هذا تقرير الهايجك تبعي
logfile of trend micro hijackthis v2.0.2
scan saved at 11:25:18 ص, on 05/01/2009
platform: Windows xp sp3 (winnt 5.01.2600)
msie: Internet explorer v7.00 (7.00.6000.16762)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\program files\ivt corporation\bluesoleil\btntservice.exe
c:\program files\java\jre6\bin\jqs.exe
c:\program files\microsoft lifecam\mscams32.exe
c:\windows\system32\svchost.exe
c:\windows\explorer.exe
c:\msn.exe
c:\windows\sm56hlpr.exe
c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
c:\progra~1\nokia\nokiap~1\launch~1.exe
c:\windows\system32\rundll32.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\program files\java\jre6\bin\jusched.exe
c:\program files\messenger\msmsgs.exe
c:\program files\nokia\nokia pc suite 6\pcsync2.exe
c:\windows\system32\ctfmon.exe
c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
c:\program files\ivt corporation\bluesoleil\bluesoleil.exe
c:\program files\common files\pcsuite\services\servicelayer.exe
c:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe
c:\program files\winzip\wzqkpick.exe
c:\progra~1\common~1\nokia\mpapi\mpapi3s.exe
c:\progra~1\yahoo!\messen~1\ymsgr_tray.exe
c:\program files\hewlett-packard\digital imaging\bin\hpqste08.exe
c:\program files\windows live\messenger\msnmsgr.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\common files\microsoft shared\windows live\wlloginproxy.exe
c:\program files\windows live\messenger\usnsvc.exe
c:\docume~1\usr\locals~1\temp\winjqfxo.exe
c:\docume~1\usr\locals~1\temp\pdbe.exe
c:\docume~1\usr\locals~1\temp\winuxshx.exe
c:\program files\windows live\messenger\msnmsgr.exe
c:\docume~1\usr\locals~1\temp\winkrda.exe
c:\docume~1\usr\locals~1\temp\awey.exe
c:\docume~1\usr\locals~1\temp\labam.exe
c:\docume~1\usr\locals~1\temp\qugs.exe
c:\documents and settings\usr\desktop\hijackthis.exe
r1 - hklm\software\microsoft\internet explorer\main,default_page_url =
r1 - hklm\software\microsoft\internet explorer\main,default_search_url =
r1 - hklm\software\microsoft\internet explorer\main,search page =
r0 - hklm\software\microsoft\internet explorer\main,start page =
r3 - urlsearchhook: Sweetim for internet explorer - {bc4ffe41-de9f-46fa-b455-aad49b9f9938} - c:\program files\macrogaming\sweetimbarforie\toolbar.dll (file missing)
r3 - urlsearchhook: (no name) - {0a94b116-4504-4e26-ab05-e61e474aa38b} - c:\program files\askpbar\srchastt\2.bin\a9srchas.dll
f2 - reg:system.ini: Shell=explorer.exe
o2 - bho: (no name) - {02478d38-c3f9-4efb-9b51-7695eca05670} - (no file)
o2 - bho: Adobe pdf reader link helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll (file missing)
o2 - bho: Ask search assistant bho - {0a94b111-4504-4e26-ab05-e61e474aa38b} - c:\program files\askpbar\srchastt\2.bin\a9srchas.dll
o2 - bho: Sweetie - {1a0aadcd-3a72-4b5f-900f-e3bb5a838e2a} - c:\progra~1\macrog~1\sweeti~1\toolbar.dll (file missing)
o2 - bho: Askbar bho - {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askbar.dll
o2 - bho: Searchperks! Perk counter - {2787ea8e-8d87-48af-88ad-b30246c917ab} - c:\program files\searchperks! Perk counter\bmbho.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: Java(tm) plug-in ssv helper - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
o2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
o2 - bho: مساعد تسجيل الدخول إلى windows live - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Google toolbar helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\googletoolbar.dll
o2 - bho: Google toolbar notifier bho - {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll
o2 - bho: Google dictionary compression sdch - {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219b3e1547538286.dll
o2 - bho: Java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
o2 - bho: Jqsiestartdetectorimpl - {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
o2 - bho: Ask toolbar bho - {f4d76f01-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\4.bin\askpbar.dll (file missing)
o3 - toolbar: Sweetim for internet explorer - {bc4ffe41-de9f-46fa-b455-aad49b9f9938} - c:\program files\macrogaming\sweetimbarforie\toolbar.dll (file missing)
o3 - toolbar: Ask toolbar - {f4d76f09-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\4.bin\askpbar.dll (file missing)
o3 - toolbar: Searchperks! Perk counter - {2787ea8e-8d87-48af-88ad-b30246c917ab} - c:\program files\searchperks! Perk counter\bmbho.dll
o3 - toolbar: Ask toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askbar.dll
o3 - toolbar: &google toolbar - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\googletoolbar.dll
o4 - hklm\..\run: [imjpmig8.1] "c:\windows\ime\imjp8_1\imjpmig.exe" /spoil /remadvdef /migration32
o4 - hklm\..\run: [phime2002async] c:\windows\system32\ime\tintlgnt\tintsetp.exe /sync
o4 - hklm\..\run: [phime2002a] c:\windows\system32\ime\tintlgnt\tintsetp.exe /imename
o4 - hklm\..\run: [smserial] sm56hlpr.exe
o4 - hklm\..\run: [nerofiltercheck] c:\windows\system32\nerocheck.exe
