مشكور يا خلود وهذا هو التقرير
ComboFix 08-11-27.07 - Administrator 11/28/2008 18:57:35.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.439 [GMT 3:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
c:\windows\regedit.com
c:\windows\system32\taskmgr.com
.
((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-28 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-28 16:02 23,552 ----a-w c:\windows\system32\wmimgr32.dll
2008-11-28 16:02 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-28 16:00 368,672 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-28 16:00 3,388 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-28 16:00 15,792 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-28 16:00 1,749,024 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-27 10:40 2,320,000 ----a-w c:\windows\system32\TUKernel.exe
2008-11-27 10:19 603,904 ----a-w c:\windows\system32\TUProgSt.exe
2008-11-27 10:19 362,240 ----a-w c:\windows\system32\TuneUpDefragService.exe
2008-11-27 10:19 --------- d-----w c:\program files\TuneUp Utilities 2009
2008-11-27 10:19 --------- d-----w c:\documents and settings\All Users\Application Data\TuneUp Software
2008-11-27 10:19 --------- d-----w c:\documents and settings\Administrator\Application Data\TuneUp Software
2008-11-27 10:18 --------- d-sh--w c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2008-11-26 20:34 73,216 ----a-w c:\windows\ST6UNST.EXE
2008-11-26 20:34 49,152 ----a-w c:\windows\reico.exe
2008-11-26 20:34 46,080 ----a-w c:\windows\setdebug.exe
2008-11-26 20:34 298,496 ----a-w c:\windows\uninst.exe
2008-11-26 20:34 172,032 ----a-w c:\windows\Setup1.exe
2008-11-26 20:04 304,128 ----a-w c:\windows\IsUninst.exe
2008-11-26 19:57 315,392 ----a-w c:\windows\HideWin.exe
2008-11-26 19:51 6,144 ----a-w c:\windows\delttsul.exe
2008-11-26 19:51 49,152 ----a-w c:\windows\ATA Live Update.exe
2008-11-26 19:50 182,784 ----a-w c:\windows\ApplyTheme.exe
2008-11-26 19:49 47,104 ----a-w c:\windows\AKDeInstall.exe
2008-11-24 20:00 --------- d-----w c:\program files\ManagerX 2.1.3
2008-11-24 16:21 --------- d-----w c:\documents and settings\Administrator\Application Data\ACD Systems
2008-11-23 18:38 --------- d-----w c:\program files\Google
2008-11-23 18:28 --------- d-----w c:\program files\Web Publish
2008-11-23 18:23 --------- d-----w c:\documents and settings\Administrator\Application Data\Resource Tuner
2008-11-22 18:59 --------- d-----w c:\program files\No-IP
2008-11-19 20:40 218,624 ----a-w c:\windows\system32\uxtheme.dll
2008-11-19 20:40 1,949,184 ----a-w c:\windows\system32\logonui.exe
2008-11-12 13:44 27,904 ----a-w c:\windows\system32\uxtuneup.dll
2008-11-01 17:05 --------- d-----w c:\documents and settings\Admin\Application Data\Resource Tuner
2008-10-26 12:49 --------- d-----w c:\program files\Fake Webcam
2008-10-16 08:29 --------- d-----w c:\program files\ShiningMorning
2008-10-15 06:13 --------- d-----w c:\documents and settings\Admin\Application Data\COWON
2008-10-15 05:51 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-13 14:39 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-10-10 12:36 --------- d-----w c:\program files\WinPcap
2008-10-10 12:35 --------- d-----w c:\program files\Messenger Plus! Live
2008-10-08 23:29 --------- d-----w c:\program files\Circle Developement
2008-10-08 22:31 96,976 ----a-w c:\windows\system32\drivers\klin.dat
2008-10-08 22:31 87,855 ----a-w c:\windows\system32\drivers\klick.dat
2008-10-08 22:00 --------- d-----w c:\program files\Kaspersky Lab
2008-10-08 21:59 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-08 21:53 --------- d-----w c:\program files\TechSmith
2008-10-08 21:53 --------- d-----w c:\documents and settings\All Users\Application Data\TechSmith
2008-10-08 21:52 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-08 21:43 --------- d-----w c:\program files\BreakPoint Software
2008-10-08 21:43 --------- d-----w c:\program files\ASProtect 1.35 Demo
2008-10-08 21:40 --------- d-----w c:\program files\Resource Tuner
2008-10-08 20:42 16,299,862 ------w C:\$Persi0.sys
2008-10-08 20:42 --------- d-----w c:\program files\Faronics
2008-10-08 19:39 --------- d-----w c:\program files\Microsoft Works
2008-10-08 18:44 --------- d-----w c:\program files\Internet Download Manager
2008-10-08 18:43 --------- d-----w c:\documents and settings\Admin\Application Data\IDM
2008-10-08 18:42 --------- d-----w c:\documents and settings\Admin\Application Data\DMCache
2008-10-08 16:53 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-08 16:53 --------- d-----w c:\program files\Realtek
2008-10-08 16:52 --------- d-----w c:\program files\CONEXANT
2008-10-08 15:42 --------- d-----w c:\program files\Windows Live
2008-10-08 15:41 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-10-08 15:41 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-10-08 15:41 --------- d-----w c:\program files\Common Files\xing shared
2008-10-08 15:41 --------- d-----w c:\program files\Common Files\Real
2008-10-08 15:15 --------- d-----w c:\program files\S3
2008-10-08 15:13 --------- d-----w c:\program files\VIA
.
