قم بمتابعة الفيديو أدناه لمعرفة كيفية تثبيت موقعنا كتطبيق ويب على الشاشة الرئيسية.
ملاحظة: قد لا تكون هذه الميزة متاحة في بعض المتصفحات.
شــــــــــــــــــــــــــــــــــــــــــــــــكراComboFix 08-12-05.06 - Administrator 2008-12-06 14:52:32.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.126 [GMT 1:00]
Running from: c:\documents and settings\Administrator\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSSVC.EXE
c:\program files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\Cache\000EF836.bin
c:\program files\MyWebSearch\bar\Cache\000F5CFB.bin
c:\program files\MyWebSearch\bar\Cache\000F5ED0.bin
c:\program files\MyWebSearch\bar\Cache\000F63A2.bin
c:\program files\MyWebSearch\bar\Cache\0092995B
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\History\search3
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\program files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL
c:\program files\MyWebSearch\SrchAstt\9.bin\MWSSRCAS.DLL
c:\windows\system32\f3PSSavr.scr
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
-------\Service_MyWebSearchService
((((((((((((((((((((((((( Files Created from 2008-11-06 to 2008-12-06 )))))))))))))))))))))))))))))))
.
2008-12-04 22:38 . 2008-12-04 22:38 <DIR> d-------- c:\program files\RM to MP3 Converter
2008-12-04 18:17 . 2008-12-04 18:17 <DIR> d--hs---- C:\FOUND.008
2008-12-03 18:17 . 2008-12-03 18:17 <DIR> d-------- c:\windows\system32\Adobe
2008-11-30 23:22 . 2008-11-30 23:22 54,156 --ah----- c:\windows\QTFont.qfn
2008-11-30 23:22 . 2008-11-30 23:22 1,409 --a------ c:\windows\QTFont.for
2008-11-30 23:07 . 2008-11-30 23:07 <DIR> d--hs---- C:\FOUND.007
2008-11-28 20:45 . 2008-11-28 20:45 <DIR> d-------- c:\documents and settings\Administrator\Application Data\skypePM
2008-11-28 20:44 . 2008-11-28 20:44 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Skype
2008-11-28 19:34 . 2008-11-28 19:34 <DIR> d-------- c:\documents and settings\Administrator\Application Data\LimeWire
2008-11-26 21:15 . 2008-11-26 21:15 <DIR> d-------- c:\program files\DAP
2008-11-26 21:15 . 2008-11-26 21:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\SpeedBit
2008-11-26 21:15 . 2008-11-26 21:15 479,298 --a------ c:\windows\system32\wbocx.ocx
2008-11-26 21:15 . 2008-11-26 21:15 172,032 --a------ c:\windows\system32\AniGIF.ocx
2008-11-26 21:15 . 2008-11-26 21:15 50,688 --a------ c:\windows\system32\wbhelp2.dll
2008-11-26 19:16 . 2008-11-26 19:16 <DIR> d-------- c:\program files\AnswerWorks 4.0
2008-11-26 19:14 . 2008-11-26 19:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\Autodesk
2008-11-26 19:12 . 2008-11-26 19:12 <DIR> d-------- c:\program files\Autodesk
2008-11-26 18:45 . 2008-11-26 18:45 <DIR> d-------- c:\program files\K-Lite Codec Pack
2008-11-24 19:17 . 2008-11-24 19:17 <DIR> d-------- C:\Temp
2008-11-23 17:39 . 2008-11-23 17:39 <DIR> d-------- c:\windows\pdf2word
2008-11-23 17:39 . 2008-11-23 17:39 <DIR> d-------- c:\program files\UltiConverters
2008-11-23 17:38 . 2008-11-23 17:39 <DIR> d-------- c:\documents and settings\Administrator\Application Data\UltiConverters
2008-11-22 22:34 . 2008-11-22 22:34 0 --a------ c:\windows\system32\FOXIT_PDF
2008-11-22 16:32 . 2004-08-04 01:55 221,184 --a------ c:\windows\system32\wmpns.dll
2008-11-22 16:30 . 2008-11-22 16:30 <DIR> d-------- c:\windows\system32\drivers\UMDF
2008-11-21 19:15 . 2008-11-21 19:15 <DIR> d-------- c:\documents and settings\Administrator\Application Data\GRETECH
2008-11-21 18:41 . 2008-11-21 18:41 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Camfrog
2008-11-21 17:17 . 2008-11-21 17:17 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Autodesk
2008-11-21 11:41 . 2008-11-21 11:42 11,776 --ahs---- c:\windows\Thumbs.db
2008-11-19 21:07 . 2004-08-04 00:55 159,232 --a------ c:\windows\system32\ptpusd.dll
2008-11-19 21:07 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-11-19 21:07 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\dllcache\usbscan.sys
2008-11-19 21:07 . 2001-09-18 14:04 5,632 --a------ c:\windows\system32\ptpusb.dll
