bent_almarah
زيزوومي جديد
- إنضم
- 14 يناير 2009
- المشاركات
- 8
- مستوى التفاعل
- 0
- النقاط
- 0
غير متصل
من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
السلام عليكم
انا عندي مشكلة ببرنامج ويندوز ميديا بلاير
اني كل مرة افتح البرنامج الجهاز بعلق كتير وبصير بطئ وبخبرني انه البرنامج غير مثبت بشكل صحيح مع العلم انه البرنامج كان شغال وسليم 100% ومافي مشاكل ابدا
حذفت البرنامج ونزلته مرة تانية ونزلت اصدار احدث منه ونفس المشكلة
كمان لما افتح أي مجلد فيه ملفات صوتيتة بعلق الجهاز وما تنحل الا لما احذف البرنامج كليا من الجهاز
وفيمشكلة تانية انه بظهري انه تقرير خطأ بدرايفر D ما بعرف شو هو
بس استخدم برنامج دكتور Tuneup 2011 بس المشكلة ما انحلت
بدي اسالكم في حل جذري للمشكلتين دون اللجوء للفورمات
انا عملت تقرير ببرنامج ComboFix وهذا التقرير التالي
ComboFix 11-07-31.03 - munamuna 08/01/2011 6:30.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1256.962.1033.18.1015.308 [GMT -7:00]
Running from: c:\documents and settings\munamuna\Desktop\ComboFix.exe
AV: ESET Smart Security 3.0 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *Enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active
.
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - system32: deleted 24 bytes in 2 streams.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\mazuki.dll
c:\documents and settings\All Users\Application Data\Tarma Installer
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
c:\documents and settings\munamuna\Application Data\Dealio
c:\documents and settings\munamuna\Application Data\Dealio\res\widgets.xml
c:\documents and settings\munamuna\Application Data\Dealio\temp\http___www_dealio_com_rss_coupons-deals_dotd_.xml
c:\documents and settings\munamuna\Application Data\Desktopicon
c:\documents and settings\munamuna\Application Data\MiniDm
c:\documents and settings\munamuna\Application Data\MiniDm\conf.ini
c:\documents and settings\munamuna\Application Data\PriceGong
c:\documents and settings\munamuna\Application Data\PriceGong\Data\1.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\a.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\b.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\c.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\d.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\e.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\f.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\g.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\h.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\i.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\J.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\k.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\l.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\m.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\n.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\o.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\p.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\q.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\r.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\s.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\t.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\u.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\v.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\w.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\x.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\y.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\z.xml
c:\documents and settings\munamuna\Local Settings\Application Data\.#
c:\documents and settings\munamuna\My Documents\Readiris.DUS
c:\documents and settings\munamuna\WINDOWS
c:\program files\Bifrost
c:\program files\Bifrost\logg.dat
c:\program files\Bifrost\server.exe
c:\windows\ktd32.atm
c:\windows\ST6UNST.000
c:\windows\system32\d3d10core.dll
c:\windows\system32\kakle.dll
c:\windows\system32\lncom_.exe
c:\windows\system32\scrnrdr.exe
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
c:\windows\system32\VIRepair
c:\windows\system32\VIRepair\vi.sif
c:\windows\system32\winitn.dll
c:\windows\system32\YMSG12ENCRYPT.dll
d:\59c4~1\طبي\210C~1.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_AFPANSI
.
.
((((((((((((((((((((((((( Files Created from 2011-07-01 to 2011-08-01 )))))))))))))))))))))))))))))))
.
.
2011-07-30 08:01 . 2011-07-30 08:01 -------- d-----w- c:\windows\system32\wbem\Repository
2011-07-30 07:24 . 2011-07-30 08:00 -------- d-----w- c:\program files\Windows Media Connect 2
2011-07-30 06:05 . 2011-06-16 04:28 142296 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-07-30 04:47 . 2011-07-30 05:16 -------- d-----w- C:\0d6a49e0c6ea070bc5811df81ff8
2011-07-30 04:29 . 2011-07-30 05:22 -------- d-----w- c:\program files\DllErrorsFix
2011-07-29 07:59 . 2011-07-29 08:05 -------- d-----w- c:\program files\GoldWave
2011-07-28 05:20 . 2011-07-29 08:00 -------- d-----w- c:\program files\AlbumPlayer
2011-07-27 20:14 . 2011-07-29 08:04 -------- d-----w- c:\program files\vanBasco's Karaoke Player
2011-07-24 14:24 . 2011-07-24 14:24 -------- d-----w- C:\d6b6d5e542e9f7c4a8500e2e4096bb
2011-07-23 17:33 . 2008-09-18 22:47 430088 ----a-w- c:\windows\system32\D3D10SDKLayers.DLL
2011-07-23 17:33 . 2005-12-15 16:57 928768 ----a-w- c:\windows\system32\d3d10.dll
2011-07-23 17:33 . 2000-07-31 19:28 286208 ----a-w- c:\windows\system32\binkw32.dll
2011-07-23 17:32 . 2010-06-14 21:26 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-07-23 17:32 . 2009-12-17 16:25 14311680 ----a-w- c:\windows\system32\xlive.dll
2011-07-23 17:32 . 2009-03-17 06:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
2011-07-23 17:32 . 2006-04-13 16:38 737280 ----a-w- c:\windows\system32\msidcrl40.dll
2011-07-23 17:32 . 2009-09-30 20:08 1892184 ----a-w- c:\windows\system32\d3dx9_42.dll
2011-07-23 17:32 . 2009-05-21 07:23 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2011-07-23 17:32 . 2008-10-09 23:36 512008 ----a-w- c:\windows\system32\D3DX10d_39.dll
2011-07-23 17:32 . 2006-11-29 20:06 440080 ----a-w- c:\windows\system32\d3dx10.dll
2011-07-23 17:26 . 2011-07-23 17:26 -------- d-----w- c:\documents and settings\munamuna\Tracing
2011-07-23 05:40 . 2011-03-26 01:03 15592 ----a-w- c:\windows\system32\roboot.exe
2011-07-23 05:06 . 2011-07-23 05:06 -------- d-----w- C:\992e245bef7daa830a4c
2011-07-23 04:55 . 2011-07-23 05:53 -------- d-----w- c:\program files\Dll-Files.com Fixer
2011-07-23 04:51 . 2011-07-23 05:05 -------- dc----w- c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-07-23 04:28 . 2011-07-23 05:06 -------- d-----w- c:\program files\Registry Easy(2)
2011-07-19 17:48 . 2011-07-19 17:48 -------- d-----w- C:\adfa1c68370455c8f1c4403d3133
2011-07-19 15:47 . 2011-07-19 16:03 -------- d-----w- C:\14878a8ed6059970b59aac9d79
