hesham77 الله يعطيك العافيه وماتقصر عساك ع القوه
وهذا تقرير الكومبو فوكس
ComboFix 09-07-25.08 - asus F3E 07/26/2009 2:23.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.1015.500 [GMT 3:00]
Running from: c:\documents and settings\asus F3E\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\acovcnt.exe
.
((((((((((((((((((((((((( Files Created from 2009-06-25 to 2009-07-25 )))))))))))))))))))))))))))))))
.
2009-07-25 22:17 . 2009-07-25 22:17 -------- d-----w- c:\windows\LastGood
2009-07-25 21:12 . 2009-07-25 21:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-07-25 03:50 . 2009-03-24 13:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-07-25 03:50 . 2009-07-25 12:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-07-25 01:13 . 2009-07-25 01:13 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2009-07-25 01:13 . 2009-07-25 01:13 29208 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2009-07-25 01:13 . 2009-07-25 01:13 -------- d-----w- c:\program files\AVG
2009-07-20 12:54 . 2009-07-20 12:54 -------- d-----w- c:\windows\system32\wbem\Repository
2009-07-20 12:26 . 2009-07-20 12:59 -------- d-----w- c:\program files\VS Revo Group
2009-06-28 22:14 . 2009-06-28 22:14 -------- d-----w- c:\documents and settings\asus F3E\Application Data\Malwarebytes
2009-06-28 22:14 . 2009-06-28 22:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-28 21:34 . 2009-06-28 21:34 -------- d-----w- c:\program files\Windows Media Connect 2
2009-06-28 21:33 . 2009-06-28 21:34 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-06-28 21:33 . 2009-06-28 21:33 -------- d-----w- c:\windows\system32\LogFiles
2009-06-28 12:16 . 2009-06-28 12:16 -------- d-----w- c:\program files\Saree PC Cleaner 2
2009-06-27 22:52 . 2009-07-25 21:44 -------- d-----w- c:\documents and settings\asus F3E\Tracing
2009-06-27 22:49 . 2009-06-27 22:49 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-06-27 22:48 . 2006-11-29 10:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-06-27 22:48 . 2009-06-27 22:48 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-06-27 22:46 . 2009-06-27 22:46 -------- d-----w- c:\program files\Microsoft
2009-06-27 22:45 . 2009-06-27 22:45 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-06-27 22:45 . 2009-06-27 22:52 -------- d-----w- c:\program files\Windows Live
2009-06-27 22:28 . 2009-06-27 22:28 -------- d-----w- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-25 21:48 . 2001-09-19 11:00 59878 ----a-w- c:\windows\system32\perfc001.dat
2009-07-25 21:48 . 2001-09-19 11:00 331342 ----a-w- c:\windows\system32\perfh001.dat
2009-07-25 21:42 . 2009-06-28 10:33 -------- d-----w- c:\documents and settings\asus F3E\Application Data\cleaner
2009-07-20 13:03 . 2009-04-30 13:47 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-07-18 22:05 . 2009-04-30 14:57 -------- d-----w- c:\documents and settings\asus F3E\Application Data\Any Video Converter
2009-07-02 04:44 . 2009-05-06 13:16 -------- d-----w- c:\documents and settings\asus F3E\Application Data\dvdcss
2009-06-28 10:33 . 2009-06-28 10:33 -------- d-----w- c:\documents and settings\asus F3E\Application Data\CyberScrub
2009-06-27 22:20 . 2009-04-30 14:29 -------- d-----w- c:\program files\GVR
2009-06-21 00:40 . 2009-06-21 00:12 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8ls
2009-06-20 20:15 . 2009-06-20 20:15 390664 ----a-w- c:\documents and settings\asus F3E\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
2009-06-10 15:11 . 2009-06-09 22:06 -------- d-----w- c:\program files\Absolute MP3 Splitter
2009-05-27 21:17 . 2009-05-27 21:11 -------- d-----w- c:\program files\eTeSoft Video Converter
2009-05-27 20:56 . 2009-05-27 20:56 -------- d-----w- c:\program files\SMPlayer
2009-05-25 01:09 . 2009-04-21 07:07 99496 ----a-w- c:\documents and settings\asus F3E\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-08 21:35 . 2009-05-08 21:35 14566424 ----a-w- c:\windows\system32\vlc-0.9.4-win32.exe
2009-04-30 14:31 . 2009-04-30 13:36 6971424 --sha-w- c:\windows\system32\drivers\fidbox.dat
.
------- Sigcheck -------
[-] 2008-04-01 08:03 1547776 DABAD58A8BA625B241B90FB1A81154ED c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Secure Disks]
@="{666C7836-A9B6-4AB4-94ED-DC238C81E925}"
[HKEY_CLASSES_ROOT\CLSID\{666C7836-A9B6-4AB4-94ED-DC238C81E925}]
2006-10-29 16:35 391168 ----a-r- c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\SFSShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"MultiFrame"="c:\program files\ASUS\Asus MultiFrame\MultiFrame.exe" [2007-06-21 999792]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2007-07-05 1040384]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-03 198160]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-15 815104]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-08-10 573440]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-08-11 137752]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-19 110592]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11776]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-06-01 823296]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-06-01 974848]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-08-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-08-11 166424]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"CognizanceTS"="c:\progra~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll" [2003-12-24 17920]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2007-07-03 7708672]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"ATKHOTKEY"="c:\program files\ATK Hotkey\Hcontrol.exe" [2007-06-29 225280]
"ASUS Screen Saver Protector"="c:\windows\ASScrPro.exe" [2009-04-21 33136]
"ASUS Live Update"="c:\program files\ASUS\ASUS Live Update\ALU.exe" [2007-07-19 49520]
"ASUS Camera ScreenSaver"="c:\windows\ASScrProlog.exe" [2009-04-21 37232]
"ACMON"="c:\program files\ASUS\Splendid\ACMON.exe" [2007-06-26 851968]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-19 2879488]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-11-17 16270848]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-4-21 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-5-22 2756608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2007-02-09 17:30 74240 ----a-r- c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\APSHook.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli ASWLNPkg
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [06/02/2009 02:23 م 106208]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [06/02/2009 02:24 م 93336]
R1 ItSDisk;ItSDisk;c:\windows\system32\drivers\itsdisk.sys [19/05/2006 08:14 م 23232]
R2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe -k Cognizance [03/08/2004 11:56 م 14336]
R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Cognizance [03/08/2004 11:56 م 14336]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [21/04/2009 08:57 ص 36864]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [25/07/2009 04:13 ص 29208]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [25/07/2009 04:13 ص 29208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker ASChannel
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
.
.
------- File Associations -------
.
txtfile=c:\windows\notepad.exe %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-26 02:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1044)
c:\windows\system32\APSHook.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\ItMsg.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\TrayIcon.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\brand.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsChnl.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItDAC.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItReports.DLL
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\BioAuth.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASBioAT.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItVCClient.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AuthWiz.dll
c:\windows\system32\igfxdev.dll
- - - - - - - > 'lsass.exe'(1292)
c:\windows\system32\APSHook.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\ASWLNPkg.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\ItMsg.dll
.
Completion time: 2009-07-25 2:27
ComboFix-quarantined-files.txt 2009-07-25 23:27
Pre-Run: 51,851,640,832 bytes free
Post-Run: 52,085,252,096 bytes free
182