2008-11-19 18:44 . 2008-11-19 18:44 <DIR> d--hs---- C:\FOUND.006
2008-11-19 16:13 . 2008-11-19 16:13 <DIR> d--hs---- C:\FOUND.005
2008-11-10 19:37 . 2008-11-10 19:37 <DIR> d--hs---- C:\FOUND.004
2008-11-08 01:31 . 2008-11-08 01:31 <DIR> d-------- c:\program files\Avira
2008-11-08 01:31 . 2008-11-08 01:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-08 00:24 . 2008-11-08 00:24 0 --a------ c:\windows\PanelExe.INI
2008-11-08 00:06 . 2008-11-08 00:06 <DIR> d-------- c:\windows\system32\DRVSTORE
2008-11-08 00:05 . 2008-05-07 07:38 90,624 --a------ c:\windows\system32\nmwcdcls.dll
2008-11-08 00:03 . 2008-11-08 00:03 <DIR> d-------- c:\documents and settings\All Users\Application Data\Installations
2008-11-06 08:36 . 2001-09-18 13:38 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2008-11-06 08:36 . 2001-09-18 13:38 12,160 --a------ c:\windows\system32\dllcache\mouhid.sys
2008-11-06 08:36 . 2001-08-17 14:02 9,600 --a------ c:\windows\system32\drivers\hidusb.sys
2008-11-06 08:36 . 2001-08-17 14:02 9,600 --a------ c:\windows\system32\dllcache\hidusb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-05 21:49 --------- d-----w c:\documents and settings\All Users\Application Data\FreeDownloadManager.ORG
2008-11-05 21:49 --------- d-----w c:\documents and settings\Administrator\Application Data\Free Download Manager
2008-11-05 21:48 --------- d-----w c:\program files\Free Download Manager
2008-11-04 16:01 --------- d-----w c:\program files\MSBuild
2008-11-04 16:01 --------- d-----w c:\program files\Microsoft Works
2008-11-04 16:00 --------- d-----w c:\program files\Microsoft.NET
2008-11-02 21:50 --------- d-----w c:\program files\Camfrog
2008-11-02 19:42 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-11-02 18:51 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-11-02 18:51 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-11-02 18:51 --------- d-----w c:\program files\Common Files\xing shared
2008-10-31 23:39 --------- d-----w c:\program files\Ela-Salaty
2008-10-31 23:20 --------- d-----w c:\program files\Quranzu1
2008-10-27 17:07 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-26 16:33 --------- d-----w c:\program files\AMT
2008-10-25 20:08 --------- d-----w c:\program files\CCleaner
2008-10-21 21:00 --------- d-----w c:\program files\ARCHICAD 10
2008-10-21 18:47 --------- d-----w c:\program files\WIBUKEY(2)
2008-10-17 22:22 --------- d-----w c:\documents and settings\Administrator\Application Data\Apple Computer
2008-10-16 19:40 --------- d-----w c:\documents and settings\Administrator\Application Data\Graphisoft
2008-10-16 19:24 --------- d-----w c:\program files\WIBU-SYSTEMS
2008-10-16 19:22 --------- d-----w c:\program files\QuickTime
2008-10-16 19:14 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-10-15 19:55 --------- d-----w c:\documents and settings\All Users\Application Data\TEMP
2008-10-12 20:13 --------- d-----w c:\program files\Java
2008-10-11 22:25 --------- d-----w c:\program files\Foxit Software
2008-10-11 22:02 --------- d-----w c:\documents and settings\Administrator\Application Data\Media Player Classic
2008-10-10 23:10 --------- d-----w c:\program files\Skype
2008-10-10 15:11 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-10-10 11:44 --------- d-----w c:\program files\Real
2008-10-10 11:44 --------- d-----w c:\program files\Common Files\Real
2008-10-10 11:14 --------- d-----w c:\program files\Opera
2008-10-10 10:48 --------- d-----w c:\program files\GRETECH
2008-10-10 10:48 --------- d-----w c:\documents and settings\All Users\Application Data\GRETECH
2008-10-10 09:47 --------- d-----w c:\program files\Google
2008-10-10 06:55 94,208 ----a-w c:\windows\system32\ScrUnZip.dll
2008-10-09 19:06 --------- d-----w c:\documents and settings\Administrator\Application Data\DMCache
2008-10-08 02:26 --------- d-----w c:\program files\Common Files\Autodesk Shared
2008-10-08 02:19 --------- d-----w c:\program files\Common Files\Adobe
2008-10-08 02:16 315,392 ----a-w c:\windows\HideWin.exe
2008-10-08 02:16 --------- d-----w c:\program files\Realtek
