• بادئ الموضوع بادئ الموضوع zouhir-01
  • تاريخ البدء تاريخ البدء
  • المشاهدات 1,090

zouhir-01

زيزوومي جديد
إنضم
23 يناير 2008
المشاركات
8
مستوى التفاعل
0
النقاط
0
الإقامة
maroc
غير متصل
اخواني الكرام :getsmile.tmp0014236 جهازي يعاني من الفيرس العنيد الاوتورن و اعوانة من البرامج الخبيثة الاخري... :cr: وخاصة الفيروس log.exe :getsmile.tmp0015325

:kmj-by0000 (24): أرجو المساعدة

و شكراً
:getsmile.tmp0018838
 

تم نقل موضوعك للقسم الانسب
 
توقيع : Abu-7arb
الله يحييك اخوي
حمل هذا البرنامج
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

شغل البرنامج ==> واضغط على
Do a system scan and save log
لحظات .. ويظهر لك تقرير داخل المفكرة==> انسخه والصقه بردك القادم
 
التعديل الأخير بواسطة المشرف:
توقيع : AbOdy
hijackthis.log

zouhir-01
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:50:01, on 12/07/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Windows\System32\bycool1\windo.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\VM331_STI.EXE
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe
C:\Program Files\TTMessenger\spool\PDFSaver.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\capep\Bureau\Rapidshare_AD_3.5.1_Rus\RapidshareAutoDownloader.exe
C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\IEUM.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DRIVESYS1] C:\Windows\System32\bycool1\windo.exe
O4 - HKLM\..\Run: [DRIVESYS] C:\Windows\System32\bycool\winacces.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [331BigDog] C:\WINDOWS\VM331_STI.EXE
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [REVAService] C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe
O4 - HKCU\..\Run: [TTMessengerPDF] "C:\Program Files\TTMessenger\spool\PDFSaver.exe"
O4 - HKCU\..\Run: [TTMessenger] "C:\Program Files\TTMessenger\ttmessenger2.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Raccourci vers RapidshareAutoDownloader.exe.lnk = C:\Documents and Settings\capep\Bureau\Rapidshare_AD_3.5.1_Rus\RapidshareAutoDownloader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
O17 - HKLM\System\CCS\Services\Tcpip\..\{326230AE-EFA0-42D8-900F-616E00582E61}: NameServer = 192.168.50.55 196.12.209.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{326230AE-EFA0-42D8-900F-616E00582E61}: NameServer = 192.168.50.55 196.12.209.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{326230AE-EFA0-42D8-900F-616E00582E61}: NameServer = 192.168.50.55 196.12.209.5
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

--
End of file - 7588 bytes​
 
حمل هذا البرنامج

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


ثبته على الجهاز ،، ثم شغله واعمل كما الشرح التالي لفحص الجهاز وعمل تقرير

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


وبعد انتهاء الفحص اعمل التالي

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


انسخ ما بداخل التقرير والصقه بمشاركتك القادمة
 

Malwarebytes' Anti-Malware 1.38
Version de la base de données: 2420
Windows 5.1.2600 Service Pack 2

13/07/2009 16:40:53
mbam-log-2009-07-13 (16-40-47).txt

Type de recherche: Examen rapide
Eléments examinés: 91293
Temps écoulé: 2 minute(s), 34 second(s)

Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 6
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 2

Processus mémoire infecté(s):
C:\WINDOWS\system32\bycool1\windo.exe (Trojan.Autoit) -> No action taken.

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df1c8e21-4045-4d67-b528-335f1a4f0de9} (Adware.Navipromo) -> No action taken.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\drivesys1 (Trojan.Autoit) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\FrameWorkService (Trojan.Delf) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\FrameWorkService (Trojan.Delf) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\3 (Security.Hijack) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\4 (Security.Hijack) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\1 (Security.Hijack) -> No action taken.

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
C:\WINDOWS\system32\bycool1 (Trojan.Autoit) -> No action taken.

