• بادئ الموضوع بادئ الموضوع amtejjal
  • تاريخ البدء تاريخ البدء
  • المشاهدات 885

amtejjal

زيزوومي جديد
إنضم
25 نوفمبر 2008
المشاركات
6
مستوى التفاعل
0
النقاط
0
غير متصل
مساعدة من فضلكم اخواني


عند تراكم الصفحات في شريط المهام المشكلة هي عند اغلاقها بتكون بطيئة او اذا فتحة الصفحة لما اغلقها بالمربع الاحمر بتنزل الصفحة ببطء شديد فارجو منكم الافادة والله يجعلها في ميزان حسناتكم
 

الله يحييك اخوي
حمل هذا البرنامج
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

شغل البرنامج ==> واضغط على
Do a system scan and save log
لحظات .. ويظهر لك تقرير داخل المفكرة==> انسخه والصقه بردك القادم
 
التعديل الأخير بواسطة المشرف:
توقيع : AbOdy
جزاك الله الف خير

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:29:12 ص, on 17/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\BandRich\BandLuxe HSDPA Utility R11\CManager.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\abderrahimamtijjal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\abderrahimamtijjal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: Shell=Explorer.exe
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O17 - HKLM\System\CCS\Services\Tcpip\..\{C0BE4430-AB6C-4491-9FE6-04BE8E6612B0}: NameServer = 84.23.102.172 84.23.101.84
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: BandLuxe Service (BandLuxe_Service) - BandRich Inc. - C:\Program Files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 7112 bytes
 
بعد أذن الغالي عبوودي

قم بعمل التالي

عطل برامج الحماية لديك

نزل هذه الاداة


يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes

اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
انتظر حتى يظهر لك تقرير ،، وبذلك يكون الفحص انتهى الصق التقرير بردك الاول

ثانيا


حمل هذا البرنامج


يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

شغل البرنامج ==> واضغط على
Do a system scan and save log
لحظات .. ويظهر لك تقرير داخل المفكرة==> انسخه والصقه بردك الثاني


ملاحظة >>> الأدوات غير متشابهه قم بتحمل الأداتين
 
التعديل الأخير بواسطة المشرف:
توقيع : أعتز بك
مشكور اخي العزيز وهذا التقرير:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:37:49 ص, on 17/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\BandRich\BandLuxe HSDPA Utility R11\CManager.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\abderrahimamtijjal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\abderrahimamtijjal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 148.233.239.24:3128
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O17 - HKLM\System\CCS\Services\Tcpip\..\{C0BE4430-AB6C-4491-9FE6-04BE8E6612B0}: NameServer = 84.23.102.172 84.23.101.84
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: BandLuxe Service (BandLuxe_Service) - BandRich Inc. - C:\Program Files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 6607 bytes
 
بعد أذن الغالي عبوودي

قم بعمل التالي

عطل برامج الحماية لديك

نزل هذه الاداة


يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

عند تشغيلها بتظهر لك رسالة ,, اضغط على >> yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> yes

اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
انتظر حتى يظهر لك تقرير ،، وبذلك يكون الفحص انتهى الصق التقرير بردك الاول

ثانيا


حمل هذا البرنامج


يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

شغل البرنامج ==> واضغط على
do a system scan and save log
لحظات .. ويظهر لك تقرير داخل المفكرة==> انسخه والصقه بردك الثاني



ملاحظة >>> الأدوات غير متشابهه قم بتحمل الأداتين

أخي أعمل بالترتيب الرقمي
 
توقيع : أعتز بك
بعد اذن أعتز بك , وعبودي
حمل هذين الملفين
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

البرنامج يتوافق مع الانترنت اكسبلور فقط
الشرح
i17763_1.png



البرنامج الثاني
.
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

متوافق مع اي نسخة ويندوز
الشرح
i17762_2.png
 
الى الاخ اعتز بك هذا هو التقرير الاول كما قلت لي وجزاك الله الف خير

ComboFix 09-06-16.01 - abderrahimamtijjal 06/17/2009 19:04.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.495.140 [GMT 3:00[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]

[/FONT]
[/FONT]
Running from: c:\documents and settings\abderrahimamtijjal\My Documents\Downloads\kssetup.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}

[/FONT]
[/FONT]
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}

[/FONT]
[/FONT]
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)] !!
.

(((((((((((((((((((((((((
[/FONT]
[/FONT]Files Created from 2009-05-17 to 2009-06-17[FONT=Arial (Arabic)][FONT=Arial (Arabic)] )))))))))))))))))))))))))))))))
.

2009-06-17 15:18 . 2009-06-17 15:18 --------
[/FONT]
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\IE Accelerator

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-16 21:28 . 2009-06-16 21:28 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Trend Micro

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-16 17:56 . 2009-06-16 18:35 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Keyboard Sounder

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-16 16:56 . 2009-06-16 16:56 15256 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-16 16:49 . 2009-06-16 16:52 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\MSN Messenger

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-16 14:45 . 2009-06-16 14:48 0 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]C:\osy3.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-14 22:41 . 2009-06-15 16:13 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\Adobe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-13 20:17 . 2009-06-13 20:17 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\All Users\Application Data\TEMP

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-13 20:16 . 2009-06-14 00:08 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Application Data\Tor

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-10 22:04 . 2009-06-10 23:53 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Meebo

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-10 15:34 . 2009-04-30 21:13 12800 -​
[/FONT]​
[/FONT]c----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\xpshims.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-10 15:34 . 2009-04-30 21:13 1985024 -​
[/FONT]​
[/FONT]c----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\iertutil.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-10 15:34 . 2009-04-30 21:13 246272 -​
[/FONT]​
[/FONT]c----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\ieproxy.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-10 15:34 . 2009-04-30 21:13 11064832 -​
[/FONT]​
[/FONT]c----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\ieframe.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-08 03:03 . 2009-06-08 03:03 --------​
[/FONT]​
[/FONT]d--h--w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\PIF

