الحالة
مغلق و غير مفتوح للمزيد من الردود.

GEOG

زيزوومي جديد
إنضم
22 فبراير 2012
المشاركات
33
مستوى التفاعل
0
النقاط
40
غير متصل
اعضاء موقع زيزوم للأمن والحماية
السلام عليكم ورحمة الله وبركاتة

هذا اول موضوع اطرحه في موقعكم
وآمل ان اجد لديكم الحل لمشكلة جهازي

اشك ان عندي فيروسات في جهازي
برنامج الحماية عندي كاسبر انترنت سيكورتي
بس جاء له فترة يطلع لي رسالة انه قواعد البيانات تالفه
ماعرفت كيف احل مشكلته حذفته ورجعت ثبتته ومشي الحال
الآن على وشك ينتهي واشتريت نسخه جديدة2012 بس لسى ماثبتها

الي صاير الآن اني ابغى انزل الفيجول ستديو 2008 بس تطلع لي رسالة ان التثبيت فشل
حاولت على جهازين آخرين ونفس الرسالة تظهر

حقيقة شكيت ان السي دي فيه مشكلة لأنه من سنتين عندي
رحت اخذت نسخه جديدة للبرنامج ونفس الشي تطلع نفس الرسالة
عرضت جهازي على استاذتي في المعهد قالت لي ان المشكلة قد يكون فيه تعارض مع برنامج آخر ولازم واحد منهم ينزل قبل الآخر
كل ال3 اجهزة منزل عليهم برنامج اسمه ArcGis برنامج نظم المعلومات الجغرافية
قالت لي ممكن تكون المشكلة في البرنامج هذا عامل تعارض معه عشان كذا مابينزل
وممكن تكون فيه فيروسات في الجهاز

رحت لمركز المدينة ونفس المشكلة ماتثبت البرنامج قال لي الشخص هناك ان ممكن فيه فيروسات عشان كذا ماينزل
انا شاكه انه فيه فيروسات عشان برنامج الحماية تعطل عندي فترة زي ماقلت لكم
طيب ما اقدر ازيل الفيروسات بدون فورمات ؟

ماابغى افرمت لأن احس الفرمته حل مؤقت وبعدها مشاكل في الجهاز
وفي نفس الوقت احتاج البرنامجين

وش تقترحون علي ؟
استاذتي نصحتني بموقعكم وقالت انوا تقدروا بملفات وطرق معينة تكشفوا فيروسات جهازي واقدر ازيلها بدون فورمات

