anascoo
زيزوومى مميز
غير متصل
من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
نزلت ويندوز جديد
لكن الجهاز صار بطى
هذا تقرير
ComboFix 08-10-10.09 - anas 10/11/2008 13:21:02.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.180 [GMT 3:00]
Running from: C:\Downloads\Software\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\x64
.
((((((((((((((((((((((((( Files Created from 2008-09-11 to 2008-10-11 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-11 08:37 --------- d-----w C:\Program Files\Hotspot_Shield
2008-10-11 08:37 --------- d-----w C:\Program Files\Hotspot Shield
2008-10-11 08:18 --------- d-----w C:\Program Files\Free Download Manager
2008-10-11 08:18 --------- d-----w C:\Documents and Settings\anas\Application Data\Free Download Manager
2008-10-11 08:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
2008-10-11 07:41 --------- d-----w C:\Program Files\Zamalek
2008-10-11 07:41 --------- d-----w C:\Program Files\Conduit
2008-10-11 06:40 --------- d-----w C:\Program Files\mDSL
2008-10-11 06:40 --------- d-----w C:\Documents and Settings\anas\Application Data\ZTEEVDO
2008-10-09 10:34 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-10-09 10:34 76,040 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-10-09 10:34 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-10-09 10:34 --------- d-----w C:\Program Files\AVG
2008-10-09 10:34 --------- d-----w C:\Documents and Settings\anas\Application Data\AVGTOOLBAR
2008-10-09 10:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-10-09 08:54 --------- d-----w C:\Program Files\D-Link
2008-10-09 08:54 --------- d-----w C:\Program Files\ANI
2008-10-09 08:53 --------- d-----w C:\Documents and Settings\anas\Application Data\InstallShield
2008-10-09 07:52 --------- d-----w C:\Program Files\Common Files\Adobe
2008-10-08 19:35 --------- d-----w C:\Program Files\SWiSH v2.01
2008-10-08 19:27 --------- d-----w C:\Program Files\SWiSH v2.0
2008-10-08 18:22 --------- d-----w C:\Documents and Settings\anas\Application Data\Talkback
2008-10-08 17:37 --------- d-----w C:\Program Files\SWiSHE.NET
2008-10-08 13:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-08 13:30 --------- d-----w C:\Program Files\Zain USB-Connect
2008-10-08 13:29 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-08 12:59 --------- d-----w C:\Documents and Settings\anas\Application Data\Media Player Classic
2008-10-08 12:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-08 12:06 --------- d-----w C:\Program Files\Microsoft.NET
2008-10-08 11:29 --------- d-----w C:\Program Files\Microsoft WSE
2008-10-08 11:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-08 11:28 --------- d-----w C:\Program Files\Reference Assemblies
2008-10-08 11:28 --------- d-----w C:\Program Files\MSXML 6.0
2008-10-08 11:28 --------- d-----w C:\Program Files\MSBuild
2008-10-08 11:27 --------- d-----w C:\Documents and Settings\anas\Application Data\Styler
2008-10-08 11:22 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Desktopicon
2008-10-08 11:22 --------- d-----w C:\Program Files\Unlocker
2008-10-08 11:22 --------- d-----w C:\Program Files\PowerCmd
2008-10-08 11:22 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-10-08 11:22 --------- d-----w C:\Program Files\Hunt Virus Utilities
2008-10-08 11:22 --------- d-----w C:\Program Files\HashTab Shell Extension
2008-10-08 11:22 --------- d-----w C:\Program Files\Common Files\Stardock
2008-10-08 11:22 --------- d-----w C:\Documents and Settings\anas\Application Data\Desktopicon
2008-10-08 11:21 --------- d-----w C:\Program Files\Sysinternals
2008-10-08 11:21 --------- d-----w C:\Program Files\IZArc
2008-10-08 11:21 --------- d-----w C:\Program Files\Alky for Applications
2008-10-08 11:15 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\uTorrent
2008-10-08 11:15 --------- d-----w C:\Program Files\uTorrent
2008-10-08 11:15 --------- d-----w C:\Documents and Settings\anas\Application Data\uTorrent
2008-10-08 11:14 --------- d-----w C:\Program Files\VistaExperience.org
2008-10-08 11:12 --------- d-----w C:\Program Files\Windows Sidebar
2008-10-08 11:12 --------- d-----w C:\Program Files\Styler
2008-10-08 11:12 --------- d-----w C:\Program Files\CCleaner
2008-10-08 11:11 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-10-08 11:11 --------- d-----w C:\Program Files\System
2008-10-08 11:11 --------- d-----w C:\Program Files\Stanimir Stoyanov
2008-10-08 11:11 --------- d-----w C:\Program Files\Desktop
2008-10-08 11:11 --------- d-----w C:\Program Files\7-Zip
2008-07-18 19:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 19:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 19:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 19:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 19:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 19:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 19:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 19:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 19:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 19:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
.
