تفضل يا اخى التقرير
ComboFix 08-12-11.04 - hamada 2008-12-12 9:49:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.225 [GMT 2:00]
Running from: c:\documents and settings\hamada\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\mpg4c32.dll
c:\windows\system32\x64
.
((((((((((((((((((((((((( Files Created from 2008-11-12 to 2008-12-12 )))))))))))))))))))))))))))))))
.
2008-12-11 17:57 . 2008-12-11 17:57 <DIR> d-------- c:\program files\Nokia
2008-12-11 17:57 . 2008-12-11 17:57 <DIR> d-------- c:\program files\Common Files\Nokia
2008-12-11 17:55 . 2008-12-11 17:55 <DIR> d-------- c:\windows\system32\QuickTime
2008-12-11 17:54 . 2004-01-27 13:53 1,024,000 --a------ c:\windows\system32\3ivx.dll
2008-12-11 17:53 . 2008-12-11 17:55 <DIR> d-------- c:\program files\K-Lite Codec Pack
2008-12-11 17:53 . 2004-10-14 08:33 2,024,448 --a------ c:\windows\system32\divx.dll
2008-12-11 17:46 . 2008-12-11 17:46 <DIR> d-------- c:\program files\SLD Codec Pack
2008-12-11 17:36 . 2008-12-11 17:52 <DIR> d-------- c:\program files\Common Files\Real
2008-12-11 17:35 . 2008-12-11 17:51 <DIR> d-------- c:\program files\Real
2008-12-11 17:06 . 2008-12-11 17:06 <DIR> d-------- c:\documents and settings\hamada\Application Data\Apple Computer
2008-12-11 17:04 . 2008-12-11 17:04 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-11 17:04 . 2008-12-11 17:04 1,409 --a------ c:\windows\QTFont.for
2008-12-11 17:00 . 2008-12-11 17:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-11 15:10 . 2008-11-02 10:11 60,273 --a------ c:\windows\system32\pthreadGC2.dll
2008-12-11 00:07 . 2008-12-11 00:07 36 ---h----- c:\windows\system32\swk.ini
2008-12-10 18:09 . 2008-12-10 18:09 189 --a------ c:\windows\GSdx9-sse2.INI
2008-12-08 10:45 . 2008-12-11 15:11 8,275 --a------ c:\windows\system32\drivers\CDSpace5.cfg
2008-12-08 10:43 . 2008-12-08 10:43 <DIR> d-------- c:\program files\SPACE INTERNATIONAL
2008-12-08 10:43 . 2004-09-13 11:59 22,517 --a------ c:\windows\system32\drivers\CDSPACEX.sys
2008-12-08 10:43 . 2003-04-23 15:39 11,120 --a------ c:\windows\system32\drivers\TwoRabts.sys
2008-12-08 10:43 . 2003-05-20 17:26 3,543 --------- c:\windows\system32\drivers\XSpaceWg.sys
2008-12-08 10:42 . 2008-12-11 17:57 <DIR> d-------- c:\program files\Common Files\InstallShield
2008-12-07 21:40 . 2008-12-07 21:40 <DIR> d-------- c:\program files\Vista Sidebar
2008-12-07 00:06 . 2006-10-03 14:37 217,088 --a------ c:\windows\system32\winsys2.exe
2008-12-07 00:06 . 2006-07-21 11:33 128,512 --a------ c:\windows\system32\madCHook.dll
2008-12-06 23:11 . 2008-12-06 23:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2008-12-06 23:09 . 2008-12-06 23:09 <DIR> d-------- c:\documents and settings\hamada\Application Data\DAEMON Tools Pro
2008-12-06 22:19 . 2008-12-06 23:09 717,296 --a------ c:\windows\system32\drivers\sptd.sys
2008-12-06 21:30 . 2008-04-14 00:15 10,368 --a------ c:\windows\system32\drivers\hidusb.sys
2008-12-06 21:30 . 2008-04-14 00:15 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2008-12-06 18:52 . 2008-12-06 18:52 <DIR> d--h----- c:\windows\PIF
2008-12-05 20:57 . 2002-11-14 22:37 22,048 --a------ c:\windows\system32\cocpyinf.dll
2008-12-05 17:20 . 2008-12-08 14:29 <DIR> d-------- c:\program files\Common Files\Adobe
2008-12-05 17:19 . 2008-12-11 17:57 <DIR> d--h----- c:\program files\InstallShield Installation Information
