أخي العزيز ،،، الحمد لله الإقلاع كان سريع والصوت رجع للجهاز وخاصية النسخ كذلك رجعت ولله الحمد والمنة والفضل لله أولا ولك ثانيا ( وربي يجزيك كل خير ويبارك بعمرك وأهلك وولدك ومالك ) وكل من مر على الموضوع وساهم فيه برأي ،،،
وهذا هو التقرير :
ComboFix 08-04-20.2 - almarri 04/21/2008 5:55:00.1 - NTFSx86
Running from: E:\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\svchost.ini
C:\WINDOWS\system32\AyFiknpo.ini
C:\WINDOWS\system32\AyFiknpo.ini2
C:\WINDOWS\system32\efcCvWOG.dll
C:\WINDOWS\system32\flivscyt.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nhatquanglan18.exe
C:\WINDOWS\system32\opnkiFyA.dll
C:\WINDOWS\system32\pmnOHwTN.dll
C:\WINDOWS\system32\SCVHSOT.exe
C:\WINDOWS\system32\setting.ini
C:\WINDOWS\system32\test1.exe
C:\WINDOWS\system32\xxyYoOFv.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-21 to 2008-04-21 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-21 02:00 0 ----a-w C:\WINDOWS\system32\drivers\lvuvc.hs
2008-04-21 01:22 --------- d-----w C:\Documents and Settings\almarri.DED-0B85697C2EF\Application Data\CyberScrub
2008-04-21 01:22 --------- d-----w C:\Documents and Settings\almarri.DED-0B85697C2EF\Application Data\cleaner
2008-04-21 00:06 --------- d-----w C:\Program Files\Trend Micro
2008-04-20 22:04 0 ----a-w C:\osy3.sys
2008-04-20 12:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-04-20 11:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\rofsfalo
2008-04-20 10:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-20 10:04 --------- d-----w C:\Program Files\SigmaTel
2008-04-20 09:47 --------- d-----w C:\Program Files\Lavalys
2008-04-20 09:40 --------- d-----w C:\Program Files\Creative
2008-04-20 09:07 --------- d-----w C:\Program Files\PC Tools AntiVirus
2008-04-20 08:30 --------- d-----w C:\Documents and Settings\almarri.DED-0B85697C2EF\Application Data\AVG7
2008-04-19 21:24 --------- d-----w C:\Program Files\FlashGet
2008-04-15 21:33 --------- d-----w C:\Program Files\Java
2008-04-15 21:28 --------- d-----w C:\Program Files\MSN Games
2008-04-15 05:13 --------- d-----w C:\Program Files\Yahoo!
2008-04-13 14:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-04-12 16:15 217,088 ----a-w C:\WINDOWS\dsktbwfe.dll
2008-04-12 16:15 188,416 ----a-w C:\WINDOWS\ogxtsepr.dll
2008-04-07 19:03 --------- d-----w C:\Documents and Settings\almarri.DED-0B85697C2EF\Application Data\Media Player Classic
2008-04-05 18:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-04-02 21:05 323,584 ----a-w C:\mojiwin.exe
2008-04-02 21:05 229,376 ----a-w C:\mojifirefox.exe
2008-04-02 21:05 167,936 ----a-w C:\mojioutlook.dll
2008-04-02 21:05 118,784 ----a-w C:\mojiim.exe
2008-04-02 21:04 --------- d-----w C:\Program Files\Mojicon
2008-04-02 21:02 --------- d-----w C:\Program Files\Mojicon Installer
2008-04-02 18:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-02 05:34 --------- d-----w C:\Documents and Settings\almarri.DED-0B85697C2EF\Application Data\uTorrent
2008-04-01 18:07 --------- d-----w C:\Program Files\GRETECH
2008-04-01 18:07 --------- d-----w C:\Documents and Settings\almarri.DED-0B85697C2EF\Application Data\GRETECH
2008-04-01 18:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\GRETECH
2008-04-01 17:54 --------- d-----w C:\Program Files\uTorrent
2008-03-22 18:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-03-09 21:17 --------- d-----w C:\Program Files\QuickTime
2008-03-09 21:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-09 21:15 --------- d-----w C:\Program Files\Apple Software Update
2008-03-09 21:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-03-07 20:09 45,056 ----a-w C:\WINDOWS\NCUNINST.EXE
2008-03-07 20:04 --------- d-----w C:\Program Files\Common Files\SWF Studio
2008-03-07 10:29 --------- d-----w C:\Program Files\Paltalk Messenger Interop
2008-03-07 04:12 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-05 18:31 --------- d-----w C:\Program Files\Paltalk Messenger
2007-05-24 20:52 0 -c--a-w C:\Documents and Settings\almarri.DED-0B85697C2EF\Application Data\wklnhst.dat
.