------- Sigcheck -------
05/18/2008 11:03 AM 361344 68f06fe0021b01e670af37b8c5964fdf C:\WINDOWS\system32\drivers\tcpip.sys
06/20/2008 02:51 PM 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp3gdr\tcpip.sys
06/20/2008 02:59 PM 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp3qfe\tcpip.sys
05/10/2008 12:49 PM 2306560 0f733106a818383806060abc29fe0f3a C:\WINDOWS\system32\ntoskrnl.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a4d2dee2-098d-4aae-ad14-b189ab17fad3}"= "C:\Program Files\Zamalek\tbZam0.dll" [06/24/2008 11:17 PM 1569304]
"{c95a4e8e-816d-4655-8c79-d736da1adb6d}"= "C:\Program Files\Hotspot_Shield\tbHots.dll" [06/24/2008 11:17 PM 1569304]
[HKEY_CLASSES_ROOT\clsid\{a4d2dee2-098d-4aae-ad14-b189ab17fad3}]
[HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{a4d2dee2-098d-4aae-ad14-b189ab17fad3}]
06/24/2008 11:17 PM 1569304 --a------ C:\Program Files\Zamalek\tbZam0.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
06/24/2008 11:17 PM 1569304 --a------ C:\Program Files\Hotspot_Shield\tbHots.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{a4d2dee2-098d-4aae-ad14-b189ab17fad3}"= "C:\Program Files\Zamalek\tbZam0.dll" [06/24/2008 11:17 PM 1569304]
"{c95a4e8e-816d-4655-8c79-d736da1adb6d}"= "C:\Program Files\Hotspot_Shield\tbHots.dll" [06/24/2008 11:17 PM 1569304]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A4D2DEE2-098D-4AAE-AD14-B189AB17FAD3}"= "C:\Program Files\Zamalek\tbZam0.dll" [06/24/2008 11:17 PM 1569304]
[HKEY_CLASSES_ROOT\clsid\{a4d2dee2-098d-4aae-ad14-b189ab17fad3}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [09/02/2007 01:58 PM 495616]
"LClock"="C:\Program Files\LClock\LClock.exe" [09/19/2004 09:27 PM 65536]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [03/22/2008 10:18 PM 1271808]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 12:00 PM 15360]
"Free Download Manager"="C:\Program Files\Free Download Manager\fdm.exe" [12/16/2007 08:39 PM 2449455]
"Free Upload Manager"="C:\Program Files\Free Download Manager\fum\fum.exe" [07/29/2007 07:13 PM 253952]
"Free Uploader Oe Integration"="C:\Program Files\Free Download Manager\FUM\fumoei.exe" [06/10/2007 06:02 PM 40960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [05/02/2008 07:15 AM 15872]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [01/13/2007 04:47 AM 131072]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [01/13/2007 04:47 AM 163840]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [01/13/2007 04:46 AM 135168]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [01/19/2007 11:49 AM 49152]
"D-Link D-Link Wireless 108G DWA-520"="C:\Program Files\D-Link\D-Link Wireless 108G DWA-520\AirPlusCFG.exe" [05/04/2007 10:27 AM 1662976]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [10/11/2008 09:49 AM 1234712]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [09/02/2007 01:58 PM 495616]
"LClock"="C:\Program Files\LClock\LClock.exe" [09/19/2004 09:27 PM 65536]
"ctfmon.exe"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 12:00 PM 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" [05/18/2008 11:03 AM 124928 C:\WINDOWS\system32\advpack.dll]
C:\Documents and Settings\anas\Start Menu\Programs\Startup\
