من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
السلام عليكم ورحمة الله يا اخوان
الحقيقة من كم يوم وانا اعاني باجهزتي من فيروس يسوي كذا شي غريب بالجهاز منها :

الحقيقة من كم يوم وانا اعاني باجهزتي من فيروس يسوي كذا شي غريب بالجهاز منها :
- يعطل معظم البرامج التشغيلية عندي واللي امتدادها exe ويرفض تركيب أي برنامج حماية .
- يلغي خيار اظهار واخفاء الملفات والمجلدات المخفية بالجهاز ويعطل هالخاصية بدون تحكم منك .
- يعطل الدخول للوضع الآمن Safe Mode بعد اعادة تشغيل الجهاز .. ويستمر باعادة التشغيل دون فائدة .
- الاحظ بطء بالجهاز وفتح الاقراص المحليه بتبويب آخر غير المكان اللي أنقر عليه ..
logfile of trend micro hijackthis v2.0.2
scan saved at 02:00:33 م, on 28/10/2008
platform: Windows xp sp3, v.3311 (winnt 5.01.2600)
msie: Internet explorer v6.00 sp3 (6.00.2900.3311)
boot mode: Normal
running processes:
c:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\progra~1\grisoft\avg7\avgamsvr.exe
c:\progra~1\grisoft\avg7\avgupsvc.exe
c:\windows\system32\dwrcs.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\logmein\x86\ramaint.exe
c:\program files\logmein\x86\logmein.exe
c:\program files\logmein\x86\lmiguardian.exe
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\hpzipm12.exe
c:\windows\system32\svchost.exe
c:\windows\system32\dwrcst.exe
c:\windows\explorer.exe
c:\windows\rthdcpl.exe
c:\windows\system32\rundll32.exe
c:\progra~1\grisoft\avg7\avgcc.exe
c:\program files\logmein\x86\logmeinsystray.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\program files\internet download manager\idman.exe
c:\program files\logmein\x86\lmiguardian.exe
c:\program files\microsoft activesync\wcescomm.exe
c:\windows\system32\ctfmon.exe
c:\progra~1\mi3aa1~1\rapimgr.exe
c:\program files\internet download manager\iemonitor.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\common files\microsoft shared\windows live\wlloginproxy.exe
d:\hshs\my documents\downloads\programs\cleanautorun.exe
c:\program files\real\realplayer\realplay.exe
d:\hshs\my documents\downloads\programs\zyzoom_hijackthis.exe
r0 - hkcu\software\microsoft\internet explorer\main,start page =
r1 - hklm\software\microsoft\internet explorer\main,default_page_url =
r1 - hkcu\software\microsoft\windows\currentversion\int ernet settings,proxyserver = isa.oge.gov.sa:8080
r1 - hkcu\software\microsoft\windows\currentversion\int ernet settings,proxyoverride = *gcu.net;<local>
o2 - bho: Idm helper - {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\idmiecc.dll
o2 - bho: Acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
o2 - bho: Windows live sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o4 - hklm\..\run: [rthdcpl] rthdcpl.exe
o4 - hklm\..\run: [alcmtr] alcmtr.exe
o4 - hklm\..\run: [gest] m‘|\ü
o4 - hklm\..\run: [nvcpldaemon] rundll32.exe c:\windows\system32\nvcpl.dll,nvstartup
o4 - hklm\..\run: [nwiz] nwiz.exe /install
o4 - hklm\..\run: [nvmediacenter] rundll32.exe c:\windows\system32\nvmctray.dll,nvtaskbarinit
o4 - hklm\..\run: [isuspm startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
o4 - hklm\..\run: [isusscheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
o4 - hklm\..\run: [avg7_cc] c:\progra~1\grisoft\avg7\avgcc.exe /startup
o4 - hklm\..\run: [logmein gui] "c:\program files\logmein\x86\logmeinsystray.exe"
o4 - hklm\..\run: [nerofiltercheck] c:\windows\system32\nerocheck.exe
o4 - hklm\..\run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
o4 - hklm\..\run: [synchronization manager] %systemroot%\system32\mobsync.exe /logon
o4 - hklm\..\run: [fouad] c:\windows\win32.exe
o4 - hkcu\..\run: [idman] c:\program files\internet download manager\idman.exe /onboot
o4 - hkcu\..\run: [h/pc connection agent] "c:\program files\microsoft activesync\wcescomm.exe"
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'local service')
o4 - hkus\s-1-5-19\..\run: [avg7_run] c:\progra~1\grisoft\avg7\avgw.exe /runonce (user 'local service')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'network service')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o6 - hkcu\software\policies\microsoft\internet explorer\control panel present
o8 - extra context menu item: &تصدير إلى microsoft excel - res://c:\progra~1\micros~2\office11\excel.exe/3000
o8 - extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\internet download manager\iegetall.htm
o8 - extra context menu item: تحميل بـ إنترنت داونلود مانيجر - c:\program files\internet download manager\ieext.htm
o8 - extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\internet download manager\iegetvl.htm
o9 - extra button: Create mobile favorite - {2eaf5bb1-070f-11d3-9307-00c04fae2d4f} - c:\progra~1\mi3aa1~1\inetrepl.dll
o9 - extra button: (no name) - {2eaf5bb2-070f-11d3-9307-00c04fae2d4f} - c:\progra~1\mi3aa1~1\inetrepl.dll
o9 - extra 'tools' menuitem: Create mobile favorite... - {2eaf5bb2-070f-11d3-9307-00c04fae2d4f} - c:\progra~1\mi3aa1~1\inetrepl.dll
o9 - extra button: بحث - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office11\refiebar.dll
o9 - extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra 'tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o14 - iereset.inf: Start_page_url=http://www.gcu.net
o16 - dpf: {17492023-c23a-453e-a040-c7c580bbf700} (windows genuine advantage validation tool) -
o16 - dpf: {6414512b-b978-451d-a0d8-fcfdf33e833c} (wuwebcontrol class) -
o16 - dpf: {fd0b6769-6490-4a91-aa0a-b5ae0dc75ac9} (performance viewer activex control) -
o17 - hklm\system\ccs\services\tcpip\parameters: Domain = oge.gov.sa
o17 - hklm\software\..\telephony: Domainname = oge.gov.sa
o17 - hklm\system\ccs\services\tcpip\..\{c2cf0357-a553-413a-8d46-7b14bf34897b}: Nameserver = 10.10.2.1,10.10.2.2
o17 - hklm\system\cs1\services\tcpip\parameters: Domain = oge.gov.sa
o23 - service: Avg7 alert manager server (avg7alrt) - grisoft, s.r.o. - c:\progra~1\grisoft\avg7\avgamsvr.exe
o23 - service: Avg7 update service (avg7updsvc) - grisoft, s.r.o. - c:\progra~1\grisoft\avg7\avgupsvc.exe
o23 - service: Dameware mini remote control (dwmrcs) - dameware development llc - c:\windows\system32\dwrcs.exe
o23 - service: Logmein maintenance service (lmimaint) - logmein, inc. - c:\program files\logmein\x86\ramaint.exe
o23 - service: Logmein - logmein, inc. - c:\program files\logmein\x86\logmein.exe
o23 - service: Nvidia display driver service (nvsvc) - nvidia corporation - c:\windows\system32\nvsvc32.exe
o23 - service: Pml driver hpz12 - hp - c:\windows\system32\hpzipm12.exe
--
end of file - 7641 bytes
scan saved at 02:00:33 م, on 28/10/2008
platform: Windows xp sp3, v.3311 (winnt 5.01.2600)
msie: Internet explorer v6.00 sp3 (6.00.2900.3311)
boot mode: Normal
running processes:
c:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\progra~1\grisoft\avg7\avgamsvr.exe
c:\progra~1\grisoft\avg7\avgupsvc.exe
c:\windows\system32\dwrcs.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\logmein\x86\ramaint.exe
c:\program files\logmein\x86\logmein.exe
c:\program files\logmein\x86\lmiguardian.exe
c:\program files\common files\microsoft shared\vs7debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\hpzipm12.exe
c:\windows\system32\svchost.exe
c:\windows\system32\dwrcst.exe
c:\windows\explorer.exe
c:\windows\rthdcpl.exe
c:\windows\system32\rundll32.exe
c:\progra~1\grisoft\avg7\avgcc.exe
c:\program files\logmein\x86\logmeinsystray.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\program files\internet download manager\idman.exe
c:\program files\logmein\x86\lmiguardian.exe
c:\program files\microsoft activesync\wcescomm.exe
c:\windows\system32\ctfmon.exe
c:\progra~1\mi3aa1~1\rapimgr.exe
c:\program files\internet download manager\iemonitor.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\common files\microsoft shared\windows live\wlloginproxy.exe
d:\hshs\my documents\downloads\programs\cleanautorun.exe
c:\program files\real\realplayer\realplay.exe
d:\hshs\my documents\downloads\programs\zyzoom_hijackthis.exe
r0 - hkcu\software\microsoft\internet explorer\main,start page =
r1 - hklm\software\microsoft\internet explorer\main,default_page_url =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
r1 - hkcu\software\microsoft\windows\currentversion\int ernet settings,proxyserver = isa.oge.gov.sa:8080
r1 - hkcu\software\microsoft\windows\currentversion\int ernet settings,proxyoverride = *gcu.net;<local>
o2 - bho: Idm helper - {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\idmiecc.dll
o2 - bho: Acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: Realplayer download and record plugin for internet explorer - {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
o2 - bho: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
