مكافح تسلم اخوي ولك من التحيه والشكر وجزاك الله الف خير على تواصلك .
تسلم اخوي
Demo-dash واطال الله في عمرك احتلت المشكله وجزاك الله الف خير
وهذا التقرير الي طلبته مع خالص تحياتي
ComboFix 08-11-03.06 - ali 11/04/2008 20:47:53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.649 [GMT 4:00]
Running from: c:\documents and settings\ali\Desktop\ملف لحل مشكلة عدم اظهار الملفات\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\program files\GamesBar\oberontb.dll
c:\windows\msettings.ini
E:\WinRAR.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-04 to 2008-11-04 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-04 16:48 --------- d-----w c:\program files\GamesBar
2008-11-04 12:29 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-03 17:34 458,784 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-03 17:34 4,175,392 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-03 17:34 34,748 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-03 17:34 3,696 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-02 12:20 --------- d-----w c:\program files\Common Files\Adobe
2008-11-01 12:36 --------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
2008-10-21 00:39 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-21 00:39 --------- d-----w c:\program files\Realtek
2008-10-21 00:38 319,488 ----a-w c:\windows\HideWin.exe
2008-10-21 00:38 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-19 21:10 --------- d-----w c:\documents and settings\ali\Application Data\cleaner
2008-10-19 20:59 --------- d-----w c:\documents and settings\ali\Application Data\CyberScrub
2008-10-18 11:59 --------- d-----w c:\program files\B4Playing
2008-10-17 06:06 96,976 ----a-w c:\windows\system32\drivers\klin.dat
2008-10-17 06:06 87,855 ----a-w c:\windows\system32\drivers\klick.dat
2008-10-16 18:04 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-10-16 18:04 --------- d-----w c:\program files\Common Files\xing shared
2008-10-16 18:04 --------- d-----w c:\program files\Common Files\Real
2008-10-16 17:57 --------- d-----w c:\documents and settings\ali\Application Data\Talkback
2008-10-14 17:42 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-10-14 17:20 --------- d-----w c:\program files\Yahoo!
2008-10-14 17:20 --------- d-----w c:\program files\CCleaner
2008-10-14 16:59 --------- d-----w c:\program files\BandRich
2008-10-14 10:18 --------- d-----w c:\documents and settings\All Users\Application Data\zyz Kaspersky Lab setup files
2008-10-14 10:14 --------- d-----w c:\program files\Kaspersky Lab
2008-10-12 12:28 --------- d-----w c:\program files\Internet Download Manager
2008-10-12 12:25 --------- d-----w c:\documents and settings\ali\Application Data\IDM
2008-10-12 12:14 --------- d-----w c:\documents and settings\ali\Application Data\DMCache
2008-09-26 10:45 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-09-18 14:48 4,816,896 ----a-w c:\windows\system32\drivers\RtkHDAud.sys
2008-09-18 14:02 16,855,040 ----a-w c:\windows\RTHDCPL.EXE
2008-09-18 11:17 2,166,272 ----a-w c:\windows\MicCal.exe
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\win32k.sys
2008-08-26 07:24 826,368 ----a-w c:\windows\system32\wininet.dll
2008-08-19 09:26 77,824 ----a-w c:\windows\SOUNDMAN.EXE
2008-08-14 10:00 2,180,352 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:22 2,057,728 ----a-w c:\windows\system32\ntkrnlpa.exe
2008-08-06 11:51 1,200,128 ----a-w c:\windows\RtlUpd.exe
2007-07-13 09:44 51,280 ----a-w c:\documents and settings\ali\Application Data\GDIPFONTCACHEV1.DAT
2007-06-02 11:53 8 --sh--r c:\windows\system32\608F4CDD6F.sys
2007-06-02 11:53 4,704 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/04/2004 04:56 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [10/16/2008 10:03 PM 185896]
"RTHDCPL"="RTHDCPL.EXE" [09/18/2008 06:02 PM 16855040 c:\windows\RTHDCPL.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"msacm.vivog723"= vivog723.acm
"VIDC.VIVO"= ivvideo.dll
"VIDC.TR20"= tr2032.dll
"msacm.l3codec"= L3codecp.acm
[HKLM\~\startupfolder\C:^Documents and Settings^ali^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\ali\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SnagIt 8.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SnagIt 8.lnk
