بالنسبة لتقرير الهايجاك .. هذا هو تحليلي
حذف القيم التالية
C:\Documents and Settings\USER\Application Data\Microsoft\csrss.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Documents and Settings\USER\Application Data\Microsoft\csrss.exe
C:\Documents and Settings\USER\Application Data\regsrv64.exe
C:\Documents and Settings\USER\Application Data\1C.exe
C:\Documents and Settings\USER\Application Data\1B.exe
C:\Documents and Settings\USER\Application Data\1B.exe
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O4 - HKLM\..\Run: [Spy-Net] C:\WINDOWS\system32\Spy-Net\server.exe
O4 - HKLM\..\Run: [csrss] C:\Documents and Settings\USER\Application Data\Microsoft\csrss.exe
O4 - HKLM\..\Run: [Windows Task Services] C:\Documents and Settings\USER\Application Data\1B.exe
O4 - HKLM\..\RunOnce: [Windows Task Services] C:\Documents and Settings\USER\Application Data\1B.exe
O4 - HKCU\..\Run: [Spy-Net] C:\WINDOWS\system32\Spy-Net\server.exe
O4 - HKCU\..\Run: [Microsoft DLL Registration] C:\Documents and Settings\USER\Application Data\regsrv64.exe
O4 - HKCU\..\Run: [Windows Task Services] C:\Documents and Settings\USER\Application Data\1B.exe
O4 - HKCU\..\RunOnce: [Windows Task Services] C:\Documents and Settings\USER\Application Data\1B.exe
O4 - HKLM\..\Policies\Explorer\Run: [Spy-Net] C:\WINDOWS\system32\Spy-Net\server.exe
O4 - HKLM\..\Policies\Explorer\Run: [csrss] C:\Documents and Settings\USER\Application Data\Microsoft\csrss.exe
O4 - HKLM\..\Policies\Explorer\Run: [Windows Task Services] C:\Documents and Settings\USER\Application Data\1B.exe
O4 - HKCU\..\Policies\Explorer\Run: [Spy-Net] C:\WINDOWS\system32\Spy-Net\server.exe
O4 - HKCU\..\Policies\Explorer\Run: [csrss] C:\Documents and Settings\USER\Application Data\Microsoft\csrss.exe
O4 - HKCU\..\Policies\Explorer\Run: [Windows Task Services] C:\Documents and Settings\USER\Application Data\1B.exe
O16 - DPF: {64E89DC6-8EB8-4459-82AE-408E18BB831B} (BMCCtl Class) -
O16 - DPF: {6AD8DF3E-C8FB-45E1-9EA1-440F11B628F4} (IM Class) -
O16 - DPF: {7253A666-683F-4D45-B6F1-549188BB79C0} (BMC Control) -
O16 - DPF: {7253A666-683F-4D45-B6F1-549188BB79C1} (BMC Control) -
O16 - DPF: {7253A666-6DA5-4FAE-89B3-BC419653381C} (BMC Control) -
O16 - DPF: {7253A666-804A-1107-A4DC-00E04C504708} (BMC Control) -
O16 - DPF: {7253A666-804A-1107-A4DC-00E04C504780} (BMC Control) -
O16 - DPF: {7253A666-804A-1107-A4DC-00E04C504788} (BMC Control) -
O16 - DPF: {7253A666-804A-1108-A4DC-00E04C504788} (BMChat Control) -
O16 - DPF: {7553A666-683F-4D45-B6F1-549188BB79C1} (BMC Control) -
O16 - DPF: {8246AC2B-4733-4964-A744-4BE60C6731D4} (IMS Control) -
O16 - DPF: {9024091F-CD97-41E1-B1D4-D9079409D453} (IMCv1 Control) -
O16 - DPF: {9753A666-804A-1107-A4DC-00E04C504736} (BMC Control) -
O16 - DPF: {9753A666-804A-1107-A4DC-00E04C504762} (BMC Control) -
O16 - DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} (ReadUid.UserControlMacEntry) -
O16 - DPF: {C171FF59-8C55-4796-A398-4F5D02B4C763} (IMC_Sec Control) -
O16 - DPF: {C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61} (DownloaderActiveX Control) -
O21 - SSODL: Windows Task Services - C:\Documents and Settings\USER\Application Data\1B.exe - (no file)
هذه القيمة يجب ان تحذف وهي ليست من ملفات الويندوز ومصابة
O23 - Service: Change Modem Device Service - Unknown owner - C:\WINDOWS\System32\ChgService.exe
حذف القيمة مع اعادة تثبيت مسنجر بلس
O2 - BHO: Messenger Plus Saudi - {9e1b5c68-1ab5-49fe-97a9-d3f777c51663} - C:\Program Files\Messenger_Plus_Saudi
\prxtbMess.dll
O3 - Toolbar: Messenger Plus Saudi Toolbar - {9e1b5c68-1ab5-49fe-97a9-d3f777c51663} - C:\Program Files\Messenger_Plus_Saudi\prxtbMess.dll
حذف القيمة مع اعادة تثبيت الجافا
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
رفع فايروس توتال
O4 - Startup: dxmiqroe.exe
تحليل قائمة البرامج المثبتة
حذف البرامج التالية
Conduit Engine
Messenger Plus Saudi Toolbar
يفضل تحديث البرنامج لاخر اصدار
Windows Internet Explorer 7
فحص بالبرامج التالية