انت غير مسجل بمنتديات إقلاع سوفت ... للإشتراك اضغط هنا    
   
شبكة إقلاع سوفت  
منتديات - برامج - فيديو - صور دليل البرامج - دروس - خطوط - ماسنجر - العاب - توبيكات - تردد القنوات - الطقس
خريطة الموقع  خدمة RSS بشبكة إقلاع سوفت  جديد البرامج   New Releases
العاب والعاب للجوال - مقاطع بلوتوث - نغمات للجوال - ابتسامات وتواقيع - مسجات الجوال
صور

منتدى مجاني

منتدى سيدتي
شات صوتي
بنات كول
ايوان
بعد الإشتراك ستصلك رسالة لتفعيل الاشتراك
افتح الرسالة واضغط على زر Reply
ثم اضغط على زر Send

شرح طريقة الإشتراك بالصور

Facebook | vip600.com إقلاع سوفت

 
طلب كود التفعيل استعادة كلمة المرور شروط الكتابة بمنتديات إقلاع سوفت الشروط المجموعات شرح طريقة التفعيل تغييرات هامة بالشروط
العودة   منتديات إقلاع سوفت > منتديات إقلاع سوفت > منتدى الكمبيوتر والإنترنت

منتدى الكمبيوتر والإنترنت مقالات واخبار ومشاكل وكل ما يتعلق بالكمبيوتر والإنترنت


لما اشبك وايرليس يكون شابك عالشبكة بس ما يفتح مواقع ولا شي "تم التعديل"

المشاركة في الموضوع
 
خيارات الموضوع طريقة العرض
قديم 15-10-2010, 01:41 AM   #1
sojood
عضو مشارك
 
الصورة الرمزية لـ sojood
 
إفتراضي لما اشبك وايرليس يكون شابك عالشبكة بس ما يفتح مواقع ولا شي "تم التعديل"

اولا السلام عليكم جميعا
انا عندي لابتوب ونازل عليه وندوز اكس بي سيرفس باك 2
المهم من حوالي شهرين بدت مشكلة غريبة
انا عندي وايرليس طبعا بالبيت
صرت لما اشبك وايرليس يكون شابك عالشبكة
بس ما يفتح مواقع ولا شي !!
قلت يمكن في مشكلة بالمودم
غيرت المودم وظلت المشكلة
حتى اني غيرت الدولة كلها وما زلت المشكلة
لا وبعد كبرت وزادت
وصار ما يفتح ولا من اي جهاز
الا بس اقفل جهازي !!
يعني سبحان الله اول ما اشبك عليه
تصير اللمبة حقت اللي عليها ال @
تطفي وتظوي !!
والله اول ما اكبس shut down
تشتغل !!!
يا ريت لو احد يعرف شو المشكلة يخبرني
انا حابة اخلي خيار فورمات الجهاز للآخر
لأن عندي كثير اشياء عالجهاز
ادري بتقولون انسخيها على هارديسك خارجي

بس حابة اعمل كل شي قبل
ما اوصل لهذا الحل

لأن فيه برامج كثير ما ودري اخسرها
sojood غير متصل   الرد مع إقتباس
قديم 15-10-2010, 02:14 AM   #2
محب المدينه
مشرف منتدى الكمبيوتر والإنترنت
حلال مشاكل الكمبيوتر
 
الصورة الرمزية لـ محب المدينه
 
محب المدينه @ Twitter
إرسال رسالة عبر MSN إلى محب المدينه
إفتراضي

ضعي تقرير بواسطة برنامج HijackThis

حملي البرنامج من هذا الرابط

http://www.hijackthis.de/downloads/HJTInstall.exe

بعد تنزيل البرنامج افتحيه واضغطي على Do system scan and save alogfile

وبعده سوف يتم حفظ تقرير في المفكرة انسخي التقرير وضعيه في ردك القادم
محب المدينه غير متصل   الرد مع إقتباس
قديم 15-10-2010, 02:32 AM   #3
sojood
عضو مشارك
 
