المعلمي

زيزوومى مميز
إنضم
7 سبتمبر 2008
المشاركات
544
مستوى التفاعل
8
النقاط
520
الإقامة
YEMEN-IBB
غير متصل
احبائي الزيزومين السلام عليكم ورحمة الله وبركاته
مشكلتي اليوم هي ان الفاير فوكس واغلب البرامج لاتعمل معي الى دقائق وبعدين رسالة exe ويقفل البرنامج
طبعا معاي افيرا سيكورتي محدث كل دقيقه
مافي فيروسات تعبت الياهو الماسنجر الفايرفوكس الأنترنت اكسبلورر يعمل دقائق وبعدين يفصل وتطلع رسالة exe
طبعا معاي الزيزومين هم مايحتاج
جيت استشيرهم وهذا تقرير الهايجك ودمتم بخير وعافيه
Logfile of HijackThis v1.99.1
Scan saved at 09:18:07 ص, on 29/03/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\USBScan\USBScan.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir Desktop\avscan.exe
H:\HijackThis.exe

O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [USBScan.exe] C:\Program Files\USBScan\USBScan.exe -Hide
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\avira\antivir desktop\avsda.dll
O10 - Unknown file in Winsock LSP: c:\program files\avira\antivir desktop\avsda.dll
O10 - Unknown file in Winsock LSP: c:\program files\avira\antivir desktop\avsda.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O23 - Service: Avira Firewall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
 

توقيع : المعلمي
عطل برامج الحماية عن العمل
ثم
حمل الاداة التالية واحفظها على سطح المكتب
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes

اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
لا تقم بتشغيل اي برنامج ،، ومهما طالت عملية الفحص انتظر حتى تنتهي
انتظر حتى يظهر لك تقرير ،،انسخه والصقه بمشاركتك القادمة
 
مشكور كل الشكر اخي الغالي maax
وجاري التحميل والتجربه
 
توقيع : المعلمي
اخي الحبيب maax
البرنامج يعلق ومايعمل ممكن حل آخر
سامحنا لو تعبناك معنا
 
توقيع : المعلمي
كيف يعلق اخي ؟
وانا وضحت لك هذا

لا تقم بتشغيل اي برنامج ،، ومهما طالت عملية الفحص انتظر حتى تنتهي
 
اخي الغالي والحبيب تفضل واعذرني على الإستعجال
ComboFix 09-03-28.06 - العمل 03/29/2009 17:46:56.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.1918.1546 [GMT 3:00]
Running from: c:\documents and settings\العمل\سطح المكتب\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated)
FW: Avira Firewall *enabled*

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\advapi32new.dll
c:\windows\system32\apphelpnew.dll
c:\windows\system32\crypt32new.dll
c:\windows\system32\d3d10core.dll
c:\windows\system32\divx.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\kernel32new.dll
c:\windows\system32\msvcrtnew.dll
c:\windows\system32\ntdsapinew.dll
c:\windows\system32\powrprofnew.dll
c:\windows\system32\secur32new.dll
c:\windows\system32\user32new.dll
c:\windows\system32\winstanew.dll

