احترف | مع مدونه احترف , احترف كل شئ

الاثنين، 29 يونيو 2015

احترف ازاله البرامج المسببه ف ازعاج جهازك ومتصفحك بالاعلانات


السلام عليكم ورحمه الله وبركاته
اهلا بكم اعضاء مدونه احترف
كثير منا عندما يتصفح الانترنت يجد المتصفح ملئ بالإعلانات
ليس الموقع بل اقول المتصفح اعلانات مزعجه فى كل مكان
ثم مره واحده تجد اعلانا يظهر يمنعك من الدخول الى الموقع

الان وداعا لهذه المشكله مع هذا البرنامج الرائع
adwcleaner
هذا البرنامج يقوم بالبحث فى ملفات جهازك عن هذه البرامج الخبيثه
ثم يقوم بعمل حذف لها
حجم البرنامج 2 ميجا
نأتى للشرح والتحميل
نقوم بتحميل البرنامج من هنا

ثم نقوم بفتح البرنامج والموافقه على سياسه الاستخدام


 ثم الضغط على Scan
ستجد الفيروسات واماكن الملفات موضحه امامك
 وبعد الانتهاء من التحميل نضغط cleaning


سيتم اغلاق البرامح المفتوحه
ثم وافق على اعاده تشغيل الجهاز
الى هنا قد نكون انتهينا
شكرا لكم وانتظرونا فى شرح قادم يفيدنا ويفيدكم باذن الله
والسلام عليكم ورحمه الله وبركاته



ملخص ما تم ازالته
يظهر بعد فتح الجهاز

# AdwCleaner v4.207 - Logfile created 30/06/2015 at 03:42:56
# Updated 21/06/2015 by Xplode
# Database : 2015-06-21.1 [Local]
# Operating system : Windows 8.1 Enterprise  (x86)
# Username : LOTUS.PC - LOTUS
# Running from : C:\Users\LOTUS.PC\Downloads\Programs\adwcleaner_4.207.exe
# Option : Cleaning

***** [ Services ] *****

[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
[#] Service Deleted : PanService

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\tencent
Folder Deleted : C:\Program Files\globalUpdate
Folder Deleted : C:\Program Files\PANDORA.TV
Folder Deleted : C:\Program Files\tencent
Folder Deleted : C:\Program Files\Common Files\tencent
Folder Deleted : C:\Users\LOTUS.PC\AppData\Local\globalUpdate
Folder Deleted : C:\Users\LOTUS.PC\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\LOTUS.PC\AppData\Roaming\tencent
Folder Deleted : C:\Users\LOTUS.PC\AppData\Roaming\cpuminer
Folder Deleted : C:\Users\LOTUS.PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjbbjfdilbioabojmcplalojlmdngbjl
Folder Deleted : C:\Users\LOTUS.PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\flogpfmjdekjoilcnmmchanikomlidie
Folder Deleted : C:\Users\LOTUS.PC\AppData\Roaming\Opera Software\Opera Stable\Extensions\fjbbjfdilbioabojmcplalojlmdngbjl
Folder Deleted : C:\Users\LOTUS.PC\AppData\Roaming\Opera Software\Opera Stable\Extensions\flogpfmjdekjoilcnmmchanikomlidie
File Deleted : C:\Users\LOTUS.PC\AppData\Roaming\Mozilla\Firefox\Profiles\r0xqqtnr.default\searchplugins\oursurfing.xml
File Deleted : C:\Program Files\Mozilla Firefox\browser\defaults\preferences\prefs.js
File Deleted : C:\Users\LOTUS.PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.oursurfing.com_0.localstorage
File Deleted : C:\Users\LOTUS.PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.oursurfing.com_0.localstorage-journal

***** [ Scheduled tasks ] *****

Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : amiupdaterExd
Task Deleted : amiupdaterExi

