شكرا
شكرا اختي خلود عالمرور
هذا التقرير الاول
ComboFix 08-11-30.02 - وســ السامرائي ـــام 12/01/2008 20:31:57.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.287 [GMT 3:00]
Running from: E:\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\msvrc20.dll
c:\windows\system32\DivXc32.dll
c:\windows\system32\DivXc32f.dll
c:\windows\system32\mpg4c32.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-01 17:32 --------- d-----w c:\documents and settings\وســ السامرائي ـــام\Application Data\DMCache
2008-12-01 17:32 --------- d-----w c:\documents and settings\وســ السامرائي ـــام\Application Data\DMCache
2008-12-01 17:32 --------- d-----w c:\documents and settings\وســ السامرائي ـــام\Application Data\DMCache
2008-11-30 19:33 8,274,311 ------w C:\Persi0.sys
2008-11-30 19:33 --------- d-----w c:\program files\Faronics
2008-11-30 19:18 --------- d-----w c:\program files\ProgDVB
2008-11-30 19:17 --------- d-----w c:\program files\Zoom Player
2008-11-30 19:17 --------- d-----w c:\program files\Projekt IGI
2008-11-30 19:17 --------- d-----w c:\program files\DVB-S PowerInstall
2008-11-30 19:11 --------- d-----w c:\program files\Golden Al-Wafi Translator
2008-11-30 19:10 73,216 ----a-w c:\windows\ST6UNST.EXE
2008-11-30 19:10 172,032 ------w c:\windows\Setup1.exe
2008-11-30 19:00 --------- d-----w c:\program files\MSN Messenger
2008-11-30 18:43 --------- d-----w c:\program files\Java
2008-11-30 18:43 --------- d-----w c:\program files\Common Files\Java
2008-11-30 18:40 --------- d-----w c:\program files\Save Flash
2008-11-30 18:38 --------- d-----w c:\documents and settings\وســ السامرائي ـــام\Application Data\IDM
2008-11-30 18:38 --------- d-----w c:\documents and settings\وســ السامرائي ـــام\Application Data\IDM
2008-11-30 18:38 --------- d-----w c:\documents and settings\وســ السامرائي ـــام\Application Data\IDM
2008-11-30 18:28 --------- d-----w c:\program files\Kaspersky Lab
2008-11-30 18:27 --------- d-----w c:\documents and settings\وســ السامرائي ـــام\Application Data\AdobeUM
2008-11-30 18:27 --------- d-----w c:\documents and settings\وســ السامرائي ـــام\Application Data\AdobeUM
2008-11-30 18:27 --------- d-----w c:\documents and settings\وســ السامرائي ـــام\Application Data\AdobeUM
2008-11-30 18:21 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-30 18:21 --------- d-----w c:\program files\PC-TV
2008-11-30 18:19 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-30 18:17 --------- d-----w c:\program files\D-Link
2008-11-30 18:17 --------- d-----w c:\program files\ANI
2008-11-30 18:15 --------- d-----w c:\program files\ASUS
2008-11-30 18:14 --------- d-----w c:\program files\Common Files\Adobe
2008-11-30 18:13 --------- d-----w c:\program files\Marvell
2008-11-30 18:13 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-11-30 18:10 --------- d-----w c:\program files\Intel
2008-11-30 07:46 --------- d-----w c:\program files\%tmp%
2008-11-30 07:45 --------- d-----w c:\program files\Vortex Windows Tools
2008-11-30 06:04 --------- d-----w c:\program files\Windows Media Connect 2
2008-11-30 06:04 --------- d-----w c:\program files\UltraISO
2008-11-30 06:04 --------- d-----w c:\program files\Common Files\EZB Systems
2008-11-30 06:03 --------- d-----w c:\program files\Yahoo!
