عاصفة
زيزوومي نشيط
غير متصل
قم بمتابعة الفيديو أدناه لمعرفة كيفية تثبيت موقعنا كتطبيق ويب على الشاشة الرئيسية.
ملاحظة: قد لا تكون هذه الميزة متاحة في بعض المتصفحات.
logfile of trend micro hijackthis v2.0.2
scan saved at 11:15:36 م, on 01/05/2009
platform: Windows xp sp2 (winnt 5.01.2600)
msie: Internet explorer v6.00 sp2 (6.00.2900.2180)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\appserv\apache2.2\bin\httpd.exe
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
c:\appserv\apache2.2\bin\httpd.exe
c:\appserv\mysql\bin\mysqld-nt.exe
c:\windows\system32\svchost.exe
c:\progra~1\speedb~1\videoacceleratorservice.exe
c:\program files\viewpoint\common\viewpointservice.exe
c:\windows\explorer.exe
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
c:\progra~1\speedb~1\videoacceleratorengine.exe
c:\program files\internet explorer\iexplore.exe
c:\documents and settings\my pc\local settings\temp\wz5f16\portable usb virus scan v2.3\usb_virus_scan.v2.3.exe
c:\program files\mozilla firefox\firefox.exe
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
c:\program files\msn messenger\msnmsgr.exe
c:\program files\msn messenger\msnmsgr.exe
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
c:\documents and settings\my pc\desktop\hijackthis.exe
o2 - bho: Acroiehlprobj class - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: Ssvhelper class - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
o2 - bho: Acroietoolbarhelper class - {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\acroiefavclient.dll
o3 - toolbar: &save flash - {4064ea35-578d-4073-a834-c96d82cbcf40} - c:\program files\save flash\saveflash.dll
o3 - toolbar: Adobe pdf - {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\acroiefavclient.dll
o4 - hklm\..\run: [avp] "c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe"
o4 - hklm\..\run: [tcactive] c:\program files\the cleaner\tca.exe
o4 - hkcu\..\run: [cdoosoft] c:\windows\system32\olhrwef.exe
o6 - hkcu\software\policies\microsoft\internet explorer\control panel present
o8 - extra context menu item: Add to anti-banner - c:\program files\kaspersky lab\kaspersky internet security 7.0\ie_banner_deny.htm
o8 - extra context menu item: Convert link target to adobe pdf - res://c:\program files\adobe\acrobat 7.0\acrobat\acroiefavclient.dll/acroiecapture.html
o8 - extra context menu item: Convert link target to existing pdf - res://c:\program files\adobe\acrobat 7.0\acrobat\acroiefavclient.dll/acroieappend.html
o8 - extra context menu item: Convert selected links to adobe pdf - res://c:\program files\adobe\acrobat 7.0\acrobat\acroiefavclient.dll/acroiecapturesellinks.html
o8 - extra context menu item: Convert selected links to existing pdf - res://c:\program files\adobe\acrobat 7.0\acrobat\acroiefavclient.dll/acroieappendsellinks.html
o8 - extra context menu item: Convert selection to adobe pdf - res://c:\program files\adobe\acrobat 7.0\acrobat\acroiefavclient.dll/acroiecapture.html
o8 - extra context menu item: Convert selection to existing pdf - res://c:\program files\adobe\acrobat 7.0\acrobat\acroiefavclient.dll/acroieappend.html
o8 - extra context menu item: Convert to adobe pdf - res://c:\program files\adobe\acrobat 7.0\acrobat\acroiefavclient.dll/acroiecapture.html
o8 - extra context menu item: Convert to existing pdf - res://c:\program files\adobe\acrobat 7.0\acrobat\acroiefavclient.dll/acroieappend.html
o8 - extra context menu item: E&xport to microsoft excel - res://c:\progra~1\micros~2\office10\excel.exe/3000
o8 - extra context menu item: الدليل السريع - c:\windows\ww80.html
o9 - extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
o9 - extra 'tools' menuitem: Sun java console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
o9 - extra button: Web anti-virus statistics - {1f460357-8a94-4d71-9ca3-aa4acf32ed8e} - c:\program files\kaspersky lab\kaspersky internet security 7.0\scieplgn.dll
o9 - extra button: الدليل - {46012075-ed62-464b-9554-ad0bec35d1ec} -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي(file missing)
o9 - extra button: (no name) - {46012076-ed62-464b-9554-ad0bec35d1ec} - c:\windows\system32\shdocvw.dll
o9 - extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office11\refiebar.dll
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o16 - dpf: {4f1e5b1a-2a80-42ca-8532-2d05cb959537} (msn photo upload tool) -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
o16 - dpf: {d27cdb6e-ae6d-11cf-96b8-444553540000} (shockwave flash object) -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
o17 - hklm\system\ccs\services\tcpip\..\{3706c425-4a05-49d4-a4ed-10263751d6e9}: Nameserver = 212.72.23.4 212.72.1.186
o20 - appinit_dlls: C:\progra~1\kasper~1\kasper~1.0\adialhk.dll
o23 - service: Adobe lm service - adobe systems - c:\program files\common files\adobe systems shared\service\adobelmsvc.exe
o23 - service: Apache2.2 - apache software foundation - c:\appserv\apache2.2\bin\httpd.exe
o23 - service: Kaspersky internet security 7.0 (avp) - kaspersky lab - c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe
o23 - service: Camelapache - unknown owner - c:\camel\apache\apache.exe (file missing)
o23 - service: Camelmysql - unknown owner - c:\camel\mysql\bin\mysqld-nt.exe (file missing)
o23 - service: Installdriver table manager (idrivert) - macrovision corporation - c:\program files\common files\installshield\driver\11\intel 32\idrivert.exe
o23 - service: Mysql - unknown owner - c:\appserv\mysql\bin\mysqld-nt.exe
o23 - service: Videoacceleratorservice - speedbit ltd. - c:\progra~1\speedb~1\videoacceleratorservice.exe
o23 - service: Viewpoint manager service - viewpoint corporation - c:\program files\viewpoint\common\viewpointservice.exe
--
end of file - 7334 bytes
c:\windows\system32\olhrwef.exe
حاولت احذف هذا الملف لكنه غير ظاهر مخفي ولم استطيع ايجاده ..