عطل برامج الحماية عن العمل
ثم
حمل الاداة التالية واحفظها على سطح المكتب
عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
لا تقم بتشغيل اي برنامج ،، ومهما طالت عملية الفحص انتظر حتى تنتهي
انتظر حتى يظهر لك تقرير ،،انسخه والصقه بمشاركتك القادمة
ComboFix 09-04-01.01 - مكتبة النصـر 04/03/2009 20:21:33.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.767.504 [GMT 3:00]
Running from: c:\documents and settings\مكتبة النصـر\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-03-03 to 2009-04-03 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-03 17:24 --------- d-----w c:\program files\microsoft frontpage
2009-04-03 17:23 32 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-03 17:23 32 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-04-03 17:23 32 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-03 17:23 32 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-03 16:21 --------- d--h--w c:\documents and settings\All Users\Application Data\{8CC5CF4A-124E-41BA-B58C-A41F05BE09CC}
2009-03-31 13:24 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-03-31 08:02 --------- d-----w c:\program files\Xilisoft
2009-03-31 08:02 --------- d-----w c:\program files\QuickTime
2009-03-30 08:47 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2009-03-30 03:42 --------- d-----w c:\program files\Autorun Eater
2009-03-29 09:27 --------- d-----w c:\program files\Common Files\Adobe AIR
2009-03-29 09:23 --------- d-----w c:\program files\Common Files\Adobe
2009-03-29 06:56 --------- d-----w c:\program files\Yahoo!
2009-03-29 03:11 --------- d-----w c:\documents and settings\مكتبة النصـر\Application Data\IDM
2009-03-29 03:11 --------- d-----w c:\documents and settings\مكتبة النصـر\Application Data\DMCache
2009-03-29 03:10 --------- d-----w c:\program files\Internet Download Manager
2009-03-29 02:49 --------- d-----w c:\documents and settings\مكتبة النصـر\Application Data\ViStart
2009-03-29 02:22 218,624 ----a-w c:\windows\system32\uxtheme.dll
2009-03-29 02:16 --------- d-----w c:\program files\Start Magic
2009-03-28 23:58 --------- d-----w c:\documents and settings\مكتبة النصـر\Application Data\GRETECH
2009-03-28 23:57 --------- d-----w c:\program files\GRETECH
2009-03-28 20:30 --------- d-----w c:\documents and settings\All Users\Application Data\CenerTCPMessenger
2009-03-28 04:11 --------- d-----w c:\program files\Logon Loader
2009-03-28 03:53 --------- d-----w c:\program files\TechSmith
2009-03-28 03:53 --------- d-----w c:\documents and settings\All Users\Application Data\TechSmith
2009-03-28 03:51 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-03-27 17:53 --------- d-----w c:\program files\Common Files\snpstd3
2009-03-26 10:43 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-03-26 10:39 --------- d-----w c:\program files\Messenger Plus! Live
2009-03-26 10:39 --------- d-----w c:\program files\Circle Devlopement
2009-03-26 09:44 --------- d-----w c:\documents and settings\مكتبة النصـر\Application Data\Media Player Classic
2009-03-26 08:44 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-03-26 08:44 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-03-26 08:44 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-02-06 15:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
2009-01-22 14:49 206,256 ----a-w c:\windows\system32\idmmbc.dll
2003-01-01 05:14 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012003010120030102\index.dat
.
