السلام عليكم
فيما يلى التقرير ولكن حدثت مشكله كبيره بعد الانتهاء من تنفيذ التعليمات فوجئت باننى لا استطيع ان افتح الانترنت اكسبلور وعندما اقوم بفتح اى صفحه على الانترنت تظهر اكثر من رساله ويتوقف فتح اى مواقع افيدونى ماذا افعل هل معنى ذلك ان الويندوز حدث فيه مشاكل ومطلب انزال نسخه ويندوز جديد ام لا مع العلم بانى قمت بتسطيب اكسبلور رقم 8 مره اخر ولكن عند فتح اى صفحه انترنت تظهر رساله ولا يتم فتح صفحات الانترنت نهائيا وعلى فكره انا اكتب لكم هذه الرساله من كبير اخر من مكان اخر
اولا الرسائل التى تظهر عند المحاوله لفتح الانترنت
وفيما يلى نص الرسالتين التى تظهر عند المحاوله فتح الانترنت
serch serrings v1.2.3
please wait while windows configures search settings v1.2.3
cancel
الثانى
search settings installer
search settings will now close all instances of internet explore before confinuing. click continue to proceed.
continue cancel
وعندما احاول بالضغط على continue لايظهر اى شىء ولا يتم فتح الانترنت
واخيرا التقرير الذى ظهر بعد تنفيذ الخطوات المطلوبه من حضراتكم وتم تنفيذها ولكن للاسف حدثت المشاكل السابق ذكرها
ComboFix 10-02-02.02 - Administrator 02/03/2010 1:13.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1256.20.1033.18.2047.1498 [GMT 2:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100202-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Files Created from 2010-01-02 to 2010-02-02 )))))))))))))))))))))))))))))))
.
2010-02-01 18:29 . 2008-04-14 03:42 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2010-02-01 18:29 . 2001-08-17 20:36 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2010-02-01 18:28 . 2008-04-14 03:42 18944 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll
2010-02-01 18:28 . 2001-08-17 20:37 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe
2010-02-01 18:28 . 2001-08-17 20:37 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe
2010-02-01 18:28 . 2001-08-17 20:37 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe
2010-02-01 18:28 . 2001-08-17 10:11 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys
2010-02-01 18:28 . 2008-04-13 20:04 19455 -c--a-w- c:\windows\system32\dllcache\wvchntxx.sys
2010-02-01 18:28 . 2008-04-13 22:16 19200 -c--a-w- c:\windows\system32\dllcache\wstcodec.sys
2010-02-01 18:28 . 2008-04-13 20:04 12063 -c--a-w- c:\windows\system32\dllcache\wsiintxx.sys
2010-02-01 18:28 . 2008-04-14 03:42 8192 -c--a-w- c:\windows\system32\dllcache\wshirda.dll
2010-02-01 18:28 . 2008-04-13 22:06 8832 -c--a-w- c:\windows\system32\dllcache\wmiacpi.sys
2010-02-01 18:28 . 2008-04-13 20:05 154624 -c--a-w- c:\windows\system32\dllcache\wlluc48.sys
2010-02-01 18:26 . 2001-08-17 11:28 64605 -c--a-w- c:\windows\system32\dllcache\vvoice.sys
2010-02-01 18:25 . 2008-04-13 22:16 121984 -c--a-w- c:\windows\system32\dllcache\usbvideo.sys
2010-02-01 18:24 . 2001-08-17 10:51 166784 -c--a-w- c:\windows\system32\dllcache\tridxpm.sys
2010-02-01 18:23 . 2001-08-17 12:56 81408 -c--a-w- c:\windows\system32\dllcache\tgiul50.dll
2010-02-01 18:22 . 2001-08-17 20:36 53760 -c--a-w- c:\windows\system32\dllcache\sw_wheel.dll
2010-02-01 18:22 . 2001-08-17 20:36 41472 -c--a-w- c:\windows\system32\dllcache\sw_effct.dll
2010-02-01 18:22 . 2008-04-13 22:16 15232 -c--a-w- c:\windows\system32\dllcache\streamip.sys
2010-02-01 18:22 . 2001-08-17 20:36 155648 -c--a-w- c:\windows\system32\dllcache\stlnprop.dll
2010-02-01 18:22 . 2001-08-17 20:36 53248 -c--a-w- c:\windows\system32\dllcache\stlncoin.dll
2010-02-01 18:22 . 2001-08-17 10:18 285760 -c--a-w- c:\windows\system32\dllcache\stlnata.sys
2010-02-01 18:02 . 2001-08-17 11:51 16896 -c--a-w- c:\windows\system32\dllcache\stcusb.sys
2010-02-01 18:02 . 2001-08-17 10:11 48736 -c--a-w- c:\windows\system32\dllcache\srwlnd5.sys
2010-02-01 18:02 . 2001-08-17 20:36 99328 -c--a-w- c:\windows\system32\dllcache\srusd.dll
2010-02-01 18:02 . 2001-08-17 20:36 24660 -c--a-w- c:\windows\system32\dllcache\spxupchk.dll
2010-02-01 18:02 . 2001-08-17 11:51 61824 -c--a-w- c:\windows\system32\dllcache\speed.sys
2010-02-01 18:00 . 2001-08-17 11:57 6784 -c--a-w- c:\windows\system32\dllcache\smbhc.sys
2010-02-01 17:59 . 2001-08-17 12:56 252032 -c--a-w- c:\windows\system32\dllcache\sis300iv.dll
2010-02-01 17:58 . 2001-08-17 11:51 23936 -c--a-w- c:\windows\system32\dllcache\sccmusbm.sys
2010-02-01 17:57 . 2001-08-17 20:36 82432 -c--a-w- c:\windows\system32\dllcache\rwia450.dll
2010-02-01 17:56 . 2001-08-17 11:53 3328 -c--a-w- c:\windows\system32\dllcache\qv2kux.sys
2010-02-01 17:55 . 2001-08-17 20:36 121344 -c--a-w- c:\windows\system32\dllcache\phvfwext.dll
2010-02-01 17:54 . 2001-08-17 20:36 41984 -c--a-w- c:\windows\system32\dllcache\ovui2rc.dll
2010-02-01 17:53 . 2001-08-17 10:50 198144 -c--a-w- c:\windows\system32\dllcache\nv3.sys
2010-02-01 17:52 . 2001-08-17 10:50 27936 -c--a-w- c:\windows\system32\dllcache\n9i3d.sys
2010-02-01 17:51 . 2001-08-17 12:00 2944 -c--a-w- c:\windows\system32\dllcache\msmpu401.sys
2010-02-01 17:50 . 2001-08-17 10:12 164586 -c--a-w- c:\windows\system32\dllcache\mdgndis5.sys
2010-02-01 17:49 . 2001-08-17 20:36 37376 -c--a-w- c:\windows\system32\dllcache\kousd.dll
2010-02-01 17:48 . 2001-08-17 20:36 372824 -c--a-w- c:\windows\system32\dllcache\iconf32.dll
2010-02-01 17:47 . 2008-04-13 21:53 220032 -c--a-w- c:\windows\system32\dllcache\hsfbs2s2.sys
2010-02-01 17:46 . 2001-08-17 20:36 126976 -c--a-w- c:\windows\system32\dllcache\hpgt34tk.dll
2010-02-01 17:45 . 2001-08-17 20:36 92160 -c--a-w- c:\windows\system32\dllcache\fuusd.dll
2010-02-01 17:44 . 2008-04-13 20:06 137088 -c--a-w- c:\windows\system32\dllcache\essm2e.sys
2010-02-01 17:43 . 2001-08-17 10:10 69692 -c--a-w- c:\windows\system32\dllcache\el575nd5.sys
2010-02-01 17:42 . 2001-08-17 20:36 41046 -c--a-w- c:\windows\system32\dllcache\digiisdn.dll
2010-02-01 17:41 . 2008-04-14 03:41 249856 -c--a-w- c:\windows\system32\dllcache\ctmasetp.dll
2010-02-01 17:06 . 2010-02-01 18:39 -------- d-----w- c:\program files\playstation 1
2010-01-30 19:29 . 2010-01-30 19:29 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\myBabylon_English
2010-01-30 19:09 . 2010-01-30 19:16 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Babylon
2010-01-30 19:08 . 2010-01-30 19:08 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Conduit
2010-01-30 19:08 . 2010-01-30 19:12 -------- d-----w- c:\program files\myBabylon_English
2010-01-30 19:08 . 2010-01-30 19:12 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\myBabylon_English
2010-01-30 19:08 . 2010-01-30 19:08 -------- d-----w- c:\program files\Conduit
2010-01-30 19:08 . 2010-01-30 19:08 -------- d-----w- c:\program files\Babylon
2010-01-30 19:08 . 2010-02-02 22:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Babylon
2010-01-30 19:08 . 2010-01-31 18:00 -------- d-----w- c:\documents and settings\Administrator\Application Data\Babylon
2010-01-29 19:58 . 2010-01-29 19:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\DivX
2010-01-29 18:13 . 2003-12-01 00:01 110592 ----a-w- c:\windows\system32\tsccvid.dll
2010-01-26 19:46 . 2010-01-26 19:46 24462216 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\NokiaSoftwareUpdaterSetup_ar_2.exe
2010-01-26 19:46 . 2010-01-26 19:46 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\Installer\CommonCustomActions\msxml6Exec.exe
2010-01-26 19:46 . 2010-01-26 19:46 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\Installer\CommonCustomActions\Sleep.exe
2010-01-26 19:46 . 2010-01-26 19:46 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{4C911A61-39EA-41CC-AB3C-FE3BFFDB5F78}\Installer\CommonCustomActions\vcredistExec.exe
2010-01-25 05:43 . 2010-01-25 05:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\Pegasys Inc
2010-01-23 19:54 . 2010-01-23 20:01 -------- d-----w- C:\downloads
2010-01-23 19:54 . 2010-01-23 19:54 -------- d-----w- c:\documents and settings\Administrator\Application Data\GrabPro
2010-01-23 19:54 . 2010-01-23 23:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\Orbit
2010-01-23 17:53 . 2010-01-30 13:01 -------- d-----w- c:\program files\DivX
2010-01-23 15:44 . 2010-02-02 23:10 -------- d-----w- c:\documents and settings\Administrator\Application Data\Search Settings
2010-01-23 15:44 . 2010-01-23 15:44 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AVNEX_Ltd._(CY)
2010-01-23 15:43 . 2010-01-23 15:43 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Application Updater
2010-01-23 15:43 . 2010-01-23 15:43 -------- d-----w- c:\program files\Application Updater
2010-01-21 18:59 . 2010-01-21 18:59 -------- d-----w- c:\program files\LeeGTs Games
2010-01-21 18:35 . 2010-02-02 19:46 -------- d-----w- c:\program files\vanBasco's Karaoke Player
2010-01-19 16:00 . 2010-01-19 16:00 -------- d-----w- c:\program files\Common Files\Doblon
2010-01-19 16:00 . 2010-01-19 16:00 -------- d-----w- c:\program files\Doblon
2010-01-18 18:07 . 2010-01-18 18:07 -------- d-----w- c:\program files\SuperCleaner
2010-01-18 18:06 . 2010-01-18 18:06 -------- d-----w- c:\documents and settings\Administrator\Application Data\Office Genuine Advantage
2010-01-16 13:52 . 2010-01-16 13:52 -------- d-----w- c:\documents and settings\Administrator\Application Data\AlMAdinahMushaf
2010-01-15 21:26 . 2010-01-21 19:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Zbshareware Lab
2010-01-15 21:26 . 2010-01-21 19:10 -------- d-----w- c:\program files\USB Disk Security
2010-01-15 21:19 . 2010-01-15 21:19 -------- d-----w- c:\program files\Autorun Remover
2010-01-15 20:32 . 2010-01-15 20:32 -------- d-----w- c:\program files\GGreat USB AntiBody
2010-01-15 20:32 . 2010-01-15 20:32 -------- d-----w- C:\usbab
2010-01-15 18:48 . 2010-01-15 18:49 -------- d-----w- c:\program files\USBAntiVirus
2010-01-11 21:32 . 2010-01-11 21:33 -------- d-----w- c:\program files\Golden Al-Wafi Translator
2010-01-11 19:28 . 2010-01-11 19:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-01-11 19:28 . 2010-01-11 19:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-11 19:28 . 2010-01-21 19:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-10 21:38 . 2010-01-26 06:26 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\WinAVI
2010-01-10 21:38 . 2010-01-10 21:38 -------- d-----w- c:\program files\WinAVI Video Converter
2010-01-10 21:16 . 2010-01-10 21:16 -------- d-----w- c:\program files\Gabest
2010-01-10 21:05 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-01-10 21:05 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2010-01-10 21:05 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2010-01-10 21:05 . 2010-01-05 18:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-01-10 21:05 . 2010-01-10 21:05 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-01-09 15:38 . 2010-01-09 15:38 -------- d-----w- c:\program files\e-PDF To Word Converter
2010-01-08 18:05 . 2010-01-08 18:06 -------- d-----w- c:\program files\VeryPDF PDF2Word v2.0
2010-01-08 14:37 . 2010-01-08 14:40 -------- d-----w- C:\Mp3 Output
2010-01-08 14:37 . 2009-06-08 13:33 8676883 ----a-w- c:\windows\system32\mp3Media2.dll
2010-01-08 14:37 . 2010-01-08 14:37 -------- d-----w- c:\program files\Smallvideosoft
2010-01-07 19:49 . 2010-01-07 19:49 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-01-07 19:49 . 2010-01-07 19:49 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-01-07 19:49 . 2010-01-07 19:49 -------- d-----w- c:\program files\OpenAL
2010-01-07 19:36 . 2010-01-07 19:36 -------- d-----w- c:\windows\Logs
2010-01-07 19:26 . 2010-01-07 19:26 -------- d-----w- c:\program files\Common Files\EZB Systems
2010-01-06 00:06 . 2010-01-06 00:06 -------- d-----w- C:\ConTemp
2010-01-03 23:27 . 2006-09-04 14:55 344064 ----a-w- c:\windows\system32\msvcr70.dll
2010-01-03 23:27 . 2005-06-01 10:11 467456 ----a-w- c:\windows\system32\NCTAudioPlayer2.dll
2010-01-03 23:27 . 2005-05-31 14:02 522752 ----a-w- c:\windows\system32\NCTAudioTransform2.dll
2010-01-03 23:27 . 2005-05-26 10:00 403968 ----a-w- c:\windows\system32\NCTWMAFile2.dll
2010-01-03 23:27 . 2005-06-01 10:15 966144 ----a-w- c:\windows\system32\NCTAudioInformation2.dll
2010-01-03 23:27 . 2005-06-01 10:11 877568 ----a-w- c:\windows\system32\NCTAudioFile2.dll
2010-01-03 23:27 . 2005-06-01 10:12 467968 ----a-w- c:\windows\system32\NCTAudioRecord2.dll
2010-01-03 23:27 . 2005-06-01 09:54 634880 ----a-w- c:\windows\system32\NCTAudioEditor2.dll
2010-01-03 23:27 . 2010-01-03 23:48 -------- d-----w- c:\program files\NewLive All Media To Mp3 Converter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-02 23:16 . 2009-07-08 18:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\DMCache
2010-02-02 22:58 . 2009-07-21 19:16 21 ----a-w- c:\windows\1 Click & Lock.dat
2010-02-02 21:43 . 2009-07-06 17:07 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-02 21:34 . 2009-08-01 20:24 -------- d-----w- c:\program files\capcom
2010-02-02 20:50 . 2009-10-02 11:56 -------- d-----w- c:\program files\MPlayer for Windows
2010-02-02 19:46 . 2009-12-26 15:34 -------- d-----w- c:\documents and settings\Administrator\Application Data\vlc
2010-02-02 19:37 . 2009-07-17 19:17 -------- d-----w- c:\documents and settings\Administrator\Application Data\dvdcss
2010-02-01 18:43 . 2009-07-07 18:10 2 ----a-w- c:\windows\AR.DAT
2010-02-01 17:27 . 2009-11-23 19:40 -------- d-----w- c:\program files\The Cleaner
2010-02-01 17:24 . 2009-11-15 18:21 -------- d-----w- c:\program files\PC Cleaner
2010-02-01 17:23 . 2009-09-05 18:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-01-30 13:01 . 2009-07-06 18:10 -------- d-----w- c:\program files\Google
2010-01-30 13:01 . 2009-07-06 18:27 -------- d-----w- c:\program files\JetAudio
2010-01-29 19:44 . 2009-07-06 18:27 -------- d-----w- c:\program files\Common Files\COWON
2010-01-26 20:15 . 2009-12-03 22:34 -------- d-----w- c:\program files\Nokia
2010-01-26 19:46 . 2009-12-03 22:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-01-25 19:07 . 2009-07-06 18:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-01-25 19:07 . 2009-07-06 17:06 -------- d-----w- c:\program files\Yahoo!
