من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
السلام
اذا اعمل فحص سكان يطفي الجهاز
وبعض الاحيان ينطفي من نفسه
الحرارة للجهاز تمام لكن اشك بوجود فايروس
ارجو المساعدة بالتخلص منة
هذا تقرير الهايجاك
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:49:14 ص, on 09/01/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ASTSRV.EXE
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrator\My Documents\Additional PROGRAMS\Zyzoom_HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Documents and Settings\Administrator\Desktop\jccatch.dll (file missing)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Documents and Settings\Administrator\Desktop\getflash.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Flashget] "C:\Documents and Settings\Administrator\Desktop\FlashGet.exe" /min
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Documents and Settings\Administrator\Desktop\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Documents and Settings\Administrator\Desktop\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: إفحص باستخدام د. وب -
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Documents and Settings\Administrator\Desktop\FlashGet.exe (file missing)
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Documents and Settings\Administrator\Desktop\FlashGet.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} (qsax Control) -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) -
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) -
O23 - Service: Nalpeiron Licensing Service (ASTSRV) - Nalpeiron Ltd. - C:\WINDOWS\system32\ASTSRV.EXE
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Unknown owner - C:\Program Files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
--
End of file - 7916 bytes
----------------------------------------------
الملف لبرنامج runscanner
------------------------------
وهذا للتقرر الثالث
BitDefender QuickScan Beta 32-bit v0.9.8.9
------------------------------------------
Scan date: Sat Jan 09 03:10:58 2010
Machine ID: C4200013
No infection found.
---------------------
Processes
---------
<unsigned> CrypKey Software Licensing System 1356 C:\WINDOWS\system32\crypserv.exe
<unsigned> jusched.exe 432 C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
<unsigned> Nalpeiron License Management 1344 C:\WINDOWS\system32\ASTSRV.EXE
<verified> ESET Smart Security 1660 C:\Program Files\ESET\ESET Smart Security\ekrn.exe
<verified> Intel(R) Common User Interface 364 C:\WINDOWS\system32\hkcmd.exe
<verified> Intel(R) Common User Interface 2044 C:\WINDOWS\system32\igfxtray.exe
<verified> Messenger 560 C:\Program Files\Messenger\msmsgs.exe
<verified> Microsoft® .NET Framework 1268 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
<verified> Microsoft® Visual Studio .NET 1736 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
<verified> Microsoft® Windows® Operating System 1568 C:\WINDOWS\Explorer.EXE
<verified> Microsoft® Windows® Operating System 2152 C:\WINDOWS\System32\alg.exe
<verified> Microsoft® Windows® Operating System 596 C:\WINDOWS\system32\csrss.exe
<verified> Microsoft® Windows® Operating System 808 C:\WINDOWS\system32\ctfmon.exe
<verified> Microsoft® Windows® Operating System 676 C:\WINDOWS\system32\lsass.exe
<verified> Microsoft® Windows® Operating System 3784 C:\WINDOWS\system32\notepad.exe
<verified> Microsoft® Windows® Operating System 664 C:\WINDOWS\system32\services.exe
<verified> Microsoft® Windows® Operating System 544 C:\WINDOWS\System32\smss.exe
<verified> Microsoft® Windows® Operating System 1196 C:\WINDOWS\system32\spoolsv.exe
<verified> Microsoft® Windows® Operating System 1304 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 840 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 944 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 984 C:\WINDOWS\System32\svchost.exe
<verified> Microsoft® Windows® Operating System 1044 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 1072 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 620 C:\WINDOWS\system32\winlogon.exe
<verified> Nero AG InCD 172 C:\Program Files\Nero\Nero 7\InCD\InCD.exe
<verified> Nero AG incdsrv 1712 C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
<verified> Nero SecurDisc client 248 C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
<verified> RealPlayer (32-bit) 112 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
<verified> Realtek Sound Manager 2032 C:\WINDOWS\SOUNDMAN.EXE
<verified> Windows Live Communications Platform 2872 C:\Program Files\Windows Live\Contacts\wlcomm.exe
<verified> Windows Live Messenger 600 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
<verified> Windows® Internet Explorer 2144 C:\Program Files\internet explorer\iexplore.exe
<verified> Windows® Internet Explorer 2480 C:\Program Files\internet explorer\iexplore.exe
Network activity
----------------
Process ekrn.exe (1660) connected on port 80 (HTTP) - bitdefender.com.122.2o7.net
Process ekrn.exe (1660) connected on port 80 (HTTP) - content.yieldmanager.edgesuite.net
Process ekrn.exe (1660) connected on port 80 (HTTP) - quickscan.bitdefender.com
Process ekrn.exe (1660) connected on port 80 (HTTP) - e2943.c.akamaiedge.net
