رائحة الهيل

زيزوومي جديد
إنضم
19 يناير 2009
المشاركات
31
مستوى التفاعل
0
النقاط
40
غير متصل
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 03:10:36 م, on 03/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\tazebama.dl_
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Documents and Settings\ksa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\ksa\Desktop\Zyzoom_HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: TweakMASTER Component - {7DAAC7DE-9EF0-4FF0-BFA5-AFF3E899054C} - C:\PROGRA~1\TWEAKM~1\TweakBHO.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TweakMASTER] "C:\Program Files\TweakMASTER\TMTray.exe"
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [GreenBrowser] C:\Documents and Settings\ksa\Desktop\GreenBrowser\GreenBrowser.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\ksa\Application Data\Symantec\Layouts\Norton AntiVirus\15.0\SymAllLanguages\NAV_ESD\20070828\Support\SymLnch\SymLnch.exe" "C:\Documents and Settings\ksa\Application Data\Symantec\Layouts\Norton AntiVirus\15.0\SymAllLanguages\NAV_ESD\20070828\Setup.exe" "/UPREBOOT /temp /patched"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\ksa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Add to &LinkFox - res://C:\PROGRA~1\TWEAKM~1\TweakBHO.dll/IESCRIPT
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: McAfee Application Installer Cleanup (0138711232484630) (0138711232484630mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\013871~1.EXE (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

--
End of file - 11145 bytes







جهازي فيه اكثر من مشكله اتمنى اجد حل
 

ان شاء الله تحصل على المساعده اللازمه

عذرا ً بنقله الى القسم الانسب ليلقى الدعم الافضل
 
توقيع : Mr.Ali4Ever
هلاا بك

استخدم هذه الاداة لحذف المكافي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


تستخدم بالوضع الامن

ثم اعمل تقرير جديد
 
تسلم اخي ماكسLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:45:15 م, on 16/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\tazebama.dl_
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Documents and Settings\ksa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\Apoint2K\Apntex.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Documents and Settings\ksa\Desktop\Zyzoom_HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: TweakMASTER Component - {7DAAC7DE-9EF0-4FF0-BFA5-AFF3E899054C} - C:\PROGRA~1\TWEAKM~1\TweakBHO.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TweakMASTER] "C:\Program Files\TweakMASTER\TMTray.exe"
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [GreenBrowser] C:\Documents and Settings\ksa\Desktop\GreenBrowser\GreenBrowser.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\ksa\Application Data\Symantec\Layouts\Norton AntiVirus\15.0\SymAllLanguages\NAV_ESD\20070828\Support\SymLnch\SymLnch.exe" "C:\Documents and Settings\ksa\Application Data\Symantec\Layouts\Norton AntiVirus\15.0\SymAllLanguages\NAV_ESD\20070828\Setup.exe" "/UPREBOOT /temp /patched"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\ksa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Add to &LinkFox - res://C:\PROGRA~1\TWEAKM~1\TweakBHO.dll/IESCRIPT
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: تدوين هذا في المدونة - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &تدوين هذا في Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: McAfee Application Installer Cleanup (0138711232484630) (0138711232484630mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\013871~1.EXE (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe
--
End of file - 12426 bytes

سويت الي قلت عليه وهذا التقرير
 
عطل استعادة النظام حسب الشرح التالي

dis_sys_xp.jpg


ثم

حمل اداة الكاسبر من الرابط التالي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


بعد التحميل ،، دبل كلك وسيتم استخراج ملف الاداة الى مجلد بسطح المكتب لحظات وتبدأ الاداة بالعمل

تابع الشرح لفحص الجهاز وتنظيفه وارفاق التقرير


zyzoom-7ce8879e89.png


zyzoom-cdd75c8aa3.png


zyzoom-89156f000e.png


zyzoom-6d533c4f2e.png


zyzoom-f20f3644d0.png


ثم قم بضغط التقرير ورفعه هنا>>>>
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
 
تفضل هذا التقرير



Scan
----
Scanned: 33
Detected: 2
Untreated: 0
Start time: 22/03/1430 03:51:11 م
Duration: 00:05:05
Finish time: 22/03/1430 03:56:16 م

Detected
--------
Status Object
------ ------
will be disinfected when the computer is restarted: virus Worm.Win32.Mabezat.b File: c:\program files\real\realplayer\realplay.exe
will be deleted when the computer is restarted: virus Worm.Win32.Mabezat.b File: C:\Documents and Settings\tazebama.dll

Events
------
Time Name Status Reason
---- ---- ------ ------
22/03/1430 03:55:37 م Running module: RealPlay.exe\RealPlay.exe ok scanned
22/03/1430 03:55:41 م File: C:\Program Files\Real\RealPlayer\RealPlay.exe detected virus 'Worm.Win32.Mabezat.b'
22/03/1430 03:55:42 م File: C:\Program Files\Real\RealPlayer\RealPlay.exe backed up
22/03/1430 03:55:43 م File: C:\Program Files\Real\RealPlayer\RealPlay.exe detected virus 'Worm.Win32.Mabezat.b'
22/03/1430 03:55:43 م File: C:\Program Files\Real\RealPlayer\RealPlay.exe disinfected virus 'Worm.Win32.Mabezat.b'
22/03/1430 03:55:52 م File: C:\Program Files\Real\RealPlayer\RealPlay.exe will be disinfected on system restart
22/03/1430 03:55:53 م Running module: RealPlay.exe\ntdll.dll ok scanned
22/03/1430 03:55:54 م File: C:\WINDOWS\system32\ntdll.dll ok scanned
22/03/1430 03:55:55 م Running module: RealPlay.exe\kernel32.dll ok scanned
22/03/1430 03:55:56 م File: C:\WINDOWS\system32\kernel32.dll ok scanned
22/03/1430 03:55:58 م Running module: RealPlay.exe\ole32.dll ok scanned
22/03/1430 03:56:00 م File: C:\WINDOWS\system32\ole32.dll ok scanned
22/03/1430 03:56:01 م Running module: RealPlay.exe\ADVAPI32.dll ok scanned
22/03/1430 03:56:02 م File: C:\WINDOWS\system32\ADVAPI32.dll ok scanned
22/03/1430 03:56:03 م Running module: RealPlay.exe\RPCRT4.dll ok scanned
22/03/1430 03:56:04 م File: C:\WINDOWS\system32\RPCRT4.dll ok scanned
22/03/1430 03:56:04 م Running module: RealPlay.exe\Secur32.dll ok scanned
22/03/1430 03:56:04 م File: C:\WINDOWS\system32\Secur32.dll ok scanned
22/03/1430 03:56:05 م Running module: RealPlay.exe\GDI32.dll ok scanned
22/03/1430 03:56:05 م File: C:\WINDOWS\system32\GDI32.dll ok scanned
22/03/1430 03:56:06 م Running module: RealPlay.exe\USER32.dll ok scanned
22/03/1430 03:56:09 م File: C:\WINDOWS\system32\USER32.dll ok scanned
22/03/1430 03:56:09 م Running module: RealPlay.exe\msvcrt.dll ok scanned
22/03/1430 03:56:10 م File: C:\WINDOWS\system32\msvcrt.dll ok scanned
22/03/1430 03:56:10 م Running module: RealPlay.exe\VERSION.dll ok scanned
22/03/1430 03:56:10 م File: C:\WINDOWS\system32\VERSION.dll ok scanned
22/03/1430 03:56:11 م Running module: RealPlay.exe\MSVCR71.dll ok scanned
22/03/1430 03:56:12 م File: C:\WINDOWS\system32\MSVCR71.dll ok scanned
22/03/1430 03:56:12 م Running module: RealPlay.exe\MSVCP71.dll ok scanned
22/03/1430 03:56:13 م File: C:\WINDOWS\system32\MSVCP71.dll ok scanned
22/03/1430 03:56:13 م Running module: RealPlay.exe\IMM32.DLL ok scanned
22/03/1430 03:56:13 م File: C:\WINDOWS\system32\IMM32.DLL ok scanned
22/03/1430 03:56:13 م Running module: RealPlay.exe\LPK.DLL ok scanned
22/03/1430 03:56:13 م File: C:\WINDOWS\system32\LPK.DLL ok scanned
22/03/1430 03:56:14 م Running module: RealPlay.exe\USP10.dll ok scanned
22/03/1430 03:56:14 م File: C:\WINDOWS\system32\USP10.dll ok scanned
22/03/1430 03:56:14 م Running module: RealPlay.exe\tazebama.dll ok scanned
22/03/1430 03:56:15 م File: C:\Documents and Settings\tazebama.dll detected virus 'Worm.Win32.Mabezat.b'
22/03/1430 03:56:16 م File: C:\Documents and Settings\tazebama.dll skipped processing stopped

