طآغي النظرهـ

زيزوومى محترف
إنضم
2 ديسمبر 2008
المشاركات
2,329
مستوى التفاعل
339
النقاط
770
الإقامة
Hotmail Company
غير متصل
السلام عليكم ورحمه الله وبركاته

الضغط إتش الاخلاق صفر وكله بسبب [ تعذر إنترنت إكسبلورر من عرض صفحه ويب ] وأيضا [ مثلث أصفر فيه علآمه تعجب ومكتوب جنبه خطأ في الصفحه ] وأيضا [ يطلع مربع صغير مكتوب فيه اسم الموقع اللي أنا أبغاه وتحته رقم الخطأ رقم السطر ] وأيضا [ تطلع لي صفحات غريبه أول مره أشوفها في حياتي ] المهم أنا ضغطي مرتفع وصرت أنتفض من القهر لذا تكفوووون أفزعولي لو تخترقون جهازي وتصلحونه تكفوووون طالبكم ..... وألحين أنزل تقرير الهايجك << صرت خبره في التقارير الله لايبلآكم..

ملآحظه // بعد حب خشوم ومطاليب وتحديث الصفحه أكثر من مليووون مره وصلت لموقع زيزوم

أبغى الحل منكم تكفووووووون ولا ترى أبغى أكسر جهازي
 

توقيع : طآغي النظرهـ
وعليكم السلام
عذرا بتعديل العنوان الى المناسب


اعمل تقرير للهايجاك
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

اذا انتهى التحميل ==> شغل البرنامج ==> واضغط على Do a system scan and save log
لحظات ويظهر لك تقرير ,, انسخه والصقه بردك القادم
 
التعديل الأخير بواسطة المشرف:
هون علييك أخوي صور لنا صورة للصفحة

وأ، شاء الله مشكلتك محلولة
 
توقيع : Corporation
ـآلسلآم عليكمـ ورحمه ـآلله وبركآته
جبت تقريرين للجهاز الحين أنزلهم .. وأنتظر منكم الحل الله يبيض وجيهكم يالزيازيم

ويعطيكم ألف ألف ألف عافيه وربي أدري غثيتكم بمشاكلي لكن أنتم كفوووو وماتقصرووون وأنا أستاهل
الله يعطيكم العافيه.... يالزيازيم
 
توقيع : طآغي النظرهـ
ComboFix 08-12-16.03 - طاغي 12/17/2008 20:25:39.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.735.479 [GMT 3:00]
Running from: d:\documents and settings\طاغي\سطح المكتب\برامج الحمايه\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_npf