Process ekrn.exe (1660) connected on port 80 (HTTP) - quickscan.bitdefender.com
Process ekrn.exe (1660) connected on port 1863 (MSN) - by2msg1010815.gateway.edge.messenger.live.com
Process ekrn.exe (1660) connected on port 80 (HTTP) - CRL.VERISIGN.NET
Process ekrn.exe (1660) connected on port 80 (HTTP) - clients.l.google.com
Process svchost.exe (944) listens on ports: 135 (RPC)
Autoruns and critical files
---------------------------
<unsigned> Adobe Systems, Inc. Adobe Gamma Loader C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
<unsigned> jusched.exe C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
<verified> ESET Smart Security C:\Program Files\ESET\ESET Smart Security\egui.exe
<verified> Intel(R) Common User Interface C:\WINDOWS\system32\hkcmd.exe
<verified> Intel(R) Common User Interface C:\WINDOWS\system32\igfxsrvc.dll
<verified> Intel(R) Common User Interface C:\WINDOWS\system32\igfxtray.exe
<verified> Messenger C:\Program Files\Messenger\msmsgs.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\browseui.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\crypt32.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\cryptnet.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\cscdll.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\ctfmon.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\logonui.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\sclgntfy.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\shell32.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\stobject.dll
<verified> Microsoft® Windows® Operating System c:\windows\system32\userinit.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\wlnotify.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\WPDShServiceObj.dll
<verified> Nero AG InCD C:\Program Files\Nero\Nero 7\InCD\InCD.exe
<verified> Nero AG NeroCheck C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
<verified> Nero SecurDisc client C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
<verified> OGAVerify.exe C:\WINDOWS\system32\OGAVerify.exe
<verified> RealPlayer (32-bit) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
<verified> Realtek Sound Manager C:\WINDOWS\SOUNDMAN.EXE
<verified> Windows Live Messenger C:\Program Files\Windows Live\Messenger\msnmsgr.exe
<verified> Windows® Internet Explorer C:\WINDOWS\system32\webcheck.dll
Browser plugins
---------------
<unsigned> Adobe Acrobat C:\Program Files\Internet Explorer\plugins\nppdf32.dll
<unsigned> bdoscandel.exe C:\WINDOWS\bdoscandel.exe
<unsigned> bdscanonline C:\WINDOWS\Downloaded Program Files\oscan82.ocx
<unsigned> ipsupd.dll C:\WINDOWS\Downloaded Program Files\ipsupd.dll
<unsigned> RealJukebox NS Plugin C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
<unsigned> RealPlayer Version Plugin C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
<verified> AcroIEHelper Library C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
<verified> Adobe® Flash® Player ActiveX C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
<verified> BitDefender QuickScan C:\WINDOWS\Downloaded Program Files\qsax.ocx
<verified> Messenger C:\Program Files\Messenger\msmsgs.exe
<verified> Microsoft® Windows Live Login Helper C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\mswsock.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\rsvpsp.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\winrnr.dll
<verified> MSN Photo Upload Control C:\WINDOWS\Downloaded Program Files\CONFLICT.1\PURen-us.dll
<verified> MSN Photo Upload Control C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll
<verified> MSN Photo Upload Control C:\WINDOWS\Downloaded Program Files\PURen-us.dll
<verified> RealPlayer Download and Record Plugin C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
<verified> RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32- C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
<verified> Silverlight Plug-In c:\Program Files\Microsoft Silverlight\3.0.40818.0\npctrl.dll
<verified> Windows Live Photo Upload Control C:\WINDOWS\Downloaded Program Files\CONFLICT.1\MsnPUpld.dll
<verified> Windows Presentation Foundation c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
<verified> Windows® Internet Explorer C:\WINDOWS\system32\ieframe.dll
<verified> Yahoo! activeX Plug-in Bridge C:\Program Files\Yahoo!\Common\npyaxmpb.dll
Missing files
-------------
File not found: C:\Documents and Settings\Administrator\Desktop\FlashGet.exe
referenced in: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"Flashget"
referenced in: HKLM\Software\Microsoft\Internet Explorer\Extensions\{D6E814A0-E0C5-11d4-8D29-0050BA6940E3}\"Exec"
File not found: C:\Program Files\Software Informer\softinfo.exe
referenced in: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\"Software Informer"
File not found: c:\documents and settings\administrator\desktop\getflash.dll
referenced in: HKCR\CLSID\{F156768E-81EF-470C-9057-481BA8380DBA}\InprocServer32\(default)
File not found: c:\documents and settings\administrator\desktop\jccatch.dll
referenced in: HKCR\CLSID\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}\InprocServer32\(default)
Scan
----
No file uploaded.
