عبدالله1

زيزوومي جديد
إنضم
28 يوليو 2008
المشاركات
24
مستوى التفاعل
0
النقاط
20
غير متصل
السلام عليكم ورحمة الله

ما ادري اذا العنوان يكفي لوصف الوضع او لاء :p:

بس من فتره طويله اشوف الانتي فايروس يمـر عليها بدون ما يتصرف معها :no:

اليوم طفح الكيـل عندي وحملت انتي مالوار وتروجان ريموفر وحذفت انتي سباي وار :q:

حذفـوا اللي قدروا عليه لكـن فيه تروجنات وباك دور لسا مستعصيه

والظاهر فيه بلاوي ثانيه مستخبيه :f:


المهم الجهاز حاس فيه بطء وثقل بس مدري السبب هل من الملفات الضاره ذي

او من كثرة البرامج عالجهاز:i:

لانه في الحمايه حاليا بس عندي الافيرا برميوم سكيورتي سايت ونورتن انتي فايروس

وبرنامج انتي مالوار الاحمر ابو حرف M :d: :q:

وهذا تقرير الهاي جاك :hh:


كود:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:21:18 ص, on 12/07/09
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\LG Software\LG Magnifier\MagnifyingGlass.exe
C:\Program Files\LG Software\On Screen Display\HotKey.exe
C:\Program Files\LG Software\BatteryMiser\BatteryMiser5.exe
C:\Program Files\lg_swupdate\GiljabiStart.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\LG Software\LG Magnifier\Maglev.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LG Magnifier] %ProgramFiles%\LG Software\LG Magnifier\MagnifyingGlass.exe
O4 - HKLM\..\Run: [KeybdUtility] C:\Program Files\LG Software\On Screen Display\HotKey.exe
O4 - HKLM\..\Run: [BatteryMiser 5] C:\Program Files\LG Software\BatteryMiser\BatteryMiser5.exe
O4 - HKLM\..\Run: [LG Intelligent Update] "C:\Program Files\lg_swupdate\giljabistart.exe" Gilautouc
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Inside Program] "C:\ProgramData\link wma wma.0e154"
O4 - HKCU\..\Run: [Loaris Trojan Remover] "C:\Program Files\Loaris Trojan Remover\TrojanRemover.exe" 0
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: []  (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: []  (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: []  (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: []  (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix: 
O15 - Trusted Zone: [URL]http://quickscan.bitdefender.com[/URL]
O15 - Trusted IP range: [URL]http://66.228.123.202[/URL]
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Avira Firewall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
--
End of file - 6558 bytes


طولتها وهي قصيـره لكن هدفي اشرح المشكله :d:
طمنونـا يا جماعه :b:
 

و عليكم السلام و رحمة الله ...

لا هنت التقرير بدون أي أكواد أو أقتباسات ...

:d:
 
توقيع : MMA_LORD_735
عــذراً :)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:21:18 ص, on 12/07/09
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\LG Software\LG Magnifier\MagnifyingGlass.exe
C:\Program Files\LG Software\On Screen Display\HotKey.exe
C:\Program Files\LG Software\BatteryMiser\BatteryMiser5.exe
C:\Program Files\lg_swupdate\GiljabiStart.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\LG Software\LG Magnifier\Maglev.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LG Magnifier] %ProgramFiles%\LG Software\LG Magnifier\MagnifyingGlass.exe
O4 - HKLM\..\Run: [KeybdUtility] C:\Program Files\LG Software\On Screen Display\HotKey.exe
O4 - HKLM\..\Run: [BatteryMiser 5] C:\Program Files\LG Software\BatteryMiser\BatteryMiser5.exe
O4 - HKLM\..\Run: [LG Intelligent Update] "C:\Program Files\lg_swupdate\giljabistart.exe" Gilautouc
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Inside Program] "C:\ProgramData\link wma wma.0e154"
O4 - HKCU\..\Run: [Loaris Trojan Remover] "C:\Program Files\Loaris Trojan Remover\TrojanRemover.exe" 0
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O15 - Trusted IP range:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Avira Firewall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
--
End of file - 6558 bytes
 
