الاداه اللى هى كومبو فيكس اشتغلت و ده التقرير بتاعها
ComboFix 08-09-16.05 - Morab3 2008-09-18 3:11:22.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.20.1033.18.521 [GMT 3:00]
Running from: C:\Documents and Settings\Morab3\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Messenger\msgmr.dll
C:\WINDOWS\AppPatch\AcSpecf.sdb
C:\WINDOWS\AppPatch\AcXtrnel.sdb
C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
C:\WINDOWS\Fonts\Framdee.ttf
C:\WINDOWS\sysocmgr.dll
C:\WINDOWS\system32\avicapwm.dll
C:\WINDOWS\system32\avicapwm.nls
C:\WINDOWS\system32\catower.dll
C:\WINDOWS\system32\comboaus.dll
C:\WINDOWS\system32\comuidsg.dll
C:\WINDOWS\system32\comuidsg.nls
C:\WINDOWS\system32\cupops.dll
C:\WINDOWS\system32\drivers\HBKernel.sys
C:\WINDOWS\system32\drivers\IsDrv118.sys
C:\WINDOWS\system32\eskisl.dll
C:\WINDOWS\system32\eskislk.exe
C:\WINDOWS\system32\explore.exe
C:\WINDOWS\system32\HBmhly.dll
C:\WINDOWS\system32\johandy.dll
C:\WINDOWS\system32\jolndyo.dll
C:\WINDOWS\system32\kildh3l.cfg
C:\WINDOWS\system32\kildh3l.dll
C:\WINDOWS\system32\lensch.dll
C:\WINDOWS\system32\lweurqhx.dll
C:\WINDOWS\system32\lweurqhx.nls
C:\WINDOWS\system32\mcromv.dll
C:\WINDOWS\system32\mduaey.dll
C:\WINDOWS\system32\micsus.dll
C:\WINDOWS\system32\mshta.dll
C:\WINDOWS\system32\mstimewd.dll
C:\WINDOWS\system32\mstimewd.nls
C:\WINDOWS\system32\slbiopfs2.dll
C:\WINDOWS\system32\slbiopfs2.nls
C:\WINDOWS\system32\tscfgwmijxsj.dll
C:\WINDOWS\system32\tscfgwmijxsj.nls
C:\WINDOWS\system32\Update.dat
C:\WINDOWS\system32\wllame.dll
C:\WINDOWS\system32\wrm32.dll
C:\WINDOWS\system32\xolehlpjh.dll
C:\WINDOWS\system32\xolehlpjh.nls
C:\WINDOWS\temp\wmsetup.dll
C:\WINDOWS\Update.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Legacy_HBKERNEL
-------\Service_asc3360pr
-------\Service_HBKernel
-------\Service_IsDrv118
((((((((((((((((((((((((( Files Created from 2008-08-18 to 2008-09-18 )))))))))))))))))))))))))))))))
.
2008-09-18 01:58 . 2008-09-18 01:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-09-17 21:39 . 2008-09-17 21:39 <DIR> d-------- C:\Documents and Settings\Morab3\Contacts
2008-09-17 21:37 . 2008-09-17 21:37 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-09-17 21:37 . 2008-09-17 21:37 <DIR> d-------- C:\Program Files\Windows Live Favorites
2008-09-17 21:37 . 2008-09-17 21:37 <DIR> d-------- C:\Program Files\Messenger Plus! Live
2008-09-17 21:37 . 2008-09-17 21:37 268 --ah----- C:\sqmdata00.sqm
2008-09-17 21:37 . 2008-09-17 21:37 244 --ah----- C:\sqmnoopt00.sqm
2008-09-17 21:36 . 2008-09-17 21:36 <DIR> d-------- C:\WINDOWS\system32\DRVSTORE
2008-09-17 21:31 . 2008-09-17 21:31 <DIR> d-------- C:\Program Files\Winamp
2008-09-17 21:31 . 2008-09-17 21:31 <DIR> d-------- C:\Documents and Settings\Morab3\Application Data\Winamp
2008-09-17 21:25 . 2008-09-17 21:25 <DIR> d--hs---- C:\Program Files\Common Files\WindowsLiveInstaller
2008-09-17 21:24 . 2008-09-17 21:25 <DIR> d-------- C:\Program Files\Windows Live
2008-09-17 21:24 . 2008-09-17 21:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-09-17 21:17 . 2008-09-18 02:00 2,393,516 --a------ C:\WINDOWS\system32\nwapi32dj.dll
2008-09-17 21:17 . 2008-09-17 21:17 28,672 --a------ C:\WINDOWS\system32\aotoppt.dll
2008-09-17 21:17 . 2008-09-17 21:17 24,576 --a------ C:\WINDOWS\system32\pewire.dll
2008-09-17 21:17 . 2008-09-17 21:17 428 --a------ C:\WINDOWS\system32\nwapi32dj.nls
