REGEDIT4
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters]
"NV Hostname"="sr"
"DataBasePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53, 79,73,74,65,6d,\
33,32,5c,64,72,69,76,65,72,73,5c,65,74,63,00
"ForwardBroadcasts"=dword:00000000
"IPEnableRouter"=dword:00000000
"Domain"=""
"Hostname"="sr"
"SearchList"=""
"UseDomainNameDevolution"=dword:00000000
"EnableICMPRedirect"=dword:00000001
"DeadGWDetectDefault"=dword:00000001
"DontAddDefaultGatewayDefault"=dword:00000000
"EnableSecurityFilters"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\Adapters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\Adapters\NdisWanIp]
"LLInterface"="WANARP"
"IpConfig"=hex(7):54,63,70,69,70,5c,50,61,72,61,6d,65,74,65, 72,73,5c,49,6e,74,\
65,72,66,61,63,65,73,5c,7b,33,37,35,44,37,30,43,36 ,2d,42,36,44,46,2d,34,39,\
43,37,2d,42,41,38,43,2d,32,36,37,45,34,41,39,31,34 ,37,37,35,7d,00,54,63,70,\
69,70,5c,50,61,72,61,6d,65,74,65,72,73,5c,49,6e,74 ,65,72,66,61,63,65,73,5c,\
7b,35,44,45,30,39,30,43,36,2d,43,38,46,34,2d,34,45 ,46,44,2d,39,35,33,34,2d,\
44,45,38,44,32,37,33,38,42,30,41,32,7d,00,54,63,70 ,69,70,5c,50,61,72,61,6d,\
65,74,65,72,73,5c,49,6e,74,65,72,66,61,63,65,73,5c ,7b,39,45,35,41,45,43,36,\
36,2d,46,39,36,33,2d,34,33,43,34,2d,38,39,42,41,2d ,36,33,36,32,41,37,30,30,\
46,37,41,37,7d,00,54,63,70,69,70,5c,50,61,72,61,6d ,65,74,65,72,73,5c,49,6e,\
74,65,72,66,61,63,65,73,5c,7b,34,36,35,31,43,32,30 ,43,2d,37,44,34,33,2d,34,\
35,35,34,2d,42,34,46,45,2d,32,44,42,41,39,33,45,34 ,41,44,34,41,7d,00,00
"NumInterfaces"=dword:00000004
"IpInterfaces"=hex:c6,70,5d,37,df,b6,c7,49,ba,8c,26,7e,4a,91,47, 75,c6,90,e0,5d,\
f4,c8,fd,4e,95,34,de,8d,27,38,b0,a2,66,ec,5a,9e,63 ,f9,c4,43,89,ba,63,62,a7,\
00,f7,a7,0c,c2,51,46,43,7d,54,45,b4,fe,2d,ba,93,e4 ,ad,4a
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\Adapters\{78AA8FA7-86E0-4736-9FE3-857ED3712B26}]
"LLInterface"=""
"IpConfig"=hex(7):54,63,70,69,70,5c,50,61,72,61,6d,65,74,65, 72,73,5c,49,6e,74,\
65,72,66,61,63,65,73,5c,7b,37,38,41,41,38,46,41,37 ,2d,38,36,45,30,2d,34,37,\
33,36,2d,39,46,45,33,2d,38,35,37,45,44,33,37,31,32 ,42,32,36,7d,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\Adapters\{8D8C23CC-2CEB-49F2-85C2-944BA5700AE5}]
"LLInterface"=""
"IpConfig"=hex(7):54,63,70,69,70,5c,50,61,72,61,6d,65,74,65, 72,73,5c,49,6e,74,\
65,72,66,61,63,65,73,5c,7b,38,44,38,43,32,33,43,43 ,2d,32,43,45,42,2d,34,39,\
46,32,2d,38,35,43,32,2d,39,34,34,42,41,35,37,30,30 ,41,45,35,7d,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\Adapters\{93CCFF0B-6D57-4B25-A894-7A03F7AF4A65}]
"LLInterface"=""
"IpConfig"=hex(7):54,63,70,69,70,5c,50,61,72,61,6d,65,74,65, 72,73,5c,49,6e,74,\
65,72,66,61,63,65,73,5c,7b,39,33,43,43,46,46,30,42 ,2d,36,44,35,37,2d,34,42,\
32,35,2d,41,38,39,34,2d,37,41,30,33,46,37,41,46,34 ,41,36,35,7d,00,00
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\DNSRegisteredAdapters]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\Interfaces]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\Interfaces\{375D70C6-B6DF-49C7-BA8C-267E4A914775}]
"UseZeroBroadcast"=dword:00000000
"EnableDHCP"=dword:00000000
"IPAddress"=hex(7):30,2e,30,2e,30,2e,30,00,00
"SubnetMask"=hex(7):30,2e,30,2e,30,2e,30,00,00
"DefaultGateway"=hex(7):00
"EnableDeadGWDetect"=dword:00000001
"DontAddDefaultGateway"=dword:00000000
"NameServer"=""
"DhcpNameServer"=""
"Domain"=""
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\Interfaces\{4651C20C-7D43-4554-B4FE-2DBA93E4AD4A}]
"UseZeroBroadcast"=dword:00000000
"EnableDHCP"=dword:00000000
"IPAddress"=hex(7):30,2e,30,2e,30,2e,30,00,00
"SubnetMask"=hex(7):30,2e,30,2e,30,2e,30,00,00
"DefaultGateway"=hex(7):00
"EnableDeadGWDetect"=dword:00000001
"DontAddDefaultGateway"=dword:00000000
"NTEContextList"=hex(7):30,78,30,30,30,30,30,30,30,33,00,00
"DhcpIPAddress"="80.178.57.247"
"DhcpSubnetMask"="255.255.255.255"
"Domain"=""
"DhcpClassIdBin"=hex:
"RegistrationEnabled"=dword:00000000
"RegisterAdapterName"=dword:00000000
"NameServer"="212.116.161.40 84.95.14.250"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\Interfaces\{5DE090C6-C8F4-4EFD-9534-DE8D2738B0A2}]
"UseZeroBroadcast"=dword:00000000
"EnableDHCP"=dword:00000000
"IPAddress"=hex(7):30,2e,30,2e,30,2e,30,00,00
"SubnetMask"=hex(7):30,2e,30,2e,30,2e,30,00,00
"DefaultGateway"=hex(7):00
"EnableDeadGWDetect"=dword:00000001
"DontAddDefaultGateway"=dword:00000000
"NTEContextList"=hex(7):00
"DhcpIPAddress"="0.0.0.0"
"DhcpSubnetMask"="0.0.0.0"
"Domain"=""
"NameServer"=""
"DhcpClassIdBin"=hex:
"RegistrationEnabled"=dword:00000000
"RegisterAdapterName"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\Interfaces\{78AA8FA7-86E0-4736-9FE3-857ED3712B26}]
"UseZeroBroadcast"=dword:00000000
"EnableDeadGWDetect"=dword:00000001
"EnableDHCP"=dword:00000001
"IPAddress"=hex(7):30,2e,30,2e,30,2e,30,00,00
"SubnetMask"=hex(7):30,2e,30,2e,30,2e,30,00,00
"DefaultGateway"=hex(7):00
"DefaultGatewayMetric"=hex(7):00
"Domain"=""
"RegistrationEnabled"=dword:00000001
"RegisterAdapterName"=dword:00000000
"TCPAllowedPorts"=hex(7):30,00,00
"UDPAllowedPorts"=hex(7):30,00,00
"RawIPAllowedProtocols"=hex(7):30,00,00
"NTEContextList"=hex(7):00
"DhcpClassIdBin"=hex:
"DhcpServer"="255.255.255.255"
"Lease"=dword:00000e10
"LeaseObtainedTime"=dword:46ec1b15
"T1"=dword:46ec221d
"T2"=dword:46ec2763
"LeaseTerminatesTime"=dword:46ec2925
"IPAutoconfigurationAddress"="0.0.0.0"
"IPAutoconfigurationMask"="255.255.0.0"
"IPAutoconfigurationSeed"=dword:00000000
"AddressType"=dword:00000000
"DhcpNameServer"=""
"NameServer"=""
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\Interfaces\{8D8C23CC-2CEB-49F2-85C2-944BA5700AE5}]
"UseZeroBroadcast"=dword:00000000
"EnableDeadGWDetect"=dword:00000001
"EnableDHCP"=dword:00000001
