من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
بسم الله الرحمن الرحيم
سأقول لكم مشكلتي باختصار على شكل نقاط:
المشكلة الاولى :قمت باستخدام هذه الاداة
وعملت تنظيف بواسطتها وما ان انتهيت الا واختفت ايقونات بعض البرامج في الجهاز
اما ملفات برامج الاوفس فعند محاولة فتحها تظهر هذه الرسالة
ـــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــ
ــــــــــــــــــــــــــــــــــــــــــــــــ
المشكلة الثانية : أواجه ثقل في جهازي وفي تصفح بعض المواقع خاصة منتدى زيزوووم.. شوفوا التقارير يمكن الجهاز مخترق..:er:
ـــــــــــــــــــــــــــــــــ
ـــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــ
سؤال أخير : سمعت ان هناك طريقة لصيانة الويندوز عن طريق سيدي الويندوز لكن لا أعلم ماهي الطريقة ياليت لو تدلوني على الطريقة...
ـــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــ
وهذه هي التقارير
الاول بـ combofix
ComboFix 08-08-10.01 - Administrator 08/10/2008 22:38:55.1 - NTFSx86
Running from: C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\.#
C:\Documents and Settings\Administrator\Application Data\.#\MBX@1EC@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@1EC@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@1EC@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@214@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@214@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@214@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@260@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@260@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@260@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@268@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@268@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@268@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@270@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@270@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@270@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@274@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@274@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@274@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@278@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@278@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@278@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@27C@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@27C@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@27C@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@284@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@284@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@284@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@B84@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@B84@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@B84@9B3320.###
.
((((((((((((((((((((((((( Files Created from 2008-07-10 to 2008-08-10 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-10 19:47 14,990,112 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-10 19:46 560,160 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-08-10 19:46 --------- d-----w C:\Documents and Settings\Administrator\Application Data\utorrent
2008-08-10 19:46 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DMCache
2008-08-10 19:45 56,600 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-08-10 19:45 210,992 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-10 18:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-10 15:37 --------- d-----w C:\Program Files\Multilizer 6
2008-08-09 21:06 --------- d-----w C:\Program Files\Stepok's Gigital Beauty
2008-08-08 21:30 --------- d-----w C:\Documents and Settings\Administrator\Application Data\TechSmith
2008-08-07 22:01 --------- d-----w C:\Program Files\TechSmith
2008-08-07 22:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\TechSmith
2008-08-07 21:57 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-06 20:18 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-08-02 12:58 --------- d-----w C:\Program Files\Memory Improve Professional
2008-08-02 12:46 --------- d-----w C:\Program Files\BearShare
2008-08-01 13:55 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Thinstall
2008-07-30 21:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-30 21:52 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-30 21:46 --------- d-----w C:\Program Files\GVR