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:24 . 2008-04-14 15:38 51712 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\i8042prt.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:24 . 2008-04-14 15:38 51712 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\drivers\i8042prt.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:15 . 2008-04-14 15:59 116224 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\xrxwiadr.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:15 . 2001-09-18 11:05 23040 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\xrxwbtmp.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:15 . 2008-04-14 15:59 18944 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\xrxscnui.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:15 . 2001-09-18 11:06 27648 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\xrxftplt.exe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:15 . 2001-09-18 11:06 4608 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\xrxflnch.exe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:15 . 2001-09-18 11:06 99865 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\xlog.exe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:15 . 2001-08-17 09:11 16970 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\xem336n5.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:13 . 2004-08-03 19:29 33599 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\watv04nt.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:12 . 2001-08-17 10:28 794399 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\usr1806v.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:11 . 2001-09-18 11:03 440576 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\tridkb.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:10 . 2001-08-17 10:50 103936 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\sx.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:09 . 2001-09-18 11:05 12288 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\EXCH_smtpctrs.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:08 . 2001-08-17 09:50 101760 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\sis300ip.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:07 . 2001-08-17 09:50 166720 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\s3m.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:06 . 2001-09-19 12:00 16384 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\quser.exe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:05 . 2008-04-13 18:44 28032 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\perm3.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:04 . 2008-04-13 18:54 28672 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\nscirda.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:03 . 2001-08-17 11:02 35200 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\msgame.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:02 . 2001-08-17 09:12 20573 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\lne100.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:01 . 2001-09-18 11:04 90200 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\io8ports.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:00 . 2008-04-13 18:41 18560 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\i2omp.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:00 . 2008-04-13 18:41 8576 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\i2omgmt.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:00 . 2001-09-19 12:00 10129408 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\hwxkor.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:00 . 2001-09-19 12:00 10096640 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\hwxcht.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:00 . 2001-08-17 10:28 488383 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\hsf_v124.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:00 . 2001-08-17 10:28 50751 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\hsf_tone.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:00 . 2001-08-17 10:28 73279 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\hsf_spkp.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-05 23:46 . 2009-06-05 23:46 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\Downloaded Installations

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-04 09:10 . 2009-06-04 09:10 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Ubi Soft

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-04 01:38 . 2009-06-07 23:38 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\XP Repair Pro 2007

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-04 01:37 . 2009-06-04 01:37 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\{AC84089A-4614-4D65-9C7F-C70274C17586[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}
2009-06-03 23:04 . 2009-06-03 23:04 --------
[/FONT]
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]C:\HDPhoto

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-03 18:49 . 2009-06-03 18:49 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Common Files\xing shared

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-03 18:49 . 2009-06-03 18:49 499712 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\msvcp71.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-03 18:49 . 2009-06-03 18:49 348160 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\msvcr71.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:49 . 2001-09-18 11:04 68608 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\hpgt53tk.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:48 . 2004-08-03 19:31 34173 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\forehe.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:47 . 2001-08-17 09:10 69692 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\el575nd5.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:46 . 2001-08-17 09:11 20928 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\defpa.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:45 . 2001-09-18 10:33 272640 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\cinemclc.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:44 . 2001-09-18 10:31 13824 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\bulltlp3.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:43 . 2001-09-19 12:00 9216 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\authfilt.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:42 . 2001-09-19 12:00 7168 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\wamregps.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:42 . 2001-09-18 11:03 66048 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\s3legacy.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:42 . 2001-09-19 12:00 19968 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\inetsloc.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:42 . 2001-09-19 12:00 7680 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\inetmgr.exe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:42 . 2001-09-19 12:00 169984 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\iisui.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:42 . 2001-09-19 12:00 5632 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\iisrstap.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:42 . 2001-09-19 12:00 14336 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\iisreset.exe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-31 15:42 . 2001-09-19 12:00 6144 -​
[/FONT]​
[/FONT]c--a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\dllcache\ftpsapi2.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-29 21:15 . 2009-05-29 21:15 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\ProxyFinder

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-29 20:40 . 2009-05-29 20:40 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\MSXML 4.0

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-29 18:27 . 2009-05-29 18:27 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\wbem\Repository

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-29 18:26 . 2009-05-29 18:41 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\TechTracker

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-29 18:26 . 2009-05-29 18:26 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Spider Player

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-29 18:26 . 2009-05-29 18:26 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Simplify Media

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-29 18:26 . 2009-05-29 18:26 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Apple Software Update

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-29 02:00 . 2009-05-29 18:25 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Error Repair Professional

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-24 17:10 . 2009-05-24 17:10 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Application Data\CyberScrub

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-24 17:08 . 2009-05-29 18:26 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Application Data\cleaner

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-24 01:00 . 2009-05-24 01:00 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\All Users\Application Data\Azureus

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-24 01:00 . 2009-05-29 18:26 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Application Data\Azureus

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-24 00:58 . 2009-05-29 18:26 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Vuze(2[FONT=Arial (Arabic)][FONT=Arial (Arabic)])
2009-05-21 18:00 . 2009-05-21 18:05 --------
[/FONT]
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Application Data\Leawo

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-21 18:00 . 2009-05-21 18:01 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Leawo

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-21 17:46 . 2009-06-05 02:59 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Simplify Media

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-21 01:51 . 2009-05-21 01:52 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Google

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-21 01:50 . 2009-05-21 01:51 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Deployment

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-20 15:27 . 2009-03-19 13:32 23400 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\drivers\GEARAspiWDM.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-20 15:27 . 2008-04-17 09:12 107368 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\GEARAspi.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-20 15:27 . 2009-05-20 15:27 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}
2009-05-20 15:26 . 2009-05-20 15:26 --------
[/FONT]
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Bonjour

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-20 15:24 . 2009-05-20 17:07 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Common Files\Apple

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-20 15:11 . 2009-05-20 15:28 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Application Data\Apple Computer

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-20 15:03 . 2009-05-20 15:03 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Apple

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-20 15:03 . 2009-05-20 15:03 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\All Users\Application Data\Apple

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-20 15:02 . 2009-05-20 15:28 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Apple Computer

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-19 23:44 . 2009-06-07 23:35 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\DivX

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-19 18:47 . 2009-05-19 18:47 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\DownUp Utilities 2009

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-18 18:15 . 2009-05-18 18:15 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\NASA

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]

.
((((((((((((((((((((((((((((((((((((((((​
[/FONT]​
[/FONT]Find3M Report[FONT=Arial (Arabic)][FONT=Arial (Arabic)] ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-17 16:09 . 2009-05-11 18:17 --------
[/FONT]
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\BitComet

