zandr
زيزوومي جديد
غير متصل
من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
ComboFix 08-12-14.01 - hichou 2008-12-14 19:51:52.5 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.591.1036.18.247.76 [GMT 0:00]
Se ejecuta desde: c:\documents and settings\hichou\Bureau\ComboFix.exe
* Creado un nuevo punto de restauración
.
(((((((((((((((((( Archivos creados desde 2008-11-14 - 2008-12-14 )))))))))))))))))))))))))))))))))
.
2008-12-12 14:18 . 2008-12-12 14:18 <REP> d--h----- c:\windows\$hf_mig$
2008-12-11 23:37 . 2008-12-11 23:37 2,560 --a------ c:\windows\_MSRSTRT.EXE
2008-12-11 23:23 . 2008-12-11 23:36 1,963 --a------ c:\windows\EXTRADNS.INI
2008-12-11 23:22 . 2008-12-11 23:22 <REP> d-------- c:\program files\ExtraTools
2008-12-11 23:22 . 1999-05-07 00:00 209,408 --a------ c:\windows\system32\TabCtl32.ocx
2008-12-11 23:22 . 1998-06-24 00:00 200,496 --a------ c:\windows\system32\Dblist32.ocx
2008-12-11 23:22 . 1998-06-18 00:00 89,360 --a------ c:\windows\system32\Vb5db.dll
2008-12-11 22:22 . 1998-06-24 10:57 205,848 --a------ c:\windows\system32\THREED32.OCX
2008-12-11 22:22 . 1998-05-22 00:00 137,736 --a------ c:\windows\system32\COMDLG32.OCX
2008-12-11 15:36 . 2008-12-11 15:36 <REP> d-------- c:\program files\Kaspersky Lab
2008-12-11 15:36 . 2008-12-14 19:26 663,072 --ahs---- c:\windows\system32\drivers\fidbox.dat
2008-12-11 15:36 . 2008-12-14 19:26 172,064 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2008-12-11 15:36 . 2008-12-11 15:36 96,976 --a------ c:\windows\system32\drivers\klin.dat
2008-12-11 15:36 . 2008-12-11 15:36 87,855 --a------ c:\windows\system32\drivers\klick.dat
2008-12-11 15:36 . 2008-12-14 19:26 7,308 --ahs---- c:\windows\system32\drivers\fidbox.idx
2008-12-11 15:36 . 2008-12-14 19:26 2,716 --ahs---- c:\windows\system32\drivers\fidbox2.idx
2008-12-09 18:20 . 2008-12-09 18:20 <REP> d--h----- c:\windows\system32\GroupPolicy
2008-12-08 21:11 . 2008-12-08 21:11 268 --ah----- C:\sqmdata19.sqm
2008-12-08 21:11 . 2008-12-08 21:11 244 --ah----- C:\sqmnoopt19.sqm
2008-12-08 21:08 . 2008-12-08 21:08 268 --ah----- C:\sqmdata18.sqm
2008-12-08 21:08 . 2008-12-08 21:08 244 --ah----- C:\sqmnoopt18.sqm
2008-12-08 21:05 . 2002-01-01 00:15 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-12-08 21:05 . 2002-01-01 00:15 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-12-08 21:05 . 2008-12-07 13:43 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-12-08 21:05 . 2002-01-01 00:15 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-12-08 21:05 . 2002-01-01 00:15 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-12-08 21:05 . 2002-01-01 00:15 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-12-08 21:05 . 2002-01-01 00:15 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-12-08 21:05 . 2008-12-08 21:05 <REP> d-------- c:\documents and settings\Administrateur
2008-12-08 20:48 . 2008-12-08 20:48 268 --ah----- C:\sqmdata17.sqm
2008-12-08 20:48 . 2008-12-08 20:48 244 --ah----- C:\sqmnoopt17.sqm