انتظر ردودكم ومساعدتكم لي

وجزاكم الله كل خير
 

 
توقيع : علي همر
ضغطت ع الرابط
وعملت تشغيل ومن ساعة تقريبا ماتغير الوضع

هذي الصورة
 
كيف اقدر اضيف الصورة ؟
 
ثم إنسخي الرابط المحدد جمبه

رابط للمنتديات
 
هذي النتيجة

Malwarebytes' Anti-Malware 1.51.2.1300

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


Database version: 7622
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
23/02/12 02:08:45 م
mbam-log-2012-02-23 (14-08-45).txt
Scan type: Full scan (C:\|D:\|G:\|)
Objects scanned: 370428
Time elapsed: 50 minute(s), 54 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 5
Registry Keys Infected: 74
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 40
Memory Processes Infected:
c:\program files\cieonetutilities_0e\bar\1.bin\0ebrmon.exe (Adware.MyWebSearch) -> 2984 -> Unloaded process successfully.
Memory Modules Infected:
c:\program files\cieonetutilities_0e\bar\1.bin\0ebrstub.dll (Adware.MyWebSearch) -> Delete on reboot.
c:\program files\cieonetutilities_0e\bar\1.bin\0eauxstb.dll (Adware.MyWebSearch) -> Delete on reboot.
c:\program files\cieonetutilities_0e\bar\1.bin\0eSrcAs.dll (Adware.MyWebSearch) -> Delete on reboot.
c:\program files\cieonetutilities_0e\bar\1.bin\0edlghk.dll (Adware.MyWebSearch) -> Delete on reboot.
c:\program files\cieonetutilities_0e\bar\1.bin\0eieovr.dll (Adware.MyWebSearch) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CieoNetUtilities_0eService (Adware.MyWebSearch) -> Quarantined and
deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4cbfd6a0-f21b-4d52-bf56-c57a37625141} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4CBFD6A0-F21B-4D52-
BF56-C57A37625141} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{4CBFD6A0-F21B-4D52-BF56-C57A37625141}
(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4CBFD6A0-F21B-4D52-BF56-C57A37625141}
(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c5818d18-4d28-4e42-bde6-1460f5d29628} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\TypeLib\{2a7e74c8-7cc3-4656-903b-c16b5419e393} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\Interface\{DF3A1434-9497-4938-8EED-C77C5493097B} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\CLSID\{1b3cf572-0d15-4e95-bd03-c59a653b30cd} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\TypeLib\{b4fc519f-3f98-450d-8a16-cc92916420f4} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\Interface\{0E6A5ADB-B294-4B4F-81D3-3F7DF3FA7A2E} (Adware.MyWebSearch) -> Quarantined and
deleted successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.SettingsPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.SettingsPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1B3CF572-0D15-4E95-BD03-C59A653B30CD}
(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1B3CF572-0D15-4E95-BD03-
C59A653B30CD} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CieoNetUtilities_0ebar Uninstall
(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8ca6701f-b8e8-43b9-b206-b2a9ee3216cf} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8CA6701F-B8E8-43B9-
B206-B2A9EE3216CF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{8CA6701F-B8E8-43B9-B206-B2A9EE3216CF}
(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8CA6701F-B8E8-43B9-B206-B2A9EE3216CF}
(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d0aceac7-b205-4a51-804b-53ba679ab30b} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.MultipleButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.MultipleButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{227c2234-107f-41d3-8be5-7f9180e7dd6c} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\TypeLib\{b4f710e6-e773-481b-bb85-3540a21db4d5} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\Interface\{1C4CB152-4A39-454E-8355-DA786E41FED3} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\CLSID\{4d9e6a3f-f05d-4f96-a826-87c38aec5599} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.DynamicBarButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.DynamicBarButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c0ccafac-ea0a-4e33-8a94-51a25453a40e} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\TypeLib\{319c598d-febe-437e-9823-173b89169e63} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\Interface\{3628CFBA-DCF1-41FF-A01D-C0CBEEA56107} (Adware.MyWebSearch) -> Quarantined and
deleted successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.FeedManager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.FeedManager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0b08513a-0187-4746-93dc-dedae21b8ab2} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\TypeLib\{a05732e8-9b6a-4d61-956d-707ad06779ca} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\Interface\{3F149704-B93D-4E37-842F-AD2713A663A0} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.HTMLPanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.HTMLPanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0B08513A-0187-4746-93DC-
DEDAE21B8AB2} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6EC936E8-224E-41AB-8A5D-E5D62EB3B6F3} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.HTMLMenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.HTMLMenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6EC936E8-224E-41AB-8A5D-
E5D62EB3B6F3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{719a0e21-6b15-468e-b4d8-d453c3ee5aab} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\TypeLib\{a48591ff-203f-4844-b6c7-4cd8b715a16b} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\Interface\{1E037492-2389-47CB-9E6B-E09AE6A67682} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\CLSID\{07e92310-4028-4869-abe8-3b94fd5e317f} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\TypeLib\{b65d3fec-897d-4cc2-8214-9e867d6623f8} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\Interface\{4C157D89-1118-44D3-86AB-B18F57EFAF18} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.XMLSessionPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.XMLSessionPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07E92310-4028-4869-ABE8-