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-17 14:53 . 2009-05-10 19:15 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\All Users\Application Data\Kaspersky Lab

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-17 03:48 . 2009-05-10 19:15 442400 --​
[/FONT]​
[/FONT]sha-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\drivers\fidbox2.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-17 03:48 . 2009-05-10 19:15 3640 --​
[/FONT]​
[/FONT]sha-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\drivers\fidbox2.idx

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-17 03:48 . 2009-05-10 19:15 1652256 --​
[/FONT]​
[/FONT]sha-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\drivers\fidbox.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-17 03:48 . 2009-05-10 19:15 15036 --​
[/FONT]​
[/FONT]sha-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\drivers\fidbox.idx

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-14 21:03 . 2009-05-12 16:12 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Application Data\skypePM

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-08 03:03 . 2009-05-11 15:34 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\All Users\Application Data\ma-config.com

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-07 23:36 . 2009-05-11 01:25 --------​
[/FONT]​
[/FONT]d--h--w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\InstallShield Installation Information

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-03 18:49 . 2009-05-11 00:27 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Common Files\Real

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-06-03 18:49 . 2009-05-11 00:26 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Real

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-29 18:26 . 2009-05-12 16:10 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\All Users\Application Data\Skype

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-29 18:26 . 2009-05-14 19:02 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Application Data\Spider Player

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-20 14:31 . 2009-05-10 19:16 94643 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\drivers\klick.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-20 14:31 . 2009-05-10 19:16 105395 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\drivers\klin.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-18 18:17 . 2009-05-11 01:25 27848 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-17 17:49 . 2001-09-19 12:00 67302 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\perfc001.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-17 17:49 . 2001-09-19 12:00 366678 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\perfh001.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-17 17:48 . 2009-05-17 17:48 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\MSBuild

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-15 22:29 . 2009-05-15 22:29 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Application Data\vlc

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-15 22:28 . 2009-05-15 22:28 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Application Data\DMV Technologies

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-15 22:26 . 2009-05-15 22:26 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\DMV

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-15 18:09 . 2009-05-15 18:09 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Application Data\Media Player Classic

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-13 21:43 . 2009-05-13 21:43 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\abderrahimamtijjal\Application Data\Moyea

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-13 19:05 . 2009-05-13 19:05 0 ---​
[/FONT]​
[/FONT]ha-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-13 19:05 . 2009-05-13 19:05 0 ---​
[/FONT]​
[/FONT]ha-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-13 05:02 . 2004-08-03 21:55 915456 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\wininet.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-12 16:12 . 2009-05-12 16:12 56 ---​
[/FONT]​
[/FONT]ha-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\ezsidmv.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-11 19:17 . 2009-05-11 19:17 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Realtek AC97

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-11 19:16 . 2009-05-11 19:16 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Common Files\InstallShield

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-11 18:51 . 2009-05-11 18:03 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Intel

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-11 14:13 . 2009-05-11 14:13 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Reference Assemblies

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-11 12:51 . 2009-05-11 12:51 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Windows Live SkyDrive

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-11 12:43 . 2009-05-11 12:43 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Common Files\Windows Live

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-11 11:46 . 2009-05-11 11:46 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Windows Media Connect 2

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-11 01:23 . 2009-05-11 01:23 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-11 01:01 . 2009-05-11 01:01 23600 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\drivers\TVICHW32.SYS

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-11 00:54 . 2009-05-11 00:54 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files[FONT=Arial (Arabic)][FONT=Arial (Arabic)]\قاموس صخر الجديد
2009-05-11 00:38 . 2009-05-11 00:38 --------
[/FONT]
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\K-Lite Codec Pack

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-11 00:03 . 2009-05-11 00:03 410984 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\deploytk.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-11 00:03 . 2009-05-11 00:03 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Java

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-10 23:53 . 2009-05-10 18:52 86327 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\pchealth\helpctr\OfflineCache\index.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-10 19:43 . 2008-01-29 15:29 33808 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\drivers\klbg.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-10 19:42 . 2009-05-10 19:42 44808 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\fssync.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-10 19:42 . 2009-05-10 19:42 206088 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\avp.exe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-10 19:42 . 2009-05-10 19:42 33808 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\klbg.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-10 19:42 . 2009-05-10 19:42 213520 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\XP\klif.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-10 19:15 . 2009-05-10 19:15 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\Kaspersky Lab

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-10 19:14 . 2009-05-10 19:14 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-10 19:12 . 2009-05-10 19:12 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\BandRich

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-10 19:04 . 2009-05-10 19:04 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\documents and settings\All Users\Application Data\Office Genuine Advantage

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-10 18:53 . 2009-05-10 18:53 --------​
[/FONT]​
[/FONT]d-----w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\program files\microsoft frontpage

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-10 18:49 . 2009-05-10 18:49 22144 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\emptyregdb.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-05-07 15:32 . 2004-08-03 21:55 345600 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\localspl.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-04-19 19:47 . 2004-08-03 21:46 1847040 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\win32k.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
2009-04-15 14:52 . 2004-08-03 21:55 585216 ----​
[/FONT]​
[/FONT]a-w-[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT][/FONT]c:\windows\system32\rpcrt4.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
.

(((((((((((((((((((((((((((((((((((((​
[/FONT]​
[/FONT]Reg Loading Points[FONT=Arial (Arabic)][FONT=Arial (Arabic)] ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*
[/FONT]
[/FONT]Note* empty entries & legit default entries are not shown[FONT=Arial (Arabic)][FONT=Arial (Arabic)]

[/FONT]
[/FONT]
REGEDIT4​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]

[​
[/FONT]​
[/FONT]HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]
"
[/FONT]
[/FONT]CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]
"
[/FONT]
[/FONT]BitComet"="c:\program files\BitComet\BitComet.exe" [2009-04-28 2591544[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]

[
[/FONT]
[/FONT]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]
"
[/FONT]
[/FONT]AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-05-10 206088[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]
"
[/FONT]
[/FONT]TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-03 198160[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]
"
[/FONT]
[/FONT]IE Accelerator"="c:\progra~1\IEACCE~1\IEAccelerator.exe" [2009-03-30 284672[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]

[
[/FONT]
[/FONT]HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]
"
[/FONT]
[/FONT]CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]

[
[/FONT]
[/FONT]HKLM\~\startupfolder\C:^Documents and Settings^abderrahimamtijjal[FONT=Arial (Arabic)][FONT=Arial (Arabic)]^قائمة ابدأ^البرامج^بدء التشغيل^[/FONT][/FONT]MaxTV.lnk[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]

[/FONT]
[/FONT]
backup=c:\windows\pss\MaxTV.lnkStartup​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]

[​
[/FONT]​
[/FONT]HKEY_LOCAL_MACHINE\software\microsoft\security center[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]
"
[/FONT]
[/FONT]AntiVirusOverride"=dword:00000001

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]

[​
[/FONT]​
[/FONT]HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]
"
[/FONT]
[/FONT]DisableMonitoring"=dword:00000001

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]

[​
[/FONT]​
[/FONT]HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]
"%
[/FONT]
[/FONT]windir%\\system32\\sessmgr.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=
"%
[/FONT]
[/FONT]windir%\\Network Diagnostic\\xpnetdiag.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=
"
[/FONT]
[/FONT]c:\\Program Files\\BitComet\\BitComet.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=
"
[/FONT]
[/FONT]c:\\Program Files\\Bonjour\\mDNSResponder.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=
"
[/FONT]
[/FONT]c:\\Program Files\\MSN Messenger\\msnmsgr.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=

[
[/FONT]
[/FONT]HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]
"8980:
[/FONT]
[/FONT]TCP"= 8980:TCP:BitComet 8980 TCP

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
"8980:​
[/FONT]​
[/FONT]UDP"= 8980:UDP:BitComet 8980 UDP

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
"3389:​
[/FONT]​
[/FONT]TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 06:29​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)] م 33808]

[/FONT]
[/FONT]
R2 BandLuxe_Service;BandLuxe Service;c:\program files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe [03/06/2008 10:12​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)] ص 87264]

[/FONT]
[/FONT]
R3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\drivers\br3gmdm.sys [10/05/2009 10:12​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)] م 100096]

[/FONT]
[/FONT]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 07:02​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)] م 26640]

[/FONT]
[/FONT]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 06:06​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)] م 24592]

[
[/FONT]
[/FONT]HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}]
"
[/FONT]
[/FONT]c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
.​
[/FONT]
[/FONT]
Contents of the 'Scheduled Tasks' folder​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]

2009-06-16​
[/FONT]​
[/FONT]c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-1275210071-1801674531-1003.job

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
-​
[/FONT]​
[/FONT]c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-21 01:51[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]

2009-06-17
[/FONT]
[/FONT]c:\windows\Tasks\User_Feed_Synchronization-{9FEFB7E6-C052-4592-A2A4-B1EF5DB8F39D}.job

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
-​
[/FONT]​
[/FONT]c:\windows\system32\msfeedssync.exe [2009-03-08 01:31[FONT=Arial (Arabic)][FONT=Arial (Arabic)]]
.
- - - -
[/FONT]
[/FONT]ORPHANS REMOVED[FONT=Arial (Arabic)][FONT=Arial (Arabic)] - - - -

[/FONT]
[/FONT]
HKCU-Run-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]

 
.
-------​
[/FONT]​
[/FONT]Supplementary Scan[FONT=Arial (Arabic)][FONT=Arial (Arabic)] -------
.

[/FONT]
[/FONT]
uStart Page = hxxp://www.google.com.sa​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]/

[/FONT]
[/FONT]
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
.

**************************************************************************
[/FONT]
[/FONT]
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Rootkit scan 2009-06-17 19:11
Windows 5.1.2600 Service Pack 3 NTFS​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
[/FONT]
[/FONT]
scanning hidden processes​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)] ...

[/FONT]
[/FONT]
scanning hidden autostart entries​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)] ...

[/FONT]
[/FONT]
scanning hidden files​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)] ...

[/FONT]
[/FONT]
scan completed successfully
hidden files: 0​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]

**************************************************************************
.
---------------------​
[/FONT]​
[/FONT]DLLs Loaded Under Running Processes[FONT=Arial (Arabic)][FONT=Arial (Arabic)] ---------------------

- - - - - - - > '
[/FONT]
[/FONT]explorer.exe'(3092[FONT=Arial (Arabic)][FONT=Arial (Arabic)])

[/FONT]
[/FONT]
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
.​
[/FONT]
[/FONT]
Completion time: 2009-06-17 19:14
ComboFix-quarantined-files.txt 2009-06-17 16:14​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]
[/FONT]
[/FONT]
Pre-Run: 72,236,236,800 bytes free
Post-Run: 72,211,238,912 bytes free​
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]

245 ---​
[/FONT]​
[/FONT]E O F ---[FONT=Arial (Arabic)][FONT=Arial (Arabic)] 2009-06-10 15:42

[/FONT]
[/FONT]]
 
بعد اذن أعتز بك , وعبودي
حمل هذين الملفين
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

البرنامج يتوافق مع الانترنت اكسبلور فقط
الشرح
i17763_1.png



البرنامج الثاني
.
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

متوافق مع اي نسخة ويندوز
الشرح
i17762_2.png

لقد شغلت البرنامج الاول وكانت النتيجة جد ممتازة بالنسبة للاينترنيت واشكرك جزيل الشكر وبارك الله فيك اخي.
 