Styler.lnk - C:\Documents and Settings\anas\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [10/8/2008 2:26:43 PM 15086]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [10/9/2008 10:53:22 AM 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
05/12/2008 10:49 AM 210168 C:\Program Files\Stardock\ Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [10/09/2008 01:34 PM 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [10/09/2008 01:34 PM 875288]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [10/09/2008 01:34 PM 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [10/09/2008 01:34 PM 76040]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [10/16/2006 03:58 PM 472832]
R3 ev19x8mp;Creative SB AudioPCI Audio Driver (WDM);C:\WINDOWS\system32\drivers\ev19x8mp.sys [11/24/2000 09:10 PM 522268]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [01/24/2008 12:25 AM 27136]
R3 zteusbser;ZTE USB Device for Legacy Serial Communication;C:\WINDOWS\system32\DRIVERS\ZTEUsbser.sys [02/06/2007 10:21 AM 97920]
*Newly Created Service* - PROCEXP90
*Newly Created Service* - SRSERVICE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,Register
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\anas\Application Data\Mozilla\Firefox\Profiles\jvjkoyp1.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q=
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-11 13:22:58
Windows 5.1.2600 Service Pack 3, v.5512 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\RocketDock\RocketDock.dll
.
Completion time: 10/11/2008 13:23:42
ComboFix-quarantined-files.txt 2008-10-11 10:23:38
Pre-Run: 15,866,953,728 bytes free
Post-Run: 15,855,960,064 bytes free
187 --- E O F --- 2008-10-09 00:19:55
لكن الجهاز صار بطى
هذا تقرير
ComboFix 08-10-10.09 - anas 10/11/2008 13:21:02.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.180 [GMT 3:00]
Running from: C:\Downloads\Software\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\x64
.
((((((((((((((((((((((((( Files Created from 2008-09-11 to 2008-10-11 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-11 08:37 --------- d-----w C:\Program Files\Hotspot_Shield
2008-10-11 08:37 --------- d-----w C:\Program Files\Hotspot Shield
2008-10-11 08:18 --------- d-----w C:\Program Files\Free Download Manager
2008-10-11 08:18 --------- d-----w C:\Documents and Settings\anas\Application Data\Free Download Manager
2008-10-11 08:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
2008-10-11 07:41 --------- d-----w C:\Program Files\Zamalek
2008-10-11 07:41 --------- d-----w C:\Program Files\Conduit
2008-10-11 06:40 --------- d-----w C:\Program Files\mDSL
2008-10-11 06:40 --------- d-----w C:\Documents and Settings\anas\Application Data\ZTEEVDO
2008-10-09 10:34 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-10-09 10:34 76,040 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-10-09 10:34 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-10-09 10:34 --------- d-----w C:\Program Files\AVG
2008-10-09 10:34 --------- d-----w C:\Documents and Settings\anas\Application Data\AVGTOOLBAR
2008-10-09 10:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-10-09 08:54 --------- d-----w C:\Program Files\D-Link
2008-10-09 08:54 --------- d-----w C:\Program Files\ANI
2008-10-09 08:53 --------- d-----w C:\Documents and Settings\anas\Application Data\InstallShield
2008-10-09 07:52 --------- d-----w C:\Program Files\Common Files\Adobe
