الاول
ComboFix 08-06-12.2 - Administrator 06/14/2008 14:45:29.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.554 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\RECYCLER\Administrator.com
C:\WINDOWS\system32\kakle.dll
D:\Autorun.inf
D:\RECYCLER\Administrator.com
E:\Autorun.inf
E:\RECYCLER\Administrator.com
.
((((((((((((((((((((((((( Files Created from 2008-05-14 to 2008-06-14 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-14 07:45 --------- d-----w C:\Documents and Settings\Administrator\Application Data\BitDefender
2008-06-14 07:44 --------- d-----w C:\Program Files\Common Files\BitDefender
2008-06-14 07:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\BitDefender
2008-06-14 07:38 0 ----a-w C:\osy3.sys
2008-06-11 13:14 --------- d-----w C:\Program Files\Total Video Converter
2008-06-11 11:40 96,520 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-11 11:40 75,272 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-11 11:40 12,424 ----a-w C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-06-11 11:40 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-06-11 11:40 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-06-11 11:38 45,568 ----a-w C:\WINDOWS\system32\avgfwdx.dll
2008-06-11 11:38 22,528 ----a-w C:\WINDOWS\system32\drivers\avgfwdx.sys
2008-06-11 11:38 --------- d-----w C:\Program Files\AVG
2008-06-11 11:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-06-09 05:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-06-07 06:24 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Thinstall
2008-05-21 17:46 14,336 ----a-w C:\Program Files\Book1.xls
2008-05-06 03:32 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-05-04 03:13 --------- d-----w C:\Documents and Settings\Administrator\Application Data\U3
2008-05-03 22:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trymedia
2008-05-03 22:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\MumboJumbo
2008-05-03 16:20 --------- d-----w C:\Program Files\Common Files\xing shared
2008-05-03 16:11 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2008-05-03 16:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-05-03 16:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-05-03 16:03 90,112 ----a-w C:\WINDOWS\system32\agsaami.dll
2008-05-03 16:03 610,304 ----a-w C:\WINDOWS\system32\agsaamg.dll
2008-05-03 16:03 372,736 ----a-w C:\WINDOWS\system32\agsaamc.dll
2008-05-03 16:03 2,535,424 ----a-w C:\WINDOWS\system32\agsaamj.dll
2008-05-03 16:03 196,608 ----a-w C:\WINDOWS\system32\maag.dll
2008-05-03 16:03 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-05-03 16:03 1,245,184 ----a-w C:\WINDOWS\system32\bkll.dll
2008-05-03 16:03 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2008-05-03 16:03 --------- d-----w C:\Program Files\Real_SC
2008-05-03 16:02 --------- d-----w C:\Program Files\Windows Live
2008-05-03 16:02 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-05-03 16:02 --------- d-----w C:\Program Files\Luxor 2
2008-05-03 16:02 --------- d-----w C:\Program Files\BFG
2008-05-03 15:59 --------- d-----w C:\Program Files\GRETECH
2008-05-03 15:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\GRETECH
2008-05-03 15:59 --------- d-----w C:\Documents and Settings\Administrator\Application Data\GRETECH
2008-05-03 15:57 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-03 15:56 298,104 ----a-w C:\WINDOWS\system32\imon.dll
2008-05-03 15:55 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ACD Systems
2008-05-03 15:54 --------- d-----w C:\Program Files\mpegable
2008-05-03 15:54 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-05-03 15:54 --------- d-----w C:\Program Files\ACD Systems
2008-05-03 15:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-05-03 15:53 --------- d-----w C:\Program Files\Video Convert Master Christmas Edition
2008-05-03 15:50 --------- d-----w C:\Program Files\MSN Messenger
2008-05-03 15:49 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-05-03 15:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-05-03 15:45 --------- d-----w C:\Program Files\Real
2008-05-03 15:45 --------- d-----w C:\Program Files\Common Files\Real
2008-05-03 15:44 155,995 ----a-w C:\WINDOWS\java\Packages\FNDBN1NR.ZIP
2008-05-03 15:44 --------- d-----w C:\Program Files\Yahoo!
