RED_CARD

زيزوومي نشيط
إنضم
20 مايو 2009
المشاركات
105
مستوى التفاعل
4
النقاط
120
غير متصل
السلام عليكم اخواني ..

أعرض عليكم مشكلتي .. وهي ان المتصفحات عندي لا تعمل ..
إلا في حالة واحدة عندما اذهب إلى ( اتصالات شبكة الاتصال ) واعمل تعطيل .. ثم تمكين ..
تنفتح المتصفحات لفترة وجيزة .. ثم من بعد ذلك لا تفتح ..


تقرير الهايجاك



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:03:48, on 18/07/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\WINDOWS\system32\igfxtray.exe
D:\WINDOWS\system32\hkcmd.exe
D:\WINDOWS\system32\igfxpers.exe
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\system32\igfxsrvc.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\Program Files\Internet Download Manager\IDMan.exe
D:\Program Files\uTorrent\utorrent.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Program Files\CyberLink\Shared files\RichVideo.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Skype\Plugin Manager\skypePM.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\Internet Download Manager\IEMonitor.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Windows Live\Messenger\usnsvc.exe
D:\Program Files\Windows Live\Messenger\Windows Live Messenger.exe
D:\Program Files\Windows Live\Messenger\Windows Live Messenger.exe
D:\Program Files\Real\RealPlayer\RecordingManager.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - (no file)
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O4 - HKLM\..\Run: [RemoteControl] "D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "D:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IgfxTray] D:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] D:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] D:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avp] "D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [IDMan] D:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [µTorrent] "D:\Program Files\uTorrent\utorrent.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Download All Links with IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - D:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: أضافة إلى مانع الأعلانات - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - D:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O16 - DPF: {E001C731-5E37-4538-A5CB-8168736A2360} (ActiveQscan Control) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - D:\Program Files\CyberLink\Shared files\RichVideo.exe

--
End of file - 7278 bytes






مشكلة اخرى ..

الانترنت داونلود مانجر .. اصبح لا يحمل ..
واعتقد ان السبب هو الكاسبر سكاي 2010 ..
فهل من حل ؟؟؟؟



تشكراتي
 

ارجوكم اخواني .. انا عندي تقديم جامعات .. وبحاجة مااااااااسة للإنترنت .. :(
 
وعليكم السلام

نبدآ بالمشكلة الاولى

حدد القيمه واحذفها

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - (no file)


طريقة الحذف

mg%20(3).png



mg%20(4).png



بعدها اذهب الى اضافة وازالة البرامج واحذف التولبار الموجود عندك (toolbar)>> ممكن ما يكون موجود


ثم نزل هذه الاداة واتبع الشرح التالي



يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي



التوافق : ويندوز اكسبيفقط


شرح الاستخدام ,,,,,,
دبل كلك على الاداة واصبر حتى تنتهي جميع النوافذ وتقف عند هذه النافذة


002.png



وعند ظهور هذه الشاشه ,, اضغط على Close ليتم اعادة تشغيل جهازك (( لتكملة عملية التنظيف ))



ثم عطل برنامج الحمايه عندك واعمل التالي


حمل هذه الأداة

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي



عند تشغيل الاداة نضغط كما محدد بالصورة التالية


wh_61624949.png

وبعدها اعد تشغيل الجهاز

ثم اعمل التالي بعد اعادة التشغيل

عطل برامج الحماية عن العمل
ثم
حمل الاداة التالية واحفظها على سطح المكتب
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
لا تقم بتشغيل اي برنامج ،، ومهما طالت عملية الفحص انتظر حتى تنتهي
انتظر حتى يظهر لك تقرير ،،انسخه والصقه بمشاركتك القادمة


بالأنتظار لعمل المطلوب
 
توقيع : AbOdy
توقيع : AbOdy
اخوي عبودي ..

اولاً أنا أرجوك انك تسامحني .. لأني فعلاً مشحون بتقديم الجامعات .. ولم أراعي الشروط ..


