قم بمتابعة الفيديو أدناه لمعرفة كيفية تثبيت موقعنا كتطبيق ويب على الشاشة الرئيسية.
ملاحظة: قد لا تكون هذه الميزة متاحة في بعض المتصفحات.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:34:49 ص, on 30/06/09
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\Sony\VAIO Wireless Wizard\AutoLaunchWLASU.exe
C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files (x86)\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files (x86)\Atheros\ACU.exe
C:\Program Files (x86)\Internet Explorer\ieuser.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10b.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files (x86)\IEPro\iepro.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files (x86)\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\partner.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SnapFlash Class - {A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E} - C:\Program Files (x86)\Common Files\justDo\Jd2002.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (file missing)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [VAIORegistration] "C:\Program Files\Sony\First Experience\WelcomeLauncher.exe"
O4 - HKLM\..\Run: [VAIOSurvey] "C:\Program Files (x86)\Sony\VAIO Survey\VAIO Sat Survey.exe"
O4 - HKLM\..\Run: [VWLASU] "C:\Program Files\Sony\VAIO Wireless Wizard\AutoLaunchWLASU.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BDRegion] "C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files (x86)\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [ACU] "C:\Program Files (x86)\Atheros\ACU.exe" -nogui
O4 - HKLM\..\Run: [adsnwm] C:\Windows\system32\adsnwm.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Litebird] "C:\ProgramData\Knob Spam Spam.39l91"
O4 - HKCU\..\Run: [ANTI LITE TITLE DEBUG] "C:\ProgramData\tick knob dart.qazhk"
O4 - HKCU\..\Run: [DesktopIconToy] C:\Program Files (x86)\Desktop Icon Toy\DesktopIconToy.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files (x86)\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files (x86)\IEPro\iepro.dll
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files (x86)\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files (x86)\IEPro\iepro.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files (x86)\Common Files\justDo\IECatcher.DLL
O9 - Extra 'Tools' menuitem: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files (x86)\Common Files\justDo\IECatcher.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: Justin.tv Publisher - http://ar.justin.tv/plugins/justintv_publisher.CAB
O16 - DPF: {3188FB46-456D-4C07-8A11-F5F3BBBA8AF2} (SeeTooControl Class) - http://www.seetoo.com/downloadAddon.php?platform=Win32&browser=ie&ref=justintv&c=c2b1b74e44c330da4&browserVersion=7.0
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) - http://67.198.202.138/talk.cab
O16 - DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} (ReadUid.UserControlMacEntry) - http://67.198.202.138/ReadUid.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files (x86)\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\Windows\system32\acs.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: خدمة تحديث Google (gupdate1c9e95da4ff8e14) (gupdate1c9e95da4ff8e14) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE (file missing)
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\partner.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Intel(R) Sample Collector (SampleCollector) - Intel Corporation - C:\Program Files\Sony\VAIO Care\collsvc.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Media plus\SOHCImp.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Media plus\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Media plus\SOHDs.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)
--
End of file - 15578 bytes
للاسف الاداة هذي لاتعمل لدي علما ان الويندوز فيستا 64 بت
![]()
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:32:41 ص, on 04/07/09
