الحالة
مغلق و غير مفتوح للمزيد من الردود.

غنوجة نجد

زيزوومى مميز
إنضم
2 نوفمبر 2007
المشاركات
920
مستوى التفاعل
7
النقاط
520
غير متصل
مرحباااا

الله يعافيكم رجعة مشكلة الاسطوانه برامج سويتها مو راضيه تفتح

فتحت معاي ورجعت ما تفتح مره ثانيه؟؟ مدري ايشش المشكله

zyzoom-1e7d9badbb.gif


موضوعي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
 


ثم نزل هذه الاداة واتبع الشرح التالي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


التوافق : ويندوز اكسبيفقط

شرح الاستخدام ,,,,,,
عند تشغيل ملف الاداة تظهر لك هذه الشاشه ,, انتظر ( وتابع مع الصور )

000.png


001.png


وعند ظهور هذه الشاشه ,, اضغط على Close ليتم اعادة تشغيل جهازك (( لتكملة عملية التنظيف ))

002.png


بعد اعادة تشغيل الجهاز جربي
 
اهلين اخوي .. عملت الطريقة كل التنظيف سويته وتقرير ولا فيه شي جهازي نظيف

بس احتمال شي من ناقص ملف معين هو السبب ياليت تشوف لي هاذي المشكله يمكن منها

فحصة عن طريق السيف مود

بالاداة ComboFix

شوف رسال طلعت لي بس مافهمت ايش يعني

zyzoom-02dcd411f9.jpg
 
اوكي
اعملي تقرير للهايجاك
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

اذا انتهى التحميل ==> شغل البرنامج ==> واضغط على Do a system scan and save log
لحظات .. ويظهر لك تقرير اعمل تحديد الكل ==> انسخه والصقه بردك القادم​


 
PHP:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:29:23 م, on 20/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\windows\Explorer.EXE
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\ManyCam 2.4\ManyCam.exe
C:\Program Files\Paltalk Messenger\paltalk.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\internet explorer\iexplore.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [ManyCam] "C:\Program Files\ManyCam 2.4\ManyCam.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: delXP.bat
O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى FLV بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1237826842468
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Helper Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
--
End of file - 7683 bytes
 
يالغلا انسخي التقرير بدون اكواد
 
توقيع : KoNaMi
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:56:45 م, on 20/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\windows\Explorer.EXE
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\ManyCam 2.4\ManyCam.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Documents and Settings\Abeer$\Desktop\Killer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [ManyCam] "C:\Program Files\ManyCam 2.4\ManyCam.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: delXP.bat
O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى FLV بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Helper Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
--
End of file - 7622 bytes
 
التقرير نظيف

طيب اختي جربي تعطلين برامج الحمايه

هذا

\AntiVir Desktop

وهذا

SUPERAntiSpyware

ثم شغلي الإسطوانه
 
سويت عطلت مو راضيه تفتح
 
عطلت البرامج مو راضيه تفتح
 
طيب يالغلااا عطلي برامج الحمايه وتأكدي من وقت وتاريخ الجهاز ولاتغيري اسم الاداة احفظيها على سطح المكتب >>
اداة الكمبوفكس
 
توقيع : KoNaMi
اختي ماهو اصدار الاتوبلي الي تعملين عليه ؟؟ هذا اولا
وثانيا طريقتك الي بالصورة لعمل اسطوانة بصيغة exe هذه فقط تستخدم للأسطوانات الصغيرة الحجم وهي غير قعالة للأسطوانات الكبيرة
بأنتظار اجابتك بعد تطبيق ما قاله الاحباب قبلي

