هذا التقرير الاول اخوي حمود
ComboFix 08-12-14.03 - Administrator 12/15/2008 0:37:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.2037.1679 [GMT 3:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\
06EA0A93.cfg
c:\windows\system32\
08223B03.cfg
c:\windows\system32\14F7F80A.cfg
c:\windows\system32\2EF0D734.cfg
c:\windows\system32\34A25F04.cfg
c:\windows\system32\3D144530.cfg
c:\windows\system32\4D023DE9.cfg
c:\windows\system32\66AFCB56.cfg
c:\windows\system32\950D1600.cfg
c:\windows\system32\9CA963CA.cfg
c:\windows\system32\B3721C07.cfg
c:\windows\system32\D9C002DD.cfg
c:\windows\system32\DA63E650.cfg
c:\windows\system32\DFB3DAC5.cfg
c:\windows\system32\E0D39066.cfg
c:\windows\system32\F8E07BB2.cfg
c:\windows\system32\FFAE967F.cfg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6457AED
-------\Legacy_B160485
-------\Service_6457aed
-------\Service_b160485
-------\Service_b71fe93
((((((((((((((((((((((((( Files Created from 2008-11-14 to 2008-12-14 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-14 21:39 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-12-14 21:39 --------- d-----w c:\documents and settings\Administrator\Application Data\DMCache
2008-12-14 21:38 5,740 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-14 21:38 462,368 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-14 21:38 2,632 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-12-14 21:38 147,488 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-12-14 01:56 96,976 ----a-w c:\windows\system32\drivers\klin.dat
2008-12-14 01:56 87,855 ----a-w c:\windows\system32\drivers\klick.dat
2008-12-14 01:27 --------- d-----w c:\program files\Kaspersky Lab
2008-12-11 23:28 --------- d-----w c:\program files\MessengerDiscovery
2008-12-11 23:21 --------- d-----w c:\program files\MSN Messenger
2008-11-30 21:58 --------- d-----w c:\program files\ESET
2008-11-30 21:58 --------- d-----w c:\documents and settings\All Users\Application Data\ESET
2008-11-30 20:58 --------- d-----w c:\documents and settings\All Users\Application Data\Zoom Player
2008-11-26 23:07 --------- d-----w c:\program files\ShadowStor
2008-11-06 14:53 --------- d-----w c:\program files\BreakPoint Software
2008-11-05 16:17 --------- d-----w c:\program files\Faronics
2008-11-05 10:13 --------- d-----w c:\program files\Microsoft Works
2008-11-05 09:48 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-11-05 09:47 --------- d-----w c:\program files\Messenger Plus! Live
2008-11-05 09:47 --------- d-----w c:\program files\Circle Developement
2008-11-05 09:45 --------- d-----w c:\program files\iVocalize Web Conference 4
2008-11-05 09:39 --------- d-----w c:\program files\Java
2008-11-05 09:32 --------- d-----w c:\program files\Common Files\Java
2008-11-05 01:44 --------- d-----w c:\documents and settings\Administrator\Application Data\IDM
2008-11-05 01:36 155,995 ----a-w c:\windows\java\Packages\GV9NLBLV.ZIP
2008-11-05 01:33 --------- d-----w c:\program files\Zoom Player
2008-11-05 01:31 --------- d-----w c:\program files\MONOGRAM AMR SplitterDecoder
2008-11-05 01:31 --------- d-----w c:\program files\DScaler5
2008-11-05 01:31 --------- d-----w c:\program files\CD Audio Reader Filter
2008-11-05 01:30 --------- d-----w c:\program files\RealMedia
2008-11-05 01:30 --------- d-----w c:\program files\OpenSource Flash Video Splitter
2008-11-05 01:25 --------- d-----w c:\program files\SHOUTcast Source
2008-11-05 01:25 --------- d-----w c:\program files\Haali
2008-11-05 01:24 --------- d-----w c:\program files\ffdshow
2008-11-05 01:24 --------- d-----w c:\program files\DSP-worx
2008-11-05 01:21 --------- d-----w c:\program files\DirectVobSub
2008-11-05 01:19 --------- d-----w c:\program files\Common Files\Real
2008-11-05 01:07 --------- d-----w c:\program files\No-IP
2008-11-05 01:04 --------- d-----w c:\documents and settings\All Users\Application Data\GRETECH
2008-11-05 01:04 --------- d-----w c:\documents and settings\Administrator\Application Data\GRETECH
2008-11-05 01:03 --------- d-----w c:\program files\GRETECH
2008-11-05 00:49 --------- d-----w c:\program files\Windows Live
2008-11-05 00:40 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-11-05 00:35 --------- d-----w c:\program files\Internet Download Manager
2008-11-05 00:31 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-05 00:24 16,608 ----a-w c:\windows\gdrv.sys
2008-11-05 00:24 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-05 00:24 --------- d-----w c:\program files\Realtek
2008-11-05 00:24 --------- d-----w c:\documents and settings\Administrator\Application Data\InstallShield
2008-11-05 00:22 315,392 ----a-w c:\windows\HideWin.exe
2008-11-05 00:22 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-05 00:20 --------- d-----w c:\program files\Intel
2008-11-04 23:51 --------- d-----w c:\program files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [11/05/2008 03:35 AM 2562560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="m‘|\ü" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [09/05/2007 12:13 PM 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [09/05/2007 12:13 PM 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [09/05/2007 12:13 PM 137752]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [07/12/2007 04:00 AM 132496]
"SuNotification"="c:\program files\ShadowStor\ShadowUser\suatshut.exe" [01/12/2005 11:49 PM 40960]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"RTHDCPL"="RTHDCPL.EXE" [02/13/2008 09:31 AM 16857600 c:\windows\RTHDCPL.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ShadowUser Pro Edition.lnk - c:\program files\ShadowStor\ShadowUser\ShadowUser.exe [2005-01-12 921600]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sunotify]
01/12/2005 11:49 PM 90112 c:\windows\system32\sunotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\HelpSvc.exe]
"Debugger"=ntsd -d
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UIHost.kxp]
"Debugger"=ntsd -d
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\english\\setup.exe"=
"c:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3359:TCP"= 3359:TCP:WWW
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R0 Shadow;Shadow;c:\windows\system32\drivers\Shadow.sys [2005-01-25 114624]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe /s c:\windows\nod32fixtemdono.reg [2001-08-23 3584]
S2 zobijzm;zobijzm;c:\windows\system32\svchost.exe -k netsvcs [2004-08-04 14336]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
zobijzm
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{12316E69-4CE5-4CD7-A174-C0BD57529D5A} - 12316E69.dll
ShellExecuteHooks-{93DEE065-EC9B-4505-ADD3-19880AD3C38F} - 93DEE065.dll
ShellExecuteHooks-{29EA67E0-9EE5-4D1A-A056-5B7BDAC4CF97} - 29EA67E0.dll
ShellExecuteHooks-{7E983C60-EBF5-4A36-BE25-EA26ED55052B} - 7E983C60.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
O16 -: Microsoft XML Parser for Java -
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-15 00:39:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1000)
c:\windows\system32\klogon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Internet Download Manager\IEMonitor.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 12/15/2008 0:40:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-14 21:40:47
Pre-Run: 21,094,412,288 bytes free
Post-Run: 21,180,358,656 bytes free
188