abdullah99
زيزوومي جديد
- إنضم
- 30 أكتوبر 2008
- المشاركات
- 7
- مستوى التفاعل
- 0
- النقاط
- 0
غير متصل
من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
السلام عليكم ورحمة الله وبركاته
أرجو من الأخوة والأخوات المشرفين المساعده في المشكلة
عندي مشكلة بالجهاز يعلق كثير والمجلدات إذا فتحتها تفتح شوي وتقفل وتجيني رسالة خطأ وتقفل وكذلك الاكسبلورر والكاسبر
وعملت تقرير ******** وتقرير hijack
هذا هو تقرير :********
******** 08-12-12.05 - malik 02/17/2009 19:20:54.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.247.135 [GMT 3:00]
Running from: c:\documents and settings\malik\سطح المكتب\tools\********.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\gasretyw0.dll
c:\windows\system32\tmp.reg
D:\Autorun.inf
E:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-01-17 to 2009-02-17 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-17 16:15 9,357,856 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-02-17 16:15 27,560 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-02-17 16:15 253,216 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-02-17 16:15 131,624 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-02-17 16:14 --------- d-----w c:\documents and settings\malik\Application Data\uTorrent
2009-02-17 16:14 --------- d-----w c:\documents and settings\malik\Application Data\Free Download Manager
2009-02-17 14:11 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-02-17 13:14 --------- d-----w c:\documents and settings\malik\Application Data\Software Informer
2009-02-17 12:33 --------- d-----w c:\program files\Free Download Manager
2009-02-17 00:00 --------- d-----w c:\program files\Messenger Plus! Live
2009-02-17 00:00 --------- d-----w c:\program files\File Anti-Copy
2009-02-17 00:00 --------- d-----w c:\program files\Circle Developement
2009-02-16 23:29 --------- d-----w c:\documents and settings\malik\Application Data\IsolatedStorage
2009-02-16 22:24 --------- d-----w c:\documents and settings\All Users\Application Data\VolumeShield
2009-02-16 22:21 --------- d-----w c:\program files\VolumeShield
2009-02-15 23:49 --------- d-----w c:\program files\Total Video Converter
2009-02-13 23:30 --------- d-----w c:\program files\TeamViewer
2009-02-13 23:30 --------- d-----w c:\documents and settings\malik\Application Data\TeamViewer
2009-02-05 14:48 --------- d-----w c:\program files\SWiSHmax
2009-02-03 06:09 --------- d-----w c:\documents and settings\malik\Application Data\option ante regs
2009-02-03 06:07 --------- d-----w c:\program files\option ante regs
2009-02-02 15:01 --------- d-----w c:\documents and settings\malik\Application Data\BSplayer PRO
2009-01-29 09:17 --------- d-----w c:\program files\ElcomSoft
2009-01-28 16:16 --------- d-----w c:\program files\Mahjong Escape Ancient Japan
2009-01-28 16:16 --------- d-----w c:\documents and settings\All Users\Application Data\Trymedia
2009-01-11 22:30 --------- d-----w c:\documents and settings\malik\Application Data\Download Manager
2009-01-11 22:14 --------- d-----w c:\program files\Software Informer
2009-01-11 22:13 --------- d-----w c:\documents and settings\All Users\Application Data\FreeDownloadManager.ORG
2009-01-11 21:33 --------- d-----w c:\documents and settings\malik\Application Data\DMCache
2009-01-08 16:51 --------- d-----w c:\documents and settings\malik\Application Data\VoipCheapCom
2008-12-19 22:48 --------- d-----w c:\documents and settings\malik\Application Data\ooVoo Details
2008-12-19 22:14 --------- d-----w c:\documents and settings\malik\Application Data\Thinstall
2008-12-17 11:50 --------- d-----w c:\program files\JetAudio
2008-10-15 19:12 81,920 ----a-w c:\documents and settings\malik\Application Data\ezpinst.exe
2008-10-15 19:12 47,360 ----a-w c:\documents and settings\malik\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Fork dent"="c:\docume~1\malik\APPLIC~1\OPTION~1\trust bike.exe" [02/03/2009 08:32 AM 598016]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [01/02/2009 04:12 PM 3399727]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [10/30/2008 04:49 AM 270128]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [08/16/2007 04:19 PM 5728112]
"Software Informer"="c:\program files\Software Informer\softinfo.exe" [01/01/2009 03:31 PM 1654853]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [10/15/2008 10:13 PM 185896]
"Cake Wipe Inside Wma"="c:\documents and settings\All Users\Application Data\flag barb cake wipe\type cdrom.exe" [02/17/2009 05:11 PM 2947072]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [10/15/2008 10:07 PM 77824]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [10/14/2004 09:11 AM 1388544]
"igfxtray"="c:\windows\system32\igfxtray.exe" [06/19/2007 04:26 PM 101144]
"igfxpers"="c:\windows\system32\igfxpers.exe" [06/19/2007 04:26 PM 125720]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [06/19/2007 04:26 PM 84760]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [06/12/2008 02:38 AM 34672]
"AGRSMMSG"="AGRSMMSG.exe" [11/16/2005 02:12 PM 88209 c:\windows\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/14/2008 06:59 PM 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-10-15 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-02-27 581693]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\malik\\سطح المكتب\\ooVoo.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Free Download Manager\\fdm.exe"=
S3 Arrakis3;BitDefender Arrakis Server;"c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe" []
S3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-08-12 108864]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-12-13 24592]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2008-01-25 25088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - xih9.cmd
\Shell\explore\Command - xih9.cmd
\Shell\open\Command - xih9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - xih9.cmd
\Shell\explore\Command - xih9.cmd
\Shell\open\Command - xih9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a72f35b-9b00-11dd-a2c0-806d6172696f}]
\Shell\AutoRun\command - xih9.cmd
\Shell\explore\Command - xih9.cmd
\Shell\open\Command - xih9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a72f35c-9b00-11dd-a2c0-806d6172696f}]
\Shell\AutoRun\command - xih9.cmd
\Shell\explore\Command - xih9.cmd
\Shell\open\Command - xih9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{479d1231-9b4a-11dd-ae88-dc2ad260f16f}]
\Shell\AutoRun\command - G:\9.cmd
\Shell\explore\Command - G:\9.cmd
\Shell\open\Command - G:\9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d7002830-9c94-11dd-aaf8-0010c6c650a1}]
\Shell\AutoRun\command - G:\xih9.cmd
\Shell\explore\Command - G:\xih9.cmd
\Shell\open\Command - G:\xih9.cmd
.
*******s of the 'Scheduled Tasks' folder
2009-02-17 c:\windows\Tasks\User_Feed_Synchronization-{E1F4185A-24A1-451C-8094-5623B05FCB1C}.job
- c:\windows\system32\msfeedssync.exe [08/22/2008 03:05 AM]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-VoipCheapCom - c:\program files\VoipCheapCom\VoipCheapCom.exe
HKCU-Run-fsm - (no file)
.
------- Supplementary Scan -------
.
O16 -: Microsoft XML Parser for Java -
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\malik\Application Data\Mozilla\Firefox\Profiles\rpiif29w.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - plugin: c:\program files\Real\RhapsodyPlayerEngine\nprhapengine.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-02-17 19:21:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(228)
c:\progra~1\KASPER~1\KASPER~1.0\adialhk.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(284)
c:\progra~1\KASPER~1\KASPER~1.0\adialhk.dll
.
Completion time: 02/17/2009 19:23:56
********-quarantined-files.txt 2009-02-17 16:22:59
Pre-Run: 2,500,620,288 bytes free
Post-Run: 2,488,528,896 bytes free
167 --- E O F --- 2009-01-17 04:04:41
أرجو من الأخوة والأخوات المشرفين المساعده في المشكلة
عندي مشكلة بالجهاز يعلق كثير والمجلدات إذا فتحتها تفتح شوي وتقفل وتجيني رسالة خطأ وتقفل وكذلك الاكسبلورر والكاسبر
وعملت تقرير ******** وتقرير hijack
هذا هو تقرير :********
******** 08-12-12.05 - malik 02/17/2009 19:20:54.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.247.135 [GMT 3:00]
Running from: c:\documents and settings\malik\سطح المكتب\tools\********.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\gasretyw0.dll
c:\windows\system32\tmp.reg
D:\Autorun.inf
E:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-01-17 to 2009-02-17 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-17 16:15 9,357,856 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-02-17 16:15 27,560 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-02-17 16:15 253,216 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-02-17 16:15 131,624 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-02-17 16:14 --------- d-----w c:\documents and settings\malik\Application Data\uTorrent
2009-02-17 16:14 --------- d-----w c:\documents and settings\malik\Application Data\Free Download Manager
2009-02-17 14:11 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-02-17 13:14 --------- d-----w c:\documents and settings\malik\Application Data\Software Informer
2009-02-17 12:33 --------- d-----w c:\program files\Free Download Manager
2009-02-17 00:00 --------- d-----w c:\program files\Messenger Plus! Live
2009-02-17 00:00 --------- d-----w c:\program files\File Anti-Copy
2009-02-17 00:00 --------- d-----w c:\program files\Circle Developement
2009-02-16 23:29 --------- d-----w c:\documents and settings\malik\Application Data\IsolatedStorage
2009-02-16 22:24 --------- d-----w c:\documents and settings\All Users\Application Data\VolumeShield
2009-02-16 22:21 --------- d-----w c:\program files\VolumeShield
2009-02-15 23:49 --------- d-----w c:\program files\Total Video Converter
2009-02-13 23:30 --------- d-----w c:\program files\TeamViewer
2009-02-13 23:30 --------- d-----w c:\documents and settings\malik\Application Data\TeamViewer
2009-02-05 14:48 --------- d-----w c:\program files\SWiSHmax
2009-02-03 06:09 --------- d-----w c:\documents and settings\malik\Application Data\option ante regs
2009-02-03 06:07 --------- d-----w c:\program files\option ante regs
2009-02-02 15:01 --------- d-----w c:\documents and settings\malik\Application Data\BSplayer PRO
2009-01-29 09:17 --------- d-----w c:\program files\ElcomSoft
2009-01-28 16:16 --------- d-----w c:\program files\Mahjong Escape Ancient Japan
2009-01-28 16:16 --------- d-----w c:\documents and settings\All Users\Application Data\Trymedia
2009-01-11 22:30 --------- d-----w c:\documents and settings\malik\Application Data\Download Manager
2009-01-11 22:14 --------- d-----w c:\program files\Software Informer
2009-01-11 22:13 --------- d-----w c:\documents and settings\All Users\Application Data\FreeDownloadManager.ORG
2009-01-11 21:33 --------- d-----w c:\documents and settings\malik\Application Data\DMCache
2009-01-08 16:51 --------- d-----w c:\documents and settings\malik\Application Data\VoipCheapCom
2008-12-19 22:48 --------- d-----w c:\documents and settings\malik\Application Data\ooVoo Details