2011-07-17 14:37 . 2011-07-17 14:37 -------- d-----w- C:\Temp
2011-07-17 11:49 . 2011-07-19 16:04 -------- d-----w- c:\program files\ChickenInvadersROTYXmas
2011-07-16 10:11 . 2011-07-16 10:11 -------- d-----w- c:\program files\ImTOO
2011-07-16 10:06 . 2011-07-16 10:07 -------- d-----w- c:\program files\Real_SC
2011-07-16 09:59 . 2011-07-16 09:59 -------- d-----w- c:\documents and settings\All Users\Application Data\InterAction studios
2011-07-14 14:58 . 2010-01-01 08:00 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-07-14 14:58 . 2010-01-01 08:00 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-07-13 14:01 . 2011-07-19 17:12 -------- d-----w- c:\program files\PIXresizer
2011-07-13 10:20 . 2011-07-19 17:13 -------- d-----w- c:\program files\JPEG Imager
2011-07-12 16:37 . 2011-07-16 10:09 -------- d-----w- c:\program files\Advanced JPEG Compressor
2011-07-03 14:53 . 2011-07-03 14:53 -------- d-----w- c:\program files\directx
2011-07-03 14:53 . 2011-07-03 14:53 -------- d-----w- c:\program files\honestech
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-16 10:06 . 2009-09-22 20:22 196608 ----a-w- c:\windows\system32\maag.dll
2011-07-16 10:06 . 2009-09-22 20:22 1212416 ----a-w- c:\windows\system32\ckll.dll
2011-07-16 10:06 . 2009-09-22 20:22 1245184 ----a-w- c:\windows\system32\bkll.dll
2011-07-16 10:06 . 2009-09-22 20:22 1986560 ----a-w- c:\windows\system32\akll.dll
2011-07-16 10:06 . 2009-09-22 20:22 2535424 ----a-w- c:\windows\system32\agsaamj.dll
2011-07-16 10:06 . 2009-09-22 20:22 90112 ----a-w- c:\windows\system32\agsaami.dll
2011-07-16 10:06 . 2009-09-22 20:22 610304 ----a-w- c:\windows\system32\agsaamg.dll
2011-07-16 10:06 . 2009-09-22 20:22 372736 ----a-w- c:\windows\system32\agsaamc.dll
2011-06-06 18:44 . 2009-09-22 20:22 626688 ----a-w- c:\windows\system32\agsaamh.dll
2011-06-06 18:44 . 2009-09-22 20:22 551424 ----a-w- c:\windows\system32\agsaame.dll
2011-06-06 18:44 . 2009-09-22 20:22 544256 ----a-w- c:\windows\system32\agsaamd.dll
2011-06-06 18:44 . 2009-09-22 20:22 215552 ----a-w- c:\windows\system32\ALOWMVFile.dll
2011-06-06 18:44 . 2009-09-22 20:22 403968 ----a-w- c:\windows\system32\ALOWMAFile2.dll
2011-06-06 18:44 . 2009-09-22 20:22 188416 ----a-w- c:\windows\system32\ALOVideoFile.dll
2011-06-06 18:44 . 2009-09-22 20:22 495104 ----a-w- c:\windows\system32\ALOVideoCoreM.dll
2011-06-06 18:44 . 2009-09-22 20:22 780288 ----a-w- c:\windows\system32\ALOVideoCompress.dll
2011-06-06 18:44 . 2009-09-22 20:22 538624 ----a-w- c:\windows\system32\agsaamb.dll
2011-06-06 18:44 . 2009-09-22 20:22 331776 ----a-w- c:\windows\system32\agsaama.dll
2011-06-06 18:44 . 2009-09-22 20:22 249856 ----a-w- c:\windows\system32\ALOQuickTimeFile.dll
2011-06-06 18:44 . 2009-09-22 20:22 382464 ----a-w- c:\windows\system32\ALOAVIFile.dll
2011-06-06 18:44 . 2009-09-22 20:22 360448 ----a-w- c:\windows\system32\agsaamf.ocx
2011-06-06 18:44 . 2009-09-22 20:22 90112 ----a-w- c:\windows\system32\ALOAudioFormatSettings3.dll
2011-06-06 18:44 . 2009-09-22 20:22 877568 ----a-w- c:\windows\system32\ALOAudioFile2.dll
2011-06-06 18:44 . 2009-09-22 20:22 2846720 ----a-w- c:\windows\system32\ALOAudioCompress3.dll
2011-06-06 18:44 . 2009-09-22 20:22 778240 ----a-w- c:\windows\system32\ALOAudioCompress2.dll
2011-06-06 18:43 . 2009-09-22 20:22 98304 ----a-w- c:\windows\system32\viscomtran.dll
2011-06-06 18:43 . 2009-09-22 20:22 81920 ----a-w- c:\windows\system32\viscomwave.dll
2011-06-06 18:43 . 2009-09-22 20:22 442368 ----a-w- c:\windows\system32\viscomswfenc.ax
2011-06-06 18:43 . 2009-09-22 20:22 48640 ----a-w- c:\windows\system32\viscomsamplerate.dll
2011-06-06 18:43 . 2009-09-22 20:22 147456 ----a-w- c:\windows\system32\viscomqtenc.dll
2011-06-06 18:43 . 2009-09-22 20:22 118784 ----a-w- c:\windows\system32\viscomrmenc.dll
2011-06-06 18:43 . 2009-09-22 20:22 602112 ----a-w- c:\windows\system32\viscomqtde.dll
2011-06-06 18:43 . 2009-09-22 20:22 1470464 ----a-w- c:\windows\system32\viscomm4aenc.dll
2011-06-06 18:43 . 2009-09-22 20:22 86016 ----a-w- c:\windows\system32\viscomframe.dll
2011-06-06 18:43 . 2009-09-22 20:22 1470464 ----a-w- c:\windows\system32\viscomdata3.dll
2011-06-06 18:43 . 2009-09-22 20:22 1462272 ----a-w- c:\windows\system32\viscomflvenc.dll
2011-06-06 18:43 . 2009-09-22 20:22 118784 ----a-w- c:\windows\system32\viscomflvdec.dll
2011-06-06 18:43 . 2009-09-22 20:22 1462272 ----a-w- c:\windows\system32\viscomdata1.dll
2011-06-06 18:43 . 2009-09-22 20:22 1454080 ----a-w- c:\windows\system32\viscomdata2.dll
2011-06-06 18:43 . 2009-09-22 20:22 18628608 ----a-w- c:\windows\system32\viscomavi.dll
2011-06-06 18:43 . 2009-09-22 20:22 94208 ----a-w- c:\windows\system32\viscomaudiodata.dll
2011-06-06 18:43 . 2009-09-22 20:22 1454080 ----a-w- c:\windows\system32\viscomamrenc.dll
2011-06-06 18:43 . 2009-09-22 20:22 110592 ----a-w- c:\windows\system32\viscomaudioencoder.dll
2011-06-06 18:43 . 2009-09-22 20:22 6963712 ----a-w- c:\windows\system32\videotrans.dll
2011-06-06 18:43 . 2009-09-22 20:22 1462272 ----a-w- c:\windows\system32\viscom3gpenc.dll
2011-06-06 18:43 . 2009-09-22 20:22 18599936 ----a-w- c:\windows\system32\videoencode.dll
2011-06-06 18:43 . 2009-09-22 20:22 262144 ----a-w- c:\windows\system32\VideoEdit.ocx
2011-06-06 18:43 . 2009-09-22 20:22 90112 ----a-w- c:\windows\system32\ssvideo.dll
2011-06-06 18:43 . 2009-09-22 20:22 421888 ----a-w- c:\windows\system32\RealMediaSplitter.ax
2011-06-06 18:43 . 2009-09-22 20:22 856064 ----a-w- c:\windows\system32\mpgfiltr.ax
2011-06-06 18:43 . 2009-09-22 20:22 1128128 ----a-w- c:\windows\system32\NMSDVDXU.dll
2011-06-06 18:43 . 2009-09-22 20:22 18595840 ----a-w- c:\windows\system32\coredata.dll
2011-05-22 13:13 . 2011-05-22 13:13 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-19 17:54 . 2011-05-19 17:55 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2011-05-19 17:54 . 2011-05-19 17:55 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
2011-05-19 17:54 . 2011-05-19 17:55 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2011-05-10 18:12 . 2011-05-10 18:30 5640352 ----a-w- C:\برنامج تشغيل الفلاش.exe
2011-06-16 04:28 . 2011-07-30 06:05 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2009-05-20 177464]
"{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}"= "c:\program files\************\prxtb4sh2.dll" [2011-01-17 175912]
"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\tbSoft.dll" [2010-10-10 3906656]
"{9565115d-c7d6-46d3-bd63-b67b481a4368}"= "c:\program files\PageRage\prxtbPag0.dll" [2011-03-28 176936]
"{6778613D-616B-4A6C-9856-65DE943CF424}"= "c:\program files\FVD Suite\addons\IE\FVDToolbar.dll" [2011-02-05 473088]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
.
