من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
السلام عليكم مساء الخير اخوتي هذا تقرير هاك بتاكد ان جهازي سليم من ملفات التجسس والفيروسات هل ممكن
logfile of hijackthis v1.99.1
scan saved at 01:40:45 م, on 09/10/2008
platform: Windows xp sp3 (winnt 5.01.2600)
msie: Internet explorer v7.00 (7.00.6000.16674)
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\windows\system32\acs.exe
c:\program files\eset\eset nod32 antivirus\ekrn.exe
c:\program files\hotspot shield\bin\openvpnas.exe
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
c:\program files\microsoft\search enhancement pack\seaport\seaport.exe
c:\windows\system32\cap3rsk.exe
c:\windows\system32\svchost.exe
c:\program files\common files\ulead systems\dvd\ulcdrsvr.exe
c:\windows\system32\cnab4rpk.exe
c:\windows\system32\wscntfy.exe
c:\windows\explorer.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\program files\atheros\acu.exe
c:\windows\system32\ctfmon.exe
c:\program files\nokia\nokia pc suite 7\pcsuite.exe
c:\program files\messenger\msmsgs.exe
c:\program files\eset\eset nod32 antivirus\egui.exe
c:\program files\pc connectivity solution\servicelayer.exe
c:\program files\pc connectivity solution\transports\nclusbsrv.exe
c:\program files\pc connectivity solution\transports\nclrssrv.exe
c:\program files\pc connectivity solution\transports\nclmsbtsrv.exe
c:\windows\system32\svchost.exe
c:\program files\windows live\contacts\wlcomm.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\windows live\messenger\msnmsgr.exe
c:\program files\windows live\messenger\msnmsgr.exe
d:\الإسطوآآنة الخرآفية\hijackthis.exe
r1 - hkcu\software\microsoft\internet explorer\main,default_page_url = about:
R1 - hklm\software\microsoft\internet explorer\main,default_page_url =
r1 - hklm\software\microsoft\internet explorer\main,default_search_url =
r1 - hklm\software\microsoft\internet explorer\main,search page =
r0 - hklm\software\microsoft\internet explorer\main,start page =
r0 - hkcu\software\microsoft\internet explorer\main,local page =
r0 - hklm\software\microsoft\internet explorer\main,local page =
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyserver = 127.0.0.1:8080
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = local
r3 - urlsearchhook: Yahoo! Toolbar - {ef99bd32-c1fb-11d2-892f-0090271d4f88} - (no file)
o2 - bho: Adobe pdf reader link helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: مساعد تسجيل الدخول إلى windows live - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Hotspot shield class - {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\hssie.dll
o4 - hklm\..\run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
o4 - hklm\..\run: [acu] "c:\program files\atheros\acu.exe" -nogui
o4 - hklm\..\run: [msnmonitor] "c:\program files\immonitor\msn messenger monitor sniffer\msnmonitor.exe"
o4 - hkcu\..\run: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [pc suite tray] "c:\program files\nokia\nokia pc suite 7\pcsuite.exe" -onlytray
o4 - hkcu\..\run: [msmsgs] "c:\program files\messenger\msmsgs.exe" /background
o4 - global startup: Eset nod32 antivirus.lnk = c:\program files\eset\eset nod32 antivirus\egui.exe
o8 - extra context menu item: E&xport to microsoft excel - res://c:\progra~1\micros~2\office11\excel.exe/3000
o9 - extra button: تدوين هذا في المدونة - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files\windows live\writer\writerbrowserextension.dll
o9 - extra 'tools' menuitem: &تدوين هذا في windows live writer - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files\windows live\writer\writerbrowserextension.dll
o9 - extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office11\refiebar.dll
o9 - extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\network diagnostic\xpnetdiag.exe (file missing)
o9 - extra 'tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\network diagnostic\xpnetdiag.exe (file missing)
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o11 - options group: [international] international*
o16 - dpf: {6414512b-b978-451d-a0d8-fcfdf33e833c} (wuwebcontrol class) -
o18 - protocol: Livecall - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\wi1f86~1\messen~1\msgrap~1.dll
o18 - protocol: Msnim - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\wi1f86~1\messen~1\msgrap~1.dll
o18 - protocol: Wlmailhtml - {03c514a3-1efb-4856-9f99-10d7be1653c0} - c:\program files\windows live\mail\mailcomm.dll
o20 - winlogon notify: Igfxcui - c:\windows\system32\igfxdev.dll
o21 - ssodl: Wpdshserviceobj - {aaa288ba-9a4c-45b0-95d7-94d524869db5} - c:\windows\system32\wpdshserviceobj.dll
o23 - service: Atheros configuration service (acs) - unknown owner - c:\windows\system32\acs.exe
o23 - service: Eset http server (ehttpsrv) - eset - c:\program files\eset\eset nod32 antivirus\ehttpsrv.exe
o23 - service: Eset service (ekrn) - eset - c:\program files\eset\eset nod32 antivirus\ekrn.exe
o23 - service: Hotspot shield service (hotspotshieldservice) - unknown owner - c:\program files\hotspot shield\bin\openvpnas.exe
o23 - service: Thinkpad pm service (ibmpmsvc) - lenovo - c:\windows\system32\ibmpmsvc.exe
o23 - service: Remote packet capture protocol v.0 (experimental) (rpcapd) - unknown owner - %programfiles%\winpcap\rpcapd.exe" -d -f "%programfiles%\winpcap\rpcapd.ini (file missing)
o23 - service: Servicelayer - nokia. - c:\program files\pc connectivity solution\servicelayer.exe
o23 - service: Ulead burning helper (uleadburninghelper) - ulead systems, inc. - c:\program files\common files\ulead systems\dvd\ulcdrsvr.exe
logfile of hijackthis v1.99.1
scan saved at 01:40:45 م, on 09/10/2008
