مشكور اخي وهذا التقرير الاول
ComboFix 08-08-25.01 - User 2009-08-26 16:13:59.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1346 [GMT -7:00]
Running from: C:\Users\User\Desktop\ComboFix.exe
* Created a new restore point
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((( Files Created from 2009-07-26 to 2009-08-26 )))))))))))))))))))))))))))))))
.
2009-08-15 15:19 . 2009-08-15 15:19 <DIR> d-------- C:\Program Files\CCleaner
2009-08-15 14:21 . 2009-08-15 14:21 <DIR> d-------- C:\Users\User\AppData\Roaming\URSoft
2009-08-15 14:21 . 2009-08-25 00:46 <DIR> d-a------ C:\Users\All Users\TEMP
2009-08-15 14:21 . 2009-08-25 00:46 <DIR> d-a------ C:\ProgramData\TEMP
2009-08-15 14:21 . 2009-08-15 23:42 <DIR> d-------- C:\Program Files\Your Uninstaller 2008
2009-08-14 22:20 . 2009-08-14 22:20 194,560 --a------ C:\Windows\System32\WebClnt.dll
2009-08-14 22:20 . 2009-08-14 22:20 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2009-08-14 22:18 . 2009-08-14 22:18 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2009-08-14 22:18 . 2009-08-14 22:18 41,984 --a------ C:\Windows\System32\drivers\monitor.sys
2009-08-14 22:17 . 2009-08-14 22:17 2,048 --a------ C:\Windows\System32\tzres.dll
2009-08-14 22:16 . 2009-08-14 22:16 3,504,696 --a------ C:\Windows\System32\ntkrnlpa.exe
2009-08-14 22:16 . 2009-08-14 22:16 3,470,392 --a------ C:\Windows\System32\ntoskrnl.exe
2009-08-14 22:16 . 2009-08-14 22:16 211,000 --a------ C:\Windows\System32\drivers\volsnap.sys
2009-08-14 22:16 . 2009-08-14 22:16 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2009-08-14 22:16 . 2009-08-14 22:16 109,624 --a------ C:\Windows\System32\drivers\ataport.sys
2009-08-14 22:16 . 2009-08-14 22:16 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2009-08-14 22:16 . 2009-08-14 22:16 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2009-08-14 22:16 . 2009-08-14 22:16 17,464 --a------ C:\Windows\System32\drivers\intelide.sys
2009-08-14 22:12 . 2009-08-14 22:12 1,585,664 --a------ C:\Windows\System32\setupapi.dll
2009-08-14 22:10 . 2009-08-14 22:10 2,027,008 --a------ C:\Windows\System32\win32k.sys
2009-08-14 22:09 . 2009-08-14 22:09 296,448 --a------ C:\Windows\System32\gdi32.dll
2009-08-14 22:09 . 2009-08-14 22:09 223,232 --a------ C:\Windows\System32\WMASF.DLL
2009-08-14 22:09 . 2009-08-14 22:09 9,728 --a------ C:\Windows\System32\LAPRXY.DLL
2009-08-14 22:09 . 2009-08-14 22:09 2,048 --a------ C:\Windows\System32\asferror.dll
