الحالة
مغلق و غير مفتوح للمزيد من الردود.

ahmed97

زيزوومى مميز
إنضم
22 سبتمبر 2012
المشاركات
360
مستوى التفاعل
92
النقاط
490
غير متصل
السلام عليكم
مشكلتي مع اضافه ‪Vonteera Safe ads‬1.0 مدري منوين طلعت بس اظن انها مضره
كل ماجيت احذفه ترجع فما الحل ؟
 

UP

مافي اي مساعده افااا
 

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي



اخي الكريم هذه الاضافة من اجل ايقاف الاعلانات و لكن للتاكد من سلامتها يفضل عمل تقرير

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي




لتحليل عمل الاضافة و نوعها .... و ان لم تكن انت من وضعها فلا مشكلة من ازالتها او ايقافها .
 
توقيع : Mazn_TNT

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي



اخي الكريم هذا يعتبر من برمجيات الادوير اعمل له ازالة و استخدم الاداة التالية :

AdwCleaner


يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي



اغلق برامج التصفح

شغل الأداة ثم اضغط على Scan سوف تبحث الأداة عن البرامج الدعائية والتولبارات ... الخ

بعد الانتهاء من البحث واظهار هذه الملفات

اضغط على Clean

سوف يعاد تشغيل الكمبيوتر ويظهر تقرير الأداة

ضع التقرير الناتج بردك القادم
 
توقيع : Mazn_TNT
UP
 
AdwCleaner v3.012 - Report created 14/11/2013 at 15:15:56
# Updated 11/11/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : HP - HP-49CD5491BF5C
# Running from : C:\Documents and Settings\HP\My Documents\Downloads\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : Application Updater
Service Deleted : hshld
Service Deleted : hsstrayservice
[#] Service Deleted : hsswd

***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Application Data\Conduit
Folder Deleted : C:\Documents and Settings\All Users\Application Data\hotspot shield
Folder Deleted : C:\Documents and Settings\All Users\Start Menu\Programs\hotspot shield
Folder Deleted : C:\Program Files\Application Updater
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\hotspot shield
Folder Deleted : C:\Program Files\Hotspot_Shield
Folder Deleted : C:\Program Files\IObit Apps Toolbar
Folder Deleted : C:\Program Files\Minibar
Folder Deleted : C:\Program Files\SimilarSites
Folder Deleted : C:\Program Files\Common Files\spigot
Folder Deleted : C:\WINDOWS\system32\hotspot shield
Folder Deleted : C:\Documents and Settings\LocalService\Application Data\hotspot shield
Folder Deleted : C:\Documents and Settings\HP\Local Settings\Application Data\Bundled software uninstaller
Folder Deleted : C:\Documents and Settings\HP\Local Settings\Application Data\Conduit
Folder Deleted : C:\Documents and Settings\HP\Local Settings\Application Data\FilesFrog Update Checker
Folder Deleted : C:\Documents and Settings\HP\Local Settings\Application Data\Hotspot_Shield
Folder Deleted : C:\Documents and Settings\HP\Local Settings\Application Data\Minibar
Folder Deleted : C:\Documents and Settings\HP\Local Settings\Application Data\webplayer
Folder Deleted : C:\Documents and Settings\HP\Application Data\hotspot shield
Folder Deleted : C:\Documents and Settings\HP\Application Data\Search Settings
Folder Deleted : C:\Documents and Settings\HP\Application Data\SimilarSites
Folder Deleted : C:\Documents and Settings\HP\Start Menu\Programs\FilesFrog Update Checker
Folder Deleted : C:\Documents and Settings\HP\Application Data\Mozilla\Firefox\Profiles\en60zryg.default\CT1561552
Folder Deleted : C:\Documents and Settings\HP\Application Data\Mozilla\Firefox\Profiles\en60zryg.default\Extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}
File Deleted : C:\Documents and Settings\HP\Application Data\Mozilla\Firefox\Profiles\en60zryg.default\Extensions\addon@defaulttab.com.xpi
File Deleted : C:\END
File Deleted : C:\Documents and Settings\HP\Application Data\Mozilla\Firefox\Profiles\en60zryg.default\searchplugins\Conduit.xml
File Deleted : C:\Documents and Settings\HP\Application Data\Mozilla\Firefox\Profiles\en60zryg.default\user.js

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Documents and Settings\HP\Start Menu\Programs\FLV Player\Uninstall.lnk

