السلام عليكم ,
الحمدلله قدرت ادخل السيف مود و جبت تقرير للـ هيجاك و رن سكانر
الهيجاك :
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:22:27 MNS, on 10/07/2012
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18639)
Boot mode: Safe mode
Running processes:
C:\Windows\Explorer.EXE
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Zyzoom_Forum_Tools\zHijak.com
C:\Windows\system32\wbem\unsecapp.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\ChatZum Toolbar\tbunsiFA93.tmp\tbhelper.dll
O1 - Hosts: ::1 localhost
O1 - Hosts: 63.146.124.21 cod4master.activision.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\ChatZum Toolbar\tbunsiFA93.tmp\tbcore3.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: ChatZum Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\ChatZum Toolbar\tbunsiFA93.tmp\tbcore3.dll
O4 - HKCU\..\Run: [IDMan] C:\Users\XMNS\AppData\Local\Temp\Rar$EXa0.996\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-GB\local\search.html
O8 - Extra context menu item: Download all links with IDM - C:\Users\XMNS\AppData\Local\Temp\Rar$EXa0.996\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Users\XMNS\AppData\Local\Temp\Rar$EXa0.996\IEExt.htm
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Hotspot Shield Service (hshld) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files\Hotspot Shield\bin\hsswd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 9169 bytes
الرن سكانر :
Runscanner logfile
* = signed file
- = file not found
General info
------------
Computer name : XMNS-PC
Creation time : 10/07/2012 12:23:10 MNS
Hosts <> 127.0.0.1 : 1
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 7.0.6001.18000
OS : Windows Vista (TM) Home Premium
OS Build : 6001
OS SP : Service Pack 1
RunScanner Version : 2.0.0.50
User Language : English (United Kingdom)
User rights : Administrator
Windows folder : C:\Windows
Running processes
-----------------
* C:\WINDOWS\System32\csrss.exe (Microsoft Corporation)
* C:\WINDOWS\System32\csrss.exe (Microsoft Corporation)
* C:\WINDOWS\System32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\System32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\System32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\System32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\System32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\System32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\System32\lsass.exe (Microsoft Corporation)
* C:\WINDOWS\System32\lsm.exe (Microsoft Corporation)
* C:\WINDOWS\System32\services.exe (Microsoft Corporation)
* C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
* C:\WINDOWS\explorer.exe (Microsoft Corporation)
* C:\WINDOWS\System32\winlogon.exe (Microsoft Corporation)
* C:\WINDOWS\System32\smss.exe (Microsoft Corporation)
* C:\WINDOWS\System32\wininit.exe (Microsoft Corporation)
* C:\WINDOWS\System32\wbem\WmiPrvSE.exe (Microsoft Corporation)
* C:\WINDOWS\System32\wbem\WmiPrvSE.exe (Microsoft Corporation)
C:\Zyzoom_Forum_Tools\zyzoom.exe
Unrated items
-------------
010 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Com for QLB software)
010 * C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (Hamachi Client Tunneling Engine)
010 c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (HP Health Check Service)
010 C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (hpqwmiex Module)
010 * C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (hsssrv.exe)
010 * C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE (HssTrayService.EXE)
010 * C:\Program Files\Hotspot Shield\bin\hsswd.exe (hsswd.exe)
010 C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (IDriverT Module)
010 * C:\Program Files\Hotspot Shield\bin\openvpnas.exe (openvpnas.exe)
010 * C:\Program Files\Skype\Updater\Updater.exe (Skype Updater Service)
010 * C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (SwitchBoard Server (32 bit))
010 C:\Windows\System32\shsvcs.dll (Windows Shell Services Dll)
010 C:\Windows\System32\shsvcs.dll (Windows Shell Services Dll)
011 * C:\Windows\system32\drivers\CHDART.sys (High Definition Audio Function Driver)
011 * C:\Windows\system32\DRIVERS\HssDrv.sys (Hotspot Shield Routing Driver)
011 * C:\Windows\system32\DRIVERS\MijXfilt.sys (MotioninJoy DS3 driver)
011 * C:\Windows\system32\DRIVERS\taphss.sys (TAP-Win32 Virtual Network Driver)
040 * C:\Program Files\ChatZum Toolbar\tbunsiFA93.tmp\tbhelper.dll {CA3EB689-8F09-4026-AA10-B9534C691CE0}
041 * C:\Program Files\ChatZum Toolbar\tbunsiFA93.tmp\tbcore3.dll {1BB22D38-A411-4B13-A746-C2A4F4EC7344}
042 GUID / CLSID not found {CCA281CA-C863-46ef-9331-5C8D4460577F}
042 GUID / CLSID not found {3369AF0D-62E9-4bda-8103-B4C75499B578}
052 GUID / CLSID not found {7E853D72-626A-48EC-A868-BA8D5E23E045}
052 * C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.) {F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
052 * C:\Program Files\ChatZum Toolbar\tbunsiFA93.tmp\tbcore3.dll {FCBCCB87-9224-4B8D-B117-F56D924BEB18}
061 C:\Program Files\Stardock\Object Desktop\IconPackager\shellext.dll (Stardock Corporation) {2CF9036B-F720-425F-918C-03A336A65FC4}
061 C:\Program Files\MediaFire Express\mf_shell_ext_d93b4.dll (MediaFire.com) {693B08DA-DA1F-4f2b-A145-C06BDF01868A}
061 C:\Windows\system32\btncopy.dll (Broadcom Corporation.) {7842554E-6BED-11D2-8CDB-B05550C10000}
061 C:\Windows\system32\themeui.dll (Microsoft Corporation) {41E300E0-78B6-11ce-849B-444553540000}
061 C:\Windows\System32\ShellvRTF.dll (XSS) {7F67036B-66F1-411A-AD85-759FB9C5B0DB}
061 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
062 C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll (Adobe Systems, Inc.) {F9DB5320-233E-11D1-9F84-707F02C10627}
100 Default_Page_URL HKCU :
100 Default_Page_URL HKLM :
100 Start Page HKLM :
105 &AOL Toolbar Search : c:\program files\aol\aol toolbar 5.0\resources\en-GB\local\search.html
105 Download all links with IDM : C:\Users\XMNS\AppData\Local\Temp\Rar$EXa0.996\IEGetAll.htm
105 Download with IDM : C:\Users\XMNS\AppData\Local\Temp\Rar$EXa0.996\IEExt.htm
105 Send image to &Bluetooth Device... : C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
105 Send page to &Bluetooth Device... : C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
173 GUID / CLSID not found
173 C:\Program Files\FreeTime\FormatFactory\ShellEx_101.dll (Free Time) {A3777921-CFD3-4A6B-89BF-08E6B95716E8}
173 C:\Program Files\Stardock\Object Desktop\IconPackager\shellext.dll (Stardock Corporation) {2CF9036B-F720-425F-918C-03A336A65FC4}
173 C:\Program Files\MediaFire Express\mf_shell_ext_d93b4.dll (MediaFire.com) {693B08DA-DA1F-4f2b-A145-C06BDF01868A}
173 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
221 GUID / CLSID not found
221 C:\Program Files\FreeTime\FormatFactory\ShellEx_101.dll (Free Time) {A3777921-CFD3-4A6B-89BF-08E6B95716E8}
221 C:\Program Files\Stardock\Object Desktop\IconPackager\shellext.dll (Stardock Corporation) {2CF9036B-F720-425F-918C-03A336A65FC4}
221 C:\Program Files\MediaFire Express\mf_shell_ext_d93b4.dll (MediaFire.com) {693B08DA-DA1F-4f2b-A145-C06BDF01868A}
221 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
223 * C:\Users\XMNS\AppData\Local\Temp\zxq2\mbamext.dll (Malwarebytes Corporation) {57CE581A-0CB6-4266-9CA0-19364C90A0B3}
225 GUID / CLSID not found
225 GUID / CLSID not found
225 * C:\Users\XMNS\AppData\Local\Temp\zxq2\mbamext.dll (Malwarebytes Corporation) {57CE581A-0CB6-4266-9CA0-19364C90A0B3}
225 * C:\Users\XMNS\AppData\Local\Temp\zxq2\mbamext.dll (Malwarebytes Corporation) {57CE581A-0CB6-4266-9CA0-19364C90A0B3}
225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
227 GUID / CLSID not found
227 C:\Program Files\FreeTime\FormatFactory\ShellEx_101.dll (Free Time) {A3777921-CFD3-4A6B-89BF-08E6B95716E8}
227 C:\Program Files\MediaFire Express\mf_shell_ext_d93b4.dll (MediaFire.com) {693B08DA-DA1F-4f2b-A145-C06BDF01868A}
227 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
229 GUID / CLSID not found
229 C:\Program Files\MediaFire Express\mf_shell_ext_d93b4.dll (MediaFire.com) {693B08DA-DA1F-4f2b-A145-C06BDF01868A}
231 C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll (Adobe Systems, Inc.) PDF Column Info
251 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
254 C:\Windows\system32\btncopy.dll (Broadcom Corporation.) {7842554E-6BED-11D2-8CDB-B05550C10000}
Missing files
-------------
003 C:\Users\XMNS\AppData\Local\Temp\Rar$EXa0.996\IDMan.exe
011 c:\windows\system32\DRIVERS\ipinip.sys
011 c:\windows\system32\DRIVERS\nwlnkflt.sys
011 c:\windows\system32\DRIVERS\nwlnkfwd.sys
011 C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys
011 C:\Windows\system32\XDva397.sys
032 rdpclip
061 C:\Users\XMNS\AppData\Local\Temp\RarSFX0\IDMShellExt.dll
241 C:\Users\XMNS\AppData\Local\Temp\RarSFX0\IDMShellExt.dll
: )