2008-12-08 20:27 . 2008-12-08 20:27 268 --ah----- C:\sqmdata16.sqm
2008-12-08 20:27 . 2008-12-08 20:27 244 --ah----- C:\sqmnoopt16.sqm
2008-12-08 19:43 . 2008-12-08 19:43 268 --ah----- C:\sqmdata15.sqm
2008-12-08 19:43 . 2008-12-08 19:43 244 --ah----- C:\sqmnoopt15.sqm
2008-12-08 19:20 . 2008-12-08 19:20 268 --ah----- C:\sqmdata13.sqm
2008-12-08 19:20 . 2008-12-08 19:20 244 --ah----- C:\sqmnoopt13.sqm
2008-12-08 19:10 . 2008-12-08 19:10 268 --ah----- C:\sqmdata12.sqm
2008-12-08 19:10 . 2008-12-08 19:10 244 --ah----- C:\sqmnoopt12.sqm
2008-12-08 19:01 . 2008-12-08 19:01 268 --ah----- C:\sqmdata11.sqm
2008-12-08 19:01 . 2008-12-08 19:01 244 --ah----- C:\sqmnoopt11.sqm
2008-12-08 15:05 . 2008-12-08 15:05 268 --ah----- C:\sqmdata07.sqm
2008-12-08 15:05 . 2008-12-08 15:05 244 --ah----- C:\sqmnoopt07.sqm
2008-12-08 14:36 . 2008-12-08 14:36 268 --ah----- C:\sqmdata06.sqm
2008-12-08 14:36 . 2008-12-08 14:36 244 --ah----- C:\sqmnoopt06.sqm
2008-12-08 11:58 . 2008-12-08 11:58 <REP> d-------- c:\program files\Marvell
2008-12-08 11:56 . 2008-12-09 00:03 <REP> d---s---- c:\documents and settings\hichou\UserData
2008-12-07 21:18 . 2008-12-09 17:35 <REP> d-------- c:\documents and settings\hichou\Contacts
2008-12-07 19:17 . 2008-12-07 19:17 268 --ah----- C:\sqmdata03.sqm
2008-12-07 19:17 . 2008-12-07 19:17 244 --ah----- C:\sqmnoopt03.sqm
2008-12-07 17:20 . 2008-12-07 17:20 268 --ah----- C:\sqmdata02.sqm
2008-12-07 17:20 . 2008-12-07 17:20 244 --ah----- C:\sqmnoopt02.sqm
2008-12-07 17:17 . 2008-12-14 19:26 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-12-07 17:15 . 2008-12-07 17:15 268 --ah----- C:\sqmdata01.sqm
2008-12-07 17:15 . 2008-12-07 17:15 244 --ah----- C:\sqmnoopt01.sqm
2008-12-07 16:55 . 2008-12-07 16:55 <REP> d-------- c:\program files\Intel
2008-12-07 16:31 . 2008-12-07 16:31 <REP> d-------- c:\documents and settings\hichou\WINDOWS
2008-12-07 16:31 . 1996-11-05 16:13 299,008 --a------ c:\windows\uninst.exe
2008-12-07 16:31 . 2004-06-24 11:00 6,656 --a------ c:\windows\system32\drivers\AsProbe.sys
2008-12-07 16:31 . 1997-04-22 10:16 6,272 --a------ c:\windows\system32\drivers\ASLM75.SYS
2008-12-07 16:21 . 2005-09-20 10:36 147,456 --a------ c:\windows\system32\igfxres.dll
2008-12-07 16:21 . 2008-12-07 16:21 268 --ah----- C:\sqmdata00.sqm
2008-12-07 16:21 . 2008-12-07 16:21 244 --ah----- C:\sqmnoopt00.sqm
2008-12-07 16:19 . 2008-12-07 16:19 <REP> d----c--- c:\windows\system32\DRVSTORE
2008-12-07 16:19 . 2008-12-10 12:32 <REP> d-------- c:\program files\MSN Messenger
2008-12-07 16:16 . 2008-12-07 16:16 <REP> d-------- c:\program files\Huawei technologies
2008-12-07 16:16 . 2006-09-08 16:24 65,152 --a------ c:\windows\system32\drivers\ewusbser.sys
2008-12-07 16:16 . 2006-09-08 16:24 65,152 --a------ c:\windows\system32\drivers\ewusbmdm.sys
2008-12-07 16:16 . 2006-09-08 16:24 65,152 --a------ c:\windows\system32\drivers\ewusbapp.sys
2008-12-07 16:16 . 2006-09-08 16:24 2,560 --a------ c:\windows\system32\E600CoInstaller.dll
.
