أخي الجنتل هذه هي التقارير
تقري log
ComboFix 08-11-03.06 - abosohail 11/04/2008 21:04:03.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.77 [GMT 2:00]
Running from: c:\documents and settings\abosohail\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\10.pif
c:\documents and settings\2.pif
c:\documents and settings\3.pif
c:\documents and settings\6.pif
c:\documents and settings\9.pif
c:\documents and settings\abosohail\Application Data\addon.dat
C:\h.pif
C:\HBGP.PIF
c:\program files\Bifrost
c:\program files\Bifrost\logg.dat
c:\program files\bifrost\server.exe
c:\program files\Common Files\PushWare
c:\program files\Common Files\PushWare\cpush.dll
c:\program files\Common Files\PushWare\Uninst.exe
c:\program files\def.pif
c:\program files\zzToolBar
c:\program files\zzToolBar\IP.dat
c:\program files\zzToolBar\SearchEngineConfig
c:\program files\zzToolBar\ToolBand.dll
c:\program files\zzToolBar\Toolbar_bho.dll
c:\program files\zzToolBar\uISGRLFile.dat
c:\program files\zzToolBar\Uninstall.exe
C:\strategy.txt
C:\tttmm.tep
c:\windows\Downloaded Program Files\SVCHOST.exe
c:\windows\Fonts\svchost.exe
c:\windows\KB611311.log
c:\windows\Poss
c:\windows\Poss\pbhealth.dll
c:\windows\system32\d3d1caps.srg
c:\windows\system32\dllcache\wuauclt.exe
c:\windows\system32\drivers\acpidisk.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\gprmsgse.axz
c:\windows\system32\gscpx32r.det
c:\windows\system32\mprmsgse.axz
c:\windows\system32\msssc.dll
c:\windows\system32\Packet.dll
c:\windows\system32\wacllt.exe
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\system32\wuauclt.exe
c:\windows\TEMP\~my1.tmp
D:\Autorun.inf
D:\HBGP.PIF
E:\Autorun.inf
E:\HBGP.PIF
F:\Autorun.inf
F:\HBGP.PIF
G:\Autorun.inf
G:\HBGP.PIF
H:\Autorun.inf
H:\HBGP.PIF
Infected copy of c:\windows\system32\drivers\beep.sys was found and disinfected
Restored copy from - c:\windows\system32\dllcache\beep.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ACPIDISK
-------\Legacy_DOG0725
-------\Legacy_NPF
-------\Service_acpidisk
-------\Service_dog0725
-------\Service_npf
((((((((((((((((((((((((( Files Created from 2008-10-04 to 2008-11-04 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-04 19:06 4,304 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-04 19:06 4,304 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-04 19:06 18,464 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-04 19:06 1,056 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-10-21 20:03 --------- d-----w c:\documents and settings\abosohail\Application Data\uTorrent
2008-10-21 19:55 --------- d-----w c:\program files\Abdullah AlZaid
2008-10-05 00:02 155,995 ----a-w c:\windows\java\Packages\ZPZDNR1R.ZIP
2008-10-02 22:36 73,216 ----a-w c:\windows\ST6UNST.EXE
2008-10-02 22:36 172,032 ------w c:\windows\Setup1.exe
2008-10-02 22:36 --------- d-----w c:\program files\Golden Al-Wafi Translator
2008-10-02 22:34 --------- d-----w c:\program files\Magic Translator
2008-10-02 21:29 --------- d-----w c:\documents and settings\abosohail\Application Data\ Windows Live
2008-09-27 10:47 --------- d-----w c:\program files\Common Files\Adobe
2008-09-16 14:40 720,896 ----a-w c:\windows\iun6002.exe
2008-09-13 15:08 --------- d-----w c:\documents and settings\abosohail\Application Data\Wildfire
2008-08-07 22:14 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-08-07 22:14 348,160 ----a-w c:\windows\system32\msvcr71.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/03/2004 10:56 PM 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [11/07/2007 03:34 PM 3739672]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [10/02/2007 08:02 AM 2553264]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [08/04/2004 01:06 AM 1667584]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [09/19/2008 05:34 PM 4347120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [10/30/2003 02:09 PM 249856]
"HTpatch"="c:\windows\htpatch.exe" [03/27/2003 08:50 AM 28672]
"tppoll"="c:\program files\Topro\tppoll.exe" [03/02/2005 05:12 PM 24576]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [08/08/2008 12:14 AM 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [08/14/2008 12:21 AM 114688]
"SMSERIAL"="sm56hlpr.exe" [04/26/2004 01:23 AM 569344 c:\windows\sm56hlpr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/03/2004 10:56 PM 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-09-27 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\برامج\\برنامج التورنت\\utorrent.exe"=
R3 DCamUSBIntel;USB Video Camera;c:\windows\system32\Drivers\TP6800.sys [05/18/2006 04:29 PM 197556]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [04/04/2007 02:58 PM 24344]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A6BD446E-5DA7-1FE9-5124-52039BAAE98A}]
c:\program files\Bifrost\server.exe s
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-SYSWIN 1.0.0 - c:\program files\Outlook Express\data\data\SYSWIN.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.eg/
R1 -: HKCU-Internet Settings,ProxyServer = 30.30.30.1:8080
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 -: IDM بواسطة FLV تحميل محتوى فيديو - c:\program files\Internet Download Manager\IEGetVL.htm
O8 -: IDM تحميل بواسطة - c:\program files\Internet Download Manager\IEExt.htm
O8 -: IDM تحميل جميع الروابط بواسطة - c:\program files\Internet Download Manager\IEGetAll.htm
O17 -: HKLM\CCS\Interface\{39C405F8-4CB3-4D89-A4D4-D45A18F8F971}: NameServer = 163.121.128.134,163.121.128.135
O16 -: Microsoft XML Parser for Java -
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-04 21:07:26
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
c:\program files\ANALOG DEVICES\SOUNDMAX\SMAGENT.EXE
c:\windows\system32\wscntfy.exe
c:\program files\Internet Download Manager\IEMonitor.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 11/04/2008 21:09:05 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-04 19:09:02
Pre-Run: 2,663,542,784 bytes free
Post-Run: 2,850,574,336 bytes free
176
ثم تقرير hijack
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:21:13 م, on 04/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\keyhook.exe
C:\WINDOWS\htpatch.exe
C:\Program Files\Topro\tppoll.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\abosohail\Desktop\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 30.30.30.1:8080
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [tppoll] C:\Program Files\Topro\tppoll.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: IDM بواسطة FLV تحميل محتوى فيديو - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: IDM تحميل بواسطة - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: IDM تحميل جميع الروابط بواسطة - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{39C405F8-4CB3-4D89-A4D4-D45A18F8F971}: NameServer = 163.121.128.134,163.121.128.135
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 4940 bytes