جزاكم الله خير
حذفت القيم المطلوبة ثم فتحت الاكسبلور وفتح معي ثم اقفلته وفتحته مرة اخرى فلم يفتح حاولت مرة اخرى دون جدوى
حملت الاداة ComboFix واتبعت الخطوات ثم اقفل الجهاز واشتغل مرة اخرى ثم فتحت المتصفح فكان عال العال ثم المسنجر فكان عال العال
وارجو ذكر ماهي المشكلة الواقعة قبل اصلاحها الموضحة في التقرير
وهذا التقرير اخي الكريم وبارك الله فيك
ComboFix 09-10-18.04 - احمد 10/19/2009 16:30.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.1012.625 [GMT 3:00]
Running from: c:\documents and settings\احمد\سطح المكتب\اصلاح اكسبلور ر ر\ComboFix.exe
AV: avast! antivirus 4.8.1356 [VPS 091018-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\احمد\Application Data\Desktopicon
c:\documents and settings\احمد\Application Data\Desktopicon\eBayShortcuts.exe
c:\windows\system32\Cache
c:\windows\system32\dl339xl.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_RKHIT
-------\Service_RkHit
((((((((((((((((((((((((( Files Created from 2009-09-19 to 2009-10-19 )))))))))))))))))))))))))))))))
.
2009-10-19 10:45 . 2009-10-19 10:45 -------- d-----w- c:\documents and settings\احمد\Application Data\GrabPro
2009-10-18 20:03 . 2004-08-03 20:10 38016 -c--a-w- c:\windows\system32\dllcache\bthmodem.sys
2009-10-18 20:03 . 2004-08-03 20:10 38016 ----a-w- c:\windows\system32\drivers\bthmodem.sys
2009-10-18 19:49 . 2004-08-03 19:29 12127 -c--a-w- c:\windows\system32\dllcache\wadv02nt.sys
2009-10-18 19:48 . 2001-09-18 11:05 24660 -c--a-w- c:\windows\system32\dllcache\spxupchk.dll
2009-10-18 19:47 . 2001-09-19 11:00 14848 -c--a-w- c:\windows\system32\dllcache\register.exe
2009-10-18 19:46 . 2004-08-03 21:48 132695 -c--a-w- c:\windows\system32\dllcache\netwlan5.sys
2009-10-18 19:45 . 2004-08-03 19:39 20864 -c--a-w- c:\windows\system32\dllcache\lwadihid.sys
2009-10-18 19:44 . 2001-09-18 11:04 372824 -c--a-w- c:\windows\system32\dllcache\iconf32.dll
2009-10-18 19:43 . 2004-08-03 21:56 226816 -c--a-w- c:\windows\system32\dllcache\fxscover.exe
2009-10-18 19:42 . 2004-08-03 21:56 42496 -c--a-w- c:\windows\system32\dllcache\davcdata.exe
2009-10-18 19:41 . 2001-09-18 10:31 13824 -c--a-w- c:\windows\system32\dllcache\bulltlp3.sys
2009-10-18 19:40 . 2001-09-19 11:00 29184 -c--a-w- c:\windows\system32\dllcache\asptxn.dll
2009-10-18 19:39 . 2004-08-03 21:56 30720 -c--a-w- c:\windows\system32\dllcache\iisrstas.exe
2009-10-18 19:26 . 2009-01-07 18:14 60273 ----a-w- c:\windows\system32\pthreadGC2.dll
2009-10-18 18:59 . 2009-10-18 18:59 -------- d-----w- C:\RegSupreme
2009-10-18 14:49 . 2009-10-18 15:42 -------- d-----w- C:\Eye Candy 4000
2009-10-18 14:39 . 2009-10-18 14:41 -------- d-----w- c:\program files\FramePhotoEditor
2009-10-17 19:12 . 2009-10-17 19:12 -------- d-----w- c:\program files\Kristanix
2009-10-17 14:49 . 2009-10-17 14:53 -------- d-----w- c:\program files\BurstCopy
2009-10-17 14:49 . 2009-10-17 14:49 -------- d-----w- c:\documents and settings\All Users\Application Data\BurstCopy Labs
2009-10-16 20:17 . 2009-10-16 20:17 1024 ----a-w- c:\windows\system32\i0k7h1t.dll
2009-10-16 19:51 . 2009-10-19 11:06 -------- d-----w- c:\documents and settings\احمد\Application Data\Orbit
2009-10-16 19:24 . 2009-10-16 19:24 -------- d-----w- c:\program files\OsamaALenezi
2009-10-16 19:24 . 2009-10-17 20:47 -------- d-----w- c:\program files\Snagit 9
2009-10-16 19:09 . 2009-10-16 19:09 -------- d-----w- c:\documents and settings\احمد\Local Settings\Application Data\TechSmith
