جزاك الله خيرا لأهتمامك يا أخي
وهذا هو أول تقرير:
ComboFix 08-12-16.03 - wael 12/17/2008 8:58:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.758.485 [GMT 2:00]
Running from: c:\documents and settings\wael\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\Cache\
00059ED7
c:\program files\MyWebSearch\bar\Cache\
0005B7DE.bin
c:\program files\MyWebSearch\bar\Cache\
0005BACC.bin
c:\program files\MyWebSearch\bar\Cache\
0005BCDF.bin
c:\program files\MyWebSearch\bar\Cache\
0005BF21.bin
c:\program files\MyWebSearch\bar\Cache\
00F2E40D
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\windows\system32\OGACheckControl.dll
.
((((((((((((((((((((((((( Files Created from 2008-11-17 to 2008-12-17 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-16 13:40 720,896 ----a-w c:\windows\iun6002ev.exe
2008-12-16 05:23 --------- d-----w c:\program files\Sony Setup
2008-12-11 20:02 --------- d-----w c:\documents and settings\All Users\Application Data\Trymedia
2008-12-11 20:01 --------- d-----w c:\program files\Disney
2008-12-07 14:25 --------- d-----w c:\program files\Golden Al-Wafi Translator
2008-11-26 06:19 --------- d-----w c:\program files\Yahoo!
2008-11-26 06:08 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-11-23 11:10 --------- d-----w c:\documents and settings\wael\Application Data\Yahoo!
2008-11-16 09:33 --------- d-----w c:\program files\TuneUp Utilities 2007
2008-11-15 09:13 --------- d-----w c:\documents and settings\wael\Application Data\TeamViewer
2008-11-13 09:52 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-11-09 18:37 --------- d-----w c:\program files\MSXML 4.0
2008-11-09 10:24 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys
2008-11-09 06:27 73,216 ----a-w c:\windows\ST6UNST.EXE
2008-11-09 06:27 172,032 ------w c:\windows\Setup1.exe
2008-11-09 06:17 --------- d-----w c:\documents and settings\wael\Application Data\Sonic Foundry
2008-11-09 06:10 --------- d-----w c:\documents and settings\wael\Application Data\Sony
2008-11-09 05:54 --------- d-----w c:\documents and settings\wael\Application Data\Sony Setup
2008-11-09 05:48 --------- d-----w c:\documents and settings\wael\Application Data\TuneUp Software
2008-11-09 05:46 --------- d-----w c:\documents and settings\All Users\Application Data\TuneUp Software
2008-11-09 05:45 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-08 19:47 --------- d-----w c:\program files\Windows Live
2008-11-08 19:47 --------- d-----w c:\program files\Microsoft
2008-11-08 19:44 --------- d-----w c:\program files\Common Files\Windows Live
2008-11-08 19:00 --------- d-----w c:\program files\Winamp
2008-11-08 18:37 --------- d-----w c:\documents and settings\wael\Application Data\Teleca
2008-11-08 18:34 --------- d-----w c:\program files\Common Files\Teleca Shared
2008-11-08 18:34 --------- d-----w c:\documents and settings\All Users\Application Data\Teleca
2008-11-08 18:34 --------- d-----w c:\documents and settings\All Users\Application Data\Sony Ericsson
2008-11-08 18:33 --------- d-----w c:\program files\Sony Ericsson
2008-11-08 18:28 94,064 ----a-w c:\windows\system32\drivers\k510mdm.sys
2008-11-08 18:28 85,408 ----a-w c:\windows\system32\drivers\k510mgmt.sys
2008-11-08 18:28 83,344 ----a-w c:\windows\system32\drivers\k510obex.sys
2008-11-08 18:28 8,336 ----a-w c:\windows\system32\drivers\k510mdfl.sys
2008-11-08 18:28 6,176 ----a-w c:\windows\system32\drivers\k510cmnt.sys
2008-11-08 18:28 6,176 ----a-w c:\windows\system32\drivers\k510cm.sys
2008-11-08 18:28 58,288 ----a-w c:\windows\system32\drivers\k510bus.sys
2008-11-08 18:28 5,808 ----a-w c:\windows\system32\drivers\k510whnt.sys
2008-11-08 18:28 5,808 ----a-w c:\windows\system32\drivers\k510wh.sys
2008-11-08 18:27 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-08 17:02 --------- d-----w c:\documents and settings\wael\Application Data\Ahead
2008-11-08 16:43 --------- d-----w c:\program files\Common Files\Adobe
2008-11-08 16:40 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-08 16:04 --------- d-----w c:\program files\AVG
2008-11-08 16:04 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-11-08 16:02 --------- d-----w c:\program files\Google
2008-11-08 15:59 --------- d-----w c:\documents and settings\All Users\Application Data\Ahead
