التقرير الأول :
ComboFix 08-07-25.7 - BVX-Messi 07/26/2008 18:38:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.350 [GMT 3:00]
Running from: C:\Documents and Settings\BVX-Messi\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-06-26 to 2008-07-26 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-25 23:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-25 23:20 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-25 23:20 --------- d-----w C:\Program Files\Analog Devices
2008-07-25 23:01 --------- d-----w C:\Program Files\VisualTaskTips
2008-07-25 23:01 --------- d-----w C:\Program Files\ViStart
2008-07-25 23:01 --------- d-----w C:\Program Files\MSN Messenger
2008-07-25 23:01 --------- d-----w C:\Documents and Settings\BVX-Messi\Application Data\ViStart
2008-07-25 22:59 --------- d-----w C:\Program Files\Internet Download Manager
2008-07-25 22:58 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-07-25 22:58 --------- d-----w C:\Program Files\BitSpirit
2008-07-25 22:57 --------- d-----w C:\Program Files\Winamp
2008-07-25 22:56 --------- d-----w C:\Program Files\Real Alternative
2008-07-25 22:56 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-07-25 22:56 --------- d-----w C:\Program Files\Java
2008-07-25 22:56 --------- d-----w C:\Program Files\Common Files\Java
2008-07-25 22:55 --------- d-----w C:\Program Files\UltraISO
2008-07-25 22:52 --------- d-----w C:\Program Files\Nero
2008-07-25 22:52 --------- d-----w C:\Program Files\DAMN NFO Viewer
2008-07-25 22:52 --------- d-----w C:\Program Files\Common Files\Nero
2008-07-25 22:52 --------- d-----w C:\Program Files\CCleaner
2008-07-25 22:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-06-01 18:03 3,418,112 ----a-w C:\WINDOWS\system32\shimgvw.dll
2008-06-01 17:58 1,495,040 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-05-31 05:36 2,968,576 ----a-w C:\WINDOWS\system32\msgina.dll
2008-05-31 04:15 3,951,104 ----a-w C:\WINDOWS\system32\winbrand.dll
2008-05-30 09:16 2,783,232 ----a-w C:\WINDOWS\system32\logonui.exe
2008-05-30 07:56 2,343,424 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-05-28 15:51 2,711,040 ----a-w C:\WINDOWS\system32\winntbbu.dll
2008-05-06 20:11 431,104 ----a-w C:\WINDOWS\system32\winsrv.dll
2008-05-06 16:20 70,656 ----a-w C:\WINDOWS\system32\notepad.exe
2008-05-06 16:20 70,656 ----a-w C:\WINDOWS\NOTEPAD.EXE
2008-05-03 20:56 1,614,848 ----a-w C:\WINDOWS\system32\sfcfiles.dll
2008-05-03 05:27 990,208 ----a-w C:\WINDOWS\system32\syssetup.dll
2008-05-03 05:27 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-05-03 05:27 140,288 ----a-w C:\WINDOWS\system32\sfc_os.dll
.
------- Sigcheck -------
05/30/2008 10:56 AM 2343424 9a64fdd5bd8ce0018af03e31b4beaa71 C:\WINDOWS\system32\ntoskrnl.exe
01/27/2008 05:04 PM 1524224 e24cd37d23a71dbb9a484a50eb255462 C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 08:42 PM 15360]
"VisualTaskTips"="C:\Program Files\VisualTaskTips\VisualTaskTips.exe" [05/31/2008 01:50 PM 65536]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [04/14/2008 05:42 AM 1695232]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 08:42 PM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.sa/
O8 -: Download Using &BitSpirit
O8 -: سأ±بجط¾«ءéدآشط(&B)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-26 18:39:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\VisualTaskTips\VttHooks.dll
.
Completion time: 07/26/2008 18:39:32
ComboFix-quarantined-files.txt 2008-07-26 15:39:27
Pre-Run: 49,816,051,712 bytes free
Post-Run: 49,812,738,048 bytes free
98