ابغي مساعده ضروري بليز بليز
ش
28-09-2009 | 08:06 PM
السلام عليكم يابنات بليز احد يساعدني الي بتساعدني والله بدعيلها من قلبي بدخل في الموضوع على طول والله انا مااعرف بالكمبيوتر كثير على قدي صار لي فتره ادخل على المفضله في صفحة غوغل او السجل الاقي صفحات والعياذ بالله يرتجف جسمي اشياء ماتطالع للعلم مااحد يستخدم جهازي الا انا هل يستطيع احد يدخل جهازي ويستخدم الشبكه حقت جهازي ويطالع هذي الاشياء الفظيعه من جهازه الشخصي وبعض الاحيان اكون جالسه استخدم الفوتو شوب وتظهر لي رساله تم تعديل هذي الصوره من قبل شخص اخر هل تريد حفظها وساعات الاحظ الكاميره تشتغل لوحدها وتطلعي رساله هل تريد تشغيل الكاميره بسرعه اكبر الحمدلله مغطيه الكاميره بستكر الله يخليكم احد يجاوبني وييساعدني صرت اكره افتح جهازي والسبب المواقع الى تظهر في المفضله والسجل كل ماحذفتها اسفه طولت عليكم بس وربي ويش اسوي واذا احد يقدر يدخل جهازي ويلعب في اعصابي شلون احمي جهازي من المخربين ودمتم في حفظ الله
ر
29-09-2009 | 02:12 AM
اختي يمكن عندج ملف تجسس
ر
29-09-2009 | 02:17 AM
اذا ماقدرتي تمسحين ملف روحي مصلح كمبيوترات يمكن يمسحه لج
ا
29-09-2009 | 02:47 AM
وعليكم السلام ورحمة الله وبركاته
أختي الغالب ان عندك ملف تجسس وفيه واحد يتجسس على جهازك وهذي مشكلة كبيرة ...
عطيني تقرير هاي جاك وراح افيدك ان شاء الله لو كان عندك تجسس أو لا ...
طريقة عمل تقرير هي كالتالي :
نزلي برنامج Hijack من هنا ...
أختي الغالب ان عندك ملف تجسس وفيه واحد يتجسس على جهازك وهذي مشكلة كبيرة ...
عطيني تقرير هاي جاك وراح افيدك ان شاء الله لو كان عندك تجسس أو لا ...
طريقة عمل تقرير هي كالتالي :
نزلي برنامج Hijack من هنا ...
ثم تابعي الصور علشان تعرفين طريقة تشغيلة وعمل تقرير لجهاز ...






ثم اعملي له لصق في ردك الجاي .......
أخوووك الهاوي ................
ش
29-09-2009 | 04:01 AM
مشكور اخوي جدا جدا ان شاء الله احمل البرنامج واطلعكم على النتائج الله يعينا ادعولي بالتوفيق
ش
30-09-2009 | 02:53 AM
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:50:04 ص, on 30/09/09
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Windows\system32\conime.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Windows Sidebar\sidebar.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Dell homepage - Computers, notebook PCs, printers, servers, and more
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\aLmunjez\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: ت&صدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: تدوين هذا في المدونة - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &تدوين هذا في Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 10078 bytes
هلا اخوي ان شاء الله خير بليز لاطول علي بالرد مشكور جدا جدا جدا الله يعطيك العافيه
Scan saved at 02:50:04 ص, on 30/09/09
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Windows\system32\conime.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Windows Sidebar\sidebar.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Dell homepage - Computers, notebook PCs, printers, servers, and more
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\aLmunjez\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: ت&صدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: تدوين هذا في المدونة - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &تدوين هذا في Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 10078 bytes
هلا اخوي ان شاء الله خير بليز لاطول علي بالرد مشكور جدا جدا جدا الله يعطيك العافيه
ا
05-10-2009 | 03:38 AM
السلام عليكم ورحمة الله وبركاته
صباح الخير ...
اسف اختي على التأخير وكويس انك نبهتيني وذكرتيني بالموضوع ...
