السلام عليكم ورحمة الله وبركاته
تفضل تقرير رنسكنر
Runscanner logfile
* = signed file
- = file not found
General info
------------
Computer name : PC_USER-PC
Creation time : 21/06/14 12:20:39 م
Hosts <> 127.0.0.1 : 0
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 9.0.8112.16421
OS : Windows 7 Home Premium
OS Build : 7600
OS SP :
RunScanner Version : 2.0.0.60
User Language : العربية (السعودية)
User rights : Administrator
Windows folder : C:\Windows
Running processes
-----------------
* C:\Program Files (x86)\Baidu Security\PC App Store\4.5.1.6024\AppStoreUtilExe.exe
* C:\Program Files (x86)\Baidu Security\PC App Store\4.5.1.6024\PCAppStoreSvc.exe (Baidu Inc.)
* C:\Windows\System32\csrss.exe (Microsoft Corporation)
* C:\Windows\System32\csrss.exe (Microsoft Corporation)
C:\Program Files (x86)\Mobile Genie\MobileMonitor.exe
* C:\Windows\System32\conhost.exe (Microsoft Corporation)
* C:\Windows\System32\dwm.exe (Microsoft Corporation)
* C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Windows\System32\hkcmd.exe (Intel Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\taskhost.exe (Microsoft Corporation)
* C:\Windows\System32\igfxtray.exe (Intel Corporation)
* C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
* C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
* C:\Program Files (x86)\Internet Download Manager\IDMGrHlp.exe (Tonec Inc.)
* C:\Program Files (x86)\Internet Explorer\ielowutil.exe (Microsoft Corporation)
* C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (Kaspersky Lab ZAO)
* C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Kaspersky Lab ZAO)
* C:\Windows\System32\lsass.exe (Microsoft Corporation)
* C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation)
* C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
* C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
* C:\Windows\System32\SearchFilterHost.exe (Microsoft Corporation)
* C:\Windows\System32\SearchIndexer.exe (Microsoft Corporation)
* C:\Windows\System32\SearchProtocolHost.exe (Microsoft Corporation)
* C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
* C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corp.)
* C:\Windows\System32\igfxpers.exe (Intel Corporation)
* C:\Users\PC_USER\Downloads\Programs\runscanner.exe (Runscanner.net)
* C:\Windows\System32\services.exe (Microsoft Corporation)
C:\Program Files (x86)\baidu\SparkSafe\sparkservice.exe (Baidu Inc.)
* C:\Windows\System32\spoolsv.exe (Microsoft Corporation)
C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
* C:\Windows\system32\audiodg.exe (Microsoft Corporation)
* C:\Windows\System32\smss.exe (Microsoft Corporation)
* C:\Windows\System32\wbem\WmiPrvSE.exe (Microsoft Corporation)
* C:\Program Files (x86)\Yahoo!\Messenger\Ymsgr_tray.exe (Yahoo! Inc.)
* C:\Windows\System32\wininit.exe (Microsoft Corporation)
* C:\Windows\System32\winlogon.exe (Microsoft Corporation)
* C:\Windows\System32\lsm.exe (Microsoft Corporation)
* C:\Windows\System32\rundll32.exe (Microsoft Corporation)
* C:\Windows\explorer.exe (Microsoft Corporation)
* C:\Windows\explorer.exe (Microsoft Corporation)
* C:\Windows\System32\taskeng.exe (Microsoft Corporation)
Unrated items
-------------
002 C:\Program Files (x86)\Mobile Genie\MobileMonitor.exe
003 * C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
003 * C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
005 C:\PROGRA~2\TP-LINK\TP-LIN~1\TWCU.exe
006 C:\PROGRA~2\TP-LINK\TP-LIN~1\TWCU.exe
010 * C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe® Flash® Player Update Service 13.0 r0)
010 * C:\Program Files (x86)\Baidu Security\PC App Store\4.5.1.6024\PCAppStoreSvc.exe (Baidu PC App Store Service)
010 * C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Kaspersky Anti-Virus)
010 * C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Anti-Malware)
010 * C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Anti-Malware)
010 C:\Program Files (x86)\Baidu\SparkSafeUpdate\SparkUpdate.exe (spark)
010 C:\Program Files (x86)\baidu\SparkSafe\sparkservice.exe (spark)
011 * C:\Windows\system32\DRIVERS\idmwfp.sys (Internet Download Manager WFP Driver)
011 * C:\Windows\system32\DRIVERS\klim6.sys (Kaspersky Lab Intermediate Network Driver)
011 * C:\Windows\system32\DRIVERS\kl1.sys (Kaspersky Unified Driver)
011 * C:\Windows\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x64])
011 * C:\Windows\system32\DRIVERS\klkbdflt.sys (KLKBDFLT Keyboard Device Filter [fre_wlh_x64])
011 * C:\Windows\system32\DRIVERS\klmouflt.sys (KLMOUFLT Mouse Device Filter [fre_wlh_x64])
011 * C:\Windows\system32\DRIVERS\klpd.sys (KLPD [fre_wnet_x64])
011 * C:\Windows\system32\DRIVERS\kneps.sys (KNEPS Power [fre_wnet_amd64])
011 * C:\Windows\system32\drivers\MBAMSwissArmy.sys (Malwarebytes Anti-Malware)
011 * C:\Windows\system32\drivers\mbam.sys (MBAMProtector)
011 * C:\Windows\system32\drivers\mwac.sys (MBAMWebAccessControl)
011 * C:\Windows\system32\DRIVERS\kltdi.sys (Network filtering component)
011 * C:\Windows\system32\DRIVERS\rtwlanu.sys (Realtek WLAN USB NDIS Driver)
011 * C:\Windows\system32\DRIVERS\revoflt.sys (Revo Uninstaller Minifilter)
