عندك أصابات كثيره
قم بعمل التالي
عطل جميع برامج الحمايه >>> تأكد من وقت وتاريخ الجهاز
>>> لاتغير اسم الاداة واحفظها على سطح المكتب
وحمل هذه الاداة واحفظها على سطح المكتب
عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
انتظر حتى الاداة تنتهي من فحص جهازك ,,, وبشكل تلقائي يعاد تشغيل جهازك ,,
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
انتظر حتى يظهر لك تقرير ,, انسخه والصقه بردك القادم
وهذا طلبك
ComboFix 09-05-12.06 - XPPRESP3 05/13/2009 12:29.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.1022.636 [GMT 3:00]
Running from: c:\documents and settings\XPPRESP3\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\cmsetac.dll
c:\windows\KB8888239.log
c:\windows\ntdtcstp.dll
.
---- Previous Run -------
.
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\cfxer.exe
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.MSNFix
c:\windows\cmsetac.dll
c:\windows\IE4 Error Log.txt
c:\windows\KB8888239.log
c:\windows\ntdtcstp.dll
c:\windows\system32\msconfig.exe
c:\windows\winsystem.exe
.
((((((((((((((((((((((((( Files Created from 2009-04-13 to 2009-05-13 )))))))))))))))))))))))))))))))
.
2009-05-12 19:01 . 2009-05-12 19:01 33994 ----a-w c:\windows\system32\iemultjx.exe
2009-05-11 19:28 . 2009-05-11 19:28 -------- d-sh--w c:\documents and settings\Remo0o\PrivacIE
2009-05-11 19:27 . 2009-05-11 19:27 -------- d-sh--w c:\documents and settings\Remo0o\IETldCache
2009-05-11 18:44 . 2009-05-11 18:44 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-05-11 18:42 . 2009-05-11 18:42 -------- d-----w c:\program files\Windows Live SkyDrive
2009-05-11 17:41 . 2009-05-11 17:41 -------- d-sh--w c:\documents and settings\XPPRESP3\PrivacIE
2009-05-11 17:40 . 2009-05-11 17:40 -------- d-sh--w c:\documents and settings\XPPRESP3\IECompatCache
2009-05-11 17:39 . 2009-05-11 17:39 -------- d-sh--w c:\documents and settings\XPPRESP3\IETldCache
2009-05-11 17:35 . 2009-05-11 17:35 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-05-11 17:29 . 2009-05-11 17:30 -------- dc-h--w c:\windows\ie8
2009-05-11 17:27 . 2008-02-26 11:59 294912 -c----w c:\windows\system32\dllcache\msctf.dll
2009-05-11 10:45 . 2009-05-11 10:45 -------- d-----w c:\documents and settings\Remo0o\Application Data\Media Player Classic
2009-05-10 11:23 . 2009-05-10 11:23 230 ----a-w c:\documents and settings\XPPRESP3\vmscon.bat
2009-05-10 11:22 . 2009-05-10 11:22 34410 ----a-w c:\windows\system32\vmscon.exe
2009-05-10 11:22 . 2009-05-10 11:22 34410 ----a-w c:\documents and settings\XPPRESP3\vmscon.exe
2009-05-08 11:01 . 2009-05-08 11:01 -------- d-----w C:\spacetoon_interactive
2009-05-06 12:34 . 2009-05-07 21:59 30872 ----a-w c:\documents and settings\Remo0o\mscup3.exe
2009-05-06 10:50 . 2009-05-06 12:13 30550 ----a-w c:\documents and settings\XPPRESP3\mscup3.exe
2009-05-04 10:24 . 2009-05-04 10:24 -------- d-----w c:\documents and settings\XPPRESP3\Application Data\DisplayTune
2009-05-04 10:23 . 2009-05-04 10:23 -------- d-----w c:\documents and settings\Remo0o\Application Data\DisplayTune
2009-05-01 10:44 . 2009-05-02 17:08 30270 ----a-w c:\documents and settings\XPPRESP3\mscup1.exe
2009-05-01 09:42 . 2009-05-13 09:55 31242 ----a-w c:\documents and settings\XPPRESP3\mscup2.exe
2009-04-22 08:26 . 2009-04-22 08:26 -------- d-----w c:\documents and settings\Remo0o\Local Settings\Application Data\PunkBuster
2009-04-21 20:55 . 2009-05-13 09:54 19968 ----a-w c:\documents and settings\XPPRESP3\tvs2.exe
2009-04-21 16:03 . 2009-05-12 13:23 30872 ----a-w c:\documents and settings\Remo0o\mscup2.exe
2009-04-19 12:18 . 2009-05-12 13:24 8552 ----a-w c:\documents and settings\Remo0o\bv2.exe
2009-04-19 08:11 . 2009-05-13 09:54 33994 ----a-w c:\windows\system32\bv2.exe
2009-04-18 11:39 . 2009-04-19 08:54 30276 ----a-w c:\documents and settings\XPPRESP3\mscupdate2.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-13 10:27 . 2009-03-11 23:20 -------- d-----w c:\program files\BitComet
2009-05-13 10:23 . 2009-02-23 18:18 -------- d-----w c:\program files\Yahoo!
