التقريرات مرة اخرى
دة تقرير الاداة
ComboFix 08-11-23.01 - Administrator 11/24/2008 4:46:41.6 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.61 [GMT 2:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-10-24 to 2008-11-24 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-22 06:33 --------- d-----w c:\documents and settings\Administrator\Application Data\TechSmith
2008-11-22 03:20 --------- d-----w c:\documents and settings\All Users\Application Data\TechSmith
2008-11-22 03:19 --------- d-----w c:\program files\TechSmith
2008-11-22 03:17 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-22 03:04 --------- d-----w c:\program files\Hide Your IP Address
2008-11-22 02:42 --------- d-----w c:\program files\Ashampoo
2008-11-22 01:12 --------- d-----w c:\documents and settings\Administrator\Application Data\TuneUp Software
2008-11-22 01:11 --------- d-----w c:\documents and settings\Administrator\Application Data\Thinstall
2008-11-21 22:49 --------- d-----w c:\program files\ColorSoft
2008-11-21 08:23 --------- d-----w c:\program files\No-IP
2008-11-21 05:48 --------- d-----w c:\program files\WWW File Share Pro
2008-11-21 01:40 --------- d-----w c:\program files\EsetOnlineScanner
2008-11-20 11:51 --------- d-----w c:\program files\PowerMenu
2008-11-20 11:23 --------- d-----w c:\program files\Desktop Icon Toy
2008-11-20 07:13 --------- d-----w c:\program files\Pic2Ico
2008-11-20 06:51 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-11-20 06:51 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-11-20 06:51 --------- d-----w c:\program files\Common Files\xing shared
2008-11-20 06:51 --------- d-----w c:\program files\Common Files\Real
2008-11-20 06:37 --------- d-----w c:\program files\Real
2008-11-20 06:32 --------- d-----w c:\program files\Winamp
2008-11-20 06:32 --------- d-----w c:\documents and settings\Administrator\Application Data\Winamp
2008-11-20 06:01 --------- d-----w c:\program files\FLV Player
2008-11-20 05:32 --------- d-----w c:\program files\D-Tools
2008-11-20 04:30 --------- d-----w c:\program files\Sun
2008-11-20 04:27 --------- d-----w c:\program files\Java
2008-11-20 04:27 --------- d-----w c:\program files\Common Files\Java
2008-11-20 01:20 --------- d-----w c:\documents and settings\Administrator\Application Data\IDM
2008-11-20 01:20 --------- d-----w c:\documents and settings\Administrator\Application Data\DMCache
2008-11-20 01:15 --------- d-----w c:\program files\Internet Download Manager
2008-11-20 00:41 --------- d-----w c:\program files\WinPcap
2008-11-19 23:53 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-11-19 21:21 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-11-19 21:08 --------- d-----w c:\program files\Yahoo!
2008-11-19 20:16 --------- d-----w c:\program files\netcut
2008-11-19 08:28 --------- d-----w c:\program files\a-squared Anti-Malware
2008-11-19 07:31 33,533 ----a-w c:\windows\system32\CoreVorbis-uninstall.exe
2008-11-19 07:27 36,734 ----a-w c:\windows\system32\OggDSuninst.exe
2008-11-19 07:27 --------- d-----w c:\program files\Morgan
2008-11-19 07:27 --------- d-----w c:\program files\ffdshow
2008-11-19 07:26 --------- d-----w c:\program files\XviD
2008-11-19 07:26 --------- d-----w c:\program files\AC3Filter
2008-11-19 07:18 --------- d-----w c:\program files\Windows Media Connect 2
2008-11-19 07:17 --------- d-----w c:\documents and settings\Administrator\Application Data\ESET
2008-11-19 07:14 1,682 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-11-19 07:14 --------- d-----w c:\program files\DivX
2008-11-19 07:12 --------- d-----w c:\program files\ESET
2008-11-19 07:12 --------- d-----w c:\documents and settings\All Users\Application Data\ESET
2008-11-19 06:57 --------- d-----w c:\program files\windows otions
2008-11-19 06:57 --------- d-----w c:\program files\SpiritPyre Extensions
2008-09-12 10:44 206,256 ----a-w c:\windows\system32\idmmbc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/14/2008 03:00 PM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="CL.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
"vidc.ffds"= c:\program files\ffdshow\ffdshow.ax
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^PowerMenu.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\PowerMenu.lnk
backup=c:\windows\pss\PowerMenu.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SnagIt 8.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SnagIt 8.lnk
backup=c:\windows\pss\SnagIt 8.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 04/14/2008 03:00 PM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 08/22/2004 05:05 PM 81920 c:\program files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DesktopIconToy]
--a------ 05/11/2008 11:26 AM 450560 c:\program files\Desktop Icon Toy\DesktopIconToy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
--a------ 06/10/2008 06:52 PM 1447168 c:\program files\ESET\ESET Smart Security\egui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 10/28/2008 01:39 PM 2606512 c:\program files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
--a------ 05/27/2008 09:58 PM 4269296 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 04/14/2008 05:42 AM 1695232 c:\program files\Messenger\msmsgs.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\WWW File Share Pro\\WWWFileSharePro.exe"=
"c:\\Program Files\\WWW File Share Pro\\Plugins\\Chat Room\\ChatRoom.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
R2 AntiARPClientLoader;AntiARP Client Loader;"c:\program files\ColorSoft\AntiARP\AntiARPClientLoader.exe" [10/17/2007 4:25:52 PM 40960]
R2 AntiArpNdisProt;AntiARP NDIS Protocol Driver;c:\windows\system32\DRIVERS\AntiArpNdisProt.sys [10/17/2007 1:33:10 PM 21120]
R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [4/14/2008 3:00:00 PM 14336]
R3 cwbmidi_device;Crystal WDM MPU-401 UART Driver;c:\windows\system32\drivers\cwbmidi.sys [11/19/2008 8:36:05 AM 3072]
R3 cwbwdm_device;Crystal WDM Audio Codec Driver;c:\windows\system32\drivers\cwbwdm.sys [11/19/2008 8:36:17 AM 72832]
R3 xAntiArp;xAntiArpSpoof Service;c:\windows\system32\DRIVERS\xAntiArp.sys [12/6/2007 2:16:26 PM 375296]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [8/2/2005 11:10:13 PM 32512]
S3 NtApm;NT Apm/Legacy Interface Driver;c:\windows\system32\DRIVERS\NtApm.sys [11/19/2008 8:38:00 AM 9344]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;c:\windows\System32\TuneUpDefragService.exe []
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-24 04:49:47
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 11/24/2008 4:51:18
ComboFix-quarantined-files.txt 2008-11-24 02:51:16
Pre-Run: 2,647,306,240 bytes free
Post-Run: 2,648,920,064 bytes free
135
ودى تقرير الهاجيك
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 04:54:20 ص, on 24/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ColorSoft\AntiARP\AntiARPClientLoader.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Administrator\Desktop\Zyzoom_HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com/
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) -
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) -
O23 - Service: AntiARP Client Loader (AntiARPClientLoader) - Unknown owner - C:\Program Files\ColorSoft\AntiARP\AntiARPClientLoader.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - Unknown owner - C:\WINDOWS\System32\TuneUpDefragService.exe (file missing)
--
End of file - 4431 bytes
يا ريت الرد السريع