الله يجزاك الجنة يالغالي
اليوم عملت فورمات للسي وركبت الويندوز مره ثانية ونفس المشكلة مستمره رغم اني فحصت الهارديسك كاملا بكاسبر وطلع فايروس ومسحه وبعدين يوم فحص السي قال في برامج تعمل بشكل مخالف او كلمة مقاربه لها وعملت لها حذف ورغم هالشيئ ماستفدت شيئ ...
وقمت ركبت البرنامج الأخير اللي اعطيتني واعطاني هالتقرير وياااااارب تعرف حل للمشكلة
ComboFix 09-07-23.04 - zakialjuhani 07/24/2009 20:14.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.446.160 [GMT 4.5:30]
Running from: c:\documents and settings\zakialjuhani\سطح المكتب\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-06-24 to 2009-07-24 )))))))))))))))))))))))))))))))
.
2009-07-24 15:26 . 2009-07-24 15:26 -------- d-----w- c:\documents and settings\zakialjuhani\Application Data\Media Player Classic
2009-07-24 15:24 . 2008-09-16 19:23 168448 ----a-w- c:\windows\system32\unrar.dll
2009-07-24 15:23 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2009-07-24 15:23 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-07-24 15:23 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2009-07-24 15:23 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-07-24 15:23 . 2008-11-06 16:37 3596288 ----a-w- c:\windows\system32\qt-dx331.dll
2009-07-24 15:23 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\divx.dll
2009-07-24 15:23 . 2009-01-07 18:14 60273 ----a-w- c:\windows\system32\pthreadGC2.dll
2009-07-24 15:23 . 2009-06-02 16:11 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-07-24 15:23 . 2004-01-11 22:00 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-07-24 15:23 . 2003-03-19 03:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-07-24 15:23 . 2009-07-24 15:25 -------- d-----w- c:\program files\K-Lite Codec Pack
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-24 15:59 . 2009-07-24 10:45 98336 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-07-24 15:59 . 2009-07-24 10:45 1416 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-07-24 15:59 . 2009-07-24 10:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-07-24 15:58 . 2009-07-24 10:45 480288 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-24 15:58 . 2009-07-24 10:45 4832 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-24 15:22 . 2008-04-15 17:00 40118 ----a-w- c:\windows\system32\perfc001.dat
2009-07-24 15:22 . 2008-04-15 17:00 251674 ----a-w- c:\windows\system32\perfh001.dat
2009-07-24 13:34 . 2009-07-24 13:21 -------- d-----w- c:\program files\Common Files\InstallShield
2009-07-24 13:21 . 2009-07-24 13:21 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-24 11:02 . 2008-01-29 12:59 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-07-24 11:02 . 2009-07-24 10:47 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-07-24 11:02 . 2009-07-24 10:47 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-07-24 11:02 . 2009-07-24 11:02 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
2009-07-24 11:02 . 2009-07-24 11:02 208616 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
2009-07-24 11:02 . 2009-07-24 11:02 226832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
2009-07-24 10:45 . 2009-07-24 10:45 -------- d-----w- c:\program files\Kaspersky Lab
2009-07-24 10:44 . 2009-07-24 10:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-07-24 10:33 . 2009-07-24 10:33 -------- d-----w- c:\program files\microsoft frontpage
2009-07-24 10:31 . 2009-07-24 10:31 -------- d-----w- c:\program files\MSXML 4.0
2009-07-24 10:30 . 2009-07-24 10:30 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-24 10:26 . 2009-07-24 10:26 22144 ----a-w- c:\windows\system32\emptyregdb.dat
2009-07-24 10:26 . 2009-07-24 10:25 -------- d-----w- c:\program files\Windows Media Connect 2
2009-06-16 14:36 . 2008-04-15 17:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2008-04-15 17:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:11 . 2009-05-31 02:16 1289216 ----a-w- c:\windows\system32\quartz.dll
2009-05-31 02:46 . 2001-09-18 11:06 77891 ----a-w- c:\windows\system32\usrmlnka.exe
2009-05-31 02:17 . 2009-05-31 02:17 938496 ----a-w- c:\windows\system32\wmnetmgr.dll
2009-05-31 02:17 . 2009-05-31 02:17 100864 ----a-w- c:\windows\system32\logagent.exe
2009-05-31 02:16 . 2009-05-31 02:16 354304 ----a-w- c:\windows\system32\winhttp.dll
2009-05-31 02:16 . 2009-05-31 02:16 144896 ----a-w- c:\windows\system32\schannel.dll
