حملت اول اداة وشغلتها لكن ماطعلت لي الرسالات اللي قلت لي عليها هاذي اولاً لكن قام يفحص لمدة 10 دقائق تقريبا ولكن لم يعيد تشغيل الجهاز على طول فتحت لي المفكرة
ComboFix 08-11-07.01 - مرتضى 11/08/2008 15:54:50.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.271 [GMT 3:00]
Running from: c:\documents and settings\مرتضى\Desktop\1\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-10-08 to 2008-11-08 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-07 15:46 --------- d-----w c:\documents and settings\مرتضى\Application Data\Uniblue
2008-11-07 15:13 --------- d-----w c:\program files\Rising
2008-11-07 15:03 1,060,864 ----a-w c:\windows\system32\mfc71.dll
2008-11-05 13:35 --------- d-----w c:\program files\Windows Media Connect 2
2008-10-31 16:52 --------- d-----w c:\documents and settings\مرتضى\Application Data\Avira
2008-10-31 16:45 --------- d-----w c:\program files\Avira
2008-10-31 16:45 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2008-10-30 12:11 --------- d-----w c:\program files\Video Convert Master
2008-10-29 17:57 --------- d-----w c:\program files\coolpro2
2008-10-25 08:52 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-25 08:52 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-10-25 08:48 --------- d-----w c:\program files\Nokia
2008-10-25 08:48 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2008-10-25 08:47 --------- d-----w c:\program files\MSXML 6.0
2008-10-25 08:47 --------- d-----w c:\program files\Common Files\Nokia
2008-10-25 08:36 --------- d-----w c:\documents and settings\All Users\Application Data\Nokia
2008-10-13 14:06 --------- d-----w c:\program files\WinASO
2008-10-13 13:50 --------- d-----w c:\documents and settings\مرتضى\Application Data\Winamp
2008-10-12 13:31 --------- d-----w c:\program files\Kaspersky Lab
2008-10-11 19:31 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-10-11 19:31 --------- d-----w c:\program files\Adobe Media Player
2008-10-08 07:52 --------- d-----w c:\program files\VerbAce Research
2008-09-21 02:42 --------- d-----w c:\program files\Tweak Marketing
2008-09-17 14:37 --------- d-----w c:\program files\Messenger Plus! Live
2008-09-15 14:27 --------- d-----w c:\documents and settings\مرتضى\Application Data\Thinstall
2008-09-13 14:19 --------- d-----w c:\program files\NSS
2008-09-09 17:39 --------- d-----w c:\documents and settings\All Users\Application Data\WEBREG
2008-09-09 17:09 --------- d-----w c:\program files\HP
2008-09-09 17:09 --------- d-----w c:\documents and settings\All Users\Application Data\HPSSUPPLY
2008-09-09 17:09 --------- d-----w c:\documents and settings\All Users\Application Data\HP
2008-09-09 17:08 --------- d-----w c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-09-09 17:04 --------- d-----w c:\program files\Common Files\HP
2008-08-29 10:58 81,920 ----a-w c:\documents and settings\مرتضى\Application Data\ezpinst.exe
2008-08-29 10:58 47,360 ----a-w c:\documents and settings\مرتضى\Application Data\pcouffin.sys
2008-07-20 23:25 105,723 ----a-w c:\program files\rst.exe
2008-07-20 08:46 910,633 ----a-w c:\program files\u.exe
2008-07-09 12:40 1,903,262 ----a-w c:\program files\The Holy Quran mp3 player online تلاوة القرآن الكريم مباشرة.mp3
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [05/23/2004 03:00 PM 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [08/16/2007 04:19 PM 5728112]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [08/04/2004 01:06 AM 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [07/29/2008 07:47 PM 185896]
"CloneCDElbyCDFL"="c:\program files\Elaborate Bytes\CloneCD\ElbyCheck.exe" [12/06/2001 03:09 PM 45056]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [07/22/2008 08:42 PM 116040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [05/27/2008 10:50 AM 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [07/30/2008 10:47 AM 289064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM 39792]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [03/11/2007 09:34 PM 49152]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [06/12/2008 02:28 PM 266497]
"BluetoothAuthenticationAgent"="bthprops.cpl" [05/23/2004 03:00 PM 110592 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [05/23/2004 03:00 PM 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-07-07 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\DynGate\\DynGate.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RecordingManager.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2151:UDP"= 2151:UDP:Windows Media Format SDK (iexplore.exe)
R2 AntiVirMailService;Avira AntiVir Premium MailGuard;c:\program files\Avira\AntiVir PersonalEdition Premium\avmailc.exe [07/11/2008 12:23 PM 164097]
R2 antivirwebservice;Avira AntiVir Premium WebGuard;c:\program files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE [06/12/2008 02:59 PM 258305]
R2 AVEService;Avira AntiVir Premium MailGuard helper service;c:\program files\Avira\AntiVir PersonalEdition Premium\avesvc.exe [05/09/2008 01:22 PM 41217]
R3 slnt;Silan SC92031 PCI Fast Ethernet Adapter;c:\windows\system32\DRIVERS\slnt.sys [11/20/2003 12:58 PM 18004]
S3 PRODIGY;PRODIGY;c:\windows\system32\Drivers\PRODIGY.SYS [08/29/2006 05:56 PM 32377]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-11-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [04/11/2008 05:57 PM]
2008-11-08 c:\windows\Tasks\WinASORegistryOptimizerForمرتضى.job
- c:\program files\WinASO\Registry Optimizer 3.2\RegOpt.exe []
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\مرتضى\Application Data\Mozilla\Firefox\Profiles\kay26urz.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-08 15:56:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 11/08/2008 15:58:05
ComboFix-quarantined-files.txt 2008-11-08 12:57:16
ComboFix2.txt 2008-11-08 12:52:10
Pre-Run: 12,868,423,680 bytes free
Post-Run: 12,860,194,816 bytes free
127