((((((((((((((((((((((((( Files Created from 2008-11-17 to 2008-12-17 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-17 17:35 15,895,072 --sha-w d:\windows\system32\drivers\fidbox.dat
2008-12-17 17:33 732,448 --sha-w d:\windows\system32\drivers\fidbox2.dat
2008-12-17 17:30 71,732 --sha-w d:\windows\system32\drivers\fidbox2.idx
2008-12-17 17:30 221,168 --sha-w d:\windows\system32\drivers\fidbox.idx
2008-12-17 16:51 --------- d-----w d:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-12-17 14:51 --------- d-----w d:\documents and settings\طاغي\Application Data\cleaner
2008-12-15 17:49 --------- d-----w d:\program files\Hotspot_Shield
2008-12-15 17:49 --------- d-----w d:\program files\Conduit
2008-12-15 00:28 --------- d-----w d:\program files\Hotspot Shield
2008-12-11 06:30 --------- d-----w d:\documents and settings\طاغي\Application Data\CyberScrub
2008-12-11 00:08 --------- d-----w d:\program files\Golden Al-Wafi Translator
2008-12-10 14:47 --------- d-----w d:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-09 22:40 --------- d-----w d:\program files\Vuze
2008-12-09 20:51 --------- d-----w d:\documents and settings\طاغي\Application Data\Azureus
2008-12-09 12:21 --------- d-----w d:\documents and settings\All Users\Application Data\Apple Computer
2008-12-09 12:13 81,920 ----a-w d:\documents and settings\طاغي\Application Data\ezpinst.exe
2008-12-09 12:13 47,360 ----a-w d:\windows\system32\drivers\pcouffin.sys
2008-12-09 12:13 47,360 ----a-w d:\documents and settings\طاغي\Application Data\pcouffin.sys
2008-12-09 12:13 --------- d-----w d:\documents and settings\طاغي\Application Data\Vso
2008-12-09 11:22 --------- d-----w d:\program files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter
2008-12-07 18:57 --------- d-----w d:\program files\Zone Labs
2008-12-05 23:51 --------- d-----w d:\program files\PC Tools Internet Security
2008-12-05 23:47 --------- d-----w d:\program files\Common Files\PC Tools
2008-12-05 23:47 --------- d-----w d:\documents and settings\All Users\Application Data\PC Tools
2008-12-05 23:46 --------- d---a-w d:\documents and settings\All Users\Application Data\TEMP
2008-12-05 23:44 --------- d-----w d:\program files\Browser Defender
2008-12-05 21:30 --------- d-----w d:\documents and settings\طاغي\Application Data\PCToolsSpamMonitorPlus
2008-12-05 21:30 --------- d-----w d:\documents and settings\طاغي\Application Data\PCToolsFirewallPlus
2008-12-05 18:20 --------- d-----w d:\program files\Common Files\InstallShield
2008-12-05 17:52 757,760 ----a-w d:\windows\system32\SkinCrafter.dll
2008-12-05 16:35 --------- d--h--w d:\program files\InstallShield Installation Information
2008-12-05 16:08 --------- d-----w d:\program files\Circle Developement
2008-12-05 16:07 --------- d-----w d:\documents and settings\طاغي\Application Data\BodyWipeNoun
2008-12-05 15:03 --------- d-----w d:\documents and settings\All Users\Application Data\Azureus
2008-12-05 14:08 --------- d-----w d:\program files\Windows Media Connect 2
2008-12-04 23:08 --------- d-----w d:\documents and settings\All Users\Application Data\Messenger Plus!
2008-12-04 23:05 --------- d-----w d:\program files\Windows Live
2008-12-04 23:04 --------- d-----w d:\documents and settings\All Users\Application Data\WLInstaller
2008-12-04 21:56 --------- d-----w d:\documents and settings\All Users\Application Data\STORE LESS JUGS SURF
2008-12-04 21:36 --------- d-----w d:\program files\BodyWipeNoun
2008-12-04 21:35 --------- d-----w d:\program files\Messenger Plus! Live
2008-12-04 19:33 --------- d-----w d:\program files\MSECACHE
2008-12-04 18:45 --------- d-----w d:\documents and settings\طاغي\Application Data\ADPHONE
2008-12-04 09:28 --------- d-----w d:\program files\MSN Messenger
2008-12-04 09:22 --------- d-----w d:\program files\Microsoft Office Outlook Connector
2008-12-04 09:09 --------- d-----w d:\program files\Windows Live Toolbar
2008-12-04 09:06 --------- d-----w d:\program files\Microsoft
2008-12-04 08:03 --------- d-----w d:\program files\Windows Installer Clean Up
2008-12-04 08:03 --------- d-----w d:\program files\Common Files\Windows Live
2008-12-04 07:29 410,976 ----a-w d:\windows\system32\deploytk.dll
2008-12-04 07:29 --------- d-----w d:\program files\Java
2008-12-04 07:01 --------- d-----w d:\program files\Yahoo!
2008-12-04 07:01 --------- d-----w d:\program files\CCleaner
2008-12-03 16:22 --------- d-----w d:\program files\IDA
2008-12-03 05:19 --------- d-----w d:\documents and settings\طاغي\Application Data\Internet Download Accelerator
2008-12-03 02:34 --------- d-----w d:\documents and settings\طاغي\Application Data\Media Player Classic
2008-12-03 02:30 2,223,653 ----a-w D:\mpc2kxp6490.zip
2008-12-02 19:50 --------- d-----w d:\program files\Common Files\Adobe
2008-12-02 18:31 75,921,920 ----a-w D:\ps55try.exe
2008-12-02 17:29 827,382 ----a-w D:\Trojan_u.zip
2008-12-02 17:14 985,989 ----a-w D:\MovieGear4.exe
2008-12-02 16:39 --------- d-----w d:\documents and settings\طاغي\Application Data\CursorArts
2008-12-02 16:36 6,766,448 ----a-w D:\imf_pro.exe
2008-12-02 14:16 40,073 ----a-w D:\patcher.zip
2008-12-02 14:09 --------- d-----w d:\program files\SWiSHmax
2008-12-02 14:05 9,783,685 ----a-w D:\SetupSwishmax_20050505.exe
