تقرير أداة
ComboFix.exe
ComboFix 08-11-10.01 - abc 11/11/2008 22:47:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.709 [GMT 3:00]
Running from: c:\documents and settings\abc\My Documents\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\windows\system32\ckvo.exe
c:\windows\system32\ckvo0.dll
c:\windows\system32\dao350.dll
C:\xih9.cmd
D:\Autorun.inf
D:\xih9.cmd
E:\Autorun.inf
E:\xih9.cmd
H:\autorun.inf
H:\xih9.cmd
.
((((((((((((((((((((((((( Files Created from 2008-10-11 to 2008-11-11 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-11 17:34 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-11-11 17:05 85,504 --sh--r c:\windows\system32\gasretyw0.dll
2008-11-11 17:04 --------- d-----w c:\program files\Kaspersky Lab
2008-11-11 17:04 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-11 15:51 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-11 13:46 109,736 --sh--r c:\windows\system32\kamsoft.exe
2008-11-11 13:46 109,736 --sh--r C:\lky.exe
2008-11-10 08:01 --------- d-----w c:\program files\PRT
2008-11-09 08:38 --------- d-----w c:\program files\idara
2008-11-08 09:54 479,232 ------w c:\windows\Setup1.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [07/21/2006 06:48 PM 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [07/21/2006 06:50 PM 86016]
"Persistence"="c:\windows\system32\igfxpers.exe" [07/21/2006 06:47 PM 81920]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [05/01/2006 10:07 AM 843776]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [06/16/2008 11:41 AM 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [10/25/2006 06:58 PM 282624]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [10/30/2006 09:36 AM 256576]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2007-08-03 389120]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\CNAB4RPK.EXE"=
S3 AVPsys;AVPsys;c:\windows\system32\drivers\cdaudio.sys [ ]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187.sys [01/11/2007 01:20 PM 194304]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3af9a75f-3f43-11dd-89ad-0019b92eaf55}]
\Shell\AutoRun\command - G:\xih9.cmd
\Shell\explore\Command - G:\xih9.cmd
\Shell\open\Command - G:\xih9.cmd
*Newly Created Service* - BITS
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-06-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [10/10/2006 05:13 PM]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.sa/
O8 -: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-11 22:48:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 11/11/2008 22:48:52
ComboFix-quarantined-files.txt 2008-11-11 19:48:51
Pre-Run: 25,570,877,440 bytes free
Post-Run: 25,686,507,520 bytes free
97