• بادئ الموضوع بادئ الموضوع fhdd
  • تاريخ البدء تاريخ البدء
  • المشاهدات 961

fhdd

زيزوومي جديد
إنضم
12 ديسمبر 2007
المشاركات
17
مستوى التفاعل
0
النقاط
20
الإقامة
بب
غير متصل
عندي برنامج محول الصوتيات 8 كان شغال وقبل يومين عندما اريد ان افتحه لا يفتح فما الحل
ملاحظة فتحت ادارة المهام فوجدت جانب محول الصوتيات عدم استجابة
 

هل تظهر لك رسالة خطأ ؟
هل جربت حذفه واعادة تثبيته ؟
 
لا يظهر شئ
نعم حذفته واعدت تثبيته ولم يعمل
 
حمل هذا البرنامج
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

شغل البرنامج ==> واضغط على
Do a system scan and save log
لحظات .. ويظهر لك تقرير داخل المفكرة==> انسخه والصقه بردك القادم
 
التعديل الأخير بواسطة المشرف:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:28:06 م, on 02/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetTimer 2000\NetTimer.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Quick Button NT\QuickPB.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Ozone\Audio Converter\mediaco.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [UVS12 Preload] C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NetTimer 2000] "C:\Program Files\NetTimer 2000\NetTimer.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: QuickPB.exe.lnk = C:\Program Files\Quick Button NT\QuickPB.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: إضافة إلى حاجب إعلان الشعار - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: ت&صدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى FLV بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: إحصائيات حماية حركة زيارة الويب - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: تدوين هذا في المدونة - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &تدوين هذا في Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 9564 bytes
 
عطل برامج الحماية عن العمل
ثم
حمل الاداة التالية واحفظها على سطح المكتب
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
لا تقم بتشغيل اي برنامج ،، ومهما طالت عملية الفحص انتظر حتى تنتهي
انتظر حتى يظهر لك تقرير ،،انسخه والصقه بمشاركتك القادمة
 