backup=c:\windows\pss\SnagIt 8.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 06/06/2005 11:46 PM 57344 c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 08/04/2004 04:56 AM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 10/27/2006 12:47 AM 31016 e:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
--a------ 10/23/2007 02:57 PM 190024 c:\program files\MessengerPlus! 3\MsgPlus.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnappau]
--a------ 08/13/2004 05:41 PM 86016 c:\program files\MSN Apps\Updater\
01.02.3000.1001\ar-xa\msnappau.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 01/19/2007 12:55 PM 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 06/15/2006 12:36 PM 229376 c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
--a------ 06/27/2006 04:21 PM 1449984 c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 08/11/2007 01:45 PM 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 10/16/2008 10:03 PM 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 07/05/2006 08:29 AM 4538368 d:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 09/18/2008 06:02 PM 16855040 c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\Program Files\\Microsoft Office\\Office12\\groove.exe"=
"e:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Squeak\\Plugin\\Squeak.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [03/25/2008 08:07 PM 24592]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\DRIVERS\br3gmdm.sys [04/03/2008 10:30 AM 100096]
S3 CAM1210;SM0121 USB 2.0 Video Camera;c:\windows\system32\Drivers\cam1210.sys [07/24/2006 05:49 PM 89856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1276fd03-946d-11dc-8ff7-0016763572d9}]
\Shell\AutoRun\command - fooool.exe
\Shell\explore\Command - fooool.exe
\Shell\open\Command - fooool.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1fd0d979-21a4-11dc-8f2a-0016763572d9}]
\Shell\Auto\command - sal.xls.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sal.xls.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4509ce58-9a11-11dd-9161-0016763572d9}]
\Shell\AutoRun\command - G:\AUTORUN.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6e762852-2d72-11dc-8f40-0016763572d9}]
\Shell\AutoRun\command - G:\un9.cmd
\Shell\explore\Command - G:\un9.cmd
\Shell\open\Command - G:\un9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7057e524-a688-11dc-9025-b8941bfb537f}]
\Shell\AutoRun\command - sysinfo.exe
\Shell\explore\command - sysinfo.exe
\Shell\open\command - sysinfo.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a7749a5b-d63a-11dc-908b-0016763572d9}]
\Shell\AutoRun\command - G:\ntde1ect.com
\Shell\explore\Command - G:\ntde1ect.com
\Shell\open\Command - G:\ntde1ect.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b3e3117c-8d32-11dc-8fe7-0016763572d9}]
\Shell\Auto\command - G:\sal.xls.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sal.xls.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1b0ed82-dbc5-11dc-909c-0016763572d9}]
\Shell\AutoRun\command - fooool.exe
\Shell\explore\Command - fooool.exe
\Shell\open\Command - fooool.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e76e72a8-7bcb-11dc-8fae-0016763572d9}]
\Shell\Auto\command - sal.xls.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sal.xls.exe
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-10-27 c:\windows\Tasks\At1.job
- c:\windows\system32\blastclnnn.exe []
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
Notify-AtiExtEvent - (no file)
MSConfigStartUp-amva - c:\windows\system32\amvo.exe
MSConfigStartUp-AVG7_CC - c:\progra~1\Grisoft\AVG7\avgcc.exe
MSConfigStartUp-AVP - d:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
MSConfigStartUp-avpa - c:\windows\system32\avpo.exe
MSConfigStartUp-egui - c:\program files\ESET\ESET NOD32 Antivirus\egui.exe
MSConfigStartUp-NBN - c:\docume~1\ali\Desktop\NBN-dm.exe
MSConfigStartUp-nod32kui - c:\program files\Eset\nod32kui.exe
MSConfigStartUp-QDict - c:\program files\QDict\QDict.exe
MSConfigStartUp-QuickTime Task - E:\qttask.exe
MSConfigStartUp-IMJPMIG8 - msime80.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\ali\Application Data\Mozilla\Firefox\Profiles\y9i4nala.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-04 20:50:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 11/04/2008 20:53:59
ComboFix-quarantined-files.txt 2008-11-04 16:53:39
Pre-Run: 7,465,607,168 bytes free
Post-Run: 9,036,533,760 bytes free
219 --- E O F --- 2008-10-28 15:59:24