عملة اول أداة طلع عندي هذا التقرير
ComboFix 08-05-29.1 - sadeq ahmad 06/01/2008 1:37:23.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.88 [GMT 3:00]
Running from: C:\Documents and Settings\sadeq ahmad\My Documents\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\autorun.inf
C:\Documents and Settings\2006\Local Settings\Application Data\inetinfo.exe
C:\Documents and Settings\2006\Local Settings\Application Data\lsass.exe
C:\Documents and Settings\2006\Local Settings\Application Data\services.exe
C:\Documents and Settings\sadeq ahmad\Application Data\macromedia\Flash Player\#Shareds\8398Y953\iforex.com
C:\Documents and Settings\sadeq ahmad\Application Data\macromedia\Flash Player\#Shareds\8398Y953\iforex.com\Emerp\Events\flash_.swf\user_data.sol
C:\Documents and Settings\sadeq ahmad\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\sadeq ahmad\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\WINDOWS\artools.dll
C:\WINDOWS\system32\agsaame.dll
C:\WINDOWS\system32\ALOQuickTimeFile.dll
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-31 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-31 22:28 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
2008-05-27 02:45 --------- d-----w C:\Documents and Settings\sadeq ahmad\Application Data\Chicaimreal
2008-05-27 02:44 --------- d-----w C:\Program Files\Chicaimreal
2008-05-27 02:44 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Bait nurb roam real
2008-05-23 00:50 780,288 ----a-w C:\WINDOWS\system32\ALOVideoCompress.dll
2008-05-23 00:50 753,664 ----a-w C:\WINDOWS\system32\agsaamg.dll
2008-05-23 00:50 626,688 ----a-w C:\WINDOWS\system32\agsaamh.dll
2008-05-23 00:50 18,628,608 ----a-w C:\WINDOWS\system32\viscomavi.dll
2008-05-22 11:46 1,245,184 ----a-w C:\WINDOWS\system32\bkll.dll
2008-05-21 15:18 --------- d-----w C:\Program Files\PrtSc
2008-05-19 08:00 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
2008-05-17 22:59 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-05-13 03:59 --------- d-----w C:\Program Files\MSN Messenger
2008-05-13 03:57 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WLInstaller
2008-05-13 02:14 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-05-13 02:14 --------- d-----w C:\Program Files\Circle Developement
2008-05-07 22:50 --------- d-----w C:\Documents and Settings\sadeq ahmad\Application Data\DeskSoft
2008-05-07 22:32 47,251 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-05-07 22:32 2,145 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-05-06 16:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Disk Cleaner
2008-05-06 16:47 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Registry Helper
2008-05-04 08:07 --------- d-----w C:\Program Files\JetAudio
2008-05-03 18:08 --------- d-----w C:\Program Files\Common Files\COWON
2008-05-02 20:01 --------- d-----w C:\Documents and Settings\2006\Application Data\storeglue
2008-05-02 12:51 --------- d-----w C:\Program Files\LtUcx
2008-05-02 11:39 --------- d-----w C:\Program Files\Common Files\Softwin
2008-05-02 11:38 --------- d-----w C:\Program Files\Softwin
2008-05-01 16:28 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype
2008-04-20 08:27 344,064 ----a-w C:\WINDOWS\system32\dkll.dll
2008-04-20 08:27 196,608 ----a-w C:\WINDOWS\system32\maag.dll
2008-04-20 08:27 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-04-20 08:27 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2008-04-16 19:04 --------- d-----w C:\Documents and Settings\sadeq ahmad\Application Data\skypePM
2008-04-14 18:30 7,680 ----a-w C:\WINDOWS\system32\spdwnwxp.exe
2008-04-14 18:30 32,866 ----a-w C:\WINDOWS\system32\slrundll.exe
2008-04-14 18:30 32,768 ----a-w C:\WINDOWS\system32\setupn.exe
2008-04-14 18:30 28,672 ----a-w C:\WINDOWS\system32\verclsid.exe
2008-04-14 18:30 20,992 ----a-w C:\WINDOWS\system32\spupdwxp.exe
2008-04-14 18:30 176,128 ----a-w C:\WINDOWS\system32\napstat.exe
2008-04-14 18:28 6,144 ----a-w C:\WINDOWS\system32\kbdpash.dll
2008-04-14 18:28 6,144 ----a-w C:\WINDOWS\system32\kbdnepr.dll
2008-04-14 18:28 6,144 ----a-w C:\WINDOWS\system32\kbdiultn.dll
2008-04-14 18:28 6,144 ----a-w C:\WINDOWS\system32\kbdbhc.dll
