• بادئ الموضوع بادئ الموضوع tthhmm1
  • تاريخ البدء تاريخ البدء
  • المشاهدات 986

tthhmm1

زيزوومي نشيط
إنضم
11 أغسطس 2007
المشاركات
158
مستوى التفاعل
9
النقاط
200
غير متصل
السلام عليكم ورحمه الله وبركاته


ياخوان شفت الصوره هذي بموقع يقولي لو انها موجوده نفسها عندك معناه جهازك مخترق هل صحيحه



fekrh-com0dc6fbf0e1.gif
 

السلام عليكم

حمل هذا البرنامج
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

شغل البرنامج ==> واضغط على
Do a system scan and save log
لحظات .. ويظهر لك تقرير داخل المفكرة==> انسخه والصقه بردك القادم
 
توقيع : ناصر الاسلام
تفضل



كود:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:34:49 ص, on 30/06/09
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\Sony\VAIO Wireless Wizard\AutoLaunchWLASU.exe
C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files (x86)\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files (x86)\Atheros\ACU.exe
C:\Program Files (x86)\Internet Explorer\ieuser.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10b.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O1 - Hosts: ::1 localhost
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files (x86)\IEPro\iepro.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files (x86)\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\partner.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SnapFlash Class - {A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E} - C:\Program Files (x86)\Common Files\justDo\Jd2002.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (file missing)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe  startup
O4 - HKLM\..\Run: [VAIORegistration] "C:\Program Files\Sony\First Experience\WelcomeLauncher.exe"
O4 - HKLM\..\Run: [VAIOSurvey] "C:\Program Files (x86)\Sony\VAIO Survey\VAIO Sat Survey.exe"
O4 - HKLM\..\Run: [VWLASU] "C:\Program Files\Sony\VAIO Wireless Wizard\AutoLaunchWLASU.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BDRegion] "C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files (x86)\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [ACU] "C:\Program Files (x86)\Atheros\ACU.exe" -nogui
O4 - HKLM\..\Run: [adsnwm] C:\Windows\system32\adsnwm.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Litebird] "C:\ProgramData\Knob Spam Spam.39l91"
O4 - HKCU\..\Run: [ANTI LITE TITLE DEBUG] "C:\ProgramData\tick knob dart.qazhk"
O4 - HKCU\..\Run: [DesktopIconToy] C:\Program Files (x86)\Desktop Icon Toy\DesktopIconToy.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files (x86)\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files (x86)\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files (x86)\IEPro\iepro.dll
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files (x86)\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files (x86)\IEPro\iepro.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files (x86)\Common Files\justDo\IECatcher.DLL
O9 - Extra 'Tools' menuitem: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files (x86)\Common Files\justDo\IECatcher.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix: 
O16 - DPF: Justin.tv Publisher - http://ar.justin.tv/plugins/justintv_publisher.CAB
O16 - DPF: {3188FB46-456D-4C07-8A11-F5F3BBBA8AF2} (SeeTooControl Class) - http://www.seetoo.com/downloadAddon.php?platform=Win32&browser=ie&ref=justintv&c=c2b1b74e44c330da4&browserVersion=7.0
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) - http://67.198.202.138/talk.cab
O16 - DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} (ReadUid.UserControlMacEntry) - http://67.198.202.138/ReadUid.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files (x86)\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\Windows\system32\acs.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: خدمة تحديث Google (gupdate1c9e95da4ff8e14) (gupdate1c9e95da4ff8e14) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE (file missing)
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\partner.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Intel(R) Sample Collector (SampleCollector) - Intel Corporation - C:\Program Files\Sony\VAIO Care\collsvc.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Media plus\SOHCImp.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Media plus\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Media plus\SOHDs.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

--
End of file - 15578 bytes
 
اخي في الله احذف القيم التاليه من التقرير
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (file missing)

O16 - DPF: Justin.tv Publisher -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


O16 - DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} (ReadUid.UserControlMacEntry) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)




طريقة الحذف
hay1.jpg



hay2.jpg



وابحث عن هذه القيمهC:\Program Files\Sony\VAIO Wireless Wizard\AutoLaunchWLASU.exe في جهازك وتأكد منها ولاكن لا تحذفها الا اذا وجدت بها اصابه من خلال عمل سكان لها بالانتي فايروس

ثم


حمل اداة الكاسبر من الرابط التالي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


بعد التحميل ،، دبل كلك وسيتم استخراج ملف الاداة الى مجلد بسطح المكتب لحظات وتبدأ الاداة بالعمل

تابع الشرح لفحص الجهاز وتنظيفه وارفاق التقرير

طريقة عمل الاداة



91963006.png


49152593.jpg


14168320.jpg


58441796.jpg


22025063.jpg


ثم قم بعمل تقرير للاداة التي اعطيتك اياه اول مره من جديد واعطني التقرير
 
توقيع : ناصر الاسلام
ثم حمل هذه الاداة واتبع الشرح


قبل التحميل يجب تعطيل برامج الحماية لانها تعتبر الاداة تطبيق خطر


يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي



يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي



يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي



ينصح بحفظ الاداة على سطح المكتب





ملف الاداة على سطح المكتب


i19201_20090626201809.png



يتم تشغيها بدبل كلك لمستخدمين الاكسبي
ويتم تشغيلها لمستخدمي الفيستا ووندوز 7 عن طريق نقرة بيمين الماوس واختيار تشغيل كمسؤل


ينصح بشدة قبل استخدام الاداة باغلاق كافة البرامج وتعطيل برامج الحماية وترك الاداة تكمل عملية الفحص مهما طالت


بعد التشغيل تابع الشرح


i19202_20090626201926.png



ثم انتظر حتى تخرج هذه الرسالة وتابع الشرح


i19203_20090626202040.png



i19204_20090626202118.png



وهذا بعض من مراحل الفحص
وتاكد من عدم تحريك الجهاز او مقاطعة الفحص


i19205_20090626202229.png



i19206_20090626202421.png



عند المرحلة التالية قد يعاد تشغيل الجهاز في حال وجود اصابة قوية
وبعد اعادة التشغيل يكمل الفحص بشكل تلقائي


i19207_20090626202708.png



وعند المرحلة التالية يكون عملية انها الفحص وانشاء تقرير الفحص على القرص C كما هو واضح


i19208_20090626202849.png


واسف على الاطاله ولكن جهازك مليئ بالقيم الشبوهه التي يمكن ان تكون مخترق

 
توقيع : ناصر الاسلام
بعد الاكتمال قم بعمل تقرير للاداة الاولى التي اعطيتك اياه وارفقه منفصل عن الاداة الثانيه
 
توقيع : ناصر الاسلام
للاسف الاداة هذي لاتعمل لدي علما ان الويندوز فيستا 64 بت


i19201_20090626201809.png
 
للاسف الاداة هذي لاتعمل لدي علما ان الويندوز فيستا 64 بت


i19201_20090626201809.png


ويتم تشغيلها لمستخدمي الفيستا ووندوز 7 عن طريق نقرة بيمين الماوس واختيار تشغيل كمسؤل
 
توقيع : ناصر الاسلام
للاسف الطريقه مانفعت برضه ماشتغلت الاداة


i20910_Untitled.jpgfdgfdg.jpg
 
عذرااا على المداخلة بس ممكن تشوفلي جهازي مخترق ولا لا !!
اذا ممكن جناح مهيض

كود:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:32:41 ص, on 04/07/09
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\SearchFilterHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [URL]http://google.com/[/URL]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [URL]http://go.microsoft.com/fwlink/?LinkId=69157[/URL]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [URL]http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html[/URL]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [URL]http://go.microsoft.com/fwlink/?LinkId=69157[/URL]
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [URL]http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com[/URL]
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = plimus.com,[URL="http://www.plimus.com,regnow.com,www.regnow.com"]www.plimus.com,regnow.com,www.regnow.com[/URL],
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix: 
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - [URL]http://cdn.scan.onecare.live.com/resource/download/scanner/en-US/wlscctrl2.cab[/URL]
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
--
End of file - 8814 bytes
 
تفضل



كود:
logfile of trend micro hijackthis v2.0.2
scan saved at 12:34:49 ص, on 30/06/09
platform: Windows vista sp1 (winnt 6.00.1905)
msie: Internet explorer v7.00 (7.00.6001.18248)
boot mode: Normal
 
running processes:
C:\program files (x86)\nokia\nokia pc suite 6\pcsuite.exe
c:\program files\sony\vaio wireless wizard\autolaunchwlasu.exe
c:\program files (x86)\sony\isb utility\isbmgr.exe
c:\program files (x86)\common files\real\update_ob\realsched.exe
c:\program files (x86)\cyberlink\shared files\brs.exe
c:\program files (x86)\cyberlink\powerdvd\pdvdserv.exe
c:\program files (x86)\atheros\acu.exe
c:\program files (x86)\internet explorer\ieuser.exe
c:\program files (x86)\pc connectivity solution\transports\nclmsbtsrv.exe
c:\program files (x86)\internet explorer\iexplore.exe
c:\windows\syswow64\macromed\flash\flashutil10b.exe
c:\program files (x86)\internet explorer\iexplore.exe
c:\program files (x86)\trend micro\hijackthis\hijackthis.exe
 
r1 - hkcu\software\microsoft\internet explorer\main,search page = http://go.microsoft.com/fwlink/?linkid=54896
r0 - hkcu\software\microsoft\internet explorer\main,start page = about:blank
r1 - hklm\software\microsoft\internet explorer\main,default_search_url = http://go.microsoft.com/fwlink/?linkid=54896
r1 - hklm\software\microsoft\internet explorer\main,search page = http://go.microsoft.com/fwlink/?linkid=54896
r0 - hklm\software\microsoft\internet explorer\search,searchassistant = 
r0 - hklm\software\microsoft\internet explorer\search,customizesearch = 
r0 - hklm\software\microsoft\internet explorer\main,local page = 
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = local
r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername = 
o1 - hosts: ::1 localhost
o2 - bho: Ie7pro - {00011268-e188-40df-a514-835fcd78b1bf} - c:\program files (x86)\iepro\iepro.dll
o2 - bho: Acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files (x86)\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: Groove gfs browser helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files (x86)\microsoft office\office12\grooveshellextensions.dll
o2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
o2 - bho: Partner bho class - {83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} - c:\programdata\partner\partner.dll
o2 - bho: Windows live sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Snapflash class - {a44cbb0b-c77d-4bf5-87cc-b4ee79ad1b7e} - c:\program files (x86)\common files\justdo\jd2002.dll
o2 - bho: Google toolbar helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files (x86)\google\google toolbar\googletoolbar.dll
o2 - bho: Google toolbar notifier bho - {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files (x86)\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
o2 - bho: Google dictionary compression sdch - {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files (x86)\google\google toolbar\component\fastsearch_219b3e1547538286.dll
o2 - bho: Java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll (file missing)
o3 - toolbar: &google toolbar - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files (x86)\google\google toolbar\googletoolbar.dll
o4 - hklm\..\run: [adobe reader speed launcher] "c:\program files (x86)\adobe\reader 9.0\reader\reader_sl.exe"
o4 - hklm\..\run: [intuit syncmanager] c:\program files (x86)\common files\intuit\sync\intuitsyncmanager.exe  startup
o4 - hklm\..\run: [vaioregistration] "c:\program files\sony\first experience\welcomelauncher.exe"
o4 - hklm\..\run: [vaiosurvey] "c:\program files (x86)\sony\vaio survey\vaio sat survey.exe"
o4 - hklm\..\run: [vwlasu] "c:\program files\sony\vaio wireless wizard\autolaunchwlasu.exe"
