وهذا التقرير الاول
ComboFix 08-08-27.06 - Administrator 08/28/2008 22:25:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.846 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-28 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-28 18:43 --------- d-----w C:\Program Files\ESET
2008-08-28 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-08-28 18:08 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-28 18:08 --------- d-----w C:\Program Files\SigmaTel
2008-08-28 18:02 2,328 ----a-w C:\WINDOWS\system32\drivers\sthdae.log
2008-08-28 18:00 --------- d-----w C:\Program Files\Driver-Soft
2008-08-28 15:13 5 ----a-w C:\WINDOWS\system32\drivers\DELL_XPS_MXC051 .MRK
2008-08-28 15:13 5 ----a-w C:\WINDOWS\system32\drivers\1028_DELL_XPS_MXC051 .MRK
2008-08-28 14:46 --------- d-----w C:\Program Files\Modem Helper
2008-08-28 14:09 --------- d--h--w C:\Documents and Settings\All Users\Application Data\{9784CF0C-B63B-4A60-A1B8-0D38CDF756EB}
2008-08-28 14:09 --------- d-----w C:\Program Files\XPC Tools
2008-08-28 13:23 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-08-28 12:52 --------- d-----w C:\Program Files\Real
2008-08-28 12:52 --------- d-----w C:\Program Files\MSN Messenger
2008-08-28 12:52 --------- d-----w C:\Program Files\Common Files\xing shared
2008-08-28 12:52 --------- d-----w C:\Program Files\Common Files\Real
2008-08-28 12:49 --------- dc-h--w C:\Documents and Settings\All Users\Application Data\~0
2008-08-28 12:29 --------- d-----w C:\Program Files\Dell
2008-08-28 12:29 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-28 12:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-08-28 12:21 --------- d-----w C:\Program Files\IDT
2008-08-28 12:15 --------- d-----w C:\Program Files\CONEXANT
2008-08-28 12:13 --------- d-----w C:\Program Files\Common Files\Zeepe Framework 7
2008-08-28 12:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Novatel Wireless
2008-08-28 01:25 21,425 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-08-28 01:25 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Intel
2008-08-28 01:25 --------- d-----w C:\Documents and Settings\NetworkService\Application Data\Intel
2008-08-28 01:25 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Intel
2008-08-28 01:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intel
2008-08-28 01:25 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Intel
2008-08-28 01:24 --------- d-----w C:\Program Files\Intel
2008-08-28 00:25 --------- d-----w C:\Program Files\Broadcom
2008-08-28 00:05 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-08-28 00:05 172,032 ------w C:\WINDOWS\Setup1.exe
2008-08-28 00:05 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-08-28 00:02 --------- d-----w C:\Program Files\Microsoft.NET
2008-08-28 00:01 --------- d-----w C:\Program Files\Microsoft Works
2008-08-27 23:47 --------- d-----w C:\Program Files\Synaptics
2008-08-27 23:32 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"DriverUpdaterPro"="C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe" [08/28/2008 05:10 PM 2480128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [09/15/2006 04:53 PM 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [09/15/2006 04:50 PM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [09/15/2006 04:54 PM 118784]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [03/08/2006 12:48 PM 761947]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [03/16/2007 06:10 PM 1392640]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [02/21/2007 11:19 AM 819200]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [02/21/2007 11:17 AM 970752]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [08/03/2004 10:32 PM 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [08/03/2004 10:31 PM 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [08/03/2004 10:32 PM 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [08/03/2004 10:32 PM 455168]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [12/21/2007 08:21 AM 1443072]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 12:56 AM 110592 C:\WINDOWS\system32\bthprops.cpl]
