بارك الله فيكم هذا تقرير البرنامج الاول
ComboFix 08-10-15.05 - badr 2008-10-15 23:36:26.2 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.572 [GMT 2:00]
Running from: C:\Documents and Settings\badr\My Documents\Downloads\Programs\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\الاسرة\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\system32\dao350.dll
.
((((((((((((((((((((((((( Files Created from 2008-09-15 to 2008-10-15 )))))))))))))))))))))))))))))))
.
2008-10-16 00:26 . 2008-10-16 00:26 <DIR> d-------- C:\مجلد جديد (2)
2008-10-15 21:59 . 2007-06-19 10:20 684,248 -ra------ C:\WINDOWS\system32\drivers\cfosspeed.sys
2008-10-15 21:59 . 2007-06-19 10:20 281,816 --a------ C:\WINDOWS\system32\cfosspeed.dll
2008-10-15 21:57 . 2008-10-15 21:57 112,144 --a------ C:\WINDOWS\system32\drivers\kl1.sys
2008-10-15 21:30 . 2008-10-15 21:57 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-15 21:30 . 2008-10-15 21:57 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-15 21:30 . 2008-10-15 21:57 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-15 21:30 . 2008-10-15 21:57 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 94208]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-08-31 22879528]
"IDMan"="E:\البرامج\Download\idm\IDMan.exe" [2007-07-28 1360304]
"wsp"="D:\star sat\مجلد جديد (2)\wsp.exe" [2006-04-14 276480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSRaid"="C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe" [2006-01-23 872448]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-25 98304]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-27 185896]
"SiSPower"="SiSPower.dll" [2006-06-28 C:\WINDOWS\system32\SiSPower.dll]
"SoundMan"="SOUNDMAN.EXE" [2006-06-20 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
C:\Documents and Settings\ںéں«©،\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Ela-Salaty.lnk - C:\Program Files\Ela-Salaty\Salaty.exe [2006-07-22 4739584]
C:\DOCUME~1\ALLUSE~1\A007~1\7D39~1\D51D~1\
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2006-12-24 262144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.DIV3"= DIVXc32.dll
"vidc.DIV4"= DIVXc32f.dll
"msacm.divxa32"= DivXa32.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^BlueSoleil.lnk]
path=C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\BlueSoleil.lnk
backup=C:\WINDOWS\pss\BlueSoleil.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2007-05-14 23:22 35328 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
*Newly Created Service* - CATCHME
*Newly Created Service* - CLR_OPTIMIZATION_V2.0.50727_32
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-NWEReboot - (no file)
Notify-WgaLogon - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/intl/ar/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 -: Download All Links with IDM - E:\البرامج\Download\idm\IEGetAll.htm
O8 -: Download FLV video with IDM - E:\البرامج\Download\idm\IEGetVL.htm
O8 -: Download with IDM - E:\البرامج\Download\idm\IEExt.htm
O17 -: HKLM\CCS\Interface\{F1015915-A694-428A-8EAB-00FD001B0BE1}: NameServer = 41.221.20.4 193.251.169.165
O16 -: Microsoft XML Parser for Java -
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-15 23:37:52
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-15 23:38:34
ComboFix-quarantined-files.txt 2008-10-15 21:38:32
Pre-Run: 16 223 911 936 bytes free
Post-Run: 16,380,395,520 bytes free
109 --- E O F --- 2007-12-27 20:55:42