سويت مثل ماقلت يابو ريما .
الكاسبر طار من عند الساعه وتغيرت الخلفيه الي بسطح المكتب صارت زرقاء .
وهذا التقريرر .
ComboFix 08-10-21.03 - user 10/22/2008 16:33:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.600 [GMT 3:00]
Running from: C:\Documents and Settings\user\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Bifrost
C:\Program Files\bifrost\server.exe
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-09-22 to 2008-10-22 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-22 13:41 --------- d--h--w C:\Program Files\Bifrost
2008-10-22 13:40 --------- d-----w C:\Documents and Settings\user\Application Data\DMCache
2008-10-22 13:39 4,240 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-22 13:39 311,328 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-22 13:39 17,704 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-22 13:39 1,591,328 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-22 13:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-10-22 13:27 --------- d-----w C:\Program Files\Registry Fast
2008-10-22 13:27 --------- d-----w C:\Program Files\Registry Compressor
2008-10-22 13:27 --------- d-----w C:\Program Files\No-IP
2008-10-22 13:27 --------- d-----w C:\Program Files\Internet Download Manager
2008-10-22 13:05 2,456 ----a-w C:\WINDOWS\system32\tmp.reg
2008-10-22 13:04 --------- d-----w C:\Documents and Settings\user\Application Data\IDM
2008-10-15 00:31 --------- d-----w C:\Program Files\TeamViewer3
2008-10-13 11:00 --------- d-----w C:\Documents and Settings\user\Application Data\axismediaball
2008-10-11 00:09 --------- d-----w C:\Documents and Settings\user\Application Data\Skype
2008-10-10 22:12 --------- d-----w C:\Documents and Settings\user\Application Data\skypePM
2008-10-07 00:47 344,064 ----a-w C:\WINDOWS\system32\dkll.dll
2008-10-07 00:47 196,608 ----a-w C:\WINDOWS\system32\maag.dll
2008-10-07 00:47 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-10-07 00:47 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2008-10-07 00:47 --------- d-----w C:\Program Files\Ozone
2008-10-06 16:19 --------- d-----w C:\Program Files\NewLive All Media To Mp3 Converter
2008-10-02 12:33 --------- d-----w C:\Documents and Settings\user\Application Data\CallingID
2008-10-02 12:28 --------- d--h--w C:\Documents and Settings\All Users\Application Data\{CC7B5EC3-5AB0-4555-9BBD-0BDBFA2B459E}
2008-10-02 12:28 --------- d-----w C:\Program Files\ExPLabs.com
2008-10-02 12:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\ExPLabs.com
2008-10-02 08:30 --------- d-----w C:\Documents and Settings\user\Application Data\Media Player Classic
2008-10-02 05:01 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-10-02 05:01 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-10-01 06:32 --------- d-----w C:\Program Files\a-squared Free
2008-10-01 05:48 --------- d-----w C:\Program Files\Kaspersky Lab
2008-10-01 05:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-01 00:10 --------- d-----w C:\Documents and Settings\user\Application Data\Paltalk
2008-09-30 23:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-09-27 01:12 --------- d-----w C:\Documents and Settings\user\Application Data\CyberLink
2008-09-21 18:02 --------- d-----w C:\Program Files\MSXML 6.0
2008-09-21 03:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Okay Way Sixth Exit
2008-09-21 03:20 --------- d-----w C:\Documents and Settings\user\Application Data\TeamViewer
2008-09-21 02:36 --------- d-----w C:\Program Files\FLV2
2008-09-20 23:45 --------- d-----w C:\Program Files\Circle Developement
2008-09-20 22:49 --------- d-----w C:\Program Files\MSN Messenger
2008-09-20 22:49 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-20 21:38 --------- d-----w C:\Program Files\Windows Live
2008-09-20 21:38 --------- d-----w C:\Program Files\axismediaball
2008-09-20 20:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-09-20 20:25 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-20 20:25 --------- d-----w C:\Program Files\CyberLink
2008-09-20 20:24 --------- d-----w C:\Program Files\QuickTime
2008-09-20 20:23 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-09-20 20:23 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-09-20 20:23 --------- d-----w C:\Program Files\Real
2008-09-20 20:23 --------- d-----w C:\Program Files\Common Files\xing shared
2008-09-20 20:23 --------- d-----w C:\Program Files\Common Files\Real
2008-09-20 20:23 --------- d-----w C:\Documents and Settings\user\Application Data\GRETECH
2008-09-20 20:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-09-20 20:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\GRETECH
2008-09-20 20:22 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-09-20 20:22 --------- d-----w C:\Program Files\GRETECH