2009-10-16 05:35 . 2009-10-18 11:34 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-10-15 16:32 . 2009-10-15 16:32 -------- d-----w- c:\program files\alfattak
2009-10-15 16:05 . 2009-10-15 16:05 -------- d-----w- c:\documents and settings\احمد\Application Data\CyberScrub
2009-10-15 16:05 . 2009-10-17 20:47 -------- d-----w- c:\documents and settings\احمد\Application Data\cleaner
2009-10-15 15:49 . 2009-10-15 15:49 -------- d-----w- c:\program files\Trend Micro
2009-10-15 12:37 . 2009-10-15 12:38 -------- d-----w- c:\program files\Adobe Photoshop CS4 ME
2009-10-15 11:29 . 2009-10-15 11:29 -------- d-----w- c:\windows\system32\wbem\Repository
2009-10-15 03:12 . 2009-10-15 03:12 -------- d-----w- c:\documents and settings\احمد\Local Settings\Application Data\Identities
2009-10-14 20:44 . 2008-01-25 20:06 -------- d-----w- c:\program files\Sakhr
2009-10-14 20:44 . 2008-01-25 20:06 -------- d-----w- c:\program files\Common Files\Sakhr
2009-10-14 19:55 . 2009-10-17 19:03 -------- d-----w- c:\documents and settings\احمد\Application Data\ImageBadger
2009-10-14 19:55 . 2009-10-17 19:14 -------- d-----w- c:\program files\ImageBadger
2009-10-14 19:28 . 2009-10-14 19:28 -------- d-----w- c:\program files\Design-Lib Creations
2009-10-14 11:44 . 2009-10-14 11:44 -------- d-----w- c:\documents and settings\احمد\Local Settings\Application Data\PC_Drivers_Headquarters
2009-10-14 11:44 . 2009-10-14 13:57 -------- d-----w- c:\program files\PC Drivers HeadQuarters
2009-10-14 11:12 . 2009-10-14 11:12 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-10-13 21:00 . 2009-10-13 21:00 -------- d-----w- C:\DRIVERS
2009-10-13 20:44 . 2009-10-13 20:44 -------- d-----w- c:\documents and settings\احمد\Application Data\DeviceDoctorSoftware
2009-10-13 18:04 . 2009-10-13 18:04 -------- d-----w- c:\program files\VS Revo Group
2009-10-13 17:06 . 2009-10-14 15:35 -------- d-----w- c:\program files\Clean Disk Security
2009-10-13 15:43 . 2009-10-13 15:43 413760 ----a-w- c:\windows\system32\mpg4c32.dll
2009-10-13 14:20 . 2009-10-13 14:20 -------- d-----w- c:\program files\Photo!
2009-10-13 13:50 . 2009-10-13 13:54 -------- d-----w- c:\program files\AskBarDis
2009-10-13 13:50 . 2009-10-13 13:50 -------- d-----w- c:\program files\Foxit Software
2009-10-13 13:50 . 2009-10-13 13:50 -------- d-----w- c:\documents and settings\احمد\Application Data\Foxit
2009-10-12 19:20 . 2009-10-12 19:20 -------- d-----w- c:\program files\portalgraphics
2009-10-12 18:37 . 2009-10-12 18:37 -------- d-----w- c:\documents and settings\احمد\Application Data\Ahead
2009-10-12 16:04 . 2009-10-12 16:04 -------- d-----w- c:\program files\Common Files\SourceTec
2009-10-12 16:04 . 2009-10-12 16:04 -------- d-----w- c:\program files\SourceTec
2009-10-12 11:53 . 2009-10-12 11:53 -------- d-----w- c:\windows\system32\RTCOM
2009-10-12 11:53 . 2004-08-03 21:55 4096 -c--a-w- c:\windows\system32\dllcache\ksuser.dll
2009-10-12 11:53 . 2004-08-03 21:55 4096 ----a-w- c:\windows\system32\ksuser.dll
2009-10-12 11:53 . 2004-08-03 20:08 60288 -c--a-w- c:\windows\system32\dllcache\drmk.sys
2009-10-12 11:53 . 2004-08-03 20:08 60288 ----a-w- c:\windows\system32\drivers\drmk.sys
2009-10-12 11:53 . 2009-09-14 17:29 352256 ----a-w- c:\windows\vncutil.exe
2009-10-12 11:53 . 2008-08-19 10:26 77824 ----a-w- c:\windows\SOUNDMAN.EXE
