ترى مااعاد تشغيل الجهاز يوم سويت الفح صالاخير
ComboFix 09-04-04.01 - sara 2009-04-11 17:28:26.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.502.105 [GMT 3:00]
Running from: c:\documents and settings\sara\Desktop\قرآشيع سطح المكتب\زيزوم\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\windows\IE4 Error Log.txt
c:\windows\system32\drivers\str.sys
c:\windows\system32\kakle.dll
c:\windows\wiaserviv.log
.
((((((((((((((((((((((((( Files Created from 2009-03-11 to 2009-04-11 )))))))))))))))))))))))))))))))
.
2009-04-11 15:31 . 2009-04-11 15:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\WinZip
2009-04-08 16:33 . 2009-04-09 11:08 54,156 --ah----- c:\windows\QTFont.qfn
2009-04-08 16:33 . 2009-04-08 16:33 1,409 --a------ c:\windows\QTFont.for
2009-04-07 15:54 . 2009-04-07 15:54 7,168 --ahs---- c:\windows\Thumbs.db
2009-03-29 17:32 . 2009-03-29 17:32 6,912,054 --a------ c:\windows\startup.bmp
2009-03-29 17:32 . 2004-08-03 19:56 218,624 --a------ c:\windows\system32\uxtheme.backup
2009-03-29 17:25 . 2009-03-29 17:32 <DIR> d-------- c:\windows\VistaMizer
2009-03-27 22:08 . 2009-03-27 22:09 <DIR> d-------- c:\program files\ScrollBar
2009-03-27 22:08 . 2009-03-27 22:08 <DIR> d-------- c:\documents and settings\sara\Application Data\Sam Francke
2009-03-26 23:45 . 2005-09-16 14:57 94,208 --a------ c:\windows\system32\TCtrlCommon.dll
2009-03-26 23:45 . 2005-09-16 14:57 73,728 --a------ c:\windows\system32\TDispVol.exe
2009-03-26 23:45 . 2002-03-03 04:40 45,056 --a------ c:\windows\system32\TDispVol.dll
2009-03-24 16:16 . 2009-03-24 16:16 552 --a------ c:\windows\system32\d3d8caps.dat
2009-03-19 17:01 . 2009-03-22 11:06 7,168 --a------ c:\windows\hello.exe
2009-03-11 20:48 . 2009-03-16 20:00 <DIR> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-03-11 06:09 . 2009-03-11 06:09 268 --ah----- C:\sqmdata01.sqm
2009-03-11 06:09 . 2009-03-11 06:09 244 --ah----- C:\sqmnoopt01.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
------- Sigcheck -------
2004-08-03 19:56 801280 8c27c9aea4f6e83675801f18697e753d c:\windows\system32\wininet.dll
2004-08-03 19:56 801280 8c27c9aea4f6e83675801f18697e753d c:\windows\system32\dllcache\wininet.dll
2004-08-03 19:56 656384 c0823fc5469663ba63e7db88f9919d70 c:\windows\VistaMizer\old\wininet.dll
2004-08-03 19:56 541696 55aca85eb80e2155e20211aaaddd711a c:\windows\system32\winlogon.exe
2004-08-03 19:56 541696 55aca85eb80e2155e20211aaaddd711a c:\windows\system32\dllcache\winlogon.exe
2004-08-03 19:56 502272 01c3346c241652f43aed8e2149881bfe c:\windows\VistaMizer\old\winlogon.exe
2004-08-03 20:05 2272256 002e42dc877017a8357ad28953cf4340 c:\windows\system32\ntkrnlpa.exe
2004-08-03 20:05 2015232 fb142b7007ca2eea76966c6c5cc12150 c:\windows\VistaMizer\old\ntkrnlpa.exe
2004-08-03 18:18 2405376 7e51de9afbc06bae346235bfd6f63a00 c:\windows\system32\ntoskrnl.exe
2004-08-03 18:18 2148352 626309040459c3915997ef98ec1c8d40 c:\windows\VistaMizer\old\ntoskrnl.exe
2004-08-03 19:56 1550336 49290030ce8bb6a2c5af4339b122261f c:\windows\explorer.exe
2004-08-03 19:56 1550336 49290030ce8bb6a2c5af4339b122261f c:\windows\system32\dllcache\explorer.exe
2004-08-03 19:56 1032192 a0732187050030ae399b241436565e64 c:\windows\VistaMizer\old\explorer.exe
2004-08-03 19:56 25088 5f1724d0e11eb88c95a3b73a6dd72779 c:\windows\system32\ctfmon.exe
2004-08-03 19:56 25088 5f1724d0e11eb88c95a3b73a6dd72779 c:\windows\system32\dllcache\ctfmon.exe
2004-08-03 19:56 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\VistaMizer\old\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-13 5793816]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 25088]
"DriverCure"="c:\program files\ParetoLogic\DriverCure\DriverCure.exe" [2009-01-21 2974800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2006-02-02 73728]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-02-13 290845]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-02-11 473232]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-28 198160]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-30 c:\windows\RTHDCPL.EXE]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" [2005-09-16 c:\windows\system32\TDispVol.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-12-20 2752512]
