• بادئ الموضوع بادئ الموضوع دوت
  • تاريخ البدء تاريخ البدء
  • المشاهدات 9,887

دوت

زيزوومي نشيط
إنضم
4 يونيو 2011
المشاركات
108
مستوى التفاعل
0
النقاط
120
غير متصل
bed2030a6b7e23909b90ea308c765a20.jpg
 

Process list saved on 06:27:12 م, on 09/08/11
Platform: Windows 7 SP1 (WinNT 6.00.3505)

[pid] [full path to filename] [file version] [company name]
2592 C:\Windows\system32\taskhost.exe 6.1.7601.17514 Microsoft Corporation
2732 C:\Windows\system32\Dwm.exe 6.1.7600.16385 Microsoft Corporation
2812 C:\Windows\Explorer.EXE 6.1.7601.17567 Microsoft Corporation
3128 C:\Windows\System32\igfxtray.exe 8.14.10.2230 Intel Corporation
3140 C:\Windows\System32\hkcmd.exe 8.14.10.2230 Intel Corporation
3148 C:\Windows\System32\igfxpers.exe 8.14.10.2230 Intel Corporation
3156 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 15.2.18.0 Synaptics Incorporated
3172 C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe 10.1.0.1008 Intel Corporation
3188 C:\Program Files\IDT\WDM\sttray.exe 1.0.6330.0 IDT, Inc.
3208 C:\Program Files\Bluetooth Suite\BtvStack.exe 7.2.0.60 شركة Atheros Communications
3236 C:\Program Files\Bluetooth Suite\AthBtTray.exe 7.2.0.60 Atheros Commnucations
3256 C:\Windows\system32\igfxsrvc.exe 8.14.10.2230 Intel Corporation
3264 C:\Program Files\Hewlett-Packard\HP QuickWeb\hpqwutils.exe 3.0.1.9280 Hewlett-Packard Company
3460 C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe 2.3.6.0 Hewlett-Packard Development Company, L.P.
3484 C:\Program Files\Hewlett-Packard\HP On Screen Display\HPOSD.exe 1.1.1.0 Hewlett-Packard Development Company, L.P.
3500 C:\Program Files\Common Files\Java\Java Update\jusched.exe 2.0.3.1 Sun Microsystems, Inc.
3844 C:\Program Files\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe 4.0.45.1 Hewlett-Packard Development Company L.P.
4572 C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe 4.0.111.1 Hewlett-Packard Development Company L.P.
4860 C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe 2.0.0.4 Trend Micro Inc.
5248 C:\Windows\system32\taskeng.exe 6.1.7601.17514 Microsoft Corporation
 
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 06:37:30 م, on 09/08/11
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\IPS\IPSBHO.DLL
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [AtherosBtStack] "C:\Program Files\Bluetooth Suite\BtvStack.exe"
O4 - HKLM\..\Run: [AthBtTray] "C:\Program Files\Bluetooth Suite\AthBtTray.exe"
O4 - HKLM\..\Run: [HPQuickWebProxy] "C:\Program Files\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
O4 - HKLM\..\Run: [HPConnectionManager] C:\Program Files\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [HPOSD] C:\Program Files\Hewlett-Packard\HP On Screen Display\HPOSD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\HA\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Evernote 4.0 - res://C:\Program Files\Evernote\Evernote\EvernoteIE.dll/204
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\aestsrv.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files\Bluetooth Suite\adminservice.exe
O23 - Service: Motorola Con App Svc (CAMOTOROLA) - Unknown owner - C:\Program Files\Motorola\Connection Manager\ConAppsSvc.exe (file missing)
O23 - Service: Motorola Connection Manager Service (CQIALService) - Unknown owner - C:\Program Files\Motorola\ConnectionManager\CMService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Auto (HPAuto) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
O23 - Service: HP Connection Manager 4.0 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - C:\Program Files\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Motorola RcAppSvc (MOTOROLARcAppSvc) - Unknown owner - C:\Program Files\Motorola\Connection Manager\RcAppSvc.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe
O23 - Service: @%SystemRoot%\system32\stlang.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV.exe

