اية التقرير كان سليم ولا اية
على العموم دة تقرير ال ComboFix
ComboFix 09-04-15.08 - Administrator 04/15/2009 12:27.2 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.20.1033.18.502.276 [GMT 2:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Created from 2009-03-15 to 2009-04-15 )))))))))))))))))))))))))))))))
.
2009-04-15 10:27 . 2009-04-15 10:27 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\ESET
2009-04-15 10:13 . 2009-04-15 10:13 -------- d-sh--w C:\FOUND.000
2009-04-15 10:06 . 2009-04-15 10:06 268 ---ha-w C:\sqmdata02.sqm
2009-04-15 10:06 . 2009-04-15 10:06 244 ---ha-w C:\sqmnoopt02.sqm
2009-04-15 07:11 . 2009-04-15 07:11 -------- d-----w c:\documents and settings\Administrator\DoctorWeb
2009-04-15 07:01 . 2009-04-15 07:01 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Identities
2009-04-15 06:59 . 2009-04-15 06:59 -------- d-----w c:\windows\system32\xircom
2009-04-15 06:59 . 2009-04-15 06:59 -------- d-----w c:\windows\system32\restore
2009-04-15 06:59 . 2009-04-15 06:59 -------- d-----w c:\windows\srchasst
2009-04-15 06:54 . 2009-04-15 06:54 -------- d-----w c:\documents and settings\Administrator\Application Data\CyberScrub
2009-04-15 06:54 . 2009-04-15 06:54 -------- d-----w c:\documents and settings\Administrator\Application Data\cleaner
2009-04-15 06:46 . 2009-04-15 06:47 -------- d-----w c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-04-15 06:46 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-15 06:46 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-15 06:46 . 2009-04-15 06:46 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-15 06:30 . 2009-04-15 06:30 -------- d-----w c:\documents and settings\Administrator\Application Data\IDM
2009-04-15 06:30 . 2009-04-15 06:30 -------- d-----w c:\documents and settings\Administrator\Application Data\DMCache
2009-04-15 05:42 . 2009-04-15 05:42 268 ---ha-w C:\sqmdata01.sqm
2009-04-15 05:42 . 2009-04-15 05:42 244 ---ha-w C:\sqmnoopt01.sqm
2009-04-15 05:40 . 2009-04-15 05:40 376 ----a-w c:\windows\ODBC.INI
2009-04-15 05:39 . 2009-04-15 05:39 -------- d-----w c:\windows\SHELLNEW
2009-04-15 05:30 . 2009-04-15 05:30 -------- d-----w c:\documents and settings\Administrator\Application Data\ADSoft
2009-04-15 05:25 . 2009-04-15 05:25 -------- d-----w c:\documents and settings\Administrator\Application Data\Thinstall
2009-04-15 05:22 . 2009-04-15 05:22 -------- d-----w c:\documents and settings\Administrator\Application Data\ESET
2009-04-15 05:21 . 2009-04-15 05:21 -------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-04-15 05:20 . 2006-10-04 14:06 1197294 ------w c:\windows\system32\dllcache\sysmain.sdb
2009-04-15 05:20 . 2006-10-04 14:06 764868 ------w c:\windows\system32\dllcache\apph_sp.sdb
2009-04-15 05:20 . 2006-10-04 14:06 217118 ------w c:\windows\system32\dllcache\apphelp.sdb
2009-04-15 05:20 . 2006-09-25 15:58 23856 ----a-w c:\windows\system32\spupdsvc.exe
2009-04-15 05:17 . 2009-04-15 05:17 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-04-15 05:12 . 2009-04-15 05:12 -------- d-----w c:\documents and settings\Administrator\Application Data\Styler
2009-04-14 23:24 . 2009-04-14 23:24 268 ---ha-w C:\sqmdata00.sqm
2009-04-14 23:24 . 2009-04-14 23:24 244 ---ha-w C:\sqmnoopt00.sqm
2009-04-14 23:17 . 2009-04-14 23:17 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft Help
2009-04-14 23:17 . 2009-04-14 23:17 -------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-14 23:13 . 2008-01-26 00:46 163840 ----a-w c:\windows\system32\igfxres.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-15 07:55 . 2009-04-15 07:55 -------- d-----w c:\program files\GRETECH