بانتظار الحـل :)
 
وبرنامج انتي مالوار الاحمر ابو حرف M

:hh:

لاهنت اخوي

دامك واثق انه جهازك فيه اشياء طيبه وحلوه :d: اعمل التالي قبل تحليل تقرير الهايجاك ليتم تنظيف الجهاز ومن ثم تعمل تقرير هايجاك بعد عمليه الفحص والتنظيف

عطل استعادة النظام حسب الشرح التالي

i7549_1.png


i7550_2.png


i7551_3.png


ادخل هذه الصفحة

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


وحمل اداة المكافي
شغلها بدبل كلك واتركها حتى تنتهي صفحة الدوس من الفحص والتنظيف
ثم توجه الى القرص c ،، وقم
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
التقرير noor_mcafee
وارفعه على هذا الموقع

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


وارفق رابط التحميل بمشاركتك القادمة
----------------------------


بعد رفق رابط التقرير اعد تشغيل الجهاز وعطني تقرير هايجاك جديد​
 
توقيع : AbOdy
أهلا أخِ abody ،

في عـآئق بسيط :q: ومدري وش يبي :b:

عند الغاء استعادة النظام ..

علامة الصح سويت كلك عليها بس ما تروح :p:

مدري اذا يحتاج صـوره :)


i22483_Untitled.jpg
 
طيب اترك استعاده النظام

اعمل فحص بالأداة وعطني التقرير
 
توقيع : AbOdy
هلا فيك عبدالله

وانا مفكر رح تطلع بلاوي

الجهاز سليم وانا اخوك ونظيف من الفيروسات

عطني تقرير هايجاك هنا جديد
 
توقيع : AbOdy
والله !! :d::king:

حتـى باك دورز مـآ فيه ؟

طيب ليـش الجـهاز أحيانا يصيـر بطيء
مثـلا أمس وأنا اغلق الجهـاز
طـول شوي وهـو يسـوي shutting down

،،


الهايجاك :hh:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:55:29 م, on 13/07/09
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\LG Software\LG Magnifier\MagnifyingGlass.exe
C:\Program Files\LG Software\On Screen Display\HotKey.exe
C:\Program Files\LG Software\BatteryMiser\BatteryMiser5.exe
C:\Program Files\lg_swupdate\GiljabiStart.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\LG Software\LG Magnifier\Maglev.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LG Magnifier] %ProgramFiles%\LG Software\LG Magnifier\MagnifyingGlass.exe
O4 - HKLM\..\Run: [KeybdUtility] C:\Program Files\LG Software\On Screen Display\HotKey.exe
O4 - HKLM\..\Run: [BatteryMiser 5] C:\Program Files\LG Software\BatteryMiser\BatteryMiser5.exe
O4 - HKLM\..\Run: [LG Intelligent Update] "C:\Program Files\lg_swupdate\giljabistart.exe" Gilautouc
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Inside Program] "C:\ProgramData\link wma wma.0e154"
O4 - HKCU\..\Run: [Loaris Trojan Remover] "C:\Program Files\Loaris Trojan Remover\TrojanRemover.exe" 0
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O15 - Trusted IP range:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Avira Firewall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
--
End of file - 6458 bytes


وجـــزآك الله خيـر abody ، الله يعطيـك العآفيه ويـوفقك ، :ok:

،، :i:
 
اعمل التالي

عطل برامج الحماية عن العمل
ثم
حمل الاداة التالية واحفظها على سطح المكتب
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
اثناء الفحص ممكن يعاد تشغيل الجهاز
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
لا تقم بتشغيل اي برنامج ،، ومهما طالت عملية الفحص انتظر حتى تنتهي
انتظر حتى يظهر لك تقرير ،،انسخه والصقه بمشاركتك القادمة

وبعدها عطني تقرير هايجاك جديد مع تقرير هذه الأداة
 
توقيع : AbOdy
هذا تقرير الاداة : :q:

سويت ريستارت للجهاز بعد انتهاء الفحص ..

