هذا التقرير الأول
ComboFix 09-04-17.01 - MacBook 04/16/2009 20:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.1768.1274 [GMT 3:00]
Running from: c:\documents and settings\MacBook\My Documents\Downloads\Programs\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090416-0] *On-access scanning enabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\mac.dll
G:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-03-17 to 2009-04-17 )))))))))))))))))))))))))))))))
.
2009-04-16 13:51 . 2009-04-16 13:51 268 ---ha-w C:\sqmdata09.sqm
2009-04-16 13:51 . 2009-04-16 13:51 244 ---ha-w C:\sqmnoopt09.sqm
2009-04-16 13:50 . 2009-03-19 13:32 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-04-16 13:50 . 2008-04-17 09:12 107368 ----a-w c:\windows\system32\GEARAspi.dll
2009-04-16 13:50 . 2009-04-16 13:50 -------- d-----w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-16 04:53 . 2009-04-16 05:13 -------- d-----w c:\documents and settings\MacBook\Application Data\dvdcss
2009-04-16 04:50 . 2009-04-16 13:50 -------- d-----w c:\documents and settings\MacBook\Application Data\Apple Computer
2009-04-16 04:47 . 2009-04-16 13:50 -------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-04-16 04:47 . 2009-04-16 13:50 -------- d-----w c:\documents and settings\MacBook\Local Settings\Application Data\Apple Computer
2009-04-14 03:30 . 2009-04-14 03:30 1555 ----a-w c:\windows\ata live update.ini
2009-04-14 03:22 . 2009-04-14 03:22 268 ---ha-w C:\sqmdata08.sqm
2009-04-14 03:22 . 2009-04-14 03:22 244 ---ha-w C:\sqmnoopt08.sqm
2009-04-14 03:22 . 2009-04-14 03:22 -------- d-----w c:\windows\speech
2009-04-14 03:22 . 2009-04-14 03:22 172032 ------w c:\windows\Setup1.exe
2009-04-14 03:22 . 2009-04-14 03:22 73216 ----a-w c:\windows\ST6UNST.EXE
2009-04-14 03:22 . 2009-04-14 03:22 -------- d-----w C:\Al-Moheet
2009-04-11 02:24 . 2009-04-14 03:23 -------- d-----w c:\documents and settings\MacBook\Application Data\uTorrent
2009-04-09 08:15 . 2009-04-09 08:15 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-04-09 00:06 . 2009-04-09 00:06 268 ---ha-w C:\sqmdata07.sqm
2009-04-09 00:06 . 2009-04-09 00:06 244 ---ha-w C:\sqmnoopt07.sqm
2009-04-08 22:43 . 2009-04-08 22:43 -------- d-----w c:\documents and settings\MacBook\Application Data\Media Player Classic
2009-04-08 22:42 . 2009-04-09 00:23 -------- d-----w c:\windows\system32\CatRoot_bak
2009-04-08 22:31 . 2009-04-08 22:31 268 ---ha-w C:\sqmdata06.sqm
2009-04-08 22:31 . 2009-04-08 22:31 244 ---ha-w C:\sqmnoopt06.sqm
2009-04-08 22:19 . 2009-04-08 22:19 268 ---ha-w C:\sqmdata05.sqm
2009-04-08 22:19 . 2009-04-08 22:19 244 ---ha-w C:\sqmnoopt05.sqm
2009-04-08 22:17 . 2009-04-08 22:18 -------- d-----w c:\documents and settings\MacBook\Application Data\vlc
2009-04-08 21:57 . 2009-04-08 21:57 268 ---ha-w C:\sqmdata04.sqm
2009-04-08 21:57 . 2009-04-08 21:57 244 ---ha-w C:\sqmnoopt04.sqm
2009-04-08 20:47 . 2009-04-16 13:19 -------- d-----w c:\documents and settings\MacBook\Local Settings\Application Data\Ares
2009-04-08 20:14 . 2008-03-17 08:56 103168 ----a-w c:\windows\system32\drivers\ewusbfake.sys
2009-04-08 20:14 . 2008-03-17 08:03 101376 ----a-w c:\windows\system32\drivers\ewusbmdm.sys
2009-04-08 20:14 . 2008-03-16 11:47 872192 ----a-w c:\windows\system32\drivers\mod7700.sys
2009-04-08 20:14 . 2008-01-22 12:09 100992 ----a-w c:\windows\system32\drivers\ewusbnet.sys
2009-04-08 20:14 . 2007-08-09 01:13 24448 ----a-w c:\windows\system32\drivers\ewdcsc.sys
2009-04-05 16:54 . 2008-08-14 13:42 2137600 -c----w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-05 16:54 . 2008-08-14 13:42 2181888 -c----w c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-05 16:54 . 2008-08-14 13:42 2059264 -c----w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-05 16:54 . 2008-08-14 13:42 2017280 -c----w c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-05 16:48 . 2009-04-05 16:48 -------- d-----w c:\documents and settings\MacBook\Application Data\GRETECH
