التقرير الأول
SmitFraudFix v2.293
Scan done at 13:41:02.35, Fri 02/22/2008
Run from C:\Documents and Settings\Administrator\«ل¥ ںéêè¢ \¦ںںںں­\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is FAT32
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CS2\Services\Tcpip\..\{4E9B49D1-D151-4A4B-95F3-648E2B091F79}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
التقرير الثاني
15/02/1429 01:45:11 م Engine version =5200.2160
15/02/1429 01:45:11 م AntiVirus DAT version =5175.0000
15/02/1429 01:45:11 م Number of detection signatures in EXTRA.DAT =None
15/02/1429 01:45:11 م Names of detection signatures in EXTRA.DAT =None
15/02/1429 01:45:06 م Scan Started MOHAMMED\Administrator On-Demand Scan
15/02/1429 01:45:40 م Deleted Administrator c:\documents and settings\administrator\s\administrator@atdmt[2].txt\00000000.ie -Atdmt(Potentially Unwanted Program)
15/02/1429 01:45:41 م Deleted Administrator c:\documents and settings\administrator\s\administrator@pro-market[2].txt\00000000.ie -ProMarket(Potentially Unwanted Program)
15/02/1429 01:45:41 م Deleted Administrator c:\documents and settings\administrator\s\administrator@pro-market[2].txt\00000000.ie -ProMarket(Potentially Unwanted Program)
15/02/1429 01:45:41 م Deleted Administrator c:\documents and settings\administrator\s\administrator@2o7[2].txt\00000000.ie -2O7(Potentially Unwanted Program)
15/02/1429 01:45:42 م Deleted Administrator c:\documents and settings\administrator\s\administrator@doubleclick[1].txt\00000000.ie -Doubleclick(Potentially Unwanted Program)
15/02/1429 01:45:43 م Deleted Administrator c:\documents and settings\administrator\s\administrator@real[2].txt\00000000.ie -Real(Potentially Unwanted Program)
15/02/1429 01:46:52 م Not scanned (The file is encrypted) Administrator c:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\.IE5\ANIBML2Z\rebuilt.%D9%86%D8%A7%D8%B1%20%D8%AD%D8%A7%D9%85%D9%8A%D8%A9[1].rar\럩 .MP3
15/02/1429 01:47:12 م Not scanned (The file is encrypted) Administrator c:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\.IE5\M7KL2XUZ\h9[1].zip\埘 驟 㠩.PDF
15/02/1429 01:47:24 م Deleted Administrator c:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\.IE5\W3U3CZSV\nokia4me[1].htm\00000036.js JS/Downloader-BDQ(Trojan)
15/02/1429 01:47:49 م Deleted Administrator C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\سطح المكتب\خااااص\SMITFRAUDFIX.EXE PrcViewer(Potentially Unwanted Program)
15/02/1429 01:48:28 م No Action Taken (Clean failed) Administrator c:\Documents and Settings\Administrator\سطح المكتب\خااااص\SmitfraudFix.exe\PROCESS.EXE PrcViewer(Potentially Unwanted Program)
15/02/1429 01:48:28 م Deleted Administrator C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\سطح المكتب\خااااص\SMITFRAUDFIX.EXE Generic PUP.g(Potentially Unwanted Program)
15/02/1429 01:48:40 م No Action Taken (Clean failed) Administrator c:\Documents and Settings\Administrator\سطح المكتب\خااااص\SmitfraudFix.exe\REBOOT.EXE Generic PUP.g(Potentially Unwanted Program)
15/02/1429 01:48:48 م Deleted Administrator C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\سطح المكتب\خااااص\SMITFRAUDFIX\PROCESS.EXE PrcViewer(Potentially Unwanted Program)
15/02/1429 01:48:48 م Deleted Administrator c:\Documents and Settings\Administrator\سطح المكتب\خااااص\SmitfraudFix\Process.exe PrcViewer(Potentially Unwanted Program)
15/02/1429 01:48:48 م Deleted Administrator C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\سطح المكتب\خااااص\SMITFRAUDFIX\REBOOT.EXE Generic PUP.g(Potentially Unwanted Program)
15/02/1429 01:48:49 م Deleted Administrator c:\Documents and Settings\Administrator\سطح المكتب\خااااص\SmitfraudFix\Reboot.exe Generic PUP.g(Potentially Unwanted Program)
15/02/1429 01:49:24 م Deleted Administrator C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\KASPERSKY LAB\AVP7\PDMHIST\4CC.1F058DCA01C8753F.HISTORY\00000183.BAK PrcViewer(Potentially Unwanted Program)
