• بادئ الموضوع بادئ الموضوع الورد
  • تاريخ البدء تاريخ البدء
  • المشاهدات 2,973

الورد

زيزوومي نشيط
إنضم
18 أبريل 2008
المشاركات
195
مستوى التفاعل
6
النقاط
230
غير متصل
الأعضاء الكرام

اليوم ظهر على سطح المكتب ثلاث ملفات بصورة فجائية !

باسم :

MS-DOS Program

و :

realsched



مع أني لم أحمل أي برنامج إطلاقا ولم أفعل أي شيء برمجي ، فقط تصفحت بعد المدونات

و ثمة مدونة كانت ثقيلة في التصفح .. المهم قبل أن أغلق الجهاز وجدت على سطح المكتب هذه الملفات

وهذه صورتها :



zyzoom-d642f8eeeb.jpg




1- كيف دخلت علي ؟
2 - هل هي خطيرة ؟
3 - كيف أزيلها ؟ لأني لم أجدها في خانة ( إضافة البرامج وإزالتها )


نفع الله بكم .
 

يا إخوان ما الحل ؟ أنا لم أدخل بريدي بسبب هذه الأشياء التي في جهازي

أرجو مطالعة صفحة 2 من فضلكم
 

هلا اخوي
الموقع ممتاز :king:

:q:

انت مصاب بــ ملف تجسس

بواسطه هاكر يستخدم

PoisonIvy

و حمل برنامج هذا البرنامج

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


و اعمل فحص و تقرير

بالنسبه لارقامك السريه الهاكر يقدر يسرق الباسوردات

عن طريق الكي لوقر

و اي شيئ تكتبه!!

:hh: في الوقت الحالي ننصحك لا تكتب ارقام سريه

و المدونات يمكن الشخص حط صفحه ملغمه و الله أعلم

 
جزاك الله خيرا ورفع قدرك آمين ، تفضل التقرير من هذا البرنامج :



Logfile of Spyware Terminator v2.3.0.487 (db:2.009.005.000)
Scan Time: 05/09/2008 03:15:05 م length: 1208 s
Platform: WXP (5.1.0.2600)
User: Admin
Boot Mode: Normal
Scan type: Full_Spyware_Scan
Scanned s: 107786 (Critical:6)
Filter: No System items, No Safe items, No Invalid items

Running Processes
st330service.exe [THOMSON Telecom Belgium] : C:\Program Files\Thomson SpeedTouch\ST330\service\st330service.exe
avp.exe [Kaspersky Lab] : C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
mysqld-nt.exe : C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
avp.exe [Kaspersky Lab] : C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
Skype.exe [Skype Technologies S.A.] : C:\Documents and Settings\USER\Desktop\خدمية\Skype.exe
usnsvc.exe [Microsoft Corporation] : C:\Program Files\Windows Live\Messenger\usnsvc.exe
msnmsgr.exe [Microsoft Corporation] : C:\Program Files\Windows Live\Messenger\msnmsgr.exe
firefox.exe [Mozilla Corporation] : C:\Program Files\Minefield\firefox.exe

Internet Settings
R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain =
R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName =

StartUps
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, msnmsgr : [Microsoft Corporation] : C:\Program Files\Windows Live\Messenger\msnmsgr.exe
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Skype : [Skype Technologies S.A.] : C:\Documents and Settings\USER\Desktop\خدمية\Skype.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, AVP : [Kaspersky Lab] : C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, !AVG Anti-Spyware : [GRISOFT s.r.o.] : C:\Program Files\GRISOFT\AVG ANTI-SPYWARE 7.5\ZYZOOM.EXE
04 - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs : [Kaspersky Lab] : C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll
04 - Startup: %STARTUP%\TempClean.lnk : C:\Program Files\TempClean\TempClean.exe

Shell Extensions
Outlook File Icon Extension - {0006F045-0000-0000-C000-000000000046} - [Microsoft Corporation] : C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL
CuteFTP 8 Professional Shell Extension - {8f7261d0-d2b9-11d2-9909-00605205b24c} - [GlobalSCAPE, Inc.] : C:\Program Files\GlobalSCAPE\CuteFTP 8 Professional\CuteShell.dll
WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} - : C:\Program Files\WinRAR\rarext.dll
UnlockerShellExtension - {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} - : C:\Program Files\Unlocker\UnlockerCOM.dll
Haali Column Provider - {0561EC90-CE54-4f0c-9C55-E226110A740C} - : C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Haali Matroska Shell Property Page - {5574006C-28F5-4a65-A28C-74DE6BFBE0BB} - : C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Haali Matroska Thumbnail Extractor - {327669A0-59A7-4be9-B99E-1C9F3A57611A} - : C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Web Anti-Virus statistics - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - [Kaspersky Lab] : C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll

Shell Extecute Hooks
CShellExecuteHookImpl - {{57B86673-276A-48B2-BAE7-C6DBB3020EB8}} - [GRISOFT s.r.o.] : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll

Protocol Handler
Data Page Pluggable Protocol mso-offdap Handler - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - [Microsoft Corporation] : C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
IEProtocolHandler Class - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - [Skype Technologies] : C:\Program Files\Common Files\Skype\Skype4COM.dll

Services
23 - : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
23 - [GRISOFT, s.r.o.] : C:\WINDOWS\system32\DRIVERS\AvgAsCln.sys
23 - [Kaspersky Lab] : C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
23 - [C-Media Inc] : C:\WINDOWS\system32\drivers\cmuda.sys
23 - [Kaspersky Lab] : C:\WINDOWS\system32\drivers\72885666.sys
23 - [Kaspersky Lab] : C:\WINDOWS\system32\drivers\kl1.sys
23 - [Kaspersky Lab] : C:\WINDOWS\system32\drivers\klif.sys
23 - [Kaspersky Lab] : C:\WINDOWS\system32\DRIVERS\klim5.sys
23 - : C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
23 - [VSO Software] : C:\WINDOWS\system32\Drivers\pcouffin.sys
23 - [PCTEL, INC.] : C:\WINDOWS\system32\DRIVERS\ptserial.sys
23 - [THOMSON Telecom Belgium] : C:\WINDOWS\system32\drivers\st330.sys
23 - [THOMSON Telecom Belgium] : C:\WINDOWS\system32\drivers\stbus.sys
23 - [THOMSON Telecom Belgium] : C:\WINDOWS\system32\DRIVERS\stppp.sys
23 - [Microsoft Corporation] : C:\Program Files\Windows Live\Messenger\usnsvc.exe
23 - [Conexant Systems, Inc.] : C:\WINDOWS\system32\DRIVERS\vmodem.sys
23 - [Conexant Systems, Inc.] : C:\WINDOWS\system32\DRIVERS\vpctcom.sys
23 - [Conexant Systems, Inc.] : C:\WINDOWS\system32\DRIVERS\vvoice.sys

Winlogon Notify
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon, DLLName : [Kaspersky Lab] : C:\WINDOWS\system32\klogon.dll

Threat Files
<Backdoor.W32.Delf.MOD> : C:\Documents and Settings\USER\Desktop\خدمية\Zyzoom_avg-anti-spyware_Book.exe
<Trojan.Agent.56757> : C:\Program Files\Ozone\Audio Converter\opt.exe
<SPR/Tool.Hide.A> : C:\System Volume Information\_restore{7AC9F497-31A3-4F74-84A9-60FE32A61A49}\RP11\A0001103.exe

