تقـرير الاداة :
ComboFix 09-06-06.04 - Maad 06/07/2009 17:27.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.1013.637 [GMT 3:00]
Running from: c:\documents and settings\Maad\My Documents\ComboFix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Fonts\PATTERN.ttf
c:\windows\IE4 Error Log.txt
.
((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 )))))))))))))))))))))))))))))))
.
2009-06-07 14:21 . 2009-06-07 14:21 -------- d-----w- c:\program files\Trend Micro
2009-06-05 15:57 . 2009-06-05 15:57 -------- d-----w- c:\windows\system32\LogFiles
2009-06-05 15:55 . 2009-06-05 15:55 -------- d-----w- c:\windows\speech
2009-06-05 15:54 . 2009-06-05 15:55 -------- d-----w- c:\program files\Golden Al-Wafi Translator
2009-06-05 15:54 . 2009-06-05 15:54 172032 ------w- c:\windows\Setup1.exe
2009-06-05 15:54 . 2009-06-05 15:54 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-06-05 15:27 . 2009-06-05 15:27 -------- d-----w- c:\documents and settings\Maad\Local Settings\Application Data\Opera
2009-06-05 15:27 . 2009-06-05 15:27 -------- d-----w- c:\program files\Opera
2009-06-05 15:13 . 2009-06-05 15:13 -------- d-----w- c:\program files\CCleaner
2009-05-28 21:35 . 2009-05-28 21:35 -------- d-----w- c:\documents and settings\Maad\Application Data\Jane s Hotel Family Hero
2009-05-21 19:48 . 2009-05-21 19:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Trymedia
2009-05-20 20:36 . 2009-05-20 20:36 -------- d-s---w- c:\documents and settings\Maad\UserData
2009-05-12 14:32 . 2009-05-12 14:32 -------- d-----w- c:\windows\Sun
2009-05-11 08:17 . 2009-05-11 10:51 -------- d-----w- c:\documents and settings\All Users\Application Data\FarmFrenzy2
2009-05-11 08:16 . 2009-05-11 08:16 -------- d-----w- c:\documents and settings\Maad\Application Data\PlayFirst
2009-05-11 08:16 . 2009-05-11 08:16 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-05-10 19:49 . 2009-05-10 19:49 -------- d-----w- c:\program files\Common Files\Nero
2009-05-10 19:49 . 2009-05-10 19:52 -------- d-----w- c:\program files\Nero 9
2009-05-10 19:47 . 2009-05-12 13:06 -------- d-----w- c:\documents and settings\Maad\Local Settings\Application Data\Adobe
2009-05-10 19:45 . 2009-05-10 19:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-05-10 19:45 . 2009-05-10 19:45 -------- d-----w- c:\program files\Yahoo!
2009-05-10 19:44 . 2009-05-10 19:44 -------- d-----w- c:\program files\MSN Messenger
2009-05-10 19:44 . 2009-05-10 19:44 -------- d-----w- c:\program files\Gogago
2009-05-10 19:44 . 2008-06-11 07:41 6294528 ----a-w- c:\windows\system32\MioEncoder1.dll
2009-05-10 19:43 . 2009-05-10 19:43 -------- d-----w- c:\program files\Common Files\xing shared
2009-05-10 19:42 . 2009-05-10 19:42 -------- d-----w- c:\program files\Common Files\Real
2009-05-10 19:42 . 2009-05-10 19:43 -------- d-----w- c:\program files\Real
2009-05-10 19:40 . 2009-05-10 19:47 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-10 19:39 . 2009-05-10 19:39 -------- d-----w- c:\program files\Nokia
2009-05-10 19:38 . 2009-06-07 14:27 -------- d-----w- c:\program files\ESET
2009-05-10 19:35 . 2009-05-10 19:35 -------- d-----w- c:\documents and settings\Maad\Local Settings\Application Data\Macromedia
2009-05-10 19:34 . 2009-05-10 19:34 45056 ----a-r- c:\documents and settings\Maad\Application Data\Microsoft\Installer\{91057632-CA70-413C-B628-2D3CDBBB906B}\ARPPRODUCTICON.exe
2009-05-10 19:34 . 2009-05-10 19:34 45056 ----a-r- c:\documents and settings\Maad\Application Data\Microsoft\Installer\{885A63EA-382B-4DD4-A755-14809B8557D6}\ARPPRODUCTICON.exe
