أخي
KONG أولاً مشكور على متابعتك للموضوع
وهذا هو التقرير الذي طلبته:-
ComboFix 08-07-28.4 - Administrator 2008-07-29 16:04:01.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.324 [GMT 3:00]
Running from: C:\Documents and Settings\XPPRESP3\My Documents\My Music\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-29 )))))))))))))))))))))))))))))))
.
2008-07-29 16:01 . 2008-07-29 16:01 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-29 15:18 . 2008-07-29 15:18 490 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-29 14:11 . 2008-07-29 14:11 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-29 13:40 . 2008-07-29 13:40 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-07-29 11:44 . 2008-07-29 11:47 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Tracing
2008-07-28 14:23 . 2008-07-28 14:43 <DIR> d-------- C:\QUARANTINE
2008-07-28 14:19 . 2008-07-28 14:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-07-26 19:31 . 2008-07-26 19:31 38 --a------ C:\WINDOWS\avisplitter.INI
2008-07-26 18:36 . 2008-07-26 18:36 <DIR> d-------- C:\WINDOWS\Sun
2008-07-26 18:05 . 2006-09-06 16:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-07-26 18:04 . 2008-07-26 18:04 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-07-26 17:45 . 2008-07-26 17:45 <DIR> d-------- C:\Documents and Settings\XPPRESP3\dwhelper
2008-07-26 16:23 . 2008-07-26 16:23 <DIR> d-------- C:\Program Files\BuddyCheck
2008-07-26 16:23 . 2008-07-26 16:24 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\Nuotex
2008-07-26 15:21 . 2008-07-26 15:21 <DIR> d-------- C:\Program Files\Java
2008-07-26 15:21 . 2008-07-26 15:21 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-26 15:21 . 2007-06-14 16:53 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-26 15:20 . 2008-07-26 15:20 <DIR> d-------- C:\Program Files\UltraISO
2008-07-26 15:20 . 2008-07-26 15:20 <DIR> d-------- C:\Program Files\Common Files\EZB Systems
2008-07-26 15:16 . 2008-07-26 15:16 <DIR> d-------- C:\Program Files\malaksoft
2008-07-26 14:54 . 2008-07-26 14:54 <DIR> d-------- C:\Program Files\IndieVolume
2008-07-26 12:58 . 2008-07-26 12:58 <DIR> d--h----- C:\WINDOWS\PIF
2008-07-26 12:57 . 2008-07-26 13:57 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\CyberPower Audio Editing Lab
2008-07-26 12:56 . 2008-07-26 12:56 <DIR> d-------- C:\Program Files\CyberPower Audio Editing Lab
2008-07-25 09:45 . 2008-07-29 14:00 1,202 --a------ C:\is.html
2008-07-25 08:57 . 2008-07-25 08:57 <DIR> d-------- C:\Documents and Settings\All Users\Application DataTechSmith
2008-07-25 08:56 . 2008-07-25 08:56 <DIR> d-------- C:\Program Files\TechSmith
2008-07-25 08:37 . 2008-07-25 08:37 <DIR> d-------- C:\OUTPUT
2008-07-25 08:36 . 2008-07-25 08:36 <DIR> d-------- C:\Program Files\Easiestutils
2008-07-25 04:55 . 2008-07-25 08:28 <DIR> d-------- C:\Program Files\Bookmark Base
2008-07-25 04:50 . 2008-07-25 04:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-07-25 04:47 . 2008-07-25 04:47 <DIR> d-------- C:\Program Files\Universal Extractor
2008-07-25 04:47 . 2008-07-25 04:47 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-07-25 04:46 . 2008-07-25 04:46 <DIR> d-------- C:\Program Files\CCleaner
2008-07-25 04:45 . 2008-07-25 04:45 <DIR> d-------- C:\Program Files\Opera
2008-07-25 04:45 . 2008-07-25 04:45 <DIR> d-------- C:\Program Files\DUHALAB
2008-07-25 04:43 . 2008-07-25 04:43 <DIR> d-------- C:\Program Files\TagRename
2008-07-25 04:43 . 2008-07-25 04:43 <DIR> d-------- C:\Program Files\Lock My PC 4
2008-07-25 04:43 . 2008-06-13 21:39 45,184 --a------ C:\WINDOWS\system32\fsp_lmwl.dll
2008-07-25 04:43 . 2007-10-08 23:59 10,096 --a------ C:\WINDOWS\system32\drivers\lmpc4.sys
2008-07-25 04:39 . 2008-07-25 04:39 <DIR> d-------- C:\Program Files\Messenger Plus! Live
2008-07-25 04:36 . 2008-07-26 17:39 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\Media Player Classic
2008-07-25 04:29 . 2005-01-04 16:50 176,128 --------- C:\WINDOWS\system32\SiSApCom.dll
2008-07-25 04:29 . 2005-01-04 16:54 110,592 --------- C:\WINDOWS\system32\TVMode.dll
2008-07-25 04:29 . 2005-01-04 16:54 28,672 --------- C:\WINDOWS\system32\SiSHook.dll
2008-07-25 04:28 . 2008-07-25 04:29 <DIR> d-------- C:\Program Files\SiS VGA Utilities V3.65
2008-07-25 04:28 . 2008-07-25 04:29 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-29 12:26 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\DMCache
2008-07-29 12:05 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-29 12:05 --------- d-----w C:\Program Files\Windows Live
2008-07-29 11:40 --------- d-----w C:\Program Files\Yahoo!
