تم عمل اللازم وهذا التقرير المطلوب
logfile of trend micro hijackthis v2.0.2
scan saved at 05:39:32 م, on 11/01/2011
platform: Unknown windows (winnt 6.01.3504)
msie: Internet explorer v8.00 (8.00.7600.16700)
boot mode: Normal
running processes:
C:\windows\system32\dwm.exe
c:\windows\system32\taskhost.exe
c:\windows\explorer.exe
c:\program files\cfosbc\wbc.exe
c:\program files\usb disk security\usbguard.exe
c:\program files\alwil software\avast5\avastui.exe
c:\program files\internet download manager\idman.exe
c:\program files\internet download manager\iemonitor.exe
c:\windows\system32\searchfilterhost.exe
c:\users\home\downloads\programs\zyzoom_hijackthis.exe
r1 - hkcu\software\microsoft\internet explorer\main,search page =
r1 - hklm\software\microsoft\internet explorer\main,default_page_url =
r1 - hklm\software\microsoft\internet explorer\main,default_search_url =
r1 - hklm\software\microsoft\internet explorer\main,search page =
r0 - hklm\software\microsoft\internet explorer\main,start page =
r0 - hklm\software\microsoft\internet explorer\search,searchassistant =
r0 - hklm\software\microsoft\internet explorer\search,customizesearch =
r0 - hkcu\software\microsoft\internet explorer\main,local page =
r0 - hklm\software\microsoft\internet explorer\main,local page =
r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername =
o2 - bho: Idm helper - {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\idmiecc.dll
o2 - bho: Acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
o2 - bho: Groove gfs browser helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\grooveex.dll
o2 - bho: Windows live id sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Windows live messenger companion helper - {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
o2 - bho: Skypeiepluginbho - {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
o2 - bho: Urlredirectionbho - {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\urlredir.dll
o2 - bho: Java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
o3 - toolbar: (no name) - {10edb994-47f8-43f7-ae96-f2ea63e9f90f} - (no file)
o4 - hklm\..\run: [cfosbc daemon] c:\program files\cfosbc\wbc.exe
o4 - hklm\..\run: [usb antivirus] c:\program files\usb disk security\usbguard.exe
o4 - hklm\..\run: [avast5] "c:\program files\alwil software\avast5\avastui.exe" /nogui
o4 - hkcu\..\run: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
o4 - hkcu\..\run: [idman] c:\program files\internet download manager\idman.exe /onboot
o4 - hkcu\..\run: [google update] "c:\users\home\appdata\local\google\update\googleupdate.exe" /c
o4 - hkus\s-1-5-19\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /autorun (user 'local service')
o4 - hkus\s-1-5-19\..\runonce: [mctadmin] c:\windows\system32\mctadmin.exe (user 'local service')
o4 - hkus\s-1-5-20\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /autorun (user 'network service')
o4 - hkus\s-1-5-20\..\runonce: [mctadmin] c:\windows\system32\mctadmin.exe (user 'network service')
o8 - extra context menu item: Download all links with idm - c:\program files\internet download manager\iegetall.htm
o8 - extra context menu item: Download flv video content with idm - c:\program files\internet download manager\iegetvl.htm
o8 - extra context menu item: Download with idm - c:\program files\internet download manager\ieext.htm
o9 - extra button: @c:\program files\windows live\companion\companionlang.dll,-600 - {0000036b-c524-4050-81a0-243669a86b9f} - c:\program files\windows live\companion\companioncore.dll
o9 - extra button: @c:\program files\windows live\writer\windowslivewritershortcuts.dll,-1004 - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files\windows live\writer\writerbrowserextension.dll
o9 - extra 'tools' menuitem: @c:\program files\windows live\writer\windowslivewritershortcuts.dll,-1003 - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files\windows live\writer\writerbrowserextension.dll
o9 - extra button: إرسال إلى onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\program files\microsoft office\office14\onbttnie.dll
o9 - extra 'tools' menuitem: إر&سال إلى onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\program files\microsoft office\office14\onbttnie.dll
o9 - extra button: ملاحظات onenote الم&رتبطة - {789fe86f-6fc4-46a1-9849-ede0db0c95ca} - c:\program files\microsoft office\office14\onbttnielinkednotes.dll
o9 - extra 'tools' menuitem: ملاحظات onenote الم&رتبطة - {789fe86f-6fc4-46a1-9849-ede0db0c95ca} - c:\program files\microsoft office\office14\onbttnielinkednotes.dll
o9 - extra button: Skype plug-in - {898ea8c8-e7ff-479b-8935-aec46303b9e5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
o9 - extra 'tools' menuitem: Skype plug-in - {898ea8c8-e7ff-479b-8935-aec46303b9e5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
o10 - unknown file in winsock lsp: C:\program files\common files\microsoft shared\windows live\wlidnsp.dll
o10 - unknown file in winsock lsp: C:\program files\common files\microsoft shared\windows live\wlidnsp.dll
o13 - gopher prefix:
O16 - dpf: {4871a87a-bfdd-4106-8153-ffde2bac2967} (dlm control) -
o16 - dpf: {e2883e8f-472f-4fb0-9522-ac9bf37916a7} -
o18 - protocol: Skype-ie-addon-data - {91774881-d725-4e58-b298-07617b9b86a8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
o18 - protocol: Skype4com - {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - c:\progra~1\common~1\skype\skype4~1.dll
o18 - protocol: Wlpg - {e43ef6cd-a37a-4a9b-9e6f-83f89b8e6324} - c:\program files\windows live\photo gallery\albumdownloadprotocolhandler.dll
o18 - filter hijack: Text/xml - {807573e5-5146-11d5-a672-00b0d022e945} - c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
o20 - winlogon notify: Rkotrig - c:\windows\system32\rkotrig.dll
o23 - service: Ati external event utility - ati technologies inc. - c:\windows\system32\ati2evxx.exe
o23 - service: Avast! Antivirus - avast software - c:\program files\alwil software\avast5\avastsvc.exe
o23 - service: Avast! Firewall - avast software - c:\program files\alwil software\avast5\afwserv.exe
o23 - service: Acronis os selector activator (os selector) - unknown owner - c:\program files\acronis\diskdirector\oss\reinstall_svc.exe
o23 - service: Teamviewer 6 (teamviewer6) - teamviewer gmbh - c:\program files\teamviewer\version6\teamviewer_service.exe
--
end of file - 7438 bytes