[HKEY_CLASSES_ROOT\clsid\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}]
.
[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
.
[HKEY_CLASSES_ROOT\clsid\{9565115d-c7d6-46d3-bd63-b67b481a4368}]
.
[HKEY_CLASSES_ROOT\clsid\{6778613d-616b-4a6c-9856-65de943cf424}]
[HKEY_CLASSES_ROOT\FVDToolbar.FVDSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{2B171655-A69C-5c18-B693-6CB5DC269D40}]
[HKEY_CLASSES_ROOT\FVDToolbar.FVDSearchHook]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}]
2011-01-17 14:54 175912 ----a-w- c:\program files\************\prxtb4sh2.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-10 23:51 3906656 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
2010-10-10 23:51 3906656 ----a-w- c:\program files\Softonic-Eng7\tbSoft.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9565115d-c7d6-46d3-bd63-b67b481a4368}]
2011-03-28 16:22 176936 ----a-w- c:\program files\PageRage\prxtbPag0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2009-05-20 22:36 1258808 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F8C564CD-2FA0-4534-AF8D-52F3D054C0EF}]
2007-11-15 12:36 2293760 ----a-w- c:\program files\AmanLinks_Beta_0.0.4\AmanLinks_Beta_0.0.4_Lite\tbu08943\untitled.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-05-20 1258808]
"{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}"= "c:\program files\************\prxtb4sh2.dll" [2011-01-17 175912]
"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\tbSoft.dll" [2010-10-10 3906656]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-10-10 3906656]
"{0C55A48A-97DC-4003-8729-7D0B159B40D3}"= "c:\program files\AmanLinks_Beta_0.0.4\AmanLinks_Beta_0.0.4_Lite\tbu08943\untitled.dll" [2007-11-15 2293760]
"{9565115d-c7d6-46d3-bd63-b67b481a4368}"= "c:\program files\PageRage\prxtbPag0.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}]
.
[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{0c55a48a-97dc-4003-8729-7d0b159b40d3}]
[HKEY_CLASSES_ROOT\TBSB09257.TBSB09257.3]
[HKEY_CLASSES_ROOT\TBSB09257.TBSB09257]
.
[HKEY_CLASSES_ROOT\clsid\{9565115d-c7d6-46d3-bd63-b67b481a4368}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9565115D-C7D6-46D3-BD63-B67B481A4368}"= "c:\program files\PageRage\prxtbPag0.dll" [2011-03-28 176936]
"{09EC805C-CB2E-4D53-B0D3-A75A428B81C7}"= "c:\program files\************\prxtb4sh2.dll" [2011-01-17 175912]
"{0C55A48A-97DC-4003-8729-7D0B159B40D3}"= "c:\program files\AmanLinks_Beta_0.0.4\AmanLinks_Beta_0.0.4_Lite\tbu08943\untitled.dll" [2007-11-15 2293760]
.
[HKEY_CLASSES_ROOT\clsid\{9565115d-c7d6-46d3-bd63-b67b481a4368}]
.
[HKEY_CLASSES_ROOT\clsid\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}]
.
[HKEY_CLASSES_ROOT\clsid\{0c55a48a-97dc-4003-8729-7d0b159b40d3}]
[HKEY_CLASSES_ROOT\TBSB09257.TBSB09257.3]
[HKEY_CLASSES_ROOT\TBSB09257.TBSB09257]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\CFi]
@="{2DBD5D71-CBB7-41D1-B170-511646B170BD}"
[HKEY_CLASSES_ROOT\CLSID\{2DBD5D71-CBB7-41D1-B170-511646B170BD}]
2007-01-28 22:50 55296 ----a-w- c:\progra~1\CFi\SHELLT~1\CFiShlJP.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CFi ShellToys Utility Manager"="c:\program files\CFi\ShellToys\CFiShlMan.exe" [2008-01-03 44032]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-10-29 2606512]
"VistaIcon"="c:\program files\VistaDriveIcon\VistaDrv.exe" [2008-01-02 132096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"USB Antivirus"="c:\program files\USB Disk Security\USBGuard.exe" [2008-05-24 794624]
"Autorun Eater"="c:\program files\Autorun Eater\oldmcdonald.exe" [2008-11-27 501768]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-24 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-24 137752]
"DrvIcon"="c:\program files\Vista Drive Icon\DrvIcon.exe" [2008-04-13 49152]
"assawsanaReader"="c:\documents and settings\munamuna\Local Settings\Apps\2.0\NH1DP5Y2.DTL\ZRLXVBEV.EH7\assa..tion_9c1c7f8c5e15d6b2_0001.0000_0865aa7080620218\assawsanaReader.exe" [2011-05-13 413696]
"Anti Mosquito"="C:\Anti Mosquito.exe" [2001-12-20 258048]
"ClocX"="c:\program files\ClocX\ClocX.exe" [2007-07-26 270336]
"TkBellExe"="c:\program files\Real\realplayer\update\realsched.exe" [2010-12-05 274608]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"VistaIcon"="c:\program files\VistaDriveIcon\VistaDrv.exe" [2008-01-02 132096]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2009-11-1 1048576]
Snagit 9.lnk - c:\program files\TechSmith\Snagit 9\Snagit32.exe [2009-1-22 7225672]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsp_lmwl]
2007-02-22 05:21 43376 ----a-w- c:\windows\system32\fsp_lmwl.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"4shared Update"="c:\program files\4shared Desktop\checkUpdate.exe"
"WatchDog"=c:\program files\InterVideo\DVD Check\DVDCheck.exe
"PDVD9LanguageShortcut"="c:\program files\CyberLink\PowerDVD9\Language\Language.exe"
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" -osboot
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe"
"SweetIM"=c:\program files\SweetIM\Messenger\SweetIM.exe
"SynTPEnh"=c:\program files\Synaptics\SynTP\SynTPEnh.exe
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD9\\PowerDVD Cinema\\PowerDVDCinema.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD9\\PowerDVD9.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\games\\Alice\\Alice\\alice.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
.
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/05/04 16:00];c:\program files\CyberLink\PowerDVD9\000.fcl [28/02/2009 07:40 م 87536]
R2 BR_Launcher;BR_Launcher;c:\program files\Zain\Zain BroadBand\BRService.exe [30/12/2010 11:24 ص 104264]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [23/03/2010 01:42 م 38144]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21/12/2007 08:21 ص 468224]
R2 ezntsvc;EasyBits Magic Desktop Services for Windows NT;c:\windows\system32\ezntsvc.exe [20/11/2010 10:53 ص 33792]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [03/08/2004 03:56 م 14336]
R2 jswpbapi;JumpStart Push-Button Service;c:\program files\TP-LINK\QSS\jswpbapi.exe [17/11/2009 06:13 م 188416]
R2 Scutum50;Scutum50 NDIS Protocol Driver;c:\windows\system32\drivers\Scutum50.sys [19/01/2011 12:13 ص 19072]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [27/10/2010 07:23 م 1483072]
R3 br_bandluxe_dc_enum;BandLuxe HSPA DC Enumerator;c:\windows\system32\drivers\br_bandluxe_dc_enum.sys [17/05/2010 04:56 م 82176]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [17/11/2009 06:13 م 57440]
R3 LMPC4;LMPC4;c:\windows\system32\drivers\lmpc4.sys [02/12/2010 11:37 ص 10096]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [07/10/2010 02:34 م 10064]
S0 Shadow;Shadow; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 01:16 م 130384]
S2 gupdate1caf0d5f051a224;Google Update Service (gupdate1caf0d5f051a224);c:\program files\Google\Update\GoogleUpdate.exe [10/05/2010 11:48 م 133104]
S3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [17/11/2009 05:47 م 1668352]
S3 athrusb;TP-LINK Extensible Wireless LAN device driver;c:\windows\system32\drivers\athrusb.sys [20/04/2010 02:26 م 857600]
S3 br_bandluxe_cdc_acm;BandLuxe HSPA CDC-ACM driver;c:\windows\system32\drivers\br_bandluxe_cdc_acm.sys [17/05/2010 04:56 م 85888]
S3 br_bandluxe_cdc_ecm;br_bandluxe_cdc_ecm;c:\windows\system32\drivers\br_bandluxe_cdc_ecm.sys [17/05/2010 04:56 م 51072]
S3 br_bandluxe_cpo;BandLuxe HSPA Mass Storage Device;c:\windows\system32\drivers\br_bandluxe_cpo.sys [17/05/2010 04:56 م 9856]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\DfSdkS.exe [06/01/2011 07:21 م 406016]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [19/05/2011 10:55 ص 13224]
S3 gupdatem;خدمة Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/05/2010 11:48 م 133104]
S3 jswpsapi;JumpStart Wi-Fi Protected Setup;c:\program files\TP-LINK\QSS\jswpsapi.exe [17/11/2009 06:13 م 360529]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 01:16 م 753504]
S3 ZD1211BU(TP-LINK);TL-WN322G Wireless USB Adapter Driver(TP-LINK);c:\windows\system32\drivers\ZD1211BU.sys [24/03/2010 12:07 ص 477696]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9C450606-ED24-4958-92BA-B8940C99D441}]
2009-03-04 23:32 8192 ----a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-11 06:48]
.
2011-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-11 06:48]
.
2011-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-1390067357-682003330-1003Core.job
- c:\documents and settings\munamuna\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-04-17 02:38]
.
2011-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-1390067357-682003330-1003UA.job
- c:\documents and settings\munamuna\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-04-17 02:38]
.
2011-08-01 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-583907252-1390067357-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 19:33]
.
2011-07-18 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-583907252-1390067357-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 19:33]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*
IE: &Download All using 4shared Desktop - c:\program files\4shared Desktop\down_all.htm
IE: &Download using 4shared Desktop - c:\program files\4shared Desktop\down_link.htm
IE: &Save Flash In This Page - c:\progra~1\Flash Saver 4.0\save.htm
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
IE: Google Sidewiki...
IE: Open using &Advanced JPEG Compressor - c:\program files\Advanced JPEG Compressor\ajcieex.htm
IE: Search - c:\program files\FVD Suite\addons\IE\FVDToolbar.dll/IECONTEXT.DLL.HTM
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
IE: الدليل السريع - c:\windows\ww80.html
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
IE: {{46012075-ED62-464b-9554-AD0BEC35D1EC} -
IE: {{46012076-ED62-464b-9554-AD0BEC35D1EC}
IE: {{C1E3533C-70F6-4f36-B97C-032C8A5EE759}
DPF: Microsoft XML Parser for Java
FF - ProfilePath - c:\documents and settings\munamuna\Application Data\Mozilla\Firefox\Profiles\bjq9dq8g.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google Custom Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.jo/
FF - prefs.js: keyword.URL - hxxp://start.flashvideodownloader.org/result.php?cx=partner-pub-5087362176467115:lyglkqaff6i&cof=FORID:10&ie=ISO-8859-1&sa=Search&q=
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
URLSearchHooks-{707db484-2428-402d-afb5-d85b387544c7} - (no file)
URLSearchHooks-{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - (no file)
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
BHO-{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - (no file)
Toolbar-{707db484-2428-402d-afb5-d85b387544c7} - (no file)
Toolbar-{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - (no file)
Toolbar-{28387537-e3f9-4ed7-860c-11e69af4a8a0} - (no file)
Toolbar-10 - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
ShellExecuteHooks-UPB:{067B597C-C099-4A08-A180-E5FEC5DCF2DF} - (no file)
Notify-WgaLogon - (no file)
HKLM_ActiveSetup-{F93F1BA6-1EAF-FBCB-4321-9963C3869E41} - c:\program files\Bifrost\server.exe
AddRemove-{889DF117-14D1-44EE-9F31-C5FB5D47F68B} - c:\docume~1\ALLUSE~1\APPLIC~1\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2011-08-01 06:51
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Anti Mosquito = C:\Anti Mosquito.exe???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD9\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):14,2d,52,90,2b,b8,a8,b1,4f,7f,5d,f2,e2,f1,c4,5d,3e,55,16,0b,ee,
70,71,8f,5d,3f,0a,a6,94,52,0a,4e,a1,ed,7c,c2,0b,16,ab,b1,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{d708e37d-17eb-43b9-94e2-82e85ffb8aba}]
@Denied: (Full) (Everyone)
"Model"=dword:0000014e
"Therad"=dword:0000000f
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
.
[HKEY_LOCAL_MACHINE\software\Classes\giffile\shell\Open\ddeexec]
@DACL=(02 0000)
@="\"file:%1\",,-1,,,,,"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(684)
c:\windows\system32\fsp_lmwl.dll
.
- - - - - - - > 'explorer.exe'(3696)
c:\program files\RocketDock\RocketDock.dll
c:\progra~1\CFi\SHELLT~1\CFiShlJP.dll
c:\program files\Internet Download Manager\idmmkb.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\browselc.dll
c:\program files\Internet Download Manager\IDMIECC.dll
c:\progra~1\Flash2X\FLASHP~1\FLASHP~1.DLL
c:\program files\Microsoft Office\Office10\msohev.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Autorun Eater\billy.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
c:\windows\system32\wscntfy.exe
c:\program files\TechSmith\Snagit 9\TSCHelp.exe
c:\program files\TechSmith\Snagit 9\SnagPriv.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\TechSmith\Snagit 9\snagiteditor.exe
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 2011-08-01 06:55:06 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-01 13:55
.
Pre-Run: 21,819,006,976 bytes free
Post-Run: 21,702,455,296 bytes free
.
