رد: رسالة خطا عند عمل استعادة نظام [تم الغاء هذه العملية بسبب تاثير القيود الموجودة على هذا الكمبيو
مشكووور أخوووي ذبحني غلآآهآآ ورآح اسوي الي قلت لي عليه لكن بخليهآ أخر طريقه
أخوي [HoBeeZ]
هذآ التقرير
ــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــ
ComboFix 08-07-27.3 - LM 05/11/2009 0:23:50.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.1600 [GMT 3:00]
Running from: C:\DOCUME~1\LM\LOCALS~1\Temp\Rar$EX00.688\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\csrss.exe
C:\WINDOWS\ctfmon.exe
C:\WINDOWS\ktd32.atm
C:\WINDOWS\services.exe
C:\WINDOWS\system\sservice.exe
C:\WINDOWS\system32\fservice.exe
C:\WINDOWS\system32\reginv.dll
C:\WINDOWS\system32\winkey.dll
D:\Autorun.inf
E:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-04-10 to 2009-05-10 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-10 00:07 --------- d-----w C:\Program Files\TGTSoft
2009-05-09 20:41 315,392 ----a-w C:\WINDOWS\HideWin.exe
2009-05-09 20:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2009-05-09 20:41 --------- d-----w C:\Program Files\Common Files\InstallShield
2009-05-09 20:25 --------- d-----w C:\Program Files\REALTEK RTL8187B Wireless LAN Driver
2009-05-09 20:25 --------- d-----w C:\Documents and Settings\LM\Application Data\InstallShield
2009-05-09 17:41 --------- d-----w C:\Program Files\microsoft frontpage
2009-03-06 14:44 282,624 ----a-w C:\WINDOWS\system32\pdh.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [03/14/2005 10:21 PM 1159168]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"= ntbackup.exe
"2"= Regedit.exe
"3"= rstrui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"
****l"="Explorer.exe C:\\WINDOWS\\system32\\fservice.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187B.sys [12/26/2007 12:20 PM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{72944d03-3cd3-11de-8927-806d6172696f}]
\
****l\AutoRun\command - C:\RECYCLER.exe
\
****l\explore\Command - C:\RECYCLER.exe
\
****l\open\Command - C:\RECYCLER.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{72944d04-3cd3-11de-8927-806d6172696f}]
\
****l\AutoRun\command - D:\RECYCLER.exe
\
****l\explore\Command - D:\RECYCLER.exe
\
****l\open\Command - D:\RECYCLER.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{72944d05-3cd3-11de-8927-806d6172696f}]
\
****l\AutoRun\command - E:\SystemVolumeInformation.exe
\
****l\explore\Command - E:\SystemVolumeInformation.exe
\
****l\open\Command - E:\SystemVolumeInformation.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8c0e8bce-3cd6-11de-8ec6-ec25fe4f18e7}]
\
****l\AutoRun\command - G:\DAT.exe
\
****l\explore\Command - G:\DAT.exe
\
****l\open\Command - G:\DAT.exe
*Newly Created Service* - CATCHME
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-csrss.exe - C:\WINDOWS\ctfmon.exe
HKLM-Explorer_Run-DirectX For Microsoft® Windows - C:\WINDOWS\system32\fservice.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
R0 -: HKLM-Main,Start Page = about:blank
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-11 00:23:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 05/11/2009 0

23
ComboFix-quarantined-files.txt 2009-05-10 21

21
Pre-Run: 52,937,904,128 bytes free
Post-Run: 52,938,276,864 bytes free
95 --- E O F --- 2009-05-10 00

35
ـــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــ