#1
|
||||
|
||||
![]()
السلام عليكم ورحمة الله وبركاته
انا حملت برامج وحذفتها بس مو راضية تروح كمان جهازي بطيئ حيييييييييييييييييييييل عملت تقارير بالادوات المعروفة الاول com...... وها التقرير ساعدوني وش المشكلة ووش حلها التقرير الاول ComboFix 11-07-26.02 - Alam 07/26/2011 15:47:45.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.894.604 [GMT 3:00] Running from: c:\documents and settings\Alam\??? ?طع???\ComboFix.exe AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))) ))))))))) . . c:\docume~1\Alam\MYDOCU~1\BLUETO~1\1C30~ 1\887E~1\ALAKed~1.exe c:\windows\system32\autorun.ini c:\windows\system32\Bifrost . . ((((((((((((((((((((((((( Files Created from 2011-06-26 to 2011-07-26 ))))))))))))))))))))))))))))))) . . 2011-07-26 11:30 . 2011-07-26 11:30 -------- d-----w- c:\program files\K.BrontOk 2011-07-26 11:07 . 2011-07-26 11:08 -------- d--h--w- c:\windows\system32\GroupPolicy 2011-07-25 23:16 . 2011-07-25 23:16 -------- d-----w- c:\windows\VB2_Skins 2011-07-25 23:13 . 2005-06-09 22:02 405504 ----a-w- c:\windows\VB2_SkinControlLt.ocx 2011-07-25 23:13 . 2004-03-09 04:00 212240 ----a-w- c:\windows\RICHTX32.OCX 2011-07-25 23:13 . 1999-03-08 05:00 147728 ----a-w- c:\windows\ASYCFILT.DLL 2011-07-25 17:54 . 2011-07-25 17:54 -------- d-----w- c:\program files\Elcomsoft 2011-07-25 17:54 . 2011-07-25 17:54 -------- d-----w- c:\program files\Elcomsoft Password Recovery 2011-07-25 17:54 . 2011-07-25 17:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Elcomsoft Password Recovery . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))) )))))))))))) . 2011-07-25 17:41 . 2011-06-13 21:13 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cp l 2011-07-04 11:43 . 2011-01-29 19:36 40112 ----a-w- c:\windows\avastSS.scr 2011-07-04 11:43 . 2011-01-29 19:36 199304 ----a-w- c:\windows\system32\aswBoot.exe 2011-07-04 11:36 . 2011-05-22 23:59 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2011-07-04 11:36 . 2011-01-29 19:36 309848 ----a-w- c:\windows\system32\drivers\aswSP.sys 2011-07-04 11:35 . 2011-01-29 19:36 43608 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2011-07-04 11:35 . 2011-01-29 19:36 102616 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2011-07-04 11:35 . 2011-01-29 19:36 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys 2011-07-04 11:32 . 2011-01-29 19:36 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2011-07-04 11:32 . 2011-01-29 19:36 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys 2011-07-04 11:32 . 2011-01-29 19:36 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-05-23 15:01 . 2011-05-23 15:01 1188041 ----a-w- c:\windows\GreenBrowserSetup.exe 2011-05-04 01:52 . 2011-02-04 22:55 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-05-03 23:25 . 2011-02-04 22:55 73728 ----a-w- c:\windows\system32\javacpl.cpl . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2007-11-25 . DABAD58A8BA625B241B90FB1A81154ED . 1547776 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))) )))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\wi ndows\currentversion\explorer\shellicono verlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-07-04 11:43 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wi ndows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "KMAP"="c:\documents and settings\All Users\Documents\hzlp\snap.exe" [2011-03-28 16384] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wi ndows\CurrentVersion\RunOnce] "bbinst"="c:\program files\tuEagles\uninst.exe" [2011-07-25 394120] . [HKEY_USERS\.DEFAULT\Software\Microsoft\W indows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON .EXE" [2004-08-03 15360] . c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-3-31 576104] REALTEK RTL8187 Wireless LAN Utility.lnk - c:\program files\REALTEK\RTL8187 Wireless LAN Utility\RtWLan.exe [2011-2-2 815104] STPStartUp.lnk - c:\documents and settings\All