هذا التقرير
ComboFix 09-07-24.01 - xroh.com 07/26/2009 16:29.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.503.325 [GMT -7:00]
Running from: c:\documents and settings\xroh.com\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\10535004
c:\documents and settings\All Users\Application Data\10535004\10535004
c:\documents and settings\All Users\Application Data\10535004\10535004.exe
c:\documents and settings\xroh.com\Application Data\wiaserva.log
c:\documents and settings\xroh.com\Desktop\System Security 2009.lnk
c:\documents and settings\xroh.com\Start Menu\Programs\System Security
c:\documents and settings\xroh.com\Start Menu\Programs\System Security\System Security
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Created from 2009-06-26 to 2009-07-26 )))))))))))))))))))))))))))))))
.
2009-07-26 22:56 . 2009-07-26 22:56 -------- d-----w- c:\program files\Trend Micro
2009-07-26 21:50 . 2009-07-26 21:50 27264 ----a-w- c:\documents and settings\xroh.com\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-26 18:26 . 2009-07-26 18:26 -------- d-----w- c:\windows\system32\KB905474
2009-07-26 18:26 . 2009-03-11 05:26 1403264 ----a-w- c:\windows\system32\KB905474\wganotifypackageinner.exe
2009-07-26 18:26 . 2009-03-11 05:18 453512 ----a-w- c:\windows\system32\KB905474\wgasetup.exe
2009-07-26 18:25 . 2009-07-26 18:25 -------- d-----w- c:\program files\CONEXANT
2009-07-26 18:25 . 2004-08-04 07:56 4096 -c--a-w- c:\windows\system32\dllcache\ksuser.dll
2009-07-26 18:25 . 2004-08-04 07:56 4096 ----a-w- c:\windows\system32\ksuser.dll
2009-07-26 18:25 . 2004-08-04 06:08 60288 -c--a-w- c:\windows\system32\dllcache\drmk.sys
2009-07-26 18:25 . 2004-08-04 06:08 60288 ----a-w- c:\windows\system32\drivers\drmk.sys
2009-07-26 03:02 . 2009-07-26 03:45 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-07-26 02:50 . 2008-10-16 21:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-07-26 02:50 . 2008-10-16 21:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-07-25 04:23 . 2006-11-29 20:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-07-25 04:22 . 2009-07-25 04:22 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-07-25 04:21 . 2009-07-26 02:48 -------- d-----w- c:\windows\SxsCaPendDel
2009-07-25 04:18 . 2009-07-25 04:19 -------- dcsh--w- c:\program files\Common Files\WindowsLiveInstaller
2009-07-25 04:18 . 2009-07-26 18:24 -------- d-----w- c:\program files\Windows Live
2009-07-25 04:18 . 2009-07-25 04:18 -------- d-----w- c:\documents and settings\All Users\Application Data\WLInstaller
2009-07-25 04:05 . 2009-07-25 04:05 -------- d-----w- c:\documents and settings\xroh.com\Contacts
2009-07-25 00:13 . 2009-02-06 17:24 2180480 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-07-25 00:13 . 2009-02-06 17:22 2136064 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-07-25 00:13 . 2009-02-06 16:49 2057728 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-07-25 00:13 . 2009-02-06 16:49 2015744 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-07-25 00:12 . 2008-06-13 13:10 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-07-25 00:12 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-07-25 00:10 . 2008-10-24 11:10 453632 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-07-24 10:00 . 2009-07-26 18:27 -------- d--h--w- c:\windows\$hf_mig$
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-26 23:24 . 2009-07-26 23:14 -------- d-----w- c:\documents and settings\xroh.com\Application Data\cleaner
2009-07-26 23:14 . 2009-07-26 23:14 -------- d-----w- c:\documents and settings\xroh.com\Application Data\CyberScrub
2009-07-26 03:56 . 2009-07-24 09:06 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-24 09:18 . 2009-07-24 09:18 -------- d-----w- c:\program files\Broadcom
2009-07-24 09:18 . 2009-07-24 09:18 -------- d-----w- c:\documents and settings\xroh.com\Application Data\InstallShield
2009-07-24 09:18 . 2009-07-24 09:18 87328 ----a-w- c:\windows\system32\bcmwlcoi.dll
2009-07-24 09:18 . 2009-07-24 09:18 1287552 ----a-w- c:\windows\system32\drivers\BCMWL5.SYS
2009-07-24 09:16 . 2009-07-24 09:16 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-24 09:16 . 2009-07-24 09:16 -------- d-----w- c:\program files\Hewlett-Packard
2009-07-24 09:16 . 2009-07-24 09:16 -------- d-----w- c:\program files\Common Files\InstallShield
2009-07-24 09:07 . 2009-07-24 09:07 -------- d-----w- c:\program files\microsoft frontpage
2009-07-24 09:03 . 2009-07-24 09:03 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-06-16 14:55 . 2004-08-04 11:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2004-08-04 11:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:27 . 2004-08-04 11:00 1290752 ----a-w- c:\windows\system32\quartz.dll
2009-05-07 15:44 . 2004-08-04 11:00 344064 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:52 . 2004-08-04 11:00 659456 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:52 . 2004-08-04 11:00 81920 ----a-w- c:\windows\system32\ieencode.dll
.
------- Sigcheck -------
[-] 2008-04-13 16:39 142592 8BED39E3C35D6A489438B8141717A557 c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\aec.sys
[-] 2008-04-14 00:12 1614848 9DD07AF82244867CA36681EA2D29CE79 c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\sfcfiles.dll
[-] 2009-03-02 11:52 1580544 32272BF10467C8ACF1F83138C61D541E c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-19 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-19 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-19 137752]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
.
Contents of the 'Scheduled Tasks' folder
2009-07-26 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-07-26 05:18]
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-26 16:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-07-26 16:31
ComboFix-quarantined-files.txt 2009-07-26 23:31
Pre-Run: 37,615,931,392 bytes free
Post-Run: 37,636,902,912 bytes free
122 --- E O F --- 2009-07-26 18:27