تفضل اخوي هذا تقريير
:
************' Anti-Malware 1.50.1.1100
Database version: 6112
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.11
24/03/2011 06:41:30 م
mbam-log-2011-03-24 (18-41-30).txt
Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 212267
Time elapsed: 1 hour(s), 21 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe (Security.Hijack) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
بعدها سويت ريستارت وسويت تقرير رن سكانر وهذا هو التقرير :
Runscanner logfile
* = signed file
- = file not found
General info
------------
Computer name : MONTE
Creation time : 24/03/2011 06:49:04 م
Hosts <> 127.0.0.1 : 0
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 7.0.5730.11
OS : Microsoft Windows XP
OS Build : 2600
OS SP : Service Pack 2
RunScanner Version : 2.0.0.50
User Language : Arabic (Egypt)
User rights : Administrator
Windows folder : C:\WINDOWS
Running processes
-----------------
* C:\WINDOWS\system32\csrss.exe (Microsoft Corporation)
* C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
* C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
* C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
* C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
* C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
C:\WINDOWS\system32\mmm.exe
* C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
* C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
* C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
* C:\Zyzoom_Forum_Tools\zRunScanner.com (Runscanner.net)
* C:\WINDOWS\system32\services.exe (Microsoft Corporation)
* C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation)
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (Alexander Avdonin)
C:\Program Files\Unlocker\UnlockerAssistant.exe
* C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtblfs.exe (Kaspersky Lab ZAO)
* C:\WINDOWS\explorer.exe (Microsoft Corporation)
* C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
* C:\WINDOWS\system32\winlogon.exe (Microsoft Corporation)
* C:\WINDOWS\system32\smss.exe (Microsoft Corporation)
* C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
* C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
* C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\Zyzoom_Forum_Tools\zyzoom.exe
Unrated items
-------------
002 C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
002 C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
002 C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
002 C:\WINDOWS\system32\mmm.exe
002 C:\Program Files\Unlocker\UnlockerAssistant.exe
003 C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (Alexander Avdonin)
005 C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
008 C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (Alexander Avdonin)
011 C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (ialm)
011 C:\Program Files\Unlocker\UnlockerDriver5.sys (UnlockerDriver5)
012 C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (Alexander Avdonin)
012 C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (Alexander Avdonin)
012 C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (Alexander Avdonin)
040 * C:\Program Files\Messenger_Plus\prxtbMes0.dll (Conduit Ltd.) {b760d5a4-8d24-4cb6-942e-d6bb540ad88c}
041 * C:\Program Files\ConduitEngine\prxConduitEngin0.dll (Conduit Ltd.) {30F9B915-B755-4826-820B-08FBA6BD249D}
041 * C:\Program Files\Messenger_Plus\prxtbMes0.dll (Conduit Ltd.) {b760d5a4-8d24-4cb6-942e-d6bb540ad88c}
045 * C:\Program Files\Messenger_Plus\prxtbMes0.dll (Conduit Ltd.) {B760D5A4-8D24-4CB6-942E-D6BB540AD88C}
052 GUID / CLSID not found {5C255C8A-E604-49b4-9D64-90988571CECB}
052 * C:\Program Files\ConduitEngine\prxConduitEngin0.dll (Conduit Ltd.) {30F9B915-B755-4826-820B-08FBA6BD249D}
052 * C:\Program Files\Messenger_Plus\prxtbMes0.dll (Conduit Ltd.) {b760d5a4-8d24-4cb6-942e-d6bb540ad88c}
052 * C:\PROGRA~1\LEAPFT~1.0\lftpie.dll (LeapWare) {A5479DA1-7843-43A7-B5C0-BE342C77B629}
061 C:\WINDOWS\system32\ShellExt\BrowserBack.dll {DD23BD50-C784-4557-BE82-1B3FDDB22CA5}
061 C:\WINDOWS\system32\ShellExt\CmdOpen.dll (ktechcomputing.com) {693B08DA-DA1F-4f2b-A145-C06BDF01868A}
061 C:\WINDOWS\system32\ShellExt\CopyToSendTo.dll {51131DA7-1D24-40e5-AE07-5E3750F5DE3C}
061 C:\WINDOWS\system32\ShellExt\MEFlCase.dll (Synesis Software (Pty) Ltd) {00537963-0001-0002-0004-00c0dfe64a64}
061 C:\WINDOWS\system32\ShellExt\FileExtToggle.dll {D8E899D8-A7B3-449C-BFDF-761FC5826313}
061 C:\WINDOWS\system32\ShellExt\FindTarget.dll {97F6E51A-2934-4297-B06C-1CCCA326C5E6}
061 C:\WINDOWS\system32\ShellExt\HashTab.dll (Beeblebrox.org) {8A56567E-A333-4843-B6E1-C3A262E41D8C}
061 C:\WINDOWS\system32\ShellExt\HiddenFilesToggle.dll {AC67E92C-D916-4058-A7B8-0913746592F4}
061 * C:\PROGRA~1\LEAPFT~1.0\lftpshl.dll (LeapWare) {724B06C1-D4EE-11D5-8B17-000103219699}
061 C:\WINDOWS\system32\ShellExt\MIPSE.dll (MiTeC) {581A1B6A-A15F-4691-81B8-A734164AB749}
061 C:\WINDOWS\system32\ShellExt\phototoy.dll (Microsoft Corporation) {1530f7ee-5128-43bd-9977-84a4b0fad7df}
061 C:\WINDOWS\system32\ShellExt\MERunPrg.dll (Synesis Software (Pty) Ltd) {00537963-0001-0004-0004-00c0dfe64a64}
061 C:\WINDOWS\system32\ShellExt\SelectAll.dll {A0F26623-302C-41E1-B00C-04EE54A3188C}
061 C:\WINDOWS\system32\wshext.dll (Microsoft Corporation) {60254CA5-953B-11CF-8C96-00AA00B8708C}
061 C:\Program Files\Unlocker\UnlockerCOM.dll {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}
061 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
067 C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
100 Start Page HKCU :
104 GUID / CLSID not found {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
105 إضافة إلى مكافحة الشعارات : C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm
170 {dddc8c23-414a-11e0-ab29-0016e663e051} : G:\ttfesn.pif
173 GUID / CLSID not found {0A435D73-6459-4b87-971D-0EEBFD2495BA}
173 C:\Program Files\Attribute Changer\acshell.dll (Romain Petges) {D3F9A525-8824-497A-BE36-B23E22F141FC}
173 C:\WINDOWS\system32\ShellExt\ClipName.dll (MainSoft sarl) {8C98C830-429E-11d3-8EBE-00A0249EABF4}
173 C:\WINDOWS\system32\ShellExt\CopyToSendTo.dll {51131DA7-1D24-40e5-AE07-5E3750F5DE3C}
173 C:\WINDOWS\system32\ShellExt\MEFlCase.dll (Synesis Software (Pty) Ltd) {00537963-0001-0002-0004-00c0dfe64a64}
173 C:\WINDOWS\system32\ShellExt\MIPSE.dll (MiTeC) {581A1B6A-A15F-4691-81B8-A734164AB749}
173 C:\Program Files\NotePad++\nppcm.dll (Burgaud.com) {120B94B5-2E6A-4F13-94D0-414BCB64FA0F}
173 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
221 GUID / CLSID not found {0A435D73-6459-4b87-971D-0EEBFD2495BA}
221 C:\Program Files\Attribute Changer\acshell.dll (Romain Petges) {D3F9A525-8824-497A-BE36-B23E22F141FC}
221 C:\WINDOWS\system32\ShellExt\ClipName.dll (MainSoft sarl) {8C98C830-429E-11d3-8EBE-00A0249EABF4}
221 C:\WINDOWS\system32\ShellExt\CopyToSendTo.dll {51131DA7-1D24-40e5-AE07-5E3750F5DE3C}
221 C:\WINDOWS\system32\ShellExt\MEFlCase.dll (Synesis Software (Pty) Ltd) {00537963-0001-0002-0004-00c0dfe64a64}
221 C:\WINDOWS\system32\ShellExt\MIPSE.dll (MiTeC) {581A1B6A-A15F-4691-81B8-A734164AB749}
221 C:\Program Files\NotePad++\nppcm.dll (Burgaud.com) {120B94B5-2E6A-4F13-94D0-414BCB64FA0F}
221 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
223 C:\Program Files\Unlocker\UnlockerCOM.dll {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}
225 C:\WINDOWS\system32\ShellExt\ClipName.dll (MainSoft sarl) {8C98C830-429E-11d3-8EBE-00A0249EABF4}
225 C:\WINDOWS\system32\ShellExt\ClipName.dll (MainSoft sarl) {8C98C830-429E-11d3-8EBE-00A0249EABF4}
