• بادئ الموضوع بادئ الموضوع dяăģôŋ
  • تاريخ البدء تاريخ البدء
  • المشاهدات 1,019

dяăģôŋ

ذيبان
إنضم
26 سبتمبر 2007
المشاركات
3,850
مستوى التفاعل
46
النقاط
830
الإقامة
بعيد عنك
غير متصل
السلام عليكم

تقرير جهازى بعد الفورمات

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:32:33 ص, on 17/05/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Atheros\ACU.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Download Manager\IDMan.exe
D:\مجلد جديد\برامج حمايه\مجلد جديد\Hijack_This.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

F2 - REG:system.ini: Shell=Explorer.exe
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: مساعد رابط Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" /minimized
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: سرعة تشغيل Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash ) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O17 - HKLM\System\CCS\Services\Tcpip\..\{81CE48B6-4ABF-4CEF-9E1B-C9D2BD7525DD}: NameServer = 212.71.32.19 212.71.32.20
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 9175 bytes
 

وعليكم السلام

التقرير سليم
 
وشرايك بالتقرير خرعنى

Warning: Use the following advice entirely at own risk! An automatic analysis should never
substitute an expert's analysis.​

These are the results of your HijackReader analysis:​
Analysis date:05-17-2008, 09:33:18
HijackThis Version: v2.0.2
Log-length: 114 lines
HijackReader Version: HijackReader v1.03 Beta

