السلام عليكم
كمبيوتري بطي مره
هل فيه فيروسات ؟؟؟
إقتباس:
logfile of trend micro hijackthis v2.0.2
scan saved at 04
43 م, on 12/08/11
platform: Unknown windows (winnt 6.01.3504)
msie: Internet explorer v8.00 (8.00.7600.16839)
boot mode: Normal
running processes:
C:\program files (x86)\windows live\messenger\msnmsgr.exe
c:\program files (x86)\ela-salaty\salaty.exe
c:\program files (x86)\intel\intel(r) rapid storage technology\iastoricon.exe
c:\program files (x86)\sony\isb utility\isbmgr.exe
c:\program files (x86)\kaspersky lab\kaspersky internet security 2011\avp.exe
c:\program files (x86)\real\realplayer\update\realsched.e xe
c:\program files (x86)\itunes\itune****per.exe
c:\program files (x86)\yuna software\messenger plus!\plusservice.exe
c:\program files\widcomm\bluetooth software\bluetoothheadsetproxy.exe
c:\program files (x86)\windows live\contacts\wlcomm.exe
c:\program files (x86)\common files\microsoft shared\virtualization handler\cvh.exe
q:\140066.enu\office14\winwordc.exe
c:\program files (x86)\common files\microsoft shared\virtualization handler\officevirt.exe
q:\140066.enu\office14\offspon.exe
c:\program files\sony\vaio care\listener.exe
c:\program files (x86)\mozilla firefox\firefox.exe
c:\program files (x86)\mozilla firefox\plugin-container.exe
c:\program files (x86)\trend micro\hijackthis\hijackthis.exe
r0 - hkcu\software\microsoft\internet explorer\main,start page = about:blank
r1 - hklm\software\microsoft\internet explorer\main,default_page_url = http://go.microsoft.com/fwlink/?linkid=69157
r1 - hklm\software\microsoft\internet explorer\main,default_search_url =
http://go.microsoft.com/fwlink/?linkid=54896
r1 - hklm\software\microsoft\internet explorer\main,search page =
http://go.microsoft.com/fwlink/?linkid=54896
r0 - hklm\software\microsoft\internet explorer\main,start page =
http://go.microsoft.com/fwlink/?linkid=69157
r0 - hklm\software\microsoft\internet explorer\search,searchassistant =
r0 - hklm\software\microsoft\internet explorer\search,customizesearch =
r1 - hkcu\software\microsoft\windows\currentv ersion\internet settings,proxyoverride = *.local
r0 - hkcu\software\microsoft\internet explorer\toolbar,linksfoldername =
o2 - bho: Acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelper shim.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserre cordplugin\ie\rpbrowserrecordplugin.dll
o2 - bho: Ievkbdbho - {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files (x86)\kaspersky lab\kaspersky internet security 2011\ievkbd.dll
o2 - bho: مساعد تسجيل الدخول إلى windows live - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: (no name) - {dbc80044-a445-435b-bc74-9c25c1c588a9} - (no file)
o2 - bho: Windows live toolbar helper - {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files (x86)\windows live\toolbar\wltcore.dll
o2 - bho: Link filter bho - {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files (x86)\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll
o3 - toolbar: &windows live toolbar - {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files (x86)\windows live\toolbar\wltcore.dll
o4 - hklm\..\run: [iastoricon] c:\program files (x86)\intel\intel(r) rapid storage technology\iastoricon.exe
o4 - hklm\..\run: [isbmgr.exe] "c:\program files (x86)\sony\isb utility\isbmgr.exe"
o4 - hklm\..\run: [startccc] "c:\program files (x86)\ati technologies\ati.ace\core-static\clistart.exe" msrun
o4 - hklm\..\run: [nortononlinebackupreminder] "c:\program files (x86)\symantec\norton online backup\activation\nobuactivation.exe" unattended
o4 - hklm\..\run: [spysweeperregister] c:\program files (x86)\***root\spy sweeper\uninst\registerspysweeper.exe