2008-10-08 02:16 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-08 00:46 --------- d-----w c:\program files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-31 39408]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2008-05-20 2474031]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-10-16 155648]
"CAP3ON"="c:\windows\system32\spool\drivers\w32x86\3\CAP3ONN.EXE" [2002-08-06 22528]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-11-02 185872]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\Administrator\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Ela-Salaty.lnk - c:\program files\Ela-Salaty\Salaty.exe [2007-03-05 5205504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 1 (0x1)
"SynchronousUserGroupPolicy"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 0 (0x0)
"MemCheckBoxInRunDlg"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoWelcomeScreen"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"ForceClassicControlPanel"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinterTabs"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoChange"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ARCHICAD 10\\ArchiCAD 10\\ArchiCAD.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\groove.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9393:TCP"= 9393:TCP:BitComet 9393 TCP
"9393:UDP"= 9393:UDP:BitComet 9393 UDP
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{002377c8-ab6c-11dd-8b65-001837050f72}]
\Shell\AutoRun\command - H:\start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b7a86334-a375-11dd-8b47-001837050f72}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.dz/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: &Search -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free Download Manager تحميل الفيديو بواسطة - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: تحميل المحددة بفري داونلود مانيجر - file://c:\program files\Free Download Manager\dlselected.htm
IE: تنزيل الكل بفري داونلود مانيجر - file://c:\program files\Free Download Manager\dlall.htm
IE: تنزيل بفري داونلود مانيجر - file://c:\program files\Free Download Manager\dllink.htm
FireFox -: Profile - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\m7cha97m.default\
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\NPMyWebS.dll
FF -: plugin - c:\program files\Opera\program\plugins\NPOFF12.DLL
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
Rootkit scan 2008-12-06 14:55:01
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\SCHED.EXE
c:\program files\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\AVGUARD.EXE
c:\windows\SYSTEM32\CAP3RSK.EXE
c:\program files\ADOBE\ACROBAT 7.0\READER\READER_SL.EXE
c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3LAK.EXE
c:\program files\WINZIP\WZQKPICK.EXE
c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-12-06 14:56:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-06 13:56:04
Pre-Run: 12 749 684 736 bytes free
Post-Run: 12,678,807,552 bytes free
251
ComboFix 08-12-05.06 - Administrator 2008-12-06 14:52:32.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.126 [GMT 1:00]
Running from: c:\documents and settings\Administrator\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSSVC.EXE
c:\program files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\Cache\000EF836.bin
c:\program files\MyWebSearch\bar\Cache\000F5CFB.bin
c:\program files\MyWebSearch\bar\Cache\000F5ED0.bin
c:\program files\MyWebSearch\bar\Cache\000F63A2.bin
c:\program files\MyWebSearch\bar\Cache\0092995B
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\History\search3
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\program files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL
c:\program files\MyWebSearch\SrchAstt\9.bin\MWSSRCAS.DLL
c:\windows\system32\f3PSSavr.scr
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
-------\Service_MyWebSearchService
((((((((((((((((((((((((( Files Created from 2008-11-06 to 2008-12-06 )))))))))))))))))))))))))))))))
.
