هذا التقرير الأول ::
ComboFix 08-11-12.01 - Administrator 11/14/2008 8:00:26.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.1338 [GMT 3:00]
Running from: c:\documents and settings\Administrator\My Documents\Downloads\Programs\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\BM534da6f2.txt
c:\windows\BM534da6f2.xml
c:\windows\s.ini
c:\windows\IE4 Error Log.txt
c:\windows\pskt.ini
c:\windows\system32\bbvvyxol.ini
c:\windows\system32\bngbgedv.ini
c:\windows\system32\bpkxexsh.ini
c:\windows\system32\cljoahiw.ini
c:\windows\system32\dvmcpxqm.ini
c:\windows\system32\dvufgtfy.ini
c:\windows\system32\eeodgntn.ini
c:\windows\system32\genjyeex.ini
c:\windows\system32\gqvgebaq.ini
c:\windows\system32\hthuaclx.ini
c:\windows\system32\kdshbuyh.ini
c:\windows\system32\mcrh.tmp
c:\windows\system32\ndreaqem.ini
c:\windows\system32\onipctym.ini
c:\windows\system32\pudrqkyr.ini
c:\windows\system32\qaimgpmd.ini
c:\windows\system32\qjgpihpx.ini
c:\windows\system32\rmfuwccm.ini
c:\windows\system32\rpfecntm.ini
c:\windows\system32\tvkflpsg.ini
c:\windows\system32\uxrloyvk.ini
c:\windows\system32\VCMoVvut.ini
c:\windows\system32\VCMoVvut.ini2
c:\windows\system32\wnhwybft.ini
c:\windows\system32\wsyacmvy.ini
.
((((((((((((((((((((((((( Files Created from 2008-10-14 to 2008-11-14 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-14 05:06 11,950,880 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-14 05:04 789,280 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-14 05:04 --------- d-----w c:\documents and settings\Administrator\Application Data\DMCache
2008-11-14 05:03 83,348 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-14 05:03 179,780 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-14 03:16 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-10-24 11:55 --------- d-----w c:\program files\BitComet
2008-02-26 23:12 82 ----a-w c:\documents and settings\All Users\Application Data\SUMQU0C1-FE20-APII-YE7M-BEDSDWMY5R6A.dat
.
------- Sigcheck -------
03/04/2006 06:58 AM 663552 c0845ecbf4f9164e618ee381b79c9032 c:\windows\$hf_mig$\KB912812\SP2QFE\wininet.dll
03/04/2006 06:33 AM 692224 4705336e9b2a69dc4c866fab696b0219 c:\windows\system32\wininet.dll
03/04/2006 06:33 AM 692224 4705336e9b2a69dc4c866fab696b0219 c:\windows\system32\dllcache\wininet.dll
03/27/2008 11:43 AM 502272 6225f14b8ce08ccba8b25ad27843c674 c:\windows\system32\winlogon.exe
08/04/2004 01:00 PM 974336 a5c1f2cf7c31874e66478910b43d6513 c:\windows\explorer.exe
08/04/2004 01:00 PM 974336 a5c1f2cf7c31874e66478910b43d6513 c:\windows\system32\dllcache\explorer.exe
08/04/2004 01:00 PM 100864 80cb133bd6c830e8ca7e90015e45c1cd c:\windows\system32\wuauclt.exe
08/04/2004 01:00 PM 100864 80cb133bd6c830e8ca7e90015e45c1cd c:\windows\system32\dllcache\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [04/11/2005 11:26 AM 65536]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [08/16/2007 04:19 PM 5728112]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [02/27/2007 10:07 AM 778240]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [08/04/2004 01:06 AM 1667584]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/03/2008 06:53 AM 68856]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [07/18/2007 05:55 PM 451872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [11/06/2007 03:37 PM 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [11/06/2007 03:37 PM 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [11/06/2007 03:37 PM 138008]
"ATKHOTKEY"="c:\program files\ATK Hotkey\Hcontrol.exe" [04/24/2007 04:00 PM 225280]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [03/21/2007 01:00 PM 174872]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [11/06/2007 03:40 PM 888832]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [03/27/2008 05:00 PM 185896]
"ClocX"="c:\program files\ClocX\ClocX.exe" [09/04/2004 11:28 AM 270336]
"NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [08/02/2007 05:30 PM 3096576]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [03/01/2007 03:57 PM 153136]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [02/08/2008 06:36 PM 227856]
"RTHDCPL"="RTHDCPL.EXE" [11/06/2007 03:40 PM 16384512 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [11/06/2007 03:40 PM 1826816 c:\windows\SkyTel.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 01:00 PM 110592 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [11/07/2007 05:35 PM 1294336]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
CaptureWiz.lnk - c:\program files\CaptureWiz\Pro\CaptureWiz.exe [2008-03-28 2011168]
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-19 630784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\CQPhone\\CQPhone.exe"=
"c:\\Program Files\\CQPhone\\cqvideo.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23250:TCP"= 23250:TCP:BitComet 23250 TCP
"23250:UDP"= 23250:UDP:BitComet 23250 UDP
R2 UxTuneUp;TuneUp Theme Extension;c:\windows\System32\svchost.exe [08/04/2004 01:00 PM 14336]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [12/13/2007 01:28 PM 24592]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [11/06/2007 03:41 PM 264576]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;c:\windows\System32\TuneUpDefragService.exe [03/27/2008 05:03 PM 306432]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{45b0f2b5-38b9-11dd-b4ec-001644984d00}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c1d409f2-a6d6-11dd-b5ea-001644984d00}]
\Shell\AutoRun\command - f:\wd_windows_tools\Setup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
s of the 'Scheduled Tasks' folder
2008-10-31 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [12/21/2007 03:17 PM]
.
- - - - ORPHANS REMOVED - - - -
BHO-{E1476A4A-29D1-4436-B71A-C88645EA2F23} - (no file)
HKLM-Run-BM534da6f2 - c:\windows\system32\djecqvnn.dll
Notify-vtUoNHXq - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ukyh0n6h.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://ar.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:ar

fficial
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-14 08:04:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: c:\windows\explorer.exe
-> c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wdfmgr.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\rundll32.exe
c:\program files\ATK Hotkey\ATKOSD.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\Internet Download Manager\IEMonitor.exe
c:\program files\Mozilla Firefox\firefox.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Completion time: 11/14/2008 8:09:00 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-14 05:08:44
Pre-Run: 18,589,474,816 bytes free
Post-Run: 18,538,971,136 bytes free
189