هذا هو التقرير
ComboFix 08-10-03.05 - a 10/04/2008 8:11:14.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.593 [GMT 3:00]
Running from: C:\********s and Settings\a\??? ??????\2.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\1u0o8bnq.cmd
C:\9yqusig.bat
C:\autorun.inf
C:\kk3.bat
C:\WINDOWS\system32\ckvo.exe
C:\WINDOWS\system32\ckvo0.dll
C:\WINDOWS\system32\ckvo1.dll
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\x64
C:\xk2n.bat
D:\1u0o8bnq.cmd
D:\9yqusig.bat
D:\Autorun.inf
D:\b3b9u.com
D:\bwpncb6.com
D:\c9hehpa.bat
D:\kk3.bat
D:\n.com
D:\njibyekk.com
D:\rqq2v.bat
D:\rs.cmd
D:\tbm9.bat
D:\u9dyi.exe
D:\xk2n.bat
D:\yssjnngm.cmd
.
((((((((((((((((((((((((( Files Created from 2008-09-04 to 2008-10-04 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-03 18:37 --------- d-----w C:\Program Files\Google
2008-09-27 00:10 --------- d-----w C:\Program Files\Common Files\Nokia
2008-09-27 00:09 --------- d-----w C:\Program Files\CONEXANT
2008-09-26 22:47 --------- d-----w C:\Program Files\Avramovic Web Solutions
2008-09-25 00:39 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-09-25 00:39 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-09-25 00:36 --------- d-----w C:\********s and Settings\All Users\Application Data\Nokia
2008-09-25 00:35 --------- d-----w C:\Program Files\Nokia
2008-09-25 00:35 --------- d-----w C:\********s and Settings\All Users\Application Data\Installations
2008-09-25 00:33 --------- d-----w C:\Program Files\MSXML 6.0
2008-09-22 18:14 --------- d-----w C:\********s and Settings\a\Application Data\Datalayer
2008-09-18 17:08 --------- d-----w C:\********s and Settings\Administrator\Application Data\Yahoo!
2008-09-16 15:42 --------- d-----w C:\********s and Settings\a\Application Data\Nokia Multimedia Player
2008-09-14 17:59 --------- d-----w C:\********s and Settings\a\Application Data\Nokia
2008-09-10 22:05 96,047 --sh--r C:\39lpji.com
2008-09-06 09:33 70,656 ----a-w C:\WINDOWS\notepad.exe
2008-09-06 09:33 32,768 ----a-w C:\WINDOWS\hh.exe
2008-09-06 09:33 225,280 ----a-w C:\WINDOWS\regedit.exe
2008-09-06 09:33 1,655,296 ----a-w C:\WINDOWS\explorer.exe
2008-09-06 09:24 --------- d-----w C:\Program Files\Total Video Converter
2008-09-05 17:35 --------- d-----w C:\********s and Settings\a\Application Data\ACD Systems
2008-09-05 17:18 --------- d-----w C:\********s and Settings\a\Application Data\CyberLink
2008-09-01 18:40 --------- d-----w C:\********s and Settings\Administrator\Application Data\Media Player Classic
2008-09-01 18:39 --------- d-----w C:\********s and Settings\Administrator\Application Data\PC Suite
2008-09-01 18:39 --------- d-----w C:\********s and Settings\Administrator\Application Data\ESET
2008-09-01 14:42 --------- d-----w C:\********s and Settings\All Users\Application Data\Messenger Plus!
2008-09-01 12:30 --------- d-----w C:\********s and Settings\a\Application Data\Media Player Classic
2008-08-31 18:14 --------- d-----w C:\Program Files\dart type math
2008-08-31 18:14 --------- d-----w C:\********s and Settings\a\Application Data\dart type math
2008-08-31 18:13 --------- d-----w C:\Program Files\MSN Messenger
2008-08-31 18:13 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-08-31 18:13 --------- d-----w C:\Program Files\Circle Developement
2008-08-31 18:06 --------- d-----w C:\********s and Settings\All Users\Application Data\Yahoo! Companion
2008-08-31 18:06 --------- d-----w C:\********s and Settings\a\Application Data\Yahoo!
2008-08-31 16:06 --------- d-----w C:\Program Files\Unlocker
2008-08-31 16:05 --------- d-----w C:\********s and Settings\a\Application Data\ESET
2008-08-31 16:04 --------- d-----w C:\Program Files\ESET
2008-08-31 16:04 --------- d-----w C:\********s and Settings\All Users\Application Data\ESET
2008-08-31 16:03 --------- d-----w C:\********s and Settings\All Users\Application Data\CyberLink
2008-08-31 16:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-31 16:02 --------- d-----w C:\Program Files\CyberLink
2008-08-31 16:02 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-31 16:00 --------- d-----w C:\Program Files\Windows Live
2008-08-31 15:52 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-31 15:22 155,995 ----a-w C:\WINDOWS\****\Packages\WMXJZ7PB.ZIP
2008-08-31 15:22 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-31 15:21 --------- d-----w C:\Program Files\Paltalk Messenger
2008-08-31 15:21 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-08-31 15:21 --------- d-----w C:\********s and Settings\All Users\Application Data\PC Suite
2008-08-31 15:21 --------- d-----w C:\********s and Settings\a\Application Data\Paltalk
2008-08-31 15:20 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-08-31 15:20 --------- d-----w C:\Program Files\DIFX
2008-08-31 15:20 --------- d-----w C:\********s and Settings\a\Application Data\PC Suite
2008-08-31 15:17 --------- d-----w C:\Program Files\WIDCOMM
2008-08-31 14:52 --------- d-----w C:\********s and Settings\a\Application Data\Ahead
2008-08-31 14:50 --------- d-----w C:\Program Files\Real_SC
2008-08-31 14:50 --------- d-----w C:\Program Files\Real
2008-08-31 14:50 --------- d-----w C:\Program Files\Common Files\xing shared
2008-08-31 14:50 --------- d-----w C:\Program Files\Common Files\Real
2008-08-31 14:47 --------- d-----w C:\********s and Settings\All Users\Application Data\GRETECH
2008-08-31 14:47 --------- d-----w C:\********s and Settings\a\Application Data\GRETECH
2008-08-31 14:46 --------- d-----w C:\Program Files\GRETECH
2008-08-31 14:45 --------- d-----w C:\Program Files\Yahoo!
