هلا اخوي ،،
سويت اللي قلت لي عليه ،، وكنت لما قلت اليه Fixet ما ادري فيكس ، بعد التحديد من اداة زيزووم للهايجاك مثل ما انت قلت ،، كان مثل اللي يرفض ..
المهم وداني لموقع على النت وفيها اختيار من 1 الى 6 وما ادري ايش المهم كملت معاه ( الاداة ) وخلصت وسويت كلينر بالرابط اللي انت وضعته ...
يعني مشيت حسب التعليمات .. وهذا التقرير الثاني :
Logfile of Trend Micro HijackThis
v2.0.2
Scan saved at 09:51:01 م, on
19/07/09
Platform: Windows Vista SP1 (WinNT
6.00.1905)
MSIE: Internet Explorer v7.00
(7.00.6001.18248)
Boot mode: Normal
Running processes:
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows
Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Power
Saver\TPwrMain.exe
C:\Program
Files\TOSHIBA\SmoothView\SmoothView.
exe
C:\Program
Files\TOSHIBA\FlashCards\TCrdMain.ex
e
C:\Program
Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program
Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Toshiba
Online Product Information\TOPI.exe
C:\Program Files\IDM\Desktop
SMS\DesktopSMS.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common
Files\Symantec Shared\PIF\{B8E1DD85
-8582-4c61-B58F-2F227FCA9A08}
\PIFSvc.exe
C:\Windows\System32\rundll32.exe
C:\Program
Files\MyWebSearch\bar\1.bin\MWSOEMON
.EXE
C:\Program
Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\Java\jre6
\bin\jusched.exe
C:\Program Files\McAfee\VirusScan
Enterprise\shstat.exe
C:\Program Files\McAfee\Common
Framework\UdaterUI.exe
C:\Program Files\Windows
Sidebar\sidebar.exe
C:\Program
Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program
Files\Apoint2K\ApMsgFwd.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Toshiba\Bluetooth
Toshiba Stack\TosBtMng.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program
Files\TOSHIBA\ConfigFree\CFSwMgr.exe
c:\Program Files\Toshiba\Bluetooth
Toshiba Stack\TosA2dp.exe
C:\Program Files\Windows
Live\Messenger\msnmsgr.exe
c:\Program Files\Toshiba\Bluetooth
Toshiba Stack\TosBtHid.exe
c:\Program Files\Toshiba\Bluetooth
Toshiba Stack\TosBtHsp.exe
c:\Program Files\Toshiba\Bluetooth
Toshiba Stack\TosAVRC.exe
C:\Program Files\Windows
Mail\WinMail.exe
c:\Program Files\Toshiba\Bluetooth
Toshiba Stack\tosOBEX.exe
C:\Program Files\TOSHIBA\Bluetooth
Toshiba Stack\TosBtProc.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Program Files\Avant
Browser\avant.exe
C:\Windows\system32
\SearchFilterHost.exe
C:\Program Files\Trend
Micro\HijackThis\HijackThis.exe
R1 -
HKCU\Software\Microsoft\Internet
Explorer\Main,Search Page =
?
LinkId=54896
R0 -
HKCU\Software\Microsoft\Internet
Explorer\Main,Start Page =
R1 -
HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
?
LinkId=69157
R1 -
HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
?
LinkId=54896
R1 -
HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page =
?
