مشكور اخوي ع الرد
حملته وبعد تشغيله كان يطلعلي اكثر من رسالتين وجربت مره ثانيه وطلعتلي رساله خياراتها تجاهل
واغلاق وفي كل مره يطلعلي تقرير يختلف تقريبا عن الثاني ومايسوي اعادة تشغيل للجهاز ابدآ
شغلت الجهاز من جديد وحملته مره ثانيه واشتغلت بس ماطلعلي ولاا رسااله على طول قام بالفحص
وطلع التقرير
وهذا اخر تقرير طلعلي
ComboFix 09-06-23.01 - home 06/25/2009 9:17.5 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1256.966.1025.18.2037.1114 [GMT 3:00]
Running from: e:\users\home\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: ESET NOD32 Antivirus 3.0 *disabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
SP: Kaspersky Internet Security *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-05-25 to 2009-06-25 )))))))))))))))))))))))))))))))
.
2009-06-25 06:21 . 2009-06-25 06:21 -------- d-----w- e:\users\home\AppData\Local\temp
2009-06-25 06:21 . 2009-06-25 06:21 -------- d-----w- e:\users\Guest\AppData\Local\temp
2009-06-25 06:21 . 2009-06-25 06:21 -------- d-----w- e:\users\••••\AppData\Local\temp
2009-06-23 23:00 . 2009-06-23 23:00 -------- d-----w- e:\users\Guest\AppData\Roaming\Apple Computer
2009-06-23 23:00 . 2009-06-23 23:00 -------- d-----w- e:\users\Guest\AppData\Local\Apple Computer
2009-06-20 21:04 . 2009-06-20 21:04 -------- d-----w- e:\users\••••\AppData\Local\Google
2009-06-18 10:09 . 2009-06-25 05:23 -------- d-----w- e:\users\••••\Tracing
2009-06-18 10:04 . 2009-06-18 10:04 -------- d-----w- e:\users\••••\Bluetooth Software
2009-06-18 09:42 . 2009-06-18 09:42 -------- d-----w- e:\users\Guest\Bluetooth Software
2009-06-18 09:42 . 2009-06-18 09:42 115576 ----a-w- e:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-10 08:57 . 2009-04-21 12:04 2028032 ----a-w- e:\windows\system32\win32k.sys
2009-06-10 08:51 . 2009-04-24 16:14 56320 ----a-w- e:\windows\system32\iesetup.dll
2009-06-10 08:51 . 2009-04-24 16:11 72704 ----a-w- e:\windows\system32\admparse.dll
2009-06-10 08:51 . 2009-04-24 13:53 26624 ----a-w- e:\windows\system32\ieUnatt.exe
2009-06-10 08:51 . 2009-04-24 12:25 48128 ----a-w- e:\windows\system32\mshtmler.dll
2009-06-06 13:29 . 2009-06-07 23:02 -------- d-----w- e:\programdata\Kaspersky Lab
2009-06-06 12:50 . 2009-06-06 12:50 -------- d-----w- e:\programdata\Kaspersky Lab Setup Files
2009-06-05 04:00 . 2009-06-05 04:00 7168 ----a-w- e:\users\home\AppData\Roaming\Thinstall\CyberScrub® Privacy Suite™ 5.1\1000000500002i\lsass.exe
2009-06-05 04:00 . 2009-06-05 04:00 7168 ----a-w- e:\users\home\AppData\Roaming\Thinstall\CyberScrub® Privacy Suite™ 5.1\400000dd00002i\CSPSeraser.exe
2009-06-02 10:31 . 2009-06-02 10:31 -------- d-----w- e:\users\home\AppData\Roaming\Thinstall
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-25 05:54 . 2009-02-20 21:25 836 ----a-w- e:\windows\bthservsdp.dat
2009-06-18 10:04 . 2009-06-18 10:04 115576 ----a-w- e:\users\••••\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-14 11:08 . 2009-02-20 23:04 -------- d-----w- e:\programdata\Microsoft Help
2009-05-24 22:45 . 2009-05-24 22:45 390664 ----a-w- e:\users\home\AppData\Roaming\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-24 22:45 . 2009-05-24 22:45 390664 ----a-w- e:\users\home\AppData\Roaming\Real\Update\temp\~Upg5\RealPlayer11.exe
2009-05-21 04:55 . 2009-05-21 04:55 -------- d-----w- e:\program files\iVocalize Web Conference 4
2009-05-11 16:34 . 2009-05-11 16:34 390664 ----a-w- e:\users\home\AppData\Roaming\Real\Update\temp\~Upg4\RealPlayer11.exe
2009-05-02 10:41 . 2009-05-02 10:41 390664 ----a-w- e:\users\home\AppData\Roaming\Real\Update\temp\~Upg3\RealPlayer11.exe
2009-04-24 16:22 . 2009-06-10 08:52 827392 ----a-w- e:\windows\system32\wininet.dll
2009-04-24 16:14 . 2009-06-10 08:52 78336 ----a-w- e:\windows\system32\ieencode.dll
2009-04-23 13:01 . 2009-06-10 08:52 788992 ----a-w- e:\windows\system32\rpcrt4.dll
2009-04-23 12:56 . 2009-06-10 08:52 696832 ----a-w- e:\windows\system32\localspl.dll
2009-04-08 01:04 . 2009-04-08 01:04 390664 ----a-w- e:\users\home\AppData\Roaming\Real\Update\temp\~Upg2\RealPlayer11.exe
2009-03-30 06:56 . 2009-03-30 06:56 1234120 ----a-w- e:\users\home\wrar380.exe
2009-03-30 01:04 . 2009-03-30 01:04 390664 ----a-w- e:\users\home\AppData\Roaming\Real\Update\temp\~Upg1\RealPlayer11.exe
2007-02-21 19:49 . 2007-02-21 19:49 8192 --sha-w- e:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2009-06-25_05.10.34 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-20 20:32 . 2009-06-25 03:57 33112 e:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-02-20 20:32 . 2009-06-25 06:13 33112 e:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-06-25 06:13 66864 e:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2006-11-02 13:02 . 2009-06-25 05:02 16384 e:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:02 . 2009-06-25 06:12 16384 e:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2009-06-25 05:02 32768 e:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-06-25 06:12 32768 e:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-06-25 06:12 16384 e:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2006-11-02 13:02 . 2009-06-25 05:02 16384 e:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-02-20 20:32 . 2009-06-25 06:13 6434 e:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2971020577-2977481277-141585040-1000_UserData.bin