------- Sigcheck -------
04/14/2008 11:00 AM 578048 894b313c52589628bb996e175b581e3a c:\windows\system32\user32.dll
04/14/2008 11:00 AM 578560 b26b135ff1b9f60c9388b4a7d16f600b c:\windows\NiwradSoft Shell Pack\Backup\user32.dll
12/22/2008 09:12 PM 894464 5f3462dfeb44f5d03fcc92cbd190a313 c:\windows\system32\wininet.dll
12/22/2008 09:12 PM 827904 0d5b75171ff51775b630a431b6c667e8 c:\windows\NiwradSoft Shell Pack\Backup\wininet.dll
12/22/2008 09:12 PM 361600 038ca45522fe9b756efb90dbfa9141ea c:\windows\system32\drivers\tcpip.sys
12/22/2008 09:19 PM 2227328 8854cfaea4802e4dba1a500aed2feeed c:\windows\system32\ntkrnlpa.exe
12/22/2008 09:19 PM 2227200 ef5680965129c44d907a66f94fcc20dc c:\windows\NiwradSoft Shell Pack\Backup\ntkrnlpa.exe
12/22/2008 09:12 PM 2350464 ba1dc9c75bb8ba0913c461d1c845645d c:\windows\system32\ntoskrnl.exe
12/22/2008 09:12 PM 2350336 eb81346c3442562354234cbb8750ed72 c:\windows\NiwradSoft Shell Pack\Backup\ntoskrnl.exe
12/09/2008 10:34 PM 1540096 415a149b42d9e6016adec28f2a7aecd7 c:\windows\explorer.exe
12/09/2008 10:34 PM 1805824 69d1729c25955b4f386ccaa2038cf069 c:\windows\NiwradSoft Shell Pack\Backup\explorer.exe
04/14/2008 11:00 AM 40448 c1d50243355a290cb3aa684fd8b38170 c:\windows\system32\ctfmon.exe
04/14/2008 11:00 AM 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 c:\windows\NiwradSoft Shell Pack\Backup\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [09/02/2007 01:58 PM 495616]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [02/06/2009 06:53 PM 3885408]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [05/27/2008 09:58 PM 4269296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [04/14/2008 11:00 AM 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [04/14/2008 11:00 AM 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [04/14/2008 11:00 AM 455168]
"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [10/05/2006 08:56 PM 280779]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [05/02/2008 12:15 AM 15872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [01/01/2003 05:23 AM 136600]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [01/01/2003 11:16 PM 206088]
"snpstd3"="c:\windows\vsnpstd3.exe" [05/10/2007 01:18 PM 835584]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [04/21/2007 09:37 AM 270336]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [06/12/2008 02:38 AM 34672]
"Autorun Eater"="c:\program files\Autorun Eater\oldmcdonald.exe" [11/27/2008 02:19 AM 501768]
"SoundMan"="SOUNDMAN.EXE" [10/24/2005 09:45 AM 90112 c:\windows\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [09/02/2007 01:58 PM 495616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"_nltide_3"="advpack.dll" [12/22/2008 09:12 PM 124928 c:\windows\system32\advpack.dll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\Resources\Themes\LogonUI\logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
09/16/2008 08:44 AM 174328 c:\program files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\startupfolder\C:^Documents and Settings^مكتبة النصـر^Start Menu^Programs^Startup^Styler.lnk]
path=c:\documents and settings\مكتبة النصـر\Start Menu\Programs\Startup\Styler.lnk
backup=c:\windows\pss\Styler.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
--a------ 07/11/2007 04:09 PM 20480 c:\windows\FixCamera.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 10/27/2006 12:47 AM 31016 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LClock]
--a------ 09/19/2004 12:27 PM 65536 c:\program files\LClock\LClock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 02/06/2009 06:53 PM 3885408 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5876:TCP"= 5876:TCP:qvuke
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
S2 yqsjw;Manager Support;c:\windows\system32\svchost.exe -k netsvcs [2008-04-14 14336]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
yqsjw
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,Register
.
Contents of the 'Scheduled Tasks' folder
2009-04-02 c:\windows\Tasks\User_Feed_Synchronization-{1F58F997-4583-4279-A629-1BE1CA2F37AB}.job
- c:\windows\system32\msfeedssync.exe [08/13/2007 06:36 PM]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = local
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
LSP: c:\windows\system32\idmmbc.dll
TCP: {CAD70A67-B00E-474C-8F06-D659FDB822C4} = 82.137.200.83,82.137.200.86
FF - ProfilePath - c:\documents and settings\مكتبة النصـر\Application Data\Mozilla\Firefox\Profiles\6kv3493e.default\
FF - prefs.js: browser.startup.homepage -
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-03 20:25:30
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\yqsjw]
"ServiceDll"="c:\windows\system32\xpwho.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1491950412-2009852829-4049741679-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Clsid]
@Denied: (Full) (LocalSystem)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1004)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\cscui.dll
c:\program files\Stardock\Object Desktop\WindowBlinds\WBSrv.dll
- - - - - - - > 'lsass.exe'(1068)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\idmmbc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\JAVA\JRE6\BIN\JQS.EXE
.
**************************************************************************
.
Completion time: 04/03/2009 20:27:24 - machine was rebooted [مكتبة النصـر]
ComboFix-quarantined-files.txt 2009-04-03 17:27:22
Pre-Run: 10,730,520,576 bytes free
Post-Run: 10,659,102,720 bytes free
198
====================
كثر الله خيرك أخي ..