تقرير رن سكان
Runscanner logfile
* = signed file
- = file not found
General info
------------
Computer name : HUSSIN
Creation time : 25/02/2011 11:18:12 م
Hosts <> 127.0.0.1 : 0
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 8.0.6001.18702
OS : Microsoft Windows XP
OS Build : 2600
OS SP : Service Pack 2
RunScanner Version : 2.0.0.50
User Language : العربية (اليمن)
User rights : Administrator
Windows folder : C:\WINDOWS
Running processes
-----------------
* C:\WINDOWS\system32\alg.exe (Microsoft Corporation)
* C:\WINDOWS\system32\CSRSS.EXE (Microsoft Corporation)
* C:\WINDOWS\system32\CTFMON.EXE (Microsoft Corporation)
C:\Program Files\NotsoSoftware\DriveDiscovery\NSSMR.EXE (Notso Software)
* C:\WINDOWS\system32\SVCHOST.EXE (Microsoft Corporation)
* C:\WINDOWS\system32\SVCHOST.EXE (Microsoft Corporation)
* C:\WINDOWS\system32\SVCHOST.EXE (Microsoft Corporation)
* C:\WINDOWS\system32\SVCHOST.EXE (Microsoft Corporation)
* C:\WINDOWS\system32\SVCHOST.EXE (Microsoft Corporation)
* C:\WINDOWS\system32\SVCHOST.EXE (Microsoft Corporation)
* C:\Documents and Settings\Hussien\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Documents and Settings\Hussien\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Documents and Settings\Hussien\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Documents and Settings\Hussien\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Program Files\HiYo\Bin\HiYo.exe (IncrediMail, Ltd.)
* C:\Program Files\Common Files\Java\Java Update\JUSCHED.EXE (Sun Microsystems, Inc.)
* C:\WINDOWS\system32\LSASS.EXE (Microsoft Corporation)
* C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
C:\Program Files\Magentic\BIN\MgApp.exe
* C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
C:\Program Files\Orbitdownloader\ORBITNET.EXE (Orbitdownloader.com)
C:\WINDOWS\RocketDock\RocketDock.exe
* C:\Zyzoom_Forum_Tools\zRunScanner.com (Runscanner.net)
* C:\WINDOWS\system32\SERVICES.EXE (Microsoft Corporation)
* C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe (Nitro PDF Software)
* C:\WINDOWS\system32\SPOOLSV.EXE (Microsoft Corporation)
* C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
* C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLSERVR.EXE (Microsoft Corporation)
* C:\WINDOWS\system32\NLSSRV32.EXE (Nalpeiron Ltd.)
* C:\WINDOWS\EXPLORER.EXE (Microsoft Corporation)
* C:\Program Files\Windows Live\Messenger\MSNMSGR.EXE (Microsoft Corporation)
* C:\Program Files\Messenger\MSMSGS.EXE (Microsoft Corporation)
* C:\WINDOWS\system32\WINLOGON.EXE (Microsoft Corporation)
* C:\WINDOWS\system32\SMSS.EXE (Microsoft Corporation)
* C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
C:\Zyzoom_Forum_Tools\zyzoom.exe
* C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
* C:\Documents and Settings\Hussien\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
Unrated items
-------------
002 C:\WINDOWS\Vistadrive\vsdrv.exe
003 C:\PROGRA~1\MAGENTIC\bin\Magentic.exe
003 C:\WINDOWS\RocketDock\RocketDock.exe
005 C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
010 C:\Program Files\HPQ\SHARED\HPQWMI.exe (HP WMI Interface)
011 C:\WINDOWS\system32\DRIVERS\tap0901.sys (TAP-Win32 Adapter V9)
011 C:\WINDOWS\System32\Drivers\SPCA561.SYS (WEB-i)
030 C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
030 C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
030 C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation) {1E66F26B-79EE-11D2-8710-00C04F79ED0D}
030 GUID / CLSID not found {B1759355-3EEC-4C1E-B0F1-B719FE26E377}
031 C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation) {0A9007C0-4076-11D3-8789-0000F8105754}
035 C:\WINDOWS\system32\mscories.dll (Microsoft Corporation) {89B4C1CD-B018-4511-B0A1-5476DBF70820}
041 C:\Program Files\Orbitdownloader\GrabPro.dll {C55BBCD6-41AD-48AD-9953-3609C48EACC7}
045 C:\Program Files\Orbitdownloader\GrabPro.dll {C55BBCD6-41AD-48AD-9953-3609C48EACC7}
052 GUID / CLSID not found {C84D72FE-E17D-4195-BB24-76C02E2E7C4E}
052 C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com) {000123B4-9B42-4900-B3F7-F4B073EFC214}
061 C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll {0561EC90-CE54-4f0c-9C55-E226110A740C}
061 C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll {5574006C-28F5-4a65-A28C-74DE6BFBE0BB}
061 C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll {327669A0-59A7-4be9-B99E-1C9F3A57611A}
061 C:\WINDOWS\system32\dfshim.dll (Microsoft Corporation) {E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}
061 C:\WINDOWS\system32\dfshim.dll (Microsoft Corporation) {e82a2d71-5b2f-43a0-97b8-81be15854de8}
061 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
062 C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll {0561EC90-CE54-4f0c-9C55-E226110A740C}
069 C:\WINDOWS\system32\mdimon.dll (Microsoft Corporation)
100 ProxyOverride HKCU : plimus.com,
,
100 Search Page HKCU :
100 SearchAssistant HKLM :
100 Start Page HKCU :
104 GUID / CLSID not found {CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
105 &Download by Orbit : res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
105 &Grab video by Orbit : res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
105 ????? ?? ?????? ??????? ?????? :
105 ????? ???? ?? ?????? ??????? ?????? :
105 ????? ????? ????? (??.??.??) ?? ?????? ??????? ?????? :
105 Do&wnload selected by Orbit : res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
105 Down&load all by Orbit : res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
105 E&xport to Microsoft Excel : res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
105 E???? ??E?? ??I?? (??.??.??) EU ??E??E IC????I ?C???? :
105 E???? C??? EU ??E??E IC????I ?C???? :
105 E???? EU ??E??E IC????I ?C???? :
105 ÊÍãíá ãÍÊæì ÝíÏíæ (ÅÝ.Åá.Ýí) ÈÜ ÅäÊÑäÊ ÏÇæäáæÏ ãÇäíÌÑ : C:\Program Files\Internet Download Manager\IEGetVL.htm
105 ÊÍãíá Çáßá ÈÜ ÅäÊÑäÊ ÏÇæäáæÏ ãÇäíÌÑ : C:\Program Files\Internet Download Manager\IEGetAll.htm
105 ÊÍãíá ÈÜ ÅäÊÑäÊ ÏÇæäáæÏ ãÇäíÌÑ : C:\Program Files\Internet Download Manager\IEExt.htm
120 NameServer {D2AD6418-529F-430E-B828-79CAA19185E8} : 192.168.1.1
170 {01911c4c-2bea-11de-92cf-00c09f473d75} : C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
170 {0909884a-b37c-11de-9358-00c09f473d75} : rundll32.exe .dll,XxKOo
170 {0909884b-b37c-11de-9358-00c09f473d75} : rundll32.exe .dll,XxKOo
170 {25b1d616-444a-11de-92f1-00c09f473d75} : G:\LaunchU3.exe -a
170 {25c3d8c3-c64b-11de-937b-00c09f473d75} : G:\start.exe
170 {2b402ce0-136d-11e0-948b-00c09f473d75} : G:\gvnwmy.pif
170 {4f5d3080-f2dc-11df-946a-00c09f473d75} : C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL CIwUT.Exe