2009-10-12 11:36 . 2009-10-12 11:36 -------- d-----w- c:\program files\SystemRequirementsLab
2009-10-11 21:01 . 2009-10-18 14:14 -------- d-----w- C:\Downloads
2009-10-11 20:22 . 2009-10-11 20:22 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-11 20:20 . 2009-10-11 20:20 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2009-10-11 20:19 . 2009-10-12 02:55 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-10-11 20:19 . 2009-10-11 20:19 -------- d-----w- c:\program files\NOS
2009-10-11 19:58 . 2009-10-13 14:42 -------- d-----w- c:\documents and settings\احمد\Application Data\OxelonMC
2009-10-11 19:58 . 2009-10-13 14:42 -------- d-----w- c:\program files\OxelonMedia
2009-10-11 13:55 . 2009-10-11 13:55 -------- d-----w- c:\documents and settings\All Users\Application Data\page
2009-10-11 13:42 . 2009-10-11 13:42 -------- d-----w- c:\program files\SuperCopier
2009-10-11 11:25 . 2009-10-11 11:25 -------- d-----w- c:\program files\Common Files\EZB Systems
2009-10-11 11:25 . 2009-10-12 20:05 -------- d-----w- c:\program files\UltraISO
2009-10-10 20:46 . 2005-10-08 22:05 23600 ----a-w- c:\windows\system32\drivers\TVICHW32.SYS
2009-10-10 20:13 . 2009-10-14 14:00 -------- d-----w- c:\program files\Lavalys
2009-10-10 17:44 . 2003-06-18 14:31 17920 ----a-w- c:\windows\system32\mdimon.dll
2009-10-10 17:42 . 2009-10-10 17:43 -------- d-----w- c:\windows\SHELLNEW
2009-10-10 17:42 . 2009-10-10 17:42 -------- d-----w- c:\program files\Microsoft.NET
2009-10-10 17:41 . 2009-10-10 17:41 -------- d-----r- C:\MSOCache
2009-10-10 17:04 . 2009-10-10 17:04 -------- d-----w- c:\program files\MSXML 4.0
2009-10-10 17:04 . 2009-10-11 16:59 -------- d-----w- C:\TempEI4
2009-10-10 14:57 . 2008-10-16 11:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-10-10 14:57 . 2008-10-16 11:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-10-10 14:42 . 2009-10-10 14:42 -------- d-----w- c:\windows\Sun
2009-10-10 13:53 . 2009-10-10 13:52 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-10 13:52 . 2009-10-10 13:52 -------- d-----w- c:\program files\Java
2009-10-10 13:35 . 2009-10-10 13:35 -------- d-----w- c:\documents and settings\احمد\Local Settings\Application Data\Innovative Solutions
2009-10-10 13:29 . 2009-10-10 13:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-10-10 11:21 . 2009-10-10 11:21 -------- d-----w- c:\documents and settings\احمد\Local Settings\Application Data\ACD Systems
2009-10-10 11:21 . 2009-10-10 11:21 -------- d-----w- c:\documents and settings\احمد\Application Data\ACD Systems
2009-10-10 11:20 . 2009-10-10 11:20 -------- d-----w- c:\documents and settings\All Users\Application Data\ACD Systems
2009-10-10 11:20 . 2009-10-10 11:20 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-10-10 11:20 . 2009-10-10 11:20 -------- d-----w- c:\program files\ACD Systems
2009-10-10 11:14 . 2009-10-14 11:43 -------- d-----w- c:\documents and settings\احمد\Local Settings\Application Data\Downloaded Installations
2009-10-10 11:10 . 2009-10-17 19:13 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-10 03:40 . 2009-10-10 03:40 -------- d-----w- c:\program files\VMware
2009-10-10 03:35 . 2009-10-10 03:35 -------- d-----w- c:\documents and settings\احمد\Application Data\Lavasoft
2009-10-10 03:20 . 2009-10-10 03:20 -------- d-----w- c:\program files\Intel
2009-10-10 03:20 . 2008-12-04 06:31 53248 ----a-w- c:\windows\system32\CSVer.dll
