تقرير ComboFix
ComboFix 08-09-05.11 - qatar 09/09/2008 15:25:35.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1256.1.1033.18.1319 [GMT 1:00]
Running from: C:\Users\qatar\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-08-09 to 2008-09-09 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-09 13:58 --------- d-----w C:\ProgramData\Kaspersky Lab
2008-09-09 13:56 327,712 --sha-w C:\Windows\system32\drivers\fidbox2.dat
2008-09-09 13:56 25,424 --sha-w C:\Windows\system32\drivers\fidbox.idx
2008-09-09 13:56 2,981,920 --sha-w C:\Windows\system32\drivers\fidbox.dat
2008-09-09 13:56 2,200 --sha-w C:\Windows\system32\drivers\fidbox2.idx
2008-09-09 13:49 --------- d-----w C:\ProgramData\Messenger Plus!
2008-09-09 13:33 --------- d-----w C:\Program Files\Windows Live
2008-09-09 13:33 --------- d-----w C:\Program Files\MSN Messenger
2008-09-09 13:33 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-09 13:21 --------- dc-h--w C:\ProgramData\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}
2008-09-09 13:21 --------- d-----w C:\Users\qatar\AppData\Roaming\Uniblue
2008-09-09 13:20 --------- d-----w C:\Program Files\Uniblue
2008-09-09 13:19 --------- d-----w C:\Program Files\IObit
2008-09-09 12:58 96,976 ----a-w C:\Windows\system32\drivers\klin.dat
2008-09-09 12:28 87,855 ----a-w C:\Windows\system32\drivers\klick.dat
2008-09-09 10:19 27,335 ----a-w C:\Users\qatar\AppData\Roaming\nvModes.dat
2008-09-09 03:15 174 --sha-w C:\Program Files\desktop.ini
2008-09-09 03:08 --------- d-----w C:\Program Files\Windows Sidebar
2008-09-09 03:08 --------- d-----w C:\Program Files\Windows Mail
2008-09-09 03:08 --------- d-----w C:\Program Files\Windows Defender
2008-09-09 03:08 --------- d-----w C:\Program Files\Windows Calendar
2008-09-09 02:49 61,440 ----a-w C:\Windows\System32\winipsec.dll
2008-09-09 02:49 361,984 ----a-w C:\Windows\System32\IPSECSVC.DLL
2008-09-09 02:49 28,672 ----a-w C:\Windows\System32\FwRemoteSvr.dll
2008-09-09 02:49 272,896 ----a-w C:\Windows\System32\polstore.dll
2008-09-09 02:47 87,040 ----a-w C:\Windows\System32\msoert2.dll
2008-09-09 02:46 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-09-09 02:46 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-09-09 02:45 49,664 ----a-w C:\Windows\System32\csrsrv.dll
2008-09-09 02:45 376,320 ----a-w C:\Windows\System32\winsrv.dll
2008-09-09 02:41 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys
2008-09-09 02:41 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-09-09 02:40 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-09-09 02:39 414,208 ----a-w C:\Windows\System32\msscp.dll
2008-09-09 02:39 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll
2008-09-09 02:36 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-09-09 02:36 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-09-09 02:36 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-09-09 02:36 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-09-09 02:36 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-09-09 02:36 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-09-09 02:36 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
2008-09-09 02:36 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-09-09 02:35 2,048 ----a-w C:\Windows\System32\msxml3r.dll
2008-09-09 02:35 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
2008-09-09 02:33 9,892,864 ----a-w C:\Windows\System32\NlsLexicons000a.dll
2008-09-09 02:31 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-09-09 02:31 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-09-09 02:30 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-09-09 02:30 29,184 ----a-w C:\Windows\system32\drivers\BTHUSB.SYS
2008-09-09 02:30 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-09-09 02:30 220,160 ----a-w C:\Windows\system32\drivers\bthport.sys
2008-09-09 02:30 19,456 ----a-w C:\Windows\system32\drivers\bthenum.sys
2008-09-09 02:30 181,760 ----a-w C:\Windows\System32\fsquirt.exe
2008-09-09 02:29 944,184 ----a-w C:\Windows\System32\winload.exe
2008-09-09 02:29 905,400 ----a-w C:\Windows\System32\winresume.exe
2008-09-09 02:29 620,088 ----a-w C:\Windows\System32\ci.dll
2008-09-09 02:29 613,888 ----a-w C:\Windows\System32\wpd_ci.dll
2008-09-09 02:29 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-09-09 02:29 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-09-09 02:29 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-09-09 02:29 224,824 ----a-w C:\Windows\System32\clfs.sys
2008-09-09 02:29 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-09-09 02:29 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-09-09 02:29 1,585,664 ----a-w C:\Windows\System32\setupapi.dll
2008-09-09 02:27 82,432 ----a-w C:\Windows\system32\drivers\sdbus.sys
2008-09-09 02:27 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-09-09 02:26 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2008-09-09 02:26 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-09-09 02:26 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-09-09 02:26 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2008-09-09 02:26 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-09-09 02:26 2,048 ----a-w C:\Windows\System32\asferror.dll
2008-09-09 02:26 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-09-09 02:25 61,440 ----a-w C:\Windows\System32\ntprint.exe
2008-09-09 02:25 269,824 ----a-w C:\Windows\System32\schannel.dll
2008-09-09 02:25 220,160 ----a-w C:\Windows\System32\ntprint.dll
2008-09-09 02:25 2,048 ----a-w C:\Windows\System32\msxml6r.dll
2008-09-09 02:25 1,335,296 ----a-w C:\Windows\System32\msxml6.dll
2008-09-09 02:23 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2008-09-09 02:23 83,968 ----a-w C:\Windows\System32\dnsrslvr.dll
2008-09-09 02:23 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2008-09-09 02:23 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-09-09 02:23 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-09-09 02:23 24,576 ----a-w C:\Windows\System32\dnscacheugc.exe
2008-09-09 02:23 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-09-09 02:23 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2008-09-09 02:23 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2008-09-09 02:23 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-09-09 02:22 84,480 ----a-w C:\Windows\System32\INETRES.dll
2008-09-09 02:22 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2008-09-09 02:22 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2008-09-09 02:22 5,120 ----a-w C:\Windows\System32\wmi.dll
2008-09-09 02:22 428,032 ----a-w C:\Windows\System32\EncDec.dll
2008-09-09 02:22 292,352 ----a-w C:\Windows\System32\psisdecd.dll
2008-09-09 02:22 152,576 ----a-w C:\Windows\System32\imagehlp.dll
2008-09-09 02:22 12,800 ----a-w C:\Windows\system32\drivers\fs_rec.sys
2008-09-09 02:22 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2008-09-09 02:22 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2008-09-09 02:21 99,840 ----a-w C:\Windows\System32\poqexec.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{A057A204-BACC-4D26-8087-36EE87E26986}]
07/29/2008 08:56 PM 1987544 --a------ C:\PROGRA~1\OOVOOT~1\OOVOOT~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-8087-36EE87E26986}"= "C:\PROGRA~1\OOVOOT~1\OOVOOT~1.DLL" [07/29/2008 08:56 PM 1987544]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-8087-36ee87e26986}]
[HKEY_CLASSES_ROOT\oovooToolbar.OOVOOTOOLBAR]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-8087-36EE87E26986}"= "C:\PROGRA~1\OOVOOT~1\OOVOOT~1.DLL" [07/29/2008 08:56 PM 1987544]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-8087-36ee87e26986}]
[HKEY_CLASSES_ROOT\oovooToolbar.OOVOOTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [09/09/2008 03:24 AM 1232896]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [01/19/2007 08:54 PM 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [01/13/2007 04:36 AM 827392]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [02/12/2007 03:37 PM 174872]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [04/24/2007 02:11 AM 176128]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [02/13/2007 07:38 PM 159744]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [03/01/2007 09:18 PM 472776]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [01/11/2007 12:12 AM 317128]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [07/15/2008 02:33 AM 77824]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [07/29/2008 08:20 PM 206088]
"RtHDVCpl"="RtHDVCpl.exe" [03/09/2007 06:50 PM 4390912 C:\WINDOWS\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="C:\Windows\SMINST\launcher.exe" [11/08/2006 01:39 AM 44128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{406F03BD-EFA3-4B9D-8B25-2A903A5FC6A7}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{162B159F-C65A-4FC2-B781-EE593350C13A}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
"{C2DD4FDE-A09E-4A8E-AD94-388E40E91911}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"TCP Query User{F82AA16F-89AD-486E-8360-AC66DE48E598}C:\\program files\\oovoo\\oovoo.exe"= UDP:C:\program files\oovoo\oovoo.exe

