عفوا اخي لااستطيع الرفع لظروف النت البطيء وارجن ان تقبله نسخ بارك الله فيك
ComboFix 09-03-12.01 - asd_541 03/13/2009 22:16:19.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.511.276 [GMT 2:00]
Running from: c:\documents and settings\asd_541\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\asd_541\Favorites\aws دليل للمواقع.exe
c:\documents and settings\asd_541\Favorites\Online Security Test.url
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2009-02-13 to 2009-03-13 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-13 18:40 --------- d-----w c:\documents and settings\asd_541\Application Data\Smart PC Solutions
2009-03-13 18:33 --------- d-----w c:\documents and settings\All Users\Application Data\TEMP
2009-03-12 17:02 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-03-12 12:36 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-12 12:36 --------- d-----w c:\program files\Creative
2009-03-12 12:20 --------- d-----w c:\documents and settings\asd_541\Application Data\Winamp
2009-03-12 12:19 --------- d-----w c:\program files\Winamp
2009-03-12 12:18 --------- d-----w c:\program files\K-Lite Codec Pack
2009-03-12 12:08 --------- d-----w c:\program files\MultiRes
2009-03-12 12:07 451,072 ----a-w c:\windows\Radeon Omega Drivers v3.8.252 Uninstall.exe
2009-03-12 12:07 --------- d-----w c:\program files\Radeon Omega Drivers
2009-03-12 11:57 --------- d-----w c:\program files\IC Media Corp
2009-03-12 11:57 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-12 11:36 --------- d-----w c:\program files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/12/2004 10:18 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [08/12/2004 10:20 AM 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [08/12/2004 10:21 AM 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [08/12/2004 10:21 AM 455168]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [01/28/2009 07:31 PM 114176]
"UpdReg"="c:\windows\UpdReg.EXE" [05/11/2000 01:00 AM 163840]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [11/29/2001 01:00 AM 28672]
"ATIModeChange"="Ati2mdxx.exe" [05/03/2006 06:45 PM 26112 c:\windows\system32\Ati2mdxx.exe]
"AtiPTA"="atiptaxx.exe" [02/22/2006 03:05 AM 413696 c:\windows\system32\atiptaxx.exe]
"WINDVDPatch"="CTHELPER.EXE" [07/02/2002 05:56 PM 24576 c:\windows\system32\CTHELPER.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/12/2004 10:18 AM 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Launchpad.lnk - c:\program files\IC Media Corp.\ICM532\Launchpad.exe [2009-03-12 126976]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\programs\\Antivirus\\Kaspersky_Internet_Security_2009_v8.0.0.454_ENG\\Kaspersky Internet Security 2009 v8.0.0.454 ENG\\kis8.0.0.454en.exe"=
"c:\\WINDOWS\\system32\\Ati2evxx.exe"=
"c:\\WINDOWS\\system32\\atiptaxx.exe"=
"c:\\WINDOWS\\UpdReg.EXE"=
"c:\\WINDOWS\\system32\\CTHELPER.EXE"=
"d:\\Conquer 2.0\\Conquer.exe"=
"c:\\WINDOWS\\system32\\CF31292.exe"=
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ASC3360PR
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-03-13 22:18:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(520)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\IC Media Corp\ICM532\launchpad.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 03/13/2009 22:20:58 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-13 20:20:54
Pre-Run: 4,731,154,432 bytes free
Post-Run: 4,689,219,584 bytes free
109 --- E O F --- 2009-03-13 16:03:40