"IPAddress"=hex(7):30,2e,30,2e,30,2e,30,00,00
"SubnetMask"=hex(7):30,2e,30,2e,30,2e,30,00,00
"DefaultGateway"=hex(7):00
"DefaultGatewayMetric"=hex(7):00
"Domain"=""
"RegistrationEnabled"=dword:00000001
"RegisterAdapterName"=dword:00000000
"TCPAllowedPorts"=hex(7):30,00,00
"UDPAllowedPorts"=hex(7):30,00,00
"RawIPAllowedProtocols"=hex(7):30,00,00
"NTEContextList"=hex(7):30,78,30,30,30,30,30,30,30,32,00,00
"DhcpClassIdBin"=hex:
"DhcpServer"="255.255.255.255"
"Lease"=dword:00000000
"LeaseObtainedTime"=dword:46fceaf9
"T1"=dword:46fceaf9
"T2"=dword:46fceaf9
"LeaseTerminatesTime"=dword:7fffffff
"IPAutoconfigurationAddress"="169.254.175.80"
"IPAutoconfigurationMask"="255.255.0.0"
"IPAutoconfigurationSeed"=dword:bc1445fb
"AddressType"=dword:00000001
"NameServer"="84.95.14.250,212.116.161.38"
"DhcpIPAddress"="169.254.175.80"
"DhcpSubnetMask"="255.255.0.0"
"DhcpRetryTime"=dword:00000112
"DhcpRetryStatus"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\Interfaces\{93CCFF0B-6D57-4B25-A894-7A03F7AF4A65}]
"UseZeroBroadcast"=dword:00000000
"EnableDeadGWDetect"=dword:00000001
"EnableDHCP"=dword:00000000
"IPAddress"=hex(7):30,2e,30,2e,30,2e,30,00,00
"SubnetMask"=hex(7):32,35,35,2e,30,2e,30,2e,30,00,00
"DefaultGateway"=hex(7):00
"DefaultGatewayMetric"=hex(7):00
"Domain"=""
"RegistrationEnabled"=dword:00000001
"RegisterAdapterName"=dword:00000001
"TCPAllowedPorts"=hex(7):30,00,00
"UDPAllowedPorts"=hex(7):30,00,00
"RawIPAllowedProtocols"=hex(7):30,00,00
"NTEContextList"=hex(7):30,78,30,30,30,30,30,30,30,33,00,00
"DhcpClassIdBin"=hex:
"DhcpNameServer"=""
"NameServer"=""
"DhcpIPAddress"="0.0.0.0"
"DhcpSubnetMask"="255.0.0.0"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\Interfaces\{9E5AEC66-F963-43C4-89BA-6362A700F7A7}]
"UseZeroBroadcast"=dword:00000000
"EnableDHCP"=dword:00000000
"IPAddress"=hex(7):30,2e,30,2e,30,2e,30,00,00
"SubnetMask"=hex(7):30,2e,30,2e,30,2e,30,00,00
"DefaultGateway"=hex(7):00
"EnableDeadGWDetect"=dword:00000001
"DontAddDefaultGateway"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\PersistentRoutes]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\tcpip\parameters\Winsock]
"UseDelayedAcceptance"=dword:00000000
"HelperDllName"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53, 79,73,74,65,\
6d,33,32,5c,77,73,68,74,63,70,69,70,2e,64,6c,6c,00
"MaxSockAddrLength"=dword:00000010
"MinSockAddrLength"=dword:00000010
"Mapping"=hex:0b,00,00,00,03,00,00,00,02,00,00,00,01,00,00, 00,06,00,00,00,02,\
00,00,00,01,00,00,00,00,00,00,00,02,00,00,00,00,00 ,00,00,06,00,00,00,00,00,\
00,00,00,00,00,00,06,00,00,00,00,00,00,00,01,00,00 ,00,06,00,00,00,02,00,00,\
00,02,00,00,00,11,00,00,00,02,00,00,00,02,00,00,00 ,00,00,00,00,02,00,00,00,\
00,00,00,00,11,00,00,00,00,00,00,00,00,00,00,00,11 ,00,00,00,00,00,00,00,02,\
00,00,00,11,00,00,00,02,00,00,00,03,00,00,00,00,00 ,00,00
לוג ה HIJACKTHIS: