التقريررررر
ComboFix 08-08-11.01 - Administrator 08/12/2008 15:12:35.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.2035 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\macromedia\Flash Player\#Shareds\LZLNYHBL\interclick.com
C:\Documents and Settings\Administrator\Application Data\macromedia\Flash Player\#Shareds\LZLNYHBL\interclick.com\ud.sol
C:\Documents and Settings\Administrator\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Administrator\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
.
((((((((((((((((((((((((( Files Created from 2008-07-12 to 2008-08-12 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-12 12:14 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-08-12 12:14 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DMCache
2008-08-12 11:59 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CyberScrub
2008-08-12 11:55 --------- d-----w C:\Documents and Settings\Administrator\Application Data\cleaner
2008-08-12 10:55 --------- d-----w C:\Program Files\Internet Download Manager
2008-08-12 07:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\BitDefender
2008-08-12 07:27 --------- d-----w C:\Documents and Settings\Administrator\Application Data\BitDefender
2008-08-11 10:39 --------- d-----w C:\Program Files\Hotspot Shield
2008-08-11 10:39 --------- d-----w C:\Program Files\Ashampoo
2008-08-11 08:57 --------- d-----w C:\Program Files\Common Files\BitDefender
2008-08-11 08:57 --------- d-----w C:\Program Files\BitDefender
2008-08-10 20:04 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-10 18:56 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-10 17:35 --------- d-----w C:\Program Files\a-squared Anti-Malware
2008-08-10 11:01 --------- d-----w C:\Program Files\Mayoko
2008-08-09 19:22 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-08-09 19:22 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-08-09 18:22 --------- d-----w C:\Program Files\VerbAce Research
2008-08-09 17:26 --------- d-----w C:\Program Files\Windows Sidebar
2008-08-09 15:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-08-09 12:11 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-09 11:07 --------- d-----w C:\Program Files\microsoft frontpage
2008-08-09 10:25 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-09 10:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-09 10:24 --------- d-----w C:\Program Files\BitComet
2008-08-09 10:24 --------- d-----w C:\Documents and Settings\Administrator\Application Data\COWON
2008-08-07 13:00 --------- d-----w C:\Program Files\Mv2Player
2008-08-07 12:17 --------- d-----w C:\Program Files\JAP
2008-08-07 03:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-08-07 00:12 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ESET
2008-08-07 00:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-08-07 00:01 --------- d-----w C:\Program Files\Windows Live
2008-08-06 11:34 46,536 ----a-w C:\WINDOWS\system32\drivers\MiniIcpt.sys
2008-08-05 10:55 --------- d-----w C:\Program Files\Hotspot_Shield
2008-08-05 10:55 --------- d-----w C:\Program Files\Conduit
2008-08-05 09:56 --------- d-----w C:\Program Files\JavaSoft
2008-08-05 01:05 --------- d-----w C:\Program Files\WinAVI VideoConverter
2008-08-04 05:25 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-08-04 05:17 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-04 05:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-04 01:00 --------- d-----w C:\Documents and Settings\Administrator\Application Data\IDM
2008-08-02 09:47 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-08-02 08:57 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Thinstall
2008-08-02 00:33 155,995 ----a-w C:\WINDOWS\java\Packages\HVTNTZXN.ZIP
2008-08-02 00:28 172,032 ------w C:\WINDOWS\Setup1.exe
2008-08-02 00:28 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-08-02 00:27 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-08-02 00:27 --------- d-----w C:\Program Files\Google
2008-08-02 00:27 --------- d-----w C:\Program Files\DivX
2008-08-02 00:26 --------- d-----w C:\Program Files\Abuwalid
2008-08-02 00:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-08-01 23:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-08-01 23:05 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-08-01 22:12 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-08-01 22:11 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-01 22:07 --------- d-----w C:\Program Files\UltraISO
2008-08-01 22:07 --------- d-----w C:\Program Files\Common Files\EZB Systems
2008-08-01 22:03 --------- d-----w C:\Program Files\Real
2008-08-01 22:03 --------- d-----w C:\Program Files\Common Files\xing shared
2008-08-01 22:03 --------- d-----w C:\Program Files\Common Files\Real
2008-08-01 22:00 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-01 21:59 --------- d-----w C:\Program Files\AAQ
2008-08-01 21:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\GRETECH
2008-08-01 21:59 --------- d-----w C:\Documents and Settings\Administrator\Application Data\GRETECH
2008-08-01 21:58 --------- d-----w C:\Program Files\GRETECH
2008-08-01 21:44 --------- d-----w C:\Program Files\Microsoft.NET
2008-08-01 21:41 --------- d-----w C:\Program Files\USB Disk Security
2008-08-01 21:41 --------- d-----w C:\Program Files\Uninstaller 2008
2008-08-01 21:41 --------- d-----w C:\Program Files\Total Video Converter
2008-08-01 21:41 --------- d-----w C:\Program Files\ImageShack
2008-08-01 21:41 --------- d-----w C:\Program Files\Foxit Reader
2008-08-01 21:41 --------- d-----w C:\Program Files\dictionary
2008-08-01 21:41 --------- d-----w C:\Program Files\CCleaner
2008-08-01 21:41 --------- d-----w C:\Program Files\Avant Browser
2008-08-01 21:41 --------- d-----w C:\Program Files\Ava Find