o4 - hklm\..\run: [isbmgr.exe] "c:\program files (x86)\sony\isb utility\isbmgr.exe"
o4 - hklm\..\run: [groovemonitor] "c:\program files (x86)\microsoft office\office12\groovemonitor.exe"
o4 - hklm\..\run: [tkbellexe] "c:\program files (x86)\common files\real\update_ob\realsched.exe" -osboot
o4 - hklm\..\run: [bdregion] "c:\program files (x86)\cyberlink\shared files\brs.exe"
o4 - hklm\..\run: [remotecontrol] "c:\program files (x86)\cyberlink\powerdvd\pdvdserv.exe"
o4 - hklm\..\run: [languageshortcut] "c:\program files (x86)\cyberlink\powerdvd\language\language.exe"
o4 - hklm\..\run: [acu] "c:\program files (x86)\atheros\acu.exe" -nogui
o4 - hklm\..\run: [adsnwm] c:\windows\system32\adsnwm.exe
o4 - hkcu\..\run: [sidebar] c:\program files\windows sidebar\sidebar.exe /autorun
o4 - hkcu\..\run: [litebird] "c:\programdata\knob spam spam.39l91"
o4 - hkcu\..\run: [anti lite title debug] "c:\programdata\tick knob dart.qazhk"
o4 - hkcu\..\run: [desktopicontoy] c:\program files (x86)\desktop icon toy\desktopicontoy.exe
o4 - hkcu\..\run: [pc suite tray] "c:\program files (x86)\nokia\nokia pc suite 6\pcsuite.exe" -onlytray
o4 - hkus\s-1-5-19\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /detectmem (user 'local service')
o4 - hkus\s-1-5-19\..\run: [windowswelcomecenter] rundll32.exe oobefldr.dll,showwelcomecenter (user 'local service')
o4 - hkus\s-1-5-20\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /detectmem (user 'network service')
o4 - hkus\s-1-5-18\..\run: [nokia.pcsync] "c:\program files (x86)\nokia\nokia pc suite 6\pcsync2.exe" /nodialog (user 'system')
o4 - hkus\.default\..\run: [nokia.pcsync] "c:\program files (x86)\nokia\nokia pc suite 6\pcsync2.exe" /nodialog (user 'default user')
o8 - extra context menu item: Send image to &bluetooth device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
o8 - extra context menu item: Send page to &bluetooth device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o9 - extra button: Ie7pro grab and drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - c:\program files (x86)\iepro\iepro.dll
o9 - extra 'tools' menuitem: Ie7pro grab and drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - c:\program files (x86)\iepro\iepro.dll
o9 - extra button: Ie7pro preferences - {0026439f-a980-4f18-8c95-4f1cbbf9c1d8} - c:\program files (x86)\iepro\iepro.dll
o9 - extra 'tools' menuitem: Ie7pro preferences - {0026439f-a980-4f18-8c95-4f1cbbf9c1d8} - c:\program files (x86)\iepro\iepro.dll
o9 - extra button: Send to onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~2\micros~2\office12\onbttnie.dll
o9 - extra 'tools' menuitem: S&end to onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~2\micros~2\office12\onbttnie.dll
o9 - extra button: Flash catcher - {90bae0ef-f4bf-4fac-b2ec-2c725c34af12} - c:\program files (x86)\common files\justdo\iecatcher.dll
o9 - extra 'tools' menuitem: Flash catcher - {90bae0ef-f4bf-4fac-b2ec-2c725c34af12} - c:\program files (x86)\common files\justdo\iecatcher.dll
o9 - extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~2\micros~2\office12\refiebar.dll
o9 - extra button: Send to bluetooth - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o9 - extra 'tools' menuitem: Send to &bluetooth device... - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o13 - gopher prefix: 
O16 - dpf: Justin.tv publisher - http://ar.justin.tv/plugins/justintv_publisher.cab
o16 - dpf: {3188fb46-456d-4c07-8a11-f5f3bbba8af2} (seetoocontrol class) - http://www.seetoo.com/downloadaddon.php?platform=win32&browser=ie&ref=justintv&c=c2b1b74e44c330da4&browserversion=7.0
o16 - dpf: {6924091f-cd97-41e1-b1d4-d9079409d413} (imcv1 control) - http://67.198.202.138/talk.cab
o16 - dpf: {b7fdb0c3-4724-46d2-b8db-6fa1dc63f7ca} (readuid.usercontrolmacentry) - http://67.198.202.138/readuid.cab
o16 - dpf: {d27cdb6e-ae6d-11cf-96b8-444553540000} (shockwave flash object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
o18 - protocol: Groovelocalgws - {88fed34c-f0ca-4636-a375-3cb6248b04cd} - c:\program files (x86)\microsoft office\office12\groovesystemservices.dll
o18 - protocol: Intu-help-qb2 - {84d77a00-41b5-4b8b-8adf-86486d72e749} - c:\program files (x86)\intuit\quickbooks 2009\helpasyncpluggableprotocol.dll
o18 - protocol: Qbwc - {fc598a64-626c-4447-85b8-53150405fd57} - mscoree.dll (file missing)
o18 - protocol: Skype4com - {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - c:\progra~2\common~1\skype\skype4~1.dll
o23 - service: Arcsoft connect daemon (acdaemon) - arcsoft inc. - c:\program files (x86)\common files\arcsoft\connection service\bin\acservice.exe
o23 - service: Atheros configuration service (acs) - unknown owner - c:\windows\system32\acs.exe
o23 - service: @%systemroot%\system32\alg.exe,-112 (alg) - unknown owner - c:\windows\system32\alg.exe (file missing)
o23 - service: Bluetooth service (btwdins) - broadcom corporation. - c:\program files\widcomm\bluetooth software\bin\btwdins.exe
o23 - service: @dfsrres.dll,-101 (dfsr) - unknown owner - c:\windows\system32\dfsr.exe (file missing)
o23 - service: Eset http server (ehttpsrv) - eset - c:\program files\eset\eset smart security\ehttpsrv.exe
o23 - service: Eset service (ekrn) - eset - c:\program files\eset\eset smart security\x86\ekrn.exe
o23 - service: Intel® proset/wireless event log (evteng) - intel(r) corporation - c:\program files\intel\wifi\bin\evteng.exe
o23 - service: خدمة تحديث google (gupdate1c9e95da4ff8e14) (gupdate1c9e95da4ff8e14) - google inc. - c:\program files (x86)\google\update\googleupdate.exe
o23 - service: Google updater service (gusvc) - google - c:\program files (x86)\google\common\google updater\googleupdaterservice.exe
o23 - service: Hotspot shield tray service (hsstrayservice) - unknown owner - c:\program files (x86)\hotspot shield\bin\hsstrayservice.exe (file missing)
o23 - service: Iviregmgr - intervideo - c:\program files (x86)\common files\intervideo\regmgr\iviregmgr.exe
o23 - service: @keyiso.dll,-100 (keyiso) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: Mscsptisrv - sony corporation - c:\program files (x86)\common files\sony shared\avlib\mscsptisrv.exe
o23 - service: @comres.dll,-2797 (msdtc) - unknown owner - c:\windows\system32\msdtc.exe (file missing)
o23 - service: @%systemroot%\system32\netlogon.dll,-102 (netlogon) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: Pacsptisvr - sony corporation - c:\program files (x86)\common files\sony shared\avlib\pacsptisvr.exe
o23 - service: Partner service - google inc. - c:\programdata\partner\partner.exe
o23 - service: @%systemroot%\system32\psbase.dll,-300 (protectedstorage) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: Qbcfmonitorservice - intuit - c:\program files (x86)\common files\intuit\quickbooks\qbcfmonitorservice.exe
o23 - service: Intuit quickbooks fcs (qbfcservice) - intuit inc. - c:\program files (x86)\common files\intuit\quickbooks\fcs\intuit.quickbooks.fcs.exe
o23 - service: Intel® proset/wireless registry service (regsrvc) - intel(r) corporation - c:\program files\common files\intel\wirelesscommon\regsrvc.exe
o23 - service: Cyberlink richvideo service(crvs) (richvideo) - unknown owner - c:\program files (x86)\cyberlink\shared files\richvideo.exe
o23 - service: Remote packet capture protocol v.0 (experimental) (rpcapd) - cace technologies - c:\program files (x86)\winpcap\rpcapd.exe