ComboFix 09-06-01.03 - ahmad 06/04/2009 13:34.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.963.1025.18.503.212 [GMT 3:00]
Running from: c:\documents and settings\ahmad\سطح المكتب\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-05-04 to 2009-06-04 )))))))))))))))))))))))))))))))
.
2009-06-01 13:36 . 2009-06-01 13:36 -------- d-----w- c:\program files\Ozone
2009-06-01 13:02 . 2009-06-01 13:02 -------- d-----w- c:\program files\Trend Micro
2009-06-01 09:15 . 1998-09-02 08:28 38160 ----a-w- c:\windows\system32\LMRTREND.dll
2009-06-01 09:15 . 1998-08-27 04:51 182032 ----a-w- c:\windows\system32\dxtmsft3.dll
2009-06-01 09:15 . 1998-09-02 08:28 63488 ----a-w- c:\windows\system32\unam4ie.exe
2009-06-01 09:14 . 1998-08-17 09:21 10240 ----a-w- c:\windows\system32\vidx16.dll
2009-06-01 09:14 . 1998-08-17 09:21 11776 ----a-w- c:\windows\system32\mciqtz.drv
2009-06-01 09:14 . 1998-09-02 08:02 194320 ----a-w- c:\windows\system32\qcut.dll
2009-06-01 09:14 . 2009-06-01 09:14 4608 ----a-w- c:\windows\system32\w95inf32.dll
2009-06-01 09:14 . 2009-06-01 09:14 2272 ----a-w- c:\windows\system32\w95inf16.dll
2009-06-01 09:13 . 2009-06-01 09:13 -------- d-----w- c:\program files\Auralog
2009-05-28 12:00 . 2009-06-01 13:37 18628608 ----a-w- c:\windows\system32\viscomavi.dll
2009-05-28 11:59 . 2009-06-01 13:37 237568 ----a-w- c:\windows\system32\lame_enc.dll
2009-05-13 12:49 . 2009-05-13 12:49 -------- d-----w- c:\program files\CequenzeTech
2009-05-11 11:08 . 2009-05-11 11:08 -------- d-----w- c:\documents and settings\ahmad\Library
2009-05-11 11:08 . 2009-05-11 11:08 -------- d-----w- c:\documents and settings\ahmad\Application Data\com.adobe.ExMan
2009-05-10 12:11 . 2009-05-10 12:11 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\FLEXnet
2009-05-10 11:56 . 2009-05-10 11:56 -------- d-----w- c:\program files\Adobe Media Player
2009-05-10 11:51 . 2009-05-10 11:51 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-05-10 11:43 . 2009-05-10 11:43 -------- d-----w- c:\program files\Common Files\Macrovision Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-04 10:37 . 2001-09-19 14:00 391262 ----a-w- c:\windows\system32\perfh001.dat
2009-06-04 10:37 . 2001-09-19 14:00 75896 ----a-w- c:\windows\system32\perfc001.dat
2009-06-04 10:32 . 2009-04-20 16:35 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2009-06-04 10:30 . 2009-04-20 16:35 565280 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-04 10:30 . 2009-04-20 16:35 4060 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-04 10:30 . 2009-04-20 16:35 2928160 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-04 10:30 . 2009-04-20 16:35 25004 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-03 11:41 . 2009-01-18 15:45 -------- d-----w- c:\documents and settings\ahmad\Application Data\DMCache
2009-06-03 11:12 . 2009-02-03 12:13 -------- d-----w- c:\program files\NetTimer 2000
2009-05-28 10:20 . 2009-01-18 15:31 -------- d---a-w- c:\docume~1\ALLUSE~1\APPLIC~1\TEMP
2009-05-26 12:04 . 2009-04-20 16:36 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-26 12:04 . 2009-04-20 16:36 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-24 12:44 . 2009-02-13 12:02 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Apple Computer
2009-05-23 13:03 . 2009-01-18 16:09 -------- d-----w- c:\documents and settings\ahmad\Application Data\PC Suite
2009-05-19 11:40 . 2009-01-18 16:05 -------- d-----w- c:\program files\AnMing
2009-05-11 10:35 . 2009-01-18 14:17 -------- d-----w- c:\program files\Quick Button NT
2009-05-10 12:15 . 2009-01-20 13:09 136848 ----a-w- c:\documents and settings\ahmad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-10 11:59 . 2009-02-19 13:19 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-03 10:51 . 2009-05-01 19:35 -------- d-----w- c:\program files\AlbaniV2
2009-05-02 11:16 . 2009-03-15 15:47 -------- d-----w- c:\documents and settings\ahmad\Application Data\Ulead Systems
2009-05-02 11:05 . 2009-05-02 11:05 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\InterVideo
2009-05-02 11:04 . 2009-01-18 14:06 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-02 11:04 . 2009-05-02 11:02 -------- d-----w- c:\program files\Common Files\Ulead Systems
2009-05-02 11:02 . 2009-03-15 14:41 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Ulead Systems
