من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
السلام عليكم
ما اقدر احمل شي ابد في نهاية التحميل يطلع (يتعذر التنزيل تم اعادة تعين الاتصال بالخادم)
و الاقلاع وقت الدخول على سطح المكتب يصير ثقيل
و شك ان الجهاز فيه برامج تجسس سويت فحص الجهاز اذا كان مخترق من هذا الموقع و طلع فعلا مخترق
ابي انظف الجهاز كا كل بدون فرمته
و شكرا مقدما
هذا تقرير الهاي جاك
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 05:13:36 ص, on 19/05/14
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFTray.exe
C:\Program Files\Surftastic\bin\Surftastic.BrowserAdapter.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Zyzoom_Forum_Tools\zHijak.com
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8555;https=127.0.0.1:8555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: VonteeraSafeAds.WordHighlighterBHO - {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} - mscoree.dll (file missing)
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [Baidu PC Faster 4.0.0.0] "C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFaster.exe" -auto -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [hao123Setting] C:\Windows\TEMP\bdgEA01.exe
(User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [hao123Setting] C:\Windows\TEMP\bdgEA01.exe
(User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Highlighter options - {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: &Highlighter options - {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} - mscoree.dll (file missing)
O17 - HKLM\System\CCS\Services\Tcpip\..\{AF2494DE-ACFE-4AB5-A17B-A3932C1A2FC4}: NameServer = 8.8.8.8
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Hotspot Shield Service (hshld) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\bin\cmw_srv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files\Hotspot Shield\bin\hsswd.exe
O23 - Service: خدمة iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files\PANDORA.TV\PanService\KMPService.exe
O23 - Service: Baidu PC App Store Service 4.3.1.5579 (PCAppStoreSvc_{PCAppStore_4.3.1.5579}) - Baidu Inc. - C:\Program Files\Baidu Security\PC App Store\4.3.1.5579\PCAppStoreSvc.exe
O23 - Service: Baidu PC Faster Service 4.0.0.0 (PCFasterSvc_{PCFaster_4.0.0.0}) - Baidu Inc. - C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFasterSvc.exe
O23 - Service: Protect Monitor (ProtectMonitor) - Unknown owner - C:\Program Files\PCData\StartHelp.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\STacSV.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Update Surftastic - Unknown owner - C:\Program Files\Surftastic\updateSurftastic.exe
O23 - Service: Util Surftastic - Unknown owner - C:\Program Files\Surftastic\bin\utilSurftastic.exe
--
End of file - 8962 bytes
و التقارير الثاني
Runscanner logfile
* = signed file
- = file not found
General info
------------
Computer name : WALEED
Creation time : 19/05/14 04:43:36 ص
Hosts <> 127.0.0.1 : 0
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 8.0.7601.17514
OS : Windows 7 Home Premium
OS Build : 7601
OS SP : Service Pack 1
RunScanner Version : 2.0.0.50
User Language : العربية (السعودية)
User rights : Administrator
Windows folder : C:\Windows
Running processes
-----------------
* C:\Program Files\Surftastic\updateSurftastic.exe
* C:\Program Files\Surftastic\bin\utilSurftastic.exe
* C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
* C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
* C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
* C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\AEstSrv.exe (Andrea Electronics Corporation)
* C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
* C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
* C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
* C:\Program Files\Baidu Security\PC App Store\4.3.1.5579\PCAppStoreSvc.exe (Baidu Inc.)
C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFasterSvc.exe (Baidu Inc.)
* C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
* C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
* C:\Windows\System32\csrss.exe (Microsoft Corporation)
* C:\Windows\System32\csrss.exe (Microsoft Corporation)
* C:\Windows\System32\conhost.exe (Microsoft Corporation)
* C:\Windows\System32\conhost.exe (Microsoft Corporation)
* C:\Windows\System32\conhost.exe (Microsoft Corporation)
* C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
* C:\Windows\System32\dwm.exe (Microsoft Corporation)
C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
* C:\Windows\System32\hkcmd.exe (Intel Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\taskhost.exe (Microsoft Corporation)
* C:\Program Files\Hotspot Shield\bin\cmw_srv.exe (AnchorFree Inc.)