170 {5d1ca550-0761-11de-929e-00c09f473d75} : I:\iqlwq.exe
170 {7d89d400-cf61-11de-938e-00c09f473d75} : G:\SystemVolumeInformation.exe
170 {7d89d401-cf61-11de-938e-00c09f473d75} : H:\SystemVolumeInformation.exe
170 {7d89d402-cf61-11de-938e-00c09f473d75} : I:\SystemVolumeInformation.exe
170 {7d89d403-cf61-11de-938e-00c09f473d75} : J:\SystemVolumeInformation.exe
170 {7d89d404-cf61-11de-938e-00c09f473d75} : K:\SystemVolumeInformation.exe
170 {a93bf674-019f-11de-9293-00c09f473d75} : x2tpc.cmd
171 C:\WINDOWS\system32\MAGENT~1.SCR (IncrediMail LTD.)
173 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
221 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 GUID / CLSID not found {967B2D40-8B7D-4127-9049-61EA0C2C6DCE}
225 GUID / CLSID not found {967B2D40-8B7D-4127-9049-61EA0C2C6DCE}
225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
227 GUID / CLSID not found {967B2D40-8B7D-4127-9049-61EA0C2C6DCE}
227 GUID / CLSID not found {BED4C38B-F765-45AC-8C56-613F76BBF43E}
227 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
231 C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\Haali\mmfinfo.dll Haali Column Provider
251 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
Missing files
-------------
002 C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
002 C:\Program Files\magentictb\ExeRunner.exe
002 C:\Program Files\Symantec\Norton AntiBot\agent\bin\NortonAntiBot.exe
002 C:\Program Files\SeePassword\SeePassword.exe
003 C:\Program Files\BitComet\BitComet.exe
003 C:\Program Files\Hide IP NG\hideipng.exe
003 C:\Program Files\USB Safely Remove\USBSafelyRemove.exe
011 C:\WINDOWS\system32\drivers\Abiosdsk.sys
011 C:\WINDOWS\system32\drivers\abp480n5.sys
011 C:\WINDOWS\system32\drivers\adpu160m.sys
011 C:\WINDOWS\system32\drivers\Aha154x.sys
011 C:\WINDOWS\system32\drivers\aic78u2.sys
011 C:\WINDOWS\system32\drivers\aic78xx.sys
011 C:\WINDOWS\system32\drivers\AliIde.sys
011 C:\WINDOWS\system32\drivers\amsint.sys
011 C:\WINDOWS\system32\drivers\asc.sys
011 C:\WINDOWS\system32\drivers\asc3350p.sys
011 C:\WINDOWS\system32\drivers\asc3550.sys
011 C:\WINDOWS\system32\drivers\Atdisk.sys
011 C:\WINDOWS\system32\drivers\cd20xrnt.sys
011 C:\WINDOWS\system32\drivers\Changer.sys
011 C:\WINDOWS\system32\drivers\CmdIde.sys
011 C:\WINDOWS\system32\drivers\Cpqarray.sys
011 C:\WINDOWS\system32\drivers\dac2w2k.sys
011 C:\WINDOWS\system32\drivers\dac960nt.sys
011 C:\WINDOWS\system32\drivers\dpti2o.sys
011 C:\WINDOWS\system32\drivers\hpn.sys
011 C:\WINDOWS\system32\drivers\i2omgmt.sys
011 C:\WINDOWS\system32\drivers\i2omp.sys
011 C:\WINDOWS\system32\drivers\ini910u.sys
011 C:\WINDOWS\system32\drivers\lbrtfdc.sys
011 C:\WINDOWS\system32\drivers\mraid35x.sys
011 C:\WINDOWS\system32\drivers\PCIDump.sys
011 C:\WINDOWS\system32\drivers\PDCOMP.sys
011 C:\WINDOWS\system32\drivers\PDFRAME.sys
011 C:\WINDOWS\system32\drivers\PDRELI.sys
011 C:\WINDOWS\system32\drivers\PDRFRAME.sys
011 C:\WINDOWS\system32\drivers\perc2.sys
011 C:\WINDOWS\system32\drivers\perc2hib.sys
011 C:\WINDOWS\system32\drivers\ql1080.sys
011 C:\WINDOWS\system32\drivers\Ql10wnt.sys
011 C:\WINDOWS\system32\drivers\ql12160.sys
011 C:\WINDOWS\system32\drivers\ql1240.sys
011 C:\WINDOWS\system32\drivers\ql1280.sys
011 c:\windows\system32\DRIVERS\RTL8139.SYS
011 C:\WINDOWS\system32\drivers\Simbad.sys
011 C:\WINDOWS\system32\drivers\Sparrow.sys
011 C:\WINDOWS\system32\drivers\sym_hi.sys
011 C:\WINDOWS\system32\drivers\sym_u3.sys
011 C:\WINDOWS\system32\drivers\symc810.sys
011 C:\WINDOWS\system32\drivers\symc8xx.sys
011 C:\WINDOWS\system32\drivers\TosIde.sys
011 C:\WINDOWS\system32\drivers\ultra.sys
011 C:\WINDOWS\system32\drivers\ViaIde.sys
011 C:\WINDOWS\system32\drivers\WDICA.sys
035 C:\Program Files\proxyExplorer\proxyExplor.exe
040 C:\PROGRA~1\DAP\SBSearch.dll
040 C:\Program Files\DVDVideoSoftTB\tbDVD0.dll
040 C:\Program Files\DVDVideoSoft\tbDVD0.dll
041 C:\Program Files\DVDVideoSoftTB\tbDVD0.dll
041 C:\Program Files\DVDVideoSoft\tbDVD0.dll
041 C:\Program Files\magentictb\magenticDx.dll
045 C:\Program Files\DVDVideoSoftTB\tbDVD0.dll
045 C:\Program Files\DVDVideoSoft\tbDVD0.dll
052 C:\Program Files\magentictb\auxi\magenticAu.dll
052 C:\Program Files\magentictb\magenticDx.dll
052 C:\Program Files\DVDVideoSoftTB\tbDVD0.dll
052 C:\Program Files\DVDVideoSoft\tbDVD0.dll
073 C:\Program Files\ReviverSoft\RegistryReviver\RegistryReviver.exe
104 C:\Program Files\Java\jre6\bin\npjpi160_21.dll
104 C:\Program Files\Java\jre6\bin\npjpi160_21.dll
104 C:\Program Files\Java\jre6\bin\npjpi160_21.dll