عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
بارك الله بك اخي زيزوم على المساعدة بالنسبة للاداة خرجت مرة واحدة فقط رسالة بالضغط على y
ولم يعد الجهاز انتهت الاداة وعمل لي تقرير وها هو التقرير
كود:
ComboFix 08-05-01.3 - hani1 2008-05-04 11:34:11.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1256.963.1036.18.692 [GMT 2:00]
Endroit: C:\Documents and Settings\hani1\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
* Resident AV is active
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RةCUPةRATION N'EST PAS INSTALLةE SUR CETTE MACHINE !![/b][/color]
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-04 to 2008-05-04 ))))))))))))))))))))))))))))))))))))
.
2008-05-02 15:30 . 2007-09-23 21:56 1,141,697 --a------ C:\WINDOWS\system32\SmitfraudFix.cmd
2008-05-02 15:08 . 2008-05-02 15:08 <REP> d-------- C:\Program Files\Fichiers communs\xing shared
2008-05-02 10:39 . 2008-05-02 10:39 <REP> d-------- C:\WINDOWS\Sun
2008-05-02 10:33 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-02 10:32 . 2008-05-02 10:33 <REP> d-------- C:\Program Files\Java
2008-05-02 10:32 . 2008-05-02 10:32 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-05-01 16:04 . 2008-05-01 16:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-05-01 10:09 . 2008-05-01 10:09 <REP> d-------- C:\Documents and Settings\hani1\Application Data\Zyzoom_Autorun_Viruses_cleaner
2008-05-01 09:46 . 2008-05-01 09:46 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-04-30 16:24 . 2008-04-30 16:27 <REP> d-------- C:\Documents and Settings\hani1\Application Data\FreeCall
2008-04-27 20:37 . 2008-04-27 20:37 <REP> d-------- C:\Documents and Settings\All Users.WIN2
2008-04-27 20:10 . 2008-05-01 16:05 <REP> d-------- C:\Documents and Settings\hani1\Application Data\Ahead
2008-04-26 09:52 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-04-25 19:53 . 2008-04-25 19:53 <REP> d-------- C:\Documents and Settings\hani1\Application Data\Downloaded Installations
2008-04-23 18:47 . 2008-04-25 19:08 <REP> d-------- C:\WINDOWS\system32\Adobe
2008-04-22 17:52 . 2008-01-07 14:29 352 --ah----- C:\WINDOWS\nod32fixtemdono.reg
2008-04-20 17:52 . 2006-12-25 04:29 9,488 -ra------ C:\WINDOWS\kill.exe
2008-04-20 17:50 . 2008-04-20 17:50 0 --a------ C:\WINDOWS\system32\WinWare.sys
2008-04-20 17:33 . 2008-04-20 17:33 <REP> d--hs---- C:\found.000
2008-04-19 17:40 . 2008-04-19 17:40 <REP> d-------- C:\Documents and Settings\hani1\Application Data\vlc
2008-04-18 19:00 . 2008-04-18 19:00 <REP> d-------- C:\Documents and Settings\hani1\Application Data\DivX
2008-04-15 17:25 . 2008-04-15 17:46 385 --a------ C:\WINDOWS\ODBC.INI
2008-04-15 17:24 . 2003-06-19 01:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-04-15 17:23 . 2008-04-15 17:23 <REP> d-------- C:\WINDOWS\SHELLNEW
2008-04-15 17:22 . 2008-04-15 17:22 <REP> d-------- C:\Program Files\Microsoft.NET
2008-04-13 22:08 . 2008-04-13 22:08 <REP> d-------- C:\Documents and Settings\invite\Application Data\FlySuite
2008-04-13 22:07 . 2008-04-13 22:10 <REP> d-------- C:\Documents and Settings\hani1\Application Data\FlySuite
2008-04-09 20:00 . 2007-10-02 20:06 <REP> d-------- C:\WINDOWS\system32\Restoration
2008-04-06 23:35 . 2008-04-06 23:37 137 --a------ C:\WINDOWS\system32\test.aok
2008-04-05 20:57 . 2008-04-06 22:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Installations
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-02 13:31 2,130 ----a-w C:\WINDOWS\system32\tmp.reg
2008-05-02 13:07 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-05-02 13:07 --------- d-----w C:\Program Files\Real
2008-05-02 13:07 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-04-28 17:21 --------- d-----w C:\Program Files\Lexmark X1100 Series
2008-04-22 17:35 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-04-22 15:50 --------- d-----w C:\Program Files\ESET
2008-04-20 16:52 --------- d-----w C:\Documents and Settings\hani1\Application Data\cleaner
2008-04-19 15:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-19 15:41 --------- d-----w C:\Documents and Settings\hani1\Application Data\PC Suite