3B94FD5E317F} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a5796feb-f4ab-43d2-8143-5dcff93dc172} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.Radio.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.Radio (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e2d12817-fbc7-41ee-8835-20e4de3ca5d9} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.ScriptButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.ScriptButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9be25e48-df8d-475a-9939-a6716ee36d79} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\TypeLib\{0894c686-3d9f-470f-a808-28ddb348d559} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\Interface\{5EB589AD-AA1F-4B04-B5F0-04B83C83061E} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.PseudoTransparentPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.PseudoTransparentPlugin (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9BE25E48-DF8D-475A-9939-
A6716EE36D79} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{23bcc7f2-0782-4d1f-af18-75dc5e7ea3f1} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\TypeLib\{fc2ae03d-efef-467d-9809-eea341538c0b} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\Interface\{45B85E52-997A-44E4-BCA5-14F26C18DC5B} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.ThirdPartyInstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.ThirdPartyInstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{23BCC7F2-0782-4D1F-AF18-
75DC5E7EA3F1} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f51c5954-93cc-468c-bf62-d7ad2df5e6f9} (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.UrlAlertButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CieoNetUtilities_0e.UrlAlertButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\CieoNetUtilities_0e Browser Plugin Loader
(Adware.MyWebSearch) -> Value: CieoNetUtilities_0e Browser Plugin Loader -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\CieoNet Utilities Search Scope Monitor
(Adware.MyWebSearch) -> Value: CieoNet Utilities Search Scope Monitor -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\program files\cieonetutilities_0e\bar\1.bin\0ebrstub.dll (Adware.MyWebSearch) -> Delete on reboot.
c:\program files\cieonetutilities_0e\bar\1.bin\0ebrmon.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Program Files\CieoNetUtilities_0e\bar\1.bin\0ebarsvc.exe (Adware.MyWebSearch) -> Delete on reboot.
c:\program files\cieonetutilities_0e\bar\1.bin\0eauxstb.dll (Adware.MyWebSearch) -> Delete on reboot.
c:\program files\cieonetutilities_0e\bar\1.bin\0eSrcAs.dll (Adware.MyWebSearch) -> Delete on reboot.
c:\program files\cieonetutilities_0e\bar\1.bin\0edlghk.dll (Adware.MyWebSearch) -> Delete on reboot.
c:\program files\cieonetutilities_0e\bar\1.bin\0eieovr.dll (Adware.MyWebSearch) -> Delete on reboot.
c:\program files\cieonetutilities_0e\bar\1.bin\0eSrchMn.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0ebar.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0emlbtn.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0edatact.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0edyn.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0efeedmg.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0ehighin.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0ehkstub.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0ehtml.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0ehtmlmu.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0ehttpct.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0eidle.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0eimpipe.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0emedint.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0emsg.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0ePlugin.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0eradio.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0eregfft.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0ereghk.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0eregiet.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0escript.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0eskin.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0eskplay.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0etpinst.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\0euabtn.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\NP0eStub.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\cieonetutilities_0e\bar\1.bin\T8RES.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\Users\User\AppData\LocalLow\cieonetutilities_0eei\Installr\Cache\008DAE0C.exe (Adware.MyWebSearch) -> Quarantined and deleted
successfully.
d:\أ-عمر\Software\corll draw\keygen.exe (Trojan.Dropper.PGen) -> Quarantined and deleted successfully.
d:\البحث2\البرنامج\visual basic\mariam\windowsapplication2\windowsapplication2\bin\Debug\windowsapplication2.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
d:\البحث2\البرنامج\visual basic\mariam\windowsapplication2\windowsapplication2\obj\Debug\windowsapplication2.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
d:\البحث2\البرنامج\visual basic\my trining\13-8\windowsapplication2\windowsapplication2\bin\Debug\windowsapplication2.exe
(Trojan.Agent) -> Quarantined and deleted successfully.
d:\البحث2\البرنامج\visual basic\my trining\13-8\windowsapplication2\windowsapplication2\obj\Debug\windowsapplication2.exe
(Trojan.Agent) -> Quarantined and deleted successfully.
 