"PMX Daemon"="ICO.EXE" [06/09/2006 12:47 PM 47104 C:\WINDOWS\system32\ico.exe]
"IDTSysTrayApp"="sttray.exe" [09/05/2007 09:24 PM 405504 C:\WINDOWS\sttray.exe]
"SigmatelSysTrayApp"="stsystra.exe" [08/24/2005 07:42 AM 393216 C:\WINDOWS\stsystra.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
R1 easdrv;easdrv;C:\WINDOWS\system32\DRIVERS\easdrv.sys [12/21/2007 08:20 AM]
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [12/21/2007 08:21 AM]
R2 BthServ;Bluetooth Support Service;C:\WINDOWS\system32\svchost.exe [08/04/2004 12:56 AM]
R2 eamon;EAMON;C:\WINDOWS\system32\DRIVERS\eamon.sys [12/21/2007 08:19 AM]
R2 ekrn;Eset Service;C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [12/21/2007 08:21 AM]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service;C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [02/21/2007 11:10 AM]
R2 s24trans;نقل WLAN;C:\WINDOWS\system32\DRIVERS\s24trans.sys [02/21/2007 11:16 AM]
R2 WLANKEEPER;Intel(R) PROSet/Wireless SSO Service;C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe [02/21/2007 11:19 AM]
R2 wltrysvc;Dell Wireless WLAN Tray Service;C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe []
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver;C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [08/05/2005 11:32 AM]
R3 BthEnum;Bluetooth Request Block Driver;C:\WINDOWS\system32\DRIVERS\BthEnum.sys [08/03/2004 11:10 PM]
R3 BthPan;Bluetooth Device (Personal Area Network);C:\WINDOWS\system32\DRIVERS\bthpan.sys [08/03/2004 10:58 PM]
R3 BTHUSB;Bluetooth Radio USB Driver;C:\WINDOWS\system32\Drivers\BTHUSB.sys [08/03/2004 11:10 PM]
R3 HSF_DPV;HSF_DPV;C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [07/22/2005 11:02 AM]
R3 HSFHWAZL;HSFHWAZL;C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [07/22/2005 11:01 AM]
R3 NWADI;NWADI Bus Enumerator;C:\WINDOWS\system32\DRIVERS\NWADIenum.sys [08/09/2006 11:11 AM]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI);C:\WINDOWS\system32\DRIVERS\rfcomm.sys [08/03/2004 11:10 PM]
R3 sdbus;sdbus;C:\WINDOWS\system32\DRIVERS\sdbus.sys [08/03/2004 11:07 PM]
R3 STHDA;SigmaTel High Definition Audio CODEC;C:\WINDOWS\system32\drivers\sthda.sys [08/30/2005 01:55 PM]
R3 SynTP;Synaptics TouchPad Driver;C:\WINDOWS\system32\DRIVERS\SynTP.sys [03/08/2006 12:35 PM]
R3 w29n51;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows XP;C:\WINDOWS\system32\DRIVERS\w29n51.sys [02/08/2007 01:51 PM]
S2 STacSV;Audio Service;C:\Documents and Settings\Administrator\Desktop\تعاريف ديل630م\IDT High Definition Audio CODEC\STacSV.exe [09/05/2007 09:25 PM]
S3 BTHPORT;Bluetooth Port Driver;C:\WINDOWS\system32\Drivers\BTHport.sys [08/03/2004 11:10 PM]
S3 bvrp_pci;bvrp_pci;C:\WINDOWS\system32\drivers\bvrp_pci.sys [09/20/2004 01:44 PM]
S3 EhttpSrv;Eset HTTP Server;C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [12/21/2007 08:22 AM]
S3 HSXHWAZL;HSXHWAZL;C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys [12/01/2005 01:40 AM]
S3 UIUSys;Conexant Setup API;C:\WINDOWS\system32\DRIVERS\UIUSYS.SYS []
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.sa/
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-28 22:27:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 08/28/2008 22:27:49
ComboFix-quarantined-files.txt 2008-08-28 19:27:42
Pre-Run: 37,222,297,600 bytes free
Post-Run: 37,466,984,448 bytes free
135