قم بمتابعة الفيديو أدناه لمعرفة كيفية تثبيت موقعنا كتطبيق ويب على الشاشة الرئيسية.
ملاحظة: قد لا تكون هذه الميزة متاحة في بعض المتصفحات.
بعد أذن الغالي عبوودي
قم بعمل التالي
عطل برامج الحماية لديك
نزل هذه الاداة
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
عند تشغيلها بتظهر لك رسالة ,, اضغط على >> yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> yes
اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
انتظر حتى يظهر لك تقرير ،، وبذلك يكون الفحص انتهى الصق التقرير بردك الاول
ثانيا
حمل هذا البرنامج
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفييجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
شغل البرنامج ==> واضغط على
do a system scan and save log
لحظات .. ويظهر لك تقرير داخل المفكرة==> انسخه والصقه بردك الثاني
ملاحظة >>> الأدوات غير متشابهه قم بتحمل الأداتين
بعد اذن أعتز بك , وعبودي
حمل هذين الملفين
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
البرنامج يتوافق مع الانترنت اكسبلور فقط
الشرح
![]()
البرنامج الثاني
.يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
متوافق مع اي نسخة ويندوز
الشرح
![]()
ComboFix 09-06-16.01 - abderrahimamtijjal 06/17/2009 19:04.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.495.140 [GMT 3:00[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
Running from: c:\documents and settings\abderrahimamtijjal\My Documents\Downloads\kssetup.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}[/FONT][/FONT]
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}[/FONT][/FONT]
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]!![/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]((((((((((((((((((((((((( [/FONT]
[/FONT]Files Created from 2009-05-17 to 2009-06-17[FONT=Arial (Arabic)][FONT=Arial (Arabic)] )))))))))))))))))))))))))))))))[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-17 15:18 . 2009-06-17 15:18 -------- [/FONT]
[/FONT]d-----w-c:\program files\IE Accelerator
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-16 21:28 . 2009-06-16 21:28 -------- [/FONT][/FONT]
d-----w-c:\program files\Trend Micro
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-16 17:56 . 2009-06-16 18:35 -------- [/FONT][/FONT]
d-----w-c:\program files\Keyboard Sounder
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-16 16:56 . 2009-06-16 16:56 15256 ----[/FONT][/FONT]
a-w-c:\documents and settings\abderrahimamtijjal\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-16 16:49 . 2009-06-16 16:52 -------- [/FONT][/FONT]
d-----w-c:\program files\MSN Messenger
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-16 14:45 . 2009-06-16 14:48 0 ----[/FONT][/FONT]
a-w-C:\osy3.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-14 22:41 . 2009-06-15 16:13 -------- [/FONT][/FONT]
d-----w-c:\windows\system32\Adobe
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-13 20:17 . 2009-06-13 20:17 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\All Users\Application Data\TEMP
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-13 20:16 . 2009-06-14 00:08 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\Tor
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-10 22:04 . 2009-06-10 23:53 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Meebo
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-10 15:34 . 2009-04-30 21:13 12800 -[/FONT][/FONT]
c----w-c:\windows\system32\dllcache\xpshims.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-10 15:34 . 2009-04-30 21:13 1985024 -[/FONT][/FONT]
c----w-c:\windows\system32\dllcache\iertutil.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-10 15:34 . 2009-04-30 21:13 246272 -[/FONT][/FONT]
c----w-c:\windows\system32\dllcache\ieproxy.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-10 15:34 . 2009-04-30 21:13 11064832 -[/FONT][/FONT]
c----w-c:\windows\system32\dllcache\ieframe.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-08 03:03 . 2009-06-08 03:03 -------- [/FONT][/FONT]
d--h--w-c:\windows\PIF
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:24 . 2008-04-14 15:38 51712 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\i8042prt.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:24 . 2008-04-14 15:38 51712 ----[/FONT][/FONT]
a-w-c:\windows\system32\drivers\i8042prt.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:15 . 2008-04-14 15:59 116224 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\xrxwiadr.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:15 . 2001-09-18 11:05 23040 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\xrxwbtmp.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:15 . 2008-04-14 15:59 18944 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\xrxscnui.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:15 . 2001-09-18 11:06 27648 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\xrxftplt.exe
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:15 . 2001-09-18 11:06 4608 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\xrxflnch.exe
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:15 . 2001-09-18 11:06 99865 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\xlog.exe
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:15 . 2001-08-17 09:11 16970 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\xem336n5.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:13 . 2004-08-03 19:29 33599 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\watv04nt.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:12 . 2001-08-17 10:28 794399 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\usr1806v.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:11 . 2001-09-18 11:03 440576 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\tridkb.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:10 . 2001-08-17 10:50 103936 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\sx.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:09 . 2001-09-18 11:05 12288 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\EXCH_smtpctrs.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:08 . 2001-08-17 09:50 101760 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\sis300ip.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:07 . 2001-08-17 09:50 166720 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\s3m.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:06 . 2001-09-19 12:00 16384 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\quser.exe
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:05 . 2008-04-13 18:44 28032 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\perm3.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:04 . 2008-04-13 18:54 28672 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\nscirda.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:03 . 2001-08-17 11:02 35200 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\msgame.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:02 . 2001-08-17 09:12 20573 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\lne100.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:01 . 2001-09-18 11:04 90200 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\io8ports.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:00 . 2008-04-13 18:41 18560 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\i2omp.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:00 . 2008-04-13 18:41 8576 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\i2omgmt.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:00 . 2001-09-19 12:00 10129408 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\hwxkor.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:00 . 2001-09-19 12:00 10096640 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\hwxcht.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:00 . 2001-08-17 10:28 488383 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\hsf_v124.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:00 . 2001-08-17 10:28 50751 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\hsf_tone.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:00 . 2001-08-17 10:28 73279 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\hsf_spkp.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-05 23:46 . 2009-06-05 23:46 -------- [/FONT][/FONT]
d-----w-c:\windows\Downloaded Installations
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-04 09:10 . 2009-06-04 09:10 -------- [/FONT][/FONT]
d-----w-c:\program files\Ubi Soft
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-04 01:38 . 2009-06-07 23:38 -------- [/FONT][/FONT]
d-----w-c:\program files\XP Repair Pro 2007
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-04 01:37 . 2009-06-04 01:37 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\{AC84089A-4614-4D65-9C7F-C70274C17586[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-03 23:04 . 2009-06-03 23:04 -------- [/FONT][/FONT]
d-----w-C:\HDPhoto
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-03 18:49 . 2009-06-03 18:49 -------- [/FONT][/FONT]
d-----w-c:\program files\Common Files\xing shared
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-03 18:49 . 2009-06-03 18:49 499712 ----[/FONT][/FONT]
a-w-c:\windows\system32\msvcp71.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-03 18:49 . 2009-06-03 18:49 348160 ----[/FONT][/FONT]
a-w-c:\windows\system32\msvcr71.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:49 . 2001-09-18 11:04 68608 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\hpgt53tk.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:48 . 2004-08-03 19:31 34173 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\forehe.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:47 . 2001-08-17 09:10 69692 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\el575nd5.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:46 . 2001-08-17 09:11 20928 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\defpa.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:45 . 2001-09-18 10:33 272640 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\cinemclc.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:44 . 2001-09-18 10:31 13824 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\bulltlp3.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:43 . 2001-09-19 12:00 9216 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\authfilt.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-19 12:00 7168 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\wamregps.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-18 11:03 66048 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\s3legacy.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-19 12:00 19968 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\inetsloc.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-19 12:00 7680 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\inetmgr.exe
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-19 12:00 169984 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\iisui.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-19 12:00 5632 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\iisrstap.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-19 12:00 14336 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\iisreset.exe
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-19 12:00 6144 -[/FONT][/FONT]
c--a-w-c:\windows\system32\dllcache\ftpsapi2.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 21:15 . 2009-05-29 21:15 -------- [/FONT][/FONT]
d-----w-c:\program files\ProxyFinder
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 20:40 . 2009-05-29 20:40 -------- [/FONT][/FONT]
d-----w-c:\program files\MSXML 4.0
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 18:27 . 2009-05-29 18:27 -------- [/FONT][/FONT]
d-----w-c:\windows\system32\wbem\Repository
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 18:26 . 2009-05-29 18:41 -------- [/FONT][/FONT]
d-----w-c:\program files\TechTracker
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 18:26 . 2009-05-29 18:26 -------- [/FONT][/FONT]
d-----w-c:\program files\Spider Player
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 18:26 . 2009-05-29 18:26 -------- [/FONT][/FONT]
d-----w-c:\program files\Simplify Media
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 18:26 . 2009-05-29 18:26 -------- [/FONT][/FONT]
d-----w-c:\program files\Apple Software Update
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 02:00 . 2009-05-29 18:25 -------- [/FONT][/FONT]
d-----w-c:\program files\Error Repair Professional
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-24 17:10 . 2009-05-24 17:10 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\CyberScrub
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-24 17:08 . 2009-05-29 18:26 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\cleaner
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-24 01:00 . 2009-05-24 01:00 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\All Users\Application Data\Azureus
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-24 01:00 . 2009-05-29 18:26 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\Azureus
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-24 00:58 . 2009-05-29 18:26 -------- [/FONT][/FONT]
d-----w-c:\program files\Vuze(2[FONT=Arial (Arabic)][FONT=Arial (Arabic)])[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-21 18:00 . 2009-05-21 18:05 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\Leawo
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-21 18:00 . 2009-05-21 18:01 -------- [/FONT][/FONT]
d-----w-c:\program files\Leawo
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-21 17:46 . 2009-06-05 02:59 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Simplify Media
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-21 01:51 . 2009-05-21 01:52 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Google
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-21 01:50 . 2009-05-21 01:51 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Deployment
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:27 . 2009-03-19 13:32 23400 ----[/FONT][/FONT]
a-w-c:\windows\system32\drivers\GEARAspiWDM.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:27 . 2008-04-17 09:12 107368 ----[/FONT][/FONT]
a-w-c:\windows\system32\GEARAspi.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:27 . 2009-05-20 15:27 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:26 . 2009-05-20 15:26 -------- [/FONT][/FONT]
d-----w-c:\program files\Bonjour
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:24 . 2009-05-20 17:07 -------- [/FONT][/FONT]
d-----w-c:\program files\Common Files\Apple
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:11 . 2009-05-20 15:28 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\Apple Computer
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:03 . 2009-05-20 15:03 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Apple
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:03 . 2009-05-20 15:03 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\All Users\Application Data\Apple
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:02 . 2009-05-20 15:28 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Apple Computer
