هذا التقرير الثانى
ComboFix 09-05-18.06 - ayman 05/19/2009 18:28.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.20.1033.18.1015.606 [GMT 3:00]
Running from: c:\documents and settings\ayman\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\windows\system32\rmoc3260.dll
F:\install.exe
.
((((((((((((((((((((((((( Files Created from 2009-04-19 to 2009-05-19 )))))))))))))))))))))))))))))))
.
2009-05-19 15:18 . 2009-05-19 15:18 -------- d-----w c:\program files\Trend Micro
2009-05-19 12:09 . 2009-05-19 12:09 -------- d-----w c:\program files\ESET
2009-05-18 21:58 . 2009-05-18 21:58 -------- d-----w c:\documents and settings\ayman\Local Settings\Application Data\Google
2009-05-18 21:57 . 2009-05-18 21:58 -------- d-----w c:\program files\Google
2009-05-18 05:29 . 2009-05-18 05:29 -------- d-----w c:\program files\OpinionSquare
2009-05-17 19:40 . 2009-05-17 19:40 -------- d-----w c:\documents and settings\ayman\Application Data\NCH Swift Sound
2009-05-17 18:33 . 2009-05-17 18:33 -------- d-----w c:\program files\ClaroCOM
2009-05-17 18:28 . 2009-05-17 18:28 -------- d-----w c:\program files\CallIT
2009-05-17 18:28 . 2009-05-17 18:28 -------- d-----w c:\windows\Downloaded Installations
2009-05-17 18:07 . 2009-05-17 18:07 -------- d-----w c:\program files\iCall
2009-05-17 17:13 . 2009-05-17 17:13 -------- d-----w c:\documents and settings\ayman\Application Data\Skype
2009-05-17 17:13 . 2009-05-17 17:13 -------- d-----w c:\program files\Skype
2009-05-17 17:13 . 2009-05-17 17:13 -------- d-----w c:\program files\Common Files\Skype
2009-05-17 17:13 . 2009-05-17 17:13 -------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-05-17 16:29 . 2009-05-17 16:29 -------- d-----w c:\program files\Kaspersky Lab
2009-05-17 15:30 . 2003-03-18 19:20 1060864 ----a-w c:\windows\system32\MFC71.dll
2009-05-17 15:30 . 2009-05-17 15:30 -------- d-----w c:\program files\Alwil Software
2009-05-17 14:29 . 2009-05-17 14:29 -------- d-sh--w C:\FOUND.001
2009-05-17 09:34 . 2009-05-17 09:34 10 ----a-w c:\windows\popcinfo.dat
2009-05-16 23:47 . 2009-05-16 23:47 -------- d-sh--w C:\FOUND.000
2009-05-16 21:08 . 2009-05-16 21:08 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-05-16 16:10 . 2009-05-16 16:10 -------- d-----w c:\program files\Technitium
2009-05-16 16:07 . 2009-05-16 16:07 -------- d-----w c:\program files\WinPcap
2009-05-16 16:07 . 2009-05-16 16:07 -------- d-----w c:\program files\netcut
2009-05-16 12:45 . 2009-05-16 12:45 -------- d-----w c:\windows\Sun
2009-05-16 08:59 . 2009-05-16 08:59 -------- d-----w c:\program files\AVG
2009-05-16 08:54 . 2009-05-16 08:54 -------- d-----w c:\program files\Opera
2009-05-16 08:08 . 2009-05-16 08:08 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2009-05-15 19:21 . 2009-05-15 19:21 -------- d-----w c:\documents and settings\ayman\Local Settings\Application Data\Identities
2009-05-15 15:57 . 2009-05-15 15:57 12876 ---ha-w c:\windows\system32\mlfcache.dat
2009-05-15 15:36 . 2009-05-15 15:36 -------- d-s---w c:\documents and settings\ayman\UserData
2009-05-15 15:32 . 2009-05-15 15:32 -------- d-----w c:\documents and settings\ayman\Local Settings\Application Data\Apple Computer
2009-05-15 15:32 . 2009-05-15 15:32 -------- d-----w c:\documents and settings\ayman\Application Data\Apple Computer
2009-05-15 15:31 . 2009-05-15 15:31 -------- d-----w c:\program files\Safari
2009-05-15 15:31 . 2009-05-15 15:31 -------- d-----w c:\documents and settings\ayman\Local Settings\Application Data\Apple
2009-05-15 15:31 . 2009-05-15 15:31 -------- d-----w c:\program files\Apple Software Update
2009-05-15 15:31 . 2009-05-15 15:31 -------- d-----w c:\documents and settings\All Users\Application Data\Apple
2009-05-15 11:05 . 2009-05-15 11:05 -------- d-----w c:\documents and settings\ayman\Local Settings\Application Data\ESET
2009-05-15 09:19 . 2009-05-15 09:19 -------- d-----w c:\documents and settings\ayman\Application Data\ESET
2009-05-15 09:18 . 2009-05-15 09:18 -------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-05-15 00:36 . 2009-05-15 00:36 -------- d-----w c:\documents and settings\ayman\Local Settings\Application Data\Yahoo
2009-05-15 00:29 . 2009-05-15 00:29 -------- d-----w c:\documents and settings\ayman\Application Data\Media Player Classic
2009-05-15 00:29 . 2009-05-15 00:29 -------- d-----w c:\program files\MSBuild
2009-05-15 00:29 . 2009-05-15 00:29 2272 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-15 00:26 . 2009-05-15 00:26 -------- d-----w c:\windows\system32\XPSViewer
2009-05-15 00:25 . 2009-05-15 00:25 -------- d-----w c:\program files\Reference Assemblies
2009-05-15 00:24 . 2006-06-29 10:07 14048 ------w c:\windows\system32\spmsg2.dll
2009-05-15 00:19 . 2008-09-16 19:23 168448 ----a-w c:\windows\system32\unrar.dll
2009-05-15 00:19 . 2004-01-25 16:18 217088 ----a-w c:\windows\system32\yv12vfw.dll
2009-05-15 00:19 . 2008-12-07 18:08 795648 ----a-w c:\windows\system32\xvidcore.dll
2009-05-15 00:19 . 2008-12-07 18:08 130048 ----a-w c:\windows\system32\xvidvfw.dll
2009-05-15 00:19 . 2008-11-06 16:37 3596288 ----a-w c:\windows\system32\qt-dx331.dll
2009-05-15 00:19 . 2008-12-11 00:33 86016 ----a-w c:\windows\system32\dpl100.dll
2009-05-15 00:19 . 2008-11-06 16:33 684032 ----a-w c:\windows\system32\divx.dll
2009-05-15 00:19 . 2009-02-09 18:56 67584 ----a-w c:\windows\system32\ff_vfw.dll
2009-05-15 00:19 . 2004-01-11 22:00 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-05-15 00:19 . 2009-05-15 00:19 -------- d-----w c:\program files\K-Lite Codec Pack
2009-05-15 00:18 . 2009-05-15 00:18 -------- d-----w c:\documents and settings\ayman\Application Data\URSoft
2009-05-15 00:18 . 2009-05-15 00:18 -------- d-----w c:\documents and settings\All Users\Application Data\TEMP
2009-05-15 00:18 . 2009-05-15 00:18 -------- d-----w c:\program files\Your Uninstaller 2008
2009-05-15 00:17 . 2009-05-15 00:17 -------- d-----w c:\documents and settings\ayman\Application Data\Webroot
2009-05-15 00:17 . 2009-05-15 00:17 -------- d-----w c:\program files\Common Files\Webroot Shared
2009-05-15 00:17 . 2009-05-15 00:17 -------- d-----w c:\documents and settings\All Users\Application Data\Webroot
2009-05-15 00:17 . 2009-05-15 00:17 -------- d-----w c:\program files\Webroot
2009-05-15 00:16 . 2007-11-26 11:47 194888 ----a-w c:\windows\Unwash6.exe
2009-05-15 00:16 . 2009-05-15 00:16 -------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2009-05-15 00:16 . 2009-05-15 00:16 -------- d-----w c:\program files\Yahoo!