اختي سبب الصفحات الاباحية والغير مرغوبة والمزعجة هو ملفات سباي وير .. وانتي عندك مكافح مكافي وللاسف مافيه انتي سباي وير وهذي المشكلة ...
طيب الحين ابغاك تعملي لي تقرير بواسطة برنامج Combofix وهذا شرحها ...
أولاً نزلي الآداة هذي من هنا ....
Download -1
أو
Download -2
واحفظيها على سطح المكتب
قبل ماتشغلينها ضروري تعملين تعطيل لأي برنامج حماية عندك والاحظ موجود عندك برنامج Mcafee وطريقة تعطيلة بهذ الشكل :
اضغطي على ايقونة البرنامج هذي

بالزر الايمن واختاري (Exit) ...
الحين شغلي الاداة اللي اسمها ComboFix وهذي ايقونتها
صباح الخير ...
اسف اختي على التأخير وكويس انك نبهتيني وذكرتيني بالموضوع ...
اختي سبب الصفحات الاباحية والغير مرغوبة والمزعجة هو ملفات سباي وير .. وانتي عندك مكافح مكافي وللاسف مافيه انتي سباي وير وهذي المشكلة ...
طيب الحين ابغاك تعملي لي تقرير بواسطة برنامج Combofix وهذا شرحها ...
أولاً نزلي الآداة هذي من هنا ....
Download -1
أو
Download -2
واحفظيها على سطح المكتب
قبل ماتشغلينها ضروري تعملين تعطيل لأي برنامج حماية عندك والاحظ موجود عندك برنامج Mcafee وطريقة تعطيلة بهذ الشكل :
اضغطي على ايقونة البرنامج هذي

بالزر الايمن واختاري (Exit) ...
الحين شغلي الاداة اللي اسمها ComboFix وهذي ايقونتها
لكن تأكدي ان الانترنت شغال علشان الاداة تعمل تحديث مباشر لقاعدة البيانات
بعد تشغيلها بتظهر لك نافذة ....

اختاري Yes ثم بتظهر لك النافذة هذي اتركيها لحد ماتخلص ...

ثم بتظهر لك النافذة هذي ....

اختاري Yes ثم نتابع .......

ضغط Yes علشان تبدأ عملية الفحص ... ثم نتابع .......

الان تم التحديث وجاري بدأ عملية الفحص للجهاز .. ويمكن الجهاز يعيد التشغيل تلقائي عادي مافيه مشكلة اتركيه ولما يبتدي التشغيل راح تكمل الاداة عملية الفحص ..
بعد ماتنتهي من عملية الفحص راح تظهر لك تقرير بهذا الشكل ...

ولو ما أظهرته افتحي جهاز الكمبيوتر ثم محرك الاقراص C وبتلاقين ملف اسمه : ComboFix.txt ارفقيه لي في ردك الجاي ...
اخوك الهاوي .........
ش
06-10-2009 | 03:21 PM
مشكور اخي الهاوي جدا جدا تعبتك معي والله خطوات كثير بجرب والله يعين ومشكور جدا جدا جدا
ش
07-10-2009 | 04:06 PM
اخي العزيز الهاوي لمل اضغط بزر الماوس الايمن على
مايطلع لي Exit وش اسوي هل اقوم بحذفه ولا شو بليز وضح لي بليز لا تتاخر بالرد علي ادري تعبتك معي الله يعطيك العافيه ما قصرت والله احس راسي بينفجر من هل الجهاز
مايطلع لي Exit وش اسوي هل اقوم بحذفه ولا شو بليز وضح لي بليز لا تتاخر بالرد علي ادري تعبتك معي الله يعطيك العافيه ما قصرت والله احس راسي بينفجر من هل الجهاز
ا
07-10-2009 | 04:48 PM
هلا فيك أختي معليش طولت عليك ...
أختي يمكن البرنامج اللي عندك هو : MCAFEE SECURITY CENTER
وبصراحه ماعرف طريقة تعطيلة للاسف ..