رجعت لقيت هذي الرسالة
بما انه ماحذف كل النتائج ممكن النتيجة ماكانت لكل الي طلع
بجرب اعيد التشغيل زي ماهو طالب

انتظركم يااعضاء

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي

 
حمل احدث اصدار من الرابط التالي

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي



نسخة محمولة محدثة لاخر اصدار دوما من موقع الشركة

ثم تابع شرح الفحص

fa33497a6dcbc00f7125a5e9c86b875f.png


1b26353b418be3416040fee21b21b01d.png


متوفر اللغة العربية ضمن الخيارات لمن يرغب

2b3141e312786215b6a60257f3d9dfe0.png


448c36b550c2236d07532f02624d2081.png


7f6dcf346a0abf125fbae716f1e13f15.png


59b265496c6617a722a5af31bffa4ff7.png


735f1ae4bd65702946a06ceb09197b84.png


3f2ac4c37775a1613d11553ca0ea8f3c.png


3dfb590f69fbd192e4ee43657e1ddd59.png


اختر اعادة التشغيل لاحقا حتى تتمكن من حفظ التقرير وعرضه على قسم الصيانة كما الشرح التالي

3711e467b86a834fd3db5a3504359c0d.png


18808771241b82993b5820aafa4b6e82.png


تخرج لك مفكرة تحتوي على التقرير .. انسخها كاملة وضعها بمشاركتك بقسم الصيانة

=============

التالي هو شرح استعادة ما اتلفته الفيروسات بواسطة البرنامج

274560a7f832e136a876de6177601748.png


400c6517cfd890124bf40bad5809ddef.png


5267f2c37ce4bced56bed98679e77fe9.png


ثم اغلق البرنامج .. سيطلب منك اعادة تشغيل الجهاز
وافق للضرورة حتى يكمل الاصلاح وتنظيف الاصابات

.
 
توقيع : format
كيف عرفتي أنه ماحذف كل شئ ؟

المهم إذا نسختي التقرير سوي ريستارت
 
عملت ريستارت زي ماهو طالب بالرسالة
انا قلت ممكن لأنه بعد ماينتهي الفحص حسب الشرح انه لازم اعمل حذف بعدها تطلع لي النتيجة في ملف نصي
ولما طلع لي الملف النصي ورجعت لنفس نافذة الفحص لقيت الرسالة تقول انه ممكن ما انحذف فشكيت في الامر
 
الأخ فورمات شكرا على الشرح
هل اطلعت على نتيجة الفحص لجهازي حسب الطريقة الي اشار فيها الأخ علي همر ؟
 
يا اعضاء المنتدى الله يعافيكم احد يرد علي
 
أين انتم يا اعضاء ؟؟
انتظر الرد
 
الأخ فورمات طبقت ماذكرته وهذه هي النتيجة

SUPERAntiSpyware Scan Log

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


Generated 02/24/2012 at 11:43 AM
Application Version : 5.0.1144
Core Rules Database Version : 8273
Trace Rules Database Version: 6085
Scan type : Complete Scan
Total Scan Time : 00:43:50
Operating System Information
Windows 7 Professional 32-bit (Build 6.01.7600)
UAC Off - Administrator
Memory items scanned : 980
Memory threats detected : 0
Registry items scanned : 44185
Registry threats detected : 0
File items scanned : 58533
File threats detected : 71
Adware.Tracking Cookie
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@ad.yieldmanager[1].txt [ /ad.yieldmanager ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@ad.yieldmanager[2].txt [ /ad.yieldmanager ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@adbrite[2].txt [ /adbrite ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@adbrite[3].txt [ /adbrite ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@adtech[1].txt [ /adtech ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@adtech[2].txt [ /adtech ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@at.atwola[2].txt [ /at.atwola ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@atdmt[2].txt [ /atdmt ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@atdmt[3].txt [ /atdmt ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@atdmt[4].txt [ /atdmt ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@bs.serving-sys[1].txt [ /bs.serving-sys ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@bs.serving-sys[2].txt [ /bs.serving-sys ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@c.atdmt[2].txt [ /c.atdmt ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@c.atdmt[3].txt [ /c.atdmt ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@clicksor[2].txt [ /clicksor ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@doubleclick[1].txt [ /doubleclick ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@doubleclick[3].txt [ /doubleclick ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@doubleclick[4].txt [ /doubleclick ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@h.atdmt[2].txt [ /h.atdmt ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@h.atdmt[3].txt [ /h.atdmt ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@h.atdmt[4].txt [ /h.atdmt ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@imrworldwide[2].txt [ /imrworldwide ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@imrworldwide[3].txt [ /imrworldwide ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@interclick[1].txt [ /interclick ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@interclick[3].txt [ /interclick ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@invitemedia[1].txt [ /invitemedia ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@kaspersky.122.2o7[1].txt [ /kaspersky.122.2o7 ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@lucidmedia[1].txt [ /lucidmedia ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@lucidmedia[2].txt [ /lucidmedia ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@mediafire[2].txt [ /mediafire ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@mediafire[3].txt [ /mediafire ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@microsoftsto.112.2o7[1].txt [ /microsoftsto.112.2o7 ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@microsoftwlsearchcrm.112.2o7[1].txt [ /microsoftwlsearchcrm.112.2o7 ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@microsoftwlsearchcrm.112.2o7[2].txt [ /microsoftwlsearchcrm.112.2o7 ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@mmotraffic[2].txt [ /mmotraffic ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@myroitracking[1].txt [ /myroitracking ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@mywebsearch[1].txt [ /mywebsearch ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@questionmarket[2].txt [ /questionmarket ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@revsci[2].txt [ /revsci ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@ru4[1].txt [ /ru4 ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@ru4[2].txt [ /ru4 ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@server.cpmstar[1].txt [ /server.cpmstar ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@serving-sys[1].txt [ /serving-sys ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@serving-sys[2].txt [ /serving-sys ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@tradefx.advertserve[1].txt [ /tradefx.advertserve ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@tradefx.advertserve[2].txt [ /tradefx.advertserve ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@tribalfusion[1].txt [ /tribalfusion ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@www.googleadservices[1].txt [ /www.googleadservices ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Cookies\user@xiti[1].txt [ /xiti ]
C:\USERS\USER\Cookies\user@mediafire[2].txt [ Cookie:user@mediafire.com/ ]
C:\USERS\USER\Cookies\user@serving-sys[1].txt [ Cookie:user@serving-sys.com/ ]
C:\USERS\USER\Cookies\user@adbrite[3].txt [ Cookie:user@adbrite.com/ ]
C:\USERS\USER\Cookies\user@adtech[2].txt [ Cookie:user@adtech.de/ ]
C:\USERS\USER\Cookies\user@ru4[2].txt [ Cookie:user@ru4.com/ ]
C:\USERS\USER\Cookies\user@mmotraffic[2].txt [ Cookie:user@mmotraffic.com/ ]
C:\USERS\USER\Cookies\user@revsci[2].txt [ Cookie:user@revsci.net/ ]
C:\USERS\USER\Cookies\user@atdmt[4].txt [ Cookie:user@atdmt.com/ ]
C:\USERS\USER\Cookies\user@tradefx.advertserve[2].txt [ Cookie:user@tradefx.advertserve.com/ ]
C:\USERS\USER\Cookies\user@lucidmedia[2].txt [ Cookie:user@lucidmedia.com/ ]
C:\USERS\USER\Cookies\user@at.atwola[2].txt [ Cookie:user@at.atwola.com/ ]
C:\USERS\USER\Cookies\user@bs.serving-sys[2].txt [ Cookie:user@bs.serving-sys.com/ ]
C:\USERS\USER\Cookies\user@h.atdmt[4].txt [ Cookie:user@h.atdmt.com/ ]
C:\USERS\USER\Cookies\user@microsoftwlsearchcrm.112.2o7[2].txt [ Cookie:user@microsoftwlsearchcrm.112.2o7.net/ ]
C:\USERS\USER\Cookies\user@interclick[3].txt [ Cookie:user@interclick.com/ ]
a.ads2.msads.net [ C:\USERS\USER\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\U244YDJ8 ]
cdn5.tribalfusion.com [ C:\USERS\USER\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\U244YDJ8 ]
media.scanscout.com [ C:\USERS\USER\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\U244YDJ8 ]
porn-tubes.us [ C:\USERS\USER\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\U244YDJ8 ]
secure-us.imrworldwide.com [ C:\USERS\USER\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\U244YDJ8 ]

