ãäÊÏì ÈäÊ ÑÂÓ ÇáÎíãÉ | ÃÞáÇã áÇ ÊÊæÞÝ Úä ÇáÅÈÏÇÚ  
ßáãÉ ÇáÅÏÇÑÉ

ÇáÓáÇã Úáíßã æÑÍãÉ Çááå æÈÑßÇÊå áÌãíÚ ÇáãäÊÏíÇÊ ÇáÊí ÚãáÊ ãÚÇäÇ ÊÈÇÏá áæ ããßä ÇÑÓÇá ÇáÈäÑ æÑÇÈØ æÓãæÍå


Go Back   ãäÊÏì ÈäÊ ÑÂÓ ÇáÎíãÉ | ÃÞáÇã áÇ ÊÊæÞÝ Úä ÇáÅÈÏÇÚ > ÞÓã ÈäÊ ÑÇß ÇáÊÞäíÉ > ÈÑÇãÌ ßãÈíæÊÑ ÌÏíÏå - ÔÑæÍÇÊ ÇáÈÑÇãÌ - ÊÍãíá ÈÑÇãÌ
Register FAQ Calendar Today's Posts Search

ÈÑÇãÌ ßãÈíæÊÑ ÌÏíÏå - ÔÑæÍÇÊ ÇáÈÑÇãÌ - ÊÍãíá ÈÑÇãÌ íóÎÊÜÕ ÈÂÎÜÑ ÈÑÂãÜÌ ÇáßãÈíÜðæÊÜöÑ æÊØæíÑ ÇáãæÇÞÚ æ ÂÎÜÑ ÊØæÑÂÊåö æ Íóáö ãõÔßáÇÊåã

 
 
Thread Tools Search this Thread Display Modes
Prev Previous Post   Next Post Next
Old 10-29-2012, 05:19 AM   #1
 
Join Date: Oct 2007
Location: ÑÇß æÇáÚÇáã æÑÇß
Age: 34
Posts: 4,470
Default ãÔßáå ãÚ ÈÑäÇãÌ internet download manager

<div>ÚäÏì ãÔßáå ãÚ ÈÑäÇãÌ internet download manager

Í*Ë Çäå áÇ*Þæã ÈÇáÊÍã*á ãØáÞÇ

åÐÇ åæ ÊÞÑ*Ñ ÇáåÇ*ÌÇß
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 04:04:08 Õ, on 29/10/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\All Users\Application Data\Premium\WxDFast\WxDFast.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\PC Cleaner\PCCSmartScan.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Zyzoom_Forum_Tools\zHijak.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O1 - Hosts: 205.199.44.156 registeridm.com
O1 - Hosts: 205.199.44.16 registeridm.com
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Incredibar.com Helper Object - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incre dibar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: ãÓÇÚÏ ÊÓÌ*á ÇáÏÎæá Åáì Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Incredibar Toolbar - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredib arTlbr.dll
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [PC Cleaner] C:\Program Files\PC Cleaner\PCCLauncher.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: ÅÑ&ÓÇá Åáì OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Ê&ÕÏ*Ñ Åáì Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: ÊÍã*á Çáßá ÈæÇÓØÉ Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: ÊÍã*á ÈæÇÓØÉ Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: ÅÑÓÇá Åáì OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: ÅÑ&ÓÇá Åáì OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: ãáÇÍÙÇÊ OneNote Çáã&ÑÊÈØÉ - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: ãáÇÍÙÇÊ OneNote Çáã&ÑÊÈØÉ - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpda teService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\WINDOWS\system32\DRIVERS\xaudio.exe

