عذرا على التأخير ,,,
ComboFix 08-10-31.02 - Administrator 11/01/2008 21:24:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.218 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-10-01 to 2008-11-01 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-01 18:22 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DMCache
2008-10-12 20:56 --------- d-----w C:\Documents and Settings\Administrator\Application Data\IDM
2008-10-11 23:32 --------- d-----w C:\Program Files\Internet Download Manager
2008-10-11 18:21 --------- d-----w C:\Documents and Settings\Administrator\Application Data\option intra
2008-10-11 15:47 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Avira
2008-10-08 13:17 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Thinstall
2008-10-08 10:20 --------- d-----w C:\Documents and Settings\Administrator\Application Data\PC Suite
2008-10-08 10:16 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia
2008-10-08 01:24 --------- d-----w C:\Program Files\PhotoRescue Pro
2008-09-29 11:24 --------- d-----w C:\Documents and Settings\عام\Application Data\PC Suite
2008-09-28 20:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\LICENSE ADMIN OPTION BIB
2008-09-28 20:54 --------- d-----w C:\Program Files\option intra
2008-09-28 20:53 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-28 20:53 --------- d-----w C:\Program Files\Circle Developement
2008-09-15 12:12 1,846,400 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-26 07:24 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 10:11 2,189,184 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:33 2,066,048 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2006-06-27 02:40 571,184 --sha-r C:\WINDOWS\system32\legitcheckcontrol.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [01/26/2008 06:57 AM 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [01/26/2008 06:57 AM 1695232]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [10/12/2008 10:03 PM 68856]
"Error One"="C:\DOCUME~1\ADMINI~1\APPLIC~1\OPTION~1\ownscool.exe" [09/28/2008 11:54 PM 479232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaDrive"="C:\WINDOWS\VistaDrive\VistaDrive.exe" [10/05/2006 08:56 PM 280779]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [11/03/2004 06:03 AM 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [11/03/2004 05:59 AM 126976]
"avgnt"="C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" [06/12/2008 02:28 PM 266497]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [06/18/2007 03:10 PM 271360]
"Option Bib Logo Log"="C:\Documents and Settings\All Users\Application Data\LICENSE ADMIN OPTION BIB\Keep Wipe.exe" [09/30/2008 04:58 AM 509440]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [01/26/2008 06:57 AM 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [06/19/2007 10:17 AM 1241088]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-07-27 113664]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\IEPro\\MiniDM.exe"=
R1 avfwot;avfwot;C:\WINDOWS\system32\DRIVERS\avfwot.sys [05/07/2008 02:20 PM 71592]
R2 AntiVirFirewallService;Avira Premium Security Suite Firewall;C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe [05/16/2008 10:19 AM 344321]
R2 AntiVirMailService;Avira Premium Security Suite MailGuard;C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe [07/11/2008 12:23 PM 164097]
R2 antivirwebservice;Avira Premium Security Suite WebGuard;C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE [06/12/2008 02:59 PM 258305]
R2 AVEService;Avira Premium Security Suite MailGuard helper service;C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe [05/09/2008 01:22 PM 41217]
R3 avfwim;AvFw Packet Filter Miniport;C:\WINDOWS\system32\DRIVERS\avfwim.sys [05/07/2008 10:51 AM 71464]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a363933a-a742-11dd-893a-000fb082f69b}]
\Shell\AutoRun\command - svdioajm.cmd
\Shell\explore\Command - svdioajm.cmd
\Shell\open\Command - svdioajm.cmd
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-11-01 C:\WINDOWS\Tasks\AEECBE21919733BD.job
- c:\docume~1\admini~1\applic~1\option~1\RuleModeBuild.exe []
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: تحميل الكل بـ إنترنت داونلود مانيجر - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX01.234\Internet Download Manager 5.14 Build 5\IEGetAll.htm
O8 -: تحميل بـ إنترنت داونلود مانيجر - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX01.234\Internet Download Manager 5.14 Build 5\IEExt.htm
O8 -: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX01.234\Internet Download Manager 5.14 Build 5\IEGetVL.htm
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-01 21:27:11
Windows 5.1.2600 Service Pack 3, v.5657 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 11/01/2008 21:28:24
ComboFix-quarantined-files.txt 2008-11-01 18:28:08
Pre-Run: 19,765,633,024 bytes free
Post-Run: 20,147,060,736 bytes free
106 --- E O F --- 2008-10-25 18:24:54