هلا بك اخوي فتى الاحزان
تدري من العجله نسيت اوقف الحمايه هههههههه وكل شوي يقول ملف مشبوه وانا موافق اسمح له الين اشتغل وطفى الجهاز من جديد وطلعت لي بمستند لوق بالاشياء الي فحصها ورحت للصفحه ولقيتك كاتب هالشي توقف الحمايه المهم مالك بالطويله طفيت الجهاز واعدت تشغيله ووقفت الحمايه وضغطت على البرنامج الي جبته وطلع لي الكلام ذا شوف:
ComboFix 08-09-25.07 - xp 09/26/2008 22:37:22.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.618 [GMT 3:00]
Running from: C:\Documents and Settings\xp\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-08-26 to 2008-09-26 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-26 19:38 --------- d-----w C:\Documents and Settings\xp\Application Data\DMCache
2008-09-26 19:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-26 19:31 319,520 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-26 19:31 3,220 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-26 19:31 14,000 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-26 19:31 1,519,648 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-19 22:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-09-19 22:21 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-19 22:14 --------- d-----w C:\Program Files\Windows Live
2008-09-17 22:55 --------- d-----w C:\Program Files\CodeLifter5
2008-09-14 21:46 --------- d-----w C:\Program Files\VirusTotalUploader
2008-09-08 00:29 --------- d-----w C:\Documents and Settings\xp\Application Data\IDM
2008-09-03 13:17 --------- d-----w C:\Documents and Settings\xp\Application Data\Media Player Classic
2008-09-03 12:49 --------- d-----w C:\Program Files\WinWatermark 2.2
2008-09-03 12:47 --------- d-----w C:\Program Files\TagRename
2008-09-03 12:19 155,995 ----a-w C:\WINDOWS\java\Packages\DJXV9RZZ.ZIP
2008-09-03 12:16 --------- d-----w C:\Program Files\Internet Download Manager
2008-09-03 12:10 --------- d-----w C:\Program Files\Wave Splitter
2008-09-03 12:07 --------- d-----w C:\Program Files\Acoustica MP3 Audio Mixer
2008-09-03 12:05 --------- d-----w C:\Program Files\SWiSHmax
2008-09-03 02:08 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-09-03 02:08 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-09-03 01:33 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-09-03 01:22 98,304 ----a-w C:\WINDOWS\system32\viscomtran.dll
2008-09-03 01:21 --------- d-----w C:\Program Files\Ozone
2008-09-03 01:19 --------- d-----w C:\Program Files\Real
2008-09-03 01:19 --------- d-----w C:\Program Files\Common Files\xing shared
2008-09-03 01:19 --------- d-----w C:\Program Files\Common Files\Real
2008-09-03 01:17 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-03 01:06 --------- d-----w C:\Program Files\Kaspersky Lab
2008-09-03 01:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-02 23:53 --------- d-----w C:\Program Files\Microsoft Works
2008-09-02 23:53 --------- d-----w C:\Program Files\Common Files\L&H
2008-09-02 23:47 --------- d-----w C:\Program Files\Microsoft.NET
2008-09-02 23:47 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-09-02 23:34 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-09-02 23:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-02 23:34 --------- d-----w C:\Program Files\Realtek
2008-09-02 23:32 --------- d-----w C:\Program Files\S3
2008-09-02 23:32 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-02 23:29 --------- d-----w C:\Program Files\VIA
2008-09-02 23:19 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-18 19:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 19:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 19:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 19:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 19:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 19:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 19:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 19:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-09 14:34 206,256 ----a-w C:\WINDOWS\system32\idmmbc.dll
2008-07-07 20:27 253,952 ----a-w C:\WINDOWS\system32\es.dll
.
(((((((((((((((((((((((((((((
snapshot@Fri 09-26-2008_22.29.48.98 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-26 16:58:29 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\s\index.dat
+ 2008-09-26 19:32:56 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\s\index.dat
- 2008-09-26 16:58:29 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-26 19:32:56 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-26 16:58:29 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\.IE5\index.dat
+ 2008-09-26 19:32:56 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\.IE5\index.dat
- 2008-09-26 18:44:46 40,118 ----a-w C:\WINDOWS\system32\perfc001.dat
+ 2008-09-26 19:37:07 40,118 ----a-w C:\WINDOWS\system32\perfc001.dat
- 2008-09-26 18:44:46 40,128 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-09-26 19:37:07 40,128 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-09-26 18:44:46 251,674 ----a-w C:\WINDOWS\system32\perfh001.dat
+ 2008-09-26 19:37:07 251,674 ----a-w C:\WINDOWS\system32\perfh001.dat
- 2008-09-26 18:44:46 311,740 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-09-26 19:37:07 311,740 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [08/16/2007 04:19 PM 5728112]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [09/03/2008 03:16 PM 2610608]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [04/14/2008 06:59 PM 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [09/03/2008 04:19 AM 185896]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"VTTimer"="VTTimer.exe" [09/21/2006 04:36 PM 53248 C:\WINDOWS\system32\VTTimer.exe]
"S3Trayp"="S3trayp.exe" [06/11/2007 11:15 AM 176128 C:\WINDOWS\system32\S3Trayp.exe]
"RTHDCPL"="RTHDCPL.EXE" [10/16/2007 06:30 PM 16855552 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [10/11/2007 11:04 AM 1826816 C:\WINDOWS\SkyTel.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [04/14/2008 07:00 PM 110592 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 06:59 PM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*

isabled

xpsp2res.dll,-22009
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R0 ViBus;ViBus;C:\WINDOWS\system32\DRIVERS\ViBus.sys [10/18/2007 01:28 PM 16896]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [09/21/2007 12:49 PM 9216]
R0 ViPrt;VIA SATA IDE Device Driver;C:\WINDOWS\system32\DRIVERS\ViPrt.sys [10/18/2007 01:28 PM 52224]
R1 BIOS;BIOS;C:\WINDOWS\system32\drivers\BIOS.sys [03/16/2005 09:23 AM 13696]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [03/25/2008 08:07 PM 24592]
R3 S3GIGP;S3GIGP;C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [07/11/2007 01:08 PM 714240]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d789b437-795b-11dd-916c-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\xp\Application Data\Mozilla\Firefox\Profiles\pzr40fyy.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-26 22:38:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 09/26/2008 22:39:48
ComboFix-quarantined-files.txt 2008-09-26 19:39:29
ComboFix2.txt 2008-09-26 19:30:15
Pre-Run: 75,765,723,136 bytes free
Post-Run: 75,754,135,552 bytes free
148 --- E O F --- 2008-09-18 14:59:36