Statistics
----------
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------

Settings
--------
Parameter Value
--------- -----
Security Level Recommended
Action Disinfect, delete if disinfection fails
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology No
Enable iSwift technology No
Show detected threats on "Detected" tab Yes
Rootkits search Yes
Deep rootkits search No
Use heuristic analyzer Yes

Quarantine
----------
Status Object Size Added
------ ------ ---- -----

Backup
------
Status Object Size
------ ------ ----
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe 748.9 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe 268.9 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows live\photo gallery\wlxphotogallery.exe 288.7 KB
Infected: virus Worm.Win32.Mabezat.b c:\zpharaoh.exe 151.2 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows live\mail\wlmail.exe 264.2 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE 216.2 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\nokia\nokia pc suite 6\launchapplication.exe 374.9 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\outlook express\setup50.exe 224.4 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\outlook express\wab.exe 197.9 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe 1.2 MB
Infected: virus Worm.Win32.Mabezat.b c:\documents and settings\ksa\desktop\greenbrowser\greenbrowser.exe 592.9 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\toshiba\toshiba applet\hwsetup.exe 180.9 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\du meter\dumeter.exe 1.7 MB
Infected: virus Worm.Win32.Mabezat.b c:\program files\spybot - search & destroy\spybotsd.exe 4.3 MB
Infected: virus Worm.Win32.Mabezat.b c:\program files\java\jre6\bin\javaws.exe 298.3 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows live\mail\wlmail.exe 264.2 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows live\photostudio.exe 1.2 MB
Infected: virus Worm.Win32.Mabezat.b c:\program files\nokia\nokia pc suite 6\pcsync2.exe 1.8 MB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\Java\jre6\bin\jqs.exe 302.3 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\google\common\google updater\googleupdaterservice.exe 286.8 KB
Infected: virus Worm.Win32.Mabezat.b c:\zpharaoh.exe 151.9 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows live\photo gallery\wlxphotogallery.exe 288.7 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\Webroot\Washer\wwDisp.exe 1.2 MB
Infected: virus Worm.Win32.Mabezat.b c:\program files\internet explorer\connection wizard\icwconn1.exe 362.4 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\Windows Live\Messenger\msnmsgr.exe 3.9 MB
Infected: virus Worm.Win32.Mabezat.b C:\Documents and Settings\tazebama.dll 32 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\Internet Explorer\iexplore.exe 772 KB
Infected: virus Worm.Win32.Mabezat.b c:\windows\system32\java.exe 294.3 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\nokia\nokia pc suite 6\pcsynclv.exe 856.9 KB
Infected: virus Worm.Win32.Mabezat.b C:\Documents and Settings\tazebama.dl_ 151.1 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\java\jre6\bin\javaw.exe 294.3 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 220.1 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\common files\real\update_ob\rnxproc.exe 210.4 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\nokia\nokia pc suite 6\contactseditor.exe 424.4 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows live\mail\wlmail.exe 264.2 KB
Infected: virus Worm.Win32.Mabezat.b C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE 1.5 MB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\Java\jre6\bin\jusched.exe 286.3 KB
Infected: virus Worm.Win32.Mabezat.b c:\zpharaoh.exe 151.3 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows media player\wmpnetwk.exe 1 MB
Infected: virus Worm.Win32.Mabezat.b c:\program files\real\realplayer\realplay.exe 362.4 KB
Infected: virus Worm.Win32.Mabezat.b C:\WINDOWS\system32\RAMASST.exe 304.9 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\pc connectivity solution\servicelayer.exe 438.9 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\outlook express\msimn.exe 211.9 KB
 
اعد تشغيل الجهاز واعمل تقرير هايجاك جديد
 
تفــــــــتضل


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:18:47 م, on 19/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Documents and Settings\ksa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Documents and Settings\tazebama.dl_
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\ksa\Desktop\Zyzoom_HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: TweakMASTER Component - {7DAAC7DE-9EF0-4FF0-BFA5-AFF3E899054C} - C:\PROGRA~1\TWEAKM~1\TweakBHO.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TweakMASTER] "C:\Program Files\TweakMASTER\TMTray.exe"
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [GreenBrowser] C:\Documents and Settings\ksa\Desktop\GreenBrowser\GreenBrowser.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\ksa\Application Data\Symantec\Layouts\Norton AntiVirus\15.0\SymAllLanguages\NAV_ESD\20070828\Support\SymLnch\SymLnch.exe" "C:\Documents and Settings\ksa\Application Data\Symantec\Layouts\Norton AntiVirus\15.0\SymAllLanguages\NAV_ESD\20070828\Setup.exe" "/UPREBOOT /temp /patched"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\ksa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Startup: is-H1SS6.lnk = C:\Documents and Settings\ksa\Desktop\Virus Removal Tool1\is-H1SS6\startup.exe
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Add to &LinkFox - res://C:\PROGRA~1\TWEAKM~1\TweakBHO.dll/IESCRIPT
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: تدوين هذا في المدونة - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &تدوين هذا في Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: McAfee Application Installer Cleanup (0138711232484630) (0138711232484630mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\013871~1.EXE (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

--
End of file - 12753 bytes
 
اعد الفحص باداة الكاسبر
وبعد انتهاء الفحص مباشرة اعد تشغيل الجهاز
ولا تشبك اي فلاش او هارد خارجي حتى الانتهاء
 
تفضل

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:20:39 ص, on 20/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Documents and Settings\ksa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Documents and Settings\ksa\Desktop\Virus Removal Tool1\is-H1SS6\is-H1SS6.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Documents and Settings\tazebama.dl_
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Documents and Settings\ksa\Desktop\Zyzoom_HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: TweakMASTER Component - {7DAAC7DE-9EF0-4FF0-BFA5-AFF3E899054C} - C:\PROGRA~1\TWEAKM~1\TweakBHO.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TweakMASTER] "C:\Program Files\TweakMASTER\TMTray.exe"
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [GreenBrowser] C:\Documents and Settings\ksa\Desktop\GreenBrowser\GreenBrowser.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\ksa\Application Data\Symantec\Layouts\Norton AntiVirus\15.0\SymAllLanguages\NAV_ESD\20070828\Support\SymLnch\SymLnch.exe" "C:\Documents and Settings\ksa\Application Data\Symantec\Layouts\Norton AntiVirus\15.0\SymAllLanguages\NAV_ESD\20070828\Setup.exe" "/UPREBOOT /temp /patched"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\ksa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Startup: is-H1SS6.lnk = C:\Documents and Settings\ksa\Desktop\Virus Removal Tool1\is-H1SS6\startup.exe
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Add to &LinkFox - res://C:\PROGRA~1\TWEAKM~1\TweakBHO.dll/IESCRIPT
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: تدوين هذا في المدونة - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &تدوين هذا في Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: McAfee Application Installer Cleanup (0138711232484630) (0138711232484630mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\013871~1.EXE (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