Advanced Files Report
%PROGRAMFILES%\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll [Kaspersky Lab] [Kaspersky Anti-Virus] MD5=65DCD932B54FFACB748B3DFC715CFDC2 SIZE=91400
%SYSDIR%\klogon.dll [Kaspersky Lab] [Kaspersky Anti-Virus] MD5=535A597F39F7F6F4A4AA250447357DA0 SIZE=206088
%PROGRAMFILES%\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll [Kaspersky Lab] [Kaspersky Anti-Virus] MD5=2812CCA795BF75BA201252C728F92787 SIZE=95496
%PROGRAMFILES%\Thomson SpeedTouch\ST330\service\st330service.exe [THOMSON Telecom Belgium] [Host Service] MD5=D0077BA4623D8CB61360837550B618A9 SIZE=389215
%PROGRAMFILES%\Thomson SpeedTouch\ST330\service\qt-mt332.dll [Trolltech AS] [Qt] MD5=EE12AF0F59D70B6CAA2058645BA69B51 SIZE=4222976
%PROGRAMFILES%\Thomson SpeedTouch\ST330\service\dmapi.dll [THOMSON Telecom Belgium] [device management functions] MD5=8A1E083DE5F15C2FADCAB0C01F72B0F6 SIZE=188416
%PROGRAMFILES%\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll [Kaspersky Lab] [Kaspersky Anti-Virus] MD5=E1A195577A9447A7A0B06EA3C056C286 SIZE=161032
%PROGRAMFILES%\WinRAR\rarext.dll MD5=023707D932BA31314210E6844D33D500 SIZE=129024
%PROGRAMFILES%\Unlocker\UnlockerCOM.dll MD5=DA66CEAF1DEF4DA337F1542E0308483D SIZE=10240
%PROGRAMFILES%\Kaspersky Lab\Kaspersky Internet Security 7.0\ShellEx.dll [Kaspersky Lab] [Kaspersky Anti-Virus] MD5=2E1840060C5447C0135AA2EE4EB78BA6 SIZE=39688
%PROGRAMFILES%\GlobalSCAPE\CuteFTP 8 Professional\CuteShell.dll [GlobalSCAPE, Inc.] [Shell Integration DLL] MD5=884ACDD9E9C0D2D232076A8F606C5A5F SIZE=245760
%PROGRAMFILES%\Grisoft\AVG Anti-Spyware 7.5\context.dll [GRISOFT s.r.o.] [AVG Anti-Spyware] MD5=C9C6386CDCF2706F1BD860D63CF6405C SIZE=144944
%PROGRAMFILES%\Haali\MatroskaSplitter\mmfinfo.dll MD5=61452B71670D12216F288D46D0879F71 SIZE=159744
%PROGRAMFILES%\Haali\MatroskaSplitter\mkunicode.dll MD5=48A2007CFE0AC7109B049711CD8878E9 SIZE=23552
%PROGRAMFILES%\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [GRISOFT s.r.o.] [AVG Anti-Spyware] MD5=3FD0B984601D65C6DA8E891A0D5905D1 SIZE=79408
%SYSDIR%\hpzsnt07.dll [HP] [HP DeskJet] MD5=FB44C8568224451A43B745C39C182406 SIZE=184386
%PROGRAMFILES%\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe MD5=895A10B17CEFA1A9585F2745EBD8CA57 SIZE=3502080
%PROGRAMFILES%\Windows Live\Messenger\usnsvc.exe [Microsoft Corporation] [Messenger] MD5=91F1745DC9BF3745BEE572FD4777C6A1 SIZE=98672
%PROGRAMFILES%\Windows Live\Messenger\MSIMG32.dll [Patchou] [Messenger Plus! Live] MD5=67DE23C7D320590168DAD1B59CF59F3A SIZE=59728
%PROGRAMFILES%\Messenger Plus! Live\MsgPlusLive.dll [Patchou] [Messenger Plus! Live] MD5=EB73B015ABE61E67F02FB14B95E6E8C2 SIZE=3374928
%PROGRAMFILES%\Messenger Plus! Live\Detoured.dll MD5=6256684495C499B22DCDBA266E4F2494 SIZE=4096
%PROGRAMFILES%\Messenger Plus! Live\MsgPlusLiveRes.dll [Patchou] [Messenger Plus! Live] MD5=68262E065949567D7B38F4EC757B09E7 SIZE=1831248
%PROGRAMFILES%\Minefield\firefox.exe [Mozilla Corporation] [Firefox] MD5=B6B1E546F05C9FF636E80171AB62A557 SIZE=79872
%PROGRAMFILES%\Minefield\xul.dll [Mozilla Foundation] [Minefield] MD5=CB6C9F6B4957CAA2E3D60015748B032B SIZE=8603136
%PROGRAMFILES%\Minefield\sqlite3.dll [sqlite.org] [SQLite Database Library] MD5=D82D6EA9D35C6AF555F838D36389C673 SIZE=393728
%PROGRAMFILES%\Minefield\MOZCRT19.dll [Mozilla Foundation] [Mozilla Custom C Runtime] MD5=99905097BDBDBDF3772F6384F83A02D0 SIZE=704512
%PROGRAMFILES%\Minefield\js3250.dll [Netscape Communications Corporation] [NETSCAPE] MD5=567802E9692A5028EDEDE4A2B700456E SIZE=595456
%PROGRAMFILES%\Minefield\nspr4.dll [Mozilla Foundation] [Netscape Portable Runtime] MD5=16E43FCC221098B2CB412B1772D0D648 SIZE=163840
%PROGRAMFILES%\Minefield\smime3.dll [Mozilla Foundation] [Network Security Services] MD5=139B3A30D040BA9B402A3ADF3304206E SIZE=98304
%PROGRAMFILES%\Minefield\nss3.dll [Mozilla Foundation] [Network Security Services] MD5=533ECD641AAA33DC49EB178BD21E905E SIZE=692224
%PROGRAMFILES%\Minefield\nssutil3.dll [Mozilla Foundation] [Network Security Services] MD5=DA56028362F9BD5B6B3572D37C524799 SIZE=81920
%PROGRAMFILES%\Minefield\plc4.dll [Mozilla Foundation] [Netscape Portable Runtime] MD5=A157125ECBDEAC8D98AA18CC0E57919A SIZE=14848
%PROGRAMFILES%\Minefield\plds4.dll [Mozilla Foundation] [Netscape Portable Runtime] MD5=CF001F02F3BB14AB27F3D842674B6069 SIZE=11264
%PROGRAMFILES%\Minefield\ssl3.dll [Mozilla Foundation] [Network Security Services] MD5=C32888BFFCB09BB421BA4CF91DB2967E SIZE=131072
%PROGRAMFILES%\Minefield\xpcom.dll [Mozilla Foundation] [Minefield] MD5=9DF775DFED95DD9FD2FD2848B4079C8A SIZE=12288
%PROGRAMFILES%\Minefield\components\browserdirprovider.dll [Mozilla Foundation] [Minefield] MD5=D3232F95FD1BD215203404E15167E8F6 SIZE=17920
%PROGRAMFILES%\Minefield\softokn3.dll [Mozilla Foundation] [Network Security Services] MD5=C4D97168AF98B5808E3B505E5CE8602A SIZE=151552
%PROGRAMFILES%\Minefield\nssdbm3.dll [Mozilla Foundation] [Network Security Services] MD5=7C2DA59D5486AEF97B91A7E6B8422051 SIZE=98304
%PROGRAMFILES%\Minefield\freebl3.dll [Mozilla Foundation] [Network Security Services] MD5=E4A89415780A86022DF2CC7441A583C7 SIZE=233472
%PROGRAMFILES%\Minefield\nssckbi.dll [Mozilla Foundation] [Network Security Services] MD5=47C9324D42B72A06296F3846FEABF56A SIZE=278528
%PROGRAMFILES%\Minefield\components\brwsrcmp.dll [Mozilla Foundation] [Minefield] MD5=3724DB9E98818059682E3EDD5A7BA4CF SIZE=129024
%PROGRAMFILES%\Lavasoft\Ad-Aware\Ad-Watch.exe
%PROGRAMFILES%\TempClean\TempClean.exe MD5=FA74FF4D6BDD5F252AEEC345AF03FA3A SIZE=356352
deskpan.dll
%PROGRAMFILES%\Microsoft Office\Office10\OLKFSTUB.DLL [Microsoft Corporation] [Microsoft Outlook] MD5=36D3D7DB63CBB3AA50D8D37908BCF80B SIZE=54688
%PROGRAMFILES%\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll [Kaspersky Lab] [Kaspersky Anti-Virus] MD5=A89F8FCE1FFEDAFD910B26783DB1CC5A SIZE=222472
%SYSDIR%\svchost.exe -k netsvcs
%PROGRAMFILES%\Grisoft\AVG Anti-Spyware 7.5\guard.sys MD5=D6F4C1450699901048818B0C3AAF7A17 SIZE=11000
%SYSDIR%\DRIVERS\AvgAsCln.sys [GRISOFT, s.r.o.] [AVG7 Clean Driver] MD5=856B0CEE009946BF2D327E6B24FE7E3F SIZE=10872
%SYSDIR%\drivers\cmuda.sys [C-Media Inc] [C-Media Audio Driver (WDM)] MD5=883F93DE120956CB25FD69D1636B5530 SIZE=1372992
%SYSDIR%\svchost -k DcomLaunch
%SYSDIR%\svchost.exe -k NetworkService
%SYSDIR%\drivers\72885666.sys [Kaspersky Lab] [Kaspersky Anti-Virus] MD5=33E4B5D3D679B0C3D274EE7E4C1C8758 SIZE=148496
%SYSDIR%\drivers\kl1.sys [Kaspersky Lab] [Kaspersky Anti-Virus] MD5=45056287CDD70803BAD130BF71FE6890 SIZE=112144
%SYSDIR%\drivers\klif.sys [Kaspersky Lab] [Kaspersky Anti-Virus] MD5=9256DA35CEE573515D346B4F3598B72E SIZE=194320
%SYSDIR%\DRIVERS\klim5.sys [Kaspersky Lab] [Kaspersky Anti-Virus] MD5=967E2224217431B21F1D04FBB4C68A4B SIZE=24344
%SYSDIR%\svchost.exe -k LocalService
%SYSDIR%\Drivers\pcouffin.sys [VSO Software] [Patin couffin engine] MD5=02AAAFB7BA137CE5DDABCDF8090954D9 SIZE=47360
%SYSDIR%\DRIVERS\ptserial.sys [PCTEL, INC.] [HSP Modem Serial Device] MD5=320BE4E259519B0EF595EA23BF494EF0 SIZE=362878
%SYSDIR%\svchost -k rpcss
%SYSDIR%\drivers\st330.sys [THOMSON Telecom Belgium] [SpeedTouch 330] MD5=C9FA6A70C051FC59D22C2E4CD211AD9B SIZE=30464
%PROGRAMFILES%\Thomson SpeedTouch\ST330\service\st330service.exe -service
%SYSDIR%\drivers\stbus.sys [THOMSON Telecom Belgium] [SpeedTouch vbus] MD5=0017202EB0224F82706F04ED35AB23C2 SIZE=12672
%SYSDIR%\svchost.exe -k imgsvc
%SYSDIR%\DRIVERS\stppp.sys [THOMSON Telecom Belgium] [SpeedTouch PPP Adapter] MD5=0A9484E3CDAFB529B392B5E9EBBC4AA6 SIZE=32000
%SYSDIR%\DRIVERS\vmodem.sys [Conexant Systems, Inc.] [HSP Modem Modem Device] MD5=64E0B9AC79424324D780D156A0B0461C SIZE=703737
%SYSDIR%\DRIVERS\vpctcom.sys [Conexant Systems, Inc.] [HSP Modem Virtual Control Device] MD5=809CCB9329171C24C9365E5E0CED448C SIZE=804754
%SYSDIR%\DRIVERS\vvoice.sys [Conexant Systems, Inc.] [Conexant HSP Modem Voice Device] MD5=0BC95D34E9C224F496C1487D167B0FB8 SIZE=70384
%COMMONFILES%\Microsoft Shared\Web Components\10\OWC10.DLL [Microsoft Corporation] [Microsoft Office XP] MD5=5CEE2E73B50AA544F512BF864748C9E5 SIZE=7436272
%COMMONFILES%\Skype\Skype4COM.dll [Skype Technologies] [Skype4COM] MD5=2F7520EFE75CA986F9E41B53162B7144 SIZE=1942864
%COMMONFILES%\Adobe\Updater5\AdobeUpdater.es_ES [Adobe Systems Incorporated] [Adobe Updater] MD5=9CD71F31D3D66802F41CB85FC40E351B SIZE=65728
%COMMONFILES%\Microsoft Shared\GRPHFLT\CGMIMP32.FLT [Microsoft Corporation] [منقيات رسومات Microsoft] MD5=A130A4D5202C410242746D2544AC2BEF SIZE=417792
%COMMONFILES%\Microsoft Shared\Smart Tag\FPERSON.DLL [Microsoft Corporation] [Microsoft Office XP] MD5=595FC7AC26E2653A343F1FE787EB8561 SIZE=288160
%SYSDIR%\mfc70.dll [Microsoft Corporation] [Microsoft® Visual Studio .NET] MD5=09AEF167EB1531E965053D0DCF6CC573 SIZE=974848