2009-04-15 07:48 . 2009-04-15 07:48 -------- d-----w c:\program files\ESET
2009-04-15 07:05 . 2009-04-15 07:04 2491 ----a-w C:\rapport.txt
2009-04-15 06:59 . 2009-04-15 06:59 -------- d-----w c:\program files\microsoft frontpage
2009-04-15 06:46 . 2009-04-15 06:46 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-15 06:22 . 2009-04-14 22:33 1065 ----a-w C:\WPI_Log.txt
2009-04-15 06:22 . 2009-04-15 06:22 -------- d-----w c:\program files\Internet Download Manager
2009-04-15 06:08 . 2009-04-14 22:38 22032 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-15 05:39 . 2009-04-15 05:39 -------- d-----w c:\program files\Microsoft ActiveSync
2009-04-15 05:39 . 2009-04-15 05:39 -------- d-----w c:\program files\Microsoft.NET
2009-04-15 05:23 . 2009-04-15 05:23 -------- d-----w c:\program files\UlisesSoft
2009-04-15 05:17 . 2009-04-15 05:17 -------- d-----w c:\program files\Save Flash
2009-04-15 05:17 . 2009-04-15 05:17 -------- d-----w c:\program files\Common Files\xing shared
2009-04-15 05:17 . 2009-04-14 22:36 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-04-15 05:17 . 2009-04-15 05:17 -------- d-----w c:\program files\Common Files\Real
2009-04-15 05:17 . 2009-04-15 05:17 -------- d-----w c:\program files\Real
2009-04-15 05:16 . 2009-04-15 05:16 -------- d-----w c:\program files\The KMPlayer
2009-04-14 22:59 . 2009-04-14 22:59 -------- d-----w c:\program files\Intel
2009-04-14 22:58 . 2009-04-14 22:58 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-14 22:58 . 2009-04-14 22:58 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-14 22:45 . 2009-04-14 22:45 -------- d-----w c:\program files\Analog Devices
2009-04-14 22:38 . 2009-04-14 22:38 -------- d-----w c:\program files\Windows Live
2009-04-14 22:37 . 2009-04-14 22:37 -------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2009-04-14 22:37 . 2009-04-14 22:37 -------- d-----w c:\program files\Yahoo!
2009-04-14 22:37 . 2009-04-14 22:37 -------- d-----w c:\program files\SLD Codec Pack
2009-04-14 22:37 . 2009-04-14 22:37 -------- d-----w c:\program files\Real Alternative
2009-04-14 22:37 . 2009-04-14 22:37 -------- d-----w c:\program files\Media Player Classic
2009-04-14 22:36 . 2009-04-14 22:36 -------- d-----w c:\program files\K-Lite Codec Pack
2009-04-14 22:36 . 2009-04-14 22:36 -------- d-----w c:\program files\Winamp
2009-04-14 22:36 . 2009-04-14 22:36 -------- d-----w c:\program files\ADSoft
2009-04-14 22:36 . 2009-04-14 22:36 -------- d-----w c:\documents and settings\All Users\Application Data\ADSoft
2009-04-14 22:36 . 2009-04-14 22:36 -------- d-----w c:\program files\Foxit Software
2009-04-14 22:36 . 2009-04-14 22:36 -------- d-----w c:\program files\Java
2009-04-14 22:36 . 2009-04-14 22:36 -------- d-----w c:\program files\Common Files\Java
2009-04-14 22:35 . 2009-04-14 22:35 -------- d-----w c:\program files\Common Files\Nero
2009-04-14 22:35 . 2009-04-14 22:35 -------- d-----w c:\program files\Nero
2009-04-14 22:35 . 2009-04-14 22:35 -------- d-----w c:\program files\My Company Name
2009-04-14 22:35 . 2009-04-14 22:35 -------- d-----w c:\program files\Opera
2009-04-14 22:35 . 2009-04-14 22:35 -------- d-----w c:\program files\Driver-Soft
2009-04-14 22:30 . 2009-04-14 22:30 -------- d-----w c:\program files\STYLER
2009-04-14 22:29 . 2009-04-14 22:29 -------- d-----w c:\program files\RocketDock
2009-04-14 22:29 . 2009-04-14 22:31 -------- d-----w c:\documents and settings\Administrator\Application Data\Notepad++