.
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-29 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 14:45 --------- d-----w c:\documents and settings\العمل\Application Data\Orbit
2009-03-29 14:45 --------- d-----w c:\documents and settings\العمل\Application Data\Orbit
2009-03-29 14:45 --------- d-----w c:\documents and settings\العمل\Application Data\Orbit
2009-03-29 14:22 --------- d-----w c:\program files\iTunes
2009-03-29 14:22 --------- d-----w c:\documents and settings\العمل\Application Data\Apple Computer
2009-03-29 14:22 --------- d-----w c:\documents and settings\العمل\Application Data\Apple Computer
2009-03-29 14:22 --------- d-----w c:\documents and settings\العمل\Application Data\Apple Computer
2009-03-29 14:21 --------- d-----w c:\program files\iPod
2009-03-29 14:21 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-03-29 14:20 --------- d-----w c:\program files\Bonjour
2009-03-29 14:19 --------- d-----w c:\program files\Apple Software Update
2009-03-29 14:18 --------- d-----w c:\program files\Orbitdownloader
2009-03-29 14:18 --------- d-----w c:\program files\Common Files\Apple
2009-03-29 14:18 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2009-03-29 08:38 --------- d-----w c:\program files\USBScan
2009-03-29 06:47 --------- d-----w c:\program files\System
2009-03-28 17:57 --------- d-----w c:\program files\Active Data Recovery Services
2009-03-28 17:57 --------- d-----w c:\documents and settings\All Users\Application Data\TEMP
2009-03-28 17:28 90,112 ----a-w c:\windows\DUMP51b9.tmp
2009-03-28 08:15 --------- d-----w c:\program files\Golden Al-Wafi Translator
2009-03-28 08:11 73,216 ----a-w c:\windows\ST6UNST.EXE
2009-03-28 08:11 172,032 ------w c:\windows\Setup1.exe
2009-03-28 07:54 --------- d-----w c:\program files\Avira
2009-03-28 07:54 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-03-27 12:17 --------- d-----w c:\documents and settings\العمل\Application Data\Ahead
2009-03-27 12:17 --------- d-----w c:\documents and settings\العمل\Application Data\Ahead
2009-03-27 12:17 --------- d-----w c:\documents and settings\العمل\Application Data\Ahead
2009-03-26 16:12 --------- d-----w c:\program files\Ahead
2009-03-26 15:51 --------- d-----w c:\program files\CCleaner
2009-03-26 15:02 45,056 ----a-w c:\windows\NCUNINST.EXE
2009-03-26 15:02 --------- d-----w c:\program files\Common Files\SWF Studio
2009-03-26 13:28 --------- d-----w c:\program files\Common Files\Adobe
2009-03-26 11:26 --------- d-----w c:\program files\Windows Live
2009-03-26 10:52 --------- d-----w c:\documents and settings\العمل\Application Data\Media Player Classic
2009-03-26 10:52 --------- d-----w c:\documents and settings\العمل\Application Data\Media Player Classic
2009-03-26 10:52 --------- d-----w c:\documents and settings\العمل\Application Data\Media Player Classic
2009-03-26 10:51 --------- d-----w c:\program files\K-Lite Codec Pack
2009-03-26 10:46 --------- d-----w c:\documents and settings\العمل\Application Data\GrabPro
2009-03-26 10:46 --------- d-----w c:\documents and settings\العمل\Application Data\GrabPro
2009-03-26 10:46 --------- d-----w c:\documents and settings\العمل\Application Data\GrabPro
2009-03-26 10:45 --------- d-----w c:\program files\Yahoo!
2009-03-26 10:45 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2009-03-26 09:55 --------- d-----w c:\program files\Alfa Autorun Killer 2
2009-03-26 08:55 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-26 08:55 --------- d-----w c:\program files\Realtek
2009-03-26 08:54 319,488 ----a-w c:\windows\HideWin.exe
2009-03-26 08:54 --------- d-----w c:\program files\Common Files\Ahead
2009-03-26 08:53 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-26 07:39 --------- d-----w c:\program files\Microsoft.NET
2009-03-26 07:37 --------- d-----w c:\program files\Microsoft Works
2009-03-26 06:59 --------- d-----w c:\program files\microsoft frontpage
2009-03-10 09:05 97,096 ----a-w c:\windows\system32\drivers\avfwot.sys
2009-02-24 09:06 69,632 ----a-w c:\windows\system32\drivers\avfwim.sys
2009-02-13 08:31 55,640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2008-03-09 04:25 236 ---ha-w c:\program files\Common Files\dx.reg
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [10/27/2007 07:51 AM 3810544]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [08/04/2004 01:09 AM 1667584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USBScan.exe"="c:\program files\USBScan\USBScan.exe" [12/18/2008 09:25 PM 1257472]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [07/09/2001 10:50 AM 155648]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [03/02/2009 12:08 PM 209153]
"QuickTime Task"="c:\program files\K-Lite Codec Pack\QuickTime\QTTask.exe" [05/27/2008 10:50 AM 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [06/02/2008 11:13 AM 267048]
"RTHDCPL"="RTHDCPL.EXE" [09/09/2008 06:39 PM 16851968 c:\windows\RTHDCPL.EXE]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]

c:\documents and settings\All Users\çں‍ê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-03-26 113664]
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2009-03-29 1719496]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll
"VIDC.VP31"= vp31vfw.dll
"msacm.l3fhg"= mp3fhg.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 avfwot;avfwot;c:\windows\system32\drivers\avfwot.sys [2009-03-28 97096]
R2 AntiVirFirewallService;Avira Firewall;c:\program files\Avira\AntiVir Desktop\avfwsvc.exe [2009-03-28 383745]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [2009-03-28 186625]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-28 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [2009-03-28 432897]
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\drivers\avfwim.sys [2009-03-28 69632]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\Shell\AutoRun\command - L:\start.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4a332d81-19db-11de-9a52-00167699e20a}]
\SHELL\AutOplay\coMmand - ylkhwk.pif
\SHELL\AutoRun\command - ylkhwk.pif
\SHELL\EXploRe\comMaNd - ylkhwk.pif
\SHELL\open\coMmand - ylkhwk.pif

