• بادئ الموضوع بادئ الموضوع صلوين
  • تاريخ البدء تاريخ البدء
  • المشاهدات 845

صلوين

زيزوومى متألق
إنضم
25 مايو 2008
المشاركات
391
مستوى التفاعل
0
النقاط
470
الإقامة
ارض الله الواسعة
غير متصل
اريد حل يا أخوان جهازي عند تركه فترة معينة من الوقت يعني عندما اشتغل علية ثم أدهب واعود اليه خلال

اربع أو خمس ساعات اجده قد تجمد يعني الماوس وكيبورد لا يشتغلا ضروري أعمل ريستارت للجهاز كي

يعملا ما هي المشكلة وما هو الحل هل هناك خلل في الجهاز أو مادا ؟

أرجو المساعدة لانني أعمل على الكمبيوتر وتركه فترة وأعود اليه ,,,


أرجو المساعدة من فضلكم ,,,,,,,, جزالكم الله خيراا ,,,
 

توقيع : صلوين
1_ حمل هالبرنامج
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

ثبت البرنامج ثم
شغل البرنامج ==> واضغط على
Do a system scan and save log

لحظات .. ويظهر لك تقرير داخل المفكرة انسخه بردك القادم
 
طيب افحص الجهاز بالكامل من الفيروسات احتمال الفايرس يتنشط . لو كل شي تمام يعني السفت وير تمام مابة اية مشكلة .
تاكد عادك انك تقوم بفورمات c
هدا اول شي ابغاك تسويها من لسفت وير
بعدين الهارد وير . مشكلتها تانية
احتمال يكون من الراامات



2Aj2D-lj8I_65879520.gif
 
مشكورين يا أخوان ,,, بارون ,, عاشق الصيانة ,, للمساعدة وفقكم الله ,,

وهدا التقرير يا بارون Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:27:40 PM, on 7/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\coIEPlg.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O17 - HKLM\System\CCS\Services\Tcpip\..\{38A9E153-8CC2-49CF-93EB-286BD737C4F8}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{38A9E153-8CC2-49CF-93EB-286BD737C4F8}: NameServer = 192.168.1.1
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 5204 bytes
 
توقيع : صلوين
عطل برامج الحماية عن العمل
ثم
حمل الاداة التالية واحفظها على سطح المكتب
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
لا تقم بتشغيل اي برنامج ،، ومهما طالت عملية الفحص انتظر حتى تنتهي
انتظر حتى يظهر لك تقرير ،،انسخه والصقه بمشاركتك القادمة
 
هدا التتقرير يا أخي بارون


ComboFix 09-07-01.04 - salahm 07/02/2009 14:37.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.511.271 [GMT -7:00]
Running from: c:\documents and settings\salahm\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2009-06-02 to 2009-07-02 )))))))))))))))))))))))))))))))
.

