مشكو اخى على تفاعلك الشديد مع هذة المشكلة وهذا هو التقرير
ComboFix 09-04-01.01 - Administrator 04/02/2009 15:52:18.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.502.272 [GMT 2:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated)
FW: ESET Personal firewall *enabled*
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-03-02 to 2009-04-02 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-02 13:22 --------- d-----w c:\program files\Abyss Web Server
2009-04-02 03:49 --------- d-----w c:\program files\WWW File Share Pro
2009-04-01 23:17 --------- d-----w c:\program files\No-IP
2009-04-01 17:43 --------- d-----w c:\program files\nLite
2009-04-01 17:24 --------- d-----w c:\program files\Windows Unattended CD Creator
2009-04-01 14:51 --------- d-----w c:\program files\SlySoft
2009-04-01 14:05 75,264 ----a-w c:\windows\system32\RestoratorContextMenu.dll
2009-04-01 02:21 --------- d-----w c:\documents and settings\Administrator\Application Data\COWON
2009-04-01 02:18 --------- d-----w c:\program files\Common Files\Ahead
2009-04-01 02:18 --------- d-----w c:\program files\Ahead
2009-04-01 01:54 --------- d--h--w c:\program files\InstallShield Installation Information
2009-04-01 01:54 --------- d-----w c:\program files\JetAudio
2009-04-01 01:54 --------- d-----w c:\program files\Common Files\COWON
2009-04-01 01:53 --------- d-----w c:\program files\Winamp
2009-04-01 01:53 --------- d-----w c:\documents and settings\Administrator\Application Data\Winamp
2009-04-01 01:53 --------- d-----w c:\documents and settings\Administrator\Application Data\InstallShield
2009-04-01 01:52 --------- d-----w c:\program files\X'nBeep 1.1
2009-04-01 01:49 --------- d-----w c:\program files\PowerMenu
2009-04-01 01:46 --------- d-----w c:\documents and settings\Administrator\Application Data\ESET
2009-04-01 01:45 --------- d-----w c:\program files\Internet Download Manager
2009-04-01 01:45 --------- d-----w c:\documents and settings\Administrator\Application Data\IDM
2009-04-01 01:45 --------- d-----w c:\documents and settings\Administrator\Application Data\DMCache
2009-04-01 01:44 --------- d-----w c:\program files\ESET
2009-04-01 01:44 --------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-04-01 01:40 --------- d-----w c:\documents and settings\Administrator\Application Data\Nero
2009-04-01 01:39 --------- d-----w c:\program files\Analog Devices
2009-04-01 01:33 --------- d-----w c:\program files\Yahoo!
2009-04-01 01:33 --------- d-----w c:\program files\Common Files\Nero
2009-04-01 01:33 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2009-04-01 01:31 499,712 ----a-w c:\windows\system32\msvcp71.dll
2009-04-01 01:31 348,160 ----a-w c:\windows\system32\msvcr71.dll
2009-04-01 01:31 --------- d-----w c:\program files\The KMPlayer
2009-04-01 01:31 --------- d-----w c:\program files\Real
2009-04-01 01:31 --------- d-----w c:\program files\flash player
2009-04-01 01:31 --------- d-----w c:\program files\Common Files\xing shared
2009-04-01 01:31 --------- d-----w c:\program files\Common Files\Real
2009-04-01 01:28 --------- d-----w c:\program files\windows otions
2009-04-01 01:27 --------- d-----w c:\program files\SpiritPyre Extensions
2009-02-06 12:24 56,280 ----a-w c:\windows\system32\drivers\epfwtdi.sys
2009-02-06 12:24 33,096 ----a-w c:\windows\system32\drivers\epfwndis.sys
2009-02-06 12:24 130,952 ----a-w c:\windows\system32\drivers\epfw.sys
2009-02-06 12:23 106,208 ----a-w c:\windows\system32\drivers\ehdrv.sys
2009-02-06 12:19 113,448 ----a-w c:\windows\system32\drivers\eamon.sys
2009-01-22 14:49 206,256 ----a-w c:\windows\system32\idmmbc.dll
.
------- Sigcheck -------
07/27/2008 05:06 AM 361344 accf5a9a1ffaa490f33dba1c632b95e1 c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"X'nBeep"="c:\program files\X'nBeep 1.1\XnBeep.exe" [01/08/2007 10:43 PM 1067520]
"AbyssWebServer"="c:\program files\abyss web server\abyssws.exe" [04/02/2009 03:22 PM 533561]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [02/06/2009 02:23 PM 2021400]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [04/14/2008 05:00 PM 169984]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/14/2008 03:00 PM 15360]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
PowerMenu 1.51.lnk - c:\program files\PowerMenu\PowerMenu.exe [4/1/2009 3:49:24 AM 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="CL.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 05/19/2005 03:47 PM 57344 c:\program files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 04/14/2008 03:00 PM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
-ra------ 01/26/2008 02:46 AM 77824 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 01/22/2009 05:16 PM 2745776 c:\program files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
-ra------ 01/26/2008 02:46 AM 94208 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 07/09/2001 11:50 AM 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
-ra------ 01/26/2008 02:46 AM 114688 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
-ra------ 01/26/2008 02:46 AM 1404928 c:\program files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 04/01/2009 03:31 AM 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 03/09/2009 05:49 PM 37888 c:\program files\Winamp\winampa.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2/6/2009 2:23:18 PM 106208]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2/6/2009 2:23:36 PM 727720]
S2 AbyssWebServer;Abyss Web Server;c:\program files\Abyss Web Server\abyssws.exe --service --> c:\program files\Abyss Web Server\abyssws.exe --service [?]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.eg/
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-02 15:53:16
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 04/02/2009 15:53:59
ComboFix-quarantined-files.txt 2009-04-02 13:53:58
Pre-Run: 3,432,849,408 bytes free
Post-Run: 3,583,635,456 bytes free
136