صديقى العزيز هذا هو التقريرComboFix 08-12-11.03 - mina 12/12/2008 1:22:05.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.1145 [GMT 2:00]
Running from: c:\documents and settings\mina\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-11-11 to 2008-12-11 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-11 23:16 --------- d-----w c:\documents and settings\mina\Application Data\IDM
2008-12-11 23:16 --------- d-----w c:\documents and settings\mina\Application Data\DMCache
2008-12-11 23:15 --------- d-----w c:\program files\Internet Download Manager
2008-12-11 23:13 --------- d-----w c:\program files\Marvell
2008-12-11 23:12 --------- d-----w c:\program files\Realtek Sound Manager
2008-12-11 23:12 --------- d-----w c:\program files\AvRack
2008-12-11 23:10 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-11 23:10 --------- d-----w c:\program files\Intel
2008-12-11 23:08 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-11 22:49 --------- d-----w c:\program files\microsoft frontpage
2008-10-16 12:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 12:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 12:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 12:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 12:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 12:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 12:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 12:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 12:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 12:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 12:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 12:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 12:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-09-12 10:44 206,256 ----a-w c:\windows\system32\idmmbc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [12/12/2008 01:16 AM 2606512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [08/04/2004 03:07 AM 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [08/04/2004 03:07 AM 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [08/04/2004 03:07 AM 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [08/04/2004 03:07 AM 455168]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [07/26/2005 09:33 AM 6803456]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [07/26/2005 09:34 AM 86016]
"nwiz"="nwiz.exe" [07/26/2005 09:34 AM 1519616 c:\windows\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [04/15/2005 05:01 AM 77824 c:\windows\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 01:07 AM 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
*Newly Created Service* - INTELIDE
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
FF - ProfilePath - c:\documents and settings\mina\Application Data\Mozilla\Firefox\Profiles\mblmqoro.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.eg/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-12 01:22:53
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 12/12/2008 1:23:17
ComboFix-quarantined-files.txt 2008-12-11 23:23:18
Pre-Run: 968,253,440 bytes free
Post-Run: 998,572,032 bytes free
84