2008-07-29 07:34 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\XnView
2008-07-28 11:16 --------- d-----w C:\Program Files\Internet Download Manager
2008-07-26 11:53 --------- d-----w C:\Program Files\XoftSpySE
2008-07-26 11:01 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\IDM
2008-07-25 06:45 --------- d-----w C:\Program Files\Image Upload
2008-07-25 05:56 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-12 18:36 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\divx.dll
2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2006-10-07 02:18 573,440 ----a-w C:\Program Files\opera\program\plugins\embd3260.dll
2008-03-19 17:22 249,856 ----a-w C:\Program Files\opera\program\plugins\PLUGIN.DLL
2008-02-21 20:21 524,288 ----a-w C:\Program Files\opera\program\plugins\rpcl3260.dll
2008-02-21 20:21 180,224 ----a-w C:\Program Files\opera\program\plugins\rpgu3260.dll
2008-02-21 20:21 598,016 ----a-w C:\Program Files\opera\program\plugins\rput3260.dll
.
------- Sigcheck -------
2005-07-13 04:07 360448 0601f83f6784c220ee302f03f702316e C:\WINDOWS\system32\drivers\tcpip.sys
2005-10-15 14:07 1182720 2904dd5ae1b65724e21dc3ca9a1405b5 C:\WINDOWS\explorer.exe
2005-10-15 14:07 1032192 45757077a47c68a603a79b03a1a836ab C:\WINDOWS\XPize\Backup\explorer.exe
2004-08-04 19:00 30208 de8fa9cf18f95341079c7e6a215c226a C:\WINDOWS\system32\ctfmon.exe
2004-08-04 19:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\XPize\Backup\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 19:00 30208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gainward"="C:\Program Files\XpertVision\TBPanel.exe" [2006-09-13 11:10 2154496]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 19:20 90112 C:\WINDOWS\Soundman.exe]
"SiSPower"="SiSPower.dll" [2005-01-04 16:54 49152 C:\WINDOWS\system32\SiSPower.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 19:00 30208]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2008-07-25 04:28:43 331776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):58,50,69,7a,65,5f,4c,6f,67,6f,6e,2e,65,78,65,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsp_lmwl]
2008-06-13 21:39 45184 C:\WINDOWS\system32\fsp_lmwl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R3 LMPC4;LMPC4;C:\WINDOWS\system32\drivers\LMPC4.sys [2007-10-08 23:59]
S2 P1100B_CT_CDI;Creative PD1100B HAL Service;C:\WINDOWS\system32\DRIVERS\P1100bCd.sys [2003-01-23 04:00]
S2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 19:00]
S3 IndieVolume;IndieVolume Service;C:\Program Files\IndieVolume\IndieVolume.sys [2006-12-22 18:06]
S3 P1100BVD;Creative WebCam Vista;C:\WINDOWS\system32\DRIVERS\P1100bVd.sys [2003-01-27 04:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WudfServiceGroup REG_SZ hex(7):57,00,55,00,44,00,46,00,53,00,76,00,63,00,00,00,00,00
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
.
s of the 'Scheduled Tasks' folder
2008-04-19 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-26 22:51]
2008-04-19 C:\WINDOWS\Tasks\XoftSpySE.job
- C:\Program Files\XoftSpySE\XoftSpy.exe [2006-06-23 20:05]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com
O16 -: Microsoft XML Parser for Java -
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-29 16:06:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
.
Completion time: 2008-07-29 16:08:25
ComboFix-quarantined-files.txt 2008-07-29 13:08:19
Pre-Run: 4,720,660,480 bytes free
Post-Run: 4,716,666,880 bytes free
179