2009-08-14 22:08 . 2009-08-14 22:08 2,605,568 --a------ C:\Windows\System32\SLsvc.exe
2009-08-14 22:08 . 2009-08-14 22:08 566,784 --a------ C:\Windows\System32\SLCommDlg.dll
2009-08-14 22:08 . 2009-08-14 22:08 351,232 --a------ C:\Windows\System32\SLUI.exe
2009-08-14 22:08 . 2009-08-14 22:08 268,288 --a------ C:\Windows\System32\mcbuilder.exe
2009-08-14 22:08 . 2009-08-14 22:08 223,232 --a------ C:\Windows\System32\SLC.dll
2009-08-14 22:08 . 2009-08-14 22:08 186,368 --a------ C:\Windows\System32\SLLUA.exe
2009-08-14 22:08 . 2009-08-14 22:08 57,856 --a------ C:\Windows\System32\SLUINotify.dll
2009-08-14 22:08 . 2009-08-14 22:08 39,936 --a------ C:\Windows\System32\slcinst.dll
2009-08-14 22:08 . 2009-08-14 22:08 33,280 --a------ C:\Windows\System32\slwmi.dll
2009-08-14 22:07 . 2009-08-14 22:07 113,664 --a------ C:\Windows\System32\drivers\rmcast.sys
2009-08-14 22:07 . 2009-08-14 22:07 14,848 --a------ C:\Windows\System32\wshrm.dll
2009-08-14 22:07 . 2009-08-14 22:07 11,776 --a------ C:\Windows\System32\sbunattend.exe
2009-08-14 22:06 . 2009-08-14 22:06 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2009-08-14 22:06 . 2009-08-14 22:06 1,686,528 --a------ C:\Windows\System32\gameux.dll
2009-08-14 22:05 . 2009-08-14 22:05 737,792 --a------ C:\Windows\System32\inetcomm.dll
2009-08-14 22:05 . 2009-08-14 22:05 148,992 --a------ C:\Windows\System32\drivers\ks.sys
2009-08-14 22:05 . 2009-08-14 22:05 130,048 --a------ C:\Windows\System32\drivers\srv2.sys
2009-08-14 22:05 . 2009-08-14 22:05 101,888 --a------ C:\Windows\System32\drivers\mrxsmb.sys
2009-08-14 22:05 . 2009-08-14 22:05 84,992 --a------ C:\Windows\System32\drivers\srvnet.sys
2009-08-14 22:05 . 2009-08-14 22:05 84,480 --a------ C:\Windows\System32\INETRES.dll
2009-08-14 22:05 . 2009-08-14 22:05 83,968 --a------ C:\Windows\System32\dnsrslvr.dll
2009-08-14 22:05 . 2009-08-14 22:05 58,368 --a------ C:\Windows\System32\drivers\mrxsmb20.sys
2009-08-14 22:05 . 2009-08-14 22:05 24,576 --a------ C:\Windows\System32\dnscacheugc.exe
2009-08-14 22:04 . 2009-08-14 22:04 1,327,104 --a------ C:\Windows\System32\quartz.dll
2009-08-14 22:04 . 2009-08-14 22:04 99,840 --a------ C:\Windows\System32\poqexec.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 08:02 --------- d-----w C:\Users\User\AppData\Roaming\Skype
2009-08-26 07:48 --------- d-----w C:\Users\User\AppData\Roaming\skypePM
2009-08-26 07:28 --------- d-----w C:\Program Files\Google
2009-08-15 22:19 --------- d-----w C:\Program Files\Yahoo!
