اولا يعطيك العافيه اخوي ع الجهد الي تبذله معي ومع غيري الله يجزاك خير
بقولك وش الي سويت ازلت علامة الصح من عند جميع برامج بدء التشغيل والى الان ماعليه صح
بعدها حملت البرنامج وحذفت الترند ميكرو وحذفت القيم ايضا زي ماقلت لي
وسويت ري ستارت وبعدها بالكمبو فكس سويت فحص وهذا التقرير وانا الان بدون حمايه وبرامج بدء التشغيل موقفه انتظر ردك ياغالي
ComboFix 09-06-26.02 - Owner 06/27/2009 2:57.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.503.299 [GMT 3:00]
Running from: c:\documents and settings\Owner\سطح المكتب\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\regedit.com
c:\windows\system32\taskmgr.com
.
((((((((((((((((((((((((( Files Created from 2009-05-26 to 2009-06-26 )))))))))))))))))))))))))))))))
.
2009-06-27 00:00 . 2009-06-27 00:00 -------- d-----w- c:\windows\LastGood
2009-06-24 11:57 . 2009-06-24 11:58 3667395 ----a-w- c:\windows\REGBK00.ZIP
2009-06-24 11:56 . 2009-06-24 11:56 -------- d---a-w- c:\windows\system32\runouce.exe
2009-06-24 11:49 . 2009-06-24 11:49 626688 ----a-w- c:\windows\system32\msvcr80.dll
2009-06-24 11:49 . 2009-06-24 11:49 548864 ----a-w- c:\windows\system32\msvcp80.dll
2009-06-24 11:49 . 2009-06-24 11:49 28672 ----a-w- c:\windows\system32\eEmpty.exe
2009-06-24 11:49 . 2008-04-14 18:30 139264 ----a-w- c:\windows\system32\T.COM
2009-06-24 11:49 . 2008-04-14 18:30 146944 ----a-w- c:\windows\R.COM
2009-06-24 11:49 . 2009-06-24 11:49 -------- d-----w- c:\program files\Common Files\MicroWorld
2009-06-24 11:49 . 2009-06-24 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\MicroWorld
2009-06-24 11:29 . 2009-06-24 11:29 165296 ----a-w- c:\documents and settings\Owner\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
2009-06-24 11:28 . 2009-06-24 11:29 -------- d-----w- c:\documents and settings\Owner\Application Data\IDM
2009-06-23 04:13 . 2009-06-23 04:13 -------- d-----w- c:\windows\system32\wbem\Repository
2009-06-23 04:12 . 2009-06-23 04:12 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-23 04:12 . 2009-06-23 04:12 -------- d-----w- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-06-23 04:06 . 2009-06-24 11:28 -------- d-----w- c:\program files\Internet Download Manager
2009-06-21 16:22 . 2009-06-23 04:06 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-06-21 12:54 . 2008-01-21 14:43 13576 ----a-w- c:\windows\system32\wnaspi32.dll
2009-06-20 17:42 . 2009-06-20 17:42 -------- d-----w- c:\documents and settings\Owner\Application Data\Media Player Classic
2009-06-19 23:58 . 2009-06-23 02:13 -------- d-----w- c:\program files\LtUcx
2009-06-19 23:09 . 2008-04-13 21:09 5504 -c--a-w- c:\windows\system32\dllcache\mstee.sys
2009-06-19 23:09 . 2008-04-13 21:09 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2009-06-19 20:54 . 2009-06-19 20:54 -------- d-----w- c:\documents and settings\Owner\Application Data\TeamViewer
2009-06-19 20:53 . 2009-06-19 20:53 -------- d-----w- c:\program files\TeamViewer
2009-06-19 20:53 . 2009-06-19 20:53 -------- d-----w- c:\documents and settings\Owner\temp
2009-06-19 19:25 . 2009-06-19 19:25 -------- d-----w- c:\program files\USB Disk Security
2009-06-19 18:59 . 2009-06-20 02:07 -------- d-----w- c:\documents and settings\Owner\Application Data\BSplayer PRO
2009-06-19 14:34 . 2009-06-19 14:40 -------- dcsh--w- c:\program files\Common Files\WindowsLiveInstaller
2009-06-19 14:32 . 2009-06-19 14:34 -------- d-----w- c:\documents and settings\All Users\Application Data\WLInstaller
2009-06-19 14:12 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-06-19 14:12 . 2009-03-06 14:20 283136 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-06-19 14:12 . 2009-02-09 11:22 2190592 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-06-19 14:12 . 2009-02-09 11:21 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-06-19 14:12 . 2009-02-09 10:51 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-06-19 14:12 . 2009-02-09 10:51 723456 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2009-06-19 14:12 . 2009-02-09 10:51 681472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2009-06-19 14:12 . 2009-02-09 10:51 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-06-19 14:12 . 2009-02-09 10:51 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-06-19 14:12 . 2009-02-09 11:22 2146816 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-06-19 14:12 . 2009-02-09 10:51 693760 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-06-19 14:12 . 2009-02-09 11:22 2025472 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-06-19 14:10 . 2008-04-21 21:14 215040 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-06-19 14:08 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2009-06-19 14:05 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-06-19 14:04 . 2008-09-04 17:15 1106944 -c----w- c:\windows\system32\dllcache\msxml3.dll
2009-06-19 14:04 . 2008-10-15 16:35 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-06-19 14:04 . 2008-05-01 14:34 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2009-06-19 14:03 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-06-19 14:01 . 2008-06-14 17:31 271616 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-06-19 14:01 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2009-06-19 13:56 . 2001-03-29 23:00 62976 ----a-w- c:\windows\system32\CTDetres.dll
2009-06-19 13:56 . 1999-12-13 01:01 44032 ------w- c:\windows\system32\CTSVCCDA.EXE
2009-06-19 13:56 . 1999-11-18 01:00 25088 ------w- c:\windows\system32\CTSVCCTL.EXE
2009-06-19 13:56 . 2002-02-20 03:00 331776 ------w- c:\windows\system32\CTMEDENG.DLL
2009-06-19 13:56 . 2000-04-19 22:00 24576 ----a-w- c:\windows\system32\CTMERes.DLL
2009-06-19 13:54 . 2009-06-19 13:57 -------- d-----w- c:\program files\Creative
2009-06-19 13:50 . 2008-10-16 11:09 43544 ----a-w- c:\windows\system32\wups2.dll
2009-06-11 15:32 . 2009-06-11 15:32 -------- d-sh--w- c:\documents and settings\Owner\UserData
2009-06-11 15:32 . 2009-06-24 13:09 -------- d-----w- c:\documents and settings\Owner\Contacts
2009-06-10 22:26 . 2009-06-10 22:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-06-10 22:15 . 2009-06-26 21:23 -------- d-----w- c:\documents and settings\Owner\Application Data\DMCache
2009-06-10 22:14 . 2009-06-10 22:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-06-10 22:12 . 2009-06-19 14:27 -------- d--h--w- c:\windows\$hf_mig$
2009-06-10 22:11 . 2009-06-10 22:11 390664 ----a-w- c:\documents and settings\Owner\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
2009-06-10 22:05 . 2008-09-10 01:14 1307648 -c----w- c:\windows\system32\dllcache\msxml6.dll
2009-06-10 22:05 . 2008-04-14 18:10 71680 -c----w- c:\windows\system32\dllcache\msxml6r.dll
2009-06-10 22:05 . 2008-04-14 18:10 71680 ------w- c:\windows\system32\msxml6r.dll
2009-06-10 22:05 . 2008-09-10 01:14 1307648 ----a-w- c:\windows\system32\msxml6.dll
2009-06-10 22:05 . 2007-06-26 08:30 22060 -c----w- c:\windows\system32\dllcache\npds.zip
2009-06-10 22:05 . 2007-06-26 08:26 403 -c----w- c:\windows\system32\dllcache\npdrmv2.zip
2009-06-10 22:02 . 2009-06-10 22:05 -------- d-----w- c:\windows\ServicePackFiles
2009-06-10 22:01 . 2008-04-14 18:29 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2009-06-10 21:57 . 2008-07-09 07:34 26488 ----a-w- c:\windows\system32\spupdsvc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-26 23:56 . 2009-06-24 16:30 -------- d-----w- c:\program files\Trend Micro
2009-06-26 23:51 . 2009-06-26 23:41 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-26 23:48 . 2009-06-26 23:41 -------- d-----w- c:\program files\Your Uninstaller 2008
2009-06-26 23:41 . 2009-06-26 23:41 -------- d-----w- c:\documents and settings\Owner\Application Data\URSoft
2009-06-24 16:17 . 2006-04-09 12:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-06-21 12:54 . 2006-04-09 11:53 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-19 23:08 . 2009-06-19 23:08 8854 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\UNINST_Uninstall_J_8527C3D5BA1D46E988D2AF25544311A3_2.exe
2009-06-19 23:08 . 2009-06-19 23:08 40960 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\NewShortcut2_8527C3D5BA1D46E988D2AF25544311A3.exe
2009-06-19 23:08 . 2009-06-19 23:08 10134 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{8527C3D5-BA1D-46E9-88D2-AF25544311A3}\ARPPRODUCTICON.exe
2009-06-19 23:08 . 2009-06-19 23:08 -------- d-----w- c:\program files\JPEG Camera
2009-06-19 18:59 . 2006-04-09 12:31 -------- d-----w- c:\program files\Webteh
2009-06-19 14:34 . 2006-04-09 12:45 -------- d-----w- c:\program files\Windows Live
2009-06-19 14:34 . 2001-09-19 12:00 39982 ----a-w- c:\windows\system32\perfc001.dat
2009-06-19 14:34 . 2001-09-19 12:00 251478 ----a-w- c:\windows\system32\perfh001.dat
2009-06-19 13:54 . 2006-04-09 11:53 -------- d-----w- c:\program files\Common Files\InstallShield
2009-06-11 15:31 . 2006-04-09 12:47 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-10 22:06 . 2006-04-09 11:33 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-07 15:32 . 2004-08-03 21:55 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:43 . 2004-08-03 21:55 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:42 . 2004-08-03 21:55 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-19 19:47 . 2004-08-03 21:46 1847040 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:52 . 2004-08-03 21:55 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 169984]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
S3 CAM1690;USB 2.0 Compliance JPEG Video Camera;c:\windows\system32\drivers\cam1690.sys [29/08/2007 12:01 م 153344]
.
Contents of the 'Scheduled Tasks' folder
2009-06-25 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
2009-06-26 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 14:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.google.com.sa/
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\onwon73y.default\
FF - component: c:\documents and settings\Owner\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-06-27 03:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-06-27 3:03
ComboFix-quarantined-files.txt 2009-06-27 00:03
Pre-Run: 21,293,170,688 bytes free
Post-Run: 21,636,456,448 bytes free
168 --- E O F --- 2009-06-25 09:00