هذا التقرير اخوي
ComboFix 09-07-29.03 - Administrator 07/30/2009 2:04.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.1014.677 [GMT 3:00]
Running from: d:\فحص الجهاز\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\ed185.msp
c:\windows\Installer\ed186.msp
c:\windows\Installer\ed187.msp
c:\windows\Installer\ed188.msp
c:\windows\Installer\ed189.msp
c:\windows\Installer\ed18a.msp
c:\windows\Installer\ed18b.msp
c:\windows\Installer\ed18c.msp
c:\windows\Installer\ed18d.msp
c:\windows\linkinfo.dll
c:\windows\system32\drivers\cdralw.sys
c:\windows\system32\wmdrtc32.dl_
c:\windows\system32\wmdrtc32.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Legacy_CDRALW
-------\Service_asc3360pr
-------\Service_cdralw
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-29 )))))))))))))))))))))))))))))))
.
2009-07-21 13:17 . 2009-07-21 13:18 -------- d-----w- c:\documents and settings\Administrator\Application Data\IDM
2009-07-21 13:15 . 2009-07-21 13:15 -------- d-----w- c:\program files\TechSmith
2009-07-21 13:12 . 2009-07-21 13:12 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-07-21 12:40 . 2004-08-03 20:07 6400 -c--a-w- c:\windows\system32\dllcache\splitter.sys
2009-07-21 12:40 . 2004-08-03 20:07 6400 ----a-w- c:\windows\system32\drivers\splitter.sys
2009-07-21 12:40 . 2004-08-03 20:15 82944 -c--a-w- c:\windows\system32\dllcache\wdmaud.sys
2009-07-21 12:40 . 2004-08-03 20:15 82944 ----a-w- c:\windows\system32\drivers\wdmaud.sys
2009-07-21 12:40 . 2004-08-03 20:07 52864 -c--a-w- c:\windows\system32\dllcache\dmusic.sys
2009-07-21 12:40 . 2004-08-03 20:07 52864 ----a-w- c:\windows\system32\drivers\DMusic.sys
2009-07-21 12:40 . 2001-08-17 11:00 54272 -c--a-w- c:\windows\system32\dllcache\swmidi.sys
2009-07-21 12:40 . 2001-08-17 11:00 54272 ----a-w- c:\windows\system32\drivers\swmidi.sys
2009-07-21 12:40 . 2004-08-03 19:39 142464 -c--a-w- c:\windows\system32\dllcache\aec.sys
2009-07-21 12:40 . 2004-08-03 19:39 142464 ----a-w- c:\windows\system32\drivers\aec.sys
2009-07-21 12:40 . 2004-08-03 20:07 171776 -c--a-w- c:\windows\system32\dllcache\kmixer.sys
2009-07-21 12:40 . 2004-08-03 20:07 171776 ----a-w- c:\windows\system32\drivers\kmixer.sys
2009-07-21 12:33 . 2005-11-16 05:41 114688 ----a-r- c:\windows\system32\Uci32103.dll
2009-07-21 12:33 . 2009-07-21 12:33 -------- d-----w- c:\program files\CONEXANT
2009-07-21 12:33 . 2005-10-05 04:57 12544 ----a-r- c:\windows\system32\drivers\mdmxsdk.sys
2009-07-21 12:33 . 2005-10-05 04:56 86016 ----a-r- c:\windows\system32\mdmxsdk.dll
2009-07-21 12:33 . 2005-12-01 07:40 936960 ----a-r- c:\windows\system32\drivers\HSX_DPV.sys
2009-07-21 12:33 . 2005-12-01 07:40 192512 ----a-r- c:\windows\system32\drivers\HSXHWAZL.sys
2009-07-21 12:33 . 2005-12-01 07:40 669696 ----a-r- c:\windows\system32\drivers\HSX_CNXT.sys
2009-07-21 12:33 . 2004-08-03 21:55 4096 -c--a-w- c:\windows\system32\dllcache\ksuser.dll
2009-07-21 12:33 . 2004-08-03 21:55 4096 ----a-w- c:\windows\system32\ksuser.dll
2009-07-21 12:33 . 2004-08-03 20:08 60288 -c--a-w- c:\windows\system32\dllcache\drmk.sys
2009-07-21 12:33 . 2004-08-03 20:08 60288 ----a-w- c:\windows\system32\drivers\drmk.sys
2009-07-21 12:29 . 2009-07-21 12:29 -------- d-----w- c:\windows\system32\vmm32
2009-07-21 12:09 . 2009-07-21 12:09 -------- d-----w- c:\program files\No-IP
2009-07-21 12:02 . 2009-07-21 12:02 -------- d-----w- c:\documents and settings\All Users\Application Data\TechSmith
2009-07-20 12:16 . 2009-07-21 12:02 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\TechSmith
2009-07-20 12:16 . 2009-07-20 12:16 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-07-20 12:16 . 2008-07-10 10:56 107864 ----a-w- c:\windows\system32\tsccvid.dll
2009-07-20 12:16 . 2009-07-20 12:16 -------- d-----w- c:\windows\system32\QuickTime
2009-07-20 12:15 . 2009-07-20 12:15 -------- d-----w- c:\windows\system32\Flash
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-01-02 20:43 . 2009-07-20 11:13 77176 ----a-w- c:\windows\Fonts\SC_OUHOD.ttf
2016-12-30 15:03 . 2009-07-20 11:13 63168 ----a-w- c:\windows\Fonts\SC_HANI.ttf
2016-12-30 15:02 . 2009-07-20 11:13 75820 ----a-w- c:\windows\Fonts\SC_DUBAI.ttf
2009-07-29 23:08 . 2009-07-21 13:17 -------- d-----w- c:\documents and settings\Administrator\Application Data\DMCache
2009-07-29 23:05 . 2001-09-19 10:00 52520 ----a-w- c:\windows\system32\perfc001.dat
2009-07-29 23:05 . 2001-09-19 10:00 280548 ----a-w- c:\windows\system32\perfh001.dat
2009-07-21 13:17 . 2009-07-21 13:17 198064 ----a-w- c:\documents and settings\Administrator\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-07-21 12:39 . 2009-07-21 12:39 -------- d-----w- c:\program files\SigmaTel
2009-07-21 12:29 . 2009-07-20 09:37 -------- d-----w- c:\program files\Dell
2009-07-21 12:28 . 2009-07-20 10:06 -------- d-----w- c:\program files\Creative
2009-07-21 12:27 . 2009-07-20 10:10 5477 ----a-w- c:\windows\system32\drivers\ltmjun.sys
2009-07-21 12:17 . 2009-07-20 10:51 -------- d-----w- c:\documents and settings\Administrator\Application Data\Skype
2009-07-20 11:16 . 2009-07-20 11:16 16299862 ------w- C:\$Persi0.sys
2009-07-20 11:16 . 2009-07-20 11:16 -------- d-----w- c:\program files\Faronics
2009-07-20 11:14 . 2009-07-20 11:14 -------- d-----w- c:\program files\Windows Live
2009-07-20 11:14 . 2009-07-20 11:14 -------- d-----w- c:\program files\Messenger Plus! Live
2009-07-20 11:14 . 2009-07-20 10:44 -------- d-----w- c:\program files\MSN Messenger
2009-07-20 11:14 . 2009-07-20 11:09 129064 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-20 11:13 . 2009-07-20 11:13 -------- d-----w- c:\program files\Internet Download Manager
2009-07-20 11:13 . 2009-07-20 11:13 -------- d-----w- c:\program files\.Tonec Inc
2009-07-20 10:57 . 2009-07-20 10:57 -------- d-----w- c:\program files\Microsoft.NET
2009-07-20 10:52 . 2009-07-20 10:52 -------- d-----w- c:\program files\Paltalk Messenger
2009-07-20 10:52 . 2009-07-20 10:52 -------- d-----w- c:\documents and settings\Administrator\Application Data\Paltalk
2009-07-20 10:51 . 2009-07-20 10:51 -------- d-----w- c:\program files\Common Files\Skype
2009-07-20 10:51 . 2009-07-20 10:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-07-20 10:51 . 2009-07-20 10:51 -------- d-----w- c:\program files\Skype
2009-07-20 10:50 . 2009-07-20 10:50 -------- d-----w- c:\program files\mpegable
2009-07-20 10:50 . 2009-07-20 10:50 47104 ------w- c:\windows\AKDeInstall.exe
2009-07-20 10:49 . 2009-07-20 09:03 2048 --s-a-w- c:\windows\bootstet.dat
2009-07-20 10:35 . 2009-07-20 10:34 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-07-20 10:34 . 2009-07-20 10:34 -------- d-----w- c:\documents and settings\All Users\Application Data\ACD Systems
2009-07-20 10:34 . 2009-07-20 10:34 -------- d-----w- c:\program files\ACD Systems
2009-07-20 10:32 . 2009-07-20 10:31 -------- d-----w- c:\program files\The KMPlayer
2009-07-20 10:30 . 2009-07-20 10:30 -------- d-----w- c:\program files\Google
2009-07-20 10:30 . 2009-07-20 10:30 -------- d-----w- c:\program files\GRETECH
2009-07-20 10:29 . 2009-07-20 10:29 0 ----a-w- c:\windows\nsreg.dat
2009-07-20 10:27 . 2009-07-20 10:27 -------- d-----w- c:\program files\Yahoo!