هنا التقرير الاول و الثاني {اهاكذا يكون الترتيب الرقمي}

ComboFix 09-06-16.01 - abderrahimamtijjal 06/17/2009 19:04.2 - NTFSx86​



Microsoft Windows XP Professional 5.1.2600.3.1256.966.1025.18.495.140 [GMT 3:00[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]
Running from: c:\documents and settings\abderrahimamtijjal\My Documents\Downloads\kssetup.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}[/FONT][/FONT]​

FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0
[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}[/FONT][/FONT]​


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED


[FONT=Arial (Arabic)][FONT=Arial (Arabic)]!![/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT][/FONT]



[FONT=Arial (Arabic)][FONT=Arial (Arabic)]((((((((((((((((((((((((( [/FONT]



[/FONT]​
Files Created from 2009-05-17 to 2009-06-17[FONT=Arial (Arabic)][FONT=Arial (Arabic)] )))))))))))))))))))))))))))))))[/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT][/FONT]



[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-17 15:18 . 2009-06-17 15:18 -------- [/FONT]



[/FONT]​
d-----w-c:\program files\IE Accelerator

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-16 21:28 . 2009-06-16 21:28 -------- [/FONT][/FONT]​


d-----w-c:\program files\Trend Micro

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-16 17:56 . 2009-06-16 18:35 -------- [/FONT][/FONT]​


d-----w-c:\program files\Keyboard Sounder

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-16 16:56 . 2009-06-16 16:56 15256 ----[/FONT][/FONT]​


a-w-c:\documents and settings\abderrahimamtijjal\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-16 16:49 . 2009-06-16 16:52 -------- [/FONT][/FONT]​


d-----w-c:\program files\MSN Messenger

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-16 14:45 . 2009-06-16 14:48 0 ----[/FONT][/FONT]​


a-w-C:\osy3.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-14 22:41 . 2009-06-15 16:13 -------- [/FONT][/FONT]​


d-----w-c:\windows\system32\Adobe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-13 20:17 . 2009-06-13 20:17 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\All Users\Application Data\TEMP

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-13 20:16 . 2009-06-14 00:08 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\Tor

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-10 22:04 . 2009-06-10 23:53 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Meebo

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-10 15:34 . 2009-04-30 21:13 12800 -[/FONT][/FONT]​


c----w-c:\windows\system32\dllcache\xpshims.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-10 15:34 . 2009-04-30 21:13 1985024 -[/FONT][/FONT]​


c----w-c:\windows\system32\dllcache\iertutil.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-10 15:34 . 2009-04-30 21:13 246272 -[/FONT][/FONT]​


c----w-c:\windows\system32\dllcache\ieproxy.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-10 15:34 . 2009-04-30 21:13 11064832 -[/FONT][/FONT]​


c----w-c:\windows\system32\dllcache\ieframe.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-08 03:03 . 2009-06-08 03:03 -------- [/FONT][/FONT]​


d--h--w-c:\windows\PIF

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:24 . 2008-04-14 15:38 51712 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\i8042prt.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:24 . 2008-04-14 15:38 51712 ----[/FONT][/FONT]​


a-w-c:\windows\system32\drivers\i8042prt.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:15 . 2008-04-14 15:59 116224 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\xrxwiadr.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:15 . 2001-09-18 11:05 23040 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\xrxwbtmp.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:15 . 2008-04-14 15:59 18944 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\xrxscnui.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:15 . 2001-09-18 11:06 27648 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\xrxftplt.exe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:15 . 2001-09-18 11:06 4608 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\xrxflnch.exe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:15 . 2001-09-18 11:06 99865 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\xlog.exe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:15 . 2001-08-17 09:11 16970 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\xem336n5.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:13 . 2004-08-03 19:29 33599 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\watv04nt.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:12 . 2001-08-17 10:28 794399 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\usr1806v.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:11 . 2001-09-18 11:03 440576 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\tridkb.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:10 . 2001-08-17 10:50 103936 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\sx.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:09 . 2001-09-18 11:05 12288 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\EXCH_smtpctrs.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:08 . 2001-08-17 09:50 101760 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\sis300ip.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:07 . 2001-08-17 09:50 166720 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\s3m.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:06 . 2001-09-19 12:00 16384 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\quser.exe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:05 . 2008-04-13 18:44 28032 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\perm3.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:04 . 2008-04-13 18:54 28672 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\nscirda.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:03 . 2001-08-17 11:02 35200 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\msgame.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:02 . 2001-08-17 09:12 20573 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\lne100.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:01 . 2001-09-18 11:04 90200 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\io8ports.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:00 . 2008-04-13 18:41 18560 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\i2omp.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:00 . 2008-04-13 18:41 8576 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\i2omgmt.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:00 . 2001-09-19 12:00 10129408 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\hwxkor.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:00 . 2001-09-19 12:00 10096640 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\hwxcht.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:00 . 2001-08-17 10:28 488383 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\hsf_v124.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:00 . 2001-08-17 10:28 50751 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\hsf_tone.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:00 . 2001-08-17 10:28 73279 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\hsf_spkp.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-05 23:46 . 2009-06-05 23:46 -------- [/FONT][/FONT]​


d-----w-c:\windows\Downloaded Installations

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-04 09:10 . 2009-06-04 09:10 -------- [/FONT][/FONT]​


d-----w-c:\program files\Ubi Soft

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-04 01:38 . 2009-06-07 23:38 -------- [/FONT][/FONT]​


d-----w-c:\program files\XP Repair Pro 2007

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-04 01:37 . 2009-06-04 01:37 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\{AC84089A-4614-4D65-9C7F-C70274C17586[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}[/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-03 23:04 . 2009-06-03 23:04 -------- [/FONT][/FONT]


d-----w-C:\HDPhoto

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-03 18:49 . 2009-06-03 18:49 -------- [/FONT][/FONT]​


d-----w-c:\program files\Common Files\xing shared

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-03 18:49 . 2009-06-03 18:49 499712 ----[/FONT][/FONT]​


a-w-c:\windows\system32\msvcp71.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-03 18:49 . 2009-06-03 18:49 348160 ----[/FONT][/FONT]​


a-w-c:\windows\system32\msvcr71.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:49 . 2001-09-18 11:04 68608 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\hpgt53tk.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:48 . 2004-08-03 19:31 34173 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\forehe.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:47 . 2001-08-17 09:10 69692 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\el575nd5.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:46 . 2001-08-17 09:11 20928 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\defpa.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:45 . 2001-09-18 10:33 272640 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\cinemclc.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:44 . 2001-09-18 10:31 13824 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\bulltlp3.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:43 . 2001-09-19 12:00 9216 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\authfilt.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-19 12:00 7168 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\wamregps.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-18 11:03 66048 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\s3legacy.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-19 12:00 19968 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\inetsloc.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-19 12:00 7680 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\inetmgr.exe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-19 12:00 169984 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\iisui.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-19 12:00 5632 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\iisrstap.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-19 12:00 14336 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\iisreset.exe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-31 15:42 . 2001-09-19 12:00 6144 -[/FONT][/FONT]​


