هذا التقرير الاول
------------------------------------
ComboFix 08-08-23.03 - adel 2008-08-26 14:35:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.253 [GMT 3:00]
Running from: C:\Documents and Settings\adel\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-07-26 to 2008-08-26 )))))))))))))))))))))))))))))))
.
2008-08-26 14:00 . 2008-08-26 14:02 <DIR> d-------- C:\Program Files\Internet Download Manager
2008-08-26 14:00 . 2008-08-26 14:00 <DIR> d-------- C:\Documents and Settings\adel\Application Data\IDM
2008-08-26 14:00 . 2008-08-26 14:38 <DIR> d-------- C:\Documents and Settings\adel\Application Data\DMCache
2008-08-26 13:49 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-08-26 13:46 . 2008-08-26 13:46 <DIR> d-------- C:\Program Files\Microsoft Works
2008-08-26 13:45 . 2008-08-26 13:45 <DIR> d-------- C:\Program Files\MSBuild
2008-08-26 13:29 . 2008-08-26 13:42 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-08-26 13:26 . 2008-08-26 13:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-26 13:23 . 2008-08-26 13:23 <DIR> dr-h----- C:\MSOCache
2008-08-26 09:17 . 2008-08-26 09:17 4,444 --a------ C:\WINDOWS\system32\pid.PNF
2008-08-26 09:16 . 2008-04-14 15:00 66,082 --a--c--- C:\WINDOWS\system32\dllcache\c_20420.nls
2008-08-26 09:16 . 2008-04-14 15:00 66,082 --a------ C:\WINDOWS\system32\c_20420.nls
2008-08-26 09:13 . 2008-04-14 03:21 101,120 --a------ C:\WINDOWS\system32\drivers\bthpan.sys
2008-08-26 09:12 . 2008-04-14 08:42 151,552 --a------ C:\WINDOWS\system32\irftp.exe
2008-08-26 09:12 . 2008-04-14 08:41 28,160 --a------ C:\WINDOWS\system32\irmon.dll
2008-08-26 09:12 . 2008-04-14 03:16 17,024 --a------ C:\WINDOWS\system32\drivers\bthenum.sys
2008-08-26 09:12 . 2008-04-14 08:42 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2008-08-26 09:12 . 2001-08-17 16:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-08-26 09:11 . 2008-04-14 03:16 273,024 --a------ C:\WINDOWS\system32\drivers\bthport.sys
2008-08-26 09:11 . 2008-04-14 03:10 57,600 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-08-26 09:11 . 2008-04-14 03:16 18,944 --a------ C:\WINDOWS\system32\drivers\BTHUSB.SYS
2008-08-26 09:10 . 2008-04-14 08:42 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2008-08-26 09:10 . 2008-04-14 03:06 14,208 --a------ C:\WINDOWS\system32\drivers\battc.sys
2008-08-26 09:10 . 2008-04-14 03:06 13,952 --a------ C:\WINDOWS\system32\drivers\CmBatt.sys
2008-08-26 09:10 . 2008-04-14 03:06 10,240 --a------ C:\WINDOWS\system32\drivers\compbatt.sys
2008-08-26 09:10 . 2001-08-17 16:46 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys
2008-08-26 09:10 . 2008-04-14 03:10 5,504 --a------ C:\WINDOWS\system32\drivers\intelide.sys
2008-08-26 09:08 . 2008-08-26 13:49 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-08-26 09:08 . 2008-08-26 06:22 <DIR> dr------- C:\Documents and Settings\All Users\Documents
2008-08-26 09:07 . 2008-08-26 06:28 <DIR> d--h----- C:\Documents and Settings\Default User
2008-08-26 09:07 . 2008-08-26 06:26 <DIR> d-------- C:\Documents and Settings\All Users
2008-08-26 09:07 . 2008-08-26 06:43 <DIR> d-------- C:\Documents and Settings
2008-08-26 09:04 . 2008-08-26 06:38 261 --a------ C:\WINDOWS\system32\$winnt$.inf
2008-08-26 07:58 . 2008-08-26 07:58 <DIR> d-------- C:\Program Files\Microsoft Firewall Client 2004
2008-08-26 07:46 . 2008-08-26 07:46 <DIR> d---s---- C:\Documents and Settings\adel\UserData
2008-08-26 07:41 . 2008-08-26 07:41 <DIR> d-------- C:\Documents and Settings\adel\Contacts
2008-08-26 07:40 . 2008-08-26 07:40 <DIR> d-------- C:\Program Files\Messenger Plus! Live
2008-08-26 07:40 . 2008-08-26 07:40 268 --ah----- C:\sqmdata00.sqm