2008-08-31 14:45 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-08-31 14:45 --------- d-----w C:\Program Files\ACD Systems
2008-08-31 14:45 --------- d-----w C:\********s and Settings\All Users\Application Data\ACD Systems
2008-08-31 14:44 --------- d-----w C:\Program Files\Nero
2008-08-31 14:44 --------- d-----w C:\Program Files\Common Files\Ahead
2008-08-31 14:22 --------- d-----w C:\Program Files\Microsoft.NET
2008-08-31 14:21 --------- d-----w C:\Program Files\Microsoft Works
2008-08-31 14:02 --------- d-----w C:\Program Files\microsoft frontpage
.
------- Sigcheck -------
09/06/2008 12:33 PM 1655296 2fd48aaeaec9c891f72277bbe701f5db C:\WINDOWS\explorer.exe
04/14/2008 06:59 PM 1031168 ca3445dce9eb70a2ca2504e0af5c543f C:\WINDOWS\SoftwareDistribution\Download\7d2cee6b1d58dd154a634d3211bdeac1\explorer.exe
09/06/2008 12:33 PM 1655296 2fd48aaeaec9c891f72277bbe701f5db C:\WINDOWS\system32\dllcache\explorer.exe
04/14/2008 07:00 PM 110592 9498cf0d334b282aa58d1dfc370738de C:\WINDOWS\SoftwareDistribution\Download\7d2cee6b1d58dd154a634d3211bdeac1\wuauclt.exe
09/06/2008 12:33 PM 80584 fdebe76dcbb058296c27f72daa6dc9ef C:\WINDOWS\system32\wuauclt.exe
09/06/2008 12:33 PM 80584 fdebe76dcbb058296c27f72daa6dc9ef C:\WINDOWS\system32\dllcache\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 11:56 AM 15360]
"managertitle"="C:\DOCUME~1\a\APPLIC~1\DARTTY~1\refbias1.exe" [08/31/2008 09:14 PM 563200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [08/31/2008 05:49 PM 185896]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [08/14/2006 02:39 PM 98304]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [08/14/2006 02:41 PM 114688]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [08/14/2006 02:38 PM 94208]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [11/08/2006 01:27 PM 222208]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [12/07/2005 10:57 PM 30208]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [04/13/2006 11:09 AM 49152]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [02/20/2008 11:06 AM 1443072]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [09/07/2006 08:19 PM 15872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 11:56 AM 15360]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [11/09/2006 05:15 PM 1634304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
"VIDC.3iv2"= C:\PROGRA~1\K-LITE~1\codecs\3IVXVF~1.DLL
"VIDC.VP60"= C:\PROGRA~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP61"= C:\PROGRA~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP62"= C:\PROGRA~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP70"= C:\PROGRA~1\K-LITE~1\codecs\vp7vfw.dll
"VIDC.VP31"= C:\PROGRA~1\K-LITE~1\codecs\vp31vfw.dll
"VIDC.FFDS"= C:\PROGRA~1\K-LITE~1\ffdshow\ff_vfw.dll
"msacm.ac3acm"= C:\PROGRA~1\K-LITE~1\codecs\ac3acm.acm
"msacm.l3fhg"= C:\PROGRA~1\K-LITE~1\codecs\l3codecp.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{35032a86-7900-11dd-8737-0016d39870eb}]
\Shell\AutoRun\command - F:\1u0o8bnq.cmd
\Shell\explore\Command - F:\1u0o8bnq.cmd
\Shell\open\Command - F:\1u0o8bnq.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a1e0301e-7774-11dd-872c-0016d39870eb}]
\Shell\AutoRun\command - F:\kk3.bat
\Shell\explore\Command - F:\kk3.bat
\Shell\open\Command - F:\kk3.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a1e03033-7774-11dd-872c-0016d39870eb}]
\Shell\AutoRun\command - F:\kk3.bat
\Shell\explore\Command - F:\kk3.bat
\Shell\open\Command - F:\kk3.bat
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.sa/
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O16 -: Microsoft XML Parser for **** -
file://C:\WINDOWS\****\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for ****.osd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-04 08:15:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Unlocker\UnlockerHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Paltalk Messenger\palstart.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\PC Connectivity Solution\NclBTHandler.exe
C:\2\pv.cfexe
C:\WINDOWS\system32\igfxsrvc.exe
.
**************************************************************************
.
Completion time: 10/04/2008 8:20:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-04 05:20:32
Pre-Run: 47,819,309,056 bytes free
Post-Run: 48,700,846,080 bytes free
220 --- E O F --- 2008-09-11 00:32:43