c--a-w-c:\windows\system32\dllcache\ftpsapi2.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 21:15 . 2009-05-29 21:15 -------- [/FONT][/FONT]​


d-----w-c:\program files\ProxyFinder

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 20:40 . 2009-05-29 20:40 -------- [/FONT][/FONT]​


d-----w-c:\program files\MSXML 4.0

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 18:27 . 2009-05-29 18:27 -------- [/FONT][/FONT]​


d-----w-c:\windows\system32\wbem\Repository

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 18:26 . 2009-05-29 18:41 -------- [/FONT][/FONT]​


d-----w-c:\program files\TechTracker

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 18:26 . 2009-05-29 18:26 -------- [/FONT][/FONT]​


d-----w-c:\program files\Spider Player

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 18:26 . 2009-05-29 18:26 -------- [/FONT][/FONT]​


d-----w-c:\program files\Simplify Media

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 18:26 . 2009-05-29 18:26 -------- [/FONT][/FONT]​


d-----w-c:\program files\Apple Software Update

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 02:00 . 2009-05-29 18:25 -------- [/FONT][/FONT]​


d-----w-c:\program files\Error Repair Professional

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-24 17:10 . 2009-05-24 17:10 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\CyberScrub

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-24 17:08 . 2009-05-29 18:26 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\cleaner

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-24 01:00 . 2009-05-24 01:00 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\All Users\Application Data\Azureus

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-24 01:00 . 2009-05-29 18:26 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\Azureus

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-24 00:58 . 2009-05-29 18:26 -------- [/FONT][/FONT]​


d-----w-c:\program files\Vuze(2[FONT=Arial (Arabic)][FONT=Arial (Arabic)])[/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-21 18:00 . 2009-05-21 18:05 -------- [/FONT][/FONT]


d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\Leawo

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-21 18:00 . 2009-05-21 18:01 -------- [/FONT][/FONT]​


d-----w-c:\program files\Leawo

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-21 17:46 . 2009-06-05 02:59 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Simplify Media

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-21 01:51 . 2009-05-21 01:52 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Google

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-21 01:50 . 2009-05-21 01:51 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Deployment

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:27 . 2009-03-19 13:32 23400 ----[/FONT][/FONT]​


a-w-c:\windows\system32\drivers\GEARAspiWDM.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:27 . 2008-04-17 09:12 107368 ----[/FONT][/FONT]​


a-w-c:\windows\system32\GEARAspi.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:27 . 2009-05-20 15:27 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}[/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:26 . 2009-05-20 15:26 -------- [/FONT][/FONT]


d-----w-c:\program files\Bonjour

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:24 . 2009-05-20 17:07 -------- [/FONT][/FONT]​


d-----w-c:\program files\Common Files\Apple

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:11 . 2009-05-20 15:28 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\Apple Computer

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:03 . 2009-05-20 15:03 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Apple

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:03 . 2009-05-20 15:03 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\All Users\Application Data\Apple

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 15:02 . 2009-05-20 15:28 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Apple Computer

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-19 23:44 . 2009-06-07 23:35 -------- [/FONT][/FONT]​


d-----w-c:\program files\DivX

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-19 18:47 . 2009-05-19 18:47 -------- [/FONT][/FONT]​


d-----w-c:\windows\DownUp Utilities 2009

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-18 18:15 . 2009-05-18 18:15 -------- [/FONT][/FONT]​


d-----w-c:\program files\NASA


[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT]

[FONT=Arial (Arabic)](((((((((((((((((((((((((((((((((((((((( [/FONT]





[/FONT]Find3M Report[FONT=Arial (Arabic)][FONT=Arial (Arabic)] ))))))))))))))))))))))))))))))))))))))))))))))))))))[/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT]

[FONT=Arial (Arabic)]2009-06-17 16:09 . 2009-05-11 18:17 -------- [/FONT]

[/FONT]




d-----w-c:\program files\BitComet

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-17 14:53 . 2009-05-10 19:15 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\All Users\Application Data\Kaspersky Lab

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-17 03:48 . 2009-05-10 19:15 442400 --[/FONT][/FONT]​


sha-w-c:\windows\system32\drivers\fidbox2.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-17 03:48 . 2009-05-10 19:15 3640 --[/FONT][/FONT]​


sha-w-c:\windows\system32\drivers\fidbox2.idx

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-17 03:48 . 2009-05-10 19:15 1652256 --[/FONT][/FONT]​


sha-w-c:\windows\system32\drivers\fidbox.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-17 03:48 . 2009-05-10 19:15 15036 --[/FONT][/FONT]​


sha-w-c:\windows\system32\drivers\fidbox.idx

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-14 21:03 . 2009-05-12 16:12 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\skypePM

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-08 03:03 . 2009-05-11 15:34 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\All Users\Application Data\ma-config.com

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-07 23:36 . 2009-05-11 01:25 -------- [/FONT][/FONT]​


d--h--w-c:\program files\InstallShield Installation Information

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-03 18:49 . 2009-05-11 00:27 -------- [/FONT][/FONT]​


d-----w-c:\program files\Common Files\Real

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-03 18:49 . 2009-05-11 00:26 -------- [/FONT][/FONT]​


d-----w-c:\program files\Real

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 18:26 . 2009-05-12 16:10 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\All Users\Application Data\Skype

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-29 18:26 . 2009-05-14 19:02 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\Spider Player

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 14:31 . 2009-05-10 19:16 94643 ----[/FONT][/FONT]​


a-w-c:\windows\system32\drivers\klick.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-20 14:31 . 2009-05-10 19:16 105395 ----[/FONT][/FONT]​


a-w-c:\windows\system32\drivers\klin.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-18 18:17 . 2009-05-11 01:25 27848 ----[/FONT][/FONT]​


a-w-c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-17 17:49 . 2001-09-19 12:00 67302 ----[/FONT][/FONT]​


a-w-c:\windows\system32\perfc001.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-17 17:49 . 2001-09-19 12:00 366678 ----[/FONT][/FONT]​


a-w-c:\windows\system32\perfh001.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-17 17:48 . 2009-05-17 17:48 -------- [/FONT][/FONT]​


d-----w-c:\program files\MSBuild

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-15 22:29 . 2009-05-15 22:29 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\vlc