ComboFix 09-07-12.03 - reem 07/13/2009 17:39.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1256.966.1033.18.1013.395 [GMT 3:00]
Running from: c:\users\reem\Desktop\ComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
SP: Norton AntiVirus *disabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
SP: Spyware Doctor *disabled* (Updated) {1C3EDD79-273E-46ac-99F8-EFA9E7CBC301}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2365545147-1999384947-2466353664-500
c:\$recycle.bin\S-1-5-21-33160004-3525513894-2012110408-500
c:\$recycle.bin\S-1-5-21-713789968-1229396252-3980441672-500
.
((((((((((((((((((((((((( Files Created from 2009-06-13 to 2009-07-13 )))))))))))))))))))))))))))))))
.
2009-07-11 20:30 . 2009-07-11 20:30 -------- d-----w- c:\program files\Trend Micro
2009-07-11 20:24 . 2009-07-11 20:24 -------- d-----w- c:\users\reem\AppData\Local\Runscanner.net
2009-07-11 19:07 . 2009-07-11 20:57 -------- d-----w- c:\program files\Loaris Trojan Remover
2009-07-11 18:34 . 2009-07-11 18:34 7680 ----a-w- c:\users\reem\AppData\Roaming\Thinstall\Loaris Trojan Remover 1.1\1000000800002i\svchost.exe
2009-07-11 18:29 . 2009-07-11 18:29 7680 ----a-w- c:\users\reem\AppData\Roaming\Thinstall\Loaris Trojan Remover 1.1\4000008000002i\Splash Screen.exe
2009-07-11 18:28 . 2009-07-11 18:28 -------- d-----w- c:\users\reem\AppData\Local\Thinstall
2009-07-11 14:20 . 2009-07-11 14:20 -------- d-----w- c:\users\reem\AppData\Roaming\Malwarebytes
2009-07-11 14:19 . 2009-06-17 08:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-11 14:19 . 2009-07-11 14:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-11 14:19 . 2009-07-11 14:19 -------- d-----w- c:\programdata\Malwarebytes
2009-07-11 14:19 . 2009-06-17 08:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-11 12:48 . 2009-07-11 12:48 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-07-11 12:20 . 2009-07-11 12:20 -------- d-----w- c:\program files\CCleaner
2009-07-10 20:02 . 2009-03-17 23:02 439672 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\scxpx86.dll
2009-07-10 20:02 . 2009-03-17 23:02 251768 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\symidsco.sys
2009-07-10 20:02 . 2009-03-17 23:02 173432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\SymIDSI.dll
2009-07-10 20:02 . 2009-03-17 23:02 685432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\idsxpx86.dll
2009-07-10 20:02 . 2009-03-17 23:02 370224 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSvia64.sys
2009-07-10 20:02 . 2009-03-17 23:02 272432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSvix86.sys
2009-07-10 20:02 . 2009-03-17 23:02 157120 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\ids9xx86.dll
2009-07-10 19:45 . 2009-07-10 19:45 -------- d-----w- c:\users\reem\AppData\Roaming\Avira
2009-07-10 19:22 . 2009-03-30 07:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-07-10 19:22 . 2009-03-24 13:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-07-10 19:22 . 2009-05-08 11:13 97608 ----a-w- c:\windows\system32\drivers\avfwot.sys
2009-07-10 19:22 . 2009-02-24 10:06 69632 ----a-w- c:\windows\system32\drivers\avfwim.sys
2009-07-10 19:22 . 2009-07-10 19:23 -------- d-----w- c:\programdata\Avira
2009-07-10 19:22 . 2009-07-10 19:22 -------- d-----w- c:\program files\Avira
2009-07-10 15:04 . 2009-07-10 21:34 -------- d-----w- c:\programdata\About shim skip
2009-07-10 13:58 . 2009-07-10 13:58 -------- d-----w- c:\programdata\FLEXnet
2009-07-10 06:27 . 2009-03-17 23:02 685432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\idsxpx86.dll
2009-07-10 06:27 . 2009-03-17 23:02 439672 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\scxpx86.dll
2009-07-10 06:27 . 2009-03-17 23:02 370224 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDSvia64.sys
2009-07-10 06:27 . 2009-03-17 23:02 272432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDSvix86.sys
