تقرير هايجاك
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:32:29 م, on 16/01/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TechSmith\Snagit 9\Snagit32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\TechSmith\Snagit 9\TSCHelp.exe
C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\TechSmith\Snagit 9\snagiteditor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
E:\games\Conquer Online 2.0\play.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll
O1 - Hosts: ::1 localhost
O1 - Hosts: 210.249.144.166 we9stun.winning-eleven.net
O1 - Hosts: 217.112.88.118 pes6gate-ec.winning-eleven.net
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.5.0.125\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.5.0.125\IPS\IPSBHO.DLL
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.5.0.125\coIEPlg.dll
O3 - Toolbar: PandoraTV Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Snagit 9.lnk = C:\Program Files\TechSmith\Snagit 9\Snagit32.exe
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Internet Download Manager تحميل بواسطة - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل محتوى FLV بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\18.5.0.125\ccSvcHst.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
--
End of file - 7846 bytes
وتقرير الاداة
====== سجل أخطاء النظام ======
Computer Name: OMAR
Event Code: 1002
Message: The IP address lease 192.168.1.4 for the Network Card with network address 001FD0147BE8 has been
denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
Record Number: 11218
Source Name: Dhcp
Time Written: 20110106123247.000000+120
Event Type: error
User:
Computer Name: OMAR
Event Code: 4226
Message: TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Record Number: 11211
Source Name: Tcpip
Time Written: 20110106090400.000000+120
Event Type: warning
User:
Computer Name: OMAR
Event Code: 4226
Message: TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Record Number: 11183
Source Name: Tcpip
Time Written: 20110106032757.000000+120
Event Type: warning
User:
Computer Name: OMAR
Event Code: 1007
Message: Your computer has automatically configured the IP address for the Network
Card with network address 001FD0147BE8. The IP address being used is 169.254.27.201.
Record Number: 11065
Source Name: Dhcp
Time Written: 20110105214144.000000+120
Event Type: warning
User:
Computer Name: OMAR
Event Code: 1003
Message: Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 001FD0147BE8. The following
error occurred:
The semaphore timeout period has expired.
.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.
Record Number: 11048
Source Name: Dhcp
Time Written: 20110105214138.000000+120
Event Type: warning
User:
===== سجل أخطاء البرامج =====
Computer Name: OMAR
Event Code: 1517
Message: Windows saved user OMAR\pop registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.
This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
Record Number: 2111
Source Name: Userenv
Time Written: 20101017011554.000000+120
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: OMAR
Event Code: 1517
Message: Windows saved user OMAR\pop registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.
This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
Record Number: 2102
Source Name: Userenv
Time Written: 20101016214055.000000+120
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: OMAR
Event Code: 1517
Message: Windows saved user OMAR\pop registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.
This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
Record Number: 2097
Source Name: Userenv
Time Written: 20101016003455.000000+120
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: OMAR
Event Code: 1000
Message: Faulting application conquer.exe, version 2009.105.0.124, faulting module conquer.exe, version 2009.105.0.124, fault address 0x00155c0e.
Record Number: 2096
Source Name: Application Error
Time Written: 20101015220258.000000+120
Event Type: error
User:
Computer Name: OMAR
Event Code: 1000
Message: Faulting application pes2011demo.exe, version 1.0.0.0, faulting module pes2011demo.exe, version 1.0.0.0, fault address 0x000354fa.
Record Number: 2091
Source Name: Application Error
Time Written: 20101015163922.000000+120
Event Type: error
User:
===== تقرير انهيار البرامج =====
===== تقرير الشاشة الزرقاء =====
==================================================
Dump File : Mini011411-01.dmp
Crash Time : 14/01/2011 07:05:23 م
Bug Check String : THREAD_STUCK_IN_DEVICE_DRIVER
Bug Check Code : 0x000000ea
Parameter 1 : 0x87b773c0
Parameter 2 : 0x88750ce8
Parameter 3 : 0x89b89178
Parameter 4 : 0x00000001
Caused By Driver : ati3duag.dll
Caused By Address : ati3duag.dll+560b0
File Description : ati3duag.dll
Product Name : ATI Technologies Inc. Radeon DirectX Universal Driver
Company : ATI Technologies Inc.
File Version : 6.14.10.0753
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini011411-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
Dump File Size : 68,000
==================================================
==================================================
Dump File : Mini011611-01.dmp
Crash Time : 16/01/2011 11:26:57 ص
Bug Check String : THREAD_STUCK_IN_DEVICE_DRIVER
Bug Check Code : 0x000000ea
Parameter 1 : 0x87d5d200
Parameter 2 : 0x87eb49f0
Parameter 3 : 0x87f102b8
Parameter 4 : 0x00000001
Caused By Driver : ati3duag.dll
Caused By Address : ati3duag.dll+560b0
File Description : ati3duag.dll
Product Name : ATI Technologies Inc. Radeon DirectX Universal Driver
Company : ATI Technologies Inc.
File Version : 6.14.10.0753
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini011611-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
Dump File Size : 68,000
==================================================
==================================================
Dump File : Mini011611-02.dmp
Crash Time : 16/01/2011 01:09:56 م
Bug Check String : THREAD_STUCK_IN_DEVICE_DRIVER
Bug Check Code : 0x000000ea
Parameter 1 : 0x8828a388
Parameter 2 : 0x88793210
Parameter 3 : 0x87feb1c8
Parameter 4 : 0x00000001
Caused By Driver : ati3duag.dll
Caused By Address : ati3duag.dll+560b0
File Description : ati3duag.dll
Product Name : ATI Technologies Inc. Radeon DirectX Universal Driver
Company : ATI Technologies Inc.
File Version : 6.14.10.0753
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini011611-02.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
Dump File Size : 68,000
==================================================
==================================================
Dump File : Mini011611-03.dmp
Crash Time : 16/01/2011 04:28:08 م
Bug Check String : THREAD_STUCK_IN_DEVICE_DRIVER
Bug Check Code : 0x000000ea
Parameter 1 : 0x87fec100
Parameter 2 : 0x8837ab78
Parameter 3 : 0x89d30150
Parameter 4 : 0x00000001
Caused By Driver : ati3duag.dll
Caused By Address : ati3duag.dll+560b0
File Description : ati3duag.dll
Product Name : ATI Technologies Inc. Radeon DirectX Universal Driver
Company : ATI Technologies Inc.
File Version : 6.14.10.0753
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini011611-03.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
Dump File Size : 68,000
==================================================