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\SearchFilterHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [URL]http://google.com/[/URL]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [URL]http://go.microsoft.com/fwlink/?LinkId=69157[/URL]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [URL]http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html[/URL]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [URL]http://go.microsoft.com/fwlink/?LinkId=69157[/URL]
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [URL]http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com[/URL]
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = plimus.com,[URL="http://www.plimus.com,regnow.com,www.regnow.com"]www.plimus.com,regnow.com,www.regnow.com[/URL],
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - [URL]http://cdn.scan.onecare.live.com/resource/download/scanner/en-US/wlscctrl2.cab[/URL]
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
--
End of file - 8814 bytes
تفضل
كود:logfile of trend micro hijackthis v2.0.2 scan saved at 12:34:49 ص, on 30/06/09 platform: Windows vista sp1 (winnt 6.00.1905) msie: Internet explorer v7.00 (7.00.6001.18248) boot mode: Normal running processes: C:\program files (x86)\nokia\nokia pc suite 6\pcsuite.exe c:\program files\sony\vaio wireless wizard\autolaunchwlasu.exe c:\program files (x86)\sony\isb utility\isbmgr.exe c:\program files (x86)\common files\real\update_ob\realsched.exe c:\program files (x86)\cyberlink\shared files\brs.exe c:\program files (x86)\cyberlink\powerdvd\pdvdserv.exe c:\program files (x86)\atheros\acu.exe c:\program files (x86)\internet explorer\ieuser.exe c:\program files (x86)\pc connectivity solution\transports\nclmsbtsrv.exe c:\program files (x86)\internet explorer\iexplore.exe c:\windows\syswow64\macromed\flash\flashutil10b.exe c:\program files (x86)\internet explorer\iexplore.exe c:\program files (x86)\trend micro\hijackthis\hijackthis.exe r1 - hkcu\software\microsoft\internet explorer\main,search page = http://go.microsoft.com/fwlink/?linkid=54896 r0 - hkcu\software\microsoft\internet explorer\main,start page = about:blank r1 - hklm\software\microsoft\internet explorer\main,default_search_url = http://go.microsoft.com/fwlink/?linkid=54896 r1 - hklm\software\microsoft\internet explorer\main,search page = http://go.microsoft.com/fwlink/?linkid=54896 r0 - hklm\software\microsoft\internet explorer\search,searchassistant = r0 - hklm\software\microsoft\internet explorer\search,customizesearch = r0 - hklm\software\microsoft\internet explorer\main,local page = r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = local r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername = o1 - hosts: ::1 localhost o2 - bho: Ie7pro - {00011268-e188-40df-a514-835fcd78b1bf} - c:\program files (x86)\iepro\iepro.dll o2 - bho: Acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files (x86)\real\realplayer\rpbrowserrecordplugin.dll o2 - bho: Groove gfs browser helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files (x86)\microsoft office\office12\grooveshellextensions.dll o2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file) o2 - bho: Partner bho class - {83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} - c:\programdata\partner\partner.dll o2 - bho: Windows live sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll o2 - bho: Snapflash class - {a44cbb0b-c77d-4bf5-87cc-b4ee79ad1b7e} - c:\program files (x86)\common files\justdo\jd2002.dll o2 - bho: Google toolbar helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files (x86)\google\google toolbar\googletoolbar.dll o2 - bho: Google toolbar notifier bho - {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files (x86)\google\googletoolbarnotifier\5.1.1309.3572\swg.dll o2 - bho: Google dictionary compression sdch - {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files (x86)\google\google toolbar\component\fastsearch_219b3e1547538286.dll o2 - bho: Java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll (file missing) o3 - toolbar: &google toolbar - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files (x86)\google\google toolbar\googletoolbar.dll o4 - hklm\..\run: [adobe reader speed launcher] "c:\program files (x86)\adobe\reader 9.0\reader\reader_sl.exe" o4 - hklm\..\run: [intuit syncmanager] c:\program files (x86)\common files\intuit\sync\intuitsyncmanager.exe startup o4 - hklm\..\run: [vaioregistration] "c:\program files\sony\first experience\welcomelauncher.exe" o4 - hklm\..\run: [vaiosurvey] "c:\program files (x86)\sony\vaio survey\vaio sat survey.exe" o4 - hklm\..\run: [vwlasu] "c:\program files\sony\vaio wireless wizard\autolaunchwlasu.exe" o4 - hklm\..\run: [isbmgr.exe] "c:\program files (x86)\sony\isb utility\isbmgr.exe" o4 - hklm\..\run: [groovemonitor] "c:\program files (x86)\microsoft office\office12\groovemonitor.exe" o4 - hklm\..\run: [tkbellexe] "c:\program files (x86)\common files\real\update_ob\realsched.exe" -osboot o4 - hklm\..\run: [bdregion] "c:\program files (x86)\cyberlink\shared files\brs.exe" o4 - hklm\..\run: [remotecontrol] "c:\program files (x86)\cyberlink\powerdvd\pdvdserv.exe" o4 - hklm\..\run: [languageshortcut] "c:\program files (x86)\cyberlink\powerdvd\language\language.exe" o4 - hklm\..\run: [acu] "c:\program files (x86)\atheros\acu.exe" -nogui o4 - hklm\..\run: [adsnwm] c:\windows\system32\adsnwm.exe o4 - hkcu\..\run: [sidebar] c:\program files\windows sidebar\sidebar.exe /autorun o4 - hkcu\..\run: [litebird] "c:\programdata\knob spam spam.39l91" o4 - hkcu\..\run: [anti lite title debug] "c:\programdata\tick knob dart.qazhk" o4 - hkcu\..\run: [desktopicontoy] c:\program files (x86)\desktop icon toy\desktopicontoy.exe o4 - hkcu\..\run: [pc suite tray] "c:\program files (x86)\nokia\nokia pc suite 6\pcsuite.exe" -onlytray o4 - hkus\s-1-5-19\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /detectmem (user 'local service') o4 - hkus\s-1-5-19\..\run: [windowswelcomecenter] rundll32.exe oobefldr.dll,showwelcomecenter (user 'local service') o4 - hkus\s-1-5-20\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /detectmem (user 'network service') o4 - hkus\s-1-5-18\..\run: [nokia.pcsync] "c:\program files (x86)\nokia\nokia pc suite 6\pcsync2.exe" /nodialog (user 'system') o4 - hkus\.default\..\run: [nokia.pcsync] "c:\program files (x86)\nokia\nokia pc suite 6\pcsync2.exe" /nodialog (user 'default user') o8 - extra context menu item: Send image to &bluetooth device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm o8 - extra context menu item: Send page to &bluetooth device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm o9 - extra button: Ie7pro grab and drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - c:\program files (x86)\iepro\iepro.dll o9 - extra 'tools' menuitem: Ie7pro grab and drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - c:\program files (x86)\iepro\iepro.dll o9 - extra button: Ie7pro preferences - {0026439f-a980-4f18-8c95-4f1cbbf9c1d8} - c:\program files (x86)\iepro\iepro.dll o9 - extra 'tools' menuitem: Ie7pro preferences - {0026439f-a980-4f18-8c95-4f1cbbf9c1d8} - c:\program files (x86)\iepro\iepro.dll o9 - extra button: Send to onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~2\micros~2\office12\onbttnie.dll o9 - extra 'tools' menuitem: S&end to onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~2\micros~2\office12\onbttnie.dll o9 - extra button: Flash catcher - {90bae0ef-f4bf-4fac-b2ec-2c725c34af12} - c:\program files (x86)\common files\justdo\iecatcher.dll o9 - extra 'tools' menuitem: Flash catcher - {90bae0ef-f4bf-4fac-b2ec-2c725c34af12} - c:\program files (x86)\common files\justdo\iecatcher.dll o9 - extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~2\micros~2\office12\refiebar.dll o9 - extra button: Send to bluetooth - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm o9 - extra 'tools' menuitem: Send to &bluetooth device... - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm o13 - gopher prefix: O16 - dpf: Justin.tv publisher - http://ar.justin.tv/plugins/justintv_publisher.cab o16 - dpf: {3188fb46-456d-4c07-8a11-f5f3bbba8af2} (seetoocontrol class) - http://www.seetoo.com/downloadaddon.php?platform=win32&browser=ie&ref=justintv&c=c2b1b74e44c330da4&browserversion=7.0 o16 - dpf: {6924091f-cd97-41e1-b1d4-d9079409d413} (imcv1 control) - http://67.198.202.138/talk.cab o16 - dpf: {b7fdb0c3-4724-46d2-b8db-6fa1dc63f7ca} (readuid.usercontrolmacentry) - http://67.198.202.138/readuid.cab o16 - dpf: {d27cdb6e-ae6d-11cf-96b8-444553540000} (shockwave flash object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab o18 - protocol: Groovelocalgws - {88fed34c-f0ca-4636-a375-3cb6248b04cd} - c:\program files (x86)\microsoft office\office12\groovesystemservices.dll o18 - protocol: Intu-help-qb2 - {84d77a00-41b5-4b8b-8adf-86486d72e749} - c:\program files (x86)\intuit\quickbooks 2009\helpasyncpluggableprotocol.dll o18 - protocol: Qbwc - {fc598a64-626c-4447-85b8-53150405fd57} - mscoree.dll (file missing) o18 - protocol: Skype4com - {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - c:\progra~2\common~1\skype\skype4~1.dll o23 - service: Arcsoft connect daemon (acdaemon) - arcsoft inc. - c:\program files (x86)\common files\arcsoft\connection service\bin\acservice.exe o23 - service: Atheros configuration service (acs) - unknown owner - c:\windows\system32\acs.exe o23 - service: @%systemroot%\system32\alg.exe,-112 (alg) - unknown owner - c:\windows\system32\alg.exe (file missing) o23 - service: Bluetooth service (btwdins) - broadcom corporation. - c:\program files\widcomm\bluetooth software\bin\btwdins.exe o23 - service: @dfsrres.dll,-101 (dfsr) - unknown owner - c:\windows\system32\dfsr.exe (file missing) o23 - service: Eset http server (ehttpsrv) - eset - c:\program files\eset\eset smart security\ehttpsrv.exe o23 - service: Eset service (ekrn) - eset - c:\program files\eset\eset smart security\x86\ekrn.exe o23 - service: Intel® proset/wireless event log (evteng) - intel(r) corporation - c:\program files\intel\wifi\bin\evteng.exe o23 - service: خدمة تحديث google (gupdate1c9e95da4ff8e14) (gupdate1c9e95da4ff8e14) - google inc. - c:\program files (x86)\google\update\googleupdate.exe o23 - service: Google updater service (gusvc) - google - c:\program files (x86)\google\common\google updater\googleupdaterservice.exe o23 - service: Hotspot shield tray service (hsstrayservice) - unknown owner - c:\program files (x86)\hotspot shield\bin\hsstrayservice.exe (file missing) o23 - service: Iviregmgr - intervideo - c:\program files (x86)\common files\intervideo\regmgr\iviregmgr.exe o23 - service: @keyiso.dll,-100 (keyiso) - unknown owner - c:\windows\system32\lsass.exe (file missing) o23 - service: Mscsptisrv - sony corporation - c:\program files (x86)\common files\sony shared\avlib\mscsptisrv.exe o23 - service: @comres.dll,-2797 (msdtc) - unknown owner - c:\windows\system32\msdtc.exe (file missing) o23 - service: @%systemroot%\system32\netlogon.dll,-102 (netlogon) - unknown owner - c:\windows\system32\lsass.exe (file missing) o23 - service: Pacsptisvr - sony corporation - c:\program files (x86)\common files\sony shared\avlib\pacsptisvr.exe o23 - service: Partner service - google inc. - c:\programdata\partner\partner.exe o23 - service: @%systemroot%\system32\psbase.dll,-300 (protectedstorage) - unknown owner - c:\windows\system32\lsass.exe (file missing) o23 - service: Qbcfmonitorservice - intuit - c:\program files (x86)\common files\intuit\quickbooks\qbcfmonitorservice.exe o23 - service: Intuit quickbooks fcs (qbfcservice) - intuit inc. - c:\program files (x86)\common files\intuit\quickbooks\fcs\intuit.quickbooks.fcs.exe o23 - service: Intel® proset/wireless registry service (regsrvc) - intel(r) corporation - c:\program files\common files\intel\wirelesscommon\regsrvc.exe o23 - service: Cyberlink richvideo service(crvs) (richvideo) - unknown owner - c:\program files (x86)\cyberlink\shared files\richvideo.exe o23 - service: Remote