(((((((((((((((((((((((((((((((((((((( Reporte Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-11 15:32 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-12-07 17:03 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-07 16:29 --------- d-----w c:\program files\Fichiers communs\InstallShield
2008-12-07 13:47 --------- d-----w c:\program files\microsoft frontpage
2008-12-07 13:45 --------- d-----w c:\program files\Services en ligne
2008-11-11 20:00 218,376 ----a-w c:\windows\system32\klogon.dll
2008-11-11 19:58 25,601 ----a-w c:\windows\system32\drivers\klopp.dat
2008-10-16 14:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 14:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 14:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 14:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 14:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 14:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 14:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 14:08 34,328 ----a-w c:\windows\system32\wups.dll
.
((((((((((((((((((((((((((((((((( Cargando Puntos Reg ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vacías & entradas legítimas predeterminadas no son mostradas
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-11-11 206088]
"HUAWEI Data Card"="c:\program files\Huawei technologies\HUAWEI Mobile Connect\HUAWEIDataCard.exe" [2006-08-18 1024000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-04 04:54 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 2005-09-20 10:32 77824 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2005-09-20 10:36 114688 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 2005-09-20 10:35 94208 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 2004-08-04 02:32 208952 c:\windows\ime\imjp8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
--a------ 2004-08-04 02:31 59392 c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 2004-08-04 02:32 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 2004-08-04 02:32 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
--a------ 2004-09-23 12:41 860160 c:\program files\Analog Devices\SoundMAX\SMax4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2004-10-14 09:11 1388544 c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R2 NwSapAgent;Agent SAP;c:\windows\system32\svchost.exe -k netsvcs [2004-08-04 14336]
R3 hwcdcmdm0;HUAWEI Mobile Connect - 3G Modem;c:\windows\system32\DRIVERS\ewusbmdm.sys [2008-12-07 65152]
R3 hwusbser;HUAWEI Mobile Connect - 3G Application Interface;c:\windows\system32\DRIVERS\ewusbser.sys [2008-12-07 65152]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{169eb877-c469-11dd-a717-806d6172696f}]
\Shell\AutoRun\command - G:\ylr.exe
\Shell\explore\Command - G:\ylr.exe
\Shell\open\Command - G:\ylr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{169eb878-c469-11dd-a717-806d6172696f}]
\Shell\AutoRun\command - H:\ylr.exe
\Shell\explore\Command - H:\ylr.exe
\Shell\open\Command - H:\ylr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{169eb879-c469-11dd-a717-806d6172696f}]
\Shell\AutoRun\command - I:\ylr.exe
\Shell\explore\Command - I:\ylr.exe
\Shell\open\Command - I:\ylr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{169eb87a-c469-11dd-a717-806d6172696f}]
\Shell\AutoRun\command - J:\ylr.exe
\Shell\explore\Command - J:\ylr.exe
\Shell\open\Command - J:\ylr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{169eb87b-c469-11dd-a717-a5ead9bbd2d2}]
\Shell\AutoRun\command - K:\ylr.exe
\Shell\explore\Command - K:\ylr.exe
\Shell\open\Command - K:\ylr.exe
.
.
------- Análisis Suplementario -------
.
uStart Page = hxxp://www.google.co.ma/
mStart Page = about:blank
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
c:\windows\Downloaded Program Files\ewidoOnlineScan.dll - O16 -: {193C772A-87BE-4B19-A7BB-445B226FE9A1}
hxxp://downloads.ewido.net/ewidoOnlineScan.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-14 19:53:08
Windows 5.1.2600 Service Pack 2 NTFS
escaneando procesos ocultos ...
escaneando entradas ocultas de autostart ...
escaneando archivos ocultos ...
el escaneo se completo con exito
archivos ocultos: 0
**************************************************************************
.
