التقرير الأول
ComboFix 08-08-29.02 - ALI_EDREES 08/30/2008 18:06:21.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1256.1.1025.18.1945 [GMT 3:00]
Running from: C:\Users\ALI_EDREES\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\ALI_EDREES\AppData\Roaming\.#
C:\Users\ALI_EDREES\AppData\Roaming\macromedia\Flash Player\#Shareds\43Z2E6NQ\bin.clearspring.com
C:\Users\ALI_EDREES\AppData\Roaming\macromedia\Flash Player\#Shareds\43Z2E6NQ\bin.clearspring.com\clearspring.sol
C:\Users\ALI_EDREES\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Users\ALI_EDREES\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Windows\system32\kakle.dll
C:\Windows\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-30 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-30 15:09 --------- d-----w C:\Users\ALI_EDREES\AppData\Roaming\DMCache
2008-08-30 15:06 175,065,888 --sha-w C:\Windows\system32\drivers\fidbox.dat
2008-08-30 14:52 --------- d-----w C:\ProgramData\Kaspersky Lab
2008-08-29 23:26 2,346,740 --sha-w C:\Windows\system32\drivers\fidbox.idx
2008-08-29 23:26 --------- d-----w C:\Users\ALI_EDREES\AppData\Roaming\DNA
2008-08-26 23:30 --------- d-----w C:\Users\ALI_EDREES\AppData\Roaming\uTorrent
2008-08-26 23:29 --------- d-----w C:\Program Files\Trend Micro
2008-08-26 21:03 --------- d-----w C:\Program Files\GoldWave
2008-08-26 07:08 203,776 ----a-w C:\Windows\System32\clrviddc.dll
2008-08-25 10:54 --------- d-----w C:\Users\ALI_EDREES\AppData\Roaming\BitTorrent
2008-08-25 09:49 --------- d-----w C:\Program Files\BitTorrent
2008-08-24 08:52 2,560 ----a-w C:\Windows\_MSRSTRT.EXE
2008-08-24 07:30 --------- d-----w C:\Program Files\Internet Download Manager
2008-08-24 06:21 --------- d-----w C:\Program Files\uTorrent
2008-08-24 00:43 --------- d-----w C:\Program Files\Common Files\xing shared
2008-08-24 00:43 --------- d-----w C:\Program Files\Common Files\Real
2008-08-23 19:29 --------- d-----w C:\Program Files\Anti Tracks
2008-08-23 17:49 --------- d-----w C:\Users\ALI_EDREES\AppData\Roaming\IDM
2008-08-23 10:12 --------- d-----w C:\ProgramData\Microsoft Corporation
2008-08-23 10:11 --------- d-----w C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2008-08-23 09:44 --------- d-----w C:\Program Files\Windows Installer 4.5 SDK
2008-08-23 08:22 --------- d-----w C:\Program Files\myphotobook
2008-08-23 07:54 --------- d-----w C:\Program Files\JetAudio
2008-08-22 20:53 --------- d-----w C:\Program Files\Folderico
2008-08-22 20:44 315,392 ----a-w C:\Windows\HideWin.exe
2008-08-22 19:56 --------- d-----w C:\Program Files\Google
2008-08-22 07:14 --------- d-----w C:\Program Files\DNA
2008-08-22 06:54 --------- d-----w C:\Program Files\Ares
2008-08-22 05:30 --------- d-----w C:\Program Files\isoHunt
2008-08-22 05:27 --------- d-----w C:\Program Files\Conduit
2008-08-21 13:46 --------- d-----w C:\Program Files\OpenOffice.org 2.0
2008-08-21 12:35 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-21 12:35 --------- d-----w C:\Program Files\Toshiba
2008-08-21 12:22 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_Apfiltr_01005.Wdf
2008-08-21 12:22 --------- d-----w C:\Program Files\Apoint2K
2008-08-21 12:18 --------- d-----w C:\Users\ALI_EDREES\AppData\Roaming\OpenOffice.org2
2008-08-21 11:59 --------- d-----w C:\ProgramData\Microsoft Help
2008-08-21 11:37 --------- d-----w C:\Program Files\Atheros
2008-08-21 11:35 --------- d-----w C:\Program Files\Cisco
2008-08-21 11:34 --------- d-----w C:\ProgramData\Atheros
2008-08-21 07:16 --------- d-----w C:\Users\ALI_EDREES\AppData\Roaming\Media Player Classic
2008-08-21 00:34 --------- d-----w C:\Program Files\MSBuild
2008-08-21 00:34 --------- d-----w C:\Program Files\Microsoft Works
2008-08-21 00:31 --------- d-----w C:\Program Files\Microsoft.NET
2008-08-21 00:28 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-08-20 13:00 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-20 12:36 --------- d-----w C:\ProgramData\Messenger Plus!