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7f4a42a0-1bc0-11de-9a64-00167699e20a}]
\Shell\AutoRun\command - L:\start.exe
.
Contents of the 'Scheduled Tasks' folder

2009-03-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [08/29/2007 02:57 PM]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.orbitdownloader.com
uInternet Settings,ProxyOverride = *.local
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
FF - ProfilePath - c:\documents and settings\العمل\Application Data\Mozilla\Firefox\Profiles\0dtoqavl.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Rootkit scan 2009-03-29 17:48:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(856)
c:\program files\Avira\AntiVir Desktop\avsda.dll
.
Completion time: 03/29/2009 17:50:14
ComboFix-quarantined-files.txt 2009-03-29 14:50:12

Pre-Run: 14,116,675,584 bytes free
Post-Run: 14,397,648,896 bytes free

182
 
توقيع : المعلمي
أعد ارفاق تقرير هايجاك جديد ,,
 
توقيع : Corporation
تفضل اخي الغالي
Logfile of HijackThis v1.99.1
Scan saved at 06:21:40 م, on 29/03/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
H:\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [USBScan.exe] C:\Program Files\USBScan\USBScan.exe -Hide
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\avira\antivir desktop\avsda.dll
O10 - Unknown file in Winsock LSP: c:\program files\avira\antivir desktop\avsda.dll
O10 - Unknown file in Winsock LSP: c:\program files\avira\antivir desktop\avsda.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O23 - Service: Avira Firewall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
 
توقيع : المعلمي
أحذف هذه القيم ,,

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [USBScan.exe] C:\Program Files\USBScan\USBScan.exe -Hide

طريقة الحذف للاكس بي


mg%20%283%29.png


mg%20%284%29.png

بعدها ,,

نظف الجهاز بهذه الاداة

التحميل من هنا

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي



التوافق : ويندوز اكسبي فقط




شرح الاستخدام ,,,,,,



عند تشغيل ملف الاداة تظهر لك هذه الشاشه ,, انتظر ( وتابع مع الصور )




000.png




001.png




وعند ظهور هذه الشاشه ,, اضغط على Close ليتم اعادة تشغيل جهازك (( لتكملة عملية التنظيف ))




002.png





وبعدها ,,

حممل هذه الاداة لأصلاح الأتصال ,,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
عند تشغيل الاداة نضغط كما محدد بالصورة التالية
wh_61624949.png

 
التعديل الأخير بواسطة المشرف:
توقيع : Corporation
لك كل الشكر اخي الغالي
كله تمام ماعد ا الفايرفوكس كل شويه ويقفل ويقول إنهار شو المشكله ولك جزيل الشكر والتقدير وسامحنا لوتعبناك معنا
 
توقيع : المعلمي
السلام عليكم يا إخواني الأعزاء
أنا قابلتني نفس المشكلة exe و عندي في جهازي برامج كتير مش بتفتح مثل adobe acrobat
و برامج أخرى و هذا هو التقرير مرفق:

ComboFix 09-05-30.03 - Ahmed 31/05/2009 15:08.3 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.44.1033.18.766.403 [GMT 3:00]
Running from: c:\downloads\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-31 )))))))))))))))))))))))))))))))
.

2009-05-31 09:23 . 2009-05-31 09:23 -------- d-sh--w C:\FOUND.003
2009-05-30 10:32 . 2009-05-30 10:32 -------- d-sh--w C:\FOUND.002
2009-05-28 11:52 . 2009-05-28 11:52 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-05-28 11:42 . 2009-05-28 11:42 -------- d-----w c:\documents and settings\Ahmed\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-05-28 11:42 . 2009-05-28 11:52 38208 ----a-w c:\documents and settings\Ahmed\Application Data\Macromedia\Flash Player\
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

