هذا التقرير طلع بعد استخدام ComboFix
ComboFix 08-12-06.06 - TOSHIBA 12/07/2008 16:57:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.1092 [GMT 3:00]
Running from: c:\documents and settings\TOSHIBA\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\resycled
c:\resycled\boot.com
c:\windows\system32\kdpqp.exe
D:\resycled
d:\resycled\boot.com
.
((((((((((((((((((((((((( Files Created from 2008-11-07 to 2008-12-07 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-07 14:25 11,775,264 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-07 14:24 --------- d-----w c:\documents and settings\TOSHIBA\Application Data\DMCache
2008-12-07 14:04 5,276 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-12-07 14:04 24,352 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-12-07 14:04 162,368 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-07 13:54 --------- d---a-w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-12-07 01:56 203,776 ----a-w c:\windows\system32\clrviddc.dll
2008-12-07 01:05 --------- d-----w c:\program files\Common Files\xing shared
2008-12-07 01:05 --------- d-----w c:\program files\Common Files\Real
2008-12-07 01:04 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-12-07 01:04 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-12-06 03:57 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-06 03:56 --------- d-----w c:\documents and settings\TOSHIBA\Application Data\Ashampoo
2008-12-06 03:55 --------- d-----w c:\program files\Ashampoo
2008-12-06 02:25 82,258 ----a-w c:\windows\system32\drivers\klin.dat
2008-12-06 02:25 82,258 ----a-w c:\windows\system32\drivers\klick.dat
2008-12-06 02:24 --------- d-----w c:\program files\Kaspersky Lab
2008-12-06 02:00 --------- d-----w c:\program files\SpeedBitPlus
2008-12-06 02:00 --------- d-----w c:\program files\Google
2008-12-06 02:00 --------- d-----w c:\program files\Conduit
2008-12-06 01:24 --------- d-----w c:\program files\DAP
2008-12-06 01:24 --------- d-----w c:\documents and settings\All Users\Application Data\SpeedBit
2008-12-05 02:53 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-12-02 04:28 --------- d-----w c:\program files\Hotspot Shield
2008-11-30 09:32 --------- d-----w c:\program files\Toshiba
2008-11-27 23:33 --------- d-----w c:\program files\LtUcx
2008-11-27 23:31 57,344 ----a-w c:\windows\system32\IMSInfo.dll
2008-11-27 23:31 397,312 ----a-w c:\windows\system32\imcv1.dll
2008-11-25 10:11 --------- d-----w c:\documents and settings\TOSHIBA\Application Data\BSplayer
2008-11-10 11:07 --------- d-----w c:\program files\BS.Player ControlBar
2008-11-10 11:04 --------- d-----w c:\program files\Webteh
2008-11-10 11:04 --------- d-----w c:\documents and settings\TOSHIBA\Application Data\BSplayer PRO
2008-11-10 10:16 --------- d-----w c:\program files\GRETECH
2008-11-09 23:56 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-08 06:15 --------- d-----w c:\program files\Ontrack
2008-10-29 06:32 --------- d-----w c:\program files\ma-config.com
2008-10-29 06:32 --------- d-----w c:\documents and settings\All Users\Application Data\ma-config.com
2008-10-28 03:17 --------- dc-h--w c:\documents and settings\All Users\Application Data\{C2278D61-978F-4EB3-A8F3-E90811A93014}
2008-10-28 03:02 --------- d-----w c:\program files\iXi Tools
2008-10-28 02:54 --------- dc-h--w c:\documents and settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2008-10-28 02:54 --------- d-----w c:\documents and settings\TOSHIBA\Application Data\Uniblue
2008-10-28 02:54 --------- d-----w c:\documents and settings\All Users\Application Data\DriverScanner
2008-10-16 11:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 11:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 11:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 11:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 11:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 11:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 11:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 11:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 11:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 11:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-10 01:40 --------- d-----w c:\documents and settings\TOSHIBA\Application Data\IDM
2008-10-10 01:37 --------- d-----w c:\program files\ONSPEED
2008-10-10 01:37 --------- d-----w c:\documents and settings\TOSHIBA\Application Data\Toshiba
2008-10-10 01:37 --------- d-----w c:\documents and settings\TOSHIBA\Application Data\SlipStream
2008-10-10 01:37 --------- d-----w c:\documents and settings\TOSHIBA\Application Data\Paltalk
2008-06-30 01:51 197 --sha-w c:\program files\Common Files\maxtreme.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
