ربما هذا يساعدكم على حل مشكلتي مع الماسنجر
هذا هو تقرير combofix وطبعاً بعد تعطيل برنامج الكاسبر و إغلاق المتصفح و الماسنجر
ComboFix 09-11-29.01 - عبدالرزاق 11/30/2009 2:34.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1256.963.1025.18.511.286 [GMT 2:00]
Running from: E:\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-1
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-10
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-2
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-21
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-22
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-23
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-24
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-25
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-26
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-27
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-28
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-29
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-3
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-30
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-4
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-5
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-6
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-7
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-8
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok-9-9
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Bron.tok.A9.em.bin
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Kosong.Bron.Tok.txt
c:\documents and settings\عبدالرزاق\Local Settings\Application Data\ListHost9.txt
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-1
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-2
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-21
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-22
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-23
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-24
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-25
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-26
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-27
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-28
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-29
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-3
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-30
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-4
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-5
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-6
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-9-9
c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok.A9.em.bin
c:\documents and settings\NetworkService\Local Settings\Application Data\Kosong.Bron.Tok.txt
c:\documents and settings\NetworkService\Local Settings\Application Data\ListHost9.txt
c:\documents and settings\NetworkService\Local Settings\Application Data\Update.9.Bron.Tok.bin
c:\windows\system32\logs
c:\windows\winhelp.ini
.
((((((((((((((((((((((((( Files Created from 2009-10-28 to 2009-11-30 )))))))))))))))))))))))))))))))
.
2009-11-29 19:50 . 2009-11-29 19:56 -------- d-----w- c:\program files\Smart Phone Recorder Demo
2009-11-29 19:45 . 2009-11-29 19:57 -------- d-----w- c:\program files\Phone Call Recorder
2009-11-29 19:28 . 2009-11-29 19:31 -------- d-----w- c:\documents and settings\عبدالرزاق\Application Data\Advanced Phone Recorder
2009-11-29 19:16 . 2009-11-29 19:24 -------- d-----w- c:\documents and settings\عبدالرزاق\Application Data\Modem Spy
2009-11-29 19:16 . 2009-11-29 19:16 -------- d-----w- c:\program files\Modem Spy
2009-11-29 12:13 . 2009-11-29 12:13 -------- d-----w- c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Runscanner.net
2009-11-29 12:13 . 2009-11-29 12:13 -------- d-----w- c:\program files\Trend Micro
2009-11-29 09:53 . 2009-11-29 09:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Modem Spy Pro
2009-11-29 09:50 . 2009-11-29 09:50 8704 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall\Modem Spy\10000004a00002i\winhlp32.exe
2009-11-29 09:50 . 2009-11-29 09:50 8704 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall\Modem Spy\4000004500002i\modemspy.exe
2009-11-29 09:50 . 2009-11-29 09:50 8704 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall\Modem Spy\4000002f00002i\p31aa0c.exe
2009-11-29 09:50 . 2009-11-29 09:50 8704 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall\Modem Spy\4000005a00003i\__modemspy.exe
2009-11-29 09:28 . 2009-11-29 09:49 368640 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall\Modem Spy\%Profile%\Local Settings\Temp\__modemspy.exe
2009-11-29 09:04 . 2009-11-29 09:04 8704 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall\Modem Spy\10000001400002i\NOTEPAD.EXE
2009-11-28 15:47 . 2009-11-28 15:47 225248 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-11-28 15:40 . 2009-11-28 15:40 -------- d-----w- c:\windows\system32\XPSViewer
2009-11-28 15:38 . 2009-11-28 15:38 -------- d-----w- c:\program files\Reference Assemblies
