منتديات المجاوشي

منتديات المجاوشي (http://www.vb.mjawshy.net/index.php)
-   Arabic Rss (http://www.vb.mjawshy.net/forumdisplay.php?f=41)
-   -   هل جهازي مخترق ! (http://www.vb.mjawshy.net/showthread.php?t=237302)

RSS 10-07-2011 09:29 AM

هل جهازي مخترق !
 
السلام عليكم ورحمة الله وبركاته

قبل شوي ارسلي شخص رابط معين دخلته ,,والمفروض انه كان فيديو . لقيت صوره فقط

حاب اعرف اذا كان جهازي مخترق ولا
وتسلمون

تقرير هايجاك
ملحوظه : القيم رقم 17 تم حذفها اكثر من مره ولكن تعاود الظهور ما هي بالضبط



كود PHP:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 07
:49:34 ص, on 07/10/2011
Platform
: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes
:
C:\Windows\system32\Dwm.exe
C
:\Windows\system32\taskhost.exe
C
:\Windows\Explorer.EXE
C
:\Program Files\Alwil Software\Avast4\ashDisp.exe
C
:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C
:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C
:\Program Files\Common Files\Java\Java Update\jusched.exe
C
:\Program Files\iTunes\iTunesHelper.exe
C
:\Windows\System32\igfxtray.exe
C
:\Windows\System32\hkcmd.exe
C
:\Windows\System32\igfxpers.exe
E
:\Ahmed\بـــرامـــج\PRO NEW PC\Download\Internet Download Manager v6.04.3 - Crack (Shaam)-{IARG}_2\crack\IDMan.exe
C
:\Program Files\DeskSpace\deskspace.exe
C
:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C
:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C
:\Program Files\Paltalk Messenger\paltalk.exe
C
:\Program Files\Ralink\Common\RaUI.exe
C
:\Program Files\Etisalat 3.5G USB Modem\Etisalat 3.5G USB Modem.exe
C
:\Windows\system32\DllHost.exe
C
:\Windows\system32\NOTEPAD.EXE
C
:\Program Files\Mozilla Firefox\firefox.exe
C
:\Windows\system32\NOTEPAD.EXE
C
:\Windows\system32\NOTEPAD.EXE
C
:\Windows\system32\NOTEPAD.EXE
C
:\Program Files\Mozilla Firefox\plugin-container.exe
C
:\Program Files\Mozilla Firefox\plugin-container.exe
C
:\Program Files\Palringo\palringo.exe
C
:\zyzooom\zyzoom.exe
C
:\zyzooom\zHijak.com

R1
- HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - E:\Ahmed\بـــرامـــج\PRO NEW PC\Download\Internet Download Manager v6.04.3 - Crack (Shaam)-{IARG}_2\crack\IDMIECC.dll
O2
- BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2
- BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2
- BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4
- HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4
- HKLM\..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4
- HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4
- HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4
- HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4
- HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4
- HKCU\..\Run: [IDMan] E:\Ahmed\بـــرامـــج\PRO NEW PC\Download\Internet Download Manager v6.04.3 - Crack (Shaam)-{IARG}_2\crack\IDMan.exe /onboot
O4
- HKCU\..\Run: [Google Update] "C:\Users\maka\AppData\Local\Google\Update\GoogleU pdate.exe" /c
O4
- HKCU\..\Run: [DeskSpace] C:\Program Files\DeskSpace\deskspace.exe
O4
- HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4
- Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
O4
- Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\Ralink\Common\RaUI.exe
O8
- Extra context menu item: Download all links with IDM - E:\Ahmed\بـــرامـــج\PRO NEW PC\Download\Internet Download Manager v6.04.3 - Crack (Shaam)-{IARG}_2\crack\IEGetAll.htm
O8
- Extra context menu item: Download FLV video content with IDM - E:\Ahmed\بـــرامـــج\PRO NEW PC\Download\Internet Download Manager v6.04.3 - Crack (Shaam)-{IARG}_2\crack\IEGetVL.htm
O8
- Extra context menu item: Download with IDM - E:\Ahmed\بـــرامـــج\PRO NEW PC\Download\Internet Download Manager v6.04.3 - Crack (Shaam)-{IARG}_2\crack\IEExt.htm
O8
- Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8
- Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9
- Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9
- Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9
- Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9
- Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10
- Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10
- Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O17
- HKLM\System\CCS\Services\Tcpip\..\{700342B8-033B-44BA-B228-903919699C5D}: NameServer = 197.199.255.254 217.52.47.130
O18
- Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GRA32A~1.DLL
O23
- Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23
- Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23
- Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23
- Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23
- Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23
- Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23
- Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23
- Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23
- Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23
- Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23
- Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23
- Service: RalinkRegistryWriter - Ralink Technology, Corp. - C:\Program Files\Ralink\Common\RaRegistry.exe
O23
- Service: Ralink UPnP Media Server (RaMediaServer) - Unknown owner - C:\Program Files\Ralink\Common\RaMediaServer.exe

--
End of file - 8385 bytes



الموضوع الأساسي: هل جهازي مخترق !
المصدر: زيزوووم للأمن والحماية








أكثر...


الساعة الآن 11:55 PM

Powered by vBulletin® Copyright ©2000 - 2025, Jelsoft Enterprises Ltd. منتديات بلاك بيري mjawshy.net
المجاوشي للتقنية المتقدمة