جزاكم الله خير ما يحتاج الاعتذار يا اخ
samirzehani اخ وغالي
وجزاك الله الف خير يا اخ ماكس بس ترى اول مرة اسوي تقرير .... الله لا يهينك علمني كيف اتعامل معة
طلع معي على شكل مستند مفكرة نص
الله يوفك دنياء واخرة يا عسل ......... هذا التقرير الي طلعلي
ComboFix 08-12-01.03 - Administrator 12/03/2008 13:50:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.1628 [GMT 3:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Starware381
c:\documents and settings\All Users\Application Data\Starware381\buttons\1316_button_1b_def.bmp
c:\documents and settings\All Users\Application Data\Starware381\buttons\1316_button_1b_over.bmp
c:\documents and settings\All Users\Application Data\Starware381\buttons\1317_button_1b_def.bmp
c:\documents and settings\All Users\Application Data\Starware381\buttons\FindIt.bmp
c:\documents and settings\All Users\Application Data\Starware381\buttons\FindItHot.bmp
c:\documents and settings\All Users\Application Data\Starware381\buttons\findithotxp.png
c:\documents and settings\All Users\Application Data\Starware381\buttons\finditxp.png
c:\documents and settings\All Users\Application Data\Starware381\buttons\logo.bmp
c:\documents and settings\All Users\Application Data\Starware381\buttons\logoxp.bmp
c:\documents and settings\All Users\Application Data\Starware381\contexts\error.xml
c:\documents and settings\All Users\Application Data\Starware381\contexts\related.xml
c:\documents and settings\All Users\Application Data\Starware381\contexts\travel.xml
c:\documents and settings\All Users\Start Menu\Programs\ADSTechnology
c:\documents and settings\All Users\Start Menu\Programs\ADSTechnology\ADSTechnology.lnk
c:\documents and settings\All Users\Start Menu\Programs\ADSTechnology\Uninstall.lnk
c:\program files\ActivationManager
c:\program files\ActivationManager\Uninstall.exe
c:\program files\ADSTechnology
c:\program files\ADSTechnology\Uninstall.exe
c:\program files\Starware381
c:\windows\IE4 Error Log.txt
c:\windows\system32\my sex world.ico
F:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-11-03 to 2008-12-03 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-03 10:54 --------- dc----w c:\documents and settings\Administrator\Application Data\DMCache
2008-12-03 10:52 368,672 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-12-03 10:52 3,519,520 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-03 10:52 29,624 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-03 10:52 2,340 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-12-02 10:59 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-18 10:46 --------- d-----w c:\program files\Gabest
2008-11-18 09:43 --------- d-----w c:\documents and settings\All Users\Application Data\SpeedBit
2008-11-18 09:39 --------- d-----w c:\program files\DAP
2008-11-18 09:36 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-10-31 04:46 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-28 14:58 --------- dc----w c:\documents and settings\Administrator\Application Data\BitSpirit
2008-10-28 14:58 --------- d-----w c:\program files\BitSpirit
2008-10-28 14:55 --------- dc----w c:\documents and settings\Administrator\Application Data\zweitgeist
2008-10-28 14:55 --------- d-----w c:\program files\weblin
2008-10-25 10:06 --------- d-----w c:\program files\Internet Download Manager
2008-10-25 10:01 --------- d-----w c:\program files\MSN Messenger
2008-10-25 09:33 --------- d-----w c:\program files\Bonjour
2008-10-25 00:16 --------- d-----w c:\program files\iTunes
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [09/12/2007 07:15 AM 1360304]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/04/2004 03:56 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [03/28/2008 11:37 PM 413696]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 12:56 AM 110592 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 03:56 AM 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk
backup=c:\windows\pss\BlueSoleil.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ONSPEED.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ONSPEED.lnk
backup=c:\windows\pss\ONSPEED.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalStart.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PalStart.lnk
backup=c:\windows\pss\PalStart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk
backup=c:\windows\pss\PalTalk.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 12/23/2006 06:05 PM 143360 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 08/04/2004 03:56 AM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 08/24/2007 07:00 AM 33648 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 09/12/2007 07:15 AM 1360304 c:\program files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 04/13/2006 11:09 AM 49152 c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 01/12/2006 03:40 PM 155648 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 03/28/2008 11:37 PM 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 12/07/2005 10:57 PM 30208 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 08/04/2004 12:56 AM 110592 c:\windows\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--a------ 09/07/2006 02:23 PM 303104 c:\windows\sttray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\BitSpirit\\BitSpirit.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [2004-08-04 14336]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - d:\autorun\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{44c2dfd6-0da7-11dc-aa7a-0019d1389c5c}]
\Shell\????...\command - F:\QQSPY.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL QQSPY.exe
.
s of the 'Scheduled Tasks' folder
2008-11-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [08/29/2007 02:57 PM]
2008-12-03 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [06/25/2007 09:08 PM]
2008-11-28 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [06/25/2007 09:08 PM]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{0A94B116-4504-4e26-AB05-E61E474AA38B} - c:\program files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
HKLM-Run-SlipStream - c:\program files\ONSPEED\onspeedcore.exe
Notify-NavLogon - (no file)
MSConfigStartUp-avgnt - c:\program files\AntiVir PersonalEdition Classic\avgnt.exe
MSConfigStartUp-BDAgent - c:\program files\BitDefender\BitDefender 2008\bdagent.exe
MSConfigStartUp-BitDefender Antiphishing Helper - c:\program files\BitDefender\BitDefender 2008\IEShow.exe
MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-ISTray - c:\docume~1\ADMINI~1\LOCALS~1\Temp\RarSFX4\pctsTray.exe
MSConfigStartUp-SlipStream - c:\program files\ONSPEED\onspeedcore.exe
MSConfigStartUp-Uniblue RegistryBooster 2 - c:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe
MSConfigStartUp-vptray - c:\progra~1\SYMANT~1\VPTray.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\
0a2fop01.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://search.speedbit.com/
FF -: plugin - c:\program files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
.
.
------- File Associations -------
.
txtfile=c:\windows\notepad.exe %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-03 13:54:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
c:\windows\system32\ZSHP1020.EXE [840] 0x8A2E2580
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(880)
c:\progra~1\MICROS~2\OFFICE11\MCPS.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\program files\a-squared Free\a2service.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\SigmaTel\C-Major Audio\WDM\stacsv.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\PAStiSvc.exe
c:\program files\Internet Download Manager\IEMonitor.exe
c:\windows\system32\wuauclt.exe.wusetup.192718.bak
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 12/03/2008 13:56:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-03 10:56:14
Pre-Run: 9,826,349,056 bytes free
Post-Run: 10,140,393,472 bytes free
215 --- E O F --- 2008-10-01 23:59:23