* C:\Program Files\Hotspot Shield\bin\hsswd.exe
* C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\stacsv.exe (IDT, Inc.)
* C:\Windows\System32\igfxtray.exe (Intel Corporation)
* C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
* C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
* C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
* C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe (PandoraTV)
* C:\Windows\System32\lsass.exe (Microsoft Corporation)
* C:\Windows\System32\SearchIndexer.exe (Microsoft Corporation)
* C:\Program Files\PANDORA.TV\PanService\KMPService.exe (Pandora.TV)
C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFTray.exe (Baidu Inc.)
* C:\Windows\System32\igfxpers.exe (Intel Corporation)
C:\Program Files\PCData\pmc.exe
* C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
* C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
* C:\Windows\System32\services.exe (Microsoft Corporation)
* C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
* C:\Windows\System32\spoolsv.exe (Microsoft Corporation)
* C:\Program Files\Surftastic\bin\Surftastic.BrowserAdapter.exe
* C:\Program Files\Surftastic\bin\Surftastic.PurBrowse.exe
* C:\Windows\system32\audiodg.exe (Microsoft Corporation)
* C:\Windows\System32\WUDFHost.exe (Microsoft Corporation)
C:\Users\DELL\AppData\Roaming\Windows Installer\Files\YouShaHD Player Service.exe (Microsoft)
* C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
* C:\Windows\System32\smss.exe (Microsoft Corporation)
* C:\Windows\System32\wbem\WmiPrvSE.exe (Microsoft Corporation)
* C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
* C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
* C:\Windows\System32\wininit.exe (Microsoft Corporation)
* C:\Windows\System32\winlogon.exe (Microsoft Corporation)
* C:\Windows\System32\lsm.exe (Microsoft Corporation)
* C:\Windows\explorer.exe (Microsoft Corporation)
Unrated items
-------------
002 * C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
002 C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFaster.exe (Baidu Inc.)
002 * C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
002 * C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
010 * C:\Program Files\Surftastic\updateSurftastic.exe ( )
010 * C:\Program Files\Surftastic\bin\utilSurftastic.exe ( )
010 * C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (.NET Runtime Optimization Service)
010 * C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Activation Licensing Service)
010 * C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Acrobat Update Service)
010 * C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe® Flash® Player Update Service 13.0 r0)
010 * C:\Program Files\AVAST Software\Avast\AvastSvc.exe (avast! Service)
010 * C:\Program Files\Baidu Security\PC App Store\4.3.1.5579\PCAppStoreSvc.exe (Baidu PC App Store Service)
010 C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFasterSvc.exe (Baidu PC Faster Service)
010 C:\Program Files\Dell\DellDock\DockLogin.exe (Dock Login Service)
010 * C:\Program Files\Hotspot Shield\bin\cmw_srv.exe (Hotspot Shield 3.33)
010 * C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE (HssTrayService.EXE)
010 * C:\Program Files\Hotspot Shield\bin\hsswd.exe (hsswd.exe)
010 * C:\Program Files\iPod\bin\iPodService.exe (iPodService Module (32-bit))
010 * C:\Windows\system32\GameMon.des (nProtect Game Monitor Rev 2024)
010 * C:\Program Files\PANDORA.TV\PanService\KMPService.exe (Pandora.TV service file)
010 * C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (rndlresolversvc.exe)
010 * C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype C2C Service)
010 * C:\Program Files\Skype\Updater\Updater.exe (Skype Updater Service)
010 C:\Program Files\PCData\StartHelp.exe (StartHelp.exe)