2008-12-01 14:09 357,973 ----a-w D:\شطرنج.zip
2008-12-01 13:03 0 ---ha-w d:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-12-01 13:03 0 ---ha-w d:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-12-01 12:33 499,712 ----a-w d:\windows\system32\msvcp71.dll
2008-12-01 12:33 348,160 ----a-w d:\windows\system32\msvcr71.dll
2008-12-01 12:33 --------- d-----w d:\program files\Common Files\xing shared
2008-12-01 12:33 --------- d-----w d:\program files\Common Files\Real
2008-12-01 11:59 8,552 ----a-w d:\windows\system32\drivers\asctrm.sys
2008-12-01 11:59 --------- d-----w d:\program files\Real
2008-12-01 11:59 --------- d-----w d:\program files\aod
2008-11-30 16:28 --------- d-----w d:\documents and settings\طاغي\Application Data\HiYo
2008-11-30 00:41 --------- d-----w d:\program files\CEDP Stealer 6.0 for Messenger
2008-11-29 23:55 --------- d-----w d:\documents and settings\All Users\Application Data\iolo
2008-11-29 23:53 --------- d-----w d:\documents and settings\طاغي\Application Data\iolo
2008-11-29 21:19 --------- d-----w d:\program files\Microsoft SQL Server Compact Edition
2008-11-29 19:56 --------- dcsh--w d:\program files\Common Files\WindowsLiveInstaller
2008-11-23 15:13 --------- d-----w d:\documents and settings\All Users\Application Data\Bluetooth
2008-11-23 05:49 102,400 ----a-w d:\windows\system32\STemp_01.exe
2008-11-19 22:54 --------- d-----w d:\documents and settings\طاغي\Application Data\AntiSpywareGuard
2008-11-16 10:03 73,216 ----a-w d:\windows\ST6UNST.EXE
2008-11-16 10:03 172,032 ------w d:\windows\Setup1.exe
2008-11-14 16:30 --------- d-----w d:\program files\Windows Live Favorites
2008-11-14 16:28 --------- d-----w d:\documents and settings\All Users\Application Data\Windows Live Toolbar
2008-11-11 15:32 21,035 ----a-w d:\windows\system32\drivers\AegisP.sys
2008-11-11 15:31 --------- d-----w d:\program files\REALTEK RTL8187 Wireless LAN Driver and Utility
2008-10-24 11:21 455,296 ----a-w d:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w d:\windows\system32\gdi32.dll
2008-10-16 11:13 202,776 ----a-w d:\windows\system32\wuweb.dll
2008-10-16 11:13 1,809,944 ----a-w d:\windows\system32\wuaueng.dll
2008-10-16 11:12 561,688 ----a-w d:\windows\system32\wuapi.dll
2008-10-16 11:12 323,608 ----a-w d:\windows\system32\wucltui.dll
2008-10-16 11:09 92,696 ----a-w d:\windows\system32\cdm.dll
2008-10-16 11:09 51,224 ----a-w d:\windows\system32\wuauclt.exe
2008-10-16 11:09 43,544 ----a-w d:\windows\system32\wups2.dll
2006-10-11 08:04 61,036 ----a-w d:\program files\mozilla firefox\components\jar50.dll
2006-10-11 08:04 48,742 ----a-w d:\program files\mozilla firefox\components\jsd3250.dll
2006-10-11 08:05 29,313 ----a-w d:\program files\mozilla firefox\components\myspell.dll
2006-10-11 08:05 41,082 ----a-w d:\program files\mozilla firefox\components\spellchk.dll
2006-10-11 08:04 166,510 ----a-w d:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((( snapshot_Mon 12-15-2008_11.17.51.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-08-13 15:39:20 71,680 ----a-w d:\windows\system32\admparse.dll
+ 2004-08-03 21:55:32 61,440 ----a-w d:\windows\system32\admparse.dll
- 2008-10-16 20:04:07 124,928 ----a-w d:\windows\system32\advpack.dll
+ 2004-08-03 21:55:32 99,840 ----a-w d:\windows\system32\advpack.dll
- 2008-04-14 15:59:33 35,328 ----a-w d:\windows\system32\corpol.dll
+ 2004-08-03 21:55:34 35,328 ----a-w d:\windows\system32\corpol.dll
- 2007-08-13 15:39:20 71,680 -c--a-w d:\windows\system32\dllcache\admparse.dll
+ 2004-08-03 21:55:32 61,440 -c--a-w d:\windows\system32\dllcache\admparse.dll
- 2008-10-16 20:04:07 124,928 -c--a-w d:\windows\system32\dllcache\advpack.dll
+ 2004-08-03 21:55:32 99,840 -c--a-w d:\windows\system32\dllcache\advpack.dll
+ 2004-08-03 21:55:34 35,328 ----a-w d:\windows\system32\dllcache\corpol.dll
- 2007-08-13 15:54:10 33,792 -c--a-w d:\windows\system32\dllcache\custsat.dll
+ 2004-08-03 21:55:34 28,672 -c--a-w d:\windows\system32\dllcache\custsat.dll
- 2008-10-16 20:04:07 347,136 -c--a-w d:\windows\system32\dllcache\dxtmsft.dll
+ 2008-08-20 05:36:11 357,888 -c--a-w d:\windows\system32\dllcache\dxtmsft.dll
- 2008-10-16 20:04:07 214,528 -c--a-w d:\windows\system32\dllcache\dxtrans.dll
+ 2008-08-20 05:36:12 205,312 -c--a-w d:\windows\system32\dllcache\dxtrans.dll
- 2008-10-16 20:04:08 133,120 -c--a-w d:\windows\system32\dllcache\extmgr.dll
+ 2008-08-20 05:36:12 55,808 -c--a-w d:\windows\system32\dllcache\extmgr.dll
- 2007-08-13 15:18:02 60,416 -c--a-w d:\windows\system32\dllcache\hmmapi.dll
+ 2004-08-03 21:55:38 38,912 -c--a-w d:\windows\system32\dllcache\hmmapi.dll
- 2008-10-16 13:09:53 70,656 -c--a-w d:\windows\system32\dllcache\ie4uinit.exe
+ 2004-08-03 21:56:16 34,304 -c--a-w d:\windows\system32\dllcache\ie4uinit.exe
- 2008-10-16 20:04:08 153,088 -c--a-w d:\windows\system32\dllcache\ieakeng.dll
+ 2004-08-03 21:55:38 139,264 -c--a-w d:\windows\system32\dllcache\ieakeng.dll
- 2008-10-16 20:04:08 230,400 -c--a-w d:\windows\system32\dllcache\ieaksie.dll
+ 2004-08-03 21:55:38 216,064 -c--a-w d:\windows\system32\dllcache\ieaksie.dll
- 2008-10-15 07:04:53 161,792 -c--a-w d:\windows\system32\dllcache\ieakui.dll