عموما مب مشكلة تقدرين تعطلينه لو دخلتي للوضع الأمن ..
طريقة الدخول للوضع الأمن انك تعملين اعادة تشغيل للجهاز واول ماتشتغل الشاشة ويطلع كلام انجليزي واسم الشركة وقتها مباشرة خليك ضاغطة على الزر F8 ولا تفكي ايدك عنه يظهر لك خيارات تحت بعض .. اختاري منها الخيار الاول اللي هو : Safe Mode ..
وادخلي على الجهاز من هذا الوضع وشغلي اداة Combofix واتبعي الشرح اللي عطيتك وعطيني تقرير ...
دمتي بكل خير ........
أختي يمكن البرنامج اللي عندك هو : MCAFEE SECURITY CENTER
وبصراحه ماعرف طريقة تعطيلة للاسف ..
عموما مب مشكلة تقدرين تعطلينه لو دخلتي للوضع الأمن ..
طريقة الدخول للوضع الأمن انك تعملين اعادة تشغيل للجهاز واول ماتشتغل الشاشة ويطلع كلام انجليزي واسم الشركة وقتها مباشرة خليك ضاغطة على الزر F8 ولا تفكي ايدك عنه يظهر لك خيارات تحت بعض .. اختاري منها الخيار الاول اللي هو : Safe Mode ..
وادخلي على الجهاز من هذا الوضع وشغلي اداة Combofix واتبعي الشرح اللي عطيتك وعطيني تقرير ...
دمتي بكل خير ........
ش
10-10-2009 | 01:39 AM
هلاا اخي العزيز الهاوي سويت الي قلت لي عليه بس اذا صار في الوضع الامن يصير غير قادر على الاتصال بشبكة الانترنت وانت قلت لازم يصير متصل بالشبكه بس بحاول مره ثانيه يمكن تضبط وعندي سؤال ثاني ضمن خيرات التشغيل الي في قائمة ابدء خيار تأمين هذا الجهاز هل هو نفسه الوضع الامن الي قلت عنه؟:confused::confused::confused: احس هل جهاز ماراح يضبط والله جنني و طفشتك معي ايش اسوي مالي حظ مشكور اخوي والله ماقصرت اشهد انك اصيل سامحني تعبتك معي
ش
12-10-2009 | 02:24 AM
هلا اخوي انا جربت مره ثانيه بس اخترت الخيار الثاني الوضع الامن مع تشغيل الشبكه اوكي يعدين شغلت برنامج compo الي حملته وبعدين طلعت لي النافذه الي قلت انت عليها وبعدين اخترت نعم وبعدين طلعتلي حاجه غير الي قلت عليها ولا فهمت منها شى وطلعلي رساله من برنامج الحمايه حقي جهازك غير محمي جيدا واضغط هنا وخرابيط عاد ماعرفت شسوي وكنسلت الخطوات بليز رد علي اي احد يرد يقولي شسوي بليز بليز
ا
12-10-2009 | 09:59 PM
مساء الخير
أختي بصراحه ما أقدر افيدك بخصوص الرسالة اللي ظهرت لك لأني ماشفتها :)
تمنيت انك مصورة الرسالة علشان اشوفها واعرف سبب المشكلة لكن بالطريقة هذي ماراح اعرف وين الخطاء فيه .. حاولي تصورين لي اي رسالة خطاء تظهر لك علشان اقدر افيدك بأسرع وقت ولا اتأخر عليك بالرد ..
دمتي بكل خير .......
أختي بصراحه ما أقدر افيدك بخصوص الرسالة اللي ظهرت لك لأني ماشفتها :)
تمنيت انك مصورة الرسالة علشان اشوفها واعرف سبب المشكلة لكن بالطريقة هذي ماراح اعرف وين الخطاء فيه .. حاولي تصورين لي اي رسالة خطاء تظهر لك علشان اقدر افيدك بأسرع وقت ولا اتأخر عليك بالرد ..
دمتي بكل خير .......
ش
13-10-2009 | 10:43 PM
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1256.966.1025.18.2037.1610 [GMT 3:00]
Running from: c:\users\aLmunjez\Desktop\ComboFix.exe ComboFix 09-10-11.01 - aLmunjez 10/13/2009 21:57.2.2 - NTFSx86 NETWORK
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\oem8.inf
.
((((((((((((((((((((((((( Files Created from 2009-09-13 to 2009-10-13 )))))))))))))))))))))))))))))))
.
2009-10-13 19:04 . 2009-10-13 19:06 -------- d-----w- c:\users\aLmunjez\AppData\Local\temp
2009-10-13 19:04 . 2009-10-13 19:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-29 23:43 . 2009-09-29 23:43 -------- d-----w- c:\program files\Trend Micro
2009-09-24 16:21 . 2009-09-24 16:21 -------- d-----w- c:\windows\system32\EventProviders
2009-09-24 03:56 . 2009-09-29 22:38 -------- d-----w- c:\users\aLmunjez\Tracing
2009-09-24 03:54 . 2009-09-24 03:54 -------- dc----w- c:\windows\system32\DRVSTORE
2009-09-24 03:54 . 2009-08-05 19:48 54632 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2009-09-24 03:53 . 2009-09-24 03:53 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-09-24 03:51 . 2006-11-29 10:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-09-24 03:50 . 2009-09-24 03:50 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-09-24 03:50 . 2008-06-26 03:21 712704 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-24 03:50 . 2008-06-26 03:21 347648 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-24 03:47 . 2009-09-24 03:47 -------- d-----w- c:\program files\Microsoft
2009-09-24 03:46 . 2009-09-24 03:46 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-24 03:34 . 2009-09-24 03:34 -------- d-----w- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-13 18:53 . 2008-12-20 22:27 6648 ----a-w- c:\users\aLmunjez\AppData\Local\d3d9caps.dat
2009-10-13 18:50 . 2008-07-26 07:50 3308 ----a-w- c:\windows\bthservsdp.dat
2009-09-30 00:10 . 2008-12-01 13:35 -------- d-----w- c:\users\aLmunjez\AppData\Roaming\DMCache
2009-09-24 03:54 . 2008-12-01 13:57 -------- d-----w- c:\program files\Windows Live
2009-09-10 11:18 . 2008-12-01 13:15 -------- d-----w- c:\programdata\Microsoft Help
2009-08-14 17:07 . 2009-09-09 12:37 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 16:29 . 2009-09-09 12:37 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:29 . 2009-09-09 12:37 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:16 . 2009-09-09 12:37 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:16 . 2009-09-09 12:37 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:16 . 2009-09-09 12:37 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:16 . 2009-09-09 12:37 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:16 . 2009-09-09 12:37 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:16 . 2009-09-09 12:37 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:16 . 2009-09-09 12:37 10240 ----a-w- c:\windows\system32\finger.exe
2009-07-31 02:27 . 2009-07-31 02:27 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-26 13:44 . 2009-07-26 13:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-21 21:52 . 2009-07-29 02:02 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 02:02 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 02:02 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 02:02 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 14:35 . 2009-08-11 21:35 71680 ----a-w- c:\windows\system32\atl.dll
2008-07-26 06:04 . 2008-07-26 06:04 76 --sh--r- c:\windows\CT4CET.bin
2008-07-26 15:42 . 2008-07-26 15:42 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Google Update"="c:\users\aLmunjez\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-05-20 133104]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-05-04 167936]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2008-03-04 36864]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 405504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-06 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-06 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-06 133656]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-05-16 3444736]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 148888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-01 185896]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-07-09 645328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
