الحالة
مغلق و غير مفتوح للمزيد من الردود.

fahad-1984

زيزوومى متألق
إنضم
17 مايو 2008
المشاركات
353
مستوى التفاعل
29
النقاط
430
غير متصل
الصوره الأولى يخبرك إنه صآد حصآن طروآده يعني ملف ملغم

والصوره الثانيه يعطيك خيارات بالتطبيق اللي تفتحه

وانا عن نفسي دايم اختار ( تقييد )

وبنفس الوقت يذكرك إن البرنآمج مجآني ولآزم تشتري نسخه أصليه

أنصحك ركب مفتآح نسخه أصليه ويآكثرها بهالموقع بس اكتب بالبحث مفاتيح وبعدها طب وتخيّر
 
اهلاا بك


حمل هذا البرنامج

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


بعدها اغلق جميع البرامج وخصوصا الانترنت اكسبلورر والماسنجر
شغل البرنامج ==> واضغط على
Do a system scan and save log
لحظات .. ويظهر لك تقرير داخل المفكرة==> انسخه والصقه بردك القادم
 
التعديل الأخير بواسطة المشرف:
Logfile of Trend Micro HijackThis v2.0.2Scan saved at 01:34:39 ص, on 30/10/2009Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.5730.0013)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\WLTRYSVC.EXEC:\WINDOWS\System32\bcmwltry.exeC:\WINDOWS\system32\spoolsv.exec:\program files\idt\xpm09_6047v002\wdm\STacSV.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Internet Download Manager\IDMan.exeC:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exeC:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exeC:\Program Files\BandRich\BandLuxe HSDPA Utility R11\BRService.exeC:\WINDOWS\system32\ChgService.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\Program Files\CyberLink\Shared Files\RichVideo.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exeC:\Program Files\PC Connectivity Solution\ServiceLayer.exeC:\Program Files\Internet Download Manager\IEMonitor.exeC:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exeC:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exeC:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exeC:\Documents and Settings\DELL\My Documents\Downloads\Programs\Zyzoom_HijackThis.exeR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي

- HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي

- HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي

- HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي

- BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dllO2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dllO2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dllO2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dllO2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllO4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onbootO4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytrayO4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')O4 - Global Startup: Bluetooth.lnk = ?O4 - Global Startup: سرعة تشغيل Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htmO8 - Extra context menu item: إرسال إلى &جهاز Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htmO8 - Extra context menu item: إرسال إلى Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htmO8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htmO8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htmO8 - Extra context menu item: تحميل محتوى FLV بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetVL.htmO9 - Extra button: &لوحة مفاتيح ظاهرية - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dllO9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exeO9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dllO9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLLO9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htmO9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htmO9 - Extra button: فحص عناوين المواقع (URL) - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dllO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي

- DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) -

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي

- Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dllO23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exeO23 - Service: BandLuxe Service (BandLuxe_Service) - BandRich Inc. - C:\Program Files\BandRich\BandLuxe HSDPA Utility R11\BRService.exeO23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exeO23 - Service: Change Modem Device Service - Unknown owner - C:\WINDOWS\system32\ChgService.exeO23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeO23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exeO23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exeO23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exeO23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\program files\idt\xpm09_6047v002\wdm\STacSV.exeO23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE--End of file - 7942 bytes
 
اعد نسخ التقرير بشكل صحيح
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:02:40 ص, on 30/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\idt\xpm09_6047v002\wdm\STacSV.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe
C:\WINDOWS\system32\ChgService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Mobily Connect Card\Mobily Connect Card.exe
C:\Documents and Settings\DELL\My Documents\Downloads\Programs\Zyzoom_HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: سرعة تشغيل Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O8 - Extra context menu item: إرسال إلى &جهاز Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: إرسال إلى Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى FLV بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: &لوحة مفاتيح ظاهرية - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: فحص عناوين المواقع (URL) - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) -

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: BandLuxe Service (BandLuxe_Service) - BandRich Inc. - C:\Program Files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Change Modem Device Service - Unknown owner - C:\WINDOWS\system32\ChgService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\program files\idt\xpm09_6047v002\wdm\STacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 7905 bytes
 
؟؟؟؟؟؟؟؟؟؟؟
 
اعطني صورة الواجهة الرئسية للكاسبر لديك

اضن عندك اصدار تجريبي
 
توقيع : رياق
عطل برامج الحماية عن العمل
ثم
حمل الاداة التالية واحفظها على سطح المكتب