010 * C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (SwitchBoard Server (32 bit))
010 C:\Users\DELL\AppData\Roaming\Windows Installer\Files\YouShaHD Player Service.exe (Windows Installer Service)
010 * C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (YSLoader.exe)
011 * C:\Windows\system32\DRIVERS\Apfiltr.sys (Alps Touch Pad Driver)
011 * C:\Windows\system32\DRIVERS\taphss6.sys (Anchorfree HSS VPN Adapter)
011 * C:\Windows\system32\drivers\aswRvrt.sys (aswRvrt.sys)
011 * C:\Windows\system32\drivers\aswVmm.sys (aswVmm.sys)
011 * C:\Windows\system32\drivers\aswMonFlt.sys (avast! File System Minifilter for Windows 2003/Vista)
011 * C:\Windows\system32\drivers\aswSP.sys (avast! self protection module)
011 * C:\Windows\system32\drivers\aswSnx.sys (avast! Virtualization Driver)
011 * C:\Windows\system32\drivers\aswRdr2.sys (avast! WFP Redirect Driver)
011 * C:\Windows\System32\drivers\Bhbase.sys (Baidu Antivirus Hook Base)
011 * C:\Windows\System32\drivers\BprotectEx.sys (Baidu Antivirus Minifilter Driver)
011 * C:\Windows\system32\DRIVERS\GEARAspiWDM.sys (CD DVD Filter)
011 * C:\Windows\system32\DRIVERS\hssdrv6.sys (Hotspot Shield Routing Driver)
011 * C:\Windows\system32\drivers\mbamswissarmy.sys (MBAMSwissArmy)
011 * C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFApiUtil.sys (PCFApiUtil)
011 C:\Windows\system32\DRIVERS\PxHelp20.sys (PxHelp20)
011 * C:\Windows\system32\DRIVERS\ssudmdm.sys (SAMSUNG Android Modem Device Driver (MSS Ver.3))
011 * C:\Windows\system32\DRIVERS\ssudbus.sys (SAMSUNG USB Composite Device Driver (MSS Ver.3))
011 * C:\Windows\system32\drivers\{01531192-f7ef-415f-a549-cfdb11836731}w.sys (StdLib)
011 * C:\Windows\system32\drivers\aswStm.sys (Stream Filter)
031 * C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) {91774881-D725-4E58-B298-07617B9B86A8}
041 * C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
042 GUID / CLSID not found {CCA281CA-C863-46ef-9331-5C8D4460577F}
042 GUID / CLSID not found {d40c654d-7c51-4eb3-95b2-1e23905c2a2d}
042 * C:\Program Files\Paltalk Messenger\Paltalk.exe (AVM Software Inc.) {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE}
042 GUID / CLSID not found {92780B25-18CC-41C8-B9BE-3C9C571A8263}
042 GUID / CLSID not found {898EA8C8-E7FF-479B-8935-AEC46303B9E5}
042 GUID / CLSID not found {2670000A-7350-4f3c-8081-5663EE0C6C49}
060 GUID / CLSID not found {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
061 * C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) {472083B0-C522-11CF-8763-00608CC02F24}
061 * C:\Program Files\iTunes\iTunesMiniPlayer.dll (Apple Inc.) {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}
061 * C:\Program Files\Real\RealPlayer\rpshell.dll (RealNetworks, Inc.) {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}
061 * C:\Program Files\WinRAR\rarext.dll (Alexander Roshal) {B41DB860-8EE4-11D2-9906-E49FADC173CA}
062 * C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll (Adobe Systems, Inc.) {F9DB5320-233E-11D1-9F84-707F02C10627}
073 Adobe Flash Player Updater.job : C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
100 ProxyOverride HKCU : 127.0.0.1;localhost;10.*;192.168.*;127.0.0.1:895;127.0.0.1:896;<local>
100 ProxyServer HKCU : http=127.0.0.1:8555;https=127.0.0.1:8555
100 Start Page HKCU :
120 NameServer {AF2494DE-ACFE-4AB5-A17B-A3932C1A2FC4} : 8.8.8.8
170 {252edd43-7634-11e3-b77e-0c60768f6e01} : C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\start.exe
170 E : E:\autoRcd.exe
173 GUID / CLSID not found {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
173 * C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) {472083B0-C522-11CF-8763-00608CC02F24}
173 C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFShellEx.dll (Baidu Inc.) {81EBAFAF-6E03-4884-87FE-C9F904A06347}
173 * C:\Program Files\Common Files\Apple\Internet Services\ShellStreams.dll (Apple Inc.) {89D984B3-813B-406A-8298-118AFA3A22AE}