End of Report
 
C:\Program Files\Ozone\Audio Converter\opt.exe

هذا برنامج شنو؟ لان مكتوب انه فايروس يفضل حذفه

C:\System Volume Information\_restore{7AC9F497-31A3-4F74-84A9-60FE32A61A49}\RP11\A0001103.exe

لديك فيروس مخزن نفسه في الريستور فايل

اتوقع الكاسبر يمسك ؟ بس يرجع صح؟

حاول تحط الأفيرا لانه الأفضل في مسح الفيروسات

افتح الران

و حط C:\System Volume Information\_restore{7AC9F497-31A3-4F74-84A9-60FE32A61A49}\RP11

و اضغط open

و ابحث هناك عن ملف باسم A0001103.exe و احذفه

***

بعدين فحص بال Spyware Terminator و امسح اي فيروس يجيك و تقرير

:) ووفقك الله

***

صح كيف هذاك الملفين راحوا ؟

اذا لا امسحهم من سطح المكتب و من الزباله ايضا
 
حقيقة لا أدري كيف أشكرك أستاذي ( القبطان الصغير )

أما بخصوص الملفين

MS-DOS Program
و :
realsched

فقد حذفتهما من سطح المكتب لمّا لم أجد جوابا على سؤالي .

لكن بقيت تبعاتها السيئة في الجهاز والكاسبر ينذر بوجودها ، فلما أضغط مسح يعترف أنه لا يستطيع مسحها ، هذا كل يوم يحدث معي !

فلما دللتني على طريقة ( الران ) حذفت أكثر من 6 ملفات مصابة يدويا ، وهذه الطريقة رهيبة :ok:

والآن أنا اتبعت كل ما أشرت به عليّ :

1- حذفت الكاسبر

2- حملت الأفيرا وفحصت الجهاز به وهذا تقرير الأفيرا :



Avira AntiVir Premium
Report file date: 05 سبتمبر, 2008 23:25

Scanning for 1599979 virus strains and unwanted programs.

Licensed to: Kevin Ponsen
Serial number: 1101196954-MEDIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: PC-9FE9660ED372

Version information:
BUILD.DAT : 8.1.0.367 20012 Bytes 12/08/2008 11:31:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 07:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 06:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 11:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 06:58:52
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 09:33:34
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 12:54:15
ANTIVIR2.VDF : 7.0.6.94 2998784 Bytes 31/08/2008 20:22:30
ANTIVIR3.VDF : 7.0.6.124 202240 Bytes 05/09/2008 20:22:33
Engineversion : 8.1.1.28
AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 08:58:21
AESCRIPT.DLL : 8.1.0.70 319866 Bytes 05/09/2008 20:22:50
AESCN.DLL : 8.1.0.23 119156 Bytes 10/07/2008 11:44:49
AERDL.DLL : 8.1.1.1 397683 Bytes 05/09/2008 20:22:48
AEPACK.DLL : 8.1.2.1 364917 Bytes 15/07/2008 11:58:35
AEOFFICE.DLL : 8.1.0.23 196987 Bytes 05/09/2008 20:22:46
AEHEUR.DLL : 8.1.0.51 1397111 Bytes 05/09/2008 20:22:44
AEHELP.DLL : 8.1.0.15 115063 Bytes 10/07/2008 11:44:48
AEGEN.DLL : 8.1.0.36 315764 Bytes 05/09/2008 20:22:39
AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 07:33:21
AECORE.DLL : 8.1.1.11 172406 Bytes 05/09/2008 20:22:37
AEBB.DLL : 8.1.0.1 53617 Bytes 10/07/2008 11:44:48
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 07:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 08:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 05/09/2008 20:22:35
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 10:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 07:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 11:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 16:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 11:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 11:05:10
RCIMAGE.DLL : 8.0.0.51 2564353 Bytes 12/06/2008 12:29:30
RCTEXT.DLL : 8.0.51.0 86273 Bytes 27/06/2008 10:00:56

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition premium\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: 05 سبتمبر, 2008 23:25

The scan of running processes will be started
Scan process 'avwsc.exe' - '0' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'avmailc.exe' - '1' Module(s) have been scanned
Scan process 'avwebgrd.exe' - '1' Module(s) have been scanned
Scan process 'avesvc.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'WINWORD.EXE' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'IDMan.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'sp_rsser.exe' - '1' Module(s) have been scanned
Scan process 'mysqld-nt.exe' - '1' Module(s) have been scanned
Scan process 'MDM.EXE' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'st330service.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
31 processes with 31 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '46' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\System Volume Information\_restore{7AC9F497-31A3-4F74-84A9-60FE32A61A49}\RP24\A0002804.exe
[DETECTION] Is the TR/Small.24064 Trojan
[NOTE] The file was moved to '48f1b0ee.qua'!
C:\System Volume Information\_restore{7AC9F497-31A3-4F74-84A9-60FE32A61A49}\RP24\A0002805.exe
[DETECTION] Is the TR/Agent.791427 Trojan
[NOTE] The file was moved to '48f1b0f2.qua'!
Begin scan in 'D:\' <DISK1_VOL2>
D:\جامع ذاكرة الهاتف 2008\ذاكرة 17-12-2007\ذاكرة n 70\Al ajme (E)\أنتي فايروس جديد.sis
[DETECTION] Contains the SYMBOS/Drever.D Symbian OS virus
[NOTE] The file was moved to '4eebb9af.qua'!


End of the scan: 06 سبتمبر, 2008 01:42
Used time: 2:17:25 Hour(s)

The scan has been done completely.

3491 Scanning directories
179953 Files were scanned
3 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
3 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
179949 Files not concerned
1174 Archives were scanned
1 Warnings
3 Notes


===================================================


===================================================



3- نزلت السباي وير ، وأنا أشكرك عليه كثيرا ، فيبدو أنه دقيق للغاية
بخلاف ما سبقه في جهازي فقد كان يمر عليها ولا يكتشفها !


وهذا تقرير السابي وير :




Logfile of Spyware Terminator v2.3.0.487 (db:2.009.005.000)
Scan Time: 06/09/2008 01:52:16 م length: 1574 s
Platform: WXP (5.1.0.2600)
User: Admin
Boot Mode: Normal
Scan type: Full_Spyware_Scan
Scanned s: 99412 (Critical:0)
Filter: No System items, No Safe items, No Invalid items

Running Processes
st330service.exe [THOMSON Telecom Belgium] : C:\Program Files\Thomson SpeedTouch\ST330\service\st330service.exe
sched.exe [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
avgnt.exe [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
msnmsgr.exe [Microsoft Corporation] : C:\Program Files\Windows Live\Messenger\msnmsgr.exe
avguard.exe [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
avesvc.exe [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
mysqld-nt.exe : C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
avmailc.exe [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
AVWEBGRD.EXE [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE

Internet Settings
R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain =
R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName =

StartUps
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, msnmsgr : [Microsoft Corporation] : C:\Program Files\Windows Live\Messenger\msnmsgr.exe
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Skype : [Skype Technologies S.A.] : C:\Documents and Settings\USER\Desktop\خدمية\SKYPE.EXE
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, avgnt : [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
04 - Startup: %STARTUP%\TempClean.lnk : C:\Program Files\TempClean\TempClean.exe

Shell Extensions
Outlook File Icon Extension - {0006F045-0000-0000-C000-000000000046} - [Microsoft Corporation] : C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL
CuteFTP 8 Professional Shell Extension - {8f7261d0-d2b9-11d2-9909-00605205b24c} - [GlobalSCAPE, Inc.] : C:\Program Files\GlobalSCAPE\CuteFTP 8 Professional\CuteShell.dll
WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} - : C:\Program Files\WinRAR\rarext.dll
UnlockerShellExtension - {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} - : C:\Program Files\Unlocker\UnlockerCOM.dll
Haali Column Provider - {0561EC90-CE54-4f0c-9C55-E226110A740C} - : C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Haali Matroska Shell Property Page - {5574006C-28F5-4a65-A28C-74DE6BFBE0BB} - : C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Haali Matroska Thumbnail Extractor - {327669A0-59A7-4be9-B99E-1C9F3A57611A} - : C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
Shell Extension for Malware scanning - {45AC2688-0253-4ED8-97DE-B5370FA7D48A} - [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\shlext.dll