oVoo
"UDP Query User{A2C98E40-CEC3-455D-AEBF-292D1F1A7709}C:\\program files\\oovoo\\oovoo.exe"= TCP:C:\program files\oovoo\oovoo.exe

oVoo
"{64EB301E-0CE0-4645-A349-2094278F6F99}"= Disabled:UDP:443

oVoo TCP المنفذ 443
"{59321333-D32C-4DF7-B733-6AD0DFD99AED}"= Disabled:TCP:443

oVoo UDP المنفذ 443
"{32CBA583-0ED5-4FB7-9AB2-E20F160DD4D9}"= Disabled:UDP:37674

oVoo TCP المنفذ 37674
"{73161EE5-E422-4241-B91D-653C49722DA0}"= Disabled:TCP:37674

oVoo UDP المنفذ 37674
"{1BD95035-DFDE-4E2B-9EBB-8A04FE3DF64D}"= Disabled:TCP:37675

oVoo UDP المنفذ 37675
"{5E09AF54-7712-465E-8F61-5597184CBABA}"= UDP:C:\Users\qatar\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
"{EFCF7B40-FEB8-4D10-AF84-1D9651927939}"= TCP:C:\Users\qatar\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\Windows\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [07/09/2008 06:28 PM 20496]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\Windows\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM 26640]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ac4bf7de-7c92-11dd-8ddb-806e6f6e6963}]
\shell\AutoRun\command - E:\AUTORUN.EXE
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-09 15:27:13
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 09/09/2008 15:28:25
ComboFix-quarantined-files.txt 2008-09-09 14:28:22
ComboFix2.txt 2008-09-09 14:24:47
ComboFix3.txt 2008-09-09 14:20:50
Pre-Run: 110,414,757,888 bytes free
Post-Run: 110,070,050,816 bytes free
199 --- E O F --- 2008-09-09 02:49:54