2009-11-28 15:37 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2009-11-26 12:11 . 2009-11-26 12:11 8704 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall\Modem Spy\4000002100002i\upgrader.exe
2009-11-26 11:50 . 2009-11-26 11:50 8704 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall\Modem Spy\1000000b00002i\RUNDLL32.EXE
2009-11-26 11:48 . 2009-11-26 11:48 8704 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall\Modem Spy\1000000600002i\svchost.exe
2009-11-26 11:46 . 2009-11-26 11:46 8704 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall\Modem Spy\10000002300002i\SNDREC32.EXE
2009-11-26 11:41 . 2009-11-26 11:41 -------- d-----w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall
2009-11-20 14:18 . 2009-11-20 14:18 -------- d-----w- c:\documents and settings\عبدالرزاق\Local Settings\Application Data\Windows Live Writer
2009-11-20 14:18 . 2009-11-20 14:18 -------- d-----w- c:\documents and settings\عبدالرزاق\Application Data\Windows Live Writer
2009-11-20 14:02 . 2009-11-20 14:05 -------- d-----w- c:\windows\Modio
2009-11-20 13:57 . 2003-02-25 12:30 45056 ----a-w- c:\windows\system32\vusetup.dll
2009-11-20 13:57 . 2002-10-24 08:07 6912 ----a-w- c:\windows\system32\drivers\vulfnth.sys
2009-11-20 13:57 . 2003-05-24 07:06 11392 ----a-w- c:\windows\system32\drivers\vulfntr.sys
2009-11-20 13:03 . 2009-08-05 20:48 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-11-20 13:02 . 2009-11-20 13:02 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-11-20 13:01 . 2009-11-20 13:01 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-11-14 15:22 . 1993-10-14 15:57 21648 ----a-w- c:\windows\system\CTL3DV2.DLL
2009-11-14 15:21 . 1995-04-28 02:50 97072 ----a-w- c:\windows\system\BWCC0007.DLL
2009-11-14 15:21 . 1995-04-28 02:50 96928 ----a-w- c:\windows\system\BWCC000C.DLL
2009-11-14 15:21 . 1995-04-28 02:50 96912 ----a-w- c:\windows\system\BWCC0009.DLL
2009-11-14 15:21 . 1995-04-28 02:50 164928 ----a-w- c:\windows\system\BWCC.DLL
2009-11-14 15:21 . 1994-11-17 00:19 264800 ----a-w- c:\windows\system\BOCOLE.DLL
2009-11-14 15:21 . 1995-04-28 02:50 58192 ----a-w- c:\windows\system\MHRUN300.DLL
2009-11-14 15:21 . 1995-04-28 02:50 244192 ----a-w- c:\windows\system\MHCARDS.DLL
2009-11-14 15:21 . 1995-04-28 02:50 81920 ----a-w- c:\windows\system\BIVBX11.DLL
2009-11-14 15:21 . 2009-11-14 15:47 -------- dc----w- C:\ACROREAD
2009-11-14 15:21 . 2009-11-14 15:21 -------- dc----w- C:\TCWIN45
2009-11-08 07:13 . 2009-11-08 07:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2009-11-08 07:11 . 2009-11-11 07:47 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-11-08 07:11 . 2009-11-08 07:11 -------- d-----w- c:\documents and settings\عبدالرزاق\Application Data\Nokia
2009-11-08 07:09 . 2009-11-08 07:09 -------- d-----w- c:\program files\DIFX
2009-11-08 07:09 . 2009-11-08 07:09 -------- d-----w- c:\documents and settings\عبدالرزاق\Application Data\PC Suite
2009-11-08 07:09 . 2009-11-08 07:09 -------- d-----w- c:\program files\PC Connectivity Solution
2009-11-08 07:09 . 2007-02-22 08:15 90624 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-11-08 07:09 . 2009-11-28 13:34 -------- d-----w- c:\program files\Nokia
2009-11-06 19:46 . 2009-11-06 19:46 452104 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Real\RealPlayer\setup\AU_setup9.exe
2009-10-31 12:23 . 2009-10-31 12:23 -------- d-----w- c:\program files\MSXML 4.0
2009-10-31 11:51 . 2009-07-03 16:55 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-10-31 11:51 . 2009-07-03 16:55 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-30 00:42 . 2009-10-10 17:55 8669728 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-11-30 00:42 . 2009-10-10 17:55 270880 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-11-30 00:31 . 2009-10-10 17:55 29408 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-11-30 00:31 . 2009-10-10 17:55 120308 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-11-30 00:31 . 2006-02-01 10:00 -------- d-----w- c:\documents and settings\عبدالرزاق\Application Data\Free Download Manager
2009-11-29 19:13 . 2006-02-01 10:01 -------- d-----w- c:\documents and settings\عبدالرزاق\Application Data\Software Informer
2009-11-29 19:12 . 2009-02-20 11:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-11-29 09:50 . 2007-09-23 08:35 42375 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall\Modem Spy\%ProgramFilesDir%\Modem Spy\uninstall.exe
2009-11-29 09:50 . 2007-09-23 08:35 38400 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall\Modem Spy\%ProgramFilesDir%\Modem Spy\modemspy.dll
2009-11-29 09:50 . 2007-09-23 08:35 86016 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall\Modem Spy\%ProgramFilesDir%\Modem Spy\upgrader.exe
2009-11-29 09:50 . 2007-09-23 08:35 258048 ----a-w- c:\documents and settings\عبدالرزاق\Application Data\Thinstall\Modem Spy\%ProgramFilesDir%\Modem Spy\modemspy.exe
2009-11-29 09:43 . 2006-02-03 20:03 -------- d-----w- c:\program files\HP
2009-11-29 09:31 . 2006-02-01 10:03 -------- d-----w- c:\program files\Opera 10 Preview