173 * C:\Program Files\Common Files\System\SysMenu.dll (Goobzo LTD) {020B1D4B-5738-4C77-9E19-4F173DD9B486}
173 * C:\Program Files\WinRAR\rarext.dll (Alexander Roshal) {B41DB860-8EE4-11D2-9906-E49FADC173CA}
220 GUID / CLSID not found {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
220 * C:\Program Files\Common Files\System\SysMenu.dll (Goobzo LTD) {020B1D4B-5738-4C77-9E19-4F173DD9B486}
221 * C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) {472083B0-C522-11CF-8763-00608CC02F24}
221 C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFShellEx.dll (Baidu Inc.) {81EBAFAF-6E03-4884-87FE-C9F904A06347}
221 * C:\Program Files\Common Files\Apple\Internet Services\ShellStreams.dll (Apple Inc.) {89D984B3-813B-406A-8298-118AFA3A22AE}
221 * C:\Program Files\Common Files\System\SysMenu.dll (Goobzo LTD) {020B1D4B-5738-4C77-9E19-4F173DD9B486}
221 * C:\Program Files\WinRAR\rarext.dll (Alexander Roshal) {B41DB860-8EE4-11D2-9906-E49FADC173CA}
223 * C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) {472083B0-C522-11CF-8763-00608CC02F24}
225 * C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) {472083B0-C522-11CF-8763-00608CC02F24}
225 * C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) {472083B0-C522-11CF-8763-00608CC02F24}
225 C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFShellEx.dll (Baidu Inc.) {81EBAFAF-6E03-4884-87FE-C9F904A06347}
225 C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFShellEx.dll (Baidu Inc.) {81EBAFAF-6E03-4884-87FE-C9F904A06347}
225 * C:\Program Files\WinRAR\rarext.dll (Alexander Roshal) {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 * C:\Program Files\WinRAR\rarext.dll (Alexander Roshal) {B41DB860-8EE4-11D2-9906-E49FADC173CA}
226 GUID / CLSID not found {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
227 * C:\Program Files\WinRAR\rarext.dll (Alexander Roshal) {B41DB860-8EE4-11D2-9906-E49FADC173CA}
228 GUID / CLSID not found {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
231 * C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll (Adobe Systems, Inc.) PDF Column Info
241 GUID / CLSID not found {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
241 GUID / CLSID not found {FB314EDA-A251-47B7-93E1-CDD82E34AF8B}
241 GUID / CLSID not found {FB314EDB-A251-47B7-93E1-CDD82E34AF8B}
241 GUID / CLSID not found {FB314EDC-A251-47B7-93E1-CDD82E34AF8B}
241 * C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) {472083B0-C522-11CF-8763-00608CC02F24}
251 * C:\Program Files\WinRAR\rarext.dll (Alexander Roshal) {B41DB860-8EE4-11D2-9906-E49FADC173CA}
Missing files
-------------
011 C:\Windows\System32\drivers\Bfilter.sys
011 C:\Windows\System32\drivers\Bfmon.sys
011 C:\Windows\System32\drivers\Bprotect.sys
013 C:\Windows\TEMP\bdgEA01.exe http:
032 rdpclip
073 C:\Program Files\Sense\Sense-chromeinstaller.exe
073 C:\Program Files\Sense\Sense-codedownloader.exe
073 C:\Program Files\Sense\Sense-firefoxinstaller.exe
ما اقدر احمل شي ابد في نهاية التحميل يطلع (يتعذر التنزيل تم اعادة تعين الاتصال بالخادم)
و الاقلاع وقت الدخول على سطح المكتب يصير ثقيل
و شك ان الجهاز فيه برامج تجسس سويت فحص الجهاز اذا كان مخترق من هذا الموقع و طلع فعلا مخترق
ابي انظف الجهاز كا كل بدون فرمته
و شكرا مقدما
هذا تقرير الهاي جاك
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 05:13:36 ص, on 19/05/14
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFTray.exe
C:\Program Files\Surftastic\bin\Surftastic.BrowserAdapter.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Zyzoom_Forum_Tools\zHijak.com
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8555;https=127.0.0.1:8555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: VonteeraSafeAds.WordHighlighterBHO - {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} - mscoree.dll (file missing)
