هذا تقرير الهايجك:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:53:56 ص, on 13/02/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\FAHESS\McciTrayApp.exe
C:\Program Files\STCWCM\McciTrayApp.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\AnchorFree\bin\ctrl\AFController.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Webshots\WebshotsTray.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\WINDOWS\System32\ChgService.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Hotspot Shield\bin\hsswd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hotspot Shield\bin\openvpntray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\مجلد ف ر غ\Zyzoom.org_Tool_V_1.0.exe
C:\DOCUME~1\user\LOCALS~1\Temp\zyaoom Tool\Hijack.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: (no name) - {EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
R3 - URLSearchHook: (no name) - {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - (no file)
R3 - URLSearchHook: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot2.dll
O2 - BHO: (no name) - {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5825.1100\swg.dll
O2 - BHO: AF BHO - {B7154C4D-87C0-4A2C-AB64-DA132BAC2EE6} - C:\Program Files\AnchorFree\bin\AFBho.dll
O2 - BHO: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot2.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll
O3 - Toolbar: AFToolbar - {1F385865-F3D4-41ff-960D-7B7D0A7A72F6} - C:\Program Files\AnchorFree\bin\AFToolbar.dll
O3 - Toolbar: (no name) - {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - (no file)
O3 - Toolbar: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot2.dll
O3 - Toolbar: PandoraTV Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [FAHESS_McciTrayApp] C:\Program Files\FAHESS\McciTrayApp.exe
O4 - HKLM\..\Run: [STCWCM_McciTrayApp] C:\Program Files\STCWCM\McciTrayApp.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AFProg] C:\Program Files\AnchorFree\bin\ctrl\AFController.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: تدوين هذا في المدونة - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &تدوين هذا في Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: &لوحة مفاتيح ظاهرية - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: فحص عناوين المواقع (URL) - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} (BitDefender QuickScan Control) -
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) -
O16 - DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} (ReadUid.UserControlMacEntry) -
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) -
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: Change Modem Device Service - Unknown owner - C:\WINDOWS\System32\ChgService.exe
O23 - Service: خدمة تحديث Google (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files\Hotspot Shield\bin\hsswd.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
--
End of file - 12660 bytes
ـــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــ
وهذا الرن سكنر:
Runscanner logfile
* = signed file
- = file not found
General info
------------
Computer name : SYSTEM-F7879B13
Creation time : 13/02/2011 01:17:52 ص
Hosts <> 127.0.0.1 : 0
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 8.0.6001.18702
OS : Microsoft Windows XP
OS Build : 2600
OS SP : Service Pack 2
RunScanner Version : 2.0.0.50
User Language : العربية (السعودية)
User rights : Administrator
Windows folder : C:\WINDOWS
Running processes
-----------------
C:\Program Files\AnchorFree\bin\ctrl\AFController.exe
* C:\WINDOWS\system32\alg.exe (Microsoft Corporation)
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\WINDOWS\system32\ChgService.exe
* C:\WINDOWS\system32\csrss.exe (Microsoft Corporation)
* C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
C:\Program Files\FAHESS\McciTrayApp.exe (Saudi Telecom)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Development Company, L.P.)
C:\DOCUME~1\user\LOCALS~1\Temp\zyaoom Tool\Hijack.exe (Trend Micro Inc.)
C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
* C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
C:\Program Files\Hotspot Shield\bin\hsswd.exe
* C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
* C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
* C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
* C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
* C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
* C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
* C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe (Kaspersky Lab)
* C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
* C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
C:\Program Files\STCWCM\McciTrayApp.exe (Motive Communications, Inc.)
* C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
* C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\bin\openvpntray.exe
* C:\WINDOWS\system32\HPZipm12.exe (HP)
* C:\Program Files\PowerArchiver\PASTARTER.EXE (ConeXware, Inc.)
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
* C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
* C:\WINDOWS\RTHDCPL.exe (Realtek Semiconductor Corp.)