2009-11-28 15:57 . 2009-03-03 05:40 99888 ----a-w- c:\documents and settings\عبدالرزاق\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-28 15:48 . 2001-09-19 12:00 72364 ----a-w- c:\windows\system32\perfc001.dat
2009-11-28 15:48 . 2001-09-19 12:00 374322 ----a-w- c:\windows\system32\perfh001.dat
2009-11-28 15:47 . 2006-01-27 11:47 -------- d-----w- c:\program files\MSBuild
2009-11-22 18:32 . 2009-02-19 22:40 106496 ----a-w- c:\windows\DUMP81d2.tmp
2009-11-21 09:26 . 2009-09-21 14:09 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-20 13:03 . 2009-04-20 15:09 -------- d-----w- c:\program files\Windows Live
2009-11-16 08:44 . 2009-05-08 20:57 -------- d-----w- c:\documents and settings\عبدالرزاق\Application Data\dvdcss
2009-11-14 15:13 . 2009-03-24 18:51 -------- d-----w- c:\program files\learn computer
2009-11-11 08:07 . 2009-06-04 22:14 15840 ----a-w- c:\windows\system32\Machnm1.exe
2009-11-10 21:02 . 2006-01-27 11:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-26 19:29 . 2009-10-26 19:29 -------- d-----w- c:\documents and settings\عبدالرزاق\Application Data\FarStone
2009-10-26 19:29 . 2009-10-26 19:29 65536 ----a-w- c:\windows\system32\VDPersns.dat
2009-10-26 19:27 . 2009-10-26 19:27 -------- d-----w- c:\program files\FarStone
2009-10-26 19:26 . 2009-10-26 19:26 81920 ----a-w- c:\windows\system32\Dversion.dll
2009-10-26 19:26 . 2009-10-26 19:26 122880 ----a-w- c:\windows\system32\DVC.dll
2009-10-26 19:26 . 2009-02-20 12:01 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-10 17:56 . 2009-10-10 17:56 91700 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-10 17:56 . 2009-10-10 17:56 85860 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-10 17:55 . 2009-10-10 17:55 -------- d-----w- c:\program files\Kaspersky Lab
2009-10-10 17:41 . 2009-10-09 23:53 -------- d-----w- c:\program files\BitDefender
2009-10-10 15:46 . 2009-10-10 15:46 192512 ----a-w- c:\windows\system32\txmlutil.dll
2009-10-10 09:04 . 2009-10-09 23:50 -------- d-----w- c:\program files\Common Files\BitDefender
2009-09-11 14:17 . 2004-08-03 22:55 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-03 22:55 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-03-21 14:08 . 2004-08-03 22:55 167324 --sha-r- c:\windows\system32\vcgzeyt.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2009-01-31 3399727]
"Software Informer"="c:\program files\Software Informer\softinfo.exe" [2009-03-11 1724485]
"AdobeBridge"="c:\program files\Adobe\Adobe Bridge CS4\Bridge.exe" [2008-08-28 13145448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-07-08 1397760]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_14\bin\jusched.exe" [2007-10-05 75256]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-20 185896]
"FixCamera"="c:\windows\FixCamera.exe" [2007-07-11 20480]
"snpstd3"="c:\windows\vsnpstd3.exe" [2007-05-10 835584]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-04-21 270336]
"USB Antivirus"="c:\program files\USB Disk Security\USBGuard.exe" [2008-09-23 798720]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"HP Software Update"="d:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-25 49152]
"hpqSRMon"="d:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]
"RAMDrive"="c:\program files\FarStone\VirtualDrive\VHD\RDTask.exe" [2004-09-22 36864]
"VirtualDrive"="c:\program files\FarStone\VirtualDrive\VDTask.exe" [2004-09-30 139264]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-06-01 86016]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-06-01 1519616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\م §ںé©ھںç\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\عبدالرزاق\\سطح المكتب\\Modem Spy 3.6 Arabic\\modemspy.exe"=
"c:\\Program Files\\Opera 10 Preview\\opera.exe"=
"c:\\Documents and Settings\\عبدالرزاق\\Application Data\\Thinstall\\Modem Spy\\4000004500002i\\modemspy.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4247:TCP"= 4247:TCP:hvgwzmj
"4100:UDP"= 4100:UDP:uPNP Router Control Port
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [20/11/2009 03:03 أبو الهيثم 54752]
R3 FVDSCSI;FVDSCSI;c:\windows\system32\drivers\fvdscsi.sys [26/10/2009 09:28 أبو الهيثم 72478]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13/12/2007 12:28 أبو الهيثم 24592]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [30/04/2009 05:19 أبو الهيثم 682232]
S2 ejjwjrbxm;Boot Monitor;c:\windows\system32\svchost.exe -k netsvcs [04/08/2004 12:56 أبو الهيثم 14336]
S3 fsssvc;خدمة أمان العائلة في Windows Live;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 10:48 أبو الهيثم 704864]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ejjwjrbxm
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: تحميل الفيديو بواسطة Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: تحميل الكل بواسطة Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: تحميل المحددة بواسطة Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: تحميل بواسطة Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
.