2009-05-10 19:34 . 2009-05-10 19:34 -------- d-----w- c:\windows\system32\QuickTime
2009-05-10 19:34 . 2009-05-10 19:34 -------- d-----w- c:\program files\Common Files\Macromedia
2009-05-10 19:34 . 2009-05-10 19:34 -------- d-----w- c:\program files\Macromedia
2009-05-10 19:33 . 2009-05-10 19:33 -------- d-----w- c:\windows\Downloaded Installations
2009-05-10 19:31 . 2001-01-12 15:04 46352 ----a-w- c:\windows\setdebug.exe
2009-05-10 19:30 . 2009-05-10 19:30 -------- d-----w- c:\program files\Common Files\Java
2009-05-10 19:30 . 2009-05-10 19:30 -------- d-----w- c:\documents and settings\Maad\Local Settings\Application Data\Sun
2009-05-10 19:30 . 2009-05-25 11:42 -------- d-----w- c:\documents and settings\Maad\Local Settings\Application Data\Google
2009-05-10 19:30 . 2009-06-07 14:24 -------- d-----w- c:\program files\FlashGet
2009-05-10 19:29 . 2009-05-10 19:30 -------- d-----w- c:\program files\Google
2009-05-10 19:29 . 2009-05-10 19:29 -------- d-----w- c:\program files\LingvoSoft
2009-05-10 19:24 . 2009-05-10 19:24 -------- d-----w- c:\program files\WinAVI MP4 Converter
2009-05-10 19:23 . 2009-05-10 19:23 -------- d-----w- c:\program files\All Video Converter
2009-05-10 19:23 . 2009-05-10 19:23 -------- d-----w- c:\program files\All To All AudioConvert
2009-05-10 19:23 . 2009-05-10 19:23 -------- d-----w- c:\documents and settings\All Users\Application Data\ACD Systems
2009-05-10 19:23 . 2009-05-10 19:23 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-05-10 19:23 . 2009-05-10 19:23 -------- d-----w- c:\program files\ACD Systems
2009-05-10 19:22 . 2009-05-10 19:22 -------- d-----w- c:\documents and settings\Maad\Local Settings\Application Data\Downloaded Installations
2009-05-10 19:20 . 2009-05-10 19:20 -------- d-----w- c:\program files\Motorola
2009-05-10 19:20 . 2001-08-17 10:57 16128 -c--a-w- c:\windows\system32\dllcache\modemcsa.sys
2009-05-10 19:20 . 2001-08-17 10:57 16128 ----a-w- c:\windows\system32\drivers\MODEMCSA.sys
2009-05-10 19:20 . 2007-01-29 22:22 196608 ----a-w- c:\windows\system32\sm56co6a.dll
2009-05-10 19:20 . 2007-01-29 22:26 984832 ----a-w- c:\windows\system32\drivers\smserial.sys
2009-05-10 19:20 . 2004-12-29 11:01 73728 ----a-w- c:\windows\system32\sm56co.dll
2009-05-10 19:05 . 2003-06-18 14:31 17920 ----a-w- c:\windows\system32\mdimon.dll
2009-05-10 19:05 . 2009-05-10 19:05 -------- d-----w- c:\documents and settings\Maad\Application Data\Media Player Classic
2009-05-10 19:05 . 2009-05-10 19:05 -------- d-----w- c:\program files\Microsoft.NET
2009-05-10 19:04 . 2009-05-10 19:04 -------- d-----w- c:\program files\Microsoft Works
2009-05-10 19:04 . 2009-05-10 19:04 -------- d-----w- c:\documents and settings\Maad\Local Settings\Application Data\ACD Systems
2009-05-10 19:04 . 2009-05-10 19:04 -------- d-----w- c:\documents and settings\Maad\Application Data\ACD Systems
2009-05-10 19:04 . 2009-05-10 19:04 -------- d-----w- c:\windows\SHELLNEW
2009-05-10 19:01 . 2009-05-10 19:01 -------- d--h--r- C:\MSOCache
2009-05-10 19:00 . 2008-01-03 14:10 105856 ----a-r- c:\windows\system32\drivers\Rtenicxp.sys
2009-05-10 19:00 . 2009-05-10 19:00 -------- d-----w- c:\windows\OPTIONS
2009-05-10 19:00 . 2009-05-10 19:00 -------- d-----w- c:\documents and settings\Maad\Application Data\InstallShield
2009-05-10 18:58 . 2004-08-03 20:07 2944 ----a-w- c:\windows\system32\drivers\drmkaud.sys
