مراحب
بس للمعلومية الجهاز لم يعد من حالو يعني دقايق وجاني التقرير في مشكلة في دا الشي ولاء ؟
على العموم دا التقرير :
ComboFix 08-12-18.03 - Administrator 12/21/2008 12:41:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.503.182 [GMT 3:00]
Running from: c:\documents and settings\Administrator\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-11-21 to 2008-12-21 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-21 09:41 --------- d-----w c:\documents and settings\Administrator\Application Data\DMCache
2008-12-18 21:32 --------- d-----w c:\documents and settings\Administrator\Application Data\uTorrent
2008-12-18 01:36 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-12-18 01:36 --------- d-----w c:\program files\Java
2008-12-14 12:40 --------- d-----w c:\documents and settings\Administrator\Application Data\IDM
2008-12-12 17:51 --------- d-----w c:\documents and settings\Guest\Application Data\FastStone
2008-12-12 09:32 --------- d-----w c:\program files\JetAudio
2008-12-11 22:24 --------- d-----w c:\documents and settings\Guest\Application Data\COWON
2008-12-11 18:51 --------- d-----w c:\documents and settings\Guest\Application Data\Products
2008-12-11 18:51 --------- d-----w c:\documents and settings\Guest\Application Data\Grisoft
2008-12-11 13:24 --------- d-----w c:\program files\No-IP
2008-12-10 04:36 --------- d-----w c:\documents and settings\Administrator\Application Data\BSplayer Pro
2008-12-05 10:21 --------- d-----w c:\documents and settings\Administrator\Application Data\Steady Recorder
2008-12-05 09:58 --------- d-----w c:\program files\XemiComputers
2008-12-05 09:23 --------- d-----w c:\program files\Steady Recorder
2008-12-05 09:21 --------- d-----w c:\program files\Power Mp3 Cutter(Mp3 Sound Cutter)
2008-12-05 08:36 --------- d-----w c:\program files\Hotspot Shield
2008-12-04 14:44 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-12-04 00:17 --------- d-----w c:\documents and settings\All Users\Application Data\Winferno
2008-12-04 00:11 --------- d-----w c:\program files\Winferno
2008-12-03 01:38 --------- d-----w c:\program files\Internet Download Manager
2008-12-03 01:11 --------- d-----w c:\program files\Common Files\Winferno
2008-11-30 15:56 --------- d-----w c:\program files\uTorrent
2008-11-29 04:45 --------- d-----w c:\documents and settings\Administrator\Application Data\Grisoft
2008-11-29 04:44 --------- d-----w c:\documents and settings\All Users\Application Data\Grisoft
2008-11-29 04:19 --------- d-----w c:\program files\Bit Che
2008-11-29 04:18 --------- d-----w c:\documents and settings\Administrator\Application Data\Convivea
2008-11-28 12:45 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-11-28 12:45 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-11-28 12:45 --------- d-----w c:\program files\Real
2008-11-28 12:45 --------- d-----w c:\program files\Common Files\xing shared
2008-11-28 12:45 --------- d-----w c:\program files\Common Files\Real
2008-11-27 08:15 --------- d-----w c:\program files\CCleaner
2008-11-27 08:12 --------- d-----w c:\program files\FastStone Image Viewer
2008-11-27 08:12 --------- d-----w c:\documents and settings\Administrator\Application Data\FastStone
2008-11-27 07:33 --------- d-----w c:\program files\Ares
2008-11-27 05:01 --------- d-----w c:\program files\Windows Live
2008-11-27 05:01 --------- d-----w c:\program files\MSN Messenger
2008-11-27 05:01 --------- d-----w c:\program files\Messenger Plus! Live
2008-11-26 23:28 --------- d-----w c:\documents and settings\Administrator\Application Data\Products
2008-11-26 23:18 --------- d-----w c:\program files\Gabest
2008-11-26 23:17 --------- d-----w c:\program files\Foxit Software
2008-11-26 23:12 --------- d-----w c:\documents and settings\Administrator\Application Data\GRETECH
2008-11-26 22:59 --------- d-----w c:\documents and settings\Administrator\Application Data\COWON
2008-11-26 22:27 --------- d-----w c:\documents and settings\All Users\Application Data\WinZip
2008-11-26 22:18 --------- d-----w c:\program files\Common Files\COWON
2008-11-26 22:17 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-26 22:17 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-26 22:16 --------- d-----w c:\program files\GRETECH
2008-11-26 22:13 --------- d-----w c:\program files\Webteh
2008-11-25 23:42 --------- d-----w c:\program files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
12/04/2008 12:42 PM 204248 --a------ c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [01/19/2007 12:55 PM 5674352]
"ares"="c:\program files\Ares\Ares.exe" [11/24/2008 12:19 AM 880640]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [11/25/2008 09:19 AM 935856]
"ANR"="c:\program files\XemiComputers\Audio Notes Recorder\ANR.exe" [10/09/2008 07:43 AM 4052480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [12/14/2003 07:20 PM 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [12/14/2003 07:07 PM 118784]
"AutoDialogs"="d:\ملفاتي\Download\adsetup.exe" [12/16/2007 11:46 PM 666112]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [11/28/2008 03:45 PM 185872]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" [11/03/2007 04:50 AM 6731312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [12/18/2008 04:36 AM 136600]
"SoundMan"="SOUNDMAN.EXE" [01/08/2004 09:54 PM 65536 c:\windows\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 01:56 AM 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-02-08 394856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"34063:TCP"= 34063:TCP:µTorrent TCP port 34063
"34063:UDP"= 34063:UDP:µTorrent UDP port 34063
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-12-20 c:\windows\Tasks\PCConfidential.job
- c:\program files\Winferno\PC Confidential\PCConfidential.exe [04/01/2008 02:10 PM]
2008-12-20 c:\windows\Tasks\RegPowerClean.job
- c:\program files\Winferno\RegistryPowerCleaner\RegPowerClean.exe [10/28/2008 02:48 PM]
2008-12-20 c:\windows\Tasks\RPCReminder.job
- c:\program files\Winferno\RegistryPowerCleaner\RPCReminder.exe [10/28/2008 02:34 PM]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
TCP: {52998351-85F7-43FC-899E-244C16E0314B} = 10.11.160.1
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ok7pbk9m.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sa/
FF - component: c:\documents and settings\Administrator\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-21 12:44:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(736)
c:\windows\system32\igfxsrvc.dll
c:\windows\system32\hccutils.DLL
.
Completion time: 12/21/2008 12:45:35
ComboFix-quarantined-files.txt 2008-12-21 09:45:29
Pre-Run: 2,795,233,280 bytes free
Post-Run: 3,086,577,664 bytes free
146