اتفضل هذا التقرير وبعد شوي اجيب تقرير الهايجك
ComboFix 09-02-25.01 - Administrator 02/26/2009 0:26:22.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.894.509 [GMT 3:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
E:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-01-25 to 2009-02-25 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-25 12:13 --------- d-----w c:\documents and settings\Administrator\Application Data\cleaner
2009-02-23 03:10 --------- d-----w c:\program files\Nokia
2009-02-23 03:10 --------- d-----w c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-02-22 06:40 --------- d-----w c:\documents and settings\Administrator\Application Data\Skype
2009-02-13 04:54 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-13 04:54 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-13 04:54 --------- d-----w c:\program files\Wireless WEP Key Password Spy
2009-02-13 04:54 --------- d-----w c:\program files\Superhunter
2009-02-13 04:54 --------- d-----w c:\program files\SpeedBit Video Downloader
2009-02-13 04:54 --------- d-----w c:\program files\SpeedBit Video Accelerator
2009-02-13 04:54 --------- d-----w c:\program files\MSN Messenger
2009-02-13 04:54 --------- d-----w c:\program files\Messenger Plus! Live
2009-02-13 04:54 --------- d-----w c:\program files\DAP
2009-02-13 04:54 --------- d-----w c:\program files\Cdrom Remote
2009-02-13 04:54 --------- d-----w c:\documents and settings\All Users\Application Data\SpeedBit
2009-02-13 04:54 --------- d-----w c:\documents and settings\Administrator\Application Data\Cdrom Remote
2009-02-13 04:38 --------- d-----w c:\program files\Circle Developement
2009-02-13 04:31 --------- d-----w c:\program files\Google
2009-02-13 04:31 --------- d-----w c:\program files\Fahess_Activation
2009-02-13 04:31 --------- d-----w c:\program files\Common Files\Motive
2009-02-13 04:31 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-02-13 04:30 --------- d-----w c:\program files\VisualRoute Lite Edition
2009-02-13 04:30 --------- d-----w c:\program files\VisualRoute 2008
2009-02-13 04:30 --------- d-----w c:\program files\The Cleaner Demo
2009-02-13 04:30 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-02-11 22:08 --------- d-----w c:\documents and settings\Administrator\Application Data\CyberScrub
2009-02-02 22:31 --------- d-----w c:\program files\Ashampoo
2009-02-01 19:39 --------- d-----w c:\program files\Common Files\Download Manager
2009-01-31 18:58 5,376 ----a-w c:\windows\system32\drivers\MS1000.sys
2009-01-26 01:07 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-26 01:07 --------- d-----w c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-01-23 22:48 --------- d-----w c:\documents and settings\Administrator\Application Data\vlc
2009-01-23 22:01 --------- d-----w c:\documents and settings\Administrator\Application Data\Motive
2009-01-23 21:56 --------- d-----w c:\documents and settings\All Users\Application Data\Motive
2009-01-15 13:14 --------- d-----w c:\documents and settings\Administrator\Application Data\Ahead
2009-01-14 13:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 13:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-09 13:02 --------- d-----w c:\program files\TypingArabic
2009-01-09 11:01 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-01-04 14:08 --------- d-----w c:\program files\tobah
2008-12-29 09:54 --------- d-----w c:\documents and settings\All Users\Application Data\****cafe
2008-10-15 12:53 883,201 ----a-w c:\program files\فلاش.zip
2008-10-11 01:17 4,865,872 ----a-w c:\program files\MsgPlusLive-470.exe
2008-10-11 00:42 883,201 ----a-w c:\program files\a88aa9c74c.zip
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [01/19/2007 12:55 PM 5674352]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [06/07/2007 02:08 PM 4670968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Azkary"="c:\program files\Azkary\Azkary" [X]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM 31016]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [09/23/2008 03:45 AM 29744]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [09/23/2008 03:35 AM 185896]
"RTHDCPL"="RTHDCPL.EXE" [02/26/2007 10:03 AM 16125440 c:\windows\RTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [05/16/2006 01:04 PM 2879488 c:\windows\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 12/05/2006 10:55 PM 54832 c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 02/26/2007 08:46 PM 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 12/06/2006 06:37 PM 69216 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 09/23/2008 03:35 AM 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 06/07/2007 02:08 PM 4670968 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\
000.fcl [2008-05-21 12:12:02 13560]
R2 BandLuxe_Service;BandLuxe Service;c:\program files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe [2008-04-15 85016]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\drivers\br3gmdm.sys [2009-01-29 100096]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-23 29744]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cae1b1da-e27c-11dd-982a-a6c159fe2dcf}]
\Shell\AutoRun\command - G:\iqe68o.bat
\Shell\explore\Command - G:\iqe68o.bat
\Shell\open\Command - G:\iqe68o.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f6474db1-ee5e-11dd-9860-0017c41849e8}]
\Shell\AutoRun\command - G:\iqe68o.bat
\Shell\explore\Command - G:\iqe68o.bat
\Shell\open\Command - G:\iqe68o.bat
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.googel.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {3C8E8DD8-D86A-4E6D-AF37-AB3CA7FDF8CD} - hxxp://75.126.240.26/imscp/talkc38.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-02-26 00:29:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\
000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(620)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 02/26/2009 0:31:23 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-25 21:31:20
Pre-Run: 15,746,387,968 bytes free
Post-Run: 15,674,331,136 bytes free
169 --- E O F --- 2008-11-12 18:43:08