2009-05-10 18:57 . 2008-02-14 09:04 4676096 ------r- c:\windows\system32\drivers\RtkHDAud.sys
2009-05-10 18:57 . 2008-02-13 06:31 16857600 ------r- c:\windows\RTHDCPL.exe
2009-05-10 18:57 . 2007-06-28 08:44 2165760 ------r- c:\windows\MicCal.exe
2009-05-10 18:57 . 2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
2009-05-10 18:57 . 2009-05-10 19:00 -------- d-----w- c:\program files\Realtek
2009-05-10 18:57 . 2006-05-04 08:26 2808832 ------r- c:\windows\alcwzrd.exe
2009-05-10 18:57 . 2009-05-10 18:57 315392 ----a-w- c:\windows\HideWin.exe
2009-05-10 18:57 . 2007-07-26 09:09 520192 ------r- c:\windows\RtlExUpd.dll
2009-05-10 18:57 . 2009-05-10 19:33 -------- d-----w- c:\program files\Common Files\InstallShield
2009-05-10 18:53 . 2009-05-10 19:45 -------- dc----w- c:\windows\system32\DRVSTORE
2009-05-10 18:53 . 2009-05-10 18:53 -------- d-----w- c:\program files\Intel
2009-05-10 18:53 . 2007-12-12 07:56 53248 ----a-r- c:\windows\system32\CSVer.dll
2009-05-10 18:53 . 2009-05-10 18:53 -------- d-----w- C:\Intel
2009-05-10 18:53 . 2009-05-10 18:53 -------- d-----w- c:\program files\Browser Configuration Utility
2009-05-10 18:53 . 2008-05-02 12:08 146528 ----a-w- c:\windows\system32\dvmurl.dll
2009-05-10 18:53 . 2009-05-10 19:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-10 18:51 . 2009-05-10 18:59 16608 ----a-w- c:\windows\gdrv.sys
2009-05-10 18:49 . 2001-08-23 11:00 1677824 -c--a-w- c:\windows\system32\dllcache\chsbrkr.dll
2009-05-10 18:49 . 2001-08-23 11:00 1677824 ----a-w- c:\windows\system32\chsbrkr.dll
2009-05-10 18:49 . 2001-08-23 11:00 838144 -c--a-w- c:\windows\system32\dllcache\chtbrkr.dll
2009-05-10 18:49 . 2001-08-23 11:00 838144 ----a-w- c:\windows\system32\chtbrkr.dll
2009-05-10 18:49 . 2001-08-23 11:00 70656 -c--a-w- c:\windows\system32\dllcache\korwbrkr.dll
2009-05-10 18:49 . 2001-08-23 11:00 70656 ----a-w- c:\windows\system32\korwbrkr.dll
2009-05-10 18:49 . 2001-08-23 11:00 98304 -c--a-w- c:\windows\system32\dllcache\msir3jp.dll
2009-05-10 18:49 . 2001-08-23 11:00 98304 ----a-w- c:\windows\system32\msir3jp.dll
2009-05-10 18:49 . 2001-08-23 11:00 19456 -c--a-w- c:\windows\system32\dllcache\agt0404.dll
2009-05-10 18:49 . 2001-08-23 11:00 10096640 -c--a-w- c:\windows\system32\dllcache\hwxcht.dll
2009-05-10 18:49 . 2001-08-23 11:00 19456 -c--a-w- c:\windows\system32\dllcache\agt0804.dll
2009-05-10 18:46 . 2009-05-10 18:46 -------- d-----w- c:\windows\system32\wbem\MUI
2009-05-10 18:45 . 2003-10-10 12:00 57344 ----a-w- c:\windows\system32\WMErrAra.dll
2009-05-10 18:41 . 2009-05-10 18:41 -------- d-s---w- c:\windows\system32\Microsoft
2009-05-10 18:41 . 2009-05-10 18:41 -------- d-sh--w- c:\documents and settings\LocalService
2009-05-10 18:41 . 2009-05-10 18:41 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Microsoft
2009-05-10 18:21 . 2009-05-10 18:21 -------- d-----w- C:\folder2.0
2009-05-10 18:07 . 2001-08-17 10:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-05-10 18:07 . 2001-08-17 10:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-05-10 17:42 . 2001-08-17 11:02 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-05-10 17:42 . 2001-08-17 11:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-06 15:22 . 2009-05-10 18:42 195080 ----a-w- c:\documents and settings\Maad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-12 13:22 . 2009-05-12 13:22 495 ---h--w- C:\Program FilesDesktop.ini