--
End of file - 7907 bytes
 
Malwarebytes' Anti-Malware 1.51.0.1200
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


Database version: 6705

Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 9.0.8112.16421

09/08/11 06:59:52 م
mbam-log-2011-08-09 (18-59-52).txt

Scan type: Full scan (C:\|)
Objects scanned: 226729
Time elapsed: 19 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:



(No malicious items detected)

الفايروس يتحكم في الجهاز يعني البرنامج هذا اللي اعطيتوني اياه هو والهايجاك يعلقك مررره مايشتغل ثم القى مره وحده انتهى من الاسكان يعني شكله تجاهل بعض الملفات

وملفات الفايروس محمية بكلمة مرور واغلب ملفات جهازي والنظام محمية بكلمة مرور يعني لا يسمح لي بدخولها يقولولي اخذ اذن من المسؤول وهو جهازي اناااااااااا:eek:


المهم

الفايروس على شكل سلة المحذوفات وينتشر بسرعه ويسيطر على لوحة التحكم ويغير نظام الويندوز بيحيث يصير نظامه وكل ما افتح اي شي يطلعلي اللوحة السوداء حقت الدوز ومكتوب فوقها dllhost

تطلع بسرعه بسرعه ورا بعض

وماقدر احمل اي شي من النت بسهوله

يعني بكل شي مقيده

واخر شي كبيت جهازي الاول واشتريت جديد hp اللي هو هذا وصابني الفايروس ثاني شكله احد مترصد لي:er:

ويجيني لوحات ارسال تقرير

والمشاركه عن بعد شغاله اجباري ماقدر الغيها

وامور كثيره

حسبي الله ونعم الوكيل

والنورتون تم ايقافه

هو شغال لكن شكل المجلد كانه ملف ويندوز نظام

وكل ماسويت اسكان مايطلع ولا فايروس

يقولي سليم مثل التقرير اللي فوق هذا

وانا عندي نورتون سكيروتي ماعندي انتي فايروس

وايش كمان ابغى اقول من هالمصيبة اللي رفعت ضغطي لها 3 شهور


ابغى حل

حرام نسخة الويندوز هذه اصليه وكل برامج الجهاز اصليه ونورتن له كم يوم اشتريته من جرير ب 99 ريال حرام والله اللي بيصير

وجهازي جديد وانا ما بدخل الا ايميلي والماسنجر واسواق ستي وسيدات الاعمال وموقع اكافي الصناعي وموقع مستعمل وموقعكم فقط

قولولي حل

هذا فايروس ولا عفريت بديت اوسوس :er:
 
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 02:34:19 ص, on 11/08/11
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Safe mode

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files\AutorunRemover\AutorunRemover.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\IPS\IPSBHO.DLL
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [AtherosBtStack] "C:\Program Files\Bluetooth Suite\BtvStack.exe"
O4 - HKLM\..\Run: [AthBtTray] "C:\Program Files\Bluetooth Suite\AthBtTray.exe"
O4 - HKLM\..\Run: [HPQuickWebProxy] "C:\Program Files\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
O4 - HKLM\..\Run: [HPConnectionManager] C:\Program Files\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [HPOSD] C:\Program Files\Hewlett-Packard\HP On Screen Display\HPOSD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AutorunRemover.exe] C:\Program Files\AutorunRemover\AutorunRemover.exe -Hide
O4 - HKCU\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
O4 - HKCU\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\aestsrv.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files\Bluetooth Suite\adminservice.exe
O23 - Service: Motorola Con App Svc (CAMOTOROLA) - Unknown owner - C:\Program Files\Motorola\Connection Manager\ConAppsSvc.exe (file missing)
O23 - Service: Motorola Connection Manager Service (CQIALService) - Unknown owner - C:\Program Files\Motorola\ConnectionManager\CMService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Auto (HPAuto) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
O23 - Service: HP Connection Manager 4.0 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - C:\Program Files\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Users\HA\AppData\Local\Temp\zxu3\files\\mbamservice.exe
O23 - Service: Motorola RcAppSvc (MOTOROLARcAppSvc) - Unknown owner - C:\Program Files\Motorola\Connection Manager\RcAppSvc.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe
O23 - Service: @%SystemRoot%\system32\stlang.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV.exe