o4 - hklm\..\run: [avp] "c:\program files (x86)\kaspersky lab\kaspersky internet security 2011\avp.exe"
o4 - hklm\..\run: [quicktime task] "c:\program files (x86)\quicktime\qttask.exe" -atboottime
o4 - hklm\..\run: [tkbellexe] "c:\program files (x86)\real\realplayer\update\realsched.e xe" -osboot
o4 - hklm\..\run: [applesyncnotifier] c:\program files (x86)\common files\apple\mobile device support\applesyncnotifier.exe
o4 - hklm\..\run: [itune****per] "c:\program files (x86)\itunes\itune****per.exe"
o4 - hklm\..\run: [plusservice] c:\program files (x86)\yuna software\messenger plus!\plusservice.exe
o4 - hkcu\..\run: [msnmsgr] "c:\program files (x86)\windows live\messenger\msnmsgr.exe" /background
o4 - hkcu\..\run: [sidebar] c:\program files\windows sidebar\sidebar.exe /autorun
o4 - hkus\s-1-5-19\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /autorun (user 'local service')
o4 - hkus\s-1-5-19\..\runonce: [mctadmin] c:\windows\system32\mctadmin.exe (user 'local service')
o4 - hkus\s-1-5-20\..\run: [sidebar] %programfiles%\windows sidebar\sidebar.exe /autorun (user 'network service')
o4 - hkus\s-1-5-20\..\runonce: [mctadmin] c:\windows\system32\mctadmin.exe (user 'network service')
o4 - startup: Ela-salaty.lnk = c:\program files (x86)\ela-salaty\salaty.exe
o4 - global startup: Adobe gamma loader.lnk = c:\program files (x86)\common files\adobe\calibration\adobe gamma loader.exe
o4 - global startup: Bluetooth.lnk = ?
O8 - extra con**** menu item: Google sidewiki... - res://c:\program files (x86)\google\google toolbar\component\googletoolbardynamic_m ui_en_70c5b381380db17f.dll/cmsidewiki.html
o8 - extra con**** menu item: إضافة إلى مكافحة الشعارات - c:\program files (x86)\kaspersky lab\kaspersky internet security 2011\ie_banner_deny.htm
o8 - extra con**** menu item: جاري إرسال الصفحة إلى &جهاز bluetooth... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o8 - extra con**** menu item: جاري إرسال الصورة إلى &جهاز bluetooth... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
o9 - extra button: تدوين هذا في المدونة - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files (x86)\windows live\writer\writerbrowserextension.dll
o9 - extra 'tools' menuitem: &تدوين هذا في windows live writer - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - c:\program files (x86)\windows live\writer\writerbrowserextension.dll
o9 - extra button: &لوحة المفاتيح الظاهرية - {4248fe82-7fcb-46ac-b270-339f08212110} - c:\program files (x86)\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll
o9 - extra button: Send to bluetooth - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o9 - extra 'tools' menuitem: Send to &bluetooth device... - {cca281ca-c863-46ef-9331-5c8d4460577f} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
o9 - extra button: فحص &عناوين المواقع (url) - {ccf151d8-d089-449f-a5a4-d9909053f20f} - c:\program files (x86)\kaspersky lab\kaspersky internet security 2011\klwtbbho.dll
o9 - extra button: Add to evernote - {e0b8c461-f8fb-49b4-8373-fe32e92528a6} - c:\program files (x86)\evernote\evernote3.5\enbar.dll
o9 - extra 'tools' menuitem: Add to evernote - {e0b8c461-f8fb-49b4-8373-fe32e92528a6} - c:\program files (x86)\evernote\evernote3.5\enbar.dll
o13 - gopher prefix:
O18 - protocol: Skype4com - {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - c:\progra~2\common~1\skype\skype4~1.dll
o20 - appinit_dlls: C:\progra~2\kasper~1\kasper~1\mzvkbd3.dl l, c:\progra~2\kasper~1\kasper~1\sbhook.dll
o23 - service: Arcsoft connect daemon (acdaemon) - arcsoft inc. - c:\program files (x86)\common files\arcsoft\connection service\bin\acservice.exe