الصورة الرمزية لـ sojood
 
إفتراضي

اخي كيف احمل البرنامج والجهاز ما بيشبك اصلا ؟؟
بينفع احملو على جهاز ثاني وانسخو ؟
sojood غير متصل   الرد مع إقتباس
قديم 15-10-2010, 02:42 AM   #4
محب المدينه
مشرف منتدى الكمبيوتر والإنترنت
حلال مشاكل الكمبيوتر
 
الصورة الرمزية لـ محب المدينه
 
محب المدينه @ Twitter
إرسال رسالة عبر MSN إلى محب المدينه
إفتراضي

لا ماينفع

لازم يكون الجهاز الثاني بجانبك تحملي منه البرنامج

ثم تنقلي البرنامج على جهازك
محب المدينه غير متصل   الرد مع إقتباس
قديم 15-10-2010, 02:06 PM   #5
sojood
عضو مشارك
 
الصورة الرمزية لـ sojood
 
إفتراضي

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:03:10 م, on 15/10/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\System Control Manager\MGSysCtrl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\System Control Manager\MSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUServi ce.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.e xe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=wbst&s={searchTerms}&f=4
R1 - HKCU\Software\Microsoft\Windows\CurrentV ersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: Brothersoft Toolbar - {e8de9422-3b2c-4243-bf6f-235da84d8ef8} - C:\Program Files\Brothersoft\tbBrot.dll
R3 - URLSearchHook: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt. dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper .dll
O2 - BHO: YSPManager - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program Files\Yahoo!\Search Protection\ysp.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplu gin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: facemoods Helper - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.3.61.3\f acemoods.dll
O2 - BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_pl ugin.dll
O2 - BHO: Brothersoft Toolbar - {e8de9422-3b2c-4243-bf6f-235da84d8ef8} - C:\Program Files\Brothersoft\tbBrot.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTS ingleInstance.dll
O3 - Toolbar: facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.3.61.3\f acemoodsTlbr.dll
O3 - Toolbar: Brothersoft Toolbar - {e8de9422-3b2c-4243-bf6f-235da84d8ef8} - C:\Program Files\Brothersoft\tbBrot.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt. dll
O3 - Toolbar: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessen ger.exe" -quiet
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\MSI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [Java developer Script Browse] C:\WINDOWS\jusched.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\MSI\Application Data\DVDVideoSoftIEHelpers\youtubedownlo ad.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\MSI\Application Data\DVDVideoSoftIEHelpers\youtubetomp3. htm
O9 - Extra button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files\iMacros\imacros.dll
O9 - Extra 'Tools' menuitem: iMacros Web Automation - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files\iMacros\imacros.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.D LL
O9 - Extra button: (no name) - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll
O9 - Extra 'Tools' menuitem: Yahoo! Search Protection - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...oUploader5.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1248064164187
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...Uploader55.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB450 707-2588-436E-954C-A02386CC9D83}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (GoogleUpdateBeta) - Unknown owner - C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google\Update\GoogleUpdateBeta.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Micro Star SCM - Unknown owner - C:\Program Files\System Control Manager\MSIService.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUServi ce.exe

--
End of file - 11537 bytes



هذا اللي طلع
sojood غير متصل   الرد مع إقتباس
قديم 15-10-2010, 05:49 PM   #6
محب المدينه
مشرف منتدى الكمبيوتر والإنترنت
حلال مشاكل الكمبيوتر
 
