تسلم يالغالي
وحلو حلو تمام عليك
البحث ظهرت الايوقانات الان بعد تحميلالاداة من جديد وتشغيلها
وباقي الرموز الانجليزية
اما البحث انتهت ولله الحمد المشكلة والفضل بعد الله يعود اليك اسأل الله لك التوفيق وان يحقق لك ماتريد ويفرج عنك من كرب الدنيا والاخرة ويرزقك السعادة بالدارين
التقرير :
ComboFix 09-05-31.06 - Free User 06/02/2009 20:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.1006.665 [GMT 3:00]
Running from: c:\documents and settings\Free User\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\mdm.exe
c:\windows\svchost.ini
c:\windows\system32\kakle.dll
c:\windows\system32\kr_done1
c:\windows\system32\msn_sl.exe.exe
c:\windows\system32\MSNTBUP.EXE.exe
c:\windows\system32\setting.ini
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
c:\windows\system32\winitn.dll
c:\windows\system32\x64
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_AVPsys
((((((((((((((((((((((((( Files Created from 2009-05-02 to 2009-06-02 )))))))))))))))))))))))))))))))
.
2009-05-31 19:46 . 2009-05-31 19:46 -------- d-----w- c:\documents and settings\Free User\Application Data\CyberScrub
2009-05-26 19:36 . 2009-05-26 19:57 -------- d-----w- c:\program files\Windows Media Connect 2
2009-05-26 19:31 . 2009-05-28 09:37 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-05-26 19:16 . 2006-07-28 22:22 51712 ----a-w- c:\windows\system32\coodest.dll
2009-05-26 19:16 . 2003-08-07 12:01 237568 ----a-w- c:\windows\system32\lame_enc.dll
2009-05-26 19:16 . 2005-05-19 00:17 40960 ----a-w- c:\windows\system32\osenxpsuite2005.dll
2009-05-26 19:16 . 2009-05-26 19:16 -------- d-----w- c:\windows\system32\RMBin
2009-05-26 19:16 . 2009-05-26 19:16 -------- d-----w- c:\program files\Ozone
2009-05-26 19:04 . 2009-05-26 19:04 390664 ----a-w- c:\documents and settings\Free User\Application Data\Real\RealPlayer\setup\AU_setup6.exe
2009-05-26 18:47 . 2009-05-26 18:47 390664 ----a-w- c:\documents and settings\Free User\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-26 18:32 . 2008-06-25 22:26 335104 ----a-r- c:\windows\system32\drivers\RTL8187B.sys
2009-05-14 05:46 . 2009-05-14 05:46 -------- d-----w- c:\documents and settings\Free User\Application Data\Microsoft Games
2009-05-12 17:58 . 2009-05-14 05:53 -------- d-----w- c:\program files\GameSpy Arcade
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-02 17:26 . 2008-06-28 15:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-02 17:24 . 2009-04-02 12:06 7132192 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-02 17:24 . 2009-04-02 12:06 688160 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-02 17:24 . 2009-04-02 12:06 57848 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-02 17:24 . 2009-04-02 12:06 4480 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-01 09:32 . 2008-11-22 15:38 -------- d-----w- c:\program files\Atlas Link(SD9000sc)
2009-05-31 19:43 . 2009-05-31 19:43 -------- d-----w- c:\documents and settings\Free User\Application Data\cleaner
2009-05-28 09:34 . 2008-02-06 08:16 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-05-27 10:11 . 2009-05-26 19:17 778240 ----a-w- c:\windows\system32\ALOAudioCompress2.dll
2009-05-26 19:12 . 2009-04-02 10:55 -------- d-----w- c:\documents and settings\All Users\Application Data\zyz Kaspersky Lab setup files
2009-05-26 18:39 . 2009-04-02 12:06 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-26 18:39 . 2009-04-02 12:06 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-26 18:11 . 2006-07-11 15:35 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-05-12 18:28 . 2009-04-17 09:45 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-06 15:35 . 2008-07-09 11:07 -------- d-----w- c:\documents and settings\Free User\Application Data\Nokia Multimedia Player
2009-05-02 08:12 . 2009-03-19 13:17 731464 ----a-w- c:\documents and settings\البيت\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-30 19:15 . 2007-06-21 20:36 731464 ----a-w- c:\documents and settings\Free User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-23 10:38 . 2009-04-23 06:11 -------- d-----w- c:\program files\Kelk 2000
2009-04-17 09:45 . 2009-04-17 09:45 -------- d-----w- c:\program files\MultiTranse
2009-04-17 05:38 . 2008-01-19 17:31 -------- d-----w- c:\program files\Golden Al-Wafi Translator
2009-04-16 18:11 . 2009-04-16 18:11 -------- d-----w- c:\program files\Ectaco
2009-04-16 17:05 . 2009-01-09 18:16 -------- d-----w- c:\program files\Common Files\GuruNet Shared
2009-04-16 16:48 . 2009-04-16 16:47 -------- d-----w- c:\program files\QuickWiz
2009-04-16 16:47 . 2009-04-16 16:47 -------- d-----w- c:\program files\Common Files\Accent Shared