--
End of file - 8589 bytes
 
دكتور ويب مسويلي مستند فاضي مافيه تقرير
 
اختي انتي استخدمتي فلاش على جهازك القديم واستعملتيه على الجهاز الجديد ؟؟

والله اعلم اذا مو من الفلاش فعندك احد المواقع اللي تزوريها منها المشكلة
 
توقيع : الوفاء طبعي
طيب الحل
 
من تقرير الهايجاك احذف القيم التالية

O9 - Extra button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files\Evernote\Evernote\EvernoteIE.dll/204 (file missing)


O9 - Extra 'Tools' menuitem: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files\Evernote\Evernote\EvernoteIE.dll/204 (file missing)

O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone

O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone

O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone

O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone

O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone


طريقة الحذف لمستخدمي الفيستا و 7

3b7ae00caf9f7ac81fda4d8ad820737e.png

ثم ضع اشارة الصح على كل القيم المطلوب منك حذفها حسب الشرح التالي​

bf28ac475e05cc3563b98b204f5a4535.png

911376dd57542a52a620006373c8483c.png

ونظف جهازك بهذه الاداة​

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي




ثم

تقرير رن سكنر + تقرير البرامج المثبته
 
Process list saved on 07:51:38 م, on 8/12/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)

[pid] [full path to filename] [file version] [company name]
2244 C:\Windows\system32\taskhost.exe 6.1.7601.17514 Microsoft Corporation
2292 C:\Windows\system32\Dwm.exe 6.1.7600.16385 Microsoft Corporation
2316 C:\Windows\Explorer.EXE 6.1.7601.17567 Microsoft Corporation
2544 C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe 2.3.6.0 Hewlett-Packard Development Company, L.P.
2564 C:\Program Files\Hewlett-Packard\HP On Screen Display\HPOSD.exe 1.1.1.0 Hewlett-Packard Development Company, L.P.
2752 C:\Windows\system32\igfxsrvc.exe 8.14.10.2230 Intel Corporation
2848 C:\Program Files\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe 4.0.45.1 Hewlett-Packard Development Company L.P.
3296 C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe 4.0.111.1 Hewlett-Packard Development Company L.P.
5932 C:\Program Files\Motorola\ConnectionManager\ConnectionManager.exe 1.0.10.119 Motorola, Inc.
4176 C:\Users\HA\AppData\Local\Google\Chrome\Application\chrome.exe 0.0.0.0 Google Inc.
6036 C:\Users\HA\AppData\Local\Google\Chrome\Application\chrome.exe 0.0.0.0 Google Inc.
5796 C:\Users\HA\AppData\Local\Google\Chrome\Application\chrome.exe 0.0.0.0 Google Inc.
3508 C:\Windows\system32\rundll32.exe 6.1.7600.16385 Microsoft Corporation
5400 C:\Users\HA\AppData\Local\Google\Chrome\Application\chrome.exe 0.0.0.0 Google Inc.
1244 C:\Users\HA\AppData\Local\Google\Chrome\Application\chrome.exe 0.0.0.0 Google Inc.
5992 C:\Users\HA\AppData\Local\Google\Chrome\Application\chrome.exe 0.0.0.0 Google Inc.
5336 C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe 2.0.0.4 Trend Micro Inc.
4624 C:\Users\HA\AppData\Local\Google\Chrome\Application\chrome.exe 0.0.0.0 Google Inc.
 