2008-07-30 12:58 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia Multimedia Player
2008-07-30 12:57 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia
2008-07-29 23:47 --------- d-----w C:\Program Files\Internet Download Manager
2008-07-29 12:12 --------- d-----w C:\Program Files\utorrent
2008-07-29 10:56 --------- d-----w C:\Program Files\Laser Dolphin
2008-07-28 09:52 --------- d-----w C:\Documents and Settings\Administrator\Application Data\IDM
2008-07-24 09:42 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-07-19 19:25 --------- d-----w C:\Program Files\Virtual Earth 3D
2008-07-19 18:31 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-07-15 08:14 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-12 00:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-07-09 15:51 --------- d-----w C:\Program Files\Rainy Screensaver
2008-07-09 15:51 --------- d-----w C:\Program Files\ma-config.com
2008-07-09 15:36 --------- d-----w C:\Program Files\STOIK
2008-07-09 13:24 --------- d-----w C:\Program Files\Ashkon Software
2008-07-08 14:30 --------- d-----w C:\Program Files\Two Pilots
2008-07-08 14:30 --------- d-----w C:\Program Files\MakeUp Pilot
2008-07-08 14:30 --------- d-----w C:\Documents and Settings\Administrator\Application Data\MakeUpPilot
2008-07-07 19:29 --------- d-----w C:\Program Files\ScannerU
2008-07-07 14:29 --------- d-----w C:\Program Files\CCleaner
2008-07-07 14:11 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-07-07 14:11 --------- d-----w C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2008-07-07 14:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-07-07 07:54 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Ahead
2008-07-07 07:17 --------- d-----w C:\Program Files\Common Files\Ahead
2008-07-07 07:14 --------- d-----w C:\Program Files\Nero
2008-07-06 22:54 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-06 13:01 --------- d-----w C:\Program Files\All-in-1 Mobile Video Convert
2008-07-06 12:44 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-07-05 21:48 --------- d-----w C:\Program Files\XPC Tools
2008-07-05 21:33 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ma-config.com
2008-07-05 19:39 --------- d-----w C:\Program Files\Avant Browser
2008-07-05 19:39 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Avant Profiles
2008-07-05 17:13 --------- d-----w C:\Program Files\Windows Live
2008-07-05 12:47 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-07-05 12:31 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-07-05 11:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-07-05 11:48 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-07-05 11:48 --------- d-----w C:\Program Files\Nokia
2008-07-05 11:48 --------- d-----w C:\Program Files\DIFX
2008-07-05 11:48 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-07-05 11:48 --------- d-----w C:\Program Files\Common Files\Nokia
2008-07-05 11:48 --------- d-----w C:\Documents and Settings\Administrator\Application Data\PC Suite
2008-07-05 11:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-07-05 11:44 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-07-05 11:35 --------- d-----w C:\Program Files\Kaspersky Lab
2008-07-05 11:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-05 11:14 --------- d-----w C:\Program Files\Driver-Soft
2008-07-05 09:41 --------- d-----w C:\Program Files\microsoft frontpage
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
.
------- Sigcheck -------
04/21/2008 09:24 AM 666624 26f240c250e5b4b395cb4b178ba75437 C:\WINDOWS\$hf_mig$\KB950759\SP3QFE\wininet.dll
04/23/2008 06:35 AM 827392 41546b396a526918da7995a02ea04e51 C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
01/26/2008 06:57 AM 666112 5390fbe8b096ef3fdfe1c06455a0d66d C:\WINDOWS\$NtUninstallKB950759$\wininet.dll
04/23/2008 07:16 AM 826368 f6589be784647cfdbc22ea51ccb1a57a C:\WINDOWS\Fedora Transformation Pack\Backup\wininet.dll
04/21/2008 09:44 AM 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\ie7\wininet.dll
08/13/2007 06:54 PM 818688 a4a0fc92358f39538a6494c42ef99fe9 C:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll
04/23/2008 07:16 AM 826368 f6589be784647cfdbc22ea51ccb1a57a C:\WINDOWS\SoftwareDistribution\Download\b3bf74f55136e7636e609c29522f7318\SP2GDR\wininet.dll
