مشكور اخوي
سويت اللي طلبته واثناء الفحص طلعت هذه الملاحظة:
وهذه هي المفكرة :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 04:21:50 ص, on 20/10/10
Platform: Windows Vista SP1 (WinNT
6.00.1905)
MSIE: Internet Explorer v8.00
(8.00.6001.18975)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program
Files\Dell\DellDock\DellDock.exe
C:\Program Files\Windows
Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix
Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program
Files\Dell\MediaDirect\PCMService.exe
C:\Windows\system32\conime.exe
C:\Program Files\Dell Support
Center\bin\sprtcmd.exe
C:\Program Files\Microsoft
Office\Office12\GrooveMonitor.exe
C:\Program
Files\SimpleCenter\bin\win\sclauncher.exe
C:\Program Files\Agnitum\Outpost
Firewall Pro\op_mon.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Avira\AntiVir
Desktop\avgnt.exe
C:\Program Files\Java\jre1.6.0_07
\bin\jusched.exe
C:\Program Files\Common
Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows
Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media
Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth
Software\BTTray.exe
C:\Program Files\Digital Line
Detect\DLG.exe
C:\Program
Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\WIDCOMM\Bluetooth
Software\BtStackServer.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\hp\kbd\kbd.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Silent
He\Downloads\Zyzoom_HijackThis.exe
C:\Windows\system32
\SearchProtocolHost.exe
C:\Windows\System32\mspaint.exe
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
.
aspx?c=sa&l=ar&s=gen
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Page =
${URL_SEARCHPAGE}
R0 - HKCU\Software\Microsoft\Internet
Explorer\Main,Start Page =
?
SearchSource=10&ctid=CT2095689
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
.
aspx?c=sa&l=ar&s=gen
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
?
LinkId=54896
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page =
${URL_SEARCHPAGE}
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page =
?
LinkId=69157
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Window Title = Internet
Explorer provided by Dell
R1 -
HKCU\Software\Microsoft\Windows\Curr
entVersion\Internet
Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Eazel-FR Toolbar -
{a8f9752d-e2b8-4e7a-86b5-
499f4330e2fe} - C:\Program Files\Eazel-
FR\tbEaze.dll
F2 - REG:system.ini: UserInit=Userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-
4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub -
{18DF081C-E8AD-4283-A596-
FA578C2EBDC3} - C:\Program
Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEHel
perShim.dll
O2 - BHO: RealPlayer Download and Record
Plugin for Internet Explorer - {3049C3E9
-B461-4BC5-8870-4C09146192CA} -
C:\ProgramData\Real\RealPlayer\BrowserR
ecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Search Helper - {6EBF7485-
159F-4bff-A14F-B9E3AAC4465B} -
C:\Program Files\Microsoft\Search
Enhancement Pack\Search
Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper -
{72853161-30C5-4D22-B7F9-
0BBC1D38A37E} - C:\Program
Files\Microsoft Office\Office12
\GrooveShellExtensions.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live
- {9030D464-4C02-4ABF-8ECC-
5164760863C6} - C:\Program
Files\Common Files\Microsoft
Shared\Windows
Live\WindowsLiveLogin.dll
O2 - BHO: Eazel-FR Toolbar - {a8f9752d
-e2b8-4e7a-86b5-499f4330e2fe} -
C:\Program Files\Eazel-FR\tbEaze.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper
- {DBC80044-A445-435b-BC74-
9C25C1C588A9} - C:\Program
Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper -
{E15A8DC0-8516-42A1-81EA-
DC94EC1ACF10} - C:\Program
Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar -
{21FA44EF-376D-4D53-9B0F-
8A89D3229068} - C:\Program
Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Eazel-FR Toolbar -
{a8f9752d-e2b8-4e7a-86b5-
499f4330e2fe} - C:\Program Files\Eazel-
FR\tbEaze.dll
O4 - HKLM\..\Run: [Windows Defender] %
ProgramFiles%\Windows
Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program
Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe]
C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [IgfxTray]
C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds]
C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence]
C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program
Files\Intel\Intel Matrix Storage
Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Broadcom Wireless
Manager UI] C:\Windows\system32
\WLTRAY.exe
O4 - HKLM\..\Run: [PCMService]
"C:\Program
Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [dellsupportcenter]
"C:\Program Files\Dell Support
Center\bin\sprtcmd.exe" /P
dellsupportcenter
O4 - HKLM\..\Run: [GrooveMonitor]
"C:\Program Files\Microsoft
Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [sclauncher] C:\Program
Files\SimpleCenter\bin\win\sclauncher.exe
O4 - HKLM\..\Run: [OutpostMonitor]
"C:\PROGRA~1\Agnitum\OUTPOS~2
\op_mon.exe" /tray /noservice
O4 - HKLM\..\Run: [OutpostFeedBack]
"C:\Program Files\Agnitum\Outpost
Firewall Pro\feedback.exe"
/dump

s_startup
O4 - HKLM\..\Run: [avgnt] "C:\Program
Files\Avira\AntiVir Desktop\avgnt.exe"
/min
O4 - HKLM\..\Run: [KBD]
C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_07
\bin\jusched.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier]
C:\Program Files\Common
Files\Apple\Mobile Device
Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [TkBellExe]
"C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -
osboot
O4 - HKLM\..\Run: [QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe"
-atboottime
O4 - HKLM\..\Run: [UpdatePDRShortCut]
"C:\Program
Files\CyberLink\PowerDirector\MUITrans
fer\MUIStartMenu.exe" "C:\Program
Files\CyberLink\PowerDirector"
UpdateWithCreateOnce
"Software\CyberLink\PowerDirector\8.0"
O4 - HKLM\..\Run: [OEM02Cfg.exe]
OEM02Cfg.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp]
%ProgramFiles%\SigmaTel\C-Major
Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Adobe Reader Speed
Launcher] "C:\Program
Files\Adobe\Reader 9.0
\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM]
"C:\Program Files\Common
Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper]
"C:\Program
Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program
Files\Windows Sidebar\sidebar.exe
/autoRun
O4 - HKCU\..\Run: [ehTray.exe]
C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Yahoo Messengger]
C:\Windows\system32\RVHOST.exe
O4 - HKCU\..\Run: [Tok-Cirrhatus-2256]
"C:\Users\Silent
He\AppData\Local\br5535on.exe"
O4 - HKCU\..\Run: [Felix] C:\Program
Files\ScreenMates\FELIX LE CHAT.EXE
O4 - HKCU\..\Run: [Pareto_Update]
C:\Program Files\Common
Files\ParetoLogic\UUS2
\Pareto_Update.exe
O4 - HKCU\..\Run: [That dent five else]
"C:\ProgramData\chin bold bike.k3edsbk"
O4 - HKCU\..\Run: [Messenger (Yahoo!)]
"C:\PROGRA~1\Yahoo!
\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Skype] "C:\Program
Files\Skype\Phone\Skype.exe" /nosplash
/minimized
O4 - HKCU\..\Run: [WMPNSCFG]
C:\Program Files\Windows Media
Player\WMPNSCFG.exe
O4 - Startup: Dell Dock.lnk = C:\Program
Files\Dell\DellDock\DellDock.exe
O4 - Startup: IMVU.lnk = Silent
He\AppData\Roaming\IMVUClient\IMVU
QualityAgent.exe
O4 - Startup: OneNote 2007 Screen
Clipper and Launcher.lnk = C:\Program
Files\Microsoft Office\Office12
\ONENOTEM.EXE
O4 - Startup: جدول محتويات OneNote.onetoc2
O4 - Global Startup: Adobe Gamma
Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma
Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line
Detect.lnk = C:\Program Files\Digital Line
Detect\DLG.exe
O4 - Global Startup: QuickSet.lnk =
C:\Program
Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: Download
Using &BitSpirit - C:\Program
Files\BitSpirit\bsurl.htm
O8 - Extra context menu item: Google
Sidewiki... - res://C:\Program
Files\Google\Google
Toolbar\Component\GoogleToolbarDynamic
_mui_en_60D6097707281E79.dll/cmsidew
iki.html
O8 - Extra context menu item: Send image
to &Bluetooth Device... - C:\Program
Files\WIDCOMM\Bluetooth
Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page
to &Bluetooth Device... - C:\Program
Files\WIDCOMM\Bluetooth
