بارك الله فيك وجزاك كل خير
هذا التقرير بالاداة الاولى ظهر ولم يعد الجهاز التشغيل لوحدة
ComboFix 08-06-07.3 - Administrator 06/08/2008 11:42:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.67 [GMT -7:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-05-08 to 2008-06-08 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-09 00:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-06-09 00:42 --------- d-----w C:\Program Files\Yahoo!
2008-06-09 00:11 --------- d-----w C:\Documents and Settings\Administrator\Application Data\IDM
2008-06-08 22:28 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-06-08 22:28 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-06-08 22:28 --------- d-----w C:\Program Files\Common Files\xing shared
2008-06-08 22:28 --------- d-----w C:\Program Files\Common Files\Real
2008-06-08 22:26 --------- d-----w C:\Program Files\Real
2008-06-08 22:14 --------- d-----w C:\Program Files\Internet Download Manager
2008-06-08 21:01 --------- d-----w C:\Program Files\microsoft frontpage
2008-06-08 20:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-08 20:56 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-06-08 20:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-06-08 19:51 --------- d-----w C:\Program Files\Kaspersky Lab
2008-06-08 19:33 155,995 ----a-w C:\WINDOWS\java\Packages\LBJ3ZT3H.ZIP
2008-06-08 19:19 --------- d-----w C:\Program Files\MSN Messenger Khalid Edition 4.2 AR
2008-06-08 18:40 --------- d-----w C:\Program Files\LeapFTP
2008-06-08 18:40 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DMCache
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [03/11/2004 05:18 PM 14336]
"msnmsgr"="C:\Program Files\MSN Messenger Khalid Edition 4.2 AR\msnmsgr.exe" [07/14/2005 07:30 PM 6848512]
"Messenger Plus3"="C:\Program Files\MSN Messenger Khalid Edition 4.2 AR\Messenger Plus! 3\MsgPlus.exe" [07/08/2005 06:08 AM 246920]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [06/08/2008 03:13 PM 2594224]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [08/09/2006 03:41 PM 4679160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/08/2008 03:28 PM 247336]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [03/11/2004 05:18 PM 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=MsgPlusLoader.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"F:\\اداة حذف المسنجـــر\\14096_remov\\Uninstall Windows Messenger.exe"=
"C:\\WINDOWS\\Explorer.EXE"=
"C:\\Program Files\\MSN Messenger Khalid Edition 4.2 AR\\msnmsgr.exe"=
"C:\\WINDOWS\\system32\\ctfmon.exe"=
"C:\\Program Files\\MSN Messenger Khalid Edition 4.2 AR\\Messenger Plus! 3\\MsgPlus.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\LeapFTP\\LeapFTP.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Internet Download Manager\\IEMonitor.exe"=
"C:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\windyvis.exe"=
"C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\winqtdcf.exe"=
R3 aic32p;aic32p;C:\WINDOWS\system32\drivers\ngpim.sys []
R3 trid3d;trid3d;C:\WINDOWS\system32\DRIVERS\trid3dm.sys [08/17/2001 05:51 AM]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-06-08 10:46:22
Windows 5.1.2600 Service Pack 2, v.2096 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 06/08/2008 10:50:03
ComboFix-quarantined-files.txt 2008-06-08 17:49:53
Pre-Run: 2,753,409,024 bytes free
Post-Run: 2,787,233,792 bytes free
82
بانتظـاركـــ لاكمال الاداة الثانية