السلام عليكم ورحمة الله وبركاته
أرجوكم جهزي في خطر
دلوني على الطريق الصحيح
c:\windows\system32\taskhost.exe
c:\windows\system32\dwm.exe
c:\windows\explorer.exe
c:\program files\cyberlink\powerdvd10\pdvd10serv.exe
c:\program files\cyberlink\shared files\brs.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\program files\avira\antivir desktop\avgnt.exe
c:\program files\my************search\bar\1.bin\mwsoemon.exe
c:\program files\windows sidebar\sidebar.exe
c:\program files\common files\ahead\lib\nmbgmonitor.exe
c:\program files\microsoft office\office14\msosync.exe
c:\program files\ela-salaty\salaty.exe
c:\program files\microsoft office\office14\onenotem.exe
c:\program files\common files\ahead\lib\nmindexstoresvr.exe
c:\program files\teamviewer\version6\teamviewer.exe
c:\windows\system32\notepad.exe
c:\program files\winrar\winrar.exe
c:\windows\system32\notepad.exe
c:\windows\system32\notepad.exe
c:\users\dell\appdata\local\temp\rar$ex00.321\procexp.exe
c:\windows\system32\searchfilterhost.exe
c:\program files\winrar\winrar.exe
c:\program files\trend micro\hijackthis\hijackthis.exe
r1 - hkcu\software\microsoft\internet explorer\main,search page = www.google.com
r0 - hkcu\software\microsoft\internet explorer\main,start page = http://search.conduit.com?searchsource=10&ctid=ct2722653
r1 - hklm\software\microsoft\internet explorer\main,default_page_url = http://go.microsoft.com/fwlink/?linkid=69157
r1 - hklm\software\microsoft\internet explorer\main,default_search_url = http://go.microsoft.com/fwlink/?linkid=54896
r1 - hklm\software\microsoft\internet explorer\main,search page = http://go.microsoft.com/fwlink/?linkid=54896
r0 - hklm\software\microsoft\internet explorer\main,start page = http://home.sweetim.com
r0 - hklm\software\microsoft\internet explorer\search,searchassistant =
r0 - hklm\software\microsoft\internet explorer\search,customizesearch =
r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername =
r3 - urlsearchhook: Sweetim toolbarurlsearchhook class - {eee6c35d-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mghelper.dll
r3 - urlsearchhook: Messengerpluslive tb toolbar - {d8fb4583-db9d-4c7b-85be-294c13a3e5c4} - c:\program files\messengerpluslive_tb\tbmess.dll
r3 - urlsearchhook: Pagerage toolbar - {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\tbpage.dll
r3 - urlsearchhook: (no name) - {00a6faf6-072e-44cf-8957-5838f569a31d} - c:\program files\my************search\bar\1.bin\mwssrcas.dll
o2 - bho: My************search search assistant bho - {00a6faf1-072e-44cf-8957-5838f569a31d} - c:\program files\my************search\bar\1.bin\mwssrcas.dll
o2 - bho: Mwsbar bho - {07b18ea1-a523-4961-b6bb-170de4475cca} - c:\program files\my************search\bar\1.bin\mwsbar.dll
o2 - bho: Acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
o2 - bho: Conduit engine - {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\conduitengine.dll
o2 - bho: (no name) - {5c255c8a-e604-49b4-9d64-90988571cecb} - (no file)
o2 - bho: Search helper - {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\sepsearchhelperie.dll
o2 - bho: Groove gfs browser helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\grooveex.dll
o2 - bho: Windows live id sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Pagerage toolbar - {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\tbpage.dll
o2 - bho: Urlredirectionbho - {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\urlredir.dll
o2 - bho: Megaiemn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\megaiemn.dll
o2 - bho: Bing bar bho - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
o2 - bho: Messengerpluslive tb - {d8fb4583-db9d-4c7b-85be-294c13a3e5c4} - c:\program files\messengerpluslive_tb\tbmess.dll
o2 - bho: Sweetie - {eee6c35c-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgtoolbarie.dll
o2 - bho: Yontoo layers - {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers client\yontooieclient.dll
o3 - toolbar: Sweetim toolbar for internet explorer - {eee6c35b-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgtoolbarie.dll
o3 - toolbar: Iadah toolbar - {3ea8d036-c9e7-4721-bcdf-c13d00c4cc39} - c:\program files\devnet\toolbar\devnet.dll
o3 - toolbar: @c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
o3 - toolbar: Messengerpluslive tb toolbar - {d8fb4583-db9d-4c7b-85be-294c13a3e5c4} - c:\program files\messengerpluslive_tb\tbmess.dll
o3 - toolbar: Conduit engine - {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\conduitengine.dll
o3 - toolbar: Pagerage toolbar - {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\tbpage.dll
o3 - toolbar: My ************ search - {07b18ea9-a523-4961-b6bb-170de4475cca} - c:\program files\my************search\bar\1.bin\mwsbar.dll
o4 - hklm\..\run: [remotecontrol10] "c:\program files\cyberlink\powerdvd10\pdvd10serv.exe"
o4 - hklm\..\run: [bdregion] c:\program files\cyberlink\shared files\brs.exe
o4 - hklm\..\run: [nerofiltercheck] c:\program files\common files\ahead\lib\nerocheck.exe
o4 - hklm\..\run: [bcssync] "c:\program files\microsoft office\office14\bcssync.exe" /delayservices
o4 - hklm\..\run: [adobeaamupdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\updaterstartuputility.exe"
o4 - hklm\..\run: [switchboard] c:\program files\common files\adobe\switchboard\switchboard.exe
o4 - hklm\..\run: [adobecs5servicemanager] "c:\program files\common files\adobe\cs5servicemanager\cs5servicemanager.exe" -launchedbylogin
o4 - hklm\..\run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
o4 - hklm\..\run: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
o4 - hklm\..\run: [my ************ search bar search scope monitor] "c:\progra~1\my************s~1\bar\1.bin\m3srchmn.exe" /m=2 /w /h
o4 - hklm\..\run: [my************search email plugin] c:\progra~1\my************s~1\bar\1.bin\mwsoemon.exe
o4 - hkcu\..\run: [sidebar] c:\program files\windows sidebar\sidebar.exe /autorun
o4 - hkcu\..\run: [google update] "c:\users\dell\appdata\local\google\update\googleupdate.exe" /c
o4 - hkcu\..\run: [bgmonitor_{79662e04-7c6c-4d9f-84c7-88d8a56b10aa}] "c:\program files\common files\ahead\lib\nmbgmonitor.exe"
o4 - hkcu\..\run: [officesyncprocess] "c:\program files\microsoft office\office14\msosync.exe"
o4 - hkcu\..\run: [my************search email plugin] c:\progra~1\my************s~1\bar\1.bin\mwsoemon.exe
o4 - hkcu\..\run: [skype] "c:\program files\skype\phone\skype.exe" /nosplash /minimized
o4 - hkus\s-1-5-19\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /autorun (user 'service local')
o4 - hkus\s-1-5-19\..\runonce: [mctadmin] c:\windows\system32\mctadmin.exe (user 'service local')
o4 - hkus\s-1-5-20\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /autorun (user 'service reseau')
o4 - hkus\s-1-5-20\..\runonce: [mctadmin] c:\windows\system32\mctadmin.exe (user 'service reseau')
o4 - startup: Ela-salaty.lnk = c:\program files\ela-salaty\salaty.exe
o4 - startup: Onenote 2010 - capture d’écran et lancement.lnk = c:\program files\microsoft office\office14\onenotem.exe
o8 - extra context menu item: &envoyer à onenote - res://c:\progra~1\micros~4\office14\onbttnie.dll/105
o8 - extra context menu item: E&xporter vers microsoft excel - res://c:\progra~1\micros~4\office14\excel.exe/3000
o9 - extra button: Envoyer à onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\program files\microsoft office\office14\onbttnie.dll
o9 - extra 'tools' menuitem: &envoyer à onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\program files\microsoft office\office14\onbttnie.dll
o9 - extra button: Notes &liées onenote - {789fe86f-6fc4-46a1-9849-ede0db0c95ca} - c:\program files\microsoft office\office14\onbttnielinkednotes.dll
o9 - extra 'tools' menuitem: Notes &liées onenote - {789fe86f-6fc4-46a1-9849-ede0db0c95ca} - c:\program files\microsoft office\office14\onbttnielinkednotes.dll
o10 - unknown file in winsock lsp: C:\program files\common files\microsoft shared\windows live\wlidnsp.dll
o10 - unknown file in winsock lsp: C:\program files\common files\microsoft shared\windows live\wlidnsp.dll
o13 - gopher prefix:
O18 - protocol: Skype4com - {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - c:\progra~1\common~1\skype\skype4~1.dll
o18 - filter hijack: Text/xml - {807573e5-5146-11d5-a672-00b0d022e945} - c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
o23 - service: Avira antivir planificateur (antivirschedulerservice) - avira gmbh - c:\program files\avira\antivir desktop\sched.exe
o23 - service: Avira antivir guard (antivirservice) - avira gmbh - c:\program files\avira\antivir desktop\avguard.exe
o23 - service: My ************ search service (my************searchservice) - my************search.com - c:\progra~1\my************s~1\bar\1.bin\mwssvc.exe
o23 - service: Nbservice - nero ag - c:\program files\nero\nero 7\nero backitup\nbservice.exe
o23 - service: Nmindexingservice - nero ag - c:\program files\common files\ahead\lib\nmindexingservice.exe
o23 - service: Switchboard - adobe systems incorporated - c:\program files\common files\adobe\switchboard\switchboard.exe
o23 - service: Teamviewer 6 (teamviewer6) - teamviewer gmbh - c:\program files\teamviewer\version6\teamviewer_service.exe
c:\windows\system32\dwm.exe
c:\windows\explorer.exe
c:\program files\cyberlink\powerdvd10\pdvd10serv.exe
c:\program files\cyberlink\shared files\brs.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\program files\avira\antivir desktop\avgnt.exe
c:\program files\my************search\bar\1.bin\mwsoemon.exe
c:\program files\windows sidebar\sidebar.exe
c:\program files\common files\ahead\lib\nmbgmonitor.exe
c:\program files\microsoft office\office14\msosync.exe
c:\program files\ela-salaty\salaty.exe
c:\program files\microsoft office\office14\onenotem.exe
c:\program files\common files\ahead\lib\nmindexstoresvr.exe
c:\program files\teamviewer\version6\teamviewer.exe
c:\windows\system32\notepad.exe
c:\program files\winrar\winrar.exe
c:\windows\system32\notepad.exe
c:\windows\system32\notepad.exe
c:\users\dell\appdata\local\temp\rar$ex00.321\procexp.exe
c:\windows\system32\searchfilterhost.exe
c:\program files\winrar\winrar.exe
c:\program files\trend micro\hijackthis\hijackthis.exe
r1 - hkcu\software\microsoft\internet explorer\main,search page = www.google.com
r0 - hkcu\software\microsoft\internet explorer\main,start page = http://search.conduit.com?searchsource=10&ctid=ct2722653
r1 - hklm\software\microsoft\internet explorer\main,default_page_url = http://go.microsoft.com/fwlink/?linkid=69157
r1 - hklm\software\microsoft\internet explorer\main,default_search_url = http://go.microsoft.com/fwlink/?linkid=54896
r1 - hklm\software\microsoft\internet explorer\main,search page = http://go.microsoft.com/fwlink/?linkid=54896
r0 - hklm\software\microsoft\internet explorer\main,start page = http://home.sweetim.com
r0 - hklm\software\microsoft\internet explorer\search,searchassistant =
r0 - hklm\software\microsoft\internet explorer\search,customizesearch =
r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername =
r3 - urlsearchhook: Sweetim toolbarurlsearchhook class - {eee6c35d-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mghelper.dll
r3 - urlsearchhook: Messengerpluslive tb toolbar - {d8fb4583-db9d-4c7b-85be-294c13a3e5c4} - c:\program files\messengerpluslive_tb\tbmess.dll
r3 - urlsearchhook: Pagerage toolbar - {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\tbpage.dll
r3 - urlsearchhook: (no name) - {00a6faf6-072e-44cf-8957-5838f569a31d} - c:\program files\my************search\bar\1.bin\mwssrcas.dll
o2 - bho: My************search search assistant bho - {00a6faf1-072e-44cf-8957-5838f569a31d} - c:\program files\my************search\bar\1.bin\mwssrcas.dll
o2 - bho: Mwsbar bho - {07b18ea1-a523-4961-b6bb-170de4475cca} - c:\program files\my************search\bar\1.bin\mwsbar.dll
o2 - bho: Acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
o2 - bho: Conduit engine - {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\conduitengine.dll
o2 - bho: (no name) - {5c255c8a-e604-49b4-9d64-90988571cecb} - (no file)
o2 - bho: Search helper - {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\sepsearchhelperie.dll
o2 - bho: Groove gfs browser helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\grooveex.dll
o2 - bho: Windows live id sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Pagerage toolbar - {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\tbpage.dll
o2 - bho: Urlredirectionbho - {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\urlredir.dll
o2 - bho: Megaiemn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\megaiemn.dll
o2 - bho: Bing bar bho - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
o2 - bho: Messengerpluslive tb - {d8fb4583-db9d-4c7b-85be-294c13a3e5c4} - c:\program files\messengerpluslive_tb\tbmess.dll
o2 - bho: Sweetie - {eee6c35c-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgtoolbarie.dll
o2 - bho: Yontoo layers - {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers client\yontooieclient.dll
o3 - toolbar: Sweetim toolbar for internet explorer - {eee6c35b-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgtoolbarie.dll
o3 - toolbar: Iadah toolbar - {3ea8d036-c9e7-4721-bcdf-c13d00c4cc39} - c:\program files\devnet\toolbar\devnet.dll
o3 - toolbar: @c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
o3 - toolbar: Messengerpluslive tb toolbar - {d8fb4583-db9d-4c7b-85be-294c13a3e5c4} - c:\program files\messengerpluslive_tb\tbmess.dll
o3 - toolbar: Conduit engine - {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\conduitengine.dll
o3 - toolbar: Pagerage toolbar - {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\tbpage.dll
o3 - toolbar: My ************ search - {07b18ea9-a523-4961-b6bb-170de4475cca} - c:\program files\my************search\bar\1.bin\mwsbar.dll
o4 - hklm\..\run: [remotecontrol10] "c:\program files\cyberlink\powerdvd10\pdvd10serv.exe"
o4 - hklm\..\run: [bdregion] c:\program files\cyberlink\shared files\brs.exe
o4 - hklm\..\run: [nerofiltercheck] c:\program files\common files\ahead\lib\nerocheck.exe
o4 - hklm\..\run: [bcssync] "c:\program files\microsoft office\office14\bcssync.exe" /delayservices
o4 - hklm\..\run: [adobeaamupdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\updaterstartuputility.exe"
o4 - hklm\..\run: [switchboard] c:\program files\common files\adobe\switchboard\switchboard.exe
o4 - hklm\..\run: [adobecs5servicemanager] "c:\program files\common files\adobe\cs5servicemanager\cs5servicemanager.exe" -launchedbylogin
o4 - hklm\..\run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
o4 - hklm\..\run: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
o4 - hklm\..\run: [my ************ search bar search scope monitor] "c:\progra~1\my************s~1\bar\1.bin\m3srchmn.exe" /m=2 /w /h
o4 - hklm\..\run: [my************search email plugin] c:\progra~1\my************s~1\bar\1.bin\mwsoemon.exe
o4 - hkcu\..\run: [sidebar] c:\program files\windows sidebar\sidebar.exe /autorun
o4 - hkcu\..\run: [google update] "c:\users\dell\appdata\local\google\update\googleupdate.exe" /c
o4 - hkcu\..\run: [bgmonitor_{79662e04-7c6c-4d9f-84c7-88d8a56b10aa}] "c:\program files\common files\ahead\lib\nmbgmonitor.exe"
o4 - hkcu\..\run: [officesyncprocess] "c:\program files\microsoft office\office14\msosync.exe"
o4 - hkcu\..\run: [my************search email plugin] c:\progra~1\my************s~1\bar\1.bin\mwsoemon.exe
o4 - hkcu\..\run: [skype] "c:\program files\skype\phone\skype.exe" /nosplash /minimized
o4 - hkus\s-1-5-19\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /autorun (user 'service local')
o4 - hkus\s-1-5-19\..\runonce: [mctadmin] c:\windows\system32\mctadmin.exe (user 'service local')
o4 - hkus\s-1-5-20\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /autorun (user 'service reseau')
o4 - hkus\s-1-5-20\..\runonce: [mctadmin] c:\windows\system32\mctadmin.exe (user 'service reseau')
o4 - startup: Ela-salaty.lnk = c:\program files\ela-salaty\salaty.exe
o4 - startup: Onenote 2010 - capture d’écran et lancement.lnk = c:\program files\microsoft office\office14\onenotem.exe
o8 - extra context menu item: &envoyer à onenote - res://c:\progra~1\micros~4\office14\onbttnie.dll/105
o8 - extra context menu item: E&xporter vers microsoft excel - res://c:\progra~1\micros~4\office14\excel.exe/3000
o9 - extra button: Envoyer à onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\program files\microsoft office\office14\onbttnie.dll
o9 - extra 'tools' menuitem: &envoyer à onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\program files\microsoft office\office14\onbttnie.dll
o9 - extra button: Notes &liées onenote - {789fe86f-6fc4-46a1-9849-ede0db0c95ca} - c:\program files\microsoft office\office14\onbttnielinkednotes.dll
o9 - extra 'tools' menuitem: Notes &liées onenote - {789fe86f-6fc4-46a1-9849-ede0db0c95ca} - c:\program files\microsoft office\office14\onbttnielinkednotes.dll
o10 - unknown file in winsock lsp: C:\program files\common files\microsoft shared\windows live\wlidnsp.dll
o10 - unknown file in winsock lsp: C:\program files\common files\microsoft shared\windows live\wlidnsp.dll
o13 - gopher prefix:
O18 - protocol: Skype4com - {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - c:\progra~1\common~1\skype\skype4~1.dll
o18 - filter hijack: Text/xml - {807573e5-5146-11d5-a672-00b0d022e945} - c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
o23 - service: Avira antivir planificateur (antivirschedulerservice) - avira gmbh - c:\program files\avira\antivir desktop\sched.exe
o23 - service: Avira antivir guard (antivirservice) - avira gmbh - c:\program files\avira\antivir desktop\avguard.exe
o23 - service: My ************ search service (my************searchservice) - my************search.com - c:\progra~1\my************s~1\bar\1.bin\mwssvc.exe
o23 - service: Nbservice - nero ag - c:\program files\nero\nero 7\nero backitup\nbservice.exe
o23 - service: Nmindexingservice - nero ag - c:\program files\common files\ahead\lib\nmindexingservice.exe
o23 - service: Switchboard - adobe systems incorporated - c:\program files\common files\adobe\switchboard\switchboard.exe
o23 - service: Teamviewer 6 (teamviewer6) - teamviewer gmbh - c:\program files\teamviewer\version6\teamviewer_service.exe
دلوني على الطريق الصحيح