2009-07-20 10:18 . 2009-07-20 10:19 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-20 10:18 . 2009-07-20 10:18 -------- d-----w- c:\program files\Java
2009-07-20 10:13 . 2009-07-20 10:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\vlc
2009-07-20 10:12 . 2009-07-20 10:11 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-07-20 10:11 . 2009-07-20 10:11 -------- d-----w- c:\program files\VideoLAN
2009-07-20 10:06 . 2009-07-20 09:46 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-20 09:53 . 2009-07-20 09:53 -------- d-----w- c:\program files\Marvell
2009-07-20 09:53 . 2009-07-20 09:37 -------- d-----w- c:\program files\Common Files\InstallShield
2009-07-20 09:53 . 2009-07-20 09:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\TMP
2009-07-20 09:44 . 2009-07-20 09:44 -------- d-----w- c:\program files\Intel
2009-07-20 09:42 . 2009-07-20 09:42 -------- d-----w- c:\program files\Broadcom
2009-07-20 09:35 . 2009-07-20 09:35 -------- d-----w- c:\program files\WIDCOMM
2009-07-20 09:01 . 2009-07-20 09:01 -------- d-----w- c:\program files\microsoft frontpage
2009-07-20 09:00 . 2009-07-20 09:00 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-20 08:57 . 2009-07-20 08:57 22144 ----a-w- c:\windows\system32\emptyregdb.dat
2009-01-20 05:18 . 2009-07-20 10:28 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
------- Sigcheck -------
[-] 2008-01-07 15:15 1547776 D74083DCEC51D5291EF24D8D055D133A c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-05-27 2815408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653]
Snagit 9.lnk - c:\program files\TechSmith\Snagit 9\Snagit32.exe [2009-4-17 7226184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DfLogon]
2007-06-28 17:39 65536 ----a-w- c:\windows\system32\LogonDll.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /k:C /k

*
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalStart.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\PalStart.lnk
backup=c:\windows\pss\PalStart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Snagit 9.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Snagit 9.lnk
backup=c:\windows\pss\Snagit 9.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\تعريفات جهازي\\MyDrivers.exe"=
"d:\\تعريف الصوت مجرب\\تعريف الصوت للديل.exe"=
"c:\\WINDOWS\\system32\\WLTRAY.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"d:\\برامج1430هـ\\snagit9.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\jqsnotify.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 DeepFrz;DeepFrz;c:\windows\system32\drivers\DeepFrz.sys [28/06/2007 08:45 م 131472]
R0 ulsata2;ulsata2;c:\windows\system32\drivers\ulsata2.sys [07/01/2008 11:19 ص 124928]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\v9k6xppv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sa/
FF - component: c:\documents and settings\Administrator\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-30 02:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(548)
c:\windows\system32\LogonDll.dll
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(2656)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\TechSmith\Snagit 9\TscHelp.exe
c:\program files\WIDCOMM\Bluetooth Software\BTStackServer.exe
c:\program files\TechSmith\Snagit 9\SnagPriv.exe
c:\program files\TechSmith\Snagit 9\SnagitEditor.exe
c:\program files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-29 2:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-29 23:10
Pre-Run: 15,799,488,512 bytes free
Post-Run: 15,790,407,680 bytes free
218