عندك باتش برورات
عطل جميع برامج الحماية ,,
وحمل هذه الاداة واحفظها على سطح المكتب
عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
انتظر حتى الاداة تنتهي من فحص جهازك ,,, وبشكل تلقائي يعاد تشغيل جهازك ,,
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
انتظر حتى يظهر لك تقرير ,, انسخه والصقه بردك القادم
حبيب ماكس الله يعطيك العافية عملت الطريقة وفحص الجهاز بس ما اعاد تشغيل الجهاز ظهر على طول التقرير
وهذا التقرير
ComboFix 08-09-20.05 - TIBA 09/22/2008 1:11:39.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.680 [GMT 3:00]
Running from: C:\Documents and Settings\TIBA\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\amvo1.dll
D:\Autorun.inf
E:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-08-21 to 2008-09-21 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-21 19:49 540,672 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-21 19:49 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-21 19:49 288 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-21 19:49 1,580 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-21 18:49 98,533 --sh--r C:\rdsfk.com
2008-09-19 23:50 --------- d-----w C:\Program Files\LSoft Technologies
2008-09-19 23:47 --------- d-----w C:\Program Files\Avant Browser
2008-09-19 23:47 --------- d-----w C:\Documents and Settings\TIBA\Application Data\Avant Browser
2008-09-19 01:07 --------- d-----w C:\Program Files\SmartCapture
2008-09-19 01:07 --------- d-----w C:\Documents and Settings\TIBA\Application Data\DeskSoft
2008-09-19 01:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\DeskSoft
2008-09-19 00:33 --------- d-----w C:\Program Files\Kaspersky Lab
2008-09-08 21:24 --------- d-----w C:\Program Files\Alwil Software
2008-09-08 21:13 --------- d-----w C:\Program Files\Microsoft.NET
2008-09-08 21:01 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-08 21:01 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-08 20:59 --------- d-----w C:\Program Files\Nero
2008-09-08 20:59 --------- d-----w C:\Program Files\Common Files\Ahead
2008-09-08 20:58 --------- d-----w C:\Program Files\MSN Messenger
2008-09-08 20:58 --------- d-----w C:\Program Files\Common Files\xing shared
2008-09-08 20:57 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-09-08 20:57 --------- d-----w C:\Program Files\Real
2008-09-08 20:57 --------- d-----w C:\Program Files\Google
2008-09-08 20:57 --------- d-----w C:\Program Files\Common Files\Real
2008-09-08 20:57 --------- d-----w C:\Documents and Settings\TIBA\Application Data\Skype
2008-09-08 20:56 --------- d-----w C:\Program Files\VideoLAN
2008-09-08 20:56 --------- d-----w C:\Program Files\Skype
2008-09-08 20:56 --------- d-----w C:\Program Files\Paltalk Messenger
2008-09-08 20:56 --------- d-----w C:\Program Files\Common Files\Skype
2008-09-08 20:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-09-08 20:55 47,104 ------w C:\WINDOWS\AKDeInstall.exe
2008-09-08 20:55 155,995 ----a-w C:\WINDOWS\java\Packages\PN57DVF5.ZIP
2008-09-08 20:55 --------- d-----w C:\Program Files\mpegable
2008-09-08 20:55 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-09-08 20:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-08 19:58 --------- d-----w C:\Program Files\WIDCOMM
2008-09-08 19:56 --------- d-----w C:\Program Files\Dell
2008-09-08 19:48 --------- d-----w C:\Program Files\Sigmatel
2008-09-08 19:46 --------- d-----w C:\Program Files\CONEXANT
2008-09-08 19:29 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-08 18:20 93,108 --sh--r C:\jdhc2x2.com
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/03/2004 09:56 PM 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [09/08/2008 11:57 PM 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [05/16/2007 04:50 PM 137752]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [05/16/2007 04:50 PM 162328]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [05/16/2007 04:50 PM 137752]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [09/08/2008 11:57 PM 185896]
"SigmatelSysTrayApp"="stsystra.exe" [05/06/2007 05:10 PM 405504 C:\WINDOWS\stsystra.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/03/2004 09:56 PM 15360]
C:\Documents and Settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-24 622653]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
07/22/2006 11:49 PM 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll
"VIDC.VP31"= vp31vfw.dll
"msacm.l3fhg"= mp3fhg.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;C:\WINDOWS\system32\drivers\IntcHdmi.sys [12/06/2006 05:40 PM 108032]
S3 AVPsys;AVPsys;C:\WINDOWS\system32\drivers\tdi.sys [08/03/2004 08:07 PM 18560]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{47274ae8-7de8-11dd-9e1d-001e4ce8b93d}]
\Shell\AutoRun\command - G:\jdhc2x2.com
\Shell\explore\Command - G:\jdhc2x2.com
\Shell\open\Command - G:\jdhc2x2.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{641325e4-85e2-11dd-9e23-001e4ce7ee3c}]
\Shell\AutoRun\command - G:\jdhc2x2.com
\Shell\explore\Command - G:\jdhc2x2.com
\Shell\open\Command - G:\jdhc2x2.com
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: &تصدير إلى Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 -: أضف إلى قائمة الإعلان السوداء - C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 -: إبراز - C:\Program Files\Avant Browser\Highlight.htm
O8 -: إفتح كلّ الوصلات في هذه الصفحة - C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 -: إمنع كلّ الصور التي في نفس الخادم - C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 -: افتح في متصفح الرائد مكرر - C:\Program Files\Avant Browser\OpenInNewBrowser.htm
O8 -: بحث - C:\Program Files\Avant Browser\Search.htm
O16 -: Microsoft XML Parser for Java -
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-22 01:13:16
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 09/22/2008 1:13:56
ComboFix-quarantined-files.txt 2008-09-21 22:13:54
Pre-Run: 22,031,712,256 bytes free
Post-Run: 22,099,640,320 bytes free
144