هذا تقرير الكومبو فكس
ComboFix 08-12-07.04 - starnet center 12/09/2008 17:32:51.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.188 [GMT 2:00]
Running from: e:\vip_prog\برامج الحماية ومضاد للفيروسات\فيرس الدودة\أحدث البرامج\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\kakle.dll
.
((((((((((((((((((((((((( Files Created from 2008-11-09 to 2008-12-09 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-09 15:35 32 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-12-09 15:35 32 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-12-09 15:35 2,396 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-09 15:35 168,480 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-09 08:56 --------- d-----w c:\program files\Trojan Remover
2008-12-09 08:56 --------- d-----w c:\documents and settings\starnet center\Application Data\Simply Super Software
2008-12-09 08:56 --------- d-----w c:\documents and settings\All Users\Application Data\Simply Super Software
2008-12-09 08:55 96,976 ----a-w c:\windows\system32\drivers\klin.dat
2008-12-09 08:55 87,855 ----a-w c:\windows\system32\drivers\klick.dat
2008-12-09 08:55 --------- d-----w c:\program files\Kaspersky Lab
2008-12-09 08:55 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-12-09 08:54 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-12-02 19:53 --------- d-----w c:\program files\Xilisoft
2008-12-02 19:51 90,112 ----a-w c:\windows\system32\agsaami.dll
2008-12-02 19:51 610,304 ----a-w c:\windows\system32\agsaamg.dll
2008-12-02 19:51 372,736 ----a-w c:\windows\system32\agsaamc.dll
2008-12-02 19:51 2,535,424 ----a-w c:\windows\system32\agsaamj.dll
2008-12-02 19:51 196,608 ----a-w c:\windows\system32\maag.dll
2008-12-02 19:51 1,986,560 ----a-w c:\windows\system32\akll.dll
2008-12-02 19:51 1,245,184 ----a-w c:\windows\system32\bkll.dll
2008-12-02 19:51 1,212,416 ----a-w c:\windows\system32\ckll.dll
2008-12-02 19:51 --------- d-----w c:\program files\Real_SC
2008-12-02 19:51 --------- d-----w c:\program files\FormatFactory
2008-12-02 19:51 --------- d-----w c:\program files\AnMing
2008-12-02 19:49 --------- d-----w c:\program files\Internet Download Manager
2008-12-02 19:49 --------- d-----w c:\documents and settings\starnet center\Application Data\IDM
2008-12-02 19:49 --------- d-----w c:\documents and settings\starnet center\Application Data\DMCache
2008-12-02 19:24 --------- d-----w c:\documents and settings\starnet center\Application Data\Media Player Classic
2008-12-02 19:22 --------- d-----w c:\program files\K-Lite Codec Pack
2008-12-02 19:20 --------- d-----w c:\program files\IObit
2008-12-02 19:19 --------- d-----w c:\program files\WinASO
2008-11-11 18:00 218,376 ----a-w c:\windows\system32\klogon.dll
2008-11-11 17:58 25,601 ----a-w c:\windows\system32\drivers\klopp.dat
2008-11-02 14:02 7,680 ----a-w c:\windows\system32\ff_vfw.dll
2008-10-28 22:35 684,032 ----a-w c:\windows\system32\divx.dll
2008-09-25 08:03 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-21 19:52 82,898 ----a-w c:\windows\uninstall.exe
2008-09-21 19:48 155,995 ----a-w c:\windows\java\Packages\TB1RZRLJ.ZIP
2008-09-19 21:57 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-12 10:44 206,256 ----a-w c:\windows\system32\idmmbc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/04/2004 07:56 AM 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [11/25/2008 09:19 AM 935856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [11/11/2008 07:59 PM 206088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [09/21/2008 09:58 PM 180269]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
backup=c:\windows\pss\Utility Tray.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 05/11/2007 03:06 AM 113776 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 08/04/2004 07:56 AM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 11/25/2008 09:19 AM 935856 c:\program files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 01/19/2007 12:54 PM 5752176 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 07/09/2001 11:50 AM 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder]
-ra------ 01/30/2006 07:00 PM 172032 c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 11/02/2004 08:24 PM 106496 c:\program files\ASUSTeK\ASUSDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSRaid]
--------- 12/22/2004 05:32 PM 966656 c:\program files\Silicon Integrated Systems\SiSRaidPackage\Sraid.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
--a------ 06/26/2006 03:53 PM 20005928 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 09/21/2008 09:58 PM 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
--a------ 12/09/2008 10:59 AM 1231752 c:\program files\Trojan Remover\Trjscan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 03/01/2007 06:11 PM 4740600 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Resume copy]
--a------ 06/10/2003 05:35 PM 131072 c:\windows\copyfstq.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSPower]
-ra------ 11/10/2005 09:28 AM 49152 c:\windows\system32\SiSPower.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-r------- 11/11/2005 09:07 AM 90112 c:\windows\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"srservice"=2 (0x2)
"BITS"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Access Remote PC 5.1\\rpcsetup.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\vip_prog\\برامج الحماية ومضاد للفيروسات\\Kaspersky Anti-Virus 2009 New\\8.0.0.506.exe"=
"c:\\Program Files\\Internet Download Manager\\IEMonitor.exe"=
"e:\\vip_prog\\برامج الحماية ومضاد للفيروسات\\فيرس الدودة\\أحدث البرامج\\ComboFix.exe"=
"e:\\vip_prog\\برامج الحماية ومضاد للفيروسات\\فيرس الدودة\\أحدث البرامج\\HijackThis\\HijackThis.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\Windows Live\\WLLoginProxy.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R2 Access Remote PC Service 5.1;Access Remote PC Service 5.1;"c:\program files\Access Remote PC 5.1\rpcsetup.exe" /service [2008-09-21 2220784]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
S3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\lgjmlo.sys []
S3 PAC207;FlyCam USB 100 XP3;c:\windows\system32\DRIVERS\pfc027.sys [2005-01-25 154112]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\F:\NTGLM7X.sys []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - AVP
.
s of the 'Scheduled Tasks' folder
2008-09-21 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [12/19/2006 04:53 PM]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
LSP: c:\windows\system32\idmmbc.dll
TCP: {E7FCF647-1243-4C3A-AA11-254BBDABF61C} = 4.2.2.2,4.2.2.3
O16 -: Microsoft XML Parser for Java - c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
-
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-09 17:36:00
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(940)
c:\windows\system32\idmmbc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\System32\PAStiSvc.exe
c:\program files\Access Remote PC 5.1\rpcgrab.exe
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 12/09/2008 17:37:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-09 15:37:32
Pre-Run: 2,944,208,896 bytes free
Post-Run: 2,839,830,528 bytes free
194