ما قصرت يا بوب والصراحة دورت علاج لها المشكله مالقيته الا عندكم
أشرح لكم مشكلتي انا تتطلعلي الرساله ( خطأ في البيانات تدقيق دوري للفائض )
مثل ميسو لاكن مو في أي نسخ إنما في احد الهاردسكين اللي عندي -عندي هاردسكين- و - وندوز xp -
الهارسك الاول اللي عليه الوندز قسمين
C) و
D) وهذاالهارسك سليم 100%
الهارسك الثاني اللي طلعلي نخله في راسي مقسم
F) و
G) وهذا اللي فيه نفس المشكله ,
إذا جيت تنسخ أي شي من
F) أو
G) ولو صوره يطلع لك هذي الرساله ( خطأ في البيانات تدقيق دوري للفائض )
وأنا سويت فحص بأداة ComboFix.exe وهذا التقرير :
ComboFix 10-02-03.07 - Administrator 02/04/2010 18:42:44.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.3061.2630 [GMT 3:00]
Running from: c:\documents and settings\Administrator\سطح المكتب\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2010-01-04 to 2010-02-04 )))))))))))))))))))))))))))))))
.
2010-02-04 15:33 . 2010-02-04 15:33 -------- d-----w- c:\documents and settings\Administrator\Application Data\Moyea
2010-02-04 13:25 . 2006-01-18 10:55 290918 ----a-w- c:\windows\system32\Install7x.dll
2010-02-04 13:25 . 2005-10-17 16:50 245376 ----a-w- c:\windows\system32\drivers\rt2500usb.SYS
2010-02-04 13:25 . 2005-05-17 13:24 311296 ----a-w- c:\windows\system32\AegisI5.exe
2010-02-04 13:25 . 2006-01-12 16:46 252928 ----a-w- c:\windows\system32\drivers\rt73.sys
2010-02-04 13:25 . 2005-11-30 08:33 2048 ----a-w- c:\windows\system32\drivers\rt73.bin
2010-02-04 13:24 . 2010-02-04 13:24 20747 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-02-04 13:24 . 2010-02-04 13:24 -------- d-----w- c:\program files\TP-LINK
2010-02-02 05:18 . 2007-02-06 20:06 544640 ----a-w- c:\windows\system32\ar5211.sys
2010-02-02 05:17 . 2010-02-02 05:17 -------- d-----w- c:\documents and settings\All Users\Application Data\TP-LINK
2010-01-30 19:05 . 2010-02-01 06:18 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2010-01-20 14:37 . 2001-09-18 10:38 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2010-01-20 14:37 . 2001-09-18 10:38 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-01-20 14:37 . 2001-08-17 11:02 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2010-01-20 14:37 . 2001-08-17 11:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-01-13 16:45 . 2010-01-13 16:45 -------- d-----w- c:\documents and settings\Administrator\Application Data\ESET
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-04 15:29 . 2001-09-19 12:00 40118 ----a-w- c:\windows\system32\perfc001.dat
2010-02-04 15:29 . 2001-09-19 12:00 251674 ----a-w- c:\windows\system32\perfh001.dat
2010-02-04 13:24 . 2009-12-15 09:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-04 13:10 . 2009-12-15 10:45 -------- d-----w- c:\program files\TuneUp Utilities 2009
2010-01-13 16:44 . 2009-12-15 10:00 -------- d-----w- c:\program files\ESET
2010-01-13 16:44 . 2009-12-15 10:00 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2010-01-05 18:15 . 2009-12-23 02:10 376832 ----a-w- c:\windows\system32\AegisI5Installer.exe
2009-12-26 23:41 . 2009-12-19 18:11 -------- d-----w- c:\documents and settings\Administrator\Application Data\Skype
2009-12-26 10:41 . 2009-12-26 10:41 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-26 10:41 . 2009-12-26 10:41 -------- d-----w- c:\documents and settings\Administrator\Application Data\skypePM
2009-12-24 11:48 . 2009-12-24 11:48 0 ----a-w- c:\windows\nsreg.dat
2009-12-23 16:27 . 2009-12-23 02:26 -------- d-----w- c:\program files\Ask.com
2009-12-23 16:27 . 2009-12-15 10:34 -------- d-----w- c:\program files\ClocX
2009-12-23 16:27 . 2009-12-15 10:33 -------- d-----w- c:\program files\mpegable
2009-12-23 05:32 . 2009-12-23 05:32 -------- d-----w- c:\program files\Google
2009-12-23 02:25 . 2009-12-23 02:25 -------- d-----w- c:\documents and settings\Administrator\Application Data\Paltalk
2009-12-23 02:25 . 2009-12-19 18:12 -------- d-----w- c:\program files\Paltalk Messenger
2009-12-22 09:49 . 2009-12-15 09:10 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-21 11:47 . 2009-12-21 11:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-12-20 20:48 . 2009-12-20 20:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\GRETECH
2009-12-20 12:25 . 2009-12-20 12:25 -------- d-----w- c:\documents and settings\Administrator\Application Data\ACD Systems
2009-12-20 10:25 . 2009-12-20 10:25 -------- d-----w- c:\documents and settings\Administrator\Application Data\AlMAdinahMushaf
