تقرير كمبو فكس
ComboFix 08-12-09.03 - XPPRESP3 12/11/2008 4:40:55.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.185 [GMT 2:00]
Running from: c:\documents and settings\XPPRESP3\My Documents\Downloads\Programs\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-11-11 to 2008-12-11 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-11 02:43 --------- d-----w c:\documents and settings\XPPRESP3\Application Data\DMCache
2008-12-11 02:28 --------- d-----w c:\program files\Realtek AC97
2008-12-11 02:27 --------- d-----w c:\documents and settings\XPPRESP3\Application Data\TeraCopy
2008-12-11 01:16 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-12-11 01:16 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-12-11 01:16 --------- d-----w c:\program files\Real
2008-12-11 01:16 --------- d-----w c:\program files\Common Files\xing shared
2008-12-11 01:16 --------- d-----w c:\program files\Common Files\Real
2008-12-08 10:18 --------- d-----w c:\documents and settings\XPPRESP3\Application Data\dvdcss
2008-12-07 15:56 --------- d-----w c:\documents and settings\XPPRESP3\Application Data\XnView
2008-12-06 15:03 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-06 14:49 --------- d-----w c:\program files\Real Alternative
2008-12-06 14:44 --------- d-----w c:\program files\K-Lite Codec Pack
2008-12-06 14:06 --------- d-----w c:\program files\IObit
2008-12-05 13:20 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-05 13:16 --------- d-----w c:\documents and settings\XPPRESP3\Application Data\vlc
2008-12-05 13:15 --------- d-----w c:\program files\VideoLAN
2008-12-03 17:25 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-12-03 16:45 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-02 19:37 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2008-12-02 19:36 --------- d-----w c:\program files\Avira
2008-12-02 16:38 2,560 ----a-w c:\windows\_MSRSTRT.EXE
2008-12-01 17:21 --------- d-----w c:\program files\Avant Browser
2008-11-28 18:20 --------- d-----w c:\program files\JetAudio
2008-10-16 12:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 12:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 12:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 12:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 12:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 12:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 12:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 12:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 12:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 12:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-09-16 00:14 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-16 00:11 683,520 ----a-w c:\windows\system32\divx.dll
2008-02-12 00:26 16,384 --sha-w c:\windows\system32\config\systemprofile\s\index.dat
2008-02-12 00:26 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
2008-02-12 00:26 16,384 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
2008-02-12 00:26 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\.IE5\index.dat
.
((((((((((((((((((((((((((((( snapshot@Sat 12-06-2008_16.41.13.79 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-10-26 09:20:40 4,124,352 ----a-w c:\windows\system32\drivers\alcxwdm.sys
+ 2008-09-24 08:40:22 4,122,368 ----a-r c:\windows\system32\drivers\alcxwdm.sys
- 2001-06-22 23:31:20 278,528 ----a-w c:\windows\system32\pncrt.dll
+ 2008-12-11 01:16:25 278,528 ----a-w c:\windows\system32\pncrt.dll
- 1998-03-26 02:57:34 6,656 ----a-w c:\windows\system32\pndx5016.dll
+ 2008-12-11 01:16:26 6,656 ----a-w c:\windows\system32\pndx5016.dll
- 1998-05-12 18:36:42 5,632 ----a-w c:\windows\system32\pndx5032.dll
+ 2008-12-11 01:16:26 5,632 ----a-w c:\windows\system32\pndx5032.dll
- 2008-09-10 19:56:28 185,920 ----a-w c:\windows\system32\rmoc3260.dll
+ 2008-12-11 01:16:31 185,920 ----a-w c:\windows\system32\rmoc3260.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 04:00 PM 30208]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [10/11/2007 03:15 AM 802816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [10/05/2006 08:56 PM 280779]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [06/06/2004 05:41 AM 118784]