 
توقيع : السّاجد لله
هاذا الفحص

ComboFix 09-05-08.03 - Free User 05/09/2009 15:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.2038.1627 [GMT 2:00]
Running from: c:\documents and settings\Free User\Desktop\دكيومانت\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated)
FW: ESET Personal firewall *enabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\_002741_.tmp.dll
c:\windows\system32\_002742_.tmp.dll
c:\windows\system32\_002743_.tmp.dll
c:\windows\system32\_002744_.tmp.dll
c:\windows\system32\_002751_.tmp.dll
c:\windows\system32\_002752_.tmp.dll
c:\windows\system32\_002753_.tmp.dll
c:\windows\system32\_002754_.tmp.dll
c:\windows\system32\_002756_.tmp.dll
c:\windows\system32\_002757_.tmp.dll
c:\windows\system32\_002760_.tmp.dll
c:\windows\system32\_002761_.tmp.dll
c:\windows\system32\_002763_.tmp.dll
c:\windows\system32\_002764_.tmp.dll
c:\windows\system32\_002765_.tmp.dll
c:\windows\system32\_002767_.tmp.dll
c:\windows\system32\_002770_.tmp.dll
c:\windows\system32\_002771_.tmp.dll
c:\windows\system32\_002775_.tmp.dll
c:\windows\system32\_002776_.tmp.dll
c:\windows\system32\_002778_.tmp.dll
c:\windows\system32\_002781_.tmp.dll
c:\windows\system32\_002783_.tmp.dll
c:\windows\system32\_002784_.tmp.dll
c:\windows\system32\_002785_.tmp.dll
c:\windows\system32\_002786_.tmp.dll
c:\windows\system32\_002787_.tmp.dll
c:\windows\system32\_002790_.tmp.dll
c:\windows\system32\_002791_.tmp.dll
c:\windows\system32\_002792_.tmp.dll
c:\windows\system32\_002793_.tmp.dll
c:\windows\system32\_002794_.tmp.dll
c:\windows\system32\_002799_.tmp.dll
c:\windows\system32\_002801_.tmp.dll
c:\windows\system32\_002802_.tmp.dll
.
((((((((((((((((((((((((( Files Created from 2009-04-09 to 2009-05-09 )))))))))))))))))))))))))))))))
.
2009-05-09 13:39 . 2009-05-09 13:39 -------- d-sh--w C:\found.000
2009-05-09 12:48 . 2009-05-09 12:48 -------- d-----w c:\program files\Common Files\EZB Systems
2009-05-09 12:48 . 2009-05-09 12:48 -------- d-----w c:\program files\UltraISO
2009-05-09 12:34 . 2009-05-09 12:34 -------- d-----w c:\documents and settings\Free User\Application Data\Downloaded Installations
2009-05-09 11:24 . 2009-05-09 11:24 -------- d-----w c:\documents and settings\Free User\Application Data\Acronis
2009-05-09 11:22 . 2009-05-09 11:22 37888 ----a-w c:\windows\system32\setupnt.dll
2009-05-09 11:22 . 2009-05-09 11:22 28896 ----a-w c:\windows\system32\drivers\tifsfilt.sys
2009-05-09 11:22 . 2009-05-09 11:22 211520 ----a-w c:\windows\system32\drivers\timntr.sys
2009-05-09 11:22 . 2009-05-09 11:22 82464 ----a-w c:\windows\system32\drivers\snapman.sys
2009-05-09 11:22 . 2009-05-09 11:22 126976 ----a-w c:\windows\system32\snapapi.dll
2009-05-09 11:22 . 2009-05-09 11:22 -------- d-----w c:\program files\Common Files\Acronis
2009-05-09 11:22 . 2009-05-09 11:22 -------- d-----w c:\program files\Acronis
2009-05-09 00:41 . 2009-05-09 00:41 -------- d-sh--w C:\viruses
2009-05-09 00:41 . 2009-05-09 00:42 160 ----a-w c:\windows\thanks.vbs
2009-05-09 00:41 . 2009-05-09 00:41 -------- d-----w c:\program files\alfattak
2009-05-08 23:38 . 2009-05-08 23:39 -------- d-----w c:\documents and settings\Free User\Application Data\Media Player Classic
2009-05-08 21:09 . 2004-08-03 22:56 53760 -c--a-w c:\windows\system32\dllcache\vfwwdm32.dll
2009-05-08 21:09 . 2004-08-03 22:56 53760 ----a-w c:\windows\system32\vfwwdm32.dll
2009-05-08 21:09 . 2009-05-08 21:10 -------- d-----w c:\documents and settings\Free User\Application Data\ManyCam
2009-05-08 21:09 . 2009-05-08 21:10 -------- d-----w c:\program files\ManyCam 2.4
2009-05-08 18:00 . 2009-05-08 18:00 -------- d-----w c:\program files\IEPro
2009-05-08 18:00 . 2009-05-08 18:00 -------- d-----w c:\documents and settings\Free User\Application Data\IEPro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-09 13:15 . 2009-05-08 15:12 -------- d-----w c:\program files\Paltalk Messenger
2009-05-08 23:57 . 2009-05-08 15:14 -------- d-----w c:\program files\K-Lite Codec Pack
2009-05-08 16:13 . 2009-05-08 14:33 166455 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-08 15:44 . 2009-05-08 15:44 -------- d-----w c:\program files\TechSmith
2009-05-08 15:43 . 2009-05-08 15:43 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-05-08 15:38 . 2009-05-08 15:13 36288 ----a-w c:\documents and settings\Free User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-08 15:28 . 2009-05-08 15:28 -------- d-----w c:\program files\ESET