2008-04-13 17:44 0 ----a-w C:\Program Files\MultiTransefind.ini
2008-04-07 15:56 --------- d-----w C:\Documents and Settings\invite\Application Data\PC Suite
2008-04-07 15:56 --------- d-----w C:\Documents and Settings\invite\Application Data\Nokia
2008-04-05 18:59 --------- d-----w C:\Documents and Settings\hani1\Application Data\Nokia
2008-04-05 18:58 --------- d-----w C:\Program Files\DIFX
2008-04-03 17:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-04-03 17:24 --------- d-----w C:\Program Files\MultiTranse
2008-04-02 18:09 --------- d-----w C:\Documents and Settings\hani1\Application Data\CyberScrub
2008-04-01 15:32 --------- d-----w C:\Program Files\Apple Software Update
2008-04-01 15:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-03-31 21:25 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-30 18:25 360,064 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-03-30 18:25 360,064 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2008-03-30 00:44 --------- d-----w C:\Program Files\MSXML 6.0
2008-03-29 12:57 --------- d-----w C:\Program Files\MSBuild
2008-03-29 12:48 --------- d-----w C:\Program Files\Reference Assemblies
2008-03-28 22:38 --------- d-----w C:\Program Files\MSXML 4.0
2008-03-28 22:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2008-03-28 16:38 --------- d-----w C:\Documents and Settings\hani1\Application Data\Leadertech
2008-03-27 22:35 --------- d-----w C:\Documents and Settings\hani1\Application Data\AdobeUM
2008-03-27 20:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nokia
2008-03-24 15:08 --------- d-----w C:\Documents and Settings\hani1\Application Data\NSeries
2008-03-24 15:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-03-23 20:08 --------- d-----w C:\Program Files\Logitech
2008-03-23 17:26 --------- d-----w C:\Documents and Settings\hani1\Application Data\Datalayer
2008-03-22 17:25 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-03-22 17:25 286,720 ------w C:\WINDOWS\Setup1.exe
2008-03-22 09:52 --------- d-----w C:\Documents and Settings\hani1\Application Data\Camtech
2008-03-21 17:22 634,628 ----a-w C:\WINDOWS\java\Packages\XJ3V7LNT.ZIP
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 18:04 --------- d-----w C:\Documents and Settings\invite\Application Data\VoipDiscount
2008-03-19 13:02 --------- d-----w C:\Documents and Settings\hani1\Application Data\VoipDiscount
2008-03-19 12:33 --------- d-----w C:\Documents and Settings\invite\Application Data\ESET
2008-03-18 20:36 --------- d-----w C:\Program Files\MSN Messenger
2008-03-18 20:26 --------- d-----w C:\Program Files\Fichiers communs\LogiShrd
2008-03-18 20:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Logitech
2008-03-18 20:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Logishrd
2008-03-18 20:11 --------- d-----w C:\Program Files\VirginMega
2008-03-18 20:08 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-03-18 20:08 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-03-18 20:03 155,995 ----a-w C:\WINDOWS\java\Packages\6QKNP775.ZIP
2008-03-18 20:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-03-18 19:55 --------- d-----w C:\Documents and Settings\hani1\Application Data\ESET
2008-03-18 19:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-03-18 19:52 --------- d-----w C:\Program Files\C-Media 3D Audio
2008-03-18 19:47 --------- d-----w C:\Program Files\SiS VGA Utilities V3.57.53
2008-03-18 19:42 --------- d-----w C:\Program Files\sisagp
2008-03-18 19:39 --------- d-----w C:\Program Files\ma-config.com
2008-03-18 19:39 --------- d-----w C:\Documents and Settings\hani1\Application Data\ma-config.com
2008-03-18 19:02 --------- d-----w C:\Program Files\microsoft frontpage
2008-03-18 18:59 --------- d-----w C:\Program Files\Services en ligne
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:35 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:02 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-09 21:41 104,960 ----a-w C:\WINDOWS\system32\ipms by genial78.exe
2008-02-05 07:48 77,824 ----a-w C:\WINDOWS\system32\OnlineScannerUninstaller.exe
.
