ابو عمارالرحيلي
زيزوومى مبدع
- إنضم
- 1 أغسطس 2007
- المشاركات
- 1,514
- مستوى التفاعل
- 46
- النقاط
- 680
غير متصل
من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
السلام عليكم ورحمة الله وبركاتة
ال usb كان شغال لدي ، غيرت الماذربورد وبعدها ولا اشتغل ،
حذفت التعريفات ونزلت تعريفات usb من اسطوانة التعريفات ...............
الا ان نفس المشكلة ما زالت قائمة
وهائنا ارفق لكم التقريين ...... اتمنى منكم ايجاد حل للمشكلة
تقرير ComboFix
ComboFix 08-08-29.02 - amer 08/30/2008 13:56:35.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.747 [GMT 3:00]
Running from: C:\Documents and Settings\amer\سطح المكتب\ComboFix.exe
[color=red]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-30 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-08-30 08:41 --------- d-----wC:\Documents and Settings\amer\Application Data\PCToolsSpamMonitorPlus
2008-08-30 08:41 --------- d-----wC:\Documents and Settings\amer\Application Data\PCToolsFirewallPlus
2008-08-30 08:40 --------- d-----wC:\Program Files\Common Files\PC Tools
2008-08-29 21:37 --------- d-----wC:\Program Files\SUPERAntiSpyware
2008-08-29 17:30 --------- d-----wC:\Program Files\Sunbelt Software
2008-08-29 17:30 --------- d-----wC:\Documents and Settings\amer\Application Data\Sunbelt
2008-08-29 17:30 --------- d-----wC:\Documents and Settings\All Users\Application Data\Sunbelt
2008-08-29 17:20 --------- d--h--wC:\Documents and Settings\All Users\Application Data\{069BCE30-6EC3-40CD-8DBA-EFECA88F79CC}
2008-08-28 09:00 --------- d-----wC:\Program Files\Spyware Doctor
2008-08-28 09:00 --------- d-----wC:\Documents and Settings\amer\Application Data\PC Tools
2008-08-19 22:47 15,600 ----a-wC:\WINDOWS\gdrv.sys
2008-08-18 21:47 --------- d-----wC:\Program Files\Internet Download Manager
2008-08-18 21:47 --------- d-----wC:\Documents and Settings\amer\Application Data\IDM
2008-08-18 21:47 --------- d-----wC:\Documents and Settings\amer\Application Data\DMCache
2008-08-06 16:44 --------- d-----wC:\Program Files\telephone directory
2008-08-05 20:28 --------- d-----wC:\Program Files\Hotspot Shield
2008-08-05 09:46 --------- d-----wC:\Program Files\anoooos
2008-08-04 13:05 --------- d-----wC:\Program Files\USB Disk Security
2008-08-02 11:53 --------- d-----wC:\Program Files\K-Lite Codec Pack
2008-08-01 17:47 --------- d-----wC:\Program Files\WinASO
2008-07-29 17:21 218,376 ----a-wC:\WINDOWS\system32\klogon.dll
2008-07-27 05:15 --------- d-----wC:\Program Files\ElcomSoft
2008-07-26 04:12 --------- d-----wC:\Program Files\Windows Live Safety Center
2008-07-25 16:13 --------- d-----wC:\Documents and Settings\All Users\Application Data\Avira
2008-07-25 08:35 102,464 ----a-wC:\WINDOWS\HarfDeleteFont.exe
2008-07-25 08:33 --------- d-----wC:\Program Files\Harf
2008-07-25 08:32 --------- d-----wC:\Program Files\quran
2008-07-19 14:50 --------- d-----wC:\Program Files\Sketch Master
2008-07-18 19:10 94,920 ----a-wC:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 19:10 94,920 ----a-wC:\WINDOWS\system32\cdm.dll
2008-07-18 19:10 53,448 ----a-wC:\WINDOWS\system32\wuauclt.exe
2008-07-18 19:10 53,448 ----a-wC:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 19:10 45,768 ----a-wC:\WINDOWS\system32\wups2.dll
2008-07-18 19:10 36,552 ----a-wC:\WINDOWS\system32\wups.dll
2008-07-18 19:10 36,552 ----a-wC:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 19:09 563,912 ----a-wC:\WINDOWS\system32\wuapi.dll
2008-07-18 19:09 563,912 ----a-wC:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 19:09 325,832 ----a-wC:\WINDOWS\system32\wucltui.dll
2008-07-18 19:09 325,832 ----a-wC:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 19:09 205,000 ----a-wC:\WINDOWS\system32\wuweb.dll
2008-07-18 19:09 205,000 ----a-wC:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 19:09 1,811,656 ----a-wC:\WINDOWS\system32\wuaueng.dll
2008-07-18 19:09 1,811,656 ----a-wC:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 19:07 270,880 ----a-wC:\WINDOWS\system32\mucltui.dll
