تفضل اخي التقرير
وياليت تخبرني إذا جهازي مخترق ام لا لكي اعمل إحتياطاتي :d:
ComboFix 09-05-29.01 - Administrator 05/30/2009 18:00.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.2037.1582 [GMT 3:00]
Running from: c:\documents and settings\Administrator\سطح المكتب\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\gyjzai.dll
c:\program files\Microsoft Common
c:\program files\Microsoft Common\emails.dat
c:\program files\Microsoft Common\log.dat
c:\program files\Microsoft Common\svchost.exe
c:\program files\Microsoft Common\wuacult.exe
c:\program files\ThunMail
c:\program files\ThunMail\testabd.dll
c:\windows\IE4 Error Log.txt
c:\windows\system32\3361
c:\windows\system32\3361\SVCHOST.EXE
c:\windows\system32\6to4v32.dll
c:\windows\system32\bversion.dll
c:\windows\system32\certstore.dat
c:\windows\system32\comsa32.sys
c:\windows\system32\dncyool64.sys
c:\windows\system32\dpcxool64.sys
c:\windows\system32\drivers\c4ca33cd.sys
c:\windows\system32\drivers\e6cb75d3.sys
c:\windows\system32\fhpatch.dll
c:\windows\system32\FInstall.sys
c:\windows\system32\fiplock.dll
c:\windows\system32\IPHACTION.dll
c:\windows\system32\iphy.dll
c:\windows\system32\IpSvchostF.dll
c:\windows\system32\kakle.dll
c:\windows\system32\msncache.dll
c:\windows\system32\ntalme.sys
c:\windows\system32\Packer.dll
c:\windows\system32\sopidkc.exe
c:\windows\system32\systeminfo.dll
c:\windows\system32\tcpcon.dll
c:\windows\system32\tpsaxyd.exe
c:\windows\system32\tpszxyd.sys
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
c:\windows\system32\winitn.dll
c:\windows\system32\wtukd32.exe
c:\windows\TEMP\mta73693.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6to4
-------\Legacy_dhcpsrv
-------\Legacy_msncache
-------\Legacy_ntalme
-------\Legacy_plyxsbe
-------\Legacy_sopidkc
-------\Service_6to4
-------\Service_c4ca33cd
-------\Service_dhcpsrv
-------\Service_e6cb75d3
-------\Service_msncache
-------\Service_ntalme
-------\Service_Plyxsbe
-------\Service_sopidkc
((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-30 )))))))))))))))))))))))))))))))
.
2009-05-30 14:29 . 2009-05-30 14:29 -------- d-----w c:\program files\Trend Micro
2009-05-30 13:54 . 2009-05-30 13:54 -------- d-----w c:\program files\LanqiEngine
2009-05-30 13:50 . 2009-05-30 13:54 735232 ----a-w c:\windows\system32\AdvOcr.dll
2009-05-30 13:35 . 2009-05-30 13:50 20176 ----a-w c:\windows\system32\TRSOCR.dll
2009-05-30 12:51 . 2009-05-30 13:35 7347183 ----a-w c:\windows\system32\TRSOCR.dat
2009-05-30 12:12 . 2009-05-30 12:37 -------- d-----w c:\documents and settings\Administrator\Application Data\DMCache
2009-05-30 11:34 . 2009-05-30 11:34 1351680 ----a-w c:\windows\system32\kernel32_check.dll
2009-05-29 13:56 . 2009-05-30 14:49 -------- d-----w c:\windows\dhcp
2009-05-27 07:22 . 2009-05-28 03:13 -------- d-----w c:\program files\Unlocker
2009-05-27 07:22 . 2009-05-28 02:59 -------- d-----w c:\documents and settings\Administrator\Application Data\Desktopicon
2009-05-24 21:10 . 2009-05-24 21:10 390664 ----a-w c:\documents and settings\Administrator\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-23 01:14 . 2009-05-23 01:14 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Identities
2009-05-19 22:28 . 2009-05-19 22:28 -------- d-----w c:\documents and settings\Administrator\Application Data\Sofrayt
2009-05-19 22:28 . 2009-05-19 22:28 -------- d-----w c:\program files\GetSmile
2009-05-17 16:59 . 2009-05-17 16:59 -------- d-----w c:\documents and settings\Administrator\Application Data\Ulead Systems
2009-05-17 16:56 . 2006-07-18 05:46 61440 ----a-r c:\windows\StkATVAp.exe
2009-05-17 16:55 . 2004-08-03 20:08 31616 -c--a-w c:\windows\system32\dllcache\usbccgp.sys
2009-05-17 16:55 . 2004-08-03 20:08 31616 ----a-w c:\windows\system32\drivers\usbccgp.sys
2009-05-17 16:53 . 2009-05-17 16:53 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Help
2009-05-17 16:53 . 2009-05-17 16:53 -------- d-----w c:\windows\system32\windows media
2009-05-17 16:53 . 2009-05-17 16:53 -------- d--h--w c:\windows\msdownld.tmp