LinkId=54896
R0 -
HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page =
R0 -
HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =
R0 -
HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch =
R1 -
HKCU\Software\Microsoft\Windows\Curr
entVersion\Internet
Settings,ProxyOverride = local
R0 -
HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: MyWebSearch Search
Assistant BHO - {00A6FAF1-072E-44cf
-8957-5838F569A31D} - C:\Program
Files\MyWebSearch\SrchAstt\1.bin\MWS
SRCAS.DLL
O2 - BHO: myBar BHO - {0494D0D1-
F8E0-41ad-92A3-14154ECE70AC} -
C:\Program
Files\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: Adobe PDF Reader Link
Helper - {06849E9F-C8D7-4D59-B87D-
784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 7.0
\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-
A523-4961-B6BB-170DE4475CCA} -
C:\Program
Files\MyWebSearch\bar\1.bin\MWSBAR.D
LL
O2 - BHO: (no name) - {1A0AADCD-
3A72-4b5f-900F-E3BB5A838E2A} - (no
file)
O2 - BHO: Search Helper - {6EBF7485
-159F-4bff-A14F-B9E3AAC4465B} -
C:\Program Files\Microsoft\Search
Enhancement Pack\Search
Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in
Helper - {9030D464-4C02-4ABF-8ECC-
5164760863C6} - C:\Program
Files\Common Files\Microsoft
Shared\Windows
Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9CB65201-
89C4-402c-BA80-02D8C59F9B1D} - (no
file)
O2 - BHO: Google Toolbar Helper -
{AA58ED58-01DD-4d91-8333-
CF10577473F7} - c:\program
files\google\googletoolbar1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV
Helper - {DBC80044-A445-435b-BC74-
9C25C1C588A9} - C:\Program
Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar
Helper - {E15A8DC0-8516-42A1-81EA-
DC94EC1ACF10} - C:\Program
Files\Windows
Live\Toolbar\wltcore.dll
O2 - BHO: SweetIM Toolbar Helper -
{EEE6C35C-6118-11DC-9C72-
001320C79847} - C:\Program
Files\SweetIM\Toolbars\Internet
Explorer\mgToolbarIE.dll
O2 - BHO: (no name) - {FE063DB1-
4EC0-403e-8DD8-394C54984B2C} - (no
file)
O3 - Toolbar: (no name) - {BC4FFE41
-DE9F-46fa-B455-AAD49B9F9938} - (no
file)
O3 - Toolbar: (no name) - {FE063DB9
-4EC0-403e-8DD8-394C54984B2C} - (no
file)
O3 - Toolbar: &Google - {2318C2B1-
4965-11d4-9B18-009027A5CD4F} -
c:\program
files\google\googletoolbar1.dll
O3 - Toolbar: SweetIM Toolbar for
Internet Explorer - {EEE6C35B-6118-
11DC-9C72-001320C79847} - C:\Program
Files\SweetIM\Toolbars\Internet
Explorer\mgToolbarIE.dll
O3 - Toolbar: My Web Search -
{07B18EA9-A523-4961-B6BB-
170DE4475CCA} - C:\Program
Files\MyWebSearch\bar\1.bin\MWSBAR.D
LL
O3 - Toolbar: &Windows Live Toolbar
- {21FA44EF-376D-4D53-9B0F-
8A89D3229068} - C:\Program
Files\Windows
Live\Toolbar\wltcore.dll
O3 - Toolbar: &SearchBar -
{0494D0D9-F8E0-41ad-92A3-
14154ECE70AC} - C:\Program
Files\MyWay\myBar\1.bin\MYBAR.DLL
O4 - HKLM\..\Run: [Windows Defender]
%ProgramFiles%\Windows
Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl]
RtHDVCpl.exe
O4 - HKLM\..\Run: [TPwrMain] %
ProgramFiles%\TOSHIBA\Power
Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %
ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %
ProgramFiles%
\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %
ProgramFiles%
\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [KeNotify]
C:\Program
Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [HWSetup]
C:\Program
Files\TOSHIBA\Utilities\HWSetup.exe
hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL]
C:\Program
Files\TOSHIBA\Utilities\SVPWUTIL.exe
SVPwUTIL
O4 - HKLM\..\Run: [NDSTray.exe]
NDSTray.exe
O4 - HKLM\..\Run: [topi] C:\Program
Files\TOSHIBA\Toshiba Online Product
Information\topi.exe -startup
O4 - HKLM\..\Run: [Desktop SMS]
C:\Program Files\IDM\Desktop
SMS\DesktopSMS.exe /auto
O4 - HKLM\..\Run: [NvSvc]
RUNDLL32.EXE C:\Windows\system32
\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon]
RUNDLL32.EXE C:\Windows\system32
\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter]
RUNDLL32.EXE C:\Windows\system32
\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IgfxTray]
C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds]
C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence]
C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint]
C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Toshiba
Registration] C:\Program
Files\Toshiba\Registration\ToshibaRe
gistration.exe
O4 - HKLM\..\Run: [Symantec PIF
AlertEng] "C:\Program Files\Common
Files\Symantec Shared\PIF\{B8E1DD85
-8582-4c61-B58F-2F227FCA9A08}
\PIFSvc.exe" /a /m "C:\Program
Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F
-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [MyWebSearch
Plugin] rundll32 C:\PROGRA~1
\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [My Web Search Bar
Search Scope Monitor] "C:\PROGRA~1
\MYWEBS~1\bar\1.bin\m3SrchMn.exe"
/m=2 /w
O4 - HKLM\..\Run: [MyWebSearch Email
Plugin] C:\PROGRA~1\MYWEBS~1
\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [SweetIM]
C:\Program
Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run:
[SunJavaUpdateSched] "C:\Program
Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [3DNADesktop]
"C:\Program
Files\3DNA\Resources\3dnasys.exe" -
open
O4 - HKLM\..\Run: [ShStatEXE]
"C:\Program Files\McAfee\VirusScan
Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI]
"C:\Program Files\McAfee\Common
Framework\UdaterUI.exe"
/StartedFromRunKey
O4 - HKCU\..\Run: [Sidebar]
C:\Program Files\Windows
Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD]
TOSCDSPD.EXE
O4 - HKCU\..\Run: [Speech
Recognition]
"C:\Windows\Speech\Common\sapisvr.ex
e" -SpeechUX -Startup
O4 - HKCU\..\Run: [ehTray.exe]
C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [googletalk]
C:\Users\taher\AppData\Roaming\Googl
e\Google Talk\googletalk.exe
/autostart
O4 - HKCU\..\Run: [MsnMsgr]
~"C:\Program Files\Windows
Live\Messenger\msnmsgr.exe"
/background
O4 - HKCU\..\Run: [MyWebSearch Email
Plugin] C:\PROGRA~1\MYWEBS~1
\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [ccleaner]
"C:\Program
Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKUS\S-1-5-19\..\Run: [Sidebar]
%ProgramFiles%\Windows
Sidebar\Sidebar.exe /detectMem (User
'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run:
[WindowsWelcomeCenter] rundll32.exe
oobefldr.dll,ShowWelcomeCenter (User
'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar]
%ProgramFiles%\Windows
Sidebar\Sidebar.exe /detectMem (User
'NETWORK SERVICE')
O4 - Global Startup: Adobe Gamma
Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma
Loader.exe
O4 - Global Startup: Adobe Reader
Speed Launch.lnk = C:\Program
Files\Adobe\Acrobat 7.0
\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth
Manager.lnk = ?
O9 - Extra button: تدوين هذا في المدونة -
{219C3416-8CB2-491a-A3C7-
D9FCDDC9D600} - C:\Program
Files\Windows
Live\Writer\WriterBrowserExtension.d
ll
O9 - Extra 'Tools' menuitem: &تدوين هذا في
Windows Live Writer - {219C3416-
8CB2-491a-A3C7-D9FCDDC9D600} -
C:\Program Files\Windows
Live\Writer\WriterBrowserExtension.d
ll
O9 - Extra button: Research -
{92780B25-18CC-41C8-B9BE-
3C9C571A8263} - C:\PROGRA~1
\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: eBay - {C08CAF1D
-C0A3-40D5-9970-06D067EAC017} -
-
bin/toshiba/tracker_url.pl?EN (file
missing)
O13 - Gopher Prefix:
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87
-1E41684E07BB} -
ache/funwebproducts/ei-
4/ZwinkyInitialSetup1.0.1.1.cab
O16 - DPF: {30528230-99f7-4bb4-88d8
-fa1d4f56a2ab} (YInstStarter Class)
- C:\Program Files\Yahoo!