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-15 22:28 . 2009-05-15 22:28 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\DMV Technologies

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-15 22:26 . 2009-05-15 22:26 -------- [/FONT][/FONT]​


d-----w-c:\program files\DMV

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-15 18:09 . 2009-05-15 18:09 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\Media Player Classic

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-13 21:43 . 2009-05-13 21:43 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\abderrahimamtijjal\Application Data\Moyea

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-13 19:05 . 2009-05-13 19:05 0 ---[/FONT][/FONT]​


ha-w-c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-13 19:05 . 2009-05-13 19:05 0 ---[/FONT][/FONT]​


ha-w-c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-13 05:02 . 2004-08-03 21:55 915456 ----[/FONT][/FONT]​


a-w-c:\windows\system32\wininet.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-12 16:12 . 2009-05-12 16:12 56 ---[/FONT][/FONT]​


ha-w-c:\windows\system32\ezsidmv.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 19:17 . 2009-05-11 19:17 -------- [/FONT][/FONT]​


d-----w-c:\program files\Realtek AC97

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 19:16 . 2009-05-11 19:16 -------- [/FONT][/FONT]​


d-----w-c:\program files\Common Files\InstallShield

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 18:51 . 2009-05-11 18:03 -------- [/FONT][/FONT]​


d-----w-c:\program files\Intel

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 14:13 . 2009-05-11 14:13 -------- [/FONT][/FONT]​


d-----w-c:\program files\Reference Assemblies

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 12:51 . 2009-05-11 12:51 -------- [/FONT][/FONT]​


d-----w-c:\program files\Windows Live SkyDrive

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 12:43 . 2009-05-11 12:43 -------- [/FONT][/FONT]​


d-----w-c:\program files\Common Files\Windows Live

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 11:46 . 2009-05-11 11:46 -------- [/FONT][/FONT]​


d-----w-c:\program files\Windows Media Connect 2

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 01:23 . 2009-05-11 01:23 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 01:01 . 2009-05-11 01:01 23600 ----[/FONT][/FONT]​


a-w-c:\windows\system32\drivers\TVICHW32.SYS

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 00:54 . 2009-05-11 00:54 -------- [/FONT][/FONT]​


d-----w-c:\program files[FONT=Arial (Arabic)][FONT=Arial (Arabic)]\قاموس صخر الجديد[/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 00:38 . 2009-05-11 00:38 -------- [/FONT][/FONT]


d-----w-c:\program files\K-Lite Codec Pack

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 00:03 . 2009-05-11 00:03 410984 ----[/FONT][/FONT]​


a-w-c:\windows\system32\deploytk.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-11 00:03 . 2009-05-11 00:03 -------- [/FONT][/FONT]​


d-----w-c:\program files\Java

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 23:53 . 2009-05-10 18:52 86327 ----[/FONT][/FONT]​


a-w-c:\windows\pchealth\helpctr\OfflineCache\index.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:43 . 2008-01-29 15:29 33808 ----[/FONT][/FONT]​


a-w-c:\windows\system32\drivers\klbg.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:42 . 2009-05-10 19:42 44808 ----[/FONT][/FONT]​


a-w-c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\fssync.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:42 . 2009-05-10 19:42 206088 ----[/FONT][/FONT]​


a-w-c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\avp.exe

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:42 . 2009-05-10 19:42 33808 ----[/FONT][/FONT]​


a-w-c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\klbg.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:42 . 2009-05-10 19:42 213520 ----[/FONT][/FONT]​


a-w-c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\XP\klif.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:15 . 2009-05-10 19:15 -------- [/FONT][/FONT]​


d-----w-c:\program files\Kaspersky Lab

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:14 . 2009-05-10 19:14 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:12 . 2009-05-10 19:12 -------- [/FONT][/FONT]​


d-----w-c:\program files\BandRich

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 19:04 . 2009-05-10 19:04 -------- [/FONT][/FONT]​


d-----w-c:\documents and settings\All Users\Application Data\Office Genuine Advantage

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 18:53 . 2009-05-10 18:53 -------- [/FONT][/FONT]​


d-----w-c:\program files\microsoft frontpage

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-10 18:49 . 2009-05-10 18:49 22144 ----[/FONT][/FONT]​


a-w-c:\windows\system32\emptyregdb.dat

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-05-07 15:32 . 2004-08-03 21:55 345600 ----[/FONT][/FONT]​


a-w-c:\windows\system32\localspl.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-04-19 19:47 . 2004-08-03 21:46 1847040 ----[/FONT][/FONT]​


a-w-c:\windows\system32\win32k.sys

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-04-15 14:52 . 2004-08-03 21:55 585216 ----[/FONT][/FONT]​


a-w-c:\windows\system32\rpcrt4.dll

[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT][/FONT]​



[FONT=Arial (Arabic)][FONT=Arial (Arabic)]((((((((((((((((((((((((((((((((((((( [/FONT]



[/FONT]​
Reg Loading Points[FONT=Arial (Arabic)][FONT=Arial (Arabic)] ))))))))))))))))))))))))))))))))))))))))))))))))))[/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT]

[FONT=Arial (Arabic)].[/FONT]
[FONT=Arial (Arabic)]*[/FONT]

[/FONT]




Note* empty entries & legit default entries are not shown

REGEDIT4



[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT][/FONT]


HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]


CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]


BitComet"="c:\program files\BitComet\BitComet.exe" [2009-04-28 2591544[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​


[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT][/FONT]


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]


AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-05-10 206088[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]


TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-03 198160[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]


IE Accelerator"="c:\progra~1\IEACCE~1\IEAccelerator.exe" [2009-03-30 284672[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​


[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT][/FONT]


HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]


CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​


[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT][/FONT]


HKLM\~\startupfolder\C:^Documents and Settings^abderrahimamtijjal[FONT=Arial (Arabic)][FONT=Arial (Arabic)]^قائمة ابدأ^البرامج^بدء التشغيل^[/FONT][/FONT]MaxTV.lnk[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​

backup=c:\windows\pss\MaxTV.lnkStartup



[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT][/FONT]


HKEY_LOCAL_MACHINE\software\microsoft\security center[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]


AntiVirusOverride"=dword:00000001


[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT]


[/FONT]HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]


DisableMonitoring"=dword:00000001


[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT]


