هذا هو التقرير الثاني
مسامحه على التأخير لان صار يبند ويشتغل بروحه
ComboFix 09-05-26.05 - user 05/28/2009 16:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.973.1033.18.2036.1639 [GMT 3:00]
Running from: F:\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-28 )))))))))))))))))))))))))))))))
.
2009-05-28 12:39 . 2009-05-28 12:39 -------- d-----w c:\program files\Trend Micro
2009-05-27 15:29 . 2008-01-16 01:12 159744 ----a-r c:\windows\system32\igfxres.dll
2009-05-27 15:25 . 2004-08-03 21:56 44544 -c--a-w c:\windows\system32\dllcache\nsepm.dll
2009-05-27 15:24 . 2001-10-05 00:13 9216 -c--a-w c:\windows\system32\dllcache\authfilt.dll
2009-05-27 15:23 . 2001-10-05 00:14 16384 -c--a-w c:\windows\system32\dllcache\isignup.exe
2009-05-27 15:08 . 2001-10-05 00:16 24661 -c--a-w c:\windows\system32\dllcache\spxcoins.dll
2009-05-27 15:08 . 2001-10-05 00:16 24661 ----a-w c:\windows\system32\spxcoins.dll
2009-05-27 15:08 . 2001-10-05 00:14 13312 -c--a-w c:\windows\system32\dllcache\irclass.dll
2009-05-27 15:08 . 2001-10-05 00:14 13312 ----a-w c:\windows\system32\irclass.dll
2009-05-26 20:23 . 2009-05-27 10:33 -------- d-----w c:\documents and settings\user\Application Data\Skype
2009-05-26 20:22 . 2009-05-26 20:22 -------- d-----r c:\program files\Skype
2009-05-26 20:06 . 2009-05-26 20:22 -------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-05-23 15:39 . 2009-05-23 15:39 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2009-05-20 14:34 . 2009-05-20 14:34 -------- dc----w c:\documents and settings\All Users\Application Data\Adobe Systems
2009-05-20 14:34 . 2009-05-20 14:34 -------- d-----w c:\program files\Common Files\Adobe Systems Shared
2009-05-15 16:08 . 2009-05-15 16:08 -------- d-----w c:\documents and settings\All Users\Application Data\MSScanAppDataDir
2009-05-15 15:51 . 2009-05-15 15:51 -------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-05-15 14:19 . 2009-05-15 14:20 -------- d-----w c:\program files\Sprint & FineReader 5.0 Office Try&Buy
2009-05-15 14:16 . 1998-11-12 12:35 311808 ----a-w c:\windows\system32\CAMSDKR.DLL
2009-05-15 14:16 . 2009-05-15 14:17 -------- d-----w c:\windows\NewSoft
2009-05-15 14:16 . 2009-05-15 14:16 -------- d-----w c:\windows\system32\color
2009-05-15 14:16 . 1997-10-13 10:19 11776 ----a-w c:\windows\system32\pmsbfn32.dll
2009-05-15 14:16 . 2009-05-15 14:16 -------- d-----w C:\My PageManager
2009-05-15 14:16 . 2009-05-22 18:14 -------- d-----w c:\program files\ScannerU
2009-05-15 14:10 . 2002-06-18 16:52 45056 ----a-w c:\windows\system32\Micdrv.dll
2009-05-15 14:10 . 2004-08-03 19:58 15104 ----a-w c:\windows\system32\drivers\usbscan.sys
2009-05-15 14:10 . 2002-04-18 07:45 32768 ----a-r c:\windows\IPCSet.dll
2009-05-15 14:10 . 2001-08-17 19:36 87040 ----a-w c:\windows\system32\wiafbdrv.dll
2009-05-15 14:07 . 2003-12-11 08:15 626960 ----a-r c:\windows\system32\hpvaut32.dll
2009-05-15 14:07 . 2003-12-11 08:15 487424 ----a-r c:\windows\system32\hpvcp70.dll
2009-05-15 14:07 . 2003-12-11 08:15 44544 ----a-r c:\windows\system32\MSXML4a.dll
2009-05-15 14:07 . 2003-12-11 08:15 344064 ----a-r c:\windows\system32\hpvcr70.dll
2009-05-15 14:06 . 2004-08-03 20:01 25856 ----a-w c:\windows\system32\drivers\usbprint.sys
2009-05-15 14:02 . 2009-05-16 14:34 -------- d-----w c:\program files\Hewlett-Packard
2009-05-15 14:02 . 2009-05-16 14:34 -------- d-----w c:\program files\HP
2009-05-13 15:01 . 2006-05-23 15:05 110592 ----a-w c:\documents and settings\user\Application Data\U3\temp\cleanup.exe
2009-05-13 14:52 . 2009-05-13 14:52 -------- d-----w c:\documents and settings\user\Application Data\Ahead
2009-05-13 14:50 . 2009-05-13 15:41 -------- d-----w c:\documents and settings\user\Application Data\U3
2009-05-13 14:50 . 2008-10-16 11:06 268648 ----a-w c:\windows\system32\mucltui.dll
2009-05-13 14:50 . 2008-10-16 11:06 208744 ----a-w c:\windows\system32\muweb.dll