2009-05-08 15:25 . 2009-05-08 15:25 -------- d-----w c:\program files\Windows Media Connect 2
2009-05-08 15:19 . 2009-05-08 15:19 -------- d-----w c:\program files\MSECache
2009-05-08 15:16 . 2009-05-08 15:16 -------- d-----w c:\program files\Internet Download Manager
2009-05-08 15:15 . 2009-05-08 15:15 -------- d-----w c:\program files\Common Files\ACD Systems
2009-05-08 15:15 . 2009-05-08 15:15 -------- d-----w c:\program files\ACD Systems
2009-05-08 15:15 . 2009-05-08 15:15 9856 ----a-w c:\windows\system32\drivers\pfc.sys
2009-05-08 15:13 . 2009-05-08 15:13 -------- d-----w c:\program files\Circle Dvelopement
2009-05-08 15:13 . 2009-05-08 15:13 -------- d-----w c:\program files\Messenger Plus! Live
2009-05-08 15:13 . 2009-05-08 15:00 -------- d-----w c:\program files\Real
2009-05-08 15:13 . 2009-05-08 15:13 203776 ----a-w c:\windows\system32\clrviddc.dll
2009-05-08 15:12 . 2009-05-08 15:12 -------- d-----w c:\program files\Common Files\xing shared
2009-05-08 15:12 . 2009-05-08 15:12 -------- d-----w c:\program files\Windows Live
2009-05-08 15:12 . 2009-05-08 15:00 -------- d-----w c:\program files\Common Files\Real
2009-05-08 15:12 . 2009-05-08 14:58 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-05-08 15:12 . 2009-05-08 14:58 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-05-08 15:08 . 2009-05-08 15:08 -------- d-----w c:\program files\Your Uninstaller 2008
2009-05-08 15:07 . 2009-05-08 15:07 -------- d-----w c:\program files\Uniblue
2009-05-08 15:03 . 2009-05-08 15:03 -------- d-----w c:\program files\PConPoint
2009-05-08 15:00 . 2009-05-08 15:00 -------- d-----w c:\program files\Common Files\Adobe
2009-05-08 14:59 . 2009-05-08 14:59 -------- d-----w c:\program files\MSXML 4.0
2009-05-08 14:59 . 2009-05-08 14:59 -------- d-----w c:\program files\CCleaner
2009-05-08 14:58 . 2009-05-08 14:58 410984 ----a-w c:\windows\system32\deploytk.dll
2009-05-08 14:58 . 2009-05-08 14:58 -------- d-----w c:\program files\Java
2009-05-08 14:54 . 2009-05-08 14:54 -------- d-----w c:\program files\Microsoft ActiveSync
2009-05-08 14:50 . 2009-05-08 14:49 -------- d-----w c:\program files\IDT
2009-05-08 14:49 . 2009-05-08 14:49 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-08 14:49 . 2009-05-08 14:49 -------- d-----w c:\program files\Common Files\InstallShield
2009-05-08 14:49 . 2009-05-08 14:45 -------- d-----w c:\program files\Intel
2009-05-08 14:34 . 2009-05-08 14:34 -------- d-----w c:\program files\microsoft frontpage
2009-05-08 14:33 . 2002-12-31 12:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-05-08 14:30 . 2009-05-08 14:30 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-04-09 13:21 . 2009-04-09 13:21 55768 ----a-w c:\windows\system32\drivers\epfwtdi.sys
2009-04-09 13:21 . 2009-04-09 13:21 33096 ----a-w c:\windows\system32\drivers\epfwndis.sys
2009-04-09 13:21 . 2009-04-09 13:21 133000 ----a-w c:\windows\system32\drivers\epfw.sys
2009-04-09 13:18 . 2009-04-09 13:18 107256 ----a-w c:\windows\system32\drivers\ehdrv.sys
2009-04-09 13:10 . 2009-04-09 13:10 113960 ----a-w c:\windows\system32\drivers\eamon.sys
2009-04-02 13:21 . 2009-05-08 15:14 84480 ----a-w c:\windows\system32\ff_vfw.dll
2009-03-26 15:35 . 2009-04-02 11:18 210352 ----a-w c:\windows\system32\idmmbc.dll
2009-03-03 00:18 . 2002-12-31 12:00 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-26 20:47 . 2009-05-08 15:14 2255360 ----a-w c:\windows\system32\x264vfw.dll
2009-02-20 18:09 . 2002-12-31 12:00 78336 ------w c:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2002-12-31 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-11-29 5724184]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-04-02 2794928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acronis True Image Monitor"="c:\program files\Acronis\TrueImage\TrueImageMonitor.exe" [2009-05-09 419408]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-05-09 69632]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2009-4-25 11057664]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRun"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IEPro\\MiniDM.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [09/04/2009 03:18 م 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [09/04/2009 03:19 م 731840]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [14/01/2008 12:06 م 21632]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)