2009-07-10 06:27 . 2009-03-17 23:02 251768 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\symidsco.sys
2009-07-10 06:27 . 2009-03-17 23:02 173432 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\SymIDSI.dll
2009-07-10 06:27 . 2009-03-17 23:02 157120 ----a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\ids9xx86.dll
2009-07-07 05:10 . 2079-07-19 15:25 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090706.032\NAVENG.SYS
2009-07-07 05:10 . 2079-07-19 15:25 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090706.032\NAVEX15.SYS
2009-07-07 05:10 . 2079-07-19 15:25 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090706.032\EECTRL.SYS
2009-07-07 05:10 . 2079-07-19 15:25 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090706.032\ECMSVR32.DLL
2009-07-07 05:10 . 2079-07-19 15:25 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090706.032\CCERASER.DLL
2009-07-07 05:10 . 2079-07-19 15:25 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090706.032\NAVENG32.DLL
2009-07-07 05:10 . 2079-07-19 15:25 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090706.032\NAVEX32A.DLL
2009-07-07 05:10 . 2079-07-19 15:25 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090706.032\ERASER.SYS
2009-07-06 07:48 . 2009-07-06 07:48 390664 ----a-w- c:\users\reem\AppData\Roaming\Real\RealPlayer\Update\realplayer11gold.exe
2009-07-06 07:48 . 2009-07-06 07:48 390664 ------w- c:\users\reem\AppData\Roaming\Real\Update\temp\~Upg2\realplayer11gold.exe
2009-07-01 07:38 . 2009-07-01 07:39 -------- d-----w- c:\windows\system32\Adobe
2009-07-01 01:41 . 2079-07-19 15:25 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090630.032\NAVENG.SYS
2009-07-01 01:41 . 2079-07-19 15:25 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090630.032\NAVEX15.SYS
2009-07-01 01:41 . 2079-07-19 15:25 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090630.032\EECTRL.SYS
2009-07-01 01:41 . 2079-07-19 15:25 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090630.032\ECMSVR32.DLL
2009-07-01 01:41 . 2079-07-19 15:25 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090630.032\CCERASER.DLL
2009-07-01 01:41 . 2079-07-19 15:25 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090630.032\NAVENG32.DLL
2009-07-01 01:41 . 2079-07-19 15:25 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090630.032\NAVEX32A.DLL
2009-07-01 01:41 . 2079-07-19 15:25 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090630.032\ERASER.SYS
2009-06-28 07:28 . 2009-06-28 07:28 390664 ------w- c:\users\reem\AppData\Roaming\Real\Update\temp\~Upg1\realplayer11gold.exe
2009-06-25 05:12 . 2009-06-25 05:12 -------- d-----w- c:\users\reem\AppData\Local\Google
2009-06-24 22:22 . 2009-06-24 22:22 -------- d-----w- c:\windows\The Ring 1_800 dir
2009-06-24 22:21 . 2009-06-24 22:22 12288 ----a-w- c:\windows\impborl.dll
2009-06-24 19:50 . 2009-07-11 18:28 -------- d-----w- c:\users\reem\AppData\Roaming\Thinstall
2009-06-24 04:35 . 2009-06-24 04:35 -------- d-----w- c:\program files\MSXML 4.0
2009-06-24 00:34 . 2009-06-24 00:34 -------- d-----w- c:\users\reem\AppData\Roaming\Samsung
2009-06-23 22:44 . 2007-07-03 13:58 106792 ----a-w- c:\windows\system32\drivers\sscdmdm.sys
2009-06-23 22:44 . 2007-07-03 14:00 9256 ----a-w- c:\windows\system32\drivers\sscdwhnt.sys
2009-06-23 22:44 . 2007-07-03 14:00 9256 ----a-w- c:\windows\system32\drivers\sscdwh.sys
2009-06-23 22:44 . 2007-07-03 13:57 11944 ----a-w- c:\windows\system32\drivers\sscdmdfl.sys
2009-06-23 22:44 . 2007-07-03 13:56 9256 ----a-w- c:\windows\system32\drivers\sscdcmnt.sys
2009-06-23 22:44 . 2007-07-03 13:56 9256 ----a-w- c:\windows\system32\drivers\sscdcm.sys
2009-06-23 22:44 . 2007-07-03 13:54 80552 ----a-w- c:\windows\system32\drivers\sscdbus.sys
2009-06-23 22:38 . 2009-06-23 22:47 -------- d-----w- c:\windows\system32\Samsung_USB_Drivers