o23 - service: @%systemroot%\system32\locator.exe,-2 (rpclocator) - unknown owner - c:\windows\system32\locator.exe (file missing)
o23 - service: Intel(r) sample collector (samplecollector) - intel corporation - c:\program files\sony\vaio care\collsvc.exe
o23 - service: @%systemroot%\system32\samsrv.dll,-1 (samss) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: Servicelayer - nokia. - c:\program files (x86)\pc connectivity solution\servicelayer.exe
o23 - service: @%systemroot%\system32\slsvc.exe,-101 (slsvc) - unknown owner - c:\windows\system32\slsvc.exe (file missing)
o23 - service: @%systemroot%\system32\snmptrap.exe,-3 (snmptrap) - unknown owner - c:\windows\system32\snmptrap.exe (file missing)
o23 - service: Vaio media plus content importer (sohcimp) - sony corporation - c:\program files (x86)\sony\vaio media plus\sohcimp.exe
o23 - service: Vaio media plus digital media server (sohdms) - sony corporation - c:\program files (x86)\sony\vaio media plus\sohdms.exe
o23 - service: Vaio media plus device searcher (sohds) - sony corporation - c:\program files (x86)\sony\vaio media plus\sohds.exe
o23 - service: @%systemroot%\system32\spoolsv.exe,-1 (spooler) - unknown owner - c:\windows\system32\spoolsv.exe (file missing)
o23 - service: Sony spti service (sptisrv) - sony corporation - c:\program files (x86)\common files\sony shared\avlib\sptisrv.exe
o23 - service: Teamviewer 4 (teamviewer4) - teamviewer gmbh - c:\program files (x86)\teamviewer\version4\teamviewer_service.exe
o23 - service: Cammonitor (ucammonitor) - arcsoft, inc. - c:\program files (x86)\arcsoft\magic-i visual effects 2\ucammonitor.exe
o23 - service: @%systemroot%\system32\ui0detect.exe,-101 (ui0detect) - unknown owner - c:\windows\system32\ui0detect.exe (file missing)
o23 - service: Vaio entertainment tv device arbitration service - sony corporation - c:\program files (x86)\common files\sony shared\vaio entertainment platform\vzhardwareresourcemanager\vzhardwareresourcemanager\vzhardwareresourcemanager.exe
o23 - service: Vaio event service - sony corporation - c:\program files (x86)\sony\vaio event service\vesmgr.exe
o23 - service: Vaio power management - sony corporation - c:\program files\sony\vaio power management\spmservice.exe
o23 - service: Vaio content folder watcher (vcfw) - sony corporation - c:\program files (x86)\common files\sony shared\vaio content folder watcher\vcfw.exe
o23 - service: Vaio content metadata intelligent analyzing manager (vcmialzmgr) - sony corporation - c:\program files\sony\vcm intelligent analyzing manager\vcmialzmgr.exe
o23 - service: Vaio content metadata xml interface (vcmxmlifhelper) - sony corporation - c:\program files\common files\sony shared\vcmxml\vcmxmlifhelper64.exe
o23 - service: Vaio entertainment upnp client adapter (vcsw) - sony corporation - c:\program files (x86)\common files\sony shared\vaio entertainment platform\vcsw\vcsw.exe
o23 - service: @%systemroot%\system32\vds.exe,-100 (vds) - unknown owner - c:\windows\system32\vds.exe (file missing)
o23 - service: @%systemroot%\system32\vssvc.exe,-102 (vss) - unknown owner - c:\windows\system32\vssvc.exe (file missing)
o23 - service: Vaio entertainment database service (vzcdbsvc) - sony corporation - c:\program files (x86)\common files\sony shared\vaio entertainment platform\vzcdb\vzcdbsvc.exe
o23 - service: @%systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiapsrv) - unknown owner - c:\windows\system32\wbem\wmiapsrv.exe (file missing)
o23 - service: @%programfiles%\windows media player\wmpnetwk.exe,-101 (wmpnetworksvc) - unknown owner - c:\program files (x86)\windows media player\wmpnetwk.exe (file missing)
o23 - service: Xaudioservice - unknown owner - c:\windows\system32\drivers\xaudio64.exe (file missing)
 