2008-11-30 06:03 --------- d-----w c:\program files\Multimedia
2008-11-30 06:02 155,995 ----a-w c:\windows\java\Packages\N7ZNVZRH.ZIP
2008-11-30 06:02 --------- d-----w c:\program files\Real Alternative
2008-11-30 06:02 --------- d-----w c:\program files\Media Player Classic
2008-11-30 06:02 --------- d-----w c:\program files\K-Lite Codec Pack
2008-11-30 06:01 --------- d-----w c:\program files\microsoft frontpage
2008-11-30 05:49 --------- d-----w c:\program files\Foxit
.
------- Sigcheck -------
12/28/2006 01:01 PM 2198144 c37e9d48a2b61919607ce62f1093444d c:\windows\system32\ntkrnlpa.exe
12/28/2006 12:51 PM 2321024 6a86e8c59d90e9bd6a3f85033adfb1b3 c:\windows\system32\ntoskrnl.exe
12/28/2006 10:51 AM 1423360 8730231e85c924a40b4600daf42c46d4 c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 05:00 PM 15360]
"IDMan"="e:\program files\Internet Download Manager\IDMan.exe" [12/20/2007 07:05 PM 2749872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS Probe"="c:\program files\ASUS\Asus Probe\AsusProb.exe" [12/06/2002 04:07 PM 617984]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 05:00 PM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="VORTEXNUI.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DfLogon]
06/12/2005 12:41 PM 49152 c:\windows\system32\LogonDll.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i263_32.drv
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"vidc.3iv2"= 3ivxVfWCodec.dll
"msacm.divxa32"= divxa32.acm
"VIDC.HFYU"= huffyuv.dll
"VIDC.i263"= i263_32.drv
"msacm.imc"= imc32.acm
"VIDC.VP31"= vp31vfw.dll
"msacm.avis"= ff_acm.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinManager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinManager.lnk
backup=c:\windows\pss\WinManager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
--a------ 06/01/2006 04:59 PM 49152 c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Probe]
--a------ 12/06/2002 04:07 PM 617984 c:\program files\ASUS\Asus Probe\AsusProb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D-Link AirPlus XtremeG]
--a------ 06/16/2006 10:24 AM 1323008 c:\program files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--ah----- 12/20/2007 07:05 PM 2749872 e:\program files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 09/20/2005 10:32 AM 77824 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 09/20/2005 10:36 AM 114688 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 09/20/2005 10:35 AM 94208 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vistadrv]
--a------ 07/30/2006 04:37 AM 121089 c:\program files\Vortex Windows Tools\Vortex\vortex\VIPhd\vsdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 08/29/2006 08:54 PM 4621816 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"d:\\برامج\\Golden Al-Wafi Translator 1.12\\Setup.exe"=
"d:\\برامج\\كرت ستلايت\\ProgDVB Power Install 7.6\\ProgDVB Power\\ProgDVBPowerInstall7.6.EXE"=
"e:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\WINDOWS\\NIRCMD.exe"=
R0 DeepFrz;DeepFrz;c:\windows\system32\drivers\DeepFrz.sys [2005-06-12 125824]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\DRIVERS\A3AB.sys [2006-05-11 472096]
R3 DtvAudio;DtvAudio;c:\windows\system32\DRIVERS\DtvAudio.sys [2008-11-30 9216]
R3 DtvVideo;DtvVideo;c:\windows\system32\DRIVERS\DtvVideo.sys [2008-11-30 23680]
S1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\vcdrom.sys [2008-11-30 8576]
*Newly Created Service* - ASC3360PR
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
IE: تحميل الكل بـ إنترنت داونلود مانيجر - e:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - e:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - e:\program files\Internet Download Manager\IEGetVL.htm
O16 -: Microsoft XML Parser for Java -
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-01 20:34:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(732)
c:\windows\system32\LogonDll.dll
c:\windows\system32\cscui.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
c:\program files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
c:\program files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
e:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 12/01/2008 20:37:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-01 17:37:42
Pre-Run: 6,750,916,608 bytes free
Post-Run: 6,669,488,128 bytes free
192