هذا هو التقرير
ComboFix 08-12-11.04 - Root 12/12/2008 6:48:03.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.173 [GMT 3:00]
Running from: c:\documents and settings\Root\«ل¥ ںéêè¢ \ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\adware.exe
C:\autorun.inf
c:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\moduleie.dll
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\svhost.exe
c:\documents and settings\LocalService\Application Data\twain_32
c:\documents and settings\LocalService\Application Data\twain_32\user.ds
c:\program files\Antivirus 2009
c:\program files\Antivirus 2009\av2009.exe
c:\program files\Antivirus 2009\file.exe
c:\program files\Spyware Guard 2008
c:\program files\Spyware Guard 2008\conf.cfg
c:\program files\Spyware Guard 2008\mbase.vdb
c:\program files\Spyware Guard 2008\quarantine.vdb
c:\program files\Spyware Guard 2008\queue.vdb
c:\program files\Spyware Guard 2008\spywareguard.exe
c:\program files\Spyware Guard 2008\uninstall.exe
c:\program files\Spyware Guard 2008\vbase.vdb
c:\windows\fxstaller.exe
c:\windows\reged.exe
c:\windows\spoolsystem.exe
c:\windows\sys.com
c:\windows\syscert.exe
c:\windows\sysexplorer.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\amvo.exe
c:\windows\system32\amvo0.dll
c:\windows\system32\amvo1.dll
c:\windows\system32\awtqnkhe.dll
c:\windows\system32\Cache
c:\windows\system32\cftmon.exe
c:\windows\system32\Drivers\TDSSmaxt.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\efcButrP.dll
c:\windows\system32\geBuUnnm.dll
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\ieupdates.exe.tmp
c:\windows\system32\kazaabackupfiles
c:\windows\system32\kazaabackupfiles\download_me.exe
c:\windows\system32\ljJYRIXn.dll
c:\windows\system32\mlJDuspO.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\PrtuBcfe.ini
c:\windows\system32\PrtuBcfe.ini2
c:\windows\system32\rqRJCRLC.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\ssqNFUNF.dll
c:\windows\system32\TDSScfum.dll
c:\windows\system32\TDSSfxmp.dll
c:\windows\system32\TDSSnrsr.dll
c:\windows\system32\TDSSofxh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSStkdv.log
c:\windows\system32\tmp.exe
c:\windows\system32\tmp.reg
c:\windows\system32\twain_32
c:\windows\system32\twain_32\local.ds
c:\windows\system32\twain_32\user.ds
c:\windows\system32\twext.exe
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\winscenter.exe
c:\windows\system32\WS2Fix.exe
c:\windows\system32\xjrfdljy.dll
c:\windows\Tasks\nicjxntq.job
c:\windows\Temp\tmp3.tmp
c:\windows\vmreg.dll
E:\Autorun.inf
----- BITS: Possible infected sites -----
hxxp://childhe.com
.
((((((((((((((((((((((((( Files Created from 2008-11-12 to 2008-12-12 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-12 03:46 26,162 ----a-w C:\iri.exe
2008-12-12 03:42 35,328 ----a-w c:\windows\system32\ljJBqonn.dll
2008-12-12 03:29 35,328 ----a-w c:\windows\system32\yayaAsTk.dll
2008-12-12 03:09 35,328 ----a-w c:\windows\system32\rqRJBUmM.dll
2008-12-12 02:56 35,328 ----a-w c:\windows\system32\xxywXRhG.dll
2008-12-12 02:43 35,328 ----a-w c:\windows\system32\wvUoOEWN.dll
2008-12-12 02:29 35,328 ----a-w c:\windows\system32\hgGvuUMf.dll
2008-12-12 02:16 35,328 ----a-w c:\windows\system32\urqOEuUO.dll
2008-12-12 02:13 --------- d-sh--w c:\windows\system32\config\systemprofile\Application Data\twain_32
2008-12-12 02:03 35,328 ----a-w c:\windows\system32\vtUmKBUO.dll
2008-12-12 01:25 90,112 ----a-w c:\windows\DUMP1bc6.tmp
2008-12-12 01:24 90,112 ----a-w c:\windows\DUMP1cb6.tmp
2008-12-12 01:23 90,112 ----a-w c:\windows\DUMP1ccc.tmp
2008-12-12 01:22 90,112 ----a-w c:\windows\DUMP1ccb.tmp
2008-12-12 01:18 90,112 ----a-w c:\windows\DUMP1cae.tmp
2008-12-12 01:17 90,112 ----a-w c:\windows\DUMP35ac.tmp
2008-12-12 01:15 90,112 ----a-w c:\windows\DUMP1b4e.tmp
2008-12-12 01:13 90,112 ----a-w c:\windows\DUMP1bf8.tmp
2008-12-12 01:04 90,112 ----a-w c:\windows\DUMP1cad.tmp
2008-12-12 01:00 90,112 ----a-w c:\windows\DUMP35a4.tmp
2008-12-12 00:59 90,112 ----a-w c:\windows\DUMP35a3.tmp
2008-12-12 00:44 90,112 ----a-w c:\windows\DUMP1cc0.tmp
2008-12-12 00:43 90,112 ----a-w c:\windows\DUMP3597.tmp
2008-12-12 00:42 90,112 ----a-w c:\windows\DUMP2053.tmp
2008-12-12 00:40 90,112 ----a-w c:\windows\DUMP2047.tmp
2008-12-12 00:39 90,112 ----a-w c:\windows\DUMP1cac.tmp
2008-12-12 00:39 90,112 ----a-w c:\windows\DUMP1ca3.tmp
2008-12-12 00:37 90,112 ----a-w c:\windows\DUMP2066.tmp
2008-12-12 00:36 90,112 ----a-w c:\windows\DUMP1b8a.tmp
2008-12-12 00:35 90,112 ----a-w c:\windows\DUMP2046.tmp
2008-12-12 00:28 90,112 ----a-w c:\windows\DUMP1cca.tmp
2008-12-12 00:26 90,112 ----a-w c:\windows\DUMP35ab.tmp
2008-12-12 00:24 90,112 ----a-w c:\windows\DUMP1ca2.tmp
2008-12-12 00:18 90,112 ----a-w c:\windows\DUMP35a2.tmp
2008-12-12 00:12 90,112 ----a-w c:\windows\DUMP35a1.tmp
2008-12-12 00:11 90,112 ----a-w c:\windows\DUMP2077.tmp
2008-12-12 00:10 90,112 ----a-w c:\windows\DUMP2060.tmp
2008-12-12 00:08 90,112 ----a-w c:\windows\DUMP206f.tmp
2008-12-12 00:07 90,112 ----a-w c:\windows\DUMP2052.tmp
2008-12-12 00:04 90,112 ----a-w c:\windows\DUMP205f.tmp
2008-12-11 23:49 90,112 ----a-w c:\windows\DUMP205e.tmp
2008-12-11 23:48 90,112 ----a-w c:\windows\DUMP2065.tmp
2008-12-11 23:47 90,112 ----a-w c:\windows\DUMP205d.tmp
2008-12-11 23:45 90,112 ----a-w c:\windows\DUMP2051.tmp
2008-12-11 23:44 90,112 ----a-w c:\windows\DUMP205c.tmp
2008-12-11 23:43 90,112 ----a-w c:\windows\DUMP205b.tmp
2008-12-11 23:42 90,112 ----a-w c:\windows\DUMP205a.tmp
2008-12-11 21:57 78,336 ----a-w c:\windows\system32\Agent.OMZ.Fix.exe
2008-12-11 12:38 90,112 ----a-w c:\windows\DUMP1f69.tmp
2008-12-10 14:44 90,112 ----a-w c:\windows\DUMP2082.tmp
2008-12-10 14:44 90,112 ----a-w c:\windows\DUMP2081.tmp
2008-12-10 14:43 90,112 ----a-w c:\windows\DUMP2045.tmp
2008-12-10 11:49 90,112 ----a-w c:\windows\DUMP2050.tmp
2008-12-10 11:48 90,112 ----a-w c:\windows\DUMP206e.tmp
2008-12-10 11:47 90,112 ----a-w c:\windows\DUMP204f.tmp
2008-12-10 11:46 90,112 ----a-w c:\windows\DUMP2064.tmp
2008-12-10 11:45 90,112 ----a-w c:\windows\DUMP2063.tmp
2008-12-10 11:44 90,112 ----a-w c:\windows\DUMP206d.tmp
2008-12-10 11:27 90,112 ----a-w c:\windows\DUMP2059.tmp
2008-12-10 11:07 --------- d-----w c:\documents and settings\LocalService\Application Data\Juniper Networks
2008-12-09 21:52 35,328 ----a-w c:\windows\system32\jkkICrOf.dll
2008-12-09 21:39 35,328 ----a-w c:\windows\system32\yayaWNdA.dll
2008-12-09 21:25 35,328 ----a-w c:\windows\system32\ddcApoPI.dll
2008-12-09 21:12 35,328 ----a-w c:\windows\system32\byXOeCrQ.dll
2008-12-09 00:10 34,816 ----a-w c:\windows\system32\cbXPhfDU.dll
2008-12-08 23:58 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-12-08 23:54 34,816 ----a-w c:\windows\system32\mlJDsTLc.dll
2008-12-07 15:38 --------- d-----w c:\program files\Messenger Plus! Live
2008-12-07 14:55 135,567 ----a-w c:\windows\bnn.exe
2008-12-07 00:25 73,216 ----a-w C:\osy.exe
2008-12-07 00:06 34,816 ----a-w c:\windows\system32\nnnliJbx.dll
2008-12-07 00:04 34,816 ----a-w c:\windows\system32\khfCtqoO.dll
2008-12-06 23:47 34,816 ----a-w c:\windows\system32\nnnmmlif.dll
2008-12-06 23:32 34,816 ----a-w c:\windows\system32\byXPGXNg.dll
2008-12-06 23:31 34,816 ----a-w c:\windows\system32\xxywXOeC.dll
2008-12-06 00:06 64,843 ----a-w C:\mpsn.exe
2008-12-05 23:58 34,816 ----a-w c:\windows\system32\urqOIaxv.dll
2008-12-05 10:27 34,816 ----a-w c:\windows\system32\ddcCSIaA.dll
2008-12-05 10:26 34,816 ----a-w c:\windows\system32\opnnomNh.dll
2008-12-02 22:48 34,816 ----a-w c:\windows\system32\wvUmllMe.dll
2008-12-02 22:39 34,816 ----a-w c:\windows\system32\opnkljgD.dll
2008-12-02 22:24 34,816 ----a-w c:\windows\system32\mlJDuvSL.dll
2008-12-02 16:45 34,816 ----a-w c:\windows\system32\vtUmLdAS.dll
2008-12-02 16:41 34,816 ----a-w c:\windows\system32\awtsRlKD.dll
2008-12-02 16:24 34,816 ----a-w c:\windows\system32\byXNEUmm.dll
2008-12-02 16:18 34,816 ----a-w c:\windows\system32\wvUljiGx.dll
2008-12-02 16:18 34,816 ----a-w c:\windows\system32\tuvSMgdD.dll
2008-12-02 16:14 34,816 ----a-w c:\windows\system32\sSmmmMCU.dll
2008-11-27 09:45 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-10-21 20:54 --------- d-----w c:\program files\Sun
2008-10-19 17:36 --------- d-----w c:\program files\koutbo6
2008-10-19 17:34 --------- d-----w c:\program files\Java
2008-10-19 17:28 --------- d-----w c:\program files\Common Files\Java
2008-10-16 11:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 11:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 11:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 11:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 11:12 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 11:12 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 11:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/03/2004 09:56 PM 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [10/11/2008 06:58 PM 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KAVPersonal50"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" [08/30/2005 03:51 PM 139367]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPHKMGR.exe" [03/08/2006 03:44 AM 94208]
"TPWAUDAP"="c:\program files\Lenovo\HOTKEY\TpWAudAp.exe" [12/10/2005 06:29 PM 24064]
"snp2std"="c:\windows\vsnp2std.exe" [11/16/2005 04:14 PM 344064]
"igfxtray"="c:\windows\system32\igfxtray.exe" [04/07/2003 10:19 AM 155648]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [04/07/2003 10:07 AM 114688]
"igfxpers"="c:\windows\system32\igfxpers.exe" [11/03/2005 03:26 PM 118784]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [04/07/2003 10:07 AM 114688]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [10/19/2006 04:00 PM 180269]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [10/19/2006 02:15 PM 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM 144784]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [01/07/2005 05:07 PM 61952 c:\windows\system32\HdAShCut.exe]
"AGRSMMSG"="AGRSMMSG.exe" [12/12/2005 02:50 PM 88204 c:\windows\AGRSMMSG.exe]
"SoundMan"="SOUNDMAN.EXE" [01/09/2004 01:54 PM 65536 c:\windows\SOUNDMAN.EXE]
"SMSERIAL"="sm56hlpr.exe" [12/29/2004 01:01 AM 544768 c:\windows\sm56hlpr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/03/2004 09:56 PM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
01/12/2006 01:05 AM 13824 c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RichVideo"=2 (0x2)
"ose"=3 (0x3)
"MDM"=2 (0x2)
"iPodService"=3 (0x3)
"IDriverT"=3 (0x3)
"Bonjour Service"=2 (0x2)
"BITS"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Paltalk Messenger\\PALTALK.EXE"=
"c:\\Program Files\\Juniper Networks\\Secure Application Manager\\dsSamProxy.exe"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
R1 Klmc;Klmc;c:\windows\system32\drivers\klmc.sys [2005-08-30 10995]
R1 NEOFLTR_600_12507;Juniper Networks TDI Filter Driver (NEOFLTR_600_12507);\??\c:\windows\system32\Drivers\NEOFLTR_600_12507.SYS [2007-12-28 64160]
.
- - - - ORPHANS REMOVED - - - -
BHO-{B5F0C6E7-C494-4153-94EC-B71ADA68E3C9} - c:\windows\system32\efcButrP.dll
HKCU-Run-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
HKLM-Run-WinDLL (tmp.exe) - c:\windows\system32\tmp.exe
HKLM-Run-spywareguard - c:\program files\Spyware Guard 2008\spywareguard.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.a2articles.com
mStart Page = about:blank
uInternet Settings,ProxyServer = proxy.saudi.net.sa:8080
uInternet Settings,ProxyOverride = <local>
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O16 -: Microsoft XML Parser for Java -
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-12 06:52:19
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(556)
c:\windows\system32\tphklock.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\BLUETOOTH SOFTWARE\BIN\BTWDINS.EXE
c:\windows\SYSTEM32\INETSRV\INETINFO.EXE
c:\program files\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KAVSVC.EXE
c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 12/12/2008 6:53:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-12 03:53:42
Pre-Run: 19,036,979,200 bytes free
Post-Run: 18,998,706,176 bytes free
292