Action:Entry:Notes:Description:Look-upFIX IF UNKNOWNR1 - HKLM\Software\Microsoft\Internet Explorer\Ma in,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
ink/?LinkId=69157Fix it, if you don't recognize the the program.Internet Explorer Start/Search pages URLsFIX IF UNKNOWNR1 - HKLM\Software\Microsoft\Internet Explorer\Ma in,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
wlink/?LinkId=54896Fix it, if you don't recognize the the program.Internet Explorer Start/Search pages URLsFIX IF UNKNOWNR1 - HKLM\Software\Microsoft\Internet Explorer\Ma in,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
LinkId=54896Fix it, if you don't recognize the the program.Internet Explorer Start/Search pages URLsFIX IF UNKNOWNR0 - HKLM\Software\Microsoft\Internet Explorer\Ma in,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
inkId=69157Fix it, if you don't recognize the the program.Internet Explorer Start/Search pages URLsFIX IF UNKNOWNF2 - REG:system.ini: Shell=Explorer.exe Fix it, if you don't recognize the the program.Autoloading programs
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNF2 - REG:system.ini: UserInit=userinit.exe Fix it, if you don't recognize the the program.Autoloading programs
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-1 7B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dllChecked with TonyK's List. No threats found.Browser Helper s
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO2 - BHO: ãÓÇÚÏ ÑÇÈØ Adobe PDF Reader - {06849E9F -C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\ Common Files\Adobe\Acrob at\ActiveX\AcroIEHelper. dllChecked with TonyK's List. No threats found.Browser Helper s
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO2 - BHO: RealPlayer Download and Record Plugin f or Internet Explorer - {3049C3E9-B461-4BC5-8870-4 C09146192CA} - C:\Progra m Files\Real\RealPlayer\ rpbrowserrecordplugin.dllChecked, but not found in Tony K's List. Status unknown.Browser Helper s
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B 6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6. 0_05\bin\ssv.dllChecked with TonyK's List. No threats found.Browser Helper s
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA 8D5E23E045} - (no file)Checked with TonyK's List. No threats found.Browser Helper s
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO2 - BHO: Windows Live Sign-in Helper - {9030D464 -4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\ Common Files\Microsoft S hared\Windows Live\Windo wsLiveLogin.dllChecked with TonyK's List. No threats found.Browser Helper s
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\ igfxtray.exe*** GOOD: igfxtray.exe - Part of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. Quick access to the control panel via a System Tray icon. Available via Start -> Settings -> Control Panel. *** GOOD: igfxtray.exe. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system 32\hkcmd.exe*** GOOD: hkcmd.exe - "Part of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. If the user wishes to have ""HotKey"" access to Intel's customised graphics properties, it is required, otherwise not. It can be disabled via the Display Properties in the Control Panel". Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system 32\igfxpers.exe*** GOOD: igfxpers.exe - Part of Intels Common User Interface for chipsets with integrated graphics controllers - which allows user to change different driver properties through Windows User Interface. Not known exactly what it does but apparently it isn't required. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe*** GOOD: HDAudPropShortcut.exe - "Realtek audio card related - probably adds the odd feature to one of the ""Sounds"" Control Panel applet tabs - doesn't appear to be required". Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\R ealtek\InstallShield\AzMixerSel.exe*** GOOD: AzMixerSel.exe - Related to Realtek_Azalia Mixer Selector. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Syn aptics\SynTP\SynTPLpr.exe*** GOOD: AlarmWatcher.exe - Associated with SynTPEnh and SynTPLpr which are from Synaptics for touchpads on laptops. What does it do and is it required?. *** GOOD: SynTP.tmp RunOnce.exe. *** GOOD: syntplpr.exe. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Syn aptics\SynTP\SynTPEnh.exe*** GOOD: AlarmWatcher.exe - Associated with SynTPEnh and SynTPLpr which are from Synaptics for touchpads on laptops. What does it do and is it required?. *** GOOD: SynTPEnh.exe. *** GOOD: SynTP.tmp RunOnce.exe. *** GOOD: syntpenh.exe. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros \ACU.exe" -nogui*** GOOD: ACU.exe - Atheros wireless Client Utility. *** GOOD: ACU.exe. *** GOOD: CypressLinkMon.exe. *** POSSIBLE THREAT: 9 - Added by the KITRO.D (or ARGEN.A) WORM! . *** POSSIBLE THREAT: svnload32.exe. *** POSSIBLE THREAT: winlogin.pif. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" / minimized*** GOOD: avgas.exe - Part of AVG Anti-Spyware from Grisoft. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE*** GOOD: Alcmtr.exe - "Installed with hardware drivers for a Realtek AC97 audio device. It's believed that Realtek uses this file in order to data about the customer. Some users report problems with their on-board sound if this is disabled - hence the ""U"" recommendation". Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO4 - HKLM\..\Run: [NSLauncher] C:\Program Files\N okia\Nokia Software Launcher\NSLauncher.exe /star tupAutoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Fi les\Common Files\Ahead\Lib\NeroCheck.exe*** GOOD: NeroCheck.exe - "Associated with ""Nero Burning Rom"" CD writing software. Checks for driver issues". Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Progra m Files\Java\jre1.6.0_05\bin\jusched.exe"*** GOOD: jusched.exe - Checks with Sun's Java updates site to see if newer Java versions are available. Visit
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
or just run the Java Plug-In Control Panel. *** POSSIBLE THREAT: scvhost.exe - Added by the SDBOT-AVX WORM!. *** POSSIBLE THREAT: javamx.exe. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspers ky Lab\Kaspersky Internet Security 7.0\avp.exe"*** POSSIBLE THREAT: AVprotect9x.exe - Added by the NETSKY.M WORM!. *** GOOD: avp.exe - AOL's Active Virus Shield. *** GOOD: avp.exe. *** POSSIBLE THREAT: [path to trojan]. *** POSSIBLE THREAT: avp-32.exe. *** GOOD: avpcc.exe. *** GOOD: avpm.exe. *** POSSIBLE THREAT: avpr.exe. *** POSSIBLE THREAT: [path to trojan]. *** POSSIBLE THREAT: expl0rer.exe. *** POSSIBLE THREAT: rund1132.exe. *** POSSIBLE THREAT: navpmc.exe. *** POSSIBLE THREAT: avp.exe. *** POSSIBLE THREAT: AVprotect.exe. *** POSSIBLE THREAT: av32.pif. *** POSSIBLE THREAT: avpx.exe. *** GOOD: KAVPF.exe. *** GOOD: avp.exe. *** POSSIBLE THREAT: svchost.exe. *** GOOD: Kav.exe. *** POSSIBLE THREAT: wscntfy.exe. *** GOOD: KavPFW.exe. *** POSSIBLE THREAT: avp.exe. *** POSSIBLE THREAT: avpguard.exe. *** POSSIBLE THREAT: navprot1.exe. *** POSSIBLE THREAT: navprotect.exe. *** POSSIBLE THREAT: navp.exe. *** POSSIBLE THREAT: NavPass.exe. *** GOOD: PavPrS9x.exe. *** GOOD: PavProt.exe. *** GOOD: Pavprot9.exe. *** POSSIBLE THREAT: msnmsgr.exe. *** POSSIBLE THREAT: [path to trojan]. *** POSSIBLE THREAT: navpxaw32.exe. *** GOOD: avp.exe. *** POSSIBLE THREAT: AvpG.exe. *** POSSIBLE THREAT: avpmondll.exe. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\C ommon Files\Real\Update_OB\realsched.exe" -osboot*** GOOD: evntsvc.exe - "Application Scheduler installed along with RealOne Player. Once installed, it runs independently of RealOne Player. See here for more information, including how to disable it. Also see evntsvc and Realsched. Note that eventsvc.exe no longer appears to be in a newer version. To disable ""tkbell.exe"" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK". *** GOOD: realsched.exe. *** GOOD: tkbell.exe. *** POSSIBLE THREAT: TkBellExe.exe... - Added by a variant of the LOVGATE WORM!. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Pr ogram Files\Adobe\Photoshop Album Starter Edition \3.0\Apps\apdproxy.exe"*** GOOD: apdproxy.exe - Part of Adobe's Photoshop Album or Photoshop Elements packages - starts each time you connect an external image device to your PC (see here). Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Fi les\QuickTime\qttask.exe" -atboottime*** GOOD: Qttask.exe - "System Tray access to Apple's ""Quick Time"" viewer from version 5 onwards". *** POSSIBLE THREAT: qttasks.exe - CoolWebSearch parasite variant. *** POSSIBLE THREAT: [random filename]. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKLM\..\Run: [RemoteControl] "C:\Program Fil es\CyberLink\PowerDVD\PDVDServ.exe"*** GOOD: rmctrl.exe - Remote Control background application for Cyberlink's PowerDVD version 4 and above. Enables you to use a remote control with your DVD drive if your drive came with one. Not required if you don't have a remote control, or don't wish to use one . *** GOOD: PDVDServ.exe. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system3 2\ctfmon.exe*** GOOD: ctfmon.exe - CTFMon is involved with the language/alternative input services in Office XP. Ctfmon.