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
لا تقم بتشغيل اي برنامج ،، ومهما طالت عملية الفحص انتظر حتى تنتهي
انتظر حتى يظهر لك تقرير ،،انسخه والصقه بمشاركتك القادمة
 
ComboFix 09-10-30.01 - DELL 11/01/2009 0:30.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.2007.1618 [GMT 3:00]
Running from: c:\documents and settings\DELL\My Documents\Downloads\Programs\ComboFix.exe
AV: برنامج Kaspersky لأمان الإنترنت *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: برنامج Kaspersky لأمان الإنترنت *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\_000110_.tmp.dll
c:\windows\system32\_000111_.tmp.dll
c:\windows\system32\_000112_.tmp.dll
c:\windows\system32\kakle.dll
c:\windows\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-31 )))))))))))))))))))))))))))))))
.
2009-10-29 14:04 . 2009-10-29 14:04 -------- d-----w- c:\documents and settings\DELL\Local Settings\Application Data\Runscanner.net
2009-10-28 23:20 . 2008-09-26 15:01 621056 ----a-w- c:\windows\system32\drivers\mod7700.sys
2009-10-28 23:20 . 2008-09-26 15:01 113664 ----a-w- c:\windows\system32\drivers\ewusbnet.sys
2009-10-28 23:20 . 2008-09-26 15:01 101376 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2009-10-28 23:20 . 2008-09-26 15:00 24448 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2009-10-28 23:19 . 2009-10-28 23:22 -------- d-----w- c:\program files\Mobily Connect Card
2009-10-28 11:45 . 2008-03-21 10:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-10-27 18:11 . 2009-10-27 18:10 724992 ----a-w- c:\windows\iun6002.exe
2009-10-27 17:14 . 2009-10-27 17:14 -------- d-----w- c:\documents and settings\DELL\Local Settings\Application Data\Identities
2009-10-27 02:04 . 2009-10-27 02:04 -------- d-----w- c:\program files\CCleaner
2009-10-23 18:52 . 2009-10-23 18:52 -------- d-----w- c:\program files\Common Files\xing shared
2009-10-22 22:28 . 2009-10-22 22:28 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-22 15:59 . 2008-05-15 07:08 104192 ----a-w- c:\windows\system32\drivers\br3gmdm.sys
2009-10-22 04:00 . 2009-10-22 04:00 -------- d-----w- c:\documents and settings\DELL\Application Data\AdobeUM
2009-10-20 19:39 . 2009-10-20 19:39 -------- d-----w- c:\program files\BandRich
2009-10-20 19:03 . 2009-10-20 19:03 -------- d-----w- c:\documents and settings\DELL\Application Data\Media Player Classic
2009-10-20 18:34 . 2009-10-20 18:34 -------- d-----w- c:\program files\Microsoft
2009-10-19 14:08 . 2009-10-19 14:08 -------- d-----w- c:\program files\Common Files\PCSuite
2009-10-19 14:08 . 2009-10-19 14:08 -------- d-----w- c:\program files\Common Files\Nokia
2009-10-19 14:07 . 2008-08-26 07:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-10-19 14:07 . 2009-10-19 14:07 -------- d-----w- c:\program files\PC Connectivity Solution
2009-10-19 14:06 . 2009-02-09 05:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-10-19 14:06 . 2009-02-09 05:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-10-19 14:06 . 2009-02-09 05:37 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2009-10-19 14:06 . 2009-02-09 05:37 659968 ----a-w- c:\windows\system32\nmwcdcocls.dll
2009-10-19 14:06 . 2009-02-09 05:37 17664 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2009-10-19 14:06 . 2009-02-09 05:32 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2009-10-19 00:49 . 2009-10-19 00:49 -------- d-----w- c:\program files\FreeTime
2009-10-18 18:50 . 2009-10-18 18:50 -------- d-----w- c:\documents and settings\DELL\Application Data\COWON
2009-10-18 16:16 . 2009-10-18 16:16 -------- d-----w- c:\windows\Sun
2009-10-18 15:35 . 2009-10-22 15:49 -------- d-----w- c:\program files\Mobile Partner
2009-10-16 16:01 . 2008-12-15 13:48 103424 ----a-w- c:\windows\system32\drivers\cmnsusbser.sys
2009-10-16 16:01 . 2009-03-03 16:09 135168 ----a-w- c:\windows\system32\ChgService.exe
2009-10-16 16:01 . 2008-09-01 14:40 103424 ----a-w- c:\windows\system32\MyDIT_GenClassCoInst.dll
2009-10-16 10:26 . 2009-10-16 10:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-10-16 03:46 . 2009-10-16 03:47 -------- d-----w- c:\program files\Circe Developement
2009-10-16 03:46 . 2009-10-16 03:46 -------- d-----w- c:\program files\Messenger Plus! Live