2009-04-13 10:59 . 2009-04-13 10:59 -------- d-----w- c:\program files\mplayerc_20081210
2009-04-11 23:09 . 2008-07-08 15:18 11376 ----a-w- c:\windows\system32\drivers\secdrv.sys
2009-04-02 16:43 . 2009-04-02 16:43 0 ----a-w- c:\windows\system32\REN27.tmp
2009-04-02 16:29 . 2009-04-02 16:29 2232 ----a-w- c:\windows\java\Packages\Data\JVDJBNNX.DAT
2009-04-02 16:29 . 2009-04-02 16:29 155995 ----a-w- c:\windows\java\Packages\Z7X3BRN5.ZIP
2009-04-02 16:29 . 2009-04-02 16:29 2678 ----a-w- c:\windows\java\Packages\Data\WYF9NXJ5.DAT
2009-04-02 16:29 . 2009-04-02 16:29 2678 ----a-w- c:\windows\java\Packages\Data\V93DBBVJ.DAT
2009-04-02 16:29 . 2009-04-02 16:29 2678 ----a-w- c:\windows\java\Packages\Data\EZ1N1N57.DAT
2009-04-02 16:29 . 2009-04-02 16:29 2678 ----a-w- c:\windows\java\Packages\Data\DRH7R3N3.DAT
2009-04-02 16:29 . 2009-04-02 16:29 2678 ----a-w- c:\windows\java\Packages\Data\2FJ5N37R.DAT
2009-04-02 15:58 . 2008-01-29 15:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-04-02 15:58 . 2009-04-02 12:32 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\klbg.sys
2009-04-02 15:58 . 2009-04-02 12:32 213520 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\XP\klif.sys
2009-04-02 15:58 . 2009-04-02 12:32 861448 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\updater.dll
2009-04-02 12:32 . 2009-04-02 12:32 21256 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\vkbd.dll
2009-04-02 12:31 . 2009-04-02 12:31 83208 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\mzvkbd.dll
2009-04-02 12:31 . 2009-04-02 12:31 62728 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\ievkbd.dll
2009-04-02 12:31 . 2009-04-02 12:31 43784 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\fssync.dll
2009-04-02 12:31 . 2009-04-02 12:31 365832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\ckahum.dll
2009-04-02 12:31 . 2009-04-02 12:31 201992 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.357\avp.exe
2008-06-28 09:01 . 2008-04-02 16:19 9 --sh--r- c:\program files\Desktop__.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2002-12-31 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2006-09-21 9138176]
"StatusClient"="c:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864]
"TomcatStartup"="c:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-26 185896]
"NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-10-01 3104768]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-02 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-13 114688]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-13 94208]
"sclauncher"="c:\program files\SimpleCenter\bin\win\sclauncher.exe" [2007-01-30 94208]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-04-02 201992]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-03-13 16116224]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2007-03-13 2879488]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2002-12-31 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2002-12-31 15360]
c:\documents and settings\Free User\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"PreXPSP2ShellProtocolBehavior"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 06:29 م 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 07:02 م 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [25/03/2008 08:07 م 24592]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [26/05/2009 09:32 م 335104]
S3 W35UND;ISSC35 802.11bg WLAN USB Adapter Driver;c:\windows\system32\DRIVERS\W35UND.SYS --> c:\windows\system32\DRIVERS\W35UND.SYS [?]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-SigmatelSysTrayApp - sttray.exe
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uStart Page = about:blank
uInternet Settings,ProxyServer = xn--4gba1b:80
uInternet Settings,ProxyOverride = <local>
DPF: Microsoft XML Parser for Java -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-02 20:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2052111302-682003330-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1140)
c:\windows\system32\klogon.dll
- - - - - - - > 'explorer.exe'(512)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\rundll32.exe
c:\program files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
c:\windows\system32\mmc.exe
c:\windows\system32\HPBPRO.EXE
.
**************************************************************************
.
Completion time: 2009-06-02 20:30 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-02 17:30
Pre-Run: 49,517,592,576 bytes free
Post-Run: 49,441,271,808 bytes free
182 --- E O F --- 2009-01-22 08:45