packet capture protocol v.0 (experimental) (rpcapd) - cace technologies - c:\program files (x86)\winpcap\rpcapd.exe o23 - service: @%systemroot%\system32\locator.exe,-2 (rpclocator) - unknown owner - c:\windows\system32\locator.exe (file missing) o23 - service: Intel(r) sample collector (samplecollector) - intel corporation - c:\program files\sony\vaio care\collsvc.exe o23 - service: @%systemroot%\system32\samsrv.dll,-1 (samss) - unknown owner - c:\windows\system32\lsass.exe (file missing) o23 - service: Servicelayer - nokia. - c:\program files (x86)\pc connectivity solution\servicelayer.exe o23 - service: @%systemroot%\system32\slsvc.exe,-101 (slsvc) - unknown owner - c:\windows\system32\slsvc.exe (file missing) o23 - service: @%systemroot%\system32\snmptrap.exe,-3 (snmptrap) - unknown owner - c:\windows\system32\snmptrap.exe (file missing) o23 - service: Vaio media plus content importer (sohcimp) - sony corporation - c:\program files (x86)\sony\vaio media plus\sohcimp.exe o23 - service: Vaio media plus digital media server (sohdms) - sony corporation - c:\program files (x86)\sony\vaio media plus\sohdms.exe o23 - service: Vaio media plus device searcher (sohds) - sony corporation - c:\program files (x86)\sony\vaio media plus\sohds.exe o23 - service: @%systemroot%\system32\spoolsv.exe,-1 (spooler) - unknown owner - c:\windows\system32\spoolsv.exe (file missing) o23 - service: Sony spti service (sptisrv) - sony corporation - c:\program files (x86)\common files\sony shared\avlib\sptisrv.exe o23 - service: Teamviewer 4 (teamviewer4) - teamviewer gmbh - c:\program files (x86)\teamviewer\version4\teamviewer_service.exe o23 - service: Cammonitor (ucammonitor) - arcsoft, inc. - c:\program files (x86)\arcsoft\magic-i visual effects 2\ucammonitor.exe o23 - service: @%systemroot%\system32\ui0detect.exe,-101 (ui0detect) - unknown owner - c:\windows\system32\ui0detect.exe (file missing) o23 - service: Vaio entertainment tv device arbitration service - sony corporation - c:\program files (x86)\common files\sony shared\vaio entertainment platform\vzhardwareresourcemanager\vzhardwareresourcemanager\vzhardwareresourcemanager.exe o23 - service: Vaio event service - sony corporation - c:\program files (x86)\sony\vaio event service\vesmgr.exe o23 - service: Vaio power management - sony corporation - c:\program files\sony\vaio power management\spmservice.exe o23 - service: Vaio content folder watcher (vcfw) - sony corporation - c:\program files (x86)\common files\sony shared\vaio content folder watcher\vcfw.exe o23 - service: Vaio content metadata intelligent analyzing manager (vcmialzmgr) - sony corporation - c:\program files\sony\vcm intelligent analyzing manager\vcmialzmgr.exe o23 - service: Vaio content metadata xml interface (vcmxmlifhelper) - sony corporation - c:\program files\common files\sony shared\vcmxml\vcmxmlifhelper64.exe o23 - service: Vaio entertainment upnp client adapter (vcsw) - sony corporation - c:\program files (x86)\common files\sony shared\vaio entertainment platform\vcsw\vcsw.exe o23 - service: @%systemroot%\system32\vds.exe,-100 (vds) - unknown owner - c:\windows\system32\vds.exe (file missing) o23 - service: @%systemroot%\system32\vssvc.exe,-102 (vss) - unknown owner - c:\windows\system32\vssvc.exe (file missing) o23 - service: Vaio entertainment database service (vzcdbsvc) - sony corporation - c:\program files (x86)\common files\sony shared\vaio entertainment platform\vzcdb\vzcdbsvc.exe o23 - service: @%systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiapsrv) - unknown owner - c:\windows\system32\wbem\wmiapsrv.exe (file missing) o23 - service: @%programfiles%\windows media player\wmpnetwk.exe,-101 (wmpnetworksvc) - unknown owner - c:\program files (x86)\windows media player\wmpnetwk.exe (file missing) o23 - service: Xaudioservice - unknown owner - c:\windows\system32\drivers\xaudio64.exe (file missing) -- end of file - 15578 bytes
عذرااا على المداخلة بس ممكن تشوفلي جهازي مخترق ولا لا !!
