• بادئ الموضوع بادئ الموضوع aser25
  • تاريخ البدء تاريخ البدء
  • المشاهدات 669

aser25

زيزوومى مميز
إنضم
26 أغسطس 2008
المشاركات
736
مستوى التفاعل
9
النقاط
520
الإقامة
البجادية
الموقع الالكتروني
www.l-masat.com
غير متصل

بسم الله الرحمن الرحيم

الاعضاء الكرام

مساكم الله بالخير والرضا

عندي مشكلة بسيطة وان شاء الله القى حل عندكم

مشكلتي ليا فتحت مجلد الصووور تجيني رسالة ( ارسال وعدم ارسال ) وليا ضغطت اي من الخيارات يطلع من المجلد مباشرة كما في الصورة التالية

97210487.jpg



كيف اتخلص من هذه الرسالة لانني الحي لا استطيع الدخول الى مجلد الصووور

في انتظار حلوولكم ح ــــبآيبي​
 

توقيع : aser25
اعمل تقرير للهايجاك
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

اذا انتهى التحميل ==> شغل البرنامج ==> واضغط على Do a system scan and save log
لحظات .. ويظهر لك تقرير اعمل تحديد الكل ==> انسخه والصقه بردك القادم​
 
هذا تقرير للهايجاك

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:54:51 م, on 26/07/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Avira\AntiVir Desktop\sched.exe
D:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
D:\Program Files\Avira\AntiVir Desktop\avguard.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\WINDOWS\system32\rundll32.exe
D:\Program Files\Analog Devices\Core\smax4pnp.exe
D:\WINDOWS\system32\hkcmd.exe
D:\WINDOWS\system32\igfxpers.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\SuperCopier2\SuperCopier2.exe
D:\Program Files\Windows Live\Messenger\msnmsgr.exe
D:\Program Files\Avira\AntiVir Desktop\avmailc.exe
D:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
D:\WINDOWS\System32\alg.exe
D:\Program Files\Windows Live\Contacts\wlcomm.exe
D:\WINDOWS\system32\drwtsn32.exe
D:\WINDOWS\system32\drwtsn32.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\drwtsn32.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\ImageShack Corp\ImageShack Uploader\ImageShackUploader.exe
D:\Documents and Settings\aser_511\سطح المكتب\Samy Soft Forum Images 1.0.exe
D:\WINDOWS\system32\drwtsn32.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\system32\drwtsn32.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\aser_511\سطح المكتب\HiJackThis.exe
D:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SoundMAXPnP] D:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [igfxtray] D:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] D:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] D:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [googletalk] D:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SuperCopier2.exe] D:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: ت&صدير إلى Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O23 - Service: Avira Firewall (AntiVirFirewallService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
--
End of file - 5809 bytes
 
توقيع : aser25


عطل جميع برامج الحماية ,,
وحمل هذه الاداة واحفظها على سطح المكتب
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

عند تشغيلها بتظهر لك رسالة ,, اضغط على >> Yes
بعدها بتظهر لك رساله ثانيه ,, اضغط على >> Yes
انتظر حتى الاداة تنتهي من فحص جهازك ,,, وبشكل تلقائي يعاد تشغيل جهازك ,,
وبعد اعادة التشغيل ,, سوف تبدأ الاداة بالفحص مرره ثانيه
انتظر حتى يظهر لك تقرير ,, انسخه والصقه بردك القادم

 
هذا التقرير

ComboFix 09-07-25.04 - aser_511 07/26/2009 14:47.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.1526.921 [GMT 3:00]
Running from: d:\documents and settings\aser_511\سطح المكتب\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: Avira Firewall *disabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
d:\program files\SuperCopier2\SC2Hook.dll