c:\users\aLmunjez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-5-13 1058088]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-1 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-7-26 50688]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-07-26 06:21 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-927122515-2350025247-341440377-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{53006D97-D13C-49F1-8B51-5AC2E0A9FFB3}"= c:\program files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect
"{BA3B4F51-E836-41E7-A5A3-7A3CEEAC3209}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{AF52B3DD-394F-428E-BDB5-7929B436A0CD}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{76D067C4-93C6-43ED-9A07-B7935CF385B5}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{99E1F5EF-C857-4F4D-A2E7-2D15DD6F8970}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{C6F0977C-929D-4145-9CE4-84CA99D2097A}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{92EAC923-04F0-40E7-9135-930A250BAD9C}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{87259CF7-C8CD-4725-A21C-5338C078800D}"= Profile=Private|Profile=Public|c:\program files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [26/07/08 10:49 Õ 73728]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [28/04/08 05:56 ã 161048]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [21/05/09 10:30 ã 206112]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [24/09/09 06:54 Õ 54632]
S3 fsssvc;ÎÏãÉ ÃãÇä ÇáÚÇÆáÉ Ýí Windows Live;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/09 10:48 ã 704864]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\System32\drivers\IntcHdmi.sys [26/07/08 06:43 ã 111616]
S3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [26/07/08 06:43 ã 235648]
S3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [26/07/08 06:43 ã 7424]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ECACHE
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-10-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-927122515-2350025247-341440377-1000Core.job
- c:\users\aLmunjez\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-20 22:39]
2009-10-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-927122515-2350025247-341440377-1000UA.job
- c:\users\aLmunjez\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-20 22:39]
2009-05-22 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-08-05 18:26]
2009-05-22 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-08-05 18:26]
2009-10-13 c:\windows\Tasks\User_Feed_Synchronization-{A5DE49CD-2359-4451-AFD5-06472275C6C0}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
.
------- Supplementary Scan -------
.
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Ê&ÕÏíÑ Åáì Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
HKLM-RunOnce-<NO NAME> - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2009-10-13 22:06
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-927122515-2350025247-341440377-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):67,d3,be,0c,c8,36,8b,39,78,6b,51,e5,73,e8,3a,3d,ca,d8,56,da,ad,
56,08,60,9d,fc,55,7f,78,65,f5,1e,be,2d,9c,b4,01,6e,82,83,00,00,00,00,00,00,\
[HKEY_USERS\S-1-5-21-927122515-2350025247-341440377-1000_Classes\CLSID\{e8bce6fe-92ab-4143-bb24-dd50f828a0ae}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000049
"Therad"=dword:00000015
"MData"=hex(0):cb,9b,ad,ef,27,7d,29,69,f5,02,f0,76,aa,4a,f1,7c,d3,d9,67,7f,6a,
4b,7b,ad,4e,c8,5d,82,d0,2b,96,ba,42,00,01,82,11,6e,de,f1,e8,3b,4b,9a,0e,80,\
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-10-13 22:08
ComboFix-quarantined-files.txt 2009-10-13 19:08
Pre-Run: 182,444,986,368 bytes free
Post-Run: 182,650,851,328 bytes free
214 --- E O F --- 2009-09-29 22:28
Running from: c:\users\aLmunjez\Desktop\ComboFix.exe ComboFix 09-10-11.01 - aLmunjez 10/13/2009 21:57.2.2 - NTFSx86 NETWORK
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\oem8.inf
.
((((((((((((((((((((((((( Files Created from 2009-09-13 to 2009-10-13 )))))))))))))))))))))))))))))))
.