2008-12-04 22:38 . 2008-12-04 22:38 <DIR> d-------- c:\program files\RM to MP3 Converter
2008-12-04 18:17 . 2008-12-04 18:17 <DIR> d--hs---- C:\FOUND.008
2008-12-03 18:17 . 2008-12-03 18:17 <DIR> d-------- c:\windows\system32\Adobe
2008-11-30 23:22 . 2008-11-30 23:22 54,156 --ah----- c:\windows\QTFont.qfn
2008-11-30 23:22 . 2008-11-30 23:22 1,409 --a------ c:\windows\QTFont.for
2008-11-30 23:07 . 2008-11-30 23:07 <DIR> d--hs---- C:\FOUND.007
2008-11-28 20:45 . 2008-11-28 20:45 <DIR> d-------- c:\documents and settings\Administrator\Application Data\skypePM
2008-11-28 20:44 . 2008-11-28 20:44 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Skype
2008-11-28 19:34 . 2008-11-28 19:34 <DIR> d-------- c:\documents and settings\Administrator\Application Data\LimeWire
2008-11-26 21:15 . 2008-11-26 21:15 <DIR> d-------- c:\program files\DAP
2008-11-26 21:15 . 2008-11-26 21:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\SpeedBit
2008-11-26 21:15 . 2008-11-26 21:15 479,298 --a------ c:\windows\system32\wbocx.ocx
2008-11-26 21:15 . 2008-11-26 21:15 172,032 --a------ c:\windows\system32\AniGIF.ocx
2008-11-26 21:15 . 2008-11-26 21:15 50,688 --a------ c:\windows\system32\wbhelp2.dll
2008-11-26 19:16 . 2008-11-26 19:16 <DIR> d-------- c:\program files\AnswerWorks 4.0
2008-11-26 19:14 . 2008-11-26 19:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\Autodesk
2008-11-26 19:12 . 2008-11-26 19:12 <DIR> d-------- c:\program files\Autodesk
2008-11-26 18:45 . 2008-11-26 18:45 <DIR> d-------- c:\program files\K-Lite Codec Pack
2008-11-24 19:17 . 2008-11-24 19:17 <DIR> d-------- C:\Temp
2008-11-23 17:39 . 2008-11-23 17:39 <DIR> d-------- c:\windows\pdf2word
2008-11-23 17:39 . 2008-11-23 17:39 <DIR> d-------- c:\program files\UltiConverters
2008-11-23 17:38 . 2008-11-23 17:39 <DIR> d-------- c:\documents and settings\Administrator\Application Data\UltiConverters
2008-11-22 22:34 . 2008-11-22 22:34 0 --a------ c:\windows\system32\FOXIT_PDF
2008-11-22 16:32 . 2004-08-04 01:55 221,184 --a------ c:\windows\system32\wmpns.dll
2008-11-22 16:30 . 2008-11-22 16:30 <DIR> d-------- c:\windows\system32\drivers\UMDF
2008-11-21 19:15 . 2008-11-21 19:15 <DIR> d-------- c:\documents and settings\Administrator\Application Data\GRETECH
2008-11-21 18:41 . 2008-11-21 18:41 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Camfrog
2008-11-21 17:17 . 2008-11-21 17:17 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Autodesk
2008-11-21 11:41 . 2008-11-21 11:42 11,776 --ahs---- c:\windows\Thumbs.db
2008-11-19 21:07 . 2004-08-04 00:55 159,232 --a------ c:\windows\system32\ptpusd.dll
2008-11-19 21:07 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-11-19 21:07 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\dllcache\usbscan.sys
2008-11-19 21:07 . 2001-09-18 14:04 5,632 --a------ c:\windows\system32\ptpusb.dll
2008-11-19 18:44 . 2008-11-19 18:44 <DIR> d--hs---- C:\FOUND.006
2008-11-19 16:13 . 2008-11-19 16:13 <DIR> d--hs---- C:\FOUND.005
2008-11-10 19:37 . 2008-11-10 19:37 <DIR> d--hs---- C:\FOUND.004
2008-11-08 01:31 . 2008-11-08 01:31 <DIR> d-------- c:\program files\Avira
2008-11-08 01:31 . 2008-11-08 01:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-08 00:24 . 2008-11-08 00:24 0 --a------ c:\windows\PanelExe.INI
2008-11-08 00:06 . 2008-11-08 00:06 <DIR> d-------- c:\windows\system32\DRVSTORE