2009-05-17 16:52 . 2009-05-17 16:52 -------- d-----w c:\program files\Windows Media Components
2009-05-17 16:52 . 2009-05-17 16:52 -------- d-----w c:\program files\Common Files\Ulead Systems
2009-05-17 16:52 . 2009-05-17 16:52 -------- d-----w c:\program files\Ulead Systems
2009-05-17 16:52 . 2009-05-17 16:59 -------- d-----w c:\documents and settings\All Users\Application Data\Ulead Systems
2009-05-16 23:35 . 2004-08-03 21:55 221184 ----a-w c:\windows\system32\wmpns.dll
2009-05-16 22:15 . 2009-05-16 22:15 -------- d-----w c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-05-16 21:42 . 2009-05-16 21:52 -------- d-----w c:\documents and settings\Administrator\Application Data\Ashampoo
2009-05-16 21:40 . 2009-05-16 21:54 -------- d-----w c:\program files\Ashampoo
2009-05-16 21:38 . 2009-05-16 21:38 -------- d-----w c:\program files\FormatFactory
2009-05-16 08:08 . 2009-05-16 08:08 -------- d-----w c:\windows\Sun
2009-05-16 05:42 . 2004-08-03 20:08 26496 -c--a-w c:\windows\system32\dllcache\usbstor.sys
2009-05-16 05:20 . 2009-05-16 05:20 -------- d-----w c:\documents and settings\Administrator\Application Data\GRETECH
2009-05-16 00:30 . 2009-05-16 00:30 -------- d-s---w c:\documents and settings\Administrator\UserData
2009-05-15 21:59 . 2009-05-15 21:59 -------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-30 12:43 . 2001-09-19 12:00 40118 ----a-w c:\windows\system32\perfc001.dat
2009-05-30 12:43 . 2001-09-19 12:00 251674 ----a-w c:\windows\system32\perfh001.dat
2009-05-29 07:31 . 2009-05-14 19:36 -------- d-----w c:\program files\Circl Developement
2009-05-26 22:10 . 2009-05-14 19:29 98304 ----a-w c:\windows\system32\viscomtran.dll
2009-05-26 08:34 . 2009-05-14 19:37 -------- d-----w c:\program files\Common Files\ACD Systems
2009-05-26 08:33 . 2009-05-14 19:31 -------- d-----w c:\program files\The KMPlayer
2009-05-26 07:54 . 2009-05-14 18:52 107376 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-23 22:45 . 2009-05-14 19:38 -------- d-----w c:\program files\Golden Al-Wafi Translator
2009-05-23 21:55 . 2009-05-14 19:27 -------- d-----w c:\program files\BS.Player
2009-05-20 06:02 . 2009-05-14 18:48 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-17 16:53 . 2009-05-14 18:54 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-17 16:52 . 2009-05-14 18:54 -------- d-----w c:\program files\Common Files\InstallShield
2009-05-15 23:38 . 2009-05-14 19:13 -------- d-----w c:\program files\Ahead
2009-05-14 19:42 . 2009-05-14 19:37 -------- d-----w c:\program files\Common Files\Adobe
2009-05-14 19:38 . 2009-05-14 19:38 73216 ----a-w c:\windows\ST6UNST.EXE
2009-05-14 19:38 . 2009-05-14 19:38 172032 ------w c:\windows\Setup1.exe
2009-05-14 19:37 . 2009-05-14 19:37 -------- d-----w c:\documents and settings\Administrator\Application Data\ACD Systems
2009-05-14 19:36 . 2009-05-14 19:36 410984 ----a-w c:\windows\system32\deploytk.dll
2009-05-14 19:36 . 2009-05-14 19:36 -------- d-----w c:\program files\Java
2009-05-14 19:36 . 2009-05-14 19:36 -------- d-----w c:\program files\Messenger Plus! Live
2009-05-14 19:36 . 2009-05-14 19:36 152576 ----a-w c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-14 19:36 . 2009-05-14 19:36 2232 ----a-w c:\windows\java\Packages\Data\3JTJZFV1.DAT
2009-05-14 19:36 . 2009-05-14 19:36 155995 ----a-w c:\windows\java\Packages\YLN9F5ZP.ZIP
2009-05-14 19:36 . 2009-05-14 19:36 2678 ----a-w c:\windows\java\Packages\Data\OWMMFJFJ.DAT
2009-05-14 19:36 . 2009-05-14 19:36 2678 ----a-w c:\windows\java\Packages\Data\D3LV1ZTB.DAT
2009-05-14 19:35 . 2009-05-14 19:35 2678 ----a-w c:\windows\java\Packages\Data\RHNZPNHJ.DAT
2009-05-14 19:35 . 2009-05-14 19:35 2678 ----a-w c:\windows\java\Packages\Data\M2UK6YSV.DAT
2009-05-14 19:35 . 2009-05-14 19:35 2678 ----a-w c:\windows\java\Packages\Data\AYGO1N7L.DAT
2009-05-14 19:35 . 2009-05-14 19:34 -------- d-----w c:\program files\Windows Live
2009-05-14 19:34 . 2009-05-14 19:34 -------- d-----w c:\program files\Microsoft
2009-05-14 19:34 . 2009-05-14 19:34 -------- d-----w c:\program files\Windows Live SkyDrive