كود:
<pre>
----a-w 312,831 2004-03-14 12:28:06 C:\Documents and Settings\almarri.DED-0B85697C2EF\Desktop\ملفات وورد\نقل ملف الدوام في مرور البرشاء\خاص بالهويدي\g\إلعب التنس .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper ******s\{3CAB59B4-55A3-4737-9FD5-B93C6430BF75}]
04/13/2008 02:42 AM 53312 --a------ C:\WINDOWS\system32\alqtrmdh.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSVolFE.exe"="C:\Program Files\Creative\Mixer\CTSVolFE.exe" [02/23/2005 03:57 PM 57344]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [01/29/2008 10:51 PM 185896]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [03/30/2007 08:00 PM 138008]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [03/30/2007 08:00 PM 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [03/30/2007 07:59 PM 138008]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [05/10/2007 10:22 AM 405504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [03/22/2007 07:29 PM 39264]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 04:00 PM 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [04/02/2008 10:34 PM 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyYoOFv]
xxyYoOFv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Scheduler for TomMade.lnk]
backup=C:\WINDOWS\pss\Scheduler for TomMade.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 10/10/2007 07:51 PM 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
--a------ 04/02/2008 10:34 PM 579072 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 08/04/2004 04:00 PM 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 08/04/2004 04:00 PM 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
--a------ 11/15/2007 09:23 AM 202544 C:\Program Files\Dell Support Center\bin\sprtcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]
--a------ 11/07/2005 05:20 AM 122940 C:\WINDOWS\System32\DLA\DLACTRLW.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
--a------ 11/15/2007 09:24 AM 16384 C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
--a------ 09/25/2007 12:10 PM 2007088 C:\Program Files\FlashGet\FlashGet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 08/04/2004 04:00 PM 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 12/28/2005 11:56 AM 602182 C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
--a------ 12/28/2005 11:55 AM 667718 C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 08/15/2007 01:54 PM 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 07/27/2004 04:50 PM 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraAssistant]
--a------ 05/04/2006 08:24 AM 489472 C:\Program Files\Logitech\Video\CameraAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideo[inspector]]
--a------ 08/15/2007 01:55 PM 73728 C:\Program Files\Logitech\Video\InstallHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
--a------ 05/04/2006 08:59 AM 237568 C:\WINDOWS\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 10/13/2004 08:24 PM 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 01/19/2007 12:54 PM 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
--a------ 08/04/2004 04:00 PM 59392 C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 07/09/2001 11:50 AM 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder]
-ra------ 01/30/2006 08:00 PM 98304 C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTAVApp]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 08/04/2004 04:00 PM 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 08/04/2004 04:00 PM 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 01/31/2008 11:13 PM 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 07/28/2007 11:00 PM 77824 C:\Program Files\Java\jre1.6.0\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 07/25/2007 11:26 PM 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 01/29/2008 10:51 PM 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 11/03/2006 06:20 PM 866584 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Java\\jre1.6.0\\bin\\javaw.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [11/15/2007 09:23 AM]
R3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [05/04/2006 09:07 AM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{04eb008d-b36a-11dc-8e77-0018de18a5bb}]
\****l\AutoRun\command - fooool.exe
\****l\explore\Command - fooool.exe
\****l\open\Command - fooool.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2bb990e7-e814-11dc-8eed-0018de18a5bb}]
\****l\AutoRun\command - fun.exe
\****l\explore\Command - fun.exe
\****l\open\Command - fun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7446acba-a0f0-11dc-8e4e-0018de18a5bb}]
\****l\AutoRun\command - fun.exe
\****l\explore\Command - fun.exe
\****l\open\Command - fun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c147b1c0-563c-11dc-8e2d-0018de18a5bb}]
\****l\AutoRun\command - fun.exe
\****l\explore\Command - fun.exe
\****l\open\Command - fun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c2ac8144-e82c-11dc-8eee-0018de18a5bb}]
\****l\AutoRun\command - fun.exe
\****l\explore\Command - fun.exe
\****l\open\Command - fun.exe
.
*******s of the 'Scheduled Tasks' folder
"2008-03-09 21:15:47 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-20 12:08:11 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-04-21 02:03:23 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-04-13 14:15:56 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-04-21 06:00:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\stacsv.exe
C:\WINDOWS\system32\igfxsrvc.exe
.
**************************************************************************
.
Completion time: 04/21/2008 6:05:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-21 02:04:59
Pre-Run: 14,168,125,440 bytes free
Post-Run: 14,169,694,208 bytes free
240 --- E O F --- 2008-04-15 03:55:17