2008-11-08 00:05 . 2008-05-07 07:38 90,624 --a------ c:\windows\system32\nmwcdcls.dll
2008-11-08 00:03 . 2008-11-08 00:03 <DIR> d-------- c:\documents and settings\All Users\Application Data\Installations
2008-11-06 08:36 . 2001-09-18 13:38 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2008-11-06 08:36 . 2001-09-18 13:38 12,160 --a------ c:\windows\system32\dllcache\mouhid.sys
2008-11-06 08:36 . 2001-08-17 14:02 9,600 --a------ c:\windows\system32\drivers\hidusb.sys
2008-11-06 08:36 . 2001-08-17 14:02 9,600 --a------ c:\windows\system32\dllcache\hidusb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-05 21:49 --------- d-----w c:\documents and settings\All Users\Application Data\FreeDownloadManager.ORG
2008-11-05 21:49 --------- d-----w c:\documents and settings\Administrator\Application Data\Free Download Manager
2008-11-05 21:48 --------- d-----w c:\program files\Free Download Manager
2008-11-04 16:01 --------- d-----w c:\program files\MSBuild
2008-11-04 16:01 --------- d-----w c:\program files\Microsoft Works
2008-11-04 16:00 --------- d-----w c:\program files\Microsoft.NET
2008-11-02 21:50 --------- d-----w c:\program files\Camfrog
2008-11-02 19:42 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-11-02 18:51 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-11-02 18:51 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-11-02 18:51 --------- d-----w c:\program files\Common Files\xing shared
2008-10-31 23:39 --------- d-----w c:\program files\Ela-Salaty
2008-10-31 23:20 --------- d-----w c:\program files\Quranzu1
2008-10-27 17:07 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-26 16:33 --------- d-----w c:\program files\AMT
2008-10-25 20:08 --------- d-----w c:\program files\CCleaner
2008-10-21 21:00 --------- d-----w c:\program files\ARCHICAD 10
2008-10-21 18:47 --------- d-----w c:\program files\WIBUKEY(2)
2008-10-17 22:22 --------- d-----w c:\documents and settings\Administrator\Application Data\Apple Computer
2008-10-16 19:40 --------- d-----w c:\documents and settings\Administrator\Application Data\Graphisoft
2008-10-16 19:24 --------- d-----w c:\program files\WIBU-SYSTEMS
2008-10-16 19:22 --------- d-----w c:\program files\QuickTime
2008-10-16 19:14 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-10-15 19:55 --------- d-----w c:\documents and settings\All Users\Application Data\TEMP
2008-10-12 20:13 --------- d-----w c:\program files\Java
2008-10-11 22:25 --------- d-----w c:\program files\Foxit Software
2008-10-11 22:02 --------- d-----w c:\documents and settings\Administrator\Application Data\Media Player Classic
2008-10-10 23:10 --------- d-----w c:\program files\Skype
2008-10-10 15:11 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-10-10 11:44 --------- d-----w c:\program files\Real
2008-10-10 11:44 --------- d-----w c:\program files\Common Files\Real
2008-10-10 11:14 --------- d-----w c:\program files\Opera
2008-10-10 10:48 --------- d-----w c:\program files\GRETECH
2008-10-10 10:48 --------- d-----w c:\documents and settings\All Users\Application Data\GRETECH
2008-10-10 09:47 --------- d-----w c:\program files\Google
2008-10-10 06:55 94,208 ----a-w c:\windows\system32\ScrUnZip.dll
2008-10-09 19:06 --------- d-----w c:\documents and settings\Administrator\Application Data\DMCache
2008-10-08 02:26 --------- d-----w c:\program files\Common Files\Autodesk Shared
2008-10-08 02:19 --------- d-----w c:\program files\Common Files\Adobe