Protocol Handler
Data Page Pluggable Protocol mso-offdap Handler - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - [Microsoft Corporation] : C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
IEProtocolHandler Class - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - [Skype Technologies] : C:\Program Files\Common Files\Skype\Skype4COM.dll

Services
23 - [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
23 - [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
23 - [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
23 - [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
23 - [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
23 - [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgntflt.sys
23 - [Avira GmbH] : C:\WINDOWS\system32\DRIVERS\avipbb.sys
23 - [C-Media Inc] : C:\WINDOWS\system32\drivers\cmuda.sys
23 - [Kaspersky Lab] : C:\WINDOWS\system32\drivers\72885666.sys
23 - : C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
23 - [VSO Software] : C:\WINDOWS\system32\Drivers\pcouffin.sys
23 - [PCTEL, INC.] : C:\WINDOWS\system32\DRIVERS\ptserial.sys
23 - [Avira GmbH] : C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
23 - [THOMSON Telecom Belgium] : C:\WINDOWS\system32\drivers\st330.sys
23 - [THOMSON Telecom Belgium] : C:\WINDOWS\system32\drivers\stbus.sys
23 - [THOMSON Telecom Belgium] : C:\WINDOWS\system32\DRIVERS\stppp.sys
23 - [Conexant Systems, Inc.] : C:\WINDOWS\system32\DRIVERS\vmodem.sys
23 - [Conexant Systems, Inc.] : C:\WINDOWS\system32\DRIVERS\vpctcom.sys
23 - [Conexant Systems, Inc.] : C:\WINDOWS\system32\DRIVERS\vvoice.sys

Advanced Files Report
%SYSDIR%\avsda.dll [Avira GmbH] [AntiVir Workstation] MD5=095D5F783AA8AE6D71EF39F31ACA8C88 SIZE=94465
%PROGRAMFILES%\Thomson SpeedTouch\ST330\service\st330service.exe [THOMSON Telecom Belgium] [Host Service] MD5=D0077BA4623D8CB61360837550B618A9 SIZE=389215
%PROGRAMFILES%\Thomson SpeedTouch\ST330\service\qt-mt332.dll [Trolltech AS] [Qt] MD5=EE12AF0F59D70B6CAA2058645BA69B51 SIZE=4222976
%PROGRAMFILES%\Thomson SpeedTouch\ST330\service\dmapi.dll [THOMSON Telecom Belgium] [device management functions] MD5=8A1E083DE5F15C2FADCAB0C01F72B0F6 SIZE=188416
%PROGRAMFILES%\Haali\MatroskaSplitter\mmfinfo.dll MD5=61452B71670D12216F288D46D0879F71 SIZE=159744
%PROGRAMFILES%\Haali\MatroskaSplitter\mkunicode.dll MD5=48A2007CFE0AC7109B049711CD8878E9 SIZE=23552
%PROGRAMFILES%\Internet Download Manager\idmmkb.dll [Tonec Inc.] [Internet Download Manager] MD5=2DAD6798DFEF87D21E58CF58F0EAE807 SIZE=34488
%PROGRAMFILES%\Unlocker\UnlockerCOM.dll MD5=DA66CEAF1DEF4DA337F1542E0308483D SIZE=10240
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\shlext.dll [Avira GmbH] [AntiVir Workstation] MD5=09B3D3F6AD9744417574676E5A2836EE SIZE=65793
%PROGRAMFILES%\WinRAR\rarext.dll MD5=023707D932BA31314210E6844D33D500 SIZE=129024
%PROGRAMFILES%\GlobalSCAPE\CuteFTP 8 Professional\CuteShell.dll [GlobalSCAPE, Inc.] [Shell Integration DLL] MD5=884ACDD9E9C0D2D232076A8F606C5A5F SIZE=245760
%SYSDIR%\hpzsnt07.dll [HP] [HP DeskJet] MD5=FB44C8568224451A43B745C39C182406 SIZE=184386
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\sched.exe [Avira GmbH] [AntiVir Workstation] MD5=9773E0650E0BAB7AE161D2A0ECC7678A SIZE=68865
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\schedr.dll [Avira GmbH] [AntiVir Workstation] MD5=EFBABD350FA0E4804CD98CE6FFE98743 SIZE=7937
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\avevtlog.dll [Avira GmbH] [AntiVir Workstation] MD5=61DBB2959632400D4D7E397EBBCEB88F SIZE=119041
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\sqlite3.dll [SQLite Database] MD5=A467ACDA6C73AE3F8DBC6B94602921B5 SIZE=339968
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\cclib.dll [Avira GmbH] [AntiVir Workstation] MD5=C27FD26297D360251B6B4D6782330E98 SIZE=160001
%PROGRAMFILES%\avira\antivir personaledition premium\ccgen.dll [Avira GmbH] [AntiVir Workstation] MD5=AFFEC62925CF3779CF776CA4B534124E SIZE=270593
%PROGRAMFILES%\avira\antivir personaledition premium\ccgenrc.dll [Avira GmbH] [AntiVir Workstation] MD5=58DA316F458B8A17A3C7216E1794956E SIZE=17665
%PROGRAMFILES%\avira\antivir personaledition premium\ccguard.dll [Avira GmbH] [AntiVir Workstation] MD5=2CB68354DCFFB53151A8152EAECE3612 SIZE=213249
%PROGRAMFILES%\avira\antivir personaledition premium\ccgrdrc.dll [Avira GmbH] [AntiVir Workstation] MD5=B8357197B0D864D67D9FD9C5043E3456 SIZE=20225
%PROGRAMFILES%\avira\antivir personaledition premium\avipc.dll [Avira GmbH] [AntiVir Workstation] MD5=922EE25E719104E6D0E166451118E9F4 SIZE=73985
%PROGRAMFILES%\avira\antivir personaledition premium\ccupdate.dll [Avira GmbH] [AntiVir Workstation] MD5=5364855ACDCCCFC8B64DE64946657FB0 SIZE=110849
%PROGRAMFILES%\avira\antivir personaledition premium\ccupdrc.dll [Avira GmbH] [AntiVir Workstation] MD5=AF87BFE66DF01B07FB4F4FC4B3AD3129 SIZE=12545
%PROGRAMFILES%\avira\antivir personaledition premium\cclic.dll [Avira GmbH] [AntiVir Workstation] MD5=97108140E1D381108C3216BC15E739E1 SIZE=53505
%PROGRAMFILES%\avira\antivir personaledition premium\cclicrc.dll [Avira GmbH] [AntiVir Workstation] MD5=208A14217848520CB3DFFB5AD9DAB82E SIZE=5889
%PROGRAMFILES%\avira\antivir personaledition premium\ccmsg.dll [Avira GmbH] [AntiVir Workstation] MD5=2DC1EC49D108D3CDA9F94BF256E42B90 SIZE=155905
%PROGRAMFILES%\Windows Live\Messenger\MSIMG32.dll [Patchou] [Messenger Plus! Live] MD5=67DE23C7D320590168DAD1B59CF59F3A SIZE=59728
%PROGRAMFILES%\Messenger Plus! Live\MsgPlusLive.dll [Patchou] [Messenger Plus! Live] MD5=EB73B015ABE61E67F02FB14B95E6E8C2 SIZE=3374928
%PROGRAMFILES%\Messenger Plus! Live\Detoured.dll MD5=6256684495C499B22DCDBA266E4F2494 SIZE=4096
%PROGRAMFILES%\Messenger Plus! Live\MsgPlusLiveRes.dll [Patchou] [Messenger Plus! Live] MD5=68262E065949567D7B38F4EC757B09E7 SIZE=1831248
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\avguard.exe [Avira GmbH] [AntiVir Workstation] MD5=6BB24E08C602E1E023FC15E25CD32490 SIZE=149761
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\guardmsg.dll [Avira GmbH] [AntiVir Workstation] MD5=FD1A14DE29EC44ED90CB2BE560B3707A SIZE=46337
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\AVPREF.DLL [Avira GmbH] [AntiVir Workstation] MD5=BF8228DD8B40E0BA612CE75CC3A9818C SIZE=38657
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\SMTPLIB.DLL [Avira GmbH] [AntiVir Workstation] MD5=8DC92F512184DBC0A0FA0117BE55BC55 SIZE=28929
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\AVGIO.DLL [Avira GmbH] MD5=7769B062FBEB74A07D47509B4140383A SIZE=124161
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\aecore.dll [Avira GmbH] [AVCORE] MD5=79CFCBE53CC1643B346BA4BF5E937A7F SIZE=172406
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\aevdf.dll [Avira GmbH] [AVVDF] MD5=C9FFFD5005F4FE7131DF6128E98E3A6A SIZE=102772
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\aescript.dll [Avira GmbH] [AVSCRIPT] MD5=432BE60BC3F4CEA43225DAA72CC11091 SIZE=319866
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\aescn.dll [Avira GmbH] [AVSCN] MD5=F519C10B10D73B2B6B75CFEBC5096236 SIZE=119156
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\aerdl.dll [Avira GmbH] [AVRDL] MD5=2D083E606B98F166C9B48AC4EB59240E SIZE=397683
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\aepack.dll [Avira GmbH] [AVPACK] MD5=BC3A6DDC19C4511CA2C37F0938EB8853 SIZE=364917
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\unacev2.dll [ACE Compression Software] [UNACE - freeware ACE extraction component] MD5=DE02C4D04088B69E64ECC30A3D9E22E5 SIZE=77312
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\aeoffice.dll [Avira GmbH] [AVOFFICE] MD5=42E347CC9F526A32F5D900258047C5F6 SIZE=196987
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\aeheur.dll [Avira GmbH] [AVHEUR] MD5=08B8DA1F5B842350A471764632509E27 SIZE=1397111
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\aehelp.dll [Avira GmbH] [AVHELP] MD5=83BAC707A4B7682201A1EB9766B54CEB SIZE=115063
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\aegen.dll [Avira GmbH] [AVGEN] MD5=63F18A1FD1A6D1069B892EC25280E595 SIZE=315764
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\aeemu.dll [Avira GmbH] [AVEMU] MD5=87A6C6E3993D3A635F8E7152FC6D1907 SIZE=430452
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\aebb.dll [Avira GmbH] [AVBB] MD5=BBAD1D9B0694F5E8FE2ACB85283CC5FE SIZE=53617
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\avesvc.exe [Avira GmbH] [AntiVir Workstation] MD5=AC8094334A76C749FF6FE23CD6FA7AB5 SIZE=41217
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\avesvc.dll [Avira GmbH] [AntiVir Workstation] MD5=5D4554333CA4D35FFCBABBD72093911B SIZE=78081
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\avesvcr.dll [Avira GmbH] [AntiVir Workstation] MD5=40B3B3CD8F85AD77C530DD3F5419A149 SIZE=8961
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\webcat.dll [Avira GmbH] [AntiVir Workstation] MD5=E829035483E48DFFD9B5A942C47F187F SIZE=110849
%PROGRAMFILES%\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe MD5=895A10B17CEFA1A9585F2745EBD8CA57 SIZE=3502080
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\avmailc.exe [Avira GmbH] [AntiVir Workstation] MD5=286DE0120C4D93AAD5AD4F60B9467D91 SIZE=164097
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\avmailcr.dll [Avira GmbH] [AntiVir Workstation] MD5=043CD9EED4F92F083CD5C878FF63ECD3 SIZE=69889
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\mgrs.dll [Avira GmbH] [AntiVir Workstation] MD5=CB9BB93C4443665D357A9E6A05C49BE7 SIZE=258305
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE [Avira GmbH] [AntiVir Workstation] MD5=D618C5917F2CB7FD6CB458684DBF415D SIZE=258305
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\msgclient.dll [Avira GmbH] [AntiVir Workstation] MD5=DC281CD8320B114161151611A3C2F56B SIZE=13569
%PROGRAMFILES%\TempClean\TempClean.exe MD5=FA74FF4D6BDD5F252AEEC345AF03FA3A SIZE=356352
deskpan.dll
%PROGRAMFILES%\Microsoft Office\Office10\OLKFSTUB.DLL [Microsoft Corporation] [Microsoft Outlook] MD5=36D3D7DB63CBB3AA50D8D37908BCF80B SIZE=54688
%SYSDIR%\svchost.exe -k netsvcs
%PROGRAMFILES%\Avira\AntiVir PersonalEdition Premium\avgntflt.sys [Avira GmbH] [AntiVir Workstation] MD5=509BB9F79F7986CB0D4D7A7BEF35C6D5 SIZE=52032
%SYSDIR%\DRIVERS\avipbb.sys [Avira GmbH] MD5=C132C2F16A99C0EAD91C600BB81A31F0 SIZE=75072
%SYSDIR%\drivers\cmuda.sys [C-Media Inc] [C-Media Audio Driver (WDM)] MD5=883F93DE120956CB25FD69D1636B5530 SIZE=1372992
%SYSDIR%\svchost -k DcomLaunch
%SYSDIR%\svchost.exe -k NetworkService
%SYSDIR%\drivers\72885666.sys [Kaspersky Lab] [Kaspersky Anti-Virus] MD5=33E4B5D3D679B0C3D274EE7E4C1C8758 SIZE=148496
%SYSDIR%\svchost.exe -k LocalService
%SYSDIR%\Drivers\pcouffin.sys [VSO Software] [Patin couffin engine] MD5=02AAAFB7BA137CE5DDABCDF8090954D9 SIZE=47360
%SYSDIR%\DRIVERS\ptserial.sys [PCTEL, INC.] [HSP Modem Serial Device] MD5=320BE4E259519B0EF595EA23BF494EF0 SIZE=362878
%SYSDIR%\svchost -k rpcss
%SYSDIR%\DRIVERS\ssmdrv.sys [Avira GmbH] MD5=3D2829FDE1C52FC64DA5413889CE4DEE SIZE=28352
%SYSDIR%\drivers\st330.sys [THOMSON Telecom Belgium] [SpeedTouch 330] MD5=C9FA6A70C051FC59D22C2E4CD211AD9B SIZE=30464
%PROGRAMFILES%\Thomson SpeedTouch\ST330\service\st330service.exe -service
%SYSDIR%\drivers\stbus.sys [THOMSON Telecom Belgium] [SpeedTouch vbus] MD5=0017202EB0224F82706F04ED35AB23C2 SIZE=12672
%SYSDIR%\svchost.exe -k imgsvc
%SYSDIR%\DRIVERS\stppp.sys [THOMSON Telecom Belgium] [SpeedTouch PPP Adapter] MD5=0A9484E3CDAFB529B392B5E9EBBC4AA6 SIZE=32000
%SYSDIR%\DRIVERS\vmodem.sys [Conexant Systems, Inc.] [HSP Modem Modem Device] MD5=64E0B9AC79424324D780D156A0B0461C SIZE=703737
%SYSDIR%\DRIVERS\vpctcom.sys [Conexant Systems, Inc.] [HSP Modem Virtual Control Device] MD5=809CCB9329171C24C9365E5E0CED448C SIZE=804754
%SYSDIR%\DRIVERS\vvoice.sys [Conexant Systems, Inc.] [Conexant HSP Modem Voice Device] MD5=0BC95D34E9C224F496C1487D167B0FB8 SIZE=70384
%COMMONFILES%\Microsoft Shared\Web Components\10\OWC10.DLL [Microsoft Corporation] [Microsoft Office XP] MD5=5CEE2E73B50AA544F512BF864748C9E5 SIZE=7436272
%COMMONFILES%\Skype\Skype4COM.dll [Skype Technologies] [Skype4COM] MD5=2F7520EFE75CA986F9E41B53162B7144 SIZE=1942864
%COMMONFILES%\Adobe\Updater5\AdobeUpdater.es_ES [Adobe Systems Incorporated] [Adobe Updater] MD5=9CD71F31D3D66802F41CB85FC40E351B SIZE=65728
%COMMONFILES%\Microsoft Shared\GRPHFLT\CGMIMP32.FLT [Microsoft Corporation] [منقيات رسومات Microsoft] MD5=A130A4D5202C410242746D2544AC2BEF SIZE=417792
%COMMONFILES%\Microsoft Shared\Smart Tag\FPERSON.DLL [Microsoft Corporation] [Microsoft Office XP] MD5=595FC7AC26E2653A343F1FE787EB8561 SIZE=288160
%SYSDIR%\mfc70.dll [Microsoft Corporation] [Microsoft® Visual Studio .NET] MD5=09AEF167EB1531E965053D0DCF6CC573 SIZE=974848

