حذف القيم الحمد لله
وهذا التقرير
ComboFix 09-07-31.04 - ssc1 08/01/2009 16:08.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.1014.571 [GMT 3:00]
Running from: c:\documents and settings\ssc1\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Outpost Firewall Pro *disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\ssc1\Application Data\FunWebProducts
c:\documents and settings\ssc1\Application Data\FunWebProducts\Data\ssc1\avatar.dat
c:\documents and settings\ssc1\Application Data\FunWebProducts\Data\ssc1\outfit.dat
c:\documents and settings\ssc1\Application Data\FunWebProducts\Data\ssc1\register.dat
c:\documents and settings\ssc1\Application Data\FunWebProducts\Data\ssc1\zbucks.dat
c:\documents and settings\ssc1\Application Data\wiaserva.log
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\program files\Spytech Software
c:\program files\WinConfig
c:\program files\WinConfig\npf_mgm.exe
C:\t92817u.exe
c:\windows\Installer\3ff9c0d.msp
c:\windows\SNMPAPI.DLL
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\drivers\aa8896fb.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\sinvfct.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\wpcap.dll
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_aa8896fb
((((((((((((((((((((((((( Files Created from 2009-07-01 to 2009-08-01 )))))))))))))))))))))))))))))))
.
2009-08-01 10:32 . 2009-08-01 10:32 -------- d-----w- c:\documents and settings\ssc1\Application Data\CyberScrub
2009-07-31 18:43 . 2009-07-31 18:43 -------- d-----w- c:\windows\system32\wbem\Repository
2009-07-29 19:44 . 2009-07-29 19:44 -------- d-----w- c:\program files\Option
2009-07-29 00:58 . 2009-07-23 08:56 714752 ----a-w- c:\windows\system32\drivers\SandBox.sys
2009-07-29 00:58 . 2009-07-13 10:19 256792 ----a-w- c:\windows\system32\drivers\afwcore.sys
2009-07-29 00:55 . 2009-02-18 14:30 31128 ----a-w- c:\windows\system32\drivers\afw.sys
2009-07-29 00:55 . 2009-07-29 21:20 -------- d-----w- c:\windows\system32\Filt
2009-07-29 00:55 . 2009-07-29 00:55 -------- d-----w- c:\program files\Agnitum
2009-07-29 00:55 . 2009-03-25 13:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Agnitum
2009-07-28 18:14 . 2009-03-25 13:27 -------- d-----w- c:\documents and settings\All Users\Agnitum
2009-07-27 21:56 . 2009-08-01 05:56 -------- d-----w- C:\MSNCleaner
2009-07-23 18:05 . 2009-07-23 18:06 -------- d-----w- c:\program files\Hamachi
2009-07-22 01:50 . 2008-01-07 11:29 352 ---ha-w- c:\windows\nod32fixtemdono.reg
2009-07-22 01:36 . 2009-07-22 01:36 -------- d-----w- c:\program files\ESET
2009-07-21 22:12 . 2009-08-01 10:20 -------- d-----w- c:\documents and settings\ssc1\Application Data\Hamachi
2009-07-21 22:11 . 2009-07-23 18:05 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2009-07-20 19:53 . 2009-07-20 19:53 -------- d-----w- c:\program files\NetBus
2009-07-20 19:52 . 1998-02-06 17:37 299520 ----a-w- c:\windows\uninst.exe
2009-07-20 17:22 . 2009-07-27 18:40 -------- d-----w- c:\windows\BDOSCAN8
2009-07-20 01:57 . 2002-11-05 11:07 126976 ----a-w- c:\windows\UNINST32.EXE
2009-07-17 03:42 . 2009-07-22 20:24 -------- d-----w- c:\documents and settings\ssc1\Local Settings\Application Data\WMTools Downloaded Files
2009-07-17 03:30 . 2009-07-17 03:30 -------- d-----w- C:\Fraps
2009-07-16 03:23 . 2009-07-20 01:34 -------- d-----w- c:\windows\NiwradSoft Shell Pack
2009-07-15 17:19 . 2004-08-03 21:56 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-07-15 16:06 . 2009-07-29 23:57 -------- d-----w- c:\program files\LimeWire
2009-07-14 14:07 . 2009-07-14 14:07 -------- d-----w- c:\windows\system32\ar-sa
2009-07-13 19:42 . 2006-09-06 14:43 22752 ----a-w- c:\windows\system32\spupdsvc.exe
2009-07-13 19:41 . 2009-07-13 19:41 -------- d--h--w- c:\windows\$hf_mig$
2009-07-11 19:30 . 2009-07-11 19:30 0 ----a-w- C:\savelist.dat
2009-07-11 19:30 . 2009-07-11 19:30 27 ----a-w- C:\savelist1.dat
2009-07-09 12:07 . 2009-07-09 12:07 -------- d-----w- C:\BackUpMSNCleaner
2009-07-05 09:02 . 2009-07-05 09:02 -------- d-----w- c:\program files\LtUcx
2009-07-03 01:19 . 2009-07-03 01:35 -------- d-----w- C:\MT
2009-07-03 01:19 . 2004-05-01 21:23 1384448 ----a-w- c:\windows\system32\msvbvm60.dll
2009-07-02 18:44 . 2009-07-02 18:46 -------- d-----w- c:\documents and settings\ssc1\amsn
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-01 13:11 . 2009-06-01 12:15 -------- d-----w- c:\documents and settings\ssc1\Application Data\uTorrent
2009-08-01 10:46 . 2007-06-24 17:17 -------- d-----w- c:\program files\Google
2009-08-01 10:31 . 2009-08-01 10:31 -------- d-----w- c:\documents and settings\ssc1\Application Data\cleaner
2009-08-01 08:37 . 2009-06-01 11:41 -------- d-----w- c:\documents and settings\ssc1\Application Data\BSplayer
2009-08-01 08:10 . 2009-07-15 00:06 -------- d-----w- c:\documents and settings\ssc1\Application Data\LimeWire
2009-08-01 04:13 . 2009-06-01 11:15 -------- d-----w- c:\program files\Unlocker
2009-07-28 11:18 . 2007-06-24 14:28 99496 ----a-w- c:\documents and settings\ssc1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-07 07:37 . 2009-07-01 01:19 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-02 11:08 . 2009-07-02 11:09 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-02 11:08 . 2009-07-02 11:08 -------- d-----w- c:\program files\Java