2008-10-08 02:16 315,392 ----a-w c:\windows\HideWin.exe
2008-10-08 02:16 --------- d-----w c:\program files\Realtek
2008-10-08 02:16 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-08 00:46 --------- d-----w c:\program files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-31 39408]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2008-05-20 2474031]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-10-16 155648]
"CAP3ON"="c:\windows\system32\spool\drivers\w32x86\3\CAP3ONN.EXE" [2002-08-06 22528]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-11-02 185872]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\Administrator\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Ela-Salaty.lnk - c:\program files\Ela-Salaty\Salaty.exe [2007-03-05 5205504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 1 (0x1)
"SynchronousUserGroupPolicy"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 0 (0x0)
"MemCheckBoxInRunDlg"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoWelcomeScreen"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"ForceClassicControlPanel"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinterTabs"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoChange"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ARCHICAD 10\\ArchiCAD 10\\ArchiCAD.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\groove.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9393:TCP"= 9393:TCP:BitComet 9393 TCP
"9393:UDP"= 9393:UDP:BitComet 9393 UDP
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{002377c8-ab6c-11dd-8b65-001837050f72}]
\Shell\AutoRun\command - H:\start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b7a86334-a375-11dd-8b47-001837050f72}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.dz/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: &Search -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free Download Manager تحميل الفيديو بواسطة - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: تحميل المحددة بفري داونلود مانيجر - file://c:\program files\Free Download Manager\dlselected.htm
IE: تنزيل الكل بفري داونلود مانيجر - file://c:\program files\Free Download Manager\dlall.htm
IE: تنزيل بفري داونلود مانيجر - file://c:\program files\Free Download Manager\dllink.htm
FireFox -: Profile - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\m7cha97m.default\
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\NPMyWebS.dll
FF -: plugin - c:\program files\Opera\program\plugins\NPOFF12.DLL
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
Rootkit scan 2008-12-06 14:55:01
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\SCHED.EXE
c:\program files\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\AVGUARD.EXE
c:\windows\SYSTEM32\CAP3RSK.EXE
c:\program files\ADOBE\ACROBAT 7.0\READER\READER_SL.EXE
c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3LAK.EXE
c:\program files\WINZIP\WZQKPICK.EXE
c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-12-06 14:56:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-06 13:56:04
Pre-Run: 12 749 684 736 bytes free
Post-Run: 12,678,807,552 bytes free
251
جهازك فيه اصابات وتم حذفها
اعمل التالي
(2)
واعمل تقرير للهايجاك
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
اذا انتهى التحميل ==> شغل البرنامج ==> واضغط على Do a system scan and save log
لحظات ويظهر لك تقرير ,, انسخه والصقه بردك القادم