السلام عليكم
جزاك الله خيرا وحفظك من كل مكروه وحقق لك امانيك
فعلا انت فارس شهم وملاك رحمة, هاهو التقرير الأول وسأوافيك بالثاني بعد قليل ان شاء الله
شكرا لتجاوبك اختي العرافة , لكنني لم افهم السؤال
ComboFix 08-07-09.5 - zoubairi mohammed 2008-07-10 20:28:31.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.1.1256.966.1036.18.13 [GMT 2:00]Endroit: D:\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RةCUPةRATION N'EST PAS INSTALLةE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\zoubairi mohammed\Application Data\rhclarj0e57j
C:\Program Files\rhclarj0e57j
C:\WINDOWS\Integrator.exe
C:\WINDOWS\system32\1.tmp
C:\WINDOWS\system32\7.tmp
C:\WINDOWS\system32\8.tmp
C:\WINDOWS\system32\9.tmp
C:\WINDOWS\system32\A.tmp
C:\WINDOWS\system32\blphcgarj0e57j.scr
C:\WINDOWS\system32\drivers\svchost.exe
C:\WINDOWS\system32\kdkrv.exe
C:\WINDOWS\system32\lphcgarj0e57j.exe
C:\WINDOWS\system32\phcgarj0e57j.bmp
C:\WINDOWS\system32\pphcgarj0e57j.exe
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-10 to 2008-07-10 ))))))))))))))))))))))))))))))))))))
.
2008-07-10 17:55 . 2008-07-10 17:55 <REP> d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-07-10 13:53 . 2008-07-10 17:31 <REP> d-------- C:\Program Files\Windows Live Safety Center
2008-07-09 23:08 . 2008-07-09 23:09 <REP> d-------- C:\Downloads
2008-07-06 00:22 . 2008-07-06 00:22 4 --a------ C:\WINDOWS\RegDefrag.dat
2008-06-15 00:30 . 2008-06-15 00:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-10 18:35 --------- d-----w C:\Program Files\FlashGet
2008-07-10 16:40 94,208 ----a-w C:\WINDOWS\system32\53.tmp
2008-07-10 16:40 94,208 ----a-w C:\WINDOWS\system32\1D.tmp
2008-07-10 16:30 94,208 ----a-w C:\WINDOWS\system32\1C.tmp
2008-07-10 16:30 94,208 ----a-w C:\WINDOWS\system32\1B.tmp
2008-07-10 16:30 94,208 ----a-w C:\WINDOWS\system32\1A.tmp
2008-07-10 16:29 94,208 ----a-w C:\WINDOWS\system32\19.tmp
2008-07-10 16:29 94,208 ----a-w C:\WINDOWS\system32\18.tmp
2008-07-10 16:29 94,208 ----a-w C:\WINDOWS\system32\17.tmp
2008-07-10 16:29 94,208 ----a-w C:\WINDOWS\system32\16.tmp
2008-07-10 16:29 94,208 ----a-w C:\WINDOWS\system32\15.tmp
2008-07-10 16:24 94,208 ----a-w C:\WINDOWS\system32\11.tmp
2008-07-10 00:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-10 00:10 --------- d-----w C:\Program Files\Dachshund Software
2008-07-09 20:24 --------- d-----w C:\Program Files\Registry Fast
2008-07-09 17:34 --------- d-----w C:\Program Files\Kaspersky Lab
2008-07-09 17:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-13 18:37 --------- d-----w C:\Documents and Settings\zoubairi mohammed\Application Data\CrystalButton
2008-06-02 15:29 --------- d-----w C:\Program Files\Registry Compressor
2008-05-15 17:35 4,270 ----a-w C:\Program Files\INSTALL.LOG
2008-05-15 17:35 387,530 ----a-w C:\WINDOWS\system32\MAGE.DLL
2008-05-15 17:35 --------- d-----w C:\Program Files\Images
2008-05-14 21:58 --------- d-----w C:\Program Files\DSL Speed
2008-04-15 20:36 49,576 ----a-w C:\Documents and Settings\zoubairi mohammed\Application Data\GDIPFONTCACHEV1.DAT
2002-09-21 10:26 1,874,381 ----a-w C:\Program Files\Hare.exe
2001-11-11 10:31 344 ------w C:\Program Files\Help.htm
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-11-15 16:18 1739776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-03-02 00:03 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 117616]
"CheckRegDefragService"="C:\PROGRA~1\REGIST~2\rbcs.exe" [2004-09-22 23:18 373248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2003-04-24 14:00 13312]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideShutdownScripts"= 0 (0x0)
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableLockWorkstation"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispCPL"= 0 (0x0)
"NoDispAppearancePage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoVisualStyleChoice"= 0 (0x0)
"NoColorChoice"= 0 (0x0)
"NoSizeChoice"= 0 (0x0)
"DisableLockWorkstation"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeKeyboardNavigationIndicators"= 0 (0x0)
"NoChange"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
