• بادئ الموضوع بادئ الموضوع yahya1
  • تاريخ البدء تاريخ البدء
  • المشاهدات 1,178

yahya1

زيزوومي جديد
إنضم
23 يناير 2008
المشاركات
7
مستوى التفاعل
0
النقاط
0
غير متصل
عند دخولي على عنواني الالكتروني سواء لدى الياهو او الهوتميل
الخطوط لا تكون واضحة اضافة الى ايقونات غريبة في قائمة الرسائل كما انه لا يمكنني مسح الرسائل الغير مرغوب بها
وعند فتح الرسالة لا تظهر المرفقات من صور او غيرها
اعتقدت ان المشكلة من الاكسبلورر ولكني نزلت نسخة جديدة وما زالت المشكلة كما هي
علما ان المشكلة لا توجد عند فتح بريد الجوجل

افيدوني ولكم الشكر
 

حمل هذا البرنامج

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


اذا انتهى التحميل ==> شغل البرنامج ==> واضغط على Do a system scan and save log
لحظات .. ويظهر لك تقرير ==> انسخه والصقه بردك القادم
 
هذا تقرير الكومبوفيكس

ComboFix 08-06-08.7 - Administrator 2008-06-09 12:47:52.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.968.1033.18.77 [GMT 4:00]
Running from: C:\Documents and Settings\Administrator.GH2007-A80566F6\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\tazebama
C:\Documents and Settings\Administrator\Application Data\tazebama\zPharaoh.dat
C:\Documents and Settings\FSH037\Application Data\HbTools
C:\Documents and Settings\FSH037\Application Data\HbTools\eskin\empty_bg_st.htm
C:\Documents and Settings\FSH037\Application Data\HbTools\eskin\FileManager.txt
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\1.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\1055531.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\1065003.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\1210754.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\1402514.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\1405095.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\1420235.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\2208948.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\2883904.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\2884334.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\2885069.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\2896152.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\566217.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\600583.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\625696.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\716566.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\805478.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\890068.sdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\ASPL1.dat
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\domains.txt
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\13546
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\1369
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\17025
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\18721
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\19650
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\2021
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\20517
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\258537
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\27503
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\3009
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\34123
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\34186
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\35047
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\398397
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\40766
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\41999
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\44228
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\44730
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\44878
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\45833
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\48525
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\52335
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\526389
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\531510
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\54189
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\56815
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\56907
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\5749
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\578081
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\578140
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\578150
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\591951
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\59844
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\64222
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\64223
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\64224
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\64517
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\6458
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\6468
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\67226
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\68021
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\6915
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\73905
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\85062
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\86379
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\87304
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\87385
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\90358
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\95610
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\97499
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\99008
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\dynamic\ustat\3291.dat
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\ads.cdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\business_promo.htm
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\buttondir.txt
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\components.cdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_1000.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_2000.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_3000.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bar.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar1.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar10.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar11.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar12.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar13.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar14.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar2.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar3.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar4.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar5.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar6.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar7.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar8.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar9.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_logos.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_other.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_x.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_weather.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\default.cdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_511745-514279.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_categorize.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_comparison.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_explorer-Mails.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_explorer-people.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_favorites.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_Games.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_Hide.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_hotbarcom.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_Hotmail.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_hsskin.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_Mails.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_new.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_premium.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_ringtone.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_SearchBoxTrapper.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_searchfor.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_searchgo.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_weather.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Default_yellowpages.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\email-def-511724-548964.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\email-def-511724-9595.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\email-t1-bg.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\hotbar-premium-hotbar-premium.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\hotbar-premium.cdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\hotbar_promo.htm
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\icons2.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\keywords.idx
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\keywords1.dat
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\layout.cdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\linkpathlegal.txt
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\progress.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\s_icons_buttons.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\t2_bg.res
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\theweb.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\top7.cdf
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\Top7_theweb.mnu
C:\Documents and Settings\FSH037\Application Data\HbTools\v3.0\HbTools\static\1\tsd_bg.res
C:\Documents and Settings\FSH037\Local Settings\Temporary Internet Files\loader.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NWSAPAGENT
-------\Service_NwSapAgent