2008-08-20 12:28 --------- d-----w C:\Users\ALI_EDREES\AppData\Roaming\COWON
2008-08-20 11:51 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-08-20 11:18 --------- d-----w C:\ProgramData\Installations
2008-08-20 11:05 --------- d-----w C:\Users\ALI_EDREES\AppData\Roaming\IrfanView
2008-08-20 11:05 --------- d-----w C:\Program Files\IrfanView
2008-08-20 11:00 --------- d-----w C:\Program Files\Java
2008-08-20 10:42 --------- d-----w C:\Program Files\Picasa2
2008-08-20 10:40 --------- d---a-w C:\ProgramData\TEMP
2008-08-20 10:26 --------- d-----w C:\Program Files\Common Files\COWON
2008-08-20 10:25 --------- d-----w C:\Users\ALI_EDREES\AppData\Roaming\InstallShield
2008-08-20 10:13 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-20 09:53 73,216 ----a-w C:\Windows\ST6UNST.EXE
2008-08-20 09:53 172,032 ------w C:\Windows\Setup1.exe
2008-08-20 09:53 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-08-20 09:42 --------- d-----w C:\Program Files\Circle Developement
2008-08-20 01:21 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-20 00:07 --------- d-----w C:\Program Files\Windows Mail
2008-08-19 22:51 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-19 22:51 --------- d-----w C:\Program Files\Windows Live
2008-08-19 22:34 --------- d-----w C:\ProgramData\ToshibaEurope
2008-08-19 22:29 --------- d-----w C:\Users\ALI_EDREES\AppData\Roaming\DesktopSMS
2008-08-19 22:26 --------- d-----w C:\Program Files\Smarty Uninstaller Pro
2008-08-19 22:24 --------- d-----w C:\ProgramData\Toshiba
2008-08-19 22:24 --------- d-----w C:\Program Files\Common Files\Toshiba Shared
2008-08-19 22:21 --------- d-----w C:\Program Files\Camera Assistant Software for Toshiba
2008-08-19 22:20 0 --sha-r C:\Windows\system32\drivers\TOSHIBA_Satellite A300_06466-AR_PSAJ4E-00V00.MRK
2008-08-19 22:17 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
2008-08-19 22:17 --------- d-----w C:\Program Files\Synaptics
2008-08-19 22:17 --------- d-----w C:\Program Files\Intel
2008-08-19 22:17 --------- d-----w C:\Program Files\ATI Technologies
2008-08-19 21:55 --------- d-----w C:\ProgramData\WLInstaller
2008-08-19 21:48 --------- d-----w C:\Users\ALI_EDREES\AppData\Roaming\Ashampoo
2008-08-19 21:47 --------- d-----w C:\ProgramData\ashampoo
2008-08-19 21:46 --------- d-----w C:\Program Files\Ashampoo
2008-08-19 21:30 96,976 ----a-w C:\Windows\system32\drivers\klin.dat
2008-08-19 21:30 87,855 ----a-w C:\Windows\system32\drivers\klick.dat
2008-08-19 21:30 112,144 ----a-w C:\Windows\system32\drivers\kl1.sys
2008-08-19 21:20 --------- d-----w C:\Program Files\Total Video Converter
2008-08-19 21:19 --------- d-----w C:\Users\ALI_EDREES\AppData\Roaming\Ulead Systems
2008-08-19 21:15 499,712 ----a-w C:\Windows\System32\msvcp71.dll
2008-08-19 21:15 348,160 ----a-w C:\Windows\System32\msvcr71.dll
2008-08-19 21:15 --------- d-----w C:\Program Files\Real
2008-08-19 21:07 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-19 21:01 --------- d-----w C:\Program Files\Ela-Salaty
2008-08-19 20:41 --------- d-----w C:\Program Files\Kaspersky Lab
2008-08-19 20:37 --------- d-----w C:\ProgramData\McAfee
2008-08-19 20:29 --------- d-----w C:\ProgramData\ATI
2008-08-19 20:15 --------- d-----w C:\Program Files\ATI
2008-08-19 20:05 --------- d-----w C:\Users\ALI_EDREES\AppData\Roaming\ATI
2008-08-19 19:56 --------- d-----w C:\Program Files\Windows Defender
2008-08-19 19:55 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-08-19 19:55 --------- d-----w C:\Program Files\Windows Sidebar
2008-08-19 19:55 --------- d-----w C:\Program Files\Windows Photo Gallery
