COMPAQ99

زيزوومى فعال
إنضم
14 أكتوبر 2010
المشاركات
210
مستوى التفاعل
6
النقاط
280
غير متصل
السلام عليكم

اليوم فاجئني بمشكلتين ولم اتطيع حلها .. هو .. عند التحليل لبرنامج CCleaner تجيلي ها الرساله ويقفل البرنامج على طول !!

d003f589bf1d30f866a158517a6a6b56.png



وعند حذف برنامج Recover My Files Pro v4.6.8.1012 Preactivated تجيلي بعد ها الرساله

114b0d455af7d2ef53bcaeaa148ca352.png




ولآ أعرف ما السبب !؟
 

اخي العزيز قم بعمل اللي موجود في هذا الموضوع

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


لا تقلي ما عنده دخل لان هذه الصورة ضهرتلي قبلك وعملت اللي في الموضوع بعدين تم كل شيء
واذا ما تصلح البرنامج عيد نصبه
بالنسبة للمشكلة الثانية البرنامج ما تنصب كامل عشان ينحذف هذه المشكلة
 
توقيع : Hmammou
متآكد يا الغالي من الحل !
 
ايه والله حبيبي
 
توقيع : Hmammou
! ما نفعت !
 
UP
 
UP
 
UP
 
حمل الاداة من هذا الموضوع

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي



واعمل تقرير هايجاك

------------------

3b3ce221851b60a78bfa55cbd704e323.jpg
 
تفضل ..

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:57:56 م, on 19/03/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winlbbkqb.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\w7c06f.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TechSmith\Snagit 9\Snagit32.exe
C:\Program Files\TechSmith\Snagit 9\TSCHelp.exe
C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe
C:\Program Files\TechSmith\Snagit 9\snagiteditor.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Zyzoom_Forum_Tools\zHijak.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


O1 - Hosts: 205.199.44.156 registeridm.com
O1 - Hosts: 205.199.44.16 registeridm.com
O2 - BHO: (no name) - {0010BB0C-2F85-46C3-B06A-0F87BB08646C} - @x.dllorkerW (file missing)
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: ت&صدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى FLV بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) -

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


O16 - DPF: {7253A666-804A-1107-A4DC-00E04C504780} (BMC Control) -

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


O16 - DPF: {7253A666-804A-1107-A4DC-00E04C504788} (BMC Control) -

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


O16 - DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} (ReadUid.UserControlMacEntry) -

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 7311 bytes
 
تفضل

************' Anti-Malware 1.50.1.1100

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي



Database version: 6046

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

20/03/2011 01:00:40 ص
mbam-log-2011-03-20 (01-00-40).txt

Scan type: Full scan (C:\|H:\|)
Objects scanned: 179401
Time elapsed: 25 minute(s), 22 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 5
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 40

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\WINDOWS\system32\@x.dllorkerw (IPH.GenericBHO) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{0010BB0C-2F85-46C3-B06A-0F87BB08646C} (IPH.GenericBHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0010BB0C-2F85-46C3-B06A-0F87BB08646C} (IPH.GenericBHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0010BB0C-2F85-46C3-B06A-0F87BB08646C} (IPH.GenericBHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_AMSINT32 (Virus.Sality) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint32 (Virus.Sality) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{0010BB0C-2F85-46C3-B06A-0F87BB08646C} (IPH.GenericBHO) -> Value: {0010BB0C-2F85-46C3-B06A-0F87BB08646C} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{0010BB0C-2F85-46C3-B06A-0F87BB08646C} (Trojan.Downloader) -> Value: {0010BB0C-2F85-46C3-B06A-0F87BB08646C} -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\@x.dllorkerw (IPH.GenericBHO) -> Delete on reboot.
c:\mjush.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\program files\GetData\recover my files v4\armaccess.dll (Malware.Packer) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP44\A0032881.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP44\A0033166.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP44\A0033469.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP44\A0033578.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP44\A0033778.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP44\A0034777.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0035097.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0035177.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0036180.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0036451.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0036691.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0036757.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0037116.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0037410.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP46\A0037704.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP46\A0037803.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP46\A0038079.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP46\A0038393.pif (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\nknwc.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP44\A0032875.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP44\A0033152.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP44\A0033455.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP44\A0033564.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP44\A0033764.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP44\A0034763.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0035091.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0035163.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0036193.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0036438.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0036677.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0036789.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0037102.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP45\A0037394.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP46\A0037699.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP46\A0037789.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP46\A0038065.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{a02785f2-4f59-4abb-81ee-4e44f61649d6}\RP46\A0038378.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.




 
up
 
وجاري عمل الفحص ..
 
لم تنفع ..
 
up
 
ياغالي ..

عطل استعاذه النظام وادخل الوضع الامن واعمل فحص
 
توقيع : YHYA -KSA

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


وهذه مشكلة ثااانيه بعد .. يا الخوي ما يبغى يدخل على الوضع الامن كل ما اسوي يعيد التشغيل تلقائيا !
 
وعليكم السلام ورحمة الله وبركاته

أولا قم بتحميل هذا الملف

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي





و تقرير مالاوري جديد اذا سمحت
 
عودة
أعلى