.. السـلامـ عليكـمـ .. أرجوا المساعدة في فحص تقارير Hijack و runscanner ..
غير أن الجهاز بطيء و أحتمل وجود فيرس
التقارير مُرفقة و أنتظر الرد و التعاون ..
تفضل أخي و مشكور للمساعدة ..
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 07:46:01 م, on 02/08/2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
AIMP2
Avira Free Antivirus
Babylon toolbar on IE
BabylonObjectInstaller
CCleaner
GOM Player
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Internet Download Manager
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Mozilla Firefox 14.0.1 (x86 en-US)
Mozilla Maintenance Service
Real Alternative 1.9.0
Storm Codec
WinRAR archiver
Yahoo! Messenger
Your Uninstaller! 7
====== سجل أخطاء النظام ======
Computer Name: tabark-PC
Event Code: 5
Message: {Registry Hive Recovered} Registry hive (file): '\??\C:\Users\tabark\AppData\Local\Microsoft\Windows\UsrClass.dat' was corrupted and it has been recovered. Some data might have been lost.
Record Number: 573
Source Name: Microsoft-Windows-Kernel-General
Time Written: 20120731183327.151239-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: tabark-PC
Event Code: 41
Message: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Record Number: 538
Source Name: Microsoft-Windows-Kernel-Power
Time Written: 20120731183314.109616-000
Event Type: Critical
User: NT AUTHORITY\SYSTEM
Computer Name: tabark-PC
Event Code: 6008
Message: The previous system shutdown at 07:52:42 م on 31/07/2012 was unexpected.
Record Number: 531
Source Name: EventLog
Time Written: 20120731183324.000000-000
Event Type: Error
User:
Computer Name: tabark-PC
Event Code: 7023
Message: The Windows Update service terminated with the following error:
%%-2147467243
Record Number: 316
Source Name: Service Control Manager
Time Written: 20120731163327.484742-000
Event Type: Error
User:
Computer Name: 37L4247D28-05
Event Code: 7026
Message: The following boot-start or system-start driver(s) failed to load:
cdrom
Record Number: 109
Source Name: Service Control Manager
Time Written: 20120731163113.745707-000
Event Type: Error
User:
===== سجل أخطاء البرامج =====
Computer Name: tabark-PC
Event Code: 3036
Message: The content source <csc://{S-1-5-21-313345390-3179463209-615719797-1000}/> cannot be accessed.
Context: Application, SystemIndex Catalog
Details:
The URL was already processed during this update. If you received this message while processing alerts, then the alerts are redundant, or else Modify should be used instead of Add. (HRESULT : 0x80040d0d) (0x80040d0d)
Record Number: 446
Source Name: Microsoft-Windows-Search
Time Written: 20120801045628.000000-000
Event Type: Warning
User:
Computer Name: tabark-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-313345390-3179463209-615719797-1000:
Process 1764 (\Device\HarddiskVolume2\Program Files\Avira\AntiVir Desktop\avguard.exe) has opened key \REGISTRY\USER\S-1-5-21-313345390-3179463209-615719797-1000\Software\Microsoft\Windows\CurrentVersion\Policies
Record Number: 378
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20120801030514.229043-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: tabark-PC
Event Code: 1015
Message: Detailed HRESULT. Returned hr=0xC004F022, Original hr=0x80049E00
Record Number: 347
Source Name: Microsoft-Windows-Security-SPP
Time Written: 20120731183600.000000-000
Event Type: Warning
User:
Computer Name: tabark-PC
Event Code: 6001
Message: The winlogon notification subscriber <GPClient> failed a notification event.
Record Number: 227
Source Name: Microsoft-Windows-Winlogon
Time Written: 20120731163718.000000-000
Event Type: Warning
User:
Computer Name: tabark-PC
Event Code: 1008
Message: The Windows Search Service is starting up and attempting to remove the old search index {Reason: Full Index Reset}.
Record Number: 190
Source Name: Microsoft-Windows-Search
Time Written: 20120731163554.000000-000
Event Type: Warning
User:
===== السجل الأمني =====
Computer Name: 37L4247D28-05
Event Code: 4735
Message: A security-enabled local group was changed.
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120731163049.253664-000
Event Type: Audit Success
User:
Computer Name: 37L4247D28-05
Event Code: 4608
Message: Windows is starting up.
This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120731163049.191264-000
Event Type: Audit Success
User:
السلام عليكم ورحمة الله وبركاته .
بعد إذن الأخوة بارك الله فيهم ،،
.
أختنا الكريمة تقاريرك سليمة ولله الحمد .
فقط المطلوب منك فضلاً لا أمراً أن تتوجهي إلى البرامج والميزات وتقومي بحذف تولبار قوقل . Google Toolbar for Internet Explorer .
يجب إغلاق جميع صفحات الإنترنت قبل إزالة التولبار لضمان حذفه من غير أي مشاكل . ----- .
وبعد الإنتهاء نظفي جهازك بأداة TFC .
و عليكمـ السلآمـ و رحمة الله و بركاته
شكراً لتوآجدك أبو راس و إفادتك
شكراً للأخوة بارك الله فيكـمـ * ملحوظة * الرآبط لا يعمل !
و أسأل إن كان هناك برامج تستدعي الحذف ؟
الإخوان الغاليين مشكورين و الله حذفت .Google Toolbar for Internet Explorer كذلك Babylon toolbar on IE _ BabylonObjectInstaller لست بحاجة إليه .. بالأخير تنصحوني بـأفضل برنامج أعتمد عليه في تصحيح أخطاء الجهاز و تنظيفه ! أيضاً و أعتذر للإطالة كيفية المحافظة على الجهاز من دون مشاكل ع الأقل المُعقدة منها
و الله أعتذر منكمـ طولت .. موقع يبدأ دوماً مع المتصفح رغمـ إختياري لجوجل حتى إني حذفت فاير فوكس و أعدت تنصيبه و لمـ يُفلح الأمر نفس الشيء مع إنترنت إكسبلور !
أخي الغـالي مشكور لتعاونك ..
الآن غيرت نسخة فاير فوكس و أظنها رآحت المشكلة لكن تبقى مع إكسبلور
تفضل التقرير
====== معلومات نظام التشغيل ======
X86 WIN_7 7600
====== قائمة البرامج المثبتة ======
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
AIMP2
Avira Free Antivirus
CCleaner
GOM Player
Internet Download Manager
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Mozilla Firefox 14.0.1 (x86 ar)
Mozilla Maintenance Service
Real Alternative 1.9.0
Storm Codec
WinRAR archiver
Yahoo! Messenger
Your Uninstaller! 7