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a6e4a4eb-d169-4e99-8988-250fcbafe767}"= "C:\Program Files\isoHunt\tbiso0.dll" [08/05/2008 02:13 AM 1610264]
[HKEY_CLASSES_ROOT\clsid\{a6e4a4eb-d169-4e99-8988-250fcbafe767}]
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{a6e4a4eb-d169-4e99-8988-250fcbafe767}]
08/05/2008 02:13 AM 1610264 --a------ C:\Program Files\isoHunt\tbiso0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{a6e4a4eb-d169-4e99-8988-250fcbafe767}"= "C:\Program Files\isoHunt\tbiso0.dll" [08/05/2008 02:13 AM 1610264]
[HKEY_CLASSES_ROOT\clsid\{a6e4a4eb-d169-4e99-8988-250fcbafe767}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A6E4A4EB-D169-4E99-8988-250FCBAFE767}"= "C:\Program Files\isoHunt\tbiso0.dll" [08/05/2008 02:13 AM 1610264]
[HKEY_CLASSES_ROOT\clsid\{a6e4a4eb-d169-4e99-8988-250fcbafe767}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [01/21/2008 05:23 AM 1233920]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [12/29/2007 12:06 PM 430080]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [07/15/2008 08:39 AM 931248]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [01/21/2008 05:25 AM 125952]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [08/22/2008 05:28 PM 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM 144784]
"ITSecMng"="C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [09/28/2007 07:03 PM 75136]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 06:06 AM 40048]
"Desktop SMS"="C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe" [06/18/2007 01:51 PM 1507328]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [12/06/2006 04:44 AM 366400]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [11/29/2007 07:58 PM 1029416]
"Camera Assistant Software"="C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" [10/25/2007 07:41 PM 413696]
"TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [01/17/2008 06:27 PM 431456]
"HSON"="C:\Program Files\TOSHIBA\TBS\HSON.exe" [11/01/2007 01:01 AM 54608]
"SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [01/25/2008 01:22 PM 509816]
"00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [01/22/2008 04:25 PM 712704]
"Toshiba Registration"="C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe" [05/04/2007 01:05 PM 571024]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [11/10/2006 02:35 PM 90112]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [08/24/2007 07:00 AM 33648]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [10/24/2007 11:02 AM 178712]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [12/15/2007 04:29 PM 184320]
"NDSTray.exe"="NDSTray.exe" [BU]
C:\Users\ALI_EDREES\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Ela-Salaty.lnk - C:\Program Files\Ela-Salaty\Salaty.exe [2007-03-05 03:33:19 5205504]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-08-20 13:13:24 113664]
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2008-01-25 13:24:08 2938184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{FECF7E97-097D-4A84-8E69-486D164CC659}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{6A0CD55F-2796-4755-A426-15EE2A7FED9A}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{45BD1987-1E85-47E5-BE31-92836607ABA8}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{B0F9305D-C16D-44BB-8617-EAF7B659311C}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{66DDBFD8-D4AC-4804-B870-37941562224A}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B27E35AB-C4C7-447B-9E9F-3BA4336413C7}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B83CD62D-D9E8-4053-BBFA-C923D5F1DBC9}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{8C019355-8D09-4F3E-8C49-964D96AFBFA6}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{233C4324-3180-42F4-9F8B-DB39C6B6387B}"= UDP:C:\Program Files\DNA\btdna.exe