- - End Of File - - FA921CCE52862FCC90318A9D881B1CFD
انا عندي مشكلة ببرنامج ويندوز ميديا بلاير
اني كل مرة افتح البرنامج الجهاز بعلق كتير وبصير بطئ وبخبرني انه البرنامج غير مثبت بشكل صحيح مع العلم انه البرنامج كان شغال وسليم 100% ومافي مشاكل ابدا
حذفت البرنامج ونزلته مرة تانية ونزلت اصدار احدث منه ونفس المشكلة
كمان لما افتح أي مجلد فيه ملفات صوتيتة بعلق الجهاز وما تنحل الا لما احذف البرنامج كليا من الجهاز
وفيمشكلة تانية انه بظهري انه تقرير خطأ بدرايفر D ما بعرف شو هو
بس استخدم برنامج دكتور Tuneup 2011 بس المشكلة ما انحلت
بدي اسالكم في حل جذري للمشكلتين دون اللجوء للفورمات
انا عملت تقرير ببرنامج ComboFix وهذا التقرير التالي
ComboFix 11-07-31.03 - munamuna 08/01/2011 6:30.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1256.962.1033.18.1015.308 [GMT -7:00]
Running from: c:\documents and settings\munamuna\Desktop\ComboFix.exe
AV: ESET Smart Security 3.0 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *Enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active
.
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - system32: deleted 24 bytes in 2 streams.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\mazuki.dll
c:\documents and settings\All Users\Application Data\Tarma Installer
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
c:\documents and settings\munamuna\Application Data\Dealio
c:\documents and settings\munamuna\Application Data\Dealio\res\widgets.xml
c:\documents and settings\munamuna\Application Data\Dealio\temp\http___www_dealio_com_rss_coupons-deals_dotd_.xml
c:\documents and settings\munamuna\Application Data\Desktopicon
c:\documents and settings\munamuna\Application Data\MiniDm
c:\documents and settings\munamuna\Application Data\MiniDm\conf.ini
c:\documents and settings\munamuna\Application Data\PriceGong
c:\documents and settings\munamuna\Application Data\PriceGong\Data\1.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\a.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\b.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\c.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\d.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\e.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\f.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\g.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\h.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\i.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\J.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\k.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\l.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\m.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\n.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\o.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\p.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\q.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\r.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\s.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\t.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\u.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\v.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\w.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\x.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\y.xml
c:\documents and settings\munamuna\Application Data\PriceGong\Data\z.xml
c:\documents and settings\munamuna\Local Settings\Application Data\.#
c:\documents and settings\munamuna\My Documents\Readiris.DUS
c:\documents and settings\munamuna\WINDOWS
c:\program files\Bifrost
c:\program files\Bifrost\logg.dat
c:\program files\Bifrost\server.exe
c:\windows\ktd32.atm
c:\windows\ST6UNST.000
c:\windows\system32\d3d10core.dll
c:\windows\system32\kakle.dll
c:\windows\system32\lncom_.exe
c:\windows\system32\scrnrdr.exe
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
c:\windows\system32\VIRepair
c:\windows\system32\VIRepair\vi.sif
c:\windows\system32\winitn.dll
c:\windows\system32\YMSG12ENCRYPT.dll
d:\59c4~1\طبي\210C~1.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_AFPANSI
.
.
((((((((((((((((((((((((( Files Created from 2011-07-01 to 2011-08-01 )))))))))))))))))))))))))))))))
.
.
2011-07-30 08:01 . 2011-07-30 08:01 -------- d-----w- c:\windows\system32\wbem\Repository
2011-07-30 07:24 . 2011-07-30 08:00 -------- d-----w- c:\program files\Windows Media Connect 2
2011-07-30 06:05 . 2011-06-16 04:28 142296 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-07-30 04:47 . 2011-07-30 05:16 -------- d-----w- C:\0d6a49e0c6ea070bc5811df81ff8
2011-07-30 04:29 . 2011-07-30 05:22 -------- d-----w- c:\program files\DllErrorsFix
2011-07-29 07:59 . 2011-07-29 08:05 -------- d-----w- c:\program files\GoldWave
2011-07-28 05:20 . 2011-07-29 08:00 -------- d-----w- c:\program files\AlbumPlayer
2011-07-27 20:14 . 2011-07-29 08:04 -------- d-----w- c:\program files\vanBasco's Karaoke Player
2011-07-24 14:24 . 2011-07-24 14:24 -------- d-----w- C:\d6b6d5e542e9f7c4a8500e2e4096bb
2011-07-23 17:33 . 2008-09-18 22:47 430088 ----a-w- c:\windows\system32\D3D10SDKLayers.DLL
2011-07-23 17:33 . 2005-12-15 16:57 928768 ----a-w- c:\windows\system32\d3d10.dll
2011-07-23 17:33 . 2000-07-31 19:28 286208 ----a-w- c:\windows\system32\binkw32.dll
2011-07-23 17:32 . 2010-06-14 21:26 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-07-23 17:32 . 2009-12-17 16:25 14311680 ----a-w- c:\windows\system32\xlive.dll
2011-07-23 17:32 . 2009-03-17 06:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
2011-07-23 17:32 . 2006-04-13 16:38 737280 ----a-w- c:\windows\system32\msidcrl40.dll
2011-07-23 17:32 . 2009-09-30 20:08 1892184 ----a-w- c:\windows\system32\d3dx9_42.dll
2011-07-23 17:32 . 2009-05-21 07:23 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2011-07-23 17:32 . 2008-10-09 23:36 512008 ----a-w- c:\windows\system32\D3DX10d_39.dll
2011-07-23 17:32 . 2006-11-29 20:06 440080 ----a-w- c:\windows\system32\d3dx10.dll
2011-07-23 17:26 . 2011-07-23 17:26 -------- d-----w- c:\documents and settings\munamuna\Tracing
2011-07-23 05:40 . 2011-03-26 01:03 15592 ----a-w- c:\windows\system32\roboot.exe
2011-07-23 05:06 . 2011-07-23 05:06 -------- d-----w- C:\992e245bef7daa830a4c
2011-07-23 04:55 . 2011-07-23 05:53 -------- d-----w- c:\program files\Dll-Files.com Fixer
2011-07-23 04:51 . 2011-07-23 05:05 -------- dc----w- c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-07-23 04:28 . 2011-07-23 05:06 -------- d-----w- c:\program files\Registry Easy(2)
2011-07-19 17:48 . 2011-07-19 17:48 -------- d-----w- C:\adfa1c68370455c8f1c4403d3133
2011-07-19 15:47 . 2011-07-19 16:03 -------- d-----w- C:\14878a8ed6059970b59aac9d79
2011-07-17 14:37 . 2011-07-17 14:37 -------- d-----w- C:\Temp
2011-07-17 11:49 . 2011-07-19 16:04 -------- d-----w- c:\program files\ChickenInvadersROTYXmas
2011-07-16 10:11 . 2011-07-16 10:11 -------- d-----w- c:\program files\ImTOO
2011-07-16 10:06 . 2011-07-16 10:07 -------- d-----w- c:\program files\Real_SC
2011-07-16 09:59 . 2011-07-16 09:59 -------- d-----w- c:\documents and settings\All Users\Application Data\InterAction studios
2011-07-14 14:58 . 2010-01-01 08:00 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-07-14 14:58 . 2010-01-01 08:00 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-07-13 14:01 . 2011-07-19 17:12 -------- d-----w- c:\program files\PIXresizer
2011-07-13 10:20 . 2011-07-19 17:13 -------- d-----w- c:\program files\JPEG Imager
2011-07-12 16:37 . 2011-07-16 10:09 -------- d-----w- c:\program files\Advanced JPEG Compressor
2011-07-03 14:53 . 2011-07-03 14:53 -------- d-----w- c:\program files\directx
2011-07-03 14:53 . 2011-07-03 14:53 -------- d-----w- c:\program files\honestech
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-16 10:06 . 2009-09-22 20:22 196608 ----a-w- c:\windows\system32\maag.dll
2011-07-16 10:06 . 2009-09-22 20:22 1212416 ----a-w- c:\windows\system32\ckll.dll
2011-07-16 10:06 . 2009-09-22 20:22 1245184 ----a-w- c:\windows\system32\bkll.dll
2011-07-16 10:06 . 2009-09-22 20:22 1986560 ----a-w- c:\windows\system32\akll.dll
2011-07-16 10:06 . 2009-09-22 20:22 2535424 ----a-w- c:\windows\system32\agsaamj.dll
2011-07-16 10:06 . 2009-09-22 20:22 90112 ----a-w- c:\windows\system32\agsaami.dll
2011-07-16 10:06 . 2009-09-22 20:22 610304 ----a-w- c:\windows\system32\agsaamg.dll
2011-07-16 10:06 . 2009-09-22 20:22 372736 ----a-w- c:\windows\system32\agsaamc.dll
2011-06-06 18:44 . 2009-09-22 20:22 626688 ----a-w- c:\windows\system32\agsaamh.dll
2011-06-06 18:44 . 2009-09-22 20:22 551424 ----a-w- c:\windows\system32\agsaame.dll
2011-06-06 18:44 . 2009-09-22 20:22 544256 ----a-w- c:\windows\system32\agsaamd.dll
2011-06-06 18:44 . 2009-09-22 20:22 215552 ----a-w- c:\windows\system32\ALOWMVFile.dll
2011-06-06 18:44 . 2009-09-22 20:22 403968 ----a-w- c:\windows\system32\ALOWMAFile2.dll
2011-06-06 18:44 . 2009-09-22 20:22 188416 ----a-w- c:\windows\system32\ALOVideoFile.dll
2011-06-06 18:44 . 2009-09-22 20:22 495104 ----a-w- c:\windows\system32\ALOVideoCoreM.dll
2011-06-06 18:44 . 2009-09-22 20:22 780288 ----a-w- c:\windows\system32\ALOVideoCompress.dll
2011-06-06 18:44 . 2009-09-22 20:22 538624 ----a-w- c:\windows\system32\agsaamb.dll
2011-06-06 18:44 . 2009-09-22 20:22 331776 ----a-w- c:\windows\system32\agsaama.dll
2011-06-06 18:44 . 2009-09-22 20:22 249856 ----a-w- c:\windows\system32\ALOQuickTimeFile.dll
2011-06-06 18:44 . 2009-09-22 20:22 382464 ----a-w- c:\windows\system32\ALOAVIFile.dll
2011-06-06 18:44 . 2009-09-22 20:22 360448 ----a-w- c:\windows\system32\agsaamf.ocx
2011-06-06 18:44 . 2009-09-22 20:22 90112 ----a-w- c:\windows\system32\ALOAudioFormatSettings3.dll
2011-06-06 18:44 . 2009-09-22 20:22 877568 ----a-w- c:\windows\system32\ALOAudioFile2.dll
2011-06-06 18:44 . 2009-09-22 20:22 2846720 ----a-w- c:\windows\system32\ALOAudioCompress3.dll
2011-06-06 18:44 . 2009-09-22 20:22 778240 ----a-w- c:\windows\system32\ALOAudioCompress2.dll
2011-06-06 18:43 . 2009-09-22 20:22 98304 ----a-w- c:\windows\system32\viscomtran.dll
2011-06-06 18:43 . 2009-09-22 20:22 81920 ----a-w- c:\windows\system32\viscomwave.dll
2011-06-06 18:43 . 2009-09-22 20:22 442368 ----a-w- c:\windows\system32\viscomswfenc.ax
2011-06-06 18:43 . 2009-09-22 20:22 48640 ----a-w- c:\windows\system32\viscomsamplerate.dll
2011-06-06 18:43 . 2009-09-22 20:22 147456 ----a-w- c:\windows\system32\viscomqtenc.dll
2011-06-06 18:43 . 2009-09-22 20:22 118784 ----a-w- c:\windows\system32\viscomrmenc.dll
2011-06-06 18:43 . 2009-09-22 20:22 602112 ----a-w- c:\windows\system32\viscomqtde.dll
2011-06-06 18:43 . 2009-09-22 20:22 1470464 ----a-w- c:\windows\system32\viscomm4aenc.dll
2011-06-06 18:43 . 2009-09-22 20:22 86016 ----a-w- c:\windows\system32\viscomframe.dll
2011-06-06 18:43 . 2009-09-22 20:22 1470464 ----a-w- c:\windows\system32\viscomdata3.dll
2011-06-06 18:43 . 2009-09-22 20:22 1462272 ----a-w- c:\windows\system32\viscomflvenc.dll
2011-06-06 18:43 . 2009-09-22 20:22 118784 ----a-w- c:\windows\system32\viscomflvdec.dll
2011-06-06 18:43 . 2009-09-22 20:22 1462272 ----a-w- c:\windows\system32\viscomdata1.dll
2011-06-06 18:43 . 2009-09-22 20:22 1454080 ----a-w- c:\windows\system32\viscomdata2.dll
2011-06-06 18:43 . 2009-09-22 20:22 18628608 ----a-w- c:\windows\system32\viscomavi.dll
2011-06-06 18:43 . 2009-09-22 20:22 94208 ----a-w- c:\windows\system32\viscomaudiodata.dll
2011-06-06 18:43 . 2009-09-22 20:22 1454080 ----a-w- c:\windows\system32\viscomamrenc.dll
2011-06-06 18:43 . 2009-09-22 20:22 110592 ----a-w- c:\windows\system32\viscomaudioencoder.dll
2011-06-06 18:43 . 2009-09-22 20:22 6963712 ----a-w- c:\windows\system32\videotrans.dll
2011-06-06 18:43 . 2009-09-22 20:22 1462272 ----a-w- c:\windows\system32\viscom3gpenc.dll
2011-06-06 18:43 . 2009-09-22 20:22 18599936 ----a-w- c:\windows\system32\videoencode.dll
2011-06-06 18:43 . 2009-09-22 20:22 262144 ----a-w- c:\windows\system32\VideoEdit.ocx
2011-06-06 18:43 . 2009-09-22 20:22 90112 ----a-w- c:\windows\system32\ssvideo.dll
2011-06-06 18:43 . 2009-09-22 20:22 421888 ----a-w- c:\windows\system32\RealMediaSplitter.ax
2011-06-06 18:43 . 2009-09-22 20:22 856064 ----a-w- c:\windows\system32\mpgfiltr.ax
2011-06-06 18:43 . 2009-09-22 20:22 1128128 ----a-w- c:\windows\system32\NMSDVDXU.dll
2011-06-06 18:43 . 2009-09-22 20:22 18595840 ----a-w- c:\windows\system32\coredata.dll
2011-05-22 13:13 . 2011-05-22 13:13 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-19 17:54 . 2011-05-19 17:55 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2011-05-19 17:54 . 2011-05-19 17:55 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
2011-05-19 17:54 . 2011-05-19 17:55 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2011-05-10 18:12 . 2011-05-10 18:30 5640352 ----a-w- C:\برنامج تشغيل الفلاش.exe
2011-06-16 04:28 . 2011-07-30 06:05 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2009-05-20 177464]
"{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}"= "c:\program files\************\prxtb4sh2.dll" [2011-01-17 175912]
"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\tbSoft.dll" [2010-10-10 3906656]
"{9565115d-c7d6-46d3-bd63-b67b481a4368}"= "c:\program files\PageRage\prxtbPag0.dll" [2011-03-28 176936]
"{6778613D-616B-4A6C-9856-65DE943CF424}"= "c:\program files\FVD Suite\addons\IE\FVDToolbar.dll" [2011-02-05 473088]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
.