------- Sigcheck -------
11/19/2008 11:43 PM 1656832 c58f0e4dae57c0dc304ecc3683958e4c c:\windows\explorer.exe
11/19/2008 11:43 PM 1656832 c58f0e4dae57c0dc304ecc3683958e4c c:\windows\system32\dllcache\explorer.exe
11/19/2008 11:43 PM 80216 1fa4b5a2899a41df1b0068e96b55e9c2 c:\windows\system32\wuauclt.exe
11/19/2008 11:43 PM 80216 1fa4b5a2899a41df1b0068e96b55e9c2 c:\windows\system32\dllcache\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [08/16/2007 04:19 PM 5728112]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [08/29/2006 07:54 PM 4621816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [10/08/2008 06:41 PM 185896]
"VTTimer"="VTTimer.exe" [03/07/2005 10:33 PM 53248 c:\windows\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [10/31/2005 11:15 PM 163840 c:\windows\system32\VTTrayp.exe]
"RTHDCPL"="RTHDCPL.EXE" [01/30/2007 01:54 PM 16116224 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [05/16/2006 01:04 PM 2899968 c:\windows\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
No-IP DUC.lnk - c:\program files\No-IP\DUC20.exe [2008-10-09 1172992]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
SnagIt 8.lnk - c:\program files\TechSmith\SnagIt 8\SnagIt32.exe [2006-03-14 5517312]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DfLogon]
06/28/2007 08:39 PM 65536 c:\windows\system32\LogonDll.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 08/04/2004 12:56 AM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
--a------ 03/20/2006 05:34 PM 213936 c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 11/26/2008 10:40 PM 155648 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 10/08/2008 06:41 PM 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"RichVideo"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NMIndexingService"=3 (0x3)
"MDM"=2 (0x2)
"BITS"=2 (0x2)
"IviRegMgr"=2 (0x2)
"IDriverT"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\InterVideo\\DVD8\\WinDVD.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
R0 DeepFrz;DeepFrz;c:\windows\system32\drivers\DeepFrz.sys [2007-06-28 131472]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R0 videX32;videX32;c:\windows\system32\DRIVERS\videX32.sys [2008-10-08 9728]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\DRIVERS\xfilt.sys [2008-10-08 11264]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2008-11-27 603904]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-04-04 24592]
R3 mcdevice;mcdevice;c:\windows\system32\DRIVERS\mcdevice.sys [2008-10-16 323584]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-01-25 42000]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
s of the 'Scheduled Tasks' folder
2008-11-28 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [11/20/2008 04:28 PM]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\epavye7g.default\
FF -: plugin - c:\program files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-28 19:02:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(784)
c:\windows\system32\LogonDll.dll
c:\windows\system32\klogon.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'explorer.exe'(1356)
c:\windows\system32\msi.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
c:\program files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
c:\program files\TechSmith\SnagIt 8\TscHelp.exe
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 11/28/2008 19:05:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-28 16:04:53
Pre-Run: 71,407,763,456 bytes free
Post-Run: 71,494,545,408 bytes free
219 --- E O F --- 2007-09-28 11:10:04