225 C:\WINDOWS\system32\ShellExt\CopyToSendTo.dll {51131DA7-1D24-40e5-AE07-5E3750F5DE3C}
225 C:\WINDOWS\system32\ShellExt\CopyToSendTo.dll {51131DA7-1D24-40e5-AE07-5E3750F5DE3C}
225 C:\Program Files\Unlocker\UnlockerCOM.dll {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}
225 C:\Program Files\Unlocker\UnlockerCOM.dll {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}
225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
227 GUID / CLSID not found {0A435D73-6459-4b87-971D-0EEBFD2495BA}
227 C:\Program Files\Attribute Changer\acshell.dll (Romain Petges) {D3F9A525-8824-497A-BE36-B23E22F141FC}
227 C:\WINDOWS\system32\ShellExt\CmdOpen.dll (ktechcomputing.com) {693B08DA-DA1F-4f2b-A145-C06BDF01868A}
227 C:\WINDOWS\system32\ShellExt\CopyToSendTo.dll {51131DA7-1D24-40e5-AE07-5E3750F5DE3C}
227 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
229 C:\WINDOWS\system32\ShellExt\BrowserBack.dll {DD23BD50-C784-4557-BE82-1B3FDDB22CA5}
229 C:\WINDOWS\system32\ShellExt\CmdOpen.dll (ktechcomputing.com) {693B08DA-DA1F-4f2b-A145-C06BDF01868A}
229 C:\WINDOWS\system32\ShellExt\FileExtToggle.dll {D8E899D8-A7B3-449C-BFDF-761FC5826313}
229 C:\WINDOWS\system32\ShellExt\HiddenFilesToggle.dll {AC67E92C-D916-4058-A7B8-0913746592F4}
229 C:\WINDOWS\system32\igfxpph.dll (Intel Corporation) {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4}
229 C:\WINDOWS\system32\ShellExt\SelectAll.dll {A0F26623-302C-41E1-B00C-04EE54A3188C}
251 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
Missing files
-------------
002 C:\Program Files\Vista Drive Icon\DrvIcon.exe
011 C:\WINDOWS\system32\drivers\Abiosdsk.sys
011 C:\WINDOWS\system32\drivers\abp480n5.sys
011 C:\WINDOWS\system32\drivers\adpu160m.sys
011 C:\WINDOWS\system32\drivers\Aha154x.sys
011 C:\WINDOWS\system32\drivers\aic78u2.sys
011 C:\WINDOWS\system32\drivers\aic78xx.sys
011 C:\WINDOWS\system32\drivers\AliIde.sys
011 C:\WINDOWS\system32\drivers\amsint.sys
011 C:\WINDOWS\system32\drivers\asc.sys
011 C:\WINDOWS\system32\drivers\asc3350p.sys
011 C:\WINDOWS\system32\drivers\asc3550.sys
011 C:\WINDOWS\system32\drivers\Atdisk.sys
011 C:\WINDOWS\system32\drivers\cd20xrnt.sys
011 C:\WINDOWS\system32\drivers\Changer.sys
011 C:\WINDOWS\system32\drivers\CmdIde.sys
011 C:\WINDOWS\system32\drivers\Cpqarray.sys
011 C:\WINDOWS\system32\drivers\dac2w2k.sys
011 C:\WINDOWS\system32\drivers\dac960nt.sys
011 C:\WINDOWS\system32\drivers\dpti2o.sys
011 C:\WINDOWS\system32\drivers\hpn.sys
011 C:\WINDOWS\system32\drivers\i2omgmt.sys
011 C:\WINDOWS\system32\drivers\i2omp.sys
011 C:\WINDOWS\system32\drivers\ini910u.sys
011 C:\WINDOWS\system32\drivers\IntelIde.sys
011 C:\WINDOWS\system32\drivers\lbrtfdc.sys
011 C:\WINDOWS\system32\drivers\mraid35x.sys
011 C:\WINDOWS\system32\drivers\PCIDump.sys
011 C:\WINDOWS\system32\drivers\PDCOMP.sys
011 C:\WINDOWS\system32\drivers\PDFRAME.sys
011 C:\WINDOWS\system32\drivers\PDRELI.sys
011 C:\WINDOWS\system32\drivers\PDRFRAME.sys
011 C:\WINDOWS\system32\drivers\perc2.sys
011 C:\WINDOWS\system32\drivers\perc2hib.sys
011 C:\WINDOWS\system32\drivers\ql1080.sys
011 C:\WINDOWS\system32\drivers\Ql10wnt.sys
011 C:\WINDOWS\system32\drivers\ql12160.sys
011 C:\WINDOWS\system32\drivers\ql1240.sys
011 C:\WINDOWS\system32\drivers\ql1280.sys
011 C:\WINDOWS\system32\drivers\Simbad.sys
011 C:\WINDOWS\system32\drivers\Sparrow.sys
011 C:\WINDOWS\system32\drivers\sym_hi.sys
011 C:\WINDOWS\system32\drivers\sym_u3.sys
011 C:\WINDOWS\system32\drivers\symc810.sys
011 C:\WINDOWS\system32\drivers\symc8xx.sys
011 C:\WINDOWS\system32\drivers\TosIde.sys
011 C:\WINDOWS\system32\drivers\ultra.sys
011 C:\WINDOWS\system32\drivers\ViaIde.sys
011 C:\WINDOWS\system32\drivers\WDICA.sys
061 deskpan.dll
171 C:\WINDOWS\System32\logon.scr
176 drwtsn32
في انتظارك
وشكرا