شكرا اخي على اهتمامك
للعلم
الجهاز ما اعاد التشغيل اثناء كمبو فكس
وهذا تقريره
ComboFix 08-11-12.02 - ahmad 11/15/2008 18:44:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.20.1033.18.1376 [GMT 4.5:30]
Running from: c:\documents and settings\ahmad\My Documents\Downloads\Programs\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\msvrc20.dll
.
((((((((((((((((((((((((( Files Created from 2008-10-15 to 2008-11-15 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-15 14:15 --------- d-----w c:\documents and settings\ahmad\Application Data\DMCache
2008-11-15 12:27 --------- d-----w c:\program files\DVBViewerTE
2008-11-15 12:25 --------- d-----w c:\program files\BearFlix
2008-11-13 05:57 --------- d-----w c:\documents and settings\ahmad\Application Data\Apple Computer
2008-11-12 16:33 --------- d-----w c:\program files\ProgDVB
2008-11-12 16:32 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-12 16:32 --------- d-----w c:\program files\مشغل الفلاش العربي
2008-11-12 16:32 --------- d-----w c:\program files\TechniSat DVB
2008-11-12 16:32 --------- d-----w c:\program files\ProgEdit
2008-11-12 16:32 --------- d-----w c:\program files\ProgDVBStd
2008-11-12 16:32 --------- d-----w c:\program files\IGI Subtitler
2008-11-12 16:32 --------- d-----w c:\program files\DVB-S PowerInstall
2008-11-12 16:32 --------- d-----w c:\program files\Common Files\Elecard
2008-11-12 16:32 --------- d-----w c:\documents and settings\ahmad\Application Data\dvdcss
2008-11-12 16:10 --------- d-----w c:\documents and settings\ahmad\Application Data\Avira
2008-11-11 21:00 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2008-11-10 17:16 --------- d-----w c:\documents and settings\ahmad\Application Data\Thinstall
2008-11-07 22:08 --------- d-----w c:\program files\MainConcept
2008-11-07 22:08 --------- d-----w c:\documents and settings\All Users\Application Data\Technisat
2008-11-07 22:08 --------- d-----w c:\documents and settings\All Users\Application Data\CMUV
2008-11-07 17:49 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01001_Coinstaller_Critical.Wdf
2008-11-07 17:49 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf
2008-11-07 17:48 --------- d-----w c:\program files\Microsoft Xbox 360 Accessories
2008-11-06 17:09 36,734 ----a-w c:\windows\system32\OggDSuninst.exe
2008-11-06 17:09 33,021 ----a-w c:\windows\system32\CoreVorbis-uninstall.exe
2008-11-06 17:09 --------- d-----w c:\program files\AC3Filter
2008-11-06 17:08 --------- d-----w c:\program files\Xvid
2008-11-06 17:08 --------- d-----w c:\program files\Elecard MPEG2 Decoder Package 2.0
2008-11-06 17:08 --------- d-----w c:\program files\DVBPortal
2008-11-06 17:07 --------- d-----w c:\program files\Mpeg2dec
2008-11-06 16:41 319,488 ----a-w c:\windows\HideWin.exe
2008-11-06 15:11 --------- d-----w c:\documents and settings\ahmad\Application Data\DivX
2008-11-06 13:37 --------- d-----w c:\program files\Intel
2008-11-06 13:36 21,035 ----a-w c:\windows\system32\drivers\AegisP.sys
2008-11-06 13:36 --------- d-----w c:\program files\REALTEK
2008-11-06 13:35 --------- d-----w c:\documents and settings\ahmad\Application Data\InstallShield
2008-11-06 13:07 --------- d-----w c:\program files\DivX
2008-11-05 20:19 --------- d-----w c:\program files\Elecard
2008-11-05 20:12 --------- d-----w c:\program files\vPlug Files Center
2008-11-05 09:34 --------- d-----w c:\documents and settings\ahmad\Application Data\XnView
2008-11-04 20:53 --------- d-----w c:\documents and settings\ahmad\Application Data\vlc
2008-11-04 20:51 --------- d-----w c:\program files\VideoLAN
2008-11-04 13:18 --------- d-----w c:\program files\Avant Browser
2008-11-03 17:40 --------- d-----w c:\program files\WorldOfGoo
2008-11-03 17:40 --------- d-----w c:\documents and settings\All Users\Application Data\2DBoy