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي

[ C:\USERS\USER\APPDATA\ROAMING\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\U244YDJ8 ]
Trojan.Agent/Gen-Frauder
C:\PROGRAM FILES\ZTE CONNECTION MANAGER\COMPONENT\BIUSBSOUND.DLL
 
حمل الاداة من هذا الموضوع

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي



واعمل تقرير هايجاك + قائمة البرامج المثبتة
 
هذي النتيجة

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 02:23:51 م, on 24/02/12
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\windows\system32\taskhost.exe
c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\ZTE Connection Manager\UIExec.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\real\realplayer\Update\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Nokia\PC Internet Access\NPCIA.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe
c:\Program Files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsender_gui.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtblfs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Zyzoom_Forum_Tools\zHijak.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {b760d5a4-8d24-4cb6-942e-d6bb540ad88c} - (no file)
R3 - URLSearchHook: (no name) - {f864ba3f-9878-458a-ba2b-dad32bcbc472} - C:\Program Files\CieoNetUtilities_0e\bar\1.bin\0eSrcAs.dll (file missing)
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll
O3 - Toolbar: CieoNet Utilities - {8175e372-1ff1-4288-8e6e-addebd415d47} - C:\Program Files\CieoNetUtilities_0e\bar\1.bin\0ebar.dll (file missing)
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
O4 - HKLM\..\Run: [IMSS] "C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [PlusService] C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [UIExec] "C:\Program Files\ZTE Connection Manager\UIExec.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [NokiaPCInternetAccess] "C:\Program Files\Nokia\PC Internet Access\NPCIA.exe" /b
O4 - HKCU\..\Run: [DriverScanner] "C:\Program Files\Uniblue\DriverScanner\launcher.exe" delay 20000
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: &لوحة المفاتيح الظاهرية - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: فحص &عناوين المواقع (URL) - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll, C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\aestsrv.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: ArcGIS License Manager - Acresso Software Inc. - C:\PROGRA~1\ESRI\License\arcgis9x\lmgrd.exe
O23 - Service: خدمة Kaspersky لمكافحة الفيروسات (AVP) - Kaspersky Lab ZAO - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP SkyRoom (Hp.Skyroom.Windows.Service) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP SkyRoom\Hp.Skyroom.Windows.Service.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP QuickLook\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Company - C:\windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\windows\system32\nvvsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Remote Graphics Sender Service (rgsender) - Hewlett-Packard, Inc. - c:\Program Files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsendersvc.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\STacSV.exe
O23 - Service: UI Assistant Service - Unknown owner - C:\Program Files\ZTE Connection Manager\AssistantServices.exe
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
--
End of file - 13853 bytes
 
عفوا اخ ماكس كيف اعرف القيم المطلوب حذفها ؟؟
هل ينفع اروح للخطوة الثانية الي هي قائمة البرامج المثبته وانا لسى ماحذفت ؟
 
الحالة
مغلق و غير مفتوح للمزيد من الردود.
عودة
أعلى