السلام عليكم أخى العزيز هذا هو التقرير بعد تطبيق الأداه التى ذكرتها لى وبعد إعادة التشغيل
ComboFix 09-07-04.08 - Ahmed 07/05/2009 18:57.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1256.20.1033.18.2037.947 [GMT 3:00]
Running from: c:\users\Ahmed\Documents\Downloads\Programs\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\FunWebProducts
c:\program files\FunWebProducts\Installr\1.bin\F3EZSETP.DLL
c:\program files\Internet Explorer\msimg32.dll
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\2.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\2.bin\F3BROVLY.DLL
c:\program files\MyWebSearch\bar\2.bin\F3CJPEG.DLL
c:\program files\MyWebSearch\bar\2.bin\F3DTACTL.DLL
c:\program files\MyWebSearch\bar\2.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\2.bin\F3HTMLMU.DLL
c:\program files\MyWebSearch\bar\2.bin\F3HTTPCT.DLL
c:\program files\MyWebSearch\bar\2.bin\F3IMSTUB.DLL
c:\program files\MyWebSearch\bar\2.bin\F3POPSWT.DLL
c:\program files\MyWebSearch\bar\2.bin\F3PSSAVR.SCR
c:\program files\MyWebSearch\bar\2.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\2.bin\F3RESTUB.DLL
c:\program files\MyWebSearch\bar\2.bin\F3SCHMON.EXE
c:\program files\MyWebSearch\bar\2.bin\F3SCRCTR.DLL
c:\program files\MyWebSearch\bar\2.bin\F3SHLLVW.DLL
c:\program files\MyWebSearch\bar\2.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\2.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\2.bin\F3WPHOOK.DLL
c:\program files\MyWebSearch\bar\2.bin\M3FFXTBR.JAR
c:\program files\MyWebSearch\bar\2.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\2.bin\M3HTML.DLL
c:\program files\MyWebSearch\bar\2.bin\M3IDLE.DLL
c:\program files\MyWebSearch\bar\2.bin\M3IMPIPE.EXE
c:\program files\MyWebSearch\bar\2.bin\M3MSG.DLL
c:\program files\MyWebSearch\bar\2.bin\M3NTSTBR.JAR
c:\program files\MyWebSearch\bar\2.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\2.bin\M3OUTLCN.DLL
c:\program files\MyWebSearch\bar\2.bin\M3PLUGIN.DLL
c:\program files\MyWebSearch\bar\2.bin\M3SKIN.DLL
c:\program files\MyWebSearch\bar\2.bin\M3SKPLAY.EXE
c:\program files\MyWebSearch\bar\2.bin\M3SLSRCH.EXE
c:\program files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\2.bin\MWSOEPLG.DLL
c:\program files\MyWebSearch\bar\2.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\2.bin\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\icons\CM.ICO
c:\program files\MyWebSearch\bar\icons\MFC.ICO
c:\program files\MyWebSearch\bar\icons\PSS.ICO
c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files\MyWebSearch\bar\icons\WB.ICO
c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\windows\system32\f3PSSavr.scr
.
((((((((((((((((((((((((( Files Created from 2009-06-05 to 2009-07-05 )))))))))))))))))))))))))))))))
.