2008-11-03 15:33 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-11-03 15:32 22,328 ----a-w c:\documents and settings\ahmad\Application Data\PnkBstrK.sys
2008-11-03 15:28 --------- d-----w c:\program files\Ubisoft
2008-11-03 15:12 --------- d-----w c:\program files\microsoft frontpage
2008-11-03 14:35 355,584 ----a-w c:\windows\system32\TuneUpDefragService.exe
2008-11-03 14:35 --------- d-----w c:\program files\TuneUp Utilities 2008
2008-11-03 14:35 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-03 13:51 --------- d-----w c:\documents and settings\All Users\Application Data\ATI
2008-11-03 13:51 --------- d-----w c:\documents and settings\ahmad\Application Data\ATI
2008-11-03 13:49 --------- d-----w c:\program files\ATI Technologies
2008-11-03 13:48 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-03 02:52 --------- d-----w c:\documents and settings\ahmad\Application Data\Winamp
2008-11-02 21:52 --------- d-----w c:\program files\BitSpirit
2008-11-02 18:40 --------- d-----w c:\program files\XP TCPIP Repair
2008-11-02 18:40 --------- d-----w c:\program files\Desktop Sidebar
2008-11-02 18:40 --------- d-----w c:\documents and settings\ahmad\Application Data\Desktop Sidebar
2008-11-02 18:17 --------- d-----w c:\documents and settings\ahmad\Application Data\IDM
2008-11-02 17:08 --------- d-----w c:\documents and settings\All Users\Application Data\TuneUp Software
2008-11-02 17:08 --------- d-----w c:\documents and settings\ahmad\Application Data\TuneUp Software
2008-11-02 16:32 --------- d-----w c:\documents and settings\ahmad\Application Data\SlipStream
2008-11-02 16:25 --------- d-----w c:\documents and settings\ahmad\Application Data\BitSpirit
2008-11-02 15:34 --------- d-----w c:\program files\Google
2008-11-02 00:55 --------- d-----w c:\program files\Common Files\Sonic Shared
2008-11-01 22:16 --------- d-----w c:\documents and settings\ahmad\Application Data\Media Player Classic
2008-11-01 09:35 --------- d-----w c:\program files\Reference Assemblies
2008-11-01 09:35 --------- d-----w c:\program files\MSBuild
2008-11-01 09:33 --------- d-----w c:\program files\K-Lite Codec Pack
2008-11-01 09:20 --------- d-----w c:\program files\Siber Systems
2008-11-01 09:20 --------- d-----w c:\documents and settings\All Users\Application Data\RoboForm
2008-11-01 09:16 --------- d-----w c:\documents and settings\ahmad\Application Data\Avant Profiles
2008-11-01 09:14 --------- d-----w c:\program files\VerbAce
2008-11-01 08:42 --------- d-----w c:\program files\Avira
2008-10-31 23:44 --------- d-----w c:\program files\Vortex Tools
2008-10-31 23:44 --------- d-----w c:\program files\%tmp%
2008-10-31 22:39 --------- d-----w c:\documents and settings\ahmad\Application Data\ViStart
2008-10-31 22:33 --------- d-----w c:\documents and settings\ahmad\Application Data\FastStone
2008-10-31 21:59 --------- d-----w c:\program files\Driver-Soft
2008-10-31 21:57 --------- d-----w c:\program files\MSXML 6.0
2008-10-31 21:57 --------- d-----w c:\program files\MSXML 4.0
2008-10-31 21:55 --------- d-----w c:\program files\Windows Media Connect 2
2008-10-31 21:55 --------- d-----w c:\program files\Windows Live
2008-10-31 21:55 --------- d-----w c:\program files\Winamp
2008-10-31 21:55 --------- d-----w c:\program files\UltraISO
2008-10-31 21:55 --------- d-----w c:\program files\Common Files\EZB Systems
2008-10-31 21:54 155,995 ----a-w c:\windows\java\Packages\MND3VPFZ.ZIP
2008-10-31 21:54 --------- d-----w c:\program files\Real Alternative
2008-10-31 21:47 --------- d-----w c:\program files\Foxit Software
2008-10-28 22:36 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-10-28 22:36 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-10-28 22:35 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-10-28 22:35 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-10-28 22:35 684,032 ----a-w c:\windows\system32\DivX.dll
