11 14:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-09 22:27 --------- d-----w C:\Documents and Settings\omar\Application Data\Skype
2008-09-09 22:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-09-09 22:04 --------- d-----w C:\Documents and Settings\omar\Application Data\skypePM
2008-09-04 15:36 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-09-04 15:36 --------- d-----w C:\Documents and Settings\omar\Application Data\SUPERAntiSpyware.com
2008-09-04 15:34 --------- d-----w C:\Documents and Settings\omar\Application Data\Paltalk
2008-09-04 15:33 --------- d-----w C:\Program Files\Agent 2002
2008-08-31 23:14 --------- d-----w C:\Program Files\Java
2008-08-31 23:13 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-08-31 23:13 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-08-29 14:43 25,088 ----a-w C:\WINDOWS\system32\msxml3a.dll
2008-08-29 08:18 87,336 ----a-w C:\WINDOWS\system32\dns-sd.exe
2008-08-29 07:53 61,440 ----a-w C:\WINDOWS\system32\dnssd.dll
2008-08-23 12:33 --------- d-----w C:\Program Files\Google
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-03-24 17:07 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2008-02-04 07:21 32 -c--a-r C:\Documents and Settings\All Users\hash.dat
2008-06-02 18:34 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008060220080603\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 05:59 PM 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [12/16/2005 12:57 PM 94208]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [04/14/2008 05:59 PM 1695232]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [10/18/2007 12:34 PM 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 10:50 AM 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [02/06/2008 11:15 PM 185896]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [11/24/2006 01:06 AM 487424]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [09/06/2008 03:09 PM 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [10/01/2008 06:57 PM 289576]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"VTTimer"="VTTimer.exe" [02/06/2008 08:51 PM 53248 C:\WINDOWS\system32\VTTimer.exe]
"S3Trayp"="S3trayp.exe" [02/06/2008 08:51 PM 159744 C:\WINDOWS\system32\S3Trayp.exe]
"SkyTel"="SkyTel.EXE" [02/06/2008 08:51 PM 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [02/06/2008 08:51 PM 16264192 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 05:59 PM 15360]
C:\Documents and Settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-02-07 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.mpegacm "= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\mpegacm.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [03/25/2008 08:07 PM 24592]
R3 S3G700;S3G700;C:\WINDOWS\system32\DRIVERS\S3G700m.sys [02/06/2008 08:51 PM 792576]
S3 se44bus;Sony Ericsson Device 068 driver (WDM);C:\WINDOWS\system32\DRIVERS\se44bus.sys [11/30/2006 02:58 PM 61536]
S3 se44mdfl;Sony Ericsson Device 068 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\se44mdfl.sys [11/30/2006 02:58 PM 9360]
S3 se44mdm;Sony Ericsson Device 068 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\se44mdm.sys [11/30/2006 02:58 PM 97088]
S3 se44mgmt;Sony Ericsson Device 068 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\se44mgmt.sys [11/30/2006 02:58 PM 88624]
S3 se44nd5;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (NDIS);C:\WINDOWS\system32\DRIVERS\se44nd5.sys [11/30/2006 02:58 PM 18704]
S3 se44obex;Sony Ericsson Device 068 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\se44obex.sys [11/30/2006 02:58 PM 86432]
S3 se44unic;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (WDM);C:\WINDOWS\system32\DRIVERS\se44unic.sys [11/30/2006 02:58 PM 90800]
.
s of the 'Scheduled Tasks' folder
2008-10-05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [07/30/2008 12:34 PM]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Antivirus - C:\Program Files\SAV\sav.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\omar\Application Data\Mozilla\Firefox\Profiles\y1cn4zet.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.googlE.com/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-12 21:57:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Documents and Settings\omar\C:\WINDOWS\explorer.exe
.
**************************************************************************
.
Completion time: 10/12/2008 22:04:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-12 20:04:13
Pre-Run: 8,877,690,880 bytes free
Post-Run: 8,793,874,432 bytes free
173 --- E O F --- 2008-08-31 23:11:23