2009-04-05 16:41 . 2008-10-24 11:10 453632 -c----w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-05 16:32 . 2009-04-16 05:05 -------- d--h--w c:\windows\$hf_mig$
2009-04-03 19:51 . 2009-04-03 19:51 0 ----a-w c:\windows\nsreg.dat
2009-04-03 19:51 . 2009-04-03 19:51 -------- d-----w c:\documents and settings\MacBook\Local Settings\Application Data\Mozilla
2009-04-03 18:08 . 2009-04-03 18:08 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-04-03 18:08 . 2009-04-03 18:08 -------- d-----w c:\documents and settings\MacBook\Application Data\SUPERAntiSpyware.com
2009-04-03 18:05 . 2009-04-03 18:07 -------- d-----w c:\documents and settings\All Users\Application Data\WinZip
2009-04-03 17:53 . 2009-04-03 17:53 99496 ----a-w c:\documents and settings\MacBook\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-03 13:24 . 2009-04-16 02:30 -------- d-----w c:\documents and settings\MacBook\Application Data\IDM
2009-04-03 13:24 . 2009-04-16 17:21 -------- d-----w c:\documents and settings\MacBook\Application Data\DMCache
2009-04-02 12:34 . 2009-04-02 12:34 268 ---ha-w C:\sqmdata02.sqm
2009-04-02 12:34 . 2009-04-02 12:34 244 ---ha-w C:\sqmnoopt02.sqm
2009-04-01 16:08 . 2009-04-01 16:08 268 ---ha-w C:\sqmdata01.sqm
2009-04-01 16:08 . 2009-04-01 16:08 244 ---ha-w C:\sqmnoopt01.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-16 17:16 . 2004-08-04 12:00 40316 ----a-w c:\windows\system32\perfc001.dat
2009-04-16 17:16 . 2004-08-04 12:00 251946 ----a-w c:\windows\system32\perfh001.dat
2009-04-16 13:50 . 2009-04-16 13:50 -------- d-----w c:\program files\iTunes
2009-04-16 13:50 . 2009-04-16 13:50 -------- d-----w c:\program files\iPod
2009-04-16 13:50 . 2009-04-16 13:49 -------- d-----w c:\program files\Common Files\Apple
2009-04-16 13:50 . 2009-04-16 13:50 -------- d-----w c:\program files\Bonjour
2009-04-16 13:28 . 2009-04-16 13:27 -------- d-----w c:\program files\Safari
2009-04-16 04:48 . 2009-04-16 04:47 -------- d-----w c:\program files\QuickTime
2009-04-15 21:43 . 2009-04-03 13:24 -------- d-----w c:\program files\Internet Download Manager
2009-04-14 03:22 . 2009-04-14 03:22 -------- d-----w c:\program files\Golden Al-Wafi Translator
2009-04-11 19:01 . 2009-04-11 18:59 -------- d-----w c:\program files\The KMPlayer
2009-04-11 02:24 . 2009-04-11 02:24 -------- d-----w c:\program files\uTorrent
2009-04-10 02:51 . 2009-02-22 13:03 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-08 22:41 . 2009-04-03 17:25 -------- d-----w c:\program files\K-Lite Codec Pack
2009-04-08 22:16 . 2009-04-08 22:16 -------- d-----w c:\program files\VideoLAN
2009-04-08 20:47 . 2009-04-08 20:46 -------- d-----w c:\program files\Ares
2009-04-08 20:17 . 2009-04-08 20:13 -------- d-----w c:\program files\ALJAWAL 3.5G HSPA
2009-04-05 16:43 . 2009-04-05 16:43 -------- d-----w c:\program files\CEP 2009, vers 7.0 - system files
2009-04-03 18:18 . 2009-04-03 18:08 -------- d-----w c:\program files\SUPERAntiSpyware
2009-04-03 18:07 . 2009-04-03 18:07 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-03 17:46 . 2009-04-03 17:46 268 ---ha-w C:\sqmdata03.sqm
2009-04-03 17:46 . 2009-04-03 17:46 244 ---ha-w C:\sqmnoopt03.sqm
2009-04-03 17:46 . 2009-04-03 17:46 -------- d-----w c:\program files\Alwil Software
2009-04-03 17:42 . 2009-04-03 17:42 -------- d-----w c:\program files\GRETECH
2009-02-22 14:31 . 2009-02-22 14:31 268 ---ha-w C:\sqmdata00.sqm
2009-02-22 14:31 . 2009-02-22 14:31 244 ---ha-w C:\sqmnoopt00.sqm
2009-02-22 14:30 . 2009-02-22 14:30 -------- d-----w c:\program files\MSN Messenger
2009-02-22 13:36 . 2009-02-22 13:32 -------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-22 13:35 . 2009-02-22 13:35 -------- d-----w c:\program files\Microsoft Works
2009-02-22 13:35 . 2009-02-22 13:35 -------- d-----w c:\program files\MSBuild
2009-02-22 13:22 . 2009-02-22 13:22 -------- d-----w c:\program files\Intel
2009-02-22 13:21 . 2009-02-22 13:21 -------- d-----w c:\program files\Boot Camp
2009-02-22 13:21 . 2009-02-22 13:21 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-02-22 13:21 . 2009-02-22 13:21 -------- d-----w c:\program files\Motorola