[HKEY_CLASSES_ROOT\clsid\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}]
.
[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
.
[HKEY_CLASSES_ROOT\clsid\{9565115d-c7d6-46d3-bd63-b67b481a4368}]
.
[HKEY_CLASSES_ROOT\clsid\{6778613d-616b-4a6c-9856-65de943cf424}]
[HKEY_CLASSES_ROOT\FVDToolbar.FVDSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{2B171655-A69C-5c18-B693-6CB5DC269D40}]
[HKEY_CLASSES_ROOT\FVDToolbar.FVDSearchHook]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}]
2011-01-17 14:54 175912 ----a-w- c:\program files\************\prxtb4sh2.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-10 23:51 3906656 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
2010-10-10 23:51 3906656 ----a-w- c:\program files\Softonic-Eng7\tbSoft.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9565115d-c7d6-46d3-bd63-b67b481a4368}]
2011-03-28 16:22 176936 ----a-w- c:\program files\PageRage\prxtbPag0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2009-05-20 22:36 1258808 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F8C564CD-2FA0-4534-AF8D-52F3D054C0EF}]
2007-11-15 12:36 2293760 ----a-w- c:\program files\AmanLinks_Beta_0.0.4\AmanLinks_Beta_0.0.4_Lite\tbu08943\untitled.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-05-20 1258808]
"{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}"= "c:\program files\************\prxtb4sh2.dll" [2011-01-17 175912]
"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\tbSoft.dll" [2010-10-10 3906656]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-10-10 3906656]
"{0C55A48A-97DC-4003-8729-7D0B159B40D3}"= "c:\program files\AmanLinks_Beta_0.0.4\AmanLinks_Beta_0.0.4_Lite\tbu08943\untitled.dll" [2007-11-15 2293760]
"{9565115d-c7d6-46d3-bd63-b67b481a4368}"= "c:\program files\PageRage\prxtbPag0.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}]
.
[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{0c55a48a-97dc-4003-8729-7d0b159b40d3}]
[HKEY_CLASSES_ROOT\TBSB09257.TBSB09257.3]
[HKEY_CLASSES_ROOT\TBSB09257.TBSB09257]
.
[HKEY_CLASSES_ROOT\clsid\{9565115d-c7d6-46d3-bd63-b67b481a4368}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9565115D-C7D6-46D3-BD63-B67B481A4368}"= "c:\program files\PageRage\prxtbPag0.dll" [2011-03-28 176936]
"{09EC805C-CB2E-4D53-B0D3-A75A428B81C7}"= "c:\program files\************\prxtb4sh2.dll" [2011-01-17 175912]
"{0C55A48A-97DC-4003-8729-7D0B159B40D3}"= "c:\program files\AmanLinks_Beta_0.0.4\AmanLinks_Beta_0.0.4_Lite\tbu08943\untitled.dll" [2007-11-15 2293760]
.
[HKEY_CLASSES_ROOT\clsid\{9565115d-c7d6-46d3-bd63-b67b481a4368}]
.
[HKEY_CLASSES_ROOT\clsid\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}]
.
[HKEY_CLASSES_ROOT\clsid\{0c55a48a-97dc-4003-8729-7d0b159b40d3}]
[HKEY_CLASSES_ROOT\TBSB09257.TBSB09257.3]
[HKEY_CLASSES_ROOT\TBSB09257.TBSB09257]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\CFi]
@="{2DBD5D71-CBB7-41D1-B170-511646B170BD}"
[HKEY_CLASSES_ROOT\CLSID\{2DBD5D71-CBB7-41D1-B170-511646B170BD}]
2007-01-28 22:50 55296 ----a-w- c:\progra~1\CFi\SHELLT~1\CFiShlJP.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CFi ShellToys Utility Manager"="c:\program files\CFi\ShellToys\CFiShlMan.exe" [2008-01-03 44032]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-10-29 2606512]
"VistaIcon"="c:\program files\VistaDriveIcon\VistaDrv.exe" [2008-01-02 132096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"USB Antivirus"="c:\program files\USB Disk Security\USBGuard.exe" [2008-05-24 794624]
"Autorun Eater"="c:\program files\Autorun Eater\oldmcdonald.exe" [2008-11-27 501768]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-24 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-24 137752]
"DrvIcon"="c:\program files\Vista Drive Icon\DrvIcon.exe" [2008-04-13 49152]
"assawsanaReader"="c:\documents and settings\munamuna\Local Settings\Apps\2.0\NH1DP5Y2.DTL\ZRLXVBEV.EH7\assa..tion_9c1c7f8c5e15d6b2_0001.0000_0865aa7080620218\assawsanaReader.exe" [2011-05-13 413696]
"Anti Mosquito"="C:\Anti Mosquito.exe" [2001-12-20 258048]
"ClocX"="c:\program files\ClocX\ClocX.exe" [2007-07-26 270336]
"TkBellExe"="c:\program files\Real\realplayer\update\realsched.exe" [2010-12-05 274608]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"VistaIcon"="c:\program files\VistaDriveIcon\VistaDrv.exe" [2008-01-02 132096]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2009-11-1 1048576]
Snagit 9.lnk - c:\program files\TechSmith\Snagit 9\Snagit32.exe [2009-1-22 7225672]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsp_lmwl]
2007-02-22 05:21 43376 ----a-w- c:\windows\system32\fsp_lmwl.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"4shared Update"="c:\program files\4shared Desktop\checkUpdate.exe"
"WatchDog"=c:\program files\InterVideo\DVD Check\DVDCheck.exe
"PDVD9LanguageShortcut"="c:\program files\CyberLink\PowerDVD9\Language\Language.exe"
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" -osboot
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe"
"SweetIM"=c:\program files\SweetIM\Messenger\SweetIM.exe
"SynTPEnh"=c:\program files\Synaptics\SynTP\SynTPEnh.exe
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD9\\PowerDVD Cinema\\PowerDVDCinema.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD9\\PowerDVD9.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\games\\Alice\\Alice\\alice.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
.
