ComboFix 08-06-20.4 - asmaa 06/22/2008 13:08:49.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.54 [GMT 3:00]Running from: C:\Documents and Settings\asmaa\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\asmaa\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\asmaa\ںé¨ںم، ںéê§©«ï، 1\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\comp clup\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ں¦¢*©ں¢ ë*ه ںéه*é 2007\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ں«êںک ê¤é،\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ڑلïںه ںéں«¢¬ىں§2\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé¢ں«م\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé¢ں«م\ںé¢é¦ï*\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé¢ں«م\ں鬩¥\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé£ںêë\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé£ںêë\ڑ§يں¢ ê«ںم§،\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé£ںêë\ںé¢é¦ï*\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé£ںêë\ں鬩¥\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé«ں*م\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé«ں§«\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé«ں§«\ںé¢é¦ï*\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںé«ں§«\ں鬩¥\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںéêë¥، ںéêںéï،\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\ںéيم§\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\*©ںê¤ ںé*ي©*يïë¢\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\*©ںê¤ ںé*ي©*يïë¢\ê¤é§ ¤§ï§\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\à¥ï، ںé¢ھïïه\Desktop_.ini
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢*\ê¤é§ ¤§ï§\à¥ï، ںé¢ھïïه\ç§ ¢èيë à¥ï، é¢ھïïه ںé*©ںê¤ - ê뢧î ںéه©ں_files\Desktop_.ini
C:\Documents and Settings\asmaa\«ل¥ ںéêè¢*\ں¤ںھں¢ ںéلںé*ں¢\ں«êںک ں*ي **ï¥\Desktop_.ini
C:\WINDOWS\hosts
.
((((((((((((((((((((((((( Files Created from 2008-05-22 to 2008-06-22 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-06-22 10:12 391,712 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-22 10:12 12,776,992 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-20 16:02 --------- d-----w C:\Program Files\TuxPaint
2008-06-20 14:30 43,628 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-20 14:30 183,872 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-20 13:40 17,055 ----a-w C:\blok.exe
2008-06-20 13:40 16,751 ----a-w C:\WINDOWS\system32\drivers\hosts
2008-06-13 20:20 32,256 ----a-w C:\winhost.exe
2008-06-12 13:27 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 13:27 --------- d-----w C:\Documents and Settings\asmaa\Application Data\Malwarebytes
2008-06-12 13:27 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-06-10 16:02 34,296 ----a-w C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-10 16:02 15,864 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-06-01 06:28 --------- d-----w C:\Documents and Settings\asmaa\Application Data\U3
2008-05-27 13:35 --------- d-----w C:\Documents and Settings\asmaa\Application Data\GPass
2008-05-27 12:05 --------- d-----w C:\Documents and Settings\asmaa\Application Data\AdobeUM
2008-05-06 12:15 960 --sha-w C:\zvnja6hw.sys
2008-04-30 16:46 --------- d-----w C:\Documents and Settings\asmaa\Application Data\DMCache
2007-12-09 19:01 32,080 ----a-w C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [08/30/2007 05:43 PM 4670704]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [01/19/2007 12:55 PM 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"kis"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" [03/24/2006 08:09 PM 139367]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [01/23/2008 09:34 AM 6731312]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [01/01/2008 08:58 PM 185632]
"NvGraphicsInterface"="C:\winhost.exe" [06/13/2008 11:20 PM 32256]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 01:56 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adi alhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 6.0\\avp.exe"=
"C:\\Program Files\\Maxthon2\\Maxthon.exe"=
"c:\\winhost.exe"= C:\\winhost.exe
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{0c049538-e6db-11dc-9d38-00138f422807}]
\Shell\AutoRun\command - H:\fooool.exe
\Shell\explore\Command - H:\fooool.exe
\Shell\open\Command - H:\fooool.exe
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{137acf09-0352-11dd-849d-00138f422807}]
\Shell\AutoRun\command - H:\scvshosts.exe
\Shell\Open\command - H:\scvshosts.exe
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{feb3a92d-bd20-11dc-8210-00138f422807}]
\Shell\AutoRun\command - H:\xn1i9x.com
\Shell\explore\Command - H:\xn1i9x.com
\Shell\open\Command - H:\xn1i9x.com
*Newly Created Service* - CATCHME
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, لا يمكنك مشاهدة الرابط الى بعد الرد على الموضوع ادا لم تكن من اعضاء المنتدى الرجاء ان تقوم بالتسجيل
Rootkit scan 2008-06-22 13:12:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 06/22/2008 13:15:06
ComboFix-quarantined-files.txt 2008-06-22 10:15:02
Pre-Run: 11,186,356,224 bytes free
Post-Run: 11,587,244,032 bytes free
123 --- E O F --- 2008-02-15 15:31:48