العزيز kong اشكرك على استجابتك التي تدل على نبل اخلاقك فلا حمك الله الاجر
بانسبة للخطوة الاولى فقد قمت بانزال برنامج ComboFixونفذت مثل ما طلبت واظهر لي مرة واحده فقط رسالة اختر فيها نعم فقط ثم بعدها ظهر لي التقرير التالي مع العلم انه لم يتم اعادة تشغيل الجهازي بشكل تلقائي بل اناالذي اعدت تشغيلة
وهذا هو التقرير
ComboFix 08-08-30.01 - Administrator 08/31/2008 1:41:30.3 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.255 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\سطح المكتب\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-30 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-30 00:12 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-29 05:33 --------- d-----w C:\Program Files\Freecorder Toolbar
2008-08-29 05:33 --------- d-----w C:\Program Files\Freecorder
2008-08-29 05:33 --------- d-----w C:\Program Files\Conduit
2008-08-29 05:32 2,788,800 ----a-w C:\Program Files\FLV PlayerFCSetup.exe
2008-08-29 05:30 --------- d-----w C:\Program Files\FLV Player
2008-08-29 05:06 --------- d-----w C:\Program Files\Internet Download Manager
2008-08-29 04:46 --------- d-----w C:\Documents and Settings\Administrator\Application Data\IDM
2008-08-16 21:00 --------- d-----w C:\Program Files\Common Files\Ahead
2008-08-16 21:00 --------- d-----w C:\Program Files\Ahead
2008-08-16 16:46 --------- d-----w C:\Program Files\Common Files\Scanner
2008-08-16 16:46 --------- d-----w C:\Program Files\CA
2008-08-16 16:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\CA
2008-08-16 13:10 62,976 ----a-w C:\WINDOWS\PegtopUI.exe
2008-08-16 09:34 --------- d-----w C:\Program Files\ESET
2008-08-15 08:03 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ESET
2008-08-15 04:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-08-09 02:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\GRETECH
2008-08-09 02:30 --------- d-----w C:\Documents and Settings\Administrator\Application Data\GRETECH
2008-08-09 02:29 --------- d-----w C:\Program Files\GRETECH
2008-08-09 02:27 --------- d-----w C:\Documents and Settings\Administrator\Application Data\vlc
2008-08-09 02:12 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Avant Profiles
2008-08-09 01:46 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-08-09 01:39 --------- d-----w C:\Program Files\TechSmith
2008-08-09 01:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\TechSmith
2008-08-09 01:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-09 01:36 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AntsSoft
2008-08-09 01:03 306,432 ----a-w C:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-09 01:03 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-08-09 01:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-08-09 01:03 --------- d-----w C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2008-08-09 00:55 40,960 ----a-w C:\WINDOWS\system32\SSubTmr6.dll
2008-08-09 00:55 --------- d-----w C:\Program Files\arabic2regclean
2008-08-09 00:53 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Thinstall
2008-08-09 00:47 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DMCache
2008-08-09 00:28 --------- d-----w C:\Program Files\Java
2008-08-09 00:28 --------- d-----w C:\Program Files\Common Files\Java
2008-08-08 20:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-08-08 16:34 47,104 ------w C:\WINDOWS\AKDeInstall.exe
2008-08-08 16:34 --------- d-----w C:\Program Files\mpegable
2008-08-08 16:21 --------- d-----w C:\Program Files\Nokia
2008-08-08 16:21 --------- d-----w C:\Program Files\Common Files\Nokia
2008-08-08 16:18 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-08 16:07 --------- d-----w C:\Program Files\MSN Messenger
2008-08-08 16:04 155,995 ----a-w C:\WINDOWS\java\Packages\UPNHJXFP.ZIP
2008-08-08 16:01 --------- d-----w C:\Program Files\Apoint
2008-08-08 15:33 14,037 ----a-w C:\WINDOWS\system32\drivers\mdc8021x.sys
2008-08-08 15:33 --------- d-----w C:\Program Files\Dell Computer Corporation
2008-08-08 15:33 --------- d-----w C:\Program Files\Dell
2008-08-08 15:31 --------- d-----w C:\Program Files\CONEXANT
2008-08-08 15:29 --------- d-----w C:\Program Files\SigmaTel
2008-08-08 15:28 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-08 15:28 --------- d-----w C:\Program Files\Intel
2008-08-08 15:27 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-08 15:18 --------- d-----w C:\Program Files\Microsoft.NET
2008-08-08 15:18 --------- d-----w C:\Program Files\Microsoft Works
2008-08-08 14:57 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-18 19:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 19:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 19:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 19:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 19:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 19:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 19:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 19:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-09 14:34 206,256 ----a-w C:\WINDOWS\system32\idmmbc.dll
2008-07-07 20:27 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:15 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:47 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-05-09 10:53 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
2008-05-09 10:53 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
2008-05-09 10:53 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
2008-05-09 10:53 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
2008-05-07 09:07 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
2008-05-07 05:10 1,286,144 ----a-w C:\WINDOWS\system32\quartz.dll
.
(((((((((((((((((((((((((((((
snapshot@Sun 08-31-2008_ 1.21.36.76 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-30 22:12:08 56,688 ----a-w C:\WINDOWS\system32\perfc001.dat
+ 2008-08-30 22:32:12 56,688 ----a-w C:\WINDOWS\system32\perfc001.dat
- 2008-08-30 22:12:08 56,698 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-08-30 22:32:12 56,698 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-30 22:12:08 323,534 ----a-w C:\WINDOWS\system32\perfh001.dat
+ 2008-08-30 22:32:12 323,534 ----a-w C:\WINDOWS\system32\perfh001.dat
- 2008-08-30 22:12:08 386,344 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-08-30 22:32:12 386,344 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 10:29 AM 15360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [07/29/2008 08:25 PM 2610608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [05/28/2003 05:32 PM 86016]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [01/30/2007 05:22 PM 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [01/30/2007 05:21 PM 118784]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [01/30/2007 05:21 PM 151552]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 10:50 AM 155648]
"BluetoothAuthenticationAgent"="bthprops.cpl" [04/14/2008 10:30 AM 110592 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 10:29 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
06/20/2003 07:03 AM 110592 C:\WINDOWS\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"cctray"="D:\تنزيلات النت\CA Anti-Spyware 2008\cctray\cctray.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [04/14/2008 10:30 AM]
R3 {E2B953A7-195A-44F9-9BA3-3D5F4E32BB55};AIM 3.0 Part 01 Codec Driver CH-7009-B;C:\WINDOWS\system32\drivers\wA301b.sys [01/30/2007 05:22 PM]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [11/22/2002 08:01 PM]
S3 PPCtlPriv;PPCtlPriv;D:\تنزيلات النت\CA Anti-Spyware 2008\CA Anti-Spyware\PPCtlPriv.exe [04/10/2008 10:39 AM]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [08/09/2008 04:03 AM]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
s of the 'Scheduled Tasks' folder
2008-08-17 C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Administrator at 06 54 .job
- D:\ [08/30/2008 03:12 AM]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page =
R1 -: HKCU-Internet Settings,ProxyOverride = local
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 -: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 -: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O16 -: Microsoft XML Parser for Java - C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-31 01:42:43
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 08/31/2008 1:43:14
ComboFix-quarantined-files.txt 2008-08-30 22:43:12
ComboFix2.txt 2008-08-30 22:21:58
Pre-Run: 16,647,553,024 bytes free
Post-Run: 16,639,377,408 bytes free
176 --- E O F --- 2008-08-16 12:02:09