هذا القرير الاول
ComboFix 08-11-16.05 - Administrator 11/17/2008 12:51:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.242 [GMT 3:00]
Running from: c:\documents and settings\Administrator.4EA567BAF5BB482\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\ADMINI~1.4EA\LOCALS~1\Temp\winlogon.exe
c:\windows\IE4 Error Log.txt
c:\windows\system32\~.exe
c:\windows\system32\AutoRun.inf
c:\windows\wiaserviv.log
g:\recycler\JetAudio dump.exe
g:\recycler\RECYCLER .exe
G:\zPharaoh.exe
h:\recycler\RECYCLER .exe
h:\recycler\WinrRarSerialInstall.exe
H:\zPharaoh.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-17 to 2008-11-17 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-17 08:54 94,080 ----a-w c:\documents and settings\Administrator.4EA567BAF5BB482\Application Data\ezplay.sys
2008-11-17 08:54 87,608 ----a-w c:\documents and settings\Administrator.4EA567BAF5BB482\Application Data\ezpinst.exe
2008-11-17 08:54 47,360 ----a-w c:\documents and settings\Administrator.4EA567BAF5BB482\Application Data\pcouffin.sys
2008-11-17 08:54 --------- d-----w c:\documents and settings\Administrator.4EA567BAF5BB482\Application Data\Vso
2008-11-17 08:49 94,080 ----a-w c:\windows\system32\drivers\ezplay.sys
2008-11-17 08:49 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2008-11-17 08:17 --------- d-----w c:\documents and settings\Administrator.4EA567BAF5BB482\Application Data\McFunSoftDVDCreator
2008-11-17 07:24 --------- d-----w c:\program files\Video Convert Master
2008-11-14 11:06 --------- d-----w c:\program files\Nokia
2008-11-14 05:20 --------- d-----w c:\program files\Internet Download Manager
2008-11-14 05:17 --------- d-----w c:\program files\Circle Developement
2008-11-12 14:40 --------- d-----w c:\program files\Avant Browser
2008-11-10 22:22 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2008-11-10 20:56 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-10 20:56 --------- d-----w c:\documents and settings\All Users\Application Data\Ulead Systems
2008-11-10 03:24 --------- d-----w c:\documents and settings\Administrator.4EA567BAF5BB482\Application Data\Ulead Systems
2008-11-10 03:17 --------- d-----w c:\program files\Windows Media Components
2008-11-10 03:15 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-09 23:13 --------- d-----w c:\program files\FLV Player
2008-11-09 22:33 --------- d-----w c:\program files\GoodOk YouTube FLV to AVI 3GP MP4 WMV ASF Converter
2008-11-09 22:32 --------- d-----w c:\program files\Common Files\Download Manager
2008-11-09 22:18 --------- d-----w c:\program files\1-Click YouTube Downloader
2008-11-08 03:44 --------- d-----w c:\documents and settings\Administrator.4EA567BAF5BB482\Application Data\uTorrent
2008-11-08 02:40 --------- d-----w c:\program files\LtUcx
2008-11-06 20:08 --------- d-----w c:\program files\MSN Messenger
2008-10-23 22:07 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-18 22:35 --------- d-----w c:\program files\Common Files\xing shared
2008-10-18 22:35 --------- d-----w c:\program files\Common Files\Real
2008-10-17 11:41 --------- d-----w c:\program files\FlashFXP
2008-10-17 08:46 --------- d-----w c:\program files\PHP Expert Editor 4.2
2008-10-17 08:43 --------- d-----w c:\program files\NO1 Video Converter
2008-10-11 00:09 --------- d-----w c:\documents and settings\Administrator.4EA567BAF5BB482\Application Data\DMCache
2008-10-11 00:06 --------- d-----w c:\documents and settings\Administrator.4EA567BAF5BB482\Application Data\IDM
2008-10-09 21:38 --------- d-----w c:\program files\uTorrent
2008-10-09 16:38 --------- d-----w c:\documents and settings\Administrator.4EA567BAF5BB482\Application Data\FlashFXP
2008-10-09 16:09 --------- d-----w c:\documents and settings\All Users\Application Data\FlashFXP
2008-10-01 09:09 --------- d-----w c:\documents and settings\Administrator.4EA567BAF5BB482\Application Data\PC Suite
2008-09-17 09:12 --------- d-----w c:\documents and settings\Administrator.4EA567BAF5BB482\Application Data\2ownsload
2008-08-06 08:11 6,144 --sha-w c:\program files\Thumbs.db
2008-07-28 13:29 24,842 ----a-w c:\documents and settings\Administrator.4EA567BAF5BB482\Application Data\ain.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [08/04/2004 01:09 AM 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [01/08/2005 02:17 AM 102491]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [01/08/2005 02:16 AM 692315]
"igfxtray"="c:\windows\system32\igfxtray.exe" [07/19/2005 06:09 AM 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [07/19/2005 06:06 AM 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [07/19/2005 06:10 AM 114688]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [07/19/2008 05:38 PM 78008]
"SDaemon"="c:\windows\sdaemon.exe" [04/19/2005 12:57 AM 111104]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [10/19/2008 01:34 AM 185896]
"RTHDCPL"="RTHDCPL.EXE" [11/17/2005 06:27 AM 15600128 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-08-05 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-01-05 618557]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R0 WINSEC;WINSEC;c:\windows\system32\drivers\WINSEC.SYS [2005-04-19 20352]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-24 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-24 20560]
S2 CamelApache;CamelApache;"c:\camel\apache\apache.exe" --ntservice [2004-10-28 20545]
S3 CamelMysql;CamelMysql;c:\camel\mysql\bin\mysqld-nt.exe --defaults-file="c:\camel\mysql\ini\my.ini" CamelMysql []
S4 winser;winser;c:\windows\system32\winsersec.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a994f233-8a9c-11dd-9393-00166f28bc0f}]
\Shell\Auto\command - auto.exe
\Shell\Autoplay\Command - smss.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe
\Shell\Explore\Command - smss.exe
\Shell\Open\Command - smss.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ca6027e2-6b21-11dd-933d-00166f28bc0f}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f952f19f-6978-11dd-9338-00166f28bc0f}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f952f1a2-6978-11dd-9338-00166f28bc0f}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ff42e9c2-5951-11dd-9307-00166f28bc0f}]
\Shell\AutoRun\command - 6x8be16.cmd
\Shell\explore\Command - 6x8be16.cmd
\Shell\open\Command - 6x8be16.cmd
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-SWd - c:\windows\winwd.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Administrator.4EA567BAF5BB482\Application Data\Mozilla\Firefox\Profiles\6ja3l7oa.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-17 12:56:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 11/17/2008 12:57:26
ComboFix-quarantined-files.txt 2008-11-17 09:57:20
Pre-Run: 15,997,313,024 bytes free
Post-Run: 18,254,012,416 bytes free
149 --- E O F --- 2008-07-29 03:48:56