الحالة
مغلق و غير مفتوح للمزيد من الردود.

الامبراطور سيف

زيزوومي جديد
إنضم
21 أبريل 2009
المشاركات
8
مستوى التفاعل
0
النقاط
0
غير متصل
السلام عليكم ورحمه الله وبركاته

اخواني انا عندي مشكلة في جهازي
عندي شريط المهام مجمد
وايضا بعلق الجهاز عندما اضغط على الزر الايمن للماوس او عندما اضغط على Delete
وبظهر لي مربع حوار

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


ممكن الحل
ولكم جزيل الشكر
 

وعليكم السلام


حمل هذا البرنامج

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

شغل البرنامج ==> واضغط على
Do a system scan and save log
لحظات .. ويظهر لك تقرير داخل المفكرة==> انسخه والصقه بردك القادم
 
التعديل الأخير بواسطة المشرف:
توقيع : أعتز بك
اخي عملت اللي قلته
ظهر لي مفكرة وفيها تقرير


Scan saved at 03:49:38 م, on 22/04/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Seekmo\bin\10.0.431.0\OEAddOn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Opera\opera.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winyibcc.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winfpnfe.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winnoxfne.exe
C:\Documents and Settings\Administrator\سطح المكتب\Zyzoom_HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

F2 - REG:system.ini: Shell=Explorer.exe
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Seekmo /fleok=1D8A83A5C2ED127E9DAB6C2A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - C:\Program Files\Seekmo\bin\10.0.431.0\HostIE.dll (file missing)
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O3 - Toolbar: Seekmo - {07AA283A-43D7-4CBE-A064-32A21112D94D} - C:\Program Files\Seekmo\bin\10.0.431.0\HostIE.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SeekmoOE] C:\Program Files\Seekmo\bin\10.0.431.0\OEAddOn.exe
O4 - HKLM\..\Run: [SystemX] C:\WINDOWS\system32\ExtraDll.bat
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: English<->Arabic - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Arabic) for Windows\Plugins\IE.htm
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: English<->Arabic - {6E314959-13AD-D246-82D4-8B753F8C4ACA} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Arabic) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: English<->Arabic - {6E314959-13AD-D246-82D4-8B753F8C4ACA} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Arabic) for Windows\Plugins\IE.htm
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Unknown owner - C:\Program Files\Symantec AntiVirus\DefWatch.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: SAVRoam (SavRoam) - Unknown owner - C:\Program Files\Symantec AntiVirus\SavRoam.exe (file missing)
O23 - Service: Symantec AntiVirus - Unknown owner - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (file missing)
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

--
End of file - 7372 bytes
 
اخي شكرا لك على مداخلتك
وده تقرير اليوم

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:49:05 ص, on 23/04/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Opera\opera.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winlnjkgb.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winxsec.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winkwile.exe
C:\Documents and Settings\Administrator\سطح المكتب\Zyzoom_HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

F2 - REG:system.ini: Shell=Explorer.exe
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O3 - Toolbar: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SeekmoOE] C:\Program Files\Seekmo\bin\10.0.431.0\OEAddOn.exe
O4 - HKLM\..\Run: [SystemX] C:\WINDOWS\system32\ExtraDll.bat
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: English<->Arabic - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Arabic) for Windows\Plugins\IE.htm
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: English<->Arabic - {6E314959-13AD-D246-82D4-8B753F8C4ACA} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Arabic) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: English<->Arabic - {6E314959-13AD-D246-82D4-8B753F8C4ACA} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Arabic) for Windows\Plugins\IE.htm
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing)
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Unknown owner - C:\Program Files\Symantec AntiVirus\DefWatch.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: SAVRoam (SavRoam) - Unknown owner - C:\Program Files\Symantec AntiVirus\SavRoam.exe (file missing)
O23 - Service: Symantec AntiVirus - Unknown owner - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (file missing)
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

--
End of file - 6800 bytes
 
عطل برامج الحماية عن العمل

نزل هذه الاداة


يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes

اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
انتظر حتى يظهر لك تقرير ،، وبذلك يكون الفحص انتهى الصق التقرير بمشاركتك القادمة
 