Fichier(s) infecté(s):
c:\WINDOWS\system32\bycool1\windo.exe (Trojan.Autoit) -> No action taken.
c:\WINDOWS\system32\bycool1\log.exe (Trojan.Autoit) -> No action taken.

fin
 
اخوي روح للرابط هنا

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


ونزل اداة المكافي وسوي فحص ثم اذهب الى مجلد السي تلاقي التقرير اسمة noor_mcafee

ثم قم بضغط التقرير>>>>
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


ورفعه هنا
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


 
zouhir-01

Virus Scan Report File

Virus Scan Information

McAfee VirusScan for Win32 v5.30.0
Copyright (c) 1992-2008 McAfee, Inc. All rights reserved.
(408) 988-3832 LICENSED COPY - Jun 16 2008

Scan engine v5.3.00 for Win32.
Virus data file v5670 created Jul 08 2009
Scanning for 535295 viruses, trojans and variants.
Virus Scan Results



07/14/2009 19:02:28


Options:
/ADL /WINMEM/CLEAN /APPEND /HTML C:\NOOR_MCAFEE.HTM

Scanning C: []
Scanning C:\*.*
C:\WINDOWS\system32\bycool1\log.exe ... Found the Generic PWS.ap trojan !!!
The file or process has been deleted.
C:\WINDOWS\system32\bycool\compilateur_auto.exe ... Found the Generic PWS.ap trojan !!!
The file or process has been deleted.
C:\System Volume Information\_restore{E66FA36A-63DD-43CC-8761-070FFDD01798}\RP240\A0068435.exe ... Found the Generic.dx!jy trojan !!!
The file or process has been deleted.
C:\System Volume Information\_restore{E66FA36A-63DD-43CC-8761-070FFDD01798}\RP245\A0069852.exe ... Found the Generic PWS.ap trojan !!!
The file or process has been deleted.
C:\System Volume Information\_restore{E66FA36A-63DD-43CC-8761-070FFDD01798}\RP245\A0069853.exe ... Found the Generic PWS.ap trojan !!!
The file or process has been deleted.

Summary report on C:\*.*
File(s)
Total files: ........... 77095
Clean: ................. 77067
Not scanned: ........... 0
Possibly Infected: ..... 5
Cleaned: ............... 0
Deleted: ............... 5
Non-critical Error(s): 1
Master Boot Record(s): ......... 1
Possibly Infected: ..... 0
Boot Sector(s): ................ 1
Possibly Infected: ..... 0
Scanning D: []
Scanning D:\*.*
D:\Disque_Local_C\Bureau\autorun remover\MSNFix\MSNFix\incl\Hostsclean.exe ... Found the Generic.dx!jy trojan !!!
The file or process has been deleted.
D:\Disque_Local_C\Bureau\bureaux\autorun remover\MSNFix\MSNFix\incl\Hostsclean.exe ... Found the Generic.dx!jy trojan !!!
The file or process has been deleted.

Summary report on D:\*.*
File(s)
Total files: ........... 19218
Clean: ................. 19213
Not scanned: ........... 0
Possibly Infected: ..... 2
Cleaned: ............... 0
Deleted: ............... 2
Non-critical Error(s): 1
Master Boot Record(s): ......... 1
Possibly Infected: ..... 0
Boot Sector(s): ................ 1
Possibly Infected: ..... 0


Time: 00:39.21

Fin
 
Malwarebytes' Anti-Malware 1.38
Version de la base de données: 2420
Windows 5.1.2600 Service Pack 2​

13/07/2009 16:40:53
mbam-log-2009-07-13 (16-40-47).txt​

Type de recherche: Examen rapide
Eléments examinés: 91293
Temps écoulé: 2 minute(s), 34 second(s)​

Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 6
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 2​

Processus mémoire infecté(s):
C:\WINDOWS\system32\bycool1\windo.exe (Trojan.Autoit) -> No action taken.​