End of Report





هل جهازي سليم من الآفات ؟



أكرر شكري أيها النبيل ..
 
السلام عليكم و الرحمه

كيف حالك أخي؟؟ ههه اريد اعزمك بيتنا خخ

المهم الكاسبر قوي خخ و يعترف << حلوه

بس الأفيرا اقوى في مسح الفيروسااات خاصه الي
تخزن نفسها في الريستور فايل >> عن تجربه!!

المهم

التقارير تشير بأن الجهاز سليم!! XD

بس ابغاك تسوي فحص بالأفيرا مرة ثانيه للــ C: و Search for rootkits

و التقرير على حسابي << امزح وياك

امم...

بخصوص Spyware Terminator هذا البرنامج قوي ولا داعي للشكر و انا اخوك XP

بصراحه انا ما جربت البرنامج!! بس... انا دورت عنه و النصائحه عنه و بعض الاكتشافات

و حصلته بالفعل دقيق و قوي و هذا اهم نقطه انه يكون معاك برنامج انتي فايروس و انتي سباي

و التقرير سليم :)

و انتمنى لك التوفيق و النجاح

و لا نطلب سوى الدعاء بالخير لي و لي جميع المسلمين المؤمنين =]

****

الحين انت تعاني من بطئ او اي مشاكل؟؟ << عشان نطمئن

في السر < وين الجنتل و كونج خخخ >

يلا السلام ختام و تقبل الله صيامك و افطار شهي > يمم سمبوسه و فيمتو خخ
 
لاهنت اخوي القبطان الصغير

كفيت ووفيت
 
توقيع : LINEZERO
عليكم السلام ورحمة الله وبركاته

أنا بخير جعلك الله بخير ، والعزيمة مقبولة :y:

الظاهر أعجبتك سالفة الكاسبر ، هههههههههههههههه


أنا سويت فحص للسي ، ثم فحص بــ rootkits

بس الثاني ما أدري هل طريقتي سليمه فيه ؟

لأني أول مرة أجربه والتقرير أمامك ، ولا تنسى هو على حسابك :hh:

أما بخصوص إذا الجهاز بطيء ، فهو بطيء قليلا . يعني إذا فتحت صفحة قوقل تأخذ كذا ثانية

وإذا فتحت ( جهاز الكمبيوتر ) يأخذ ثواني على ما يطلع معي السي والدي .

مع إن الرامات 1 قيقا .


وهذا تقرير فحص السي :





Avira AntiVir Premium
Report file date: 09 سبتمبر, 2008 00:16

Scanning for 1603796 virus strains and unwanted programs.

Licensed to: Kevin Ponsen
Serial number: 1101196954-MEDIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: USER
Computer name: PC-9FE9660ED372

Version information:
BUILD.DAT : 8.1.0.367 20012 Bytes 12/08/2008 11:31:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 07:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 06:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 11:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 06:58:52
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 09:33:34
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 12:54:15
ANTIVIR2.VDF : 7.0.6.94 2998784 Bytes 31/08/2008 20:22:30
ANTIVIR3.VDF : 7.0.6.130 252928 Bytes 08/09/2008 19:59:15
Engineversion : 8.1.1.28
AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 08:58:21
AESCRIPT.DLL : 8.1.0.70 319866 Bytes 05/09/2008 20:22:50
AESCN.DLL : 8.1.0.23 119156 Bytes 10/07/2008 11:44:49
AERDL.DLL : 8.1.1.1 397683 Bytes 05/09/2008 20:22:48
AEPACK.DLL : 8.1.2.1 364917 Bytes 15/07/2008 11:58:35
AEOFFICE.DLL : 8.1.0.23 196987 Bytes 05/09/2008 20:22:46
AEHEUR.DLL : 8.1.0.51 1397111 Bytes 05/09/2008 20:22:44
AEHELP.DLL : 8.1.0.15 115063 Bytes 10/07/2008 11:44:48
AEGEN.DLL : 8.1.0.36 315764 Bytes 05/09/2008 20:22:39
AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 07:33:21
AECORE.DLL : 8.1.1.11 172406 Bytes 05/09/2008 20:22:37
AEBB.DLL : 8.1.0.1 53617 Bytes 10/07/2008 11:44:48
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 07:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 08:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 05/09/2008 20:22:35
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 10:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 07:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 11:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 16:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 11:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 11:05:10
RCIMAGE.DLL : 8.0.0.51 2564353 Bytes 12/06/2008 12:29:30
RCTEXT.DLL : 8.0.51.0 86273 Bytes 27/06/2008 10:00:56

Configuration settings for the scan:
Jobname..........................: ShlExt
Configuration file...............: C:\DOCUME~1\USER\LOCALS~1\Temp\bdea1223.avp
Logging..........................: low
Primary action...................: repair
Secondary action.................: delete
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Process scan.....................: off
Scan registry....................: off
Search for rootkits..............: off
Scan all files...................: All files
Scan archives....................: on
Recursion depth..................: 99
Smart extensions.................: on
Deviating archive types..........: +BSD Mailbox, +Netscape/Mozilla Mailbox, +Eudora Mailbox, +Squid cache, +Pegasus Mailbox, +MS Outlook Mailbox,
Macro heuristic..................: on
File heuristic...................: high

Start of the scan: 09 سبتمبر, 2008 00:16

Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!