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [Baidu PC Faster 4.0.0.0] "C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFaster.exe" -auto -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [hao123Setting] C:\Windows\TEMP\bdgEA01.exe
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O4 - HKUS\.DEFAULT\..\RunOnce: [hao123Setting] C:\Windows\TEMP\bdgEA01.exe
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Highlighter options - {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: &Highlighter options - {d40c654d-7c51-4eb3-95b2-1e23905c2a2d} - mscoree.dll (file missing)
O17 - HKLM\System\CCS\Services\Tcpip\..\{AF2494DE-ACFE-4AB5-A17B-A3932C1A2FC4}: NameServer = 8.8.8.8
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Hotspot Shield Service (hshld) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\bin\cmw_srv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files\Hotspot Shield\bin\hsswd.exe
O23 - Service: خدمة iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files\PANDORA.TV\PanService\KMPService.exe
O23 - Service: Baidu PC App Store Service 4.3.1.5579 (PCAppStoreSvc_{PCAppStore_4.3.1.5579}) - Baidu Inc. - C:\Program Files\Baidu Security\PC App Store\4.3.1.5579\PCAppStoreSvc.exe
O23 - Service: Baidu PC Faster Service 4.0.0.0 (PCFasterSvc_{PCFaster_4.0.0.0}) - Baidu Inc. - C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFasterSvc.exe
O23 - Service: Protect Monitor (ProtectMonitor) - Unknown owner - C:\Program Files\PCData\StartHelp.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\STacSV.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Update Surftastic - Unknown owner - C:\Program Files\Surftastic\updateSurftastic.exe
O23 - Service: Util Surftastic - Unknown owner - C:\Program Files\Surftastic\bin\utilSurftastic.exe
--
End of file - 8962 bytes
و التقارير الثاني
Runscanner logfile
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
* = signed file
- = file not found
General info
------------
Computer name : WALEED
Creation time : 19/05/14 04:43:36 ص
Hosts <> 127.0.0.1 : 0
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 8.0.7601.17514
OS : Windows 7 Home Premium
OS Build : 7601
OS SP : Service Pack 1
RunScanner Version : 2.0.0.50
User Language : العربية (السعودية)
User rights : Administrator
Windows folder : C:\Windows
Running processes
-----------------
* C:\Program Files\Surftastic\updateSurftastic.exe
* C:\Program Files\Surftastic\bin\utilSurftastic.exe
* C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
* C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
* C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
* C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\AEstSrv.exe (Andrea Electronics Corporation)
* C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
* C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
* C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
* C:\Program Files\Baidu Security\PC App Store\4.3.1.5579\PCAppStoreSvc.exe (Baidu Inc.)
C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFasterSvc.exe (Baidu Inc.)
* C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
* C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
* C:\Windows\System32\csrss.exe (Microsoft Corporation)
* C:\Windows\System32\csrss.exe (Microsoft Corporation)
* C:\Windows\System32\conhost.exe (Microsoft Corporation)
* C:\Windows\System32\conhost.exe (Microsoft Corporation)
* C:\Windows\System32\conhost.exe (Microsoft Corporation)
* C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
* C:\Windows\System32\dwm.exe (Microsoft Corporation)
C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
* C:\Windows\System32\hkcmd.exe (Intel Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\taskhost.exe (Microsoft Corporation)
* C:\Program Files\Hotspot Shield\bin\cmw_srv.exe (AnchorFree Inc.)