2008-07-18 19:07 210,976 ----a-wC:\WINDOWS\system32\muweb.dll
2008-07-17 23:05 --------- d-----wC:\Program Files\Common Files\Wise Installation Wizard
2008-07-17 23:05 --------- d-----wC:\Program Files\AlbaniV2
2008-07-15 20:18 352,256 ----a-wC:\WINDOWS\system32\IJL151.dll
2008-07-12 23:38 --------- d-----wC:\Documents and Settings\amer\Application Data\TuneUp Software
2008-07-12 23:20 --------- d-----wC:\Program Files\VIA Technologies, INC
2008-07-10 17:04 --------- d-----wC:\Program Files\BearFlix
2008-07-07 20:27 253,952 ----a-wC:\WINDOWS\system32\es.dll
2008-07-07 20:27 253,952 ------wC:\WINDOWS\system32\dllcache\es.dll
2008-07-06 22:10 --------- d-----wC:\Program Files\Your Uninstaller 2008
2008-07-05 18:09 --------- d-----wC:\Program Files\Common Files\NSV
2008-06-30 17:03 --------- d-----wC:\Program Files\ATI Multimedia
2008-06-30 17:02 --------- d-----wC:\Program Files\Common Files\SnapStream
2008-06-30 17:02 --------- d-----wC:\Documents and Settings\All Users\Application Data\SnapStream
2008-06-30 16:38 --------- d-----wC:\Program Files\SnapStream Media
2008-06-26 08:13 617,472 ------wC:\WINDOWS\system32\dllcache\urlmon.dll
2008-06-26 08:13 1,499,136 ------wC:\WINDOWS\system32\dllcache\shdocvw.dll
2008-06-24 16:43 74,240 ----a-wC:\WINDOWS\system32\mscms.dll
2008-06-24 16:43 74,240 ------wC:\WINDOWS\system32\dllcache\mscms.dll
2008-06-23 15:10 664,576 ----a-wC:\WINDOWS\system32\wininet.dll
2008-06-23 15:10 664,576 ------wC:\WINDOWS\system32\dllcache\wininet.dll
2008-06-23 15:10 3,088,384 ------wC:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-20 20:09 148,992 ----a-wC:\WINDOWS\system32\DNSAPI(3).dll
2008-06-20 20:09 148,992 ----a-wC:\WINDOWS\system32\dnsapi(2).dll
2008-06-20 17:47 245,248 ----a-wC:\WINDOWS\system32\mswsock.dll
2008-06-20 17:47 245,248 ------wC:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:47 147,968 ------wC:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 17:39 245,248 ----a-wC:\WINDOWS\system32\mswsock(3).dll
2008-06-20 17:39 245,248 ----a-wC:\WINDOWS\system32\mswsock(2).dll
2008-06-20 11:51 361,600 ------wC:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ------wC:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ------wC:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-14 17:31 271,616 ------wC:\WINDOWS\system32\dllcache\bthport.sys
2008-06-12 18:36 7,680 ----a-wC:\WINDOWS\system32\ff_vfw.dll
2008-06-01 21:24 12,288 ----a-wC:\WINDOWS\system32\impborl.dll
2008-05-30 23:22 683,520 ----a-wC:\WINDOWS\system32\divx.dll
2008-05-22 22:22 3,596,288 ----a-wC:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:19 81,920 ----a-wC:\WINDOWS\system32\dpl100.dll
2008-05-09 10:53 90,112 ----a-wC:\WINDOWS\system32\wshext.dll
2008-05-09 10:53 90,112 ------wC:\WINDOWS\system32\dllcache\wshext.dll
2008-05-09 10:53 512,000 ------wC:\WINDOWS\system32\dllcache\jscript.dll
2008-05-09 10:53 430,080 ----a-wC:\WINDOWS\system32\vbscript.dll
2008-05-09 10:53 430,080 ------wC:\WINDOWS\system32\dllcache\vbscript.dll
2008-05-09 10:53 180,224 ----a-wC:\WINDOWS\system32\scrobj.dll
2008-05-09 10:53 180,224 ------wC:\WINDOWS\system32\dllcache\scrobj.dll
2008-05-09 10:53 172,032 ----a-wC:\WINDOWS\system32\scrrun.dll
2008-05-09 10:53 172,032 ------wC:\WINDOWS\system32\dllcache\scrrun.dll
2008-05-08 14:02 203,136 ------wC:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-08 11:24 155,648 ----a-wC:\WINDOWS\system32\wscript.exe
2008-05-08 11:24 155,648 ------wC:\WINDOWS\system32\dllcache\wscript.exe
2008-05-07 09:07 135,168 ----a-wC:\WINDOWS\system32\cscript.exe
2008-05-07 09:07 135,168 ------wC:\WINDOWS\system32\dllcache\cscript.exe
2008-05-07 05:10 1,286,144 ----a-wC:\WINDOWS\system32\quartz.dll
2008-05-07 05:10 1,286,144 ------wC:\WINDOWS\system32\dllcache\quartz.dll
2008-05-01 14:34 331,776 ------wC:\WINDOWS\system32\dllcache\msadce.dll
.
[code]<pre>
----a-w 8,009,320 2008-08-06 18:39:08 C:\Documents and Settings\amer\سطح المكتب\برامج\spywareterminatorمحطم ملفات التجسس .exe
</pre>[/code]
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"AFProg"="C:\Program Files\AnchorFree\bin\ctrl\AFController.exe" [11/20/2006 11:19 AM 81920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\system]
"NoSecCpl"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"DisableLockWorkstation"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"NoUserNameInStartMenu"= 0 (0x0)
"NoStartMenuPinnedList"= 0 (0x0)
"NoStartMenuMFUprogramsList"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinterTabs"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChange"= 0 (0x0)
"NoChangeKeyboardNavigationIndicators"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 01/11/2008 10:16 PM 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AFProg]
--a------ 11/20/2006 11:19 AM 81920 C:\Program Files\AnchorFree\bin\ctrl\AFController.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 04/14/2008 06:59 PM 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
-ra------ 05/11/2007 10:47 AM 790528 C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 04/14/2008 06:59 PM 1695232 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 04/11/2008 09:10 PM 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\MSMSGS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Paltalk Messenger\\PALTALK.EXE"=
"C:\\WINDOWS\\system32\\wjview.exe"=
"C:\\Program Files\\SnapStream Media\\Beyond TV\\BTVLibraryService.exe"=
"C:\\Program Files\\SnapStream Media\\Beyond TV\\BTVGuideDataLoader.exe"=
"C:\\Program Files\\SnapStream Media\\Beyond TV\\BTVSettingsService.exe"=
"C:\\Program Files\\SnapStream Media\\Beyond TV\\BTVTaskManagerService.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=
R0 ViBus;ViBus;C:\WINDOWS\system32\DRIVERS\ViBus.sys [03/26/2007 10:26 AM]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX3 2.sys [03/29/2007 06:36 AM]
R0 ViPrt;VIA SATA IDE Device Driver;C:\WINDOWS\system32\DRIVERS\ViPrt.sys [03/26/2007 10:26 AM]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [01/24/2008 12:25 AM]
S3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [04/17/2007 06:58 AM]
S3 SBRE;SBRE;C:\WINDOWS\system32\drivers\SBREdrv.sys []
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-08-29 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe []
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\amer\Application Data\Mozilla\Firefox\Profiles\pze0em4g.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
.
.
------- File Associations (Beta) -------
.
txtfile=C:\WINDOWS\notepad.exe %1
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-30 13:57:28
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 08/30/2008 13:57:54
ComboFix-quarantined-files.txt 2008-08-30 10:57:54
ComboFix2.txt 2008-08-30 10:54:36
Pre-Run: 18,072,584,192 bytes free
Post-Run: 18,062,753,792 bytes free
214 --- E O F --- 2008-08-29 21:58:26
تقرير hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 01:59:57 م, on 30/08/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\amer\سطح المكتب\hijackthis_199\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\s wg.dll
O2 - BHO: CEventSink Class - {B7154C4D-87C0-4A2C-AB64-DA132BAC2EE6} - C:\Program Files\AnchorFree\bin\AFBho.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: AFToolbar - {1F385865-F3D4-41ff-960D-7B7D0A7A72F6} - C:\Program Files\AnchorFree\bin\AFToolbar.dll
O4 - HKCU\..\Run: [AFProg] C:\Program Files\AnchorFree\bin\ctrl\AFController.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) -
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} -
O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} -
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} -
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
ال usb كان شغال لدي ، غيرت الماذربورد وبعدها ولا اشتغل ،
حذفت التعريفات ونزلت تعريفات usb من اسطوانة التعريفات ...............