[/FONT]HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"%[/FONT][/FONT]


windir%\\system32\\sessmgr.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=[/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"%[/FONT][/FONT]


windir%\\Network Diagnostic\\xpnetdiag.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=[/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]


c:\\Program Files\\BitComet\\BitComet.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=[/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]


c:\\Program Files\\Bonjour\\mDNSResponder.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=[/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]


c:\\Program Files\\MSN Messenger\\msnmsgr.exe[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"=[/FONT][/FONT]​


[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT][/FONT]


HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"8980:[/FONT][/FONT]


TCP"= 8980:TCP:BitComet 8980 TCP

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"8980:[/FONT][/FONT]​


UDP"= 8980:UDP:BitComet 8980 UDP

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"3389:[/FONT][/FONT]​


TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009


R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 06:29


[FONT=Arial (Arabic)][FONT=Arial (Arabic)]م 33808][/FONT][/FONT]​

R2 BandLuxe_Service;BandLuxe Service;c:\program files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe [03/06/2008 10:12


[FONT=Arial (Arabic)][FONT=Arial (Arabic)]ص 87264][/FONT][/FONT]​

R3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\drivers\br3gmdm.sys [10/05/2009 10:12


[FONT=Arial (Arabic)][FONT=Arial (Arabic)]م 100096][/FONT][/FONT]​

R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 07:02


[FONT=Arial (Arabic)][FONT=Arial (Arabic)]م 26640][/FONT][/FONT]​

R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 06:06


[FONT=Arial (Arabic)][FONT=Arial (Arabic)]م 24592][/FONT][/FONT]​


[FONT=Arial (Arabic)][FONT=Arial (Arabic)][[/FONT][/FONT]


HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF[FONT=Arial (Arabic)][FONT=Arial (Arabic)]}][/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]"[/FONT][/FONT]


c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT][/FONT]

Contents of the 'Scheduled Tasks' folder





[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-16 [/FONT][/FONT]


c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-1275210071-1801674531-1003.job

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]- [/FONT][/FONT]​


c:\documents and settings\abderrahimamtijjal\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-21 01:51[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​


[FONT=Arial (Arabic)][FONT=Arial (Arabic)]2009-06-17 [/FONT][/FONT]


c:\windows\Tasks\User_Feed_Synchronization-{9FEFB7E6-C052-4592-A2A4-B1EF5DB8F39D}.job

[FONT=Arial (Arabic)][FONT=Arial (Arabic)]- [/FONT][/FONT]​


c:\windows\system32\msfeedssync.exe [2009-03-08 01:31[FONT=Arial (Arabic)][FONT=Arial (Arabic)]][/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT]

[FONT=Arial (Arabic)]- - - - [/FONT]

[/FONT]




ORPHANS REMOVED[FONT=Arial (Arabic)][FONT=Arial (Arabic)] - - - -[/FONT][/FONT]​


HKCU-Run-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe



[FONT=Arial (Arabic)][FONT=Arial (Arabic)] [/FONT]

[FONT=Arial (Arabic)].[/FONT]
[FONT=Arial (Arabic)]------- [/FONT]

[/FONT]




Supplementary Scan[FONT=Arial (Arabic)][FONT=Arial (Arabic)] -------[/FONT][/FONT]​

[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT]


[/FONT]
uStart Page = hxxp://www.google.com.sa




[FONT=Arial (Arabic)][FONT=Arial (Arabic)]/[/FONT][/FONT]​

IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm

IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT][/FONT]​





[FONT=Arial (Arabic)][FONT=Arial (Arabic)]**************************************************************************[/FONT]




[/FONT]​
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


Rootkit scan 2009-06-17 19:11
Windows 5.1.2600 Service Pack 3 NTFS





scanning hidden processes


[FONT=Arial (Arabic)][FONT=Arial (Arabic)]... [/FONT][/FONT]​


scanning hidden autostart entries


[FONT=Arial (Arabic)][FONT=Arial (Arabic)]... [/FONT][/FONT]​


scanning hidden files


[FONT=Arial (Arabic)][FONT=Arial (Arabic)]... [/FONT][/FONT]​


scan completed successfully

hidden files: 0





[FONT=Arial (Arabic)][FONT=Arial (Arabic)]**************************************************************************[/FONT]

[FONT=Arial (Arabic)].[/FONT]
[FONT=Arial (Arabic)]--------------------- [/FONT]

[/FONT]




DLLs Loaded Under Running Processes[FONT=Arial (Arabic)][FONT=Arial (Arabic)] ---------------------[/FONT][/FONT]​


[FONT=Arial (Arabic)][FONT=Arial (Arabic)]- - - - - - - > '[/FONT][/FONT]


explorer.exe'(3092[FONT=Arial (Arabic)][FONT=Arial (Arabic)])[/FONT][/FONT]​

c:\windows\system32\WININET.dll

c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
[FONT=Arial (Arabic)][FONT=Arial (Arabic)].[/FONT][/FONT]
Completion time: 2009-06-17 19:14
ComboFix-quarantined-files.txt 2009-06-17 16:14





Pre-Run: 72,236,236,800 bytes free

Post-Run: 72,211,238,912 bytes free





[FONT=Arial (Arabic)][FONT=Arial (Arabic)]245 --- [/FONT][/FONT]


E O F ---[FONT=Arial (Arabic)][FONT=Arial (Arabic)] 2009-06-10 15:42[/FONT][/FONT]​

]



Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 07:31:16 م, on 17/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BandRich\BandLuxe HSDPA Utility R11\CManager.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\IEACCE~1\IEAccelerator.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IE Accelerator] C:\PROGRA~1\IEACCE~1\IEAccelerator.exe /Auto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O17 - HKLM\System\CCS\Services\Tcpip\..\{C0BE4430-AB6C-4491-9FE6-04BE8E6612B0}: NameServer = 84.23.102.172 84.23.101.84
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: BandLuxe Service (BandLuxe_Service) - BandRich Inc. - C:\Program Files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
--
End of file - 6469 bytes​
 
طيب يا الغلا

قم بعمل الشرح الموجود

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


وبعدها هات تقرير الأداة الموجود بالشرح + تقرير هايجاك جديد
 
توقيع : أعتز بك
عودة
أعلى