فريق اول

زيزوومي نشيط
إنضم
18 أبريل 2009
المشاركات
175
مستوى التفاعل
0
النقاط
200
غير متصل
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:17:54 م, on 08/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\drivers\services.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Atheros\ACU.exe
C:\WINDOWS\system32\drivers\services.exe
C:\Documents and Settings\user\svchost.exe
C:\WINDOWS\System32\reader_s.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ManyCam 2.3\ManyCam.exe
C:\WINDOWS\system32\drivers\services.exe
C:\Documents and Settings\user\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\REALTEK RTL8187 Wireless LAN Driver and Utility\RtWLan.exe
C:\Program Files\TechSmith\SnagIt 9\SnagIt32.exe
C:\Documents and Settings\user\قائمة ابدأ\البرامج\بدء التشغيل\userinit.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\TechSmith\SnagIt 9\TSCHelp.exe
C:\Program Files\TechSmith\SnagIt 9\SnagPriv.exe
C:\Program Files\TechSmith\SnagIt 9\snagiteditor.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\user\LOCALS~1\Temp\aquwv.exe
C:\DOCUME~1\user\LOCALS~1\Temp\winhfgw.exe
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\KD850X49\HiJackThis[1].exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDO WS\system32\drivers\services.exe
O2 - BHO: (no name) - {006b4e79-a789-44cd-bbf0-2d53da2357f2} - C:\WINDOWS\system32\hfdlrxuc.dll
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {e430eae4-bae5-4d17-be3b-7447045f1f59} - c:\windows\system32\zsgqrfg.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [[system]] C:\WINDOWS\system32\drivers\services.exe
O4 - HKLM\..\Run: [winlogon] C:\Documents and Settings\user\svchost.exe
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [MFCD THAT BAIT BASH] C:\Documents and Settings\All Users\Application Data\Third Pure Mfcd That\Cool bags.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ManyCam] "C:\Program Files\ManyCam 2.3\ManyCam.exe"
O4 - HKCU\..\Run: [[system]] C:\WINDOWS\system32\drivers\services.exe
O4 - HKCU\..\Run: [winlogon] C:\Documents and Settings\user\svchost.exe
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\user\reader_s.exe
O4 - HKCU\..\Run: [LessFilm] C:\DOCUME~1\user\APPLIC~1\FUNKCH~1\Softknob.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: userinit.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
O4 - Global Startup: REALTEK RTL8187 Wireless LAN Utility.lnk = ?
O4 - Global Startup: SnagIt 9.lnk = C:\Program Files\TechSmith\SnagIt 9\SnagIt32.exe
O4 - Global Startup: سرعة تشغيل Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System, DisableRegedit=1
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {7253A666-804A-1107-A4DC-00E04C504780} (BMC Control) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} (ReadUid.UserControlMacEntry) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {C171FF59-8C55-4796-A398-4F5D02B4C763} (IMC_Sec Control) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O20 - Winlogon Notify: toovhdph - C:\WINDOWS\SYSTEM32\zsgqrfg.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ESET HTTP Server (ehttpsrv) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe (file missing)
O23 - Service: ESET Service (ekrn) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\ekrn.exe (file missing)
O23 - Service: Removable Storage NtmsSvcmnmsrvc (NtmsSvcmnmsrvc) - Unknown owner - C:\WINDOWS\system32\3ivxVfWCodecm.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\
--
End of file - 8174 bytes
 

اهلااا بك اخي
وعذرا بنقله للقسم المناسب للمتابعة
هذا القسم خاص بتحليل تقارير برامج الحماية ،، وباقي التقارير تكون عند الطلب فقط


يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
 
نعم مصاب

عطل برامج الحماية عن العمل
ثم
حمل الاداة التالية واحفظها على سطح المكتب
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
لا تقم بتشغيل اي برنامج ،، ومهما طالت عملية الفحص انتظر حتى تنتهي
انتظر حتى يظهر لك تقرير ،،انسخه والصقه بمشاركتك القادمة
 