Tiempo completado: 2008-12-14 19:54:04
ComboFix-quarantined-files.txt 2008-12-14 19:54:01
Pre-Run: 56 945 176 576 octets libres
Post-Run: 56,960,188,416 octets libres
190 --- E O F --- 2002-01-01 00:23:51
Microsoft Windows XP Professionnel 5.1.2600.2.1252.591.1036.18.247.76 [GMT 0:00]
Se ejecuta desde: c:\documents and settings\hichou\Bureau\ComboFix.exe
* Creado un nuevo punto de restauración
.
(((((((((((((((((( Archivos creados desde 2008-11-14 - 2008-12-14 )))))))))))))))))))))))))))))))))
.
2008-12-12 14:18 . 2008-12-12 14:18 <REP> d--h----- c:\windows\$hf_mig$
2008-12-11 23:37 . 2008-12-11 23:37 2,560 --a------ c:\windows\_MSRSTRT.EXE
2008-12-11 23:23 . 2008-12-11 23:36 1,963 --a------ c:\windows\EXTRADNS.INI
2008-12-11 23:22 . 2008-12-11 23:22 <REP> d-------- c:\program files\ExtraTools
2008-12-11 23:22 . 1999-05-07 00:00 209,408 --a------ c:\windows\system32\TabCtl32.ocx
2008-12-11 23:22 . 1998-06-24 00:00 200,496 --a------ c:\windows\system32\Dblist32.ocx
2008-12-11 23:22 . 1998-06-18 00:00 89,360 --a------ c:\windows\system32\Vb5db.dll
2008-12-11 22:22 . 1998-06-24 10:57 205,848 --a------ c:\windows\system32\THREED32.OCX
2008-12-11 22:22 . 1998-05-22 00:00 137,736 --a------ c:\windows\system32\COMDLG32.OCX
2008-12-11 15:36 . 2008-12-11 15:36 <REP> d-------- c:\program files\Kaspersky Lab
2008-12-11 15:36 . 2008-12-14 19:26 663,072 --ahs---- c:\windows\system32\drivers\fidbox.dat
2008-12-11 15:36 . 2008-12-14 19:26 172,064 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2008-12-11 15:36 . 2008-12-11 15:36 96,976 --a------ c:\windows\system32\drivers\klin.dat
2008-12-11 15:36 . 2008-12-11 15:36 87,855 --a------ c:\windows\system32\drivers\klick.dat
2008-12-11 15:36 . 2008-12-14 19:26 7,308 --ahs---- c:\windows\system32\drivers\fidbox.idx
2008-12-11 15:36 . 2008-12-14 19:26 2,716 --ahs---- c:\windows\system32\drivers\fidbox2.idx
2008-12-09 18:20 . 2008-12-09 18:20 <REP> d--h----- c:\windows\system32\GroupPolicy
2008-12-08 21:11 . 2008-12-08 21:11 268 --ah----- C:\sqmdata19.sqm
2008-12-08 21:11 . 2008-12-08 21:11 244 --ah----- C:\sqmnoopt19.sqm
2008-12-08 21:08 . 2008-12-08 21:08 268 --ah----- C:\sqmdata18.sqm
2008-12-08 21:08 . 2008-12-08 21:08 244 --ah----- C:\sqmnoopt18.sqm
2008-12-08 21:05 . 2002-01-01 00:15 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-12-08 21:05 . 2002-01-01 00:15 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-12-08 21:05 . 2008-12-07 13:43 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-12-08 21:05 . 2002-01-01 00:15 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-12-08 21:05 . 2002-01-01 00:15 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-12-08 21:05 . 2002-01-01 00:15 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-12-08 21:05 . 2002-01-01 00:15 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-12-08 21:05 . 2008-12-08 21:05 <REP> d-------- c:\documents and settings\Administrateur
2008-12-08 20:48 . 2008-12-08 20:48 268 --ah----- C:\sqmdata17.sqm