2008-04-14 18:10 71,680 ----a-w C:\WINDOWS\system32\msxml6r.dll
2008-04-14 18:09 72,704 ----a-w C:\WINDOWS\system32\msshavmsg.dll
2008-04-14 18:04 700,928 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-04-14 18:04 326,912 ----a-w C:\WINDOWS\system32\drivers\ati2mtaa.sys
2008-04-14 07:52 --------- d-----w C:\Documents and Settings\sadeq ahmad\Application Data\Uniblue
2008-04-13 21:13 9,728 ----a-w C:\WINDOWS\system32\comsdupd.exe
2008-04-13 21:10 10,240 ----a-w C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-04-13 20:53 95,424 ----a-w C:\WINDOWS\system32\drivers\slnthal.sys
2008-04-13 20:53 404,990 ----a-w C:\WINDOWS\system32\drivers\slntamr.sys
2008-04-13 20:53 180,360 ----a-w C:\WINDOWS\system32\drivers\ntmtlfax.sys
2008-04-13 20:53 13,776 ----a-w C:\WINDOWS\system32\drivers\recagent.sys
2008-04-13 20:53 13,240 ----a-w C:\WINDOWS\system32\drivers\slwdmsup.sys
2008-04-13 20:53 129,535 ----a-w C:\WINDOWS\system32\drivers\slnt7554.sys
2008-04-13 20:53 126,686 ----a-w C:\WINDOWS\system32\drivers\mtlmnt5.sys
2008-04-13 20:53 1,309,184 ----a-w C:\WINDOWS\system32\drivers\mtlstrm.sys
2008-04-13 19:06 144,384 ----a-w C:\WINDOWS\system32\drivers\hdaudbus.sys
2008-04-10 17:13 --------- d-----w C:\Program Files\Google
2008-04-09 16:43 --------- d-----w C:\Program Files\Java
2008-04-09 16:34 --------- d-----w C:\Program Files\Common Files\Java
2008-04-08 02:01 --------- d-----w C:\Program Files\edFullEditor1.3
2008-04-07 00:41 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-06 04:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-05 22:33 --------- d-----w C:\Program Files\Armor2net
2008-03-17 22:37 32 ----a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\ezsid.dat
2008-02-16 17:18 82 ----a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\SUMQU0C1-FE20-APII-YE7M-BEDSDWMY5R6A.dat
2008-02-08 00:56 155,995 ----a-w C:\WINDOWS\java\Packages\G3HNHZLV.ZIP
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [10/18/2007 11:34 AM 5724184]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [04/14/2008 09:30 PM 1695232]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [08/30/2007 05:43 PM 4670704]
"error road"="C:\DOCUME~1\SADEQA~1\APPLIC~1\CHICAI~1\GplRdrLive.exe" [05/27/2008 05:43 AM 406016]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [04/11/2008 01:00 AM 68856]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"Registry Helper"="C:\Program Files\Registry Helper\RegistryHelper.exe" [ ]
"Disk Cleaner"="C:\Program Files\Disk Cleaner\DiskCleaner.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [12/25/2007 04:36 AM 185896]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [02/07/2007 04:24 PM 71216]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [02/07/2007 04:21 PM 54832]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04/27/2007 09:41 AM 282624]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM 144784]
"ROAM REAL CLOSE OBJ"="C:\Documents and Settings\All Users.WINDOWS\Application Data\Bait nurb roam real\copy logo.exe" [06/01/2008 01:29 AM 622592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
C:\Documents and Settings\sadeq ahmad\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Stardock Dock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\Dock\Dock.exe [2005-02-21 16:56:00 1826885]
Y'z ToolBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe [2002-09-29 16:41:00 90112]
C:\Documents and Settings\All Users.WINDOWS\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-07-10 00:43:06 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yv12"= yv12vfw.dll
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\
000.fcl [11/02/2006 04:51 PM]
.
s of the 'Scheduled Tasks' folder
"2008-05-31 22:00:03 C:\WINDOWS\Tasks\A70E4F969185C90E.job"
- c:\docume~1\sadeqa~1\applic~1\chicai~1\Remote loud blah.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-06-01 01:39:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\
000.fcl"
.
Completion time: 06/01/2008 1:44:03
ComboFix-quarantined-files.txt 2008-05-31 22:43:38
Pre-Run: 14,821,871,616 bytes free
Post-Run: 14,814,932,992 bytes free
165 --- E O F --- 2008-05-31 06:26:18