# Copyright (c) 1993-2009 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
# 127.0.0.1 localhost
# ::1 localhost
 
ActiveCheck component for HP Active Support Library
Adobe Flash Player 10 ActiveX
Adobe Reader X - Arabic
Adobe Shockwave Player 11.5
Adware . Mediapipe Removal Tool
Atheros Driver Installation Program
Bejeweled 2 Deluxe
Blasterball 3
Bluetooth Win7 Suite
Bounce Symphony
Chuzzle Deluxe
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Connection Manager
D3DX10
Diner Dash 2 Restaurant Rescue
Dream Chronicles
Energy Star Digital Logo
ESU for Microsoft Windows 7
Evernote v. 4.2.2
Farm Frenzy
FATE
Fishdom
HiJackThis
HP Auto
HP Camera
HP Connection Manager
HP Customer Experience Enhancements
HP Documentation
HP Games
HP On Screen Display
HP Power Manager
HP Quick Launch
HP QuickWeb
HP Setup
HP Software Framework
HP Support Assistant
HPAsset component for HP Active Support Library
IDT Audio
Insaniquarium Deluxe
Intel(R) Control Center
Intel(R) Graphics Media *********** Driver
Intel(R) Rapid Storage Technology
Java(TM) 6 Update 24
Jewel Quest - Heritage
Jewel Quest Solitaire
JoJo's Fashion Show
Junk Mail filter update
Mah Jong Medley
Mahjongg Artifacts
Malwarebytes' Anti-Malware النسخة 1.51.1.1800
Mesh Runtime
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile ARA Language Pack
Microsoft Office 2010
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MSVCRT
Namco All-Stars PAC-MAN
Norton Internet Security
Penguins!
Plants vs. Zombies - Game of the Year
Polar Bowler
Realtek Ethernet Controller Driver
Realtek USB 2.0 Card Reader
Recovery Manager
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for حزمة اللغة العربية لـ Microsoft .NET Framework 4 (KB2478663)
Security Update for حزمة اللغة العربية لـ Microsoft .NET Framework 4 (KB2518870)
Skip-Bo - Castaway Caper
Slingo Deluxe
Synaptics Pointing Device Driver
Tradewinds Legends
Uniblue DriverScanner
Uniblue PowerSuite
Uniblue RegistryBooster
Uniblue SpeedUpMyPC
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update Installer for WildTangent Games App
Virtual Villagers - The Secret City
WDM Driver
Wedding Dash
WildTangent Games App (HP Games)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mail
Windows Live Mesh
Windows Live Mesh
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Messenger
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Movie Maker
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Common
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer
Windows Live Writer
Windows Live Writer
Windows Live Writer Resources
Windows Live Writer Resources
WinRAR archiver
Zuma Deluxe
بريد Windows Live
حزمة اللغة العربية لـ Microsoft .NET Framework 4
معرض صور Windows Live
 
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 08:08:00 م, on 8/12/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe
C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Program Files\Motorola\ConnectionManager\ConnectionManager.exe
C:\Users\HA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\HA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HA\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\system32\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\IPS\IPSBHO.DLL
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll
O4 - HKLM\..\Run: [HPConnectionManager] C:\Program Files\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [HPOSD] C:\Program Files\Hewlett-Packard\HP On Screen Display\HPOSD.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [PowerSuite] "C:\PROGRA~1\Uniblue\POWERS~1\launcher.exe" delay 20000 -m
O8 - Extra context menu item: Add to Evernote 4.0 - res://C:\Program Files\Evernote\Evernote\EvernoteIE.dll/204
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\aestsrv.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files\Bluetooth Suite\adminservice.exe
O23 - Service: Motorola Connection Manager Service (CQIALService) - Unknown owner - C:\Program Files\Motorola\ConnectionManager\CMService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Auto (HPAuto) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
O23 - Service: HP Connection Manager 4.0 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - C:\Program Files\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe
O23 - Service: @%SystemRoot%\system32\stlang.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV.exe

--
End of file - 7393 bytes
 
Malwarebytes' Anti-Malware 1.51.1.1800
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


نسخة قاعدة البيانات : 7446

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

8/12/2011 08:16:20 م
mbam-log-2011-08-12 (20-16-20).txt

نوع الفحص : فحص كامل (C:\|D:\|E:\|)
الكائنات المفحوصة : 264483
الوقت المنقضي : 32 دقيقة, 10 ثانية

عمليات الذاكرة المصابة : 0
وحدات الذاكرة المصابة : 0
مفاتيح الريجستري المصابة : 0
قيم الريجستري المصابة : 0
مواد بيانات الريجستري المصابة : 0
المجلدات المصابة : 0
الملفات المصابة : 0

