من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
بسم الله الرحمن الرحيم ..
بدون مقدمـآت مآطول عليكم ..
يا شبــأإب انىآ تعقدت مع هالمشكلــة ..
وهي مشكلــة تثبيت الكـــآسبـر 2009
المشــكــلة هي .. عندما اوصل لهذهـ النقــطـة ..
اضغط على زر Next .. فيتوقــف التثبــيـــت ..
ولا يستكمل لوضع مفتآح التسجيل ..
ويطهر البرنآمج في قآئــمة البــرآمج ولكن وجودهـ كعدمــه ..
طبعا جربت الفحص بأدآة combo Fix
وهذا هو التقرير
والنتيــجة كما هي ..
الصــرآحــــــه تعقدت ومآعرفت وش اسوي
ومآسجلت الا وانا وآثـــق اني بلآقي الحل عنـدكـــــم ..
بانتظـــآر ردودكـــ/ــم ..
بدون مقدمـآت مآطول عليكم ..
يا شبــأإب انىآ تعقدت مع هالمشكلــة ..
وهي مشكلــة تثبيت الكـــآسبـر 2009
المشــكــلة هي .. عندما اوصل لهذهـ النقــطـة ..

اضغط على زر Next .. فيتوقــف التثبــيـــت ..
ولا يستكمل لوضع مفتآح التسجيل ..
ويطهر البرنآمج في قآئــمة البــرآمج ولكن وجودهـ كعدمــه ..
طبعا جربت الفحص بأدآة combo Fix
وهذا هو التقرير
جربت ادآة Zyzoom .. لحل مشآكل تثبيت الكآسبرComboFix 08-11-22.02 - User 11/23/2008 21:28:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.1015 [GMT 3:00]
Running from: d:\downloads\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Messenger\msgmr.dll
c:\windows\Downloaded Program Files\ThunderAdvise.dll
c:\windows\Fonts\Framdee.ttf
c:\windows\system32\08223B03.cfg
c:\windows\system32\122B901E.cfg
c:\windows\system32\2EF0D734.cfg
c:\windows\system32\43ACDCC5.cfg
c:\windows\system32\4D023DE9.cfg
c:\windows\system32\58FF3024.cfg
c:\windows\system32\66AFCB56.cfg
c:\windows\system32\8566F82E.cfg
c:\windows\system32\9CA963CA.cfg
c:\windows\system32\9F684DE8.cfg
c:\windows\system32\B3721C07.cfg
c:\windows\system32\BA7EDF54.cfg
c:\windows\system32\D7C79813.cfg
c:\windows\system32\DA63E650.cfg
c:\windows\system32\DFEC5CB7.cfg
c:\windows\system32\E0D39066.cfg
c:\windows\system32\E3367679.cfg
c:\windows\system32\E4814792.cfg
c:\windows\system32\F65BDEC7.cfg
c:\windows\system32\mdm.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_C39E8DB
-------\Legacy_ETH8023
-------\Legacy_NM
-------\Service_c39e8db
-------\Service_d7b49fa
-------\Service_eth8023
-------\Service_nm
((((((((((((((((((((((((( Files Created from 2008-10-23 to 2008-11-23 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-23 18:25 --------- d-----w c:\documents and settings\User\Application Data\DMCache
2008-11-23 18:22 --------- d-----w c:\documents and settings\User\Application Data\IDM
2008-11-20 14:04 --------- d-----w c:\program files\BitDefender
2008-11-20 13:19 --------- d-----w c:\documents and settings\All Users\Application Data\BitDefender
2008-11-20 13:17 --------- d-----w c:\program files\Common Files\BitDefender
2008-11-20 10:40 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-20 10:20 24,625 ----a-w c:\windows\MSVB50CHS.dll
2008-11-20 10:17 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2008-11-20 10:15 5,504 ----a-w c:\windows\system32\f35ee9e.sys
2008-11-20 10:14 --------- d-----w c:\documents and settings\User\Application Data\two bind wait
2008-11-20 10:12 --------- d-----w c:\documents and settings\All Users\Application Data\File dvd base road
2008-11-20 10:11 --------- d-----w c:\program files\two bind wait
2008-11-19 22:07 5,504 ----a-w c:\windows\system32\b160485.sys
2008-11-19 22:07 217,378 ----a-w c:\windows\system32\4FBFD5A4.VIR
2008-11-13 12:26 --------- d-----w c:\program files\Circle Developement
2008-11-13 04:01 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-13 03:31 --------- d-----w c:\documents and settings\User\Application Data\Malwarebytes
2008-11-13 03:31 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-13 02:44 5,504 ----a-w c:\windows\system32\de8296f.sys
2008-11-13 02:35 --------- d-----w c:\program files\ESET
2008-11-13 02:34 --------- d-----w c:\documents and settings\User\Application Data\Skype
2008-10-29 14:33 --------- d-----w c:\program files\MSN Messenger
2008-10-29 14:18 --------- d-----w c:\program files\Messenger Plus! Live
2008-10-29 14:04 --------- d-----w c:\program files\Yahoo!
