التقرير الاول
ComboFix 08-07-25.7 - TNT 07/26/2008 19:29:16.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.180 [GMT 3:00]
Running from: C:\Documents and Settings\TNT\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\TNT\Local Settings\Temporary Internet Files\.IE5\E75RQRX9\cnsminex_empty[1].htm
C:\Documents and Settings\TNT\Local Settings\Temporary Internet Files\.IE5\EVMSJ9DJ\cnsminex_empty[1].htm
C:\Documents and Settings\TNT\Local Settings\Temporary Internet Files\.IE5\EVMSJ9DJ\cnsminex_empty[3].htm
C:\Documents and Settings\TNT\Local Settings\Temporary Internet Files\.IE5\YTGJSJQH\cnsminex_empty[1].htm
C:\Documents and Settings\TNT\Local Settings\Temporary Internet Files\.IE5\YTGJSJQH\cnsminex_empty[2].htm
C:\Documents and Settings\TNT\Local Settings\Temporary Internet Files\.IE5\YTGJSJQH\cnsminex_empty[3].htm
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\Update.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-26 to 2008-07-26 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-26 16:31 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-26 10:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\SRS Labs
2008-07-26 10:52 --------- d-----w C:\Program Files\SRS Labs
2008-07-26 09:10 --------- d-----w C:\Documents and Settings\TNT\Application Data\Sunbelt Software
2008-07-26 05:51 155,995 ----a-w C:\WINDOWS\java\Packages\5FXB9FBL.ZIP
2008-07-26 05:49 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-26 05:49 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-07-26 05:37 --------- d-----w C:\Program Files\AntiARP Stand-alone Edition
2008-07-25 12:10 --------- d-----w C:\Documents and Settings\TNT\Application Data\Grisoft
2008-07-25 12:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-07-25 11:44 --------- d-----w C:\Program Files\ESET
2008-07-25 08:50 203,776 ----a-w C:\WINDOWS\system32\clrviddc.dll
2008-07-25 08:48 --------- d-----w C:\Program Files\Common Files\xing shared
2008-07-25 08:47 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-07-25 08:47 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-07-25 08:47 --------- d-----w C:\Program Files\Real
2008-07-25 08:47 --------- d-----w C:\Program Files\Common Files\Real
2008-07-25 05:15 720,896 ----a-w C:\WINDOWS\iun6002ev.exe
2008-07-24 20:19 --------- d-----w C:\Documents and Settings\TNT\Application Data\ESET
2008-07-24 20:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-07-24 19:10 --------- d-----w C:\Program Files\uTorrent
2008-07-24 19:10 --------- d-----w C:\Documents and Settings\TNT\Application Data\uTorrent
2008-07-24 16:29 --------- d-----w C:\Program Files\Web Publish
2008-07-24 16:03 --------- d-----w C:\Program Files\Windows Live
2008-07-24 15:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-07-24 15:29 --------- d-----w C:\Program Files\Internet Download Manager
2008-07-24 15:29 --------- d-----w C:\Documents and Settings\TNT\Application Data\IDM
2008-07-24 15:29 --------- d-----w C:\Documents and Settings\TNT\Application Data\DMCache
2008-07-24 15:27 --------- d-----w C:\Program Files\AGC System Player & Support
2008-07-24 15:26 36,864 ----a-w C:\WINDOWS\system32\mssetd.dll
2008-07-24 14:52 --------- d-----w C:\Documents and Settings\TNT\Application Data\InstallShield
2008-07-24 14:50 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-07-24 14:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-24 14:50 --------- d-----w C:\Program Files\Realtek
2008-07-24 14:50 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-24 14:48 --------- d-----w C:\Program Files\Yahoo!
2008-07-24 14:48 --------- d-----w C:\Program Files\Intel
2008-07-24 14:46 --------- d-----w C:\Program Files\Winamp
2008-07-24 14:46 --------- d-----w C:\Program Files\QuickTime
2008-07-24 14:46 --------- d-----w C:\Program Files\Media Player Classic
2008-07-24 14:46 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-07-24 14:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-07-09 14:34 206,256 ----a-w C:\WINDOWS\system32\idmmbc.dll
2008-07-01 06:04 71,688 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2008-07-01 06:04 54,280 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2008-07-01 06:04 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2008-07-01 05:57 53,256 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2008-07-01 05:56 39,944 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
.
------- Sigcheck -------
09/24/2005 06:59 PM 2319232 6c4f02302936a8aa8958bdd147d86ed1 C:\WINDOWS\system32\NTOSKRNL.EXE
08/27/2005 11:15 PM 1043456 7ba90a94cd2cd9eb62374afd52ffcf60 C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [11/07/2007 03:34 PM 3739672]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [07/15/2008 01:47 AM 2606512]
"SRS Audio Sandbox"="C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" [09/26/2007 09:42 AM 3158016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [07/01/2008 09:01 AM 1447168]
"AntiARPStandalone"="C:\Program Files\AntiARP Stand-alone Edition\AntiArp.exe" [08/15/2007 03:27 PM 5044736]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/03/2004 09:56 PM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 08/03/2004 09:56 PM 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 07/15/2008 01:47 AM 2606512 C:\Program Files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
-ra------ 11/28/2005 08:52 AM 77824 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
-ra------ 11/28/2005 08:55 AM 118784 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
-ra------ 11/28/2005 08:55 AM 98304 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 11/07/2007 03:34 PM 3739672 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 07/25/2008 11:47 AM 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 12/20/2004 09:41 PM 33792 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 05/03/2005 01:43 PM 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 07/05/2007 11:08 AM 16380416 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
-r------- 06/15/2007 11:45 AM 1826816 C:\WINDOWS\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
R2 AntiArpNdisProt;AntiARP NDIS Protocol Driver;C:\WINDOWS\system32\DRIVERS\AntiArpNdisProt.sys [04/18/2007 07:16 PM]
R3 xAntiArp;xAntiArpSpoof Service;C:\WINDOWS\system32\DRIVERS\xAntiArp.sys [08/11/2007 11:06 PM]
S2 cdralw;NVIDIA Compatible Windows Miniport Driver;C:\WINDOWS\system32\DRIVERS\nvmini.sys []
S3 eth8023;eth8023;C:\WINDOWS\system32\drivers\eth8023.sys []
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-!AVG Anti-Spyware - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
MSConfigStartUp-3PMmUpdate - C:\WINDOWS\Update.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.eg/
R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.yahoo.com/
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 -: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 -: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O17 -: HKLM\CCS\Interface\{5E7C3E7F-FC98-4034-B487-162234364F88}: NameServer = 163.121.128.134,212.103.160.18
O16 -: Microsoft XML Parser for Java -
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-26 19:31:40
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\ESET\ESET SMART SECURITY\EKRN.EXE
C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IEMONITOR.EXE
.
**************************************************************************
.
Completion time: 07/26/2008 19:32:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-26 16:32:12
Pre-Run: 5,183,971,328 bytes free
Post-Run: 5,138,808,832 bytes free
170