هذا التقرير بارك الله فيك
ComboFix 08-12-12.05
[FONT=Courier New (Arabic)] - ابو ابراهيم 12/13/2008 23:03:13.1 - [/FONT]NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.502.310 [GMT 3:00[FONT=Courier New (Arabic)]]
[/FONT]
Running from: c:\documents and settings
[FONT=Courier New (Arabic)]\ابو ابراهيم\[/FONT]My Documents\Downloads\Programs\ComboFix.exe
[FONT=Courier New (Arabic)]
[
[/FONT]COLOR=RED]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/COLOR[FONT=Courier New (Arabic)]]
.
((((((((((((((((((((((((((((((((((((((( [/FONT]Other Deletions[FONT=Courier New (Arabic)] )))))))))))))))))))))))))))))))))))))))))))))))))
.
[/FONT]
d:\recycler\Lock Folder.exe
d:\recycler\RECYCLER .exe
D:\zPharaoh.exe
[FONT=Courier New (Arabic)]
.
----
[/FONT]Previous Run[FONT=Courier New (Arabic)] -------
.
[/FONT]
C:\autorun.inf
c:\documents and settings
[FONT=Courier New (Arabic)]\ابو ابراهيم\[/FONT]Application Data\tazebama
c:\documents and settings[FONT=Courier New (Arabic)]\ابو ابراهيم\[/FONT]Application Data\tazebama\tazebama.log
c:\documents and settings[FONT=Courier New (Arabic)]\ابو ابراهيم\[/FONT]Application Data\tazebama\zPharaoh.dat
c:\windows\system32\BASSMOD.dll
C:\zPharaoh.exe
D:\Autorun.inf
d:\recycler\RECYCLER .exe
d:\recycler\WinrRarSerialInstall.exe
D:\zPharaoh.exe
[FONT=Courier New (Arabic)]
-----
[/FONT]File Replicators[FONT=Courier New (Arabic)] -----
[/FONT]
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP6\A0000191.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP6\A0000214.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP6\A0000222.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP6\A0000247.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP6\A0000272.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP6\A0000301.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP6\A0000302.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP6\A0000303.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP6\A0000397.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP6\A0000411.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP6\A0000434.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP6\A0000447.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP6\A0000448.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP6\A0000449.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP7\A0000549.exe
c:\system volume information\_restore{D5A7FC6F-1BC1-4B24-A4C5-A545A058AB51}\RP7\A0000581.exe
c:\windows\NOTEPAD.EXE
c:\windows\system32\dllcache\notepad.exe
c:\windows\system32\notepad.exe
[FONT=Courier New (Arabic)]
.
.
(((((((((((((((((((((((((((((((((((((((
[/FONT]Drivers/Services[FONT=Courier New (Arabic)] )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\[/FONT]Legacy_ASC3360PR
[FONT=Courier New (Arabic)]
-------\
[/FONT]Service_asc3360pr
[FONT=Courier New (Arabic)]
-------\
[/FONT]Legacy_ASC3360PR
[FONT=Courier New (Arabic)]
-------\
[/FONT]Service_asc3360pr
[FONT=Courier New (Arabic)]
(((((((((((((((((((((((((
[/FONT]Files Created from 2008-11-13 to 2008-12-13[FONT=Courier New (Arabic)] )))))))))))))))))))))))))))))))
.
[/FONT]
No new files created in this timespan
[FONT=Courier New (Arabic)]
.