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)​

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df1c8e21-4045-4d67-b528-335f1a4f0de9} (Adware.Navipromo) -> No action taken.​

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\drivesys1 (Trojan.Autoit) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\FrameWorkService (Trojan.Delf) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\FrameWorkService (Trojan.Delf) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\3 (Security.Hijack) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\4 (Security.Hijack) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun\1 (Security.Hijack) -> No action taken.​

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)​

Dossier(s) infecté(s):
C:\WINDOWS\system32\bycool1 (Trojan.Autoit) -> No action taken.​

Fichier(s) infecté(s):
c:\WINDOWS\system32\bycool1\windo.exe (Trojan.Autoit) -> No action taken.
c:\WINDOWS\system32\bycool1\log.exe (Trojan.Autoit) -> No action taken.​

fin​
اعد الفحص وطبق هذا الشرح للحذف

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
 
zouhir-01

Virus Scan Report File

Virus Scan Information

McAfee VirusScan for Win32 v5.30.0
Copyright (c) 1992-2008 McAfee, Inc. All rights reserved.
(408) 988-3832 LICENSED COPY - Jun 16 2008​

Scan engine v5.3.00 for Win32.
Virus data file v5670 created Jul 08 2009
Scanning for 535295 viruses, trojans and variants.​

Virus Scan Results



07/14/2009 19:02:28​


Options:
/ADL /WINMEM/CLEAN /APPEND /HTML C:\NOOR_MCAFEE.HTM​

Scanning C: []
Scanning C:\*.*
C:\WINDOWS\system32\bycool1\log.exe ... Found the Generic PWS.ap trojan !!!
The file or process has been deleted.
C:\WINDOWS\system32\bycool\compilateur_auto.exe ... Found the Generic PWS.ap trojan !!!
The file or process has been deleted.
C:\System Volume Information\_restore{E66FA36A-63DD-43CC-8761-070FFDD01798}\RP240\A0068435.exe ... Found the Generic.dx!jy trojan !!!
The file or process has been deleted.
C:\System Volume Information\_restore{E66FA36A-63DD-43CC-8761-070FFDD01798}\RP245\A0069852.exe ... Found the Generic PWS.ap trojan !!!
The file or process has been deleted.
C:\System Volume Information\_restore{E66FA36A-63DD-43CC-8761-070FFDD01798}\RP245\A0069853.exe ... Found the Generic PWS.ap trojan !!!
The file or process has been deleted.​

Summary report on C:\*.*
File(s)
Total files: ........... 77095
Clean: ................. 77067
Not scanned: ........... 0
Possibly Infected: ..... 5
Cleaned: ............... 0
Deleted: ............... 5
Non-critical Error(s): 1
Master Boot Record(s): ......... 1
Possibly Infected: ..... 0
Boot Sector(s): ................ 1
Possibly Infected: ..... 0
Scanning D: []
Scanning D:\*.*
D:\Disque_Local_C\Bureau\autorun remover\MSNFix\MSNFix\incl\Hostsclean.exe ... Found the Generic.dx!jy trojan !!!
The file or process has been deleted.
D:\Disque_Local_C\Bureau\bureaux\autorun remover\MSNFix\MSNFix\incl\Hostsclean.exe ... Found the Generic.dx!jy trojan !!!
The file or process has been deleted.​

Summary report on D:\*.*
File(s)
Total files: ........... 19218
Clean: ................. 19213
Not scanned: ........... 0
Possibly Infected: ..... 2
Cleaned: ............... 0
Deleted: ............... 2
Non-critical Error(s): 1
Master Boot Record(s): ......... 1
Possibly Infected: ..... 0
Boot Sector(s): ................ 1
Possibly Infected: ..... 0​


Time: 00:39.21​

Fin​
تم حذف الفيروس log.exe
هل تواجه اي مشاكل اخرى ؟
 
عودة
أعلى