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-19 23:44 . 2009-06-07 23:35 -------- [/FONT][/FONT]
d-----w-c:\program files\DivX
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-19 18:47 . 2009-05-19 18:47 -------- [/FONT][/FONT]
d-----w-c:\windows\DownUp Utilities 2009
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-18 18:15 . 2009-05-18 18:15 -------- [/FONT][/FONT]
d-----w-c:\program files\NASA
[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT]
[FONT=Arial (Arabic)](((((((((((((((((((((((((((((((((((((((( [/FONT]
[/FONT]Find3M Report[FONT=Arial (Arabic)][FONT=Arial (Arabic)] ))))))))))))))))))))))))))))))))))))))))))))))))))))[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT]
[FONT=Arial (Arabic)]2009-06-17 16:09 . 2009-05-11 18:17 -------- [/FONT]
[/FONT]
d-----w-c:\program files\BitComet
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-17 14:53 . 2009-05-10 19:15 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\All Users\Application Data\Kaspersky Lab
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-17 03:48 . 2009-05-10 19:15 442400 --[/FONT][/FONT]
sha-w-c:\windows\system32\drivers\fidbox2.dat
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-17 03:48 . 2009-05-10 19:15 3640 --[/FONT][/FONT]
sha-w-c:\windows\system32\drivers\fidbox2.idx
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-17 03:48 . 2009-05-10 19:15 1652256 --[/FONT][/FONT]
sha-w-c:\windows\system32\drivers\fidbox.dat
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-17 03:48 . 2009-05-10 19:15 15036 --[/FONT][/FONT]
sha-w-c:\windows\system32\drivers\fidbox.idx
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-14 21:03 . 2009-05-12 16:12 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\skypePM
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-08 03:03 . 2009-05-11 15:34 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\All Users\Application Data\ma-config.com
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:36 . 2009-05-11 01:25 -------- [/FONT][/FONT]
d--h--w-c:\program files\InstallShield Installation Information
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-03 18:49 . 2009-05-11 00:27 -------- [/FONT][/FONT]
d-----w-c:\program files\Common Files\Real
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-03 18:49 . 2009-05-11 00:26 -------- [/FONT][/FONT]
d-----w-c:\program files\Real
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 18:26 . 2009-05-12 16:10 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\All Users\Application Data\Skype
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 18:26 . 2009-05-14 19:02 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\Spider Player
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 14:31 . 2009-05-10 19:16 94643 ----[/FONT][/FONT]
a-w-c:\windows\system32\drivers\klick.dat
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 14:31 . 2009-05-10 19:16 105395 ----[/FONT][/FONT]
a-w-c:\windows\system32\drivers\klin.dat
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-18 18:17 . 2009-05-11 01:25 27848 ----[/FONT][/FONT]
a-w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-17 17:49 . 2001-09-19 12:00 67302 ----[/FONT][/FONT]
a-w-c:\windows\system32\perfc001.dat
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-17 17:49 . 2001-09-19 12:00 366678 ----[/FONT][/FONT]
a-w-c:\windows\system32\perfh001.dat
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-17 17:48 . 2009-05-17 17:48 -------- [/FONT][/FONT]
d-----w-c:\program files\MSBuild
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-15 22:29 . 2009-05-15 22:29 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\vlc
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-15 22:28 . 2009-05-15 22:28 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\DMV Technologies
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-15 22:26 . 2009-05-15 22:26 -------- [/FONT][/FONT]
d-----w-c:\program files\DMV
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-15 18:09 . 2009-05-15 18:09 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\Media Player Classic
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-13 21:43 . 2009-05-13 21:43 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\Moyea
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-13 19:05 . 2009-05-13 19:05 0 ---[/FONT][/FONT]
ha-w-c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-13 19:05 . 2009-05-13 19:05 0 ---[/FONT][/FONT]
ha-w-c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-13 05:02 . 2004-08-03 21:55 915456 ----[/FONT][/FONT]
a-w-c:\windows\system32\wininet.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-12 16:12 . 2009-05-12 16:12 56 ---[/FONT][/FONT]
ha-w-c:\windows\system32\ezsidmv.dat
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 19:17 . 2009-05-11 19:17 -------- [/FONT][/FONT]
d-----w-c:\program files\Realtek AC97
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 19:16 . 2009-05-11 19:16 -------- [/FONT][/FONT]
d-----w-c:\program files\Common Files\InstallShield