--
end of file - 15578 bytes


قم بالرفع بدون أكواد او اقتبااس
 
توقيع : أعتز بك
عذرااا على المداخلة بس ممكن تشوفلي جهازي مخترق ولا لا !!
اذا ممكن جناح مهيض

كود:
logfile of trend micro hijackthis v2.0.2
scan saved at 12:32:41 ص, on 04/07/09
platform: Windows vista sp1 (winnt 6.00.1905)
msie: Internet explorer v7.00 (7.00.6001.18248)
boot mode: Normal
running processes:
C:\windows\system32\dwm.exe
c:\windows\system32\taskeng.exe
c:\windows\explorer.exe
c:\program files\bitdefender\bitdefender 2008\bdagent.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\program files\java\jre6\bin\jusched.exe
c:\windows\rthdvcpl.exe
c:\program files\cyberlink\powerdvd\pdvdserv.exe
c:\program files\quicktime\qttask.exe
c:\program files\hp\quickplay\qpservice.exe
c:\program files\hewlett-packard\hp quicktouch\hpkbdapp.exe
c:\windows\system32\rundll32.exe
c:\program files\itunes\ituneshelper.exe
c:\program files\hp\hp software update\hpwuschd2.exe
c:\program files\microsoft office\office12\groovemonitor.exe
c:\program files\windows sidebar\sidebar.exe
c:\windows\ehome\ehtray.exe
c:\program files\common files\ahead\lib\nmbgmonitor.exe
c:\windows\ehome\ehmsas.exe
c:\program files\common files\ahead\lib\nmindexstoresvr.exe
c:\program files\yahoo!\messenger\ymsgr_tray.exe
c:\program files\internet explorer\ieuser.exe
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\macromed\flash\flashutil10b.exe
c:\program files\trend micro\hijackthis\hijackthis.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\searchfilterhost.exe
r0 - hkcu\software\microsoft\internet explorer\main,start page = [url]http://google.com/[/url]
r1 - hklm\software\microsoft\internet explorer\main,default_page_url = [url]http://go.microsoft.com/fwlink/?linkid=69157[/url]
r1 - hklm\software\microsoft\internet explorer\main,default_search_url = [url]http://go.microsoft.com/fwlink/?linkid=54896[/url]
r1 - hklm\software\microsoft\internet explorer\main,search bar = [url]http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html[/url]
r1 - hklm\software\microsoft\internet explorer\main,search page = [url]http://go.microsoft.com/fwlink/?linkid=54896[/url]
r0 - hklm\software\microsoft\internet explorer\main,start page = [url]http://go.microsoft.com/fwlink/?linkid=69157[/url]
r1 - hkcu\software\microsoft\internet explorer\searchurl,(default) = [url]http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com[/url]
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyserver = socks=
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = plimus.com,[url="http://www.plimus.com,regnow.com,www.regnow.com"]www.plimus.com,regnow.com,www.regnow.com[/url],
r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername = 
o1 - hosts: ::1 localhost
o2 - bho: (no name) - {02478d38-c3f9-4efb-9b51-7695eca05670} - (no file)
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: (no name) - {5c255c8a-e604-49b4-9d64-90988571cecb} - (no file)
o2 - bho: Groove gfs browser helper - {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\gra8e1~1.dll
o2 - bho: Windows live sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Google toolbar helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
o2 - bho: Java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
o3 - toolbar: &google - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
o3 - toolbar: Bitdefender toolbar - {381ffde8-2394-4f90-b10d-fc6124a40f8c} - c:\program files\bitdefender\bitdefender 2008\ietoolbar.dll
o4 - hklm\..\run: [bdagent] "c:\program files\bitdefender\bitdefender 2008\bdagent.exe"
o4 - hklm\..\run: [windows defender] %programfiles%\windows defender\msascui.exe -hide
o4 - hklm\..\run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe"  -osboot
o4 - hklm\..\run: [sunjavaupdatesched] "c:\program files\java\jre6\bin\jusched.exe"
o4 - hklm\..\run: [rthdvcpl] rthdvcpl.exe
o4 - hklm\..\run: [remotecontrol] "c:\program files\cyberlink\powerdvd\pdvdserv.exe"
o4 - hklm\..\run: [quicktime task] "c:\program files\quicktime\qttask.exe" -atboottime
o4 - hklm\..\run: [qpservice] "c:\program files\hp\quickplay\qpservice.exe"
o4 - hklm\..\run: [onscreendisplay] c:\program files\hewlett-packard\hp quicktouch\hpkbdapp.exe
o4 - hklm\..\run: [nvmediacenter] rundll32.exe c:\windows\system32\nvmctray.dll,nvtaskbarinit