2010-01-25 13:18 . 2009-10-03 19:10 -------- d-----w- c:\program files\Winamp
2010-01-21 17:03 . 2009-12-02 13:14 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-19 16:09 . 2009-08-03 18:54 63 ----a-w- c:\windows\AlfaStart.CMD
2010-01-18 18:12 . 2009-12-13 19:56 -------- d-----w- c:\program files\Common Files\XpressUpdate
2010-01-11 21:32 . 2009-08-21 19:43 172032 ------w- c:\windows\Setup1.exe
2010-01-11 21:32 . 2009-08-21 19:43 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-01-08 15:28 . 2009-08-08 21:33 -------- d-----w- c:\documents and settings\Administrator\Application Data\Hoyle Puzzle and Board Games
2010-01-07 19:26 . 2009-07-19 15:59 -------- d-----w- c:\program files\UltraISO
2010-01-06 00:07 . 2009-07-08 18:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\IDM
2009-12-30 20:13 . 2009-07-08 20:04 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-30 17:38 . 2009-12-18 20:02 -------- d-----w- c:\program files\Total Video Converter
2009-12-29 06:12 . 2009-12-29 06:12 -------- d-----w- c:\program files\Intelore
2009-12-26 15:14 . 2009-12-26 15:06 -------- d-----w- c:\program files\MultiTranse
2009-12-26 15:12 . 2009-12-26 15:12 0 ----a-w- c:\program files\MultiTransefind.ini
2009-12-26 05:40 . 2009-12-26 05:40 -------- d-----w- c:\documents and settings\Guest\Application Data\Ulead Systems
2009-12-23 18:53 . 2009-11-15 18:28 627094 ----a-w- c:\windows\system32\PCCleaner.zip
2009-12-23 17:39 . 2009-12-21 22:01 -------- d-----w- c:\program files\Video Enhancer
2009-12-21 19:14 . 2008-04-14 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-12-21 16:51 . 2009-12-20 23:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Ulead Systems
2009-12-21 00:21 . 2009-12-21 00:21 -------- d-----w- c:\documents and settings\All Users\Application Data\InterVideo
2009-12-21 00:20 . 2009-12-21 00:19 -------- d-----w- c:\program files\Common Files\Ulead Systems
2009-12-21 00:19 . 2009-12-20 23:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Ulead Systems
2009-12-21 00:19 . 2009-12-20 23:05 -------- d-----w- c:\program files\Corel
2009-12-20 23:53 . 2009-12-19 19:49 -------- d-----w- c:\program files\Media Convert Master
2009-12-20 23:50 . 2009-12-20 23:50 107280 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-12-20 23:50 . 2009-07-06 19:04 8224 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-20 23:08 . 2009-12-20 23:08 -------- d-----w- c:\program files\Windows Media Components
2009-12-20 22:28 . 2009-12-16 17:38 -------- d-----w- c:\program files\Boilsoft Video Splitter
2009-12-20 22:13 . 2009-12-20 22:13 17920 ----a-w- c:\documents and settings\Administrator\Application Data\Thinstall\Readiris Pro 11 Mr.Underground Edition\1000000500002i\hh.exe
2009-12-19 23:09 . 2009-12-16 17:45 -------- d-----w- c:\program files\PowerPoint to Video
2009-12-19 19:49 . 2009-12-19 19:49 -------- d-----w- c:\documents and settings\Administrator\Application Data\Vso
2009-12-19 19:49 . 2009-12-19 19:49 81920 ----a-w- c:\documents and settings\Administrator\Application Data\ezpinst.exe
2009-12-19 19:49 . 2009-12-19 19:49 81920 ----a-w- c:\documents and settings\Administrator\Application Data\ezpinst.exe
2009-12-19 19:49 . 2009-12-19 19:49 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-12-19 19:49 . 2009-12-19 19:49 47360 ----a-w- c:\documents and settings\Administrator\Application Data\pcouffin.sys
2009-12-19 19:49 . 2009-12-19 19:49 47360 ----a-w- c:\documents and settings\Administrator\Application Data\pcouffin.sys
2009-12-17 23:22 . 2009-11-19 05:13 -------- d-----w- c:\program files\Green box
2009-12-17 21:39 . 2009-12-17 21:39 -------- d-----w- c:\program files\ImTOO
2009-12-16 19:40 . 2009-12-16 01:09 -------- d-----w- c:\program files\Replay Converter
2009-12-16 17:05 . 2009-12-16 17:05 17920 ----a-w- c:\documents and settings\Administrator\Application Data\Thinstall\Readiris Pro 11 Mr.Underground Edition\400000500002i\AcrobatInfo.exe
2009-12-16 17:05 . 2009-12-16 17:05 17920 ----a-w- c:\documents and settings\Administrator\Application Data\Thinstall\Readiris Pro 11 Mr.Underground Edition\1000000b00002i\verclsid.exe
2009-12-16 01:09 . 2009-12-16 01:09 737280 ----a-w- c:\windows\iun6002.exe
2009-12-15 20:48 . 2009-12-15 20:48 17920 ----a-w- c:\documents and settings\Administrator\Application Data\Thinstall\Readiris Pro 11 Mr.Underground Edition\4000001400002i\pdf2bmp.exe
2009-12-15 20:46 . 2009-07-29 18:56 -------- d-----w- c:\documents and settings\Administrator\Application Data\Thinstall
2009-12-13 20:06 . 2009-12-13 20:06 -------- d-----w- c:\documents and settings\Administrator\Application Data\PixelPlanet
2009-12-13 19:57 . 2009-12-13 19:57 -------- d-----w- c:\documents and settings\All Users\Application Data\PixelPlanet
2009-12-13 16:55 . 2009-12-11 16:36 -------- d-----w- c:\program files\YahooFriend
2009-12-08 23:04 . 2009-12-03 22:35 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nokia
2009-12-08 00:10 . 2009-07-08 20:38 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-12-07 22:29 . 2009-07-06 17:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-03 22:33 . 2009-12-03 22:33 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\pcswpcsi.exe
2009-12-03 22:33 . 2009-12-03 22:33 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-12-03 22:33 . 2009-12-03 22:33 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstPCS.exe
2009-12-03 22:33 . 2009-12-03 22:33 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Installer\CommonCustomActions\UninstCCD.exe
2009-12-03 22:32 . 2009-12-03 22:33 34691976 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_ara_web.exe
2009-11-24 23:54 . 2009-07-06 17:44 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2009-07-06 17:44 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:49 . 2009-07-06 17:44 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-07-06 17:44 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-07-06 17:44 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2009-07-06 17:44 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-21 15:51 . 2008-04-14 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-09 18:50 . 2009-11-09 18:50 356352 ----a-w- c:\windows\eSellerateEngine.dll
2005-06-22 06:37 . 2006-05-24 18:37 45568 --sha-r- c:\windows\system32\cygz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{E312764E-7706-43F1-8DAB-FCDD2B1E416D}"= "c:\program files\Search Settings\SearchSettings.dll" [BU]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\program files\myBabylon_English\tbmyBa.dll" [2009-06-08 2124824]
[HKEY_CLASSES_ROOT\clsid\{e312764e-7706-43f1-8dab-fcdd2b1e416d}]
[HKEY_CLASSES_ROOT\SearchSettings.BHO.1]
[HKEY_CLASSES_ROOT\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}]
[HKEY_CLASSES_ROOT\SearchSettings.BHO]
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
2009-06-08 07:55 2124824 ----a-w- c:\program files\myBabylon_English\tbmyBa.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
c:\program files\Search Settings\SearchSettings.dll [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\program files\myBabylon_English\tbmyBa.dll" [2009-06-08 2124824]
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7}"= "c:\program files\myBabylon_English\tbmyBa.dll" [2009-06-08 2124824]
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-07-08 2815408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 153136]
"TTMessengerPDF"="c:\program files\TTMessenger\spool\PDFSaver.exe" [2004-03-22 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-14 623992]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"1cla.exe"="c:\progra~1\1click~1\1cla.exe" [2009-01-17 656384]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2009-10-26 15872]
"UVS12 Preload"="c:\program files\Corel\Corel VideoStudio 12\uvPL.exe" [2008-06-09 397456]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-10 198160]
"SearchSettings"="c:\program files\Search Settings\SearchSettings.exe" [BU]
"Babylon Client"="c:\program files\Babylon\Babylon-Pro\Babylon.exe" [2010-01-30 3682192]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 12:00 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 12:00 208952 ----a-w- c:\windows\ime\IMJP8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
