تفضل يااغالي
ComboFix 09-04-04.01 - WIN XP 04/12/2009 14:32:27.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.766.409 [GMT 3:00]
Running from: c:\documents and settings\WIN XP\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
c:\documents and settings\tazebama.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\WIN XP\Application Data\tazebama
c:\documents and settings\WIN XP\Application Data\tazebama\tazebama.log
c:\documents and settings\WIN XP\Application Data\tazebama\zPharaoh.dat
C:\zPharaoh.exe
D:\Autorun.inf
d:\recycler\JetAudio dump.exe
d:\recycler\RECYCLER .exe
D:\zPharaoh.exe
E:\Autorun.inf
e:\recycler\InstallMSN11En.exe
e:\recycler\RECYCLER .exe
E:\zPharaoh.exe
.
((((((((((((((((((((((((( Files Created from 2009-03-12 to 2009-04-12 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-12 11:45 21,944,352 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-12 11:45 155,581 --sh--r C:\zPharaoh.exe
2009-04-12 11:45 --------- d-----w c:\documents and settings\WIN XP\Application Data\tazebama
2009-04-12 11:40 255,524 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-11 22:07 --------- d-----w c:\program files\MSN Messenger
2009-04-11 22:06 498,543 ----a-w c:\windows\system32\mspaint.exe
2009-04-11 22:06 225,647 ----a-w c:\windows\system32\notepad.exe
2009-04-11 22:06 1,360,751 ----a-w c:\windows\system32\ntbackup.exe
2009-04-11 22:05 925,551 ----a-w c:\windows\pchealth\helpctr\binaries\helpctr.exe
2009-04-11 18:44 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-04-11 18:32 69,632 ----a-w c:\windows\Alcmtr.exe
2009-04-11 18:32 2,879,488 ----a-w c:\windows\SkyTel.exe
2009-04-11 18:32 --------- d-----w c:\documents and settings\WIN XP\Application Data\TRAY SIXTH LESS
2009-04-11 18:32 --------- d-----w c:\documents and settings\All Users\Application Data\Admin Inter 1 Mags
2009-02-16 21:12 --------- d-----w c:\documents and settings\WIN XP\Application Data\Nokia Multimedia Player
2009-02-09 14:04 1,846,656 ----a-w c:\windows\system32\win32k.sys
2009-01-26 23:29 9,866,095 ----a-w c:\windows\RTLCPL.exe
2009-01-26 23:29 521,071 ----a-w c:\windows\RtlUpd.exe
2009-01-26 23:29 463,215 ----a-w c:\windows\IsUninst.exe
2009-01-26 23:29 456,047 ----a-w c:\windows\uninst.exe
2009-01-26 23:29 242,543 ----a-w c:\windows\SoundMan.exe
2009-01-26 23:29 202,879 ----a-w c:\windows\setdebug.exe
2009-01-26 23:29 2,315,119 ----a-w c:\windows\MicCal.exe
2009-01-26 22:59 2,965,359 ----a-w c:\windows\alcwzrd.exe
2009-01-22 23:54 0 ----a-w c:\documents and settings\MyDocuments\readthis.doc.exe
2009-01-22 23:54 0 ----a-w c:\documents and settings\MyDocuments\Readme.doc .exe
2008-01-13 18:11 157 ----a-w c:\program files\COM.NET.txt
2008-11-26 08:02 76,288 --sh--r c:\windows\system32\symdbsvc.exe
2008-10-13 17:46 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008101320081014\index.dat
.
------- Sigcheck -------
01/01/2009 06:03 AM 1187695 1ac4da767b94c78704efeca81463c785 c:\windows\explorer.exe
08/04/2004 01:56 AM 1029632 932f97b77f2625f7ff7dfc97552548f8 c:\windows\$NtServicePackUninstall$\explorer.exe
04/14/2008 06:59 PM 1031168 ca3445dce9eb70a2ca2504e0af5c543f c:\windows\ServicePackFiles\i386\explorer.exe
.