2009-05-31 02:16 . 2009-05-31 02:16 56832 ----a-w- c:\windows\system32\secur32.dll
2009-05-31 02:15 . 2009-05-31 02:15 333952 ----a-w- c:\windows\system32\drivers\srv.sys
2009-05-31 02:15 . 2009-05-31 02:15 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-05-31 02:15 . 2009-05-31 02:15 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2009-05-31 02:15 . 2009-05-31 02:15 286720 ----a-w- c:\windows\system32\gdi32.dll
2009-05-31 02:15 . 2009-07-24 10:25 227840 ----a-w- c:\windows\system32\wbem\wmiprvse.exe
2009-05-31 02:15 . 2009-07-24 10:25 453120 ----a-w- c:\windows\system32\wbem\wmiprvsd.dll
2009-05-31 02:15 . 2009-05-31 02:15 35328 ----a-w- c:\windows\system32\sc.exe
2009-05-31 02:15 . 2009-05-31 02:15 110592 ----a-w- c:\windows\system32\services.exe
2009-05-31 02:15 . 2009-05-31 02:15 401408 ----a-w- c:\windows\system32\rpcss.dll
2009-05-31 02:15 . 2009-05-31 02:15 283136 ----a-w- c:\windows\system32\pdh.dll
2009-05-31 02:15 . 2009-05-31 02:15 2146816 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-05-31 02:14 . 2009-05-31 02:14 723456 ----a-w- c:\windows\system32\lsasrv.dll
2009-05-31 02:14 . 2009-07-24 10:25 473600 ----a-w- c:\windows\system32\wbem\fastprox.dll
2009-05-31 02:14 . 2009-05-31 02:14 681472 ----a-w- c:\windows\system32\advapi32.dll
2009-05-31 02:14 . 2009-05-31 02:14 1106944 ----a-w- c:\windows\system32\msxml3.dll
2009-05-31 02:14 . 2009-05-31 02:14 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-05-31 02:14 . 2009-05-31 02:14 1379840 ----a-w- c:\windows\system32\msxml6.dll
2009-05-31 02:14 . 2009-05-31 02:14 104960 ----a-w- c:\windows\system32\win32spl.dll
2009-05-31 02:14 . 2009-05-31 02:14 74752 ----a-w- c:\windows\system32\msw3prt.dll
2009-05-31 02:14 . 2009-05-31 02:14 74240 ----a-w- c:\windows\system32\mscms.dll
2009-05-31 02:13 . 2009-07-24 10:25 91648 ----a-w- c:\windows\system32\mtxoci.dll
2009-05-31 02:13 . 2009-07-24 10:25 161792 ----a-w- c:\windows\system32\msdtcuiu.dll
2009-05-31 02:13 . 2009-05-31 02:13 66560 ----a-w- c:\windows\system32\mtxclu.dll
2009-05-31 02:13 . 2009-07-24 10:25 956928 ----a-w- c:\windows\system32\msdtctm.dll
2009-05-31 02:13 . 2009-07-24 10:25 428032 ----a-w- c:\windows\system32\msdtcprx.dll
2009-05-31 02:13 . 2009-07-24 10:25 58880 ----a-w- c:\windows\system32\msdtclog.dll
2009-05-31 02:13 . 2009-05-31 02:13 225856 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2009-05-31 02:13 . 2009-05-31 02:13 361600 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-05-31 02:13 . 2009-05-31 02:13 245248 ----a-w- c:\windows\system32\mswsock.dll
2009-05-31 02:13 . 2009-05-31 02:13 271616 ----a-w- c:\windows\system32\drivers\bthport.sys
2009-05-31 02:11 . 2009-07-24 10:27 691712 ----a-w- c:\windows\system32\inetcomm.dll
2009-05-31 02:11 . 2009-05-31 02:11 253952 ----a-w- c:\windows\system32\es.dll
2009-05-31 02:11 . 2009-05-31 02:11 203136 ----a-w- c:\windows\system32\drivers\RMCast.sys
2009-05-07 15:32 . 2008-04-15 17:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:43 . 2008-06-23 18:15 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:42 . 2008-09-17 22:41 78336 ----a-w- c:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-07-24 208616]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-10-27 73728]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_2"="shell32" [X]
"_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-04-29 124928]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 05:29 م 33808]
R0 ulsata2;ulsata2;c:\windows\system32\drivers\ulsata2.sys [18/09/2008 03:12 ص 124928]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [24/07/2009 05:50 م 13696]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 06:02 م 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 05:06 م 24592]
S3 S3chipid;S3chipid;\??\c:\docume~1\ZAKIAL~1\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys --> c:\docume~1\ZAKIAL~1\LOCALS~1\Temp\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys [?]
.
.
------- Supplementary Scan -------
.
IE: إضافة إلى حاجب إعلان الشعار - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-24 20:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3880)
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
Completion time: 2009-07-24 20:33 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-24 16:03
Pre-Run: 22,153,650,176 bytes free
Post-Run: 22,111,019,008 bytes free
148 --- E O F --- 2009-07-24 13:50