+ 2001-09-19 12:00:00 221,184 -c--a-w d:\windows\system32\dllcache\ieakui.dll
- 2008-10-16 20:04:09 384,512 -c--a-w d:\windows\system32\dllcache\iedkcs32.dll
+ 2004-08-03 21:55:38 323,584 -c--a-w d:\windows\system32\dllcache\iedkcs32.dll
- 2007-08-13 15:44:02 69,120 -c--a-w d:\windows\system32\dllcache\iedw.exe
+ 2008-08-19 09:30:39 18,432 -c--a-w d:\windows\system32\dllcache\iedw.exe
+ 2004-08-03 21:55:38 81,920 ----a-w d:\windows\system32\dllcache\ieencode.dll
- 2007-08-13 15:54:10 191,488 -c--a-w d:\windows\system32\dllcache\iepeers.dll
+ 2008-08-20 05:36:12 250,880 -c--a-w d:\windows\system32\dllcache\iepeers.dll
- 2008-10-16 20:04:12 44,544 -c--a-w d:\windows\system32\dllcache\iernonce.dll
+ 2004-08-03 21:55:38 48,128 -c--a-w d:\windows\system32\dllcache\iernonce.dll
- 2007-08-13 15:39:12 55,296 -c--a-w d:\windows\system32\dllcache\iesetup.dll
+ 2004-08-03 21:55:38 62,976 -c--a-w d:\windows\system32\dllcache\iesetup.dll
- 2008-10-15 07:06:26 633,632 -c--a-w d:\windows\system32\dllcache\iexplore.exe
+ 2004-08-03 21:56:16 93,184 -c--a-w d:\windows\system32\dllcache\iexplore.exe
- 2007-08-13 15:36:06 36,352 -c--a-w d:\windows\system32\dllcache\imgutil.dll
+ 2004-08-03 21:55:38 35,840 -c--a-w d:\windows\system32\dllcache\imgutil.dll
- 2007-08-13 15:39:02 92,672 -c--a-w d:\windows\system32\dllcache\inseng.dll
+ 2008-08-20 05:36:12 96,256 -c--a-w d:\windows\system32\dllcache\inseng.dll
- 2008-05-09 10:53:39 512,000 -c----w d:\windows\system32\dllcache\jscript.dll
+ 2007-12-18 14:41:00 450,560 -c--a-w d:\windows\system32\dllcache\jscript.dll
- 2008-10-16 20:04:13 27,648 -c--a-w d:\windows\system32\dllcache\jsproxy.dll
+ 2008-08-20 05:36:14 16,384 -c--a-w d:\windows\system32\dllcache\jsproxy.dll
- 2007-08-13 15:44:18 40,960 -c--a-w d:\windows\system32\dllcache\licmgr10.dll
+ 2004-08-03 21:55:40 22,016 -c--a-w d:\windows\system32\dllcache\licmgr10.dll
- 2007-08-13 15:32:30 45,568 -c--a-w d:\windows\system32\dllcache\mshta.exe
+ 2004-08-03 21:56:22 29,184 -c--a-w d:\windows\system32\dllcache\mshta.exe
- 2008-10-16 22:34:18 3,593,216 -c--a-w d:\windows\system32\dllcache\mshtml.dll
+ 2008-08-20 05:36:17 3,081,216 -c--a-w d:\windows\system32\dllcache\mshtml.dll
- 2008-10-16 20:04:16 477,696 -c--a-w d:\windows\system32\dllcache\mshtmled.dll
+ 2008-08-20 05:36:14 449,024 -c--a-w d:\windows\system32\dllcache\mshtmled.dll
- 2007-08-13 15:01:12 48,128 -c--a-w d:\windows\system32\dllcache\mshtmler.dll
+ 2004-08-03 21:53:52 56,832 -c--a-w d:\windows\system32\dllcache\mshtmler.dll
- 2007-08-13 15:54:10 156,160 -c--a-w d:\windows\system32\dllcache\msls31.dll
+ 2001-09-19 12:00:00 146,432 -c--a-w d:\windows\system32\dllcache\msls31.dll
- 2008-10-16 20:04:17 193,024 -c--a-w d:\windows\system32\dllcache\msrating.dll
+ 2008-08-20 05:36:12 146,432 -c--a-w d:\windows\system32\dllcache\msrating.dll
- 2008-10-16 20:04:17 671,232 -c--a-w d:\windows\system32\dllcache\mstime.dll
+ 2008-08-20 05:36:12 532,480 -c--a-w d:\windows\system32\dllcache\mstime.dll
- 2008-10-16 20:04:17 102,912 -c--a-w d:\windows\system32\dllcache\occache.dll
+ 2004-08-03 21:55:46 96,256 -c--a-w d:\windows\system32\dllcache\occache.dll
- 2008-10-16 20:04:17 44,544 -c--a-w d:\windows\system32\dllcache\pngfilt.dll
+ 2008-08-20 05:36:12 39,424 -c--a-w d:\windows\system32\dllcache\pngfilt.dll
- 2008-10-16 20:04:17 105,984 -c--a-w d:\windows\system32\dllcache\url.dll
+ 2004-08-03 21:55:54 48,640 -c--a-w d:\windows\system32\dllcache\url.dll
- 2008-10-16 20:04:18 1,160,192 -c--a-w d:\windows\system32\dllcache\urlmon.dll
+ 2008-08-20 05:36:15 614,912 -c--a-w d:\windows\system32\dllcache\urlmon.dll
- 2008-05-09 10:53:40 430,080 -c----w d:\windows\system32\dllcache\vbscript.dll
+ 2007-12-18 14:41:00 417,792 -c--a-w d:\windows\system32\dllcache\vbscript.dll
- 2008-05-27 17:23:58 765,952 -c--a-w d:\windows\system32\dllcache\vgx.dll
+ 2004-08-03 21:55:54 848,384 -c--a-w d:\windows\system32\dllcache\vgx.dll
- 2008-10-16 20:04:18 233,472 -c--a-w d:\windows\system32\dllcache\webcheck.dll
+ 2004-08-03 21:55:58 276,480 -c--a-w d:\windows\system32\dllcache\webcheck.dll
- 2008-10-16 20:04:19 826,368 -c--a-w d:\windows\system32\dllcache\wininet.dll
+ 2008-08-20 05:36:13 657,920 -c--a-w d:\windows\system32\dllcache\wininet.dll
- 2008-10-16 20:04:07 347,136 ----a-w d:\windows\system32\dxtmsft.dll
+ 2008-08-20 05:36:11 357,888 ----a-w d:\windows\system32\dxtmsft.dll
- 2008-10-16 20:04:07 214,528 ----a-w d:\windows\system32\dxtrans.dll
+ 2008-08-20 05:36:12 205,312 ----a-w d:\windows\system32\dxtrans.dll
- 2008-10-16 20:04:08 133,120 ----a-w d:\windows\system32\extmgr.dll
+ 2008-08-20 05:36:12 55,808 ----a-w d:\windows\system32\extmgr.dll
- 2008-10-16 13:09:53 70,656 ----a-w d:\windows\system32\ie4uinit.exe
+ 2004-08-03 21:56:16 34,304 ----a-w d:\windows\system32\ie4uinit.exe
- 2008-10-16 20:04:08 153,088 ----a-w d:\windows\system32\ieakeng.dll
+ 2004-08-03 21:55:38 139,264 ----a-w d:\windows\system32\ieakeng.dll
- 2008-10-16 20:04:08 230,400 ----a-w d:\windows\system32\ieaksie.dll
+ 2004-08-03 21:55:38 216,064 ----a-w d:\windows\system32\ieaksie.dll
- 2008-10-15 07:04:53 161,792 ----a-w d:\windows\system32\ieakui.dll
+ 2001-09-19 12:00:00 221,184 ----a-w d:\windows\system32\ieakui.dll