عمليات الذاكرة المصابة :
(لم يتم إكتشاف مواد ضارة)

وحدات الذاكرة المصابة :
(لم يتم إكتشاف مواد ضارة)

مفاتيح الريجستري المصابة :
(لم يتم إكتشاف مواد ضارة)

قيم الريجستري المصابة :
(لم يتم إكتشاف مواد ضارة)

مواد بيانات الريجستري المصابة :
(لم يتم إكتشاف مواد ضارة)

المجلدات المصابة :
(لم يتم إكتشاف مواد ضارة)

الملفات المصابة :
(لم يتم إكتشاف مواد ضارة)
 
اختي جهازك مسخن (( الحرارة عالية جدا ))

هذا سبب التعليق (( انصحك بشراء مشتت حراري للاب او تنظيف المرواح تبع الجهاز من الغبار ))

لو ضل على هذا الحال رح ينعدم عليك​
 
Operating System
MS Windows 7 Starter 32-bit SP1
Installation Date: 04 August 2011, 23:36
Serial Number: RH98C-M9PW4-6DHR7-X99PJ-3FGDB
Windows Security Center
User Account Control (UAC) Enabled
Notify level 3 - Always Notify
Firewall Enabled
Windows Update
AutoUpdate Download Automatically and Install at Set Scheduled time
Schedule Frequency Every day
Schedule Time 3 am
Windows Defender
Windows Defender Enabled
TimeZone
TimeZone GMT +3 Hours
Language Arabic
Country المملكة العربية السعودية
Currency ر.س.‏
Date Format M/d/yyyy
Time Format hh:mm:ss tt
Power Profile
Active power scheme Home/Office Desk
Hibernation Enabled
Scheduler
9/12/1432 11:25 م GoogleUpdateTaskUserS-1-5-21-3040226808-315911390-314760281-1000UA
9/13/1432 04:25 ص GoogleUpdateTaskUserS-1-5-21-3040226808-315911390-314760281-1000Core
11/6/1432 04:14 ص HPCeeScheduleForHA
11/13/1432 05:05 ص HPCeeScheduleForHA-HP$
Hotfixes
9/12/1432 Definition Update for Windows Defender - KB915597 (Definition 1.109.1657.0)
9/11/1432 Definition Update for Windows Defender - KB915597 (Definition 1.109.1371.0)
9/11/1432 تحديث لـ Microsoft .NET Framework 4 على Windows XP و Windows Server 2003 و Windows Vista و Windows 7 وWindows Server 2008 x86 رقم (KB2533523)
9/11/1432 تحديث لـ Windows 7 رقم (KB2563227)
9/11/1432 تحديث أمان لـ Windows 7 رقم (KB2556532)
9/11/1432 تحديث لـ Microsoft .NET Framework 4 على Windows XP و Windows Server 2003 و Windows Vista و Windows 7 وWindows Server 2008 x86 رقم (KB2468871)
9/11/1432 تحديث أمان لـ Windows 7 رقم (KB2536276)
9/11/1432 تحديث أمني لبرنامج Microsoft .NET Framework 3.5.1 على نظام التشغيل Windows 7 x86 (KB2539635)
9/11/1432 تحديث أمان لـ Windows 7 رقم (KB2563894)
9/11/1432 مجموعة تحديثات لـ ActiveX Killbits لـ Windows 7 رقم (KB2562937)
9/11/1432 تحديث الأمان التراكمي لـ Internet Explorer 9 الخاص بـ Windows 7 رقم (KB2559049)
9/11/1432 تحديث أمان لـ Windows 7 رقم (KB2567680)
9/11/1432 أداة إزالة البرامج الضارة لـ Windows- أغسطس 2011 (KB890830)
9/11/1432 تحديث أمان لـ Windows 7 رقم (KB2560656)
9/11/1432 تحديث أمني لـ Microsoft .NET Framework 4 على Windows XP وWindows Server 2003 وWindows Vista وWindows 7 وWindows Server 2008 x86 رقم (KB2539636)
9/7/1432 تحديث لـ Windows 7 رقم (KB2529073)
9/7/1432 تحديث لـ Windows 7 رقم (KB982018)
9/7/1432 تحديث أمان لـ Windows 7 رقم (KB2532531)
9/7/1432 تحديث أمني لـ Microsoft .NET Framework 4 على Windows XP وWindows Server 2003 وWindows Vista وWindows 7 وWindows Server 2008 x86 رقم (KB2478663)
9/7/1432 تحديث أمني لـ Microsoft .NET Framework 4 على Windows XP وWindows Server 2003 وWindows Vista وWindows 7 وWindows Server 2008 x86 رقم (KB2518870)
9/6/1432 Microsoft .NET Framework 4 Client Profile لـ Windows 7 x86 (KB982670)
9/6/1432 أداة إزالة البرامج الضارة لـ Windows- يوليو 2011 (KB890830)
9/6/1432 تحديث أمان لـ Windows 7 رقم (KB2536275)
9/6/1432 تحديث أمان لـ Windows 7 رقم (KB2503665)
9/6/1432 تحديث لـ Windows 7 رقم (KB2492386)
9/6/1432 تحديث أمان تراكمي لـ ActiveX Killbits لنظام التشغيل Windows 7 رقم (KB2508272)
9/6/1432 تحديث لـ Windows 7 رقم (KB2506928)
9/6/1432 تحديث أمان لـ Windows 7 رقم (KB2476490)
9/6/1432 تحديث أمان لـ Windows 7 رقم (KB2509553)
9/6/1432 تحديث أمان لـ Windows 7 رقم (KB2507618)
9/6/1432 تحديث لـ Windows 7 رقم (KB2552343)
9/6/1432 تحديث لـ Windows 7 رقم (KB2545698)
9/6/1432 تحديث أمان لـ Windows 7 رقم (KB2532531)
9/6/1432 تحديث أمني لـ ‎.NET Framework 3.5.1 على Windows 7 SP1 x86 رقم (KB2518869)
9/6/1432 تحديث لـ Windows 7 رقم (KB2524375)
9/6/1432 تحديث أمان لـ Windows 7 رقم (KB2507938)
9/6/1432 تحديث الأمان التراكمي لـ Internet Explorer 9 الخاص بـ Windows 7 رقم (KB2530548)
9/6/1432 تحديث أمان لـ Windows 7 رقم (KB2544893)
9/6/1432 تحديث لـ Windows 7 رقم (KB2533623)
9/6/1432 تحديث لـ Windows 7 رقم (KB2547666)
9/6/1432 تحديث أمان لـ Windows 7 رقم (KB2491683)
9/6/1432 تحديث لـ Windows 7 رقم (KB2522422)
9/6/1432 تحديث لـ Windows 7 رقم (KB2511250)
9/6/1432 تحديث لـ Windows 7 رقم (KB2515325)
9/6/1432 تحديث أمان لـ Windows 7 رقم (KB2555917)
9/6/1432 تحديث لـ Windows 7 رقم (KB2534366)
9/6/1432 تحديث أمني لـ ‎.NET Framework 3.5.1 على Windows 7 SP1 x86 رقم (KB2478662)
9/6/1432 تحديث أمان لـ Windows 7 رقم (KB2506212)
9/6/1432 تحديث أمان لـ Windows 7 رقم (KB2511455)
9/6/1432 تحديث لـ Windows 7 رقم (KB2533552)
9/6/1432 تحديث لـ Windows 7 رقم (KB2541014)
9/6/1432 تحديث أمان لـ Windows 7 رقم (KB2536276)
Battery
AC line Offline
Battery full time Unknown
Battery Charge % 67 %
Battery State High
Amount of time remaining (sec) 2 : 53
Services
Running Andrea ST Filters Service
Running Application Experience
Running Application Information
Running Atheros Bt&Wlan Coex Agent
Running AtherosSvc
Running Audio Service
Running Background Intelligent Transfer Service
Running Base Filtering Engine
Running CNG Key Isolation
Running COM+ Event System
Running Cryptographic Services
Running DCOM Server Process Launcher
Running Desktop Window Manager Session Manager
Running DHCP Client
Running Diagnostic Policy Service
Running Diagnostic Service Host
Running DNS Client
Running Extensible Authentication Protocol
Running Group Policy Client
Running HP Auto
Running HP Connection Manager 4.0 Service
Running HP Health Check Service
Running HP Quick Synchronization Service
Running HP Software Framework Service
Running HPWMISVC
Running IKE and AuthIP IPsec Keying Modules
Running Intel(R) Rapid Storage Technology
Running IPsec Policy Agent
Running MBAMService
Running Microsoft .NET Framework NGEN v4.0.30319_X86
Running Motorola Connection Manager Service
Running Multimedia Class Scheduler
Running Network Connections
Running Network List Service
Running Network Location Awareness
Running Network Store Interface Service
Running Norton Internet Security
Running Peer Networking Identity Manager
