تفضل
ComboFix 09-05-08.03 - so cute 05/09/2009 0:15.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.958.704 [GMT 3:00]
Running from: c:\documents and settings\so cute\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
c:\windows\system32\prsgrc.dll
c:\windows\system32\ssprs.dll
.
((((((((((((((((((((((((( Files Created from 2009-04-08 to 2009-05-08 )))))))))))))))))))))))))))))))
.
2009-05-08 19:38 . 2009-05-08 19:38 -------- d-----w c:\program files\Trend Micro
2009-05-08 18:05 . 2009-05-08 18:05 -------- d-----w c:\windows\LastGood
2009-05-06 19:54 . 2009-05-08 21:19 3692576 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-06 19:30 . 2009-05-06 19:30 -------- d-s---w c:\documents and settings\so cute\UserData
2009-05-05 16:55 . 2009-05-05 16:55 -------- d-----w c:\windows\Adobe Illustrator CS
2009-04-29 13:41 . 2009-04-29 13:41 -------- d-----w c:\program files\AmitySource
2009-04-24 11:36 . 2009-04-24 11:36 -------- d-----w c:\documents and settings\so cute\Application Data\Ambient Design
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-07 14:51 . 2008-12-18 16:32 26 ----a-w c:\windows\popcinfo.dat
2009-05-07 13:30 . 2009-05-06 19:54 29288 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-05 16:56 . 2008-12-16 18:28 -------- d-----w c:\program files\Common Files\Adobe
2009-05-05 16:55 . 2008-12-16 18:15 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-04 19:13 . 2001-09-19 11:00 256190 ----a-w c:\windows\system32\perfh001.dat
2009-05-04 19:13 . 2001-09-19 11:00 42044 ----a-w c:\windows\system32\perfc001.dat
2009-04-24 13:29 . 2008-12-16 18:57 -------- d-----w c:\program files\Google
2009-03-31 12:35 . 2009-03-31 12:35 -------- d-----w c:\program files\Vertus Fluid Mask 3
2009-03-31 12:20 . 2008-04-14 17:29 1024 ----a-w c:\windows\system32\kvmdjjn.dll
2009-03-31 12:20 . 2008-04-14 17:29 1024 ----a-w c:\windows\system32\grcauth2.dll
2009-03-31 12:20 . 2008-04-14 17:29 1024 ----a-w c:\windows\system32\grcauth1.dll
2009-03-31 12:20 . 2008-04-14 17:29 1024 ----a-w c:\windows\system32\clauth2.dll
2009-03-31 12:20 . 2008-04-14 17:29 1024 ----a-w c:\windows\system32\clauth1.dll
2009-03-30 18:08 . 2009-01-07 19:44 -------- d-----w c:\program files\WMV9_VCM
2009-03-30 18:08 . 2009-01-07 19:44 -------- d-----w c:\program files\Common Files\xara
2009-03-30 18:08 . 2009-01-07 19:44 -------- d-----w c:\program files\Xara
2009-03-27 19:53 . 2008-12-28 18:56 480584 ----a-w c:\documents and settings\so cute\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-24 14:18 . 2008-12-19 21:24 -------- d-----w c:\program files\Kelk 2000
2009-03-13 10:24 . 2009-02-06 17:15 -------- d-----w c:\program files\MessengerPlus! 3
2009-03-12 17:07 . 2008-12-16 18:40 -------- d-----w c:\program files\Ahead
2009-03-11 22:44 . 2009-03-09 14:14 -------- d-----w c:\program files\2D and 3D Animator
2009-03-07 14:58 . 2009-03-07 14:58 319488 ----a-w c:\windows\HideWin.exe
2009-03-06 14:20 . 2008-04-14 17:29 283136 ----a-w c:\windows\system32\pdh.dll
2009-02-20 08:09 . 2008-04-14 17:29 664576 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:09 . 2008-04-14 17:29 81920 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 14:04 . 2008-04-14 17:07 1846656 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:22 . 2008-04-14 21:12 2025472 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:22 . 2008-04-14 17:12 2146816 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:21 . 2008-04-14 17:30 110592 ----a-w c:\windows\system32\services.exe
2009-02-09 10:51 . 2008-04-14 17:29 723456 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:51 . 2008-04-14 17:29 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:51 . 2008-04-14 17:29 681472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:51 . 2008-04-14 17:29 693760 ----a-w c:\windows\system32\ntdll.dll
.
------- Sigcheck -------
[-] 2008-06-09 19:04 1571328 CA1867A515E40A015BA6D9ADD83FB823 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2009-03-13 190024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-16 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-16 185872]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2009-03-13 190024]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-08-02 577536]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2005-03-07 53248]
"VTTrayp"="VTtrayp.exe" - c:\windows\system32\VTTrayp.exe [2006-04-11 176128]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-16 110592]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mobily Connect Card\\Mobily Connect Card.exe"=
"c:\\Documents and Settings\\so cute\\سطح المكتب\\فرش باكسوليه1(\\MSN Messenger\\msnmsgr.exe"=
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [16/12/2008 09:17 م 11264]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - IS-TPPTDDRV
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5cc1ee82-cdcc-11dd-ae65-0019db7144e1}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc85023c-31ab-11de-b04e-0019db7144e1}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc85023d-31ab-11de-b04e-0019db7144e1}]
\Shell\AutoRun\command - F:\AutoRun.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-TrueTransparency - c:\documents and settings\so cute\سطح المكتب\TrueTransparency\TrueTransparency.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{46012075-ED62-464b-9554-AD0BEC35D1EC} -
IE: {{46012076-ED62-464b-9554-AD0BEC35D1EC}
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-09 00:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-05-08 0:22
ComboFix-quarantined-files.txt 2009-05-08 21:21
Pre-Run: 26,239,004,672 bytes free
Post-Run: 28,222,046,208 bytes free
130 --- E O F --- 2009-05-03 11:56