• بادئ الموضوع بادئ الموضوع asdadin
  • تاريخ البدء تاريخ البدء
  • المشاهدات 2,182

asdadin

زيزوومي نشيط
إنضم
25 مارس 2011
المشاركات
123
مستوى التفاعل
4
النقاط
170
غير متصل
السلام عليكم .......
عندي مشكلة في برنامج speedupmypc
ما اقدر اسوي شي فيه اظغط على التسجيل ما يجي شي
واظغط على scan start
ما يجي شي ....
وتجيني رسالة خطا (((عدم ارسال)))
ارجو الأفادة .......
بوركتم ......
 

طيب ليه الناس تقوووول انه يسررررع
فيه ناس تقووول انه غير شي كبير في اجهزتهم
بنعيد من جديد خلاص ......
 

هذا تقرير الهايجاك::الجديد
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 02:18:17 ص, on 01/04/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\WINDOWS\system32\msfeedssync.exe
C:\Zyzoom_Forum_Tools\zHijak.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R3 - URLSearchHook: (no name) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - (no file)
R3 - URLSearchHook: BrotherSoft Extreme Toolbar - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files\BrotherSoft_Extreme\prxtbBrot.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: BrotherSoft Extreme - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files\BrotherSoft_Extreme\prxtbBrot.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: BrotherSoft Extreme Toolbar - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files\BrotherSoft_Extreme\prxtbBrot.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: ت&صدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى FLV بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: &لوحة مفاتيح ظاهرية - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: فحص عناوين المواقع (URL) - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: البرنامج الخفي لذاكرة التخزين المؤقت لفئات المكونات - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 7659 bytes
 
وهذا تقرير سجلات النظام والاخطاء:::::



====== سجل أخطاء النظام ======

Computer Name: USER-D00830FCD2
Event Code: 16
Message: ‏‏تعذر الاتصال: تعذر على Windows الاتصال بخدمة "التحديثات التلقائية" ولذلك لن يتمكن من تنزيل التحديثات وتثبيتها وفقاً للجدول الزمني المحدد. سيتابع Windows محاولة تأسيس الاتصال.

Record Number: 4597
Source Name: Windows Update Agent
Time Written: 20110401100736.000000+180
Event Type: error
User:

Computer Name: USER-D00830FCD2
Event Code: 4226
Message: وصل TCP/IP إلى أقصى حد للأمان بناءاً على محاولات اتصال TCP المتلاحقة.

Record Number: 4579
Source Name: Tcpip
Time Written: 20110401042508.000000+180
Event Type: warning
User:

Computer Name: USER-D00830FCD2
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 4578
Source Name: W32Time
Time Written: 20110401041901.000000+180
Event Type: warning
User:

Computer Name: USER-D00830FCD2
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 4576
Source Name: W32Time
Time Written: 20110122202955.000000+180
Event Type: warning
User:

Computer Name: USER-D00830FCD2
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 4574
Source Name: W32Time
Time Written: 20110718001831.000000+180
Event Type: warning
User:



===== سجل أخطاء البرامج =====

Computer Name: USER-D00830FCD2
Event Code: 60
Message: ‏‏لم يتمكن WMI ADAP من معالجة مكتبات الأداء: 0x80041001

Record Number: 753
Source Name: WinMgmt
Time Written: 20110117070228.000000+180
Event Type: warning
User:

Computer Name: USER-D00830FCD2
Event Code: 60
Message: ‏‏لم يتمكن WMI ADAP من معالجة مكتبات الأداء: 0x80041001

Record Number: 748
Source Name: WinMgmt
Time Written: 20110116143959.000000+180
Event Type: warning
User:

Computer Name: USER-D00830FCD2
Event Code: 60
Message: ‏‏لم يتمكن WMI ADAP من معالجة مكتبات الأداء: 0x80041001

Record Number: 743
Source Name: WinMgmt
Time Written: 20110116125850.000000+180
Event Type: warning
User:

Computer Name: USER-D00830FCD2
Event Code: 60
Message: ‏‏لم يتمكن WMI ADAP من معالجة مكتبات الأداء: 0x80041001

Record Number: 738
Source Name: WinMgmt
Time Written: 20110116060016.000000+180
Event Type: warning
User:

