هدا التتقرير يا أخي بارون
ComboFix 09-07-01.04 - salahm 07/02/2009 14:37.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.511.271 [GMT -7:00]
Running from: c:\documents and settings\salahm\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-06-02 to 2009-07-02 )))))))))))))))))))))))))))))))
.
2009-07-02 21:27 . 2009-07-02 21:27 -------- d-----w- c:\program files\Trend Micro
2009-07-02 20:22 . 2009-07-01 08:00 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVENG.SYS
2009-07-02 20:22 . 2009-07-01 08:00 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVEX15.SYS
2009-07-02 20:22 . 2009-07-01 08:00 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\EECTRL.SYS
2009-07-02 20:22 . 2009-07-01 08:00 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\ECMSVR32.DLL
2009-07-02 20:22 . 2009-07-01 08:00 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\CCERASER.DLL
2009-07-02 20:22 . 2009-07-01 08:00 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVENG32.DLL
2009-07-02 20:22 . 2009-07-01 08:00 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVEX32A.DLL
2009-07-02 20:22 . 2009-07-01 08:00 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\ERASER.SYS
2009-07-02 20:03 . 2009-07-02 07:22 165240 ----a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2009-07-02 08:02 . 2009-06-26 06:16 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\Scxpx86.dll
2009-07-02 08:02 . 2009-06-26 06:16 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSxpx86.dll
2009-07-02 08:02 . 2009-06-26 06:16 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSviA64.sys
2009-07-02 08:02 . 2009-06-26 06:16 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSvix86.sys
2009-07-02 08:02 . 2009-06-26 06:16 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys
2009-07-02 07:21 . 2009-07-02 07:21 -------- d-----w- c:\windows\system32\drivers\NIS
2009-07-02 07:21 . 2009-07-02 07:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-07-02 07:21 . 2009-07-02 07:21 -------- d-----w- c:\program files\Norton Internet Security
2009-07-02 07:21 . 2009-07-02 07:21 -------- d-----w- c:\program files\Windows Sidebar
2009-07-02 07:21 . 2009-07-02 07:21 -------- d-----w- c:\program files\NortonInstaller
2009-07-02 07:21 . 2009-07-02 07:21 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-07-02 00:44 . 2008-04-14 07:15 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2009-07-01 22:40 . 1999-09-10 11:06 5600 ----a-w- c:\windows\system\winaspi.dll
2009-07-01 22:40 . 1999-09-10 11:06 4672 ----a-w- c:\windows\system\wowpost.exe
2009-07-01 22:40 . 1999-09-10 11:06 25244 ----a-w- c:\windows\system32\drivers\aspi32.sys
2009-07-01 22:40 . 1999-09-10 11:06 45056 ----a-w- c:\windows\system32\wnaspi32.dll
2009-07-01 22:36 . 2009-07-01 22:36 203776 ----a-w- c:\windows\system32\clrviddc.dll
2009-07-01 22:33 . 2009-07-01 22:33 -------- d-----w- c:\program files\Common Files\xing shared
2009-07-01 22:32 . 2009-07-01 22:32 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-07-01 22:32 . 2009-07-01 22:32 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-07-01 22:32 . 2009-07-01 22:32 -------- d-----w- c:\program files\Common Files\Real
2009-07-01 22:32 . 2009-07-01 22:32 -------- d-----w- c:\program files\Real
2009-07-01 21:04 . 2009-07-01 21:04 -------- d-----w- c:\documents and settings\salahm\Local Settings\Application Data\Identities
2009-07-01 19:50 . 2009-07-01 19:50 -------- d-----w- c:\windows\Sun
2009-06-30 20:51 . 2009-06-30 20:51 0 ----a-w- c:\windows\nsreg.dat
2009-06-30 20:51 . 2009-06-30 20:51 -------- d-----w- c:\documents and settings\salahm\Local Settings\Application Data\Mozilla
2009-06-30 20:41 . 2009-06-30 20:41 -------- d-----w- c:\documents and settings\salahm\Local Settings\Application Data\Yahoo
2009-06-30 20:19 . 2009-06-30 20:19 -------- d-----w- c:\docume~1\salahm\APPLIC~1\Yahoo!
2009-06-30 20:13 . 2009-06-30 20:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-06-30 20:13 . 2009-05-27 02:50 607472 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-06-30 20:13 . 2009-07-01 02:47 -------- d-----w- c:\program files\Yahoo!
2009-06-30 04:43 . 2008-04-14 12:00 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-06-30 04:42 . 2008-04-14 12:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-06-30 04:42 . 2009-06-30 04:42 -------- d-----w- c:\program files\Windows Media Connect 2
2009-06-30 04:40 . 2009-06-30 04:41 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-06-30 04:40 . 2009-06-30 04:40 -------- d-----w- c:\windows\system32\LogFiles
2009-06-30 04:40 . 2006-09-26 00:58 23856 ----a-w- c:\windows\system32\spupdsvc.exe
2009-06-30 04:38 . 2009-06-30 04:38 -------- d-----w- c:\program files\CCleaner
2009-06-30 04:35 . 2009-06-30 04:35 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-30 04:35 . 2009-06-30 04:35 -------- d-----w- c:\program files\Java
2009-06-30 04:34 . 2009-06-30 04:34 -------- d-----w- c:\documents and settings\salahm\Local Settings\Application Data\Adobe
2009-06-30 04:32 . 2009-06-30 04:33 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-30 04:30 . 2009-07-01 21:58 -------- d-----w- c:\docume~1\salahm\APPLIC~1\IDM
2009-06-30 04:30 . 2009-07-02 21:35 -------- d-----w- c:\docume~1\salahm\APPLIC~1\DMCache
2009-06-30 04:30 . 2009-06-30 04:30 -------- d-----w- c:\program files\Internet Download Manager
2009-06-30 04:30 . 2008-09-29 05:00 439440 ----a-w- c:\program files\un_Internet Download Manager_16575.exe
2009-06-29 23:01 . 2009-06-29 23:01 -------- d-s---w- c:\documents and settings\salahm\UserData
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-02 20:30 . 2009-07-02 07:22 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-02 07:22 . 2009-07-02 07:22 -------- d-----w- c:\program files\Symantec
2009-07-02 07:22 . 2009-07-02 07:22 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-07-02 07:22 . 2009-07-02 07:22 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-07-02 07:22 . 2009-07-02 07:22 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-07-02 07:22 . 2009-07-02 07:22 10635 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-07-02 07:22 . 2009-07-02 07:22 35888 ----a-r- c:\windows\system32\drivers\SymIM.sys
2009-07-02 07:22 . 2009-07-02 07:22 1294680 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-07-02 07:22 . 2009-07-02 07:22 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-05-08 2807216]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-30 148888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-07-01 198160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-6-29 352256]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1000000.07D\SymEFA.sys [7/2/2009 12:22 AM 309296]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1000000.07D\BHDrvx86.sys [7/2/2009 12:22 AM 254512]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1000000.07D\ccHPx86.sys [7/2/2009 12:22 AM 362544]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys [7/2/2009 1:02 AM 276344]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe [7/2/2009 12:22 AM 115560]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [6/29/2009 3:46 PM 377920]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - EECTRL
*NewlyCreated* - ERASERUTILDRV10910
*Deregistered* - EraserUtilDrv10910
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
.
------- Supplementary Scan -------
.
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
TCP: {38A9E153-8CC2-49CF-93EB-286BD737C4F8} = 192.168.1.1
FF - ProfilePath - c:\docume~1\salahm\APPLIC~1\Mozilla\Firefox\Profiles\53a6rqn7.default\
FF - component: c:\documents and settings\salahm\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-02 14:39
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(892)
c:\windows\system32\antiwpa.dll
- - - - - - - > 'explorer.exe'(2344)
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-02 14:41
ComboFix-quarantined-files.txt 2009-07-02 21:41
Pre-Run: 49,191,968,768 bytes free
Post-Run: 49,187,889,152 bytes free
201