الصورة الرمزية لـ محب المدينه
 
محب المدينه @ Twitter
إرسال رسالة عبر MSN إلى محب المدينه
إفتراضي

حملي أداة ComboFix

من احدى الروابط التالية

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

عطلي برنامج الحماية Nod32

الطريقة اضغطي علىالثلاثة أزرة ( ALT + Ctrl + Delete ) معا

تظهر نافذة ادارة المهام اختاري العمليات ثم اعملي كما في الصورة



عند تشغيل أداة الكمبوفكس سوف تظهر عدة رسائل وافقي عليها

سوف تقوم الأداة بفحص الجهاز وقد تعيد لك التشغيل

واذا أعادت التشغيل سوف تستكمل الفحص

وفي النهاية سوف يظهر تقرير باسم ( ComboFix ) , وسوف يتم حفظه بالـ C

انسخي ما بالتقرير والصقيه في ردك القادم

ثم اعطينا تقرير هايجاك جديد
محب المدينه غير متصل   الرد مع إقتباس
قديم 16-10-2010, 12:32 AM   #7
sojood
عضو مشارك
 
الصورة الرمزية لـ sojood
 
إفتراضي

ComboFix 10-10-14.04 - MSI 10/15/2010 23:57:49.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.767.434 [GMT 3:00]
Running from: F:\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))) )))))))))
.

c:\docume~1\MSI\LOCALS~1\Temp\install_fl ash_player.exe
c:\docume~1\MSI\MYDOCU~1\CDF3~1.exe
c:\documents and settings\MSI\Application Data\facemoods.com
c:\documents and settings\MSI\Application Data\PriceGong
c:\documents and settings\MSI\Application Data\PriceGong\Data\1.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\a.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\b.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\c.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\d.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\e.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\f.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\g.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\h.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\i.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\J.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\k.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\l.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\m.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\n.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\o.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\p.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\q.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\r.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\s.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\t.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\u.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\v.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\w.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\x.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\y.xml
c:\documents and settings\MSI\Application Data\PriceGong\Data\z.xml
c:\documents and settings\MSI\Recent\Thumbs.db
c:\program files\facemoods.com
c:\program files\facemoods.com\facemoods\1.3.61.3\f acemoods.crx
c:\program files\facemoods.com\facemoods\1.3.61.3\f acemoods.dll
c:\program files\facemoods.com\facemoods\1.3.61.3\f acemoods.png
c:\program files\facemoods.com\facemoods\1.3.61.3\f acemoodsEng.dll
c:\program files\facemoods.com\facemoods\1.3.61.3\f acemoodssafe.dll
c:\program files\facemoods.com\facemoods\1.3.61.3\f acemoodsTlbr.dll
c:\program files\facemoods.com\facemoods\1.3.61.3\u ninstall.exe
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \.svn\all-wcprops
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \.svn\entries
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \.svn\prop-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \.svn\text-base\chrome.manifest.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \.svn\text-base\install.rdf.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \.svn\text-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \chrome.manifest
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \chrome\.svn\all-wcprops
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \chrome\.svn\entries
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \components\FFHst.dll
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \components\FFHst.xpt
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\all-wcprops
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\entries
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\prop-base\facemoods.png.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\prop-base\Thumbs.db.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\prop-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\text-base\facemoods.css.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\text-base\facemoods.png.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\text-base\facemoods.xul.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\text-base\fcmdDef.js.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\text-base\Loader.js.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\text-base\mtrprt.js.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\text-base\newTabLgc.js.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\text-base\prefman.js.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\text-base\script-compiler.js.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\text-base\Thumbs.db.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\text-base\utils.js.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\text-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\text-base\xmlhttprequester.js.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\.svn\text-base\xpiInstallLgc.js.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\facemoods.css
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\facemoods.png
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\facemoods.xul
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\fcmdDef.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\all-wcprops
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\entries
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\prop-base\facemoods.png.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\prop-base\fb.gif.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\prop-base\help_16.gif.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\prop-base\home.gif.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\prop-base\logo.png.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\prop-base\moodsIcon.png.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\prop-base\pref.jpg.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\prop-base\privecy_16_hot.gif.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\prop-base\stripicons.png.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\prop-base\tellafriend.gif.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\prop-base\Thumbs.db.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\prop-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\text-base\facemoods.png.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\text-base\fb.gif.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\text-base\help_16.gif.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\text-base\home.gif.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\text-base\logo.png.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\text-base\moodsIcon.png.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\text-base\pref.jpg.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\text-base\privecy_16_hot.gif.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\text-base\stripicons.png.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\text-base\tellafriend.gif.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\text-base\Thumbs.db.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\.svn\text-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\facemoods.png
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\fb.gif
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\help_16.gif
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\home.gif
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\logo.png
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\moodsIcon.png
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\pref.jpg
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\privecy_16_hot.gif
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\stripicons.png
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\tellafriend.gif
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\Thumbs.db
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\images\vssver.scc
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\instlgc.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\Loader.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\mtrprt.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\newTabLgc.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\preferences\.svn\all-wcprops
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\preferences\.svn\entries
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\preferences\.svn\prop-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\preferences\.svn\text-base\preferences.js.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\preferences\.svn\text-base\preferences.xul.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\preferences\.svn\text-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\preferences\preferences.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\preferences\preferences.xul
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\preferences\vssver.scc
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\prefman.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\script-compiler.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\Thumbs.db
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\utils.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\vssver.scc
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\xmlhttprequester.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \content\xpiInstallLgc.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \defaults\.svn\all-wcprops
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \defaults\.svn\entries
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \defaults\preferences\.svn\all-wcprops
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \defaults\preferences\.svn\entries
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \defaults\preferences\.svn\prop-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \defaults\preferences\.svn\text-base\instlPref.js.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \defaults\preferences\.svn\text-base\vssver.scc.svn-base
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \defaults\preferences\instlPref.js
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \defaults\preferences\vssver.scc
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \install.rdf
c:\program files\Mozilla Firefox\extensions\ffxtlbr@Facemoods.com \vssver.scc
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
c:\windows\system32\config\systemprofile \Application Data\PriceGong
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\1.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\a.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\b.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\c.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\d.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\e.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\f.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\g.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\h.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\i.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\J.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\k.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\l.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\m.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\n.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\o.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\p.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\q.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\r.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\s.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\t.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\u.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\v.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\w.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\x.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\y.xml
c:\windows\system32\config\systemprofile \Application Data\PriceGong\Data\z.xml
c:\windows\system32\drivers\str.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))) )))))))))
.

-------\Legacy_GOOGLEUPDATEBETA
-------\Service_GoogleUpdateBeta
-------\Service_synsend


((((((((((((((((((((((((( Files Created from 2010-09-15 to 2010-10-15 )))))))))))))))))))))))))))))))
.

2010-10-15 11:02 . 2010-10-15 11:02 -------- d-----w- c:\program files\Trend Micro
2010-09-20 20:12 . 2010-09-20 20:12 -------- d-----w- c:\documents and settings\MSI\Application Data\DVDVideoSoft
2010-09-20 19:36 . 2006-06-29 10:07 14048 ------w- c:\windows\system32\spmsg2.dll
2010-09-20 19:36 . 2010-09-20 19:36 -------- d-----w- c:\windows\system32\ar-SA
2010-09-20 19:33 . 2010-09-20 19:36 -------- d-----w- c:\windows\system32\XPSViewer
2010-09-20 19:33 . 2010-09-20 19:33 -------- d-----w- c:\program files\Reference Assemblies
2010-09-20 19:32 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x8 6\filterpipelineprintproc.dll
2010-09-20 19:32 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipel ineprintproc.dll
2010-09-20 19:32 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-09-20 19:32 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilter pipelinesvc.exe
2010-09-20 19:32 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x8 6\printfilterpipelinesvc.exe
2010-09-20 19:32 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dl l
2010-09-20 19:32 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-09-20 19:32 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-09-20 19:32 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-09-20 19:28 . 2010-09-20 19:28 -------- d-----w- c:\program files\MSXML 6.0

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))) ))))))))))))
.
.