* C:\Program Files\Hotspot Shield\bin\hsswd.exe
* C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\stacsv.exe (IDT, Inc.)
* C:\Windows\System32\igfxtray.exe (Intel Corporation)
* C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
* C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
* C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
* C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe (PandoraTV)
* C:\Windows\System32\lsass.exe (Microsoft Corporation)
* C:\Windows\System32\SearchIndexer.exe (Microsoft Corporation)
* C:\Program Files\PANDORA.TV\PanService\KMPService.exe (Pandora.TV)
C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFTray.exe (Baidu Inc.)
* C:\Windows\System32\igfxpers.exe (Intel Corporation)
C:\Program Files\PCData\pmc.exe
* C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
* C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
* C:\Windows\System32\services.exe (Microsoft Corporation)
* C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
* C:\Windows\System32\spoolsv.exe (Microsoft Corporation)
* C:\Program Files\Surftastic\bin\Surftastic.BrowserAdapter.exe
* C:\Program Files\Surftastic\bin\Surftastic.PurBrowse.exe
* C:\Windows\system32\audiodg.exe (Microsoft Corporation)
* C:\Windows\System32\WUDFHost.exe (Microsoft Corporation)
C:\Users\DELL\AppData\Roaming\Windows Installer\Files\YouShaHD Player Service.exe (Microsoft)
* C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
* C:\Windows\System32\smss.exe (Microsoft Corporation)
* C:\Windows\System32\wbem\WmiPrvSE.exe (Microsoft Corporation)
* C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
* C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
* C:\Windows\System32\wininit.exe (Microsoft Corporation)
* C:\Windows\System32\winlogon.exe (Microsoft Corporation)
* C:\Windows\System32\lsm.exe (Microsoft Corporation)
* C:\Windows\explorer.exe (Microsoft Corporation)
Unrated items
-------------
002 * C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
002 C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFaster.exe (Baidu Inc.)
002 * C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
002 * C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
010 * C:\Program Files\Surftastic\updateSurftastic.exe ( )
010 * C:\Program Files\Surftastic\bin\utilSurftastic.exe ( )
010 * C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (.NET Runtime Optimization Service)
010 * C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Activation Licensing Service)
010 * C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Acrobat Update Service)
010 * C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe® Flash® Player Update Service 13.0 r0)
010 * C:\Program Files\AVAST Software\Avast\AvastSvc.exe (avast! Service)
010 * C:\Program Files\Baidu Security\PC App Store\4.3.1.5579\PCAppStoreSvc.exe (Baidu PC App Store Service)
010 C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFasterSvc.exe (Baidu PC Faster Service)
010 C:\Program Files\Dell\DellDock\DockLogin.exe (Dock Login Service)
010 * C:\Program Files\Hotspot Shield\bin\cmw_srv.exe (Hotspot Shield 3.33)
010 * C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE (HssTrayService.EXE)
010 * C:\Program Files\Hotspot Shield\bin\hsswd.exe (hsswd.exe)
010 * C:\Program Files\iPod\bin\iPodService.exe (iPodService Module (32-bit))
010 * C:\Windows\system32\GameMon.des (nProtect Game Monitor Rev 2024)
010 * C:\Program Files\PANDORA.TV\PanService\KMPService.exe (Pandora.TV service file)
010 * C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (rndlresolversvc.exe)