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
* C:\Zyzoom_Forum_Tools\zRunScanner.com (Runscanner.net)
* C:\WINDOWS\system32\services.exe (Microsoft Corporation)
* C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation)
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe (TOSHIBA Corporation)
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
C:\Program Files\Webshots\WebshotsTray.exe (The Webshots Corporation)
* C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe (Kaspersky Lab)
* C:\WINDOWS\explorer.exe (Microsoft Corporation)
* C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation)
* C:\WINDOWS\system32\winlogon.exe (Microsoft Corporation)
* C:\WINDOWS\system32\smss.exe (Microsoft Corporation)
* C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\مجلد ف ر غ\Zyzoom.org_Tool_V_1.0.exe
Unrated items
-------------
002 C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
002 C:\Program Files\FAHESS\McciTrayApp.exe (Saudi Telecom)
002 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Development Company, L.P.)
002 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
002 C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
002 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
002 C:\Program Files\STCWCM\McciTrayApp.exe (Motive Communications, Inc.)
002 C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe (TOSHIBA)
003 C:\Program Files\AnchorFree\bin\ctrl\AFController.exe
003 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
003 * C:\Program Files\PowerArchiver\PASTARTER.EXE (ConeXware, Inc.)
004 C:\Program Files\Webshots\WebshotsTray.exe (The Webshots Corporation)
005 C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
010 C:\WINDOWS\System32\ChgService.exe (Change Modem Device Service)
010 C:\Program Files\CyberLink\Shared Files\RichVideo.exe (Cyberlink RichVideo Service(CRVS))
010 C:\Program Files\Hotspot Shield\bin\hsswd.exe (Hotspot Shield Monitoring Service)
010 C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (Hotspot Shield Routing Service)
010 C:\Program Files\Hotspot Shield\bin\openvpnas.exe (Hotspot Shield Service)
010 C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE (Hotspot Shield Tray Service)
010 C:\Program Files\Common Files\Motive\McciCMService.exe (McciCMService)
010 C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (NBService)
010 C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Application Service)
011 * C:\WINDOWS\system32\DRIVERS\taphss.sys (Anchorfree HSS Adapter)
011 C:\WINDOWS\system32\DRIVERS\ar5211.sys (Atheros Wireless Network Adapter Service)
011 * C:\WINDOWS\system32\DRIVERS\HssDrv.sys (Hotspot Shield Helper Miniport)
011 C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS (MREMP50 NDIS Protocol Driver)
011 C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS (MRESP50 NDIS Protocol Driver)
011 C:\WINDOWS\system32\drivers\pfc.sys (Padus ASPI Shell)
011 C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys (Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver)
011 C:\WINDOWS\system32\DRIVERS\RTL8187B.sys (Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter)
031 C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation) {0A9007C0-4076-11D3-8789-0000F8105754}
040 C:\Program Files\Hotspot_Shield\tbHot2.dll (Conduit Ltd.) {c95a4e8e-816d-4655-8c79-d736da1adb6d}
041 C:\Program Files\AnchorFree\bin\AFToolbar.dll {1F385865-F3D4-41ff-960D-7B7D0A7A72F6}
041 C:\Program Files\Hotspot_Shield\tbHot2.dll (Conduit Ltd.) {c95a4e8e-816d-4655-8c79-d736da1adb6d}
045 C:\Program Files\Hotspot_Shield\tbHot2.dll (Conduit Ltd.) {C95A4E8E-816D-4655-8C79-D736DA1ADB6D}
052 GUID / CLSID not found {09ec805c-cb2e-4d53-b0d3-a75a428b81c7}
052 C:\Program Files\AnchorFree\bin\AFBho.dll {B7154C4D-87C0-4A2C-AB64-DA132BAC2EE6}
