ComboFix 080620.4 asmaa 06/22/2008 130849.1 NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.54 [GMT 300Running from C\Documents and Settings\asmaa\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\asmaa\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\asmaa\ںé¨ںم، ںéê§©«ï، 1\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\comp clup\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ں¦¢*©ں¢ ë*ه ںéه*é 2007\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ں«êںک ê¤é،\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ڑلïںه ںéں«¢¬ىں§2\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé¢ں«م\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé¢ں«م\ںé¢é¦ï*\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé¢ں«م\ں鬩¥\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé£ںêë\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé£ںêë\ڑ§يں¢ ê«ںم§،\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé£ںêë\ںé¢é¦ï*\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé£ںêë\ں鬩¥\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé«ں*م\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé«ں§«\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé«ں§«\ںé¢é¦ï*\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé«ں§«\ں鬩¥\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںéêë¥، ںéêںéï،\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںéيم§\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\*©ںê¤ ںé*ي©*يïë¢\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\*©ںê¤ ںé*ي©*يïë¢\ê¤é§ ¤§ï§\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\à¥ï، ںé¢ھïïه\Desktop_.ini
C\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\à¥ï، ںé¢ھïïه\ç§ ¢èيë à¥ï، é¢ھïïه ںé*©ںê¤ ê뢧î ںéه©ں_files\Desktop_.ini
C\Documents and Settings\asmaa\«ل¥ ںéêè¢*\ں¤ںھں¢ ںéلںé*ں¢\ں«êںک ں*ي **ï¥\Desktop_.ini
C\WINDOWS\hosts
.
((((((((((((((((((((((((( Files Created from 20080522 to 20080622 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
20080622 1012 391,712 shaw C\WINDOWS\system32\drivers\fidbox2.dat
20080622 1012 12,776,992 shaw C\WINDOWS\system32\drivers\fidbox.dat
20080620 1602 dw C\Program Files\TuxPaint
20080620 1430 43,628 shaw C\WINDOWS\system32\drivers\fidbox2.idx
20080620 1430 183,872 shaw C\WINDOWS\system32\drivers\fidbox.idx
20080620 1340 17,055 aw C\blok.exe
20080620 1340 16,751 aw C\WINDOWS\system32\drivers\hosts
20080613 2020 32,256 aw C\winhost.exe
20080612 1327 dw C\Program Files\Malwarebytes' AntiMalware
20080612 1327 dw C\Documents and Settings\asmaa\Application Data\Malwarebytes
20080612 1327 dw C\Documents and Settings\All s.WINDOWS\Application Data\Malwarebytes
20080610 1602 34,296 aw C\WINDOWS\system32\drivers\mbamcatchme.sys
20080610 1602 15,864 aw C\WINDOWS\system32\drivers\mbam.sys
20080601 0628 dw C\Documents and Settings\asmaa\Application Data\U3
20080527 1335 dw C\Documents and Settings\asmaa\Application Data\GPass
20080527 1205 dw C\Documents and Settings\asmaa\Application Data\AdobeUM
20080506 1215 960 shaw C\zvnja6hw.sys
20080430 1646 dw C\Documents and Settings\asmaa\Application Data\DMCache
20071209 1901 32,080 aw C\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries amp; legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_\\Microsoft\Windows\Curre ntVersion\Run
quot;CTFMON.EXEquot;=quot;C\WINDOWS\system32\ctfmon.exequot; [08/04/2004 0156 AM 15360
quot;Yahoo! Pagerquot;=quot;C\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXEquot; [08/30/2007 0543 PM 4670704
quot;msnmsgrquot;=quot;C\Program Files\MSN Messenger\msnmsgr.exequot; [01/19/2007 1255 PM 5674352
[HKEY_LOCAL_MACHINE\\Microsoft\Windows\Curr entVersion\Run
quot;kisquot;=quot;C\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exequot; [03/24/2006 0809 PM 139367
quot;!AVG AntiSpywarequot;=quot;C\Program Files\Grisoft\AVG AntiSpyware 7.5\avgas.exequot; [01/23/2008 0934 AM 6731312
quot;TkBellExequot;=quot;C\Program Files\Common Files\Real\Update_OB\realsched.exequot; [01/01/2008 0858 PM 185632
quot;NvGraphicsInterfacequot;=quot;C\winhost.exequot; [06/13/2008 1120 PM 32256
[HKEY_S\.DEFAULT\\Microsoft\Windows\Cur rentVersion\Run
quot;CTFMON.EXEquot;=quot;C\WINDOWS\system32\CTFMON.EXEquot; [08/04/2004 0156 AM 15360
[HKEY_LOCAL_MACHINE\\microsoft\windows nt\currentversion\windows
quot;AppInit_DLLsquot;=C\PROGRA~1\KASPER~1\KASPER~1.0\adi alhk.dll
[HKEY_LOCAL_MACHINE\\microsoft\windows nt\currentversion\drivers32
quot;msacm.l3acmquot;= l3codecp.acm
[HKEY_LOCAL_MACHINE\\microsoft\security center
quot;AntiVirusDisableNotifyquot;=dword00000001
quot;UpdatesDisableNotifyquot;=dword00000001
quot;AntiVirusOverridequot;=dword00000001
[HKEY_LOCAL_MACHINE\\microsoft\security center\Monitoring\KasperskyAntiVirus
quot;DisableMonitoringquot;=dword00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List
quot;%windir%\\system32\\sessmgr.exequot;=
quot;C\\Program Files\\Messenger\\msmsgs.exequot;=
quot;C\\Program Files\\MSN Messenger\\msnmsgr.exequot;=
quot;C\\Program Files\\MSN Messenger\\livecall.exequot;=
quot;C\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exequot;=
quot;C\\Program Files\\Yahoo!\\Messenger\\YServer.exequot;=
quot;C\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 6.0\\avp.exequot;=
quot;C\\Program Files\\Maxthon2\\Maxthon.exequot;=
quot;c\\winhost.exequot;= C\\winhost.exe
[HKEY_CURRENT_\\microsoft\windows\curre ntversion\explorer\mountpoints2\{0c049538e6db11dc9d3800138f422807
\Shell\AutoRun\command H\fooool.exe
\Shell\explore\Command H\fooool.exe
\Shell\\Command H\fooool.exe
[HKEY_CURRENT_\\microsoft\windows\curre ntversion\explorer\mountpoints2\{137acf09035211dd849d00138f422807
\Shell\AutoRun\command H\scvshosts.exe
\Shell\\command H\scvshosts.exe
[HKEY_CURRENT_\\microsoft\windows\curre ntversion\explorer\mountpoints2\{feb3a92dbd2011dc821000138f422807
\Shell\AutoRun\command H\xn1i9x.com
\Shell\explore\Command H\xn1i9x.com
\Shell\\Command H\xn1i9x.com
*Newly Created Service* CATCHME
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista rootkit/stealth malware detector by Gmer, لا يمكنك مشاهدة الرابط الى بعد الرد على الموضوع ادا لم تكن من اعضاء المنتدى الرجاء ان تقوم بالتسجيل
Rootkit scan 20080622 131243
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files 0
************************************************** ************************
.
Completion time 06/22/2008 131506
ComboFixquarantinedfiles.txt 20080622 101502
PreRun 11,186,356,224 bytes free
PostRun 11,587,244,032 bytes free
123 E O F 20080215 153148