Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 04:52:16 م, on 26/07/12
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Program Files\Zain Broadband\Zain Broadband.exe
C:\Users\TOSHIBA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\TOSHIBA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\TOSHIBA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\TOSHIBA\Downloads\Programs\runscanner.exe
C:\Program Files\Your Uninstaller! 7\urmain.exe
C:\Program Files\Your Uninstaller! 7\urmain.exe
C:\Users\TOSHIBA\Downloads\Programs\TFC.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\explorer.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Zyzoom_Forum_Tools\zHijak.com
C:\Program Files\Internet Explorer\IELowutil.exe
C:\Windows\system32\RunDll32.exe
C:\Windows\explorer.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - (no file)
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Block frame with Ad Muncher -
O8 - Extra context menu item: Block image with Ad Muncher -
O8 - Extra context menu item: Block link with Ad Muncher -
O8 - Extra context menu item: Don't filter page with Ad Muncher -
O8 - Extra context menu item: Report page to the Ad Muncher developers -
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى FLV بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: تحميل ملفات FLV الـ 10 الأخيرة بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetVL2.htm
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{3F76212F-CD2A-4684-893E-604E6C6FE65A}: NameServer = 79.170.50.4 79.170.50.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{CF49270B-A60B-40BD-B72E-4040789D5289}: NameServer = 79.170.50.4 79.170.50.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{D4831DBE-9DE6-41AF-B228-1BA222104C2B}: NameServer = 79.170.50.4 79.170.50.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{3F76212F-CD2A-4684-893E-604E6C6FE65A}: NameServer = 79.170.50.4 79.170.50.3
O17 - HKLM\System\CS2\Services\Tcpip\..\{3F76212F-CD2A-4684-893E-604E6C6FE65A}: NameServer = 79.170.50.4 79.170.50.3
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: HWDeviceService.exe - Unknown owner - C:\ProgramData\DatacardService\HWDeviceService.exe
O23 - Service: Ma-Config Service (maconfservice) - Unknown owner - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Zain Broadband. OUC (Zain Broadband. RunOuc) - Unknown owner - C:\Program Files\Zain Broadband\UpdateDog\ouc.exe
--
End of file - 6334 bytes