2008-12-19 22:14 --------- d-----w c:\documents and settings\malik\Application Data\Thinstall
2008-12-17 11:50 --------- d-----w c:\program files\JetAudio
2008-10-15 19:12 81,920 ----a-w c:\documents and settings\malik\Application Data\ezpinst.exe
2008-10-15 19:12 47,360 ----a-w c:\documents and settings\malik\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Fork dent"="c:\docume~1\malik\APPLIC~1\OPTION~1\trust bike.exe" [02/03/2009 08:32 AM 598016]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [01/02/2009 04:12 PM 3399727]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [10/30/2008 04:49 AM 270128]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [08/16/2007 04:19 PM 5728112]
"Software Informer"="c:\program files\Software Informer\softinfo.exe" [01/01/2009 03:31 PM 1654853]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [10/15/2008 10:13 PM 185896]
"Cake Wipe Inside Wma"="c:\documents and settings\All Users\Application Data\flag barb cake wipe\type cdrom.exe" [02/17/2009 05:11 PM 2947072]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [10/15/2008 10:07 PM 77824]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [10/14/2004 09:11 AM 1388544]
"igfxtray"="c:\windows\system32\igfxtray.exe" [06/19/2007 04:26 PM 101144]
"igfxpers"="c:\windows\system32\igfxpers.exe" [06/19/2007 04:26 PM 125720]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [06/19/2007 04:26 PM 84760]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [06/12/2008 02:38 AM 34672]
"AGRSMMSG"="AGRSMMSG.exe" [11/16/2005 02:12 PM 88209 c:\windows\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/14/2008 06:59 PM 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-10-15 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-02-27 581693]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\malik\\سطح المكتب\\ooVoo.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Free Download Manager\\fdm.exe"=
S3 Arrakis3;BitDefender Arrakis Server;"c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe" []
S3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-08-12 108864]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-12-13 24592]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2008-01-25 25088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - xih9.cmd
\Shell\explore\Command - xih9.cmd
\Shell\open\Command - xih9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - xih9.cmd
\Shell\explore\Command - xih9.cmd
\Shell\open\Command - xih9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a72f35b-9b00-11dd-a2c0-806d6172696f}]
\Shell\AutoRun\command - xih9.cmd
\Shell\explore\Command - xih9.cmd
\Shell\open\Command - xih9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a72f35c-9b00-11dd-a2c0-806d6172696f}]
\Shell\AutoRun\command - xih9.cmd
\Shell\explore\Command - xih9.cmd
\Shell\open\Command - xih9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{479d1231-9b4a-11dd-ae88-dc2ad260f16f}]
\Shell\AutoRun\command - G:\9.cmd
\Shell\explore\Command - G:\9.cmd
\Shell\open\Command - G:\9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d7002830-9c94-11dd-aaf8-0010c6c650a1}]
\Shell\AutoRun\command - G:\xih9.cmd
\Shell\explore\Command - G:\xih9.cmd
\Shell\open\Command - G:\xih9.cmd
.
*******s of the 'Scheduled Tasks' folder
2009-02-17 c:\windows\Tasks\User_Feed_Synchronization-{E1F4185A-24A1-451C-8094-5623B05FCB1C}.job
- c:\windows\system32\msfeedssync.exe [08/22/2008 03:05 AM]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-VoipCheapCom - c:\program files\VoipCheapCom\VoipCheapCom.exe
HKCU-Run-fsm - (no file)
.
------- Supplementary Scan -------
.
O16 -: Microsoft XML Parser for Java -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\malik\Application Data\Mozilla\Firefox\Profiles\rpiif29w.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - plugin: c:\program files\Real\RhapsodyPlayerEngine\nprhapengine.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
Rootkit scan 2009-02-17 19:21:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(228)
c:\progra~1\KASPER~1\KASPER~1.0\adialhk.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(284)
c:\progra~1\KASPER~1\KASPER~1.0\adialhk.dll
.
Completion time: 02/17/2009 19:23:56
********-quarantined-files.txt 2009-02-17 16:22:59
Pre-Run: 2,500,620,288 bytes free
Post-Run: 2,488,528,896 bytes free
167 --- E O F --- 2009-01-17 04:04:41
