وهذا التقرير بعد بعد تحميل الاداتين وتنظيف الجهاز ،،،
logfile of trend micro hijackthis v2.0.2
scan saved at 05:41:32 م, on 05/06/2009
platform: Windows xp sp3 (winnt 5.01.2600)
msie: Internet explorer v6.00 sp3 (6.00.2900.5512)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\program files\widcomm\bluetooth software\bin\btwdins.exe
c:\windows\system32\svchost.exe
c:\windows\system32\wltrysvc.exe
c:\windows\system32\bcmwltry.exe
c:\windows\system32\spoolsv.exe
c:\program files\eset\eset nod32 antivirus\ekrn.exe
c:\windows\system32\wgatray.exe
c:\windows\explorer.exe
c:\windows\system32\svchost.exe
c:\windows\system32\wltray.exe
c:\program files\sigmatel\c-major audio\wdm\stsystra.exe
c:\windows\system32\igfxtray.exe
c:\windows\system32\hkcmd.exe
c:\windows\system32\igfxpers.exe
c:\program files\microsoft office\office12\groovemonitor.exe
c:\program files\eset\eset nod32 antivirus\egui.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\ctfmon.exe
c:\program files\messenger\msmsgs.exe
c:\program files\dell\dell webcam manager\dellwmgr.exe
c:\program files\skype\phone\skype.exe
c:\program files\nokia\nokia pc suite 6\pcsync2.exe
c:\program files\nokia\nokia pc suite 6\pcsuite.exe
c:\program files\widcomm\bluetooth software\bttray.exe
c:\program files\techsmith\snagit 8\snagit32.exe
c:\program files\pc connectivity solution\servicelayer.exe
c:\program files\microsoft office\office12\onenotem.exe
c:\program files\pc connectivity solution\transports\nclrssrv.exe
c:\program files\yahoo!\widgets\yahoowidgetengine.exe
c:\program files\techsmith\snagit 8\tschelp.exe
c:\progra~1\widcomm\blueto~1\btstac~1.exe
c:\program files\pc connectivity solution\transports\nclusbsrv.exe
c:\program files\common files\nokia\mpapi\mpapi3s.exe
c:\program files\yahoo!\widgets\yahoowidgetengine.exe
c:\program files\yahoo!\widgets\yahoowidgetengine.exe
c:\program files\yahoo!\widgets\yahoowidgetengine.exe
c:\program files\yahoo!\widgets\yahoowidgetengine.exe
c:\program files\yahoo!\widgets\yahoowidgetengine.exe
c:\program files\skype\plugin manager\skypepm.exe
c:\documents and settings\conan\سطح المكتب\hijackthis.exe
r0 - hkcu\software\microsoft\internet explorer\main,start page = about:blank
r0 - hklm\software\microsoft\internet explorer\main,start page = about:blank
r1 - hkcu\software\microsoft\internet explorer\searchurl,(default) =
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyserver = 127.0.0.1:9666
o2 - bho: Helperobject class - {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 8\snagitbho.dll
o2 - bho: Groove gfs browser helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\gra8e1~1.dll
o2 - bho: Windows live sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Oovoo toolbar - {a057a204-bacc-4d26-8087-36ee87e26986} - c:\progra~1\oovoot~1\oovoot~1.dll
o3 - toolbar: Oovoo toolbar - {a057a204-bacc-4d26-8087-36ee87e26986} - c:\progra~1\oovoot~1\oovoot~1.dll
o3 - toolbar: Snagit - {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 8\snagitieaddin.dll
o4 - hklm\..\run: [broadcom wireless manager ui] c:\windows\system32\wltray.exe
o4 - hklm\..\run: [sigmatelsystrayapp] %programfiles%\sigmatel\c-major audio\wdm\stsystra.exe
o4 - hklm\..\run: [igfxtray] c:\windows\system32\igfxtray.exe
o4 - hklm\..\run: [hotkeyscmds] c:\windows\system32\hkcmd.exe
o4 - hklm\..\run: [persistence] c:\windows\system32\igfxpers.exe
o4 - hklm\..\run: [groovemonitor] "c:\program files\microsoft office\office12\groovemonitor.exe"
o4 - hklm\..\run: [autodetect] c:\windows\system32\supportappxl\autodect.exe
o4 - hklm\..\run: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [msnmsgr] ~"c:\program files\msn messenger\msnmsgr.exe" /background
o4 - hkcu\..\run: [msmsgs] "c:\program files\messenger\msmsgs.exe" /background
o4 - hkcu\..\run: [dell webcam manager] "c:\program files\dell\dell webcam manager\dellwmgr.exe" /s
o4 - hkcu\..\run: [skype] "c:\program files\skype\phone\skype.exe" /nosplash /minimized
o4 - hkcu\..\run: [intelinet] c:\program files\intelinet\intelinet.exe
o4 - hkcu\..\run: [nokia.pcsync] "c:\program files\nokia\nokia pc suite 6\pcsync2.exe" /nodialog
o4 - hkcu\..\run: [pc suite tray] "c:\program files\nokia\nokia pc suite 6\pcsuite.exe" -onlytray
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'local service')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'network service')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o4 - startup: Onenote 2007 screen clipper and launcher.lnk = c:\program files\microsoft office\office12\onenotem.exe
o4 - startup: Yahoo! Widget engine.lnk = c:\program files\yahoo!\widgets\yahoowidgetengine.exe
o4 - global startup: Bluetooth.lnk = ?
O4 - global startup: Snagit 8.lnk = c:\program files\techsmith\snagit 8\snagit32.exe
o8 - extra context menu item: E&xport to microsoft excel - res://c:\progra~1\micros~2\office12\excel.exe/3000
o8 - extra context menu item: Send to &bluetooth device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
o9 - extra button: إرسال إلى onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~1\micros~2\office12\onbttnie.dll
o9 - extra 'tools' menuitem: إر&سال إلى onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~1\micros~2\office12\onbttnie.dll
o9 - extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office12\refiebar.dll
o9 - extra button: @btrez.dll,-4015 - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o9 - extra 'tools' menuitem: @btrez.dll,-12650 - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o9 - extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra 'tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o16 - dpf: {05ca9fb0-3e3e-4b36-bf41-0e3a5caa8cd8} (office genuine advantage validation tool) -
o16 - dpf: {17492023-c23a-453e-a040-c7c580bbf700} (windows genuine advantage validation tool) -
o16 - dpf: {d27cdb6e-ae6d-11cf-96b8-444553540000} (shockwave flash object) -
o18 - protocol: Groovelocalgws - {88fed34c-f0ca-4636-a375-3cb6248b04cd} - c:\progra~1\micros~2\office12\gr99d3~1.dll
o18 - protocol: Skype4com - {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - c:\progra~1\common~1\skype\skype4~1.dll
o23 - service: Bluetooth service (btwdins) - broadcom corporation. - c:\program files\widcomm\bluetooth software\bin\btwdins.exe
o23 - service: Eset http server (ehttpsrv) - unknown owner - c:\program files\eset\eset nod32 antivirus\ehttpsrv.exe
o23 - service: Eset service (ekrn) - eset - c:\program files\eset\eset nod32 antivirus\ekrn.exe
o23 - service: Hotspot shield tray service (hsstrayservice) - unknown owner - c:\program files\hotspot shield\bin\hsstrayservice.exe (file missing)
o23 - service: Servicelayer - nokia. - c:\program files\pc connectivity solution\servicelayer.exe
o23 - service: Dell wireless wlan tray service (wltrysvc) - unknown owner - c:\windows\system32\wltrysvc.exe
--
end of file - 8317 bytes