توقيع : Corporation
شكرا لك على المداخلة
وده التقرير بعد ما استخدم الاداه

ComboFix 09-04-23.A0 - Administrator 04/23/2009 14:10.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.247.42 [GMT 3:00]
Running from: c:\documents and settings\Administrator\سطح المكتب\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\ADMINI~1\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\ابو حسـام\Application Data\ShoppingReport
c:\documents and settings\ابو حسـام\Application Data\ShoppingReport\cs\Config.xml
c:\documents and settings\ابو حسـام\Application Data\ShoppingReport\cs\db\Aliases.dbs
c:\documents and settings\ابو حسـام\Application Data\ShoppingReport\cs\db\Sites.dbs
c:\documents and settings\ابو حسـام\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
c:\documents and settings\ابو حسـام\Application Data\ShoppingReport\cs\report\aggr_storage.xml
c:\documents and settings\ابو حسـام\Application Data\ShoppingReport\cs\report\send_storage.xml
c:\documents and settings\ابو حسـام\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
c:\documents and settings\Administrator\Application Data\Seekmo
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\030104_emte10_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\030104_emte11_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\030104_emte12_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\030104_emte13_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\030104_emte14_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\030104_emte19_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\030104_emte20_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\030104_emte21_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\030104_emte9_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\030203lib_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102angel_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102bigluf_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102bigsmile_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102birthday_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102cheers_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102flo_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102good_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102jump_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102king_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102lough_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102luf_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102smile_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102smiled_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102sor_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102thanx_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\033102uhu_1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\040103ahh_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\040103wow_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\040104_emi2_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\042102_1134_112_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\050103big_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\050103gig_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\050103hm_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\050103nomail_emoti_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\050103norm_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\060104_ema15_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\060104_ema16_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\060104_ema17_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\060104_ema18_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\060104_ema19_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\060104_ema20_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\060104_ema21_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\060104_ema24_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\060104_ema25_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\060104_ema26_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\060104_ema30_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\060104_ema33_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\060104_ema34_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\062802hippi_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\062802jumpie_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\080402argh_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\080402oops_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\080402ouch_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\082502no_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\082502yes_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\110103_boring1_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\110103_confused_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\110103_crying_ugly_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\110103_fantastic_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\110103_feel_better_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\110103_gimme_break_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\110103_heehee_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\110103_hlopaet_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\110103_ign_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\110103_lol_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\110103_no_comment_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\110103_peace_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\110103_smashing_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\110103_talk2thehand_prv.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\block_sm.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\block_sm2.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\block_smli.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\block_smli2.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\blocked.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\blocked2.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\btn_add-but.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\btn_back-but.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\btn_left_cut_enabled_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\btn_left_enabled_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\btn_left_pressed_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\btn_middle_enabled_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\btn_middle_pressed_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\btn_right_cut_enabled_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\btn_right_enabled_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\btn_right_pressed_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\business_promo.htm
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\buttondir.txt
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\components.cdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\css_cattree.css
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\css_flashpreview.css
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\css2_main.css
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\css2_pagingmodule.css
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\css2_topbuttons.css
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\cursors.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\delete.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\edit_clear_sound.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\edit_fs.htm
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\edit_select.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-511724-543450.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-511724-548964.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-511724-589306.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-511724-591943.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-511724-592579.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-511724-598579.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-511724-603763.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-511724-9595.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-511724-9696.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-511745-514279.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-backgrounds.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-bcards.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-ecards.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-emoticons.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-estationery.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-funny.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-help.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-images.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-info.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-more.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-my.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-new.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-new2.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-options.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-people.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-photo.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-tell.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-temp.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-text.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def-email-voice.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-def.cdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-premium-email-premium.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-t1-bg.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\email-temp-bg.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\estatationery.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\flashpatch.js
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\flashpreview.htm
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\fs3.htm
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\hotbar_promo.htm
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_checked_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_close_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_close_pressed_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_edit_preview.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_edit_send.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_flash_preview.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_recently_used.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_remove_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_remove_pressed_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_sand-clock2.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_tell_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_tell_pressed_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_tree_null.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_unchecked_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\icon_unchecked_pressed_1.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\img_barlayout.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\img_barlayout2.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\img_barlayout4.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\img_corner_left.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\img_local_logo.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\js2_basetemplate.js
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\js2_hbgroups.js
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\js2_hbobject3.js
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\js2_hbobjectset3.js
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\js2_hotbarwrapper.js
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\js2_iteratorsandreaders3nf.js
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\js2_pagingmoduleobj3.js
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\js2_texts3.js
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\js2_xmltree3nf.js
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\layout.cdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\linkpathlegal.txt