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
Infected copy of d:\windows\system32\sfcfiles.dll was found and disinfected
Restored copy from - d:\windows\system32\dllcache\sfcfiles.dll
.
((((((((((((((((((((((((( Files Created from 2009-06-26 to 2009-07-26 )))))))))))))))))))))))))))))))
.
2009-07-26 10:47 . 2004-08-04 08:55 221184 ----a-w- d:\windows\system32\wmpns.dll
2009-07-26 09:00 . 2009-07-26 09:00 -------- d-----w- d:\documents and settings\All Users\Application Data\InstallShield
2009-07-26 08:56 . 2009-07-26 08:56 -------- d-----w- d:\program files\Nokia
2009-07-26 08:56 . 2009-07-26 08:56 -------- d-----w- d:\documents and settings\aser_511\Application Data\InstallShield
2009-07-25 15:50 . 2004-08-04 06:32 15872 -c--a-w- d:\windows\system32\dllcache\padrs404.dll
2009-07-25 12:14 . 2009-07-25 12:14 -------- d-----w- d:\documents and settings\aser_511\Local Settings\Application Data\Identities
2009-07-25 11:42 . 2009-07-25 11:42 -------- d-----w- d:\program files\ImageShack Corp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-26 11:52 . 2009-07-25 08:41 -------- d-----w- d:\program files\SuperCopier2
2009-07-26 10:44 . 2009-07-25 09:10 -------- d-----w- d:\documents and settings\aser_511\Application Data\Media Player Classic
2009-07-26 09:44 . 2009-07-25 07:41 86327 ----a-w- d:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-26 08:56 . 2009-07-25 07:59 -------- d--h--w- d:\program files\InstallShield Installation Information
2009-07-26 08:56 . 2009-07-25 07:59 -------- d-----w- d:\program files\Common Files\InstallShield
2009-07-26 07:51 . 2001-09-19 12:00 39982 ----a-w- d:\windows\system32\perfc001.dat
2009-07-26 07:51 . 2001-09-19 12:00 251478 ----a-w- d:\windows\system32\perfh001.dat
2009-07-25 18:06 . 2009-07-25 08:40 43600 ----a-w- d:\documents and settings\aser_511\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-25 10:38 . 2009-07-25 10:38 -------- d-----w- d:\program files\Google
2009-07-25 10:33 . 2009-07-25 10:33 -------- d-----w- d:\documents and settings\All Users\Application Data\Messenger Plus!
2009-07-25 10:31 . 2009-07-25 08:02 -------- d-----w- d:\documents and settings\aser_511\Application Data\DMCache
2009-07-25 10:02 . 2009-07-25 10:02 -------- d-----w- d:\program files\Messenger Plus! Live
2009-07-25 09:51 . 2009-07-25 09:50 -------- d-----w- d:\program files\Common Files\Real
2009-07-25 09:51 . 2009-07-25 09:51 -------- d-----w- d:\program files\Common Files\xing shared
2009-07-25 09:51 . 2009-07-25 08:28 -------- d-----w- d:\program files\Java
2009-07-25 09:50 . 2009-07-25 08:42 348160 ----a-w- d:\windows\system32\msvcr71.dll
2009-07-25 09:50 . 2009-07-25 08:42 499712 ----a-w- d:\windows\system32\msvcp71.dll
2009-07-25 09:50 . 2009-07-25 09:50 -------- d-----w- d:\program files\Real
2009-07-25 09:49 . 2009-07-25 09:49 152576 ----a-w- d:\documents and settings\aser_511\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-25 09:09 . 2009-07-25 09:09 -------- d-----w- d:\program files\Recode Media
2009-07-25 09:09 . 2009-07-25 09:08 -------- d-----w- d:\program files\Windows Live
2009-07-25 09:08 . 2009-07-25 09:08 -------- d-----w- d:\program files\Microsoft
2009-07-25 09:08 . 2009-07-25 09:08 -------- d-----w- d:\program files\Windows Live SkyDrive
2009-07-25 09:07 . 2009-07-25 09:04 -------- d-----w- d:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-25 08:58 . 2009-07-25 08:58 -------- d-----w- d:\documents and settings\aser_511\Application Data\TuneUp Software
2009-07-25 08:43 . 2009-07-25 08:43 -------- d-----w- d:\program files\FreeTime
2009-07-25 08:42 . 2009-07-25 08:42 -------- d-----w- d:\documents and settings\All Users\Application Data\Apple Computer
2009-07-25 08:42 . 2009-07-25 08:42 -------- d-----w- d:\program files\QuickTime Alternative
2009-07-25 08:42 . 2009-07-25 08:42 -------- d-----w- d:\program files\Media Player Classic
2009-07-25 08:42 . 2009-07-25 08:42 -------- d-----w- d:\program files\4shared Uploader
2009-07-25 08:42 . 2009-07-25 08:42 -------- d-----w- d:\documents and settings\aser_511\Application Data\4shared Uploader
2009-07-25 08:40 . 2009-07-25 08:40 -------- d-----w- d:\program files\Common Files\Windows Live
2009-07-25 08:30 . 2009-07-25 08:30 -------- d-----w- d:\program files\Sun
2009-07-25 08:28 . 2009-07-25 08:28 152576 ----a-w- d:\documents and settings\aser_511\Application Data\Sun\Java\jre1.6.0_11\lzma.dll
2009-07-25 08:05 . 2009-07-25 08:05 -------- d-----w- d:\documents and settings\All Users\Application Data\Avira
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SuperCopier2.exe"="d:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
"msnmsgr"="d:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="d:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"igfxtray"="d:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="d:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="d:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"avgnt"="d:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"TkBellExe"="d:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-07-25 198160]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"googletalk"="d:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"BluetoothAuthenticationAgent"="bthprops.cpl" - d:\windows\system32\bthprops.cpl [2004-08-04 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
d:\documents and settings\All Users\çں‍ê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-7-25 113664]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
R1 avfwot;avfwot;d:\windows\system32\drivers\avfwot.sys [25/07/2009 11:05 ص 97608]
R2 AntiVirFirewallService;Avira Firewall;d:\program files\Avira\AntiVir Desktop\avfwsvc.exe [25/07/2009 11:05 ص 388865]
R2 AntiVirMailService;Avira AntiVir MailGuard;d:\program files\Avira\AntiVir Desktop\avmailc.exe [25/07/2009 11:05 ص 194817]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;d:\program files\Avira\AntiVir Desktop\sched.exe [25/07/2009 11:05 ص 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;d:\program files\Avira\AntiVir Desktop\avwebgrd.exe [25/07/2009 11:05 ص 434945]
R3 avfwim;AvFw Packet Filter Miniport;d:\windows\system32\drivers\avfwim.sys [25/07/2009 11:05 ص 69632]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"d:\windows\system32\rundll32.exe" "d:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.internetdownloadmanager.com/welcome.html
IE: ت&صدير إلى Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: d:\program files\Avira\AntiVir Desktop\avsda.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Rootkit scan 2009-07-26 14:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\d:\docume~1\aser_511\LOCALS~1\Temp\mc21.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(1044)
d:\program files\Avira\AntiVir Desktop\avsda.dll
- - - - - - - > 'explorer.exe'(3956)
d:\program files\SuperCopier2\SC2Hook.dll
d:\windows\system32\msi.dll
d:\windows\system32\ieframe.dll
d:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
d:\program files\Avira\AntiVir Desktop\avguard.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\windows\system32\rundll32.exe
d:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-26 14:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-26 11:55
Pre-Run: 21,742,882,816 bytes free
Post-Run: 21,940,973,568 bytes free
145
 
توقيع : aser25
اخي البارون

ما زلت انتظر ردك يا غالي
 
توقيع : aser25
عودة
أعلى