o4 - hklm\..\run: [nvcpldaemon] rundll32.exe c:\windows\system32\nvcpl.dll,nvstartup
o4 - hklm\..\run: [nerofiltercheck] c:\program files\common files\ahead\lib\nerocheck.exe
o4 - hklm\..\run: [ituneshelper] c:\program files\itunes\ituneshelper.exe
o4 - hklm\..\run: [hp software update] c:\program files\hp\hp software update\hpwuschd2.exe
o4 - hklm\..\run: [groovemonitor] "c:\program files\microsoft office\office12\groovemonitor.exe"
o4 - hklm\..\run: [bitdefender antiphishing helper] "c:\program files\bitdefender\bitdefender 2008\ieshow.exe"
o4 - hklm\..\run: [adobe reader speed launcher] "c:\program files\adobe\reader 8.0\reader\reader_sl.exe"
o4 - hkcu\..\run: [uniblue registrybooster 2009] c:\program files\uniblue\registrybooster\startregistrybooster.exe
o4 - hkcu\..\run: [sidebar] c:\program files\windows sidebar\sidebar.exe /autorun
o4 - hkcu\..\run: [messenger (yahoo!)] "c:\program files\yahoo!\messenger\yahoomessenger.exe" -quiet
o4 - hkcu\..\run: [ehtray.exe] c:\windows\ehome\ehtray.exe
o4 - hkcu\..\run: [bgmonitor_{79662e04-7c6c-4d9f-84c7-88d8a56b10aa}] "c:\program files\common files\ahead\lib\nmbgmonitor.exe"
o8 - extra context menu item: &google search - res://c:\program files\google\googletoolbar1.dll/cmsearch.html
o8 - extra context menu item: Backward &links - res://c:\program files\google\googletoolbar1.dll/cmbacklinks.html
o8 - extra context menu item: Cac&hed snapshot of page - res://c:\program files\google\googletoolbar1.dll/cmcache.html
o8 - extra context menu item: E&xport to microsoft excel - res://c:\progra~1\micros~2\office12\excel.exe/3000
o8 - extra context menu item: Si&milar pages - res://c:\program files\google\googletoolbar1.dll/cmsimilar.html
o8 - extra context menu item: Translate page - res://c:\program files\google\googletoolbar1.dll/cmtrans.html
o9 - extra button: Blog this - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files\windows live\writer\writerbrowserextension.dll
o9 - extra 'tools' menuitem: &blog this in windows live writer - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files\windows live\writer\writerbrowserextension.dll
o9 - extra button: Send to onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~1\micros~2\office12\onbttnie.dll
o9 - extra 'tools' menuitem: S&end to onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - c:\progra~1\micros~2\office12\onbttnie.dll
o9 - extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\mic273~1\office12\refiebar.dll
o13 - gopher prefix: 
O16 - dpf: {3860dd98-0549-4d50-aa72-5d17d200ee10} (windows live onecare safety scanner control) - [url]http://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab[/url]
o18 - protocol: Groovelocalgws - {88fed34c-f0ca-4636-a375-3cb6248b04cd} - c:\progra~1\micros~2\office12\gr99d3~1.dll
o23 - service: Hp health check service - hewlett-packard - c:\program files\hewlett-packard\hp health check\hphc_service.exe
o23 - service: Ipod service (ipodservice) - apple computer, inc. - c:\program files\ipod\bin\ipodservice.exe
o23 - service: Bitdefender desktop update service (livesrv) - bitdefender srl - c:\program files\common files\bitdefender\bitdefender update service\livesrv.exe
o23 - service: Nbservice - nero ag - c:\program files\nero\nero 7\nero backitup\nbservice.exe
o23 - service: Nmindexingservice - nero ag - c:\program files\common files\ahead\lib\nmindexingservice.exe
o23 - service: Nvidia display driver service (nvsvc) - nvidia corporation - c:\windows\system32\nvvsvc.exe
o23 - service: Quickplay background capture service (qbcs) (qpcapsvc) - unknown owner - c:\program files\hp\quickplay\kernel\tv\qpcapsvc.exe
o23 - service: Quickplay task scheduler (qts) (qpsched) - unknown owner - c:\program files\hp\quickplay\kernel\tv\qpsched.exe
o23 - service: Remote packet capture protocol v.0 (experimental) (rpcapd) - cace technologies - c:\program files\winpcap\rpcapd.exe
o23 - service: Bitdefender virus shield (vsserv) - bitdefender s.r.l. - c:\program files\bitdefender\bitdefender 2008\vsserv.exe
o23 - service: Bitdefender communicator (xcomm) - bitdefender - c:\program files\common files\bitdefender\bitdefender communicator\xcommsvr.exe
--
end of file - 8814 bytes


قم بفتح موضوع

ويكون التقرير بدون كوود او اقتبااس

بالتوفيق
 
توقيع : أعتز بك
عودة
أعلى