((((((((((((((((((((((((( Files Created from 2008-05-09 to 2008-06-09 )))))))))))))))))))))))))))))))
.
2008-06-09 10:25 . 2008-03-01 17:06 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-06-09 10:25 . 2007-04-17 13:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-06-09 10:25 . 2007-03-08 09:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-06-09 10:25 . 2008-03-01 17:06 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-06-09 10:25 . 2008-03-01 17:06 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-06-09 10:25 . 2008-03-01 17:06 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-06-09 10:25 . 2008-03-01 17:06 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-06-09 10:25 . 2008-03-01 17:06 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-06-09 10:25 . 2008-02-22 14:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-09 07:43 . 2008-06-09 07:43 <DIR> d----c--- C:\Documents and Settings\All Users.WINDOWS\Application Data\Flood Light Games
2008-06-09 07:08 . 2008-06-09 07:08 <DIR> d----c--- C:\Documents and Settings\Administrator.GH2007-A80566F6\Application Data\Flood Light Games
2008-06-08 13:13 . 2008-06-08 13:13 1,169 --a------ C:\WINDOWS\Active Setup Log.BAK
2008-06-04 07:39 . 2008-06-09 13:18 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-04 07:39 . 2008-06-09 12:54 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-24 11:44 . 2008-05-24 11:44 91 --a------ C:\WINDOWS\pdf2rtf.INI
2008-05-24 11:41 . 2008-05-24 11:42 1,024 --a------ C:\WINDOWS\system32\pdf2word.DAT
2008-05-24 11:40 . 2008-05-24 11:40 <DIR> d-------- C:\Program Files\PDF2Word v1.6
2008-05-10 10:22 . 2008-05-10 10:37 <DIR> d----c--- C:\Documents and Settings\Administrator.GH2007-A80566F6\Application Data\U3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-09 03:42 --------- dc----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2008-06-09 03:29 --------- dc--a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-06-09 03:07 --------- d-----w C:\Program Files\MSN Games
2008-04-29 10:08 --------- d-----w C:\Program Files\IVT Corporation
2008-04-27 04:56 667 -c-ha-w C:\os848618.bin
2008-04-27 04:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-27 04:27 --------- d-----w C:\Program Files\Common Files\Adobe
2007-01-10 08:32 47,400 -c--a-w C:\Documents and Settings\Administrator.GH2007-A80566F6\Application Data\GDIPFONTCACHEV1.DAT
1998-12-08 23:53 99,840 -c--a-w C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-08 23:53 70,144 -c--a-w C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-08 23:53 48,640 -c--a-w C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-08 23:53 31,744 -c--a-w C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-08 23:53 186,368 -c--a-w C:\Program Files\Common Files\IRAREG.DLL
1998-12-08 23:53 17,920 -c--a-w C:\Program Files\Common Files\IRASRIAL.DLL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:56 15360]
"FlyAway"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-04-05 18:22 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-04-05 18:19 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-04-05 18:23 114688]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50 139320]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43 83608]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-10 13:02 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-13 12:59 77824]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-09-17 01:27 52848]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:56 15360]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45 36040]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
desktop(2).ini [2004-06-27 10:52:39 84]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoRun"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e252fc7-1d49-11dc-acf5-101111111111}]
\Shell\AutoRun\command - RavMon.exe
\Shell\explore\Command - RavMon.exe -e
\Shell\open\Command - RavMon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{248584ad-debd-11dc-adce-000bcd30678b}]
\Shell\AutoRun\command - F:\8ng8w.com
\Shell\explore\Command - F:\8ng8w.com
\Shell\open\Command - F:\8ng8w.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2f0a949c-efdd-11db-acdd-101111111111}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{452cbfb6-f97c-11dc-ade3-000bcd30678b}]
\Shell\AutoRun\command - F:\fooool.exe
\Shell\explore\Command - F:\fooool.exe
\Shell\open\Command - F:\fooool.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6b97b321-1e4a-11dd-ae10-000bcd30678b}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a713ff83-20a5-11dd-ae13-000bcd30678b}]
\Shell\AutoRun\command - F:\8ng8w.com
\Shell\explore\Command - F:\8ng8w.com
\Shell\open\Command - F:\8ng8w.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c44cf85e-601d-11dc-ad4c-101111111111}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8a45168-e4e7-11dc-add4-000bcd30678b}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc1f3177-a88f-11dc-ad8b-000bcd30678b}]
\Shell\AutoRun\command - RavMon.exe
\Shell\explore\Command - RavMon.exe -e
\Shell\open\Command - RavMon.exe
.
s of the 'Scheduled Tasks' folder
"2008-02-16 05:16:37 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Administrator.job"
- C:\PROGRA~1\NORTON~1\Navw32.exep/TASK:
"2008-06-09 09:22:19 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Rootkit scan 2008-06-09 13:17:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Real\RealPlayer\realplay.exe
.
**************************************************************************
.
Completion time: 2008-06-09 13:25:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-09 09:24:49
Pre-Run: 8,317,587,456 bytes free
Post-Run: 9,733,398,528 bytes free
297
 
وهذا تقرير الهاي جاك
Logfile of HijackThis v1.99.1
Scan saved at 1:32:16 PM, on 6/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\DOCUME~1\ADMINI~1.GH2\LOCALS~1\Temp\Rar$EX00.015\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.137.10.9:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {34F12AFD-E9B5-492A-85D2-40FA4535BE83} -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = maf.com
O17 - HKLM\Software\..\Telephony: DomainName = maf.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = maf.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = maf.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
وينك the fantasy
انتظر الحل لجهازي
ولا تأخذني تراه جهاز العمل
وعذرا ممكن ازعجناك
 
اشوف التقرير وارجع ان شاء الله

واداة الكومبواا حاذفة ملفات كثيرة جداا !!
 
احذف هالقيم

O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - (no file)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = maf.com

O17 - HKLM\Software\..\Telephony: DomainName = maf.com

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = maf.com

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = maf.com

طريقة الحذف

wh_31752766.png


ثم نزل هالاداة لتنظيف الجهاز

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


wh_15149054.png


اعد التشغيل وشوف تروح المشكلة لو استمرت نزل هالاداة وشغلها

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
 
مشكورين اخواني بس المشكلة ما زالت قائمة
ايضا لاحظت عند محاولتي لاتباع وصلة (لينك) في صفحة اخرى تفتح الصفحة على العنوان
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

دائما تفتح ها الصفحة عند محاولتي فتح لينك في نافذة اخرى
عندها يعلق الاكسبولورر حتى مؤشر الفارة يهتز بنفسه
نزلت كل الادوات وفعلتها واعدت تشغيل الجهاز بس المشكلة ما زالت
 
عودة
أعلى