تقرير الأداة
ComboFix 08-08-29.02 - ابوحسام 08/30/2008 17:18:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.1655 [GMT 2:00]
Running from: C:\Documents and Settings\ابوحسام\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\kk3.bat
C:\rs.cmd
C:\WINDOWS\system32\ckvo.exe
C:\WINDOWS\system32\ckvo0.dll
C:\WINDOWS\system32\ckvo1.dll
D:\Autorun.inf
D:\kk3.bat
D:\rs.cmd
E:\Autorun.inf
E:\kk3.bat
E:\rs.cmd
F:\Autorun.inf
F:\kk3.bat
F:\rs.cmd
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-30 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-30 15:19 --------- d-----w C:\Documents and Settings\ابوحسام\Application Data\DMCache
2008-08-30 14:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-30 14:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-30 11:26 --------- d-----w C:\Documents and Settings\ابوحسام\Application Data\ooVoo Details
2008-08-30 11:06 --------- d-----w C:\Documents and Settings\ابوحسام\Application Data\Media Player Classic
2008-08-30 10:28 --------- d-----w C:\Documents and Settings\ابوحسام\Application Data\IDM
2008-08-30 09:59 --------- d-----w C:\Program Files\Windows Live
2008-08-30 09:52 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-30 09:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-30 09:28 155,995 ----a-w C:\WINDOWS\java\Packages\8WDJZF5F.ZIP
2008-08-30 09:28 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-30 09:28 --------- d-----w C:\Program Files\oovooToolbar
2008-08-30 09:28 --------- d-----w C:\Program Files\ooVoo
2008-08-30 09:28 --------- d-----w C:\Documents and Settings\ابوحسام\Application Data\oovooToolbar
2008-08-30 09:27 --------- d-----w C:\Program Files\Internet Download Manager
2008-08-30 09:26 --------- d-----w C:\Program Files\Marah
2008-08-30 09:25 --------- d-----w C:\Program Files\Real
2008-08-30 09:25 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-30 09:25 --------- d-----w C:\Program Files\Common Files\xing shared
2008-08-30 09:25 --------- d-----w C:\Program Files\Common Files\Real
2008-08-30 09:23 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-30 09:21 --------- d-----w C:\Program Files\VistaDrives
2008-08-30 09:11 --------- d-----w C:\Program Files\Norton Internet Security
2008-08-30 06:20 --------- d-----w C:\Program Files\Counter-Strike 1.6
2008-08-30 05:48 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-08-30 05:48 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-08-30 05:48 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-08-30 05:48 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-08-30 05:48 --------- d-----w C:\Program Files\Symantec
2008-08-30 05:21 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-08-30 05:21 --------- d-----w C:\Program Files\Realtek
2008-08-30 05:21 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-30 05:06 --------- d-----w C:\Program Files\microsoft frontpage
2008-08-29 19:51 91,084 --sh--r C:\ph.com
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{A057A204-BACC-4D26-8087-36EE87E26986}]
07/29/2008 09:56 PM 1987544 --a------ C:\PROGRA~1\OOVOOT~1\OOVOOT~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-8087-36EE87E26986}"= "C:\PROGRA~1\OOVOOT~1\OOVOOT~1.DLL" [07/29/2008 09:56 PM 1987544]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-8087-36ee87e26986}]
[HKEY_CLASSES_ROOT\oovooToolbar.OOVOOTOOLBAR]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-8087-36EE87E26986}"= "C:\PROGRA~1\OOVOOT~1\OOVOOT~1.DLL" [07/29/2008 09:56 PM 1987544]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-8087-36ee87e26986}]
[HKEY_CLASSES_ROOT\oovooToolbar.OOVOOTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [02/20/2008 04:13 PM 2594224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [01/09/2007 11:59 PM 115816]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [01/14/2007 01:11 AM 771704]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [01/29/2008 05:38 PM 583048]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [09/16/2007 07:07 PM 8491008]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [09/16/2007 07:07 PM 81920]
"Vistadrv"="C:\Program Files\VistaDrives\vsdrv.exe" [07/30/2006 03:37 AM 121089]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [08/30/2008 11:25 AM 185896]
"nwiz"="nwiz.exe" [09/16/2007 07:07 PM 1626112 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\oovoo.exe]
--a------ 08/17/2008 04:42 PM 13498160 C:\Program Files\ooVoo\ooVoo.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 05/03/2005 12:43 PM 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 10/25/2007 05:57 AM 16855552 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
-ra------ 10/11/2007 05:04 AM 1826816 C:\WINDOWS\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\ooVoo\\ooVoo.exe"=
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;C:\WINDOWS\system32\DRIVERS\l251x86.sys [10/17/2007 02:12 PM]
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-08-30 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - ابوحسام.job
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe [01/14/2007 03:09 AM]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\ابوحسام\Application Data\Mozilla\Firefox\Profiles\hb19ia46.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-30 17:19:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 08/30/2008 17:21:11
ComboFix-quarantined-files.txt 2008-08-30 15:20:52
Pre-Run: 34,031,345,664 bytes free
Post-Run: 34,020,507,648 bytes free
152