2009-02-22 13:21 . 2009-02-22 13:20 1655 ----a-w C:\RHDSetup.log
2009-02-22 13:20 . 2009-02-22 13:20 -------- d-----w c:\program files\Realtek
2009-02-22 13:20 . 2009-02-22 13:20 319488 ----a-w c:\windows\HideWin.exe
2009-02-22 13:20 . 2009-02-22 13:20 -------- d--h--w c:\program files\InstallShield Installation Information
2009-02-22 13:20 . 2009-02-22 13:19 -------- d-----w c:\program files\Common Files\InstallShield
2009-02-22 13:20 . 2009-02-22 13:20 -------- d-----w c:\program files\SigmaTel
2009-02-22 13:18 . 2009-02-22 13:18 -------- d-----w c:\program files\DIFX
2009-02-22 13:18 . 2009-02-22 13:18 -------- d-----w c:\program files\Apple Software Update
2009-02-22 13:18 . 2009-02-22 13:18 -------- d-----w c:\documents and settings\All Users\Application Data\Apple
2009-02-22 13:04 . 2009-02-22 13:04 -------- d-----w c:\program files\microsoft frontpage
2009-02-22 13:01 . 2009-02-22 13:01 22144 ----a-w c:\windows\system32\emptyregdb.dat
2009-02-09 14:15 . 2004-08-04 12:00 1846144 ----a-w c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-04-03 932864]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-04-03 1830128]
"ares"="c:\program files\Ares\Ares.exe" [2009-02-03 1004544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-13 13545472]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-13 86016]
"Apple_KbdMgr"="c:\program files\Boot Camp\KbdMgr.exe" [2008-10-13 431408]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-10-13 1630208]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-10-13 16864768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2007-4-11 394856]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 09:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@="Driver Group"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
S1 aswSP;avast! Self Protection; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-03-23 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-03-23 72944]
S2 AppleOSSMgr;Apple OS Switch Manager;c:\windows\system32\AppleOSSMgr.exe [2008-10-13 136496]
S2 AppleTimeSrv;Apple Time Service;c:\windows\system32\AppleTimeSrv.exe [2008-10-13 99632]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
S2 KeyAgent;KeyAgent;c:\windows\system32\drivers\KeyAgent.sys [2008-10-13 5760]
S2 MacHALDriver;Mac HAL;c:\windows\system32\drivers\MacHALDriver.sys [2008-10-13 6784]
S3 applemtm;Apple Multitouch Mouse;c:\windows\system32\DRIVERS\applemtm.sys [2008-12-16 10496]
S3 applemtp;Apple Multitouch;c:\windows\system32\DRIVERS\applemtp.sys [2008-12-16 28544]
S3 IRRemoteFlt;IR Receiver Filter Driver;c:\windows\system32\DRIVERS\IRFilter.sys [2008-10-13 16512]
S3 KeyMagic;USB Keyboard HID Filter;c:\windows\system32\DRIVERS\KeyMagic.sys [2008-10-13 22528]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94773427-28a4-11de-a7a1-00236cb524e9}]
\Shell\AutoRun\command - e:\wd_windows_tools\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{95b29928-2079-11de-a79b-00236cb524e9}]
\Shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{adfe1e0a-2548-11de-a7a0-00236cb524e9}]
\Shell\AutoRun\command - v.cmd
\Shell\explore\Command - v.cmd
\Shell\open\Command - v.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e4a8f9c8-2488-11de-a79c-00236cb524e9}]
\Shell\AutoRun\command - E:\AutoRun.exe
.
Contents of the 'Scheduled Tasks' folder
2009-04-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\MacBook\Application Data\Mozilla\Firefox\Profiles\fp398t4v.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\documents and settings\MacBook\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-16 20:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(764)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\documents and settings\MacBook\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
.
Completion time: 2009-04-16 20:22
ComboFix-quarantined-files.txt 2009-04-16 17:22
Pre-Run: 86,394,347,520 bytes free
Post-Run: 86,452,948,992 bytes free
225 --- E O F --- 2009-04-09 00:01