حنون لدرجة الجنون

زيزوومي جديد
إنضم
26 يناير 2009
المشاركات
67
مستوى التفاعل
3
النقاط
80
الإقامة
الرياض
غير متصل
كيف احذف الفايروس العنيد للاعلانات كان موجود في البرامج وقمت با ازلته ولكن الى الان موجود

C:\Program Files (x86)\MTV20160128



Malwarebytes Anti-Malware
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي



Detection, 2/24/2016 8:06 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 55973, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:06 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 55973, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:06 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 55979, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:06 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 55980, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:07 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56037, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:07 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56044, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:07 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56049, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:07 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56055, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:07 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56056, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:07 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56057, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:09 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56527, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:09 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56528, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:09 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56529, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:10 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56581, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:10 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56582, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:10 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56583, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:12 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56658, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:12 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56668, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:12 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56669, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:12 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56677, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:12 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56678, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:12 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56679, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:13 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56927, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:13 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56928, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:13 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 56929, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:14 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 57143, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:14 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 57155, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:14 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.91, show-g.mediav.com, 57156, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Update, 2/24/2016 8:15 PM, SYSTEM, ALANAZIT3, Scheduler, Malware Database, 2016.2.24.5, 2016.2.24.6,
Protection, 2/24/2016 8:15 PM, SYSTEM, ALANAZIT3, Protection, Refresh, Starting,
Protection, 2/24/2016 8:15 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, Stopping,
Protection, 2/24/2016 8:15 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, Stopped,
Protection, 2/24/2016 8:15 PM, SYSTEM, ALANAZIT3, Protection, Refresh, Success,
Protection, 2/24/2016 8:15 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, Starting,
Protection, 2/24/2016 8:15 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, Started,
Detection, 2/24/2016 8:30 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59369, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:30 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59369, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:30 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59389, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:30 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59390, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:30 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59461, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:31 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59501, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:31 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59513, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:31 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59514, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:31 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59517, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:31 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59518, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:31 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59519, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:31 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59580, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:31 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59588, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:31 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59589, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:32 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59606, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:32 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59643, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:33 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59667, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:33 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59668, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,
Detection, 2/24/2016 8:33 PM, SYSTEM, ALANAZIT3, Protection, Malicious Website Protection, IP, 121.12.120.93, show-g.mediav.com, 59669, Outbound, C:\Program Files (x86)\MTV20160128\MTview.exe,

(end)
 

وهذا تقرير الهيجاك


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:05:28 PM, on 2/24/2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Hewlett-Packard\PC COE\ida.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\MTV20160128\MTview.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe
C:\Program Files (x86)\McAfee\Common Framework\McTray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Hewlett-Packard\PC COE\COEMsgDisplay.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE
C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Zyzoom_Forum_Tools\zHijak.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: BDHOOK - {15DEE173-1BE9-4424-81E0-58A87076E9B1} - (no file)
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20150916122415.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IDA] C:\Program Files (x86)\Hewlett-Packard\PC COE\IDA.EXE
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_942D8E5218DDA26CEC8825B633285017] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [Advanced SystemCare 9] "C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe" /Auto
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: create_shortcut.lnk = macraedu\create_shortcut.vbs (User 'Default user')
O4 - .DEFAULT User Startup: reg_off2k7.lnk = macraedu\reg_off2k7.vbs (User 'Default user')
O4 - .DEFAULT User Startup: set_theme.lnk = C:\Users\MACRAEDU\set_theme.vbs (User 'Default user')
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O15 - Trusted Zone: *.eds.com
O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {AB01FF2E-A848-410C-B47B-CB467C476AD9} (HPPKI Control) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = auth.hpicorp.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = auth.hpicorp.net
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = auth.hpicorp.net
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 9 (AdvancedSystemCareService9) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: McAfee Host Intrusion Prevention Service (enterceptAgent) - McAfee, Inc. - C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: McAfee Host Intrusion Prevention lpc Service (HipMgmt) - McAfee, Inc. - C:\Program Files (x86)\McAfee\Host Intrusion Prevention\HipMgmt.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company, L.P. - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: MBAMScheduler - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Service Controller (mfemms) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: HPCA Notify Daemon (Radexecd) - Persistent Systems - C:\Program Files (x86)\Hewlett-Packard\PC COE 3\OV CMS\radexecd.exe
O23 - Service: HPCA Scheduler Daemon (Radsched) - Persistent Systems - C:\Program Files (x86)\Hewlett-Packard\PC COE 3\OV CMS\radsched.exe
O23 - Service: HPCA MSI Redirector (Radstgms) - Persistent Systems - C:\Program Files (x86)\Hewlett-Packard\PC COE 3\OV CMS\Radstgms.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Timing Service (svctimehpc) - Unknown owner - C:\Program Files (x86)\Products\Time Service\svctimehpc.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 16284 bytes
 
وهذا تقرير AdwCleaner v5.036

# AdwCleaner v5.036 - Logfile created 24/02/2016 at 21:21:04
# Updated 22/02/2016 by Xplode
# Database : 2016-02-24.1 [Server]
# Operating system : Windows 7 Enterprise Service Pack 1 (x64)
# Username : alanazit - ALANAZIT3
# Running from : C:\Users\alanazit.AUTH\Downloads\adwcleaner_5.036.exe
# Option : Cleaning
# Support :
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\MTV20160128
[#] Folder Deleted : C:\ProgramData\mntemp
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ÃÀͼä¯ÀÀ
[-] Folder Deleted : C:\Users\Public\Documents\Guid
[-] Folder Deleted : C:\windows\SysWOW64\config\systemprofile\AppData\Roaming\CalendarTool

***** [ Files ] *****

[-] File Deleted : C:\Users\alanazit.AUTH\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.snapdo.com_0.localstorage
[-] File Deleted : C:\Users\alanazit.AUTH\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.snapdo.com_0.localstorage-journal
[-] File Deleted : C:\Users\alanazit.AUTH\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ÃÀͼä¯ÀÀ.lnk

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15DEE173-1BE9-4424-81E0-58A87076E9B1}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15DEE173-1BE9-4424-81E0-58A87076E9B1}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : HKCU\Software\STA
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\qq.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\v.qq.com

***** [ Web browsers ] *****


*************************

:: "Tracing" keys removed
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [2435 bytes] - [24/02/2016 21:21:04]
C:\AdwCleaner\AdwCleaner[S1].txt - [2395 bytes] - [24/02/2016 21:12:00]
C:\AdwCleaner\AdwCleaner[S2].txt - [2468 bytes] - [24/02/2016 21:18:32]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [2654 bytes] ##########
 
توقيع : The Thunder
اذهب للوحة التحكم واختر ازالة البرامج
control-panel-programs.png



بعد ذلك ابحث عن برنامج MTview او Hao123

uninhstall-a-program.png



اعد ضبط المتصفحات

للفايرفكس

اكتب في مكان العنوان about:support

firefox-about-support.png

اضغط على خيار
spot the Refresh Firefox

firefox-refresh.png



firefox-refresh-2.png
\



بعدها اعد تشغيل البرنامج



Google Chrome



chrome-settings.png


Show advanced settings
chrome-advanced-settings.png


chrome-reset-settings.png



chrome-reset.png




Internet Explorer


ie-internet-options.png



ie-reset.png





ie-reset-confirm.png





ثم قم بالفحص بهذه الاداة من السيف مود

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
 
توقيع : The Thunder
هل حلت المشكلة
 
توقيع : The Thunder
عودة
أعلى