2009-05-15 00:14 . 2009-05-15 00:14 410976 ----a-w c:\windows\system32\deploytk.dll
2009-05-15 00:14 . 2009-05-15 00:14 -------- d-----w c:\program files\Java
2009-05-15 00:09 . 2009-05-15 00:09 -------- d-----w c:\program files\No More Cut
2009-05-15 00:06 . 2009-05-15 00:32 335 ----a-w c:\windows\nsreg.dat
2009-05-15 00:06 . 2009-05-15 00:06 -------- d-----w c:\documents and settings\ayman\Local Settings\Application Data\Mozilla
2009-05-15 00:05 . 2009-05-15 00:05 -------- d-----w c:\documents and settings\ayman\Application Data\IDM
2009-05-15 00:05 . 2009-05-15 00:05 -------- d-----w c:\documents and settings\ayman\Application Data\DMCache
2009-05-15 00:04 . 2009-05-15 00:04 -------- d-----w c:\program files\Internet Download Manager
2009-05-15 00:00 . 2007-10-17 12:12 30720 ----a-r c:\windows\system32\drivers\l251x86.sys
2009-05-15 00:00 . 2009-05-15 00:00 -------- d-----w c:\windows\system32\Atheros_L2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-15 00:33 . 2009-05-15 00:33 -------- d-----w c:\program files\AOL Companion
2009-05-15 00:33 . 2009-05-15 00:33 -------- d-----w c:\program files\Viewpoint
2009-05-15 00:33 . 2009-05-15 00:33 -------- d-----w c:\program files\Common Files\Nullsoft
2009-05-15 00:33 . 2009-05-15 00:33 8552 ----a-w c:\windows\system32\drivers\asctrm.sys
2009-05-15 00:33 . 2009-05-15 00:33 -------- d-----w c:\program files\Real
2009-05-15 00:33 . 2009-05-15 00:33 -------- d-----w c:\program files\Common Files\Real
2009-05-15 00:33 . 2009-05-15 00:33 -------- d-----w c:\program files\Common Files\aolshare
2009-05-15 00:33 . 2009-05-15 00:33 -------- d-----w c:\program files\America Online 8.0
2009-05-15 00:33 . 2009-05-15 00:32 -------- d-----w c:\program files\Common Files\AOL
2009-05-14 23:58 . 2009-05-14 23:58 -------- d-----w c:\program files\Realtek
2009-05-14 23:58 . 2009-05-14 23:58 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-14 23:58 . 2009-05-14 23:58 315392 ----a-w c:\windows\HideWin.exe
2009-05-14 23:58 . 2009-05-14 23:58 -------- d-----w c:\program files\Common Files\InstallShield
2009-05-14 23:50 . 2009-05-14 23:50 -------- d-----w c:\program files\Intel
2009-05-14 23:46 . 2009-05-14 23:48 11744 ----a-w c:\documents and settings\ayman\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-14 23:45 . 2009-05-14 23:45 -------- d-----w c:\program files\iColorFolder
2009-05-14 23:42 . 2009-05-14 23:42 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-04-09 12:21 . 2009-04-09 12:21 33096 ----a-w c:\windows\system32\drivers\epfwndis.sys
2009-03-26 15:35 . 2009-05-07 07:42 210352 ----a-w c:\windows\system32\idmmbc.dll
.
------- Sigcheck -------
[-] 2007-09-29 21:44 2321920 0E8A78B032C8D1D5B1C8F7487D841CF4 c:\windows\system32\ntoskrnl.exe
[-] 2007-06-22 14:27 3597824 79FAC11072B5FFE1E54ED4E2A367E0A2 c:\windows\explorer.exe
[-] 2007-05-01 03:21 172544 799CA26CE13F012F37AEC542913E00A5 c:\windows\system32\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Window Washer"="c:\program files\Webroot\Washer\wwDisp.exe" [2007-11-26 1206600]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-05-15 2807216]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Index Washer"="c:\program files\Webroot\Washer\WashIdx.exe" [2007-11-26 55624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-11-08 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-11-08 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-11-08 137752]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-10-24 1451264]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-10-25 16855552]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2007-10-11 1826816]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ObjectDock.lnk - c:\windows\system32\OpjctDock\ObjectDock.exe [2009-5-15 1826885]
AOL Companion.lnk - c:\program files\AOL Companion\companion.exe [2009-5-15 221258]
America Online 8.0 Tray Icon.lnk - c:\program files\America Online 8.0\aoltray.exe [2009-5-15 36940]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 1 (0x1)
"NoSMBalloonTip"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 1 (0x1)
"NoSMBalloonTip"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.321\\English\\setup.exe"=
"c:\\Program Files\\iCall\\iCall.exe"=
"c:\\program files\\opinionsquare\\opnsqr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8000:UDP"= 8000:UDP:Express Talk RTP Incoming Audio (UDP)
"5070:UDP"= 5070:UDP:Express Talk Sip Incoming Calls (UDP)
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [24/10/2008 08:53 مساءاً 34824]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [24/10/2008 08:51 مساءاً 468224]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [15/05/2009 03:16 صباحاً 598856]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [03/08/2005 12:10 صباحاً 32512]
.
Contents of the 'Scheduled Tasks' folder
2009-05-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-VisualTask - Windows\\system32\\VisualTask\\VisualTask.exe
HKCU-Run-eyeBeam SIP Client - (no file)
HKU-Default-Run-VisualTask - Windows\\system32\\VisualTask\\VisualTask.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.inbox.com/?tb_id=80028
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
TCP: {F00B39F7-0745-4A44-97FA-CB5E2A140B88} = 217.52.47.140,217.52.47.130
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\ayman\Application Data\Mozilla\Firefox\Profiles\1xji6dov.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&tbid=60195&qkw=
FF - component: c:\documents and settings\ayman\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-19 18:29
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(636)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(692)
c:\windows\system32\SETUPAPI.dll
.
Completion time: 2009-05-19 18:30
ComboFix-quarantined-files.txt 2009-05-19 15:30
Pre-Run: 3,697,713,152 bytes free
Post-Run: 3,690,536,960 bytes free
219