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\n.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\nav_b_2.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\nav_bb_2.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\nav_f_2.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\nav_ff_2.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\progress.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\sales_buttons.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\searchbtn.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\seekmo_btn.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\submit.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\tab_bg.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\tab_bga.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\tab_bgia.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\tab_l.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\tab_la.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\tab_lia.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\tab_r.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\tab_ra.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\tab_ria.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\tree_dots.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\tree_minus.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\tree_plus.gif
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\treedata_animations.xml
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\treedata_backgrounds.xml
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\treedata_ecards.xml
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\treedata_emoticons.xml
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\treedata_notifiers.xml
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\1\treedata_text.xml
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\business_promo.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\buttondir.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\code.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\cursors.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\email-def.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\email-t1-bg.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\email-temp-bg.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\hotbar_promo.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\images.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\layout.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\linkpathlegal.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\localcontent.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\progress.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\sales_buttons.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\seekmo_btn.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\HostOI\static\DownLoad\treexml.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\1.sdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\1389439.sdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\2883915.sdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\322472.sdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\3893159.sdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\395368.sdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\600583.sdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\622897.sdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\domains.txt
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\1000091499
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\13617
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\13677
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\2021
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\218859
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\29547
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\31537
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\41999
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\42013
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\42208
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\43377
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\51194
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\52335
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\55004
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\555618
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\559580
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\58197
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\59844
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\59872
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\61779
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\68829
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\69325
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\748893
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\753197
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\83743
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\86173
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\87385
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\90358
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\93899
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\93934
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\ustat\37f5.dat
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\dynamic\ustat\37f6.dat
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\btntrans.idx
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\btntrans1.dat
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\buttondir.txt
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\components.cdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\cursors.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_1000.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_2000.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_3000.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_bar.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_bbar1.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_logos.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_other.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_weather.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\default.cdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_511745-514279.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_categorize.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_comparison.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_explorer-Mails.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_explorer-people.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_favorites.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Games.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Hide.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_hotbarcom.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Hotmail.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_hsskin.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Mails.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_new.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_premium.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_searchfor.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_searchgo.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_weather.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_yellowpages.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\email-def-511724-548964.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\email-def-511724-9595.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\email-t1-bg.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\icons2.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\ie_games_icon.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\ie_video.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\keywords.idx
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\keywords1.dat
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\layout.cdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\linkpathlegal.txt
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\progress.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\s_icons_buttons.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\sales_buttons.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\seekmo.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\seekmo_ie_menu.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\t2_bg.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\theweb.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\top7.cdf
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\Top7_theweb.mnu
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\2\tsd_bg.res
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\BtnTrans.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\BtnTrans1.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\buttondir.txt
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\buttondir.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\cursors.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_1000.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_2000.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_3000.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_bar.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_bbar1.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_logos.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_other.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_weather.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\default.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\email-t1-bg.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\icons2.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\ie_games_icon.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\ie_video.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords1.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\layout.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\linkpathlegal.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\progress.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\s_icons_buttons.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\sales_buttons.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\samplegroups2.txt
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\samplegroups2.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\seekmo.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\seekmo_ie_menu.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\t2_bg.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\top7.xip
c:\documents and settings\Administrator\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\tsd_bg.xip
c:\documents and settings\Administrator\Application Data\ShoppingReport
c:\documents and settings\Administrator\Application Data\ShoppingReport\cs\Config.xml
c:\documents and settings\Administrator\Application Data\ShoppingReport\cs\db\Aliases.dbs
c:\documents and settings\Administrator\Application Data\ShoppingReport\cs\db\Sites.dbs
c:\documents and settings\Administrator\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
c:\documents and settings\Administrator\Application Data\ShoppingReport\cs\report\aggr_storage.xml
c:\documents and settings\Administrator\Application Data\ShoppingReport\cs\report\send_storage.xml
c:\documents and settings\Administrator\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
c:\documents and settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
c:\documents and settings\All Users\Application Data\SeekmoSA
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSA.dat
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSA_kyf.dat
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSAAbout.mht
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSAau.dat
c:\documents and settings\All Users\Application Data\SeekmoSA\SeekmoSAEULA.mht
c:\program files\ShoppingReport
c:\program files\ShoppingReport\Uninst.exe
c:\windows\IE4 Error Log.txt
c:\windows\system32\kakle.dll
c:\windows\system32\winitn.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ASC3360PR
-------\Service_asc3360pr


