حياك الله اخي بالله.. ,,****
طيب يالغلا اعمل الاتي
عطل جميع برامج الحمايه ,, >>> تأكد من وقت وتاريخ الجهاز >>> لاتغير اسم الاداة احفظها على سطح المكتب
نزل هذه الاداة
عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
انتظر حتى يظهر لك تقرير ،، وبذلك يكون الفحص انتهى الصق التقرير بمشاركتك القادمة
اولا شكرا ليك اخي بالله لتفاعلك معي:q::q:
k:
k::d:
ثانيا تم عمل المطلوب بالتفصيل ولكن لم يعمل اعادة التشغيل وانتهي الفحص بنجاح وهذا هو التقرير
ComboFix 09-04-27.02 - Shukran 04/28/2009 4:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.20.1033.18.255.80 [GMT 2:00]
Running from: c:\documents and settings\Shukran\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Shukran\Application Data\addons.dat
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-28 )))))))))))))))))))))))))))))))
.
2009-04-28 02:00 . 2009-04-28 02:00 -------- d-----w c:\program files\Messenger Jump! MSN Winks Installer
2009-04-26 03:45 . 2009-04-26 03:45 -------- d-----w c:\program files\Common Files\Adobe
2009-04-25 21:14 . 2009-04-25 21:23 -------- d-----w c:\documents and settings\Shukran\Local Settings\Application Data\Google
2009-04-25 21:06 . 2009-04-25 21:06 11744 ----a-w c:\documents and settings\Shukran\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-25 21:06 . 2009-04-25 21:14 -------- d-----w c:\documents and settings\Shukran\Local Settings\Application Data\Deployment
2009-04-25 00:24 . 2009-04-25 00:24 16384 ----a-w C:\cf.exe
2009-04-24 00:32 . 2009-04-24 00:32 -------- d-----w c:\documents and settings\Shukran\Application Data\VitySoft
2009-04-23 14:04 . 2009-04-23 14:04 -------- d-----w c:\documents and settings\Shukran\Local Settings\Application Data\Help
2009-04-23 00:32 . 2009-04-23 00:32 -------- d-----w c:\program files\SatcoDX
2009-04-20 01:26 . 2009-04-20 15:18 -------- d-----w c:\program files\Paltalk Messenger
2009-04-20 00:58 . 2009-04-20 14:46 -------- d-----w c:\documents and settings\Shukran\Application Data\Paltalk
2009-04-17 01:20 . 2009-04-24 10:41 1632 ----a-w c:\windows\system32\d3d8caps.dat
2009-04-16 20:52 . 2009-04-16 20:53 -------- d-----w c:\documents and settings\Shukran\Local Settings\Application Data\Adobe
2009-04-16 20:26 . 2009-04-16 20:26 -------- d-----w c:\windows\Sun
2009-04-16 19:47 . 2009-04-16 19:47 -------- d-----w c:\program files\Common Files\Business Objects
2009-04-16 19:21 . 2009-04-16 19:21 -------- d-----w c:\documents and settings\Shukran\Local Settings\Application Data\Identities
2009-04-16 17:14 . 2009-04-16 17:14 -------- d--h--w c:\windows\system32\GroupPolicy
2009-04-16 00:31 . 2009-04-16 00:31 -------- d-s---w c:\documents and settings\Shukran\UserData
2009-04-15 15:00 . 2009-04-15 15:00 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\ESET
2009-04-15 14:35 . 2006-08-01 13:02 49152 ----a-w c:\windows\system32\ChCfg.exe
2009-04-15 14:34 . 2008-09-24 08:40 4122368 ----a-r c:\windows\system32\drivers\alcxwdm.sys
2009-04-15 14:34 . 2009-04-15 14:34 -------- d-----w c:\program files\Realtek AC97
2009-04-15 14:34 . 2006-12-08 13:20 10528768 ----a-w c:\windows\system32\RTLCPL.exe
2009-04-15 14:34 . 2007-04-16 13:28 577536 ----a-w c:\windows\soundman.exe
2009-04-15 14:34 . 2006-10-18 00:53 147456 ----a-w c:\windows\system32\RtlCPAPI.dll
2009-04-15 14:33 . 2006-07-31 09:19 315392 ----a-w c:\windows\alcupd.exe
2009-04-15 14:33 . 2006-07-31 09:27 217088 ----a-w c:\windows\Alcrmv.exe
2009-04-15 00:39 . 2009-04-20 10:32 -------- d-----w c:\documents and settings\Shukran\Local Settings\Application Data\WinAVI
2009-04-15 00:10 . 2009-04-15 00:11 -------- d-----w c:\documents and settings\Shukran\Application Data\ManyCam
2009-04-15 00:10 . 2009-04-15 00:11 -------- d-----w c:\program files\ManyCam 2.4
2009-04-14 02:39 . 2009-04-24 22:52 -------- d-----w c:\documents and settings\Shukran\Contacts
2009-04-14 01:46 . 2009-04-25 23:23 1744 ----a-w c:\windows\system32\d3d9caps.dat
2009-04-14 01:38 . 2001-08-17 20:36 8192 ----a-w c:\windows\system32\kbdkor.dll
2009-04-14 01:38 . 2001-08-17 20:36 8704 ----a-w c:\windows\system32\kbdjpn.dll
2009-04-14 01:32 . 2009-04-14 01:32 -------- d-----w c:\documents and settings\Shukran\Application Data\Camfrog
2009-04-14 01:31 . 2009-04-15 16:00 -------- d-----w c:\program files\Camfrog
2009-04-14 01:30 . 2009-04-14 01:29 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-14 01:29 . 2009-04-14 01:29 -------- d-----w c:\program files\Java
2009-04-14 00:19 . 2009-04-14 00:19 -------- dc----w c:\windows\system32\DRVSTORE
2009-04-14 00:18 . 2009-04-14 00:20 -------- d-----w c:\program files\MSN Messenger