NA
"{4AC63DF3-40AE-46A8-AE08-1861B39BCEE4}"= TCP:C:\Program Files\DNA\btdna.exe

NA
"{FC3BA7AC-90F3-472D-ABD8-E804535BB1C7}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{C18A0FF3-0D8E-46F2-9A3C-8C088878C04A}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{3848A924-CDFF-4876-AEE6-02B0AD8E3740}C:\\program files\\real\\realplayer\\realplay.exe"= UDP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{547E6264-4088-46E7-9A15-961D57FB40B6}C:\\program files\\real\\realplayer\\realplay.exe"= TCP:C:\program files\real\realplayer\realplay.exe:RealPlayer
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [10/16/2007 01:05 PM]
R2 ConfigFree Service;ConfigFree Service;C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [12/25/2007 04:07 PM]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [12/03/2007 07:03 PM]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [01/30/2008 06:24 PM]
R3 CnxtHdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service;C:\Windows\system32\drivers\CHDART.sys [02/01/2008 01:46 PM]
R3 O2MDRDR;O2MDRDR;C:\Windows\system32\DRIVERS\o2media.sys [01/15/2008 12:34 PM]
R3 QIOMem;Generic IO & Memory Access;C:\Windows\system32\DRIVERS\QIOMem.sys [04/09/2007 06:13 PM]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [12/06/2007 12:51 PM]
S3 tapvpn;TAP VPN Adapter;C:\Windows\system32\DRIVERS\tapvpn.sys [01/24/2008 12:25 AM]
S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [01/21/2008 05:23 AM]
S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [01/21/2008 05:23 AM]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Users\ALI_EDREES\AppData\Roaming\Mozilla\Firefox\Profiles\bfhfju3h.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://s9.travian.ae/dorf1.php|
FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll
FF -: plugin - C:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - C:\Users\ALI_EDREES\Program Files\DNA\plugins\npbtdna.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-30 18:09:16
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 08/30/2008 18:11:34
ComboFix-quarantined-files.txt 2008-08-30 15:11:31
Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application.
Post-Run: 114,081,464,320 bytes free
235 --- E O F --- 2008-08-29 22:22:33
التقرير الثاني:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:15:47 م, on 30/08/08
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe
C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Ela-Salaty\Salaty.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Windows\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\ALI_EDREES\Documents\Downloads\Programs\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: isoHunt Toolbar - {a6e4a4eb-d169-4e99-8988-250fcbafe767} - C:\Program Files\isoHunt\tbiso0.dll
O1 - Hosts: ::1 localhost
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: isoHunt Toolbar - {a6e4a4eb-d169-4e99-8988-250fcbafe767} - C:\Program Files\isoHunt\tbiso0.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: isoHunt Toolbar - {a6e4a4eb-d169-4e99-8988-250fcbafe767} - C:\Program Files\isoHunt\tbiso0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Startup: Ela-Salaty.lnk = C:\Program Files\Ela-Salaty\Salaty.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: eBay.co.uk - Buy It Sell It Love It - {76577871-04EC-495E-A12B-91F7C3600AFA} -
(file missing)
O9 - Extra button: Amazon.co.uk - {8A918C1D-E123-4E36-B562-5C1519E434CE} -
(file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 10210 bytes