2009-08-15 06:14 --------- d-----w C:\Program Files\Common Files\Adobe
2009-08-15 05:32 174 --sha-w C:\Program Files\desktop.ini
2009-08-15 05:28 --------- d-----w C:\Program Files\Windows Sidebar
2009-08-15 05:28 --------- d-----w C:\Program Files\Windows Mail
2009-08-15 05:15 826,368 ----a-w C:\Windows\System32\wininet.dll
2009-08-15 05:15 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2009-08-15 05:15 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2009-08-15 05:15 24,064 ----a-w C:\Windows\System32\netcfg.exe
2009-08-15 05:15 22,016 ----a-w C:\Windows\System32\netiougc.exe
2009-08-15 05:15 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2009-08-15 05:15 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2009-08-15 05:14 56,320 ----a-w C:\Windows\System32\iesetup.dll
2009-08-15 05:14 29,184 ----a-w C:\Windows\system32\drivers\BTHUSB.SYS
2009-08-15 05:14 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2009-08-15 05:14 220,160 ----a-w C:\Windows\system32\drivers\bthport.sys
2009-08-15 05:14 19,456 ----a-w C:\Windows\system32\drivers\bthenum.sys
2009-08-15 05:14 181,760 ----a-w C:\Windows\System32\fsquirt.exe
2009-08-15 05:08 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2009-08-15 05:08 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2009-08-15 05:08 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2009-08-15 05:06 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2009-08-15 05:06 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2009-08-14 05:47 --------- d-----w C:\ProgramData\Sony Corporation
2008-08-13 15:32 56 ---ha-w C:\Users\All Users\ezsidmv.dat
2008-08-13 15:32 56 ---ha-w C:\ProgramData\ezsidmv.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2009-08-14 22:07 1232896]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-09 18:58 835584]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2007-09-19 12:09 311296]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-07 19:33 4423680 C:\Windows\RtHDVCpl.exe]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CCC.lnk - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2007-06-01 10:52:34 49152]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-10-30 12:04:08 748072]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-08-14 21:05 98304 C:\Windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4C6884F8-5833-42C8-BA6A-B5FB50A6E352}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{D8549B65-4AE1-4EC8-A09A-3BD38FDBB711}"= Disabled:UDP:C:\Program Files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{89CB3EC1-4E29-4CD4-97B9-D8DA6D2CF4C8}"= Disabled:TCP:C:\Program Files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{DA1F4FDF-7737-4525-84FE-2E08E8C66376}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{CFF8BED3-E871-45BA-B164-7C3805A28711}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{B23317DA-4664-4181-89AC-E6EEC2FE5B5C}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{021B2FAE-AC86-4F96-A322-599106D7B32A}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{74CCA1C9-D30F-45EE-B93B-0B0D6BAA688D}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2006-04-14 10:07]
R2 regi;regi;C:\Windows\system32\drivers\regi.sys [2007-04-17 20:09]
R2 uCamMonitor;CamMonitor;C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe [2007-10-31 09:40]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2007-10-29 19:30]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-10-18 17:22]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;C:\Windows\system32\Drivers\R5U870FLx86.sys [2007-10-16 17:01]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;C:\Windows\system32\Drivers\R5U870FUx86.sys [2007-10-16 17:01]
R3 SFEP;Sony Firmware Extension Parser;C:\Windows\system32\DRIVERS\SFEP.sys [2007-08-28 18:58]
R3 ti21sony;ti21sony;C:\Windows\system32\drivers\ti21sony.sys [2007-11-15 17:29]
S3 btwaudio;Bluetooth Audio Device Service;C:\Windows\system32\drivers\btwaudio.sys [2007-11-14 17:02]
S3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-11-14 17:02]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys [2007-11-14 17:01]
S3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-11-14 17:02]
S3 ICScsiSV;Image Converter SCSI Service;C:\Program Files\Sony\Image Converter 3\ICScsiSV.exe [2007-06-14 19:07]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Program Files\Sony\Image Converter 3\IcVzMon.exe [2007-06-14 19:07]
S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Collection;C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe [2007-01-10 16:51]
S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Collection (HTTP);C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [2007-08-09 00:51]
S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Collection (UPnP);C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-08-09 00:51]
S3 VcmIAlzMgr;VAIO data Intelligent Analyzing Manager;C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2007-09-28 21:11]
S3 VcmXmlIfHelper;VAIO data XML Interface;C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2007-09-20 18:52]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-IgfxTray - C:\Windows\system32\igfxtray.exe
HKLM-Run-HotKeysCmds - C:\Windows\system32\hkcmd.exe
HKLM-Run-Persistence - C:\Windows\system32\igfxpers.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://vaio-online.sony.com/
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 -: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 -: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-08-26 16:14:42
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-08-26 16:16:25
ComboFix-quarantined-files.txt 2009-08-26 23:16:22
Pre-Run: 206,004,441,088 bytes free
Post-Run: 205,999,890,432 bytes free
176 --- E O F --- 2009-08-15 05:22:18