2009-05-12 20:06 . 2009-02-28 15:22 138168 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-05-12 20:06 . 2009-02-28 15:21 189472 ----a-w c:\windows\system32\PnkBstrB.exe
2009-05-12 13:24 . 2009-03-20 10:38 33522 ----a-w c:\documents and settings\Remo0o\iemultjx.exe
2009-05-12 13:24 . 2009-03-27 07:38 34410 ----a-w c:\documents and settings\Remo0o\vmscon.exe
2009-05-12 13:24 . 2009-03-21 12:38 19968 ----a-w c:\documents and settings\Remo0o\tvs2.exe
2009-05-11 18:45 . 2009-03-17 17:21 -------- d-----w c:\program files\Windows Live
2009-05-03 20:33 . 2009-02-24 06:33 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-03 20:33 . 2009-05-03 20:33 -------- d-----w c:\program files\Common Files\Portrait Displays
2009-05-03 20:33 . 2009-05-03 20:33 -------- d-----w c:\program files\Portrait Displays
2009-05-02 17:08 . 2009-03-20 16:47 30270 ----a-w c:\documents and settings\XPPRESP3\mscupdate.exe
2009-04-19 14:32 . 2009-03-21 12:37 30276 ----a-w c:\documents and settings\Remo0o\mscupdate.exe
2009-04-05 11:57 . 2009-03-21 12:37 33762 ----a-w c:\documents and settings\Remo0o\cmgrs.exe
2009-04-04 18:29 . 2009-04-04 18:29 -------- d-----w c:\program files\microsoft frontpage
2009-03-31 11:27 . 2009-02-24 20:33 -------- d-----w c:\program files\GameSpy Arcade
2009-03-30 16:09 . 2009-03-17 12:54 18312 ----a-w c:\documents and settings\Remo0o\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-26 14:08 . 2004-07-17 20:36 163644 ----a-w c:\windows\system32\drivers\secdrv.sys
2009-03-26 13:32 . 2009-03-26 13:32 -------- d-----w c:\program files\Activision
2009-03-26 07:25 . 2009-02-28 15:20 75064 ----a-w c:\windows\system32\PnkBstrA.exe
2009-03-17 19:01 . 2009-02-28 11:43 18312 ----a-w c:\documents and settings\XPPRESP3\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-17 17:27 . 2009-03-17 17:27 -------- d-----w c:\program files\Microsoft Silverlight
2009-03-17 17:27 . 2009-03-17 17:22 -------- d-----w c:\program files\Microsoft
2009-03-17 17:24 . 2009-03-17 17:24 -------- d-----w c:\program files\Microsoft Sync Framework
2009-03-17 14:50 . 2009-03-17 14:50 -------- d-----w c:\program files\Common Files\Windows Live
2009-03-16 14:01 . 2009-03-16 14:01 -------- d-----w c:\program files\HitFixer
2009-03-16 14:00 . 2009-03-16 14:00 -------- d-----w c:\program files\AutoHotkey
2009-03-15 10:51 . 2009-02-28 13:32 -------- d-----w c:\program files\Hotspot Shield
2009-03-08 01:34 . 2005-10-21 03:38 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 01:34 . 2004-08-04 09:56 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 01:33 . 2004-08-04 09:56 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 01:33 . 2004-08-04 09:56 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 01:32 . 2004-08-04 09:56 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 01:32 . 2004-08-04 09:56 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 01:31 . 2004-08-04 09:56 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 01:31 . 2004-08-04 09:56 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 01:31 . 2004-08-04 09:56 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 01:22 . 2001-08-23 14:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-04 22:57 . 2009-03-04 22:57 2560 ----a-w c:\windows\_MSRSTRT.EXE
2009-03-02 13:22 . 2009-03-02 13:22 81920 ----a-w c:\windows\system32\W32N50.DLL
2009-03-02 13:22 . 2009-03-02 13:22 17134 ----a-w c:\windows\system32\PCANDIS5.SYS
2009-02-24 08:53 . 2003-03-19 06:14 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-02-23 18:15 . 2009-02-23 18:15 2806 ----a-w c:\windows\mozver.dat
2009-02-23 18:07 . 2009-02-23 18:07 110592 ----a-w c:\windows\mstwain34.exe
2009-02-23 18:06 . 2001-08-23 14:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-02-23 18:04 . 2009-02-23 18:04 21640 ----a-w c:\windows\system32\emptyregdb.dat
.