2009-10-13 19:04 . 2009-10-13 19:06 -------- d-----w- c:\users\aLmunjez\AppData\Local\temp
2009-10-13 19:04 . 2009-10-13 19:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-29 23:43 . 2009-09-29 23:43 -------- d-----w- c:\program files\Trend Micro
2009-09-24 16:21 . 2009-09-24 16:21 -------- d-----w- c:\windows\system32\EventProviders
2009-09-24 03:56 . 2009-09-29 22:38 -------- d-----w- c:\users\aLmunjez\Tracing
2009-09-24 03:54 . 2009-09-24 03:54 -------- dc----w- c:\windows\system32\DRVSTORE
2009-09-24 03:54 . 2009-08-05 19:48 54632 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2009-09-24 03:53 . 2009-09-24 03:53 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-09-24 03:51 . 2006-11-29 10:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-09-24 03:50 . 2009-09-24 03:50 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-09-24 03:50 . 2008-06-26 03:21 712704 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-24 03:50 . 2008-06-26 03:21 347648 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-24 03:47 . 2009-09-24 03:47 -------- d-----w- c:\program files\Microsoft
2009-09-24 03:46 . 2009-09-24 03:46 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-24 03:34 . 2009-09-24 03:34 -------- d-----w- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-13 18:53 . 2008-12-20 22:27 6648 ----a-w- c:\users\aLmunjez\AppData\Local\d3d9caps.dat
2009-10-13 18:50 . 2008-07-26 07:50 3308 ----a-w- c:\windows\bthservsdp.dat
2009-09-30 00:10 . 2008-12-01 13:35 -------- d-----w- c:\users\aLmunjez\AppData\Roaming\DMCache
2009-09-24 03:54 . 2008-12-01 13:57 -------- d-----w- c:\program files\Windows Live
2009-09-10 11:18 . 2008-12-01 13:15 -------- d-----w- c:\programdata\Microsoft Help
2009-08-14 17:07 . 2009-09-09 12:37 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 16:29 . 2009-09-09 12:37 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:29 . 2009-09-09 12:37 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:16 . 2009-09-09 12:37 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:16 . 2009-09-09 12:37 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:16 . 2009-09-09 12:37 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:16 . 2009-09-09 12:37 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:16 . 2009-09-09 12:37 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:16 . 2009-09-09 12:37 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:16 . 2009-09-09 12:37 10240 ----a-w- c:\windows\system32\finger.exe
2009-07-31 02:27 . 2009-07-31 02:27 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-26 13:44 . 2009-07-26 13:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-21 21:52 . 2009-07-29 02:02 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 02:02 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 02:02 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 02:02 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 14:35 . 2009-08-11 21:35 71680 ----a-w- c:\windows\system32\atl.dll
2008-07-26 06:04 . 2008-07-26 06:04 76 --sh--r- c:\windows\CT4CET.bin
2008-07-26 15:42 . 2008-07-26 15:42 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Google Update"="c:\users\aLmunjez\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-05-20 133104]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-05-04 167936]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2008-03-04 36864]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 405504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-06 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-06 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-06 133656]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-05-16 3444736]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 148888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-01 185896]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-07-09 645328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
c:\users\aLmunjez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-5-13 1058088]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-1 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-7-26 50688]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-07-26 06:21 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-927122515-2350025247-341440377-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{53006D97-D13C-49F1-8B51-5AC2E0A9FFB3}"= c:\program files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect
"{BA3B4F51-E836-41E7-A5A3-7A3CEEAC3209}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{AF52B3DD-394F-428E-BDB5-7929B436A0CD}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{76D067C4-93C6-43ED-9A07-B7935CF385B5}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{99E1F5EF-C857-4F4D-A2E7-2D15DD6F8970}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{C6F0977C-929D-4145-9CE4-84CA99D2097A}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{92EAC923-04F0-40E7-9135-930A250BAD9C}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{87259CF7-C8CD-4725-A21C-5338C078800D}"= Profile=Private|Profile=Public|c:\program files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [26/07/08 10:49 Õ 73728]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [28/04/08 05:56 ã 161048]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [21/05/09 10:30 ã 206112]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [24/09/09 06:54 Õ 54632]
S3 fsssvc;ÎÏãÉ ÃãÇä ÇáÚÇÆáÉ Ýí Windows Live;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/09 10:48 ã 704864]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\System32\drivers\IntcHdmi.sys [26/07/08 06:43 ã 111616]
S3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [26/07/08 06:43 ã 235648]
S3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [26/07/08 06:43 ã 7424]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ECACHE
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-10-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-927122515-2350025247-341440377-1000Core.job
- c:\users\aLmunjez\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-20 22:39]
2009-10-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-927122515-2350025247-341440377-1000UA.job
- c:\users\aLmunjez\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-20 22:39]
2009-05-22 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-08-05 18:26]
2009-05-22 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-08-05 18:26]
2009-10-13 c:\windows\Tasks\User_Feed_Synchronization-{A5DE49CD-2359-4451-AFD5-06472275C6C0}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
.