------- Sigcheck -------

[-] 2009-05-15 . 6E266AAF4168B3569A330C61AB01F6B4 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
[-] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download \9866fb57abdc0ea2f5d4e132d055ba4e\sfcfil es.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))) ))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Int ernet Explorer\URLSearchHooks]
"{e8de9422-3b2c-4243-bf6f-235da84d8ef8}"= "c:\program files\Brothersoft\tbBrot.dll" [2010-06-13 2734688]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\tbDVD0.dll" [2010-10-14 2735200]

[HKEY_CLASSES_ROOT\clsid\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}]

[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
2010-10-14 19:56 2735200 ----a-w- c:\program files\DVDVideoSoftTB\tbDVD0.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}]
2010-06-13 16:10 2734688 ----a-w- c:\program files\Brothersoft\tbBrot.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\In ternet Explorer\Toolbar]
"{e8de9422-3b2c-4243-bf6f-235da84d8ef8}"= "c:\program files\Brothersoft\tbBrot.dll" [2010-06-13 2734688]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\tbDVD0.dll" [2010-10-14 2735200]

[HKEY_CLASSES_ROOT\clsid\{e8de9422-3b2c-4243-bf6f-235da84d8ef8}]

[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Win dows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\Y ahooMessenger.exe" [2010-06-01 5252408]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-07-02 288048]
"Google Update"="c:\documents and settings\MSI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-08-20 133104]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wi ndows\CurrentVersion\Run]
"SiSPower"="SiSPower.dll" [2008-03-20 53248]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2008-06-11 1454080]
"MGSysCtrl"="c:\program files\System Control Manager\MGSysCtrl.exe" [2008-08-12 684032]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 16862720]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 1443072]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-05 185896]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-28 75136]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-03-05 1135912]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2010-06-12 190024]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\W indows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON .EXE" [2004-08-03 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\W indows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2010-05-04 124928]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2008-2-22 2938184]
Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-6-5 262144]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\sh ared tools\msconfig\startupreg\Device Detector]
DevDetect.exe -autorun [X]

[HKEY_LOCAL_MACHINE\software\microsoft\sh ared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 13:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\sh ared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 19:16 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\sh ared tools\msconfig\startupreg\TkBellExe]
2009-06-05 16:39 185896 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKLM\~\services\sharedaccess\parameters\ firewallpolicy\standardprofile\Authorize dApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger .exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\U.S. Robotics\\EasyConfigurator\\jre\\bin\\ja va.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binarie s\\HelpCtr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\MSI\\My Documents\\Downloads\\PIC67572374533-JPG-www.facebook.com.scr"= c:\\WINDOWS\\jusched.exe
"c:\\Program Files\\ooVoo\\ooVoo.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\ firewallpolicy\standardprofile\GloballyO penPorts\List]
"443:TCP"= 443:TCPoVoo TCP المنفذ 443
"443:UDP"= 443:UDPoVoo UDP المنفذ 443
"37674:TCP"= 37674:TCPoVoo TCP المنفذ 37674
"37674:UDP"= 37674:UDPoVoo UDP المنفذ 37674
"37675:UDP"= 37675:UDPoVoo UDP المنفذ 37675

R1 epfwtdir;epfwtdir;c:\windows\system32\dr ivers\epfwtdir.sys [21/12/2007 08:21 ص 33800]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [21/12/2007 08:21 ص 468224]
R2 Micro Star SCM;Micro Star SCM;c:\program files\System Control Manager\MSIService.exe [05/06/2009 07:21 م 159744]
S2 djhqkjn;djhqkjn;\??\c:\windows\TEMP\obgv xl.sys --> c:\windows\TEMP\obgvxl.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-10-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-507921405-682003330-1003Core.job
- c:\documents and settings\MSI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-20 15:41]

2010-10-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-507921405-682003330-1003UA.job
- c:\documents and settings\MSI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-20 15:41]