2009-05-12 21:04 . 2009-05-12 21:04 -------- d-----w c:\program files\Common Files\Windows Live
2009-05-12 17:25 . 2009-05-12 17:38 -------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2009-05-12 17:24 . 2009-05-12 17:24 -------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2009-05-12 15:30 . 2009-05-12 15:30 -------- d-----w c:\windows\system32\scripting
2009-05-12 15:30 . 2009-05-12 15:30 -------- d-----w c:\windows\l2schemas
2009-05-12 15:30 . 2009-05-12 15:30 -------- d-----w c:\windows\system32\en
2009-05-12 15:30 . 2009-05-12 15:30 -------- d-----w c:\windows\system32\bits
2009-05-12 15:28 . 2009-05-12 15:28 -------- d-----w c:\windows\ServicePackFiles
2009-05-11 21:10 . 2004-08-03 19:29 73216 ----a-w c:\windows\system32\drivers\atintuxx.sys
2009-05-11 17:13 . 2008-05-03 11:55 2560 ----a-w c:\windows\system32\xpsp4res.dll
2009-05-11 15:57 . 2009-05-13 15:00 -------- d--h--w c:\windows\$hf_mig$
2009-05-11 01:03 . 2009-05-11 01:03 -------- d-----w c:\documents and settings\user\Local Settings\Application Data\Identities
2009-05-11 00:56 . 2007-04-09 10:23 28040 ----a-w c:\windows\system32\mdimon.dll
2009-05-11 00:56 . 2009-05-11 00:56 -------- d-----w c:\program files\Microsoft.NET
2009-05-11 00:56 . 2009-05-11 00:56 -------- d-----w c:\program files\Microsoft ActiveSync
2009-05-11 00:55 . 2009-05-11 00:56 -------- d--h--w c:\windows\ShellNew
2009-05-10 23:47 . 2009-05-10 23:47 -------- d-----w c:\documents and settings\user\Local Settings\Application Data\ESET
2009-05-10 15:26 . 2009-05-10 15:26 -------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-05-10 15:21 . 2009-05-10 15:21 -------- d-s---w c:\documents and settings\user\UserData
2009-05-10 14:57 . 2009-05-12 17:24 -------- d-----w c:\program files\Windows Live
2009-05-10 14:57 . 2009-05-10 14:57 -------- d-----w c:\program files\Messenger Plus! Live
2009-05-10 14:33 . 2009-05-10 14:33 -------- d-----w c:\program files\Common Files\xing shared
2009-05-10 13:39 . 2009-05-10 13:39 -------- d-----w c:\documents and settings\user\Contacts
2009-05-10 13:38 . 2009-05-10 14:32 -------- d-----w c:\documents and settings\user\Local Settings\Application Data\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-27 15:29 . 2009-05-09 14:39 57104 ----a-w c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-27 15:22 . 2009-05-09 14:32 22720 ----a-w c:\windows\system32\emptyregdb.dat
2009-05-22 18:14 . 2009-05-22 18:14 65736 -c--a-w C:\sam.tmp
2009-05-20 14:36 . 2009-05-09 09:59 -------- d-----w c:\program files\Common Files\Adobe
2009-05-15 14:16 . 2009-05-09 14:43 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-15 14:15 . 2009-05-09 14:44 -------- d-----w c:\program files\Common Files\InstallShield
2009-05-12 17:39 . 2009-05-09 09:57 -------- d-----w c:\program files\MSN Messenger
2009-05-12 15:31 . 2009-05-09 14:34 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-11 15:52 . 2009-05-09 14:52 -------- d-----w c:\program files\Golden Al-Wafi Translator
2009-05-11 15:46 . 2009-05-09 14:50 -------- d-----w c:\program files\3GP Player
2009-05-10 14:33 . 2009-05-09 10:02 -------- d-----w c:\program files\Common Files\Real
2009-05-10 14:33 . 2009-05-09 10:02 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-05-10 14:33 . 2009-05-09 10:02 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-05-10 14:24 . 2009-05-09 10:02 -------- d-----w c:\program files\Google
2009-05-09 14:51 . 2009-05-09 14:51 73216 ----a-w c:\windows\ST6UNST.EXE
2009-05-09 14:51 . 2009-05-09 14:51 172032 ----a-w c:\windows\Setup1.exe
2009-05-09 14:51 . 2009-05-09 14:51 -------- d-----w c:\program files\Windows Media Connect 2
2009-05-09 14:50 . 2009-05-09 14:50 -------- d-----w c:\program files\X'nBeep 1.1
2009-05-09 14:44 . 2009-05-09 14:43 -------- d-----w c:\program files\Realtek
2009-05-09 14:44 . 2009-05-09 14:44 315392 ----a-w c:\windows\HideWin.exe