------- Supplementary Scan -------
.
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Ê&ÕÏíÑ Åáì Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
HKLM-RunOnce-<NO NAME> - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2009-10-13 22:06
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-927122515-2350025247-341440377-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):67,d3,be,0c,c8,36,8b,39,78,6b,51,e5,73,e8,3a,3d,ca,d8,56,da,ad,
56,08,60,9d,fc,55,7f,78,65,f5,1e,be,2d,9c,b4,01,6e,82,83,00,00,00,00,00,00,\
[HKEY_USERS\S-1-5-21-927122515-2350025247-341440377-1000_Classes\CLSID\{e8bce6fe-92ab-4143-bb24-dd50f828a0ae}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000049
"Therad"=dword:00000015
"MData"=hex(0):cb,9b,ad,ef,27,7d,29,69,f5,02,f0,76,aa,4a,f1,7c,d3,d9,67,7f,6a,
4b,7b,ad,4e,c8,5d,82,d0,2b,96,ba,42,00,01,82,11,6e,de,f1,e8,3b,4b,9a,0e,80,\
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-10-13 22:08
ComboFix-quarantined-files.txt 2009-10-13 19:08
Pre-Run: 182,444,986,368 bytes free
Post-Run: 182,650,851,328 bytes free
214 --- E O F --- 2009-09-29 22:28
ا
13-10-2009 | 10:45 PM
مااعرف
ش
13-10-2009 | 10:52 PM
يمين يسار وهذا الي طلع معي ولا ادري كانت الطريقه صح والا لا ان شاء الله ضبطت هالمره ننتظر ان شاء الله الاخبار الزينه ومشكور اخي الهاوي جدا جدا جدا
ا
14-10-2009 | 12:18 AM
السلام عليكم ورحمة الله وبركاته
أختي البرنامج اظهر النتيجة كاملة بس فيه مشكلة وهي ان بعض المفاتيح ماقدر يعدل عليها لأنها محمية من النظام .. عموما فيه حل ان شاء الله يساعدك وينهي المشكلة هذي ...
اعملي ازالة لبرنامج MCAFEE لمكافحة الفايروسات وركبي برنامج :Kaspersky Internet Security 2010
اضمن لك ان شاء الله ودقيق في اي عملية عن طريق الشبكة ويعطيك خبر بأي عملية راح تبتدي من غير اذنك ...
وهذا رابط النسخة العربية ...
Download
وشرح طريقة التركيب على هذا الرابط ......
http://forums.3roos.com/t485560-3.html
دمتي بكل خير ...........
أختي البرنامج اظهر النتيجة كاملة بس فيه مشكلة وهي ان بعض المفاتيح ماقدر يعدل عليها لأنها محمية من النظام .. عموما فيه حل ان شاء الله يساعدك وينهي المشكلة هذي ...
اعملي ازالة لبرنامج MCAFEE لمكافحة الفايروسات وركبي برنامج :Kaspersky Internet Security 2010
اضمن لك ان شاء الله ودقيق في اي عملية عن طريق الشبكة ويعطيك خبر بأي عملية راح تبتدي من غير اذنك ...
وهذا رابط النسخة العربية ...
Download
وشرح طريقة التركيب على هذا الرابط ......
http://forums.3roos.com/t485560-3.html
دمتي بكل خير ...........
ش
14-10-2009 | 02:31 AM
هلا اخي العزيز الهاوي بس لاحضت ان البرنامج يحتاج اعدادات يعني السالفه ناقصه هل نزلت موضوع عن برنامج الحمايه الجديد والله يعطيك العافيه و الله يديم عليك الصحه ويرزقك الرزق الحلال الطيب في حفظ الله والف شكر لك ماقصرت
v
06-11-2009 | 04:01 AM
up up up