15/02/1429 01:49:57 م No Action Taken (Clean failed) Administrator c:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\PdmHist\4cc.1F058DCA01C8753F.history\00000183.bak PrcViewer(Potentially Unwanted Program)
15/02/1429 01:50:20 م Deleted Administrator C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\KASPERSKY LAB\AVP7\PDMHIST\EBC.1F70D79C01C8753F.HISTORY\00000184.BAK PrcViewer(Potentially Unwanted Program)
15/02/1429 01:50:59 م No Action Taken (Clean failed) Administrator c:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\PdmHist\ebc.1F70D79C01C8753F.history\00000184.bak PrcViewer(Potentially Unwanted Program)
15/02/1429 01:51:10 م Delete failed (Clean failed) Administrator c:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\PdmHist\f40.F0AE582A01C8753F.history\00000005.bak\00000036.js JS/Downloader-BDQ(Trojan)
15/02/1429 01:51:10 م Deleted Administrator C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\KASPERSKY LAB\AVP7\PDMHIST\F40.F0AE582A01C8753F.HISTORY\00000006.BAK PrcViewer(Potentially Unwanted Program)
15/02/1429 01:51:32 م Delete failed (Clean failed) Administrator c:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\PdmHist\f40.F0AE582A01C8753F.history\00000006.bak PrcViewer(Potentially Unwanted Program)
15/02/1429 01:51:32 م Deleted Administrator C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\KASPERSKY LAB\AVP7\PDMHIST\F40.F0AE582A01C8753F.HISTORY\00000007.BAK Generic PUP.g(Potentially Unwanted Program)
15/02/1429 01:51:49 م Delete failed (Clean failed) Administrator c:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\PdmHist\f40.F0AE582A01C8753F.history\00000007.bak Generic PUP.g(Potentially Unwanted Program)
15/02/1429 02:03:19 م Not scanned (The file is encrypted) Administrator e:\سطح المكتب\أبونواااااااااااااف\Zyzoom_Kaspersky_Internet_Security_7[1].0.0.123.rar\ZYZOOM_KASPERSKY_INTERNET_SECURITY_7.0.0.123.EXE\ZYZOOM.EXE\CLICK1.OGG
15/02/1429 02:03:31 م Not scanned (The file is encrypted) Administrator e:\سطح المكتب\أبونواااااااااااااف\zyzoom_kis7_lang.exe\CLICK1.OGG
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Scan Summary
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Processes scanned : 26
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Processes detected : 0
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Processes cleaned : 0
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Boot sectors scanned : 4
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Boot sectors detected: 0
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Boot sectors cleaned : 0
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Files scanned : 35583
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Files with detections: 9
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator File detections : 18
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Files cleaned : 0
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Files deleted : 3
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Files not scanned : 32
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Scan Summary (Registry Scanning)
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Keys scanned : 25804
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Keys detected : 0
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Keys cleaned : 0
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Keys deleted : 0
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Scan Summary ( Scanning)
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator s scanned : 876
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator s detected : 6
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator s cleaned : 0
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator s deleted : 6
15/02/1429 02:05:29 م Scan Summary MOHAMMED\Administrator Run time : 0:20:23
15/02/1429 02:05:29 م Scan Complete MOHAMMED\Administrator On-Demand Scan