2009-10-15 20:52 . 2009-10-15 21:01 -------- d-----w- c:\windows\SxsCaPendDel
2009-10-15 20:00 . 2009-10-15 20:00 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-10-15 19:53 . 2009-10-15 21:46 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-15 19:53 . 2009-10-15 21:46 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-15 19:51 . 2009-10-31 21:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-10-15 19:51 . 2009-10-15 19:51 -------- d-----w- c:\program files\Kaspersky Lab
2009-10-15 19:50 . 2009-10-15 19:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-10-15 00:17 . 2009-10-31 21:37 -------- d-----w- c:\documents and settings\DELL\Application Data\DMCache
2009-10-15 00:17 . 2009-10-23 14:24 -------- d-----w- c:\documents and settings\DELL\Application Data\IDM
2009-10-15 00:17 . 2009-10-19 01:35 -------- d-----w- c:\program files\Internet Download Manager
2009-10-14 19:50 . 2009-10-14 19:50 -------- d-sh--w- c:\documents and settings\DELL\UserData
2009-10-14 19:44 . 2004-08-03 20:08 25600 -c--a-w- c:\windows\system32\dllcache\usbser.sys
2009-10-14 19:44 . 2004-08-03 20:08 25600 ----a-w- c:\windows\system32\drivers\usbser.sys
2009-10-14 13:29 . 2009-10-14 13:29 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-10-14 13:29 . 2009-10-23 19:40 -------- d-----w- c:\documents and settings\DELL\Application Data\CyberLink
2009-10-14 13:18 . 2004-08-03 20:08 26496 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2009-10-14 11:01 . 2004-08-03 22:58 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2009-10-14 11:01 . 2004-08-03 23:10 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2009-10-14 11:01 . 2004-08-03 23:10 85376 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2009-10-14 11:01 . 2004-08-03 23:10 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2009-10-14 11:01 . 2004-08-03 23:10 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2009-10-14 11:01 . 2004-08-03 23:10 19328 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2009-10-14 11:01 . 2004-08-03 22:58 7552 ----a-w- c:\windows\system32\drivers\MSKSSRV.sys
2009-10-14 11:01 . 2004-08-03 22:58 5376 ----a-w- c:\windows\system32\drivers\MSPCLOCK.sys
2009-10-14 11:01 . 2004-08-03 23:10 15360 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2009-10-14 11:01 . 2004-08-03 22:58 4992 ----a-w- c:\windows\system32\drivers\MSPQM.sys
2009-10-14 11:01 . 2001-08-17 13:59 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2009-10-14 11:00 . 2004-08-04 00:55 21504 ----a-w- c:\windows\system32\hidserv.dll
2009-10-14 11:00 . 2004-08-04 00:55 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2009-10-14 11:00 . 2004-08-04 00:55 4096 ----a-w- c:\windows\system32\ksuser.dll
2009-10-14 11:00 . 2004-08-03 23:10 78464 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2009-10-14 11:00 . 2004-08-04 00:41 57216 ----a-w- c:\windows\system32\drivers\redbook.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-31 19:58 . 2001-09-19 12:00 58920 ----a-w- c:\windows\system32\perfc001.dat
2009-10-31 19:58 . 2001-09-19 12:00 328690 ----a-w- c:\windows\system32\perfh001.dat
2009-10-28 11:46 . 2009-10-28 11:46 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-10-28 11:46 . 2009-10-28 11:46 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-10-27 19:53 . 2009-10-14 08:13 94768 ----a-w- c:\documents and settings\DELL\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-23 19:42 . 2009-10-14 08:31 -------- d-----w- c:\program files\CyberLink
2009-10-23 18:52 . 2009-10-14 08:21 -------- d-----w- c:\program files\Common Files\Real
2009-10-23 18:51 . 2009-10-14 08:21 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-10-23 18:51 . 2009-10-14 08:21 -------- d-----w- c:\program files\Real
2009-10-20 18:39 . 2009-10-14 09:10 -------- d-----w- c:\program files\Windows Live
2009-10-19 14:29 . 2009-10-14 08:28 -------- d-----w- c:\documents and settings\DELL\Application Data\Nokia
2009-10-19 14:08 . 2009-10-14 08:27 -------- d-----w- c:\program files\Nokia
2009-10-19 14:07 . 2009-10-14 08:28 -------- d-----w- c:\program files\DIFX