--
End of file - 12757 bytes
 
وهذا تقرير الكاسبر

Scan
----
Scanned: 579
Detected: 1
Untreated: 0
Start time: 24/03/1430 12:12:24 ص
Duration: 00:02:56
Finish time: 24/03/1430 12:15:20 ص

Detected
--------
Status Object
------ ------
will be deleted when the computer is restarted: virus Worm.Win32.Mabezat.b File: C:\Documents and Settings\tazebama.dl_

Events
------
Time Name Status Reason
---- ---- ------ ------
24/03/1430 12:14:43 ص Running module: iexplore.exe\iexplore.exe ok scanned
24/03/1430 12:14:50 ص File: C:\Program Files\Internet Explorer\iexplore.exe ok scanned
24/03/1430 12:14:50 ص Running module: iexplore.exe\ntdll.dll ok scanned
24/03/1430 12:14:50 ص File: C:\WINDOWS\system32\ntdll.dll ok scanned
24/03/1430 12:14:51 ص Running module: iexplore.exe\kernel32.dll ok scanned
24/03/1430 12:14:52 ص File: C:\WINDOWS\system32\kernel32.dll ok scanned
24/03/1430 12:14:52 ص Running module: iexplore.exe\msvcrt.dll ok scanned
24/03/1430 12:14:52 ص File: C:\WINDOWS\system32\msvcrt.dll ok scanned
24/03/1430 12:14:52 ص Running module: iexplore.exe\USER32.dll ok scanned
24/03/1430 12:14:53 ص File: C:\WINDOWS\system32\USER32.dll ok scanned
24/03/1430 12:14:53 ص Running module: iexplore.exe\GDI32.dll ok scanned
24/03/1430 12:14:54 ص File: C:\WINDOWS\system32\GDI32.dll ok scanned
24/03/1430 12:14:54 ص Running module: iexplore.exe\SHLWAPI.dll ok scanned
24/03/1430 12:14:54 ص File: C:\WINDOWS\system32\SHLWAPI.dll ok scanned
24/03/1430 12:14:54 ص Running module: iexplore.exe\ADVAPI32.dll ok scanned
24/03/1430 12:14:56 ص File: C:\WINDOWS\system32\ADVAPI32.dll ok scanned
24/03/1430 12:14:56 ص Running module: iexplore.exe\RPCRT4.dll ok scanned
24/03/1430 12:14:56 ص File: C:\WINDOWS\system32\RPCRT4.dll ok scanned
24/03/1430 12:14:56 ص Running module: iexplore.exe\Secur32.dll ok scanned
24/03/1430 12:14:56 ص File: C:\WINDOWS\system32\Secur32.dll ok scanned
24/03/1430 12:14:57 ص Running module: iexplore.exe\SHDOCVW.dll ok scanned
24/03/1430 12:14:57 ص File: C:\WINDOWS\system32\SHDOCVW.dll ok scanned
24/03/1430 12:14:58 ص Running module: iexplore.exe\CRYPT32.dll ok scanned
24/03/1430 12:14:58 ص File: C:\WINDOWS\system32\CRYPT32.dll ok scanned
24/03/1430 12:14:58 ص Running module: iexplore.exe\MSASN1.dll ok scanned
24/03/1430 12:14:58 ص File: C:\WINDOWS\system32\MSASN1.dll ok scanned
24/03/1430 12:14:59 ص Running module: iexplore.exe\CRYPTUI.dll ok scanned
24/03/1430 12:14:59 ص File: C:\WINDOWS\system32\CRYPTUI.dll ok scanned
24/03/1430 12:15:00 ص Running module: iexplore.exe\NETAPI32.dll ok scanned
24/03/1430 12:15:00 ص File: C:\WINDOWS\system32\NETAPI32.dll ok scanned
24/03/1430 12:15:00 ص Running module: iexplore.exe\OLEAUT32.dll ok scanned
24/03/1430 12:15:00 ص File: C:\WINDOWS\system32\OLEAUT32.dll ok scanned
24/03/1430 12:15:00 ص Running module: iexplore.exe\ole32.dll ok scanned
24/03/1430 12:15:00 ص File: C:\WINDOWS\system32\ole32.dll ok scanned
24/03/1430 12:15:00 ص Running module: iexplore.exe\VERSION.dll ok scanned
24/03/1430 12:15:00 ص File: C:\WINDOWS\system32\VERSION.dll ok scanned
24/03/1430 12:15:00 ص Running module: iexplore.exe\WININET.dll ok scanned
24/03/1430 12:15:00 ص File: C:\WINDOWS\system32\WININET.dll packed file PE_Patch
24/03/1430 12:15:00 ص File: C:\WINDOWS\system32\WININET.dll//PE_Patch ok scanned
24/03/1430 12:15:00 ص File: C:\WINDOWS\system32\WININET.dll ok scanned
24/03/1430 12:15:00 ص Running module: iexplore.exe\Normaliz.dll ok scanned
24/03/1430 12:15:00 ص File: C:\WINDOWS\system32\Normaliz.dll ok scanned
24/03/1430 12:15:00 ص Running module: iexplore.exe\iertutil.dll ok scanned
24/03/1430 12:15:00 ص File: C:\WINDOWS\system32\iertutil.dll ok scanned
24/03/1430 12:15:01 ص Running module: iexplore.exe\WINTRUST.dll ok scanned
24/03/1430 12:15:01 ص File: C:\WINDOWS\system32\WINTRUST.dll ok scanned
24/03/1430 12:15:01 ص Running module: iexplore.exe\IMAGEHLP.dll ok scanned
24/03/1430 12:15:01 ص File: C:\WINDOWS\system32\IMAGEHLP.dll ok scanned
24/03/1430 12:15:01 ص Running module: iexplore.exe\WLDAP32.dll ok scanned
24/03/1430 12:15:01 ص File: C:\WINDOWS\system32\WLDAP32.dll ok scanned
24/03/1430 12:15:01 ص Running module: iexplore.exe\IMM32.DLL ok scanned
24/03/1430 12:15:01 ص File: C:\WINDOWS\system32\IMM32.DLL ok scanned
24/03/1430 12:15:01 ص Running module: iexplore.exe\LPK.DLL ok scanned
24/03/1430 12:15:01 ص File: C:\WINDOWS\system32\LPK.DLL ok scanned
24/03/1430 12:15:01 ص Running module: iexplore.exe\USP10.dll ok scanned
24/03/1430 12:15:01 ص File: C:\WINDOWS\system32\USP10.dll ok scanned
24/03/1430 12:15:01 ص Running module: iexplore.exe\comctl32.dll ok scanned
24/03/1430 12:15:01 ص File: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll ok scanned
24/03/1430 12:15:01 ص Running module: iexplore.exe\ieframe.dll ok scanned
24/03/1430 12:15:02 ص File: C:\WINDOWS\system32\ieframe.dll ok scanned
24/03/1430 12:15:02 ص Running module: iexplore.exe\PSAPI.DLL ok scanned
24/03/1430 12:15:02 ص File: C:\WINDOWS\system32\PSAPI.DLL ok scanned
24/03/1430 12:15:02 ص Running module: iexplore.exe\SHELL32.dll ok scanned
24/03/1430 12:15:02 ص File: C:\WINDOWS\system32\SHELL32.dll ok scanned
24/03/1430 12:15:02 ص Running module: iexplore.exe\UxTheme.dll ok scanned
24/03/1430 12:15:02 ص File: C:\WINDOWS\system32\UxTheme.dll ok scanned
24/03/1430 12:15:02 ص Running module: iexplore.exe\comctl32.dll ok scanned
24/03/1430 12:15:02 ص File: C:\WINDOWS\system32\comctl32.dll ok scanned
24/03/1430 12:15:02 ص Running module: iexplore.exe\MSCTF.dll ok scanned
24/03/1430 12:15:02 ص File: C:\WINDOWS\system32\MSCTF.dll ok scanned
24/03/1430 12:15:02 ص Running module: iexplore.exe\BROWSEUI.dll ok scanned
24/03/1430 12:15:02 ص File: C:\WINDOWS\system32\BROWSEUI.dll ok scanned
24/03/1430 12:15:02 ص Running module: iexplore.exe\browselc.dll ok scanned
24/03/1430 12:15:03 ص File: C:\WINDOWS\system32\browselc.dll archive EmbeddedHTML
24/03/1430 12:15:03 ص File: C:\WINDOWS\system32\browselc.dll//data0001.html ok scanned
24/03/1430 12:15:03 ص File: C:\WINDOWS\system32\browselc.dll//data0002.html ok scanned
24/03/1430 12:15:03 ص File: C:\WINDOWS\system32\browselc.dll//data0003.html ok scanned
24/03/1430 12:15:03 ص File: C:\WINDOWS\system32\browselc.dll ok scanned
24/03/1430 12:15:03 ص Running module: iexplore.exe\appHelp.dll ok scanned
24/03/1430 12:15:03 ص File: C:\WINDOWS\system32\appHelp.dll ok scanned
24/03/1430 12:15:03 ص Running module: iexplore.exe\CLBCATQ.DLL ok scanned
24/03/1430 12:15:03 ص File: C:\WINDOWS\system32\CLBCATQ.DLL ok scanned
24/03/1430 12:15:03 ص Running module: iexplore.exe\COMRes.dll ok scanned
24/03/1430 12:15:03 ص File: C:\WINDOWS\system32\COMRes.dll ok scanned
24/03/1430 12:15:03 ص Running module: iexplore.exe\msctfime.ime ok scanned
24/03/1430 12:15:03 ص File: C:\WINDOWS\system32\msctfime.ime ok scanned
24/03/1430 12:15:03 ص Running module: iexplore.exe\urlmon.dll ok scanned
24/03/1430 12:15:03 ص File: C:\WINDOWS\system32\urlmon.dll ok scanned
24/03/1430 12:15:03 ص Running module: iexplore.exe\ws2_32.dll ok scanned
24/03/1430 12:15:03 ص File: C:\WINDOWS\system32\ws2_32.dll ok scanned
24/03/1430 12:15:03 ص Running module: iexplore.exe\WS2HELP.dll ok scanned
24/03/1430 12:15:03 ص File: C:\WINDOWS\system32\WS2HELP.dll ok scanned
24/03/1430 12:15:03 ص Running module: iexplore.exe\cscui.dll ok scanned
24/03/1430 12:15:03 ص File: C:\WINDOWS\System32\cscui.dll ok scanned
24/03/1430 12:15:03 ص Running module: iexplore.exe\CSCDLL.dll ok scanned
24/03/1430 12:15:03 ص File: C:\WINDOWS\System32\CSCDLL.dll ok scanned
24/03/1430 12:15:03 ص Running module: iexplore.exe\SETUPAPI.dll ok scanned
24/03/1430 12:15:04 ص File: C:\WINDOWS\system32\SETUPAPI.dll ok scanned
24/03/1430 12:15:04 ص Running module: iexplore.exe\yt.dll ok scanned
24/03/1430 12:15:04 ص File: C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll ok scanned
24/03/1430 12:15:04 ص Running module: iexplore.exe\WSOCK32.dll ok scanned
24/03/1430 12:15:04 ص File: C:\WINDOWS\system32\WSOCK32.dll ok scanned
24/03/1430 12:15:04 ص Running module: iexplore.exe\WINMM.dll ok scanned
24/03/1430 12:15:04 ص File: C:\WINDOWS\system32\WINMM.dll ok scanned
24/03/1430 12:15:04 ص Running module: iexplore.exe\RASAPI32.DLL ok scanned
24/03/1430 12:15:04 ص File: C:\WINDOWS\system32\RASAPI32.DLL ok scanned
24/03/1430 12:15:04 ص Running module: iexplore.exe\rasman.dll ok scanned
24/03/1430 12:15:04 ص File: C:\WINDOWS\system32\rasman.dll ok scanned
24/03/1430 12:15:04 ص Running module: iexplore.exe\TAPI32.dll ok scanned
24/03/1430 12:15:04 ص File: C:\WINDOWS\system32\TAPI32.dll ok scanned
24/03/1430 12:15:04 ص Running module: iexplore.exe\rtutils.dll ok scanned
24/03/1430 12:15:04 ص File: C:\WINDOWS\system32\rtutils.dll ok scanned
24/03/1430 12:15:04 ص Running module: iexplore.exe\mlang.dll ok scanned
24/03/1430 12:15:04 ص File: C:\WINDOWS\system32\mlang.dll ok scanned
24/03/1430 12:15:04 ص Running module: iexplore.exe\wltcore.dll ok scanned
24/03/1430 12:15:04 ص File: C:\Program Files\Windows Live\Toolbar\wltcore.dll ok scanned
24/03/1430 12:15:04 ص Running module: iexplore.exe\MSVCR80.dll ok scanned
24/03/1430 12:15:04 ص File: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1801_x-ww_5eed8217\MSVCR80.dll ok scanned
24/03/1430 12:15:04 ص Running module: iexplore.exe\sqmapi.dll ok scanned
24/03/1430 12:15:04 ص File: C:\Program Files\Windows Live\Toolbar\sqmapi.dll ok scanned
24/03/1430 12:15:04 ص Running module: iexplore.exe\msidcrl40.dll ok scanned
24/03/1430 12:15:04 ص File: C:\Program Files\Windows Live\Toolbar\msidcrl40.dll ok scanned
24/03/1430 12:15:04 ص Running module: iexplore.exe\OLEACC.dll ok scanned
24/03/1430 12:15:04 ص File: C:\WINDOWS\system32\OLEACC.dll ok scanned
24/03/1430 12:15:04 ص Running module: iexplore.exe\MSVCP60.dll ok scanned
24/03/1430 12:15:05 ص File: C:\WINDOWS\system32\MSVCP60.dll ok scanned
24/03/1430 12:15:05 ص Running module: iexplore.exe\SensApi.dll ok scanned
24/03/1430 12:15:05 ص File: C:\WINDOWS\system32\SensApi.dll ok scanned
24/03/1430 12:15:05 ص Running module: iexplore.exe\gdiplus.dll ok scanned
24/03/1430 12:15:05 ص File: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\gdiplus.dll ok scanned
24/03/1430 12:15:05 ص Running module: iexplore.exe\MSIMG32.dll ok scanned
24/03/1430 12:15:05 ص File: C:\WINDOWS\system32\MSIMG32.dll ok scanned
24/03/1430 12:15:05 ص Running module: iexplore.exe\Cabinet.dll ok scanned
24/03/1430 12:15:05 ص File: C:\WINDOWS\system32\Cabinet.dll ok scanned
24/03/1430 12:15:05 ص Running module: iexplore.exe\xpsp2res.dll ok scanned
24/03/1430 12:15:05 ص File: C:\WINDOWS\system32\xpsp2res.dll ok scanned
24/03/1430 12:15:05 ص Running module: iexplore.exe\actxprxy.dll ok scanned
24/03/1430 12:15:05 ص File: C:\WINDOWS\system32\actxprxy.dll ok scanned
24/03/1430 12:15:05 ص Running module: iexplore.exe\msi.dll ok scanned
24/03/1430 12:15:05 ص File: C:\WINDOWS\system32\msi.dll ok scanned
24/03/1430 12:15:05 ص Running module: iexplore.exe\SXS.DLL ok scanned
24/03/1430 12:15:05 ص File: C:\WINDOWS\system32\SXS.DLL ok scanned
24/03/1430 12:15:05 ص Running module: iexplore.exe\wltcore.market.dll.mui ok scanned
24/03/1430 12:15:05 ص File: C:\Program Files\Windows Live\Toolbar\ar-sa\wltcore.market.dll.mui ok scanned
24/03/1430 12:15:05 ص Running module: iexplore.exe\wltcore.dll.mui ok scanned
24/03/1430 12:15:06 ص File: C:\Program Files\Windows Live\Toolbar\ar\wltcore.dll.mui archive EmbeddedHTML
24/03/1430 12:15:06 ص File: C:\Program Files\Windows Live\Toolbar\ar\wltcore.dll.mui//data0001.html ok scanned
24/03/1430 12:15:06 ص File: C:\Program Files\Windows Live\Toolbar\ar\wltcore.dll.mui ok scanned
24/03/1430 12:15:06 ص Running module: iexplore.exe\msxml3.dll ok scanned
24/03/1430 12:15:06 ص File: C:\WINDOWS\system32\msxml3.dll ok scanned
24/03/1430 12:15:06 ص Running module: iexplore.exe\rsaenh.dll ok scanned
24/03/1430 12:15:06 ص File: C:\WINDOWS\system32\rsaenh.dll ok scanned
24/03/1430 12:15:06 ص Running module: iexplore.exe\userenv.dll ok scanned
24/03/1430 12:15:06 ص File: C:\WINDOWS\system32\userenv.dll ok scanned
24/03/1430 12:15:06 ص Running module: iexplore.exe\GoogleToolbar.dll ok scanned
24/03/1430 12:15:06 ص File: C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ok scanned
24/03/1430 12:15:06 ص Running module: iexplore.exe\GoogleToolbarDynamic_F423308312A7B033.dll ok scanned
24/03/1430 12:15:06 ص File: C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_F423308312A7B033.dll ok scanned
24/03/1430 12:15:06 ص Running module: iexplore.exe\dbghelp.dll ok scanned
24/03/1430 12:15:06 ص File: C:\WINDOWS\system32\dbghelp.dll ok scanned
24/03/1430 12:15:06 ص Running module: iexplore.exe\cryptnet.dll ok scanned
24/03/1430 12:15:06 ص File: C:\WINDOWS\system32\cryptnet.dll ok scanned
24/03/1430 12:15:06 ص Running module: iexplore.exe\WINHTTP.dll ok scanned
24/03/1430 12:15:06 ص File: C:\WINDOWS\system32\WINHTTP.dll ok scanned
24/03/1430 12:15:06 ص Running module: iexplore.exe\swg.dll ok scanned
24/03/1430 12:15:06 ص File: C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll ok scanned
24/03/1430 12:15:06 ص Running module: iexplore.exe\iphlpapi.dll ok scanned
24/03/1430 12:15:06 ص File: C:\WINDOWS\system32\iphlpapi.dll ok scanned
24/03/1430 12:15:06 ص Running module: iexplore.exe\AcroIEHelperShim.dll ok scanned
24/03/1430 12:15:06 ص File: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll ok scanned
24/03/1430 12:15:06 ص Running module: iexplore.exe\MSVCP80.dll ok scanned
24/03/1430 12:15:06 ص File: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1801_x-ww_5eed8217\MSVCP80.dll ok scanned
24/03/1430 12:15:06 ص Running module: iexplore.exe\AcroIEHelper.dll ok scanned
24/03/1430 12:15:06 ص File: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll ok scanned
24/03/1430 12:15:06 ص Running module: iexplore.exe\rpbrowserrecordplugin.dll ok scanned
24/03/1430 12:15:07 ص File: C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll ok scanned
24/03/1430 12:15:07 ص Running module: iexplore.exe\comdlg32.dll ok scanned
24/03/1430 12:15:07 ص File: C:\WINDOWS\system32\comdlg32.dll ok scanned
24/03/1430 12:15:07 ص Running module: iexplore.exe\MSVCP71.dll ok scanned
24/03/1430 12:15:07 ص File: C:\WINDOWS\system32\MSVCP71.dll ok scanned
24/03/1430 12:15:07 ص Running module: iexplore.exe\MSVCR71.dll ok scanned
24/03/1430 12:15:07 ص File: C:\WINDOWS\system32\MSVCR71.dll ok scanned
24/03/1430 12:15:07 ص Running module: iexplore.exe\SDHelper.dll ok scanned
24/03/1430 12:15:07 ص File: C:\PROGRA~1\SPYBOT~1\SDHelper.dll ok scanned
24/03/1430 12:15:07 ص Running module: iexplore.exe\olepro32.dll ok scanned
24/03/1430 12:15:07 ص File: C:\WINDOWS\system32\olepro32.dll ok scanned
24/03/1430 12:15:07 ص Running module: iexplore.exe\SearchHelper.dll ok scanned
24/03/1430 12:15:07 ص File: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll ok scanned
24/03/1430 12:15:07 ص Running module: iexplore.exe\SRCHBXEX.dll ok scanned
24/03/1430 12:15:07 ص File: C:\Program Files\Microsoft\Search Enhancement Pack\Search Box Extension\SRCHBXEX.dll ok scanned
24/03/1430 12:15:07 ص Running module: iexplore.exe\SEASHADO.dll ok scanned
24/03/1430 12:15:07 ص File: C:\Program Files\Microsoft\Search Enhancement Pack\SeaShadow\SEASHADO.dll ok scanned
24/03/1430 12:15:07 ص Running module: iexplore.exe\ssv.dll ok scanned
24/03/1430 12:15:07 ص File: C:\Program Files\Java\jre6\bin\ssv.dll ok scanned
24/03/1430 12:15:07 ص Running module: iexplore.exe\TweakBHO.dll ok scanned
24/03/1430 12:15:07 ص File: C:\PROGRA~1\TWEAKM~1\TweakBHO.dll ok scanned
24/03/1430 12:15:07 ص Running module: iexplore.exe\WindowsLiveLogin.dll ok scanned
24/03/1430 12:15:08 ص File: C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll ok scanned
24/03/1430 12:15:08 ص Running module: iexplore.exe\fastsearch_219B3E1547538286.dll ok scanned
24/03/1430 12:15:08 ص File: C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll ok scanned
24/03/1430 12:15:08 ص Running module: iexplore.exe\jp2ssv.dll ok scanned
24/03/1430 12:15:08 ص File: C:\Program Files\Java\jre6\bin\jp2ssv.dll ok scanned
24/03/1430 12:15:08 ص Running module: iexplore.exe\jqs_plugin.dll ok scanned
24/03/1430 12:15:08 ص File: C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll ok scanned
24/03/1430 12:15:08 ص Running module: iexplore.exe\mswsock.dll ok scanned
24/03/1430 12:15:08 ص File: C:\WINDOWS\system32\mswsock.dll ok scanned
24/03/1430 12:15:08 ص Running module: iexplore.exe\hnetcfg.dll ok scanned
24/03/1430 12:15:08 ص File: C:\WINDOWS\system32\hnetcfg.dll ok scanned
24/03/1430 12:15:08 ص Running module: iexplore.exe\wshtcpip.dll ok scanned
24/03/1430 12:15:08 ص File: C:\WINDOWS\System32\wshtcpip.dll ok scanned
24/03/1430 12:15:08 ص Running module: iexplore.exe\shdoclc.dll ok scanned
24/03/1430 12:15:08 ص File: C:\WINDOWS\system32\shdoclc.dll ok scanned
24/03/1430 12:15:08 ص Running module: iexplore.exe\msidcrl40.dll ok scanned
24/03/1430 12:15:08 ص File: C:\Program Files\Common Files\Microsoft Shared\Windows Live\msidcrl40.dll ok scanned
24/03/1430 12:15:08 ص Running module: iexplore.exe\msv1_0.dll ok scanned
24/03/1430 12:15:08 ص File: C:\WINDOWS\system32\msv1_0.dll ok scanned
24/03/1430 12:15:08 ص Running module: iexplore.exe\rasadhlp.dll ok scanned
24/03/1430 12:15:08 ص File: C:\WINDOWS\system32\rasadhlp.dll ok scanned
24/03/1430 12:15:08 ص Running module: iexplore.exe\DNSAPI.dll ok scanned
24/03/1430 12:15:08 ص File: C:\WINDOWS\system32\DNSAPI.dll ok scanned
24/03/1430 12:15:08 ص Running module: iexplore.exe\winrnr.dll ok scanned
24/03/1430 12:15:08 ص File: C:\WINDOWS\System32\winrnr.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\MPRAPI.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\system32\MPRAPI.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\ACTIVEDS.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\system32\ACTIVEDS.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\adsldpc.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\system32\adsldpc.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\ATL.DLL ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\system32\ATL.DLL ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\SAMLIB.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\system32\SAMLIB.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\ntshrui.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\system32\ntshrui.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\MPR.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\system32\MPR.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\ntlanman.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\System32\ntlanman.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\NETUI0.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\System32\NETUI0.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\NETUI1.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\System32\NETUI1.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\NETRAP.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\System32\NETRAP.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\drprov.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\System32\drprov.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\davclnt.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\System32\davclnt.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\PortableDeviceApi.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\system32\PortableDeviceApi.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\MSGINA.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\system32\MSGINA.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\ODBC32.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\system32\ODBC32.dll ok scanned
24/03/1430 12:15:09 ص Running module: iexplore.exe\WINSTA.dll ok scanned
24/03/1430 12:15:09 ص File: C:\WINDOWS\system32\WINSTA.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\odbcint.dll ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\odbcint.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\sti.dll ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\sti.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\CFGMGR32.dll ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\CFGMGR32.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\mshtml.dll ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\mshtml.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\msls31.dll ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\msls31.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\ieapfltr.dll ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\ieapfltr.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\NTMARTA.DLL ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\NTMARTA.DLL ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\pubmod.dll ok scanned
24/03/1430 12:15:10 ص File: C:\Program Files\Yahoo!\Companion\Installs\cpn\pubmod.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\ypubc.dll ok scanned
24/03/1430 12:15:10 ص File: C:\Program Files\Yahoo!\Companion\Installs\cpn\ypubc.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\YMERemote.dll ok scanned
24/03/1430 12:15:10 ص File: C:\Program Files\Yahoo!\Companion\Installs\cpn\YMERemote.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\msimtf.dll ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\msimtf.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\jscript.dll ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\jscript.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\iepeers.dll ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\iepeers.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\WINSPOOL.DRV ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\WINSPOOL.DRV ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\ImgUtil.dll ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\ImgUtil.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\pngfilt.dll ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\pngfilt.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\mshtmled.dll ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\mshtmled.dll ok scanned
24/03/1430 12:15:10 ص Running module: iexplore.exe\wdmaud.drv ok scanned
24/03/1430 12:15:10 ص File: C:\WINDOWS\system32\wdmaud.drv ok scanned
24/03/1430 12:15:11 ص Running module: iexplore.exe\msacm32.drv ok scanned
24/03/1430 12:15:11 ص File: C:\WINDOWS\system32\msacm32.drv ok scanned
24/03/1430 12:15:11 ص Running module: iexplore.exe\MSACM32.dll ok scanned
24/03/1430 12:15:11 ص File: C:\WINDOWS\system32\MSACM32.dll ok scanned
24/03/1430 12:15:11 ص Running module: iexplore.exe\midimap.dll ok scanned
24/03/1430 12:15:11 ص File: C:\WINDOWS\system32\midimap.dll ok scanned
24/03/1430 12:15:11 ص Running module: iexplore.exe\Flash10b.ocx ok scanned
24/03/1430 12:15:11 ص File: C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx ok scanned
24/03/1430 12:15:11 ص Running module: iexplore.exe\mscms.dll ok scanned
24/03/1430 12:15:11 ص File: C:\WINDOWS\system32\mscms.dll ok scanned
24/03/1430 12:15:11 ص Running module: iexplore.exe\schannel.dll ok scanned
24/03/1430 12:15:11 ص File: C:\WINDOWS\system32\schannel.dll ok scanned
24/03/1430 12:15:11 ص Running module: iexplore.exe\ddrawex.dll ok scanned
24/03/1430 12:15:11 ص File: C:\WINDOWS\system32\ddrawex.dll ok scanned
24/03/1430 12:15:11 ص Running module: iexplore.exe\DDRAW.dll ok scanned
24/03/1430 12:15:11 ص File: C:\WINDOWS\system32\DDRAW.dll ok scanned
24/03/1430 12:15:11 ص Running module: iexplore.exe\DCIMAN32.dll ok scanned
24/03/1430 12:15:11 ص File: C:\WINDOWS\system32\DCIMAN32.dll ok scanned
24/03/1430 12:15:11 ص Running module: TosBtHsp.exe\TosBtHsp.exe ok scanned
24/03/1430 12:15:11 ص File: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe ok scanned
24/03/1430 12:15:11 ص Running module: TosBtHsp.exe\ntdll.dll ok scanned
24/03/1430 12:15:11 ص File: C:\WINDOWS\system32\ntdll.dll ok scanned
24/03/1430 12:15:11 ص Running module: TosBtHsp.exe\kernel32.dll ok scanned
24/03/1430 12:15:11 ص File: C:\WINDOWS\system32\kernel32.dll ok scanned
24/03/1430 12:15:11 ص Running module: TosBtHsp.exe\TosBtECCAPI.dll ok scanned
24/03/1430 12:15:11 ص File: C:\WINDOWS\system32\TosBtECCAPI.dll ok scanned
24/03/1430 12:15:11 ص Running module: TosBtHsp.exe\TosBtAPI.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\TosBtAPI.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\TosBdAPI.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\TosBdAPI.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\USER32.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\USER32.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\GDI32.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\GDI32.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\ADVAPI32.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\ADVAPI32.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\RPCRT4.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\RPCRT4.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\Secur32.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\Secur32.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\ole32.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\ole32.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\msvcrt.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\msvcrt.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\SETUPAPI.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\SETUPAPI.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\LCWizard.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\LCWizard.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\SHELL32.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\SHELL32.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\SHLWAPI.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\SHLWAPI.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\COMCTL32.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\COMCTL32.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\HHCTRL.OCX ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\HHCTRL.OCX ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\OLEAUT32.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\OLEAUT32.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\TosSndAPI.dll ok scanned
24/03/1430 12:15:12 ص File: C:\WINDOWS\system32\TosSndAPI.dll ok scanned
24/03/1430 12:15:12 ص Running module: TosBtHsp.exe\WINMM.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\WINMM.dll ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHsp.exe\TosSndPlug.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\TosSndPlug.dll ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHsp.exe\WINSPOOL.DRV ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\WINSPOOL.DRV ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHsp.exe\IMM32.DLL ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\IMM32.DLL ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHsp.exe\LPK.DLL ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\LPK.DLL ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHsp.exe\USP10.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\USP10.dll ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHsp.exe\comctl32.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHsp.exe\uxtheme.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\uxtheme.dll ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHsp.exe\MSCTF.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\MSCTF.dll ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHsp.exe\msctfime.ime ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\msctfime.ime ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHsp.exe\CLBCATQ.DLL ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\CLBCATQ.DLL ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHsp.exe\COMRes.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\COMRes.dll ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHsp.exe\VERSION.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\VERSION.dll ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHid.exe\TosBtHid.exe ok scanned
24/03/1430 12:15:13 ص File: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHid.exe\ntdll.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\ntdll.dll ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHid.exe\kernel32.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\kernel32.dll ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHid.exe\USER32.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\USER32.dll ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHid.exe\GDI32.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\GDI32.dll ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHid.exe\ADVAPI32.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\ADVAPI32.dll ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHid.exe\RPCRT4.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\RPCRT4.dll ok scanned
24/03/1430 12:15:13 ص Running module: TosBtHid.exe\Secur32.dll ok scanned
24/03/1430 12:15:13 ص File: C:\WINDOWS\system32\Secur32.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosBtHid.exe\IMM32.DLL ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\IMM32.DLL ok scanned
24/03/1430 12:15:14 ص Running module: TosBtHid.exe\LPK.DLL ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\LPK.DLL ok scanned
24/03/1430 12:15:14 ص Running module: TosBtHid.exe\USP10.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\USP10.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosBtHid.exe\uxtheme.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\uxtheme.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosBtHid.exe\msvcrt.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\msvcrt.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosBtHid.exe\MSCTF.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\MSCTF.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosBtHid.exe\msctfime.ime ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\msctfime.ime ok scanned
24/03/1430 12:15:14 ص Running module: TosBtHid.exe\ole32.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\ole32.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosBtHid.exe\CLBCATQ.DLL ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\CLBCATQ.DLL ok scanned
24/03/1430 12:15:14 ص Running module: TosBtHid.exe\COMRes.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\COMRes.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosBtHid.exe\OLEAUT32.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\OLEAUT32.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosBtHid.exe\VERSION.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\VERSION.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosA2dp.exe\TosA2dp.exe ok scanned
24/03/1430 12:15:14 ص File: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe ok scanned
24/03/1430 12:15:14 ص Running module: TosA2dp.exe\ntdll.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\ntdll.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosA2dp.exe\kernel32.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\kernel32.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosA2dp.exe\TosBtECCAPI.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\TosBtECCAPI.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosA2dp.exe\TosBtAPI.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\TosBtAPI.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosA2dp.exe\TosBdAPI.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\TosBdAPI.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosA2dp.exe\USER32.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\USER32.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosA2dp.exe\GDI32.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\GDI32.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosA2dp.exe\ADVAPI32.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\ADVAPI32.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosA2dp.exe\RPCRT4.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\RPCRT4.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosA2dp.exe\Secur32.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\Secur32.dll ok scanned
24/03/1430 12:15:14 ص Running module: TosA2dp.exe\ole32.dll ok scanned
24/03/1430 12:15:14 ص File: C:\WINDOWS\system32\ole32.dll ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\msvcrt.dll ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\msvcrt.dll ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\SETUPAPI.dll ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\SETUPAPI.dll ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\TosAvdtAPI.dll ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\TosAvdtAPI.dll ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\TosSndAPI.dll ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\TosSndAPI.dll ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\TosSndPlug.dll ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\TosSndPlug.dll ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\WINMM.dll ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\WINMM.dll ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\WINSPOOL.DRV ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\WINSPOOL.DRV ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\COMCTL32.dll ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.dll ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\SHLWAPI.dll ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\SHLWAPI.dll ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\IMM32.DLL ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\IMM32.DLL ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\LPK.DLL ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\LPK.DLL ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\USP10.dll ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\USP10.dll ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\uxtheme.dll ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\uxtheme.dll ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\MSCTF.dll ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\MSCTF.dll ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\msctfime.ime ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\msctfime.ime ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\CLBCATQ.DLL ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\CLBCATQ.DLL ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\COMRes.dll ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\COMRes.dll ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\OLEAUT32.dll ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\OLEAUT32.dll ok scanned
24/03/1430 12:15:15 ص Running module: TosA2dp.exe\VERSION.dll ok scanned
24/03/1430 12:15:15 ص File: C:\WINDOWS\system32\VERSION.dll ok scanned
24/03/1430 12:15:15 ص Running module: BTSTAC~1.EXE\BTSTAC~1.EXE ok scanned
24/03/1430 12:15:16 ص File: C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\ntdll.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\ntdll.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\kernel32.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\kernel32.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\btins.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\btins.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\msi.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\msi.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\ADVAPI32.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\ADVAPI32.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\RPCRT4.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\RPCRT4.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\Secur32.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\Secur32.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\GDI32.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\GDI32.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\USER32.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\USER32.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\msvcrt.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\msvcrt.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\SHLWAPI.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\SHLWAPI.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\TAPI32.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\TAPI32.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\rtutils.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\rtutils.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\WINMM.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\WINMM.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\SETUPAPI.dll ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\SETUPAPI.dll ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\MFC42.DLL ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\MFC42.DLL ok scanned
24/03/1430 12:15:16 ص Running module: BTSTAC~1.EXE\WINSPOOL.DRV ok scanned
24/03/1430 12:15:16 ص File: C:\WINDOWS\system32\WINSPOOL.DRV ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\SHELL32.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\SHELL32.dll ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\ole32.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\ole32.dll ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\VERSION.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\VERSION.dll ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\MSVCP60.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\MSVCP60.dll ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\btosif.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\btosif.dll ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\WS2_32.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\WS2_32.dll ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\WS2HELP.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\WS2HELP.dll ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\OLEAUT32.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\OLEAUT32.dll ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\iphlpapi.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\iphlpapi.dll ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\BtAudioHelper.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\BtAudioHelper.dll ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\IMM32.DLL ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\IMM32.DLL ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\LPK.DLL ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\LPK.DLL ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\USP10.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\USP10.dll ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\comctl32.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\comctl32.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\comctl32.dll ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\btrez.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\btrez.dll ok scanned
24/03/1430 12:15:17 ص Running module: BTSTAC~1.EXE\CSH.dll ok scanned
24/03/1430 12:15:17 ص File: C:\WINDOWS\system32\CSH.dll ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\comdlg32.dll ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\comdlg32.dll ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\WINTRUST.dll ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\WINTRUST.dll ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\CRYPT32.dll ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\CRYPT32.dll ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\MSASN1.dll ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\MSASN1.dll ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\IMAGEHLP.dll ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\IMAGEHLP.dll ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\CLBCATQ.DLL ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\CLBCATQ.DLL ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\COMRes.dll ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\COMRes.dll ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\xpsp2res.dll ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\xpsp2res.dll ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\uxtheme.dll ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\uxtheme.dll ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\SXS.DLL ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\SXS.DLL ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\MSCTF.dll ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\MSCTF.dll ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\msctfime.ime ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\msctfime.ime ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\Wtsapi32.dll ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\Wtsapi32.dll ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\WINSTA.dll ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\WINSTA.dll ok scanned
24/03/1430 12:15:18 ص Running module: BTSTAC~1.EXE\NETAPI32.dll ok scanned
24/03/1430 12:15:18 ص File: C:\WINDOWS\system32\NETAPI32.dll ok scanned
24/03/1430 12:15:18 ص Running module: tazebama.dl_\tazebama.dl_ ok scanned
24/03/1430 12:15:18 ص File: C:\Documents and Settings\tazebama.dl_ detected virus 'Worm.Win32.Mabezat.b'