04/23/2008 06:35 AM 827392 41546b396a526918da7995a02ea04e51 C:\WINDOWS\SoftwareDistribution\Download\b3bf74f55136e7636e609c29522f7318\SP2QFE\wininet.dll
04/23/2008 07:16 AM 833536 978d59dbdba7ec3141aa8d4273af47b1 C:\WINDOWS\system32\wininet.dll
04/23/2008 07:16 AM 833536 978d59dbdba7ec3141aa8d4273af47b1 C:\WINDOWS\system32\dllcache\wininet.dll
01/25/2008 11:21 PM 2065792 61045b444f5d94091d340fff2abe948e C:\WINDOWS\Fedora Transformation Pack\Backup\ntkrnlpa.exe
01/25/2008 11:21 PM 2221824 c6f69483f3d61be2e793834c57535996 C:\WINDOWS\system32\ntkrnlpa.exe
01/25/2008 11:21 PM 2221824 c6f69483f3d61be2e793834c57535996 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
01/26/2008 07:05 AM 2065792 61045b444f5d94091d340fff2abe948e C:\WINDOWS\system32\ReinstallBackups\0057\DriverFiles\i386\ntkrnlpa.exe
01/26/2008 12:18 AM 2188928 2a138674e8cfe24373a638ef75a8d076 C:\WINDOWS\Fedora Transformation Pack\Backup\ntoskrnl.exe
01/26/2008 12:18 AM 2344960 948fcd4b512cc8238050b7751e8246a3 C:\WINDOWS\system32\ntoskrnl.exe
01/26/2008 12:18 AM 2344960 948fcd4b512cc8238050b7751e8246a3 C:\WINDOWS\system32\dllcache\ntoskrnl.exe
01/26/2008 12:18 AM 2188928 2a138674e8cfe24373a638ef75a8d076 C:\WINDOWS\system32\ReinstallBackups\0057\DriverFiles\i386\ntoskrnl.exe
01/26/2008 06:57 AM 1385984 58f982c9a2fb3215f40c28485c9338f4 C:\WINDOWS\explorer.exe
01/26/2008 06:57 AM 1033728 d4801bb68068c2979144d3defceb4f6d C:\WINDOWS\Fedora Transformation Pack\Backup\explorer.exe
01/26/2008 06:57 AM 1385984 58f982c9a2fb3215f40c28485c9338f4 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [01/26/2008 06:57 AM 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [11/29/2007 07:25 PM 5724184]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [07/15/2008 08:39 AM 931248]
"uTorrent"="C:\Program Files\utorrent\utorrent.exe" [07/29/2008 03:10 PM 219952]
"Memory Improve Professional"="C:\Program Files\Memory Improve Professional\MemoryImproveProfessional.exe" [07/28/2008 11:00 AM 5398016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaDrive"="C:\WINDOWS\VistaDrive\VistaDrive.exe" [10/05/2006 08:56 PM 280779]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [10/08/2004 03:31 AM 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [10/08/2004 03:27 AM 126976]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [01/26/2008 06:57 AM 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [06/19/2007 10:17 AM 1241088]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-07-14 19:57:52 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
07/23/2006 02:49 AM 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"SMSERIAL"=sm56hlpr.exe
"SoundMan"=SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Avant Browser\\avant.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"C:\\Program Files\\utorrent\\utorrent.exe"=
"C:\\Program Files\\BearShare\\BearShare.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*
isabled
xpsp2res.dll,-22009
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [01/26/2008 06:57 AM]
S2 BulkUsb;Plustek USB Scanner;C:\WINDOWS\system32\DRIVERS\usbscan.sys [01/25/2008 11:33 PM]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/04/2007 02:58 PM]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [07/07/2008 05:11 PM]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
s of the 'Scheduled Tasks' folder
2008-08-08 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe [12/21/2007 03:17 PM]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
المشكلة الاولى :قمت باستخدام هذه الاداة
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
وعملت تنظيف بواسطتها وما ان انتهيت الا واختفت ايقونات بعض البرامج في الجهاز
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
اما ملفات برامج الاوفس فعند محاولة فتحها تظهر هذه الرسالة
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
ـــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــ
ــــــــــــــــــــــــــــــــــــــــــــــــ
المشكلة الثانية : أواجه ثقل في جهازي وفي تصفح بعض المواقع خاصة منتدى زيزوووم.. شوفوا التقارير يمكن الجهاز مخترق..:er:
ـــــــــــــــــــــــــــــــــ
ـــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــ
سؤال أخير : سمعت ان هناك طريقة لصيانة الويندوز عن طريق سيدي الويندوز لكن لا أعلم ماهي الطريقة ياليت لو تدلوني على الطريقة...
ـــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــ
وهذه هي التقارير
الاول بـ combofix
ComboFix 08-08-10.01 - Administrator 08/10/2008 22:38:55.1 - NTFSx86
Running from: C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\.#
C:\Documents and Settings\Administrator\Application Data\.#\MBX@1EC@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@1EC@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@1EC@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@214@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@214@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@214@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@260@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@260@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@260@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@268@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@268@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@268@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@270@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@270@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@270@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@274@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@274@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@274@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@278@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@278@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@278@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@27C@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@27C@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@27C@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@284@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@284@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@284@9B3320.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@B84@9B3300.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@B84@9B3310.###
C:\Documents and Settings\Administrator\Application Data\.#\MBX@B84@9B3320.###
.
((((((((((((((((((((((((( Files Created from 2008-07-10 to 2008-08-10 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-10 19:47 14,990,112 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-10 19:46 560,160 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-08-10 19:46 --------- d-----w C:\Documents and Settings\Administrator\Application Data\utorrent
2008-08-10 19:46 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DMCache
2008-08-10 19:45 56,600 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-08-10 19:45 210,992 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-10 18:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-10 15:37 --------- d-----w C:\Program Files\Multilizer 6
2008-08-09 21:06 --------- d-----w C:\Program Files\Stepok's Gigital Beauty
2008-08-08 21:30 --------- d-----w C:\Documents and Settings\Administrator\Application Data\TechSmith
2008-08-07 22:01 --------- d-----w C:\Program Files\TechSmith
2008-08-07 22:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\TechSmith
2008-08-07 21:57 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-06 20:18 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-08-02 12:58 --------- d-----w C:\Program Files\Memory Improve Professional
2008-08-02 12:46 --------- d-----w C:\Program Files\BearShare
2008-08-01 13:55 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Thinstall
2008-07-30 21:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-30 21:52 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-30 21:46 --------- d-----w C:\Program Files\GVR
2008-07-30 12:58 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia Multimedia Player
2008-07-30 12:57 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia
2008-07-29 23:47 --------- d-----w C:\Program Files\Internet Download Manager
2008-07-29 12:12 --------- d-----w C:\Program Files\utorrent
2008-07-29 10:56 --------- d-----w C:\Program Files\Laser Dolphin
2008-07-28 09:52 --------- d-----w C:\Documents and Settings\Administrator\Application Data\IDM
2008-07-24 09:42 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-07-19 19:25 --------- d-----w C:\Program Files\Virtual Earth 3D
2008-07-19 18:31 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-07-15 08:14 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-12 00:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-07-09 15:51 --------- d-----w C:\Program Files\Rainy Screensaver
2008-07-09 15:51 --------- d-----w C:\Program Files\ma-config.com
2008-07-09 15:36 --------- d-----w C:\Program Files\STOIK
2008-07-09 13:24 --------- d-----w C:\Program Files\Ashkon Software
2008-07-08 14:30 --------- d-----w C:\Program Files\Two Pilots
2008-07-08 14:30 --------- d-----w C:\Program Files\MakeUp Pilot
2008-07-08 14:30 --------- d-----w C:\Documents and Settings\Administrator\Application Data\MakeUpPilot
2008-07-07 19:29 --------- d-----w C:\Program Files\ScannerU
2008-07-07 14:29 --------- d-----w C:\Program Files\CCleaner
2008-07-07 14:11 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-07-07 14:11 --------- d-----w C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2008-07-07 14:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-07-07 07:54 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Ahead
2008-07-07 07:17 --------- d-----w C:\Program Files\Common Files\Ahead
2008-07-07 07:14 --------- d-----w C:\Program Files\Nero
2008-07-06 22:54 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-06 13:01 --------- d-----w C:\Program Files\All-in-1 Mobile Video Convert
2008-07-06 12:44 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-07-05 21:48 --------- d-----w C:\Program Files\XPC Tools
2008-07-05 21:33 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ma-config.com
2008-07-05 19:39 --------- d-----w C:\Program Files\Avant Browser
2008-07-05 19:39 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Avant Profiles
2008-07-05 17:13 --------- d-----w C:\Program Files\Windows Live
2008-07-05 12:47 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-07-05 12:31 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-07-05 11:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-07-05 11:48 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-07-05 11:48 --------- d-----w C:\Program Files\Nokia
2008-07-05 11:48 --------- d-----w C:\Program Files\DIFX
2008-07-05 11:48 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-07-05 11:48 --------- d-----w C:\Program Files\Common Files\Nokia
2008-07-05 11:48 --------- d-----w C:\Documents and Settings\Administrator\Application Data\PC Suite
2008-07-05 11:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-07-05 11:44 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-07-05 11:35 --------- d-----w C:\Program Files\Kaspersky Lab
2008-07-05 11:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-05 11:14 --------- d-----w C:\Program Files\Driver-Soft
2008-07-05 09:41 --------- d-----w C:\Program Files\microsoft frontpage
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
.
