هذا هو التقري
وآسف على التأخير
ComboFix 08-12-17.01 - Abu Bader 12/18/2008 6:04:42.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1256.1.1033.18.1279.877 [GMT -8:00]
Running from: c:\documents and settings\Abu Bader\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\awtrSkKa.dll
c:\windows\system32\dratwdhp.ini
c:\windows\system32\ijbgrgoc.ini
c:\windows\system32\odporwrt.ini
c:\windows\system32\phdwtard.dll
c:\windows\system32\pvodkoxp.ini
c:\windows\system32\rbfjdl.dll
c:\windows\system32\SBLloUtv.ini
c:\windows\system32\SBLloUtv.ini2
c:\windows\system32\soeohlig.ini
c:\windows\system32\taylbrwv.dll
c:\windows\system32\vtUolLBS.dll
c:\windows\system32\vwrblyat.ini
c:\windows\wiaserviv.log
.
((((((((((((((((((((((((( Files Created from 2008-11-18 to 2008-12-18 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-18 12:38 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-18 12:38 --------- d-----w c:\documents and settings\Abu Bader\Application Data\Malwarebytes
2008-12-18 12:37 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-18 12:17 --------- d-----w c:\documents and settings\Abu Bader\Application Data\CyberScrub
2008-12-18 12:16 --------- d-----w c:\documents and settings\Abu Bader\Application Data\cleaner
2008-12-18 10:21 --------- d-----w c:\program files\TechSmith
2008-12-18 10:21 --------- d-----w c:\documents and settings\All Users\Application Data\TechSmith
2008-12-18 10:15 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-17 13:54 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-16 10:14 --------- d-----w c:\program files\Moyea
2008-12-16 10:06 --------- d-----w c:\documents and settings\Abu Bader\Application Data\Moyea
2008-12-15 07:12 --------- d-----w c:\documents and settings\Abu Bader\Application Data\Media Player Classic
2008-12-15 06:40 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-12-15 06:17 --------- d-----w c:\documents and settings\Abu Bader\Application Data\Avant Profiles
2008-12-15 05:53 --------- d-----w c:\program files\K-Lite Codec Pack
2008-12-15 05:53 --------- d-----w c:\program files\Common Files\Real
2008-12-15 03:34 --------- d-----w c:\program files\Windows Live
2008-12-15 03:34 --------- d-----w c:\program files\MSN Messenger
2008-12-15 03:34 --------- d-----w c:\program files\Messenger Plus! Live
2008-12-14 07:31 --------- d-----w c:\program files\Hotspot Shield
2008-12-14 06:08 --------- d-----w c:\program files\Avira
2008-12-14 06:08 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2008-12-14 05:51 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-14 05:46 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-12-14 05:42 --------- d-----w c:\program files\Common Files\AOL
2008-12-14 05:42 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2008-12-14 05:36 --------- d-----w c:\program files\Your Uninstaller 2008
2008-12-14 05:36 --------- d-----w c:\documents and settings\Abu Bader\Application Data\URSoft
2008-12-14 05:21 14,037 ----a-w c:\windows\system32\drivers\mdc8021x.sys
2008-12-14 05:21 --------- d-----w c:\program files\Intel
2008-12-04 03:53 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-04 03:53 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [01/19/2007 12:55 PM 5674352]
"ctfmon.exe"="c:\windows\System32\ctfmon.exe" [03/31/2003 04:00 AM 13312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"="c:\windows\System32\
00THotkey.exe" [04/15/2003 08:01 PM 258048]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [06/12/2008 02:28 PM 266497]
"ezShieldProtector for Px"="c:\windows\System32\ezSP_Px.exe" [08/20/2002 10:29 AM 40960]
"000StTHK"="000StTHK.exe" [06/23/2001 08:28 PM 24576 c:\windows\system32\
000StTHK.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
SnagIt 9.lnk - c:\program files\TechSmith\SnagIt 9\SnagIt32.exe [2008-05-15 6822728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
12/16/2003 04:49 PM 110592 c:\windows\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=rbfjdl.dll
R0 avgntmgr;avgntmgr;c:\windows\System32\DRIVERS\avgntmgr.sys [2008-12-13 22336]
R0 BsStor;B.H.A Storage Helper Driver;c:\windows\System32\drivers\BsStor.sys [2004-02-06 10112]
R1 avgntdd;avgntdd;c:\windows\System32\DRIVERS\avgntdd.sys [2008-12-13 45376]
S2 mrtRate;mrtRate; []
.
- - - - ORPHANS REMOVED - - - -
BHO-{77AB59B4-55A3-4737-9FD5-B93C6430BF78} - c:\windows\System32\npupoygu.dll
BHO-{B4BCFA4A-F7B2-4DC9-8244-E5BCECADFBBA} - c:\windows\System32\vtUolLBS.dll
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearch Bar = hxxp://www.toshiba.com/search
mDefault_Page_URL = hxxp://www.toshiba.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm -
FF - ProfilePath - c:\documents and settings\Abu Bader\Application Data\Mozilla\Firefox\Profiles\cisi9gnl.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sa
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
ATTENTION: FIREFOX POLICES IS IN FORCE
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.rights.version", 3);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.rights.3.shown", false);
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-18 06:31:04
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(884)
c:\windows\System32\ODBC32.dll
c:\windows\System32\LgNotify.dll
- - - - - - - > 'lsass.exe'(940)
c:\windows\System32\dssenh.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\S24EvMon.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\windows\system32\ZCfgSvc.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\RegSrvc.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\windows\system32\1XConfig.exe
c:\program files\TechSmith\SnagIt 9\TscHelp.exe
c:\program files\TechSmith\SnagIt 9\SnagItEditor.exe
.
**************************************************************************
.
Completion time: 12/18/2008 6:36:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-18 14:36:11
Pre-Run: 26,747,637,760 bytes free
Post-Run: 26,682,085,376 bytes free
147