هذا التقرير الاول يا kong
ComboFix 08-09-27.03 - أبوعبدالملك 09/28/2008 15:10:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.654 [GMT 3:00]
Running from: F:\Documents and Settings\ابو عبدالملك\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
F:\setup.exe
.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-28 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-28 12:11 --------- d-----w F:\Documents and Settings\أبوعبدالملك\Application Data\DMCache
2008-09-28 02:20 81,984 ----a-w F:\WINDOWS\system32\bdod.bin
2008-09-28 01:32 --------- d-----w F:\Program Files\Common Files\Symantec Shared
2008-09-28 01:31 --------- d-----w F:\Documents and Settings\All Users\Application Data\NortonInstaller
2008-09-27 19:57 --------- d-----w F:\Documents and Settings\All Users\Application Data\Google Updater
2008-09-25 03:31 --------- d---a-w F:\Documents and Settings\All Users\Application Data\TEMP
2008-09-23 04:36 --------- d-----w F:\Program Files\DAEMON Tools Toolbar
2008-09-23 04:36 --------- d-----w F:\Program Files\DAEMON Tools Lite
2008-09-22 16:31 717,296 ----a-w F:\WINDOWS\system32\drivers\sptd.sys
2008-09-22 16:31 --------- d-----w F:\Documents and Settings\أبوعبدالملك\Application Data\DAEMON Tools
2008-09-20 22:32 --------- d-----w F:\Program Files\Family Tree Maker 2008
2008-09-20 22:26 --------- d--h--w F:\Program Files\InstallShield Installation Information
2008-09-20 22:25 --------- d-----w F:\Program Files\Microsoft.NET
2008-09-20 22:25 --------- d-----w F:\Program Files\Microsoft WSE
2008-09-20 22:25 --------- d-----w F:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-20 14:41 --------- d-----w F:\Program Files\Google
2008-09-18 18:22 --------- d-----w F:\Program Files\Sarm Software
2008-09-18 01:21 --------- d-----w F:\Program Files\Kelk 2000
2008-09-17 23:54 --------- d-----w F:\Program Files\Xilisoft
2008-09-17 11:34 --------- d-----w F:\Program Files\Real
2008-09-17 11:34 --------- d-----w F:\Program Files\Common Files\xing shared
2008-09-17 11:34 --------- d-----w F:\Program Files\Common Files\Real
2008-09-16 15:16 --------- d-----w F:\Documents and Settings\أبوعبدالملك\Application Data\Ahead
2008-09-16 15:11 --------- d-----w F:\Program Files\UltraISO
2008-09-16 15:11 --------- d-----w F:\Program Files\Common Files\EZB Systems
2008-09-14 23:41 --------- d-----w F:\Program Files\Common Files\Adobe
2008-09-13 11:31 --------- d-----w F:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-09-13 11:27 --------- d-----w F:\Documents and Settings\أبوعبدالملك\Application Data\globalhold
2008-09-13 11:26 --------- d-----w F:\Program Files\Messenger Plus! Live
2008-09-13 11:26 --------- d-----w F:\Program Files\Circle Developement
2008-09-13 11:21 --------- d-----w F:\Program Files\MessengerPlus! 3
2008-09-13 11:15 --------- d-----w F:\Program Files\Windows Live
2008-09-13 09:17 --------- d-----w F:\Documents and Settings\أبوعبدالملك\Application Data\IDM
2008-09-13 09:13 --------- d-----w F:\Program Files\Java
2008-09-13 09:05 --------- d-----w F:\Program Files\Common Files\Java
2008-09-13 02:34 --------- d-----w F:\Program Files\GetData
2008-09-13 02:21 --------- d-----w F:\Program Files\NTFS Undelete
2008-09-12 17:04 --------- d-----w F:\Program Files\TechSmith
2008-09-12 17:04 --------- d-----w F:\Documents and Settings\All Users\Application Data\TechSmith
2008-09-12 17:03 --------- d-----w F:\Program Files\Common Files\Wise Installation Wizard
2008-09-12 15:44 --------- d-----w F:\Program Files\Your Uninstaller 2008
2008-09-12 15:42 --------- d-----w F:\Documents and Settings\أبوعبدالملك\Application Data\URSoft
2008-09-12 15:36 --------- d-----w F:\Documents and Settings\أبوعبدالملك\Application Data\Symantec
2008-09-12 15:31 --------- d-----w F:\Program Files\HP
2008-09-12 15:23 --------- d-----w F:\Program Files\Hewlett-Packard
2008-09-12 15:23 --------- d-----w F:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-09-12 15:22 --------- d-----w F:\Program Files\Common Files\Hewlett-Packard
2008-09-12 15:14 --------- d-----w F:\Program Files\Microsoft Works
2008-09-12 14:52 --------- d-----w F:\Program Files\Internet Download Manager
2008-09-12 14:48 --------- d-----w F:\Documents and Settings\أبوعبدالملك\Application Data\Apple Computer
2008-09-12 14:47 --------- d-----w F:\Program Files\QuickTime
2008-09-12 14:46 --------- d-----w F:\Program Files\Common Files\InstallShield
2008-09-12 14:46 --------- d-----w F:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-12 14:45 155,995 ----a-w F:\WINDOWS\java\Packages\53HN1V9F.ZIP
2008-09-12 14:26 --------- d-----w F:\Program Files\Common Files\Ahead
2008-09-12 14:26 --------- d-----w F:\Documents and Settings\All Users\Application Data\Ahead