2008-10-27 05:34 70,992 ----a-w c:\windows\system32\XAPOFX1_2.dll
2008-10-27 05:34 514,384 ----a-w c:\windows\system32\XAudio2_3.dll
2008-10-27 05:34 235,856 ----a-w c:\windows\system32\xactengine3_3.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [04/14/2008 04:42 AM 15360]
"IDMan"="c:\documents and settings\Default User\Local Settings\Temp\bsasee3y5d\IDMan.exe" [12/21/2007 07:16 PM 2573744]
"LClock"="c:\program files\Vortex Tools\Classes\vortex\vista\LClock\LClock.exe" [09/19/2004 10:57 PM 65536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Vistadrv"="c:\program files\Vortex Tools\Classes\vortex\vista\VIPhd\vsdrv.exe" [07/30/2006 05:07 AM 121089]
"avgnt"="c:\program files\Avira\Avira Premium Security Suite\avgnt.exe" [06/12/2008 02:28 PM 266497]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [08/01/2008 03:23 PM 61440]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [09/26/2007 06:05 PM 734264]
"RTHDCPL"="RTHDCPL.EXE" [10/09/2008 02:54 PM 17021440 c:\windows\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/14/2008 04:42 AM 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
REALTEK RTL8187 Wireless LAN Utility.lnk - c:\program files\REALTEK\RTL8187 Wireless LAN Utility\RtWLan.exe [2008-11-06 815104]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"VisualTooltip"=c:\program files\Vortex Tools\Classes\vortex\vista\VisualTaskTips\VisualTaskTips.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitSpirit\\BitSpirit.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"e:\\Downloads\\Pro.Evolution.Soccer.2009.Full-Rip.Skullptura\\PES 2009\\pes2009.exe"=
R1 avfwot;avfwot;c:\windows\system32\DRIVERS\avfwot.sys [05/07/2008 02:20 PM 71592]
R1 Cinemsup;Cinemsup;c:\windows\system32\drivers\Cinemsup.sys [07/19/2002 08:10 AM 6656]
R2 AntiVirFirewallService;Avira Premium Security Suite Firewall;c:\program files\Avira\Avira Premium Security Suite\avfwsvc.exe [05/16/2008 10:19 AM 344321]
R2 AntiVirMailService;Avira Premium Security Suite MailGuard;c:\program files\Avira\Avira Premium Security Suite\avmailc.exe [07/11/2008 12:23 PM 164097]
R2 antivirwebservice;Avira Premium Security Suite WebGuard;c:\program files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE [06/12/2008 02:59 PM 258305]
R2 AVEService;Avira Premium Security Suite MailGuard helper service;c:\program files\Avira\Avira Premium Security Suite\avesvc.exe [05/09/2008 01:22 PM 41217]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\DRIVERS\EAPPkt.sys [10/09/2007 01:13 PM 38144]
R2 UxTuneUp;TuneUp Theme Extension;c:\windows\System32\svchost.exe [04/14/2008 04:42 AM 14336]
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\DRIVERS\avfwim.sys [05/07/2008 10:51 AM 71464]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187.sys [06/27/2008 09:39 AM 332928]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\DRIVERS\SkyNET.SYS [09/24/2008 09:27 AM 510992]
S3 tap0801co;TAP-Win32 Adapter V8 (coLinux);c:\windows\system32\DRIVERS\tap0801co.sys [08/31/2006 03:47 AM 25856]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;c:\windows\System32\TuneUpDefragService.exe [11/03/2008 07:05 PM 355584]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-11-15 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [06/20/2008 09:09 AM]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\ahmad\Application Data\Mozilla\Firefox\Profiles\fi1ljg3j.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - google.com.sa
FF -: plugin - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-15 18:45:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 11/15/2008 18:45:40
ComboFix-quarantined-files.txt 2008-11-15 14:15:33
Pre-Run: 85,580,738,560 bytes free
Post-Run: 86,560,714,752 bytes free
207 --- E O F --- 2008-11-13 10:59:17