تقرير الكومبو فيكس
ComboFix 09-04-17.05 - MGH 06/18/2009 14:57.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.971.1033.18.503.293 [GMT 4:00]
Running from: c:\documents and settings\MGH\Desktop\rebuilt.كرم\كرم\زيزووم\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\MGH\LOCALS~1\Temp\7zS9.tmp\msnmsgr.exe
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\PortableYahoo.exe
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\d32-fw.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\ft60.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\GIPSVoiceEngineDLL.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\id3lib.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\idle.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\msvcp71.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\msvcr71.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\MyYahoo.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\nspr4.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\pcre.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\res_msgr.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\XMLParse.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\Xmltok.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\YahooMessenger.exe
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\yaudiomgr.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\YCPFoundation.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\YImage.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\YIniDom.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\Yml.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\YPluginRegistry.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Messenger\yvoiceui.dll
c:\docume~1\MGH\LOCALS~1\Temp\RarSFX0\Yahoo!\Shared\YbSkin2.dll
.
((((((((((((((((((((((((( Files Created from 2009-05-18 to 2009-06-18 )))))))))))))))))))))))))))))))
.
2009-06-17 17:47 . 2009-06-18 07:42 32 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-06-17 17:47 . 2009-06-18 07:42 32 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-06-17 16:41 . 2008-07-28 21:01 486519 ----a-w c:\windows\SuperCopier.exe
2009-06-17 00:08 . 2009-06-17 00:08 -------- d-----w c:\documents and settings\MGH\Local Settings\Application Data\Deployment
2009-06-16 10:26 . 2009-06-16 10:26 -------- d-----w c:\documents and settings\MGH\Application Data\Thinstall
2009-06-15 15:24 . 2009-06-15 15:25 -------- d-s---w c:\documents and settings\MGH\UserData
2009-06-15 12:12 . 2009-06-15 12:12 -------- d-----w c:\documents and settings\MGH\Local Settings\Application Data\Adobe
2009-06-14 16:09 . 2009-06-14 16:09 -------- d-----w c:\documents and settings\MGH\Local Settings\Application Data\Identities
2009-06-11 23:11 . 2009-06-11 23:11 -------- d-----w c:\documents and settings\MGH\Local Settings\Application Data\Help
2009-06-11 13:40 . 2009-06-11 13:40 -------- d-----w c:\windows\system32\LogFiles
2009-06-07 16:23 . 2009-06-01 10:19 126976 ----a-r c:\windows\system32\igfxres.dll
2009-06-07 16:13 . 2009-06-01 10:20 2732032 ----a-r c:\windows\system32\Netw2r32.dll
2009-06-07 16:13 . 2009-06-01 10:20 2210048 ----a-r c:\windows\system32\drivers\w29n51.sys
2009-06-07 16:13 . 2009-06-01 10:20 557056 ----a-r c:\windows\system32\Netw2c32.dll
2009-06-07 16:12 . 2009-06-01 10:18 88363 ----a-r c:\windows\AGRSMMSG.exe
2009-06-07 16:12 . 2009-06-01 10:18 64512 ----a-r c:\windows\agrsmdel.exe
2009-06-07 16:12 . 2009-06-01 10:18 1268204 ----a-r c:\windows\system32\drivers\AGRSM.sys
2009-06-07 16:11 . 2009-06-01 10:19 97280 ----a-r c:\windows\system32\drivers\gtipci21.sys
2009-06-07 16:11 . 2009-06-01 10:19 28672 ----a-r c:\windows\cttib1.dll
2009-06-07 16:11 . 2009-06-01 10:19 17120 ----a-r c:\windows\system32\drivers\tiscfw.deb
2009-06-07 16:09 . 2009-06-01 10:19 319488 ----a-r c:\windows\system32\drivers\tifm21.sys
2009-06-07 16:09 . 2009-06-01 10:20 77824 ----a-r c:\windows\system32\btw_ci.dll
2009-06-07 16:09 . 2009-06-01 10:20 57320 ----a-r c:\windows\system32\drivers\btwusb.sys
2009-06-07 16:08 . 2009-06-01 10:20 142720 ----a-w c:\windows\system32\dllcache\b57xp32.sys
2009-06-07 16:08 . 2009-06-01 10:20 142720 ----a-r c:\windows\system32\drivers\b57xp32.sys
2009-06-07 16:04 . 2004-08-03 20:56 7168 ----a-w c:\windows\system32\hccoin.dll
2009-06-07 16:04 . 2004-08-03 20:56 7168 ----a-w c:\windows\system32\dllcache\hccoin.dll
2009-06-07 16:04 . 2004-08-03 19:08 26624 ----a-w c:\windows\system32\drivers\usbehci.sys
2009-06-07 16:04 . 2004-08-03 19:08 26624 ----a-w c:\windows\system32\dllcache\usbehci.sys
2009-06-07 16:04 . 2009-06-07 16:04 -------- d-sh--w C:\FOUND.000
2009-06-07 15:54 . 2004-08-03 19:07 8832 ----a-w c:\windows\system32\drivers\wmiacpi.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-17 17:39 . 2009-06-17 17:39 -------- d-----w c:\program files\SuperCopier2
2009-06-16 14:21 . 2006-07-10 13:47 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-11 13:56 . 2009-06-11 13:56 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-06-11 13:54 . 2009-06-11 13:54 -------- d-----w c:\program files\Common Files\Adobe
2009-06-11 00:45 . 2006-07-10 14:21 30128 ----a-w c:\documents and settings\MGH\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-01 10:18 . 2009-06-07 16:10 127744 ----a-r c:\windows\system32\drivers\aeaudio.sys
2004-08-03 18:56 . 2004-08-03 18:56 25058 ---h--w c:\documents and settings\MGH\Application Data\addon.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-03 1667584]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2009-06-01 101144]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2009-06-01 84760]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2009-06-01 125720]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2009-06-01 88363]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R3 NECIRDA;NEC IrCC Miniport Device Driver;c:\windows\system32\DRIVERS\smcirda.sys [2001-08-17 35913]
S3 GTIPCI21;GTIPCI21;c:\windows\system32\DRIVERS\gtipci21.sys [2009-06-01 97280]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d0d2c861-0fe2-11db-a190-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{34F7905A-B033-BBD3-3771-64BF8FF19B85}]
c:\windows\systemB\systemB.exe s
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ae/
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-18 14:59
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\MGH\LOCALS~1\Temp\mc22.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3064)
c:\program files\SuperCopier2\SC2Hook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\SCARDSVR.EXE
.
**************************************************************************
.
Completion time: 2009-06-18 14:59 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-18 10:59
Pre-Run: 3,934,281,728 bytes free
Post-Run: 4,130,865,152 bytes free
144