c:\program files\iTunes\iTunesHelper.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-05-26 18:06 4351216 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 14:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-07-05 08:08 16380416 ------r- c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
c:\program files\Yahoo!\Search Protection\SearchProtection.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2006-11-10 09:35 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-09-10 18:56 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
c:\program files\Yahoo!\Search Protection\SearchProtection.exe [BU]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [06/11/2009 07:01 م 43792]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [06/07/2009 07:44 م 114768]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [16/12/2009 05:38 م 375296]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [06/07/2009 07:44 م 20560]
R2 fsproflt;FSPro Filter Service;c:\windows\system32\fsproflt.exe [06/11/2009 07:01 م 73392]
S1 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S2 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys --> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S2 gupdate1ca9c54f9a930e2;خدمة تحديث Google (gupdate1ca9c54f9a930e2);c:\program files\Google\Update\GoogleUpdate.exe [23/01/2010 07:53 م 133104]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 PPDrv;Protector Plus Driver;\??\c:\protector plus\PPDrv.sys --> c:\protector plus\PPDrv.sys [?]
S3 PPEMSCAN;Protector Plus Email Scan Driver;\??\c:\protector plus\PPEMSCAN.sys --> c:\protector plus\PPEMSCAN.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - APPLICATION_UPDATER
.
Contents of the 'Scheduled Tasks' folder
2010-01-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 09:34]
2010-02-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-23 17:53]
2010-02-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-23 17:53]
2010-02-02 c:\windows\Tasks\User_Feed_Synchronization-{4DD47D08-E8A7-4D39-B11D-908A3D342966}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 01:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.eg/
mSearch Bar = hxxp://www.google.com/ie
IE: Alexa Web Search... -
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Get Alexa Data... -
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: See Related Links... -
IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - c:\windows\web\related.htm
IE: {{F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
DPF: Microsoft XML Parser for Java -
.
.
------- File Associations -------
.
txtfile=c:\windows\notepad.exe %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2010-02-03 01:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1078081533-1637723038-1606980848-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b9,f7,9d,68,3d,ba,ce,4c,96,02,ad,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a0,65,ef,91,1a,b9,d0,47,a0,15,0d,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b9,f7,9d,68,3d,ba,ce,4c,96,02,ad,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2cf998b3-c622-4a22-b1f7-6de673d40e36}]
@Denied: (Full) (Everyone)
"Model"=dword:00000139
"Therad"=dword:0000001e
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):7a,49,ca,15,74,77,49,07,e4,89,d9,2b,f1,53,e8,83,b8,fe,14,d5,92,
7c,cf,83,7b,34,d5,d9,96,6f,65,cf,05,ce,79,46,b5,1b,f9,3e,00,00,00,00,00,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(720)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3776)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll
c:\program files\Common Files\Ahead\Lib\MFC71U.DLL
c:\program files\Common Files\Ahead\Lib\BCGCBPRO860un71.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-02-03 01:18:16
ComboFix-quarantined-files.txt 2010-02-02 23:18
ComboFix2.txt 2010-02-02 23:08
Pre-Run: 3,775,291,392 bytes free
Post-Run: 3,752,681,472 bytes free
- - End Of File - - 2EEAD433B40E276D9CC5E7463C246532
ارجوكم افيدونى وساعدونى ماذا فعل فى كل هذه المشاكل التى ظهرت فجأه