2008-10-29 14:04 --------- d-----w c:\program files\CCleaner
2008-10-21 17:09 --------- d-----w c:\documents and settings\M-pCx\Application Data\ATI
2008-10-20 20:52 --------- d-----w c:\program files\Extension Changer
2008-10-20 20:49 --------- d-----w c:\program files\SCREEN2EXE
2008-10-20 20:47 --------- d-----w c:\program files\Skype
2008-10-20 20:47 --------- d-----w c:\program files\Google
2008-10-20 20:47 --------- d-----w c:\program files\Common Files\Skype
2008-10-20 20:47 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-10-20 20:46 --------- d-----w c:\program files\Paltalk Messenger
2008-10-20 20:46 --------- d-----w c:\documents and settings\User\Application Data\Paltalk
2008-10-20 20:37 --------- d-----w c:\program files\Opera
2008-10-20 20:24 --------- d-----w c:\program files\Safari
2008-10-20 20:24 --------- d-----w c:\program files\Bonjour
2008-10-20 20:23 --------- d-----w c:\program files\Apple Software Update
2008-10-20 20:23 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-10-20 20:22 --------- d-----w c:\program files\BreakPoint Software
2008-10-20 20:14 91,648 ----a-w c:\windows\system32\cabview.dll
2008-10-20 20:11 218,624 ----a-w c:\windows\system32\uxtheme.dll
2008-10-20 20:11 1,949,184 ----a-w c:\windows\system32\logonui.exe
2008-10-09 12:31 192,512 ----a-w c:\windows\system32\txmlutil.dll
2008-09-12 10:44 206,256 ----a-w c:\windows\system32\idmmbc.dll
.
------- Sigcheck -------
10/20/2008 11:14 PM 1655296 2fd48aaeaec9c891f72277bbe701f5db c:\windows\explorer.exe
10/20/2008 11:14 PM 1655296 2fd48aaeaec9c891f72277bbe701f5db c:\windows\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [01/19/2007 12:55 PM 5674352]
"JUNK FORK"="c:\docume~1\User\APPLIC~1\TWOBIN~1\license eggs.exe" [11/20/2008 01:11 PM 640000]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [11/20/2008 12:59 AM 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [05/01/2008 10:12 PM 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [07/12/2007 04:00 AM 132496]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [07/14/2006 07:13 AM 471040]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [08/16/2006 06:20 AM 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [08/16/2006 06:34 AM 766041]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DfLogon]
06/28/2007 08:39 PM 65536 c:\windows\system32\LogonDll.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\PalTalk.lnk
backup=c:\windows\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^SnagIt 8.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\SnagIt 8.lnk
backup=c:\windows\pss\SnagIt 8.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
--a------ 05/10/2006 11:12 AM 90112 c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Base road long save]
--a------ 11/23/2008 09:33 PM 3281408 c:\documents and settings\All Users\Application Data\File dvd base road\axis dent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 04/13/2006 11:09 AM 49152 c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 12/07/2005 10:57 PM 30208 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 05/30/2008 03:54 PM 21718312 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 11/20/2008 12:59 AM 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 08/16/2006 06:20 AM 69632 c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 08/16/2006 06:23 AM 16248320 c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
-r------- 08/16/2006 06:21 AM 2879488 c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Visual Studio\\COMMON\\Tools\\VS-Ent98\\Vanalyzr\\VARPC.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R0 DeepFrz;DeepFrz;c:\windows\system32\drivers\DeepFrz.sys [2007-06-28 131472]
R2 UxTuneUp;TuneUp Theme Extension;c:\windows\System32\svchost.exe -k netsvcs [2004-08-04 14336]
S2 BDVEDISK;BDVEDISK;\??\c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys []
S3 b160485;b160485;\??\c:\windows\system32\b160485.sys [2008-11-20 5504]
S3 de8296f;de8296f;\??\c:\windows\system32\de8296f.sys [2008-11-13 5504]
S3 f35ee9e;f35ee9e;\??\c:\windows\system32\f35ee9e.sys [2008-11-20 5504]
S3 NPF;NPF;c:\windows\system32\drivers\NPF.sys [2007-01-25 42000]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;c:\windows\System32\TuneUpDefragService.exe [2008-05-17 307968]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
s of the 'Scheduled Tasks' folder
2008-11-23 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [02/29/2008 02:24 PM]
2008-11-20 c:\windows\Tasks\AE3770279300E7B3.job
- c:\docume~1\user\applic~1\twobin~1\Each sect sign.exe [11/20/2008 01:14 PM]
2008-10-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [04/11/2008 05:57 PM]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
ShellExecuteHooks-{3F21AA0C-2A9E-4BE9-9083-9E58AB41BA01} - 3F21AA0C.dll
ShellExecuteHooks-{4FBFD5A4-5FE8-4444-8BD9-FD0FAFA64F96} - 4FBFD5A4.dll
ShellExecuteHooks-{F2CBFAC4-6FF9-4DE9-BCB1-0F2FA2AA0B4C} - F2CBFAC4.dll
ShellExecuteHooks-{F8E07BB2-7A19-4057-80F1-E14646E630B4} - F8E07BB2.dll
ShellExecuteHooks-{70B0129E-726E-4789-A7C0-5DDC33241E94} - 70B0129E.dll
ShellExecuteHooks-{01AFE3DC-2242-436E-9B44-6DD1C664E828} - 01AFE3DC.dll
ShellExecuteHooks-{5934EA2B-B2C4-4BE7-BF7A-FBA781A12E40} - 5934EA2B.dll
ShellExecuteHooks-{93DEE065-EC9B-4505-ADD3-19880AD3C38F} - 93DEE065.dll
ShellExecuteHooks-{C8FFD223-C0FB-40C5-94A0-FD7891AC18E9} - C8FFD223.dll
ShellExecuteHooks-{E1D19FCC-4777-4D71-B863-6A0A5B4E59BC} - E1D19FCC.dll
ShellExecuteHooks-{16AF66EB-93C8-49F9-BB09-B4F87CEDCE46} - 16AF66EB.dll
ShellExecuteHooks-{34A25F04-008D-403E-8EE6-2307BC02FA2E} - 34A25F04.dll
ShellExecuteHooks-{B8E83D3C-9466-4091-9AD1-1F89418A6EB7} - B8E83D3C.dll
SSODL-Upnp-{DE01DA19-A6A8-EB80-4D47-248DEB2A9399} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\amhpj331.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com.sa/firefox?client=firefox-a&rls=org.mozilla:arfficial
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
Rootkit scan 2008-11-23 21:32:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NPF]
"ImagePath"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(632)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\LogonDll.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(688)
c:\windows\system32\msprivs.dll
c:\windows\system32\rsaenh.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 11/23/2008 21:34:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-23 18:34:51
Pre-Run: 30,617,812,992 bytes free
Post-Run: 30,609,133,568 bytes free
241
والنتيــجة كما هي ..
الصــرآحــــــه تعقدت ومآعرفت وش اسوي
ومآسجلت الا وانا وآثـــق اني بلآقي الحل عنـدكـــــم ..
بانتظـــآر ردودكـــ/ــم ..