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SDP]
Key Deleted : HKCU\Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1561552
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{539F76FD-084E-4858-86D5-62F02F54AE86}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{60EACC1A-33FA-443D-9846-17B28E2C9BDB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{87EAB409-97D7-4889-ACFA-C548FC6F3ECF}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AAA38851-3CFF-475F-B5E0-720D3645E4A5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06E50566-0AB7-431C-841D-62794727DAF9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F13D3582-1359-4F8F-9A48-EF3AE9F5701C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{87EAB409-97D7-4889-ACFA-C548FC6F3ECF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AAA38851-3CFF-475F-B5E0-720D3645E4A5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FC0BEE81-3524-4460-9595-2EDF6A825EDD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70CE984E-A58E-4428-BCD5-CFB43E34978A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C99FDC39-A1AE-4B24-8D71-E5274F8D7C54}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{539F76FD-084E-4858-86D5-62F02F54AE86}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}]
Key Deleted : HKCU\Software\anchorfree
Key Deleted : HKCU\Software\BI
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\Hotspot_Shield
Key Deleted : HKCU\Software\Minibar
Key Deleted : HKCU\Software\Search Settings
Key Deleted : HKCU\Software\SearchProtect
Key Deleted : HKCU\Software\smartbar
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\Somoto
Key Deleted : HKCU\Software\Webplayer
Key Deleted : HKCU\Software\AppDataLow\Software\Search Settings
Key Deleted : HKLM\Software\Application Updater
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DefaultTab
Key Deleted : HKLM\Software\Hotspot_Shield
Key Deleted : HKLM\Software\hotspotshield
Key Deleted : HKLM\Software\Search Settings
Key Deleted : HKLM\Software\SearchProtect
Key Deleted : HKLM\Software\Uniblue
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile Apps
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hotspotshield
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\hotspotshield

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Mozilla Firefox v24.0 (ar)

[ File : C:\Documents and Settings\HP\Application Data\Mozilla\Firefox\Profiles\en60zryg.default\prefs.js ]

Line Deleted : أ¯آ»طںط·آ£ط¢آ¯ط·آ¢ط¢آ»ط·آ·ط¹ط›user_pref("CT1561552.FF19Solved", "true");
Line Deleted : user_pref("CT1561552.UserID", "UN25382991188603192");
Line Deleted : user_pref("CT1561552.browser.search.defaultthis.engineName", "true");
Line Deleted : user_pref("CT1561552.fullUserID", "UN25382991188603192.IN.20131102194719");
Line Deleted : user_pref("CT1561552.installDate", "02/11/2013 19:47:24");
Line Deleted : user_pref("CT1561552.installSessionId", "-1");
Line Deleted : user_pref("CT1561552.installSp", "TRUE");
Line Deleted : user_pref("CT1561552.installerVersion", "1.8.0.14");
Line Deleted : user_pref("CT1561552.keyword", "true");
Line Deleted : user_pref("CT1561552.originalSearchAddressUrl", "");
Line Deleted : user_pref("CT1561552.originalSearchEngine", "");
Line Deleted : user_pref("CT1561552.originalSearchEngineName", "");
Line Deleted : user_pref("CT1561552.searchRevert", "false");
Line Deleted : user_pref("CT1561552.searchUserMode", "2");
Line Deleted : user_pref("CT1561552.toolbarInstallDate", "02-11-2013 19:47:20");
Line Deleted : user_pref("CT1561552.versionFromInstaller", "10.21.1.7");
Line Deleted : user_pref("CT1561552.xpeMode", "0");
Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
Line Deleted : user_pref("browser.search.defaultthis.engineName", "Hotspot Shield Customized Web Search");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&CUI=UN25382991188603192&UM=2&SearchSource=3&q={searchTerms}");
Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT1561552");
Line Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=2&CUI=UN25382991188603192&UM=2&q=");
Line Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT1561552");
Line Deleted : user_pref("smartbar.machineId", "MUHBPTKXEXMVZZO1MNHCDWETO9KHFMBYUNPZH0QXZGRT2AW/NUHQDYCJP1IPK/HDPFVD1B4CFMMWDOBKRB/2/Q");
Line Deleted : user_pref("CT1561552.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT1561552.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT1561552.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT1561552.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT1561552.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT1561552.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"false\"}");

-\\ Google Chrome v31.0.1650.48

[ File : C:\Documents and Settings\HP\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [7756 octets] - [24/09/2013 20:23:56]
AdwCleaner[R1].txt - [4568 octets] - [26/10/2013 11:38:24]
AdwCleaner[R2].txt - [11474 octets] - [14/11/2013 15:14:12]
AdwCleaner[S0].txt - [7414 octets] - [24/09/2013 20:26:25]
AdwCleaner[S1].txt - [4741 octets] - [26/10/2013 11:39:01]
AdwCleaner[S2].txt - [10828 octets] - [14/11/2013 15:15:56]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [10889 octets] ##########
 
ممتاز اخي الان اعمل فحص كامل للجهاز بالبرنامج التالي و ازل الاصابات :

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي



و ضع التقرير الناتج بردك القادم .
 