2009-07-02 21:27 . 2009-07-02 21:27 -------- d-----w- c:\program files\Trend Micro
2009-07-02 20:22 . 2009-07-01 08:00 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVENG.SYS
2009-07-02 20:22 . 2009-07-01 08:00 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVEX15.SYS
2009-07-02 20:22 . 2009-07-01 08:00 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\EECTRL.SYS
2009-07-02 20:22 . 2009-07-01 08:00 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\ECMSVR32.DLL
2009-07-02 20:22 . 2009-07-01 08:00 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\CCERASER.DLL
2009-07-02 20:22 . 2009-07-01 08:00 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVENG32.DLL
2009-07-02 20:22 . 2009-07-01 08:00 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVEX32A.DLL
2009-07-02 20:22 . 2009-07-01 08:00 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\ERASER.SYS
2009-07-02 20:03 . 2009-07-02 07:22 165240 ----a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2009-07-02 08:02 . 2009-06-26 06:16 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\Scxpx86.dll
2009-07-02 08:02 . 2009-06-26 06:16 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSxpx86.dll
2009-07-02 08:02 . 2009-06-26 06:16 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSviA64.sys
2009-07-02 08:02 . 2009-06-26 06:16 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSvix86.sys
2009-07-02 08:02 . 2009-06-26 06:16 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys
2009-07-02 07:21 . 2009-07-02 07:21 -------- d-----w- c:\windows\system32\drivers\NIS
2009-07-02 07:21 . 2009-07-02 07:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-07-02 07:21 . 2009-07-02 07:21 -------- d-----w- c:\program files\Norton Internet Security
2009-07-02 07:21 . 2009-07-02 07:21 -------- d-----w- c:\program files\Windows Sidebar
2009-07-02 07:21 . 2009-07-02 07:21 -------- d-----w- c:\program files\NortonInstaller
2009-07-02 07:21 . 2009-07-02 07:21 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-07-02 00:44 . 2008-04-14 07:15 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2009-07-01 22:40 . 1999-09-10 11:06 5600 ----a-w- c:\windows\system\winaspi.dll
2009-07-01 22:40 . 1999-09-10 11:06 4672 ----a-w- c:\windows\system\wowpost.exe
2009-07-01 22:40 . 1999-09-10 11:06 25244 ----a-w- c:\windows\system32\drivers\aspi32.sys
2009-07-01 22:40 . 1999-09-10 11:06 45056 ----a-w- c:\windows\system32\wnaspi32.dll
2009-07-01 22:36 . 2009-07-01 22:36 203776 ----a-w- c:\windows\system32\clrviddc.dll
2009-07-01 22:33 . 2009-07-01 22:33 -------- d-----w- c:\program files\Common Files\xing shared
2009-07-01 22:32 . 2009-07-01 22:32 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-07-01 22:32 . 2009-07-01 22:32 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-07-01 22:32 . 2009-07-01 22:32 -------- d-----w- c:\program files\Common Files\Real
2009-07-01 22:32 . 2009-07-01 22:32 -------- d-----w- c:\program files\Real
2009-07-01 21:04 . 2009-07-01 21:04 -------- d-----w- c:\documents and settings\salahm\Local Settings\Application Data\Identities
2009-07-01 19:50 . 2009-07-01 19:50 -------- d-----w- c:\windows\Sun
2009-06-30 20:51 . 2009-06-30 20:51 0 ----a-w- c:\windows\nsreg.dat
2009-06-30 20:51 . 2009-06-30 20:51 -------- d-----w- c:\documents and settings\salahm\Local Settings\Application Data\Mozilla
2009-06-30 20:41 . 2009-06-30 20:41 -------- d-----w- c:\documents and settings\salahm\Local Settings\Application Data\Yahoo
2009-06-30 20:19 . 2009-06-30 20:19 -------- d-----w- c:\docume~1\salahm\APPLIC~1\Yahoo!
2009-06-30 20:13 . 2009-06-30 20:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-06-30 20:13 . 2009-05-27 02:50 607472 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-06-30 20:13 . 2009-07-01 02:47 -------- d-----w- c:\program files\Yahoo!
2009-06-30 04:43 . 2008-04-14 12:00 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-06-30 04:42 . 2008-04-14 12:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-06-30 04:42 . 2009-06-30 04:42 -------- d-----w- c:\program files\Windows Media Connect 2
2009-06-30 04:40 . 2009-06-30 04:41 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-06-30 04:40 . 2009-06-30 04:40 -------- d-----w- c:\windows\system32\LogFiles
2009-06-30 04:40 . 2006-09-26 00:58 23856 ----a-w- c:\windows\system32\spupdsvc.exe
2009-06-30 04:38 . 2009-06-30 04:38 -------- d-----w- c:\program files\CCleaner
2009-06-30 04:35 . 2009-06-30 04:35 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-30 04:35 . 2009-06-30 04:35 -------- d-----w- c:\program files\Java
2009-06-30 04:34 . 2009-06-30 04:34 -------- d-----w- c:\documents and settings\salahm\Local Settings\Application Data\Adobe
2009-06-30 04:32 . 2009-06-30 04:33 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-30 04:30 . 2009-07-01 21:58 -------- d-----w- c:\docume~1\salahm\APPLIC~1\IDM
2009-06-30 04:30 . 2009-07-02 21:35 -------- d-----w- c:\docume~1\salahm\APPLIC~1\DMCache
2009-06-30 04:30 . 2009-06-30 04:30 -------- d-----w- c:\program files\Internet Download Manager
2009-06-30 04:30 . 2008-09-29 05:00 439440 ----a-w- c:\program files\un_Internet Download Manager_16575.exe
2009-06-29 23:01 . 2009-06-29 23:01 -------- d-s---w- c:\documents and settings\salahm\UserData

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-02 20:30 . 2009-07-02 07:22 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-02 07:22 . 2009-07-02 07:22 -------- d-----w- c:\program files\Symantec
2009-07-02 07:22 . 2009-07-02 07:22 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-07-02 07:22 . 2009-07-02 07:22 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-07-02 07:22 . 2009-07-02 07:22 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-07-02 07:22 . 2009-07-02 07:22 10635 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-07-02 07:22 . 2009-07-02 07:22 35888 ----a-r- c:\windows\system32\drivers\SymIM.sys
2009-07-02 07:22 . 2009-07-02 07:22 1294680 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-07-02 07:22 . 2009-07-02 07:22 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-05-08 2807216]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-30 148888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-07-01 198160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-6-29 352256]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1000000.07D\SymEFA.sys [7/2/2009 12:22 AM 309296]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1000000.07D\BHDrvx86.sys [7/2/2009 12:22 AM 254512]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1000000.07D\ccHPx86.sys [7/2/2009 12:22 AM 362544]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys [7/2/2009 1:02 AM 276344]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe [7/2/2009 12:22 AM 115560]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [6/29/2009 3:46 PM 377920]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - EECTRL
*NewlyCreated* - ERASERUTILDRV10910
*Deregistered* - EraserUtilDrv10910
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Cmaudio - cmicnfg.cpl


.
------- Supplementary Scan -------
.
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
TCP: {38A9E153-8CC2-49CF-93EB-286BD737C4F8} = 192.168.1.1
FF - ProfilePath - c:\docume~1\salahm\APPLIC~1\Mozilla\Firefox\Profiles\53a6rqn7.default\
FF - component: c:\documents and settings\salahm\Application Data\IDM\idmmzcc3\components\idmmzcc.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Rootkit scan 2009-07-02 14:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(892)
c:\windows\system32\antiwpa.dll

- - - - - - - > 'explorer.exe'(2344)
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-02 14:41
ComboFix-quarantined-files.txt 2009-07-02 21:41

Pre-Run: 49,191,968,768 bytes free
Post-Run: 49,187,889,152 bytes free

201
 
توقيع : صلوين
ادا لم تظهر الصور هدا رابط تحميل الصور من جهازي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
 
توقيع : صلوين
كنت منصب الكاسبر انترنت سيكورتي 2009 تظهر معاي المشكلة ثم كاسبر 2010 تضهر كدلك المشكلة وبعد دلك نورتون انترنت سكورتي 2009 ومازالت المشكلة باقية
 
توقيع : صلوين
اخوي اظن مشكلتك من برنامج الحماية

شوف كم يستهلك من الرام 256 MB of RAM والرامات عندك 512 يعني نص الرام يستهلكه
شوف الافاست وعربي انصحك به جرب لعل ان يخف من ثقل الجهاز
 
مشكور أخي الجهاز سريع مثل البرق و خفيف مع النورتون 2009 لان النسخة خفيفة وقوية للهاكر

مشكور على تعبك
 
توقيع : صلوين
عودة
أعلى