2008-09-12 14:24 --------- d-----w F:\Program Files\Nero
2008-09-12 14:24 --------- d-----w F:\Documents and Settings\All Users\Application Data\Nero
2008-09-12 14:21 --------- d-----w F:\Program Files\D-Link
2008-09-12 14:13 --------- d-----w F:\Program Files\Analog Devices
2008-09-12 14:08 --------- d-----w F:\Program Files\Intel
2008-09-12 10:57 --------- d-----w F:\Program Files\Windows Media Connect 2
2008-07-18 19:10 94,920 ----a-w F:\WINDOWS\system32\cdm.dll
2008-07-18 19:10 53,448 ----a-w F:\WINDOWS\system32\wuauclt.exe
2008-07-18 19:10 45,768 ----a-w F:\WINDOWS\system32\wups2.dll
2008-07-18 19:10 36,552 ----a-w F:\WINDOWS\system32\wups.dll
2008-07-18 19:09 563,912 ----a-w F:\WINDOWS\system32\wuapi.dll
2008-07-18 19:09 325,832 ----a-w F:\WINDOWS\system32\wucltui.dll
2008-07-18 19:09 205,000 ----a-w F:\WINDOWS\system32\wuweb.dll
2008-07-18 19:09 1,811,656 ----a-w F:\WINDOWS\system32\wuaueng.dll
2008-07-18 19:07 270,880 ----a-w F:\WINDOWS\system32\mucltui.dll
2008-07-18 19:07 210,976 ----a-w F:\WINDOWS\system32\muweb.dll
2008-07-07 20:27 253,952 ----a-w F:\WINDOWS\system32\es.dll
2008-07-07 20:27 253,952 ------w F:\WINDOWS\system32\dllcache\es.dll
2006-06-23 06:48 32,768 ----a-r F:\WINDOWS\inf\UpdateUSB.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="F:\WINDOWS\system32\ctfmon.exe" [04/15/2008 12:29 AM 15360]
"IDMan"="F:\Program Files\Internet Download Manager\IDMan.exe" [02/21/2008 07:44 AM 2594224]
"Trayrect"="F:\DOCUME~1\5EFE~1\APPLIC~1\GLOBAL~1\Chin Jugs.exe" [09/13/2008 02:27 PM 482304]
"MessengerPlus3"="F:\Program Files\MessengerPlus! 3\MsgPlus.exe" [09/13/2008 02:20 PM 190024]
"msnmsgr"="F:\PROGRA~1\WINDOW~3\MESSEN~1\msnmsgr.exe" [08/16/2007 04:19 PM 5728112]
"DAEMON Tools Lite"="F:\Program Files\DAEMON Tools Lite\daemon.exe" [08/08/2008 03:11 PM 490952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="F:\Program Files\Analog Devices\Core\smax4pnp.exe" [05/01/2006 01:07 PM 843776]
"DSLSTATEXE"="F:\Program Files\D-Link\DSL-200\dslstat.exe" [12/12/2005 10:44 AM 344064]
"DSLAGENTEXE"="F:\Program Files\D-Link\DSL-200\dslagent.exe" [08/25/2005 12:47 PM 65536]
"NeroFilterCheck"="F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [03/01/2007 03:57 PM 153136]
"SecurDisc"="F:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [05/15/2007 03:55 PM 1628208]
"InCD"="F:\Program Files\Nero\Nero 7\InCD\InCD.exe" [05/15/2007 03:55 PM 1057328]
"QuickTime Task"="F:\Program Files\QuickTime\qttask.exe" [09/12/2008 05:47 PM 155648]
"NvCplDaemon"="F:\WINDOWS\system32\NvCpl.dll" [05/02/2008 10:46 PM 13529088]
"NvMediaCenter"="F:\WINDOWS\system32\NvMcTray.dll" [05/02/2008 10:46 PM 86016]
"HP Software Update"="F:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [02/12/2004 01:38 PM 49152]
"HP Component Manager"="F:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [05/12/2004 03:18 PM 241664]
"pdfFactory Pro Dispatcher v2"="F:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" [11/10/2003 11:06 PM 385024]
"SunJavaUpdateSched"="F:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM 144784]
"Adobe Reader Speed Launcher"="F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM 39792]
"TkBellExe"="F:\Program Files\Common Files\Real\Update_OB\realsched.exe" [09/17/2008 02:34 PM 185896]
"nwiz"="nwiz.exe" [05/02/2008 10:46 PM 1630208 F:\WINDOWS\system32\nwiz.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [04/15/2008 12:30 AM 110592 F:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="F:\WINDOWS\system32\CTFMON.EXE" [04/15/2008 12:29 AM 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
F:\Documents and Settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-09-13 113664]
HP Digital Imaging Monitor.lnk - F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 241664]
SnagIt 9.lnk - F:\Program Files\TechSmith\SnagIt 9\SnagIt32.exe [2008-08-29 6824264]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"F:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"F:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"F:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"F:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 ulsata2;ulsata2;F:\WINDOWS\system32\drivers\ulsata2.sys [05/07/2008 08:09 AM 124928]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - F:\Documents and Settings\أبوعبدالملك\Application Data\Mozilla\Firefox\Profiles\kcb5vm83.default\
FF -: plugin - F:\Program Files\Google\Google Updater\2.3.1334.1308\npCIDetect13.dll
FF -: plugin - F:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-28 15:11:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 09/28/2008 15:13:48
ComboFix-quarantined-files.txt 2008-09-28 12:13:44
Pre-Run: 63,758,319,616 bytes free
Post-Run: 64,218,583,040 bytes free
172 --- E O F --- 2008-09-21 23:01:45