Software\btsendto_ie.htm
O8 - Extra context menu item: ت&صدير إلى
Microsoft Excel - res://C:\PROGRA~1
\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: تدوين هذا في المدونة -
{219C3416-8CB2-491a-A3C7-
D9FCDDC9D600} - C:\Program
Files\Windows
Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &تدوين هذا في
Windows Live Writer - {219C3416-8CB2-
491a-A3C7-D9FCDDC9D600} - C:\Program
Files\Windows
Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: إرسال إلى OneNote -
{2670000A-7350-4f3c-8081-
5663EE0C6C49} - C:\PROGRA~1
\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى
OneNote - {2670000A-7350-4f3c-8081-
5663EE0C6C49} - C:\PROGRA~1
\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PalTalk - {4EAFEF58-
EEFA-4116-983D-03B49BCBFFFE} -
C:\Program Files\Paltalk
Messenger\Paltalk.exe
O9 - Extra button: Research - {92780B25
-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\Office12
\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 -
{CCA281CA-C863-46ef-9331-
5C8D4460577F} - C:\Program
Files\WIDCOMM\Bluetooth
Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-
12650 - {CCA281CA-C863-46ef-9331-
5C8D4460577F} - C:\Program
Files\WIDCOMM\Bluetooth
Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328
-7C28EA3B433A} (BitDefender
QuickScan Control) -
ax.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522
-AC9BF37916A7} -
Plus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS -
{88FED34C-F0CA-4636-A375-
3CB6248B04CD} - C:\Program
Files\Microsoft Office\Office12
\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-
9B40-4DFF-9458-1830C7DD7F5D} -
C:\PROGRA~1\COMMON~1
\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\progra~1
\agnitum\outpos~2\wl_hook.dll
O20 - Winlogon Notify: GoToAssist -
C:\Program Files\Citrix\GoToAssist\514
\G2AWinLogon.dll
O23 - Service: Agnitum Client Security
Service (acssrv) - Agnitum Ltd. -
C:\PROGRA~1\Agnitum\OUTPOS~2
\acs.exe
O23 - Service: Andrea ST Filters Service
(AESTFilters) - Andrea Electronics
Corporation - C:\Windows\system32
\aestsrv.exe
O23 - Service: Avira AntiVir Scheduler
(AntiVirSchedulerService) - Avira GmbH -
C:\Program Files\Avira\AntiVir
Desktop\sched.exe
O23 - Service: Avira AntiVir Guard
(AntiVirService) - Avira GmbH -
C:\Program Files\Avira\AntiVir
Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple
Inc. - C:\Program Files\Common
Files\Apple\Mobile Device
Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc.
- C:\Program
Files\Bonjour\mDNSResponder.exe
O23 - Service: Dock Login Service
(DockLoginService) - Stardock
Corporation - C:\Program
Files\Dell\DellDock\DockLogin.exe
O23 - Service: GoToAssist - Citrix Online,
a division of Citrix Systems, Inc. -
C:\Program Files\Citrix\GoToAssist\514
\g2aservice.exe
O23 - Service: Google Update Service
(gupdate) (gupdate) - Google Inc. -
C:\Program
Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Matrix Storage
Event Monitor (IAANTMON) - Intel
Corporation - C:\Program Files\Intel\Intel
Matrix Storage Manager\Iaantmon.exe
O23 - Service: iPod Service - Apple Inc. -
C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: RealtekUSB - Realtek -
C:\Program Files\REALTEK\RTL8187
Wireless LAN Utility\RtlService.exe
O23 - Service: Cyberlink RichVideo
Service(CRVS) (RichVideo) - Unknown
owner - C:\Program
Files\CyberLink\Shared
Files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. -
C:\Program Files\PC Connectivity
Solution\ServiceLayer.exe
O23 - Service: SupportSoft Sprocket
Service (DellSupportCenter)
(sprtsvc_DellSupportCenter) -
SupportSoft, Inc. - C:\Program Files\Dell
Support Center\bin\sprtsvc.exe
O23 - Service: TeamViewer 5
(TeamViewer5) - TeamViewer GmbH -
C:\Program Files\TeamViewer\Version5
\TeamViewer_Service.exe
O23 - Service: Dell Wireless WLAN Tray
Service (wltrysvc) - Unknown owner -
C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant
Systems, Inc. - C:\Windows\system32
\DRIVERS\xaudio.exe
O23 - Service: Yahoo! Updater
(YahooAUService) - Yahoo! Inc. -
C:\Program Files\Yahoo!
\SoftwareUpdate\YahooAUService.exe
--
End of file - 13269 bytes