هلا اخوي الليث
هذا التقرير حق الاداه الاولى
_______
ComboFix 08-06-20.4 - a 06/27/2008 18:55:42.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.214 [GMT 3:00]
Running from: C:\Documents and Settings\a\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-05-27 to 2008-06-27 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-14 08:15 --------- d-----w C:\Program Files\JetAudio
2008-06-13 12:32 --------- d-----w C:\Documents and Settings\a\Application Data\MakeUpPilot
2008-06-10 22:28 --------- d-----w C:\Program Files\Google
2008-06-06 07:39 --------- d-----w C:\Program Files\LtUcx
2008-06-05 06:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-06-04 17:51 --------- d-----w C:\Program Files\Yahoo!
2008-05-30 19:49 --------- d-----w C:\Documents and Settings\a\Application Data\Avira
2008-05-29 23:26 --------- d-----w C:\Program Files\Avira
2008-05-29 23:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-05-29 20:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-05-25 18:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-05-25 18:44 --------- d-----w C:\Program Files\ESET
2008-05-22 13:34 --------- d-----w C:\Program Files\WinWatermark 2.2
2008-05-22 13:30 --------- d-----w C:\Documents and Settings\a\Application Data\Thinstall
2008-05-22 01:51 --------- d-----w C:\Program Files\Kaspersky Lab
2008-05-21 23:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-05-10 20:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-05-10 20:32 --------- d-----w C:\Documents and Settings\a\Application Data\CyberLink
2008-05-06 09:06 --------- d-----w C:\Documents and Settings\a\Application Data\Media Player Classic
2008-05-02 11:21 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-04-13 19:27 47,104 ------w C:\WINDOWS\AKDeInstall.exe
2008-04-13 14:00 315,392 ----a-w C:\WINDOWS\HideWin.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"sxs2"="c:\sxs2.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [02/12/2008 10:06 AM 262401]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [02/13/2007 09:29 PM 35328]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [04/13/2007 10:31 PM 185896]
"SkyTel"="SkyTel.EXE" [06/15/2007 11:45 AM 1826816 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [07/05/2007 11:08 AM 16380416 C:\WINDOWS\RTHDCPL.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [12/07/2005 10:57 PM 30208]
"PV92TRAY"="PV92Tray.exe" [08/11/2004 10:42 PM 128000 C:\WINDOWS\system32\PV92Tray.exe]
"PCTVOICE"="pctspk.exe" [08/11/2004 10:42 PM 176128 C:\WINDOWS\system32\pctspk.exe]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [04/13/2006 11:09 AM 49152]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [11/28/2005 08:55 AM 98304]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [11/28/2005 08:55 AM 118784]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [11/28/2005 08:52 AM 77824]
"BluetoothAuthenticationAgent"="bthprops.cpl,,BluetoothAuthenticationAgent" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 01:56 AM 15360]
C:\Documents and Settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-04-13 22:38:06 113664]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-04-28 11:20:00 415072]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\English\\setup.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=
R2 AntiVirMailService;Avira AntiVir Premium MailGuard;"C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe" [05/30/2008 02:29 AM]
R2 antivirwebservice;Avira AntiVir Premium WebGuard;"C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE" [04/09/2008 03:57 PM]
R2 AVEService;Avira AntiVir Premium MailGuard helper service;"C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe" [02/07/2008 10:06 AM]
S3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [06/08/2007 09:52 AM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{347014e0-111c-11dd-b69b-001d7dc2635e}]
\Shell\Auto\command - H:\sxs2.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs2.exe
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-06-27 18:58:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 06/27/2008 18:59:46
ComboFix-quarantined-files.txt 2008-06-27 15:59:29
Pre-Run: 2,897,408,000 bytes free
Post-Run: 3,131,551,744 bytes free
97