اخي MA222 نزلت الاداه وعملت صيانة وتم اعادة تشغيل الجهاز ونتج عنها هذا التقرير
ComboFix 08-08-03.05 - salem 08/05/2008 0:00:01.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.202 [GMT 3:00]
Running from: D:\downloads\اداة صيانة\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\HDSNLib.dll
C:\WINDOWS\system32\Ultra.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-04 to 2008-08-04 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-02 15:03 --------- d-----w C:\Program Files\Error Repair Professional
2008-08-02 14:55 --------- d-----w C:\Program Files\SoftwareDoctor
2008-07-30 20:35 --------- d-----w C:\Program Files\Common Files\delet
2008-07-28 19:33 311,296 ----a-w C:\WINDOWS\FastFolders.dll
2008-07-28 19:33 28,672 ----a-w C:\WINDOWS\FFUninst.exe
2008-07-15 07:49 --------- d-----w C:\Documents and Settings\salem\Application Data\vlc
2008-07-15 07:48 --------- d-----w C:\Program Files\VideoLAN
2008-07-03 21:43 23,600 ----a-w C:\WINDOWS\system32\drivers\TVICHW32.SYS
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-16 14:50 --------- d-----w C:\Program Files\Common Files\LogoManager
2008-06-16 11:01 --------- d-----w C:\Program Files\MobiMB Mobile Media Browser
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 07:59 --------- d-----w C:\Documents and Settings\salem\Application Data\Nokia
2008-06-13 07:59 --------- d-----w C:\Documents and Settings\salem\Application Data\Datalayer
2008-06-08 17:54 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-08 17:54 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-06-05 20:49 --------- d-----w C:\Program Files\MSXML 6.0
2008-06-05 20:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nokia
2008-06-05 20:48 --------- d-----w C:\Program Files\Nokia
2008-06-05 20:48 --------- d-----w C:\Program Files\Common Files\Nokia
2008-06-05 20:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-06-04 18:21 --------- d-----w C:\Program Files\Lavasoft
2008-06-04 18:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-29 21:20 679,936 ----a-w C:\WINDOWS\3D World Map.scr
2007-12-09 20:34 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-04-25 21:21 32 --sha-w C:\WINDOWS\System32b\drivers\fidbox.dat
2008-04-25 21:21 32 --sha-w C:\WINDOWS\System32b\drivers\fidbox2.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{F4F10C1D-87C7-404A-B4B3-000000000000}"= "C:\PROGRA~1\DAP\SBSearch.dll" [01/01/2008 09:16 PM 32768]
[HKEY_CLASSES_ROOT\clsid\{f4f10c1d-87c7-404a-b4b3-000000000000}]
[HKEY_CLASSES_ROOT\SearchHook.SrchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}]
[HKEY_CLASSES_ROOT\SearchHook.SrchHook]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [01/19/2007 12:55 PM 5674352]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [06/02/2008 10:15 PM 68856]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 07:24 PM 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [09/01/2004 12:00 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [02/07/2006 03:39 AM 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [02/07/2006 03:36 AM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [02/07/2006 03:40 AM 118784]
"SDaemon"="C:\WINDOWS\sdaemon.exe" [04/19/2005 12:57 AM 111104]
"SWd"="C:\WINDOWS\winwd.exe" [04/19/2005 12:56 AM 26624]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [03/03/2008 07:10 AM 185896]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [09/07/2006 08:19 PM 15872]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [07/18/2008 11:22 PM 266497]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [09/01/2004 12:00 AM 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
PS2 Keyboard English Edition 2.0.lnk - C:\Program Files\Delux\PS2 Keyboard English Edition 2.0\kb_2k.exe [2007-12-03 20:44:45 262144]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.MSNAUDIO"= msnaudio.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Avant Browser\\avant.exe"=
"C:\\Program Files\\DAP\\DAP.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Free Download Manager\\fdmwi.exe"=
"C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"C:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 WINSEC;WINSEC;C:\WINDOWS\system32\drivers\WINSEC.SYS [04/19/2005 12:57 AM]
R2 AntiVirMailService;Avira AntiVir Premium MailGuard;C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe [07/18/2008 11:22 PM]
R2 antivirwebservice;Avira AntiVir Premium WebGuard;C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE [07/18/2008 11:22 PM]
R2 AVEService;Avira AntiVir Premium MailGuard helper service;C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe [07/18/2008 11:22 PM]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [09/01/2004 12:00 AM]
R2 winser;winser;C:\WINDOWS\system32\winsersec.exe [04/14/2005 01:37 AM]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;C:\WINDOWS\system32\drivers\nmwcdnsu.sys [02/01/2008 03:17 PM]
S3 nmwcdnsuc;Nokia USB Flashing Generic;C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [02/01/2008 03:17 PM]
S3 SNP2STD;USB2.0 PC Camera (SNP2STD);C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [06/07/2006 10:34 AM]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [03/12/2008 11:41 PM]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
s of the 'Scheduled Tasks' folder
2008-08-01 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe [01/08/2008 01:31 PM]
2008-07-03 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1207245649.job
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe [06/26/2003 06:50 PM]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-fsm - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R0 -: HKCU-Main,Start Page = hxxp://www.google.com
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 -: &Download All with FlashGet -
O8 -: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 -: &Download with FlashGet -
O8 -: Add to &Teleport - C:\PROGRA~1\TELEPO~1\teleport.htm
O8 -: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: Free Download Manager تحميل الفيديو بواسطة -
Files\Free Download Manager\dlfvideo.htm
O8 -: Send To &Bluetooth -
O8 -: الدليل السريع - C:\WINDOWS\ww80.html
O8 -: تحميل المحددة بفري داونلود مانيجر -
Files\Free Download Manager\dlselected.htm
O8 -: تنزيل الكل بفري داونلود مانيجر -
Files\Free Download Manager\dlall.htm
O8 -: تنزيل بفري داونلود مانيجر -
Files\Free Download Manager\dllink.htm
O9 -: {46012076-ED62-464b-9554-AD0BEC35D1EC}
O18 -: Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\PROGRA~1\DAP\dapie.dll
O18 -: Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\PROGRA~1\DAP\dapie.dll
O16 -: Microsoft XML Parser for Java - C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-05 00:04:42
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\sccfg.sys 16384 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Unlocker\UnlockerHook.dll
-> C:\WINDOWS\WSEC32HK.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\STacSV.exe
.
**************************************************************************
.
Completion time: 08/05/2008 0:06:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-04 21:06:46
Pre-Run: 11,433,672,704 bytes free
Post-Run: 11,370,610,688 bytes free
171 --- E O F --- 2008-07-30 19:04:45
فما النتيجة بشرني جزاك الله خيرا