هلا اخووي
Demo-dash
هذا تقرير combofix
ComboFix 08-08-08.08 - alhusaintoon 08/10/2008 0:43:41.1 - NTFSx86
Microsoft® Windows Vista™ Business 6.0.6000.0.1256.1.1033.18.382 [GMT 4:00]
Running from: C:\Users\alhusaintoon\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\AutoRun.inf
.
((((((((((((((((((((((((( Files Created from 2008-07-09 to 2008-08-09 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-09 20:47 --------- d-----w C:\Users\alhusaintoon\AppData\Roaming\DMCache
2008-08-09 16:53 --------- d-----w C:\ProgramData\HP Product Assistant
2008-08-09 16:53 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-07 13:17 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-06 14:35 --------- d-----w C:\Users\alhusaintoon\AppData\Roaming\Apple Computer
2008-08-06 14:15 --------- d-----w C:\Users\alhusaintoon\AppData\Roaming\IDM
2008-08-06 14:00 --------- d-----w C:\Program Files\Internet Download Manager
2008-08-05 19:56 --------- d-----w C:\Users\alhusaintoon\AppData\Roaming\eBookPro6
2008-08-05 12:24 --------- d-----w C:\ProgramData\WEBREG
2008-08-05 11:42 --------- d-----w C:\ProgramData\HP
2008-08-05 11:34 --------- d-----w C:\ProgramData\HPSSUPPLY
2008-08-05 11:34 --------- d-----w C:\Program Files\HP
2008-08-05 11:32 --------- d-----w C:\Program Files\Common Files\HP
2008-08-05 11:31 --------- d-----w C:\Program Files\Hewlett-Packard
2008-08-05 11:31 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-08-05 11:20 --------- d-----w C:\ProgramData\Hewlett-Packard
2008-08-04 21:15 --------- d-----w C:\ProgramData\Symantec
2008-08-04 11:32 --------- d-----w C:\Program Files\MessengerDiscovery
2008-08-03 19:06 --------- d-----w C:\Program Files\MSN Messenger
2008-08-03 14:57 --------- d-----w C:\Program Files\Covey Inc
2008-07-30 13:42 23,888 ----a-w C:\Windows\system32\drivers\COH_Mon.sys
2008-07-30 13:28 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf
2008-07-30 13:28 10,537 ----a-w C:\Windows\system32\drivers\coh_mon.cat
2008-07-28 12:42 --------- d-----w C:\Program Files\Java
2008-07-28 12:41 --------- d-----w C:\Program Files\Common Files\Java
2008-07-27 17:00 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2008-07-27 17:00 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2008-07-27 17:00 10,563 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2008-07-27 17:00 --------- d-----w C:\Program Files\Symantec
2008-07-27 16:42 240,128 ----a-w C:\Windows\system32\drivers\royal.sys
2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [01/19/2007 12:54 PM 5674352]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [02/07/2008 10:28 AM 2586032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [02/01/2008 01:25 AM 115560]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM 144784]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antvirus]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 01/11/2008 10:16 PM 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 03/11/2007 09:34 PM 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 02/07/2008 10:28 AM 2586032 C:\Program Files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 11/02/2006 04:34 PM 1004136 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{72261045-F3D0-4FD3-81AC-C7BBD77E5052}"= UDP:C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe:SMC Service
"{6042BB97-1125-40CE-8D15-86408B6868EB}"= TCP:C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe:SMC Service
"{47F79FF1-FA90-4FCE-A793-38B756CD03A7}"= UDP:C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE:SNAC Service
"{ABAF677B-06D5-428A-AD13-0BB09BFEDB5D}"= TCP:C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE:SNAC Service
"{A5048EDE-51F8-4F11-B678-92EFB5E3E2C9}"= UDP:C:\Program Files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"{11801807-1BC3-44AF-83A2-F45CD56FAAD5}"= TCP:C:\Program Files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"TCP Query User{04C19089-E806-4BB9-A9D2-1B4EFFAFAE13}C:\\program files\\messengerdiscovery\\messengerdiscovery live.exe"= UDP:C:\program files\messengerdiscovery\messengerdiscovery live.exe:MessengerDiscovery Live the Windows Live Messenger addon
"UDP Query User{1F76ED0D-9584-4FE2-99C9-D17119B3F1E8}C:\\program files\\messengerdiscovery\\messengerdiscovery live.exe"= TCP:C:\program files\messengerdiscovery\messengerdiscovery live.exe:MessengerDiscovery Live the Windows Live Messenger addon
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
S0 OemBiosDevice;Royalty OEM Bios Extension;C:\Windows\system32\drivers\royal.sys [07/27/2008 08:42 PM]
S3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [07/30/2008 05:42 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-08-08 C:\Windows\Tasks\User_Feed_Synchronization-{8E801505-60C3-4645-B15E-3CC29576C1FF}.job
- C:\Windows\system32\msfeedssync.exe [11/02/2006 01:45 PM]
.
.
------- Supplementary Scan -------
.
O8 -: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 -: Download FLV video with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 -: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-10 00:47:51
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 08/10/2008 0:49:32
ComboFix-quarantined-files.txt 2008-08-09 20:49:27
Pre-Run: 18,185,695,232 bytes free
Post-Run: 18,138,415,104 bytes free
129