2008-11-08 15:58 --------- d-----w c:\program files\Common Files\Ahead
2008-11-08 15:56 --------- d-----w c:\program files\Nero
2008-11-08 15:56 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2008-11-08 15:48 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-08 15:46 --------- d-----w c:\program files\Microsoft Works
2008-11-08 15:45 --------- d-----w c:\program files\MSBuild
2008-11-08 15:41 --------- d-----w c:\documents and settings\wael\Application Data\Media Player Classic
2008-11-08 15:40 --------- d-----w c:\program files\K-Lite Codec Pack
2008-11-08 15:40 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-08 15:32 --------- d-----w c:\program files\Realtek AC97
2008-11-08 15:31 --------- d-----w c:\program files\Intel
2008-11-08 15:24 --------- d-----w c:\program files\microsoft frontpage
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2005-03-11 15:28 20,640 ----a-w c:\windows\inf\pxhelp20.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [04/14/2008 05:42 AM 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [11/19/2008 02:41 PM 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [11/27/2008 10:45 AM 1261336]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [04/14/2008 05:42 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.3iv2"= c:\progra~1\K-LITE~1\codecs\3IVXVF~1.DLL
"VIDC.VP60"= c:\progra~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP61"= c:\progra~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP62"= c:\progra~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP70"= c:\progra~1\K-LITE~1\codecs\vp7vfw.dll
"VIDC.VP31"= c:\progra~1\K-LITE~1\codecs\vp31vfw.dll
"VIDC.FFDS"= c:\progra~1\K-LITE~1\ffdshow\ff_vfw.dll
"msacm.ac3acm"= c:\progra~1\K-LITE~1\codecs\ac3acm.acm
"msacm.l3fhg"= c:\progra~1\K-LITE~1\codecs\l3codecp.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^wael^Start Menu^Programs^Startup^WinampAgent.lnk]
path=c:\documents and settings\wael\Start Menu\Programs\Startup\WinampAgent.lnk
backup=c:\windows\pss\WinampAgent.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 06/01/2007 10:21 AM 153136 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 04/14/2008 05:42 AM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 10/27/2006 12:47 AM 31016 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
-ra------ 08/23/2005 06:00 PM 77824 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
-ra------ 08/23/2005 06:00 PM 114688 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
-ra------ 08/23/2005 06:00 PM 94208 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 04/14/2008 05:42 AM 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 09/09/2008 12:02 AM 3513344 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 03/01/2007 03:57 PM 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 10/26/2005 04:17 PM 159744 c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 11/19/2008 02:41 PM 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-r------- 03/01/2006 10:22 AM 577536 c:\windows\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-08 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-08 231704]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\DRIVERS\k510bus.sys [2008-11-08 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\DRIVERS\k510mdfl.sys [2008-11-08 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\DRIVERS\k510mdm.sys [2008-11-08 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\k510mgmt.sys [2008-11-08 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\k510obex.sys [2008-11-08 83344]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
s of the 'Scheduled Tasks' folder
2008-11-28 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [04/26/2007 09:51 PM]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
IE: &Search -
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-17 09:02:37
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\wdfmgr.exe
c:\program files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 12/17/2008 9:05:23 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-17 07:05:19
Pre-Run: 9,789,730,816 bytes free
Post-Run: 9,751,220,224 bytes free
196 --- E O F --- 2008-12-16 14:26:26