010 * C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype C2C Service)
010 * C:\Program Files\Skype\Updater\Updater.exe (Skype Updater Service)
010 C:\Program Files\PCData\StartHelp.exe (StartHelp.exe)
010 * C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (SwitchBoard Server (32 bit))
010 C:\Users\DELL\AppData\Roaming\Windows Installer\Files\YouShaHD Player Service.exe (Windows Installer Service)
010 * C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (YSLoader.exe)
011 * C:\Windows\system32\DRIVERS\Apfiltr.sys (Alps Touch Pad Driver)
011 * C:\Windows\system32\DRIVERS\taphss6.sys (Anchorfree HSS VPN Adapter)
011 * C:\Windows\system32\drivers\aswRvrt.sys (aswRvrt.sys)
011 * C:\Windows\system32\drivers\aswVmm.sys (aswVmm.sys)
011 * C:\Windows\system32\drivers\aswMonFlt.sys (avast! File System Minifilter for Windows 2003/Vista)
011 * C:\Windows\system32\drivers\aswSP.sys (avast! self protection module)
011 * C:\Windows\system32\drivers\aswSnx.sys (avast! Virtualization Driver)
011 * C:\Windows\system32\drivers\aswRdr2.sys (avast! WFP Redirect Driver)
011 * C:\Windows\System32\drivers\Bhbase.sys (Baidu Antivirus Hook Base)
011 * C:\Windows\System32\drivers\BprotectEx.sys (Baidu Antivirus Minifilter Driver)
011 * C:\Windows\system32\DRIVERS\GEARAspiWDM.sys (CD DVD Filter)
011 * C:\Windows\system32\DRIVERS\hssdrv6.sys (Hotspot Shield Routing Driver)
011 * C:\Windows\system32\drivers\mbamswissarmy.sys (MBAMSwissArmy)
011 * C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFApiUtil.sys (PCFApiUtil)
011 C:\Windows\system32\DRIVERS\PxHelp20.sys (PxHelp20)
011 * C:\Windows\system32\DRIVERS\ssudmdm.sys (SAMSUNG Android Modem Device Driver (MSS Ver.3))
011 * C:\Windows\system32\DRIVERS\ssudbus.sys (SAMSUNG USB Composite Device Driver (MSS Ver.3))
011 * C:\Windows\system32\drivers\{01531192-f7ef-415f-a549-cfdb11836731}w.sys (StdLib)
011 * C:\Windows\system32\drivers\aswStm.sys (Stream Filter)
031 * C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) {91774881-D725-4E58-B298-07617B9B86A8}
041 * C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}
042 GUID / CLSID not found {CCA281CA-C863-46ef-9331-5C8D4460577F}
042 GUID / CLSID not found {d40c654d-7c51-4eb3-95b2-1e23905c2a2d}
042 * C:\Program Files\Paltalk Messenger\Paltalk.exe (AVM Software Inc.) {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE}
042 GUID / CLSID not found {92780B25-18CC-41C8-B9BE-3C9C571A8263}
042 GUID / CLSID not found {898EA8C8-E7FF-479B-8935-AEC46303B9E5}
042 GUID / CLSID not found {2670000A-7350-4f3c-8081-5663EE0C6C49}
060 GUID / CLSID not found {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
061 * C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) {472083B0-C522-11CF-8763-00608CC02F24}
061 * C:\Program Files\iTunes\iTunesMiniPlayer.dll (Apple Inc.) {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}
061 * C:\Program Files\Real\RealPlayer\rpshell.dll (RealNetworks, Inc.) {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}
061 * C:\Program Files\WinRAR\rarext.dll (Alexander Roshal) {B41DB860-8EE4-11D2-9906-E49FADC173CA}
062 * C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll (Adobe Systems, Inc.) {F9DB5320-233E-11D1-9F84-707F02C10627}
073 Adobe Flash Player Updater.job : C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
100 ProxyOverride HKCU : 127.0.0.1;localhost;10.*;192.168.*;127.0.0.1:895;127.0.0.1:896;<local>
100 ProxyServer HKCU : http=127.0.0.1:8555;https=127.0.0.1:8555
100 Start Page HKCU :
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
