هكذا التقرير مع انه ما عندي برنامج حماية اصلا
ComboFix 09-05-31.06 - الله فحسب 06/07/2009 18:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.127.23 [GMT 3:00]
Running from: c:\documents and settings\الله فحسب\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\d1vmq.exe
c:\windows\system32\optyhww0.dll
c:\windows\system32\urretnd.exe
D:\Autorun.inf
D:\d1vmq.exe
.
((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 )))))))))))))))))))))))))))))))
.
2009-06-07 14:47 . 2009-06-07 14:47 -------- d-----w- c:\program files\Trend Micro
2009-06-03 10:13 . 2003-06-18 14:31 17920 ----a-w- c:\windows\system32\mdimon.dll
2009-06-03 10:11 . 2009-06-03 10:12 -------- d-----w- c:\windows\SHELLNEW
2009-06-03 10:11 . 2009-06-03 10:11 -------- d-----w- c:\program files\Microsoft.NET
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-02 23:34 . 2009-06-02 23:33 -------- d-----w- c:\program files\Windows Live
2009-06-02 23:33 . 2009-06-02 23:33 318 ----a-r- c:\documents and settings\الله فحسب\Application Data\Microsoft\Installer\{1CB92574-96F2-467B-B793-5CEB35C40C29}\ARPPRODUCTICON.exe
2009-06-02 23:33 . 2009-06-02 23:33 318 ----a-r- c:\documents and settings\الله فحسب\Application Data\Microsoft\Installer\{6855CCDD-BDF9-48E4-B80A-80DFB96FE36C}\ARPPRODUCTICON.exe
2009-06-02 23:33 . 2009-06-02 23:33 -------- d-----w- c:\program files\Internet Download Manager
2009-06-02 23:31 . 2009-06-02 23:32 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-02 23:31 . 2009-06-02 23:31 -------- d-----w- c:\program files\Java
2009-06-02 23:31 . 2009-06-02 23:31 -------- d-----w- c:\program files\UltraISO
2009-06-02 23:31 . 2009-06-02 23:31 -------- d-----w- c:\program files\Extension Changer
2009-06-02 23:30 . 2009-06-02 23:30 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-06-02 23:19 . 2008-04-15 11:00 71050 ----a-w- c:\windows\system32\perfc001.dat
2009-06-02 23:19 . 2008-04-15 11:00 375478 ----a-w- c:\windows\system32\perfh001.dat
2009-06-02 23:08 . 2009-06-02 23:08 2272 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-02 23:08 . 2009-06-02 23:08 -------- d-----w- c:\program files\MSBuild
2009-06-02 23:08 . 2009-06-02 23:08 -------- d-----w- c:\program files\Reference Assemblies
2009-06-02 22:57 . 2009-06-02 22:57 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-02 22:54 . 2009-06-02 22:54 22144 ----a-w- c:\windows\system32\emptyregdb.dat
2009-06-02 22:53 . 2009-06-02 22:53 -------- d-----w- c:\program files\Windows Media Connect 2
2009-04-07 12:41 . 2009-04-07 12:41 218624 ----a-w- c:\windows\system32\uxtheme.dll
2009-04-07 12:41 . 2009-04-07 12:41 139264 ----a-w- c:\windows\system32\sfc_os.dll
2009-04-07 12:39 . 2009-04-07 12:39 1574912 ----a-w- c:\windows\system32\wmvencod.dll
2009-04-07 12:38 . 2009-04-07 12:38 45056 ----a-w- c:\windows\system32\mfc71CHT.dll
2009-03-16 18:18 . 2009-06-02 23:01 69448 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-03-16 18:18 . 2009-06-02 23:01 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
2009-03-16 18:18 . 2009-06-02 23:01 235352 ----a-w- c:\windows\system32\XactEngine3_4.dll
2009-03-16 18:18 . 2009-06-02 23:01 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
2009-03-09 19:27 . 2009-06-02 23:01 4178264 ----a-w- c:\windows\system32\d3dx9_41.dll
2009-03-09 19:27 . 2009-06-02 23:01 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
2009-03-09 19:27 . 2009-06-02 23:01 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
.
------- Sigcheck -------
[-] 2008-11-07 08:52 1571328 CA1867A515E40A015BA6D9ADD83FB823 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-05 280779]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-cbvcs - c:\windows\system32\urretnd.exe
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.extra-pc.com/forum
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-07 18:37
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-06-07 18:38
ComboFix-quarantined-files.txt 2009-06-07 15:38
Pre-Run: 10,888,720,384 bytes free
Post-Run: 10,881,056,768 bytes free
109