"RestrictRun"= 0 (0x0)
"NoRecycleFiles"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoWinKeys"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoInstrumentation"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuMFUprogramsList"= 0 (0x0)
"NoStartMenuPinnedList"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"ForceStartMenuLogoff"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"LockTaskbar"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
"NoExpandedNewMenu"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"EnforceShellExtensionSecurity"= 0 (0x0)
"NoLogOff"= 0 (0x0)
"NoRunasInstallPrompt"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoResolveSearch"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoThemesTab"= 0 (0x0)
"NoChangeKeyboardNavigationIndicators"= 0 (0x0)
"NoChange"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
"RestrictRun"= 0 (0x0)
"DisallowRun"= 0 (0x0)
"NoRecycleFiles"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoViewContextMenu"= 0 (0x0)
"NoWinKeys"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoInstrumentation"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoRun"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoFind"= 0 (0x0)
"NoStartMenuMFUprogramsList"= 0 (0x0)
"NoStartMenuPinnedList"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
"NoStartMenuMorePrograms"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"ForceStartMenuLogoff"= 0 (0x0)
"StartMenuLogoff"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"NoSetFolders"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"NoTrayContextMenu"= 0 (0x0)
"LockTaskbar"= 0 (0x0)
"HideClock"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoActiveDesktopChanges"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)
"NoExpandedNewMenu"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"EnforceShellExtensionSecurity"= 0 (0x0)
"NoClose"= 0 (0x0)
"NoLogOff"= 0 (0x0)
"NoRunasInstallPrompt"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoResolveSearch"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^zoubairi mohammed^Menu Démarrer^Programmes^Démarrage^Eurobarre.lnk]
backup=C:\WINDOWS\pss\Eurobarre.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^zoubairi mohammed^Menu Démarrer^Programmes^Démarrage^Hare.lnk]
backup=C:\WINDOWS\pss\Hare.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Error Nuker]
--a------ 2005-01-17 20:10 3072000 C:\Program Files\Error Nuker\bin\ErrorNuker.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
--a------ 2007-04-16 17:10 1773568 C:\Program Files\FlashGet\flashget.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-11-15 16:18 1739776 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"Messenger"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe"=
"C:\\DOCUME~1\\ZOUBAI~1\\LOCALS~1\\Temp\\hmvyc.exe"=
"C:\\DOCUME~1\\ZOUBAI~1\\LOCALS~1\\Temp\\goxgo.exe"=
"C:\\DOCUME~1\\ZOUBAI~1\\LOCALS~1\\Temp\\windlmadg.exe"=
"C:\\Program Files\\Fichiers communs\\Real\\Update_OB\\realsched.exe"=
R3 asc3360pr;asc3360pr;C:\WINDOWS\System32\drivers\udmjjl.sys []
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-CheckRegDefragService - (no file)
HKLM-Run-C:\WINDOWS\system32\kdkrv.exe - C:\WINDOWS\system32\kdkrv.exe
HKLM-Run-lphcgarj0e57j - C:\WINDOWS\System32\lphcgarj0e57j.exe
HKLM-Run-SMrhclarj0e57j - C:\Program Files\rhclarj0e57j\rhclarj0e57j.exe
Notify-fsp_lmwl - (no file)
Notify-WgaLogon - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-10 20:37:09
Windows 5.1.2600 Service Pack 1 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
C:\ComboFix\CreateD00 32 bytes
C:\ComboFix\CreateD00.bat 88 bytes
Scan termin‚ avec succٹs
Les fichiers cach‚s: 2
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\DOCUME~1\ZOUBAI~1\LOCALS~1\Temp\goxgo.exe
C:\DOCUME~1\ZOUBAI~1\LOCALS~1\Temp\hmvyc.exe
C:\DOCUME~1\ZOUBAI~1\LOCALS~1\Temp\windlmadg.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-10 20:45:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-10 18:44:40
Pre-Run: 5,216,923,648 octets libres
Post-Run: 5,768,396,800 octets libres
278