owsha
زيزوومي نشيط
غير متصل
قم بمتابعة الفيديو أدناه لمعرفة كيفية تثبيت موقعنا كتطبيق ويب على الشاشة الرئيسية.
ملاحظة: قد لا تكون هذه الميزة متاحة في بعض المتصفحات.
ملحوظة تانية وجدت فيرس على الجهاز عملت اسكان وحزف الفيرس لكن كل لما اجى افتح اى دريف
يكتبلى الكلام دة
![]()
ولما اجى ادوس كليك يمين تظهرلى الصورة دى
![]()
مع انى معرفش اية اوتو بلاى دى الى اول واحدة اسبها واجى ادوس على كلمة open تظهرلى الصورة دى
![]()
يا ريت اعرف الحل باسرع ما يمكن
ComboFix 08-11-05.02 - MoHaMeD 11/06/2008 9:13:27.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.111 [GMT 2:00]
Running from: c:\documents and settings\MoHaMeD\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\resycled
c:\windows\system32\autorun.ini
D:\Autorun.inf
E:\Autorun.inf
F:\Autorun.inf
G:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-10-06 to 2008-11-06 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-03 14:11 --------- d-----w c:\program files\Download Direct
2008-11-03 13:32 2,320,640 ----a-w c:\windows\system32\TUKernel.exe
2008-11-03 10:17 --------- d-----w c:\documents and settings\MoHaMeD\Application Data\Styler
2008-11-03 10:15 --------- d-----w c:\program files\Styler
2008-11-03 08:39 --------- d-----w c:\program files\Eusing Free Registry Cleaner
2008-11-03 08:07 81,920 ----a-w c:\documents and settings\MoHaMeD\Application Data\ezpinst.exe
2008-11-03 08:07 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2008-11-03 08:07 47,360 ----a-w c:\documents and settings\MoHaMeD\Application Data\pcouffin.sys
2008-11-03 08:07 --------- d-----w c:\documents and settings\MoHaMeD\Application Data\Vso
2008-11-03 08:06 --------- d-----w c:\program files\Video Convert Master
2008-11-01 17:39 --------- d-----w c:\documents and settings\MoHaMeD\Application Data\Thinstall
2008-11-01 17:36 --------- d-----w c:\program files\MP3Gain
2008-11-01 11:46 --------- d-----w c:\documents and settings\MoHaMeD\Application Data\Media Player Classic
2008-11-01 11:45 --------- d-----w c:\program files\K-Lite Codec Pack
2008-10-29 16:40 --------- d-----w c:\documents and settings\MoHaMeD\Application Data\DMCache
2008-10-28 20:29 634,628 ----a-w c:\windows\java\Packages\ELJBXRVH.ZIP
2008-10-28 16:19 155,995 ----a-w c:\windows\java\Packages\YOYOA1NR.ZIP
2008-10-28 16:07 --------- d-----w c:\program files\RealDrawPro By Method
2008-10-28 16:06 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-10-28 16:06 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-10-28 16:06 --------- d-----w c:\program files\Real
2008-10-28 16:06 --------- d-----w c:\program files\Common Files\xing shared
2008-10-28 16:06 --------- d-----w c:\program files\Common Files\Real
2008-10-28 16:01 --------- d-----w c:\program files\BearShare Applications
2008-10-28 16:01 --------- d-----w c:\documents and settings\MoHaMeD\Application Data\BearShare
2008-10-28 15:59 --------- d-----w c:\program files\CCleaner
2008-10-28 15:58 --------- d-----w c:\program files\Your Uninstaller 2008
2008-10-28 15:58 --------- d-----w c:\documents and settings\MoHaMeD\Application Data\URSoft
2008-10-28 15:58 --------- d-----w c:\documents and settings\All Users\Application Data\TEMP
2008-10-28 15:53 --------- d-----w c:\program files\AIMP2
2008-10-28 15:53 --------- d-----w c:\documents and settings\MoHaMeD\Application Data\AIMP
2008-10-28 15:51 --------- d-----w c:\program files\Yahoo!
2008-10-28 15:51 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-10-28 15:49 --------- d-----w c:\program files\Windows Live
2008-10-28 15:46 --------- d-----w c:\documents and settings\MoHaMeD\Application Data\TuneUp Software
2008-10-28 15:42 --------- d-----w c:\documents and settings\MoHaMeD\Application Data\Avira
2008-10-28 15:40 --------- d-----w c:\program files\Avira
2008-10-28 15:40 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2008-10-28 14:16 --------- d-----w c:\program files\Common Files\Nero
2008-10-28 14:14 --------- d-----w c:\program files\Common Files\Ahead
2008-10-28 14:14 --------- d-----w c:\program files\Ahead
2008-10-28 14:12 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-28 14:12 --------- d-----w c:\program files\Realtek Sound Manager
2008-10-28 14:12 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-28 14:12 --------- d-----w c:\program files\AvRack
2008-10-28 14:02 --------- d-----w c:\program files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/03/2004 10:56 PM 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [10/18/2007 11:34 AM 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [06/12/2008 02:28 PM 266497]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [10/28/2008 06:06 PM 185872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/03/2004 10:56 PM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 10/18/2007 11:34 AM 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
R2 AntiVirMailService;Avira AntiVir Premium MailGuard;c:\program files\Avira\AntiVir PersonalEdition Premium\avmailc.exe [07/11/2008 12:23 PM 164097]
R2 antivirwebservice;Avira AntiVir Premium WebGuard;c:\program files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE [06/12/2008 02:59 PM 258305]
R2 AVEService;Avira AntiVir Premium MailGuard helper service;c:\program files\Avira\AntiVir PersonalEdition Premium\avesvc.exe [05/09/2008 01:22 PM 41217]
R2 UxTuneUp;TuneUp Design Expansion;c:\windows\System32\svchost.exe [08/03/2004 10:56 PM 14336]
R3 slnt;Realtek RTL8139 Family PCI Fast Ethernet NIC;c:\windows\system32\DRIVERS\slnt.sys [06/22/2004 09:17 AM 18004]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com c:
\Shell\Open\command - resycled\boot.com c:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com d:
\Shell\Open\command - resycled\boot.com d:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com e:
\Shell\Open\command - resycled\boot.com e:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com f:
\Shell\Open\command - resycled\boot.com f:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com g:
\Shell\Open\command - resycled\boot.com g:
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.eg/
O16 -: Microsoft XML Parser for Java -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
O16 -: Yahoo! Pool 2 - hxxp://origin.games.yahoo.net/games/clients/y/poti_x.cab
c:\windows\Downloaded Program Files\Yahoo! Pool 2.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
Rootkit scan 2008-11-06 09:19:13
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Premium\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Premium\avguard.exe
c:\windows\system32\wscntfy.exe
c:\program files\Avira\AntiVir PersonalEdition Premium\avcenter.exe
.
**************************************************************************
.
Completion time: 11/06/2008 9:20:57 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-06 07:20:54
Pre-Run: 3,170,492,416 bytes free
Post-Run: 3,130,318,848 bytes free
148
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:21:46 ص, on 06/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Avira\AntiVir PersonalEdition Premium\avcenter.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\MoHaMeD\Desktop\Zyzoom_HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Pool 2 -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash ) -يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
--
End of file - 3971 bytes