011 * C:\Program Files (x86)\Baidu Security\Baidu Antivirus\Spring64.sys (Spring64.sys)
035 * C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe (Google Inc.) {8A69D345-D564-463c-AFF1-A69D9E530F96}
042 GUID / CLSID not found {0000036B-C524-4050-81A0-243669A86B9F}
042 GUID / CLSID not found {2670000A-7350-4f3c-8081-5663EE0C6C49}
042 GUID / CLSID not found {CCF151D8-D089-449F-A5A4-D9909053F20F}
042 GUID / CLSID not found {0C4CC089-D306-440D-9772-464E226F6539}
042 GUID / CLSID not found {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}
052 * C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}
052 * C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.) {0055C089-8582-441B-A0BF-17B458C2A3A8}
052 * C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}
052 * C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) {E33CF602-D945-461A-83F0-819F76A199F8}
052 * C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) {73455575-E40C-433C-9784-C78DC7761455}
060 GUID / CLSID not found {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
061 C:\Program Files (x86)\K-Lite Codec Pack\Icaros\32-bit\IcarosThumbnailProvider.dll (Tabibito Technology) {c5aec3ec-e812-4677-a9a7-4fee1f9aa000}
061 C:\Program Files (x86)\JetAudio\JetFlExt.dll (JetAudio) {8D1636FD-CA49-4B4E-90E4-0A20E03A15E8}
061 * C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\shellex.dll (Kaspersky Lab ZAO) {dd230880-495a-11d1-b064-008048ec2fc5}
061 C:\Program Files (x86)\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
069 * C:\Windows\system32\hpinksts8811LM.dll (Hewlett-Packard Co.)
100 Start Page HKCU :
105 إر&سال إلى OneNote : res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
105 إضافة إلى مكافحة الشعارات : C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ie_banner_deny.htm
105 ت&صدير إلى Microsoft Excel : res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
105 تحميل الكل بواسطة Internet Download Manager : C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
105 تحميل بواسطة Internet Download Manager : C:\Program Files (x86)\Internet Download Manager\IEExt.htm
145 * C:\Windows\system32\drivers\klkbdflt.sys (Kaspersky Lab ZAO)
170 {b99d22ab-f37c-11e3-8c55-50e549a0232b} : G:\setup.exe
170 {c58f7041-dc57-11e3-8d13-806e6f6e6963} : F:\Autorun.exe
173 GUID / CLSID not found {B41DB860-64E4-11D2-9906-E49FADC173CA}
173 * C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\shellex.dll (Kaspersky Lab ZAO) {dd230880-495a-11d1-b064-008048ec2fc5}
173 C:\Program Files (x86)\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
221 GUID / CLSID not found {B41DB860-64E4-11D2-9906-E49FADC173CA}
221 * C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\shellex.dll (Kaspersky Lab ZAO) {dd230880-495a-11d1-b064-008048ec2fc5}
221 C:\Program Files (x86)\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
223 GUID / CLSID not found {57CE581A-0CB6-4266-9CA0-19364C90A0B3}
223 C:\Program Files (x86)\JetAudio\JetFlExt.dll (JetAudio) {8D1636FD-CA49-4B4E-90E4-0A20E03A15E8}
225 GUID / CLSID not found {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7}
225 GUID / CLSID not found {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7}
225 GUID / CLSID not found {57CE581A-0CB6-4266-9CA0-19364C90A0B3}
225 GUID / CLSID not found {57CE581A-0CB6-4266-9CA0-19364C90A0B3}
225 GUID / CLSID not found {B41DB860-64E4-11D2-9906-E49FADC173CA}
225 GUID / CLSID not found {B41DB860-64E4-11D2-9906-E49FADC173CA}
225 * C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\shellex.dll (Kaspersky Lab ZAO) {dd230880-495a-11d1-b064-008048ec2fc5}
225 * C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\shellex.dll (Kaspersky Lab ZAO) {dd230880-495a-11d1-b064-008048ec2fc5}
225 C:\Program Files (x86)\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 C:\Program Files (x86)\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
227 GUID / CLSID not found {B41DB860-64E4-11D2-9906-E49FADC173CA}
227 * C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\shellex.dll (Kaspersky Lab ZAO) {dd230880-495a-11d1-b064-008048ec2fc5}
227 C:\Program Files (x86)\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
229 GUID / CLSID not found {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4}
251 GUID / CLSID not found {B41DB860-64E4-11D2-9906-E49FADC173CA}
251 C:\Program Files (x86)\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
Missing files
-------------
003 C:\Program Files (x86)\Earth Alerts\EarthAlerts.exe
010 C:\Windows\system32\srvany.exe
011 C:\Windows\System32\drivers\Bfilter.sys
011 C:\Windows\System32\drivers\Bfmon.sys
011 System32\drivers\bnbasex64.sys
011 C:\Windows\System32\drivers\bndef64.sys
011 C:\Windows\System32\drivers\Bprotect.sys
011 C:\Windows\System32\drivers\BprotectEx.sys
011 C:\Program Files (x86)\Baidu Security\PC Faster\4.0.0.0\PCFApiUtil64.sys
011 C:\Program Files\Common Files\ShopperPro\spbiw.sys
032 rdpclip
135 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --remote-debugging-port=9222 --flag-switches-begin --flag-switches-end --restore-last-session -- http: