[/]الاسلام عليكم اخوان سويت التقارير وانه ابي مساعدتكم في حل مشكلتي واعطائي النتيجه
اطلب كل من لديه الخبرة والمعرفه ان يشوف التقارير ويعطيني النتيجة
1- تقرير hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:06:02, on 25/11/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10k_Ac tiveX.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\QUSAI\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://uk.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://uk.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 74.208.10.249 gs.apple.com
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin \IE\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\s wg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [MobileBroadband] C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe"
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950D F09FAB501E03.dll/cmsidewiki.html
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{324B1BD3-31B1-4E02-9FBB-5149147A75EF}: NameServer = 10.203.129.68 10.203.129.68
O17 - HKLM\System\CS1\Services\Tcpip\..\{324B1BD3-31B1-4E02-9FBB-5149147A75EF}: NameServer = 10.203.129.68 10.203.129.68
O17 - HKLM\System\CS2\Services\Tcpip\..\{324B1BD3-31B1-4E02-9FBB-5149147A75EF}: NameServer = 10.203.129.68 10.203.129.68
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: @C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
O23 - Service: Vodafone Mobile Broadband Service (VmbService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
--
End of file - 7159 bytes
2-تقرير uninstall_list
7-Zip 9.17 beta
Adobe AIR
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.3
Adobe Shockwave Player 11.5
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Bonjour
Definition update for Microsoft Office 2010 (KB982726)
Dell Dock
Dell Dock
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Plus Web Player
FormatFactory 2.30
Foxit Reader
Golden Al-Wafi Translator
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Google Update Helper
IncrediMail
IncrediMail 2.0
IncrediMail JunkFilter Plus
Intel(R) Graphics Media *********** Driver
iPhone Folders
iPhoneBrowser
iTunes
Java(TM) 6 Update 21
JunkFilterPlus
Laptop Integrated Webcam Driver (1.04.01.1011)
Lingoes 2.6.3
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile
Microsoft Antimalware
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office ScreenTip Language 2010 - ???????
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Security Essentials
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Mobiola Webcam for iPhone 1.0.6
Orbit Downloader
QuickTime
Rapport
Rapport
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Security Update for Microsoft Word 2010 (KB2345000)
Skype™ 4.2
SmartVoip
TeamViewer 5
TuneUp Utilities
Update for Microsoft Office 2010 (KB2202188)
Update for Microsoft OneNote 2010 (KB2288640)
Update for Microsoft Outlook Social Connector (KB2289116)
Update for Microsoft Outlook Social Connector (KB2289116)
VC80CRTRedist - 8.0.50727.4053
VLC media player 1.1.0-pre1
Vodafone Mobile Broadband Lite
WinRAR archiver
Yahoo! Messenger
3 - تقرير runscanner
http://www.up-master.com/okay.php?up...369bea9a9827e2
4 -تقرير StartUp
Start-Up Items; List generated by Start-Up Tool. http://Soft.EM-TNT.com
swg
Name:swgCommand:"C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe"Reg_Path:HKEY_CURRENT_USER\Software\Mic rosoft\Windows\CurrentVersion\RunStatus:
enabledDescription:GoogleToolbarNotifierCompany:Google Inc.
Skype
Name:SkypeCommand:"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimizedReg_Path:HKEY_CURRENT_USER\Software\Micro soft\Windows\CurrentVersion\RunStatus:
enabledDescription:Skype Company:Skype Technologies S.A.
Search Protection
Name:Search ProtectionCommand:C:\Program Files\Yahoo!\Search Protection\SearchProtection.exeReg_Path:HKEY_CURRE NT_USER\Software\Microsoft\Windows\CurrentVersion\ RunStatus:
enabledDescription:n/aCompany:n/a
Phone Disk
Name:Phone DiskCommand:C:\Program Files\Phone Disk\PhoneDisk.exeReg_Path:HKEY_CURRENT_USER\Softw are\Microsoft\Windows\CurrentVersion\RunStatus:
enabledDescription:n/aCompany:n/a
OfficeSyncProcess
Name:OfficeSyncProcessCommand:"C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"Reg_Path:HKEY_CURRENT_ USER\Software\Microsoft\Windows\CurrentVersion\Run Status:
enabledDescription:Microsoft Office Document CacheCompany:Microsoft Corporation
Messenger (Yahoo!)
Name:Messenger (Yahoo!)Command:"C:\PROGRA~1\Yahoo!\Messenger\Yaho oMessenger.exe" -quietReg_Path:HKEY_CURRENT_USER\Software\Microsoft \Windows\CurrentVersion\RunStatus:
enabledDescription:Yahoo! MessengerCompany:Yahoo! Inc.
Lingoes
Name:LingoesCommand:C:\Program Files\Lingoes\Translator2\Lingoes.exe -minimizeReg_Path:HKEY_CURRENT_USER\Software\Micros oft\Windows\CurrentVersion\RunStatus:
enabledDescription:n/aCompany:n/a
IncrediMail
Name:IncrediMailCommand:C:\Program Files\IncrediMail\bin\IncMail.exe /cReg_Path:HKEY_CURRENT_USER\Software\Microsoft\Win dows\CurrentVersion\RunStatus:
enabledDescription:IncrediMail ApplicationCompany:IncrediMail, Ltd.
Google Update
Name:Google UpdateCommand:"C:\Users\QUSAI\AppData\Local\Google \Update\GoogleUpdate.exe" /cReg_Path:HKEY_CURRENT_USER\Software\Microsoft\Win dows\CurrentVersion\RunStatus:
enabledDescription:n/aCompany:n/a
MobileBroadband
Name:MobileBroadbandCommand:C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silentReg_Path:HKEY_LOCAL_MACHINE\Software\Microso ft\Windows\CurrentVersion\RunStatus:
enabledDescription:MobileBroadbandCompany:Vodafone
SunJavaUpdateSched
Name:SunJavaUpdateSchedCommand:"C:\Program Files\Common Files\Java\Java Update\jusched.exe"Reg_Path:HKEY_LOCAL_MACHINE\Sof tware\Microsoft\Windows\CurrentVersion\RunStatus:
enabledDescription:Java(TM) Update SchedulerCompany:Sun Microsystems, Inc.
QuickTime Task
Name:QuickTime TaskCommand:"C:\Program Files\QuickTime\QTTask.exe" -atboottimeReg_Path:HKEY_LOCAL_MACHINE\Software\Mic rosoft\Windows\CurrentVersion\RunStatus:
enabledDescription:QuickTime TaskCompany:Apple Inc.
Persistence
Name:PersistenceCommand:C:\Windows\system32\igfxpe rs.exeReg_Path:HKEY_LOCAL_MACHINE\Software\Microso ft\Windows\CurrentVersion\RunStatus:
enabledDescription:persistence ModuleCompany:Intel Corporation
OEM02Mon.exe
Name:OEM02Mon.exeCommand:C:\Windows\OEM02Mon.exeRe g_Path:HKEY_LOCAL_MACHINE\Software\Microsoft\Windo ws\CurrentVersion\RunStatus:
enabledDescription:Live! Cam Console Auto LauncherCompany:Creative Technology Ltd.
MSSE
Name:MSSECommand:"C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkeyReg_Path:HKEY_LOCAL_MACHINE\Software\Microso ft\Windows\CurrentVersion\RunStatus:
enabledDescription:Microsoft Security Essentials User InterfaceCompany:Microsoft Corporation
MobileConnect
Name:MobileConnectCommand:%programfiles%\Vodafone\ Vodafone Mobile Connect\Bin\MobileConnect.exe /silentReg_Path:HKEY_LOCAL_MACHINE\Software\Microso ft\Windows\CurrentVersion\RunStatus:
enabledDescription:n/aCompany:n/a
iTunesHelper
Name:iTunesHelperCommand:"C:\Program Files\iTunes\iTunesHelper.exe"Reg_Path:HKEY_LOCAL_ MACHINE\Software\Microsoft\Windows\CurrentVersion\ RunStatus:
enabledDescription:iTunesHelperCompany:Apple Inc.
IgfxTray
Name:IgfxTrayCommand:C:\Windows\system32\igfxtray. exeReg_Path:HKEY_LOCAL_MACHINE\Software\Microsoft\ Windows\CurrentVersion\RunStatus:
enabledDescription:igfxTray ModuleCompany:Intel Corporation
HotKeysCmds
Name:HotKeysCmdsCommand:C:\Windows\system32\hkcmd. exeReg_Path:HKEY_LOCAL_MACHINE\Software\Microsoft\ Windows\CurrentVersion\RunStatus:
enabledDescription:hkcmd ModuleCompany:Intel Corporation
BCSSync
Name:BCSSyncCommand:"C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServicesReg_Path:HKEY_LOCAL_MACHINE\Software\ Microsoft\Windows\CurrentVersion\RunStatus:
enabledDescription:Microsoft Office 2010 componentCompany:Microsoft Corporation
Adobe Reader Speed Launcher
Name:Adobe Reader Speed LauncherCommand:"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"Reg_Path:HKEY_LOCAL_MACHI NE\Software\Microsoft\Windows\CurrentVersion\RunSt atus:
enabledDescription:Adobe Acrobat SpeedLauncherCompany:Adobe Systems Incorporated
Adobe ARM
Name:Adobe ARMCommand:"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"Reg_Path:HKEY_LOC AL_MACHINE\Software\Microsoft\Windows\CurrentVersi on\RunStatus:
enabledDescription:Adobe Reader and Acrobat ManagerCompany:Adobe Systems Incorporated
TkBellExe
Name:TkBellExeCommand:"C:\Program Files\Real\RealPlayer\Update\realsched.exe" -osbootReg_Path:HKEY_LOCAL_MACHINE\Software\Microso ft\Windows\CurrentVersion\Run-Status:
disabledDescription:RealNetworks SchedulerCompany:RealNetworks, Inc.
Dell Dock.lnk
Name:Dell Dock.lnkCommand:C:\PROGRA~1\Dell\DellDock\DellDock .exeLinkPath:C:\Users\QUSAI\AppData\Roaming\Micros oft\Windows\Start Menu\Programs\Startup\Dell Dock.lnkStatus:
enabledDescription:Dell DockCompany:Stardock Corporation
أكثر...