الا ان نفس المشكلة ما زالت قائمة
وهائنا ارفق لكم التقريين ...... اتمنى منكم ايجاد حل للمشكلة
تقرير ComboFix
ComboFix 08-08-29.02 - amer 08/30/2008 13:56:35.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.747 [GMT 3:00]
Running from: C:\Documents and Settings\amer\سطح المكتب\ComboFix.exe
[color=red]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-30 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-08-30 08:41 --------- d-----wC:\Documents and Settings\amer\Application Data\PCToolsSpamMonitorPlus
2008-08-30 08:41 --------- d-----wC:\Documents and Settings\amer\Application Data\PCToolsFirewallPlus
2008-08-30 08:40 --------- d-----wC:\Program Files\Common Files\PC Tools
2008-08-29 21:37 --------- d-----wC:\Program Files\SUPERAntiSpyware
2008-08-29 17:30 --------- d-----wC:\Program Files\Sunbelt Software
2008-08-29 17:30 --------- d-----wC:\Documents and Settings\amer\Application Data\Sunbelt
2008-08-29 17:30 --------- d-----wC:\Documents and Settings\All Users\Application Data\Sunbelt
2008-08-29 17:20 --------- d--h--wC:\Documents and Settings\All Users\Application Data\{069BCE30-6EC3-40CD-8DBA-EFECA88F79CC}
2008-08-28 09:00 --------- d-----wC:\Program Files\Spyware Doctor
2008-08-28 09:00 --------- d-----wC:\Documents and Settings\amer\Application Data\PC Tools
2008-08-19 22:47 15,600 ----a-wC:\WINDOWS\gdrv.sys
2008-08-18 21:47 --------- d-----wC:\Program Files\Internet Download Manager
2008-08-18 21:47 --------- d-----wC:\Documents and Settings\amer\Application Data\IDM
2008-08-18 21:47 --------- d-----wC:\Documents and Settings\amer\Application Data\DMCache
2008-08-06 16:44 --------- d-----wC:\Program Files\telephone directory
2008-08-05 20:28 --------- d-----wC:\Program Files\Hotspot Shield
2008-08-05 09:46 --------- d-----wC:\Program Files\anoooos
2008-08-04 13:05 --------- d-----wC:\Program Files\USB Disk Security
2008-08-02 11:53 --------- d-----wC:\Program Files\K-Lite Codec Pack
2008-08-01 17:47 --------- d-----wC:\Program Files\WinASO
2008-07-29 17:21 218,376 ----a-wC:\WINDOWS\system32\klogon.dll
2008-07-27 05:15 --------- d-----wC:\Program Files\ElcomSoft
2008-07-26 04:12 --------- d-----wC:\Program Files\Windows Live Safety Center
2008-07-25 16:13 --------- d-----wC:\Documents and Settings\All Users\Application Data\Avira
2008-07-25 08:35 102,464 ----a-wC:\WINDOWS\HarfDeleteFont.exe
2008-07-25 08:33 --------- d-----wC:\Program Files\Harf
2008-07-25 08:32 --------- d-----wC:\Program Files\quran
2008-07-19 14:50 --------- d-----wC:\Program Files\Sketch Master
2008-07-18 19:10 94,920 ----a-wC:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 19:10 94,920 ----a-wC:\WINDOWS\system32\cdm.dll
2008-07-18 19:10 53,448 ----a-wC:\WINDOWS\system32\wuauclt.exe
2008-07-18 19:10 53,448 ----a-wC:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 19:10 45,768 ----a-wC:\WINDOWS\system32\wups2.dll
2008-07-18 19:10 36,552 ----a-wC:\WINDOWS\system32\wups.dll
2008-07-18 19:10 36,552 ----a-wC:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 19:09 563,912 ----a-wC:\WINDOWS\system32\wuapi.dll
2008-07-18 19:09 563,912 ----a-wC:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 19:09 325,832 ----a-wC:\WINDOWS\system32\wucltui.dll
2008-07-18 19:09 325,832 ----a-wC:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 19:09 205,000 ----a-wC:\WINDOWS\system32\wuweb.dll
2008-07-18 19:09 205,000 ----a-wC:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 19:09 1,811,656 ----a-wC:\WINDOWS\system32\wuaueng.dll
2008-07-18 19:09 1,811,656 ----a-wC:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 19:07 270,880 ----a-wC:\WINDOWS\system32\mucltui.dll
2008-07-18 19:07 210,976 ----a-wC:\WINDOWS\system32\muweb.dll
2008-07-17 23:05 --------- d-----wC:\Program Files\Common Files\Wise Installation Wizard