2008-12-05 09:17 . 2008-12-05 09:16 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-01 21:13 . 2008-12-01 21:13 <DIR> d-------- c:\program files\Opera
2008-12-01 13:36 . 2008-12-12 09:27 81,984 --a------ c:\windows\system32\bdod.bin
2008-11-30 20:55 . 2008-12-01 10:01 <DIR> d--h----- c:\windows\Icons
2008-11-30 20:54 . 2008-12-02 10:39 2,328,832 --a------ c:\windows\system32\TUKernel.exe
2008-11-30 20:27 . 2008-11-30 20:28 <DIR> d-------- c:\program files\TuneUp Utilities 2009
2008-11-30 20:27 . 2008-11-30 20:27 <DIR> d-------- c:\documents and settings\hamada\Application Data\TuneUp Software
2008-11-30 20:27 . 2008-11-30 20:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\TuneUp Software
2008-11-30 20:27 . 2008-11-30 20:27 <DIR> d--hs---- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2008-11-30 20:27 . 2008-11-30 20:27 603,904 --a------ c:\windows\system32\TUProgSt.exe
2008-11-30 20:27 . 2008-11-30 20:27 362,240 --a------ c:\windows\system32\TuneUpDefragService.exe
2008-11-30 20:27 . 2008-11-12 16:44 27,904 --a------ c:\windows\system32\uxtuneup.dll
2008-11-30 20:25 . 2008-11-30 20:25 <DIR> d-------- c:\program files\Yahoo!
2008-11-30 20:25 . 2008-11-30 20:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2008-11-30 20:23 . 2008-12-05 09:16 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-11-30 20:22 . 2008-12-05 09:15 <DIR> d-------- c:\program files\Java
2008-11-30 20:22 . 2008-11-30 20:22 <DIR> d-------- c:\program files\Common Files\Java
2008-11-30 20:21 . 2008-12-02 10:41 <DIR> d-------- c:\program files\Unlocker
2008-11-30 20:21 . 2008-11-30 20:21 <DIR> d-------- c:\documents and settings\hamada\Application Data\Desktopicon
2008-11-30 19:52 . 2008-12-12 09:52 121 --a------ c:\windows\bdagent.INI
2008-11-30 19:51 . 2008-11-30 19:51 <DIR> d-------- c:\documents and settings\hamada\Application Data\BitDefender
2008-11-30 19:50 . 2008-11-30 19:50 <DIR> d-------- c:\program files\BitDefender
2008-11-30 19:50 . 2008-11-30 20:10 <DIR> d-------- c:\documents and settings\All Users\Application Data\BitDefender
2008-11-30 18:57 . 2008-04-14 00:15 26,368 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-11-30 17:11 . 2008-11-30 19:50 <DIR> d-------- c:\program files\Common Files\BitDefender
2008-11-30 17:09 . 2008-12-04 21:31 <DIR> d-------- c:\program files\Internet Download Manager
2008-11-30 17:09 . 2008-12-12 09:26 <DIR> d-------- c:\documents and settings\hamada\Application Data\IDM
2008-11-30 17:09 . 2008-12-12 09:52 <DIR> d-------- c:\documents and settings\hamada\Application Data\DMCache
2008-11-30 17:05 . 2008-11-30 17:05 <DIR> d-------- c:\program files\AIMP2
2008-11-30 17:04 . 2008-11-30 17:05 <DIR> d-------- c:\documents and settings\hamada\Application Data\Media Player Classic
2008-11-30 17:04 . 2003-06-23 02:44 1,415,680 --a------ c:\windows\system32\WMV9VCM.dll
2008-11-30 17:04 . 2004-07-29 02:23 401,408 --a------ c:\windows\system32\lameACM.acm
2008-11-30 17:04 . 2003-04-21 15:09 245,408 --a------ c:\windows\system32\unicows.dll
2008-11-30 17:04 . 2004-01-22 19:06 157,696 --a------ c:\windows\system32\unrar.dll
2008-11-30 17:04 . 2001-09-17 13:20 19,968 --a------ c:\windows\system32\cpuinf32.dll
2008-11-30 17:00 . 2008-11-30 17:00 <DIR> d-------- c:\program files\Ashampoo
2008-11-30 17:00 . 2008-11-30 17:00 <DIR> d-------- c:\documents and settings\hamada\Application Data\SoftMaker
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-11 15:55 98,304 ----a-w c:\windows\system32\qttask.exe
2008-12-01 08:01 86,792 ----a-w c:\windows\system32\drivers\bdfndisf.sys
2008-11-30 11:59 --------- d-----w c:\program files\microsoft frontpage
2008-11-30 11:57 --------- d-----w c:\program files\Windows Media Connect 2
2008-11-30 11:56 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-16 12:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 12:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 12:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 12:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 12:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 12:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 12:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 12:08 34,328 ----a-w c:\windows\system32\wups.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"TuneUp MemOptimizer"="c:\program files\TuneUp Utilities 2009\MemOptimizer.exe" [2008-11-20 155904]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-02-07 935344]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-07 4670968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2008-12-01 368640]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-05 136600]
"WinSys2"="c:\windows\system32\winsys2.exe" [2006-10-03 217088]
"QuickTime Task"="c:\windows\system32\qttask.exe" [2008-12-11 98304]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-10 c:\windows\RTHDCPL.EXE]
c:\documents and settings\hamada\Start Menu\Programs\Startup\
Rainmeter.lnk - c:\program files\Vista Sidebar\Rainmeter.exe [2008-12-07 118784]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-08 113664]
LCDPlayer.lnk - c:\program files\SPACE INTERNATIONAL\CDSpace 5\LCDPlyer.exe [2008-12-08 323584]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.3iv2"= 3ivxVfWCodec.dll
"VIDC.HFYU"= huffyuv.dll
"VIDC.VP31"= vp31vfw.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"IDMan"=c:\program files\Internet Download Manager\IDMan.exe /onboot
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
R1 XSPACEWG;XSPACEWG;\??\c:\windows\system32\drivers\XSpaceWg.sys [2008-12-08 3543]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2008-11-30 603904]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\bdfndisf.sys [2008-01-25 86792]
R3 cdspacex;cdspacex;c:\windows\system32\DRIVERS\CDSPACEX.sys [2008-12-08 22517]
R3 TwoRabts;Two Rabbits Live Bus;c:\windows\system32\DRIVERS\TwoRabts.sys [2008-12-08 11120]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{af85820e-c51d-11dd-874d-0019db865b51}]
\shELl\AutopLaY\commAnd - I:\fxcb.pif
\shELl\AutoRun\command - I:\fxcb.pif
\shELl\EXPlore\CommAnD - I:\fxcb.pif
\shELl\oPEn\CommaNd - I:\fxcb.pif
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-12-12 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 16:28]
.
.
------- Supplementary Scan -------
.
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
TCP: {A801F120-C27B-4618-80BD-F2CEF5E72ADB} = 163.121.128.134,163.121.128.135
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-12 09:52:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-12-12 9:54:03
ComboFix-quarantined-files.txt 2008-12-12 07:53:23
Pre-Run: 4,937,117,696 bytes free
Post-Run: 4,941,135,872 bytes free
189