2009-07-05 15:54 . 2009-07-05 15:54 6736 ----a-w- c:\windows\system32\drivers\PROCEXP90.SYS
2009-07-05 15:07 . 2009-07-05 15:07 -------- d-----w- c:\program files\Trend Micro
2009-07-05 14:32 . 2009-05-13 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090705.003\NAVENG.SYS
2009-07-05 14:32 . 2009-05-13 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090705.003\NAVEX15.SYS
2009-07-05 14:32 . 2009-05-13 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090705.003\NAVENG32.DLL
2009-07-05 14:32 . 2009-05-13 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090705.003\NAVEX32A.DLL
2009-07-05 14:32 . 2009-05-13 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090705.003\ERASER.SYS
2009-07-05 14:32 . 2009-05-13 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090705.003\EECTRL.SYS
2009-07-05 14:32 . 2009-05-13 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090705.003\CCERASER.DLL
2009-07-05 14:32 . 2009-02-17 07:07 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090705.003\ECMSVR32.DLL
2009-07-04 19:51 . 2009-05-13 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090704.006\NAVENG.SYS
2009-07-04 19:51 . 2009-05-13 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090704.006\NAVEX15.SYS
2009-07-04 19:51 . 2009-05-13 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090704.006\EECTRL.SYS
2009-07-04 19:51 . 2009-05-13 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090704.006\CCERASER.DLL
2009-07-04 19:51 . 2009-05-13 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090704.006\NAVENG32.DLL
2009-07-04 19:51 . 2009-05-13 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090704.006\NAVEX32A.DLL
2009-07-04 19:51 . 2009-05-13 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090704.006\ERASER.SYS
2009-07-04 19:51 . 2009-02-17 07:07 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090704.006\ECMSVR32.DLL
2009-07-02 19:37 . 2009-03-06 17:25 439672 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090625.001\Scxpx86.dll
2009-07-02 19:37 . 2009-02-09 22:59 272432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090625.001\IDSvix86.sys
2009-07-02 19:37 . 2009-02-09 22:59 251768 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090625.001\SymIDSco.sys
2009-07-02 19:37 . 2009-02-09 22:59 685432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090625.001\IDSxpx86.dll
2009-07-02 19:37 . 2009-02-09 22:59 173432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090625.001\SymIDSI.dll
2009-07-02 19:37 . 2009-02-09 22:59 370224 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090625.001\IDSviA64.sys
2009-07-02 19:37 . 2009-02-05 21:55 157120 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090625.001\IDS9xx86.dll
2009-06-29 22:15 . 2009-06-29 22:16 -------- d-----w- c:\windows\system32\ca-ES
2009-06-29 22:15 . 2009-06-29 22:16 -------- d-----w- c:\windows\system32\eu-ES
2009-06-29 22:15 . 2009-06-29 22:16 -------- d-----w- c:\windows\system32\vi-VN
2009-06-29 19:57 . 2009-06-29 19:57 -------- d-----w- c:\windows\system32\EventProviders
2009-06-29 19:55 . 2009-04-11 06:28 17920 ----a-w- c:\windows\system32\wscisvif.dll
2009-06-29 16:37 . 2009-06-29 16:37 577536 ----a-w- c:\users\Ahmed\AppData\Roaming\RipIt4Me\updater\ri4mupdater.exe
2009-06-29 16:36 . 2009-06-29 16:37 -------- d-----w- c:\users\Ahmed\AppData\Roaming\RipIt4Me
2009-06-23 19:27 . 2009-06-23 19:27 390664 ----a-w- c:\users\Ahmed\AppData\Roaming\Real\RealPlayer\Update\realplayer11gold.exe
2009-06-23 19:27 . 2009-06-23 19:27 390664 ------w- c:\users\Ahmed\AppData\Roaming\Real\Update\temp\~Upg0\realplayer11gold.exe
2009-06-20 19:36 . 2009-03-06 17:25 439672 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090618.001\Scxpx86.dll
2009-06-20 19:36 . 2009-02-09 22:59 272432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090618.001\IDSvix86.sys
2009-06-20 19:36 . 2009-02-09 22:59 251768 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090618.001\SymIDSco.sys
2009-06-20 19:36 . 2009-02-09 22:59 685432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090618.001\IDSxpx86.dll
2009-06-20 19:36 . 2009-02-09 22:59 173432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090618.001\SymIDSI.dll
2009-06-20 19:36 . 2009-02-09 22:59 370224 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090618.001\IDSviA64.sys
2009-06-20 19:36 . 2009-02-05 21:55 157120 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090618.001\IDS9xx86.dll
2009-06-18 21:15 . 1992-10-27 21:00 135696 ----a-w- c:\windows\system\AAPLAY.DLL