- 2009-02-20 20:32 . 2009-06-25 04:55 6434 e:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2971020577-2977481277-141585040-1000_UserData.bin
- 2009-06-25 03:54 . 2009-06-25 04:53 2048 e:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-06-25 06:11 . 2009-06-25 06:11 2048 e:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-06-25 03:54 . 2009-06-25 04:53 2048 e:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-06-25 06:11 . 2009-06-25 06:11 2048 e:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-06-25 06:16 610142 e:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-06-25 04:58 610142 e:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-06-25 04:58 103924 e:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-06-25 06:16 103924 e:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="e:\program files\Windows Sidebar\sidebar.exe" [2009-02-20 1232896]
"MsnMsgr"="e:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Google Desktop Search"="e:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-02-20 120320]
"swg"="e:\program files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe" [2009-02-20 155896]
"ehTray.exe"="e:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"{9D71D88C-C598-4935-C5D1-43AA4DB90836}"="e:\users\home\AppData\Roaming\Bifrost\server.exe" [2009-02-20 40829]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="e:\windows\system32\igfxtray.exe" [2008-02-22 141848]
"HotKeysCmds"="e:\windows\system32\hkcmd.exe" [2008-02-22 166424]
"Persistence"="e:\windows\system32\igfxpers.exe" [2008-02-22 133656]
"Apoint"="e:\program files\DellTPad\Apoint.exe" [2007-10-11 163840]
"Broadcom Wireless Manager UI"="e:\windows\system32\WLTRAY.exe" [2008-03-12 3563520]
"IAAnotif"="e:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"egui"="e:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 1443072]
"TkBellExe"="e:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-20 185896]
"GrooveMonitor"="e:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="e:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
e:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - e:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - e:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Bluetooth.lnk - e:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-2-8 752168]
QuickSet.lnk - e:\program files\Dell\QuickSet\quickset.exe [2008-3-3 1207376]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D5FC1C87-3751-4BF8-85B7-714890F14C08}"= TCP:6004|e:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{E29CC054-ED33-4E77-9F04-744EE5446F74}"= UDP:e:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{D81DFBF5-1190-4E48-B39E-4911AD4CC7F3}"= TCP:e:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{05636D3B-3A29-4084-A78F-1EE430206E38}"= UDP:e:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5DCE61ED-5296-4F41-8148-4FB4D0D5A61F}"= TCP:e:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{CDD16F6C-1195-4DC8-BB17-2F1AF338D10A}"= UDP:e:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{390951CB-5517-410D-862A-6E4D40C355A2}"= TCP:e:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{4AD738CB-85EC-47EB-A410-7868DAB8D556}"= UDP:e:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{410D8FD7-E337-49C7-99D0-B85E84CC4880}"= TCP:e:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{50E340B7-8DDE-477B-8326-751DEA21FD99}"= UDP:e:\program files\iTunes\iTunes.exe:iTunes
"{361BC643-6FE9-4C99-8318-81A1B92320BE}"= TCP:e:\program files\iTunes\iTunes.exe:iTunes
"{1973BAC2-E9C9-4057-AECD-54C74E62E460}"= UDP:e:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{336605F0-C1B7-40B1-BFF8-84321CC0503E}"= TCP:e:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R1 epfwtdir;epfwtdir;e:\windows\System32\drivers\epfwtdir.sys [21/12/07 08:21 33800]
R2 ekrn;Eset Service;e:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [21/12/07 08:21 468224]
R3 btwl2cap;Bluetooth L2CAP Service;e:\windows\System32\drivers\btwl2cap.sys [21/02/09 00:23 29736]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;e:\windows\System32\drivers\IntcHdmi.sys [20/02/09 18:20 111616]
R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;e:\windows\System32\drivers\k57nd60x.sys [29/01/08 20:08 203264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder
2009-06-25 e:\windows\Tasks\User_Feed_Synchronization-{9BFA64F5-E97C-4D8A-9CAA-F5687F91BEC0}.job
- e:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Settings,ProxyOverride = *.local
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-25 09:21
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(4484)
e:\windows\system32\btmmhook.dll
.
Completion time: 2009-06-25 9:23
ComboFix-quarantined-files.txt 2009-06-25 06:23
ComboFix2.txt 2009-06-25 05:47
ComboFix3.txt 2009-06-25 05:40
ComboFix4.txt 2009-06-25 05:21
ComboFix5.txt 2009-06-25 06:17
Pre-Run: 81,477,632,000 bytes free
Post-Run: 81,452,204,032 bytes free
178 --- E O F --- 2009-06-22 16:47