((((((((((((((((((((((((( Files Created from 2009-05-23 to 2009-4-23 )))))))))))))))))))))))))))))))
.

2009-04-22 23:59 . 2009-04-22 23:59 -------- d-----w c:\windows\system32\CatRoot_bak
2009-04-22 16:01 . 2009-04-22 16:01 -------- d-----w c:\windows\system32\KB905474
2009-04-22 16:01 . 2009-03-10 19:26 1430400 ----a-w c:\windows\system32\KB905474\wganotifypackageinner.exe
2009-04-22 16:01 . 2009-03-10 19:18 514440 ----a-w c:\windows\system32\KB905474\wgasetup.exe
2009-04-22 16:01 . 2009-02-09 15:51 11874 ----a-w c:\windows\system32\KB905474\wga_eula.txt
2009-04-21 09:20 . 2009-04-21 09:20 -------- d-----w c:\documents and settings\Administrator\Application Data\Ectaco
2009-04-20 15:02 . 2009-04-20 15:02 -------- d-----w C:\LightC
2009-04-19 04:16 . 2009-04-23 11:04 94556 ----a-w c:\windows\system32\ExtraDll
2009-04-19 04:16 . 2009-04-19 04:16 31744 ----a-w c:\windows\system32\ExtraDll.bat
2009-04-19 04:16 . 2009-03-06 19:32 265014 ----a-w c:\windows\a.jpg
2009-04-19 03:52 . 2009-04-19 03:52 -------- d-sh--w C:\FOUND.007
2009-04-18 11:00 . 2009-04-18 11:00 0 ----a-w c:\windows\VPC32.INI
2009-04-18 09:51 . 2009-04-18 09:52 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Symantec
2009-04-18 09:51 . 2004-03-04 20:46 83168 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-04-18 09:51 . 2004-03-04 20:46 82832 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-04-18 09:50 . 2009-04-18 09:51 -------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-04-17 11:21 . 2009-04-17 11:21 -------- d-sh--w C:\FOUND.006
2009-04-16 15:46 . 2009-04-16 15:46 -------- d-----w c:\documents and settings\Administrator\Application Data\Advanced Clock
2009-04-16 07:41 . 2009-02-09 11:48 2059264 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-04-16 07:41 . 2009-02-09 11:48 2182016 ------w c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-16 07:41 . 2009-02-09 11:48 2017280 ------w c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-16 07:41 . 2009-02-09 11:48 2137600 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-15 13:50 . 2009-02-13 08:31 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-04-14 12:23 . 2008-06-14 17:59 271616 ------w c:\windows\system32\drivers\bthport.sys
2009-04-14 12:23 . 2008-06-14 17:59 271616 ------w c:\windows\system32\dllcache\bthport.sys
2009-04-14 11:35 . 2008-10-24 11:10 453632 ------w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-13 18:13 . 2008-07-09 07:34 26488 ----a-w c:\windows\system32\spupdsvc.exe
2009-04-13 18:13 . 2009-04-13 18:13 -------- d--h--w c:\windows\$hf_mig$
2009-04-13 17:16 . 2009-04-21 09:26 1555 ----a-w c:\windows\ata live update.ini
2009-04-13 17:16 . 2009-04-13 17:16 -------- d-----w c:\windows\speech
2009-04-13 17:14 . 2009-04-13 17:14 172032 ------w c:\windows\Setup1.exe
2009-04-13 17:14 . 2009-04-13 17:14 73216 ----a-w c:\windows\ST6UNST.EXE
2009-04-13 17:14 . 2009-04-13 17:14 8920 ----a-w c:\windows\SETUP.LST
2009-04-13 13:00 . 2009-04-13 13:00 45056 ----a-w c:\windows\NCUNINST.EXE
2009-04-12 14:14 . 2009-04-12 14:14 -------- d-sh--w C:\FOUND.005
2009-04-08 09:17 . 2009-04-08 09:17 -------- d-sh--w C:\FOUND.004
2009-04-07 18:14 . 2009-04-14 13:36 54156 ---ha-w c:\windows\QTFont.qfn
2009-04-07 18:14 . 2009-04-07 18:14 1409 ----a-w c:\windows\QTFont.for
2009-04-07 13:34 . 2009-04-07 13:34 65 ----a-w c:\windows\poolemup.ini
2009-04-07 13:22 . 2009-04-07 13:22 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Help
2009-04-07 13:22 . 2009-04-07 13:22 -------- d-----w C:\My Documents
2009-04-07 13:07 . 2009-04-07 13:07 -------- d-----w c:\documents and settings\ابو حسـام\Application Data\Babylon
2009-04-05 02:41 . 2009-04-05 02:41 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-04-01 03:24 . 2009-04-01 03:24 90112 ----a-w c:\windows\system32\ALOAudioFormatSettings3.dll
2009-04-01 03:24 . 2009-04-01 03:24 877568 ----a-w c:\windows\system32\ALOAudioFile2.dll
2009-04-01 03:24 . 2009-04-01 03:24 780288 ----a-w c:\windows\system32\ALOVideoCompress.dll
2009-04-01 03:24 . 2009-04-01 03:24 495104 ----a-w c:\windows\system32\ALOVideoCoreM.dll
2009-04-01 03:24 . 2009-04-01 03:24 403968 ----a-w c:\windows\system32\ALOWMAFile2.dll
2009-04-01 03:24 . 2009-04-01 03:24 382464 ----a-w c:\windows\system32\ALOAVIFile.dll
2009-04-01 03:24 . 2009-04-01 03:24 2846720 ----a-w c:\windows\system32\ALOAudioCompress3.dll
2009-04-01 03:24 . 2009-04-01 03:24 249856 ----a-w c:\windows\system32\ALOQuickTimeFile.dll
2009-04-01 03:24 . 2009-04-01 03:24 215552 ----a-w c:\windows\system32\ALOWMVFile.dll
2009-04-01 03:24 . 2009-04-01 03:24 188416 ----a-w c:\windows\system32\ALOVideoFile.dll
2009-04-01 03:24 . 2009-04-01 03:24 778240 ----a-w c:\windows\system32\ALOAudioCompress2.dll
2009-03-31 15:11 . 2009-03-31 15:11 -------- d-----w c:\documents and settings\All Users\Application Data\NCH Software
2009-03-27 11:25 . 1998-10-29 13:45 306688 ----a-w c:\windows\IsUninst.exe
2009-03-27 06:45 . 2009-03-27 06:45 823296 ----a-w c:\windows\system32\agsaamh.dll
2009-03-27 06:45 . 2009-03-27 06:45 671869 ----a-w c:\windows\system32\agsaame.dll
2009-03-27 06:45 . 2009-03-27 06:45 643072 ----a-w c:\windows\system32\agsaamd.dll
2009-03-27 06:45 . 2009-03-27 06:45 638976 ----a-w c:\windows\system32\agsaamb.dll
2009-03-27 06:45 . 2009-03-27 06:45 360448 ----a-w c:\windows\system32\agsaamf.ocx
2009-03-27 06:45 . 2009-03-27 06:45 315392 ----a-w c:\windows\system32\agsaama.dll
2009-03-26 18:52 . 2009-03-26 18:52 -------- d-sh--w C:\FOUND.003
2009-03-26 11:09 . 2009-04-22 11:52 720896 ----a-w c:\windows\iun6002.exe
2009-03-26 04:23 . 2009-03-26 04:23 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer
2009-03-24 23:18 . 2009-03-24 23:18 -------- d-----w c:\documents and settings\Administrator\Application Data\USBSafelyRemove
2009-03-24 23:18 . 2009-03-24 23:18 -------- d-----w c:\documents and settings\All Users\Application Data\USBSRService
2009-03-24 15:07 . 2009-03-24 15:07 -------- d-----w c:\documents and settings\ابو حسـام\Local Settings\Application Data\Google
2009-03-24 14:43 . 2007-06-12 01:04 2267368 ----a-w c:\windows\system32\Flash9d.ocx
2009-03-24 14:43 . 2000-05-22 14:58 608448 ----a-w c:\windows\system32\comctl32.ocx
2009-03-24 14:43 . 1998-06-23 21:00 203576 ----a-w c:\windows\system32\RICHTX32.OCX
2009-03-24 14:43 . 1998-06-23 21:00 115016 ----a-w c:\windows\system32\MSINET.OCX

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-22 11:52 . 2009-04-22 11:52 -------- d-----w c:\program files\قاموس صخر
2009-04-21 09:20 . 2009-04-21 09:20 -------- d-----w c:\program files\LingvoSoft
2009-04-18 09:51 . 2009-04-18 09:50 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-16 11:54 . 2001-09-19 09:00 41076 ----a-w c:\windows\system32\perfc001.dat
2009-04-16 11:54 . 2001-09-19 09:00 254326 ----a-w c:\windows\system32\perfh001.dat
2009-04-13 17:15 . 2009-04-13 17:15 -------- d-----w c:\program files\Golden Al-Wafi Translator
2009-04-13 13:00 . 2009-04-13 13:00 -------- d-----w c:\program files\Common Files\SWF Studio
2009-04-01 03:24 . 2009-03-17 12:48 1245184 ----a-w c:\windows\system32\bkll.dll
2009-04-01 03:24 . 2009-04-01 03:24 -------- d-----w c:\program files\Arabic_video
2009-03-31 15:10 . 2009-03-31 15:10 -------- d-----w c:\program files\NCH Software
2009-03-29 13:12 . 2009-03-29 13:12 -------- d-----w c:\program files\Foxit Software
2009-03-27 11:29 . 2009-03-27 11:29 -------- d-----w c:\program files\Common Files\Adobe
2009-03-27 06:45 . 2009-03-17 12:48 90112 ----a-w c:\windows\system32\agsaami.dll
2009-03-27 06:45 . 2009-03-17 12:48 610304 ----a-w c:\windows\system32\agsaamg.dll
2009-03-27 06:45 . 2009-03-17 12:48 2535424 ----a-w c:\windows\system32\agsaamj.dll
2009-03-27 06:45 . 2009-03-17 12:48 1986560 ----a-w c:\windows\system32\akll.dll
2009-03-27 06:45 . 2009-03-17 12:48 196608 ----a-w c:\windows\system32\maag.dll
2009-03-27 06:45 . 2009-03-17 12:48 1212416 ----a-w c:\windows\system32\ckll.dll
2009-03-27 06:45 . 2009-03-17 12:48 372736 ----a-w c:\windows\system32\agsaamc.dll
2009-03-26 11:09 . 2009-03-26 11:09 -------- d-----w c:\program files\الدليل الفلسطيني 2007
2009-03-24 14:43 . 2009-03-24 14:43 -------- d-----w c:\program files\GVR
2009-03-24 06:58 . 2009-03-24 06:57 -------- d-----w c:\program files\Abadisoft
2009-03-22 14:24 . 2009-03-22 14:24 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-22 14:24 . 2009-03-22 14:24 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-21 14:19 . 2004-08-03 21:55 1354240 ----a-w c:\windows\system32\dllcache\kernel32.dll
2009-03-21 09:02 . 2009-03-21 09:01 -------- d-----w c:\documents and settings\Administrator\Application Data\Yahoo!
2009-03-18 17:58 . 2009-03-18 17:58 -------- d-----w c:\program files\VoiceMaskPro
2009-03-18 17:43 . 2009-03-18 17:43 -------- d-----w c:\documents and settings\Administrator\Application Data\skypePM
2009-03-17 14:32 . 2009-03-17 14:32 -------- d-----w c:\program files\Opera
2009-03-17 13:32 . 2009-03-16 19:37 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-17 12:56 . 2009-03-16 19:45 73208 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-17 12:49 . 2009-03-17 12:49 -------- d-----w c:\program files\SuperCopier2
2009-03-17 12:47 . 2009-03-17 12:47 -------- d-----w c:\program files\Real_SC
2009-03-16 20:34 . 2009-03-16 20:34 -------- d-----w c:\program files\Microsoft.NET
2009-03-16 20:28 . 2009-03-16 20:28 268 ---ha-w C:\sqmdata01.sqm
2009-03-16 20:28 . 2009-03-16 20:28 244 ---ha-w C:\sqmnoopt01.sqm
2009-03-16 20:23 . 2009-03-16 20:23 -------- d-----w c:\documents and settings\Administrator\Application Data\ESET
2009-03-16 20:22 . 2009-03-16 20:22 -------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-03-16 20:19 . 2009-03-16 20:19 -------- d-----w c:\documents and settings\Administrator\Application Data\Skype
2009-03-16 20:18 . 2009-03-16 20:18 -------- d-----w c:\program files\Common Files\Skype
2009-03-16 20:18 . 2009-03-16 20:18 -------- d-----r c:\program files\Skype
2009-03-16 20:18 . 2009-03-16 20:18 -------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-03-16 20:17 . 2009-03-16 20:17 -------- d-----w c:\documents and settings\Administrator\Application Data\Webroot
2009-03-16 20:17 . 2009-03-16 20:17 -------- d-----w c:\program files\Webroot
2009-03-16 20:17 . 2009-03-16 20:17 -------- d-----w c:\program files\Common Files\Webroot Shared
2009-03-16 20:17 . 2009-03-16 20:17 -------- d-----w c:\documents and settings\All Users\Application Data\Webroot
2009-03-16 20:16 . 2009-03-16 20:16 -------- d-----w c:\program files\Common Files\xing shared
2009-03-16 20:16 . 2004-04-05 01:31 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-03-16 20:16 . 2009-03-16 20:16 -------- d-----w c:\program files\Google
2009-03-16 20:16 . 2009-03-16 20:16 -------- d-----w c:\program files\Real
2009-03-16 20:13 . 2009-03-16 20:13 -------- d-----w c:\documents and settings\Administrator\Application Data\COWON
2009-03-16 20:13 . 2009-03-16 20:13 -------- d-----w c:\program files\Common Files\COWON
2009-03-16 20:13 . 2009-03-16 20:13 -------- d-----w c:\program files\JetAudio
