تقرير الكومبو فيكس
ComboFix 08-08-19.06 - Mohamad 2008-08-21 10:22:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.243 [GMT -7:00]
Running from: C:\Documents and Settings\Mohamad\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\RECYCLER\ADAPT_Installer.exe
C:\WINDOWS\system32\__c00845FC.dat
C:\WINDOWS\system32\__c009C0A2.dat
C:\WINDOWS\system32\__c00A42A3.dat
C:\WINDOWS\system32\__c00BE236.dat
C:\xcrashdump.dat
.
((((((((((((((((((((((((( Files Created from 2008-07-21 to 2008-08-21 )))))))))))))))))))))))))))))))
.
2008-08-17 18:11 . 2008-08-17 18:33 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-08-16 09:49 . 2008-08-16 09:49 173 --a------ C:\WINDOWS\wininit.ini
2008-08-16 09:37 . 2008-08-16 09:37 1,427 --a------ C:\WINDOWS\lol.bat
2008-08-13 16:16 . 2008-08-13 16:16 244 --ah----- C:\sqmnoopt09.sqm
2008-08-13 16:16 . 2008-08-13 16:16 232 --ah----- C:\sqmdata09.sqm
2008-08-12 22:06 . 2008-08-12 22:06 <DIR> d-------- C:\Program Files\Norton PC Checkup
2008-08-12 22:06 . 2008-08-20 14:31 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-08-12 19:39 . 2008-08-12 19:39 <DIR> d-------- C:\Program Files\directx
2008-08-12 19:06 . 2008-08-12 19:06 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-08-11 20:10 . 2008-08-16 09:37 <DIR> d-------- C:\Program Files\Common Files\delet
2008-07-31 17:47 . 2008-07-31 17:47 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-07-30 18:51 . 2008-06-13 06:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-07-30 18:51 . 2008-06-13 06:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-30 15:55 . 2008-07-30 15:55 268 --ah----- C:\sqmdata08.sqm
2008-07-30 15:55 . 2008-07-30 15:55 268 --ah----- C:\sqmdata07.sqm
2008-07-30 15:55 . 2008-07-30 15:55 244 --ah----- C:\sqmnoopt08.sqm
2008-07-30 15:55 . 2008-07-30 15:55 244 --ah----- C:\sqmnoopt07.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-21 16:57 --------- d-----w C:\Program Files\Google
2008-08-17 18:54 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-10 23:18 --------- d-----w C:\Documents and Settings\Mohamad\Application Data\Skype
2008-08-01 00:46 --------- d-----w C:\Program Files\The Weather Channel FW
2008-03-31 22:27 0 -c--a-w C:\Program Files\temp01
2008-03-03 20:42 32 -c--a-r C:\Documents and Settings\All Users\hash.dat
2007-12-16 00:03 774,144 -c--a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-27 15:22 4670968]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:54 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:56 15360]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-11-17 04:53 171464]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-06-14 16:45 2321600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" [2004-09-22 20:00 94208]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50 139320]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" [2003-10-07 09:48 147514]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"DrvLsnr"="C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe" [2002-05-28 08:37 69632]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36 114688]
"PTHOSTTR"="C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE" [2005-04-08 11:08 73728]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2006-02-28 05:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2006-02-28 05:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-02-28 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-02-28 05:00 455168]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 16:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 16:37 2178832]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-05-01 09:34 185896]
C:\Documents and Settings\Mohamad\Start Menu\Programs\Startup\
Ela-Salaty.lnk - C:\Program Files\Ela-Salaty\Salaty.exe [2007-03-04 16:33:19 5205504]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.speex32"= speex32.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\VoipRaider.com\\VoipRaider\\VoipRaider.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
Contents of the 'Scheduled Tasks' folder
2008-08-21 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{1B8DB3CB-CC40-41B8-8A00-9AFC2187A64D} - (no file)
HKCU-Run-LowRateVoip - C:\Program Files\LowRateVoip\LowRateVoip.exe
Notify-__c00BE236 - C:\WINDOWS\system32\__c00BE236.dat
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Mohamad\Application Data\Mozilla\Firefox\Profiles\kwrgnguz.default\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-21 10:28:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2008-08-21 10:34:46 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-21 17:34:42
Pre-Run: 22,858,899,456 bytes free
Post-Run: 22,859,915,264 bytes free
136 --- E O F --- 2008-08-20 08:51:35