2010-10-15 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.ex e [2009-07-31 19:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\MSI\Application Data\DVDVideoSoftIEHelpers\youtubedownlo ad.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\MSI\Application Data\DVDVideoSoftIEHelpers\youtubetomp3. htm
TCP: {DB450707-2588-436E-954C-A02386CC9D83} = 8.8.8.8,8.8.4.4
FF - ProfilePath - c:\documents and settings\MSI\Application Data\Mozilla\Firefox\Profiles\d6k8k3mt.d efault\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSou rce=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sa/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&q=
FF - component: c:\documents and settings\MSI\Application Data\Mozilla\Firefox\Profiles\d6k8k3mt.d efault\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert .dll
FF - component: c:\documents and settings\MSI\Application Data\Mozilla\Firefox\Profiles\d6k8k3mt.d efault\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dl l
FF - plugin: c:\documents and settings\MSI\Application Data\Facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\MSI\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\MSI\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOn eClick8.dll
FF - plugin: c:\documents and settings\MSI\Local Settings\Application Data\Yahoo!\BrowserPlus\2.7.1\Plugins\np ybrowserplus_2.7.1.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll

---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true.
- - - - ORPHANS REMOVED - - - -

BHO-{64182481-4F71-486b-A045-B233BD0DA8FC} - c:\program files\facemoods.com\facemoods\1.3.61.3\f acemoods.dll
Toolbar-{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - c:\program files\facemoods.com\facemoods\1.3.61.3\f acemoodsTlbr.dll
AddRemove-facemoods - c:\program files\facemoods.com\facemoods\1.3.61.3\u ninstall.exe



Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x82EE9ACE]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75cdfc3
\Driver\ACPI -> ACPI.sys @ 0xf7460cb8
\Driver\atapi -> atapi.sys @ 0xf73f27b4
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80582414
ParseProcedure -> ntkrnlpa.exe @ 0x80581554
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80582414
ParseProcedure -> ntkrnlpa.exe @ 0x80581554
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
user & kernel MBR OK

**************************************** **********************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSI D\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system3 2\\Macromed\\Flash\\FlashUtil10h_ActiveX .exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSI D\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSI D\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flas h\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSI D\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Inte rface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Inte rface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Inte rface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(644)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(704)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(1276)
c:\windows\system32\WININET.dll
c:\program files\MessengerPlus! 3\MsgPlusLoader.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUServi ce.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.e xe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
.
**************************************** **********************************
.
Completion time: 2010-10-16 00:26:18 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-15 21:26

Pre-Run: 3,981,316,096 bytes free
Post-Run: 6,204,096,512 bytes free

- - End Of File - - 6E84BBAA0BE6E0815ABC886074BB2223


هذا اللي طلع
بالمناسبة احس الكمبيوتر اجاه شلل اطفال
بعد ما عمل ريستارت ما طلعلي الديسكتوب !!
وحتى لما اجيت احفظ هذا التقرير
حفظته على طول بالفلاش
لأنو مو طالع عندي ولا ايقونة
ولا حتى ابدأ !!
sojood غير متصل   الرد مع إقتباس
قديم 16-10-2010, 01:46 AM   #8
محب المدينه
مشرف منتدى الكمبيوتر والإنترنت
حلال مشاكل الكمبيوتر
 
الصورة الرمزية لـ محب المدينه
 
محب المدينه @ Twitter
إرسال رسالة عبر MSN إلى محب المدينه
إفتراضي

اي نعم المفروض تنتظري البرنامج الى ان ينتهي من الفحص

وعلى فكره هو حذف لك فيروسات وملفات ضارة كثيرة جدا تلقينها تحت عبارة Other Deletions هذا

بالاضافة الى منافذ مفتوحة

اضغطي على الازرة alt , ctrl , Delete معا

راح تفتح نافذة ادارة المهام

اضغطي على مهمة جديدة واكتبي فيها explorer.exe ثم اضغطي موافق وراح تظهر الايقونات ان شاء الله

واعطيني تقرير هايجاك جديد
محب المدينه غير متصل   الرد مع إقتباس
قديم 16-10-2010, 03:12 PM   #9
sojood
عضو مشارك
 