12/02/2008 07:26 AM 204248 --a------ c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [06/19/2008 03:53 AM 894208]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [10/13/2004 09:21 AM 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [03/23/2006 09:17 PM 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [03/23/2006 09:13 PM 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [03/23/2006 09:17 PM 118784]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [01/05/2006 02:02 PM 352256]
"SVRemote"="c:\program files\SVRemote\Watch.exe" [06/06/2006 08:23 AM 20480]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 01:06 PM 40048]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [12/07/2008 04:04 AM 185872]
"SkyTel"="SkyTel.EXE" [05/16/2006 06:04 PM 2879488 c:\windows\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [12/19/2006 11:12 AM 16062464 c:\windows\RTHDCPL.exe]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" [09/16/2005 02:57 PM 73728 c:\windows\system32\TDispVol.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
"CFSServ.exe"="CFSServ.exe" [BU]
"TPSMain"="TPSMain.exe" [08/03/2005 02:26 PM 266240 c:\windows\system32\TPSMain.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 01:56 AM 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="c:\windows\Installer\TSClientMsiTrans\tscuinst.vbs" [04/23/2007 07:54 AM 12451]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [08/03/2004 11:59 PM 44544]
"nltide_3"="advpack.dll" [12/07/2007 05:04 AM 124928 c:\windows\system32\advpack.dll]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-02-16 113664]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-12-07 1744896]
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2008-05-09 10452992]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Red Swoosh
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-04-04 24344]
R3 WSIMD;wsimd Service;c:\windows\system32\DRIVERS\wsimd.sys [2008-02-15 57344]
S3 3xHybrid;3xHybrid service;c:\windows\system32\DRIVERS\3xHybrid.sys [2008-08-23 974464]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-03 32512]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187.sys [2008-05-13 194304]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06d4e3c8-6416-11dd-9519-0016e3e5d5c8}]
\Shell\AutoRun\command - f:\wd_windows_tools\setup.exe
.
- - - - ORPHANS REMOVED - - - -
BHO-{60270dc7-9ea0-472f-9b77-66652c06246e} - (no file)
HKCU-Run-DriverUpdaterPro - c:\program files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe
HKCU-Run-SmsDiscount - c:\program files\SmsDiscount.com\SmsDiscount\SmsDiscount.exe
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
HKLM-Run-SysMetrix - c:\program files\SysMetrix\SysMetrix.exe
HKLM-Run-c:\windows\system32\kdpqp.exe - c:\windows\system32\kdpqp.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
mStart Page = hxxp://www.windowsxlive.net
uInternet Settings,ProxyServer = 212.116.219.211:8080
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Download All Links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 -: Microsoft XML Parser for Java -
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\system32\msvcrt.dll - c:\windows\system32\mfc42.dll
c:\windows\system32\olepro32.dll
c:\program files\LtUcx\1003\imcv1.dll
O16 -: {6924091F-CD97-41E1-B1D4-D9079409D413}
hxxp://ghalaa.digivoice.net:1999/talk.cab
c:\windows\Downloaded Program Files\talk.inf
c:\windows\Downloaded Program Files\plinstll.dll - O16 -: {79E54B26-46B9-40EF-BFDC-0B1BB0D68897}
hxxp://www.piclens.com/shared/plinstll.cab
c:\windows\Downloaded Program Files\plinstll.inf
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_3_1.cab
c:\windows\Downloaded Program Files\hardwaredetection.inf
c:\windows\Downloaded Program Files\ReadUid.ocx - O16 -: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA}
hxxp://ghalaa.digivoice.net:1999/ReadUid.CAB
c:\windows\Downloaded Program Files\ReadUid.INF
.
.
------- File Associations -------
.
txtfile=c:\windows\notepad.exe %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-07 17:24:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(556)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\windows\system32\klogon.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll
- - - - - - - > 'lsass.exe'(608)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
- - - - - - - > 'explorer.exe'(3648)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
c:\program files\Internet Download Manager\IEMonitor.exe
c:\windows\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 12/07/2008 17:27:23 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-07 14:27:17
Pre-Run: 1,456,787,456 bytes free
Post-Run: 3,666,386,944 bytes free
221