اذا ممكن جناح مهيض
كود:logfile of trend micro hijackthis v2.0.2 scan saved at 12:32:41 ص, on 04/07/09 platform: Windows vista sp1 (winnt 6.00.1905) msie: Internet explorer v7.00 (7.00.6001.18248) boot mode: Normal running processes: C:\windows\system32\dwm.exe c:\windows\system32\taskeng.exe c:\windows\explorer.exe c:\program files\bitdefender\bitdefender 2008\bdagent.exe c:\program files\common files\real\update_ob\realsched.exe c:\program files\java\jre6\bin\jusched.exe c:\windows\rthdvcpl.exe c:\program files\cyberlink\powerdvd\pdvdserv.exe c:\program files\quicktime\qttask.exe c:\program files\hp\quickplay\qpservice.exe c:\program files\hewlett-packard\hp quicktouch\hpkbdapp.exe c:\windows\system32\rundll32.exe c:\program files\itunes\ituneshelper.exe c:\program files\hp\hp software update\hpwuschd2.exe c:\program files\microsoft office\office12\groovemonitor.exe c:\program files\windows sidebar\sidebar.exe c:\windows\ehome\ehtray.exe c:\program files\common files\ahead\lib\nmbgmonitor.exe c:\windows\ehome\ehmsas.exe c:\program files\common files\ahead\lib\nmindexstoresvr.exe c:\program files\yahoo!\messenger\ymsgr_tray.exe c:\program files\internet explorer\ieuser.exe c:\program files\internet explorer\iexplore.exe c:\windows\system32\macromed\flash\flashutil10b.exe c:\program files\trend micro\hijackthis\hijackthis.exe c:\windows\system32\dllhost.exe c:\windows\system32\searchfilterhost.exe r0 - hkcu\software\microsoft\internet explorer\main,start page = [url]http://google.com/[/url] r1 - hklm\software\microsoft\internet explorer\main,default_page_url = [url]http://go.microsoft.com/fwlink/?linkid=69157[/url] r1 - hklm\software\microsoft\internet explorer\main,default_search_url = [url]http://go.microsoft.com/fwlink/?linkid=54896[/url] r1 - hklm\software\microsoft\internet explorer\main,search bar = [url]http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html[/url] r1 - hklm\software\microsoft\internet explorer\main,search page = [url]http://go.microsoft.com/fwlink/?linkid=54896[/url] r0 - hklm\software\microsoft\internet explorer\main,start page = [url]http://go.microsoft.com/fwlink/?linkid=69157[/url] r1 - hkcu\software\microsoft\internet explorer\searchurl,(default) = [url]http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com[/url] r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyserver = socks= r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = plimus.com,[url="http://www.plimus.com,regnow.com,www.regnow.com"]www.plimus.com,regnow.com,www.regnow.com[/url], r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername = o1 - hosts: ::1 localhost o2 - bho: (no name) - {02478d38-c3f9-4efb-9b51-7695eca05670} - (no file) o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll o2 - bho: (no name) - {5c255c8a-e604-49b4-9d64-90988571cecb} - (no file) o2 - bho: Groove gfs browser helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\gra8e1~1.dll o2 - bho: Windows live sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll o2 - bho: Google toolbar helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll o2 - bho: Java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll o3 - toolbar: &google - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll o3 - toolbar: Bitdefender toolbar - {381ffde8-2394-4f90-b10d-fc6124a40f8c} - c:\program files\bitdefender\bitdefender 2008\ietoolbar.dll o4 - hklm\..\run: [bdagent] "c:\program files\bitdefender\bitdefender 2008\bdagent.exe" o4 - hklm\..\run: [windows defender] %programfiles%\windows defender\msascui.exe -hide o4 - hklm\..\run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot o4 - hklm\..\run: [sunjavaupdatesched] "c:\program files\java\jre6\bin\jusched.exe" o4 - hklm\..\run: [rthdvcpl] rthdvcpl.exe o4 - hklm\..\run: [remotecontrol] "c:\program files\cyberlink\powerdvd\pdvdserv.exe" o4 - hklm\..\run: [quicktime task] "c:\program files\quicktime\qttask.exe" -atboottime o4 - hklm\..\run: [qpservice] "c:\program files\hp\quickplay\qpservice.exe" o4 - hklm\..\run: [onscreendisplay] c:\program files\hewlett-packard\hp quicktouch\hpkbdapp.exe o4 - hklm\..\run: [nvmediacenter] rundll32.exe c:\windows\system32\nvmctray.dll,nvtaskbarinit o4 - hklm\..