.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.googel.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
IE: {{000002a3-84fe-43f1-b958-f2c3ca804f1a} - {CD275D4E-791A-4993-9D4D-6A071EDD2709} - c:\program files\IEPro\iepro.dll
LSP: c:\windows\system32\idmmbc.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Rootkit scan 2009-05-09 15:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(1020)
c:\windows\system32\idmmbc.dll
- - - - - - - > 'explorer.exe'(3052)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\IDT\IntelXPV_v83\WDM\stacsv.exe
c:\windows\system32\wscntfy.exe
c:\program files\ESET\ESET Smart Security\egui.exe
.
**************************************************************************
.
Completion time: 2009-05-09 15:48 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-09 13:48
Pre-Run: 46,461,689,856 bytes free
Post-Run: 46,875,041,792 bytes free
195


هشام اخوي الاصدار هو AutoPlay Media Studio 7.0
 
طيب انحذف من جهازك عدد كبير من الملفات الضارة هل ما زالت المشكلة قائمة
 
توقيع : السّاجد لله
عارفه حذف هاذي الملفت

c:\windows\system32\_002741_.tmp.dll
c:\windows\system32\_002742_.tmp.dll
c:\windows\system32\_002743_.tmp.dll
c:\windows\system32\_002744_.tmp.dll
c:\windows\system32\_002751_.tmp.dll
c:\windows\system32\_002752_.tmp.dll
c:\windows\system32\_002753_.tmp.dll
c:\windows\system32\_002754_.tmp.dll
c:\windows\system32\_002756_.tmp.dll
c:\windows\system32\_002757_.tmp.dll
c:\windows\system32\_002760_.tmp.dll
c:\windows\system32\_002761_.tmp.dll
c:\windows\system32\_002763_.tmp.dll
c:\windows\system32\_002764_.tmp.dll
c:\windows\system32\_002765_.tmp.dll
c:\windows\system32\_002767_.tmp.dll
c:\windows\system32\_002770_.tmp.dll
c:\windows\system32\_002771_.tmp.dll
c:\windows\system32\_002775_.tmp.dll
c:\windows\system32\_002776_.tmp.dll
c:\windows\system32\_002778_.tmp.dll
c:\windows\system32\_002781_.tmp.dll
c:\windows\system32\_002783_.tmp.dll
c:\windows\system32\_002784_.tmp.dll
c:\windows\system32\_002785_.tmp.dll
c:\windows\system32\_002786_.tmp.dll
c:\windows\system32\_002787_.tmp.dll
c:\windows\system32\_002790_.tmp.dll
c:\windows\system32\_002791_.tmp.dll
c:\windows\system32\_002792_.tmp.dll
c:\windows\system32\_002793_.tmp.dll
c:\windows\system32\_002794_.tmp.dll
c:\windows\system32\_002799_.tmp.dll
c:\windows\system32\_002801_.tmp.dll
c:\windows\system32\_002802_.tmp.dll


لاكن للحين المشكله موجوده مممممممم الحل ابي اجربها في جهاز ثاني اشوف ايش المشكله
 
طيب راح اعطيك رابط البرنامج النسخة السادسة الاحترافية الي انا اعمل عليها مع الملحقات وش رايك ؟؟
وان شاء الله تنحل المشكلة

 
توقيع : السّاجد لله
طيب حلو الله يعافيك ياليت
 
توقيع : السّاجد لله
مشكووووووور جاررري التحميل
 
الحالة
مغلق و غير مفتوح للمزيد من الردود.
عودة
أعلى