2009-10-10 03:14 . 2009-10-10 03:14 -------- d-----w- c:\windows\system32\Lang
2009-10-10 03:14 . 2009-01-29 07:12 993816 ----a-w- c:\windows\system32\igxpun.exe
2009-10-10 03:14 . 2006-11-10 05:25 319456 ----a-w- c:\windows\system32\difxapi.dll
2009-10-10 03:14 . 2009-10-10 03:14 -------- d-----w- C:\Intel
2009-10-10 03:11 . 2009-10-10 03:11 -------- d-----w- c:\program files\A4Tech
2009-10-10 03:10 . 2005-09-29 07:12 49152 ----a-w- c:\windows\system32\Amhooker.dll
2009-10-10 03:10 . 2005-09-21 13:27 12800 ----a-r- c:\windows\system32\drivers\Amps2prt.sys
2009-10-10 03:10 . 2005-09-21 13:26 6656 ----a-w- c:\windows\system32\drivers\Amfilter.sys
2009-10-10 03:10 . 2005-09-21 13:25 12800 ----a-w- c:\windows\system32\drivers\Amusbprt.sys
2009-10-10 03:10 . 2004-08-25 14:09 7424 ----a-w- c:\windows\system32\drivers\Arfumftr.sys
2009-10-10 03:10 . 2009-10-10 03:10 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-10-10 03:09 . 2009-10-17 20:47 -------- d-----w- c:\windows\OPTIONS
2009-10-10 03:09 . 2008-06-27 06:39 332928 ----a-w- c:\windows\system32\drivers\rtl8187.sys
2009-10-10 03:09 . 2008-06-27 06:39 332928 ----a-w- c:\windows\system\rtl8187.sys
2009-10-10 03:09 . 2009-10-10 03:09 -------- d-----w- c:\windows\system32\REALTEK RTL8187 Wireless LAN Driver and Utility
2009-10-10 03:09 . 2007-10-09 10:13 38144 ----a-w- c:\windows\system32\drivers\EAPPkt.sys
2009-10-10 03:09 . 2009-10-14 20:47 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-10 03:09 . 2009-10-12 11:52 -------- d-----w- c:\program files\REALTEK
2009-10-10 03:09 . 2009-10-10 03:09 -------- d-----w- c:\documents and settings\احمد\Application Data\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-19 13:35 . 2009-10-09 19:26 -------- d-----w- c:\documents and settings\احمد\Application Data\DMCache
2009-10-19 12:05 . 2001-09-19 11:00 60894 ----a-w- c:\windows\system32\perfc001.dat
2009-10-19 12:05 . 2001-09-19 11:00 332786 ----a-w- c:\windows\system32\perfh001.dat
2009-10-19 11:10 . 2009-10-09 19:26 -------- d-----w- c:\documents and settings\احمد\Application Data\IDM
2009-10-18 19:37 . 2009-10-09 18:17 -------- d-----w- c:\documents and settings\احمد\Application Data\Thinstall
2009-10-18 19:26 . 2009-10-09 18:25 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-10-18 19:26 . 2009-10-18 19:26 -------- d-----w- c:\program files\Real Alternative
2009-10-18 19:26 . 2009-10-18 19:26 -------- d-----w- c:\program files\AviSynth 2.5
2009-10-18 19:26 . 2009-10-18 19:25 -------- d-----w- c:\program files\OZOMEDIA9
2009-10-17 19:49 . 2009-10-09 18:40 84312 ----a-w- c:\documents and settings\احمد\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-17 14:47 . 2009-10-09 19:21 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-16 19:23 . 2009-10-09 18:16 -------- d-----w- c:\program files\Unlocker
2009-10-16 13:11 . 2009-10-09 18:24 -------- d-----w- c:\program files\Google
2009-10-14 20:45 . 2009-10-12 11:52 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-12 20:05 . 2009-10-09 18:36 -------- d-----w- c:\program files\Internet Download Manager
2009-10-11 13:55 . 2009-10-09 20:28 -------- d-----w- c:\program files\Ashampoo
2009-10-09 20:29 . 2009-10-09 20:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-10-09 20:25 . 2009-10-09 20:25 -------- d-----w- c:\program files\CCleaner
2009-10-09 20:25 . 2009-10-09 20:25 -------- d-----w- c:\program files\Yahoo!