2008-12-08 20:48 . 2008-12-08 20:48 244 --ah----- C:\sqmnoopt17.sqm
2008-12-08 20:27 . 2008-12-08 20:27 268 --ah----- C:\sqmdata16.sqm
2008-12-08 20:27 . 2008-12-08 20:27 244 --ah----- C:\sqmnoopt16.sqm
2008-12-08 19:43 . 2008-12-08 19:43 268 --ah----- C:\sqmdata15.sqm
2008-12-08 19:43 . 2008-12-08 19:43 244 --ah----- C:\sqmnoopt15.sqm
2008-12-08 19:20 . 2008-12-08 19:20 268 --ah----- C:\sqmdata13.sqm
2008-12-08 19:20 . 2008-12-08 19:20 244 --ah----- C:\sqmnoopt13.sqm
2008-12-08 19:10 . 2008-12-08 19:10 268 --ah----- C:\sqmdata12.sqm
2008-12-08 19:10 . 2008-12-08 19:10 244 --ah----- C:\sqmnoopt12.sqm
2008-12-08 19:01 . 2008-12-08 19:01 268 --ah----- C:\sqmdata11.sqm
2008-12-08 19:01 . 2008-12-08 19:01 244 --ah----- C:\sqmnoopt11.sqm
2008-12-08 15:05 . 2008-12-08 15:05 268 --ah----- C:\sqmdata07.sqm
2008-12-08 15:05 . 2008-12-08 15:05 244 --ah----- C:\sqmnoopt07.sqm
2008-12-08 14:36 . 2008-12-08 14:36 268 --ah----- C:\sqmdata06.sqm
2008-12-08 14:36 . 2008-12-08 14:36 244 --ah----- C:\sqmnoopt06.sqm
2008-12-08 11:58 . 2008-12-08 11:58 <REP> d-------- c:\program files\Marvell
2008-12-08 11:56 . 2008-12-09 00:03 <REP> d---s---- c:\documents and settings\hichou\UserData
2008-12-07 21:18 . 2008-12-09 17:35 <REP> d-------- c:\documents and settings\hichou\Contacts
2008-12-07 19:17 . 2008-12-07 19:17 268 --ah----- C:\sqmdata03.sqm
2008-12-07 19:17 . 2008-12-07 19:17 244 --ah----- C:\sqmnoopt03.sqm
2008-12-07 17:20 . 2008-12-07 17:20 268 --ah----- C:\sqmdata02.sqm
2008-12-07 17:20 . 2008-12-07 17:20 244 --ah----- C:\sqmnoopt02.sqm
2008-12-07 17:17 . 2008-12-14 19:26 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-12-07 17:15 . 2008-12-07 17:15 268 --ah----- C:\sqmdata01.sqm
2008-12-07 17:15 . 2008-12-07 17:15 244 --ah----- C:\sqmnoopt01.sqm
2008-12-07 16:55 . 2008-12-07 16:55 <REP> d-------- c:\program files\Intel
2008-12-07 16:31 . 2008-12-07 16:31 <REP> d-------- c:\documents and settings\hichou\WINDOWS
2008-12-07 16:31 . 1996-11-05 16:13 299,008 --a------ c:\windows\uninst.exe
2008-12-07 16:31 . 2004-06-24 11:00 6,656 --a------ c:\windows\system32\drivers\AsProbe.sys
2008-12-07 16:31 . 1997-04-22 10:16 6,272 --a------ c:\windows\system32\drivers\ASLM75.SYS
2008-12-07 16:21 . 2005-09-20 10:36 147,456 --a------ c:\windows\system32\igfxres.dll
2008-12-07 16:21 . 2008-12-07 16:21 268 --ah----- C:\sqmdata00.sqm
2008-12-07 16:21 . 2008-12-07 16:21 244 --ah----- C:\sqmnoopt00.sqm
2008-12-07 16:19 . 2008-12-07 16:19 <REP> d----c--- c:\windows\system32\DRVSTORE
2008-12-07 16:19 . 2008-12-10 12:32 <REP> d-------- c:\program files\MSN Messenger
2008-12-07 16:16 . 2008-12-07 16:16 <REP> d-------- c:\program files\Huawei technologies
2008-12-07 16:16 . 2006-09-08 16:24 65,152 --a------ c:\windows\system32\drivers\ewusbser.sys
2008-12-07 16:16 . 2006-09-08 16:24 65,152 --a------ c:\windows\system32\drivers\ewusbmdm.sys
2008-12-07 16:16 . 2006-09-08 16:24 65,152 --a------ c:\windows\system32\drivers\ewusbapp.sys
2008-12-07 16:16 . 2006-09-08 16:24 2,560 --a------ c:\windows\system32\E600CoInstaller.dll
.