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don't need these features. For more info on ctfmon see here. Ctfmon can be disabled from Control Panel, Text & Speech Services. Note - the file will always be located in the System32 folder, if it is located elsewhere it will likely be a worm or trojan! Can cause problems with some other programs if left enabled - see here for such an example. *** GOOD: ctfmon.exe. *** POSSIBLE THREAT: ctfmon32.exe - CoolWebSearch Ctfmon32 parasite variant. *** POSSIBLE THREAT: ctfmon.exe. *** POSSIBLE THREAT: msupdate32.exe. *** GOOD: ctfmon.exe. ***USERLIST: Office XP-related.Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background*** POSSIBLE THREAT: msnmsgrr.exe - Added by the RBOT.PZ WORM!. *** POSSIBLE THREAT: msnmsgr.exe. *** POSSIBLE THREAT: msnmsgr.exe. *** POSSIBLE THREAT: MSNMSGR.EXE. *** POSSIBLE THREAT: msnmsgr.exe. *** POSSIBLE THREAT: msnmsgr.exe. *** POSSIBLE THREAT: MSNMSGR.EXE. *** POSSIBLE THREAT: amsnmsgrs.exe. *** POSSIBLE THREAT: msnmsgr16.exe. *** POSSIBLE THREAT: msnmsgr7.exe. *** GOOD: msnmsgr.exe - "MSN Messenger (now superseeded by Windows Live Messenger) utility. If you don't use MSN Messenger, this can be annoying. Available via Start -> Programs. Go to MS Messenger -> Tools -> Options -> Preferences and uncheck ""Run this program when Windows starts""". *** POSSIBLE THREAT: MsnMsgrs.exe. *** POSSIBLE THREAT: msnmsgr.exe. *** POSSIBLE THREAT: msnmsgr-.exe. *** POSSIBLE THREAT: MSNMSGR5.exe. *** POSSIBLE THREAT: swef.bat. *** POSSIBLE THREAT: swin.bat. *** POSSIBLE THREAT: swe.bat. *** POSSIBLE THREAT: swiss.bat. *** POSSIBLE THREAT: swed.bat. *** POSSIBLE THREAT: msnmsgr.exe. *** POSSIBLE THREAT: msnmsgrs.exe. *** POSSIBLE THREAT: msnmsgrsc.exe. *** POSSIBLE THREAT: msnmsgrs.exe. *** POSSIBLE THREAT: msnmsgrsrvc.exe. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO4 - HKCU\..\Run: [IDMan] C:\Program Files\Intern et Download Manager\IDMan.exe /onboot*** GOOD: raidman.exe - HighPoint RAID management - hard disk striping/mirroring utility for increased performance and reliability. See here for more information on RAID. *** GOOD: IDMan.exe. *** POSSIBLE THREAT: idman.exe - Added by the RBOT-BMS WORM!. *** GOOD: Kraidman.exe. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOW S\system32\CTFMON.EXE (User 'SYSTEM')*** GOOD: ctfmon.exe - CTFMon is involved with the language/alternative input services in Office XP. Ctfmon.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don't need these features. For more info on ctfmon see here. Ctfmon can be disabled from Control Panel, Text & Speech Services. Note - the file will always be located in the System32 folder, if it is located elsewhere it will likely be a worm or trojan! Can cause problems with some other programs if left enabled - see here for such an example. *** GOOD: ctfmon.exe. *** POSSIBLE THREAT: ctfmon32.exe - CoolWebSearch Ctfmon32 parasite variant. *** POSSIBLE THREAT: ctfmon.exe. *** POSSIBLE THREAT: msupdate32.exe. *** GOOD: ctfmon.exe. ***USERLIST: Office XP-related.Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOW S\system32\CTFMON.EXE (User 'Default user')*** GOOD: ctfmon.exe - CTFMon is involved with the language/alternative input services in Office XP. Ctfmon.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don't need these features. For more info on ctfmon see here. Ctfmon can be disabled from Control Panel, Text & Speech Services. Note - the file will always be located in the System32 folder, if it is located elsewhere it will likely be a worm or trojan! Can cause problems with some other programs if left enabled - see here for such an example. *** GOOD: ctfmon.exe. *** POSSIBLE THREAT: ctfmon32.exe - CoolWebSearch Ctfmon32 parasite variant. *** POSSIBLE THREAT: ctfmon.exe. *** POSSIBLE THREAT: msupdate32.exe. *** GOOD: ctfmon.exe. ***USERLIST: Office XP-related.Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
OKO4 - Global Startup: Bluetooth.lnk = ?*** GOOD: ftflauncher.exe - Associated with an Anycom bluetooth wireless card. What does it do and is it required?. *** GOOD: BLUESO~1.EXE. *** GOOD: BlueSpaceNE.exe. *** GOOD: RunDLL32.exe irprops.cpl, BluetoothAuthenticationAgent. *** GOOD: btinst.exe. *** GOOD: BTSetBootKey.exe. *** GOOD: btstart.exe. *** GOOD: bttray.exe. *** GOOD: BtUsrBdg.exe. *** GOOD: BtUsrBdg.exe. *** GOOD: hpotdd01.exe. *** GOOD: hpotdd01.exe. *** GOOD: HP Wireless Assistant.exe. *** GOOD: QtZgAcer.EXE. *** GOOD: QtZpAcer.exe. *** GOOD: HotkeyApp.exe. *** GOOD: mRouterConfig.exe. *** GOOD: NclConf.exe. *** GOOD: RunDLL32.exe irprops.cpl, BluetoothAuthenticationAgent. *** GOOD: sppbridge.exe. *** GOOD: Switcher.exe. *** GOOD: voip phone.exe. *** GOOD: Switcher.exe. Autoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO4 - Global Startup: ÓÑÚÉ ÊÔÛíá Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader _sl.exeAutoloading programs from Registry or Startup group
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO6 - HKCU\Software\Policies\Microsoft\Internet Ex plorer\Control Panel presentFix it, unless you use SpyBot's 'Lock homepage' or caused intentionally by admin.IE Options access restricted by AdministratorFIX IF UNKNOWNO6 - HKLM\Software\Policies\Microsoft\Internet Ex plorer\Control Panel presentFix it, unless you use SpyBot's 'Lock homepage' or caused intentionally by admin.IE Options access restricted by AdministratorFIX IF UNKNOWNO8 - Extra context menu item: &ÊÕÏíÑ Åáì Microsof t Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXC EL.EXE/3000Fix it, if you don't recognize the name of the item in IE's right-click menu.Extra items in IE right-click menu
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Intern et Security 7.0\ie_banne r_deny.htmFix it, if you don't recognize the name of the item in IE's right-click menu.Extra items in IE right-click menu
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\bts endto_ie_ctx.htmFix it, if you don't recognize the name of the item in IE's right-click menu.Extra items in IE right-click menu
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO8 - Extra context menu item: ÊÍãíá Çáßá ÈÜ ÅäÊÑä Ê ÏÇæäáæÏ ãÇäíÌÑ - C:\Program Files\Internet Down load Manager\IEGetAll.htmFix it, if you don't recognize the name of the item in IE's right-click menu.Extra items in IE right-click menu
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO8 - Extra context menu item: ÊÍãíá ÈÜ ÅäÊÑäÊ ÏÇæ äáæÏ ãÇäíÌÑ - C:\Program Files\Internet Download Manager\IEExt.htmFix it, if you don't recognize the name of the item in IE's right-click menu.Extra items in IE right-click menu
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO8 - Extra context menu item: ÊÍãíá ãÍÊæì ÝíÏíæ ( ÅÝ.Åá.Ýí) ÈÜ ÅäÊÑäÊ ÏÇæäáæÏ ãÇäíÌÑ - C:\Program F iles\Internet Download M anager\IEGetVL.htmFix it, if you don't recognize the name of the item in IE's right-click menu.Extra items in IE right-click menu
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO9 - Extra button: (no name) - {08B0E5C0-4FCB-11C F-AAA5-00401C608501} - C:\Program Files\Java\jre1 .6.0_05\bin\ssv.dllFix it, if you don't recognize the button or menuitem (in the IE menu).Extra buttons or menu-items on main IE toolbar
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO9 - Extra 'Tools' menuitem: Sun Java Console - { 08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Progra m Files\Java\jre1.6.0_05 \bin\ssv.dllFix it, if you don't recognize the button or menuitem (in the IE menu).Extra buttons or menu-items on main IE toolbar
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO9 - Extra button: Web Anti-Virus statistics - {1 F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kas persky Internet Security 7.0\SCIEPlgn.dllFix it, if you don't recognize the button or menuitem (in the IE menu).Extra buttons or menu-items on main IE toolbar
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116- 983D-03B49BCBFFFE} - C:\Program Files\Paltalk Mes senger\Paltalk.exeFix it, if you don't recognize the button or menuitem (in the IE menu).Extra buttons or menu-items on main IE toolbar
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO9 - Extra button: ÈÍË - {92780B25-18CC-41C8-B9BE -3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\RE FIEBAR.DLLFix it, if you don't recognize the button or menuitem (in the IE menu).Extra buttons or menu-items on main IE toolbar
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C 863-46ef-9331-5C8D4460577F} - C:\Program Files\WI DCOMM\Bluetooth Software \btsendto_ie.htmFix it, if you don't recognize the button or menuitem (in the IE menu).Extra buttons or menu-items on main IE toolbar
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - { CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Progra m Files\WIDCOMM\Bluetoot h Software\btsendto_ie.h tmFix it, if you don't recognize the button or menuitem (in the IE menu).Extra buttons or menu-items on main IE toolbar
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO9 - Extra button: (no name) - {e2e2dd38-d088-413 4-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnos tic\xpnetdiag.exeFix it, if you don't recognize the button or menuitem (in the IE menu).Extra buttons or menu-items on main IE toolbar
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WI NDOWS\Network Diagnostic \xpnetdiag.exeFix it, if you don't recognize the button or menuitem (in the IE menu).Extra buttons or menu-items on main IE toolbar
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO9 - Extra button: Messenger - {FB5F1910-F110-11d 2-BB9E-00C04F795683} - C:\Program Files\Messenger \msmsgs.exeFix it, if you don't recognize the button or menuitem (in the IE menu).Extra buttons or menu-items on main IE toolbar