------- Sigcheck -------
04/21/2008 09:24 AM 666624 26f240c250e5b4b395cb4b178ba75437 C:\WINDOWS\$hf_mig$\KB950759\SP3QFE\wininet.dll
04/23/2008 06:35 AM 827392 41546b396a526918da7995a02ea04e51 C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
01/26/2008 06:57 AM 666112 5390fbe8b096ef3fdfe1c06455a0d66d C:\WINDOWS\$NtUninstallKB950759$\wininet.dll
04/23/2008 07:16 AM 826368 f6589be784647cfdbc22ea51ccb1a57a C:\WINDOWS\Fedora Transformation Pack\Backup\wininet.dll
04/21/2008 09:44 AM 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\ie7\wininet.dll
08/13/2007 06:54 PM 818688 a4a0fc92358f39538a6494c42ef99fe9 C:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll
04/23/2008 07:16 AM 826368 f6589be784647cfdbc22ea51ccb1a57a C:\WINDOWS\SoftwareDistribution\Download\b3bf74f55136e7636e609c29522f7318\SP2GDR\wininet.dll
04/23/2008 06:35 AM 827392 41546b396a526918da7995a02ea04e51 C:\WINDOWS\SoftwareDistribution\Download\b3bf74f55136e7636e609c29522f7318\SP2QFE\wininet.dll
04/23/2008 07:16 AM 833536 978d59dbdba7ec3141aa8d4273af47b1 C:\WINDOWS\system32\wininet.dll
04/23/2008 07:16 AM 833536 978d59dbdba7ec3141aa8d4273af47b1 C:\WINDOWS\system32\dllcache\wininet.dll
01/25/2008 11:21 PM 2065792 61045b444f5d94091d340fff2abe948e C:\WINDOWS\Fedora Transformation Pack\Backup\ntkrnlpa.exe
01/25/2008 11:21 PM 2221824 c6f69483f3d61be2e793834c57535996 C:\WINDOWS\system32\ntkrnlpa.exe
01/25/2008 11:21 PM 2221824 c6f69483f3d61be2e793834c57535996 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
01/26/2008 07:05 AM 2065792 61045b444f5d94091d340fff2abe948e C:\WINDOWS\system32\ReinstallBackups\0057\DriverFiles\i386\ntkrnlpa.exe
01/26/2008 12:18 AM 2188928 2a138674e8cfe24373a638ef75a8d076 C:\WINDOWS\Fedora Transformation Pack\Backup\ntoskrnl.exe
01/26/2008 12:18 AM 2344960 948fcd4b512cc8238050b7751e8246a3 C:\WINDOWS\system32\ntoskrnl.exe
01/26/2008 12:18 AM 2344960 948fcd4b512cc8238050b7751e8246a3 C:\WINDOWS\system32\dllcache\ntoskrnl.exe
01/26/2008 12:18 AM 2188928 2a138674e8cfe24373a638ef75a8d076 C:\WINDOWS\system32\ReinstallBackups\0057\DriverFiles\i386\ntoskrnl.exe
01/26/2008 06:57 AM 1385984 58f982c9a2fb3215f40c28485c9338f4 C:\WINDOWS\explorer.exe
01/26/2008 06:57 AM 1033728 d4801bb68068c2979144d3defceb4f6d C:\WINDOWS\Fedora Transformation Pack\Backup\explorer.exe
01/26/2008 06:57 AM 1385984 58f982c9a2fb3215f40c28485c9338f4 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [01/26/2008 06:57 AM 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [11/29/2007 07:25 PM 5724184]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [07/15/2008 08:39 AM 931248]
"uTorrent"="C:\Program Files\utorrent\utorrent.exe" [07/29/2008 03:10 PM 219952]
"Memory Improve Professional"="C:\Program Files\Memory Improve Professional\MemoryImproveProfessional.exe" [07/28/2008 11:00 AM 5398016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaDrive"="C:\WINDOWS\VistaDrive\VistaDrive.exe" [10/05/2006 08:56 PM 280779]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [10/08/2004 03:31 AM 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [10/08/2004 03:27 AM 126976]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [01/26/2008 06:57 AM 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [06/19/2007 10:17 AM 1241088]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-07-14 19:57:52 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
07/23/2006 02:49 AM 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"SMSERIAL"=sm56hlpr.exe
"SoundMan"=SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Avant Browser\\avant.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"C:\\Program Files\\utorrent\\utorrent.exe"=
