هذا التقرير
ComboFix 09-07-25.04 - aser_511 07/26/2009 14:47.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.1526.921 [GMT 3:00]
Running from: d:\documents and settings\aser_511\سطح المكتب\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: Avira Firewall *disabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
d:\program files\SuperCopier2\SC2Hook.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
Infected copy of d:\windows\system32\sfcfiles.dll was found and disinfected
Restored copy from - d:\windows\system32\dllcache\sfcfiles.dll
.
((((((((((((((((((((((((( Files Created from 2009-06-26 to 2009-07-26 )))))))))))))))))))))))))))))))
.
2009-07-26 10:47 . 2004-08-04 08:55 221184 ----a-w- d:\windows\system32\wmpns.dll
2009-07-26 09:00 . 2009-07-26 09:00 -------- d-----w- d:\documents and settings\All Users\Application Data\InstallShield
2009-07-26 08:56 . 2009-07-26 08:56 -------- d-----w- d:\program files\Nokia
2009-07-26 08:56 . 2009-07-26 08:56 -------- d-----w- d:\documents and settings\aser_511\Application Data\InstallShield
2009-07-25 15:50 . 2004-08-04 06:32 15872 -c--a-w- d:\windows\system32\dllcache\padrs404.dll
2009-07-25 12:14 . 2009-07-25 12:14 -------- d-----w- d:\documents and settings\aser_511\Local Settings\Application Data\Identities
2009-07-25 11:42 . 2009-07-25 11:42 -------- d-----w- d:\program files\ImageShack Corp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-26 11:52 . 2009-07-25 08:41 -------- d-----w- d:\program files\SuperCopier2
2009-07-26 10:44 . 2009-07-25 09:10 -------- d-----w- d:\documents and settings\aser_511\Application Data\Media Player Classic
2009-07-26 09:44 . 2009-07-25 07:41 86327 ----a-w- d:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-26 08:56 . 2009-07-25 07:59 -------- d--h--w- d:\program files\InstallShield Installation Information
2009-07-26 08:56 . 2009-07-25 07:59 -------- d-----w- d:\program files\Common Files\InstallShield
2009-07-26 07:51 . 2001-09-19 12:00 39982 ----a-w- d:\windows\system32\perfc001.dat
2009-07-26 07:51 . 2001-09-19 12:00 251478 ----a-w- d:\windows\system32\perfh001.dat
2009-07-25 18:06 . 2009-07-25 08:40 43600 ----a-w- d:\documents and settings\aser_511\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-25 10:38 . 2009-07-25 10:38 -------- d-----w- d:\program files\Google
2009-07-25 10:33 . 2009-07-25 10:33 -------- d-----w- d:\documents and settings\All Users\Application Data\Messenger Plus!
2009-07-25 10:31 . 2009-07-25 08:02 -------- d-----w- d:\documents and settings\aser_511\Application Data\DMCache
2009-07-25 10:02 . 2009-07-25 10:02 -------- d-----w- d:\program files\Messenger Plus! Live
2009-07-25 09:51 . 2009-07-25 09:50 -------- d-----w- d:\program files\Common Files\Real
2009-07-25 09:51 . 2009-07-25 09:51 -------- d-----w- d:\program files\Common Files\xing shared
2009-07-25 09:51 . 2009-07-25 08:28 -------- d-----w- d:\program files\Java
2009-07-25 09:50 . 2009-07-25 08:42 348160 ----a-w- d:\windows\system32\msvcr71.dll
2009-07-25 09:50 . 2009-07-25 08:42 499712 ----a-w- d:\windows\system32\msvcp71.dll
2009-07-25 09:50 . 2009-07-25 09:50 -------- d-----w- d:\program files\Real
2009-07-25 09:49 . 2009-07-25 09:49 152576 ----a-w- d:\documents and settings\aser_511\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-25 09:09 . 2009-07-25 09:09 -------- d-----w- d:\program files\Recode Media
2009-07-25 09:09 . 2009-07-25 09:08 -------- d-----w- d:\program files\Windows Live
2009-07-25 09:08 . 2009-07-25 09:08 -------- d-----w- d:\program files\Microsoft
2009-07-25 09:08 . 2009-07-25 09:08 -------- d-----w- d:\program files\Windows Live SkyDrive
2009-07-25 09:07 . 2009-07-25 09:04 -------- d-----w- d:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-25 08:58 . 2009-07-25 08:58 -------- d-----w- d:\documents and settings\aser_511\Application Data\TuneUp Software
2009-07-25 08:43 . 2009-07-25 08:43 -------- d-----w- d:\program files\FreeTime
2009-07-25 08:42 . 2009-07-25 08:42 -------- d-----w- d:\documents and settings\All Users\Application Data\Apple Computer
2009-07-25 08:42 . 2009-07-25 08:42 -------- d-----w- d:\program files\QuickTime Alternative
2009-07-25 08:42 . 2009-07-25 08:42 -------- d-----w- d:\program files\Media Player Classic
2009-07-25 08:42 . 2009-07-25 08:42 -------- d-----w- d:\program files\4shared Uploader
2009-07-25 08:42 . 2009-07-25 08:42 -------- d-----w- d:\documents and settings\aser_511\Application Data\4shared Uploader
2009-07-25 08:40 . 2009-07-25 08:40 -------- d-----w- d:\program files\Common Files\Windows Live
2009-07-25 08:30 . 2009-07-25 08:30 -------- d-----w- d:\program files\Sun
2009-07-25 08:28 . 2009-07-25 08:28 152576 ----a-w- d:\documents and settings\aser_511\Application Data\Sun\Java\jre1.6.0_11\lzma.dll
2009-07-25 08:05 . 2009-07-25 08:05 -------- d-----w- d:\documents and settings\All Users\Application Data\Avira
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SuperCopier2.exe"="d:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
"msnmsgr"="d:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="d:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"igfxtray"="d:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="d:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="d:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"avgnt"="d:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"TkBellExe"="d:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-07-25 198160]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"googletalk"="d:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"BluetoothAuthenticationAgent"="bthprops.cpl" - d:\windows\system32\bthprops.cpl [2004-08-04 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
d:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-7-25 113664]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
R1 avfwot;avfwot;d:\windows\system32\drivers\avfwot.sys [25/07/2009 11:05 ص 97608]
R2 AntiVirFirewallService;Avira Firewall;d:\program files\Avira\AntiVir Desktop\avfwsvc.exe [25/07/2009 11:05 ص 388865]
R2 AntiVirMailService;Avira AntiVir MailGuard;d:\program files\Avira\AntiVir Desktop\avmailc.exe [25/07/2009 11:05 ص 194817]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;d:\program files\Avira\AntiVir Desktop\sched.exe [25/07/2009 11:05 ص 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;d:\program files\Avira\AntiVir Desktop\avwebgrd.exe [25/07/2009 11:05 ص 434945]
R3 avfwim;AvFw Packet Filter Miniport;d:\windows\system32\drivers\avfwim.sys [25/07/2009 11:05 ص 69632]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"d:\windows\system32\rundll32.exe" "d:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.internetdownloadmanager.com/welcome.html
IE: ت&صدير إلى Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: d:\program files\Avira\AntiVir Desktop\avsda.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-26 14:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\d:\docume~1\aser_511\LOCALS~1\Temp\mc21.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(1044)
d:\program files\Avira\AntiVir Desktop\avsda.dll
- - - - - - - > 'explorer.exe'(3956)
d:\program files\SuperCopier2\SC2Hook.dll
d:\windows\system32\msi.dll
d:\windows\system32\ieframe.dll
d:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
d:\program files\Avira\AntiVir Desktop\avguard.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\windows\system32\rundll32.exe
d:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-26 14:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-26 11:55
Pre-Run: 21,742,882,816 bytes free
Post-Run: 21,940,973,568 bytes free
145