[code]<pre>
----a-w 225,388 2008-04-25 17:52:51 C:\Documents and Settings\hani1\Mes documents\Nouveau dossier (2)\AIO mon cd avec tous\CD_Root\AutoPlay\Docs\Anti virus\KasperSky-AntiVirus-English\Key-Kaspersky 18th April keys .exe
----a-w 225,388 2008-04-25 17:52:51 C:\Documents and Settings\hani1\Mes documents\Nouveau dossier (2)\AIO mon cd avec tous\CD_Root\AutoPlay\Docs\Anti virus\KasperSky-AntiVirus.Francais\Key-Kaspersky 18th April keys .exe
----a-w 225,388 2008-04-25 17:52:51 C:\Documents and Settings\hani1\Mes documents\Nouveau dossier (2)\AIO mon cd avec tous\CD_Root\AutoPlay\Docs\Anti virus\KasperSky-internet-security7.0.1.325en\Key-Kaspersky 18th April keys .exe
----a-w 225,388 2008-04-25 17:52:51 C:\Documents and Settings\hani1\Mes documents\Nouveau dossier (2)\AIO mon cd avec tous\CD_Root\AutoPlay\Docs\Anti virus\KaspeSky-internet-security7.0.1.325-frrancais\Key-Kaspersky 18th April keys .exe
----a-w 225,388 2008-04-25 17:52:51 C:\Documents and Settings\hani1\Mes documents\Nouveau dossier (2)\AIO mon cd avec tous\CD_Root\AutoPlay\Docs\Serials\Nouveau dossier\KasperSky-AntiVirus-English\Key-Kaspersky 18th April keys .exe
----a-w 225,388 2008-04-25 17:52:51 C:\Documents and Settings\hani1\Mes documents\Nouveau dossier (2)\AIO mon cd avec tous\CD_Root\AutoPlay\Docs\Serials\Nouveau dossier\KasperSky-AntiVirus.Francais\Key-Kaspersky 18th April keys .exe
----a-w 225,388 2008-04-25 17:52:51 C:\Documents and Settings\hani1\Mes documents\Nouveau dossier (2)\AIO mon cd avec tous\CD_Root\AutoPlay\Docs\Serials\Nouveau dossier\KasperSky-internet-security7.0.1.325en\Key-Kaspersky 18th April keys .exe
----a-w 225,388 2008-04-25 17:52:51 C:\Documents and Settings\hani1\Mes documents\Nouveau dossier (2)\AIO mon cd avec tous\CD_Root\AutoPlay\Docs\Serials\Nouveau dossier\KaspeSky-internet-security7.0.1.325-frrancais\Key-Kaspersky 18th April keys .exe
</pre>
------- Sigcheck -------
2007-10-30 18:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-03-30 20:25 360064 8ccb240c262c8f9877fffdc174afca8e C:\WINDOWS\system32\dllcache\TCPIP.SYS
2008-03-30 20:25 360064 8ccb240c262c8f9877fffdc174afca8e C:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2008-03-18 22:36 7094272]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:54 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-02-20 12:06 1443072]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-05-02 15:07 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:54 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LexPPS.exe]
--a------ 2003-08-18 11:32 174592 C:\WINDOWS\system32\lexpps.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RRT-Auto]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zyz1]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2006-02-14 17:02]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-05-04 11:37:34
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-05-04 11:39:29
ComboFix-quarantined-files.txt 2008-05-04 09:39:23
Pre-Run: 13,353,594,880 octets libres
Post-Run: 13,896,040,448 octets libres
170 --- E O F --- 2008-04-30 15:30:47
[/CODE]
وهذا تقرير الهيجاك
كود:
Logfile of HijackThis v1.99.1
Scan saved at 11:40:39, on 04/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\hani1\LOCALS~1\Temp\Rar$EX00.213\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [URL]http://www.google.be/[/URL]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [URL]http://go.microsoft.com/fwlink/?LinkId=69157[/URL]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Pool 2 - [URL]http://origin.games.yahoo.net/games/clients/y/poti_x.cab[/URL]
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - [URL]http://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_2_0_4_13.cab[/URL]
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
شكرا لك مرة اخرى اخي زيزوم