2008-10-08 19:35 --------- d-----w C:\Program Files\SWiSH v2.01
2008-10-08 19:27 --------- d-----w C:\Program Files\SWiSH v2.0
2008-10-08 18:22 --------- d-----w C:\Documents and Settings\anas\Application Data\Talkback
2008-10-08 17:37 --------- d-----w C:\Program Files\SWiSHE.NET
2008-10-08 13:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-08 13:30 --------- d-----w C:\Program Files\Zain USB-Connect
2008-10-08 13:29 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-08 12:59 --------- d-----w C:\Documents and Settings\anas\Application Data\Media Player Classic
2008-10-08 12:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-08 12:06 --------- d-----w C:\Program Files\Microsoft.NET
2008-10-08 11:29 --------- d-----w C:\Program Files\Microsoft WSE
2008-10-08 11:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-08 11:28 --------- d-----w C:\Program Files\Reference Assemblies
2008-10-08 11:28 --------- d-----w C:\Program Files\MSXML 6.0
2008-10-08 11:28 --------- d-----w C:\Program Files\MSBuild
2008-10-08 11:27 --------- d-----w C:\Documents and Settings\anas\Application Data\Styler
2008-10-08 11:22 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Desktopicon
2008-10-08 11:22 --------- d-----w C:\Program Files\Unlocker
2008-10-08 11:22 --------- d-----w C:\Program Files\PowerCmd
2008-10-08 11:22 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-10-08 11:22 --------- d-----w C:\Program Files\Hunt Virus Utilities
2008-10-08 11:22 --------- d-----w C:\Program Files\HashTab Shell Extension
2008-10-08 11:22 --------- d-----w C:\Program Files\Common Files\Stardock
2008-10-08 11:22 --------- d-----w C:\Documents and Settings\anas\Application Data\Desktopicon
2008-10-08 11:21 --------- d-----w C:\Program Files\Sysinternals
2008-10-08 11:21 --------- d-----w C:\Program Files\IZArc
2008-10-08 11:21 --------- d-----w C:\Program Files\Alky for Applications
2008-10-08 11:15 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\uTorrent
2008-10-08 11:15 --------- d-----w C:\Program Files\uTorrent
2008-10-08 11:15 --------- d-----w C:\Documents and Settings\anas\Application Data\uTorrent
2008-10-08 11:14 --------- d-----w C:\Program Files\VistaExperience.org
2008-10-08 11:12 --------- d-----w C:\Program Files\Windows Sidebar
2008-10-08 11:12 --------- d-----w C:\Program Files\Styler
2008-10-08 11:12 --------- d-----w C:\Program Files\CCleaner
2008-10-08 11:11 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-10-08 11:11 --------- d-----w C:\Program Files\System
2008-10-08 11:11 --------- d-----w C:\Program Files\Stanimir Stoyanov
2008-10-08 11:11 --------- d-----w C:\Program Files\Desktop
2008-10-08 11:11 --------- d-----w C:\Program Files\7-Zip
2008-07-18 19:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 19:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 19:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 19:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 19:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 19:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 19:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 19:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 19:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 19:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
.