2009-06-18 21:15 . 1992-10-27 21:00 12816 ----a-w- c:\windows\system\AAVGA.DLL
2009-06-18 21:15 . 1992-10-27 21:00 11280 ----a-w- c:\windows\system\MCIAAP.DRV
2009-06-18 11:16 . 2009-06-18 11:19 -------- d--h--w- C:\msdownld.tmp
2009-06-15 19:59 . 2009-05-09 05:50 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-15 19:59 . 2009-05-09 05:34 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-06-15 19:56 . 2009-04-23 12:14 623616 ----a-w- c:\windows\system32\localspl.dll
2009-06-15 19:56 . 2009-04-21 11:39 2034688 ----a-w- c:\windows\system32\win32k.sys
2009-06-15 19:56 . 2009-04-23 12:15 784896 ----a-w- c:\windows\system32\rpcrt4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-05 16:01 . 2009-03-04 12:38 -------- d-----w- c:\users\Ahmed\AppData\Roaming\DMCache
2009-07-05 15:44 . 2009-03-04 10:19 -------- d-----w- c:\users\Ahmed\AppData\Roaming\Skype
2009-07-05 14:16 . 2009-03-04 11:46 -------- d-----w- c:\users\Ahmed\AppData\Roaming\skypePM
2009-07-02 20:05 . 2009-03-10 18:08 -------- d-----w- c:\users\Ahmed\AppData\Roaming\uTorrent
2009-06-29 22:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-06-29 22:16 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-06-29 22:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-06-29 22:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-06-29 22:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-06-29 22:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-06-29 22:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-06-29 22:15 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-06-20 19:19 . 2009-03-03 20:47 680 ----a-w- c:\users\Ahmed\AppData\Local\d3d9caps.dat
2009-06-15 20:28 . 2009-03-06 22:08 -------- d-----w- c:\programdata\Microsoft Help
2009-06-15 19:53 . 2009-03-25 20:15 -------- d-----w- c:\program files\UltraISO
2009-05-22 19:54 . 2009-05-22 19:54 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-05-22 19:54 . 2009-05-22 19:54 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-05-22 19:54 . 2009-05-11 16:25 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-05-13 08:00 . 2009-05-13 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng.sys
2009-05-13 08:00 . 2009-05-13 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex15.sys
2009-05-13 08:00 . 2009-05-13 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\eeCtrl.sys
2009-05-13 08:00 . 2009-05-13 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\cceraser.dll
2009-05-13 08:00 . 2009-05-13 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng32.dll
2009-05-13 08:00 . 2009-05-13 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex32a.dll
2009-05-13 08:00 . 2009-05-13 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ERASER.sys
2009-05-11 17:43 . 2009-05-11 17:43 -------- d-----w- c:\program files\Microsoft Silverlight
2009-05-11 17:36 . 2009-05-11 17:36 -------- d-----w- c:\programdata\Microsoft Corporation
2009-05-11 16:26 . 2009-05-11 16:26 -------- d-----w- c:\users\Ahmed\AppData\Roaming\TuneUp Software
2009-05-11 16:25 . 2009-05-11 16:25 -------- d-----w- c:\programdata\TuneUp Software
2009-05-11 16:24 . 2009-05-11 16:24 -------- d-sh--w- c:\programdata\{55A29068-F2CE-456C-9148-C869879E2357}
2009-05-11 15:55 . 2009-05-01 22:05 -------- d-----r- c:\program files\TypingMaster
2009-05-10 12:29 . 2009-03-03 20:48 148432 ----a-w- c:\users\Ahmed\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-10 10:35 . 2009-03-10 16:32 8673792 ----a-w- c:\programdata\atscie.msi
2009-05-10 10:34 . 2009-05-10 10:34 -------- d-----w- c:\program files\Common Files\Pure Networks Shared
2009-04-27 12:21 . 2009-05-22 19:54 17152 ----a-w- c:\windows\system32\authuitu.dll
2009-04-27 12:21 . 2009-05-22 19:54 28928 ----a-w- c:\windows\system32\uxtuneup.dll
2009-04-11 06:33 . 2009-06-29 19:56 986600 ----a-w- c:\windows\system32\winload.exe
2009-04-11 06:33 . 2009-06-29 19:56 926184 ----a-w- c:\windows\system32\winresume.exe
2009-04-11 06:33 . 2009-06-29 19:56 292840 ----a-w- c:\windows\system32\drivers\volmgrx.sys
2009-04-11 06:33 . 2009-06-29 19:56 897000 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-04-11 06:33 . 2009-06-29 19:56 614376 ----a-w- c:\windows\system32\ci.dll
2009-04-11 06:28 . 2009-06-29 19:56 56320 ----a-w- c:\windows\system32\xmlfilter.dll
2009-04-11 06:27 . 2009-06-29 19:56 441344 ----a-w- c:\windows\system32\SearchIndexer.exe
2009-04-11 06:22 . 2009-06-29 19:55 7168 ----a-w- c:\windows\system32\f3ahvoas.dll
2009-04-11 06:21 . 2009-06-29 19:55 37376 ----a-w- c:\windows\system32\cdd.dll