2009-03-16 20:13 . 2009-03-16 20:13 -------- d-----w c:\documents and settings\Administrator\Application Data\InstallShield
2009-03-16 20:11 . 2009-03-16 20:11 -------- d-----w c:\documents and settings\Administrator\Application Data\IDM
2009-03-16 20:11 . 2009-03-16 20:11 -------- d-----w c:\documents and settings\Administrator\Application Data\DMCache
2009-03-16 20:11 . 2009-03-16 20:11 -------- d-----w c:\program files\Internet Download Manager
2009-03-16 20:11 . 2009-03-16 20:11 268 ---ha-w C:\sqmdata00.sqm
2009-03-16 20:11 . 2009-03-16 20:11 244 ---ha-w C:\sqmnoopt00.sqm
2009-03-16 20:09 . 2009-03-16 20:09 -------- d-----w c:\program files\Windows Live
2009-03-16 20:08 . 2009-03-16 20:08 -------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2009-03-16 20:08 . 2009-03-16 20:08 146 ----a-w C:\YServer.txt
2009-03-16 20:08 . 2009-03-16 20:08 -------- d-----w c:\program files\Yahoo!
2009-03-16 20:04 . 2009-03-16 20:04 -------- d-----w c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-03-16 20:03 . 2009-03-16 20:03 -------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-03-16 20:03 . 2009-03-16 20:03 -------- d-----w c:\program files\Common Files\Real
2009-03-16 20:03 . 2009-03-16 20:03 -------- d-----w c:\program files\Ringz Studio
2009-03-16 19:56 . 2009-03-16 19:56 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-16 19:56 . 2009-03-16 19:56 -------- d-----w c:\program files\Topro
2009-03-16 19:56 . 2009-03-16 19:56 -------- d-----w c:\program files\Common Files\InstallShield
2009-03-16 19:38 . 2009-03-16 19:38 -------- d-----w c:\program files\microsoft frontpage
2009-03-16 19:34 . 2009-03-16 19:34 22144 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-06 14:44 . 2004-08-03 19:55 282624 ----a-w c:\windows\system32\pdh.dll
2009-03-06 14:44 . 2004-08-03 19:55 282624 ----a-w c:\windows\system32\dllcache\pdh.dll
2009-03-02 23:49 . 2004-08-03 21:55 1495552 ----a-w c:\windows\system32\dllcache\shdocvw.dll
2009-02-20 08:30 . 2004-08-03 19:55 3080704 ----a-w c:\windows\system32\dllcache\mshtml.dll
2009-02-19 09:58 . 2009-03-16 19:34 18432 ----a-w c:\windows\system32\dllcache\iedw.exe
2009-02-09 13:15 . 2004-08-03 21:46 1846144 ----a-w c:\windows\system32\dllcache\win32k.sys
2009-02-09 13:15 . 2004-08-03 19:46 1846144 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:48 . 2004-08-03 21:48 2059264 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:48 . 2004-08-03 19:49 2182016 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 10:19 . 2004-08-03 21:55 399360 ----a-w c:\windows\system32\dllcache\rpcss.dll
2009-02-09 10:19 . 2004-08-03 21:55 717824 ----a-w c:\windows\system32\dllcache\lsasrv.dll
2009-02-09 10:19 . 2004-08-03 21:55 680960 ----a-w c:\windows\system32\dllcache\advapi32.dll
2009-02-09 10:19 . 2004-08-03 19:55 399360 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:19 . 2004-08-03 19:55 717824 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:19 . 2004-08-03 19:55 680960 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:19 . 2009-03-16 19:33 453120 ----a-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-02-09 10:19 . 2009-03-16 19:33 473088 ----a-w c:\windows\system32\dllcache\fastprox.dll
2009-02-09 10:19 . 2004-08-03 21:55 693760 ----a-w c:\windows\system32\dllcache\ntdll.dll
2009-02-09 10:19 . 2004-08-03 19:55 693760 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 10:05 . 2004-08-03 21:56 110592 ----a-w c:\windows\system32\dllcache\services.exe
2009-02-09 10:05 . 2004-08-03 19:56 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 16:54 . 2001-09-19 09:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 16:54 . 2001-09-19 09:00 35328 ----a-w c:\windows\system32\dllcache\sc.exe
2009-02-06 16:39 . 2009-03-16 19:33 227840 ----a-w c:\windows\system32\dllcache\wmiprvse.exe
2009-02-03 20:08 . 2004-08-03 21:55 55808 ----a-w c:\windows\system32\dllcache\secur32.dll
2009-02-03 20:08 . 2004-08-03 19:55 55808 ----a-w c:\windows\system32\secur32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-11 4802040]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-03-16 994304]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2005-03-13 1057280]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-17 208120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-05 225280]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-05 139264]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-05 176128]
"StormCodec_Helper"="c:\program files\Ringz Studio\Storm Codec\StormSet.exe" [2009-03-21 306253]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-16 247336]
"SystemX"="c:\windows\system32\ExtraDll.bat" [2009-04-19 31744]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-11-15 139264]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

