الفارس1427
زيزوومي جديد
غير متصل
من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
السلام عليكم اخواني
عند فتح البارتش d
او اي بارتش تظهر شاشة زرقاء ويعود بي الجهاز على سطح المكتب
شنهو الحل ؟؟
هذا التقرير لجهازي
عند فتح البارتش d
او اي بارتش تظهر شاشة زرقاء ويعود بي الجهاز على سطح المكتب
شنهو الحل ؟؟
هذا التقرير لجهازي
logfile of trend micro hijackthis v2.0.2
scan saved at 7:07:14 pm, on 4/20/2009
platform: Windows xp sp3 (winnt 5.01.2600)
msie: Internet explorer v6.00 sp3 (6.00.2900.5512)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\windows\system32\rundll32.exe
c:\program files\kaspersky lab\kaspersky anti-virus 2009\avp.exe
c:\windows\rthdcpl.exe
c:\program files\java\jre6\bin\jusched.exe
c:\windows\system32\svcl32\svcl32.exe
c:\windows\system32\ctfmon.exe
c:\program files\pando networks\pando\pando.exe
c:\program files\common files\nero\nero backitup 4\nbcore.exe
c:\program files\kaspersky lab\kaspersky anti-virus 2009\avp.exe
c:\program files\hotspot shield\bin\openvpnas.exe
c:\program files\hotspot shield\hsswpr\hsssrv.exe
c:\program files\java\jre6\bin\jqs.exe
c:\program files\common files\nero\nero backitup 4\nbservice.exe
c:\windows\system32\svchost.exe
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\nvsvc32.exe
c:\windows\explorer.exe
c:\documents and settings\رسيفر\desktop\zyzoom_hijackthis.exe
r0 - hkcu\software\microsoft\internet explorer\main,start page =يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = local
r3 - urlsearchhook: (no name) - {06663b56-0d73-4f9f-bcc5-4aa941470afd} - c:\program files\pandobar\srchastt\1.bin\p4srchas.dll
o2 - bho: Pando search assistant bho - {06663b51-0d73-4f9f-bcc5-4aa941470afd} - c:\program files\pandobar\srchastt\1.bin\p4srchas.dll
o2 - bho: Pccbho.cpccbho - {22fc6ce8-7d47-479f-b74a-bfbb04adb9af} - c:\program files\winferno\pc confidential\pccbho.dll (file missing)
o2 - bho: Ievkbdbho - {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky anti-virus 2009\ievkbd.dll
o2 - bho: Java(tm) plug-in ssv helper - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
o2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
o2 - bho: Java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
o2 - bho: Pando toolbar bho - {e3ea4fd1-cade-4ae5-84f7-086eee888be4} - c:\program files\pandobar\bar\1.bin\pandobar.dll
o2 - bho: Jqsiestartdetectorimpl - {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
o2 - bho: Ask toolbar bho - {fe063db1-4ec0-403e-8dd8-394c54984b2c} - c:\program files\asktbar\bar\2.bin\asktbar.dll (file missing)
o3 - toolbar: Pando toolbar - {e3ea4fd9-cade-4ae5-84f7-086eee888be4} - c:\program files\pandobar\bar\1.bin\pandobar.dll
o3 - toolbar: Ask toolbar - {fe063db9-4ec0-403e-8dd8-394c54984b2c} - c:\program files\asktbar\bar\2.bin\asktbar.dll (file missing)
o4 - hklm\..\run: [bluetoothauthenticationagent] rundll32.exe bthprops.cpl,,bluetoothauthenticationagent
o4 - hklm\..\run: [gest] =
o4 - hklm\..\run: [avp] "c:\program files\kaspersky lab\kaspersky anti-virus 2009\avp.exe"
o4 - hklm\..\run: [winvnc] "c:\program files\ultravnc\winvnc.exe" -servicehelper
o4 - hklm\..\run: [rthdcpl] rthdcpl.exe
o4 - hklm\..\run: [alcmtr] alcmtr.exe
o4 - hklm\..\run: [unlockerassistant] "c:\program files\unlocker\unlockerassistant.exe"
o4 - hklm\..\run: [sunjavaupdatesched] "c:\program files\java\jre6\bin\jusched.exe"
o4 - hklm\..\run: [wah] invalide
o4 - hklm\..\run: [system restore] c:\windows\scanreg.exe
o4 - hklm\..\run: [sysvcontoller32] c:\windows\system32\svcl32\svcl32.exe
o4 - hklm\..\run: [nvcpldaemon] rundll32.exe c:\windows\system32\nvcpl.dll,nvstartup
o4 - hklm\..\run: [nwiz] nwiz.exe /install
o4 - hklm\..\run: [nvmediacenter] rundll32.exe c:\windows\system32\nvmctray.dll,nvtaskbarinit
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [pando] "c:\program files\pando networks\pando\pando.exe" /minimized
o4 - hkcu\..\run: [lightscribe control panel] c:\program files\common files\lightscribe\lightscribecontrolpanel.exe -hidden
o4 - hkcu\..\run: [nbcore] "c:\program files\common files\nero\nero backitup 4\nbcore.exe"
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o8 - extra context menu item: &تصدير إلى microsoft excel - res://c:\progra~1\micros~2\office11\excel.exe/3000
o9 - extra button: Web traffic protection statistics - {1f460357-8a94-4d71-9ca3-aa4acf32ed8e} - c:\program files\kaspersky lab\kaspersky anti-virus 2009\scieplgn.dll
o9 - extra button: (no name) - {53f6fccd-9e22-4d71-86ea-6e43136192ab} - c:\program files\winferno\pc confidential\pcconfidential.exe (file missing)
o9 - extra 'tools' menuitem: Pc confidential - {53f6fccd-9e22-4d71-86ea-6e43136192ab} - c:\program files\winferno\pc confidential\pcconfidential.exe (file missing)
o9 - extra button: Pc confidential - {925dab62-f9ac-4221-806a-057bfb1014aa} - c:\program files\winferno\pc confidential\pcconfidential.exe (file missing)
o9 - extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra 'tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o16 - dpf: {17492023-c23a-453e-a040-c7c580bbf700} -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
o16 - dpf: {867e13f2-7f31-44fb-ac97-cd38e0dc46ef} -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
o16 - dpf: {c3f79a2b-b9b4-4a66-b012-3ee46475b072} (messengerstatsclient class) -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
o20 - appinit_dlls: C:\progra~1\kasper~1\kasper~1\mzvkbd.dll
o20 - winlogon notify: Antiwpa - c:\windows\system32\antiwpa.dll
o23 - service: Kaspersky anti-virus (avp) - kaspersky lab - c:\program files\kaspersky lab\kaspersky anti-virus 2009\avp.exe
o23 - service: Hotspot shield service (hotspotshieldservice) - unknown owner - c:\program files\hotspot shield\bin\openvpnas.exe
o23 - service: Hotspot shield helper service (hsssrv) - anchorfree inc. - c:\program files\hotspot shield\hsswpr\hsssrv.exe
o23 - service: Java quick starter (javaquickstarterservice) - sun microsystems, inc. - c:\program files\java\jre6\bin\jqs.exe
o23 - service: Nero backitup scheduler 4.0 - nero ag - c:\program files\common files\nero\nero backitup 4\nbservice.exe
o23 - service: Nvidia display driver service (nvsvc) - nvidia corporation - c:\windows\system32\nvsvc32.exe
o23 - service: Vnc server (winvnc) - unknown owner - c:\program files\ultravnc\winvnc.exe (file missing)
--
end of file - 7175 bytes