2009-12-20 09:37 . 2009-12-15 10:13 336656 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-19 21:37 . 2009-12-19 21:37 -------- d-----w- c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-12-19 18:11 . 2009-12-19 18:11 -------- d-----w- c:\program files\Skype
2009-12-19 18:11 . 2009-12-19 18:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-12-19 18:11 . 2009-12-19 18:11 -------- d-----w- c:\program files\Common Files\Skype
2009-12-15 10:45 . 2009-12-15 10:45 603904 ----a-w- c:\windows\system32\TUProgSt.exe
2009-12-15 10:45 . 2009-12-15 10:45 362240 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-12-15 10:45 . 2009-12-15 10:45 -------- d-----w- c:\documents and settings\Administrator\Application Data\TuneUp Software
2009-12-15 10:45 . 2009-12-15 10:45 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-12-15 10:45 . 2009-12-15 10:45 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-12-15 10:34 . 2009-12-15 10:34 -------- d-----w- c:\program files\Common Files\Real
2009-12-15 10:34 . 2009-12-15 10:34 -------- d-----w- c:\program files\Common Files\xing shared
2009-12-15 10:34 . 2009-12-15 10:32 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-12-15 10:34 . 2009-12-15 10:32 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-12-15 10:34 . 2009-12-15 10:34 -------- d-----w- c:\program files\Real
2009-12-15 10:33 . 2009-12-15 10:33 47104 ------w- c:\windows\AKDeInstall.exe
2009-12-15 10:32 . 2009-12-15 10:32 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-12-15 10:29 . 2009-12-15 10:29 -------- d-----w- c:\program files\GRETECH
2009-12-15 10:28 . 2009-12-15 10:28 -------- d-----w- c:\program files\Moyea
2009-12-15 10:26 . 2009-12-15 10:20 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-12-15 10:20 . 2009-12-15 10:20 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-12-15 10:20 . 2009-12-15 10:19 -------- d-----w- c:\program files\مصحف المدينة النبوية
2009-12-15 10:20 . 2009-12-15 09:30 -------- d-----w- c:\program files\Common Files\InstallShield
2009-12-15 10:16 . 2009-12-15 10:16 -------- d-----w- c:\program files\CCleaner
2009-12-15 10:13 . 2009-12-15 10:13 -------- d-----w- c:\program files\Messenger Plus! Live
2009-12-15 10:11 . 2009-12-15 10:11 -------- d-----w- c:\program files\Windows Live
2009-12-15 10:09 . 2009-12-15 10:09 -------- d-----w- c:\program files\Java
2009-12-15 10:09 . 2009-12-15 10:09 -------- d-----w- c:\program files\Common Files\Java
2009-12-15 10:06 . 2009-12-15 10:06 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-12-15 10:05 . 2009-12-15 09:52 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-15 10:04 . 2009-12-15 10:04 2232 ----a-w- c:\windows\java\Packages\Data\5VVPNLRF.DAT
2009-12-15 10:04 . 2009-12-15 10:04 155995 ----a-w- c:\windows\java\Packages\D3BNF9V9.ZIP
2009-12-15 10:04 . 2009-12-15 10:04 2678 ----a-w- c:\windows\java\Packages\Data\B1VF3JHB.DAT
2009-12-15 10:04 . 2009-12-15 10:04 2678 ----a-w- c:\windows\java\Packages\Data\XN5FH3VV.DAT
2009-12-15 10:04 . 2009-12-15 10:04 2678 ----a-w- c:\windows\java\Packages\Data\TBLVNZ71.DAT
2009-12-15 10:04 . 2009-12-15 10:04 2678 ----a-w- c:\windows\java\Packages\Data\FTF7B797.DAT
2009-12-15 10:04 . 2009-12-15 10:04 2678 ----a-w- c:\windows\java\Packages\Data\5ZFZ75B7.DAT
2009-12-15 10:03 . 2009-12-15 10:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Macrovision
2009-12-15 10:01 . 2009-12-15 10:01 -------- d-----w- c:\program files\Common Files\Macromedia Shared
2009-12-15 10:01 . 2009-12-15 10:01 -------- d-----w- c:\program files\Common Files\Macromedia
2009-12-15 10:01 . 2009-12-15 10:01 -------- d-----w- c:\program files\Macromedia
2009-12-15 10:01 . 2009-12-15 10:01 90112 ----a-w- c:\windows\system32\agsaami.dll
2009-12-15 10:01 . 2009-12-15 10:01 610304 ----a-w- c:\windows\system32\agsaamg.dll
2009-12-15 10:01 . 2009-12-15 10:01 372736 ----a-w- c:\windows\system32\agsaamc.dll
2009-12-15 10:01 . 2009-12-15 10:01 2535424 ----a-w- c:\windows\system32\agsaamj.dll
2009-12-15 10:01 . 2009-12-15 10:01 1986560 ----a-w- c:\windows\system32\akll.dll
2009-12-15 10:01 . 2009-12-15 10:01 196608 ----a-w- c:\windows\system32\maag.dll
2009-12-15 10:01 . 2009-12-15 10:01 1245184 ----a-w- c:\windows\system32\bkll.dll
2009-12-15 10:01 . 2009-12-15 10:01 1212416 ----a-w- c:\windows\system32\ckll.dll
2009-12-15 10:01 . 2009-12-15 10:00 -------- d-----w- c:\program files\Real_SC
2009-12-15 09:57 . 2009-12-15 09:57 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-12-15 09:57 . 2009-12-15 09:57 -------- d-----w- c:\documents and settings\All Users\Application Data\ACD Systems
2009-12-15 09:57 . 2009-12-15 09:57 -------- d-----w- c:\program files\ACD Systems
2009-12-15 09:51 . 2009-12-15 09:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-15 09:51 . 2009-12-15 09:51 -------- d-----w- c:\program files\Microsoft Works
2009-12-15 09:51 . 2009-12-15 09:51 -------- d-----w- c:\program files\MSBuild
2009-12-15 09:32 . 2009-12-15 09:30 -------- d-----w- c:\program files\Realtek
2009-12-15 09:32 . 2009-12-15 09:32 -------- d-----w- c:\documents and settings\Administrator\Application Data\InstallShield
2009-12-15 09:32 . 2009-12-15 09:27 16608 ----a-w- c:\windows\gdrv.sys
2009-12-15 09:27 . 2009-12-15 09:27 -------- d-----w- c:\program files\Intel
2009-12-15 09:11 . 2009-12-15 09:11 -------- d-----w- c:\program files\microsoft frontpage
2009-12-15 09:09 . 2009-12-15 09:09 22144 ----a-w- c:\windows\system32\emptyregdb.dat
2009-11-16 06:06 . 2009-11-16 06:06 55768 ----a-w- c:\windows\system32\drivers\epfwtdi.sys
2009-11-16 06:06 . 2009-11-16 06:06 135048 ----a-w- c:\windows\system32\drivers\epfw.sys
2009-11-16 06:03 . 2009-11-16 06:03 108792 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-11-16 05:56 . 2009-11-16 05:56 116520 ----a-w- c:\windows\system32\drivers\eamon.sys
.
(((((((((((((((((((((((((((((
SnapShot@2010-02-04_14.54.49 )))))))))))))))))))))))))))))))))))))))))
.
- 2001-09-19 12:00 . 2010-02-04 13:31 40128 c:\windows\system32\perfc009.dat
+ 2001-09-19 12:00 . 2010-02-04 15:29 40128 c:\windows\system32\perfc009.dat
+ 2001-09-19 12:00 . 2010-02-04 15:29 311740 c:\windows\system32\perfh009.dat
- 2001-09-19 12:00 . 2010-02-04 13:31 311740 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-07-10 14:28 1174920 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-23 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-11-24 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-11-24 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-11-24 141336]
"RTHDCPL"="RTHDCPL.EXE" [2009-01-13 18084864]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [2009-12-15 77824]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-12-15 198160]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-11-16 2054360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-12-15 113664]
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2009-12-3 11552768]
TL-WN321G Wireless Utility.lnk - c:\program files\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe [2010-2-4 622592]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [16/11/2009 09:03 ص 108792]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [16/11/2009 09:04 ص 735960]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-02-04 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 13:28]
2010-02-04 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-07-10 14:29]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: ت&صدير إلى Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xtdnp0au.default\
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2010-02-04 18:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1124)
c:\windows\system32\igfxdev.dll
- - - - - - - > 'explorer.exe'(3096)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-02-04 18:46:23
ComboFix-quarantined-files.txt 2010-02-04 15:46
ComboFix2.txt 2010-02-04 14:55
Pre-Run: 73,863,327,744 bytes free
Post-Run: 73,834,708,992 bytes free
- - End Of File - - 1806DDAF1D7C8F8B966FA8CF693FBE2B
وهذا تقرير الـ هايجـاك :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:19:31 م, on 05/02/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Paltalk Messenger\paltalk.exe
C:\Program Files\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Paltalk Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
O4 - Global Startup: TL-WN321G Wireless Utility.lnk = C:\Program Files\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O8 - Extra context menu item: ت&صدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
--
End of file - 6538 bytes
..............................................
مع كل الشكر والتقدير لك اخي بوب