c:\documents and settings\All Users\çں‍ê، ں*§ڑ\ںé*©ںê¤\*§ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-3-27 244736]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Ringz Studio\\Storm Codec\\StormSet.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\ymsgr_tray.exe"=
"c:\\WINDOWS\\system32\\wuauclt.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\Program Files\\SuperCopier2\\SuperCopier2.exe"=
"c:\\WINDOWS\\system32\\igfxpers.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\Program Files\\Real_SC\\opt.exe"=
"c:\\LightC\\VClient.exe"=
"c:\\PROGRA~1\\Yahoo!\\MESSEN~1\\YAHOOM~1.EXE"=
"c:\\Program Files\\Ringz Studio\\Storm Codec\\mplayerc.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"c:\\WINDOWS\\system32\\KB905474\\wgasetup.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe"=

R3 DCamUSBIntel;zc211 PC Camera;c:\windows\system32\Drivers\TP6800.sys [2004-12-21 218504]
R3 SavRoam;SavRoam; [x]
S2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [2007-11-26 598856]
S3 aic32p;aic32p; [x]


--- Other Services/Drivers In Memory ---

*Deregistered* - mchInjDrv

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{493D072E-975C-79A8-AEEB-94C5E10AF4CC}]
c:\windows\system32\ExtraDll.bat
.
Contents of the 'Scheduled Tasks' folder

2009-04-23 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-22 19:18]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-vptray - c:\progra~1\SYMANT~1\VPTray.exe
HKLM-Run-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
HKU-Default-Run-Yahoo Messengger - c:\windows\system32\SSVICHOSST.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: English<->Arabic - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Arabic) for Windows\Plugins\IE.htm
IE: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\Internet Download Manager\IEGetVL.htm
IE: {{6E314959-13AD-D246-82D4-8B753F8C4ACA} - c:\program files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Arabic) for Windows\Plugins\IE.htm
IE: {{C5428486-50A0-4a02-9D20-520B59A9F9B3} - {A16AD1E9-F69A-45af-9462-B1C286708842} -
.
.
------- File Associations -------
.
txtfile=c:\windows\notepad.exe %1
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Rootkit scan 2009-04-23 14:15
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SystemX = c:\windows\system32\ExtraDll.bat??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(4000)
c:\program files\SuperCopier2\SC2Hook.dll
c:\windows\system32\shdoclc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-23 14:17 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-23 11:17

Pre-Run: 9,942,417,408 bytes free
Post-Run: 14,565,081,088 bytes free

676 --- E O F --- 2009-04-22 16:01
 
لكن اخي للاسف لم تحل مشكلة الضغط بالزر الايمن او دليت
يظهر لي مربع الحوار
AIk92975.jpg
 
جهآزك مزرعة فيرسآت ,,

هايجـآك جديد لاهنت ,,​
 
توقيع : Corporation
اخي ذاك تقرير للاداة وليس للهايجاك
وده تقرير الهايجاك بعد استخدام الاداة
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:26:03 م, on 23/04/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\opera.exe
C:\WINDOWS\system32\msiexec.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winwoian.exe
C:\WINDOWS\notepad.exe
C:\Documents and Settings\Administrator\سطح المكتب\Zyzoom_HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SystemX] C:\WINDOWS\system32\ExtraDll.bat
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: English<->Arabic - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Arabic) for Windows\Plugins\IE.htm
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: English<->Arabic - {6E314959-13AD-D246-82D4-8B753F8C4ACA} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Arabic) for Windows\Plugins\IE.htm
O9 - Extra 'Tools' menuitem: English<->Arabic - {6E314959-13AD-D246-82D4-8B753F8C4ACA} - C:\Program Files\LingvoSoft\LingvoSoft Talking Dictionary 2007 (English-Arabic) for Windows\Plugins\IE.htm
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Unknown owner - C:\Program Files\Symantec AntiVirus\DefWatch.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: SAVRoam (SavRoam) - Unknown owner - C:\Program Files\Symantec AntiVirus\SavRoam.exe (file missing)
O23 - Service: Symantec AntiVirus - Unknown owner - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (file missing)
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

--
End of file - 6334 bytes
 
عطل أستعادة النظام حسب الشرح التالي ,,

كليك يمين على جهازك الكمبيوتر ,,

بعدها تدخل على ريمو

وتحط صح على المربع

allow

وتطبيق وموآفق​

ثم​

حمل اداة الكاسبر من الرابط التالي


يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


بعد التحميل ،، دبل كلك وسيتم استخراج ملف الاداة الى مجلد بسطح المكتب لحظات وتبدأ الاداة بالعمل

تابع الشرح لفحص الجهاز وتنظيفه وارفاق التقرير


zyzoom-7ce8879e89.png

zyzoom-cdd75c8aa3.png

zyzoom-89156f000e.png

zyzoom-6d533c4f2e.png

zyzoom-f20f3644d0.png

ثم قم بضغط التقرير ورفعه هنا>>>>
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

بـ أنتظار التقرير ,,​
 
التعديل الأخير بواسطة المشرف:
توقيع : Corporation
اخي جزاك الله كل خيرا
المشكلة انحلت
وشكرا لكم على الاطلال والمساعدة
تحياتي للجميع
 
الحالة
مغلق و غير مفتوح للمزيد من الردود.
عودة
أعلى