2009-05-14 19:33 . 2009-05-14 19:33 -------- d-----w c:\program files\Common Files\Windows Live
2009-05-14 19:31 . 2009-05-14 19:31 -------- d-----w c:\program files\GRETECH
2009-05-14 19:30 . 2009-05-14 19:30 -------- d-----w c:\program files\DVD X Studios
2009-05-14 19:30 . 2009-05-14 19:30 -------- d-----w c:\program files\K-Lite Codec Pack
2009-05-14 19:29 . 2009-05-14 19:29 344064 ----a-w c:\windows\system32\dkll.dll
2009-05-14 19:29 . 2009-05-14 19:29 1986560 ----a-w c:\windows\system32\akll.dll
2009-05-14 19:29 . 2009-05-14 19:29 196608 ----a-w c:\windows\system32\maag.dll
2009-05-14 19:29 . 2009-05-14 19:29 1212416 ----a-w c:\windows\system32\ckll.dll
2009-05-14 19:29 . 2009-05-14 19:29 -------- d-----w c:\program files\Ozone
2009-05-14 19:28 . 2009-05-14 19:28 -------- d-----w c:\program files\Common Files\xing shared
2009-05-14 19:28 . 2009-05-14 19:28 -------- d-----w c:\program files\Real
2009-05-14 19:28 . 2009-05-14 19:28 -------- d-----w c:\program files\Common Files\Real
2009-05-14 19:28 . 2009-05-14 19:27 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-05-14 19:28 . 2009-05-14 19:27 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-05-14 19:15 . 2009-05-14 19:12 96104 ----a-w c:\windows\system32\drivers\avipbb.sys
2009-05-14 19:15 . 2009-05-14 19:12 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-14 19:12 . 2009-05-14 19:12 -------- d-----w c:\program files\Avira
2009-05-14 19:12 . 2009-05-14 19:12 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-05-14 19:10 . 2009-05-14 19:10 -------- d-----w c:\program files\Microsoft.NET
2009-05-14 19:10 . 2009-05-14 19:10 -------- d-----w c:\program files\Microsoft Works
2009-05-14 19:06 . 2009-05-14 18:59 16608 ----a-w c:\windows\gdrv.sys
2009-05-14 19:04 . 2009-05-14 18:54 -------- d-----w c:\program files\Realtek
2009-05-14 19:02 . 2009-05-14 19:02 -------- d-----w c:\program files\Intel
2009-05-14 18:56 . 2009-05-14 18:56 -------- d-----w c:\documents and settings\Administrator\Application Data\InstallShield
2009-05-14 18:54 . 2009-05-14 18:54 315392 ----a-w c:\windows\HideWin.exe
2009-05-14 18:49 . 2009-05-14 18:49 -------- d-----w c:\program files\microsoft frontpage
2009-05-14 18:47 . 2009-05-14 18:47 22144 ----a-w c:\windows\system32\emptyregdb.dat
2009-04-09 11:32 . 2009-04-09 11:32 89088 ----a-w c:\documents and settings\Administrator\Application Data\Desktopicon\eBayShortcuts.exe
2009-03-02 18:10 . 2009-05-14 19:30 67584 ----a-w c:\windows\system32\ff_vfw.dll
.
------- Sigcheck -------
[-] 2009-05-30 11:34 1351680 EC5CCE0AE3C3EA8F70DD04623673F027 c:\windows\system32\kernel32.dll
[7] 2004-08-03 21:55 1351680 458F1764A02B43A053D0E2CEF2A6AE5B c:\windows\system32\dllcache\kernel32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-05 141848]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-14 185896]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-02-13 16857600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-5-14 113664]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
«©م، ¢¬نïé Adobe Reader.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^سرعة تشغيل Adobe Reader.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\سرعة تشغيل Adobe Reader.lnk
backup=c:\windows\pss\سرعة تشغيل Adobe Reader.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [14/05/2009 10:12 م 108289]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-UnlockerAssistant - c:\program files\Unlocker\UnlockerAssistant.exe
SafeBoot-procexp90.sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.ozonemediatec.com/update.html
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-30 18:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2176)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\StkASv2K.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
.
**************************************************************************
.
Completion time: 2009-05-30 18:04 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-30 15:04
Pre-Run: 139,352,379,392 bytes free
Post-Run: 140,382,502,912 bytes free
240