- 2008-10-16 20:04:09 384,512 ----a-w d:\windows\system32\iedkcs32.dll
+ 2004-08-03 21:55:38 323,584 ----a-w d:\windows\system32\iedkcs32.dll
- 2008-04-14 15:59:35 81,920 ----a-w d:\windows\system32\ieencode.dll
+ 2004-08-03 21:55:38 81,920 ----a-w d:\windows\system32\ieencode.dll
- 2007-08-13 15:54:10 191,488 ----a-w d:\windows\system32\iepeers.dll
+ 2008-08-20 05:36:12 250,880 ----a-w d:\windows\system32\iepeers.dll
- 2008-10-16 20:04:12 44,544 ----a-w d:\windows\system32\iernonce.dll
+ 2004-08-03 21:55:38 48,128 ----a-w d:\windows\system32\iernonce.dll
- 2007-08-13 15:39:12 55,296 ----a-w d:\windows\system32\iesetup.dll
+ 2004-08-03 21:55:38 62,976 ----a-w d:\windows\system32\iesetup.dll
- 2007-08-13 15:36:06 36,352 ----a-w d:\windows\system32\imgutil.dll
+ 2004-08-03 21:55:38 35,840 ----a-w d:\windows\system32\imgutil.dll
- 2007-08-13 15:39:02 92,672 ----a-w d:\windows\system32\inseng.dll
+ 2008-08-20 05:36:12 96,256 ----a-w d:\windows\system32\inseng.dll
- 2008-05-09 10:53:39 512,000 ----a-w d:\windows\system32\jscript.dll
+ 2007-12-18 14:41:00 450,560 ----a-w d:\windows\system32\jscript.dll
- 2008-10-16 20:04:13 27,648 ----a-w d:\windows\system32\jsproxy.dll
+ 2008-08-20 05:36:14 16,384 ----a-w d:\windows\system32\jsproxy.dll
- 2007-08-13 15:44:18 40,960 ----a-w d:\windows\system32\licmgr10.dll
+ 2004-08-03 21:55:40 22,016 ----a-w d:\windows\system32\licmgr10.dll
- 2007-08-13 15:32:30 45,568 ----a-w d:\windows\system32\mshta.exe
+ 2004-08-03 21:56:22 29,184 ----a-w d:\windows\system32\mshta.exe
- 2008-10-16 22:34:18 3,593,216 ----a-w d:\windows\system32\mshtml.dll
+ 2008-08-20 05:36:17 3,081,216 ----a-w d:\windows\system32\mshtml.dll
- 2008-10-16 20:04:16 477,696 ----a-w d:\windows\system32\mshtmled.dll
+ 2008-08-20 05:36:14 449,024 ----a-w d:\windows\system32\mshtmled.dll
- 2007-08-13 15:01:12 48,128 ----a-w d:\windows\system32\mshtmler.dll
+ 2004-08-03 21:53:52 56,832 ----a-w d:\windows\system32\mshtmler.dll
- 2007-08-13 15:54:10 156,160 ----a-w d:\windows\system32\msls31.dll
+ 2001-09-19 12:00:00 146,432 ----a-w d:\windows\system32\msls31.dll
- 2008-10-16 20:04:17 193,024 ----a-w d:\windows\system32\msrating.dll
+ 2008-08-20 05:36:12 146,432 ----a-w d:\windows\system32\msrating.dll
- 2008-10-16 20:04:17 671,232 ----a-w d:\windows\system32\mstime.dll
+ 2008-08-20 05:36:12 532,480 ----a-w d:\windows\system32\mstime.dll
- 2008-10-16 20:04:17 102,912 ----a-w d:\windows\system32\occache.dll
+ 2004-08-03 21:55:46 96,256 ----a-w d:\windows\system32\occache.dll
- 2008-10-16 20:04:17 44,544 ----a-w d:\windows\system32\pngfilt.dll
+ 2008-08-20 05:36:12 39,424 ----a-w d:\windows\system32\pngfilt.dll
- 2008-10-16 20:04:17 105,984 ----a-w d:\windows\system32\url.dll
+ 2004-08-03 21:55:54 48,640 ----a-w d:\windows\system32\url.dll
- 2008-10-16 20:04:18 1,160,192 ----a-w d:\windows\system32\urlmon.dll
+ 2008-08-20 05:36:15 614,912 ----a-w d:\windows\system32\urlmon.dll
- 2008-05-09 10:53:40 430,080 ----a-w d:\windows\system32\vbscript.dll
+ 2007-12-18 14:41:00 417,792 ----a-w d:\windows\system32\vbscript.dll
- 2008-10-16 20:04:18 233,472 ----a-w d:\windows\system32\webcheck.dll
+ 2004-08-03 21:55:58 276,480 ----a-w d:\windows\system32\webcheck.dll
- 2008-10-16 20:04:19 826,368 ----a-w d:\windows\system32\wininet.dll
+ 2008-08-20 05:36:13 657,920 ----a-w d:\windows\system32\wininet.dll
- 2008-12-11 10:24:08 4,212 ---h--w d:\windows\system32\zllictbl.dat
+ 2008-12-17 12:48:06 4,212 ---h--w d:\windows\system32\zllictbl.dat
+ 2008-12-17 17:32:54 16,384 ----atw d:\windows\Temp\Perflib_Perfdata_11c.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\ctfmon.exe" [04/14/2008 06:59 PM 15360]
"MsnMsgr"="d:\program files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"MSMSGS"="d:\program files\Messenger\msmsgs.exe" [04/14/2008 06:59 PM 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [08/24/2007 07:00 AM 33648]
"TkBellExe"="d:\program files\Common Files\Real\Update_OB\realsched.exe" [12/01/2008 03:33 PM 185872]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [12/04/2008 10:29 AM 136600]
"ZoneAlarm Client"="d:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [11/14/2007 04:05 PM 919016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [04/14/2008 06:59 PM 15360]
d:\documents and settings\All Users\çں‍ê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.exe.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-02 113664]
REALTEK RTL8187 Wireless LAN Utility.lnk - d:\program files\REALTEK RTL8187 Wireless LAN Driver and Utility\RtWLan.exe [2008-11-11 737280]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"d:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Messenger\\msmsgs.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 oxser;OX16C95x Serial port driver;d:\windows\system32\DRIVERS\oxser.sys [2008-08-25 51169]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;d:\windows\system32\DRIVERS\klim5.sys [2007-04-04 24344]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;d:\windows\system32\DRIVERS\RTL8187.sys [2008-11-11 194304]
R3 SjyPkt;SjyPkt;\??\d:\windows\System32\Drivers\SjyPkt.sys [2008-11-11 13532]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - d:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

IE: Download ALL with IDA
IE: Download with IDA
IE: ت&صدير إلى Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 -: Microsoft XML Parser for Java -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

d:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
d:\windows\system32\msvcrt.dll - d:\windows\system32\mfc42.dll
d:\windows\system32\olepro32.dll
d:\windows\Downloaded Program Files\imcv1.dll
O16 -: {6924091F-CD97-41E1-B1D4-D9079409D413}
hxxp://76.76.24.100/IMSCP/talk.cab
d:\windows\Downloaded Program Files\talk.inf
FF - ProfilePath - d:\documents and settings\طاغي\Application Data\Mozilla\Firefox\Profiles\n6esbnl1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Rootkit scan 2008-12-17 20:33:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1620)
d:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
d:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(1676)
d:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll
d:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
- - - - - - - > 'explorer.exe'(3912)
d:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
d:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll
d:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
d:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
d:\program files\Hotspot Shield\bin\openvpnas.exe
d:\program files\Java\jre6\bin\jqs.exe
.
**************************************************************************
.
Completion time: 12/17/2008 20:38:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-17 17:38:10
ComboFix2.txt 2008-12-15 08:19:55
ComboFix3.txt 2008-12-10 02:17:13
Pre-Run: 616,851,968 bytes free
Post-Run: 600,952,320 bytes free
378 --- E O F --- 2008-12-10 14:47:38
 