.
------- File Associations -------
.
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - c:\program files\myBabylon_English\tbmyBa.dll
BHO-{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - c:\program files\myBabylon_English\tbmyBa.dll
Toolbar-{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - c:\program files\myBabylon_English\tbmyBa.dll
WebBrowser-{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - c:\program files\myBabylon_English\tbmyBa.dll
HKLM-Run-SMPAutoStart - c:\progra~1\SMARTP~1\smpdemo.exe
AddRemove-MetaProducts Mass Downloader - c:\program files\Mass Downloader\massdown.exe
AddRemove-NVIDIA Drivers - c:\windows\system32\nvudisp.exe UninstallGUI
AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-Turbo Pascal 7.0 - c:\windows\MSPUNIN.EXE `C:\Tp` Turbo Pascal 7.0
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-30 02:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ejjwjrbxm]
"ServiceDll"="c:\windows\system32\vcgzeyt.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1343024091-854245398-839522115-1003\Software\Microsoft\Speech\AudioOutput\TokenEnums\MMAudioOut\ B1'!) *.7 *'DEH/E *#*0*\Attributes]
"Vendor"="Microsoft"
"Technology"="MMSys"
[HKEY_USERS\S-1-5-21-1343024091-854245398-839522115-1003\Software\Microsoft\Speech\AudioOutput\TokenEnums\MMAudioOut\ B1'!) *.7 *'DEH/E *#*0*\UI\AudioVolume]
"CLSID"="{364D8E0B-67CB-4547-9948-9E7F1B1743ED}"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1044)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(1100)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll
.
Completion time: 2009-11-30 02:44
ComboFix-quarantined-files.txt 2009-11-30 00:44
Pre-Run: 5,016,707,072 bytes free
Post-Run: 5,027,856,384 bytes free
- - End Of File - - BFDABF1ABF29A18F4FA6D81BFF0CD5AD
و هذا تقرير الهايجاك بعد التقرير المذكور آنفاً وطبعاً كان الكاسبر معطل
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:34:12 أبو الهيثم, on 30/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\slrundll.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_14\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\vsnpstd3.exe
C:\WINDOWS\tsnpstd3.exe
C:\Program Files\USB Disk Security\USBGuard.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
D:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Program Files\FarStone\VirtualDrive\VHD\RDTask.exe
C:\Program Files\FarStone\VirtualDrive\VDTask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\Software Informer\softinfo.exe
C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_14\bin\ssv.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll (file missing)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_14\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [USB Antivirus] C:\Program Files\USB Disk Security\USBGuard.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] D:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RAMDrive] "C:\Program Files\FarStone\VirtualDrive\VHD\RDTask.exe"
O4 - HKLM\..\Run: [VirtualDrive] "C:\Program Files\FarStone\VirtualDrive\VDTask.exe" /AutoRestore
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun
O4 - HKCU\..\Run: [AdobeBridge] "C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe" -stealth
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: تحميل الفيديو بواسطة Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: تحميل الكل بواسطة Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: تحميل المحددة بواسطة Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: تحميل بواسطة Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_14\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_14\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: تدوين هذا في المدونة - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &تدوين هذا في Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{759193F0-F288-4DE7-896B-AC9DF2FD2EC4}: NameServer = 213.178.225.25
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
--
End of file - 10108 bytes