2009-04-14 00:00 . 2009-04-14 02:41 -------- d-----w c:\documents and settings\Shukran\Application Data\Media Player Classic
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-25 20:28 . 2009-04-13 22:08 -------- d-----w c:\program files\ESET
2009-04-20 16:10 . 2009-04-13 23:58 -------- d-----w c:\program files\Internet Download Manager
2009-04-20 11:29 . 2009-04-13 23:29 98304 ----a-w c:\windows\DUMP562e.tmp
2009-04-15 16:08 . 2009-04-13 21:49 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-15 14:33 . 2009-04-13 23:55 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-14 01:26 . 2009-04-14 01:26 -------- d-----w c:\program files\K-Lite Codec Pack
2009-04-13 23:55 . 2009-04-13 23:55 -------- d-----w c:\program files\Common Files\PAC207
2009-04-13 23:55 . 2009-04-13 23:55 -------- d-----w c:\program files\PC Camera
2009-04-13 23:54 . 2009-04-13 23:54 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-13 23:03 . 2009-04-13 23:03 -------- d-----w c:\program files\Yahoo!
2009-04-13 22:19 . 2009-04-13 22:19 -------- d-----w c:\program files\Opera
2009-04-13 22:17 . 2009-04-13 22:17 0 ----a-w c:\windows\nsreg.dat
2009-04-13 21:50 . 2009-04-13 21:50 -------- d-----w c:\program files\LClock
2009-04-13 21:50 . 2006-05-05 12:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-04-13 21:47 . 2009-04-13 21:47 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-26 15:35 . 2009-04-03 13:24 210352 ----a-w c:\windows\system32\idmmbc.dll
.
------- Sigcheck -------
[-] 2006-05-05 12:00 360448 9C515B8621D34478DFAA89B6B5434A54 c:\windows\system32\drivers\tcpip.sys
[-] 2006-05-05 12:00 2188032 C072BEF8FAF78EF13EA9F4C56BA9C98A c:\windows\system32\ntoskrnl.exe
[-] 2006-05-05 12:00 1770496 05082B49A9A6C954D2F6A2902C1DB691 c:\windows\explorer.exe
[-] 2006-05-05 12:00 1580544 9A3022C3C508761A4AAF20E5D4BE13FA c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-05-05 15360]
"Google Update"="c:\documents and settings\Shukran\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-25 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LClock"="c:\program files\LClock\LClock.exe" [2004-09-19 65536]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-10-24 1451264]
"PAC207_Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-14 136600]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2007-04-16 577536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-05-05 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-05-05 44544]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2009-1-28 3474432]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2008-10-24 468224]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
S3 PAC207;PC
Camer@;c:\windows\system32\DRIVERS\PFC027.SYS [2007-10-25 616064]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DB1F3C6A-2778-E0C0-8909-7DB05C44B314}]
c:\windows\system32\system32\camfrog.exe s
.
Contents of the 'Scheduled Tasks' folder
2009-04-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1532298954-839522115-1003.job
- c:\documents and settings\Shukran\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-25 21:14]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = local
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: {BAEE131D-290A-4541-A50A-8936F159563A} - hxxp://support.businessobjects.com/CRforVS2005/PrintControl.cab
FF - ProfilePath - c:\documents and settings\Shukran\Application Data\Mozilla\Firefox\Profiles\bfgnohqb.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\Shukran\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\documents and settings\Shukran\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Opera\program\plugins\NP_IDM1.dll
FF - plugin: c:\program files\Opera\program\plugins\NP_IDM2.dll
FF - plugin: c:\program files\Opera\program\plugins\NP_IDM3.dll
FF - plugin: c:\program files\Opera\program\plugins\NP_IDM4.dll
FF - plugin: c:\program files\Opera\program\plugins\NP_IDM5.dll
FF - plugin: c:\program files\Opera\program\plugins\NP_IDM6.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll
.
.
------- File Associations -------
.
regfile\shell\edit\command=%SystemRoot%\system32\NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-28 04:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
c:\program files\Internet Explorer\IEXPLORE.EXE [1840] 0x818AE770
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-04-28 4:16
ComboFix-quarantined-files.txt 2009-04-28 02:16
Pre-Run: 4,866,248,704 bytes free
Post-Run: 5,175,320,576 bytes free
167
وبعدين؟؟
:?::?: