السلام عليكم .. اخي ابو ريما برنامجي الحمايه افيرا ولا اعرف ايقافه لكني ازلت اشاره الصح واقفلت المظله ..
هذا هو التقرير
ComboFix 09-06-07.07 - شخصي 06/09/2009 16:55.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.1014.575 [GMT 3:00]
Running from: c:\documents and settings\شخصي\سطح المكتب\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: Avira Firewall *enabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Avira\AntiVir Desktop\avsda.dll
c:\windows\system32\videoformat.dll
c:\windows\system32\WgaLogon.dll
.
((((((((((((((((((((((((( Files Created from 2009-05-09 to 2009-06-09 )))))))))))))))))))))))))))))))
.
2009-06-08 12:06 . 2008-12-24 19:08 38200 ----a-w- c:\documents and settings\شخصي\Application Data\Macromedia\Flash Player\
2009-06-07 17:25 . 2009-06-07 17:25 -------- d-----w- c:\documents and settings\شخصي\Application Data\Media Player Classic
2009-06-05 13:22 . 2009-06-05 13:22 -------- d-----w- c:\program files\Microsoft Math Add-in for Word 2007
2009-06-05 13:22 . 2009-06-05 13:22 -------- d-----w- c:\program files\Classic Menu for Office
2009-06-04 23:19 . 2009-06-04 23:19 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-04 23:14 . 2009-06-04 23:14 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-06-04 23:13 . 2009-06-04 23:13 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-06-04 23:13 . 2009-06-04 23:13 -------- d-----w- c:\program files\Common Files\Intel
2009-06-04 22:35 . 2009-06-04 22:35 -------- d-----w- c:\program files\Microsoft Silverlight
2009-06-04 22:16 . 2009-06-04 22:24 97480 ----a-w- c:\windows\system32\drivers\avfwot.sys
2009-06-04 22:16 . 2009-06-04 22:24 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-04 22:16 . 2009-06-04 22:24 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-04 22:16 . 2009-02-24 09:06 69632 ----a-w- c:\windows\system32\drivers\avfwim.sys
2009-06-04 22:16 . 2009-02-13 08:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-06-04 22:16 . 2009-02-13 08:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-06-04 22:16 . 2009-06-04 22:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-06-04 22:16 . 2009-06-04 22:16 -------- d-----w- c:\program files\Avira
2009-06-04 22:13 . 2009-06-04 22:13 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-06-04 22:12 . 2009-06-04 22:12 -------- d-----w- c:\program files\My Company
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-09 14:04 . 2008-09-11 21:39 -------- d-----w- c:\documents and settings\شخصي\Application Data\DMCache
2009-06-09 13:53 . 2001-09-19 17:00 72342 ----a-w- c:\windows\system32\perfc001.dat
2009-06-09 13:53 . 2001-09-19 17:00 378594 ----a-w- c:\windows\system32\perfh001.dat
2009-06-08 12:06 . 2008-09-10 13:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Babylon
2009-06-07 19:49 . 2008-09-10 15:36 90112 ----a-w- c:\windows\DUMP4362.tmp
2009-06-05 13:53 . 2008-09-10 14:02 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-05 13:49 . 2008-09-10 13:14 156792 ----a-w- c:\documents and settings\شخصي\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-05 13:44 . 2008-09-10 13:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-05 13:41 . 2009-02-14 13:53 -------- d-----w- c:\program files\Microsoft Works
2009-06-05 13:41 . 2008-09-10 13:21 -------- d-----w- c:\program files\MSBuild
2009-06-05 13:23 . 2009-02-13 19:14 -------- d-----w- c:\program files\Microsoft
2009-06-04 23:46 . 2008-09-12 21:53 -------- d-----w- c:\program files\LtUcx
2009-06-04 23:19 . 2008-09-10 14:05 -------- d-----w- c:\program files\Java
2009-06-04 23:15 . 2008-09-10 16:16 -------- d-----w- c:\program files\Intel
2009-06-04 22:34 . 2009-06-04 22:33 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-05-01 21:02 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 ----a-w- c:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 ----a-w- c:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\DivX.dll
2009-04-26 20:56 . 2009-04-26 20:56 -------- d-----w- c:\program files\Trend Micro
2009-04-26 19:24 . 2009-04-26 19:24 -------- d-----w- c:\program files\GRETECH
2009-04-23 22:08 . 2008-09-10 14:01 -------- d-----w- c:\program files\Messenger Plus! Live
2009-03-20 11:33 . 2009-03-20 11:33 48 ---ha-w- c:\windows\system32\ezsidmv.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-09-15 2606512]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-04 148888]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-5-17 568176]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"OEM02Mon.exe"=c:\windows\OEM02Mon.exe
"Persistence"=c:\windows\system32\igfxpers.exe
"StormCodec_Helper"="c:\program files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
R0 ulsata2;ulsata2;c:\windows\system32\drivers\ulsata2.sys [07/05/2008 07:09 ص 124928]
R1 avfwot;avfwot;c:\windows\system32\drivers\avfwot.sys [05/06/2009 01:16 ص 97480]
R2 AntiVirFirewallService;Avira Firewall;c:\program files\Avira\AntiVir Desktop\avfwsvc.exe [05/06/2009 01:16 ص 388865]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [05/06/2009 01:16 ص 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [05/06/2009 01:16 ص 432897]
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\drivers\avfwim.sys [05/06/2009 01:16 ص 69632]
R3 OEM02Afx;Provides a software interface to control audio effects of OEM002 camera.;c:\windows\system32\drivers\OEM02Afx.sys [10/09/2008 06:04 م 141376]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\OEM02Dev.sys [10/09/2008 06:04 م 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\OEM02Vfx.sys [10/09/2008 06:04 م 7424]
S2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [05/06/2009 01:16 ص 194817]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [16/06/2008 11:31 ص 7808]
S3 tap0901;TAP-Win32 Adapter V9;c:\windows\system32\drivers\tap0901.sys [17/12/2008 11:37 م 25216]
.
Contents of the 'Scheduled Tasks' folder
2009-06-08 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 19:34]
2009-06-09 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 19:34]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ae/
IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-09 17:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(992)
c:\windows\system32\netprovcredman.dll
- - - - - - - > 'explorer.exe'(3792)
c:\windows\system32\btmmhook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
.
**************************************************************************
.
Completion time: 2009-06-09 17:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-09 14:07
ComboFix2.txt 2009-05-10 18:35
ComboFix3.txt 2009-04-26 21:50
ComboFix4.txt 2009-04-26 21:30
ComboFix5.txt 2009-06-09 13:55
Pre-Run: 35,232,116,736 bytes free
Post-Run: 36,017,483,776 bytes free
183 --- E O F --- 2009-06-01 22:12