(((((((((((((((((((((((((((((
SnapShot@Sun 04-12-2009_ 0.38.12.17 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-04-11 20:49:53 326,511 ----a-w c:\windows\pchealth\helpctr\binaries\msconfig.exe
+ 2008-04-14 15:59:57 169,984 ----a-w c:\windows\pchealth\helpctr\binaries\msconfig.exe
- 2009-04-11 20:55:53 322,264 ----a-w c:\windows\system32\perfc001.dat
+ 2009-04-12 11:07:24 323,874 ----a-w c:\windows\system32\perfc001.dat
- 2009-04-11 20:55:53 331,130 ----a-w c:\windows\system32\perfc009.dat
+ 2009-04-12 11:07:24 332,790 ----a-w c:\windows\system32\perfc009.dat
- 2009-04-11 20:55:53 749,014 ----a-w c:\windows\system32\perfh001.dat
+ 2009-04-12 11:07:24 751,814 ----a-w c:\windows\system32\perfh001.dat
- 2009-04-11 20:55:53 462,828 ----a-w c:\windows\system32\perfh009.dat
+ 2009-04-12 11:07:24 465,448 ----a-w c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [04/11/2009 09:32 PM 190024]
"PC Suite Tray"="c:\nokia pc suite 6\PCSuite.exe" [04/12/2009 01:06 AM 852335]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [04/11/2009 09:32 PM 53248]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [07/09/2001 10:50 AM 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [09/18/2006 11:08 AM 29696]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [04/11/2009 09:32 PM 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [01/13/2008 09:13 PM 185896]
"NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [04/12/2009 01:06 AM 3240815]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [04/12/2009 01:06 AM 566127]
"SkyTel"="SkyTel.EXE" [04/11/2009 09:32 PM 2879488 c:\windows\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [06/28/2006 09:54 AM 16248320 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/14/2008 06:59 PM 15360]
"Nokia.PCSync"="c:\nokia pc suite 6\PcSync2.exe" [04/11/2009 09:32 PM 1294336]
c:\documents and settings\WIN XP\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
is-KVT0B.lnk - c:\documents and settings\WIN XP\«ل¥ ںéêè¢ \Virus Removal Tool\is-KVT0B\startup.exe [2009-04-11 65536]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-01-30 270191]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 891399]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-01-17 775084]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Macromedia\\Flash MX\\Flash_original.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
R1 is-KVT0Bdrv;is-KVT0Bdrv;c:\windows\system32\drivers\52742153.sys [2009-04-11 148496]
R2 BandLuxe_Service;BandLuxe Service;c:\program files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe [2008-06-03 87264]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\drivers\br3gmdm.sys [2008-10-21 100096]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19e5bed2-0280-11de-9160-0016d4ce9c5f}]
\Shell\AutoRun\command - G:\zPharaoh.exe
\Shell\explore\command - G:\zPharaoh.exe
\Shell\open\command - G:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{355951b4-04dd-11dd-8d4d-0016d4ce9c5f}]
\Shell\AutoRun\command - G:\xn1i9x.com
\Shell\explore\Command - G:\xn1i9x.com
\Shell\open\Command - G:\xn1i9x.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{59ab8634-c911-11dc-8c92-0016d4ce9c5f}]
\Shell\AutoRun\command - I:\zPharaoh.exe
\Shell\explore\command - I:\zPharaoh.exe
\Shell\open\command - I:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{59e9b684-26c6-11de-91e9-0016d4ce9c5f}]
\Shell\AutoRun\command - G:\zPharaoh.exe
\Shell\explore\command - G:\zPharaoh.exe
\Shell\open\command - G:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5c464d23-81e1-11dd-8f73-0016d4ce9c5f}]
\Shell\AutoRun\command - H:\xn1i9x.com
\Shell\explore\Command - H:\xn1i9x.com
\Shell\open\Command - H:\xn1i9x.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9ff2e106-754f-11dd-8f32-0016d4ce9c5f}]
\Shell\AutoRun\command - G:\xn1i9x.com
\Shell\explore\Command - G:\xn1i9x.com
\Shell\open\Command - G:\xn1i9x.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b804a954-1e84-11dd-8db3-0016d4ce9c5f}]
\Shell\AutoRun\command - G:\xn1i9x.com
\Shell\explore\Command - G:\xn1i9x.com
\Shell\open\Command - G:\xn1i9x.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c240aec5-07e0-11de-9172-0016d4ce9c5f}]
\Shell\AutoRun\command - G:\zPharaoh.exe
\Shell\explore\command - G:\zPharaoh.exe
\Shell\open\command - G:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c415a107-1ae3-11de-91b8-0016d4ce9c5f}]
\Shell\AutoRun\command - G:\zPharaoh.exe
\Shell\explore\command - G:\zPharaoh.exe
\Shell\open\command - G:\zPharaoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da7208d8-9fa3-11dd-9013-0016d4ce9c5f}]
\Shell\AutoRun\command - H:\AUTORUN_BANDLUXE.EXE
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-12 14:45:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\WgaTray.exe
c:\documents and settings\tazebama.dl_
c:\documents and settings\WIN XP\c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
c:\program files\MSN Messenger\MsnMsgr.Exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
.
**************************************************************************
.
Completion time: 04/12/2009 14:48:01 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-12 11:47:58
ComboFix2.txt 2009-04-11 21:39:57
Pre-Run: 41,120,632,832 bytes free
Post-Run: 42,155,876,352 bytes free
211 --- E O F --- 2009-03-27 13:01:13