السلام عليكم ورحمة الله وبركاته
اخوي خلــود يعطيك العافيه
سويت اللي قلته لي
وانا على بالي ان المشكله جذي انحلت رحت نزلت الكاسبر من جديد
المهم ماكو فايده والحين الأداتين اللي نزلتهم لي مايفتحون معاي
وهذا التقرير
==============================
ComboFix 08-12-15.01 - A 2008-12-16 1:11:55.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.965.1033.18.246.87 [GMT 3:00]
Running from: c:\documents and settings\A\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2008-11-15 to 2008-12-15 )))))))))))))))))))))))))))))))
.
2008-12-16 01:13 . 2008-12-16 01:13 836 --a------ c:\windows\bthservsdp.dat
2008-12-15 23:57 . 2008-12-15 23:57 <DIR> d-------- c:\program files\RM to MP3 Converter
2008-12-15 23:57 . 2005-02-27 21:48 356,352 --a------ c:\windows\system32\bsrmdec.ax
2008-12-15 23:52 . 2004-08-03 23:10 18,944 --a------ c:\windows\system32\drivers\BTHUSB.SYS
2008-12-15 23:52 . 2004-08-03 23:10 18,944 --a------ c:\windows\system32\dllcache\bthusb.sys
2008-12-15 19:02 . 2008-12-15 19:02 <DIR> d---s---- c:\documents and settings\A\UserData
2008-12-15 08:33 . 2001-08-17 14:02 9,600 --a------ c:\windows\system32\drivers\hidusb.sys
2008-12-15 08:33 . 2001-08-17 14:02 9,600 --a------ c:\windows\system32\dllcache\hidusb.sys
2008-12-15 08:13 . 2008-12-15 08:13 <DIR> d-------- c:\program files\Internet Download Manager
2008-12-15 08:13 . 2008-12-15 08:13 <DIR> d-------- c:\documents and settings\A\Application Data\IDM
2008-12-15 08:13 . 2008-12-15 08:13 <DIR> d-------- c:\documents and settings\A\Application Data\DMCache
2008-12-15 08:07 . 2008-12-15 08:07 <DIR> d-------- c:\program files\Common Files\xing shared
2008-12-15 08:06 . 2008-12-15 08:06 <DIR> d-------- c:\program files\Real
2008-12-15 08:06 . 2008-12-15 08:06 <DIR> d-------- c:\program files\Common Files\Real
2008-12-15 07:47 . 2008-12-15 07:47 <DIR> d-------- c:\documents and settings\A\Contacts
2008-12-15 07:43 . 2008-12-15 07:43 <DIR> d-------- c:\docume~1\ALLUSE~1\APPLIC~1\Messenger Plus!
2008-12-15 05:55 . 2001-08-23 18:00 195,618 --a------ c:\windows\system32\dllcache\c_10002.nls
2008-12-15 05:54 . 2001-08-23 18:00 189,986 --a------ c:\windows\system32\dllcache\c_1361.nls
2008-12-15 05:54 . 2001-08-23 18:00 177,698 --a------ c:\windows\system32\dllcache\c_10003.nls
2008-12-15 05:54 . 2001-08-23 18:00 173,602 --a------ c:\windows\system32\dllcache\c_10008.nls
2008-12-15 05:52 . 2001-08-23 18:00 180,770 --a------ c:\windows\system32\dllcache\c_20932.nls
2008-12-15 05:52 . 2001-08-23 18:00 180,258 --a------ c:\windows\system32\dllcache\c_20000.nls
2008-12-15 05:52 . 2001-08-23 18:00 177,698 --a------ c:\windows\system32\dllcache\c_20949.nls
2008-12-15 05:52 . 2001-08-23 18:00 173,602 --a------ c:\windows\system32\dllcache\c_20936.nls
2008-12-15 05:52 . 2001-08-23 18:00 162,850 --a------ c:\windows\system32\dllcache\c_10001.nls
2008-12-15 05:52 . 2001-08-23 18:00 66,082 --a------ c:\windows\system32\dllcache\c_21027.nls
2008-12-15 05:52 . 2001-08-23 18:00 66,082 --a------ c:\windows\system32\dllcache\c_20290.nls
2008-12-15 04:38 . 2008-12-15 04:38 268 --ah----- C:\sqmdata01.sqm
2008-12-15 04:38 . 2008-12-15 04:38 244 --ah----- C:\sqmnoopt01.sqm
2008-12-15 04:19 . 2008-12-15 04:19 <DIR> d-------- c:\program files\Windows Live
2008-12-15 04:19 . 2008-12-15 04:19 <DIR> d-------- c:\program files\Messenger Plus! Live
2008-12-15 04:19 . 2008-12-15 04:19 <DIR> d-------- c:\program files\Adverts
2008-12-15 04:19 . 2008-12-15 04:19 268 --ah----- C:\sqmdata00.sqm
2008-12-15 04:19 . 2008-12-15 04:19 244 --ah----- C:\sqmnoopt00.sqm
2008-12-15 04:18 . 2008-12-15 04:18 <DIR> d-------- c:\windows\system32\DRVSTORE
2008-12-15 04:17 . 2008-12-15 04:17 <DIR> d-------- c:\program files\MSN Messenger
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-15 00:59 --------- d-----w c:\docume~1\ALLUSE~1\APPLIC~1\Kaspersky Lab Setup Files
2008-12-15 00:46 --------- d-----w c:\program files\CONEXANT
2008-12-15 00:08 --------- d-----w c:\program files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5748080]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-12-15 2688432]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-02-08 200704]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-15 180269]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2005-02-08 10:36 155648 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1444cefa-ca43-11dd-9e5b-00c09fc4aa29}]
\Shell\Autoplay\cOMmanD - F:\kmbbtf.pif
\Shell\AutoRun\command - F:\kmbbtf.pif
\Shell\exPlorE\CommaNd - F:\kmbbtf.pif
\Shell\oPen\cOmmanD - F:\kmbbtf.pif
*Newly Created Service* - ASC3360PR
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
TCP: {4E99F87D-9CB8-4C80-8915-1916E998342D} = 194.54.234.234 194.54.234.235
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-16 01:14:05
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\rundll32.exe
c:\program files\INTERNET DOWNLOAD MANAGER\IEMONITOR.EXE
.
**************************************************************************
.
Completion time: 2008-12-16 1:14:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-15 22:14:50
Pre-Run: 22,972,481,536 bytes free
Post-Run: 22,972,923,904 bytes free
129
=====================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:16:46 AM, on 12/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\A\Desktop\Zyzoom_HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4E99F87D-9CB8-4C80-8915-1916E998342D}: NameServer = 194.54.234.234 194.54.234.235
--
End of file - 3286 bytes
ان شاءالله تلقى الحل
والف شكر لك مقدما