يعطيك العافيه اخوي هشام ....ربك يعين ..
اختي خلود هذا التقرير الاول
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.364 [GMT 3:00]
Running from: c:\documents and settings\Free User\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-10-21 to 2008-11-21 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-21 00:30 --------- d-----w c:\documents and settings\Free User\Application Data\Free Download Manager
2008-11-21 00:25 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-21 00:07 712,736 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-21 00:07 3,516 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-21 00:07 25,228 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-21 00:07 2,956,832 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-20 12:20 --------- d-----w c:\program files\Wireless WEP Key Password Spy
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-10 01:58 --------- d-----w c:\program files\Common Files\xing shared
2008-10-10 01:58 --------- d-----w c:\program files\Common Files\Real
2008-10-06 01:34 --------- d-----w c:\program files\Total Video Converter
2008-10-05 22:08 --------- d-----w c:\program files\ImTOO
2008-10-03 12:32 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-09-24 02:47 --------- d-----w c:\program files\KoolMoves Demo
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\win32k.sys
2008-09-04 16:42 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-29 17:06 1,350,664 ----a-w c:\windows\system32\msxml6.dll
2008-08-26 07:24 826,368 ----a-w c:\windows\system32\wininet.dll
2008-04-02 16:43 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2008-06-28 09:57 16,384 --sha-w c:\windows\system32\config\systemprofile\s\index.dat
2008-06-28 09:57 16,384 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
2008-06-28 09:57 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [12/31/2002 03:00 PM 15360]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [08/16/2006 01:53 AM 2089007]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [01/28/2008 09:06 PM 68856]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [01/19/2007 02:55 PM 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [07/09/2001 11:50 AM 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [11/10/2005 03:03 PM 36975]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [03/16/2007 08:10 PM 1392640]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [02/21/2007 01:19 PM 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [02/21/2007 01:17 PM 970752]
"MsgCenterExe"="c:\program files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" [10/10/2008 04:57 AM 69632]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [10/19/2007 10:16 PM 286720]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [01/26/2004 01:38 PM 866816]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [10/10/2008 04:57 AM 185872]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"BluetoothAuthenticationAgent"="bthprops.cpl" [12/31/2002 03:00 PM 110592 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [12/31/2002 03:00 PM 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-12-30 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2105:UDP"= 2105:UDP:Windows Media Format SDK (IEXPLORE.EXE)
"2104:UDP"= 2104:UDP:Windows Media Format SDK (IEXPLORE.EXE)
"2109:UDP"= 2109:UDP:Windows Media Format SDK (IEXPLORE.EXE)
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592]
.
s of the 'Scheduled Tasks' folder
2008-11-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [04/11/2008 05:57 PM]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Free User\Application Data\Mozilla\Firefox\Profiles\ddgq1nlr.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://uk.msn.com/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-11-21 03:31:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 11/21/2008 3:32:45
ComboFix-quarantined-files.txt 2008-11-21 00:32:38
Pre-Run: 35,632,553,984 bytes free
Post-Run: 35,626,704,896 bytes free
108 --- E O F --- 2008-11-13 00:54:45