2009-05-23 11:21 . 2009-05-23 11:21 -------- d-sh--w C:\FOUND.001
2009-05-23 07:24 . 2009-05-23 07:24 -------- d-sh--w C:\FOUND.000
2009-05-19 08:54 . 2009-05-19 08:54 604416 ----a-w c:\windows\system32\TUProgSt.exe
2009-05-19 08:54 . 2009-04-27 12:21 28928 ----a-w c:\windows\system32\uxtuneup.dll
2009-05-19 08:54 . 2009-05-19 08:54 361216 ----a-w c:\windows\system32\TuneUpDefragService.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-31 11:44 . 2009-02-18 12:34 32 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-31 11:44 . 2009-02-18 12:34 32 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-31 11:44 . 2009-02-18 12:34 32 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-31 11:44 . 2009-02-18 12:34 32 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-31 11:44 . 2009-01-06 08:19 12 ----a-w c:\windows\bthservsdp.dat
2009-05-31 11:32 . 2009-05-31 11:32 -------- d-----w c:\documents and settings\Ahmed\Application Data\CyberScrub
2009-05-31 11:32 . 2009-05-31 11:32 -------- d-----w c:\documents and settings\Ahmed\Application Data\cleaner
2009-05-26 14:00 . 2007-10-23 22:47 96760 ----a-w c:\windows\system32\dfshim.dll
2009-05-26 09:26 . 2008-04-20 09:48 155648 ----a-w c:\windows\system32\NeroCheck.exe
2009-05-26 09:26 . 2005-09-23 04:01 153800 ----a-w c:\windows\system32\vsjitdebugger.exe
2009-05-26 09:21 . 2008-06-03 14:22 110592 ----a-w c:\documents and settings\Ahmed\Application Data\U3\temp\cleanup.exe
2009-05-26 09:21 . 2008-06-03 14:21 3072000 ---ha-w c:\documents and settings\Ahmed\Application Data\U3\temp\Launchpad Removal.exe
2009-05-26 09:19 . 2009-02-18 12:34 94643 ----a-w c:\windows\system32\drivers\klick.dat
2009-05-26 09:19 . 2009-02-18 12:34 105395 ----a-w c:\windows\system32\drivers\klin.dat
2009-05-26 09:02 . 2008-03-01 07:45 45056 ----a-r c:\documents and settings\Ahmed\Application Data\Microsoft\Installer\{90B5E602-1867-449D-86FD-FC9DEA4434BF}\NewShortcut1_5B69D3033CA54B39B5ECE7D051297E77.exe
2009-05-26 08:44 . 2008-04-25 13:46 70992 ----a-w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 2009\English\setup.exe
2009-05-24 12:55 . 2008-04-09 08:05 77312 ----a-w c:\windows\ua2.dll
2009-04-05 08:57 . 2009-04-05 08:57 -------- d-----w c:\program files\TuneUp Utilities 2009
2009-04-05 08:57 . 2009-04-05 08:57 -------- d-sh--w c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-03-06 13:44 . 2004-08-03 21:56 283648 ----a-w c:\windows\system32\pdh.dll
2009-03-02 23:18 . 2004-08-03 21:56 826368 ----a-w c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-03-28 21712680]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2009-05-26 2035712]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-03-14 486856]
"X'nBeep"="c:\program files\X'nBeep 1.1\XnBeep.exe" [2007-01-08 1067520]
"Google Update"="c:\documents and settings\Ahmed\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-23 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StatusClient 2.6"="c:\program files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2004-02-27 61440]
"TomcatStartup 2.5"="c:\program files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2009-05-26 266240]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-01-07 49152]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 36975]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2009-05-26 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-26 259624]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-18 201992]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-03 110592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"CryptSvc"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\WgaTray.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26151:TCP"= 26151:TCP:BitComet 26151 TCP
"26151:UDP"= 26151:UDP:BitComet 26151 UDP
"18422:TCP"= 18422:TCP:BitComet 18422 TCP
"18422:UDP"= 18422:UDP:BitComet 18422 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 18:29 33808]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [19/05/2009 11:54 604416]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 19:02 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [25/03/2008 20:07 24592]
S3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\hlnnin.sys --> c:\windows\system32\drivers\hlnnin.sys [?]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23/09/2005 07:01 2799808]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2009-05-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-2077806209-682003330-1003.job
- c:\documents and settings\Ahmed\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-23 07:47]

2009-05-31 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:37]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.eg/
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = 126.100.100.103:8080
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: {{89E551A3-C402-4F52-AD12-FD6D3BC69CC2} - {89E551A3-C402-4F52-AD12-FD6D3BC69CC2} - c:\program files\IEToolbar\شريط أدوات الدرر السنية\ltr.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Rootkit scan 2009-05-31 15:10
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(512)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\klogon.dll
.
Completion time: 2009-05-31 15:12
ComboFix-quarantined-files.txt 2009-05-31 12:12
ComboFix2.txt 2009-05-31 11:20

Pre-Run: 3,271,704,576 bytes free
Post-Run: 3,260,612,608 bytes free

153 --- E O F --- 2009-05-06 14:31

أرجو الرد سريعاً يا إخواني لأن جهازي في مشكلة كبيرة ومحتاج أشغل برامج كتيرة
 
عودة
أعلى