مشكور أخوي علي ناين ون ون :b:
هيو التقرير
/
logfile of trend micro hijackthis v2.0.2
scan saved at 09:37:01 م, on 31/10/2009
platform: Windows xp sp2 (winnt 5.01.2600)
msie: Internet explorer v6.00 sp2 (6.00.2900.2180)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\program files\gigabyte\easysaver\essvr.exe
c:\program files\java\jre6\bin\jqs.exe
c:\windows\system32\svchost.exe
c:\windows\explorer.exe
c:\windows\system32\igfxtray.exe
c:\windows\system32\hkcmd.exe
c:\windows\system32\igfxpers.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\hp\hp software update\hpwuschd2.exe
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ctfmon.exe
c:\program files\messenger\msmsgs.exe
c:\program files\hp\digital imaging\bin\hpqtra08.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\hp\digital imaging\bin\hpqimzone.exe
c:\program files\hp\digital imaging\bin\hpqste08.exe
c:\program files\mobily connect card\mobily connect card.exe
c:\documents and settings\dgc\سطح المكتب\zyzoom_hijackthis.exe
r1 - hkcu\software\microsoft\internet connection wizard,shellnext =
r3 - urlsearchhook: Devicevm url search hook - {0063bf63-bfff-4b8f-9d26-4267df7f17dd} - c:\windows\system32\dvmurl.dll
o2 - bho: Adobe pdf reader link helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\acroiehelper.dll
o2 - bho: Ievkbdbho - {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll
o2 - bho: Java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
o2 - bho: Link filter bho - {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
o2 - bho: Jqsiestartdetectorimpl - {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
o4 - hklm\..\run: [igfxtray] c:\windows\system32\igfxtray.exe
o4 - hklm\..\run: [hotkeyscmds] c:\windows\system32\hkcmd.exe
o4 - hklm\..\run: [persistence] c:\windows\system32\igfxpers.exe
o4 - hklm\..\run: [blue peak seek up] c:\documents and settings\all users\application data\program amen blue peak\wait ball.exe
o4 - hklm\..\run: [adobe reader speed launcher] "c:\program files\adobe\reader 8.0\reader\reader_sl.exe"
o4 - hklm\..\run: [hp software update] c:\program files\hp\hp software update\hpwuschd2.exe
o4 - hklm\..\run: [avp] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe"
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
o4 - hkcu\..\run: [grimclose] c:\docume~1\dgc\applic~1\datath~1\nurbway.exe
o4 - hkcu\..\run: [msmsgs] "c:\program files\messenger\msmsgs.exe" /background
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'local service')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'network service')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o4 - global startup: Hp digital imaging monitor.lnk = c:\program files\hp\digital imaging\bin\hpqtra08.exe
o4 - global startup: Hp image zone fast start.lnk = c:\program files\hp\digital imaging\bin\hpqthb08.exe
o8 - extra context menu item: &تصدير إلى microsoft excel - res://c:\progra~1\micros~2\office11\excel.exe/3000
o9 - extra button: &virtual keyboard - {4248fe82-7fcb-46ac-b270-339f08212110} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
o9 - extra button: بحث - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office11\refiebar.dll
o9 - extra button: Urls c&heck - {ccf151d8-d089-449f-a5a4-d9909053f20f} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o17 - hklm\system\ccs\services\tcpip\..\{cca74740-f96f-4040-b724-a14b08f7ba89}: Nameserver = 84.23.102.172 84.23.101.84
o20 - appinit_dlls: C:\progra~1\kasper~1\kasper~1\mzvkbd3.dll
o23 - service: Kaspersky internet security (avp) - kaspersky lab - c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe
o23 - service: Es lite service for program management. (es lite service) - unknown owner - c:\program files\gigabyte\easysaver\essvr.exe
o23 - service: Java quick starter (javaquickstarterservice) - sun microsystems, inc. - c:\program files\java\jre6\bin\jqs.exe
o23 - service: Pml driver hpz12 - hp - c:\windows\system32\hpzipm12.exe
o24 - desktop component 0: (no name) - file:///c:/docume~1/dgc/locals~1/temp/msohtml1/01/clip_image002.jpg
--
end of file - 5265 bytes