--
End of file - 7993 bytes

ÊÞÑ*Ñ ÇáÈÑÇãÌ ÇáãËÈÊå
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Photoshop CS
Adobe Reader 9.1
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
Ask.com Search Assistant 1.0.2
ATI Display Driver
Bonjour
COWON Media Center - jetAudio Plus VX
FormatFactory 2.60
Golden Al-Wafi Translator
HDAUDIO Soft Data Fax Modem with SmartCP
HijackThis 2.0.2
Incredibar Toolbar on IE
Internet Download Manager
iTunes
J2SE Runtime Environment 5.0 Update 4
K-Lite Mega Codec Pack 4.7.0
Messenger Plus! Live
Microsoft Choice Guard
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (Arabic) 2010
Microsoft Office Excel MUI (Arabic) 2010
Microsoft Office Groove MUI (Arabic) 2010
Microsoft Office InfoPath MUI (Arabic) 2010
Microsoft Office OneNote MUI (Arabic) 2010
Microsoft Office Outlook MUI (Arabic) 2010
Microsoft Office PowerPoint MUI (Arabic) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (Arabic) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proofing (Arabic) 2010
Microsoft Office Publisher MUI (Arabic) 2010
Microsoft Office Shared MUI (Arabic) 2010
Microsoft Office Word MUI (Arabic) 2010
Microsoft Text-to-Speech Engine 4.0 (English)
Mozilla Firefox (3.6.27)
Mozilla Maintenance Service
mpegable Player
MSVCRT
nCleaner second 2.3.4.0
Nero 7 Ultra Edition
PC Cleaner v3.1
Picasa 3
PowerDVD
QuickTime
Realtek High Definition Audio Driver
Registry Cleaner Free
Security Update for Windows XP (KB923789)
Segoe UI
System Cleaner 6
The KMPlayer (remove only)
VLC media player 1.1.9
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Internet Explorer 8
Windows Internet Explorer 8 Multilingual User Interface (MUI)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Messenger
WinRAR archiver
WxDFast
wxDownload
ÃÏÇÉ ÇáÊÍã*á Windows Live Upload Tool
ãÓÇÚÏ ÊÓÌ*á ÇáÏÎæá Åáì Windows Live

ÊÞÑ*Ñ ãÇáææ*ÑÈÇ*Ê

Malwarebytes' Anti-Malware 1.51.2.1300
Malwarebytes : Free anti-malware download

Database version: 7622

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

29/10/2012 04:18:48 Õ
mbam-log-2012-10-29 (04-18-48).txt

Scan type: Quick scan
Objects scanned: 187811
Time elapsed: 3 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items
ÈäÊ ÑÇß is offline   Reply With Quote
 

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
ÈÑäÇãÌ Internet Download Manager 6.12+ crack 2012 ÈäÊ ÑÇß ÈÑÇãÌ ßãÈíæÊÑ ÌÏíÏå - ÔÑæÍÇÊ ÇáÈÑÇãÌ - ÊÍãíá ÈÑÇãÌ 1 11-14-2012 07:24 PM
internet download manager ÇáÑÞã ÇáÊÓáÓá*(ØáÈ ãä* æÔ ÇáÍá )ÊßÝæææä ÞäÇÕÉ ÇáÈäÇÊ ÇáÑíÇÖå ÇáÚÇáãíå 0 10-27-2012 09:32 AM
ÃÏÇÉ ÊÝÚ*á Internet Download Manager ãÏå ÇáÍ*Çå | æÇáÔÑÍ| ÈäÊ ÑÇß ÈÑÇãÌ ßãÈíæÊÑ ÌÏíÏå - ÔÑæÍÇÊ ÇáÈÑÇãÌ - ÊÍãíá ÈÑÇãÌ 0 10-27-2012 01:09 AM
ÈÑäÇãÌ Internet.Download.Manager.v6.11 ÇáÏãíÉ ÈÑÇãÌ ßãÈíæÊÑ ÌÏíÏå - ÔÑæÍÇÊ ÇáÈÑÇãÌ - ÊÍãíá ÈÑÇãÌ 1 05-05-2012 06:24 AM
ÈÑäÇãÌ ÊÍã*á ÇáãáÝÇÊ ãä Úáì ÇáÇäÊÑäÊ Internet Download Manager 6.07 Build 10 Finalþ bntrak ÈÑÇãÌ ßãÈíæÊÑ ÌÏíÏå - ÔÑæÍÇÊ ÇáÈÑÇãÌ - ÊÍãíá ÈÑÇãÌ 3 09-28-2011 05:19 PM


All times are GMT +4. The time now is 11:46 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.