ودة التقرير
ComboFix 08-08-23.03 - KaRieMo 08/24/2008 21:44:46.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.285 [GMT 3:00]
Running from: C:\Documents and Settings\KaRieMo.KIMOO\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\ADSTechnology
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\ADSTechnology\ADSTechnology.lnk
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\ADSTechnology\Uninstall.lnk
C:\Program Files\ActivationManager
C:\Program Files\ActivationManager\Uninstall.exe
C:\Program Files\ADSTechnology
C:\Program Files\ADSTechnology\Uninstall.exe
.
((((((((((((((((((((((((( Files Created from 2008-07-24 to 2008-08-24 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-24 18:49 --------- d-----w C:\Documents and Settings\KaRieMo.KIMOO\Application Data\DMCache
2008-08-24 18:46 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-08-24 18:42 --------- d-----w C:\Documents and Settings\KaRieMo.KIMOO\Application Data\uTorrent
2008-08-24 18:23 --------- d-----w C:\Program Files\Trend Micro
2008-08-24 17:17 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-24 17:15 --------- d-----w C:\Program Files\MPEG2_Decoders
2008-08-24 17:14 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-08-24 17:10 823,296 ----a-w C:\WINDOWS\isRS-000.tmp
2008-08-24 17:07 --------- d-----w C:\Program Files\DVBPortal
2008-08-24 11:45 --------- d-----w C:\Program Files\uTorrent
2008-08-24 09:23 --------- d-----w C:\Program Files\SpeedFan
2008-08-23 23:16 --------- d-----w C:\Program Files\Nokia
2008-08-23 23:15 --------- d-----w C:\Documents and Settings\KaRieMo.KIMOO\Application Data\Skype
2008-08-23 23:14 --------- d-----w C:\Documents and Settings\KaRieMo.KIMOO\Application Data\skypePM
2008-08-23 20:55 --------- d-----w C:\Documents and Settings\KaRieMo.KIMOO\Application Data\Nokia
2008-08-23 12:27 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-08-23 12:27 --------- d-----w C:\Program Files\Common Files\Nokia
2008-08-23 12:26 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-08-23 12:25 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Installations
2008-08-22 23:38 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-08-22 23:38 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-08-22 23:38 --------- d-----w C:\Documents and Settings\KaRieMo.KIMOO\Application Data\PC Suite
2008-08-22 23:31 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Suite
2008-08-22 23:30 --------- d-----w C:\Program Files\DIFX
2008-08-22 23:02 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-22 11:41 --------- d-----w C:\Program Files\Internet Download Manager
2008-08-22 11:33 --------- d-----w C:\Program Files\Skype
2008-08-22 11:33 --------- d-----w C:\Program Files\Google
2008-08-22 11:33 --------- d-----w C:\Program Files\Common Files\Skype
2008-08-22 11:33 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype
2008-08-22 11:31 --------- d-----w C:\Documents and Settings\KaRieMo.KIMOO\Application Data\IDM
2008-08-21 22:30 --------- d-----w C:\Documents and Settings\KaRieMo.KIMOO\Application Data\ACD Systems
2008-08-21 22:27 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\TechSmith
2008-08-21 22:26 --------- d-----w C:\Program Files\TechSmith
2008-08-21 22:26 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-08-21 22:25 --------- d-----w C:\Program Files\ACD Systems
2008-08-21 22:25 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\ACD Systems
2008-08-21 22:24 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-21 21:33 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus!
2008-08-21 12:58 --------- d-----w C:\Program Files\Ahead
2008-08-21 11:55 --------- d-----w C:\Documents and Settings\KaRieMo.KIMOO\Application Data\Talkback
2008-08-21 11:14 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-08-21 11:13 --------- d-----w C:\Program Files\Windows Live
2008-08-21 11:13 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo!
2008-08-21 11:12 --------- d-----w C:\Program Files\Yahoo!
2008-08-21 10:22 --------- d-----w C:\Program Files\MagicISO
2008-08-21 09:40 --------- d-----w C:\Documents and Settings\KaRieMo.KIMOO\Application Data\Ahead
2008-08-21 09:39 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-21 09:33 --------- d-----w C:\Program Files\Common Files\LightScribe
2008-08-21 09:17 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2008-08-21 09:17 --------- d-----w C:\Documents and Settings\KaRieMo.KIMOO\Application Data\Media Player Classic
2008-08-21 09:16 --------- d-----w C:\Program Files\Microsoft IntelliType Pro
2008-08-21 09:12 --------- d-----w C:\Program Files\Symantec
2008-08-21 09:12 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec
2008-08-21 09:10 --------- d-----w C:\Program Files\Your Uninstaller 2008
2008-08-21 09:08 --------- d-----w C:\Documents and Settings\KaRieMo.KIMOO\Application Data\URSoft
2008-08-21 07:34 --------- d-----w C:\Program Files\Common Files\Ahead
2008-08-21 07:31 --------- d-----w C:\Program Files\Nero
2008-08-21 02:11 --------- d-----w C:\Program Files\MSBuild
2008-08-21 02:06 --------- d-----w C:\Program Files\Reference Assemblies
2008-08-21 01:52 --------- d-----w C:\Program Files\WIDCOMM
2008-08-21 01:51 --------- d-----w C:\Program Files\Elaborate Bytes
2008-08-21 01:29 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-25 08:34 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-07-25 08:34 683,520 ----a-w C:\WINDOWS\system32\divx.dll
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-21 12:11 24,392 ----a-w C:\WINDOWS\system32\drivers\ElbyCDIO.sys
2008-07-17 00:12 28,672 ----a-w C:\WINDOWS\system32\drivers\VClone.sys
2008-07-14 16:52 80,840 ----a-w C:\WINDOWS\system32\ElbyVCD.dll
2008-07-09 14:34 206,256 ----a-w C:\WINDOWS\system32\idmmbc.dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-29 18:48 311,128 ----a-w C:\WINDOWS\system32\libssl32.dll
2008-06-29 18:48 1,526,468 ----a-w C:\WINDOWS\system32\libeay32.dll
2008-06-26 11:06 93,128 ----a-w C:\WINDOWS\system32\ElbyCDIO.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:09 666,112 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-12 18:36 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 03:00 PM 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [03/02/2007 02:27 PM 149040]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [08/09/2006 03:41 PM 4617720]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [08/22/2008 02:33 PM 171448]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" [08/11/2008 08:31 AM 1124352]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [08/24/2008 02:52 PM 267056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VirtualCloneDrive"="C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [06/30/2008 01:01 AM 52168]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [05/29/2007 04:33 PM 52840]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [04/17/2005 12:30 PM 85184]
"itype"="c:\Program Files\Microsoft IntelliType Pro\itype.exe" [08/31/2007 12:13 PM 988584]
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [08/31/2007 12:01 PM 1037736]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 11:50 AM 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 03:00 PM 15360]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-12 13:33:22 581693]
SnagIt 9.lnk - C:\Program Files\TechSmith\SnagIt 9\SnagIt32.exe [2008-05-15 16:49:44 6822728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\KaRieMo.KIMOO\Application Data\Mozilla\Firefox\Profiles\sbairji7.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF -: plugin - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-24 21:49:39
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\EraserUtilDrv10821]
"ImagePath"="\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10821.sys"
.
Completion time: 08/24/2008 22:06:32
ComboFix-quarantined-files.txt 2008-08-24 19:05:22
Pre-Run: 2,979,934,208 bytes free
Post-Run: 3,222,847,488 bytes free
171 --- E O F --- 2008-08-23 12:48:36
معلش بتعبك معايا