Running Performance Logs & Alerts
Running Plug and Play
Running Power
Running Print Spooler
Running Program Compatibility Assistant Service
Running Remote Procedure Call (RPC)
Running RPC Endpoint Mapper
Running Security Accounts Manager
Running Security Center
Running Server
Running Shell Hardware Detection
Running SSDP Discovery
Running Superfetch
Running System Event Notification Service
Running Task Scheduler
Running Themes
Running UPnP Device Host
Running User Profile Service
Running Windows Audio
Running Windows Audio Endpoint Builder
Running Windows Defender
Running Windows Driver Foundation - User-mode Driver Framework
Running Windows Event Log
Running Windows Firewall
Running Windows Font Cache Service
Running Windows Live ID Sign-in Assistant
Running Windows Management Instrumentation
Running Windows Modules Installer
Running Windows Presentation Foundation Font Cache 3.0.0.0
Running Windows Search
Running Windows Update
Running WLAN AutoConfig
Running Workstation
Stopped ActiveX Installer (AxInstSV)
Stopped Application Identity
Stopped Application Layer Gateway Service
Stopped BitLocker Drive Encryption Service
Stopped Block Level Backup Engine Service
Stopped Bluetooth Support Service
Stopped Certificate Propagation
Stopped COM+ System Application
Stopped Computer Browser
Stopped Credential Manager
Stopped Diagnostic System Host
Stopped Disk Defragmenter
Stopped Distributed Link Tracking Client
Stopped Distributed Transaction Coordinator
Stopped Encrypting File System (EFS)
Stopped Fax
Stopped Function Discovery Provider Host
Stopped Function Discovery Resource Publication
Stopped GamesAppService
Stopped Health Key and Certificate Management
Stopped HomeGroup Listener
Stopped HomeGroup Provider
Stopped Human Interface Device Access
Stopped Interactive Services Detection
Stopped Internet Connection Sharing (ICS)
Stopped IP Helper
Stopped KtmRm for Distributed Transaction Coordinator
Stopped Link-Layer Topology Discovery Mapper
Stopped Microsoft .NET Framework NGEN v2.0.50727_X86
Stopped Microsoft iSCSI Initiator Service
Stopped Microsoft Software Shadow Copy Provider
Stopped Motorola Con App Svc
Stopped Motorola RcAppSvc
Stopped Net.Tcp Port Sharing Service
Stopped Netlogon
Stopped Network Access Protection Agent
Stopped Parental Controls
Start pending Peer Name Resolution Protocol
Stopped Peer Networking Grouping
Stopped PnP-X IP Bus Enumerator
Stopped PNRP Machine Name Publication Service
Stopped Portable Device Enumerator Service
Stopped Problem Reports and Solutions Control Panel Support
Stopped Protected Storage
Stopped Quality Windows Audio Video Experience
Stopped Remote Access Auto Connection Manager
Stopped Remote Access Connection Manager
Stopped Remote Desktop Configuration
Stopped Remote Desktop Services
Stopped Remote Procedure Call (RPC) Locator
Stopped Remote Registry
Stopped Routing and Remote Access
Stopped Secondary Logon
Stopped Secure Socket Tunneling Protocol Service
Stopped Smart Card
Stopped Smart Card Removal Policy
Stopped SNMP Trap
Stopped Software Protection
Stopped SPP Notification Service
Stopped Tablet PC Input Service