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [sweetsearch@gmail.com]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [searchffv2@gmail.com]
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKCU\Software\Mozilla\Extends
Key Deleted : HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\globalupdate.exe
Key Deleted : HKLM\SOFTWARE\CLASSES\METNSD
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules [TCP Query User{066D1512-7BC2-402E-BE8C-AD3D7203FD6E}C:\program files\baidu\spark\bdtray.exe]
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\sharedaccess\Parameters\FirewallPolicy\FirewallRules [UDP Query User{F0643E38-2AFD-4F75-A020-E6E3D2EC66F2}C:\program files\baidu\spark\bdtray.exe]
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\Crossbrowse
Key Deleted : HKCU\Software\YorkNewCin
Key Deleted : HKCU\Software\HighDefAction
Key Deleted : HKCU\Software\ArenaHD
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\Crossbrowse
Key Deleted : HKLM\SOFTWARE\YorkNewCin
Key Deleted : HKLM\SOFTWARE\HighDefAction
Key Deleted : HKLM\SOFTWARE\oursurfingSoftware
Key Deleted : HKLM\SOFTWARE\ArenaHD
Key Deleted : HKLM\SOFTWARE\FFPluginHp
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\QQPlayer
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\globalupdate.exe

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17037

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Mozilla Firefox v38.0.5 (x86 en-US)

[r0xqqtnr.default\prefs.js] - Line Deleted : user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");
[r0xqqtnr.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.alias", "oursurfing");
[r0xqqtnr.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.iconURL", "hxxp://www.oursurfing.com/favicon.ico");
[r0xqqtnr.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.name", "oursurfing");
[r0xqqtnr.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.url", "hxxp://www.oursurfing.com/web/?type=ds&ts=1435077691&z=a5096d747da37c6f2648973g5zcc8w6ebm3m5q9t1g&from=amt&uid=TOSHIBAXMQ01ABF050_63LESIXXSXX63LESIXXS&q={[...]
[r0xqqtnr.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "oursurfing");
[r0xqqtnr.default\prefs.js] - Line Deleted : user_pref("extensions.crossrider.bic", "14e269bdcbc88533ceec00fe626799c4");
[r0xqqtnr.default\prefs.js] - Line Deleted : user_pref("extensions.quick_start.enable_search1", false);
[r0xqqtnr.default\prefs.js] - Line Deleted : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);

-\\ Google Chrome v43.0.2357.130

[C:\Users\LOTUS.PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.oursurfing.com/web/?type=ds&ts=1435077691&z=a5096d747da37c6f2648973g5zcc8w6ebm3m5q9t1g&from=amt&uid=TOSHIBAXMQ01ABF050_63LESIXXSXX63LESIXXS&q={searchTerms}
[C:\Users\LOTUS.PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Homepage] : hxxp://www.oursurfing.com/?type=hp&ts=1435077691&z=a5096d747da37c6f2648973g5zcc8w6ebm3m5q9t1g&from=amt&uid=TOSHIBAXMQ01ABF050_63LESIXXSXX63LESIXXS
[C:\Users\LOTUS.PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Startup_URLs] : 6C0CC661C9C4E707688202BE3BF29D9E4B56BBD3556B90D1E8C001616A276E33"},"software_reporter":{"prompt_reason":"485A366BDEEFBF202BEFA38C71E8443DD817790B6B2E681EF7FE2C16791E0F3B","prompt_seed":"ADD4F05C910EEBD0170FB42092D698CF493F34F3757A16613AAAEA8D57D0D3FC","prompt_version":"DB461A77225F3F3E021D6913F77E99471CC9703662649EF04D560E2223881D98"},"sync":{"remaining_rollback_tries":"2610547650972FCF406E47F1A32073A522B47D7C15FFACA128A505EDD132233A"}},"super_mac":"279526485C95621FCA22487063F785A3F0B41F6928E6FA91735640B0F9FFD46E"},"session":{"restore_on_startup":4,"startup_urls":["hxxp://www.oursurfing.com/?type=hp&ts=1435077691&z=a5096d747da37c6f2648973g5zcc8w6ebm3m5q9t1g&from=amt&uid=TOSHIBAXMQ01ABF050_63LESIXXSXX63LESIXXS

-\\ Opera v30.0.1835.88


*************************

AdwCleaner[R0].txt - [12962 bytes] - [30/06/2015 03:41:41]
AdwCleaner[S0].txt - [12093 bytes] - [30/06/2015 03:42:56]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12153  bytes] ##########

0 التعليقات:

إرسال تعليق