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 18:51 . 2009-05-11 18:03 -------- [/FONT][/FONT]
d-----w-c:\program files\Intel
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 14:13 . 2009-05-11 14:13 -------- [/FONT][/FONT]
d-----w-c:\program files\Reference Assemblies
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 12:51 . 2009-05-11 12:51 -------- [/FONT][/FONT]
d-----w-c:\program files\Windows Live SkyDrive
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 12:43 . 2009-05-11 12:43 -------- [/FONT][/FONT]
d-----w-c:\program files\Common Files\Windows Live
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 11:46 . 2009-05-11 11:46 -------- [/FONT][/FONT]
d-----w-c:\program files\Windows Media Connect 2
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 01:23 . 2009-05-11 01:23 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 01:01 . 2009-05-11 01:01 23600 ----[/FONT][/FONT]
a-w-c:\windows\system32\drivers\TVICHW32.SYS
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 00:54 . 2009-05-11 00:54 -------- [/FONT][/FONT]
d-----w-c:\program files[FONT=Arial (Arabic)][FONT=Arial (Arabic)]\قاموس صخر الجديد[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 00:38 . 2009-05-11 00:38 -------- [/FONT][/FONT]
d-----w-c:\program files\K-Lite Codec Pack
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 00:03 . 2009-05-11 00:03 410984 ----[/FONT][/FONT]
a-w-c:\windows\system32\deploytk.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 00:03 . 2009-05-11 00:03 -------- [/FONT][/FONT]
d-----w-c:\program files\Java
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 23:53 . 2009-05-10 18:52 86327 ----[/FONT][/FONT]
a-w-c:\windows\pchealth\helpctr\OfflineCache\index.dat
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:43 . 2008-01-29 15:29 33808 ----[/FONT][/FONT]
a-w-c:\windows\system32\drivers\klbg.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:42 . 2009-05-10 19:42 44808 ----[/FONT][/FONT]
a-w-c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\fssync.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:42 . 2009-05-10 19:42 206088 ----[/FONT][/FONT]
a-w-c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\avp.exe
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:42 . 2009-05-10 19:42 33808 ----[/FONT][/FONT]
a-w-c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\klbg.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:42 . 2009-05-10 19:42 213520 ----[/FONT][/FONT]
a-w-c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\XP\klif.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:15 . 2009-05-10 19:15 -------- [/FONT][/FONT]
d-----w-c:\program files\Kaspersky Lab
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:14 . 2009-05-10 19:14 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:12 . 2009-05-10 19:12 -------- [/FONT][/FONT]
d-----w-c:\program files\BandRich
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:04 . 2009-05-10 19:04 -------- [/FONT][/FONT]
d-----w-c:\documents and settings\All Users\Application Data\Office Genuine Advantage
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 18:53 . 2009-05-10 18:53 -------- [/FONT][/FONT]
d-----w-c:\program files\microsoft frontpage
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 18:49 . 2009-05-10 18:49 22144 ----[/FONT][/FONT]
a-w-c:\windows\system32\emptyregdb.dat
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-07 15:32 . 2004-08-03 21:55 345600 ----[/FONT][/FONT]
a-w-c:\windows\system32\localspl.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-04-19 19:47 . 2004-08-03 21:46 1847040 ----[/FONT][/FONT]
a-w-c:\windows\system32\win32k.sys
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-04-15 14:52 . 2004-08-03 21:55 585216 ----[/FONT][/FONT]
a-w-c:\windows\system32\rpcrt4.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]((((((((((((((((((((((((((((((((((((( [/FONT]
[/FONT]Reg Loading Points[FONT=Arial (Arabic)][FONT=Arial (Arabic)] ))))))))))))))))))))))))))))))))))))))))))))))))))[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT]
[FONT=Arial (Arabic)].[/FONT]
[FONT=Arial (Arabic)]*[/FONT]
[/FONT]
Note* empty entries & legit default entries are not shown
REGEDIT4
[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT][/FONT]
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]
CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]
BitComet"="c:\program files\BitComet\BitComet.exe" [2009-04-28 2591544[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT][/FONT]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]
AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-05-10 206088[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]
TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-03 198160[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]
IE Accelerator"="c:\progra~1\IEACCE~1\IEAccelerator.exe" [2009-03-30 284672[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT][/FONT]
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]
CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT][/FONT]