2009-07-02 11:08 . 2009-07-02 11:08 152576 ----a-w- c:\documents and settings\ssc1\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-02 10:38 . 2009-07-02 10:38 2678 ----a-w- c:\windows\java\Packages\Data\C0SAJHF1.DAT
2009-07-02 10:38 . 2009-07-02 10:38 2678 ----a-w- c:\windows\java\Packages\Data\N17X3F1B.DAT
2009-07-02 10:38 . 2009-07-02 10:38 2678 ----a-w- c:\windows\java\Packages\Data\UFT3Z71B.DAT
2009-07-02 10:38 . 2009-07-02 10:38 2678 ----a-w- c:\windows\java\Packages\Data\JRV5FFVH.DAT
2009-07-02 10:38 . 2009-07-02 10:38 2678 ----a-w- c:\windows\java\Packages\Data\1R3FVZZJ.DAT
2009-07-01 16:40 . 2009-05-31 15:32 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-30 19:03 . 2009-06-30 19:03 -------- d-----w- c:\program files\CCleaner
2009-06-29 19:29 . 2009-06-29 19:29 390664 ----a-w- c:\documents and settings\ssc1\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
2009-06-04 18:09 . 2009-06-04 18:09 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-06-04 16:49 . 2009-06-01 17:48 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-06-04 16:31 . 2009-06-04 16:31 -------- d-----w- c:\documents and settings\ssc1\Application Data\Creative
2009-06-02 13:47 . 2009-06-02 13:47 -------- d-----w- c:\documents and settings\All Users\Application Data\MSScanAppDataDir
2009-06-02 13:35 . 2009-06-02 13:35 737280 ----a-w- c:\windows\iun6002.exe
2009-06-01 14:25 . 2009-05-31 19:23 390664 ----a-w- c:\documents and settings\ssc1\Application Data\Real\RealPlayer\setup\AU_setup6.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DELL Webcam Manager"="c:\program files\DELL\DELL Webcam Manager\DellWMgr.exe" [2007-06-07 118784]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-08-16 5728112]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\ypager.exe" [2005-08-19 3084288]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2006-10-13 184320]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-02-01 36864]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-11 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-11 81920]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-05-16 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-05-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-05-16 138008]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-01 198160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-02 148888]
"Dell QuickSet"="c:\program files\Dell\QuickSet\Quickset.exe" [2006-08-03 1032192]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 1443072]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-07-24 1259336]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall Pro\feedback.exe" [2009-07-24 436552]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-05-11 1626112]
"NVHotkey"="nvHotkey.dll" - c:\windows\system32\nvhotkey.dll [2007-05-11 67584]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2007-05-06 405504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\ssc1\Start Menu\Programs\Startup\
وTorrent.lnk - c:\program files\uTorrent\uTorrent.exe [2009-6-1 288048]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-7-1 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4389:TCP"= 4389:TCP:erizbfhe
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [21/12/2007 08:21 ص 33800]
R1 sandbox;SandBox;c:\windows\system32\drivers\SandBox.sys [29/07/2009 03:58 ص 714752]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [29/07/2009 03:55 ص 1312584]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [21/12/2007 08:21 ص 468224]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [29/07/2009 03:55 ص 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [29/07/2009 03:58 ص 256792]
R3 OEM02Afx;Provides a software interface to control audio effects of M08 Internal webcam.;c:\windows\system32\drivers\OEM02Afx.sys [10/10/2007 01:55 م 141376]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\OEM02Dev.sys [10/10/2007 01:55 م 234496]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\OEM02Vfx.sys [10/10/2007 01:55 م 7424]
S2 sefwwfprw;Manager Support;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 12:56 ص 14336]
S3 aswfilt;ASWFilt;c:\windows\system32\Filt\ASWFilt.dll [29/07/2009 03:58 ص 33920]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
sefwwfprw
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Settings,ProxyOverride = local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-08-01 16:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sefwwfprw]
"ServiceDll"="c:\windows\system32\jezpb.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(536)
c:\windows\system32\msi.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\program files\Common Files\Ahead\Lib\NeroDigitalExt.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\windows\system32\stacsv.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Agnitum\Outpost Firewall Pro\op_mon.exe
c:\program files\WIDCOMM\Bluetooth Software\BTStackServer.exe
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
c:\windows\system32\wbem\wmiadap.exe
.
**************************************************************************
.
Completion time: 2009-08-01 16:17 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-01 13:17
Pre-Run: 48,714,674,176 bytes free
Post-Run: 48,621,658,112 bytes free
225