------- Sigcheck -------
[-] 2005-12-19 17:49 1580544 784DDC1F40C4F729284D5A73930F0C9D c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{271CE47E-CAFF-4A35-A6DD-C0CE906898AA}]
2008-01-25 14:24 2359296 ----a-w c:\program files\M5zn Toolbar\m5zn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2005-07-27 61952]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904]
"BitComet"="c:\program files\BitComet\BitComet.exe" [2009-03-09 2564408]
"mstwain34"="c:\windows\mstwain34.exe" [2009-02-23 110592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-11 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-11 81920]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"DT HPW"="c:\program files\Portrait Displays\HP My Display\DTHtml.exe" [2007-06-29 278528]
"iemultjx"="c:\windows\system32\iemultjx.exe" [2009-05-12 33994]
"vmscon"="c:\windows\system32\vmscon.exe" [2009-05-10 34410]
"bv2"="c:\windows\system32\bv2.exe" [2009-05-13 33994]
"C-Media Mixer"="Mixer.exe" - c:\windows\mixer.exe [2003-03-20 1855488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-05-11 1626112]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-04 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"nlhr"="c:\windows\System32\AdvPack.Dll" [2009-03-08 128512]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18160:TCP"= 18160:TCP:BitComet 18160 TCP
"18160:UDP"= 18160:UDP:BitComet 18160 UDP
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-03-17 55152]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 RTL8187B;TG123g USB Wireless Adapter;c:\windows\system32\drivers\RTL8187B.sys [2009-03-02 264576]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - HELPSVC
NETSVCS REQUIRES REPAIRS - current entries shown
6to4
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
ERSvc
EventSystem
FastUserSwitchingCompatibility
HidServ
Ias
Iprip
Irmon
LanmanServer
LanmanWorkstation
Netman
Nla
NWCWorkstation
Nwsapagent
Rasauto
Rasman
Remoteaccess
Schedule
Seclogon
SENS
Sharedaccess
SRService
Tapisrv
Themes
TrkWks
WZCSVC
Wmi
WmdmPmSp
winmgmt
xmlprov
BITS
wuauserv
ShellHWDetection
WmdmPmSN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{02bc39de-0599-11de-bf1b-001b2f34d8d5}]
\sheLL\AUtOplaY\ComManD - K:\jgnio.exe
\sheLL\AutoRun\command - K:\jgnio.exe
\sheLL\expLore\CoMMANd - K:\jgnio.exe
\sheLL\oPen\coMMAND - K:\jgnio.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-05-13 c:\windows\Tasks\User_Feed_Synchronization-{1BB56199-1F88-478B-A52B-58EBD7FA81DC}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 01:31]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-12CFG914-K641-26SF-N32P - c:\recycler\S-1-5-21-0243336031-4052116379-881863308-0851\vse432.exe
HKLM-Run-Windows API Control Center - winsystem.exe
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-13 12:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1568)
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Common Files\Portrait Displays\Shared\DTSRVC.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Portrait Displays\Shared\HookManager.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Windows Live\Toolbar\wltuser.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2009-05-13 12:34 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-13 09:33
Pre-Run: 54,058,213,376 bytes free
Post-Run: 54,527,180,800 bytes free
286