ComboFix 09-05-08.03 - user 05/09/2009 2:56.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.479.256 [GMT 3:00]
Running from: c:\documents and settings\user\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\LocalService\svchost.exe
c:\documents and settings\user\قائمة ابدأ\البرامج\بدء التشغيل\userinit.exe
c:\documents and settings\user\svchost.exe
c:\program files\Microsoft Common
c:\program files\Microsoft Common\svchost.exe
C:\userinit.exe
c:\windows\IE4 Error Log.txt
c:\windows\system32\3ivxVfWCodecm.exe
c:\windows\system32\config\systemprofile\قائمة ابدأ\البرامج\بدء التشغيل\userinit.exe
c:\windows\system32\config\systemprofile\reader_s.exe
c:\windows\system32\config\systemprofile\svchost.exe
c:\windows\system32\crypts.dll
c:\windows\system32\digiwet.dll
c:\windows\system32\drivers\4329c4e1.sys
c:\windows\system32\drivers\services.exe
c:\windows\system32\mpg4c32.dll
c:\windows\system32\reader_s.exe
c:\windows\system32\server.exe
c:\windows\system32\wsnpoem
g:\recycler\msjavx86.exe
g:\recycler\RECYCLER .exe
h:\recycler\Office2003 CD-Key.doc.exe
h:\recycler\RECYCLER .exe
c:\windows\system32\hfdlrxuc.dll . . . . failed to delete
c:\windows\system32\zsgqrfg.dll . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_hnhjehfd
-------\Legacy_NTMSSVCMNMSRVC
-------\Service_hnhjehfd
-------\Service_NtmsSvcmnmsrvc

