طيب عزيزي عطني هالتقرير
عطل جميع برامج الحماية ,,
وحمل هذه الاداة واحفظها على سطح المكتب
عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
انتظر حتى الاداة تنتهي من فحص جهازك ,,, وبشكل تلقائي يعاد تشغيل جهازك ,,
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
انتظر حتى يظهر لك تقرير ,, انسخه والصقه بردك القادم
بارك الله فيكم اخوانى الاحباب هكذا كما تعودنا منكم
جزاكم الله خيرا
مشكور اخى فارس الملاك على اهتمامك
اليك اخى الكريم التقرير
ComboFix 08-07-02.5 - XPPRESP3 2008-07-04 3:14:55.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.131 [GMT 3:00]
Running from: G:\للصيانة\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-06-04 to 2008-07-04 )))))))))))))))))))))))))))))))
.
2008-08-03 21:32 . 2008-08-03 21:32 1,293,654 --a------ C:\WINDOWS\ACD Wallpaper.bmp
2008-08-03 21:30 . 2008-08-03 21:30 <DIR> d--hs---- C:\FOUND.001
2008-08-03 21:25 . 2008-08-03 21:25 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-08-03 21:24 . 2008-08-03 21:24 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-08-03 21:20 . 2008-08-03 21:20 <DIR> d--hs---- C:\FOUND.000
2008-07-03 21:36 . 2008-07-03 21:36 <DIR> d-------- C:\Program Files\Real
2008-07-03 21:36 . 2008-07-03 21:36 <DIR> d-------- C:\Program Files\Debugging Tools for Windows
2008-07-03 21:36 . 2008-07-03 21:36 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-07-03 21:36 . 2008-07-03 21:36 <DIR> d-------- C:\Program Files\Common Files\Real
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-03 18:31 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\ACD Systems
2008-07-31 22:40 --------- d-----w C:\Program Files\S3
2008-07-31 22:39 --------- d-----w C:\Program Files\VIA Technologies, Inc
2008-07-31 22:26 --------- d-----w C:\Program Files\Yahoo!
2008-07-31 22:25 --------- d-----w C:\Program Files\Winamp
2008-07-31 22:25 --------- d-----w C:\Program Files\TaskSwitchXP
2008-07-31 22:24 --------- d-----w C:\Program Files\Java
2008-07-31 22:24 --------- d-----w C:\Program Files\Common Files\Java
2008-07-31 22:21 --------- d-----w C:\Documents and Settings\XPPRESP3\Application Data\Media Player Classic
2008-07-31 22:20 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-07-31 22:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-31 22:13 --------- d-----w C:\Program Files\Google
2008-07-31 22:13 --------- d-----w C:\Program Files\FlashGet
2008-07-31 22:13 --------- d-----w C:\Program Files\CCleaner
2008-07-31 22:12 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-31 22:11 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-07-31 22:11 --------- d-----w C:\Program Files\ACD Systems
2008-07-31 22:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\ACD Systems
2005-03-11 14:28 20,640 ----a-w C:\WINDOWS\inf\pxhelp20.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:56 15360]
"TaskSwitchXP"="C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe" [2005-07-27 22:00 61952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-07-03 21:36 180269]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 09:56 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AudioDeck.lnk - C:\Program Files\VIA Technologies, Inc\VIA Audio Driver Setup Program\AudioDeck\AudioDeck.exe [2008-08-01 01:39:37 581632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.3iv2"= C:\PROGRA~1\K-LITE~1\codecs\3IVXVF~1.DLL
"VIDC.VP60"= C:\PROGRA~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP61"= C:\PROGRA~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP62"= C:\PROGRA~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP70"= C:\PROGRA~1\K-LITE~1\codecs\vp7vfw.dll
"VIDC.VP31"= C:\PROGRA~1\K-LITE~1\codecs\vp31vfw.dll
"VIDC.FFDS"= C:\PROGRA~1\K-LITE~1\ffdshow\ff_vfw.dll
"msacm.ac3acm"= C:\PROGRA~1\K-LITE~1\codecs\ac3acm.acm
"msacm.l3fhg"= C:\PROGRA~1\K-LITE~1\codecs\l3codecp.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
S3 Vsp;Vsp;C:\WINDOWS\system32\drivers\Vsp.sys [2003-05-27 16:45]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-04 03:15:52
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-04 3:16:16
ComboFix-quarantined-files.txt 2008-07-04 00:16:14
Pre-Run: 5,619,580,928 bytes free
Post-Run: 5,612,609,536 bytes free
100