Statistics
----------
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------

Settings
--------
Parameter Value
--------- -----
Security Level Recommended
Action Disinfect, delete if disinfection fails
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology No
Enable iSwift technology No
Show detected threats on "Detected" tab Yes
Rootkits search Yes
Deep rootkits search No
Use heuristic analyzer Yes

Quarantine
----------
Status Object Size Added
------ ------ ---- -----

Backup
------
Status Object Size
------ ------ ----
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe 748.9 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe 268.9 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows live\photo gallery\wlxphotogallery.exe 288.7 KB
Infected: virus Worm.Win32.Mabezat.b c:\zpharaoh.exe 151.2 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows live\mail\wlmail.exe 264.2 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE 216.2 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\nokia\nokia pc suite 6\launchapplication.exe 374.9 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\outlook express\setup50.exe 224.4 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\outlook express\wab.exe 197.9 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe 1.2 MB
Infected: virus Worm.Win32.Mabezat.b c:\documents and settings\ksa\desktop\greenbrowser\greenbrowser.exe 592.9 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\toshiba\toshiba applet\hwsetup.exe 180.9 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\du meter\dumeter.exe 1.7 MB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows live\mail\wlmail.exe 264.2 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\spybot - search & destroy\spybotsd.exe 4.3 MB
Infected: virus Worm.Win32.Mabezat.b c:\program files\java\jre6\bin\javaws.exe 298.3 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows live\mail\wlmail.exe 264.2 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows live\photostudio.exe 1.2 MB
Infected: virus Worm.Win32.Mabezat.b c:\zpharaoh.exe 151.6 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\nokia\nokia pc suite 6\pcsync2.exe 1.8 MB
Infected: virus Worm.Win32.Mabezat.b C:\Documents and Settings\tazebama.dl_ 151.1 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\Java\jre6\bin\jqs.exe 302.3 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\google\common\google updater\googleupdaterservice.exe 286.8 KB
Infected: virus Worm.Win32.Mabezat.b c:\zpharaoh.exe 151.9 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows live\photo gallery\wlxphotogallery.exe 288.7 KB
Infected: virus Worm.Win32.Mabezat.b c:\documents and settings\ksa\desktop\virus removal tool1\is-h1ss6\is-h1ss6.exe 364.9 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\Webroot\Washer\wwDisp.exe 1.2 MB
Infected: virus Worm.Win32.Mabezat.b c:\program files\internet explorer\connection wizard\icwconn1.exe 362.4 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\Windows Live\Messenger\msnmsgr.exe 3.9 MB
Infected: virus Worm.Win32.Mabezat.b C:\Documents and Settings\tazebama.dll 32 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\Internet Explorer\iexplore.exe 772 KB
Infected: virus Worm.Win32.Mabezat.b c:\windows\system32\java.exe 294.3 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\nokia\nokia pc suite 6\pcsynclv.exe 856.9 KB
Infected: virus Worm.Win32.Mabezat.b C:\Documents and Settings\tazebama.dl_ 151.1 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\java\jre6\bin\javaw.exe 294.3 KB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 220.1 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\common files\real\update_ob\rnxproc.exe 210.4 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\nokia\nokia pc suite 6\contactseditor.exe 424.4 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows live\mail\wlmail.exe 264.2 KB
Infected: virus Worm.Win32.Mabezat.b C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE 1.5 MB
Infected: virus Worm.Win32.Mabezat.b C:\Program Files\Java\jre6\bin\jusched.exe 286.3 KB
Infected: virus Worm.Win32.Mabezat.b c:\zpharaoh.exe 151.3 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\windows media player\wmpnetwk.exe 1 MB
Infected: virus Worm.Win32.Mabezat.b c:\program files\real\realplayer\realplay.exe 362.4 KB
Infected: virus Worm.Win32.Mabezat.b C:\WINDOWS\system32\RAMASST.exe 304.9 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\pc connectivity solution\servicelayer.exe 438.9 KB
Infected: virus Worm.Win32.Mabezat.b c:\program files\outlook express\msimn.exe 211.9 KB
 
بارك الله فيك
احتاج تقرير الهايجاك بعد اعادة التشغيل
 
تفضـــــــل




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:34:21 م, on 20/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Documents and Settings\ksa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Documents and Settings\tazebama.dl_
C:\WINDOWS\system32\TPSBattM.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\system32\wwSecure.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Documents and Settings\ksa\Desktop\Zyzoom_HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: TweakMASTER Component - {7DAAC7DE-9EF0-4FF0-BFA5-AFF3E899054C} - C:\PROGRA~1\TWEAKM~1\TweakBHO.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TweakMASTER] "C:\Program Files\TweakMASTER\TMTray.exe"
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [GreenBrowser] C:\Documents and Settings\ksa\Desktop\GreenBrowser\GreenBrowser.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [SymLnch] "C:\Documents and Settings\ksa\Application Data\Symantec\Layouts\Norton AntiVirus\15.0\SymAllLanguages\NAV_ESD\20070828\Support\SymLnch\SymLnch.exe" "C:\Documents and Settings\ksa\Application Data\Symantec\Layouts\Norton AntiVirus\15.0\SymAllLanguages\NAV_ESD\20070828\Setup.exe" "/UPREBOOT /temp /patched"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\ksa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Startup: is-H1SS6.lnk = C:\Documents and Settings\ksa\Desktop\Virus Removal Tool1\is-H1SS6\startup.exe
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Add to &LinkFox - res://C:\PROGRA~1\TWEAKM~1\TweakBHO.dll/IESCRIPT
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: تدوين هذا في المدونة - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &تدوين هذا في Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: McAfee Application Installer Cleanup (0138711232484630) (0138711232484630mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\013871~1.EXE (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe
--
End of file - 12609 bytes
 
ما زالت الاصابة
جرب استخدام هذه الاداة

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


وارفع تقرير جديد

وتاكد من ابقاء استعادة النظام معطلة
 
عودة
أعلى