((((((((((((((((((((((((( Files Created from 2009-04-09 to 2009-05-09 )))))))))))))))))))))))))))))))
.
2009-05-08 05:08 . 2009-05-08 05:08 -------- d-----w c:\documents and settings\All Users\Application Data\Third Pure Mfcd That
2009-05-08 05:07 . 2009-05-08 05:07 -------- d-----w c:\program files\Funk Chin Regs
2009-05-08 05:07 . 2009-05-08 05:08 -------- d-----w c:\documents and settings\user\Application Data\Funk Chin Regs
2009-05-08 05:07 . 2009-05-08 05:07 -------- d-----w c:\program files\Circle Developeent
2009-05-07 23:16 . 2009-05-07 23:16 -------- d-----w c:\documents and settings\user\Application Data\CyberScrub
2009-05-07 23:15 . 2009-05-07 23:15 -------- d-----w c:\documents and settings\user\Application Data\cleaner
2009-05-07 22:15 . 2009-05-07 22:15 705 ----a-w C:\rmmre.exe
2009-05-07 22:14 . 2009-05-08 16:09 0 ----a-w c:\windows\system32\drivers\452fbfd3.sys
2009-05-07 22:13 . 2009-05-07 22:14 159744 ----a-w C:\demxrb.exe
2009-05-07 21:35 . 2009-05-07 21:35 -------- d-----w c:\program files\ESET
2009-05-07 19:51 . 2009-05-07 19:51 30859 ----a-w C:\shl.exe
2009-05-07 19:44 . 2009-05-07 19:44 -------- d-----w c:\documents and settings\user\Application Data\AdobeUM
2009-05-07 19:21 . 2009-05-07 19:21 102403 ----a-w C:\svacm.exe
2009-05-06 18:18 . 2009-05-06 18:18 -------- d-----w c:\program files\Common Files\NSV
2009-05-06 18:16 . 2009-05-06 18:16 -------- d-----w c:\program files\Common Files\Nullsoft
2009-05-06 11:50 . 2009-05-06 11:50 705 ----a-w C:\lngc.exe
2009-05-06 11:50 . 2009-05-06 11:50 705 ----a-w C:\oqdvjxdc.exe
2009-05-06 11:50 . 2009-05-06 11:50 33792 ----a-w c:\windows\cezhwm.dll
2009-05-06 11:50 . 2009-05-07 22:13 151552 ----a-w C:\epxx.exe
2009-05-05 01:11 . 2009-05-07 21:01 0 ----a-w c:\windows\system32\drivers\8293c0c8.sys
2009-05-03 02:43 . 2009-05-03 02:43 -------- d-----w c:\windows\PaltalkScene
2009-05-03 00:23 . 2009-05-05 01:11 145 --s-a-w c:\windows\system32\820318634.dat
2009-05-02 11:33 . 2009-05-02 11:33 -------- d-----w c:\program files\Common Files\xing shared
2009-04-25 03:55 . 2009-03-13 21:25 25088 ----a-w c:\windows\system32\msxml3a.dll
2009-04-19 00:40 . 2009-05-02 11:32 -------- d-----w c:\program files\AskBarDis
2009-04-19 00:29 . 2009-04-19 00:39 -------- d-----w c:\documents and settings\user\Application Data\Paltalk
2009-04-19 00:29 . 2009-05-03 02:43 -------- d-----w c:\program files\Paltalk Messenger
2009-04-10 13:35 . 2009-05-02 11:34 -------- d-----w c:\program files\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-09 00:00 . 2001-09-19 12:00 143872 ----a-w c:\windows\system32\hfdlrxuc.dll
2009-05-08 23:59 . 2001-09-19 12:00 102912 ----a-w c:\windows\system32\fhsesjx.dll
2009-05-08 05:07 . 2009-03-31 21:58 -------- d-----w c:\program files\Messenger Plus! Live
2009-05-08 05:07 . 2009-03-30 16:18 -------- d-----w c:\program files\MSN Messenger
2009-05-07 22:12 . 2009-03-30 16:09 -------- d-----w c:\program files\Yahoo!
2009-05-02 11:33 . 2009-03-30 16:17 -------- d-----w c:\program files\Common Files\Real
2009-04-08 01:55 . 2009-04-08 01:50 127545 ----a-w c:\windows\hpoins11.dat
2009-04-05 14:46 . 2009-04-05 14:46 -------- d-----w c:\program files\TechSmith
2009-04-05 14:45 . 2009-04-05 14:45 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-04 22:11 . 2009-04-04 22:03 -------- d-----w c:\program files\Image-Line
2009-04-04 22:11 . 2009-04-04 22:11 -------- d-----w c:\program files\ASIO4ALL v2
2009-04-04 22:11 . 2009-04-04 22:11 -------- d-----w c:\program files\VstPlugins
2009-04-04 22:08 . 2009-04-04 22:08 -------- d-----w c:\program files\Outsim
2009-04-04 00:37 . 2009-04-04 00:37 -------- d-----w c:\program files\Steady Recorder
2009-04-02 22:18 . 2009-04-02 22:18 0 ----a-w c:\windows\system32\drivers\SET3D80.tmp
2009-04-02 22:14 . 2009-04-02 22:13 -------- d-----w c:\program files\SplitCam
2009-04-02 22:13 . 2009-03-30 16:32 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-02 14:42 . 2009-04-02 14:40 -------- d-----w c:\program files\ManyCam 2.3
2009-03-31 21:58 . 2009-03-31 21:58 -------- d-----w c:\program files\Circle Deelopement
2009-03-31 21:58 . 2009-03-31 21:58 -------- d-----w c:\program files\Windows Live
2009-03-31 21:09 . 2009-03-31 21:09 252 ----a-w C:\q99202w.exe
2009-03-31 21:06 . 2009-03-30 16:35 94632 ----a-w c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-31 19:05 . 2009-03-30 15:26 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-30 21:32 . 2009-03-30 21:32 -------- d-----w c:\program files\LtUcx