"avgnt"="c:\program files\Avira\Avira Premium Security Suite\avgnt.exe" [06/12/2008 02:28 PM 266497]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [12/11/2008 03:16 AM 185872]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [08/08/2007 06:24 PM 61952 c:\windows\system32\HDAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [05/05/2005 02:28 AM 14414848 c:\windows\Rthdcpl.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 04:00 PM 30208]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [03/19/2007 12:05 AM 630784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" [08/08/2007 06:24 PM 124928 c:\windows\system32\advpack.dll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):58,50,69,7a,65,5f,4c,6f,67,6f,6e,2e,65,78,65,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MyProxy"=c:\program files\myproxy\MyProxy.exe
"Rainlendar2"=c:\program files\Rainlendar2\Rainlendar2.exe
"RocketDock"="c:\program files\RocketDock\RocketDock.exe"
"MsnMsgr"="c:\program files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe"
"TrueImageMonitor.exe"=c:\program files\Acronis\TrueImageWorkstation\TrueImageMonitor.exe
"LClock"=c:\program files\LClock\LClock.exe
"Resume copy"=copyfstq.exe /startup
"AcronisTimounterMonitor"=c:\program files\Acronis\TrueImageWorkstation\TimounterMonitor.exe
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
R1 avfwot;avfwot;c:\windows\system32\DRIVERS\avfwot.sys [2008-12-02 71592]
R2 AntiVirFirewallService;Avira Premium Security Suite Firewall;"c:\program files\Avira\Avira Premium Security Suite\avfwsvc.exe" [2008-12-02 344321]
R2 antivirwebservice;Avira Premium Security Suite WebGuard;"c:\program files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE" [2008-12-02 258305]
R2 AVEService;Avira Premium Security Suite MailGuard helper service;"c:\program files\Avira\Avira Premium Security Suite\avesvc.exe" [2008-12-02 41217]
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\DRIVERS\avfwim.sys [2008-12-02 71464]
S2 AntiVirMailService;Avira Premium Security Suite MailGuard;"c:\program files\Avira\Avira Premium Security Suite\avmailc.exe" [2008-12-02 164097]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WudfServiceGroup REG_SZ hex(7):57,00,55,00,44,00,46,00,53,00,76,00,63,00,00,00,00,00
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
s of the 'Scheduled Tasks' folder
2008-12-05 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [12/21/2007 03:17 PM]
2008-12-11 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [10/19/2007 11:20 AM]
.
.
------- Supplementary Scan -------
.
uLocal Page = c:\program files\Common Files\Microsoft Shared\Stationery\Blank.htm
mLocal Page = c:\program files\Common Files\Microsoft Shared\Stationery\Blank.htm
uInternet Settings,ProxyServer = 127.0.0.1:8080
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
IE: IDM بواسطة FLV تحميل محتوى فيديو - c:\program files\Internet Download Manager\IEGetVL.htm
IE: IDM تحميل بواسطة - c:\program files\Internet Download Manager\IEExt.htm
IE: IDM تحميل جميع الروابط بواسطة - c:\program files\Internet Download Manager\IEGetAll.htm
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: تخصيص القائمه - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: حفظ النماذج - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: شريط ادوات روبوفورم - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: ملئ النماذج - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
FireFox -: Profile - c:\documents and settings\XPPRESP3\Application Data\Mozilla\Firefox\Profiles\3zzlbtre.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - google.com.sa
FF -: plugin - c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF -: plugin - c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.
.
------- File Associations -------
.
txtfile=c:\program files\Win32Pad\win32pad.exe "%L"
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-11 04:43:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(556)
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(612)
c:\windows\system32\relog_ap.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\Avira Premium Security Suite\sched.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Avira\Avira Premium Security Suite\avguard.exe
c:\program files\FolderSize\FolderSizeSvc.exe
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 12/11/2008 4:46:12 - machine was rebooted [XPPRESP3]
ComboFix-quarantined-files.txt 2008-12-11 02:46:09
ComboFix2.txt 2008-12-08 10:58:11
ComboFix3.txt 2008-12-06 14:41:42
ComboFix4.txt 2008-12-02 16:14:58
Pre-Run: 31,566,188,544 bytes free
Post-Run: 31,593,283,584 bytes free
223