Users\Documents\hzlp\snap.exe [2011-4-14 16384] . [HKEY_LOCAL_MACHINE\software\microsoft\sh ared tools\msconfig\startupreg\CTFMON.EXE] 2004-08-03 21:56 15360 ----a-w- c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\sh ared tools\msconfig\startupreg\GrooveMonitor] 2006-10-26 21:47 31016 -c--a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe . [HKEY_LOCAL_MACHINE\software\microsoft\sh ared tools\msconfig\startupreg\S3Trayp] 2007-06-11 10:15 176128 -c--a-w- c:\windows\system32\S3Trayp.exe . [HKEY_LOCAL_MACHINE\software\microsoft\sh ared tools\msconfig\startupreg\SoundMAXPnP] 2007-12-19 08:20 1044480 -c--a-w- c:\program files\Analog Devices\Core\smax4pnp.exe . [HKEY_LOCAL_MACHINE\software\microsoft\sh ared tools\msconfig\startupreg\VTTimer] 2006-09-21 15:36 53248 -c--a-w- c:\windows\system32\VTTimer.exe . [HKLM\~\services\sharedaccess\parameters\ firewallpolicy\standardprofile\Authorize dApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= . R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaud io.sys [29/01/2011 08:34 م 23040] R1 aswSnx;aswSnx;c:\windows\system32\driver s\aswSnx.sys [23/05/2011 02:59 ص 441176] R1 aswSP;aswSP;c:\windows\system32\drivers\ aswSP.sys [29/01/2011 10:36 م 309848] R2 aswFsBlk;aswFsBlk;c:\windows\system32\dr ivers\aswFsBlk.sys [29/01/2011 10:36 م 19544] R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAP Pkt.sys [02/02/2011 10:33 م 38144] R3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\rtl8 187.sys [02/02/2011 10:33 م 332928] R4 egldrv;egldrv;\??\c:\program files\tuEagles\egldrv.sys --> c:\program files\tuEagles\egldrv.sys [?] S2 gupdate;خدمة تحديث Google (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [04/02/2011 10:45 م 136176] S3 gupdatem;خدمة Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [04/02/2011 10:45 م 136176] . Contents of the 'Scheduled Tasks' folder . 2011-07-26 c:\windows\Tasks\GoogleUpdateTaskMachine Core.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-02-04 19:45] . 2011-07-26 c:\windows\Tasks\GoogleUpdateTaskMachine UA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-02-04 19:45] . 2011-07-26 c:\windows\Tasks\User_Feed_Synchronizati on-{E5374A4A-18A7-4527-958E-197CAF2A5E00}.job - c:\windows\system32\msfeedssync.exe [2009-03-08 01:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com// IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_m ui_en_89D8574934B26AC4.dll/cmsidewiki.html IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.1 192.168.1.1 . - - - - ORPHANS REMOVED - - - - . HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1 128.5462\GoogleToolbarNotifier.exe . . . **************************************** ********************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-07-26 16:24 Windows 5.1.2600 Service Pack 2 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . **************************************** ********************************** . Completion time: 2011-07-26 16:35:24 ComboFix-quarantined-files.txt 2011-07-26 13:35 . Pre-Run: 74,674,192,384 bytes free Post-Run: 74,914,361,344 bytes free . WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition (1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WIND OWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect . - - End Of File - - 8D061BADD6BBE9A1B5B0845224A76FBE أكثر... |
مواقع النشر (المفضلة) |
|
|
![]() |
||||
الموضوع | كاتب الموضوع | المنتدى | مشاركات | آخر مشاركة |
فجأة الاب توب انقلب حالو (جنّ) . . . | RSS | Arabic Rss | 0 | 04-12-2011 09:28 PM |
الي عنده خبرة في الكومبيوتر يتفضل | RSS | Arabic Rss | 0 | 01-06-2011 07:31 PM |
ضيفن جديدن حالن عليكم | RSS | Arabic Rss | 0 | 09-14-2010 06:53 AM |
داونلود منجر أنحذف من حالو | RSS | Arabic Rss | 0 | 07-21-2010 06:27 PM |
توقعات بمشاكل حادة للبنوك الأميركية واستبعاد تأميمها | المجاوشي | المجاوشي للأخبار العامه والسياسية والرياضية | 0 | 04-19-2009 11:18 PM |
|