Computer Name: USER-D00830FCD2
Event Code: 60
Message: ‏‏لم يتمكن WMI ADAP من معالجة مكتبات الأداء: 0x80041001

Record Number: 729
Source Name: WinMgmt
Time Written: 20110115125102.000000+180
Event Type: warning
User:



===== تقرير انهيار البرامج =====




===== تقرير الشاشة الزرقاء =====

==================================================
Dump File : Mini012611-01.dmp
Crash Time : 21/02/1432 02:26:44 م
Bug Check String : SYSTEM_THREAD_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000007e
Parameter 1 : 0xc0000005
Parameter 2 : 0xefee11a8
Parameter 3 : 0xf970d93c
Parameter 4 : 0xf970d638
Caused By Driver : aswSP.SYS
Caused By Address : aswSP.SYS+191a8
File Description : avast! self protection module
Product Name : avast! Antivirus System
Company : AVAST Software
File Version : 6.0.999.0
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini012611-01.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 90,112
==================================================

==================================================
Dump File : Mini012711-01.dmp
Crash Time : 22/02/1432 07:45:54 ص
Bug Check String : SYSTEM_THREAD_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000007e
Parameter 1 : 0xc0000005
Parameter 2 : 0xef2d91a8
Parameter 3 : 0xf970d93c
Parameter 4 : 0xf970d638
Caused By Driver : aswSP.SYS
Caused By Address : aswSP.SYS+191a8
File Description : avast! self protection module
Product Name : avast! Antivirus System
Company : AVAST Software
File Version : 6.0.999.0
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini012711-01.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 90,112
==================================================

==================================================
Dump File : Mini050211-01.dmp
Crash Time : 29/05/1432 02:02:58 م
Bug Check String : IRQL_NOT_LESS_OR_EQUAL
Bug Check Code : 0x1000000a
Parameter 1 : 0x6e614c31
Parameter 2 : 0x00000002
Parameter 3 : 0x00000000
Parameter 4 : 0x804e53cc
Caused By Driver : tcpip.sys
Caused By Address : tcpip.sys+4942
File Description : TCP/IP Protocol Driver
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini050211-01.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 90,112
==================================================

==================================================
Dump File : Mini050711-01.dmp
Crash Time : 04/06/1432 04:24:48 م
Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
Bug Check Code : 0x10000050
Parameter 1 : 0xba601000
Parameter 2 : 0x00000000
Parameter 3 : 0x804f8e68
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+21e68
File Description : ‎‎NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647)
Processor : 32-bit
Computer Name :
Full Path : C:\WINDOWS\Minidump\Mini050711-01.dmp
Processors Count : 1
Major Version : 15
Minor Version : 2600
Dump File Size : 90,112
==================================================


 
ياااااااااااااا نااااااااااااس فيه احد يعرف الحل...
 
هذا هو فحص المالوير
************' Anti-Malware 1.50.1.1100
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


Database version: 6227

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

01/04/2011 01:25:48 م
mbam-log-2011-04-01 (13-25-48).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 190826
Time elapsed: 2 hour(s), 11 minute(s), 21 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\system volume information\_restore{ab061468-8677-4825-a01d-882f4818ebcc}\RP59\A0078607.DLL (PUP.FunWebProducts) -> Delete on reboot.
c:\system volume information\_restore{ab061468-8677-4825-a01d-882f4818ebcc}\RP59\A0078608.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{ab061468-8677-4825-a01d-882f4818ebcc}\RP59\A0078609.ocx (Hacktool.KewlButtonz) -> Quarantined and deleted successfully.
c:\system volume information\_restore{ab061468-8677-4825-a01d-882f4818ebcc}\RP59\A0078610.ocx (Hacktool.KewlButtonz) -> Quarantined and deleted successfully.
c:\system volume information\_restore{ab061468-8677-4825-a01d-882f4818ebcc}\RP59\A0078611.ocx (Hacktool.KewlButtonz) -> Quarantined and deleted successfully.
c:\system volume information\_restore{ab061468-8677-4825-a01d-882f4818ebcc}\RP59\A0078612.dll (Trojan.Agent.Gen) -> Quarantined and deleted successfully.

 
عودة
أعلى