o2 - bho: Windows live sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o4 - hklm\..\run: [rthdcpl] rthdcpl.exe
o4 - hklm\..\run: [alcmtr] alcmtr.exe
o4 - hklm\..\run: [gest] m‘|\ü
o4 - hklm\..\run: [nvcpldaemon] rundll32.exe c:\windows\system32\nvcpl.dll,nvstartup
o4 - hklm\..\run: [nwiz] nwiz.exe /install
o4 - hklm\..\run: [nvmediacenter] rundll32.exe c:\windows\system32\nvmctray.dll,nvtaskbarinit
o4 - hklm\..\run: [isuspm startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
o4 - hklm\..\run: [isusscheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
o4 - hklm\..\run: [avg7_cc] c:\progra~1\grisoft\avg7\avgcc.exe /startup
o4 - hklm\..\run: [logmein gui] "c:\program files\logmein\x86\logmeinsystray.exe"
o4 - hklm\..\run: [nerofiltercheck] c:\windows\system32\nerocheck.exe
o4 - hklm\..\run: [tkbellexe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
o4 - hklm\..\run: [synchronization manager] %systemroot%\system32\mobsync.exe /logon
o4 - hklm\..\run: [fouad] c:\windows\win32.exe
o4 - hkcu\..\run: [idman] c:\program files\internet download manager\idman.exe /onboot
o4 - hkcu\..\run: [h/pc connection agent] "c:\program files\microsoft activesync\wcescomm.exe"
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'local service')
o4 - hkus\s-1-5-19\..\run: [avg7_run] c:\progra~1\grisoft\avg7\avgw.exe /runonce (user 'local service')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'network service')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o6 - hkcu\software\policies\microsoft\internet explorer\control panel present
o8 - extra context menu item: &تصدير إلى microsoft excel - res://c:\progra~1\micros~2\office11\excel.exe/3000
o8 - extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - c:\program files\internet download manager\iegetall.htm
o8 - extra context menu item: تحميل بـ إنترنت داونلود مانيجر - c:\program files\internet download manager\ieext.htm
o8 - extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - c:\program files\internet download manager\iegetvl.htm
o9 - extra button: Create mobile favorite - {2eaf5bb1-070f-11d3-9307-00c04fae2d4f} - c:\progra~1\mi3aa1~1\inetrepl.dll
o9 - extra button: (no name) - {2eaf5bb2-070f-11d3-9307-00c04fae2d4f} - c:\progra~1\mi3aa1~1\inetrepl.dll
o9 - extra 'tools' menuitem: Create mobile favorite... - {2eaf5bb2-070f-11d3-9307-00c04fae2d4f} - c:\progra~1\mi3aa1~1\inetrepl.dll
o9 - extra button: بحث - {92780b25-18cc-41c8-b9be-3c9c571a8263} - c:\progra~1\micros~2\office11\refiebar.dll
o9 - extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra 'tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - c:\windows\network diagnostic\xpnetdiag.exe
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\program files\messenger\msmsgs.exe
o14 - iereset.inf: Start_page_url=http://www.gcu.net
o16 - dpf: {17492023-c23a-453e-a040-c7c580bbf700} (windows genuine advantage validation tool) -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
o16 - dpf: {6414512b-b978-451d-a0d8-fcfdf33e833c} (wuwebcontrol class) -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
o16 - dpf: {fd0b6769-6490-4a91-aa0a-b5ae0dc75ac9} (performance viewer activex control) -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
o17 - hklm\system\ccs\services\tcpip\parameters: Domain = oge.gov.sa
o17 - hklm\software\..\telephony: Domainname = oge.gov.sa
o17 - hklm\system\ccs\services\tcpip\..\{c2cf0357-a553-413a-8d46-7b14bf34897b}: Nameserver = 10.10.2.1,10.10.2.2
o17 - hklm\system\cs1\services\tcpip\parameters: Domain = oge.gov.sa
o23 - service: Avg7 alert manager server (avg7alrt) - grisoft, s.r.o. - c:\progra~1\grisoft\avg7\avgamsvr.exe
o23 - service: Avg7 update service (avg7updsvc) - grisoft, s.r.o. - c:\progra~1\grisoft\avg7\avgupsvc.exe
o23 - service: Dameware mini remote control (dwmrcs) - dameware development llc - c:\windows\system32\dwrcs.exe
o23 - service: Logmein maintenance service (lmimaint) - logmein, inc. - c:\program files\logmein\x86\ramaint.exe
o23 - service: Logmein - logmein, inc. - c:\program files\logmein\x86\logmein.exe
o23 - service: Nvidia display driver service (nvsvc) - nvidia corporation - c:\windows\system32\nvsvc32.exe
o23 - service: Pml driver hpz12 - hp - c:\windows\system32\hpzipm12.exe
--
end of file - 7641 bytes