2008-09-17 21:12 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-09-17 21:12 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-09-17 21:12 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-09-17 21:12 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-09-17 21:12 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-09-17 21:08 . 2008-09-17 21:08 <DIR> d---s---- C:\Documents and Settings\Morab3\UserData
2008-09-17 21:08 . 2008-09-17 21:08 22 --a------ C:\WINDOWS\system32\ati64hlp.stb
2008-09-17 20:59 . 2008-09-17 20:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-17 20:50 . 2001-08-23 14:00 19,456 --a------ C:\WINDOWS\system32\dllcache\agt0804.dll
2008-09-17 20:50 . 2001-08-23 14:00 19,456 --a------ C:\WINDOWS\system32\dllcache\agt0412.dll
2008-09-17 20:50 . 2001-08-23 14:00 19,456 --a------ C:\WINDOWS\system32\dllcache\agt0404.dll
2008-09-17 20:44 . 2001-08-23 14:00 66,594 --a------ C:\WINDOWS\system32\dllcache\c_857.nls
2008-09-17 20:44 . 2001-08-23 14:00 66,082 --a------ C:\WINDOWS\system32\dllcache\c_28599.nls
2008-09-17 20:44 . 2001-08-23 14:00 66,082 --a------ C:\WINDOWS\system32\dllcache\c_10081.nls
2008-09-17 20:02 . 2008-09-17 20:02 <DIR> d-------- C:\Documents and Settings\Morab3\Application Data\Media Player Classic
2008-09-17 19:58 . 2006-09-24 16:11 389,120 --a------ C:\WINDOWS\system32\lameACM.acm
2008-09-17 19:58 . 2007-09-04 17:56 164,352 --a------ C:\WINDOWS\system32\unrar.dll
2008-09-17 19:58 . 2007-09-21 01:52 118,784 --a------ C:\WINDOWS\system32\ac3acm.acm
2008-09-17 19:58 . 2007-10-03 16:03 414 --a------ C:\WINDOWS\system32\lame_acm.xml
2008-09-17 19:57 . 2008-09-17 19:57 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-09-17 19:57 . 2007-09-28 17:07 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-09-17 19:57 . 2007-07-25 14:24 1,559,040 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-09-17 19:57 . 2007-09-28 17:05 739,840 --a------ C:\WINDOWS\system32\divx.dll
2008-09-17 19:57 . 2004-01-11 23:00 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-09-17 19:57 . 2007-03-10 12:51 282,624 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-09-17 19:57 . 2004-01-25 17:18 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2008-09-17 19:57 . 2007-09-28 17:05 81,920 --a------ C:\WINDOWS\system32\dpl100.dll
2008-09-17 19:57 . 2007-07-29 16:51 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-09-17 19:57 . 2007-07-10 17:10 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-09-17 19:55 . 2008-09-17 19:55 <DIR> d-------- C:\Program Files\Internet Download Manager
2008-09-17 19:55 . 2008-09-17 19:55 <DIR> d-------- C:\Documents and Settings\Morab3\Application Data\IDM
2008-09-17 19:55 . 2008-09-17 19:55 <DIR> d-------- C:\Documents and Settings\Morab3\Application Data\DMCache
2008-09-17 19:52 . 2008-09-17 19:52 22 --a------ C:\WINDOWS\system32\ati64hl2.stb
2008-09-17 19:51 . 2004-08-01 08:43 524,850 -ra------ C:\WINDOWS\system32\drivers\ativcaxx.cpa
2008-09-17 19:51 . 2005-06-28 21:05 516,096 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-09-17 19:51 . 2004-08-01 08:42 307,200 -ra------ C:\WINDOWS\system32\atiiiexx.dll
2008-09-17 19:51 . 2004-08-01 08:42 95,617 -ra------ C:\WINDOWS\system32\atiicdxx.dat
2008-09-17 19:51 . 2004-08-01 08:43 58,521 -ra------ C:\WINDOWS\system32\drivers\ativckxx.vp
2008-09-17 19:51 . 2004-08-01 08:43 21,472 -ra------ C:\WINDOWS\system32\drivers\ativvpxx.vp
2008-09-17 19:51 . 2004-08-01 08:42 5,396 -ra------ C:\WINDOWS\system32\atifglpf.xml
2008-09-17 19:51 . 2004-08-01 08:43 900 -ra------ C:\WINDOWS\system32\drivers\ativcaxx.vp
2008-09-17 19:50 . 2008-09-17 19:50 <DIR> d-------- C:\Program Files\ATI Technologies