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Progr am Files\Messenger\msmsg s.exeFix it, if you don't recognize the button or menuitem (in the IE menu).Extra buttons or menu-items on main IE toolbar
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
ft.com/windowsupdate/v6/ V5Controls/en/x86/client /wuweb_site.cab?12109224 93656You may check the CLSID using SpywareBlaster's database, or try the Castlecops website.ActiveX s (aka Downloaded Program Files)
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash ) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
cromedia.com/get/shockwa ve/cabs/flash/swflash.cabYou may check the CLSID using SpywareBlaster's database, or try the Castlecops website.ActiveX s (aka Downloaded Program Files)
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX IF UNKNOWNO17 - HKLM\System\CCS\Services\Tcpip\..\{81CE48B6 -4ABF-4CEF-9E1B-C9D2BD7525DD}: NameServer = 212.7 1.32.19 212.71.32.20Fix if you do not recognize the domain as your company or ISP's. For NameServer, check the IP using Google.Lop.com domain hijacks
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX (CHECK NOTES!)O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1 .0\adialhk.dllO20s are usually (not always) malicious and should be fixed.AppInit_DLLs Registry value autorun
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
FIX (CHECK NOTES!)O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTE M32\antiwpa.dllO20s are usually (not always) malicious and should be fixed.AppInit_DLLs Registry value autorun
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO23 - Service: Atheros Configuration Service (ACS ) - Unknown owner - C:\WINDOWS\system32\acs.exeO23s should also appear in MSCONFIG. If malicious, the full name is often important sounding, while the filename is garbage. Use Delete NT Service after fixing a malicious O23! NT Services
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO23 - Service: AVG Anti-Spyware Guard - GRISOFT s .r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeO23s should also appear in MSCONFIG. If malicious, the full name is often important sounding, while the filename is garbage. Use Delete NT Service after fixing a malicious O23! NT Services
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO23 - Service: Kaspersky Internet Security 7.0 (A VP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet S ecurity 7.0\avp.exeO23s should also appear in MSCONFIG. If malicious, the full name is often important sounding, while the filename is garbage. Use Delete NT Service after fixing a malicious O23! NT Services
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO23 - Service: Bluetooth Service (btwdins) - Broa dcom Corporation. - C:\Program Files\WIDCOMM\Blue tooth Software\bin\btwdi ns.exeO23s should also appear in MSCONFIG. If malicious, the full name is often important sounding, while the filename is garbage. Use Delete NT Service after fixing a malicious O23! NT Services
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO23 - Service: OwnershipProtocol - Intel Corporat ion - C:\Program Files\Intel\Wireless\Bin\OProtSv c.exeO23s should also appear in MSCONFIG. If malicious, the full name is often important sounding, while the filename is garbage. Use Delete NT Service after fixing a malicious O23! NT Services
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO23 - Service: RegSrvc - Intel Corporation - C:\P rogram Files\Intel\Wireless\Bin\RegSrvc.exeO23s should also appear in MSCONFIG. If malicious, the full name is often important sounding, while the filename is garbage. Use Delete NT Service after fixing a malicious O23! NT Services
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO23 - Service: Spectrum24 Event Monitor (S24Event Monitor) - Intel Corporation - C:\Program Files\ Intel\Wireless\Bin\S24Ev Mon.exeO23s should also appear in MSCONFIG. If malicious, the full name is often important sounding, while the filename is garbage. Use Delete NT Service after fixing a malicious O23! NT Services
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exeO23s should also appear in MSCONFIG. If malicious, the full name is often important sounding, while the filename is garbage. Use Delete NT Service after fixing a malicious O23! NT Services
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
UNDETERMINEDO23 - Service: TuneUp Drive Defrag Service (TuneU p.Defrag) - TuneUp Software GmbH - C:\WINDOWS\Sys tem32\TuneUpDefragServic e.exeO23s should also appear in MSCONFIG. If malicious, the full name is often important sounding, while the filename is garbage. Use Delete NT Service after fixing a malicious O23! NT Services
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
 
عودة
أعلى