Stopped TCP/IP NetBIOS Helper
Stopped Telephony
Stopped Thread Ordering Server
Stopped TPM Base Services
Stopped Virtual Disk
Stopped Volume Shadow Copy
Stopped WebClient
Stopped Windows Backup
Stopped Windows Biometric Service
Stopped Windows CardSpace
Stopped Windows Color System
Stopped Windows Connect Now - Config Registrar
Stopped Windows Error Reporting Service
Stopped Windows Event Collector
Stopped Windows Image Acquisition (WIA)
Stopped Windows Installer
Stopped Windows Live Mesh remote connections service
Stopped Windows Media Player Network Sharing Service
Stopped Windows Remote Management (WS-Management)‎
Stopped Windows Time
Stopped WinHTTP Web Proxy Auto-Discovery Service
Stopped Wired AutoConfig
Stopped WMI Performance Adapter
Stopped WWAN AutoConfig
Device Tree
ACPI x86-based PC
Microsoft Watchdog Timer
Microsoft ACPI-Compliant System
Intel(R) Atom(TM) CPU N570 @ 1.66GHz
Intel(R) Atom(TM) CPU N570 @ 1.66GHz
Intel(R) Atom(TM) CPU N570 @ 1.66GHz
Intel(R) Atom(TM) CPU N570 @ 1.66GHz
ACPI Fan
ACPI Thermal Zone
ACPI Power Button
ACPI Lid
Microsoft ACPI-Compliant Control Method Battery
Microsoft AC Adapter
Microsoft Windows Management Interface for ACPI
ACPI Fixed Feature Button
PCI bus
Intel(R) N10 Family DMI Bridge - A010
Intel(R) Graphics Media *********** 3150
Intel(R) 82801 PCI Bridge - 2448
Intel(R) N10/ICH7 Family SMBus Controller - 27DA
Intel(R) Graphics Media *********** 3150
Generic PnP Monitor
وحدة تحكم High Definition Audio
IDT High Definition Audio CODEC
Intel(R) N10/ICH7 Family PCI Express Root Port - 27D0
Realtek PCIe FE Family Controller
Intel(R) N10/ICH7 Family PCI Express Root Port - 27D2
Atheros AR9285 802.11b/g/n WiFi Adapter
Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C8
Intel(R) N10/ICH7 Family USB Universal Host Controller - 27C9
USB Root Hub
Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CA
USB Root Hub
Intel(R) N10/ICH7 Family USB Universal Host Controller - 27CB
USB Root Hub
Intel(R) N10/ICH7 Family USB2 Enhanced Host Controller - 27CC
USB Root Hub
USB Composite Device
HP Webcam-50
WiMAX Bus Driver
WiMAX Network Adapter
Intel(R) NM10 Family LPC Interface Controller - 27BC
Motherboard resources
Direct memory access controller
System CMOS/real time clock
High precision event timer
Programmable interrupt controller
Numeric data processor
System timer
Intel(R) 82802 Firmware Hub Device
Microsoft ACPI-Compliant Embedded Controller
Lenovo ThinkPad PS/2 keyboard
Synaptics PS/2 Port TouchPad
Intel(R) NM10 Express Chipset
SAMSUNG HM321HI
 
CPU
Intel Atom
Cores 2
Threads 4
Name Intel Atom
Package Socket 437 FCBGA8
Technology 45nm
Specification Intel(R) Atom(TM) CPU N570 @ 1.66GHz
Family 6
Extended Family 6
Model C
Extended Model 1C
Stepping A
Revision B0
Instructions MMX, SSE, SSE2, SSE3, SSSE3, Intel 64
Virtualization Supported, Disabled
Hyperthreading Supported, Enabled
Bus Speed 166.3 MHz
Rated Bus Speed 665.1 MHz
Stock Core Speed 1666 MHz
Stock Bus Speed 166 MHz
Average Temperature 74 °C
Caches
L1 Data Cache Size 2 x 24 KBytes
L1 Instructions Cache Size 2 x 32 KBytes
L2 Unified Cache Size 2 x 512 KBytes
Core 0
Core 1
 
عودة
أعلى