((((((((((((((((((((((((((((((((((((((((
[/FONT]Find3M Report[FONT=Courier New (Arabic)] ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-13 20:02 --------- [/FONT]d-----w[FONT=Courier New (Arabic)] [/FONT]c:\documents and settings[FONT=Courier New (Arabic)]\ابو ابراهيم\[/FONT]Application Data\DMCache
[FONT=Courier New (Arabic)]
2008-12-13 17:23 ---------
[/FONT]d-----w[FONT=Courier New (Arabic)] [/FONT]c:\documents and settings[FONT=Courier New (Arabic)]\ابو ابراهيم\[/FONT]Application Data\IDM
[FONT=Courier New (Arabic)]
2008-12-13 17:07 ---------
[/FONT]d-----w[FONT=Courier New (Arabic)] [/FONT]c:\program files\Real
[FONT=Courier New (Arabic)]
2008-12-13 17:07 ---------
[/FONT]d-----w[FONT=Courier New (Arabic)] [/FONT]c:\program files\Common Files\xing shared
[FONT=Courier New (Arabic)]
2008-12-13 17:07 ---------
[/FONT]d-----w[FONT=Courier New (Arabic)] [/FONT]c:\program files\Common Files\Real
[FONT=Courier New (Arabic)]
2008-12-13 16:11 ---------
[/FONT]d-----w[FONT=Courier New (Arabic)] [/FONT]c:\program files\Internet Download Manager
[FONT=Courier New (Arabic)]
2008-12-13 15:03 ---------
[/FONT]d-----w[FONT=Courier New (Arabic)] [/FONT]c:\program files\Alcohol Soft
[FONT=Courier New (Arabic)]
2008-12-13 14:54 ---------
[/FONT]d--h--w[FONT=Courier New (Arabic)] [/FONT]c:\program files\InstallShield Installation Information
[FONT=Courier New (Arabic)]
2008-12-13 14:54 ---------
[/FONT]d-----w[FONT=Courier New (Arabic)] [/FONT]c:\program files\Rockstar Games
[FONT=Courier New (Arabic)]
2008-12-13 14:31 ---------
[/FONT]d-----w[FONT=Courier New (Arabic)] [/FONT]c:\program files\Microsoft.NET
[FONT=Courier New (Arabic)]
2008-12-13 14:25 ---------
[/FONT]d-----w[FONT=Courier New (Arabic)] [/FONT]c:\program files\Common Files\InstallShield
[FONT=Courier New (Arabic)]
2008-12-13 14:23 ---------
[/FONT]d-----w[FONT=Courier New (Arabic)] [/FONT]c:\program files\Realtek Sound Manager
[FONT=Courier New (Arabic)]
2008-12-13 14:23 ---------
[/FONT]d-----w[FONT=Courier New (Arabic)] [/FONT]c:\program files\AvRack
[FONT=Courier New (Arabic)]
2008-12-13 14:17 ---------
[/FONT]d-----w[FONT=Courier New (Arabic)] [/FONT]c:\program files\microsoft frontpage
[FONT=Courier New (Arabic)]
.
(((((((((((((((((((((((((((((((((((((
[/FONT]Reg Loading Points[FONT=Courier New (Arabic)] ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*[/FONT]Note* empty entries & legit default entries are not shown[FONT=Courier New (Arabic)]
[/FONT]
REGEDIT4
[FONT=Courier New (Arabic)]
[
[/FONT]HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run[FONT=Courier New (Arabic)]]
"[/FONT]CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360[FONT=Courier New (Arabic)]]
"[/FONT]IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [12/13/2008 07:11 PM 2815408[FONT=Courier New (Arabic)]]
[[/FONT]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run[FONT=Courier New (Arabic)]]
"[/FONT]NvCplDaemon"="c:\windows\system32\NvCpl.dll" [06/28/2007 07:43 PM 8466432[FONT=Courier New (Arabic)]]
"[/FONT]NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [06/28/2007 07:43 PM 81920[FONT=Courier New (Arabic)]]
"[/FONT]TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [12/13/2008 08:07 PM 185872[FONT=Courier New (Arabic)]]
"[/FONT]SoundMan"="SOUNDMAN.EXE" [11/14/2007 04:37 AM 137216 c:\windows\SOUNDMAN.EXE[FONT=Courier New (Arabic)]]