2009-03-30 19:51 . 2009-03-30 19:32 21035 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-03-30 19:51 . 2009-03-30 19:51 -------- d-----w c:\program files\REALTEK RTL8187 Wireless LAN Driver and Utility
2009-03-30 19:32 . 2009-03-30 19:32 -------- d-----w c:\program files\Atheros
2009-03-30 18:57 . 2009-03-30 17:54 -------- d-----w c:\program files\Creative
2009-03-30 18:56 . 2009-03-30 17:56 -------- d--h--w c:\program files\Creative Installation Information
2009-03-30 17:56 . 2009-03-30 17:56 -------- d-----w c:\program files\Common Files\Creative
2009-03-30 17:54 . 2009-03-30 16:32 -------- d-----w c:\program files\Common Files\InstallShield
2009-03-30 16:49 . 2009-03-30 16:49 -------- d-----w c:\program files\Microsoft.NET
2009-03-30 16:48 . 2009-03-30 16:48 -------- d-----w c:\program files\Microsoft Works
2009-03-30 16:41 . 2001-09-19 12:00 39982 ----a-w c:\windows\system32\perfc001.dat
2009-03-30 16:41 . 2001-09-19 12:00 251478 ----a-w c:\windows\system32\perfh001.dat
2009-03-30 16:33 . 2009-03-30 16:10 -------- d-----w c:\program files\Common Files\Adobe
2009-03-30 16:21 . 2009-03-30 16:21 -------- d-----w c:\program files\K-Lite Codec Pack
2009-03-30 16:20 . 2009-03-30 16:19 -------- d-----w c:\program files\Java
2009-03-30 16:19 . 2009-03-30 16:19 -------- d-----w c:\program files\Common Files\Java
2009-03-30 16:17 . 2009-03-30 16:17 -------- d-----w c:\program files\Real
2009-03-30 16:17 . 2003-03-17 20:00 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-03-30 16:17 . 2003-02-20 20:00 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-03-30 16:16 . 2009-03-30 16:15 -------- d-----w c:\program files\QuickTime
2009-03-30 16:15 . 2009-03-30 16:15 -------- d-----w c:\program files\Apple Software Update
2009-03-30 16:15 . 2009-03-30 16:15 -------- d-----w c:\program files\mpegable
2009-03-30 16:15 . 2009-03-30 16:15 47104 ------w c:\windows\AKDeInstall.exe
2009-03-30 16:12 . 2009-03-30 16:12 -------- d-----w c:\program files\GRETECH
2009-03-30 16:10 . 2009-03-30 16:10 -------- d-----w c:\program files\Webteh
2009-03-30 16:09 . 2009-03-30 16:08 -------- d-----w c:\program files\Common Files\ACD Systems
2009-03-30 16:08 . 2009-03-30 16:08 -------- d-----w c:\program files\ACD Systems
2009-03-30 15:27 . 2009-03-30 15:27 -------- d-----w c:\program files\microsoft frontpage
2009-03-30 15:26 . 2001-09-19 12:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-03-30 15:24 . 2009-03-30 15:24 22144 ----a-w c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{006b4e79-a789-44cd-bbf0-2d53da2357f2}]
2009-05-09 00:00 143872 ----a-w c:\windows\system32\hfdlrxuc.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e430eae4-bae5-4d17-be3b-7447045f1f59}]
2001-09-19 12:00 102912 ----a-w c:\windows\system32\zsgqrfg.dll
c:\documents and settings\All Users\çں‍ê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-3-30 191488]
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2009-4-25 11127296]
REALTEK RTL8187 Wireless LAN Utility.lnk - c:\program files\REALTEK RTL8187 Wireless LAN Driver and Utility\RtWLan.exe [2009-3-30 737280]
SnagIt 9.lnk - c:\program files\TechSmith\SnagIt 9\SnagIt32.exe [2008-9-22 6825288]
«©م، ¢¬نïé Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe"=
"c:\\Program Files\\TechSmith\\SnagIt 9\\SnagIt32.exe"=
"c:\\Program Files\\REALTEK RTL8187 Wireless LAN Driver and Utility\\RtWLan.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\Windows Live\\WLLoginProxy.exe"=
"c:\\WINDOWS\\system32\\CF14430.exe"=
"c:\\Program Files\\Atheros\\ACU.exe"=
R0 lzkvowor;lzkvowor;c:\windows\system32\drivers\lzkvowor.sys [19/09/2001 03:00 م 23424]
R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\nrlqjn.sys --> c:\windows\system32\drivers\nrlqjn.sys [?]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [14/01/2008 01:06 م 21632]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [30/03/2009 10:51 م 194304]
S1 452fbfd3;452fbfd3;c:\windows\system32\drivers\452fbfd3.sys [08/05/2009 01:14 ص 0]
S1 8293c0c8;8293c0c8;c:\windows\system32\drivers\8293c0c8.sys [05/05/2009 04:11 ص 0]
S2 ekrn;ESET Service;"c:\program files\ESET\ESET Smart Security\ekrn.exe" --> c:\program files\ESET\ESET Smart Security\ekrn.exe [?]
S2 histg;HIstg;c:\windows\System32\svchost.exe -k netsvcs [04/08/2004 12:56 ص 14336]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [19/09/2001 03:00 م 3584]
.
Contents of the 'Scheduled Tasks' folder
2009-05-09 c:\windows\Tasks\A81A586E91A9D47A.job
- c:\docume~1\user\applic~1\funkch~1\BOOB ONLINE SAFE.exe [2009-05-08 05:08]
2009-05-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 10:42]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)

.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Connection Wizard,ShellNext = iexplore
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {7253A666-804A-1107-A4DC-00E04C504781} - hxxp://66.228.123.202/bmc.cab
DPF: {9E45BE3C-DE06-4492-AB7D-E51447CF2ED0} - hxxp://75.126.208.164/imscp/talka.cab
DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} - hxxp://69.65.39.45/ReadUid.CAB
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Rootkit scan 2009-05-09 03:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...

c:\docume~1\user\LOCALS~1\Temp\Perflib_Perfdata_954.dat 16384 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-507921405-1844823847-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c*t*t* \OpenWithList]
@Class="Shell"
"a"="NOTEPAD.EXE"
"MRUList"="a"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(616)
c:\windows\system32\athgina.dll
c:\windows\system32\athcfg11.dll
c:\windows\system32\athcfg11Res.dll
- - - - - - - > 'explorer.exe'(2896)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\slserv.exe
c:\program files\Common Files\Real\Update_OB\realsched.exe
c:\program files\Java\jre1.6.0_04\bin\jusched.exe
c:\windows\SOUNDMAN.EXE
c:\program files\Messenger\msmsgs.exe
c:\program files\ManyCam 2.3\ManyCam.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\program files\TechSmith\SnagIt 9\TscHelp.exe
c:\program files\TechSmith\SnagIt 9\SnagPriv.exe
c:\program files\TechSmith\SnagIt 9\SnagItEditor.exe
c:\docume~1\user\LOCALS~1\Temp\winxoglb.exe
c:\docume~1\user\LOCALS~1\Temp\wincpflr.exe
.
**************************************************************************
.
Completion time: 2009-05-09 3:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-09 00:10
Pre-Run: 15,219,822,592 bytes free
Post-Run: 15,260,241,920 bytes free
253
 
ادخل هذه الصفحة

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


وحمل اداة المكافي
شغلها بدبل كلك واتركها حتى تنتهي صفحة الدوس من الفحص والتنظيف
ثم توجه الى القرص c ،، وقم
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
التقرير noor_mcafee
وارفعه على هذا الموقع

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


وارفق رابط التحميل بمشاركتك القادمة
 
آخوي ممكن رآبط ثآني لاآدآهـ المكآفي لان الرآبط اللي عطيتنى لايعمل
 
آخوي ممكن رآبط ثآني لاآدآهـ المكآفي لان الرآبط اللي عطيتنى لايعمل

أخي اي رابط أداة ؟ ...

الأستاذ ماكس قالك تدخل على موقع و تحمل أول أداة تشوفها ...

<< المكافي ...

و بعدها تابع شرحه ...
 
توقيع : MMA_LORD_735
أخي اي رابط أداة ؟ ...

الأستاذ ماكس قالك تدخل على موقع و تحمل أول أداة تشوفها ...

<< المكافي ...

و بعدها تابع شرحه ...
رآبط الصفحـة لانهآ لاتعمل ~:no:
 
كيف ما يفتح أخي ؟

ماذا يظهر لك ؟

و هل فقط الصفحة لا تظهر لك ؟

يعني يوجد مشكلة بصفحة آخر ؟
 
توقيع : MMA_LORD_735
كيف ما يفتح أخي ؟

ماذا يظهر لك ؟

و هل فقط الصفحة لا تظهر لك ؟

يعني يوجد مشكلة بصفحة آخر ؟

تطول ماتفتح الصفحة ,بس هذى الصفحة :er:
 
توقيع : MMA_LORD_735
توقيع : MMA_LORD_735
عودة
أعلى