o4 - hklm\..\run: [devicediscovery] c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
o4 - hklm\..\run: [ysearchprotection] "c:\program files\yahoo!\search protection\searchprotection.exe"
o4 - hklm\..\run: [pcsuitetrayapplication] c:\progra~1\nokia\nokiap~1\launch~1.exe -startup
o4 - hklm\..\run: [quicktime task] "c:\program files\quicktime\qttask.exe" -atboottime
o4 - hklm\..\run: [bluetoothauthenticationagent] rundll32.exe bthprops.cpl,,bluetoothauthenticationagent
o4 - hklm\..\run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
o4 - hklm\..\run: [vx1000] c:\windows\vvx1000.exe
o4 - hklm\..\run: [lifecam] "c:\program files\microsoft lifecam\lifeexp.exe"
o4 - hklm\..\run: [forum] c:\msn.exe
o4 - hklm\..\run: [sunjavaupdatesched] "c:\program files\java\jre6\bin\jusched.exe"
o4 - hklm\..\run: [avp] "c:\program files\kaspersky lab\kaspersky anti-virus 7.0\avp.exe"
o4 - hkcu\..\run: [msmsgs] "c:\program files\messenger\msmsgs.exe" /background
o4 - hkcu\..\run: [pcsync] c:\program files\nokia\nokia pc suite 6\pcsync2.exe /nodialog
o4 - hkcu\..\run: [lowratevoip] "c:\program files\lowratevoip\lowratevoip.exe" -nosplash -minimized
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [yahoo! Pager] "c:\progra~1\yahoo!\messen~1\yahoom~1.exe" -quiet
o4 - hkcu\..\run: [swg] c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
o4 - hkcu\..\run: [opentalk] c:\program files\opentalk\opentalk.exe
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'local service')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'network service')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o4 - startup: Adobe gamma.lnk = c:\program files\common files\adobe\calibration\adobe gamma loader.exe
o4 - startup: Adobe media player.lnk = c:\program files\adobe media player\adobe media player.exe
o4 - global startup: Adobe reader speed launch.lnk = c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
o4 - global startup: Bluesoleil.lnk = c:\program files\ivt corporation\bluesoleil\bluesoleil.exe
o4 - global startup: Hp digital imaging monitor.lnk = c:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe
o4 - global startup: Paltalk.lnk = c:\program files\paltalk messenger\paltalk.exe
o4 - global startup: Winzip quick pick.lnk = c:\program files\winzip\wzqkpick.exe
o7 - hkcu\software\microsoft\windows\currentversion\policies\system, disableregedit=1
o8 - extra context menu item: &search -
o8 - extra context menu item: &تصدير إلى microsoft excel - res://c:\progra~1\micros~2\office11\excel.exe/3000
o9 - extra button: Web anti-virus statistics - {1f460357-8a94-4d71-9ca3-aa4acf32ed8e} - c:\program files\kaspersky lab\kaspersky anti-virus 7.0\scieplgn.dll
o9 - extra button: Paltalk - {4eafef58-eefa-4116-983d-03b49bcbfffe} - c:\program files\paltalk messenger\paltalk.exe (file missing)
o9 - extra button: بحث - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office11\refiebar.dll
o9 - extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra 'tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o10 - unknown file in winsock lsp: C:\windows\system32\nwprovau.dll
o12 - plugin for .spop: C:\program files\internet explorer\plugins\npdocbox.dll
o16 - dpf: Cabbuilder -
o16 - dpf: {17492023-c23a-453e-a040-c7c580bbf700} (windows genuine advantage validation tool) -
o16 - dpf: {20a60f0d-9afa-4515-a0fd-83bd84642501} (checkers class) -
o16 - dpf: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (installation support) - c:\program files\yahoo!\common\yinsthelper.dll
o16 - dpf: {4f1e5b1a-2a80-42ca-8532-2d05cb959537} (msn photo upload tool) -
o16 - dpf: {5c051655-fcd5-4969-9182-770ea5aa5565} (solitaire showdown class) -
o16 - dpf: {5d6f45b3-9043-443d-a792-115447494d24} (unoctrl class) -
o16 - dpf: {6924091f-cd97-41e1-b1d4-d9079409d413} (imcv1 control) -
o16 - dpf: {b7fdb0c3-4724-46d2-b8db-6fa1dc63f7ca} (readuid.usercontrolmacentry) -
o16 - dpf: {b8be5e93-a60c-4d26-a2dc-220313175592} (msn games - installer) -
o16 - dpf: {c3f79a2b-b9b4-4a66-b012-3ee46475b072} (messengerstatsclient class) -
o16 - dpf: {cf40acc5-e1bb-4aff-ac72-04c2f616bca7} (get_atlcom class) -
o16 - dpf: {d27cdb6e-ae6d-11cf-96b8-444553540000} (shockwave flash ******) -
o23 - service: Adobe lm service - adobe systems - c:\program files\common files\adobe systems shared\service\adobelmsvc.exe
o23 - service: Bluesoleil hid service - unknown owner - c:\program files\ivt corporation\bluesoleil\btntservice.exe
o23 - service: Google updater service (gusvc) - google - c:\program files\google\common\google updater\googleupdaterservice.exe
o23 - service: Installdriver table manager (idrivert) - macrovision corporation - c:\program files\common files\installshield\driver\11\intel 32\idrivert.exe
o23 - service: Java quick starter (javaquickstarterservice) - sun microsystems, inc. - c:\program files\java\jre6\bin\jqs.exe
o23 - service: Pml driver hpz12 - hp - c:\windows\system32\hpzipm12.exe
o23 - service: Servicelayer - nokia. - c:\program files\common files\pcsuite\services\servicelayer.exe
--
end of file - 12584 bytes