2008-08-01 21:41 --------- d-----w C:\Program Files\Adobe Photoshop CS
2008-07-18 18:39 586,240 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-07-09 14:34 206,256 ----a-w C:\WINDOWS\system32\idmmbc.dll
2008-07-03 19:34 2,833,920 ----a-w C:\WINDOWS\system32\logonui.exe
2008-07-03 04:13 70,144 ----a-w C:\WINDOWS\system32\notepad.exe
2008-07-03 04:13 70,144 ----a-w C:\WINDOWS\NOTEPAD.EXE
2008-07-01 20:13 8,192 ----a-w C:\WINDOWS\system32\streamci.dll
2008-07-01 19:52 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-07-01 19:52 139,264 ----a-w C:\WINDOWS\system32\sfc_os.dll
2008-07-01 19:48 1,297,408 ----a-w C:\WINDOWS\system32\syssetup.dll
2008-07-01 02:56 3,134,464 ----a-w C:\WINDOWS\system32\msgina.dll
2008-07-01 02:56 1,550,336 ----a-w C:\WINDOWS\explorer.exe
2008-07-01 02:56 1,098,752 ----a-w C:\WINDOWS\system32\shimgvw.dll
2008-07-01 02:54 883,200 ----a-w C:\WINDOWS\system32\wiaacmgr.exe
2008-07-01 02:54 769,024 ----a-w C:\WINDOWS\system32\wiashext.dll
2008-07-01 02:54 290,816 ----a-w C:\WINDOWS\system32\winsrv.dll
2008-07-01 02:53 905,216 ----a-w C:\WINDOWS\system32\zipfldr.dll
2008-07-01 02:53 594,432 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-07-01 02:53 384,000 ----a-w C:\WINDOWS\system32\themeui.dll
2008-07-01 02:53 218,624 ----a-w C:\WINDOWS\system32\taskmgr.exe
2008-07-01 02:53 192,512 ----a-w C:\WINDOWS\system32\sndvol32.exe
2008-07-01 02:53 182,272 ----a-w C:\WINDOWS\system32\sysocmgr.exe
2008-07-01 02:53 180,224 ----a-w C:\WINDOWS\system32\sndrec32.exe
2008-07-01 02:53 152,576 ----a-w C:\WINDOWS\system32\st.dll
2008-07-01 02:53 1,230,848 ----a-w C:\WINDOWS\system32\rasdlg.dll
.
------- Sigcheck -------
07/01/2008 05:56 AM 1550336 8b32164ba0d813886f00724795f47eb6 C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/15/2008 03:00 PM 15360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [07/14/2008 05:42 PM 2606512]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DrvIcon"="C:\WINDOWS\VistaDrives\DrvIcon.exe" [07/04/2007 09:59 PM 45056]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [12/05/2006 11:54 PM 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [12/05/2006 11:54 PM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [12/05/2006 11:54 PM 118784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [08/02/2008 01:03 AM 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [06/12/2008 02:38 AM 34672]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [10/09/2007 04:46 PM 61440]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [05/23/2008 07:16 PM 368640]
"RTHDCPL"="RTHDCPL.EXE" [12/05/2006 11:55 PM 16005120 C:\WINDOWS\RTHDCPL.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [12/05/2006 11:54 PM 88204 C:\WINDOWS\AGRSMMSG.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"WIAWizardMenu"="C:\WINDOWS\system32\sti_ci.dll" [04/15/2008 03:00 PM 136192]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/15/2008 03:00 PM 15360]
C:\Documents and Settings\Administrator\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Thaker.lnk - C:\Program Files\zaker\Thaker.exe [2008-08-02 00:40:16 1343488]
C:\Documents and Settings\Administrator\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Thaker.lnk - C:\Program Files\zaker\Thaker.exe [2008-08-02 00:40:16 1343488]
C:\Documents and Settings\Administrator\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Thaker.lnk - C:\Program Files\zaker\Thaker.exe [2008-08-02 00:40:16 1343488]
C:\Documents and Settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
VerbAce-Pro Startup Agent.lnk - C:\Program Files\VerbAce Research\VerbAce-Pro\VerbAce-Pro.exe [2008-08-09 21:22:21 229376]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11677:TCP"= 11677:TCP:BitComet 11677 TCP
"11677:UDP"= 11677:UDP:BitComet 11677 UDP
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [06/02/2008 04:16 PM]
R3 lv321av;Logitech USB PC Camera (VC0321);C:\WINDOWS\system32\DRIVERS\lv321av.sys [12/05/2006 11:54 PM]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [01/24/2008 12:25 AM]
S3 DrvFltIp;DrvFltIp;C:\Documents and Settings\Administrator\Local Settings\TEMP\DrvFltIp []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-08-11 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Administrator.job
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe []
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-FortKnoxPersonalFirewall - C:\Program Files\NETGATE\FortKnox Personal Firewall 2008\FortKnoxGUI.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.sa/
R1 -: HKCU-Internet Settings,ProxyOverride = local;<local>
R1 -: HKCU-Internet Settings,ProxyServer = 127.0.0.1:4001
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/keyword/%s
O8 -: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 -: Backward &Links - C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 -: Cac&hed Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 -: Si&milar Pages - C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 -: Translate into English - C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 -: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 -: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 -: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O16 -: Microsoft XML Parser for Java -
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-12 15:14:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\C:\Documents and Settings\Administrator\Local Settings\TEMP\ASFWHide"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\DrvFltIp]
"ImagePath"="\??\C:\Documents and Settings\Administrator\Local Settings\TEMP\DrvFltIp"
.
Completion time: 08/12/2008 15:15:53
ComboFix-quarantined-files.txt 2008-08-12 12:15:50
Pre-Run: 64,920,944,640 bytes free
Post-Run: 64,912,707,584 bytes free
227 --- E O F --- 2008-08-07 13:29:44
وكتب الملف تم حذفه ؟