وهدا التقرير عن طريق برنامج combofix :
ComboFix 08-08-19.05 - Administrator 08/21/2008 2:13:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.20.1025.18.69 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\Documents and Settings\Administrator\«ل¥ ںéêè¢ \ê¤é§ ¤§ï§\çé ï ںé­نï© §يë\Desktop_.ini
C:\WINDOWS\system32\msvcsv60.dll
H:\autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2008-07-20 to 2008-08-20 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-20 23:15 333 ----a-w C:\Documents and Settings\Administrator\catchme.zip
2008-08-20 21:47 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Premium Security Suite
2008-08-20 21:33 --------- d-----w C:\Program Files\Avira
2008-08-20 21:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-08-18 11:17 --------- d-----w C:\Program Files\VstPlugins
2008-08-18 11:17 --------- d-----w C:\Program Files\IK Multimedia
2008-08-18 11:17 --------- d-----w C:\Program Files\Digidesign
2008-08-18 10:41 --------- d-----w C:\Program Files\Antares
2008-08-18 09:16 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-18 09:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-18 09:12 --------- d-----w C:\Program Files\Common Files\xing shared
2008-08-18 09:12 --------- d-----w C:\Program Files\Common Files\Real
2008-08-18 09:11 --------- d-----w C:\Program Files\Real
2008-08-16 00:59 --------- d-----w C:\Program Files\Total Video Converter
2008-08-15 23:21 --------- d-----w C:\Program Files\Windows Live
2008-08-15 22:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-08-15 22:23 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2008-08-15 22:23 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-15 17:51 --------- d-----w C:\Program Files\ShadowStor
2008-08-15 17:50 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-08-15 13:26 --------- d-----w C:\Documents and Settings\Administrator\Application Data\InterTrust
2008-08-15 13:25 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-15 13:25 --------- d-----w C:\Program Files\Intel
2008-08-15 13:25 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-15 11:56 --------- d-----w C:\Program Files\Image-Line
2008-08-15 11:52 --------- d-----w C:\Program Files\microsoft frontpage
.
------- Sigcheck -------
01/27/2006 09:45 PM 576512 c287c8218dac8ee3aef1fb2018064699 C:\WINDOWS\system32\user32.dll
05/10/2006 08:25 AM 662016 4bc88c82ed023c36f906111864c16bf6 C:\WINDOWS\$hf_mig$\KB916281\SP2QFE\wininet.dll
09/12/2006 06:53 AM 663040 705a23dce4cdf6b3df8de4481250d30d C:\WINDOWS\system32\wininet.dll
05/10/2006 08:23 AM 656896 2d38385877cb32db7c3d2271d2dc84db C:\WINDOWS\system32\dllcache\wininet.dll
09/12/2006 07:22 AM 2196608 e2e05ac6e25670d9a9f592e3e223b92d C:\WINDOWS\system32\ntkrnlpa.exe
09/09/2006 02:01 AM 2321024 ef63859e4fd9cb3ec31a111481f4b1b6 C:\WINDOWS\system32\ntoskrnl.exe
09/12/2006 06:12 AM 1616384 810316e2e8d32075c8b984320a6011cf C:\WINDOWS\explorer.exe
07/01/2006 01:50 PM 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\system32\spoolsv.exe
09/12/2006 06:32 AM 125208 b79383100a456e981c5aba1bead8b035 C:\WINDOWS\system32\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" [08/31/2007 12:25 PM 323624]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [08/18/2008 12:11 PM 255528]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 04:56 AM 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"MPlayer2_FixUp"="C:\WINDOWS\inf\unregmp2.exe" [05/10/2006 02:59 AM 180736]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"NoFolderOptions"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoClose"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sunotify]
01/25/2005 09:59 PM 45056 C:\WINDOWS\system32\sunotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 08/04/2004 04:56 AM 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
-ra------ 04/05/2005 09:19 AM 77824 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
-ra------ 04/05/2005 09:22 AM 94208 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 08/16/2007 04:19 PM 5728112 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
-ra------ 04/05/2005 09:23 AM 114688 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SuNotification]
--a------ 01/28/2005 10:31 PM 114688 C:\Program Files\ShadowStor\ShadowSurfer\suatshut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 08/18/2008 12:11 PM 255528 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
--a------ 04/18/2003 02:44 PM 176128 C:\WINDOWS\system32\pctspk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\igfxtray.exe"=
"C:\\Program Files\\ShadowStor\\ShadowSurfer\\suatshut.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.323\\English\\setup.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\notepad.exe"=
"C:\\Program Files\\Adobe\\Adobe Audition 3.0\\Audition.exe"=
"C:\\Program Files\\Common Files\\Real\\Update_OB\\RealOneMessageCenter.exe"=
"C:\\Program Files\\K-Lite Codec Pack\\Media Player Classic\\mplayerc.exe"=
"C:\\Program Files\\ShadowStor\\ShadowSurfer\\ShadowSurfer.exe"=
"C:\\Program Files\\Avira\\Avira Premium Security Suite\\avgnt.exe"=
"C:\\WINDOWS\\system32\\userinit.exe"=
"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"C:\\ComboFix\\nircmd.com"=
"C:\\WINDOWS\\system32\\cmd.exe"=
R0 Shadow;Shadow;C:\WINDOWS\system32\drivers\Shadow.sys [01/25/2005 07:21 PM]
R1 avfwot;avfwot;C:\WINDOWS\system32\DRIVERS\avfwot.sys [08/30/2007 01:12 PM]
R2 AntiVirFirewallService;Avira Premium Security Suite Firewall;C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe [09/11/2007 03:55 PM]
R2 AntiVirMailService;Avira Premium Security Suite MailGuard;C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe [08/28/2007 01:08 PM]
R2 antivirwebservice;Avira Premium Security Suite WebGuard;C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE [08/14/2007 01:22 PM]
R2 AVEService;Avira Premium Security Suite MailGuard helper service;C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe [07/18/2007 08:09 AM]
R3 avfwim;AvFw Packet Filter Miniport;C:\WINDOWS\system32\DRIVERS\avfwim.sys [08/30/2007 01:12 PM]
*Newly Created Service* - ASC3360PR
.
- - - - ORPHANS REMOVED - - - -
HKLM-RunServices-raVe - (no file)
HKLM-RunServices-Driver32 - (no file)
MSConfigStartUp-kingpro - C:\WINDOWS\system32\SysRoot\king for programm.exe
MSConfigStartUp-kingpro1 - D:\WINDOWS\system32\SysRoot\king for programm.exe
MSConfigStartUp-kingpro2 - E:\WINDOWS\system32\SysRoot\king for programm.exe
MSConfigStartUp-kingpro3 - F:\WINDOWS\system32\SysRoot\king for programm.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
.
.
------- File Associations (Beta) -------
.
txtfile=NOTEPAD %1
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-21 02:16:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asc3360pr]
"ImagePath"="\??\C:\WINDOWS\system32\drivers\ehjgop.sys"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
C:\Program Files\ShadowStor\ShadowSurfer\ShadowSurfer.exe
.
**************************************************************************
.
Completion time: 08/21/2008 2:20:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-20 23:20:44
Pre-Run: 15,989,022,720 bytes free
Post-Run: 16,041,082,880 bytes free
188