ودة يااخى تقرير combofix
ComboFix 08-10-31.02 - Administrator 11/01/2008 10:34:41.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.20.1033.18.1068 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINXP\system32\dao350.dll
.
((((((((((((((((((((((((( Files Created from 2008-10-01 to 2008-11-01 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-01 07:13 --------- d-----w C:\Program Files\Microsoft.NET
2008-11-01 07:13 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-10-31 17:43 --------- d-----w C:\Program Files\Real
2008-10-31 17:43 --------- d-----w C:\Program Files\Common Files\xing shared
2008-10-31 15:08 --------- d-----w C:\Program Files\Google
2008-10-29 18:37 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Uniblue
2008-10-27 16:35 --------- d-----w C:\Program Files\Profiler3D
2008-10-27 13:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-10-27 13:26 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Yahoo!
2008-10-27 12:41 --------- d-----w C:\Program Files\Yahoo!
2008-10-27 09:41 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-10-27 09:19 --------- d-----w C:\Program Files\Sjboy Emulator
2008-10-27 07:17 --------- d-----w C:\Program Files\Common Files\Adobe
2008-10-27 06:04 90,112 ----a-w C:\WINXP\DUMP4a53.tmp
2008-10-26 21:50 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-10-26 21:50 --------- d-----w C:\Program Files\DIFX
2008-10-26 21:50 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-10-26 21:50 --------- d-----w C:\Program Files\Common Files\Nokia
2008-10-26 21:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-10-26 21:50 --------- d-----w C:\Documents and Settings\Administrator\Application Data\PC Suite
2008-10-26 21:50 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia
2008-10-26 21:49 --------- d-----w C:\Program Files\Nokia
2008-10-25 12:48 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-25 09:41 --------- d-----w C:\Program Files\MSN Messenger
2008-10-24 17:49 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-10-24 15:53 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Avira
2008-10-24 15:29 --------- d-----w C:\Program Files\Turbo BaramgyFox English Edition
2008-10-24 13:51 --------- d-----w C:\Program Files\myproxy
2008-10-24 13:42 --------- d-----w C:\Program Files\Internet Download Manager
2008-10-24 13:42 --------- d-----w C:\Documents and Settings\Administrator\Application Data\IDM
2008-10-24 13:42 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DMCache
2008-10-24 00:20 --------- d-----w C:\Program Files\Java
2008-10-24 00:20 --------- d-----w C:\Program Files\Common Files\Java
2008-10-24 00:17 --------- d-----w C:\Program Files\Ela-Salaty
2008-10-24 00:09 --------- d-----w C:\Program Files\Avira
2008-10-24 00:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-10-24 00:04 --------- d-----w C:\Program Files\Windows Doctor
2008-10-23 23:57 --------- d-----w C:\Program Files\Nero
2008-10-23 23:57 --------- d-----w C:\Program Files\Common Files\Ahead
2008-10-23 23:56 --------- d-----w C:\Program Files\Ringz Studio
2008-10-23 23:56 --------- d-----w C:\Program Files\Common Files\Real
2008-10-23 23:56 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Winamp
2008-10-23 23:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-10-23 23:49 155,995 ----a-w C:\WINXP\java\Packages\53XNZJXV.ZIP
2008-10-23 23:39 --------- d-----w C:\Program Files\Intel
2008-10-23 23:35 --------- d-----w C:\Program Files\WINAMP
2008-09-12 10:44 206,256 ----a-w C:\WINXP\system32\idmmbc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
07/28/2008 12:46 PM 160496 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [09/12/2008 12:45 PM 2606512]
"Search Protection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [10/07/2008 05:23 PM 111856]
"Messenger (Yahoo!)"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [09/19/2008 05:34 PM 4347120]
"CTFMON.EXE"="C:\WINXP\system32\ctfmon.exe" [01/01/2002 02:33 AM 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [12/16/2005 12:57 PM 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" [06/12/2008 02:28 PM 266497]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [10/07/2008 05:23 PM 111856]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [12/20/2007 05:16 PM 37376]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [10/31/2008 07:43 PM 185872]
"StormCodec_Helper"="C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" [02/07/2005 04:04 AM 94037]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [01/23/2007 11:19 AM 223232]
"NeroFilterCheck"="C:\WINXP\system32\NeroCheck.exe" [07/09/2001 10:50 AM 155648]
"igfxtray"="C:\WINXP\system32\igfxtray.exe" [11/28/2005 07:55 AM 98304]
"igfxpers"="C:\WINXP\system32\igfxpers.exe" [11/28/2005 07:55 AM 118784]
"igfxhkcmd"="C:\WINXP\system32\hkcmd.exe" [11/28/2005 07:52 AM 77824]
"SkyTel"="SkyTel.EXE" [05/16/2006 12:04 PM 2879488 C:\WINXP\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [07/21/2006 10:56 AM 16261632 C:\WINXP\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINXP\system32\CTFMON.EXE" [01/01/2002 02:33 AM 15360]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [11/09/2006 05:15 PM 1634304]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Ela-Salaty.lnk - C:\Program Files\Ela-Salaty\Salaty.exe [2007-03-05 5090816]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
MAYHILL_TROFISH.EXE [2002-01-01 13305444]
Adobe Reader Speed Launch.lnk - C:\WINXP\Installer\{AC76BA86-7AD7-1033-7B44-A70001000000}\SC_Reader.exe [2008-10-27 25214]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.vp31"= vp31vfw.dll
"vidc.DIV3"= DIVXc32.dll
"vidc.DIV4"= DIVXc32f.dll
"msacm.divxa32"= DivXa32.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\myproxy\\MyProxy.exe"=
"C:\\Program Files\\Turbo BaramgyFox English Edition\\Turbo baramgyFox.exe"=
R1 avfwot;avfwot;C:\WINXP\system32\DRIVERS\avfwot.sys [05/07/2008 02:20 PM 71592]
R2 AntiVirFirewallService;Avira Premium Security Suite Firewall;C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe [05/16/2008 10:19 AM 344321]
R2 AntiVirMailService;Avira Premium Security Suite MailGuard;C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe [07/11/2008 12:23 PM 164097]
R2 antivirwebservice;Avira Premium Security Suite WebGuard;C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE [06/12/2008 02:59 PM 258305]
R2 AVEService;Avira Premium Security Suite MailGuard helper service;C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe [05/09/2008 01:22 PM 41217]
R3 avfwim;AvFw Packet Filter Miniport;C:\WINXP\system32\DRIVERS\avfwim.sys [05/07/2008 10:51 AM 71464]
S3 IPPackwatch1;Watch IP and store the Row Packets;C:\Program Files\Profiler3D\Scannet 3.9\IPPWatch.exe [02/25/2007 02:45 PM 520192]
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.eg/
R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.yahoo.com/
R1 -: HKCU-Internet Settings,ProxyServer = 127.0.0.1:8080
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 -: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 -: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 -: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O16 -: Microsoft XML Parser for Java - C:\WINXP\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-01 10:35:35
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 11/01/2008 10:35:58
ComboFix-quarantined-files.txt 2008-11-01 08:35:58
Pre-Run: 10,443,587,584 bytes free
Post-Run: 10,489,847,808 bytes free
149