2009-04-14 22:29 . 2009-04-14 22:30 -------- d-----w c:\windows\system32\config\systemprofile\Application Data\Notepad++
2009-04-14 22:29 . 2009-04-14 22:29 -------- d-----w c:\program files\Notepad++
2009-04-14 22:29 . 2009-04-14 22:29 -------- d-----w c:\program files\Notepad2
2009-04-14 22:29 . 2009-04-14 22:29 -------- d-----w c:\program files\System
2009-04-14 22:26 . 2009-04-14 22:26 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-04-14 22:26 . 2009-04-14 22:26 -------- d-----w c:\program files\Windows Media Connect 2
2009-03-26 15:35 . 2009-04-03 13:24 210352 ----a-w c:\windows\system32\idmmbc.dll
2007-08-07 22:49 . 2009-04-14 22:31 100247 ----a-w c:\documents and settings\Administrator\xmlUpdater.exe
2007-08-07 22:49 . 2009-04-14 22:30 100247 ----a-w c:\windows\system32\config\systemprofile\xmlUpdater.exe
2007-08-07 22:49 . 2007-08-07 22:49 100247 ----a-w c:\documents and settings\Default User\xmlUpdater.exe
.
------- Sigcheck -------
[-] 2008-04-02 07:07 2225792 2F37894AEB0F167B556E0A9A37AD491E c:\windows\system32\ntkrnlpa.exe
[-] 2008-03-20 06:16 2344960 497B9F0053BECB485D0F6D57BC792156 c:\windows\system32\ntoskrnl.exe
[-] 2008-03-29 07:12 1514496 2FC27528FAB09949D37CFBA7A1FB85B0 c:\windows\explorer.exe
.
(((((((((((((((((((((((((((((
SnapShot@2009-04-15_06.37.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-15 06:46 . 2009-04-06 13:32 38496 c:\windows\system32\drivers\mbamswissarmy.sys
+ 2009-04-15 06:46 . 2009-04-06 13:32 15504 c:\windows\system32\drivers\mbam.sys
+ 2008-06-10 16:48 . 2008-06-10 16:48 53256 c:\windows\system32\drivers\easdrv.sys
+ 2009-04-15 10:03 . 2009-04-15 10:03 34308 c:\windows\system32\BASSMOD.dll
+ 2009-04-15 07:50 . 2009-04-15 07:50 10134 c:\windows\Installer\{58E05C78-4785-443D-8A1B-CBFF49C2A84E}\callmsi.exe
+ 2009-04-03 13:24 . 2009-03-26 15:35 210352 c:\windows\system32\idmmbc.dll
+ 2009-04-15 07:50 . 2009-04-15 07:50 140544 c:\windows\Installer\{58E05C78-4785-443D-8A1B-CBFF49C2A84E}\egui.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-10-27 3810544]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-11-07 3739672]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-04-03 2794928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-05 280779]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2006-11-21 35328]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-01-26 1404928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-26 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-26 126976]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-15 185896]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-06-10 1447168]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2007-07-22 124928]
c:\windows\system32\config\systemprofile\Start Menu\Programs\Startup\
RocketDock.lnk - c:\program files\RocketDock\RocketDock.exe [2009-4-15 495616]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
RocketDock.lnk - c:\program files\RocketDock\RocketDock.exe [2009-4-15 495616]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
TrueTransparency.lnk - c:\program files\TrueTransparency\TrueTransparency.exe [2009-4-15 133120]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"="0x00000000"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2008-06-10 468224]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.eg/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-15 12:28
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-04-15 12:29
ComboFix-quarantined-files.txt 2009-04-15 10:29
ComboFix2.txt 2009-04-15 06:38
Pre-Run: 3,797,307,392 bytes free
Post-Run: 3,913,084,928 bytes free
213