2009-05-10 19:42 . 2009-05-10 19:32 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-05-10 19:42 . 2009-05-10 19:32 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-05-10 19:32 . 2009-05-10 19:32 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-05-10 19:31 . 2009-05-10 19:31 2232 ----a-w- c:\windows\java\Packages\Data\D75BH3RL.DAT
2009-05-10 19:31 . 2009-05-10 19:31 155995 ----a-w- c:\windows\java\Packages\O7FZNFBF.ZIP
2009-05-10 19:31 . 2009-05-10 19:31 2678 ----a-w- c:\windows\java\Packages\Data\X7LR5JJX.DAT
2009-05-10 19:31 . 2009-05-10 19:31 2678 ----a-w- c:\windows\java\Packages\Data\JZNPJTRL.DAT
2009-05-10 19:31 . 2009-05-10 19:31 2678 ----a-w- c:\windows\java\Packages\Data\B9JRRT3F.DAT
2009-05-10 19:31 . 2009-05-10 19:31 2678 ----a-w- c:\windows\java\Packages\Data\AR9B9BV1.DAT
2009-05-10 19:31 . 2009-05-10 19:31 2678 ----a-w- c:\windows\java\Packages\Data\
0F5RTR37.DAT
2009-05-10 19:31 . 2009-05-10 19:30 -------- d-----w- c:\program files\Java
2009-05-10 18:46 . 2009-05-10 07:59 166455 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-10 08:06 . 2009-05-10 08:06 512096 ----a-w- c:\windows\system32\drivers\amon.sys
2009-05-10 08:06 . 2009-05-10 08:06 298104 ----a-w- c:\windows\system32\imon.dll
2009-05-10 08:06 . 2009-05-10 08:06 15424 ----a-w- c:\windows\system32\drivers\nod32drv.sys
2009-05-10 08:01 . 2009-05-10 08:01 -------- d-----w- c:\program files\microsoft frontpage
2009-05-10 07:57 . 2009-05-10 07:57 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-05-10 07:56 . 2009-05-10 07:56 -------- d-----w- c:\program files\Windows Media Connect 2
.
------- Sigcheck -------
[-] 2006-08-15 23:28 2058368 D20855E9A650415E4F65E0CE249839BD c:\windows\system32\ntkrnlpa.exe
[-] 2007-12-31 14:00 1580544 6E266AAF4168B3569A330C61AB01F6B4 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-11-06 3810544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="m‘|\ü" [X]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2005-11-23 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-05 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-05 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-05 137752]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-29 638976]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_09\bin\jusched.exe" [2006-09-07 49263]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-10 185896]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-05-10 949376]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-02-13 16857600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [10/05/2009 11:06 ص 15424]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Device Detector - DevDetect.exe
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Download All by FlashGet - c:\program files\FlashGet\jc_all.htm
IE: Download using FlashGet - c:\program files\FlashGet\jc_link.htm
IE: Download Video on This Page - c:\program files\Gogago\YouTube Video Downloader\IEPage.html
IE: Download Video This Links To - c:\program files\Gogago\YouTube Video Downloader\IELink.html
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
IE: {{7966A32A-5783-4F0B-824C-09077C023080} - c:\program files\Gogago\YouTube Video Downloader\IEPage.html
LSP: c:\windows\system32\imon.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-07 17:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(764)
c:\windows\system32\imon.dll
.
Completion time: 2009-06-07 17:31
ComboFix-quarantined-files.txt 2009-06-07 14:31
Pre-Run: 24,585,543,680 bytes free
Post-Run: 24,726,859,776 bytes free
228