120 NameServer {AF2494DE-ACFE-4AB5-A17B-A3932C1A2FC4} : 8.8.8.8
170 {252edd43-7634-11e3-b77e-0c60768f6e01} : C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\start.exe
170 E : E:\autoRcd.exe
173 GUID / CLSID not found {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
173 * C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) {472083B0-C522-11CF-8763-00608CC02F24}
173 C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFShellEx.dll (Baidu Inc.) {81EBAFAF-6E03-4884-87FE-C9F904A06347}
173 * C:\Program Files\Common Files\Apple\Internet Services\ShellStreams.dll (Apple Inc.) {89D984B3-813B-406A-8298-118AFA3A22AE}
173 * C:\Program Files\Common Files\System\SysMenu.dll (Goobzo LTD) {020B1D4B-5738-4C77-9E19-4F173DD9B486}
173 * C:\Program Files\WinRAR\rarext.dll (Alexander Roshal) {B41DB860-8EE4-11D2-9906-E49FADC173CA}
220 GUID / CLSID not found {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
220 * C:\Program Files\Common Files\System\SysMenu.dll (Goobzo LTD) {020B1D4B-5738-4C77-9E19-4F173DD9B486}
221 * C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) {472083B0-C522-11CF-8763-00608CC02F24}
221 C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFShellEx.dll (Baidu Inc.) {81EBAFAF-6E03-4884-87FE-C9F904A06347}
221 * C:\Program Files\Common Files\Apple\Internet Services\ShellStreams.dll (Apple Inc.) {89D984B3-813B-406A-8298-118AFA3A22AE}
221 * C:\Program Files\Common Files\System\SysMenu.dll (Goobzo LTD) {020B1D4B-5738-4C77-9E19-4F173DD9B486}
221 * C:\Program Files\WinRAR\rarext.dll (Alexander Roshal) {B41DB860-8EE4-11D2-9906-E49FADC173CA}
223 * C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) {472083B0-C522-11CF-8763-00608CC02F24}
225 * C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) {472083B0-C522-11CF-8763-00608CC02F24}
225 * C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) {472083B0-C522-11CF-8763-00608CC02F24}
225 C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFShellEx.dll (Baidu Inc.) {81EBAFAF-6E03-4884-87FE-C9F904A06347}
225 C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFShellEx.dll (Baidu Inc.) {81EBAFAF-6E03-4884-87FE-C9F904A06347}
225 * C:\Program Files\WinRAR\rarext.dll (Alexander Roshal) {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 * C:\Program Files\WinRAR\rarext.dll (Alexander Roshal) {B41DB860-8EE4-11D2-9906-E49FADC173CA}
226 GUID / CLSID not found {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
227 * C:\Program Files\WinRAR\rarext.dll (Alexander Roshal) {B41DB860-8EE4-11D2-9906-E49FADC173CA}
228 GUID / CLSID not found {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
231 * C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll (Adobe Systems, Inc.) PDF Column Info
241 GUID / CLSID not found {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
241 GUID / CLSID not found {FB314EDA-A251-47B7-93E1-CDD82E34AF8B}
241 GUID / CLSID not found {FB314EDB-A251-47B7-93E1-CDD82E34AF8B}
241 GUID / CLSID not found {FB314EDC-A251-47B7-93E1-CDD82E34AF8B}
241 * C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) {472083B0-C522-11CF-8763-00608CC02F24}
251 * C:\Program Files\WinRAR\rarext.dll (Alexander Roshal) {B41DB860-8EE4-11D2-9906-E49FADC173CA}
Missing files
-------------
011 C:\Windows\System32\drivers\Bfilter.sys
011 C:\Windows\System32\drivers\Bfmon.sys
011 C:\Windows\System32\drivers\Bprotect.sys
013 C:\Windows\TEMP\bdgEA01.exe http:
032 rdpclip
073 C:\Program Files\Sense\Sense-chromeinstaller.exe
073 C:\Program Files\Sense\Sense-codedownloader.exe
073 C:\Program Files\Sense\Sense-firefoxinstaller.exe