platform: Windows xp sp3 (winnt 5.01.2600)
msie: Internet explorer v7.00 (7.00.6000.16674)
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\windows\system32\acs.exe
c:\program files\eset\eset nod32 antivirus\ekrn.exe
c:\program files\hotspot shield\bin\openvpnas.exe
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
c:\program files\microsoft\search enhancement pack\seaport\seaport.exe
c:\windows\system32\cap3rsk.exe
c:\windows\system32\svchost.exe
c:\program files\common files\ulead systems\dvd\ulcdrsvr.exe
c:\windows\system32\cnab4rpk.exe
c:\windows\system32\wscntfy.exe
c:\windows\explorer.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\program files\atheros\acu.exe
c:\windows\system32\ctfmon.exe
c:\program files\nokia\nokia pc suite 7\pcsuite.exe
c:\program files\messenger\msmsgs.exe
c:\program files\eset\eset nod32 antivirus\egui.exe
c:\program files\pc connectivity solution\servicelayer.exe
c:\program files\pc connectivity solution\transports\nclusbsrv.exe
c:\program files\pc connectivity solution\transports\nclrssrv.exe
c:\program files\pc connectivity solution\transports\nclmsbtsrv.exe
c:\windows\system32\svchost.exe
c:\program files\windows live\contacts\wlcomm.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\windows live\messenger\msnmsgr.exe
c:\program files\windows live\messenger\msnmsgr.exe
d:\الإسطوآآنة الخرآفية\hijackthis.exe
r1 - hkcu\software\microsoft\internet explorer\main,default_page_url = about:
R1 - hklm\software\microsoft\internet explorer\main,default_page_url =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
r1 - hklm\software\microsoft\internet explorer\main,default_search_url =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
r1 - hklm\software\microsoft\internet explorer\main,search page =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
r0 - hklm\software\microsoft\internet explorer\main,start page =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
r0 - hkcu\software\microsoft\internet explorer\main,local page =
r0 - hklm\software\microsoft\internet explorer\main,local page =
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyserver = 127.0.0.1:8080
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = local
r3 - urlsearchhook: Yahoo! Toolbar - {ef99bd32-c1fb-11d2-892f-0090271d4f88} - (no file)
o2 - bho: Adobe pdf reader link helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: مساعد تسجيل الدخول إلى windows live - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: Hotspot shield class - {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\hssie.dll
o4 - hklm\..\run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
o4 - hklm\..\run: [acu] "c:\program files\atheros\acu.exe" -nogui
o4 - hklm\..\run: [msnmonitor] "c:\program files\immonitor\msn messenger monitor sniffer\msnmonitor.exe"
o4 - hkcu\..\run: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [pc suite tray] "c:\program files\nokia\nokia pc suite 7\pcsuite.exe" -onlytray
o4 - hkcu\..\run: [msmsgs] "c:\program files\messenger\msmsgs.exe" /background
o4 - global startup: Eset nod32 antivirus.lnk = c:\program files\eset\eset nod32 antivirus\egui.exe
o8 - extra context menu item: E&xport to microsoft excel - res://c:\progra~1\micros~2\office11\excel.exe/3000
o9 - extra button: تدوين هذا في المدونة - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files\windows live\writer\writerbrowserextension.dll
o9 - extra 'tools' menuitem: &تدوين هذا في windows live writer - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files\windows live\writer\writerbrowserextension.dll
o9 - extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office11\refiebar.dll
o9 - extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\network diagnostic\xpnetdiag.exe (file missing)
o9 - extra 'tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\network diagnostic\xpnetdiag.exe (file missing)
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o11 - options group: [international] international*
o16 - dpf: {6414512b-b978-451d-a0d8-fcfdf33e833c} (wuwebcontrol class) -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
o18 - protocol: Livecall - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\wi1f86~1\messen~1\msgrap~1.dll
o18 - protocol: Msnim - {828030a1-22c1-4009-854f-8e305202313f} - c:\progra~1\wi1f86~1\messen~1\msgrap~1.dll
o18 - protocol: Wlmailhtml - {03c514a3-1efb-4856-9f99-10d7be1653c0} - c:\program files\windows live\mail\mailcomm.dll
o20 - winlogon notify: Igfxcui - c:\windows\system32\igfxdev.dll
o21 - ssodl: Wpdshserviceobj - {aaa288ba-9a4c-45b0-95d7-94d524869db5} - c:\windows\system32\wpdshserviceobj.dll
o23 - service: Atheros configuration service (acs) - unknown owner - c:\windows\system32\acs.exe
o23 - service: Eset http server (ehttpsrv) - eset - c:\program files\eset\eset nod32 antivirus\ehttpsrv.exe
o23 - service: Eset service (ekrn) - eset - c:\program files\eset\eset nod32 antivirus\ekrn.exe
o23 - service: Hotspot shield service (hotspotshieldservice) - unknown owner - c:\program files\hotspot shield\bin\openvpnas.exe
o23 - service: Thinkpad pm service (ibmpmsvc) - lenovo - c:\windows\system32\ibmpmsvc.exe
o23 - service: Remote packet capture protocol v.0 (experimental) (rpcapd) - unknown owner - %programfiles%\winpcap\rpcapd.exe" -d -f "%programfiles%\winpcap\rpcapd.ini (file missing)
o23 - service: Servicelayer - nokia. - c:\program files\pc connectivity solution\servicelayer.exe
o23 - service: Ulead burning helper (uleadburninghelper) - ulead systems, inc. - c:\program files\common files\ulead systems\dvd\ulcdrsvr.exe
