وهذا تقرير الكومب فكس
ComboFix 09-06-11.06 - win 06/12/2009 14:13.3 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.502.321 [GMT 3:00]
Running from: c:\documents and settings\win\My Documents\Downloads\Programs\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
.
((((((((((((((((((((((((( Files Created from 2009-05-12 to 2009-06-12 )))))))))))))))))))))))))))))))
.
2009-06-11 23:11 . 2009-06-11 23:11 -------- d-----w- c:\documents and settings\win\DoctorWeb
2009-06-09 22:14 . 2009-06-09 22:14 -------- d-----w- c:\documents and settings\All Users\Application Data\SWiSHMax2WorkFolder
2009-06-09 22:05 . 2009-06-09 22:05 -------- d-----w- c:\program files\Common Files\SWiSHzone.com
2009-06-09 22:05 . 2009-06-09 22:05 -------- d-----w- c:\program files\SWiSH Max2
2009-06-01 08:03 . 2009-06-01 08:27 6496250 ----a-w- c:\documents and settings\win\Application Data\IDM\DwnlData\win\netbeans-6.0.1-ml-windows_4049\netbeans-6.0.1-ml-windows.exe
2009-05-31 23:30 . 2009-06-01 00:35 25444778 ----a-w- c:\documents and settings\win\Application Data\IDM\DwnlData\win\netbeans-6.0.1-ml-windows_4048\netbeans-6.0.1-ml-windows.exe
2009-05-31 14:18 . 2009-05-31 15:54 23147066 ----a-w- c:\documents and settings\win\Application Data\IDM\DwnlData\win\netbeans-6.0.1-ml-windows_4046\netbeans-6.0.1-ml-windows.exe
2009-05-31 12:26 . 2009-05-31 13:54 50778178 ----a-w- c:\documents and settings\win\Application Data\IDM\DwnlData\win\netbeans-6.0.1-ml-windows_4044\netbeans-6.0.1-ml-windows.exe
2009-05-26 08:20 . 2009-05-26 08:21 -------- d-----w- c:\program files\zuhrof
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-12 04:44 . 2007-10-26 11:03 317216 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-12 04:44 . 2007-10-26 11:03 2336 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-12 04:44 . 2007-10-26 11:03 2336 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-12 04:44 . 2007-10-26 11:03 16808 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-12 04:44 . 2007-07-03 08:25 12 ----a-w- c:\windows\bthservsdp.dat
2009-05-20 14:27 . 2007-10-26 11:03 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-20 14:27 . 2007-10-26 11:03 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-12 12:37 . 2009-05-12 12:37 -------- d-----w- c:\program files\Trend Micro
2009-05-03 17:06 . 2009-05-03 17:06 -------- d-----w- c:\documents and settings\All Users\Application Data\QuickTime
2009-05-03 17:06 . 2009-05-03 17:06 28672 ----a-w- c:\windows\system32\qttask.exe
2009-05-02 19:01 . 2007-07-03 08:10 159304 ----a-w- c:\documents and settings\win\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-26 05:54 . 2009-04-26 05:54 -------- d-----w- c:\program files\Kelk 2000
2009-04-23 08:46 . 2009-04-23 08:46 -------- d-----w- c:\program files\Common Files\xing shared
2009-04-23 08:45 . 2007-09-23 16:44 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-04-23 08:45 . 2007-09-23 16:44 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-04-15 18:52 . 2009-04-15 18:52 -------- d-----w- c:\program files\iVocalize Web Conference 4
2009-04-14 00:28 . 2009-04-14 00:28 -------- d-----w- c:\documents and settings\All Users\Application Data\MSScanAppDataDir
2009-04-11 11:24 . 2009-04-11 11:24 390664 ----a-w- c:\documents and settings\win\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-04-04 14:36 . 2009-04-04 14:36 308 ----a-w- c:\windows\GooGleeee.pif
2009-04-04 14:36 . 2009-04-04 14:36 210 ----a-w- c:\windows\GooGleeee.vbs
2009-03-31 17:47 . 2001-09-19 09:00 41274 ----a-w- c:\windows\system32\perfc001.dat
2009-03-31 17:47 . 2001-09-19 09:00 254598 ----a-w- c:\windows\system32\perfh001.dat
2008-05-10 06:51 . 2008-02-10 18:13 286 ----a-w- c:\program files\uniextract.txt
2005-06-22 05:37 . 2006-05-24 17:37 45568 --sha-r- c:\windows\system32\cygz.dll
.
------- Sigcheck -------
[-] 2004-08-03 17:14 359040 6A603809F598332DBEDD535BDBCE313E c:\windows\system32\drivers\tcpip.sys
[7] 2004-08-03 17:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\system32\dllcache\tcpip.sys
.
(((((((((((((((((((((((((((((
SnapShot@2009-05-12_12.31.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-03 00:20 . 2004-03-29 13:23 90112 c:\windows\unvise32.exe
- 2008-01-03 00:20 . 2004-03-29 12:23 90112 c:\windows\unvise32.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-02-08 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-02-08 126976]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 385024]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2004-10-15 356352]
"LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2005-03-28 319488]
"DataLayer"="c:\program files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-09-06 820736]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-06-29 176128]
"ACU"="c:\program files\Atheros\ACU.exe" [2005-05-31 303104]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-23 198160]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-5-25 565309]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-7-4 113664]
REALTEK PCI&Cardbus Wireless LAN Utility.lnk - c:\program files\REALTEK PCI&Cardbus Wireless LAN Driver and Utility\RtWLan.exe [2009-2-15 794624]
REALTEK RTL8187 Wireless LAN Utility.lnk - c:\program files\REALTEK RTL8187 Wireless LAN Driver and Utility\RtWLan.exe [2009-2-15 737280]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 08:27 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKLM\~\startupfolder\C:^Documents and Settings^win^قائمة ابدأ^البرامج^بدء التشغيل^ctfmon.exe]
path=c:\documents and settings\win\قائمة ابدأ\البرامج\بدء التشغيل\ctfmon.exe
backup=c:\windows\pss\ctfmon.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\REALPLAY.EXE"=
"c:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\AVP.EXE"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\AppServ\\Apache2.2\\bin\\httpd.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\SpeedTouch_upgrade_wizard_R4421\\upgradeST.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\BINARIES\\HelpCtr.exe"=
R2 Apache2.2;Apache2.2;c:\appserv\Apache2.2\bin\httpd.exe [09/01/2007 07:17 م 20539]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [15/02/2009 01:14 ص 38144]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [04/04/2007 02:58 م 24344]
S2 7C0D52E37CEADD4820437743F169C150;7C0D52E37CEADD4820437743F169C150;cmd /k start /i "/dC:" "c:\combofix\HIDEC.exe" "c:\combofix\SWREG.EXE" ACL "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep" /RESET /Q --> cmd [?]
S2 PHPGeekUtil;PHPGeekUtil;"c:\apache\APACHE.EXE" --ntservice --> c:\apache\APACHE.EXE [?]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\DRIVERS\br3gmdm.sys --> c:\windows\system32\DRIVERS\br3gmdm.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25/01/2007 08:31 م 42000]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [15/02/2009 01:25 ص 194304]
S3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [15/02/2009 01:24 ص 13532]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EE3DD54E-05C4-5931-50B9-AF1B8E9563EE}]
c:\program files\Common Files\WD\winIogon.exe s
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 212.67.97.23:8080
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Download All Links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Lookup on Merriam Webster -
files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia -
files\ieSpell\wikipedia.HTM
IE: Save F&lash with FlashCapture - c:\program files\FlashCapture\fciext.dll/FCIEXT.htm
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: Microsoft XML Parser for Java -
FF - ProfilePath -
.
.
------- File Associations -------
.
txtfile=c:\windows\notepad.exe %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-12 14:25
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\7C0D52E37CEADD4820437743F169C150]
"ImagePath"="cmd /k start /i \"/d%systemdrive%\" \"c:\combofix\HIDEC.exe\" \"c:\combofix\SWREG.EXE\" ACL \"HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep\" /RESET /Q"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mysql]
"ImagePath"="c:\appserv\MySQL\bin\mysqld-nt --defaults-file=c:\appserv\MySQL\my.ini mysql"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1409082233-1647877149-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.* j*p*g*\OpenWithList]
@Class="Shell"
"a"="mspaint.exe"
"MRUList"="ba"
"b"="shimgvw.dll"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):ba,0b,a4,24,7d,4f,9d,26,91,84,50,74,eb,24,07,cf,0c,f4,02,18,33,
ba,19,68,ba,22,4d,43,5a,cb,d3,ab,78,64,32,a5,85,5b,07,04,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):b8,0a,15,b5,58,cc,fd,7d,b6,f4,5b,dc,f4,b7,e5,22,38,0b,f7,2c,f6,
d8,d9,45,32,22,fc,72,eb,f1,93,49,86,4c,39,7f,8d,1b,06,80,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{85f68ba6-5c97-45dd-a30a-814fe6761874}]
@Denied: (Full) (Everyone)
"Model"=dword:00000125
"Therad"=dword:00000017
"MData"=hex(0):cb,9b,ad,ef,27,7d,29,69,f5,02,f0,76,aa,4a,f1,7c,d3,d9,67,7f,6a,
4b,7b,ad,04,7a,b1,b5,76,9b,27,47,8d,5f,a0,ce,48,c0,b1,ca,4f,22,68,df,28,28,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{baaed58b-0cdf-4bc7-acc2-93d8d6fd80fd}]
@Denied: (Full) (Everyone)
"Model"=dword:000000e4
"Therad"=dword:0000001a
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1680)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
c:\windows\system32\klogon.dll
c:\windows\system32\athgina.dll
c:\windows\system32\athcfg11.dll
c:\windows\system32\athcfg11Res.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
- - - - - - - > 'lsass.exe'(1736)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
.
Completion time: 2009-06-12 14:27
ComboFix-quarantined-files.txt 2009-06-12 11:27
ComboFix2.txt 2009-05-12 12:36
Pre-Run: 1,470,660,608 bytes free
Post-Run: 2,062,204,928 bytes free
205