أخوي البااورن عدلت و حملت ملفات ... الخ لكن على الفاضي و بعد التعديل و الحذف و ما شابه التقارير
كمان مره
هايجاك
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:17:33, on 8/27/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\hason\Documents\Downloads\Compressed\runscanner.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\hason\Documents\Downloads\Compressed\Zyzoom_HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\4.2.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\4.2.0.12\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GR469A~1.DLL
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.2.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [HotKeysCmds] ; C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [IgfxTray] ; C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] ; C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] ; C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى FLV بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetVL.htm
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} (SysInfo Class) -
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: AutoUpdateD - Unknown owner - C:\Program Files\Philips\Xcelera\Programs\AutoUpdateD.exe
O23 - Service: EnConcertRMS - Philips Medical Systems Nederland BV - C:\Program Files\Philips\Xcelera\Programs\enconcertrms.exe
O23 - Service: GEARSecurity - GEAR Software - C:\Windows\System32\gearsec.exe
O23 - Service: II?E E?I?E Google (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Company - C:\Windows\system32\Hpservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 5249 bytes
تــــــــــــقـــــــــرير البرامج المثبته
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop CS
Adobe Reader 9.3.3
COWON Media Center - jetAudio Basic
E??I Windows Live
Google Update Helper
HijackThis 2.0.2
Internet Download Manager
Junk Mail filter update
Media Player Classic - Home Cinema v1.3.1659.0
Messenger Plus! Live
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft Choice Guard
Microsoft Office Access MUI (Arabic) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (Arabic) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (Arabic) 2007
Microsoft Office InfoPath MUI (Arabic) 2007
Microsoft Office OneNote MUI (Arabic) 2007
Microsoft Office Outlook MUI (Arabic) 2007
Microsoft Office PowerPoint MUI (Arabic) 2007
Microsoft Office Proof (Arabic) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proofing (Arabic) 2007
Microsoft Office Publisher MUI (Arabic) 2007
Microsoft Office Shared MUI (Arabic) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Word MUI (Arabic) 2007
Mozilla Firefox (3.6.8)
MSVC80_x86_v2
MSVCRT
Nero 7 Essentials
Nokia Connectivity Cable Driver
Nokia PC Suite
Nokia PC Suite
Norton 360
Norton Internet Security
NVIDIA PhysX
PC Connectivity Solution
Quick Screen Recorder 1.5
RealPlayer
RealUpgrade 1.0
redist
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Skype™ 3.8
System Requirements Lab
System Requirements Lab CYRI
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Outlook 2007 Junk Email Filter (kb2279264)
Windows Driver Package - Nokia Modem (02/15/2007 3.1)
Windows Driver Package - Nokia Modem (02/15/2007 3.1)
Windows Driver Package - Nokia Modem (05/24/2007 6.84.0.1)
Windows Driver Package - Nokia Modem (06/09/2010 4.5)
Windows Driver Package - Nokia Modem (06/09/2010 7.01.0.7)
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Messenger
Windows Live Upload Tool
WinRAR archiver
Xcelera
Yahoo! Messenger
Your Uninstaller! 2010
تقرير سارت أب
Start-Up Items Table { font-size: 12; }
[SIZE=-1]Start-Up Items; List generated by Start-Up Tool.
[/SIZE]
[SIZE=-1] msnmsgr
Name: msnmsgr Command: "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background Reg_Path: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Status: enabled Description: Windows Live Messenger Company: Microsoft Corporation[/SIZE]
[SIZE=-1] IDMan
Name: IDMan Command: C:\Program Files\Internet Download Manager\IDMan.exe /onboot Reg_Path: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Status: enabled Description: Internet Download Manager (IDM) Company: Tonec Inc.[/SIZE]
[SIZE=-1] Sidebar
Name: Sidebar Command: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun Reg_Path: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Status: enabled Description: Windows Desktop Gadgets Company: Microsoft Corporation[/SIZE]
[SIZE=-1] HotKeysCmds
Name: HotKeysCmds Command: ; C:\Windows\system32\hkcmd.exe Reg_Path: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run Status: enabled Description: n/a Company: n/a[/SIZE]
[SIZE=-1] IgfxTray
Name: IgfxTray Command: ; C:\Windows\system32\igfxtray.exe Reg_Path: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run Status: enabled Description: n/a Company: n/a[/SIZE]
[SIZE=-1] Persistence
Name: Persistence Command: ; C:\Windows\system32\igfxpers.exe Reg_Path: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run Status: enabled Description: n/a Company: n/a[/SIZE]
[SIZE=-1] SoundMAXPnP
Name: SoundMAXPnP Command: ; C:\Program Files\Analog Devices\Core\smax4pnp.exe Reg_Path: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run Status: enabled Description: n/a Company: n/a[/SIZE]
[SIZE=-1] NeroFilterCheck
Name: NeroFilterCheck Command: C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe Reg_Path: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run- Status: disabled Description: NeroCheck Company: Nero AG[/SIZE]
[SIZE=-1] Adobe Reader Speed Launcher
Name: Adobe Reader Speed Launcher Command: "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" Reg_Path: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run- Status: disabled Description: Adobe Acrobat SpeedLauncher Company: Adobe Systems Incorporated[/SIZE]
[SIZE=-1] Adobe ARM
Name: Adobe ARM Command: "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" Reg_Path: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run- Status: disabled Description: Adobe Reader and Acrobat Manager Company: Adobe Systems Incorporated[/SIZE]
تقرير الرن سكان و أيضا قمت برفع تقرير الرن سكان لو كان مش واضح