2009-10-19 14:04 . 2009-10-14 08:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-10-16 07:40 . 2009-10-14 08:36 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-10-16 03:55 . 2009-10-14 09:52 -------- d-----w- c:\documents and settings\DELL\Application Data\Amen This Link
2009-10-14 19:45 . 2009-10-14 08:28 -------- d-----w- c:\documents and settings\DELL\Application Data\PC Suite
2009-10-14 19:44 . 2009-10-14 19:44 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2009-10-14 10:04 . 2009-10-14 08:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-14 09:56 . 2009-10-14 09:56 -------- d-----w- c:\program files\Microsoft Works
2009-10-14 09:54 . 2009-10-14 09:54 -------- d-----w- c:\program files\Microsoft.NET
2009-10-14 09:53 . 2009-10-14 09:53 -------- d-----w- c:\documents and settings\All Users\Application Data\wipe time date four
2009-10-14 09:52 . 2009-10-14 08:29 -------- d-----w- c:\program files\Java
2009-10-14 09:52 . 2009-10-14 09:52 -------- d-----w- c:\program files\Amen This Link
2009-10-14 09:10 . 2009-10-14 09:10 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-14 09:07 . 2009-10-14 09:07 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-14 09:04 . 2009-10-14 09:04 -------- d-----w- c:\program files\Broadcom
2009-10-14 09:03 . 2009-10-14 09:03 -------- d-----w- c:\program files\Synaptics
2009-10-14 08:57 . 2009-10-14 08:57 -------- d-----w- c:\program files\WIDCOMM
2009-10-14 08:56 . 2009-10-14 08:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Dell
2009-10-14 08:56 . 2009-10-14 08:47 -------- d-----w- c:\program files\Dell
2009-10-14 08:53 . 2009-10-14 08:53 -------- d-----w- c:\program files\Marvell
2009-10-14 08:53 . 2009-10-14 08:24 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-14 08:53 . 2009-10-14 08:53 -------- d-----w- c:\documents and settings\DELL\Application Data\TMP
2009-10-14 08:52 . 2009-10-14 08:52 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_Apfiltr_01005.Wdf
2009-10-14 08:52 . 2009-10-14 08:52 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-10-14 08:51 . 2009-10-14 08:51 -------- d-----w- c:\program files\DellTPad
2009-10-14 08:51 . 2009-10-14 08:51 -------- d-----w- c:\program files\Realtek
2009-10-14 08:51 . 2009-10-14 08:51 -------- d-----w- c:\documents and settings\DELL\Application Data\InstallShield
2009-10-14 08:50 . 2009-10-14 08:50 -------- d-----w- c:\program files\Intel
2009-10-14 08:48 . 2009-10-14 08:48 -------- d-----w- c:\program files\IDT
2009-10-14 08:41 . 2009-10-14 08:41 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-14 08:37 . 2009-10-14 08:37 -------- d-----w- c:\documents and settings\DELL\Application Data\ACD Systems
2009-10-14 08:36 . 2009-10-14 08:36 10368 ----a-w- c:\windows\system32\drivers\pfc.sys
2009-10-14 08:36 . 2009-10-14 08:36 -------- d-----w- c:\program files\ACD Systems
2009-10-14 08:34 . 2009-10-14 08:34 -------- d-----w- c:\program files\Common Files\Ahead
2009-10-14 08:34 . 2009-10-14 08:34 -------- d-----w- c:\program files\Nero
2009-10-14 08:34 . 2009-10-14 08:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-10-14 08:31 . 2009-10-14 08:31 -------- d-----w- c:\documents and settings\DELL\Application Data\Skype
2009-10-14 08:30 . 2009-10-14 08:30 -------- d-----w- c:\program files\Google
2009-10-14 08:30 . 2009-10-14 08:30 -------- d-----w- c:\program files\Common Files\Skype
2009-10-14 08:30 . 2009-10-14 08:30 -------- d-----r- c:\program files\Skype
2009-10-14 08:30 . 2009-10-14 08:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-10-14 08:30 . 2009-10-14 08:30 -------- d-----w- c:\program files\Paltalk Messenger
2009-10-14 08:30 . 2009-10-14 08:30 -------- d-----w- c:\documents and settings\DELL\Application Data\Paltalk
2009-10-14 08:28 . 2009-10-14 08:28 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-10-14 08:26 . 2009-10-14 08:25 -------- d-----w- c:\program files\JetAudio
2009-10-14 08:26 . 2009-10-14 08:25 -------- d-----w- c:\program files\Common Files\COWON
2009-10-14 08:24 . 2009-10-14 08:24 -------- d-----w- c:\program files\Video Convert Master
2009-10-14 08:24 . 2009-10-14 08:24 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-10-14 08:24 . 2009-10-14 08:24 -------- d-----w- c:\documents and settings\DELL\Application Data\Vso
2009-10-14 08:24 . 2009-10-14 08:24 81920 ----a-w- c:\documents and settings\DELL\Application Data\ezpinst.exe
2009-10-14 08:24 . 2009-10-14 08:24 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-10-14 08:24 . 2009-10-14 08:24 47360 ----a-w- c:\documents and settings\DELL\Application Data\pcouffin.sys
2009-10-14 08:22 . 2009-10-14 08:22 344064 ----a-w- c:\windows\system32\dkll.dll
2009-10-14 08:22 . 2009-10-14 08:22 196608 ----a-w- c:\windows\system32\maag.dll
2009-10-14 08:22 . 2009-10-14 08:22 1986560 ----a-w- c:\windows\system32\akll.dll
2009-10-14 08:22 . 2009-10-14 08:22 1212416 ----a-w- c:\windows\system32\ckll.dll
2009-10-14 08:22 . 2009-10-14 08:22 -------- d-----w- c:\program files\Ozone
2009-10-14 08:21 . 2009-10-14 08:21 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-10-14 08:20 . 2009-10-14 08:20 -------- d-----w- c:\program files\VideoLAN
2009-10-14 08:18 . 2009-10-14 08:18 -------- d-----w- c:\program files\Golden Al-Wafi Translator
2009-10-14 08:17 . 2009-10-14 08:17 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-10-14 08:17 . 2009-10-14 08:17 172032 ------w- c:\windows\Setup1.exe
2009-10-14 08:08 . 2009-10-14 08:08 -------- d-----w- c:\program files\microsoft frontpage
2009-10-14 08:04 . 2009-10-14 08:04 22144 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-09 10:43 . 2009-09-16 12:26 210352 ----a-w- c:\windows\system32\idmmbc.dll
.
------- Sigcheck -------
[-] 2008-01-09 . DABAD58A8BA625B241B90FB1A81154ED . 1547776 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-10-19 3118512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-10-23 198160]
"avp"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-07-03 303376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çں‍ê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-8-15 604776]
«©م، ¢¬نïé Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\PalTalk.lnk
backup=c:\windows\pss\PalTalk.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [15/12/2008 08:41 م 33808]
R2 BandLuxe_Service;BandLuxe Service;c:\program files\BandRich\BandLuxe HSDPA Utility R11\BRService.exe [03/10/2008 10:41 ص 87264]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [14/10/2009 11:48 ص 108160]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [14/10/2009 11:55 ص 110080]
R3 k57w2k;Broadcom NetLink (TM) Gigabit Ethernet;c:\windows\system32\drivers\k57xp32.sys [17/08/2009 07:28 م 176640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13/05/2009 05:46 م 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16/05/2009 08:59 م 19472]
S2 Change Modem Device Service;Change Modem Device Service;c:\windows\system32\ChgService.exe [16/10/2009 07:01 م 135168]
S3 br3gmdm;BandLuxe 3.5G HSDPA Adapter - USB;c:\windows\system32\drivers\br3gmdm.sys [22/10/2009 06:59 م 104192]
S3 cmnsusbser;Mobile Connector USB Device for Legacy Serial Communication LCT2053s;c:\windows\system32\drivers\cmnsusbser.sys [16/10/2009 07:01 م 103424]
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTS5121.sys --> c:\windows\system32\Drivers\RTS5121.sys [?]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
IE: إرسال إلى &جهاز Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: إرسال إلى Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: Microsoft XML Parser for Java -

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


.
- - - - ORPHANS REMOVED - - - -
AddRemove-HijackThis - c:\documents and settings\DELL\My Documents\Downloads\Programs\HijackThis.exe

**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


Rootkit scan 2009-11-01 00:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1380)
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(1860)
c:\windows\system32\btmmhook.dll
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\bcmwltry.exe
c:\program files\idt\xpm09_6047v002\wdm\STacSV.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\wdfmgr.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-10-31 0:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-31 21:40
Pre-Run: 61,143,609,344 bytes free
Post-Run: 61,034,594,304 bytes free
- - End Of File - - 29F7B8155D239288FA0C414E01F57ACD
 
تمااام
هل باقي اي مشاكل ؟
 
الله يوفقك اخي
 
الحالة
مغلق و غير مفتوح للمزيد من الردود.
عودة
أعلى