ComboFix 08-12-05.02 - maha 12/05/2008 13:22:59.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.859 [GMT 3:00]
Running from: c:\documents and settings\maha\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-11-05 to 2008-12-05 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-05 03:34 --------- d-----w c:\program files\Microsoft.NET
2008-12-05 03:26 --------- d-----w c:\program files\Realtek Sound Manager
2008-12-05 03:26 --------- d-----w c:\program files\AvRack
2008-12-05 03:25 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-05 03:25 --------- d-----w c:\program files\VIA
2008-12-05 03:24 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-05 03:22 --------- d-----w c:\program files\S3
2008-12-05 02:33 --------- d-----w c:\program files\microsoft frontpage
.
(((((((((((((((((((((((((((((
snapshot@Fri 12-05-2008_13.13.25.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-05 02:37:57 151,584 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-05 10:21:54 282,928 ----a-w c:\windows\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 03:00 PM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RaidTool"="c:\program files\VIA\RAID\raid_tool.exe" [10/11/2004 09:54 AM 589824]
"VTTrayp"="VTtrayp.exe" [06/21/2004 09:57 PM 143360 c:\windows\system32\VTTrayp.exe]
"VTTimer"="VTTimer.exe" [09/01/2004 11:28 AM 53248 c:\windows\system32\VTTimer.exe]
"SoundMan"="SOUNDMAN.EXE" [02/09/2004 11:54 AM 65024 c:\windows\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 03:00 PM 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-05 13:24:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 12/05/2008 13:24:52
ComboFix-quarantined-files.txt 2008-12-05 10:24:31
ComboFix2.txt 2008-12-05 10:14:11
Pre-Run: 27,707,027,456 bytes free
Post-Run: 27,699,445,760 bytes free
58
هذا التقرير اللي طلبته مني
ولك جزيل الشكر