وهذا التقرير ياشباب بس تكفوون شوف لي حل
ComboFix 09-05-12.06 - nesnas 05/13/2009 16:45.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.1015.656 [GMT 3:00]
Running from: c:\documents and settings\nesnas\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - explorer.exe: deleted 51344 bytes in 5 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2009-04-13 to 2009-05-13 )))))))))))))))))))))))))))))))
.
2009-05-11 18:10 . 2009-05-11 18:10 -------- d-----w c:\program files\Windows Doctor
2009-05-11 07:09 . 2008-06-21 15:54 11779 ----a-w c:\windows\REGTWEAK.REG
2009-04-26 10:55 . 2009-04-26 10:55 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-25 14:49 . 2009-04-25 14:49 -------- d-----w c:\windows\Sun
2009-04-23 21:48 . 2009-04-26 10:55 -------- d-----w c:\program files\Java
2009-04-23 21:43 . 2009-04-23 21:43 -------- d-----w c:\program files\Common Files\Java
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-13 13:37 . 2008-04-14 17:29 1031168 ----a-w c:\windows\explorer.exe
2009-04-26 08:36 . 2001-09-19 10:00 472414 ----a-w c:\windows\system32\perfh001.dat
2009-04-26 08:36 . 2001-09-19 10:00 154332 ----a-w c:\windows\system32\perfc001.dat
2009-03-29 03:10 . 2009-03-29 03:10 -------- d-----w c:\program files\LtUcx
2009-03-18 13:48 . 2009-03-18 13:48 -------- d-----r c:\program files\Skype
2009-03-05 21:04 . 2008-08-29 19:13 94632 ----a-w c:\documents and settings\nesnas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((
SnapShot@2009-05-12_20.34.44 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-13 13:47 . 2009-05-13 13:47 16384 c:\windows\Temp\Perflib_Perfdata_678.dat
+ 2008-04-14 17:29 . 2009-05-13 13:37 1031168 c:\windows\system32\dllcache\explorer.exe
- 2008-04-14 17:29 . 2009-05-12 20:34 1031168 c:\windows\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-08-16 5797744]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-03-11 24095528]
"SoundMan"="c:\windows\system32\SOUNDMAN.EXE" [2009-01-18 6656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-29 185896]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-26 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-11-14 16270848]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2008-04-14 99840]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 117872]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= c:\\Program Files\\Windows Live\\Messenger\\MsnMsgr.Exe
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\explorer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\ALCMTR.EXE"=
"c:\\Program Files\\Adobe\\Reader 8.0\\Reader\\reader_sl.exe"=
"c:\\Documents and Settings\\nesnas\\My Documents\\فضائي\\ShareMax(special)\\ShareMax(special)\\ShareMax.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\usnsvc.exe"=
"c:\\Documents and Settings\\nesnas\\سطح المكتب\\ShareMax(special)\\ShareMax(special)\\ShareMax.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ASC3360PR
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyServer = 87.109.229.67:80
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {06D7FA8D-4A71-48CE-8F7A-9BD03367D0DA} = 208.67.222.222,208.67.220.220
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} - hxxp://209.11.244.90/ReadUid.CAB
FF - ProfilePath - c:\documents and settings\nesnas\Application Data\Mozilla\Firefox\Profiles\5gngbw3z.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-13 16:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-05-13 16:48 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-13 13:48
ComboFix2.txt 2009-05-12 20:35
Pre-Run: 34,666,819,584 bytes free
Post-Run: 34,600,828,928 bytes free
133