تفضل اخوي
الجهاز ما عمل ري استارت نفس اول مرة
ComboFix 09-06-20.04 - SUHAIL_10 06/22/2009 0:01.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.971.1033.18.501.288 [GMT 4:00]
Running from: c:\documents and settings\SUHAIL_10\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-05-21 to 2009-06-21 )))))))))))))))))))))))))))))))
.
2009-06-21 19:02 . 2009-06-21 19:02 -------- d-----w- c:\program files\Microsoft
2009-06-21 19:02 . 2009-06-21 19:02 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-06-21 18:17 . 2009-06-21 18:17 -------- d-----w- c:\windows\system32\wbem\Repository
2009-06-21 18:16 . 2009-06-21 18:16 -------- d-----w- C:\bf85c05ec0a8d33baaec9a4771a0c1f7
2009-06-21 17:59 . 2009-06-21 18:15 -------- d-----w- c:\program files\Icon Constructor 3
2009-06-21 14:04 . 2009-06-21 14:04 -------- d-----w- c:\documents and settings\SUHAIL_10\Application Data\HP
2009-06-21 14:01 . 2009-06-21 14:01 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-06-21 13:48 . 2009-06-21 14:03 -------- d-----w- c:\program files\HP
2009-06-21 13:45 . 2009-06-21 14:04 128617 ----a-w- c:\windows\hpoins11.dat
2009-06-20 13:21 . 2009-06-21 18:16 -------- d-----w- c:\documents and settings\SUHAIL_10\Application Data\MessengerDiscovery 2
2009-06-20 13:20 . 2009-06-21 18:16 -------- d-----w- c:\program files\MessengerDiscovery 2
2009-06-20 10:58 . 2009-06-20 10:58 4096 ----a-w- c:\windows\d3dx.dat
2009-06-20 09:36 . 2009-06-20 09:36 -------- d-----w- c:\documents and settings\SUHAIL_10\Local Settings\Application Data\Identities
2009-06-20 07:35 . 2009-06-21 18:16 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-20 07:24 . 2009-06-21 20:00 -------- d-----w- c:\documents and settings\SUHAIL_10\Tracing
2009-06-20 07:17 . 2009-06-21 19:02 -------- d-----w- c:\program files\Windows Live
2009-06-20 06:51 . 2009-06-20 06:51 -------- d-----w- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-21 19:09 . 2009-06-19 16:37 34816 ----a-w- c:\documents and settings\SUHAIL_10\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-20 16:35 . 2009-06-19 16:25 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-19 20:31 . 2009-06-19 20:31 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-06-19 20:27 . 2009-06-19 16:22 -------- d-----w- c:\program files\Windows Media Connect 2
2009-06-19 16:50 . 2009-06-19 16:50 -------- d-----w- c:\program files\ESET
2009-06-19 16:50 . 2009-06-19 16:50 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-06-19 16:26 . 2009-06-19 16:26 -------- d-----w- c:\program files\microsoft frontpage
2009-06-19 16:23 . 2009-06-19 16:23 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-05-14 11:49 . 2009-05-14 11:49 94360 ----a-w- c:\windows\system32\drivers\epfwtdir.sys
2009-05-14 11:47 . 2009-05-14 11:47 107256 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-05-14 11:41 . 2009-05-14 11:41 114472 ----a-w- c:\windows\system32\drivers\eamon.sys
.
(((((((((((((((((((((((((((((
SnapShot@2009-06-21_19.17.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-21 19:37 . 2009-06-21 19:37 10134 c:\windows\Installer\{2EEBAC31-3EEF-4118-91CB-1A286A507DB2}\callmsi.exe
+ 2007-07-22 13:16 . 2007-07-22 13:16 113152 c:\windows\system32\utilman.exe
+ 2005-05-11 01:51 . 2005-05-11 01:51 134656 c:\windows\system32\telnet.exe
+ 2007-07-22 13:15 . 2007-07-22 13:15 119296 c:\windows\system32\narrator.exe
+ 2009-06-19 16:21 . 2004-08-04 01:56 402432 c:\windows\system32\mspaint.exe
+ 2007-07-22 13:15 . 2008-05-18 21:57 147968 c:\windows\system32\msiexec.exe
+ 2007-07-22 13:14 . 2007-07-22 13:14 131584 c:\windows\system32\magnify.exe
+ 2007-07-22 13:18 . 2007-07-22 13:18 150016 c:\windows\system32\logagent.exe
+ 2009-06-19 20:18 . 2004-08-03 23:32 514048 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
+ 2007-07-22 13:18 . 2007-07-22 13:18 111616 c:\windows\system32\ie4uinit.exe
+ 2007-07-22 13:13 . 2007-07-22 13:13 155648 c:\windows\system32\cscript.exe
+ 2004-08-04 01:56 . 2004-08-04 01:56 206336 c:\windows\regedit.exe
+ 2009-06-19 20:12 . 2004-08-04 01:56 131584 c:\windows\NOTEPAD.EXE
+ 2007-07-22 13:17 . 2007-07-22 13:17 615936 c:\windows\Network Diagnostic\xpnetdiag.exe
+ 2007-07-22 13:13 . 2007-07-22 13:13 313344 c:\windows\msagent\agentsvr.exe
+ 2009-06-21 19:37 . 2009-06-21 19:37 101480 c:\windows\Installer\{2EEBAC31-3EEF-4118-91CB-1A286A507DB2}\egui.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2007-07-22 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 514048]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 514048]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\SUHAIL_10\\Desktop\\DriversBackup.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14/05/2009 03:47 م 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [14/05/2009 03:49 م 94360]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14/05/2009 03:47 م 731840]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ae/
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-22 00:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3456)
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
Completion time: 2009-06-21 0:04
ComboFix-quarantined-files.txt 2009-06-21 20:04
ComboFix2.txt 2009-06-21 19:19
Pre-Run: 21,898,108,928 bytes free
Post-Run: 21,890,113,536 bytes free
113
و هذا الهايجك
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:05:36 ص, on 22/06/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20583)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\CF29827.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\SUHAIL_10\Desktop\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O9 - Extra button: تدوين هذا في المدونة - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &تدوين هذا في Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
--
End of file - 3779 bytes