052 C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) {30F9B915-B755-4826-820B-08FBA6BD249D}
052 C:\Program Files\Hotspot_Shield\tbHot2.dll (Conduit Ltd.) {c95a4e8e-816d-4655-8c79-d736da1adb6d}
052 C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.) {F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
052 C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) {E7E6F031-17CE-4C07-BC86-EABFE594F69C}
061 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
061 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
061 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79305-84BE-11CE-9641-444553540000}
061 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79306-84BE-11CE-9641-444553540000}
061 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79307-84BE-11CE-9641-444553540000}
104 * C:\WINDOWS\DOWNLO~1\qsax.dll (BitDefender LLC) {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A}
104 C:\PROGRA~1\LtUcx\1003\c0.dll (Lotuspond Software Technology (Beijing) Co.,Ltd.) {6924091F-CD97-41E1-B1D4-D9079409D413}
104 C:\WINDOWS\Downloaded Program Files\ReadUid.ocx (Digivoice Computer Systems) {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA}
105 Add to Anti-Banner : C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
105 E&xport to Microsoft Excel : res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
170 {02e78238-2c58-11df-a047-0024d225ded2} : G:\AutoRun.exe
170 {02e7823c-2c58-11df-a047-0024d225ded2} : G:\AutoRun.exe
170 {02ef95cd-7638-11df-a115-941fcce71963} : G:\AutoRun.exe
170 {0df7386a-e303-11de-9fb1-0024d225ded2} : G:\AutoRun.exe
170 {15e9246a-310b-11df-a060-0024d225ded2} : G:\AutoRun.exe
170 {15e9246d-310b-11df-a060-0024d225ded2} : G:\AutoRun.exe
170 {22db4c94-766a-11df-a117-c0b487f7e861} : G:\AutoRun.exe
170 {270d25f0-4a57-11df-a0ba-0024d225ded2} : G:\.\ShowModem.exe
170 {2d4e656e-8abd-11df-a131-8d84dea1676e} : H:\AutoRun.exe
170 {2e390d80-952e-11de-9ebe-806d6172696f} : E:\setupSNK.exe
170 {2f99af2c-544e-11df-a0de-0024d225ded2} : G:\AutoRun.exe
170 {4b16a9dc-d72e-11de-9fa5-0024d225ded2} : G:\AutoRun.exe
170 {5071f4dc-51c8-11dd-b74e-001b9eea40f1} : F:\xfoolavp.com
170 {72d3bdd6-1fed-11df-a01a-0024d225ded2} : G:\AutoRun.exe
170 {89874d84-2c7f-11df-a04a-0024d225ded2} : G:\AutoRun.exe
170 {89874d86-2c7f-11df-a04a-0024d225ded2} : G:\AutoRun.exe
170 {89874d88-2c7f-11df-a04a-0024d225ded2} : G:\AutoRun.exe
170 {89950dd8-f3d1-11de-9fc1-0024d225ded2} : G:\AutoRun.exe
170 {9365d19a-2c74-11df-a049-0024d225ded2} : G:\AutoRun.exe
170 {9c34bad8-01e1-11df-9fd0-0024d225ded2} : G:\AutoRun.exe
170 {b96b09f6-9597-11de-9eca-0024d225ded2} : G:\AutoRun.exe
170 {b96b09f7-9597-11de-9eca-0024d225ded2} : G:\AutoRun.exe
170 {d643bec9-caf9-11de-9f94-0024d225ded2} : G:\AutoRun.exe
170 {de0fe464-10ed-11df-9fe7-0024d225ded2} : G:\AutoRun.exe
170 {ee309614-dbfe-11de-9fa9-0024d225ded2} : G:\AutoRun.exe
170 {f585d730-35bb-11df-a06f-0024d225ded2} : G:\AutoRun.exe
170 {fc09cf36-2c69-11df-a048-0024d225ded2} : G:\AutoRun.exe
170 {fc09cf3a-2c69-11df-a048-0024d225ded2} : G:\AutoRun.exe
171 C:\WINDOWS\system32\MAT2.scr
173 C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll (Nero AG)
173 * C:\Program Files\PowerArchiver\PASHLEXT.DLL (ConeXware, Inc.) {d03d3e68-0c44-3d45-b15f-bcfd8a8b4c7e}
173 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
173 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
221 C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll (Nero AG)
221 * C:\Program Files\PowerArchiver\PASHLEXT.DLL (ConeXware, Inc.) {d03d3e68-0c44-3d45-b15f-bcfd8a8b4c7e}
221 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
221 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
225 C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll (Nero AG)
225 C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll (Nero AG)
225 * C:\Program Files\PowerArchiver\PASHLEXT.DLL (ConeXware, Inc.) {d03d3e68-0c44-3d45-b15f-bcfd8a8b4c7e}
225 * C:\Program Files\PowerArchiver\PASHLEXT.DLL (ConeXware, Inc.) {d03d3e68-0c44-3d45-b15f-bcfd8a8b4c7e}
225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
225 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
227 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
227 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
251 * C:\Program Files\PowerArchiver\PASHLEXT.DLL (ConeXware, Inc.) {d03d3e69-0c44-3d45-b15f-bcfd8a8b4c7e}
251 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
251 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79305-84BE-11CE-9641-444553540000}
Missing files
-------------
002 TFncKy.exe
011 C:\WINDOWS\system32\drivers\Abiosdsk.sys
011 C:\WINDOWS\system32\drivers\abp480n5.sys
011 C:\WINDOWS\system32\drivers\adpu160m.sys
011 C:\WINDOWS\system32\drivers\Aha154x.sys
011 C:\WINDOWS\system32\drivers\aic78u2.sys
011 C:\WINDOWS\system32\drivers\aic78xx.sys
011 C:\WINDOWS\system32\drivers\AliIde.sys
011 C:\WINDOWS\system32\drivers\amsint.sys
011 C:\WINDOWS\system32\drivers\asc.sys
011 C:\WINDOWS\system32\drivers\asc3350p.sys
011 C:\WINDOWS\system32\drivers\asc3550.sys
011 C:\WINDOWS\system32\drivers\Atdisk.sys
011 C:\Program Files\Anti Trojan Elite\ATEPMon.sys
011 c:\windows\system32\DRIVERS\blueletaudio.sys
011 System32\Drivers\vbtenum.sys
011 System32\Drivers\BTHidMgr.sys
011 c:\windows\system32\DRIVERS\btnetdrv.sys
011 c:\windows\system32\DRIVERS\BlueletSCOAudio.sys
011 C:\WINDOWS\system32\drivers\cd20xrnt.sys
011 C:\WINDOWS\system32\drivers\Changer.sys
011 C:\WINDOWS\system32\drivers\CmdIde.sys
011 C:\WINDOWS\system32\drivers\Cpqarray.sys
011 C:\WINDOWS\system32\drivers\dac2w2k.sys
011 C:\WINDOWS\system32\drivers\dac960nt.sys
011 C:\WINDOWS\system32\drivers\dpti2o.sys
011 C:\WINDOWS\system32\drivers\hpn.sys
011 c:\windows\system32\DRIVERS\ewusbmdm.sys
011 C:\WINDOWS\system32\drivers\i2omgmt.sys
011 C:\WINDOWS\system32\drivers\i2omp.sys
011 C:\WINDOWS\system32\drivers\ini910u.sys
011 C:\WINDOWS\system32\drivers\IntelIde.sys
011 C:\WINDOWS\system32\drivers\lbrtfdc.sys
011 c:\windows\system32\DRIVERS\mdmxsdk.sys
011 C:\WINDOWS\system32\drivers\mraid35x.sys
011 C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS
011 C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS
011 C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS
011 C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS
011 C:\WINDOWS\system32\drivers\PCIDump.sys
011 C:\WINDOWS\system32\drivers\PDCOMP.sys
011 C:\WINDOWS\system32\drivers\PDFRAME.sys
011 C:\WINDOWS\system32\drivers\PDRELI.sys
011 C:\WINDOWS\system32\drivers\PDRFRAME.sys
011 C:\WINDOWS\system32\drivers\perc2.sys
011 C:\WINDOWS\system32\drivers\perc2hib.sys
011 C:\WINDOWS\system32\drivers\ql1080.sys
011 C:\WINDOWS\system32\drivers\Ql10wnt.sys
011 C:\WINDOWS\system32\drivers\ql12160.sys
011 C:\WINDOWS\system32\drivers\ql1240.sys
011 C:\WINDOWS\system32\drivers\ql1280.sys
011 C:\WINDOWS\system32\drivers\Simbad.sys
011 C:\WINDOWS\system32\drivers\Sparrow.sys
011 C:\WINDOWS\system32\drivers\sym_hi.sys
011 C:\WINDOWS\system32\drivers\sym_u3.sys
011 C:\WINDOWS\system32\drivers\symc810.sys
011 C:\WINDOWS\system32\drivers\symc8xx.sys
011 C:\WINDOWS\system32\drivers\TosIde.sys
011 C:\WINDOWS\system32\drivers\ultra.sys
011 C:\WINDOWS\system32\drivers\ViaIde.sys
011 C:\WINDOWS\system32\drivers\WDICA.sys
061 deskpan.dll
067
ـــــــــــــــــــــــــــــــــــــــ
وهذي صورة للشاشه لانه فيها مشكلة الصورة ماتطول على الشاشه:
وكمان الجهاز ثقيييييييل ويعلق ..
هذا اللي عرفت له ولاتكثرون طلبات ترى معرفتي على قدي:hh: ,, وشكرا