2009-05-02 11:02 . 2009-05-02 10:59 -------- d-----w- c:\program files\Corel
2009-05-02 10:59 . 2009-05-02 10:59 -------- d-----w- c:\documents and settings\ahmad\Application Data\InstallShield
2009-05-01 21:15 . 2009-03-06 18:20 -------- d-----w- c:\program files\Ashampoo
2009-05-01 19:58 . 2009-05-01 19:22 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-05-01 19:51 . 2009-03-15 14:35 -------- d-----w- c:\program files\Ulead Systems
2009-05-01 19:34 . 2009-05-01 19:34 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-01 12:33 . 2009-01-18 15:45 -------- d-----w- c:\documents and settings\ahmad\Application Data\IDM
2009-05-01 12:32 . 2009-01-18 15:45 -------- d-----w- c:\program files\Internet Download Manager
2009-04-21 11:17 . 2008-01-29 14:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-04-20 17:10 . 2009-04-20 17:10 -------- d-----w- c:\documents and settings\ahmad\Application Data\Windows Live Writer
2009-04-20 17:02 . 2009-01-18 16:20 -------- d-----w- c:\program files\Kaspersky Lab
2009-04-20 16:18 . 2009-04-01 11:38 -------- d-----w- c:\program files\Windows Live
2009-04-20 16:17 . 2009-04-20 16:17 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-04-20 16:16 . 2009-04-20 16:16 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-04-18 11:13 . 2009-01-18 15:57 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-04-15 13:13 . 2009-04-15 13:13 -------- d-----w- c:\program files\Common Files\xing shared
2009-04-15 13:12 . 2009-01-18 16:03 -------- d-----w- c:\program files\Common Files\Real
2009-04-15 13:12 . 2009-01-18 15:21 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-04-13 14:16 . 2009-01-18 14:48 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Microsoft Help
2009-04-07 11:07 . 2009-04-07 11:07 -------- d-----w- c:\documents and settings\ahmad\Application Data\Transcend
2009-03-26 15:35 . 2009-04-29 12:20 210352 ----a-w- c:\windows\system32\idmmbc.dll
2009-03-24 13:55 . 2009-01-18 15:55 29480 ----a-w- c:\windows\system32\msxml3a.dll
2009-03-24 13:55 . 2009-01-18 15:21 353576 ----a-w- c:\windows\system32\msvcr71.dll
2009-03-14 11:52 . 2009-03-14 11:52 63488 ----a-w- c:\windows\xobglu16.dll
2009-03-14 11:52 . 2009-03-14 11:52 23552 ----a-w- c:\windows\xobglu32.dll
2009-03-12 13:15 . 2009-02-25 15:58 450560 ----a-w- c:\windows\system32\maai.dll
2009-03-12 13:15 . 2009-02-25 15:58 1040384 ----a-w- c:\windows\system32\maah.dll
2009-03-12 13:15 . 2009-02-25 15:58 835584 ----a-w- c:\windows\system32\maae.dll
2009-03-12 13:15 . 2009-02-25 15:58 729088 ----a-w- c:\windows\system32\maad.dll
2009-03-12 13:15 . 2009-02-25 15:58 335872 ----a-w- c:\windows\system32\maac.dll
2009-03-12 13:15 . 2009-02-25 15:58 315392 ----a-w- c:\windows\system32\maab.dll
2009-03-12 13:15 . 2009-02-25 15:58 311296 ----a-w- c:\windows\system32\maaf.dll
2009-03-08 01:34 . 2008-04-14 10:29 914944 ----a-w- c:\windows\system32\wininet.dll
2009-03-08 01:34 . 2008-04-14 10:29 43008 ----a-w- c:\windows\system32\licmgr10.dll
2009-03-08 01:33 . 2008-04-14 10:29 18944 ----a-w- c:\windows\system32\corpol.dll
2009-03-08 01:33 . 2008-04-14 10:29 420352 ----a-w- c:\windows\system32\vbscript.dll
2009-03-08 01:32 . 2008-04-14 10:29 72704 ----a-w- c:\windows\system32\admparse.dll
2009-03-08 01:32 . 2008-04-14 10:29 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-03-08 01:31 . 2008-04-14 10:29 34816 ----a-w- c:\windows\system32\imgutil.dll
2009-03-08 01:31 . 2008-04-14 10:05 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-03-08 01:31 . 2008-04-14 10:29 45568 ----a-w- c:\windows\system32\mshta.exe
2009-03-08 01:22 . 2001-09-19 14:00 156160 ----a-w- c:\windows\system32\msls31.dll
2009-03-06 14:20 . 2008-04-14 10:29 283136 ----a-w- c:\windows\system32\pdh.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-04_10.17.38 )))))))))))))))))))))))))))))))))))))))))
.
- 2001-09-19 14:00 . 2009-06-03 11:11 75792 c:\windows\system32\perfc009.dat
+ 2001-09-19 14:00 . 2009-06-04 10:37 75792 c:\windows\system32\perfc009.dat
+ 2001-09-19 14:00 . 2009-06-04 10:37 457138 c:\windows\system32\perfh009.dat