توقيع : طآغي النظرهـ
Logfile of HijackThis v1.99.1
Scan saved at 04:10:58 م, on 17/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
D:\Program Files\Hotspot Shield\bin\openvpnas.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
D:\Program Files\REALTEK RTL8187 Wireless LAN Driver and Utility\RtWLan.exe
D:\Program Files\internet explorer\iexplore.exe
D:\Documents and Settings\طاغي\سطح المكتب\برامج الحمايه\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar.dll
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVP] "D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: REALTEK RTL8187 Wireless LAN Utility.lnk = ?
O8 - Extra context menu item: &Google Search - res://D:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: &Windows Live Search - res://D:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O8 - Extra context menu item: Backward &Links - res://D:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://D:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://D:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://D:\Program Files\Google\googletoolbar.dll/cmtrans.html
O8 - Extra context menu item: ت&صدير إلى Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - D:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash ) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - D:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - D:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: klogon - D:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - D:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - D:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - D:\Program Files\Java\jre6\bin\jqs.exe" -service -config "D:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZoneLabs\vsmon.exe
 
توقيع : طآغي النظرهـ
تكفووووون يالزيازيم صار لي ساعه وأنا أنتظر حلولكم تكفوووووون وربي طفشني الجهاز
 
توقيع : طآغي النظرهـ
يا هلا بك

حدد التالي ثم احذفها

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar.dll

O8 - Extra context menu item: Backward &Links - res://D:\Program Files\Google\googletoolbar.dll/cmbacklinks.html

O8 - Extra context menu item: Cac&hed Snapshot of Page - res://D:\Program Files\Google\googletoolbar.dll/cmcache.html

O8 - Extra context menu item: Si&milar Pages - res://D:\Program Files\Google\googletoolbar.dll/cmsimilar.html

O8 - Extra context menu item: Translate into English - res://D:\Program Files\Google\googletoolbar.dll/cmtrans.html

O8 - Extra context menu item: ت&صدير إلى Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O11 - Options group: [INTERNATIONAL] International*


طريقة الحذف

mg%20(3).png



mg%20(4).png



بعدها اذهب الى اضافة وازالة البرامج واحذف التولبار الموجود عندك (toolbar)


ثم نزل هذه الاداة واتبع الشرح التالي



يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي



التوافق : ويندوز اكسبي فقط


شرح الاستخدام ,,,,,,
دبل كلك على الاداة واصبر حتى تنتهي جميع النوافذ وتقف عند هذه النافذة


002.png



وعند ظهور هذه الشاشه ,, اضغط على Close ليتم اعادة تشغيل جهازك (( لتكملة عملية التنظيف ))

ثم حمل هذه الاداة ,,
واتبع الشرح التالي ,, لتنظيف جهازك من هذه الدعايات
و عمل تقرير بالعمليه حتى ترفقه بردك القادم ,,

رابط تحميل آخر تحديث للاداة
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي



شرح الاستخدام ,,,,,,
قم بتشغيل الملف SmitfraudFix.exe ,, وتابع الشرح كماا بهذه الصور


000.png





001.png





002.png





003.png





004.png



ثم هات تقرير اخر باداة هايجيك
 
تقرير الاداه..................................................

SmitFraudFix v2.387
Scan done at 14:14:07.20, Thu 12/18/2008
Run from D:\Documents and Settings\طاغي\سطح المكتب\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process

»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
D:\Documents and Settings\All Users\Application Data\Microsoft\Protect\conf.sys Deleted
D:\Documents and Settings\All Users\Application Data\Microsoft\Protect\svhost.exe Deleted
D:\Documents and Settings\All Users\Application Data\Microsoft\Protect\track.sys Deleted
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» RK

»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter - منفذ مصغر لجدولة الحزم
DNS Server Search Order: 82.167.0.131
DNS Server Search Order: 205.252.144.228
HKLM\SYSTEM\CCS\Services\Tcpip\..\{CC121BDC-22F7-4E40-B3CC-C2ACBD4EEA4F}: DhcpNameServer=82.167.0.131 205.252.144.228
HKLM\SYSTEM\CS1\Services\Tcpip\..\{CC121BDC-22F7-4E40-B3CC-C2ACBD4EEA4F}: DhcpNameServer=82.167.0.131 205.252.144.228
HKLM\SYSTEM\CS3\Services\Tcpip\..\{CC121BDC-22F7-4E40-B3CC-C2ACBD4EEA4F}: DhcpNameServer=82.167.0.131 205.252.144.228
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=82.167.0.131 205.252.144.228
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=82.167.0.131 205.252.144.228
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=82.167.0.131 205.252.144.228

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""

»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» End
 
توقيع : طآغي النظرهـ
Logfile of HijackThis v1.99.1
Scan saved at 14:23:28, on 18/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
D:\Program Files\Hotspot Shield\bin\openvpnas.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
D:\WINDOWS\system32\rundll32.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
D:\Program Files\REALTEK RTL8187 Wireless LAN Driver and Utility\RtWLan.exe
D:\Program Files\internet explorer\iexplore.exe
D:\Program Files\Windows Live\Messenger\usnsvc.exe
D:\WINDOWS\explorer.exe
D:\Documents and Settings\طاغي\سطح المكتب\برامج الحمايه\HijackThis.exe
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: REALTEK RTL8187 Wireless LAN Utility.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://D:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O8 - Extra context menu item: ت&صدير إلى Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - D:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} (IMCv1 Control) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash ) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - D:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - D:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: klogon - D:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - D:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - D:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - D:\Program Files\Java\jre6\bin\jqs.exe" -service -config "D:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZoneLabs\vsmon.exe
 
توقيع : طآغي النظرهـ
أخي نصب أحد برامج النتي فايروس التالية : نود , كاسبر , أفيرا , بتدفندر , إذا جهازك بستحمل Gdata إذا لم تنفع المشكلة جرب متصفح اخر مثل Mozila firefox
 
توقيع : المنتصر بإذن الله
تقرير جيد

كيف الجهاز الان؟
 
الان ماعاد تطلع لي صفحات التحذير وصفحات انترنت اكسبلورر الله يجزاك الف خير وأنا أعتذر عن طريقه طرحي للمشكله بأسلوب كان همجي لكن وربي من القهر اللي فيني وبيض الله وجيهكم وماقصرتوا
ملآحظه // أنا نزلت إنترنت إكسبلورر بدل اللي كان عندي يعني لآزم أنزل متصفح جديد ولا يكفي خلص
والله يرزقك ويرزق والدينك الجنه
 
توقيع : طآغي النظرهـ
الحمد لله على انتهاء المشكلة
يكفي متصفح اكسبلورر
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

بالتوفيق
 
عودة
أعلى