o23 - service: Adobe active file monitor v8 (adobeactivefilemonitor8.0) - adobe systems incorporated - c:\program files (x86)\adobe\elements organizer 8.0\photoshopelementsfileagent.exe
o23 - service: @%systemroot%\system32\alg.exe,-112 (alg) - unknown owner - c:\windows\system32\alg.exe (file missing)
o23 - service: Amd external events utility - unknown owner - c:\windows\system32\atiesrxx.exe (file missing)
o23 - service: Apple mobile device - apple inc. - c:\program files (x86)\common files\apple\mobile device support\applemobiledeviceservice.exe
o23 - service: خدمة kaspersky لمكافحة الفيروسات (avp) - kaspersky lab zao - c:\program files (x86)\kaspersky lab\kaspersky internet security 2011\avp.exe
o23 - service: Bonjour service - apple inc. - c:\program files (x86)\bonjour\mdnsresponder.exe
o23 - service: Bluetooth service (btwdins) - broadcom corporation. - c:\program files\widcomm\bluetooth software\btwdins.exe
o23 - service: @%systemroot%\system32\efssvc.dll,-100 (efs) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: Intel(r) proset/wireless event log (evteng) - intel(r) corporation - c:\program files\intel\wifi\bin\evteng.exe
o23 - service: @%systemroot%\system32\fxsresm.dll,-118 (fax) - unknown owner - c:\windows\system32\fxssvc.exe (file missing)
o23 - service: Flexnet licensing service - acresso software inc. - c:\program files (x86)\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe
o23 - service: خدمة تحديث google (gupdate) (gupdate) - google inc. - c:\program files (x86)\google\update\googleupdate.exe
o23 - service: خدمة google update (gupdatem) (gupdatem) - google inc. - c:\program files (x86)\google\update\googleupdate.exe
o23 - service: Intel(r) rapid storage technology (iastordatamgrsvc) - intel corporation - c:\program files (x86)\intel\intel(r) rapid storage technology\iastordatamgrsvc.exe
o23 - service: Ipod service - apple inc. - c:\program files\ipod\bin\ipodservice.exe
o23 - service: @keyiso.dll,-100 (keyiso) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: Intel(r) management and security application local management service (lms) - intel corporation - c:\program files (x86)\intel\intel(r) management engine components\lms\lms.exe
o23 - service: @comres.dll,-2797 (msdtc) - unknown owner - c:\windows\system32\msdtc.exe (file missing)
o23 - service: @%systemroot%\system32\netlogon.dll,-102 (netlogon) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\psbase.dll,-300 (protectedstorage) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: Intel(r) proset/wireless registry service (regsrvc) - intel(r) corporation - c:\program files\common files\intel\wirelesscommon\regsrvc.exe
o23 - service: Roxio upnp renderer 10 - sonic solutions - c:\program files (x86)\roxio\digital home 10\roxioupnprenderer10.exe
o23 - service: Roxio upnp server 10 - sonic solutions - c:\program files (x86)\roxio\digital home 10\roxioupnpservice10.exe
o23 - service: @%systemroot%\system32\locator.exe,-2 (rpclocator) - unknown owner - c:\windows\system32\locator.exe (file missing)
o23 - service: Vaio care performance service (samplecollector) - sony corporation - c:\program files\sony\vaio care\vcperfservice.exe
o23 - service: @%systemroot%\system32\samsrv.dll,-1 (samss) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: @%systemroot%\system32\snmptrap.exe,-3 (snmptrap) - unknown owner - c:\windows\system32\snmptrap.exe (file missing)
o23 - service: Vaio media plus ******* importer (sohcimp) - sony corporation - c:\program files (x86)\common files\sony shared\sohlib\sohcimp.exe
o23 - service: Vaio media plus database manager (sohdbsvr) - sony corporation - c:\program files (x86)\common files\sony shared\sohlib\sohdbsvr.exe
o23 - service: Vaio media plus digital media server (sohdms) - sony corporation - c:\program files (x86)\common files\sony shared\sohlib\sohdms.exe
o23 - service: Vaio media plus device searcher (sohds) - sony corporation - c:\program files (x86)\common files\sony shared\sohlib\sohds.exe
o23 - service: Vaio media plus playlist manager (sohplmgr) - sony corporation - c:\program files (x86)\common files\sony shared\sohlib\sohplmgr.exe
o23 - service: @%systemroot%\system32\spoolsv.exe,-1 (spooler) - unknown owner - c:\windows\system32\spoolsv.exe (file missing)
o23 - service: @%systemroot%\system32\sppsvc.exe,-101 (sppsvc) - unknown owner - c:\windows\system32\sppsvc.exe (file missing)
o23 - service: Cammonitor (ucammonitor) - arcsoft, inc. - c:\program files (x86)\arcsoft\magic-i visual effects 2\ucammonitor.exe
o23 - service: @%systemroot%\system32\ui0detect.exe,-101 (ui0detect) - unknown owner - c:\windows\system32\ui0detect.exe (file missing)
o23 - service: Intel(r) management & security application user notification service (uns) - intel corporation - c:\program files (x86)\intel\intel(r) management engine components\uns\uns.exe
o23 - service: Vaio entertainment tv device arbitration service - sony corporation - c:\program files (x86)\common files\sony shared\vaio entertainment platform\vzhardwareresourcemanager\vzhar dwareresourcemanager\vzhardwareresourcem anager.exe
o23 - service: Vaio event service - sony corporation - c:\program files (x86)\sony\vaio event service\vesmgr.exe
o23 - service: Vaio power management - sony corporation - c:\program files\sony\vaio power management\spmservice.exe
o23 - service: @%systemroot%\system32\vaultsvc.dll,-1003 (vaultsvc) - unknown owner - c:\windows\system32\lsass.exe (file missing)
o23 - service: Vaio ******* folder watcher (vcfw) - sony corporation - c:\program files (x86)\common files\sony shared\vaio ******* folder watcher\vcfw.exe
o23 - service: Vaio ******* ****data intelligent analyzing manager (vcmialzmgr) - sony corporation - c:\program files\sony\vcm intelligent analyzing manager\vcmialzmgr.exe
o23 - service: Vaio ******* ****data intelligent network service manager (vcminsmgr) - sony corporation - c:\program files\sony\vcm intelligent network service manager\vcminsmgr.exe
o23 - service: Vaio ******* ****data xml interface (vcmxmlifhelper) - sony corporation - c:\program files\common files\sony shared\vcmxml\vcmxmlifhelper64.exe
o23 - service: Vcservice - sony corporation - c:\program files\sony\vaio care\vcservice.exe
o23 - service: @%systemroot%\system32\vds.exe,-100 (vds) - unknown owner - c:\windows\system32\vds.exe (file missing)
o23 - service: @%systemroot%\system32\vssvc.exe,-102 (vss) - unknown owner - c:\windows\system32\vssvc.exe (file missing)
o23 - service: Vuagent - sony corporation - c:\program files\sony\vaio update 5\vuagent.exe
o23 - service: Vaio entertainment database service (vzcdbsvc) - sony corporation - c:\program files (x86)\common files\sony shared\vaio entertainment platform\vzcdb\vzcdbsvc.exe
o23 - service: @%systemroot%\system32\wat\watux.exe,-601 (watadminsvc) - unknown owner - c:\windows\system32\wat\watadminsvc.exe (file missing)
o23 - service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - unknown owner - c:\windows\system32\wbengine.exe (file missing)
o23 - service: @%systemroot%\system32\wbem\wmiapsrv.exe ,-110 (wmiapsrv) - unknown owner - c:\windows\system32\wbem\wmiapsrv.exe (file missing)
o23 - service: @%programfiles%\windows media player\wmpnetwk.exe,-101 (wmpnetworksvc) - unknown owner - c:\program files (x86)\windows media player\wmpnetwk.exe (file missing)
--
end of file - 15162 bytes
تستطيع المشاركة هنا والرد على الموضوع ومشاركة رأيك عبر حسابك في الفيس بوك
;lfd,jvd f'd