شكرا اخي هشام
تفضل اخي تقرير ComboFix مع العلم لم يعمل ريستارت اعطاني التقرير بدون ريستارت
ComboFix 08-09-05.12 - al3alawy 2008-10-01 20:35:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.965.1033.18.549 [GMT 3:00]
Running from: D:\ملف خاص لادوات التصليح\ادوات التقارير\اداة ComboFix\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((( Files Created from 2008-09-01 to 2008-10-01 )))))))))))))))))))))))))))))))
.
2008-10-01 20:21 . 2008-10-01 20:21 268 --ah----- C:\sqmdata02.sqm
2008-10-01 20:21 . 2008-10-01 20:21 244 --ah----- C:\sqmnoopt02.sqm
2008-10-01 20:16 . 2008-10-01 20:16 268 --ah----- C:\sqmdata01.sqm
2008-10-01 20:16 . 2008-10-01 20:16 244 --ah----- C:\sqmnoopt01.sqm
2008-10-01 20:10 . 2008-10-01 20:10 268 --ah----- C:\sqmdata00.sqm
2008-10-01 20:10 . 2008-10-01 20:10 244 --ah----- C:\sqmnoopt00.sqm
2008-10-01 20:04 . 2008-10-01 20:04 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-10-01 20:04 . 2008-10-01 20:04 <DIR> d-------- C:\WINDOWS\system32\bits
2008-10-01 20:04 . 2008-10-01 20:04 <DIR> d-------- C:\WINDOWS\l2schemas
2008-10-01 20:02 . 2008-10-01 20:05 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-10-01 19:58 . 2007-08-10 20:46 26,488 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-10-01 14:34 . 2008-04-14 03:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-10-01 11:43 . 2008-10-01 11:44 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-10-01 11:43 . 2008-10-01 11:43 <DIR> d-------- C:\Program Files\Windows Live Favorites
2008-10-01 11:37 . 2008-10-01 11:37 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-10-01 11:17 . 2008-10-01 11:17 <DIR> d---s---- C:\Documents and Settings\al3alawy\UserData
2008-10-01 11:04 . 2008-10-01 11:37 <DIR> d-------- C:\Program Files\Windows Live
2008-10-01 11:04 . 2008-10-01 11:36 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-10-01 11:02 . 2008-10-01 11:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-01 17:36 --------- d-----w C:\Documents and Settings\al3alawy\Application Data\DMCache
2008-10-01 17:10 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-01 17:10 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-01 17:10 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-01 17:10 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-01 07:53 --------- d-----w C:\Documents and Settings\al3alawy\Application Data\IDM
2008-10-01 07:29 96,645 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-10-01 07:29 87,941 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-10-01 07:28 --------- d-----w C:\Program Files\Kaspersky Lab
2008-10-01 07:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-10-01 07:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-01 07:26 --------- d-----w C:\Program Files\SuperAudiotool
2008-10-01 07:25 --------- d-----w C:\Program Files\Internet Download Manager
2008-10-01 07:23 --------- d-----w C:\Program Files\PhotoFiltre
2008-10-01 07:22 --------- d-----w C:\Program Files\Streambox
2008-10-01 04:41 --------- d-----w C:\Program Files\microsoft frontpage
2008-10-01 04:37 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-07-18 19:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 19:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 19:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 19:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 19:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 19:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 19:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 19:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2007-12-20 2651568]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\برامج الحماية\\الكاسبر\\2009\\kav8.0.0.357en.exe"=
"C:\\WINDOWS\\Explorer.EXE"=
"C:\\WINDOWS\\system32\\cleanmgr.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"D:\\ملف خاص لادوات التصليح\\ادوات التقارير\\اداة ComboFix\\ComboFix.exe"=
"D:\\ملف خاص لادوات التصليح\\ادوات التقارير\\اداة مهمه لفحص الجهاز واعطاء التقارير\\ComboFix.exe"=
"C:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"C:\\DOCUME~1\\al3alawy\\LOCALS~1\\Temp\\winfdvcv.exe"=
"C:\\DOCUME~1\\al3alawy\\LOCALS~1\\Temp\\qhlf.exe"=
"C:\\DOCUME~1\\al3alawy\\LOCALS~1\\Temp\\qujnc.exe"=
"D:\\E?C?? C???C?E\\C??C?E?\\2009\\kav8.0.0.357en.exe"=
"D:\\??? IC? ?CI?CE C?E????\\CI?CE C?E?C???\\CICE ComboFix\\ComboFix.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R3 asc3360pr;asc3360pr;C:\WINDOWS\system32\drivers\jrrhqn.sys [ ]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 24592]
*Newly Created Service* - KL1
*Newly Created Service* - KLBG
.
s of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-AVP - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
.
------- Supplementary Scan -------
.
O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 -: Add to Windows &Live Favorites -
O8 -: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 -: Download FLV video with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 -: Download FLV videos with IDM from 10 last requested - C:\Program Files\Internet Download Manager\IEGetVL2.htm
O8 -: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-01 20:36:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-01 20:37:44
ComboFix-quarantined-files.txt 2008-10-01 17:37:39
Pre-Run: 20,451,282,944 bytes free
Post-Run: 20,447,170,560 bytes free
129
----------------------------------------------------------------------
وهذا تقرير الهايجاك
Logfile of HijackThis v1.99.1
Scan saved at 8:23:18 PM, on 10/1/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
D:\ملف خاص لادوات التصليح\ادوات التقارير\اداة فحص للجهاز واعطاء تقرير\HijackThis.exe
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download FLV videos with IDM from 10 last requested - C:\Program Files\Internet Download Manager\IEGetVL2.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{1AEB0497-C07A-4EF4-B5F9-849B5EC2C458}: NameServer = 217.69.178.34 217.69.179.34
O17 - HKLM\System\CS1\Services\Tcpip\..\{1AEB0497-C07A-4EF4-B5F9-849B5EC2C458}: NameServer = 217.69.178.34 217.69.179.34
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
وكل الشكر