اخوي سويت بحث وطلع لي النتيجة..
وهذي هي النتيجة..
ComboFix 08-10-18.03 - xp 2008-10-19 18:49:30.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1025.18.1495 [GMT 3:00]
Running from: C:\Documents and Settings\xp\??? ??????\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\TfSysMon.sys
J:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-09-19 to 2008-10-19 )))))))))))))))))))))))))))))))
.
2008-10-19 16:38 . 2008-10-19 16:38 <DIR> d--h-c--- C:\Documents and Settings\All Users\Application Data\{8A09CD83-59E1-4DB1-AAFC-E25174FC6706}
2008-10-18 21:54 . 2008-10-18 21:54 148 --a------ C:\WINDOWS\system32\ikhcore.cfg
2008-10-18 16:38 . 2008-10-18 16:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-10-18 16:38 . 2008-10-18 16:31 160,792 --a------ C:\WINDOWS\system32\drivers\pctfw2.sys
2008-10-18 16:32 . 2008-10-18 16:32 51,520 --a------ C:\WINDOWS\system32\drivers\TfFsMon.sys
2008-10-18 16:32 . 2008-10-18 16:32 33,088 --a------ C:\WINDOWS\system32\drivers\TfNetMon.sys
2008-10-18 16:32 . 2008-10-18 16:32 12,608 --a------ C:\WINDOWS\system32\drivers\TfKbMon.sys
2008-10-18 16:25 . 2008-10-18 16:38 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-10-18 09:24 . 2008-10-19 18:39 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-10-18 09:24 . 2008-10-18 09:24 <DIR> d-------- C:\Documents and Settings\xp\Application Data\PC Tools
2008-10-18 09:24 . 2008-10-18 09:39 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-10-18 09:24 . 2008-10-18 09:39 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-10-18 09:24 . 2008-10-18 09:39 40,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-10-18 09:24 . 2008-06-02 15:19 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-10-17 22:24 . 2008-10-19 18:39 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-17 20:17 . 2008-10-17 20:28 <DIR> d-------- C:\WINDOWS\LastGood(2)
2008-10-17 19:33 . 2001-09-19 15:00 66,082 --a--c--- C:\WINDOWS\system32\dllcache\c_20420.nls
2008-10-17 19:33 . 2001-09-19 15:00 66,082 --a------ C:\WINDOWS\system32\c_20420.nls
2008-10-10 00:43 . 2008-10-10 00:43 <DIR> d-------- C:\Program Files\2K Games
2008-10-05 20:38 . 2008-10-06 00:50 <DIR> d-------- C:\WINDOWS\NV55405880.TMP
2008-10-05 20:37 . 2008-10-05 20:37 <DIR> d-------- C:\NVIDIA
2008-10-05 19:35 . 2008-10-15 22:40 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-10-05 19:35 . 2008-10-15 22:39 <DIR> d-------- C:\Documents and Settings\xp\Application Data\SystemRequirementsLab
2008-10-05 03:56 . 2008-10-05 03:56 <DIR> d-------- C:\Program Files\Portable AVG Anti-Spyware 7.5
2008-10-03 06:19 . 2008-10-03 06:20 <DIR> d-------- C:\Program Files\Hotspot Shield
2008-10-02 08:12 . 2008-10-05 11:19 <DIR> d-------- C:\Program Files\The KMPlayer
2008-10-01 02:24 . 2008-10-18 17:41 <DIR> d-------- C:\Program Files\sXe Injected
2008-09-19 16:27 . 2006-03-17 03:38 28,672 --------- C:\WINDOWS\system32\verclsid.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-19 14:10 --------- d-----w C:\Documents and Settings\xp\Application Data\uTorrent
2008-10-10 03:15 --------- d-----w C:\Program Files\Image-Line
2008-10-09 21:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-05 17:39 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-10-04 00:35 --------- d-----w C:\Program Files\Image Upload
2008-10-02 04:59 --------- d-----w C:\Program Files\The KMPlayer1431
2008-09-20 04:32 --------- d-----w C:\Program Files\Kelk 2000
2008-09-16 18:27 453,152 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2008-09-16 04:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-09-16 04:22 --------- d-----w C:\Program Files\Windows Live
2008-09-16 03:09 921,632 ----a-w C:\PA207.DAT
2008-09-15 15:37 1,845,888 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-15 00:12 --------- d-----w C:\Program Files\Vstplugins
2008-09-15 00:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Codemasters
2008-09-15 00:08 --------- d-----w C:\Program Files\Ela-Salaty
2008-09-14 02:25 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-13 00:30 --------- d-----w C:\Program Files\ETAJV PC
2008-09-12 05:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-12 02:01 --------- d-----w C:\Program Files\DVB-S PowerInstall
2008-09-12 02:01 --------- d-----w C:\Program Files\Common Files\Elecard
2008-09-10 04:16 --------- d-----w C:\Program Files\D-Link
2008-09-10 04:16 --------- d-----w C:\Program Files\ANI
2008-09-08 02:55 --------- d-----w C:\Program Files\KWorld Multimedia
2008-09-08 02:27 --------- d-----w C:\Program Files\Internet Download Manager
2008-09-08 02:27 --------- d-----w C:\Documents and Settings\xp\Application Data\IDM
2008-09-07 19:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\DriverScanner
2008-09-07 19:28 --------- dc-h--w C:\Documents and Settings\All Users\Application Data\{5A76C6B3-3FA8-46D0-AA81-62C3805E38BC}
2008-09-07 19:28 --------- d-----w C:\Program Files\Uniblue
2008-09-07 19:28 --------- d-----w C:\Documents and Settings\xp\Application Data\Uniblue
2008-09-07 17:56 --------- d-----w C:\Program Files\aboal7roof
2008-09-07 17:54 --------- d-----w C:\Documents and Settings\xp\Application Data\DMCache
2008-09-06 19:04 --------- d-----w C:\Program Files\KONAMI
2008-09-06 18:43 --------- d--h--r C:\Documents and Settings\xp\Application Data\SecuROM
2008-09-05 22:31 --------- d-----w C:\Program Files\vPlug Files Center
