تفضل الله يجزيك الخير
والبرنامج حذف تلاقئيا
بس لي سؤال يا غانم انا مركب الكاسبر سيكورتي نسخه 8.0.0.506
والتصفح والجهاز بطيءين جدا فما السبب بارك الله فيك
ComboFix 09-05-17.05 - MN 05/19/2009 4:39.2 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.383.217 [GMT 3:00]
Running from: c:\documents and settings\MN\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\sqlite3.dll
.
((((((((((((((((((((((((( Files Created from 2009-04-19 to 2009-05-19 )))))))))))))))))))))))))))))))
.
2009-05-18 23:29 . 2009-05-18 23:29 -------- d-----w c:\program files\Yahoo!
2009-05-18 23:28 . 2009-05-18 23:28 -------- d-----w c:\program files\CCleaner
2009-05-18 23:24 . 2009-05-18 23:24 -------- d-----w c:\documents and settings\MN\Application Data\CyberScrub
2009-05-18 23:23 . 2009-05-18 23:23 -------- d-----w c:\documents and settings\MN\Application Data\cleaner
2009-05-18 09:23 . 2009-05-18 09:23 -------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-05-18 05:46 . 2009-05-18 05:46 -------- d-----w c:\windows\system32\CatRoot_bak
2009-05-18 05:41 . 2008-10-24 10:10 453632 ------w c:\windows\system32\dllcache\mrxsmb.sys
2009-05-18 05:40 . 2009-05-18 05:40 -------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-05-18 04:44 . 2008-06-13 12:10 272128 ------w c:\windows\system32\dllcache\bthport.sys
2009-05-18 04:44 . 2008-06-13 12:10 272128 ------w c:\windows\system32\drivers\bthport.sys
2009-05-17 19:33 . 2009-02-06 16:22 2136064 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-05-17 19:33 . 2009-02-06 16:24 2180480 ------w c:\windows\system32\dllcache\ntoskrnl.exe
2009-05-17 19:33 . 2009-02-06 15:49 2015744 ------w c:\windows\system32\dllcache\ntkrpamp.exe
2009-05-17 19:33 . 2009-02-06 15:49 2057728 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-05-17 19:10 . 2008-07-09 06:38 26488 ----a-w c:\windows\system32\spupdsvc.exe
2009-05-17 19:10 . 2009-05-17 19:10 -------- d--h--w c:\windows\$hf_mig$
2009-05-17 19:08 . 2009-05-17 19:08 -------- d-----w c:\documents and settings\MN\Local Settings\Application Data\Adobe
2009-05-17 19:06 . 2009-05-17 19:06 -------- d-----w c:\program files\Common Files\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-19 01:36 . 2009-05-17 17:55 32 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-19 01:36 . 2009-05-17 17:55 32 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-19 01:36 . 2009-05-17 17:55 32 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-19 01:36 . 2009-05-17 17:55 32 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-18 23:35 . 2009-05-18 23:17 28 ----a-w c:\windows\liccyval.dat
2009-05-17 18:51 . 2009-05-17 18:51 -------- d-----w c:\program files\Circle Developement
2009-05-17 18:51 . 2009-05-17 18:51 -------- d-----w c:\program files\Windows Live
2009-05-17 18:51 . 2009-05-17 18:51 -------- d-----w c:\program files\Messenger Plus! Live
2009-05-17 18:51 . 2009-05-17 18:51 94632 ----a-w c:\documents and settings\MN\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-17 18:40 . 2009-05-17 18:40 -------- d-----w c:\program files\Microsoft.NET
2009-05-17 18:38 . 2009-05-17 18:38 -------- d-----w c:\program files\Microsoft Works
2009-05-17 18:24 . 2008-01-29 14:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-05-17 18:24 . 2009-05-17 17:56 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-05-17 18:24 . 2009-05-17 17:56 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-05-17 18:04 . 2009-05-17 18:04 -------- d-----w c:\program files\Common Files\xing shared
2009-05-17 18:04 . 2009-05-17 18:04 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-05-17 18:04 . 2009-05-17 18:04 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-05-17 18:04 . 2009-05-17 18:04 -------- d-----w c:\program files\Common Files\Real
2009-05-17 18:04 . 2009-05-17 18:04 -------- d-----w c:\program files\Google
2009-05-17 18:04 . 2009-05-17 18:04 -------- d-----w c:\program files\Real
2009-05-17 18:03 . 2009-05-17 18:03 -------- d-----w c:\program files\microsoft frontpage
2009-05-17 17:59 . 2009-05-17 17:59 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-05-17 17:55 . 2009-05-17 17:55 -------- d-----w c:\program files\Kaspersky Lab
2009-05-17 17:45 . 2009-05-17 17:45 -------- d-----w c:\program files\Internet Download Manager
2009-05-17 17:45 . 2009-05-17 17:45 -------- d-----w c:\program files\Quranzu1
2009-05-17 17:42 . 2009-05-17 17:42 -------- d-----w c:\program files\Your Uninstaller 2008
2009-05-17 17:38 . 2009-05-17 17:38 -------- d-----w c:\program files\MSN Messenger
2009-03-06 13:44 . 2004-05-23 09:00 283648 ----a-w c:\windows\system32\pdh.dll
2009-02-20 07:30 . 2004-05-23 09:00 81920 ----a-w c:\windows\system32\ieencode.dll
2009-02-20 07:30 . 2004-05-23 09:00 659456 ----a-w c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-05-23 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-05-17 206088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-17 185872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"C2K"="c:\windows\CYB2K.EXE" [2007-01-20 3342336]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-05-23 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\Cyb2k.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [1/29/2008 5:29 PM 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [3/13/2008 6:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [4/30/2008 5:06 PM 24592]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.jo/
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
LSP: c:\windows\system32\lspcs.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-19 04:42
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(988)
c:\windows\system32\lspcs.dll
- - - - - - - > 'explorer.exe'(3336)
c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\MSVCR80.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
Completion time: 2009-05-19 4:44
ComboFix-quarantined-files.txt 2009-05-19 01:44
Pre-Run: 4,014,194,688 bytes free
Post-Run: 4,004,315,136 bytes free
131 --- E O F --- 2009-05-18 08:44