2009-04-11 05:42 . 2009-06-29 19:55 93696 ----a-w- c:\windows\system32\drivers\bridge.sys
2009-04-11 05:03 . 2009-06-29 19:56 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-04-11 05:03 . 2009-06-29 19:56 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2009-04-11 04:57 . 2009-06-29 19:55 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-04-11 04:54 . 2009-06-29 19:55 2048 ----a-w- c:\windows\system32\mferror.dll
2009-04-11 04:51 . 2009-06-29 19:55 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2009-04-11 04:47 . 2009-06-29 19:55 273920 ----a-w- c:\windows\system32\drivers\afd.sys
2009-04-11 04:46 . 2009-06-29 19:55 69120 ----a-w- c:\windows\system32\drivers\rassstp.sys
2009-04-11 04:46 . 2009-06-29 19:55 121344 ----a-w- c:\windows\system32\drivers\ndiswan.sys
2009-04-11 04:46 . 2009-06-29 19:55 41472 ----a-w- c:\windows\system32\drivers\raspppoe.sys
2009-04-11 04:46 . 2009-06-29 19:55 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2009-04-11 04:46 . 2009-06-29 19:55 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2009-04-11 04:46 . 2009-06-29 19:55 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-04-11 04:45 . 2009-06-29 19:55 72192 ----a-w- c:\windows\system32\drivers\tdx.sys
2009-04-11 04:45 . 2009-06-29 19:55 72192 ----a-w- c:\windows\system32\drivers\pacer.sys
2009-04-11 04:45 . 2009-06-29 19:56 185856 ----a-w- c:\windows\system32\drivers\netbt.sys
2009-04-11 04:45 . 2009-06-29 19:56 401408 ----a-w- c:\windows\system32\drivers\http.sys
2009-04-11 04:45 . 2009-06-29 19:55 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2009-04-11 04:45 . 2009-06-29 19:55 66560 ----a-w- c:\windows\system32\drivers\smb.sys
2009-04-11 04:43 . 2009-06-29 19:55 148480 ----a-w- c:\windows\system32\drivers\nwifi.sys
2009-04-11 04:43 . 2009-06-29 19:56 196096 ----a-w- c:\windows\system32\drivers\usbhub.sys
2009-04-11 04:43 . 2009-06-29 19:56 236544 ----a-w- c:\windows\system32\drivers\HdAudio.sys
2009-04-11 04:42 . 2009-06-29 19:56 226304 ----a-w- c:\windows\system32\drivers\usbport.sys
2009-04-11 04:42 . 2009-06-29 19:55 25856 ----a-w- c:\windows\system32\drivers\USBCAMD2.sys
2009-04-11 04:42 . 2009-06-29 19:55 25856 ----a-w- c:\windows\system32\drivers\USBCAMD.sys
2009-04-11 04:42 . 2009-06-29 19:56 39936 ----a-w- c:\windows\system32\drivers\usbehci.sys
2009-04-11 04:42 . 2009-06-29 19:55 167936 ----a-w- c:\windows\system32\drivers\portcls.sys
2009-04-11 04:42 . 2009-06-29 19:55 52992 ----a-w- c:\windows\system32\drivers\stream.sys
2009-04-11 04:42 . 2009-06-29 19:56 561152 ----a-w- c:\windows\system32\drivers\hdaudbus.sys
2009-04-11 04:39 . 2009-06-29 19:55 16384 ----a-w- c:\windows\system32\iscsilog.dll
2009-04-11 04:39 . 2009-06-29 19:55 67072 ----a-w- c:\windows\system32\drivers\cdrom.sys
2009-04-11 04:39 . 2009-06-29 19:55 19456 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2009-04-11 04:38 . 2009-06-29 19:56 149504 ----a-w- c:\windows\system32\drivers\ks.sys
2009-04-11 04:27 . 2009-06-29 19:55 2560 ----a-w- c:\windows\system32\msimsg.dll
2009-04-11 04:23 . 2009-06-29 19:56 626176 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-04-11 04:23 . 2009-06-29 19:55 76288 ----a-w- c:\windows\system32\drivers\dxg.sys
2009-04-11 04:23 . 2009-06-29 19:55 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-04-11 04:22 . 2009-06-29 19:55 33280 ----a-w- c:\windows\system32\drivers\watchdog.sys
2009-04-11 04:15 . 2009-06-29 19:56 288768 ----a-w- c:\windows\system32\drivers\srv.sys
2009-04-11 04:15 . 2009-06-29 19:56 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-04-11 04:15 . 2009-06-29 19:56 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2009-04-11 04:14 . 2009-06-29 19:56 114688 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2009-04-11 04:14 . 2009-06-29 19:56 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-04-11 04:14 . 2009-06-29 19:56 225280 ----a-w- c:\windows\system32\drivers\rdbss.sys
2009-04-11 04:14 . 2009-06-29 19:56 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2009-04-11 04:14 . 2009-06-29 19:56 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-04-11 04:14 . 2009-06-29 19:55 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2009-04-11 04:14 . 2009-06-29 19:55 35328 ----a-w- c:\windows\system32\drivers\npfs.sys
2009-04-11 04:13 . 2009-06-29 19:55 226816 ----a-w- c:\windows\system32\drivers\udfs.sys
2009-04-11 04:13 . 2009-06-29 19:55 136704 ----a-w- c:\windows\system32\drivers\exfat.sys
2009-04-11 04:13 . 2009-06-29 19:55 142848 ----a-w- c:\windows\system32\drivers\fastfat.sys
2009-04-11 04:12 . 2009-06-29 19:56 617984 ----a-w- c:\windows\system32\adtschema.dll
2009-04-11 02:52 . 2009-06-29 19:56 684032 ----a-w- c:\windows\system32\drivers\spsys.sys
2009-04-11 01:59 . 2009-06-29 19:56 107612 ----a-w- c:\windows\system32\StructuredQuerySchema.bin
2009-03-14 20:09 . 2009-03-14 20:06 2930904 ----a-w- c:\program files\FLV PlayerFCSetup.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnhancedStorageShell]
@="{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}"
[HKEY_CLASSES_ROOT\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}]
2009-04-11 06:28 114176 ----a-w- c:\windows\System32\EhStorShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2009-03-03 171448]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-01-29 23975720]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-03-04 2745776]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-01 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-01 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-01 133656]
"ZSSnp211"="c:\windows\ZSSnp211.exe" [2007-04-06 57344]
"Domino"="c:\windows\Domino.exe" [2006-08-18 49152]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-11-02 167936]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2009-05-11 467240]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"BindDirectlyToPropertySetStorage"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\Ahmed\AppData\Local\Google\Update\GoogleUpdate.exe" /c
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):2f,8d,1a,38,08,f9,c9,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DB61B010-3961-4492-86E2-72687EBB9ECC}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{F906FDB4-A58F-4E35-AD60-23A6B4E31B13}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{03EAA512-065D-42E1-B18B-97950AF5669B}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{7F531139-E345-42A8-B36A-E02147135519}"= TCP:67

HCP Discovery Service
"{C7BE2954-0448-4B89-A3A4-6C05944ACC37}"= TCP:67

HCP Discovery Service
"{F8C11CB0-8D72-47BF-9913-171707DB966D}"= UDP:c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe

ure Networks Platform Service
"{34495383-3CFB-4C8E-AF94-4B084CB50C90}"= TCP:c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe

ure Networks Platform Service
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090625.001\IDSvix86.sys [02/07/2009 10:37 م 272432]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [18/02/2008 10:37 م 149352]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [22/05/2009 10:54 م 604416]
R3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [13/01/2008 05:32 ص 23888]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [16/06/2009 06:58 م 101936]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [19/02/2009 12:31 م 41008]
R3 vvftav;vvftav;c:\windows\System32\drivers\vvftav.sys [04/03/2009 01:23 ص 474368]
R3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\System32\drivers\ZS211.sys [04/03/2009 01:23 ص 1470592]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-05 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:37]
2009-06-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1184485708-3090429561-1360756931-1000.job
- c:\users\Ahmed\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-11 15:59]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
LSP: c:\windows\system32\idmmbc.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-05 19:03
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1184485708-3090429561-1360756931-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):d6,3d,16,dd,4a,f0,86,1d,3e,d4,d5,d8,48,7e,a1,48,38,51,f2,a6,a4,
9a,93,e1,6d,43,92,c8,1d,e6,d6,c0,02,cd,a4,7f,5c,1c,bc,9b,00,00,00,00,00,00,\
[HKEY_USERS\S-1-5-21-1184485708-3090429561-1360756931-1000_Classes\CLSID\{d5ac7452-b58f-478c-91b8-4ee7b7dea257}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000081
"Therad"=dword:0000000a
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,98,07,ff,fc,5d,
df,1c,2f,3b,8a,0a,32,11,89,01,b5,a8,c6,9e,a4,c3,19,fb,f8,bf,69,6a,be,e5,69,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(2868)
c:\windows\System32\NLSLexicons0009.dll
c:\windows\system32\pnidui.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\IoctlSvc.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\windows\System32\conime.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2009-07-05 19:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-05 16:05
Pre-Run: 72,685,297,664 bytes free
Post-Run: 72,652,464,128 bytes free
359 --- E O F --- 2009-06-29 21:59
وشكرا لك وجزاك الله عنا كل خير هل الجهاز نظيف الآن