2008-09-05 16:04 --------- d-----w C:\Program Files\Magic Video Converter
2008-09-05 16:02 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-09-05 15:59 --------- d-----w C:\Program Files\Sony Setup
2008-09-05 15:59 --------- d-----w C:\Documents and Settings\xp\Application Data\Sony
2008-09-05 15:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony
2008-09-03 14:59 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-03 14:59 --------- d-----w C:\Program Files\Circle Developement
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-26 07:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:42 2,137,600 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:42 2,017,280 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-04 01:58 81,920 ----a-w C:\Documents and Settings\xp\Application Data\ezpinst.exe
2008-08-04 01:58 47,360 ----a-w C:\Documents and Settings\xp\Application Data\pcouffin.sys
2008-07-30 01:38 30,615 ----a-w C:\WINDOWS\java\x.exe
2008-07-25 08:10 155,995 ----a-w C:\WINDOWS\java\Packages\8DJR5Z5J.ZIP
2008-07-25 08:06 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-07-25 08:06 388,466 ----a-w C:\WINDOWS\system32\cdky1.reg
2008-07-25 08:06 172,032 ------w C:\WINDOWS\Setup1.exe
2008-07-25 07:52 16,608 ----a-w C:\WINDOWS\gdrv.sys
2008-07-25 07:45 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-07-23 13:51 16,804,864 ----a-w C:\WINDOWS\RTHDCPL.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Steam"="e:\steam\steam.exe" [2008-10-10 1410296]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Google Update"="C:\Documents and Settings\xp\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-05 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-06-10 1447168]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"D-Link AirPlus G"="C:\Program Files\D-Link\AirPlus G\AirGCFG.exe" [2005-11-23 1544192]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2005-10-19 49152]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-09-17 13574144]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-07-31 185896]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-09-17 86016]
"nwiz"="nwiz.exe" [2008-09-17 C:\WINDOWS\system32\nwiz.exe]
"MsmqIntCert"="mqrt.dll" [2007-07-06 C:\WINDOWS\system32\mqrt.dll]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-23 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
C:\DOCUME~1\ALLUSE~1\A007~1\7D39~1\D51D~1\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 110592]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
C:\DOCUME~1\xp\A007~1\7D39~1\D51D~1\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
[HKLM\~\startupfolder\C:^Documents and Settings^xp^????? ????^???????^??? ???????^MagicDisc.lnk]
path=C:\Documents and Settings\xp\????? ????\???????\??? ???????\MagicDisc.lnk
backup=C:\WINDOWS\pss\MagicDisc.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xp^????? ????^???????^??? ???????^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Documents and Settings\xp\????? ????\???????\??? ???????\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USDownloader]
--a------ 2008-06-24 14:11 531456 C:\Documents and Settings\xp\My Documents\Downloads\Compressed\USDownloader135-ar\USDownloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"E:\\SteaM\\steamapps\\mohammed1412\\counter-strike source\\hl2.exe"=
"E:\\SteaM\\steamapps\\mohammed1412\\counter-strike\\hl.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"E:\\Counter-Strike DeathMatch\\hl.exe"=
"J:\\Games\\????? ??????\\Counter-Strike CPL\\hl.exe"=
"E:\\SteaM\\Steam.exe"=
"E:\\SteaM\\steamapps\\mohammed1412\\dedicated server\\hlds.exe"=
"D:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\WINDOWS\\system32\\mqsvc.exe"=
"G:\\Battlefield 2\\BF2.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Documents and Settings\\xp\\??? ??????\\iTunesv711\\iTunes.exe"=
"C:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization IV Colonization\\Colonization.exe"=
"E:\\SteaM\\steamapps\\mohammed1412\\diprip warm up\\hl2.exe"=
R0 878BDA;DVB-TV 878 BDA Driver;C:\WINDOWS\system32\Drivers\878BDA.sys [2006-04-04 86016]
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-06-10 34312]
R1 pctfw2;pctfw2;C:\WINDOWS\system32\drivers\pctfw2.sys [2008-10-18 160792]
R3 DAdderFltr;DeathAdder Mouse;C:\WINDOWS\system32\drivers\dadder.sys [2007-04-11 10880]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2008-01-24 27136]
S3 PAC207;Look 110;C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-03-01 507264]
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-10-19 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\xp\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-05 00:48]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\xp\Application Data\Mozilla\Firefox\Profiles\xy9khrlj.default\
FF -: plugin - C:\Documents and Settings\xp\Local Settings\Application Data\Google\Update\1.2.131.25\npGoogleOneClick6.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-19 18:50:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-10-19 18:52:21
ComboFix-quarantined-files.txt 2008-10-19 15:51:19
Pre-Run: 28,064,587,776 bytes free
Post-Run: 29,701,423,104 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
205 --- E O F --- 2008-10-18 06:03:42
اما الهآي جآك مآ اشتغل يقول خطأ 326
وش رآيك يالغلا..