2009-05-09 14:43 . 2009-05-09 14:43 -------- d-----w c:\documents and settings\user\Application Data\InstallShield
2009-05-09 14:40 . 2009-05-09 14:40 -------- d-----w c:\program files\Intel
2009-05-09 14:39 . 2009-05-09 14:39 -------- d-----w c:\program files\MSXML 4.0
2009-05-09 14:35 . 2009-05-09 14:35 -------- d-----w c:\program files\microsoft frontpage
2009-05-09 10:08 . 2009-05-09 10:08 390664 ----a-w c:\documents and settings\user\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-09 10:04 . 2009-05-09 10:04 -------- d-----w c:\program files\Ahead
2009-05-09 10:04 . 2009-05-09 10:04 -------- d-----w c:\program files\Common Files\Ahead
2009-05-09 10:02 . 2009-05-09 10:02 -------- d-----w c:\program files\Real
2009-05-09 10:01 . 2009-05-09 10:01 -------- d-----w c:\program files\NCH Swift Sound
2009-05-09 10:01 . 2009-05-09 10:01 592 ----a-w c:\windows\chgkey.vbs
2009-05-09 09:58 . 2009-05-09 09:58 -------- d-----w c:\program files\Combined Community Codec Pack
2009-05-09 09:57 . 2009-05-09 09:57 -------- d-----w c:\documents and settings\user\Application Data\Apple Computer
2009-05-09 09:57 . 2009-05-09 09:57 -------- d-----w c:\program files\iTunes
2009-05-09 09:57 . 2009-05-09 09:57 -------- d-----w c:\program files\iPod
2009-05-09 09:57 . 2009-05-09 09:56 -------- dc----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-05-09 09:57 . 2009-05-09 09:57 -------- d-----w c:\program files\QuickTime
2009-05-09 09:56 . 2009-05-09 09:56 -------- d-----w c:\program files\Apple Software Update
2009-05-09 09:54 . 2009-05-09 09:54 -------- dc----w c:\documents and settings\All Users\Application Data\ESET
2009-05-09 09:54 . 2009-05-09 09:54 -------- d-----w c:\program files\ESET
2009-05-09 09:53 . 2009-05-09 09:53 2232 ----a-w c:\windows\java\Packages\Data\JN3LNTBD.DAT
2009-05-09 09:53 . 2009-05-09 09:53 155995 ----a-w c:\windows\java\Packages\SK1JJ1B9.ZIP
2009-05-09 09:53 . 2009-05-09 09:53 2678 ----a-w c:\windows\java\Packages\Data\9ND7JN1R.DAT
2009-05-09 09:53 . 2009-05-09 09:53 2678 ----a-w c:\windows\java\Packages\Data\SGS3RDN1.DAT
2009-05-09 09:53 . 2009-05-09 09:53 2678 ----a-w c:\windows\java\Packages\Data\QK3HFZ1V.DAT
2009-05-09 09:53 . 2009-05-09 09:53 2678 ----a-w c:\windows\java\Packages\Data\L7ZJB7HF.DAT
2009-05-09 09:53 . 2009-05-09 09:53 2678 ----a-w c:\windows\java\Packages\Data\1VRHZJFR.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-10 39408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-10-24 1451264]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-10-30 256576]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-10 198160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-16 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-16 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-16 137752]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-01-16 16384512]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\user\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Action Manager 32.lnk - c:\program files\ScannerU\AM32.exe [2009-5-15 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [24/10/2008 08:53 م 34824]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [24/10/2008 08:51 م 468224]
.
Contents of the 'Scheduled Tasks' folder
2009-05-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-10-10 14:13]
2009-05-26 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-05-28 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.bh/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: Microsoft XML Parser for Java -
DPF: {7253A666-804A-1107-A4DC-00E04C504781} - hxxp://66.228.123.202/bmc.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-28 16:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1864)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-05-28 16:31
ComboFix-quarantined-files.txt 2009-05-28 13:31
Pre-Run: 93,319,176,192 bytes free
Post-Run: 93,545,267,200 bytes free
210 --- E O F --- 2009-05-16 16:03