\Common\yinsthelper.dll
O16 - DPF: {8AD9C840-044E-11D1-B3E9
-00805F499D93} (Java Runtime
Environment 1.6.0) -
-09.sun.com/s/ESD7/JSCDL/jdk/6u13-
b03/jinstall-6u13-windows-i586-
jc.cab?
e=1241708283229&h=45d94cc7d6d872723c
e27b6b365a52f9/&filename=jinstall-
6u13-windows-i586-jc.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72
-04C2F616BCA7} (get_atlcom Class) -
.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8
-444553540000} (Shockwave Flash
Object) -
t/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8
-444553712000} -
t/shockwave/cabs/flash/swflash.cab
O23 - Service: Agere Modem Call
Progress Audio (AgereModemAudio) -
Agere Systems - C:\Windows\system32
\agrsmsvc.exe
O23 - Service: Automatic LiveUpdate
Scheduler - Symantec Corporation -
C:\Program
Files\Symantec\LiveUpdate\ALUSchedul
erSvc.exe
O23 - Service: Kaspersky Anti-Virus
(AVP) - Unknown owner - C:\Program
Files\Kaspersky Lab\Kaspersky Anti-
Virus 2009\avp.exe (file missing)
O23 - Service: Capture Device
Service - InterVideo Inc. -
C:\Program Files\Common
Files\InterVideo\DeviceService\DevSv
c.exe
O23 - Service: ConfigFree Service
(CFSvcs) - TOSHIBA CORPORATION -
C:\Program
Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic
NetConnect service (CLTNetCnService)
- Unknown owner - C:\Program
Files\Common Files\Symantec
Shared\ccSvcHst.exe (file missing)
O23 - Service: getPlus(R) Helper -
NOS Microsystems Ltd. - C:\Program
Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: LightScribeService
Direct Disc Labeling Service
(LightScribeService) - Hewlett-
Packard Company - C:\Program
Files\Common
Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec
Corporation - C:\PROGRA~1
\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice
Service Ex (LiveUpdate Notice Ex) -
Unknown owner - C:\Program
Files\Common Files\Symantec
Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice
Service - Symantec Corporation -
C:\Program Files\Common
Files\Symantec Shared\PIF\{B8E1DD85
-8582-4c61-B58F-2F227FCA9A08}
\PIFSvc.exe
O23 - Service: McAfee Framework
Service (McAfeeFramework) - McAfee,
Inc. - C:\Program
Files\McAfee\Common
Framework\FrameworkService.exe
O23 - Service: McAfee McShield
(McShield) - McAfee, Inc. -
C:\Program Files\McAfee\VirusScan
Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager
(McTaskManager) - McAfee, Inc. -
C:\Program Files\McAfee\VirusScan
Enterprise\vstskmgr.exe
O23 - Service: My Web Search Service
(MyWebSearchService) -
MyWebSearch.com - C:\PROGRA~1
\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: NMIndexingService -
Unknown owner - C:\Program
Files\Common
Files\Ahead\Lib\NMIndexingService.ex
e (file missing)
O23 - Service: TOSHIBA Optical Disc
Drive Service (TODDSrv) - TOSHIBA
Corporation - C:\Windows\system32
\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver
(TosCoSrv) - TOSHIBA Corporation -
C:\Program Files\TOSHIBA\Power
Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth
Service - TOSHIBA CORPORATION -
c:\Program Files\Toshiba\Bluetooth
Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper
(UleadBurningHelper) - Ulead
Systems, Inc. - C:\Program
Files\Common Files\Ulead
Systems\DVD\ULCDRSvr.exe
--
End of file - 13622 bytes