2009-10-09 19:37 . 2009-10-09 18:40 -------- d-----w- c:\program files\Windows Live
2009-10-09 19:34 . 2009-10-09 19:34 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-10-09 19:33 . 2009-10-09 19:33 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-10-09 19:33 . 2009-10-09 18:40 -------- d-----w- c:\program files\MSN Messenger
2009-10-09 19:32 . 2009-10-09 19:32 -------- d-----w- c:\program files\Microsoft
2009-10-09 19:32 . 2009-10-09 19:32 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-09 19:28 . 2009-10-09 19:28 0 ----a-w- c:\windows\nsreg.dat
2009-10-09 19:27 . 2009-10-09 19:27 -------- d-----w- c:\documents and settings\احمد\Application Data\Media Player Classic
2009-10-09 19:17 . 2009-10-09 19:17 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-09 19:03 . 2009-10-09 19:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-10-09 18:59 . 2009-10-09 18:59 -------- d-----w- c:\program files\Alwil Software
2009-10-09 18:42 . 2009-10-09 18:42 -------- d-----w- c:\program files\Driver-Soft
2009-10-09 18:40 . 2009-10-09 18:40 -------- d-----w- c:\program files\Messenger Plus! Live
2009-10-09 18:26 . 2009-10-09 18:26 -------- d-----w- c:\program files\Media Player Classic
2009-10-09 18:16 . 2009-10-09 18:16 -------- d-----w- c:\program files\iColorFolder
2009-10-09 18:00 . 2009-10-09 18:00 -------- d-----w- c:\program files\microsoft frontpage
2009-10-09 17:57 . 2009-10-09 17:57 22144 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-16 18:28 . 2009-10-12 11:52 5915136 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2009-09-15 10:59 . 2009-10-09 18:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe
2009-09-15 10:56 . 2009-10-09 18:59 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-09-15 10:56 . 2009-10-09 18:59 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-09-15 10:55 . 2009-10-09 19:18 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-09-15 10:55 . 2009-10-09 19:18 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-09-15 10:54 . 2009-10-09 18:59 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-09-15 10:54 . 2009-10-09 18:59 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-09-15 10:53 . 2009-10-09 18:59 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-09-15 10:53 . 2009-10-09 18:59 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-09-11 10:33 . 2009-10-12 11:52 18717696 ----a-w- c:\windows\RTHDCPL.EXE
2009-09-02 11:56 . 2009-10-12 11:52 41472 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2009-08-18 14:16 . 2009-10-12 11:52 831488 ----a-w- c:\windows\RtlExUpd.dll
2009-08-05 19:48 . 2009-10-09 19:37 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-08-04 11:31 . 2009-10-12 11:52 2170880 ----a-w- c:\windows\MicCal.exe
2009-07-26 13:44 . 2009-07-26 13:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-11-25 935856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-10 149280]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-09-11 18717696]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe"
"WheelMouse"=c:\progra~1\A4Tech\Mouse\Amoumain.exe
"IgfxTray"=c:\windows\system32\igfxtray.exe
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"Persistence"=c:\windows\system32\igfxpers.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [09/10/2009 10:18 م 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [09/10/2009 10:18 م 20560]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [10/10/2009 06:09 ص 38144]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [09/10/2009 10:37 م 54752]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [12/10/2009 02:52 م 1684736]
S3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\drivers\Amps2prt.sys [10/10/2009 06:10 ص 12800]
S3 fsssvc;خدمة أمان العائلة في Windows Live;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 10:48 م 704864]
S3 getPlusHelper;getPlus(R) Helper;c:\windows\System32\svchost.exe -k getPlusHelper [04/08/2004 12:56 ص 14336]
S3 maconfservice;Ma-Config Service; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://search.orbitdownloader.com
uInternet Settings,ProxyOverride = local
uInternet Settings,ProxyServer = 127.0.0.1:9666
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
FF - ProfilePath - c:\documents and settings\احمد\Application Data\Mozilla\Firefox\Profiles\ydxmg4zz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Orbit Search (Powered By Google)
FF - prefs.js: browser.startup.homepage - hxxp://search.orbitdownloader.com
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - component: c:\documents and settings\احمد\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-10-19 16:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3408)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\combofix\CF15977.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\snmp.exe
c:\windows\system32\rundll32.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 2009-10-19 16:39 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-19 13:39
Pre-Run: 61,428,011,008 bytes free
Post-Run: 61,336,203,264 bytes free
- - End Of File - - E8B2D805896426E8AB22681C90F655FA