الصورة الرمزية لـ sojood
 
إفتراضي

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:14:47 م, on 16/10/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\System Control Manager\MSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUServi ce.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\System Control Manager\MGSysCtrl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.e xe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentV ersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Brothersoft Toolbar - {e8de9422-3b2c-4243-bf6f-235da84d8ef8} - C:\Program Files\Brothersoft\tbBrot.dll
R3 - URLSearchHook: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt. dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper .dll
O2 - BHO: YSPManager - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program Files\Yahoo!\Search Protection\ysp.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplu gin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_pl ugin.dll
O2 - BHO: Brothersoft Toolbar - {e8de9422-3b2c-4243-bf6f-235da84d8ef8} - C:\Program Files\Brothersoft\tbBrot.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTS ingleInstance.dll
O3 - Toolbar: Brothersoft Toolbar - {e8de9422-3b2c-4243-bf6f-235da84d8ef8} - C:\Program Files\Brothersoft\tbBrot.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt. dll
O3 - Toolbar: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessen ger.exe" -quiet
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\MSI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\MSI\Application Data\DVDVideoSoftIEHelpers\youtubedownlo ad.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\MSI\Application Data\DVDVideoSoftIEHelpers\youtubetomp3. htm
O9 - Extra button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files\iMacros\imacros.dll
O9 - Extra 'Tools' menuitem: iMacros Web Automation - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files\iMacros\imacros.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.D LL
O9 - Extra button: (no name) - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll
O9 - Extra 'Tools' menuitem: Yahoo! Search Protection - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...oUploader5.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1248064164187
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...Uploader55.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB450 707-2588-436E-954C-A02386CC9D83}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Micro Star SCM - Unknown owner - C:\Program Files\System Control Manager\MSIService.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUServi ce.exe

--
End of file - 10285 bytes
sojood غير متصل   الرد مع إقتباس
قديم 16-10-2010, 03:13 PM   #10
sojood
عضو مشارك
 
الصورة الرمزية لـ sojood
 
إفتراضي

بس اخي حبيت اخبرك ان النت اشتغل
جزئيا بالجهاز ..
يعني الحين انا لما حاولت ارسلك التقرير من جهازي ما قبل
وحتى لما جيت ابعت ايميل ما رضي
sojood غير متصل   الرد مع إقتباس
قديم 16-10-2010, 05:03 PM   #11
محب المدينه
مشرف منتدى الكمبيوتر والإنترنت
حلال مشاكل الكمبيوتر
 
الصورة الرمزية لـ محب المدينه
 
محب المدينه @ Twitter
إرسال رسالة عبر MSN إلى محب المدينه
إفتراضي

عطلي برنامج الحماية ثم استخدمي هذا البرنامج

http://vb.vip600.com/showthread.php?t=645475

........................................ ........................................ ........................................ ........

بعد اعادة التشغيل

افتحي برنامج HijackThis مرة أخرى

واضغطي على Do system system scan only

ثم ضعي اشارة صح امام الملفات التالية

R1 - HKCU\Software\Microsoft\Windows\CurrentV ersion\Internet Settings,ProxyOverride = *.local

R3 - URLSearchHook: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll

O3 - Toolbar: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll

ثم اضغطي على Fix checked

تظهر نافذة وافقي عليها

........................................ ........................................ ........................................ .....................

من اضافة وازالة البرامج احذفي

Brothersoft Toolbar

DVDVideoSoftTB Toolbar

Yahoo! Toolbar

........................................ ........................................ ........................................ ...................