وهذا هو تقرير الكومبوفكس .. علماً بأن الكومبوفكس لم يعمل ري ستارت للكمبيوتر .. وأيضاً .. المودم سوا ري ستارت لوحده مرتين خلال فحص الكومبو فكس .. لا ادري ان كان لذلك علاقة .. ولكن هذا ما حصل :>


التقرير



ComboFix 09-07-14.08 - MAS 07/18/2009 2:55.10.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.2037.1550 [GMT 3:00]
Running from: d:\documents and settings\MAS\My Documents\Downloads\Programs\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2009-06-17 to 2009-07-17 )))))))))))))))))))))))))))))))
.

2009-07-17 00:08 . 2009-07-17 00:08 604140 --sha-w- d:\windows\system32\drivers\ISwift3.dat
2009-07-17 00:05 . 2009-07-17 00:05 94643 ----a-w- d:\windows\system32\drivers\klick.dat
2009-07-17 00:05 . 2009-07-17 00:05 105395 ----a-w- d:\windows\system32\drivers\klin.dat
2009-07-17 00:04 . 2009-07-17 23:53 -------- d-----w- d:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-07-17 00:04 . 2009-07-17 00:04 -------- d-----w- d:\program files\Kaspersky Lab
2009-07-16 23:13 . 2009-07-16 23:48 -------- d-----w- d:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-07-16 09:39 . 2009-07-16 09:39 -------- d-----w- d:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-07-15 20:00 . 2009-07-17 13:14 -------- d-----w- D:\Pokemon Season 2
2009-07-12 01:08 . 2000-08-10 18:21 86016 ----a-w- d:\windows\unvise32.exe
2009-07-12 01:08 . 2009-04-02 12:21 84480 ----a-w- d:\windows\system32\ff_vfw.dll
2009-07-12 01:08 . 2008-06-08 20:58 60273 ----a-w- d:\windows\system32\pthreadGC2.dll
2009-07-12 01:08 . 2009-07-12 01:08 -------- d-----w- d:\program files\ffdshow
2009-07-12 01:08 . 2009-07-12 01:08 81920 ----a-w- d:\documents and settings\MAS\Application Data\ezpinst.exe
2009-07-12 01:08 . 2009-07-12 01:08 47360 ----a-w- d:\windows\system32\drivers\pcouffin.sys
2009-07-12 01:08 . 2009-07-12 01:08 47360 ----a-w- d:\documents and settings\MAS\Application Data\pcouffin.sys
2009-07-12 01:08 . 2009-07-12 01:08 -------- d-----w- d:\documents and settings\MAS\Application Data\Vso
2009-07-12 01:08 . 2004-02-21 22:11 719872 ----a-w- d:\windows\system32\devil.dll
2009-07-12 01:08 . 2005-10-28 06:44 308224 ----a-w- d:\windows\system32\avisynth.dll
2009-07-12 01:08 . 2009-07-12 01:08 -------- d-----w- d:\program files\Video Convert Master
2009-07-11 23:47 . 2009-03-19 13:32 23400 ----a-w- d:\windows\system32\drivers\GEARAspiWDM.sys
2009-07-11 23:47 . 2008-04-17 09:12 107368 ----a-w- d:\windows\system32\GEARAspi.dll
2009-07-11 23:47 . 2009-07-11 23:47 -------- d-----w- d:\program files\iPod
2009-07-11 23:47 . 2009-07-11 23:47 -------- d-----w- d:\program files\iTunes
2009-07-11 23:47 . 2009-07-11 23:47 -------- d-----w- d:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-11 23:47 . 2009-07-11 23:47 -------- d-----w- d:\program files\Bonjour
2009-07-11 23:46 . 2009-07-11 23:46 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\Apple
2009-07-11 23:46 . 2009-07-11 23:46 -------- d-----w- d:\program files\Apple Software Update
2009-07-11 23:46 . 2009-06-05 08:42 39424 ----a-w- d:\windows\system32\drivers\usbaapl.sys
2009-07-11 23:46 . 2009-06-05 08:42 2060288 ----a-w- d:\windows\system32\usbaaplrc.dll
2009-07-11 23:45 . 2009-07-11 23:48 -------- d-----w- d:\documents and settings\All Users\Application Data\Apple
2009-07-11 23:45 . 2009-07-11 23:47 -------- d-----w- d:\program files\Common Files\Apple
2009-07-11 23:45 . 2009-07-11 23:48 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\Apple Computer
2009-07-11 23:19 . 2001-08-17 19:36 5632 ----a-w- d:\windows\system32\ptpusb.dll
2009-07-11 23:19 . 2004-08-03 21:56 159232 ----a-w- d:\windows\system32\ptpusd.dll
2009-07-11 23:19 . 2004-08-03 19:58 15104 -c--a-w- d:\windows\system32\dllcache\usbscan.sys
2009-07-11 23:19 . 2004-08-03 19:58 15104 ----a-w- d:\windows\system32\drivers\usbscan.sys
2009-07-11 12:17 . 2009-07-15 19:59 -------- d-----w- D:\Pokemon Season 1
2009-07-09 12:40 . 2009-07-09 12:44 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\WMTools Downloaded Files
2009-07-07 11:52 . 2009-07-07 11:52 -------- d-----w- d:\program files\danny_kay1710
2009-07-06 13:17 . 2007-07-23 18:25 -------- d-----w- d:\program files\Languages
2009-07-03 12:48 . 2009-07-03 12:48 219664 ----a-w- d:\windows\system32\klogon.dll
2009-07-03 12:45 . 2009-07-03 12:45 27507 ----a-w- d:\windows\system32\drivers\klopp.dat
2009-07-03 12:10 . 2009-07-03 12:10 59992 ----a-w- d:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 2010 9.0.0.463\English\setup.exe
2009-06-28 09:28 . 2009-07-05 13:32 -------- d-----w- d:\program files\Heroes
2009-06-28 08:40 . 2004-04-30 06:37 160640 ----a-w- d:\windows\system32\drivers\a347bus.sys
2009-06-28 08:40 . 2004-04-30 06:33 5248 ----a-w- d:\windows\system32\drivers\a347scsi.sys
2009-06-28 08:40 . 2009-06-28 08:40 -------- d-----w- d:\program files\Alcohol Soft
2009-06-28 08:36 . 2009-06-28 08:36 -------- d-----w- d:\program files\Okoker ISO Maker
2009-06-28 07:46 . 2004-05-04 11:53 1645320 ----a-w- d:\windows\system32\gdiplus.dll
2009-06-28 07:28 . 1994-09-21 03:00 12800 ----a-w- d:\windows\system32\WING32.DLL
2009-06-28 07:19 . 1997-04-08 17:08 299520 ----a-w- d:\windows\uninst.exe
2009-06-28 07:19 . 2009-06-28 07:19 -------- d-----w- d:\documents and settings\MAS\WINDOWS
2009-06-28 07:00 . 2009-06-28 07:00 98304 ----a-w- d:\windows\system32\CmdLineExt.dll
2009-06-28 06:58 . 2009-06-28 07:57 -------- d-----w- d:\program files\Ubisoft
2009-06-28 06:38 . 2005-05-26 12:34 2297552 ----a-w- d:\windows\system32\d3dx9_26.dll
2009-06-28 06:15 . 2009-06-28 06:15 -------- d--h--w- d:\windows\PIF
2009-06-28 06:09 . 2009-06-28 06:09 -------- d-----w- d:\program files\MagicISO
2009-06-26 16:28 . 2009-06-26 16:28 8854 ----a-r- d:\documents and settings\MAS\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\Uninstall_Project64__9559F7CA5E344237A2D9D856464AD727.exe
2009-06-26 16:28 . 2009-06-26 16:28 40960 ----a-r- d:\documents and settings\MAS\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
2009-06-26 16:28 . 2009-06-26 16:28 40960 ----a-r- d:\documents and settings\MAS\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
2009-06-26 16:28 . 2009-06-26 19:37 -------- d-----w- d:\program files\Project64 1.6
2009-06-26 16:25 . 2009-06-26 16:25 416256 ----a-w- d:\windows\system32\glide3x.dll
2009-06-25 00:09 . 2009-06-25 00:10 3561743 ----a-w- d:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-25 00:08 . 2009-06-25 00:08 -------- d-----w- d:\documents and settings\MAS\Application Data\Malwarebytes
2009-06-25 00:08 . 2009-06-17 08:27 19096 ----a-w- d:\windows\system32\drivers\mbam.sys
2009-06-25 00:08 . 2009-06-17 08:27 38160 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2009-06-25 00:08 . 2009-06-25 00:10 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2009-06-25 00:08 . 2009-06-25 00:08 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-24 20:11 . 2009-06-24 20:11 -------- d-----w- d:\documents and settings\MAS\Application Data\CyberScrub
2009-06-24 08:18 . 2009-07-16 17:43 -------- d-----w- d:\documents and settings\MAS\Application Data\QuickScan
2009-06-24 08:15 . 2009-06-24 08:15 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\Runscanner.net
2009-06-24 07:52 . 2009-06-24 07:52 -------- d-----w- d:\program files\Trend Micro
2009-06-22 06:15 . 2009-06-22 06:15 0 ----a-w- d:\windows\nsreg.dat
2009-06-22 06:11 . 2009-06-22 06:11 -------- d-----w- d:\documents and settings\MAS\Local Settings\Application Data\Mozilla
2009-06-21 08:47 . 2009-06-21 08:47 -------- d-----w- d:\program files\URUSoft
2009-06-20 18:00 . 2009-06-20 18:00 -------- d-----w- d:\documents and settings\MAS\Application Data\ImgBurn
2009-06-20 17:59 . 2009-06-20 17:59 -------- d-----w- d:\program files\ImgBurn
2009-06-19 19:42 . 2009-06-19 19:42 -------- d-----w- d:\program files\Pokemon PC 2.0
2009-06-18 23:51 . 2009-06-19 00:01 -------- d-----w- d:\program files\blueMSX
2009-06-18 22:51 . 2009-06-18 22:51 -------- d-----w- d:\program files\Gabest
2009-06-18 22:47 . 2009-06-18 22:47 -------- d-----w- d:\program files\DirectVobSub

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-17 23:58 . 2009-06-11 15:01 -------- d-----w- d:\documents and settings\MAS\Application Data\DMCache
2009-07-17 23:54 . 2009-06-16 12:10 -------- d-----w- d:\documents and settings\MAS\Application Data\uTorrent
2009-07-17 23:53 . 2009-06-11 15:02 117760 ----a-w- d:\documents and settings\MAS\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-17 23:50 . 2009-06-14 20:42 -------- d-----w- d:\documents and settings\MAS\Application Data\skypePM
2009-07-17 23:47 . 2009-06-24 20:10 -------- d-----w- d:\documents and settings\MAS\Application Data\cleaner
2009-07-16 07:39 . 2009-06-10 13:25 -------- d-----w- d:\program files\Common Files\Adobe
2009-07-16 00:28 . 2009-06-11 15:02 -------- d-----w- d:\program files\SUPERAntiSpyware
2009-07-15 19:56 . 2009-06-10 13:28 -------- d-----w- d:\program files\Messenger Plus! Live
2009-07-13 10:47 . 2009-06-10 13:42 -------- d-----w- d:\program files\Golden Al-Wafi Translator
2009-07-12 01:08 . 2009-07-12 01:08 752 ----a-w- d:\program files\Common Files\uninstal.log
2009-07-11 23:53 . 2009-06-10 13:30 -------- d-----w- d:\documents and settings\MAS\Application Data\Apple Computer
2009-07-11 23:47 . 2009-06-10 13:30 -------- d-----w- d:\documents and settings\All Users\Application Data\Apple Computer
2009-07-11 23:47 . 2009-06-10 13:30 -------- d-----w- d:\program files\QuickTime
2009-07-08 07:16 . 2009-06-11 15:06 -------- d-----w- d:\documents and settings\MAS\Application Data\Skype
2009-07-06 13:17 . 2009-06-11 15:01 -------- d-----w- d:\program files\Internet Download Manager
2009-06-28 07:47 . 2009-06-10 13:29 -------- d--h--w- d:\program files\InstallShield Installation Information
2009-06-28 07:14 . 2009-06-10 13:29 -------- d-----w- d:\program files\Common Files\InstallShield
2009-06-20 20:22 . 2009-06-11 15:01 -------- d-----w- d:\documents and settings\MAS\Application Data\IDM
2009-06-17 21:01 . 2009-06-17 21:01 -------- d-----w- d:\program files\Ask Search Assistant
2009-06-16 12:10 . 2009-06-16 12:10 -------- d-----w- d:\program files\uTorrent
2009-06-15 11:01 . 2009-06-15 11:01 128016 ----a-w- d:\windows\system32\drivers\kl1.sys
2009-06-14 20:42 . 2009-06-14 20:42 56 ---ha-w- d:\windows\system32\ezsidmv.dat
2009-06-14 18:22 . 2009-06-14 18:22 165296 ----a-w- d:\documents and settings\MAS\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
2009-06-13 15:04 . 2009-06-11 14:57 -------- d-----w- d:\documents and settings\All Users\Application Data\Messenger Plus!
2009-06-13 13:06 . 2009-06-13 13:06 -------- d-----w- d:\program files\mpegable
2009-06-13 13:06 . 2009-06-13 13:06 47104 ------w- d:\windows\AKDeInstall.exe
2009-06-13 11:43 . 2009-06-10 14:10 -------- d-----w- d:\program files\ESET
2009-06-12 10:07 . 2009-06-12 10:07 -------- d-----w- d:\documents and settings\MAS\Application Data\GRETECH
2009-06-12 10:07 . 2009-06-12 10:07 112 ----a-w- d:\windows\mbuff.sys
2009-06-11 23:37 . 2009-06-11 23:37 -------- d-----w- d:\documents and settings\MAS\Application Data\Ahead
2009-06-11 23:14 . 2009-06-11 23:14 -------- d-----w- d:\documents and settings\MAS\Application Data\vlc
2009-06-11 15:29 . 2009-06-11 15:29 -------- d-----w- d:\documents and settings\MAS\Application Data\Media Player Classic
2009-06-11 15:02 . 2009-06-11 15:02 -------- d-----w- d:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-11 15:02 . 2009-06-11 15:02 -------- d-----w- d:\documents and settings\MAS\Application Data\SUPERAntiSpyware.com
2009-06-11 15:02 . 2009-06-11 15:02 -------- d-----w- d:\program files\Common Files\Wise Installation Wizard
2009-06-11 14:59 . 2009-06-11 14:59 -------- d-----w- d:\program files\Common Files\Skype
2009-06-11 14:59 . 2009-06-11 14:59 -------- d-----r- d:\program files\Skype
2009-06-11 14:59 . 2009-06-11 14:59 -------- d-----w- d:\documents and settings\All Users\Application Data\Skype
2009-06-10 14:05 . 2009-06-10 14:05 -------- d-----w- d:\program files\CONEXANT
2009-06-10 13:52 . 2009-06-10 13:49 -------- d-----w- d:\program files\Realtek
2009-06-10 13:52 . 2009-06-10 13:52 -------- d-----w- d:\documents and settings\MAS\Application Data\InstallShield
2009-06-10 13:52 . 2009-06-10 13:45 16608 ----a-w- d:\windows\gdrv.sys
2009-06-10 13:49 . 2009-06-10 13:49 315392 ----a-w- d:\windows\HideWin.exe
2009-06-10 13:46 . 2009-06-10 13:46 -------- d-----w- d:\program files\Intel
2009-06-10 13:46 . 2009-06-10 13:46 -------- d-----w- d:\program files\Browser Configuration Utility
2009-06-10 13:41 . 2009-06-10 13:41 73216 ----a-w- d:\windows\ST6UNST.EXE
2009-06-10 13:41 . 2009-06-10 13:41 172032 ------w- d:\windows\Setup1.exe
2009-06-10 13:39 . 2009-06-10 13:39 2232 ----a-w- d:\windows\java\Packages\Data\DN7TBB7D.DAT
2009-06-10 13:39 . 2009-06-10 13:39 155995 ----a-w- d:\windows\java\Packages\375BHVLN.ZIP
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\8QTVTBVZ.DAT
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\8J97ZVRR.DAT
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\NPJ9J31R.DAT
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\I3TJJBL3.DAT
2009-06-10 13:39 . 2009-06-10 13:39 2678 ----a-w- d:\windows\java\Packages\Data\9VJ5RR31.DAT
2009-06-10 13:38 . 2009-06-10 13:38 1023035 ----a-w- d:\windows\system32\Setup.scr
2009-06-10 13:37 . 2009-06-10 13:37 -------- d-----w- d:\program files\Windows Media Connect 2
2009-06-10 13:35 . 2009-06-10 13:35 -------- d-----w- d:\program files\Common Files\xing shared
2009-06-10 13:35 . 2009-06-10 13:35 -------- d-----w- d:\program files\Common Files\Real
2009-06-10 13:35 . 2009-06-10 13:29 348160 ----a-w- d:\windows\system32\msvcr71.dll
2009-06-10 13:35 . 2009-06-10 13:29 499712 ----a-w- d:\windows\system32\msvcp71.dll
2009-06-10 13:35 . 2009-06-10 13:35 -------- d-----w- d:\program files\Real
2009-06-10 13:34 . 2009-06-10 13:34 -------- d-----w- d:\documents and settings\All Users\Application Data\CyberLink
2009-06-10 13:31 . 2009-06-10 13:31 -------- d-----w- d:\program files\CyberLink
2009-06-10 13:30 . 2009-06-10 13:30 -------- d-----w- d:\program files\VideoLAN
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\Nokia
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\Common Files\Nokia
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\GRETECH
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\Common Files\Ahead
2009-06-10 13:29 . 2009-06-10 13:29 -------- d-----w- d:\program files\Nero
2009-06-10 13:28 . 2009-06-10 08:31 94632 ----a-w- d:\documents and settings\MAS\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-10 13:25 . 2009-06-10 13:25 -------- d-----w- d:\program files\Windows Live
2009-06-10 13:23 . 2009-06-10 13:22 -------- d-----w- d:\documents and settings\All Users\Application Data\WinZip
2009-06-10 13:19 . 2009-06-10 13:19 -------- d-----w- d:\program files\Common Files\L&H
2009-06-10 13:19 . 2009-06-10 13:19 -------- d-----w- d:\program files\Microsoft.NET
2009-06-10 13:19 . 2009-06-10 13:19 -------- d-----w- d:\program files\Microsoft ActiveSync
2009-06-10 13:19 . 2009-06-10 13:19 -------- d-----w- d:\program files\Microsoft Works
2009-06-10 08:32 . 2009-06-10 08:23 166455 ----a-w- d:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-10 08:24 . 2009-06-10 08:24 -------- d-----w- d:\program files\microsoft frontpage
2009-06-10 08:20 . 2009-06-10 08:20 21640 ----a-w- d:\windows\system32\emptyregdb.dat
2009-06-05 10:57 . 2009-06-05 10:57 75048 ----a-w- d:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-05-16 17:59 . 2009-05-16 17:59 19472 ----a-w- d:\windows\system32\drivers\klmouflt.sys
2009-05-13 14:46 . 2009-05-13 14:46 31760 ----a-w- d:\windows\system32\drivers\klim5.sys
.

