ComboFix 08-12-18.01 - Administrator 12/19/2008 5:39:08.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.503.264 [GMT 3:00]
Running from: c:\documents and settings\Administrator\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-11-19 to 2008-12-19 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-18 22:04 --------- d-----w c:\program files\Yahoo!
2008-12-18 22:04 --------- d-----w c:\program files\MSN Messenger
2008-12-18 22:04 --------- d-----w c:\program files\Messenger Plus! Live
2008-12-18 22:04 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-18 22:04 --------- d-----w c:\documents and settings\Administrator\Application Data\Yahoo!
2008-12-18 22:04 --------- d-----w c:\documents and settings\Administrator\Application Data\Grisoft
2008-12-18 22:04 --------- d-----w c:\documents and settings\Administrator\Application Data\cleaner
2008-12-18 16:52 --------- d-----w c:\documents and settings\Administrator\Application Data\CyberScrub
2008-12-18 10:35 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-12-18 10:29 --------- d-----w c:\program files\Windows Live
2008-12-18 02:47 --------- d-----w c:\program files\Avira
2008-12-18 02:47 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2008-12-18 02:40 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-12-18 02:40 --------- d-----w c:\documents and settings\All Users\Application Data\Avg7
2008-12-18 00:24 --------- d-----w c:\documents and settings\All Users\Application Data\Grisoft
2008-12-15 20:48 --------- d-----w c:\program files\MSN Games
2008-12-13 17:05 104,328 ----a-w c:\windows\system32\drivers\bdfndisf.sys
2008-12-13 15:31 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-13 03:21 --------- d-----w c:\documents and settings\All Users\Application Data\BitDefender
2008-12-13 02:56 --------- d-----w c:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2008-12-12 22:02 --------- d-----w c:\program files\Real
2008-12-12 22:02 --------- d-----w c:\program files\Common Files\Real
2008-12-12 22:02 --------- d-----w c:\program files\aod
2008-12-12 11:31 --------- d-----w c:\documents and settings\Administrator\Application Data\AVGTOOLBAR
2008-12-10 16:57 90,112 ----a-w c:\windows\system32\agsaami.dll
2008-12-10 16:57 610,304 ----a-w c:\windows\system32\agsaamg.dll
2008-12-10 16:57 372,736 ----a-w c:\windows\system32\agsaamc.dll
2008-12-10 16:57 2,535,424 ----a-w c:\windows\system32\agsaamj.dll
2008-12-10 16:57 196,608 ----a-w c:\windows\system32\maag.dll
2008-12-10 16:57 1,986,560 ----a-w c:\windows\system32\akll.dll
2008-12-10 16:57 1,245,184 ----a-w c:\windows\system32\bkll.dll
2008-12-10 16:57 1,212,416 ----a-w c:\windows\system32\ckll.dll
2008-12-10 16:57 --------- d-----w c:\program files\Real_SC
2008-12-10 16:18 --------- d-----w c:\program files\Ahead
2008-12-10 16:18 --------- d-----w c:\documents and settings\All Users\Application Data\Ahead
2008-12-10 16:15 --------- d-----w c:\program files\Common Files\Nero
2008-12-10 16:14 --------- d-----w c:\program files\Common Files\Ahead
2008-12-10 14:51 --------- d-----w c:\program files\Hotspot Shield
2008-12-10 14:47 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-10 14:45 --------- d-----w c:\program files\MSBuild
2008-12-10 14:45 --------- d-----w c:\program files\Microsoft Works
2008-12-10 02:14 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-10 01:21 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-12-10 01:21 --------- d-----w c:\program files\Java
2008-12-10 00:51 --------- d-----w c:\program files\Alawar
2008-12-10 00:45 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-12-10 00:43 73,216 ----a-w c:\windows\ST6UNST.EXE
2008-12-10 00:43 172,032 ------w c:\windows\Setup1.exe
2008-12-10 00:43 --------- d-----w c:\program files\Golden Al-Wafi Translator
2008-12-10 00:11 --------- d-----w c:\program files\Circle Developement
2008-12-09 20:11 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-09 20:11 --------- d-----w c:\program files\Realtek Sound Manager
2008-12-09 20:11 --------- d-----w c:\program files\AvRack
2008-12-09 20:02 --------- d-----w c:\program files\Intel
2008-12-09 19:52 --------- d-----w c:\program files\microsoft frontpage
2008-10-16 20:04 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 11:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 11:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 11:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 11:12 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 11:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 11:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 11:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 11:08 34,328 ----a-w c:\windows\system32\wups.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [01/19/2007 12:55 PM 5674352]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [08/04/2004 01:09 AM 1667584]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe" [11/05/2008 09:59 PM 4347120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [03/11/2003 05:24 AM 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [03/11/2003 05:11 AM 114688]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [12/10/2008 04:21 AM 136600]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM 31016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [07/09/2001 11:50 AM 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\evntsvc.exe" [12/13/2008 01:02 AM 146432]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [06/12/2008 01:28 PM 266497]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" [11/03/2007 04:50 AM 6731312]
"SoundMan"="SOUNDMAN.EXE" [08/15/2003 10:34 AM 57344 c:\windows\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--------- 01/27/2005 08:17 PM 1381376 c:\program files\Ahead\InCD\InCD.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
S2 BDVEDISK;BDVEDISK;\??\c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys []
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-19 05:40:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 12/19/2008 5:41:59
ComboFix-quarantined-files.txt 2008-12-19 02:41:27
ComboFix2.txt 2008-12-19 02:34:51
Pre-Run: 16,168,038,400 bytes free
Post-Run: 16,165,474,304 bytes free
139
هذا هو التقرير ارجوا افادة من هذا التقرير
وشكرا لك