السلام عليكم
هذا تقرير عن الجهاز
بعد استخدام اداه ComboFix
ComboFix 08-11-11.01 - Administrator 11/13/2008 19:02:07.1 -
FAT32x86 MINIMAL
Running from: d:\برامج نت\ادوات مهمه للجهاز\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
c:\windows\system32\urlmon.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\WS2HELP.dll
c:\windows\system32\WININET.dll
c:\windows\system32\psapi.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\resycled
c:\resycled\boot.com
c:\windows\regedit.com
c:\windows\system32\taskmgr.com
D:\Autorun.inf
E:\Autorun.inf
F:\Autorun.inf
G:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-10-13 to 2008-11-13 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-13 13:17 --------- d-----w c:\program files\'Full Speed' Internet Booster + Performance Tests
2008-11-13 11:38 --------- d-----w c:\program files\Unlocker
2008-11-13 11:38 --------- d-----w c:\documents and settings\Administrator\Application Data\Desktopicon
2008-11-12 18:02 --------- d-----w c:\documents and settings\Administrator\Application Data\CyberScrub
2008-11-12 18:02 --------- d-----w c:\documents and settings\Administrator\Application Data\cleaner
2008-11-11 12:52 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2008-11-10 22:24 27,904 ----a-w c:\windows\system32\drivers\ndisprot.sys
2008-11-10 20:52 --------- d-----w c:\program files\ColorSoft
2008-11-06 19:32 --------- d-----w c:\program files\Yahoo!
2008-11-04 22:38 --------- d-----w c:\documents and settings\Administrator\Application Data\Avira
2008-11-04 22:32 --------- d-----w c:\program files\Avira
2008-11-02 13:56 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-11-02 09:00 --------- d-----w c:\program files\Windows Live Safety Center
2008-11-01 20:48 --------- d-----w c:\program files\MSXML 4.0
2008-11-01 08:22 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2008-10-27 20:07 --------- d-----w c:\program files\Winamp
2008-10-27 20:07 --------- d-----w c:\documents and settings\Administrator\Application Data\Winamp
2008-10-23 15:07 --------- d-----w c:\program files\Diskeeper Corporation
2008-10-23 15:07 --------- d-----w c:\documents and settings\All Users\Application Data\Diskeeper Corporation
2008-10-23 12:54 --------- d-----w c:\documents and settings\All Users\Application Data\JH Software
2008-10-15 16:34 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-15 12:12 1,846,400 ------w c:\windows\system32\dllcache\win32k.sys
2008-09-08 10:41 333,824 ------w c:\windows\system32\dllcache\srv.sys
2008-09-05 21:30 241,704 ----a-w c:\windows\system32\dllcache\wgaLogon.dll
2008-09-05 21:29 917,032 ----a-w c:\windows\system32\dllcache\WgaTray.exe
2008-08-20 05:30 1,499,136 ------w c:\windows\system32\dllcache\shdocvw.dll
2008-08-14 10:11 2,189,184 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 10:11 2,189,184 ------w c:\windows\system32\dllcache\ntoskrnl.exe
2008-08-14 10:09 2,145,280 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
2008-08-14 10:04 138,496 ------w c:\windows\system32\dllcache\afd.sys
2008-08-14 09:33 2,066,048 ----a-w c:\windows\system32\ntkrnlpa.exe
2008-08-14 09:33 2,066,048 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
2008-08-14 09:33 2,023,936 ------w c:\windows\system32\dllcache\ntkrpamp.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [06/11/2007 06:16 PM 4670968]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [06/15/2008 11:33 PM 880896]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [04/14/2008 02:12 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"c:\windows\system32\kddoo.exe"="c:\windows\system32\kddoo.exe" [04/14/2008 02:12 AM 69120]
"avgnt"="c:\program files\Avira\Avira Premium Security Suite\avgnt.exe" [06/12/2008 02:28 PM 266497]
"AntiARPStandalone"="c:\program files\ColorSoft\AntiARP\AntiARP.exe" [12/10/2007 02:49 PM 7176704]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [04/14/2008 02:12 AM 169984]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoFileAssociate"= 0 (0x0)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 04/14/2008 02:12 AM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 06/15/2008 11:33 PM 880896 c:\program files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 01/19/2007 12:54 PM 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 06/15/2008 11:27 PM 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 06/11/2007 06:16 PM 4670968 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSPower]
-ra------ 03/03/2005 09:50 PM 49152 c:\windows\system32\SiSPower.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 11/15/2004 01:20 PM 77824 c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
S1 avfwot;avfwot;c:\windows\system32\DRIVERS\avfwot.sys [05/07/2008 02:20 PM 71592]
S2 AntiARPClientLoader;AntiARP Client Loader;c:\program files\ColorSoft\AntiARP\AntiARPClientLoader.exe [10/17/2007 04:25 PM 40960]
S2 AntiArpNdisProt;AntiARP NDIS Protocol Driver;c:\windows\system32\DRIVERS\AntiArpNdisProt.sys [10/17/2007 01:33 PM 21120]
S2 AntiVirFirewallService;Avira Premium Security Suite Firewall;c:\program files\Avira\Avira Premium Security Suite\avfwsvc.exe [05/16/2008 10:19 AM 344321]
S2 AntiVirMailService;Avira Premium Security Suite MailGuard;c:\program files\Avira\Avira Premium Security Suite\avmailc.exe [07/11/2008 12:23 PM 164097]
S2 AVEService;Avira Premium Security Suite MailGuard helper service;c:\program files\Avira\Avira Premium Security Suite\avesvc.exe [05/09/2008 01:22 PM 41217]
S3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\DRIVERS\avfwim.sys [05/07/2008 10:51 AM 71464]
S3 Ndisprot;ArcNet NDIS Protocol Driver;c:\windows\system32\drivers\Ndisprot.sys [11/11/2008 12:24 AM 27904]
S3 xAntiArp;xAntiArpSpoof Service;c:\windows\system32\DRIVERS\xAntiArp.sys [12/06/2007 02:16 PM 375296]
S4 antivirwebservice;Avira Premium Security Suite WebGuard;c:\program files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE [06/12/2008 02:59 PM 258305]
.
.
------- Supplementary Scan -------
.
R1 -: HKCU-Internet Settings,ProxyServer = 127.0.0.1:80
O8 -: Download All Links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
O8 -: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
.
.
------- File Associations -------
.
txtfile=c:\windows\notepad.exe %1
vbefile\shell\edit\command=c:\windows\Notepad.exe %1
vbsfile\shell\edit\command=c:\windows\Notepad.exe %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-13 19:09:28
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\PCHealth\HelpCtr\Binaries\HelpSvc.exe
.
**************************************************************************
.
Completion time: 11/13/2008 19:10:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-13 17:10:38
Pre-Run: 3,884,331,008 bytes free
Post-Run: 3,827,417,088 bytes free
169 --- E O F --- 2008-11-03 10:53:43
ارجو منكم ان اجد المساعده بصوره اسرع من ذلك
خصوصا وان المنتدى غنى بالخبرات والمواهب العظيمه
وهذا من اسباب اهتمامى وحبى للمنتدى
تقبلوا تحياتى
وفى انتظار ردودكم ومساعدتكم