"C:\\Program Files\\BearShare\\BearShare.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [01/26/2008 06:57 AM]
S2 BulkUsb;Plustek USB Scanner;C:\WINDOWS\system32\DRIVERS\usbscan.sys [01/25/2008 11:33 PM]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/04/2007 02:58 PM]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [07/07/2008 05:11 PM]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
s of the 'Scheduled Tasks' folder
2008-08-08 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe [12/21/2007 03:17 PM]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.sa/
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 -: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 -: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
C:\WINDOWS\Downloaded Program Files\SysReqLab3.osd
C:\WINDOWS\Downloaded Program Files\sysreqlab3.dll
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.sa/
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 -: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 -: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
C:\WINDOWS\Downloaded Program Files\SysReqLab3.osd
C:\WINDOWS\Downloaded Program Files\sysreqlab3.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-10 22:46:57
Windows 5.1.2600 Service Pack 3, v.3300 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 08/10/2008 22:52:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-10 19:52:07
Pre-Run: 22,893,142,016 bytes free
Post-Run: 22,892,064,768 bytes free
224 --- E O F --- 2008-07-09 17:22:29
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
Rootkit scan 2008-08-10 22:46:57
Windows 5.1.2600 Service Pack 3, v.3300 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 08/10/2008 22:52:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-10 19:52:07
Pre-Run: 22,893,142,016 bytes free
Post-Run: 22,892,064,768 bytes free
224 --- E O F --- 2008-07-09 17:22:29
ـــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــ
والثاني : بـالهايجاك
والثاني : بـالهايجاك
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:54:49 م, on 10/08/2008
Platform: Windows XP SP3, v.3300 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\VistaDrive\VistaDrive.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\Zyzoom_HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll
O2 - BHO: مساعد رابط Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: WebBlock Class - {C6B08E8D-3F9A-4710-9F38-E4BF827C6AC2} - C:\Program Files\Ashkon Software\Website Block\webblock.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\utorrent\utorrent.exe"
O4 - HKCU\..\Run: [Memory Improve Professional] C:\Program Files\Memory Improve Professional\MemoryImproveProfessional.exe /autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 5208 bytes
Scan saved at 10:54:49 م, on 10/08/2008
Platform: Windows XP SP3, v.3300 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\VistaDrive\VistaDrive.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\Zyzoom_HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll
O2 - BHO: مساعد رابط Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: WebBlock Class - {C6B08E8D-3F9A-4710-9F38-E4BF827C6AC2} - C:\Program Files\Ashkon Software\Website Block\webblock.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\utorrent\utorrent.exe"
O4 - HKCU\..\Run: [Memory Improve Professional] C:\Program Files\Memory Improve Professional\MemoryImproveProfessional.exe /autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 5208 bytes