2009-06-23 22:37 . 2009-06-24 00:30 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2009-06-23 22:36 . 2009-06-23 22:36 -------- d-----w- c:\program files\Samsung
2009-06-20 06:49 . 2009-06-20 06:49 390664 ------w- c:\users\reem\AppData\Roaming\Real\Update\temp\~Upg0\realplayer11gold.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2079-07-19 15:25 . 2009-04-01 16:10 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\NAVENG.SYS
2079-07-19 15:25 . 2009-04-01 16:10 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\NAVEX15.SYS
2079-07-19 15:25 . 2009-04-01 16:10 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\NAVENG32.DLL
2079-07-19 15:25 . 2009-04-01 16:10 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\NAVEX32A.DLL
2079-07-19 15:25 . 2009-04-01 16:10 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\EECTRL.SYS
2079-07-19 15:25 . 2009-04-01 16:10 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ECMSVR32.DLL
2079-07-19 15:25 . 2009-04-01 16:10 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\CCERASER.DLL
2079-07-19 15:25 . 2009-04-01 16:10 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ERASER.SYS
2009-07-13 12:51 . 2007-03-24 00:39 12 ----a-w- c:\windows\bthservsdp.dat
2009-07-11 16:13 . 2009-02-01 20:40 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-07-11 16:12 . 2009-03-13 13:58 117760 ----a-w- c:\users\reem\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-11 13:20 . 2009-05-06 15:40 -------- d-----w- c:\users\reem\AppData\Roaming\uTorrent
2009-07-10 21:34 . 2009-02-12 14:26 -------- d-----w- c:\program files\Crcle Developement
2009-07-10 19:38 . 2008-12-30 11:09 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-10 17:15 . 2008-04-27 11:32 78440 ----a-w- c:\users\reem\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-10 15:03 . 2009-02-12 12:35 -------- d-----w- c:\program files\Messenger Plus! Live
2009-07-01 03:51 . 2008-12-03 13:48 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-01 03:50 . 2008-10-11 09:38 -------- d-----w- c:\program files\Java
2009-06-28 06:10 . 2007-03-24 02:40 -------- d-----w- c:\program files\lg_swupdate
2009-06-23 22:59 . 2007-03-24 00:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-09 10:32 . 2009-06-09 10:33 203776 ----a-w- c:\windows\system32\clrviddc.dll
2009-06-02 21:47 . 2009-06-02 21:47 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-05-30 16:00 . 2009-05-30 15:52 172032 ------w- c:\windows\Setup1.exe
2009-05-30 16:00 . 2009-05-30 15:52 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-05-30 15:17 . 2009-05-30 15:10 -------- d-----w- c:\users\reem\AppData\Roaming\Ectaco
2009-05-29 12:03 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-05-29 12:03 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-29 12:03 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-05-29 12:03 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2009-05-29 12:03 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2009-05-29 12:03 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-05-29 12:02 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-05-28 00:35 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2009-05-28 00:35 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2009-05-25 14:19 . 2009-05-25 14:19 -------- d-----w- c:\users\reem\AppData\Roaming\GeoVid
2009-05-11 23:58 . 2009-05-11 23:58 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-05-11 22:28 . 2009-05-11 22:28 390664 ----a-w- c:\users\reem\AppData\Roaming\Real\RealPlayer\setup\AU_setup6.exe
2009-05-09 05:50 . 2009-06-10 02:35 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-10 02:35 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-04-28 08:58 . 2007-03-24 02:40 42288 ----a-w- c:\windows\system32\giljabiunis.exe
2009-04-28 08:56 . 2007-03-24 02:40 1140016 ----a-w- c:\windows\system32\CS.dll