Scan finished - communication took 7 sec
Total traffic - 0.04 MB sent, 2.17 KB recvd
Scanned 899 files and modules - 113 seconds
اذا اعمل فحص سكان يطفي الجهاز
وبعض الاحيان ينطفي من نفسه
الحرارة للجهاز تمام لكن اشك بوجود فايروس
ارجو المساعدة بالتخلص منة
هذا تقرير الهايجاك
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:49:14 ص, on 09/01/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ASTSRV.EXE
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrator\My Documents\Additional PROGRAMS\Zyzoom_HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Documents and Settings\Administrator\Desktop\jccatch.dll (file missing)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Documents and Settings\Administrator\Desktop\getflash.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Flashget] "C:\Documents and Settings\Administrator\Desktop\FlashGet.exe" /min
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Documents and Settings\Administrator\Desktop\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Documents and Settings\Administrator\Desktop\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: إفحص باستخدام د. وب -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Documents and Settings\Administrator\Desktop\FlashGet.exe (file missing)
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Documents and Settings\Administrator\Desktop\FlashGet.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} (qsax Control) -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O23 - Service: Nalpeiron Licensing Service (ASTSRV) - Nalpeiron Ltd. - C:\WINDOWS\system32\ASTSRV.EXE
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Unknown owner - C:\Program Files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
--
End of file - 7916 bytes
----------------------------------------------
الملف لبرنامج runscanner
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
------------------------------
وهذا للتقرر الثالث
BitDefender QuickScan Beta 32-bit v0.9.8.9
------------------------------------------
Scan date: Sat Jan 09 03:10:58 2010
Machine ID: C4200013
No infection found.
---------------------
Processes
---------
<unsigned> CrypKey Software Licensing System 1356 C:\WINDOWS\system32\crypserv.exe
<unsigned> jusched.exe 432 C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
<unsigned> Nalpeiron License Management 1344 C:\WINDOWS\system32\ASTSRV.EXE
<verified> ESET Smart Security 1660 C:\Program Files\ESET\ESET Smart Security\ekrn.exe
<verified> Intel(R) Common User Interface 364 C:\WINDOWS\system32\hkcmd.exe
<verified> Intel(R) Common User Interface 2044 C:\WINDOWS\system32\igfxtray.exe
<verified> Messenger 560 C:\Program Files\Messenger\msmsgs.exe
<verified> Microsoft® .NET Framework 1268 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
<verified> Microsoft® Visual Studio .NET 1736 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
<verified> Microsoft® Windows® Operating System 1568 C:\WINDOWS\Explorer.EXE
<verified> Microsoft® Windows® Operating System 2152 C:\WINDOWS\System32\alg.exe
<verified> Microsoft® Windows® Operating System 596 C:\WINDOWS\system32\csrss.exe
<verified> Microsoft® Windows® Operating System 808 C:\WINDOWS\system32\ctfmon.exe
<verified> Microsoft® Windows® Operating System 676 C:\WINDOWS\system32\lsass.exe
<verified> Microsoft® Windows® Operating System 3784 C:\WINDOWS\system32\notepad.exe
<verified> Microsoft® Windows® Operating System 664 C:\WINDOWS\system32\services.exe
<verified> Microsoft® Windows® Operating System 544 C:\WINDOWS\System32\smss.exe
<verified> Microsoft® Windows® Operating System 1196 C:\WINDOWS\system32\spoolsv.exe
<verified> Microsoft® Windows® Operating System 1304 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 840 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 944 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 984 C:\WINDOWS\System32\svchost.exe
<verified> Microsoft® Windows® Operating System 1044 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 1072 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 620 C:\WINDOWS\system32\winlogon.exe
<verified> Nero AG InCD 172 C:\Program Files\Nero\Nero 7\InCD\InCD.exe
<verified> Nero AG incdsrv 1712 C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
<verified> Nero SecurDisc client 248 C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
<verified> RealPlayer (32-bit) 112 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
<verified> Realtek Sound Manager 2032 C:\WINDOWS\SOUNDMAN.EXE
<verified> Windows Live Communications Platform 2872 C:\Program Files\Windows Live\Contacts\wlcomm.exe
<verified> Windows Live Messenger 600 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
<verified> Windows® Internet Explorer 2144 C:\Program Files\internet explorer\iexplore.exe
<verified> Windows® Internet Explorer 2480 C:\Program Files\internet explorer\iexplore.exe
Network activity
----------------
Process ekrn.exe (1660) connected on port 80 (HTTP) - bitdefender.com.122.2o7.net
Process ekrn.exe (1660) connected on port 80 (HTTP) - content.yieldmanager.edgesuite.net
Process ekrn.exe (1660) connected on port 80 (HTTP) - quickscan.bitdefender.com
Process ekrn.exe (1660) connected on port 80 (HTTP) - e2943.c.akamaiedge.net