2008-08-26 07:40 . 2008-08-26 07:40 244 --ah----- C:\sqmnoopt00.sqm
2008-08-26 07:38 . 2008-08-26 07:38 <DIR> d-------- C:\Program Files\Windows Live
2008-08-26 07:18 . 2008-01-07 14:29 352 --ah----- C:\WINDOWS\nod32fixtemdono.reg
2008-08-26 07:09 . 2008-08-26 07:09 <DIR> d-------- C:\Program Files\ESET
2008-08-26 07:09 . 2008-08-26 07:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-08-26 07:04 . 2008-08-26 07:04 <DIR> d-------- C:\Documents and Settings\adel\Application Data\Nokia
2008-08-26 07:02 . 2008-08-26 07:02 <DIR> d-------- C:\Program Files\DIFX
2008-08-26 07:02 . 2008-08-26 07:02 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-08-26 07:01 . 2008-08-26 07:02 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-08-26 07:01 . 2008-08-26 07:02 <DIR> d-------- C:\Program Files\Nokia
2008-08-26 07:01 . 2008-08-26 07:02 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-08-26 07:01 . 2008-08-26 07:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Suite
2008-08-26 07:01 . 2008-08-26 07:01 <DIR> d-------- C:\Documents and Settings\adel\Application Data\PC Suite
2008-08-26 07:01 . 2006-05-29 08:26 127,488 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2008-08-26 07:01 . 2006-05-29 08:26 50,688 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2008-08-26 07:01 . 2006-05-29 08:26 30,720 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2008-08-26 07:01 . 2006-05-29 08:26 13,312 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2008-08-26 07:01 . 2006-05-29 08:26 13,312 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys
2008-08-26 07:01 . 2006-05-29 08:26 8,704 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
2008-08-26 07:01 . 2006-05-29 08:26 4,608 --a------ C:\WINDOWS\system32\nmwcdlog.dll
2008-08-26 07:00 . 2008-08-26 07:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-26 05:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-08-26 03:49 --------- d-----w C:\Program Files\CONEXANT
2008-08-26 03:48 --------- d-----w C:\Program Files\Sigmatel
2008-08-26 03:30 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-08-16 16:19 5728112]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-08-26 14:01 896256]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-09-15 16:53 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-09-15 16:50 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-09-15 16:54 118784]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [2006-06-15 12:36 229376]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-04-23 14:57 1443072]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 15:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"SigmatelSysTrayApp"="stsystra.exe" [2005-09-10 02:19 393216 C:\WINDOWS\stsystra.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15:00 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Firewall Client Management.lnk - C:\Program Files\Microsoft Firewall Client 2004\FwcMgmt.exe [2006-12-09 19:04:10 117568]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-04-23 15:00]
R2 FwcAgent;Firewall Client Agent;C:\Program Files\Microsoft Firewall Client 2004\FwcAgent.exe [2006-12-09 19:04]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://go.eset.eu/versioninfo?lng=1033&version=3048
R1 -: HKCU-Internet Settings,ProxyServer = stuproxy.kfupm.edu.sa:80
R1 -: HKCU-Internet Settings,ProxyOverride = <local>
O8 -: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 -: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-26 14:38:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-26 14:40:46
ComboFix-quarantined-files.txt 2008-08-26 11:40:38
Pre-Run: 37,609,062,400 bytes free
Post-Run: 37,619,486,720 bytes free
138 --- E O F --- 2008-08-26 05:25:34