((((((((((((((((((((((((((((( SnapShot_2009-07-14_20.11.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-15 17:41 . 2008-12-15 17:41 33808 d:\windows\system32\drivers\klbg.sys
+ 2009-07-16 23:14 . 2009-07-17 00:04 296976 d:\windows\system32\drivers\klif.sys
+ 2009-07-17 00:05 . 2009-07-17 00:05 3193344 d:\windows\Installer\cfe9c.msi
+ 2009-06-27 10:32 . 2009-06-27 10:32 37766656 d:\windows\Installer\130de.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Skype"="d:\program files\Skype\Phone\Skype.exe" [2009-04-21 24264488]
"SUPERAntiSpyware"="d:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-07-16 1830128]
"IDMan"="d:\program files\Internet Download Manager\IDMan.exe" [2007-07-23 800768]
"µTorrent"="d:\program files\uTorrent\utorrent.exe" [2007-02-15 177152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="d:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-02-07 71216]
"LanguageShortcut"="d:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 54832]
"TkBellExe"="d:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-10 185896]
"IgfxTray"="d:\windows\system32\igfxtray.exe" [2007-09-05 141848]
"HotKeysCmds"="d:\windows\system32\hkcmd.exe" [2007-09-05 166424]
"Persistence"="d:\windows\system32\igfxpers.exe" [2007-09-05 137752]
"QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"avp"="d:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-07-03 303376]
"RTHDCPL"="RTHDCPL.EXE" - d:\windows\RTHDCPL.exe [2008-02-13 16857600]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

d:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-6-10 113664]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 09:05 356352 ----a-w- d:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"d:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"d:\\Program Files\\uTorrent\\utorrent.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\Windows Live Messenger.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;d:\windows\system32\drivers\klbg.sys [15/12/2008 08:41 م 33808]
R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [14/05/2009 02:22 م 9968]
R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [14/05/2009 02:22 م 72944]
R3 klmouflt;Kaspersky Lab KLMOUFLT;d:\windows\system32\drivers\klmouflt.sys [16/05/2009 08:59 م 19472]
R3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [14/05/2009 02:22 م 7408]
.
Contents of the 'Scheduled Tasks' folder

2009-07-16 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com.sa/
uInternet Settings,ProxyOverride = local
IE: Download All Links with IDM - d:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - d:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - d:\program files\Internet Download Manager\IEExt.htm
IE: تحميل الكل بـ إنترنت داونلود مانيجر - d:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - d:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - d:\program files\Internet Download Manager\IEGetVL.htm
DPF: Microsoft XML Parser for Java -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Rootkit scan 2009-07-18 02:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0

**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\d:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):0b,00,7c,c0,c7,32,ff,fd,69,01,97,98,a0,2a,c3,1e,38,44,82,e6,7f,
9f,51,fa,20,e7,63,6e,73,62,35,b6,a8,c9,d0,1a,3b,e5,aa,dc,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8ca61fa3-62de-48ed-9a83-e6bb9774ff0b}]
@Denied: (Full) (Everyone)
"Model"=dword:000000b9
"Therad"=dword:00000019
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(556)
d:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(1516)
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-17 3:00
ComboFix-quarantined-files.txt 2009-07-18 00:00
ComboFix2.txt 2009-07-17 00:46
ComboFix3.txt 2009-07-16 15:55
ComboFix4.txt 2009-07-14 20:39
ComboFix5.txt 2009-07-17 23:54

Pre-Run: 22,124,417,024 bytes free
Post-Run: 22,097,227,776 bytes free

290
 
Aboody

Where are you man ?

I need your help !!

please >> :)
 
اخي انتبه من رفع الموضوع حتى لا يغلق موضوعك !!
ماهو مزود الخدمة عندك ؟
 
عودة
أعلى