(((((((((((((((((((((((((((((((((((((( Reporte Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-11 15:32 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-12-07 17:03 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-07 16:29 --------- d-----w c:\program files\Fichiers communs\InstallShield
2008-12-07 13:47 --------- d-----w c:\program files\microsoft frontpage
2008-12-07 13:45 --------- d-----w c:\program files\Services en ligne
2008-11-11 20:00 218,376 ----a-w c:\windows\system32\klogon.dll
2008-11-11 19:58 25,601 ----a-w c:\windows\system32\drivers\klopp.dat
2008-10-16 14:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 14:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 14:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 14:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 14:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 14:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 14:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 14:08 34,328 ----a-w c:\windows\system32\wups.dll
.
((((((((((((((((((((((((((((((((( Cargando Puntos Reg ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vacías & entradas legítimas predeterminadas no son mostradas
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-11-11 206088]
"HUAWEI Data Card"="c:\program files\Huawei technologies\HUAWEI Mobile Connect\HUAWEIDataCard.exe" [2006-08-18 1024000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-04 04:54 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 2005-09-20 10:32 77824 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2005-09-20 10:36 114688 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 2005-09-20 10:35 94208 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 2004-08-04 02:32 208952 c:\windows\ime\imjp8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
--a------ 2004-08-04 02:31 59392 c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 2004-08-04 02:32 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 2004-08-04 02:32 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
--a------ 2004-09-23 12:41 860160 c:\program files\Analog Devices\SoundMAX\SMax4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2004-10-14 09:11 1388544 c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R2 NwSapAgent;Agent SAP;c:\windows\system32\svchost.exe -k netsvcs [2004-08-04 14336]
R3 hwcdcmdm0;HUAWEI Mobile Connect - 3G Modem;c:\windows\system32\DRIVERS\ewusbmdm.sys [2008-12-07 65152]
R3 hwusbser;HUAWEI Mobile Connect - 3G Application Interface;c:\windows\system32\DRIVERS\ewusbser.sys [2008-12-07 65152]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{169eb877-c469-11dd-a717-806d6172696f}]
\Shell\AutoRun\command - G:\ylr.exe
\Shell\explore\Command - G:\ylr.exe
\Shell\open\Command - G:\ylr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{169eb878-c469-11dd-a717-806d6172696f}]
\Shell\AutoRun\command - H:\ylr.exe
\Shell\explore\Command - H:\ylr.exe
\Shell\open\Command - H:\ylr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{169eb879-c469-11dd-a717-806d6172696f}]
\Shell\AutoRun\command - I:\ylr.exe
\Shell\explore\Command - I:\ylr.exe
\Shell\open\Command - I:\ylr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{169eb87a-c469-11dd-a717-806d6172696f}]
\Shell\AutoRun\command - J:\ylr.exe
\Shell\explore\Command - J:\ylr.exe
\Shell\open\Command - J:\ylr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{169eb87b-c469-11dd-a717-a5ead9bbd2d2}]
\Shell\AutoRun\command - K:\ylr.exe
\Shell\explore\Command - K:\ylr.exe
\Shell\open\Command - K:\ylr.exe
.
.
------- Análisis Suplementario -------
.
uStart Page = hxxp://www.google.co.ma/
mStart Page = about:blank
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
c:\windows\Downloaded Program Files\ewidoOnlineScan.dll - O16 -: {193C772A-87BE-4B19-A7BB-445B226FE9A1}
hxxp://downloads.ewido.net/ewidoOnlineScan.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
Rootkit scan 2008-12-14 19:53:08
Windows 5.1.2600 Service Pack 2 NTFS
escaneando procesos ocultos ...
escaneando entradas ocultas de autostart ...
escaneando archivos ocultos ...
el escaneo se completo con exito
archivos ocultos: 0
**************************************************************************
.
Tiempo completado: 2008-12-14 19:54:04
ComboFix-quarantined-files.txt 2008-12-14 19:54:01
Pre-Run: 56 945 176 576 octets libres
Post-Run: 56,960,188,416 octets libres
190 --- E O F --- 2002-01-01 00:23:51