2008-09-20 20:19 --------- d-----w C:\Program Files\Nokia
2008-09-20 20:19 --------- d-----w C:\Program Files\Common Files\Nokia
2008-09-20 20:19 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-20 20:18 --------- d-----w C:\Program Files\Skype
2008-09-20 20:18 --------- d-----w C:\Program Files\Common Files\Skype
2008-09-20 20:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-09-20 20:17 --------- d-----w C:\Program Files\Paltalk Messenger
2008-09-20 20:16 155,995 ----a-w C:\WINDOWS\java\Packages\2B7NZJJH.ZIP
2008-09-20 20:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-09-20 20:04 --------- d-----w C:\Program Files\Microsoft.NET
2008-09-20 20:04 --------- d-----w C:\Program Files\Microsoft Works
2008-09-20 19:55 --------- d-----w C:\Program Files\WIDCOMM
2008-09-20 19:51 --------- d-----w C:\Program Files\Broadcom
2008-09-20 19:49 356,352 ----a-w C:\WINDOWS\system32\AegisI5Installer.exe
2008-09-20 19:49 21,393 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-09-20 19:49 21,393 ----a-w C:\WINDOWS\AegisP.sys
2008-09-20 19:49 --------- d-----w C:\Program Files\Intel
2008-09-20 19:49 --------- d-----w C:\Documents and Settings\user\Application Data\Intel
2008-09-20 19:49 --------- d-----w C:\Documents and Settings\NetworkService\Application Data\Intel
2008-09-20 19:49 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Intel
2008-09-20 19:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intel
2008-09-20 19:47 --------- d-----w C:\Program Files\CONEXANT
2008-09-20 19:44 --------- d-----w C:\Program Files\Synaptics
2008-09-20 19:42 --------- d-----w C:\Program Files\Realtek
2008-09-20 19:41 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-09-20 19:34 --------- d-----w C:\Documents and Settings\user\Application Data\InstallShield
2008-09-20 19:13 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [01/19/2007 12:55 PM 5674352]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [10/21/2008 12:18 PM 932864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [09/20/2008 11:23 PM 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [09/20/2008 11:24 PM 77824]
"LinkScanner Monitor"="C:\Program Files\ExPLabs.com\LinkScanner\LinkScannerMonitor.exe" [08/21/2007 07:00 AM 1742104]
"CheckRegDefragService"="C:\PROGRA~1\REGIST~2\rbcs.exe" [09/22/2004 11:18 PM 299520]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
C:\Documents and Settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-04-01 568176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
--------- 06/11/2005 02:51 PM 53248 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
-ra------ 06/13/2007 07:55 AM 162584 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
--a------ 03/21/2007 01:00 PM 174872 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
-ra------ 06/13/2007 07:56 AM 142104 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 04/16/2007 11:22 AM 970752 C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
--a------ 04/16/2007 11:24 AM 819200 C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 01/19/2007 12:55 PM 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
-ra------ 06/13/2007 07:55 AM 138008 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 09/20/2008 11:24 PM 77824 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 11/02/2004 08:24 PM 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 08/11/2008 05:46 PM 21741864 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 12/16/2005 11:32 AM 761945 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 05/03/2005 01:43 PM 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 05/28/2007 11:32 AM 16132608 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\TeamViewer3\\TeamViewer.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\english\\setup.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM 26640]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}]
C:\Program Files\Bifrost\server.exe s
.
s of the 'Scheduled Tasks' folder
2008-10-22 C:\WINDOWS\Tasks\ACD640479189F043.job
- c:\docume~1\user\applic~1\axisme~1\PLAN REGS MEET.exe []
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-CheckRegDefragService - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\x5vyi7f0.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-22 16:40:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
C:\Program Files\Internet Explorer\IEXPLORE.EXE [2568] 0x84BD5DA0
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Bifrost\server.exe
.
**************************************************************************
.
Completion time: 10/22/2008 16:43:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-22 13:43:12
Pre-Run: 50,672,676,864 bytes free
Post-Run: 51,180,429,312 bytes free
218 --- E O F --- 2008-09-21 23:20:09