"[/FONT]nwiz"="nwiz.exe" [06/28/2007 07:43 PM 1703936 c:\windows\system32\nwiz.exe[FONT=Courier New (Arabic)]]
[[/FONT]HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run[FONT=Courier New (Arabic)]]
"[/FONT]CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360[FONT=Courier New (Arabic)]]
[[/FONT]HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system[FONT=Courier New (Arabic)]]
"[/FONT]EnableLUA"= 0 (0x0[FONT=Courier New (Arabic)])
[[/FONT]HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List[FONT=Courier New (Arabic)]]
"%[/FONT]windir%\\system32\\sessmgr.exe[FONT=Courier New (Arabic)]"=
"[/FONT]d[FONT=Courier New (Arabic)]:\\العاب [/FONT]PC\\Live For Speed\\LFS.exe[FONT=Courier New (Arabic)]"=
"[/FONT]c:\\Documents and Settings[FONT=Courier New (Arabic)]\\ابو ابراهيم\\[/FONT]My Documents\\Downloads\\Programs\\ComboFix.exe[FONT=Courier New (Arabic)]"=
"[/FONT]c:\\WINDOWS\\SOUNDMAN.EXE[FONT=Courier New (Arabic)]"=
"[/FONT]c:\\WINDOWS\\system32\\wscntfy.exe[FONT=Courier New (Arabic)]"=
*[/FONT]Newly Created Service* - ASC3360PR
[FONT=Courier New (Arabic)]
.
.
-------
[/FONT]Supplementary Scan[FONT=Courier New (Arabic)] -------
.
[/FONT]
uStart Page = hxxp://www.google.com.sa
[FONT=Courier New (Arabic)]/
[/FONT]
IE
[FONT=Courier New (Arabic)]: &تصدير إلى [/FONT]Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE[FONT=Courier New (Arabic)]: تحميل الكل بواسطة [/FONT]Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE[FONT=Courier New (Arabic)]: تحميل بواسطة [/FONT]Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE[FONT=Courier New (Arabic)]: تحميل محتوى [/FONT]FLV[FONT=Courier New (Arabic)] بواسطة [/FONT]Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
FF - ProfilePath - c:\documents and settings[FONT=Courier New (Arabic)]\ابو ابراهيم\[/FONT]Application Data\Mozilla\Firefox\Profiles\gtrvgtop.default[FONT=Courier New (Arabic)]\
.
**************************************************************************
[/FONT]
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-13 23:05:25
Windows 5.1.2600 Service Pack 2 NTFS
[FONT=Courier New (Arabic)]
[/FONT]
scanning hidden processes
[FONT=Courier New (Arabic)] ...
[/FONT]
scanning hidden autostart entries
[FONT=Courier New (Arabic)] ...
[/FONT]
scanning hidden files
[FONT=Courier New (Arabic)] ...
[/FONT]
c:\windows\system32\drivers\mhkmnd.sys
[FONT=Courier New (Arabic)]
[/FONT]
scan completed successfully
hidden files: 1
[FONT=Courier New (Arabic)]
**************************************************************************
.
------------------------
[/FONT]Other Running Processes[FONT=Courier New (Arabic)] ------------------------
.
[/FONT]
c:\windows\system32\nvsvc32.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\Internet Download Manager\IEMonitor.exe
[FONT=Courier New (Arabic)]
.
**************************************************************************
.
[/FONT]
Completion time: 12/13/2008 23:07:24 - machine was rebooted
[FONT=Courier New (Arabic)] [ابو ابراهيم]
[/FONT]
ComboFix-quarantined-files.txt 2008-12-13 20:07:22
[FONT=Courier New (Arabic)]
[/FONT]
Pre-Run: 33,291,157,504 bytes free
Post-Run: 33,232,728,064 bytes free
[FONT=Courier New (Arabic)]
134 ---
[/FONT]E O F ---[FONT=Courier New (Arabic)] 2008-12-13 15:09:53
[/FONT]