التقرير الأول
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 05:12:32 ص, on 14/07/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\AFAQ Wireless\AFAQ Wireless.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Documents and Settings\Almaher\Desktop\تقارير زيزووم\RunScanner.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: مساعد رابط Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Azkary] C:\Program Files\Azkary\Azkary
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [UVS12 Preload] C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [Profissonal Viewer] 0
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Project1] C:\Program Files\Microsoft Visual Studio\VB98/Project1
O4 - HKCU\..\Run: [مجلدجديد.exe] C:\WINDOWS\system32\winlog0n.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Athkar] C:\Program Files\Athkar\Athkar\Athkar.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: AFAQ Wireless.lnk = C:\Program Files\AFAQ Wireless\AFAQ Wireless.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O8 - Extra context menu item: أضافة إلى مانع الأعلانات - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com.sa
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCBC4EED-8D60-44C9-8B33-37D88FE9BA6C}: NameServer = 84.235.7.58 84.235.6.58
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O24 - Desktop Component 1: يا له من دين | نتاج المشرف العام - الصفحة الرئيسية -
--
End of file - 8573 bytes
التقرير الثاني
BitDefender QuickScan Beta v0.9.4.7
-----------------------------------
Scan date: Tue Jul 14 05:19:39 2009
Machine ID: D486E753
No infection found.
--------------------
Processes
---------
<unsigned> AFAQ Wireless.exe 2904 C:\Program Files\AFAQ Wireless\AFAQ Wireless.exe
<unsigned> RichVideo Module 1196 C:\Program Files\CyberLink\Shared Files\RichVideo.exe
<unsigned> Hewlett-Packard Product Assistant 2156 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
<unsigned> CrypKey NT Service 1004 C:\WINDOWS\system32\crypserv.exe
<unsigned> PML Driver 1128 C:\WINDOWS\system32\HPZipm12.exe
<unsigned> FinePrint pdfFactory 2324 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
<verified> Runscanner freeware startup analyzer 2488 C:\Documents and Settings\Almaher\Desktop\تقارير زيزووم\RunScanner.exe
<verified> Machine Debug Manager 1080 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
<verified> WLLoginProxy.exe 2708 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
<verified> RealNetworks Scheduler 2196 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
<verified> ULCDRSvr 1352 C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
<verified> GoogleToolbarNotifier 2844 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
<verified> Internet Explorer 324 C:\Program Files\Internet Explorer\iexplore.exe
<verified> Kaspersky Anti-Virus 2232 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
<verified> Kaspersky Anti-Virus 844 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
<verified> Firefox 3968 C:\Program Files\Mozilla Firefox\firefox.exe
<verified> incdsrv 1048 C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
<verified> RealPlayer 2720 C:\Program Files\Real\RealPlayer\RealPlay.exe
<verified> TOSHIBA Bluetooth Service 1324 C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
<verified> Windows Explorer 1824 C:\WINDOWS\Explorer.EXE
<verified> Application Layer Gateway Service 808 C:\WINDOWS\System32\alg.exe
<verified> Client Server Runtime Process 1432 C:\WINDOWS\system32\csrss.exe
<verified> CTF Loader 2788 C:\WINDOWS\system32\ctfmon.exe
<verified> igfxsrvc Module 2036 C:\WINDOWS\system32\igfxsrvc.exe
<verified> LSA Shell (Export Version) 1512 C:\WINDOWS\system32\lsass.exe
<verified> Services and Controller app 1500 C:\WINDOWS\system32\services.exe
<verified> Windows NT Session Manager 1292 C:\WINDOWS\System32\smss.exe
<verified> Spooler SubSystem App 564 C:\WINDOWS\system32\spoolsv.exe
<verified> Generic Host Process for Win32 Services 668 C:\WINDOWS\system32\svchost.exe
<verified> Generic Host Process for Win32 Services 1676 C:\WINDOWS\system32\svchost.exe
<verified> Generic Host Process for Win32 Services 1732 C:\WINDOWS\system32\svchost.exe
<verified> Generic Host Process for Win32 Services 1772 C:\WINDOWS\System32\svchost.exe
<verified> Generic Host Process for Win32 Services 1952 C:\WINDOWS\system32\svchost.exe
<verified> Generic Host Process for Win32 Services 1252 C:\WINDOWS\system32\svchost.exe
<verified> Generic Host Process for Win32 Services 884 C:\WINDOWS\system32\svchost.exe
<verified> Windows NT Logon Application 1456 C:\WINDOWS\system32\winlogon.exe
Autoruns and critical files
---------------------------
<unsigned> AFAQ Wireless.exe C:\Program Files\AFAQ Wireless\AFAQ Wireless.exe
<unsigned> traybar C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
<unsigned> Adobe Gamma Loader C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
<unsigned> Ulead VideoStudio C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe
<unsigned> Hewlett-Packard Product Assistant C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
<unsigned> FinePrint pdfFactory C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
<verified> Adobe Acrobat SpeedLauncher C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
<verified> RealNetworks Scheduler C:\Program Files\Common Files\Real\Update_OB\realsched.exe
<verified> Language Application C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
<verified> GoogleToolbarNotifier C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
<verified> kldialhk C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\adialhk.dll
<verified> Kaspersky Anti-Virus C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
<verified> Kaspersky OE plugin loader C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\kloehk.dll
<verified> Mozilla 3 Virtual Keyboard C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd3.dll
<verified> Mozilla 2 Virtual Keyboard C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd.dll
<verified> IT Security Manager for Toshiba Stack C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe
<verified> Crypto API32 C:\WINDOWS\system32\CRYPT32.dll
<verified> Crypto Network Related API C:\WINDOWS\system32\cryptnet.dll
<verified> Offline Network Agent C:\WINDOWS\System32\CSCDLL.dll
<verified> CTF Loader C:\WINDOWS\system32\ctfmon.exe
<verified> Windows Error Reporting Dump Reporting Tool C:\WINDOWS\system32\dumprep.exe
<verified> hkcmd Module C:\WINDOWS\system32\hkcmd.exe
<verified> igfxdev Module C:\WINDOWS\system32\igfxdev.dll
<verified> persistence Module C:\WINDOWS\system32\igfxpers.exe
<verified> igfxTray Module C:\WINDOWS\system32\igfxtray.exe
<verified> Logon Visualizer C:\WINDOWS\system32\klogon.dll
<verified> Microsoft Windows Sockets 2.0 Service Provider C:\WINDOWS\system32\mswsock.dll
<verified> Microsoft Windows Rsvp 1.0 Service Provider C:\WINDOWS\system32\rsvpsp.dll
<verified> Secondary Logon Service Notification DLL C:\WINDOWS\system32\sclgntfy.dll
<verified> LDAP RnR Provider DLL C:\WINDOWS\System32\winrnr.dll
<verified> Common DLL to receive Winlogon notifications C:\WINDOWS\system32\WlNotify.dll
<verified> Windows Sockets Helper DLL C:\WINDOWS\system32\wshbth.dll
<verified> Windows Logon UI logonui.exe
Browser plugins
---------------
<unsigned> PaltalkScene C:\Program Files\Paltalk Messenger\Paltalk.exe
<unsigned> RealJukebox Netscape Plugin C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
<unsigned> 6.0.12.69 C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
<verified> Adobe PDF Helper for Internet Explorer C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
<verified> WindowsLiveLogin.dll C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
<verified> شريط أدوات Google لمستخدم IE c:\program files\google\googletoolbar1.dll
<verified> GoogleToolbarNotifier C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
<verified> IE Virtual Keyboard C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
<verified> Default Plug-in C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
<verified> Adobe PDF Plug-In For Firefox and Netscape C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
<verified> RealPlayer(tm) LiveConnect-Enabled Plug-In C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
<verified> RealPlayer Download and Record Plugin C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
<verified> Rhapsody Player Engine Plugin C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
<verified> SnagIt Browser Helper Object for Internet Explorer C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll
<verified> SnagIt Add-in for Internet Explorer c:\program files\techsmith\snagit 9\snagitieaddin.dll
<verified> BitDefender QuickScan Client ActiveX C:\WINDOWS\Downloaded Program Files\ActiveQscan.ocx
<verified> Adobe® Flash® Player ActiveX Installer C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
<verified> NPSWF32.dll C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
<verified> Shell Doc Object and Control Library C:\WINDOWS\system32\SHDOCVW.dll
Missing files
-------------
File not found: 0
referenced in: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"Profissonal Viewer"
File not found: C:\Program Files\Athkar\Athkar\Athkar.exe
referenced in: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\"Athkar"
File not found: C:\Program Files\Azkary\Azkary
referenced in: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"Azkary"
File not found: C:\Program Files\Microsoft Visual Studio\VB98/Project1
referenced in: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\"Project1"
File not found: C:\WINDOWS\system32\winlog0n.exe
referenced in: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\"مجلدجديد.exe"
Scan
----
The following file(s) must be uploaded for server-side scanning:
C:\WINDOWS\system32\ckldrv.sys
C:\Program Files\Real\RealPlayer\rpplugins\rpap3260.dll
C:\Program Files\Real\RealPlayer\rpplugins\rpmn3260.dll
Upload started - 3 file(s)
Upload: C:\WINDOWS\system32\ckldrv.sys - 29414 bytes, hash: ca56c723fb797b6db9d9f3b6a5ddea13
Upload: C:\Program Files\Real\RealPlayer\rpplugins\rpmn3260.dll - 536576 bytes, hash: 19291f878283116170cd56a676648e2e
Upload: C:\Program Files\Real\RealPlayer\rpplugins\rpap3260.dll - 913408 bytes, hash: 1f7e467fc1e799ce37c8396d3fd57c27
Upload speed - 19 KB/s
Upload finished - 3 uploaded, 0 failed
The uploaded file(s) were found clean.