هلا هلا زيزووم :noskjiuyweat:
قفلت برامج الحمايه وحملت الاداة وشغلتها ,, بس التقرير طلع لي بدون مايعاد تشغيل الجهاز :iconmju17:
وهذا هو التقرير
ComboFix 08-01-13.1 - 01/13/2008 22:13:03.1 - NTFSx86
Running from: C:\Documents and Settingsسطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Helper
C:\Program Files\Helper\prolooker.dll
C:\WINDOWS\system32\vm.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-13 to 2008-01-13 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-13 19:16 993,056 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-13 19:16 24,224,288 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-13 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-13 18:43 --------- d-----w C:\Documents and Settings\زوزو\Application Data\Orbit
2008-01-13 18:41 96,068 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-13 18:41 329,420 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-08 19:27 --------- d-----w C:\Program Files\Circle Developement
2008-01-07 18:09 --------- d-----w C:\Program Files\Avant Browser
2008-01-04 19:00 --------- d-----w C:\Program Files\VoiceMaskPro
2007-12-23 18:42 --------- d-----w C:\Program Files\JAP
2007-12-23 01:35 91,492 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2007-12-21 01:19 --------- d-----w C:\Program Files\MSN Messenger
2007-12-21 01:19 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-12-20 01:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-20 01:17 --------- d-----w C:\Program Files\QuickTime
2007-12-15 04:42 --------- d-----w C:\Documents and Settings\زوزو\Application Data\Nokia Multimedia Player
2007-12-12 20:51 85,860 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2007-11-20 22:42 --------- d-----w C:\Documents and Settings\زوزو\Application Data\Nokia
2007-11-20 22:37 --------- d-----w C:\Program Files\Nokia
2007-11-20 22:37 --------- d-----w C:\Program Files\Common Files\PCSuite
2007-11-20 22:37 --------- d-----w C:\Program Files\Common Files\Nokia
2007-11-20 22:36 --------- d-----w C:\Program Files\PC Connectivity Solution
2007-11-20 22:36 --------- d-----w C:\Program Files\DIFX
2007-11-20 22:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2007-11-20 00:02 --------- d-----w C:\Program Files\MSXML 4.0
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:42 1,285,632 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 07:00 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-08-23 19:06 1,082 ----a-w C:\Program Files\2.bat
2007-06-16 21:11 27,136 ----a-w C:\Program Files\nir.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA0BACB5-FC95-451E-94D2-4959AB0949D2}]
C:\Program Files\Video Add-on\isfmdl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{F2BADA0D-FD61-45EF-A994-64A073FD6613}
[HKEY_CLASSES_ROOT\clsid\{f2bada0d-fd61-45ef-a994-64a073fd6613}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [07/19/2006 04:42 AM 16248320 C:\WINDOWS\RTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [07/19/2006 04:42 AM 2879488 C:\WINDOWS\SkyTel.exe]
"AGRSMMSG"="AGRSMMSG.exe" [12/13/2005 04:50 PM 88204 C:\WINDOWS\AGRSMMSG.exe]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [06/13/2006 04:57 AM 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [06/13/2006 04:57 AM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [06/13/2006 04:57 AM 118784]
"DNP"="C:\Program Files\Desktop Notepad\Desktop Notepad.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [10/05/2007 09:21 PM 185632]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [06/18/2007 03:10 PM 271360]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [06/28/2007 12:51 PM 218376]
C:\Documents and Settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-06-22 03:57:30]
Orbit.lnk - C:\Program Files\Orbitdownloader\orbitdm.exe [2007-09-10 05:49:35]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{c7cd9e83-3bf6-47f8-b2e2-b114c96c1888}"= C:\WINDOWS\system32\qhcvdw.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsp_lmwl]
fsp_lmwl.dll 06/12/2007 07:56 PM 44400 C:\WINDOWS\system32\fsp_lmwl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/04/2007 02:58 PM]
R3 LMPC4;LMPC4;C:\WINDOWS\system32\drivers\LMPC4.sys [02/21/2007 09:21 PM]
S3 NPF;WinPcap Packet Driver (NPF);C:\WINDOWS\system32\drivers\NPF.sys [01/25/2007 08:31 PM]
S3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [12/16/2006 11:37 PM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b25e187f-2114-11dc-bef5-001636a5911a}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL rose.exe
*Newly Created Service* - PROCEXP90
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-01-13 22:16:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 01/13/2008 22:19:37
ComboFix-quarantined-files.txt 2008-01-13 19:19:21
.
2007-12-24 05:17:28 --- E O F ---
بس واجهتني مشكله عويصه :jhuyno:
المتصفح ماعاد يشتغل معي :jhuyno::jhuyno: انا داخله من جهاز ثاني الان عشان تحلون لي المشكله :biggrin:
شف الصور
وش السواه :frown: