قم بمتابعة الفيديو أدناه لمعرفة كيفية تثبيت موقعنا كتطبيق ويب على الشاشة الرئيسية.
ملاحظة: قد لا تكون هذه الميزة متاحة في بعض المتصفحات.
أرجو أن تتمكن أخي من إكتشاف الخلل وفقك الله .logfile of trend micro hijackthis v2.0.2
scan saved at 05:47:20 م, on 14/04/2009
platform: Windows xp sp3 (winnt 5.01.2600)
msie: Internet explorer v8.00 (8.00.6001.18702)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\program files\bonjour\mdnsresponder.exe
c:\windows\system32\wgatray.exe
c:\windows\explorer.exe
c:\windows\system32\wscntfy.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\windows\system32\ctfmon.exe
c:\documents and settings\يحيى\local settings\application data\google\update\googleupdate.exe
c:\program files\msn messenger\msnmsgr.exe
c:\program files\nokia\nokia pc suite 6\pcsuite.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\pc connectivity solution\servicelayer.exe
c:\program files\pc connectivity solution\transports\nclusbsrv.exe
c:\program files\pc connectivity solution\transports\nclrssrv.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\msn messenger\usnsvc.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\internet explorer\iexplore.exe
c:\documents and settings\يحيى\سطح المكتب\مجلد جديد\zyzoom_hijackthis.exe
r1 - hklm\software\microsoft\internet explorer\main,default_page_url =يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
r1 - hklm\software\microsoft\internet explorer\main,default_search_url =يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
r1 - hklm\software\microsoft\internet explorer\main,search page =يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
r0 - hklm\software\microsoft\internet explorer\main,start page =يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
r0 - hkcu\software\microsoft\internet explorer\main,local page =
r0 - hklm\software\microsoft\internet explorer\main,local page =
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyserver = socks=
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = *.local
r3 - urlsearchhook: Hotspot shield toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - c:\program files\hotspot_shield\tbhots.dll
r3 - urlsearchhook: Sweetim toolbarurlsearchhook class - {eee6c35d-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mghelper.dll
o2 - bho: Idm helper - {0055c089-8582-441b-a0bf-17b458c2a3a8} - (no file)
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: Groove gfs browser helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\grooveshellextensions.dll
o2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
o2 - bho: Tbsb01923 - {7ff4e31c-74eb-433d-a8aa-a12a99521674} - (no file)
o2 - bho: Ppvadownloader - {a986e409-30cc-4185-89bb-ab212c104524} - c:\program files\ppliveva\downloadermanager.dll
o2 - bho: Google toolbar helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\googletoolbar.dll
o2 - bho: Sweetie - {eee6c35c-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgtoolbarie.dll
o3 - toolbar: (no name) - {0bf43445-2f28-4351-9252-17fe6e806aa0} - (no file)
o3 - toolbar: Hotspot shield toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - c:\program files\hotspot_shield\tbhots.dll
o3 - toolbar: Sweetim toolbar for internet explorer - {eee6c35b-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgtoolbarie.dll
o3 - toolbar: Sahate toolbar - {1a295e8e-e51b-42ce-81b2-b73614f0fcd2} - (no file)
o3 - toolbar: &google toolbar - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\googletoolbar.dll
o4 - hklm\..\run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
o4 - hklm\..\run: [axis tons the mp3] c:\documents and settings\all users\application data\readme live axis tons\bat online.exe
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [google update] "c:\documents and settings\يحيى\local settings\application data\google\update\googleupdate.exe" /c
o4 - hkcu\..\run: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background
o4 - hkcu\..\run: [thunk sign] c:\docume~1\f58f~1\applic~1\openju~1\mathfilmmedia.exe
o4 - hkcu\..\run: [pc suite tray] "c:\program files\nokia\nokia pc suite 6\pcsuite.exe" -onlytray
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'local service')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'network service')
o8 - extra context menu item: &iespell options - res://c:\program files\iespell\iespell.dll/spelloption.htm
o8 - extra context menu item: Check &spelling - res://c:\program files\iespell\iespell.dll/spellcheck.htm
o8 - extra context menu item: Lookup on merriam webster -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفيfiles\iespell\merriam webster.htm
o8 - extra context menu item: Lookup on wikipedia -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفيfiles\iespell\wikipedia.htm
o8 - extra context menu item: ت&صدير إلى microsoft excel - res://c:\progra~1\micros~2\office12\excel.exe/3000
o9 - extra button: Iespell - {0e17d5b7-9f5d-4fee-9df6-ca6ee38b68a8} - c:\program files\iespell\iespell.dll
o9 - extra 'tools' menuitem: Iespell - {0e17d5b7-9f5d-4fee-9df6-ca6ee38b68a8} - c:\program files\iespell\iespell.dll
o9 - extra button: (no name) - {1606d6f9-9d3b-4aea-a025-ed5b2fd488e7} - c:\program files\iespell\iespell.dll
o9 - extra 'tools' menuitem: Iespell options - {1606d6f9-9d3b-4aea-a025-ed5b2fd488e7} - c:\program files\iespell\iespell.dll
o9 - extra button: Sahate toolbar - {1a295e8e-e51b-42ce-81b2-b73614f0fcd2} - c:\windows\system32\shdocvw.dll
o9 - extra 'tools' menuitem: Sahate toolbar - {1a295e8e-e51b-42ce-81b2-b73614f0fcd2} - c:\windows\system32\shdocvw.dll
o9 - extra button: إرسال إلى onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~1\micros~2\office12\onbttnie.dll
o9 - extra 'tools' menuitem: إر&سال إلى onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~1\micros~2\office12\onbttnie.dll
o9 - extra button: Skype - {77bf5300-1474-4ec7-9980-d32b190e9b07} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
o9 - extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office12\refiebar.dll
o9 - extra button: Pp.tv video-search - {95b3f550-91c4-4627-bcc4-521288c52978} -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي(file missing)
o9 - extra 'tools' menuitem: Pp.tv video-search - {95b3f550-91c4-4627-bcc4-521288c52978} -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي(file missing)
o9 - extra button: Pplive video accelerator - {95b3f550-91c4-4627-bcc4-521288c52979} - c:\program files\ppliveva\ppliveva.exe
o9 - extra 'tools' menuitem: Pplive video accelerator - {95b3f550-91c4-4627-bcc4-521288c52979} - c:\program files\ppliveva\ppliveva.exe
o9 - extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra 'tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra button: Yahoo! Messenger - {e5d12c4e-7b4f-11d3-b5c9-0050045c3c96} - c:\progra~1\yahoo!\messen~1\ypager.exe
o9 - extra 'tools' menuitem: Yahoo! Messenger - {e5d12c4e-7b4f-11d3-b5c9-0050045c3c96} - c:\progra~1\yahoo!\messen~1\ypager.exe
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o12 - plugin for .spop: C:\program files\internet explorer\plugins\npdocbox.dll
o18 - protocol: Groovelocalgws - {88fed34c-f0ca-4636-a375-3cb6248b04cd} - c:\program files\microsoft office\office12\groovesystemservices.dll
o18 - protocol: Skype4com - {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - c:\progra~1\common~1\skype\skype4~1.dll
o23 - service: Bonjour service - apple inc. - c:\program files\bonjour\mdnsresponder.exe
o23 - service: Servicelayer - nokia. - c:\program files\pc connectivity solution\servicelayer.exe
--
end of file - 8551 bytes