2008-05-03 15:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-05-03 15:43 --------- d-----w C:\Program Files\Macromedia
2008-05-03 15:42 50,688 ----a-w C:\WINDOWS\system32\wbhelp2.dll
2008-05-03 15:42 --------- d-----w C:\Program Files\Google
2008-05-03 15:42 --------- d-----w C:\Program Files\DAP
2008-05-03 15:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-03 15:30 --------- d-----w C:\Program Files\CONEXANT
2008-05-03 13:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-03 13:52 --------- d-----w C:\Program Files\Realtek
2008-05-03 13:52 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-03 13:51 --------- d-----w C:\Program Files\Intel
2008-05-03 13:38 --------- d-----w C:\Program Files\Microsoft.NET
2008-05-03 13:38 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-05-03 13:38 --------- d-----w C:\Program Files\Common Files\L&H
2008-05-03 13:37 --------- d-----w C:\Program Files\Microsoft Works
2008-05-03 13:26 --------- d-----w C:\Program Files\microsoft frontpage
2008-02-25 18:51 61,952 --sha-r C:\WINDOWS\system32\KUW-A9EB02A4C50.com
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/03/2004 11:56 PM 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [05/08/2008 05:28 AM 68856]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [01/19/2007 12:55 PM 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [02/07/2006 03:39 AM 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [02/07/2006 03:36 AM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [02/07/2006 03:40 AM 118784]
"SkyTel"="SkyTel.EXE" [05/17/2006 05:04 AM 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [11/15/2006 04:21 AM 16270848 C:\WINDOWS\RTHDCPL.exe]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.exe" [05/03/2008 06:42 PM 4568576]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM 39792]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05/03/2008 07:20 PM 185896]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/03/2004 11:56 PM 110592 C:\WINDOWS\system32\bthprops.cpl]
"Karen"="" []
"raVe"="" []
"SystemInit"="" []
"startIE"="" []
"Win32BaseServiceMOD"="" []
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [06/11/2008 02:40 PM 1177368]
"Administrator"="C:\WINDOWS\RECYCLER\Administrator.com" [ ]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [ ]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [ ]
"RRT-Auto"="C:\Documents and Settings\Administrator\Desktop\RRT.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"raVe"="" []
"Driver32"="" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/03/2004 11:56 PM 15360]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-08-03 11:10:00 394856]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
"DisableTaskmgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
"NoFind"= 0 (0x0)
"NoRun"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe KUW-A9EB02A4C50.com"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll,avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XVID"= xvid.dll
"VIDC.YV12"= yv12vfw.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [06/11/2008 02:40 PM]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [06/11/2008 02:40 PM]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [06/11/2008 02:40 PM]
R2 avgfws8;AVG8 Firewall;C:\PROGRA~1\AVG\AVG8\avgfws8.exe [06/11/2008 02:40 PM]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [06/11/2008 02:40 PM]
R3 Avgfwdx;Avgfwdx;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [06/11/2008 02:38 PM]
S3 Avgfwfd;AVG network filter service;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [06/11/2008 02:38 PM]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [07/05/2006 03:35 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{797a2db6-1987-11dd-adbf-0019d167f2b6}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{797a2db7-1987-11dd-adbf-0019d167f2b6}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Administrator.com
\Shell\open\command - I:\Administrator.com
\Shell\read\command - I:\Administrator.com
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-06-14 14:48:26
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\KUW-A9EB02A4C50.com
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\KUW-A9EB02A4C50.com
.
**************************************************************************
.
Completion time: 06/14/2008 14:49:55 - machine was rebooted [Administrator]
ComboFix-quarantined-files.txt 2008-06-14 11:49:52
Pre-Run: 12,479,676,416 bytes free
Post-Run: 12,490,145,792 bytes free
217