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/05/04 16:00];c:\program files\CyberLink\PowerDVD9\000.fcl [28/02/2009 07:40 م 87536]
R2 BR_Launcher;BR_Launcher;c:\program files\Zain\Zain BroadBand\BRService.exe [30/12/2010 11:24 ص 104264]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [23/03/2010 01:42 م 38144]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21/12/2007 08:21 ص 468224]
R2 ezntsvc;EasyBits Magic Desktop Services for Windows NT;c:\windows\system32\ezntsvc.exe [20/11/2010 10:53 ص 33792]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [03/08/2004 03:56 م 14336]
R2 jswpbapi;JumpStart Push-Button Service;c:\program files\TP-LINK\QSS\jswpbapi.exe [17/11/2009 06:13 م 188416]
R2 Scutum50;Scutum50 NDIS Protocol Driver;c:\windows\system32\drivers\Scutum50.sys [19/01/2011 12:13 ص 19072]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [27/10/2010 07:23 م 1483072]
R3 br_bandluxe_dc_enum;BandLuxe HSPA DC Enumerator;c:\windows\system32\drivers\br_bandluxe_dc_enum.sys [17/05/2010 04:56 م 82176]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [17/11/2009 06:13 م 57440]
R3 LMPC4;LMPC4;c:\windows\system32\drivers\lmpc4.sys [02/12/2010 11:37 ص 10096]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [07/10/2010 02:34 م 10064]
S0 Shadow;Shadow; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 01:16 م 130384]
S2 gupdate1caf0d5f051a224;Google Update Service (gupdate1caf0d5f051a224);c:\program files\Google\Update\GoogleUpdate.exe [10/05/2010 11:48 م 133104]
S3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [17/11/2009 05:47 م 1668352]
S3 athrusb;TP-LINK Extensible Wireless LAN device driver;c:\windows\system32\drivers\athrusb.sys [20/04/2010 02:26 م 857600]
S3 br_bandluxe_cdc_acm;BandLuxe HSPA CDC-ACM driver;c:\windows\system32\drivers\br_bandluxe_cdc_acm.sys [17/05/2010 04:56 م 85888]
S3 br_bandluxe_cdc_ecm;br_bandluxe_cdc_ecm;c:\windows\system32\drivers\br_bandluxe_cdc_ecm.sys [17/05/2010 04:56 م 51072]
S3 br_bandluxe_cpo;BandLuxe HSPA Mass Storage Device;c:\windows\system32\drivers\br_bandluxe_cpo.sys [17/05/2010 04:56 م 9856]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\DfSdkS.exe [06/01/2011 07:21 م 406016]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [19/05/2011 10:55 ص 13224]
S3 gupdatem;خدمة Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/05/2010 11:48 م 133104]
S3 jswpsapi;JumpStart Wi-Fi Protected Setup;c:\program files\TP-LINK\QSS\jswpsapi.exe [17/11/2009 06:13 م 360529]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 01:16 م 753504]
S3 ZD1211BU(TP-LINK);TL-WN322G Wireless USB Adapter Driver(TP-LINK);c:\windows\system32\drivers\ZD1211BU.sys [24/03/2010 12:07 ص 477696]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9C450606-ED24-4958-92BA-B8940C99D441}]
2009-03-04 23:32 8192 ----a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-11 06:48]
.
2011-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-11 06:48]
.
2011-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-1390067357-682003330-1003Core.job
- c:\documents and settings\munamuna\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-04-17 02:38]
.
2011-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-1390067357-682003330-1003UA.job
- c:\documents and settings\munamuna\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-04-17 02:38]
.
2011-08-01 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-583907252-1390067357-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 19:33]
.
2011-07-18 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-583907252-1390067357-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 19:33]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
IE: &Download All using 4shared Desktop - c:\program files\4shared Desktop\down_all.htm
IE: &Download using 4shared Desktop - c:\program files\4shared Desktop\down_link.htm
IE: &Save Flash In This Page - c:\progra~1\Flash Saver 4.0\save.htm
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
IE: Google Sidewiki...
IE: Open using &Advanced JPEG Compressor - c:\program files\Advanced JPEG Compressor\ajcieex.htm
IE: Search - c:\program files\FVD Suite\addons\IE\FVDToolbar.dll/IECONTEXT.DLL.HTM
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
IE: الدليل السريع - c:\windows\ww80.html
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
IE: {{46012075-ED62-464b-9554-AD0BEC35D1EC} -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
IE: {{46012076-ED62-464b-9554-AD0BEC35D1EC}
IE: {{C1E3533C-70F6-4f36-B97C-032C8A5EE759}
DPF: Microsoft XML Parser for Java
FF - ProfilePath - c:\documents and settings\munamuna\Application Data\Mozilla\Firefox\Profiles\bjq9dq8g.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google Custom Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.jo/
FF - prefs.js: keyword.URL - hxxp://start.flashvideodownloader.org/result.php?cx=partner-pub-5087362176467115:lyglkqaff6i&cof=FORID:10&ie=ISO-8859-1&sa=Search&q=
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
URLSearchHooks-{707db484-2428-402d-afb5-d85b387544c7} - (no file)
URLSearchHooks-{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - (no file)
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
BHO-{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - (no file)
Toolbar-{707db484-2428-402d-afb5-d85b387544c7} - (no file)
Toolbar-{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - (no file)
Toolbar-{28387537-e3f9-4ed7-860c-11e69af4a8a0} - (no file)
Toolbar-10 - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
ShellExecuteHooks-UPB:{067B597C-C099-4A08-A180-E5FEC5DCF2DF} - (no file)
Notify-WgaLogon - (no file)
HKLM_ActiveSetup-{F93F1BA6-1EAF-FBCB-4321-9963C3869E41} - c:\program files\Bifrost\server.exe
AddRemove-{889DF117-14D1-44EE-9F31-C5FB5D47F68B} - c:\docume~1\ALLUSE~1\APPLIC~1\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
Rootkit scan 2011-08-01 06:51
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Anti Mosquito = C:\Anti Mosquito.exe???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD9\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):14,2d,52,90,2b,b8,a8,b1,4f,7f,5d,f2,e2,f1,c4,5d,3e,55,16,0b,ee,
70,71,8f,5d,3f,0a,a6,94,52,0a,4e,a1,ed,7c,c2,0b,16,ab,b1,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{d708e37d-17eb-43b9-94e2-82e85ffb8aba}]
@Denied: (Full) (Everyone)
"Model"=dword:0000014e
"Therad"=dword:0000000f
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
.
[HKEY_LOCAL_MACHINE\software\Classes\giffile\shell\Open\ddeexec]
@DACL=(02 0000)
@="\"file:%1\",,-1,,,,,"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(684)
c:\windows\system32\fsp_lmwl.dll
.
- - - - - - - > 'explorer.exe'(3696)
c:\program files\RocketDock\RocketDock.dll
c:\progra~1\CFi\SHELLT~1\CFiShlJP.dll
c:\program files\Internet Download Manager\idmmkb.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\browselc.dll
c:\program files\Internet Download Manager\IDMIECC.dll
c:\progra~1\Flash2X\FLASHP~1\FLASHP~1.DLL
c:\program files\Microsoft Office\Office10\msohev.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Autorun Eater\billy.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
c:\windows\system32\wscntfy.exe
c:\program files\TechSmith\Snagit 9\TSCHelp.exe
c:\program files\TechSmith\Snagit 9\SnagPriv.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\TechSmith\Snagit 9\snagiteditor.exe
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 2011-08-01 06:55:06 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-01 13:55
.
Pre-Run: 21,819,006,976 bytes free
Post-Run: 21,702,455,296 bytes free
.
- - End Of File - - FA921CCE52862FCC90318A9D881B1CFD