Process ekrn.exe (1660) connected on port 80 (HTTP) - quickscan.bitdefender.com
Process ekrn.exe (1660) connected on port 1863 (MSN) - by2msg1010815.gateway.edge.messenger.live.com
Process ekrn.exe (1660) connected on port 80 (HTTP) - CRL.VERISIGN.NET
Process ekrn.exe (1660) connected on port 80 (HTTP) - clients.l.google.com
Process svchost.exe (944) listens on ports: 135 (RPC)
Autoruns and critical files
---------------------------
<unsigned> Adobe Systems, Inc. Adobe Gamma Loader C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
<unsigned> jusched.exe C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
<verified> ESET Smart Security C:\Program Files\ESET\ESET Smart Security\egui.exe
<verified> Intel(R) Common User Interface C:\WINDOWS\system32\hkcmd.exe
<verified> Intel(R) Common User Interface C:\WINDOWS\system32\igfxsrvc.dll
<verified> Intel(R) Common User Interface C:\WINDOWS\system32\igfxtray.exe
<verified> Messenger C:\Program Files\Messenger\msmsgs.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\browseui.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\crypt32.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\cryptnet.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\cscdll.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\ctfmon.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\logonui.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\sclgntfy.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\shell32.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\stobject.dll
<verified> Microsoft® Windows® Operating System c:\windows\system32\userinit.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\wlnotify.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\WPDShServiceObj.dll
<verified> Nero AG InCD C:\Program Files\Nero\Nero 7\InCD\InCD.exe
<verified> Nero AG NeroCheck C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
<verified> Nero SecurDisc client C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
<verified> OGAVerify.exe C:\WINDOWS\system32\OGAVerify.exe
<verified> RealPlayer (32-bit) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
<verified> Realtek Sound Manager C:\WINDOWS\SOUNDMAN.EXE
<verified> Windows Live Messenger C:\Program Files\Windows Live\Messenger\msnmsgr.exe
<verified> Windows® Internet Explorer C:\WINDOWS\system32\webcheck.dll
Browser plugins
---------------
<unsigned> Adobe Acrobat C:\Program Files\Internet Explorer\plugins\nppdf32.dll
<unsigned> bdoscandel.exe C:\WINDOWS\bdoscandel.exe
<unsigned> bdscanonline C:\WINDOWS\Downloaded Program Files\oscan82.ocx
<unsigned> ipsupd.dll C:\WINDOWS\Downloaded Program Files\ipsupd.dll
<unsigned> RealJukebox NS Plugin C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
<unsigned> RealPlayer Version Plugin C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
<verified> AcroIEHelper Library C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
<verified> Adobe® Flash® Player ActiveX C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
<verified> BitDefender QuickScan C:\WINDOWS\Downloaded Program Files\qsax.ocx
<verified> Messenger C:\Program Files\Messenger\msmsgs.exe
<verified> Microsoft® Windows Live Login Helper C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\mswsock.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\rsvpsp.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\winrnr.dll
<verified> MSN Photo Upload Control C:\WINDOWS\Downloaded Program Files\CONFLICT.1\PURen-us.dll
<verified> MSN Photo Upload Control C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll
<verified> MSN Photo Upload Control C:\WINDOWS\Downloaded Program Files\PURen-us.dll
<verified> RealPlayer Download and Record Plugin C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
<verified> RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32- C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
<verified> Silverlight Plug-In c:\Program Files\Microsoft Silverlight\3.0.40818.0\npctrl.dll
<verified> Windows Live Photo Upload Control C:\WINDOWS\Downloaded Program Files\CONFLICT.1\MsnPUpld.dll
<verified> Windows Presentation Foundation c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
<verified> Windows® Internet Explorer C:\WINDOWS\system32\ieframe.dll
<verified> Yahoo! activeX Plug-in Bridge C:\Program Files\Yahoo!\Common\npyaxmpb.dll
Missing files
-------------
File not found: C:\Documents and Settings\Administrator\Desktop\FlashGet.exe
referenced in: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"Flashget"
referenced in: HKLM\Software\Microsoft\Internet Explorer\Extensions\{D6E814A0-E0C5-11d4-8D29-0050BA6940E3}\"Exec"
File not found: C:\Program Files\Software Informer\softinfo.exe
referenced in: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\"Software Informer"
File not found: c:\documents and settings\administrator\desktop\getflash.dll
referenced in: HKCR\CLSID\{F156768E-81EF-470C-9057-481BA8380DBA}\InprocServer32\(default)
File not found: c:\documents and settings\administrator\desktop\jccatch.dll
referenced in: HKCR\CLSID\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}\InprocServer32\(default)
Scan
----
No file uploaded.
Scan finished - communication took 7 sec
Total traffic - 0.04 MB sent, 2.17 KB recvd
Scanned 899 files and modules - 113 seconds