\run: [nvcpldaemon] rundll32.exe c:\windows\system32\nvcpl.dll,nvstartup o4 - hklm\..\run: [nerofiltercheck] c:\program files\common files\ahead\lib\nerocheck.exe o4 - hklm\..\run: [ituneshelper] c:\program files\itunes\ituneshelper.exe o4 - hklm\..\run: [hp software update] c:\program files\hp\hp software update\hpwuschd2.exe o4 - hklm\..\run: [groovemonitor] "c:\program files\microsoft office\office12\groovemonitor.exe" o4 - hklm\..\run: [bitdefender antiphishing helper] "c:\program files\bitdefender\bitdefender 2008\ieshow.exe" o4 - hklm\..\run: [adobe reader speed launcher] "c:\program files\adobe\reader 8.0\reader\reader_sl.exe" o4 - hkcu\..\run: [uniblue registrybooster 2009] c:\program files\uniblue\registrybooster\startregistrybooster.exe o4 - hkcu\..\run: [sidebar] c:\program files\windows sidebar\sidebar.exe /autorun o4 - hkcu\..\run: [messenger (yahoo!)] "c:\program files\yahoo!\messenger\yahoomessenger.exe" -quiet o4 - hkcu\..\run: [ehtray.exe] c:\windows\ehome\ehtray.exe o4 - hkcu\..\run: [bgmonitor_{79662e04-7c6c-4d9f-84c7-88d8a56b10aa}] "c:\program files\common files\ahead\lib\nmbgmonitor.exe" o8 - extra context menu item: &google search - res://c:\program files\google\googletoolbar1.dll/cmsearch.html o8 - extra context menu item: Backward &links - res://c:\program files\google\googletoolbar1.dll/cmbacklinks.html o8 - extra context menu item: Cac&hed snapshot of page - res://c:\program files\google\googletoolbar1.dll/cmcache.html o8 - extra context menu item: E&xport to microsoft excel - res://c:\progra~1\micros~2\office12\excel.exe/3000 o8 - extra context menu item: Si&milar pages - res://c:\program files\google\googletoolbar1.dll/cmsimilar.html o8 - extra context menu item: Translate page - res://c:\program files\google\googletoolbar1.dll/cmtrans.html o9 - extra button: Blog this - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files\windows live\writer\writerbrowserextension.dll o9 - extra 'tools' menuitem: &blog this in windows live writer - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files\windows live\writer\writerbrowserextension.dll o9 - extra button: Send to onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~1\micros~2\office12\onbttnie.dll o9 - extra 'tools' menuitem: S&end to onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~1\micros~2\office12\onbttnie.dll o9 - extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\mic273~1\office12\refiebar.dll o13 - gopher prefix: O16 - dpf: {3860dd98-0549-4d50-aa72-5d17d200ee10} (windows live onecare safety scanner control) - [url]http://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab[/url] o18 - protocol: Groovelocalgws - {88fed34c-f0ca-4636-a375-3cb6248b04cd} - c:\progra~1\micros~2\office12\gr99d3~1.dll o23 - service: Hp health check service - hewlett-packard - c:\program files\hewlett-packard\hp health check\hphc_service.exe o23 - service: Ipod service (ipodservice) - apple computer, inc. - c:\program files\ipod\bin\ipodservice.exe o23 - service: Bitdefender desktop update service (livesrv) - bitdefender srl - c:\program files\common files\bitdefender\bitdefender update service\livesrv.exe o23 - service: Nbservice - nero ag - c:\program files\nero\nero 7\nero backitup\nbservice.exe o23 - service: Nmindexingservice - nero ag - c:\program files\common files\ahead\lib\nmindexingservice.exe o23 - service: Nvidia display driver service (nvsvc) - nvidia corporation - c:\windows\system32\nvvsvc.exe o23 - service: Quickplay background capture service (qbcs) (qpcapsvc) - unknown owner - c:\program files\hp\quickplay\kernel\tv\qpcapsvc.exe o23 - service: Quickplay task scheduler (qts) (qpsched) - unknown owner - c:\program files\hp\quickplay\kernel\tv\qpsched.exe o23 - service: Remote packet capture protocol v.0 (experimental) (rpcapd) - cace technologies - c:\program files\winpcap\rpcapd.exe o23 - service: Bitdefender virus shield (vsserv) - bitdefender s.r.l. - c:\program files\bitdefender\bitdefender 2008\vsserv.exe o23 - service: Bitdefender communicator (xcomm) - bitdefender - c:\program files\common files\bitdefender\bitdefender communicator\xcommsvr.exe -- end of file - 8814 bytes