2008-07-17 23:05 --------- d-----wC:\Program Files\AlbaniV2
2008-07-15 20:18 352,256 ----a-wC:\WINDOWS\system32\IJL151.dll
2008-07-12 23:38 --------- d-----wC:\Documents and Settings\amer\Application Data\TuneUp Software
2008-07-12 23:20 --------- d-----wC:\Program Files\VIA Technologies, INC
2008-07-10 17:04 --------- d-----wC:\Program Files\BearFlix
2008-07-07 20:27 253,952 ----a-wC:\WINDOWS\system32\es.dll
2008-07-07 20:27 253,952 ------wC:\WINDOWS\system32\dllcache\es.dll
2008-07-06 22:10 --------- d-----wC:\Program Files\Your Uninstaller 2008
2008-07-05 18:09 --------- d-----wC:\Program Files\Common Files\NSV
2008-06-30 17:03 --------- d-----wC:\Program Files\ATI Multimedia
2008-06-30 17:02 --------- d-----wC:\Program Files\Common Files\SnapStream
2008-06-30 17:02 --------- d-----wC:\Documents and Settings\All Users\Application Data\SnapStream
2008-06-30 16:38 --------- d-----wC:\Program Files\SnapStream Media
2008-06-26 08:13 617,472 ------wC:\WINDOWS\system32\dllcache\urlmon.dll
2008-06-26 08:13 1,499,136 ------wC:\WINDOWS\system32\dllcache\shdocvw.dll
2008-06-24 16:43 74,240 ----a-wC:\WINDOWS\system32\mscms.dll
2008-06-24 16:43 74,240 ------wC:\WINDOWS\system32\dllcache\mscms.dll
2008-06-23 15:10 664,576 ----a-wC:\WINDOWS\system32\wininet.dll
2008-06-23 15:10 664,576 ------wC:\WINDOWS\system32\dllcache\wininet.dll
2008-06-23 15:10 3,088,384 ------wC:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-20 20:09 148,992 ----a-wC:\WINDOWS\system32\DNSAPI(3).dll
2008-06-20 20:09 148,992 ----a-wC:\WINDOWS\system32\dnsapi(2).dll
2008-06-20 17:47 245,248 ----a-wC:\WINDOWS\system32\mswsock.dll
2008-06-20 17:47 245,248 ------wC:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:47 147,968 ------wC:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 17:39 245,248 ----a-wC:\WINDOWS\system32\mswsock(3).dll
2008-06-20 17:39 245,248 ----a-wC:\WINDOWS\system32\mswsock(2).dll
2008-06-20 11:51 361,600 ------wC:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ------wC:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ------wC:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-14 17:31 271,616 ------wC:\WINDOWS\system32\dllcache\bthport.sys
2008-06-12 18:36 7,680 ----a-wC:\WINDOWS\system32\ff_vfw.dll
2008-06-01 21:24 12,288 ----a-wC:\WINDOWS\system32\impborl.dll
2008-05-30 23:22 683,520 ----a-wC:\WINDOWS\system32\divx.dll
2008-05-22 22:22 3,596,288 ----a-wC:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:19 81,920 ----a-wC:\WINDOWS\system32\dpl100.dll
2008-05-09 10:53 90,112 ----a-wC:\WINDOWS\system32\wshext.dll
2008-05-09 10:53 90,112 ------wC:\WINDOWS\system32\dllcache\wshext.dll
2008-05-09 10:53 512,000 ------wC:\WINDOWS\system32\dllcache\jscript.dll
2008-05-09 10:53 430,080 ----a-wC:\WINDOWS\system32\vbscript.dll
2008-05-09 10:53 430,080 ------wC:\WINDOWS\system32\dllcache\vbscript.dll
2008-05-09 10:53 180,224 ----a-wC:\WINDOWS\system32\scrobj.dll
2008-05-09 10:53 180,224 ------wC:\WINDOWS\system32\dllcache\scrobj.dll
2008-05-09 10:53 172,032 ----a-wC:\WINDOWS\system32\scrrun.dll
2008-05-09 10:53 172,032 ------wC:\WINDOWS\system32\dllcache\scrrun.dll
2008-05-08 14:02 203,136 ------wC:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-08 11:24 155,648 ----a-wC:\WINDOWS\system32\wscript.exe
2008-05-08 11:24 155,648 ------wC:\WINDOWS\system32\dllcache\wscript.exe
2008-05-07 09:07 135,168 ----a-wC:\WINDOWS\system32\cscript.exe
2008-05-07 09:07 135,168 ------wC:\WINDOWS\system32\dllcache\cscript.exe
2008-05-07 05:10 1,286,144 ----a-wC:\WINDOWS\system32\quartz.dll
2008-05-07 05:10 1,286,144 ------wC:\WINDOWS\system32\dllcache\quartz.dll
2008-05-01 14:34 331,776 ------wC:\WINDOWS\system32\dllcache\msadce.dll
.
