هذا الاول ياقلبي
ComboFix 09-07-27.02 - m88x 08/05/2009 1:02.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.446.182 [GMT -7:00]
Running from: d:\كل شي\جديدك\جديدك\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Autorun.inf
D:\1f.bat
D:\2.bat
D:\2a.exe
D:\2fiy.bat
D:\2nuk.com
D:\3j2h0tf.bat
D:\8dtyjjf.exe
D:\8paf1d.com
D:\9dlvtiil.exe
D:\9kretct.exe
D:\Autorun.inf
D:\cj1m.com
D:\cv8j.exe
D:\d9c.bat
D:\dbrxubcw.com
D:\e2.cmd
D:\ej10fkdo.bat
D:\eyt.exe
D:\fbak.exe
D:\fsaht.cmd
D:\g1ljsm.com
D:\gbm6n.exe
D:\gclwpivc.cmd
D:\gi2ky.exe
D:\hifdmgt.com
D:\i6g6x.cmd
D:\ix8bmwx.bat
D:\lc.exe
D:\m.com
D:\metdgv.bat
D:\n68mqcra.exe
D:\nu.cmd
D:\o.exe
D:\p.exe
D:\q0dhfjf.exe
D:\q1alx.exe
D:\sv8c2bjw.bat
D:\vwewav8.com
D:\xbvv6o.com
D:\xdglur.bat
D:\xs6kpr0.exe
D:\xsia.bat
D:\yhh.bat
D:\ymxf2.exe
D:\ysep1.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_AVPsys
((((((((((((((((((((((((( Files Created from 2009-07-05 to 2009-08-05 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-05 07:49 . 2009-08-05 07:49 108489 --sh--r- C:\mb9x.exe
2009-08-05 07:40 . 2009-08-05 07:40 27264 ----a-w- c:\documents and settings\m88x\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 07:40 . 2009-08-05 07:40 -------- d-----w- c:\documents and settings\m88x\Application Data\ATI
2009-08-05 07:38 . 2009-08-05 07:38 -------- d-----w- c:\program files\Launch Manager
2009-08-05 07:37 . 2009-08-05 07:37 -------- d-----w- c:\program files\Atheros
2009-08-05 07:37 . 2009-08-05 07:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-05 07:36 . 2009-08-05 07:36 -------- d-----w- c:\program files\Broadcom
2009-08-05 07:35 . 2009-08-05 07:35 -------- d-----w- c:\program files\DIFX
2009-08-05 07:34 . 2009-08-05 07:34 -------- d-----w- c:\program files\CONEXANT
2009-08-05 07:31 . 2009-08-05 07:31 -------- d-----w- c:\program files\Realtek
2009-08-05 07:26 . 2009-08-05 07:22 -------- d-----w- c:\program files\ATI Technologies
2009-08-05 07:26 . 2009-08-05 07:21 -------- d-----w- c:\program files\Common Files\InstallShield
2009-08-05 07:13 . 2009-08-05 07:13 -------- d-----w- c:\program files\microsoft frontpage
2009-08-05 07:12 . 2009-08-05 07:12 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-08-05 07:09 . 2009-08-05 07:09 21640 ----a-w- c:\windows\system32\emptyregdb.dat
.
------- Sigcheck -------
[-] 2009-03-02 11:52 1580544 32272BF10467C8ACF1F83138C61D541E c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-08-16 53248]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-08-16 1236992]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2006-09-07 479232]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-08-16 16248320]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-08-16 2879488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-INPROCOMMWireless - c:\program files\Atheros\Wireless\Utility\WlanUtil.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
.
**************************************************************************
driver loading error catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-08-05 01:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(580)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
Completion time: 2009-08-05 1:05
ComboFix-quarantined-files.txt 2009-08-05 08:05
Pre-Run: 37,249,937,408 bytes free
Post-Run: 37,231,755,264 bytes free
131