------- Sigcheck -------
05/18/2008 11:03 AM 361344 68f06fe0021b01e670af37b8c5964fdf C:\WINDOWS\system32\drivers\tcpip.sys
06/20/2008 02:51 PM 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp3gdr\tcpip.sys
06/20/2008 02:59 PM 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp3qfe\tcpip.sys
05/10/2008 12:49 PM 2306560 0f733106a818383806060abc29fe0f3a C:\WINDOWS\system32\ntoskrnl.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a4d2dee2-098d-4aae-ad14-b189ab17fad3}"= "C:\Program Files\Zamalek\tbZam0.dll" [06/24/2008 11:17 PM 1569304]
"{c95a4e8e-816d-4655-8c79-d736da1adb6d}"= "C:\Program Files\Hotspot_Shield\tbHots.dll" [06/24/2008 11:17 PM 1569304]
[HKEY_CLASSES_ROOT\clsid\{a4d2dee2-098d-4aae-ad14-b189ab17fad3}]
[HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{a4d2dee2-098d-4aae-ad14-b189ab17fad3}]
06/24/2008 11:17 PM 1569304 --a------ C:\Program Files\Zamalek\tbZam0.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
06/24/2008 11:17 PM 1569304 --a------ C:\Program Files\Hotspot_Shield\tbHots.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{a4d2dee2-098d-4aae-ad14-b189ab17fad3}"= "C:\Program Files\Zamalek\tbZam0.dll" [06/24/2008 11:17 PM 1569304]
"{c95a4e8e-816d-4655-8c79-d736da1adb6d}"= "C:\Program Files\Hotspot_Shield\tbHots.dll" [06/24/2008 11:17 PM 1569304]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A4D2DEE2-098D-4AAE-AD14-B189AB17FAD3}"= "C:\Program Files\Zamalek\tbZam0.dll" [06/24/2008 11:17 PM 1569304]
[HKEY_CLASSES_ROOT\clsid\{a4d2dee2-098d-4aae-ad14-b189ab17fad3}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [09/02/2007 01:58 PM 495616]
"LClock"="C:\Program Files\LClock\LClock.exe" [09/19/2004 09:27 PM 65536]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [03/22/2008 10:18 PM 1271808]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 12:00 PM 15360]
"Free Download Manager"="C:\Program Files\Free Download Manager\fdm.exe" [12/16/2007 08:39 PM 2449455]
"Free Upload Manager"="C:\Program Files\Free Download Manager\fum\fum.exe" [07/29/2007 07:13 PM 253952]
"Free Uploader Oe Integration"="C:\Program Files\Free Download Manager\FUM\fumoei.exe" [06/10/2007 06:02 PM 40960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [05/02/2008 07:15 AM 15872]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [01/13/2007 04:47 AM 131072]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [01/13/2007 04:47 AM 163840]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [01/13/2007 04:46 AM 135168]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [01/19/2007 11:49 AM 49152]
"D-Link D-Link Wireless 108G DWA-520"="C:\Program Files\D-Link\D-Link Wireless 108G DWA-520\AirPlusCFG.exe" [05/04/2007 10:27 AM 1662976]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [10/11/2008 09:49 AM 1234712]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [09/02/2007 01:58 PM 495616]
"LClock"="C:\Program Files\LClock\LClock.exe" [09/19/2004 09:27 PM 65536]
"ctfmon.exe"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 12:00 PM 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" [05/18/2008 11:03 AM 124928 C:\WINDOWS\system32\advpack.dll]
C:\Documents and Settings\anas\Start Menu\Programs\Startup\
Styler.lnk - C:\Documents and Settings\anas\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [10/8/2008 2:26:43 PM 15086]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [10/9/2008 10:53:22 AM 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
05/12/2008 10:49 AM 210168 C:\Program Files\Stardock\ Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [10/09/2008 01:34 PM 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [10/09/2008 01:34 PM 875288]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [10/09/2008 01:34 PM 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [10/09/2008 01:34 PM 76040]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [10/16/2006 03:58 PM 472832]
R3 ev19x8mp;Creative SB AudioPCI Audio Driver (WDM);C:\WINDOWS\system32\drivers\ev19x8mp.sys [11/24/2000 09:10 PM 522268]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [01/24/2008 12:25 AM 27136]
R3 zteusbser;ZTE USB Device for Legacy Serial Communication;C:\WINDOWS\system32\DRIVERS\ZTEUsbser.sys [02/06/2007 10:21 AM 97920]
*Newly Created Service* - PROCEXP90
*Newly Created Service* - SRSERVICE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,Register
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\anas\Application Data\Mozilla\Firefox\Profiles\jvjkoyp1.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q=
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
Rootkit scan 2008-10-11 13:22:58
Windows 5.1.2600 Service Pack 3, v.5512 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\RocketDock\RocketDock.dll
.
Completion time: 10/11/2008 13:23:42
ComboFix-quarantined-files.txt 2008-10-11 10:23:38
Pre-Run: 15,866,953,728 bytes free
Post-Run: 15,855,960,064 bytes free
187 --- E O F --- 2008-10-09 00:19:55