- 2001-09-19 14:00 . 2009-06-03 11:11 457138 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"NetTimer 2000"="c:\program files\NetTimer 2000\NetTimer.exe" [2001-09-08 788992]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2003-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2003-01-23 114688]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-03-20 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-03-20 634880]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-04-21 206088]
"UVS12 Preload"="c:\program files\Corel\Corel VideoStudio 12\uvPL.exe" [2009-04-10 393216]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-15 198160]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-11-15 77824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\ahmad\çں‍ê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
QuickPB.exe.lnk - c:\program files\Quick Button NT\QuickPB.exe [2009-1-18 802816]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ComPlusSetup]
2008-04-14 10:29 625664 ----a-w- c:\windows\system32\catsrvut.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"OPSE reminder"="c:\program files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "c:\program files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"BDRegion"=c:\program files\Cyberlink\Shared Files\brs.exe
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe"
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 05:29 م 33808]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [27/06/2008 05:50 م 61424]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [18/01/2009 06:57 م 603904]
R3 {5C8B2B62-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-A;c:\windows\system32\drivers\a311.sys [18/01/2009 05:09 م 31799]
R3 {5C8B2B65-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-B;c:\windows\system32\drivers\a310.sys [18/01/2009 05:09 م 33335]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 06:02 م 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 05:06 م 24592]
S3 PortTalk;PortTalk; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/ig?hl=ar
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: إضافة إلى حاجب إعلان الشعار - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} - hxxp://www.qurancomplex.com/Downloads/FontSmooth.cab
FF - ProfilePath - c:\docume~1\ahmad\APPLIC~1\Mozilla\Firefox\Profiles\1lpwxvth.default\
FF - prefs.js: browser.startup.homepage - hxxp://scs-net.org/portal/
FF - prefs.js: network.proxy.ftp - proxy.scs-net.org
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - proxy.scs-net.org
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - proxy.scs-net.org
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - proxy.scs-net.org
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - proxy.scs-net.org
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 1
FF - component: c:\documents and settings\ahmad\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: content.notify.interval - 750000
FF - user.js: content.max.tokenizing.time - 2250000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Rootkit scan 2009-06-04 13:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-854245398-746137067-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*n*b*u*)* \OpenWithList]
@Class="Shell"
"a"="ContentCopier.exe"
"MRUList"="a"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):87,58,b1,b2,90,25,0a,55,ec,c9,da,77,8a,96,cf,6e,66,ae,3b,b8,1a,
79,70,75,4c,f2,72,aa,79,44,3d,ce,a4,31,d6,85,04,c8,9f,81,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{afa1dba9-bf73-4184-8cb8-4473cb37fead}]
@Denied: (Full) (Everyone)
"Model"=dword:00000092
"Therad"=dword:00000021
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,98,07,ff,fc,5d,
df,1c,2f,3b,8a,0a,32,11,89,01,b5,4c,21,de,81,97,76,b9,7c,3a,9a,63,c8,7b,43,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1308)
c:\windows\system32\msi.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(812)
c:\windows\system32\SynTPFcs.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2009-06-04 13:58
ComboFix-quarantined-files.txt 2009-06-04 10:57
Pre-Run: 2,993,778,688 bytes free
Post-Run: 2,971,512,832 bytes free
271 --- E O F --- 2009-05-27 11:14
 
الافضل حذفه واعاد تثبيته بعد تحميل نسخة جديدة
 
هل لديك نسخة جديدة وشكرا
 
تفضل :

الملف يحتوي على البرنامج + الكراك

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


بالتوفيق

 
توقيع : king_man
الموقع لا يعمل
 
عودة
أعلى