2009-04-23 12:15 . 2009-06-10 02:35 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:14 . 2009-06-10 02:35 623616 ----a-w- c:\windows\system32\localspl.dll
2009-04-21 11:39 . 2009-06-10 02:36 2034688 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Inside Program"="c:\programdata\link wma wma.0e154" [X]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-02-12 174872]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-10 845360]
"LG Magnifier"="c:\program files\LG Software\LG Magnifier\MagnifyingGlass.exe" [2007-03-03 112184]
"KeybdUtility"="c:\program files\LG Software\On Screen Display\HotKey.exe" [2007-03-22 2655800]
"BatteryMiser 5"="c:\program files\LG Software\BatteryMiser\BatteryMiser5.exe" [2007-02-22 337464]
"LG Intelligent Update"="c:\program files\lg_swupdate\giljabistart.exe" [2009-04-28 251184]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-11 198160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-01 148888]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-03-14 4399104]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2007-03-14 1822720]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{26F5978F-6493-4ee3-B114-C0C3ACCF9D4D}"= "c:\windows\system32\bmpsap.dll" [2006-12-11 114688]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):f4,27,db,78,56,e0,c9,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-33160004-3525513894-2012110408-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{78240C1A-9431-4EDA-A970-2834566F61BB}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{20C47794-84CE-4710-B8AE-3EFA2FAB1F35}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{C62EA2CF-1782-442C-98FB-8CBA86DB8203}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{00FAF890-2112-4791-8EFE-8BF4585EF86C}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{DE63D698-689B-4BAB-8346-101ABCF88AEB}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{6E18A21C-D099-48B0-8EF0-E5789033EF13}"= UDP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{2802E999-8D0B-4E30-BA7D-E3EE8039B01A}"= TCP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{FB9504BF-E55E-46EE-A256-F257CBB26ABB}"= TCP:16999:utorrent
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 avfwot;avfwot;c:\windows\System32\drivers\avfwot.sys [7/10/2009 10:22 م 97608]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090709.001\IDSvix86.sys [7/10/2009 11:02 م 272432]
R2 AntiVirFirewallService;Avira Firewall;c:\program files\Avira\AntiVir Desktop\avfwsvc.exe [7/10/2009 10:22 م 388865]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [7/10/2009 10:22 م 194817]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [7/10/2009 10:22 م 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [7/10/2009 10:22 م 434945]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [3/5/2009 09:23 م 149352]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [3/30/2009 04:28 م 1533808]
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\System32\drivers\avfwim.sys [7/10/2009 10:22 م 69632]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [4/23/2009 03:31 م 101936]
R3 EUCR;USB Mass Storage;c:\windows\System32\drivers\EUCR6SK.sys [3/19/2007 11:10 م 40064]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [11/17/2008 03:40 م 3668480]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2/19/2009 11:31 ص 41008]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [5/29/2007 11:55 م 23888]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-29 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - reem.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-27 01:19]
2009-07-13 c:\windows\Tasks\User_Feed_Synchronization-{293BB019-3888-4059-A1A7-87808926EB8A}.job
- c:\windows\system32\msfeedssync.exe [2009-05-27 11:31]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{072EA664-15C7-4F40-8DDE-284C99025ADE} - (no file)

.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
Trusted Zone: bitdefender.com\quickscan
Trusted Zone: microsoft.com\
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Rootkit scan 2009-07-13 17:46
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(5280)
c:\program files\LG Software\BatteryMiser\McIdle.dll
.
Completion time: 2009-07-13 17:50
ComboFix-quarantined-files.txt 2009-07-13 14:50
Pre-Run: 134,783,041,536 bytes free
Post-Run: 134,374,359,040 bytes free
276 --- E O F --- 2009-06-28 06:08


بسوي فحص الهايجاك الحين وبحطه بالرد الجاي ان شاء الله :d:



،،
 
وهذا الهايجاك

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:08:35 م, on 7/13/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\LG Software\LG Magnifier\MagnifyingGlass.exe
C:\Program Files\LG Software\On Screen Display\HotKey.exe
C:\Program Files\LG Software\BatteryMiser\BatteryMiser5.exe
C:\Program Files\lg_swupdate\GiljabiStart.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\LG Software\LG Magnifier\Maglev.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LG Magnifier] %ProgramFiles%\LG Software\LG Magnifier\MagnifyingGlass.exe
O4 - HKLM\..\Run: [KeybdUtility] C:\Program Files\LG Software\On Screen Display\HotKey.exe
O4 - HKLM\..\Run: [BatteryMiser 5] C:\Program Files\LG Software\BatteryMiser\BatteryMiser5.exe
O4 - HKLM\..\Run: [LG Intelligent Update] "C:\Program Files\lg_swupdate\giljabistart.exe" Gilautouc
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Inside Program] "C:\ProgramData\link wma wma.0e154"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O15 - Trusted IP range:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Avira Firewall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
--
End of file - 5684 bytes



،،

الحين اذا خلاص تاكدت ان الجهاز مافيه مشآكل
أحـذف الهايجاك والكمبو ولا اخليهم

وحاقـه أخـرى ..
اذا الجهـاز سليــم .. اتطمن خـلآص ان قـدرآت برامج الحمـآيه في جهـآزي اوكيه ؟


،،
 
احذف هذه القيم

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O13 - Gopher Prefix:

O15 - Trusted Zone:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


O15 - Trusted IP range:
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي



طريقه الحذف

i16155_5aznhec3b746572.png



mg%20(3).png


mg%20(4).png



ثم اعمل التالي


حمل هذه الأداة

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


او

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي



شغلها بدبل كلك

i20932_1.png


i20933_2.png


i20934_3.png


i20935_4.png


ثم اعد تشغيل الجهاز

وبعدا وضع جهازك تمام

موفق​

 
توقيع : AbOdy
بارك الله فيك اخ عبودي علي جهودك الطيبة وعملك السليم
 
بالاضافه لكلاام اخوان الاعزاء

عندك برامج حمايه اخرة .. وتعتبر سبب رئيسي للبطئ الحاصل بجهازك

الافضل تحذفها
برنامج / Trojan Remover
وبرنامج / النورتون سيمنتيك ... باستخدام هذه الاداة
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
 
بالاضافه لكلاام اخوان الاعزاء

عندك برامج حمايه اخرة .. وتعتبر سبب رئيسي للبطئ الحاصل بجهازك

الافضل تحذفها
برنامج / Trojan Remover
وبرنامج / النورتون سيمنتيك ... باستخدام هذه الاداة
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


بارك الله فيك يا بعدي على الملاحظه

ترى على فكرة موقع الهايجاك مايفتح عندنا حللت تقريره من رده على طول

عشان كذا مانتبهت لبرامج الحمايه الأخرى الي عنده

كان عندك بروكسي حق سعودي نت عطني ياه :bleh:
 
توقيع : AbOdy
توقيع : AbOdy
بارك الله فيكـم abody و زيزوم ، مـاقصرتـم والله

النورتن حـذفتـه :)

برنآمج تروجـآن ريموفر كنت فعلآ منزلـه عالجهـاز

لكـن الحيـن مو مـوجود عنـدي في اضافة وازالة البرامج ولا في قائمة برامج ابدأ

فمـدري كيف احذفـه :) أصلا الظآهـر أظـن حذفته قبل كم يوم بالطريقه اللي تحت ذي ..

وبالمنآسبه ودي اسأل بعض البرامج لمآ انزلها عالجهآز ما القاها في اضافة وازالة البرامج

فلما ابي احذفها اسويلها كلك وديليت لسلة المحذوفات واحذف الملف المضغوط حق البرنامج وبس

فهـل طريقتي ذي صح؟ ولا فيه غيرهـآ ؟




،،
 
لـلـرفـع :smile: ،،
 
عودة
أعلى