ثم نظفي الجهاز ببرنامج CCleaner

شرح مختصر له

http://vb.vip600.com/showpost.php?p=...2&postcount=12

ثم اعطينا تقرير هايجاك جديد
محب المدينه غير متصل   الرد مع إقتباس
قديم 17-10-2010, 02:01 PM   #12
sojood
عضو مشارك
 
الصورة الرمزية لـ sojood
 
إفتراضي

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:41:48 ص, on 17/10/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\System Control Manager\MSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUServi ce.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\System Control Manager\MGSysCtrl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.e xe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper .dll
O2 - BHO: YSPManager - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program Files\Yahoo!\Search Protection\ysp.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplu gin.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_pl ugin.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessen ger.exe" -quiet
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\MSI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\MSI\Application Data\DVDVideoSoftIEHelpers\youtubedownlo ad.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\MSI\Application Data\DVDVideoSoftIEHelpers\youtubetomp3. htm
O9 - Extra button: iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files\iMacros\imacros.dll
O9 - Extra 'Tools' menuitem: iMacros Web Automation - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C:\Program Files\iMacros\imacros.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.D LL
O9 - Extra button: (no name) - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll
O9 - Extra 'Tools' menuitem: Yahoo! Search Protection - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...oUploader5.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1248064164187
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...Uploader55.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB450 707-2588-436E-954C-A02386CC9D83}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Micro Star SCM - Unknown owner - C:\Program Files\System Control Manager\MSIService.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUServi ce.exe

--
End of file - 9484 bytes

بس انا بالبرنامج اللي حكيتلي عنو
نسيت اعمل الخطوة الثانية ( التحليل )
سويت تنظيف على طول ..

ارجع اعيد الخطوات ؟
sojood غير متصل   الرد مع إقتباس
قديم 17-10-2010, 02:11 PM   #13
محب المدينه
مشرف منتدى الكمبيوتر والإنترنت
حلال مشاكل الكمبيوتر
 
الصورة الرمزية لـ محب المدينه
 
محب المدينه @ Twitter
إرسال رسالة عبر MSN إلى محب المدينه
إفتراضي

خلاص مايحتاج تعيدي الخطوات

اغلقي صفحات الاكسبلورر

افتحي برنامج HijackThis مرة أخرى

واضغطي على Do system system scan only

ثم ضعي اشارة صح امام الملفات التالية

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: YSPManager - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program Files\Yahoo!\Search Protection\ysp.dll

O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\MSI\Application Data\DVDVideoSoftIEHelpers\youtubetomp3. htm

O9 - Extra button: (no name) - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll

O17 - HKLM\System\CCS\Services\Tcpip\..\{DB450 707-2588-436E-954C-A02386CC9D83}: NameServer = 8.8.8.8,8.8.4.4

ثم اضغطي على Fix checked

تظهر نافذة وافقي عليه

وشوفي هل تستمر المشكلة
محب المدينه غير متصل   الرد مع إقتباس
قديم 17-10-2010, 02:33 PM   #14
sojood
عضو مشارك
 
الصورة الرمزية لـ sojood
 
إفتراضي

عملت كل شي وانشالله اذا انرسل
هذا الرد تكون انحلت المشكلة
sojood غير متصل   الرد مع إقتباس
قديم 17-10-2010, 02:34 PM   #15
sojood
عضو مشارك
 
الصورة الرمزية لـ sojood
 
إفتراضي

ياااااااااااااااااااااااااااه انا عاجزة اني اشكرك
والله ما قصرت )
sojood غير متصل   الرد مع إقتباس
المشاركة في الموضوع

العلامات المرجعية

خيارات الموضوع
طريقة العرض

قوانين المشاركة
لا تستطيع إضافة مواضيع جديدة
لا تستطيع الرد على المواضيع
لا تستطيع إرفاق ملفات
لا تستطيع تعديل مشاركاتك

BB code is متاح
كود [IMG] متاح
كود HTML غير متاح
الإنتقال السريع


جميع الأوقات بتوقيت غرينتش +3. الساعة الآن هي 03:24 PM.

 

 

 


[ برامج هامة ا أخبار التقنية ا الايفون ا الايباد ا كتب عربية ا جوالات ا الاندرويد ا جوجل ا القائمة البريدية ا مايكروسوفت ا
ابل ا سامسونج ا الجيميل ا سيري ا تصفح سريع للبرامج ا جافا ا اعلن لدينا]
عداد إقلاع سوفت