توقيع : Mazn_TNT
Malwarebytes Anti-Malware 1.75.0.1300

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي



Database version: v2013.11.14.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
HP :: HP-49CD5491BF5C [administrator]

11/01/1435 04:08:47 م
mbam-log-2013-11-14 (16-08-47).txt

Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 308524
Time elapsed: 35 minute(s), 26 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

Folders Detected: 0
(No malicious items detected)

Files Detected: 25
C:\AdwCleaner\Quarantine\C\Documents and Settings\HP\Local Settings\Application Data\Bundled software uninstaller\biclient.exe.vir (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\HP\Local Settings\Application Data\Conduit\CT1561552\Hotspot_ShieldAutoUpdateHelper.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\HP\Local Settings\Application Data\FilesFrog Update Checker\uninstall.exe.vir (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files\Hotspot_Shield\Hotspot_ShieldToolbarHelper.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files\Minibar\Minibar.dll.vir (PUP.Optional.MiniBar.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Local Settings\Application Data\AppsHat Mobile Apps\Uninstall.exe (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Local Settings\Application Data\Google\Chrome\User Data\Default\File System\008\t\00\00000000 (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Local Settings\Temp\minibar-master.exe (PUP.Optional.MiniBar.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Local Settings\Temp\appshat-distribution.exe (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Local Settings\Temp\UpdateCheckerSetup.exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\My Documents\Downloads\VideoPlayer-c66ug0D.exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP68\A0052447.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP71\A0057069.dll (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP71\A0057070.exe (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP71\A0057071.exe (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP71\A0057073.dll (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP71\A0057074.dll (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP71\A0057076.exe (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP71\A0057079.exe (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP78\A0059863.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP90\A0064189.exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP90\A0064152.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP90\A0064169.dll (PUP.Optional.MiniBar.A) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP90\A0064185.exe (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP90\A0064186.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

(end)
 
عمل رائع اخي ... الان فضلا طبق التالي بالترتيب :

حمل برنامج

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي

و حدد جميع الخانات الموجودة في القائمة اليسرى و لكن ابق على خانة طمس المساحة الحرة بدون تحديد

---- و انتقل الى تبويب التطبيقات من الاعلى و حدد جميع الخانات من بدايتها لنهايتها

الان اعمل تحليل ثم تنظيف عدة مرات حتى لا يبقى ما ينظفه البرنامج .

--- انتقل من البرنامج الى تبويب الريجستري و ايضا تحليل ثم تنظيف عدة مرات حتى لا يبقى شيء بحاجة لتنظيف .

----- الان حمل اداة

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي

و شغلها و نظف بها الجهاز مرة اخرى ان طلب البرنامج اعادة تشغيل الجهاز وافق عليها .


ثم بعد اعادة التشغيل طبق التالي :

البرنامج التالي للصيانه والتنظيف والتحسين والتسريع
حمله من هنا

يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي


وثبته وحول اللغه للعربي
اول ماتشغل البرنامج انقر ع الايقونه
[ التدقيق الان ] ـــــــ بعدها تنظيف
بعدها من نفس واجهة البرنامج
DMuID.png

SCPxC.png


بعدها ادخل على الغاء تجزئة الرجستري و طبقه ثم اعد تشغيل الجهاز بعد ذلك.


ثم رد لنا خبر عن وضع الجهاز ...
 
توقيع : Mazn_TNT
طبقت كل شيء بالحرف
الجهاز احسن من اول والاضافه نزلت نهائياً
شكرا لك ..
 
بالتوفيق اخي الغالي ...

و اي استفسار اخر لا تتردد .. اهلا بك باي وقت .


يغلق الموضوع للانتهاء .
 
توقيع : Mazn_TNT
الحالة
مغلق و غير مفتوح للمزيد من الردود.
عودة
أعلى