[code]<pre>
----a-w 8,009,320 2008-08-06 18:39:08 C:\Documents and Settings\amer\سطح المكتب\برامج\spywareterminatorمحطم ملفات التجسس .exe
</pre>[/code]
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"AFProg"="C:\Program Files\AnchorFree\bin\ctrl\AFController.exe" [11/20/2006 11:19 AM 81920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\system]
"NoSecCpl"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"DisableLockWorkstation"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"NoUserNameInStartMenu"= 0 (0x0)
"NoStartMenuPinnedList"= 0 (0x0)
"NoStartMenuMFUprogramsList"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinterTabs"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChange"= 0 (0x0)
"NoChangeKeyboardNavigationIndicators"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 01/11/2008 10:16 PM 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AFProg]
--a------ 11/20/2006 11:19 AM 81920 C:\Program Files\AnchorFree\bin\ctrl\AFController.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 04/14/2008 06:59 PM 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
-ra------ 05/11/2007 10:47 AM 790528 C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 04/14/2008 06:59 PM 1695232 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 04/11/2008 09:10 PM 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\MSMSGS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Paltalk Messenger\\PALTALK.EXE"=
"C:\\WINDOWS\\system32\\wjview.exe"=
"C:\\Program Files\\SnapStream Media\\Beyond TV\\BTVLibraryService.exe"=
"C:\\Program Files\\SnapStream Media\\Beyond TV\\BTVGuideDataLoader.exe"=
"C:\\Program Files\\SnapStream Media\\Beyond TV\\BTVSettingsService.exe"=
"C:\\Program Files\\SnapStream Media\\Beyond TV\\BTVTaskManagerService.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=
R0 ViBus;ViBus;C:\WINDOWS\system32\DRIVERS\ViBus.sys [03/26/2007 10:26 AM]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX3 2.sys [03/29/2007 06:36 AM]
R0 ViPrt;VIA SATA IDE Device Driver;C:\WINDOWS\system32\DRIVERS\ViPrt.sys [03/26/2007 10:26 AM]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [01/24/2008 12:25 AM]
S3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [04/17/2007 06:58 AM]
S3 SBRE;SBRE;C:\WINDOWS\system32\drivers\SBREdrv.sys []
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
s of the 'Scheduled Tasks' folder
2008-08-29 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe []
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\amer\Application Data\Mozilla\Firefox\Profiles\pze0em4g.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
.
.
------- File Associations (Beta) -------
.
txtfile=C:\WINDOWS\notepad.exe %1
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
Rootkit scan 2008-08-30 13:57:28
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 08/30/2008 13:57:54
ComboFix-quarantined-files.txt 2008-08-30 10:57:54
ComboFix2.txt 2008-08-30 10:54:36
Pre-Run: 18,072,584,192 bytes free
Post-Run: 18,062,753,792 bytes free
214 --- E O F --- 2008-08-29 21:58:26
تقرير hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 01:59:57 م, on 30/08/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\amer\سطح المكتب\hijackthis_199\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\s wg.dll
O2 - BHO: CEventSink Class - {B7154C4D-87C0-4A2C-AB64-DA132BAC2EE6} - C:\Program Files\AnchorFree\bin\AFBho.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: AFToolbar - {1F385865-F3D4-41ff-960D-7B7D0A7A72F6} - C:\Program Files\AnchorFree\bin\AFToolbar.dll
O4 - HKCU\..\Run: [AFProg] C:\Program Files\AnchorFree\bin\ctrl\AFController.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