HKLM\~\startupfolder\C:^Documents and Settings^abderrahimamtijjal[FONT=Arial (Arabic)][FONT=Arial (Arabic)]^قائمة ابدأ^البرامج^بدء التشغيل^[/FONT][/FONT]MaxTV.lnk[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
backup=c:\windows\pss\MaxTV.lnkStartup
[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT][/FONT]
HKEY_LOCAL_MACHINE\software\microsoft\security center[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]
AntiVirusOverride"=dword:00000001
[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT]
[/FONT]HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]
DisableMonitoring"=dword:00000001
[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT]
[/FONT]HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"%[/FONT][/FONT]
windir%\\system32\\sessmgr.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"%[/FONT][/FONT]
windir%\\Network Diagnostic\\xpnetdiag.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]
c:\\Program Files\\BitComet\\BitComet.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]
c:\\Program Files\\Bonjour\\mDNSResponder.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]
c:\\Program Files\\MSN Messenger\\msnmsgr.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT][/FONT]
HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"8980:[/FONT][/FONT]
TCP"= 8980:TCP:BitComet 8980 TCP
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"8980:[/FONT][/FONT]
UDP"= 8980:UDP:BitComet 8980 UDP
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"3389:[/FONT][/FONT]
TCP"= 3389:TCP:*isabled
xpsp2res.dll,-22009
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 06:29
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]م 33808][/FONT][/FONT]
R2 BandLuxe_Service;BandLuxe Service;c:\program files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe [03/06/2008 10:12
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]ص 87264][/FONT][/FONT]
R3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\drivers\br3gmdm.sys [10/05/2009 10:12
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]م 100096][/FONT][/FONT]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 07:02
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]م 26640][/FONT][/FONT]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 06:06
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]م 24592][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT][/FONT]
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]
c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT][/FONT]
Contents of the 'Scheduled Tasks' folder
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-16 [/FONT][/FONT]
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-1275210071-1801674531-1003.job
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]- [/FONT][/FONT]
c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-21 01:51[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-17 [/FONT][/FONT]
c:\windows\Tasks\User_Feed_Synchronization-{9FEFB7E6-C052-4592-A2A4-B1EF5DB8F39D}.job
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]- [/FONT][/FONT]
c:\windows\system32\msfeedssync.exe [2009-03-08 01:31[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT]
[FONT=Arial (Arabic)]- - - - [/FONT]
[/FONT]
ORPHANS REMOVED[FONT=Arial (Arabic)][FONT=Arial (Arabic)] - - - -[/FONT][/FONT]
HKCU-Run-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT]
[FONT=Arial (Arabic)].[/FONT]
[FONT=Arial (Arabic)]------- [/FONT]
[/FONT]
Supplementary Scan[FONT=Arial (Arabic)][FONT=Arial (Arabic)] -------[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT]
[/FONT]uStart Page = hxxp://www.google.com.sa
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]/[/FONT][/FONT]
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]**************************************************************************[/FONT]
[/FONT]catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
Rootkit scan 2009-06-17 19:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]... [/FONT][/FONT]
scanning hidden autostart entries
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]... [/FONT][/FONT]
scanning hidden files
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]... [/FONT][/FONT]
scan completed successfully
hidden files: 0
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]**************************************************************************[/FONT]
[FONT=Arial (Arabic)].[/FONT]
[FONT=Arial (Arabic)]--------------------- [/FONT]
[/FONT]
DLLs Loaded Under Running Processes[FONT=Arial (Arabic)][FONT=Arial (Arabic)] ---------------------[/FONT][/FONT]
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]- - - - - - - > '[/FONT][/FONT]
explorer.exe'(3092[FONT=Arial (Arabic)][FONT=Arial (Arabic)])[/FONT][/FONT]
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT][/FONT]
Completion time: 2009-06-17 19:14
ComboFix-quarantined-files.txt 2009-06-17 16:14
Pre-Run: 72,236,236,800 bytes free
Post-Run: 72,211,238,912 bytes free
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]245 --- [/FONT][/FONT]
E O F ---[FONT=Arial (Arabic)][FONT=Arial (Arabic)] 2009-06-10 15:42[/FONT][/FONT]
]