Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:19:06 AM, on 17/08/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16660)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\DeviceVM\SmartView\SmartViewAgent.exe
C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Windows\System32\wscript.exe
C:\Windows\System32\wscript.exe
C:\Users\mohamed ana\AppData\Roaming\Easy-hide-ip.exe
C:\Windows\system32\wbem\unsecapp.exe
D:\برامج\Google\Chrome\Application\chrome.exe
D:\برامج\Google\Chrome\Application\chrome.exe
D:\برامج\Google\Chrome\Application\chrome.exe
D:\برامج\Google\Chrome\Application\chrome.exe
D:\برامج\Google\Chrome\Application\chrome.exe
D:\برامج\Google\Chrome\Application\chrome.exe
D:\برامج\Google\Chrome\Application\chrome.exe
D:\برامج\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\mohamed ana\Desktop\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = عفوا ,,, لايمكنك مشاهده الروابط لانك غير مسجل لدينا
[ للتسجيل اضغط هنا ]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = عفوا ,,, لايمكنك مشاهده الروابط لانك غير مسجل لدينا
[ للتسجيل اضغط هنا ]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = عفوا ,,, لايمكنك مشاهده الروابط لانك غير مسجل لدينا
[ للتسجيل اضغط هنا ]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = عفوا ,,, لايمكنك مشاهده الروابط لانك غير مسجل لدينا
[ للتسجيل اضغط هنا ]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SearchHook Class - {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - C:\Program Files\DeviceVM\SmartView\AddressBarSearch.dll
R3 - URLSearchHook: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\prxtbHots.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: SmartView VisualBookmark - {0E5680D1-BF44-4929-94AF-FD30D784AD1D} - C:\Program Files\DeviceVM\SmartView\SmartView.dll
O2 - BHO: Hotspot Shield - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\prxtbHots.dll
O3 - Toolbar: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\prxtbHots.dll
O4 - HKLM\..\Run: [SmartViewAgent] "C:\Program Files\DeviceVM\SmartView\SmartViewAgent.exe"
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Bypass] wscript.exe //B "C:\Users\MOHAME~1\AppData\Local\Temp\Bypass.vbs.v bs"
O4 - HKLM\..\Run: [New] wscript.exe //B "C:\Users\MOHAME~1\AppData\Local\Temp\New.vbs. vbs"
O4 - HKLM\..\Run: [d35abdc53beb89b8dcd206ccbe8234c4] "C:\Users\mohamed ana\AppData\Roaming\Easy-hide-ip.exe" ..
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [Bypass] wscript.exe //B "C:\Users\MOHAME~1\AppData\Local\Temp\Bypass.vbs.v bs"
O4 - HKCU\..\Run: [New] wscript.exe //B "C:\Users\MOHAME~1\AppData\Local\Temp\New.vbs. vbs"
O4 - HKCU\..\Run: [d35abdc53beb89b8dcd206ccbe8234c4] "C:\Users\mohamed ana\AppData\Roaming\Easy-hide-ip.exe" ..
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Bypass.vbs.vbs
O4 - Startup: d35abdc53beb89b8dcd206ccbe8234c4.exe
O4 - Startup: New.vbs.vbs
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{09741973-3E3F-4899-8B5A-F8EFD3A29122}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE5B1E5C-EB9A-48AD-A30F-C88DCE535321}: NameServer = 192.168.0.1 213.131.65.20
O17 - HKLM\System\CS1\Services\Tcpip\..\{09741973-3E3F-4899-8B5A-F8EFD3A29122}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{09741973-3E3F-4899-8B5A-F8EFD3A29122}: NameServer = 8.8.8.8,8.8.4.4
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpda teService.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Smart View Service (SmartViewService) - DeviceVM, Inc. - C:\Program Files\DeviceVM\SmartView\SmartViewService.exe
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - VIA Technologies, Inc. - C:\Windows\system32\viakaraokesrv.exe
O23 - Service: Splashtop Connect IE Software Updater Service (WCUService_STC_IE) - Splashtop Inc. - C:\Program Files\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe
--
End of file - 6350 bytes