SnagIt 8.lnk - c:\program files\TechSmith\SnagIt 8\SnagIt32.exe [2006-11-30 6444616]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Documents and Settings\\sara\\Desktop\\برآمج وتعاريف\\BlueSoleil 6.4.240.2_Crack\\BlueSoleilCS.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\The KMPlayer\\KMPlayer.exe"=
"c:\\Program Files\\Toshiba\\Tvs\\TvsTray.exe"=
"c:\\WINDOWS\\RTHDCPL.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\ParetoLogic\\DriverCure\\DriverCure.exe"=
"c:\\WINDOWS\\system32\\wuauclt.exe"=
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [2008-07-31 20616]
R2 Apache2.2;Apache2.2;c:\appserv\Apache2.2\bin\httpd.exe [2008-01-17 24635]
R2 ISD;Intel(r) 82802 Firmware Hub Device (Intel(r) Security Driver);c:\windows\system32\drivers\ISECDRV.SYS [2009-01-28 32108]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-02-13 179856]
R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\kqprdn.sys --> c:\windows\system32\drivers\kqprdn.sys [?]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-02-13 15504]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2009-01-28 27632]
S2 CamelApache;CamelApache;"c:\camel\apache\apache.exe" --ntservice --> c:\camel\apache\apache.exe [?]
S2 yfknyqz;yfknyqz;\??\c:\windows\system32\drivers\srwgapggv.sys --> c:\windows\system32\drivers\srwgapggv.sys [?]
S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [2008-12-07 30088]
S3 CamelMysql;CamelMysql;c:\camel\mysql\bin\mysqld-nt.exe --defaults-file="c:\camel\mysql\ini\my.ini" CamelMysql --> c:\camel\mysql\bin\mysqld-nt.exe --defaults-file=c:\camel\mysql\ini\my.ini [?]
S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [2008-07-02 26248]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{391c5a62-f924-11dd-8a3b-0018dea75ad9}]
\sHell\AUTOplaY\coMmAnD - D:\deov.pif
\sHell\AutoRun\command - D:\deov.pif
\sHell\eXpLore\CommAND - D:\deov.pif
\sHell\open\cOmMAnd - D:\deov.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d6c4458e-ee22-11dd-8a25-0018dea75ad9}]
\SheLL\AUtOplay\ComMand - E:\ichqj.cmd
\SheLL\AutoRun\command - E:\ichqj.cmd
\SheLL\exploRe\COMmanD - E:\ichqj.cmd
\SheLL\opeN\COmmANd - E:\ichqj.cmd
.
Contents of the 'Scheduled Tasks' folder
2009-04-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-04-08 c:\windows\Tasks\DriverCure.job
- c:\program files\ParetoLogic\DriverCure\DriverCure.exe [2009-01-21 08:38]
2009-04-07 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2009-01-21 08:36]
2009-04-10 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-02-13 02:39]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Settings,ProxyOverride = local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\sara\Application Data\Mozilla\Firefox\Profiles\o1sy6ywa.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: keyword.URL - hxxp://mystart.hiyo.com/?loc=ff_address&search=
FF - component: c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
FF - component: c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metricsloader.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.
.
------- File Associations -------
.
regfile\shell\edit\command=%SystemRoot%\system32\NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-11 17:33:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mysql]
"ImagePath"="c:\appserv\MySQL\bin\mysqld-nt --defaults-file=c:\appserv\MySQL\my.ini mysql"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(812)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(868)
c:\windows\system32\setupapi.dll
c:\windows\system32\psbase.dll
.
Completion time: 2009-04-11 17:35:53
ComboFix-quarantined-files.txt 2009-04-11 14:35:51
Pre-Run: 144,080,928,768 bytes free
Post-Run: 145,721,323,520 bytes free
193