وهذا تقرير الأداة الثانية
ComboFix 09-06-03.04 - ziad 06/04/2009 13:57.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.1023.664 [GMT 3:00]
Running from: c:\documents and settings\ziad\سطح المكتب\ComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
.
((((((((((((((((((((((((( Files Created from 2009-05-04 to 2009-06-04 )))))))))))))))))))))))))))))))
.
2009-06-04 06:40 . 2009-06-03 08:00 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090603.052\NAVENG.SYS
2009-06-04 06:40 . 2009-06-03 08:00 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090603.052\NAVEX15.SYS
2009-06-04 06:40 . 2009-06-03 08:00 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090603.052\EECTRL.SYS
2009-06-04 06:40 . 2009-06-03 08:00 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090603.052\ECMSVR32.DLL
2009-06-04 06:40 . 2009-06-03 08:00 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090603.052\CCERASER.DLL
2009-06-04 06:40 . 2009-06-03 08:00 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090603.052\NAVENG32.DLL
2009-06-04 06:40 . 2009-06-03 08:00 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090603.052\NAVEX32A.DLL
2009-06-04 06:40 . 2009-06-03 08:00 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090603.052\ERASER.SYS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-04 01:37 . 2009-06-04 00:30 -------- d-----w- c:\program files\Symantec
2009-06-04 01:37 . 2009-06-04 00:30 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-06-04 01:37 . 2009-06-04 00:30 7386 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-06-04 01:37 . 2009-06-04 00:30 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-06-04 01:37 . 2009-06-04 00:30 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-06-04 00:54 . 2009-06-04 00:30 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-04 00:30 . 2009-06-04 00:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-06-04 00:30 . 2009-06-04 00:30 35888 ----a-r- c:\windows\system32\drivers\SymIM.sys
2009-06-04 00:30 . 2009-06-04 00:30 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2009-06-04 00:30 . 2009-06-04 00:30 1294680 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-06-04 00:30 . 2009-06-04 00:30 791920 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-06-04 00:30 . 2009-06-04 00:30 -------- d-----w- c:\program files\Norton AntiVirus
2009-06-04 00:30 . 2009-06-04 00:30 -------- d-----w- c:\program files\Windows Sidebar
2009-06-04 00:29 . 2009-06-04 00:29 -------- d-----w- c:\program files\NortonInstaller
2009-06-04 00:29 . 2009-06-04 00:29 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-06-04 00:27 . 2009-06-04 00:26 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-04 00:11 . 2009-06-04 00:11 -------- d-----w- c:\program files\Microsoft.NET
2009-06-04 00:11 . 2009-06-04 00:11 -------- d-----w- c:\program files\Microsoft Works
2009-06-04 00:06 . 2009-06-04 00:01 -------- d-----w- c:\program files\Common Files\InstallShield
2009-06-04 00:04 . 2009-06-04 00:01 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-04 00:04 . 2009-06-04 00:04 -------- d-----w- c:\program files\Realtek Sound Manager
2009-06-04 00:04 . 2009-06-04 00:04 -------- d-----w- c:\program files\AvRack
2009-06-04 00:02 . 2009-06-04 00:02 -------- d-----w- c:\program files\Intel
2009-06-03 23:57 . 2001-09-19 14:00 39982 ----a-w- c:\windows\system32\perfc001.dat
2009-06-03 23:57 . 2001-09-19 14:00 251478 ----a-w- c:\windows\system32\perfh001.dat
2009-06-03 23:52 . 2009-06-03 23:52 -------- d-----w- c:\program files\microsoft frontpage
2009-06-03 23:51 . 2009-06-03 23:51 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-03 23:48 . 2009-06-03 23:48 22144 ----a-w- c:\windows\system32\emptyregdb.dat
2009-03-24 13:08 . 2009-06-04 00:17 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-03-16 20:03 . 2009-06-04 00:52 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090528.001\Scxpx86.dll
2009-03-16 20:03 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\Scxpx86.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-20 7110656]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-07-20 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-04-15 77824]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-07-20 1519616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1005000.086\SymEFA.sys [04/06/2009 04:37 ص 310320]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090528.001\IDSxpx86.sys [04/06/2009 03:52 ص 276344]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe [04/06/2009 04:37 ص 115560]
R3 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1000000.07D\BHDrvx86.sys [04/06/2009 03:30 ص 254512]
R3 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1000000.07D\ccHPx86.sys [04/06/2009 03:30 ص 362544]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - EECTRL
*NewlyCreated* - ERASERUTILDRV10910
*Deregistered* - EraserUtilDrv10910
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-04 13:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.5.0.134\diMaster.dll\" /prefetch:1"
.
Completion time: 2009-06-04 14:00
ComboFix-quarantined-files.txt 2009-06-04 11:00
Pre-Run: 29,144,211,456 bytes free
Post-Run: 29,194,424,320 bytes free
107