2008-09-17 19:48 . 2008-09-18 03:14 5,509 --a------ C:\WINDOWS\system32\drivers\gpjill.sys
2008-09-17 19:47 . 2008-09-17 19:47 <DIR> d-------- C:\WINDOWS\OPTIONS
2008-09-17 19:47 . 2008-09-17 19:47 <DIR> d-------- C:\Program Files\AvRack
2008-09-17 19:47 . 2008-09-17 19:47 <DIR> d-------- C:\Program Files\Avance Sound Manager
2008-09-17 19:47 . 2002-09-16 04:52 1,256,448 --a------ C:\WINDOWS\system32\ALSNDMGR.CPL
2008-09-17 19:47 . 2002-09-16 13:25 941,516 --a------ C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2008-09-17 19:47 . 2001-08-27 15:21 327,680 --------- C:\WINDOWS\alcupd.exe
2008-09-17 19:47 . 2002-04-23 05:13 258,048 --------- C:\WINDOWS\alcrmv.exe
2008-09-17 19:47 . 2002-09-11 05:57 163,328 --a------ C:\WINDOWS\SOUNDMAN.EXE
2008-09-17 19:47 . 2002-02-05 08:54 141,016 --a------ C:\WINDOWS\system32\ALSNDMGR.WAV
2008-09-17 19:47 . 2001-07-05 19:19 164 --------- C:\WINDOWS\avrack.ini
2008-09-17 19:46 . 2008-09-17 19:46 <DIR> d-------- C:\Program Files\Intel
2008-09-17 19:46 . 2008-09-17 19:46 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-09-17 19:46 . 2008-09-17 19:46 <DIR> d-------- C:\Program Files\Gigabyte
2008-09-17 19:46 . 2008-09-17 19:46 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-09-17 19:46 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-09-17 19:46 . 2002-10-15 00:00 101,431 --a------ C:\WINDOWS\system32\drivers\IdeChnDr.sys
2008-09-17 19:46 . 2002-10-15 00:00 44,875 --a------ C:\WINDOWS\system32\IPrtCnst.dll
2008-09-17 19:46 . 2002-10-15 00:00 13,891 --a------ C:\WINDOWS\system32\drivers\IdeBusDr.sys
2008-09-17 19:45 . 2008-09-17 19:45 5,311 --a------ C:\huadio.tmp
2008-09-17 19:45 . 2008-09-17 19:45 3,808 --a------ C:\mapmem.tmp
2008-09-17 19:40 . 2008-09-17 19:40 <DIR> d-------- C:\Documents and Settings\Morab3
2008-09-01 15:56 . 2008-07-09 17:34 206,256 --a------ C:\WINDOWS\system32\idmmbc.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-17 15:21 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 15360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-09-01 2684336]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5802008]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-28 344064]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-04 36352]
"SoundMan"="SOUNDMAN.EXE" [2002-09-11 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{A2C3BA54-DF75-4881-8EB3-E54B26BBBBC9}"= "C:\WINDOWS\system32\nwapi32dj.dll" [2008-09-18 2393516]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceDelayLoad]
"nwapi32dj.dll"= {A2C3BA54-DF75-4881-8EB3-E54B26BBBBC9} - C:\WINDOWS\system32\nwapi32dj.dll [2008-09-18 2393516]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"F:\\S O U R C E S\\Drivers\\setup.exe"=
"C:\\WINDOWS\\SOUNDMAN.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\Ati2evxx.exe"=
*Newly Created Service* - ASC3360PR
.
s of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.facebook.com/
O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 -: Add to Windows &Live Favorites -
O8 -: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 -: Download FLV video with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 -: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-18 03:14:12
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nvmini]
"ImagePath"="system32\DRIVERS\nvmini.sys"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-09-18 3:15:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-18 00:15:42
Pre-Run: 6,501,015,552 bytes free
Post-Run: 6,566,387,712 bytes free
227