End of the scan: 09 سبتمبر, 2008 01:11
Used time: 55:05 Minute(s)

The scan has been done completely.

2790 Scanning directories
123708 Files were scanned
0 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
123707 Files not concerned
1032 Archives were scanned
1 Warnings
0 Notes


=================================================



وهذا تقرير فحص rootkits :





Avira AntiVir Premium
Report file date: 09 سبتمبر, 2008 01:44

Scanning for 1603796 virus strains and unwanted programs.

Licensed to: Kevin Ponsen
Serial number: 1101196954-MEDIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: USER
Computer name: PC-9FE9660ED372

Version information:
BUILD.DAT : 8.1.0.367 20012 Bytes 12/08/2008 11:31:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 07:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 06:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 11:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 06:58:52
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 09:33:34
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 12:54:15
ANTIVIR2.VDF : 7.0.6.94 2998784 Bytes 31/08/2008 20:22:30
ANTIVIR3.VDF : 7.0.6.130 252928 Bytes 08/09/2008 19:59:15
Engineversion : 8.1.1.28
AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 08:58:21
AESCRIPT.DLL : 8.1.0.70 319866 Bytes 05/09/2008 20:22:50
AESCN.DLL : 8.1.0.23 119156 Bytes 10/07/2008 11:44:49
AERDL.DLL : 8.1.1.1 397683 Bytes 05/09/2008 20:22:48
AEPACK.DLL : 8.1.2.1 364917 Bytes 15/07/2008 11:58:35
AEOFFICE.DLL : 8.1.0.23 196987 Bytes 05/09/2008 20:22:46
AEHEUR.DLL : 8.1.0.51 1397111 Bytes 05/09/2008 20:22:44
AEHELP.DLL : 8.1.0.15 115063 Bytes 10/07/2008 11:44:48
AEGEN.DLL : 8.1.0.36 315764 Bytes 05/09/2008 20:22:39
AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 07:33:21
AECORE.DLL : 8.1.1.11 172406 Bytes 05/09/2008 20:22:37
AEBB.DLL : 8.1.0.1 53617 Bytes 10/07/2008 11:44:48
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 07:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 08:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 05/09/2008 20:22:35
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 10:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 07:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 11:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 16:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 11:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 11:05:10
RCIMAGE.DLL : 8.0.0.51 2564353 Bytes 12/06/2008 12:29:30
RCTEXT.DLL : 8.0.51.0 86273 Bytes 27/06/2008 10:00:56

Configuration settings for the scan:
Jobname..........................: Rootkit search
Configuration file...............: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Premium\PROFILES\rootkit.avp
Logging..........................: high
Primary action...................: interactive
Secondary action.................: delete
Scan master boot sector..........: on
Scan boot sector.................: on
Process scan.....................: off
Scan registry....................: off
Search for rootkits..............: on
Scan all files...................: All files
Scan archives....................: on
Recursion depth..................: 99
Smart extensions.................: on
Deviating archive types..........: +BSD Mailbox, +Netscape/Mozilla Mailbox, +Eudora Mailbox, +Squid cache, +Pegasus Mailbox, +MS Outlook Mailbox,
Macro heuristic..................: on
File heuristic...................: high
Expanded search settings.........: 0x00300922

Start of the scan: 09 سبتمبر, 2008 01:44

Starting search for hidden s.
'413062' s were checked, '0' hidden s were found.


End of the scan: 09 سبتمبر, 2008 01:48
Used time: 04:03 Minute(s)

The scan has been done completely.

0 Scanning directories
0 Files were scanned
0 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
0 Files cannot be scanned
0 Files not concerned
0 Archives were scanned
0 Warnings
0 Notes
413062 s were scanned with rootkit scan
0 Hidden s were found



و أنا شاكر لك و داعيا لك و للأخ LINEZERO وكل من أفادني و جميع المسلمين بالرحمة في هذا الشهر والعتق من النار آمين
 
عليكم السلام ورحمة الله وبركاته

أنا بخير جعلك الله بخير ، والعزيمة مقبولة :y:
:king:
الظاهر أعجبتك سالفة الكاسبر ، هههههههههههههههه
يس يس :d:
أنا سويت فحص للسي ، ثم فحص بــ rootkits

بس الثاني ما أدري هل طريقتي سليمه فيه ؟
مفيش مشاكل :bleh:

لأني أول مرة أجربه والتقرير أمامك ، ولا تنسى هو على حسابك :hh:
:q:

أما بخصوص إذا الجهاز بطيء ، فهو بطيء قليلا . يعني إذا فتحت صفحة قوقل تأخذ كذا ثانية

وإذا فتحت ( جهاز الكمبيوتر ) يأخذ ثواني على ما يطلع معي السي والدي .

مع إن الرامات 1 قيقا .

بخصوص هذا !! هل كان سريع من قبل؟ اذا نعم يمكن انت ركبت برنامج جديد و يأثر
او :er: خخخ او انه في برامج كثيره تشتغل مع بدأ الجهاز << مثلي كان بطيئ

الحل: افتح run اكتب msconfig اضغل على startup و علطل البرامج لي ما تحتاجها عند بدأ التشغيل
و التصفح يمكن الأفيرا يبطأ شويه في انترنت جارد >> اذا كان بطيئ كثير قولي بس اكسر راسه خخ اقصد الأعدادات



التقرير زي السمبووسه باللبن
:hh:

و أنا شاكر لك و داعيا لك و للأخ LINEZERO وكل من أفادني و جميع المسلمين بالرحمة في هذا الشهر والعتق من النار آمين

ان شاء الله آمين و جعلك الله من الصالحين و الثابتين على دينه :b:

خخ مضطر احط شيئ خارج الاقتباس

المشاركة التي كتبتها قصيرة جداً. الرجاء إجعل رسالتك على الأقل 1 حقول.
:eek:
 
نفع الله بك

لقد استفدت كثيرا من توجيهاتك بخصوص الران :ok: ، وألغيت البرامج التي لا داع لها والجهاز يعمل جيدا والحمد لله

أما بخصوص انترنت جارد أتمنى أن تنورني زادك الله نورا وجميع الأعضاء آمين
 
يا هلا و غللا

توجيهات الران مفيده جدا خخ تقريبا في كل الأمور

الحمد لله

******

ابشر يا غالي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


 
تسلم والله ما قصرت ، وشرح الغالي
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
واضح جدا ، يعطيكم العافية جميعا وسهّل أموركم كلها آمين
 
عودة
أعلى