من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
السلام عليكم يا شباب
نعم يا شباب الجهاز يعلق وحرارة الجهاز نارفي نار اريد حلول يا شباب تكفون
تقرير HijackThis
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 02:25:42 ص, on 15/02/12
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Zyzoom_Forum_Tools\zHijak.com
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.DLL
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: ScreenCannon.lnk = C:\Program Files\ScreenCannon\ScreenCannon.exe
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Hotspot Shield Service (hshld) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files\Hotspot Shield\bin\hsswd.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe
--
End of file - 3798 bytes
تقرير عن قائمة البرامج
====== معلومات نظام التشغيل ======
X86 WIN_7 7601 Service Pack 1
====== قائمة البرامج المثبتة ======
Adobe Flash Player 11 ActiveX
CCleaner
Hotspot Shield 2.24
Internet Download Manager
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Norton Internet Security
RefreshPC
Search-Results Toolbar
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
WinRAR 4.10 (32-بت)
Yahoo! Messenger
Your Uninstaller! 7
تقريرعن نقاط بدء التشغيل
"Silent Runners.vbs", revision 61,
Operating System: Windows 7 SP1
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"IDMan" = "C:\Program Files\Internet Download Manager\IDMan.exe /onboot" ["Tonec Inc."]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{0055C089-8582-441B-A0BF-17B458C2A3A8}\(Default) = "IDM Helper"
-> {HKLM...CLSID} = "IDM integration (IDMIEHlprObj Class)"
\InProcServer32\(Default) = "C:\Program Files\Internet Download Manager\IDMIECC.dll" ["Internet Download Manager, Tonec Inc."]
{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\(Default) = "Norton Identity Protection"
-> {HKLM...CLSID} = "Norton Identity Protection"
\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll" ["Symantec Corporation"]
{6D53EC84-6AAE-4787-AEEE-F4628F01010C}\(Default) = "Norton Vulnerability Protection"
-> {HKLM...CLSID} = "Norton Vulnerability Protection"
\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.DLL" ["Symantec Corporation"]
{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Hotspot Shield Class"
\InProcServer32\(Default) = "C:\Program Files\Hotspot Shield\HssIE\HssIE.dll" ["AnchorFree Inc."]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\
IDM Shell Extension\(Default) = "{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
-> {HKLM...CLSID} = "IDM Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Internet Download Manager\IDMShellExt.dll" ["Tonec Inc."]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
"{CDC95B92-E27C-4745-A8C5-64A52A78855D}" = "IDM Shell Extension"
-> {HKLM...CLSID} = "IDM Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Internet Download Manager\IDMShellExt.dll" ["Tonec Inc."]
HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}"
-> {HKLM...CLSID} = "IEContextMenu Class"
\InProcServer32\(Default) = ""C:\Program Files\Norton Internet Security\Engine\19.5.0.145\NavShExt.dll"" ["Symantec Corporation"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
HKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}"
-> {HKLM...CLSID} = "IEContextMenu Class"
\InProcServer32\(Default) = ""C:\Program Files\Norton Internet Security\Engine\19.5.0.145\NavShExt.dll"" ["Symantec Corporation"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
Active Desktop and Wallpaper:
-----------------------------
Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Users\windows 7\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg"
Startup items in "windows 7" & "All Users" startup folders:
-----------------------------------------------------------
C:\Users\windows 7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
"ScreenCannon" -> shortcut to: "C:\Program Files\ScreenCannon\ScreenCannon.exe" [file not found]
Non-disabled Scheduled Tasks:
-----------------------------
C:\Users\windows 7\AppData\Local\Microsoft\Windows Sidebar\Settings.ini
C:\Windows\System32\Tasks
"Norton WSC Integration" -> (HIDDEN!) launches: ""C:\Program Files\Norton Internet Security\Engine\19.5.0.145\WSCStub.exe" /taskschd" ["Symantec Corporation"]
"Scheduled Update for Ask Toolbar" -> launches: "C:\Program Files\Ask.com\UpdateTask.exe" [file not found]
C:\Windows\System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client
"AD RMS Rights Policy Template Management (Manual)" -> launches: "{BF5CB148-7C77-4d8a-A53E-D81C70CF743C}"
-> {HKLM...CLSID} = "AD RMS Rights Policy Template Management (Manual) Task Handler"
\InProcServer32\(Default) = "C:\Windows\system32\msdrm.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience
"AitAgent" -> launches: "aitagent" [MS]
"ProgramDataUpdater" -> launches: "%windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Autochk
"Proxy" -> launches: "%windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Bluetooth
"UninstallDeviceTask" -> launches: "BthUdTask.exe $(Arg0)" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\CertificateServicesClient
"SystemTask" -> launches: "{58fb76b9-ac85-4e55-ac04-427593b1d060}"
-> {HKLM...CLSID} = "Certificate Services Client Task Handler"
\InProcServer32\(Default) = "C:\Windows\system32\dimsjob.dll" [MS]
"UserTask" -> launches: "{58fb76b9-ac85-4e55-ac04-427593b1d060}"
-> {HKLM...CLSID} = "Certificate Services Client Task Handler"
\InProcServer32\(Default) = "C:\Windows\system32\dimsjob.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program
"Consolidator" -> launches: "%SystemRoot%\System32\wsqmcons.exe" [MS]
"KernelCeipTask" -> (HIDDEN!) launches: "{e7ed314f-2816-4c26-aeb5-54a34d02404c}"
-> {HKLM...CLSID} = "KernelCeipCustomHandler"
\InProcServer32\(Default) = "C:\Windows\System32\kernelceip.dll" [MS]
"UsbCeip" -> (HIDDEN!) launches: "{c27f6b1d-fe0b-45e4-9257-38799fa69bc8}"
-> {HKLM...CLSID} = "UsbCeip"
\InProcServer32\(Default) = "C:\Windows\System32\usbceip.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Defrag
"ScheduledDefrag" -> launches: "%windir%\system32\defrag.exe -c" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Diagnosis
"Scheduled" -> (HIDDEN!) launches: "{c1f85ef8-bcc2-4606-bb39-70c523715eb3}"
-> {HKLM...CLSID} = "ScheduledDiagnosticCustomHandler"
\InProcServer32\(Default) = "C:\Windows\System32\sdiagschd.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\DiskDiagnostic
"Microsoft-Windows-DiskDiagnosticDataCollector" -> (HIDDEN!) launches: "%windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Location
"Notifications" -> launches: "%windir%\System32\LocationNotifications.exe" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance
"WinSAT" -> launches: "A9A33436-678B-4c9c-A211-7CC38785E79D"" [InProcServer32 entry not found]
C:\Windows\System32\Tasks\Microsoft\Windows\MemoryDiagnostic
"CorruptionDetector" -> (HIDDEN!) launches: "{190BA3F6-0205-4f46-B589-95C6822899D2}"
-> {HKLM...CLSID} = "MemoryDiagnosticCustomHandler"
\InProcServer32\(Default) = "C:\Windows\System32\memdiag.dll" [MS]
"DecompressionFailureDetector" -> (HIDDEN!) launches: "{190BA3F6-0205-4f46-B589-95C6822899D2}"
-> {HKLM...CLSID} = "MemoryDiagnosticCustomHandler"
\InProcServer32\(Default) = "C:\Windows\System32\memdiag.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\MobilePC
"HotStart" -> launches: "{06DA0625-9701-43da-BFD7-FBEEA2180A1E}"
-> {HKLM...CLSID} = "HotStart User Agent"
\InProcServer32\(Default) = "C:\Windows\System32\HotStartUserAgent.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\MUI
"Lpksetup" -> launches: "C:\Windows\System32\lpksetup.exe -v" [MS]
"LPRemove" -> launches: "%windir%\system32\lpremove.exe" [MS]
"Mcbuilder" -> launches: "C:\Windows\System32\mcbuilder.exe" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia
"SystemSoundsService" -> launches: "{2DEA658F-54C1-4227-AF9B-260AB5FC3543}"
-> {HKLM...CLSID} = "Microsoft PlaySoundService Class"
\InProcServer32\(Default) = "C:\Windows\System32\PlaySndSrv.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\NetTrace
"GatherNetworkInfo" -> launches: "%windir%\system32\gatherNetworkInfo.vbs" [null data]
C:\Windows\System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics
"AnalyzeSystem" -> launches: "%SystemRoot%\System32\powercfg.exe -energy -auto" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\RAC
"RacTask" -> (HIDDEN!) launches: "{42060D27-CA53-41f5-96E4-B1E8169308A6}"
-> {HKLM...CLSID} = "ReliabilityAnalysisCustomHandler"
\InProcServer32\(Default) = "C:\Windows\system32\RacEngn.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Ras
"MobilityManager" -> launches: "{c463a0fc-794f-4fdf-9201-01938ceacafa}"
-> {HKLM...CLSID} = "RasMobilityManager"
\InProcServer32\(Default) = "C:\Windows\system32\rasmbmgr.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Registry
"RegIdleBackup" -> (HIDDEN!) launches: "{ca767aa8-9157-4604-b64b-40747123d5f2}"
-> {HKLM...CLSID} = "RegistryIdleBackupHandler"
\InProcServer32\(Default) = "C:\Windows\System32\regidle.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\RemoteAssistance
"RemoteAssistanceTask" -> (HIDDEN!) launches: "%windir%\system32\RAServer.exe /offerraupdate" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\SideShow
"GadgetManager" -> launches: "{FF87090D-4A9A-4f47-879B-29A80C355D61}"
-> {HKLM...CLSID} = "GadgetsManager Class"
\InProcServer32\(Default) = "C:\Windows\System32\AuxiliaryDisplayServices.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\SystemRestore
"SR" -> launches: "%windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Task Manager
"Interactive" -> (HIDDEN!) launches: "{855fec53-d2e4-4999-9e87-3414e9cf0ff4}"
-> {HKLM...CLSID} = "RunTask"
\InProcServer32\(Default) = "C:\Windows\system32\wdc.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Tcpip
"IpAddressConflict1" -> launches: "%windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem" [MS]
"IpAddressConflict2" -> launches: "%windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\TextServicesFramework
"MsCtfMonitor" -> (HIDDEN!) launches: "{01575cfe-9a55-4003-a5e1-f38d1ebdcbe1}"
-> {HKLM...CLSID} = "MsCtfMonitor task handler"
\InProcServer32\(Default) = "C:\Windows\system32\MsCtfMonitor.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Time Synchronization
"SynchronizeTime" -> launches: "%windir%\system32\sc.exe start w32time task_started" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\UPnP
"UPnPHostConfig" -> launches: "sc.exe config upnphost start= auto" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\WDI
"ResolutionHost" -> (HIDDEN!) launches: "{900be39d-6be8-461a-bc4d-b0fa71f5ecb1}"
-> {HKLM...CLSID} = "DiagnosticInfrastructureCustomHandler"
\InProcServer32\(Default) = "C:\Windows\System32\wdi.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Activation Technologies
"ValidationTask" -> (HIDDEN!) launches: "%SystemRoot%\system32\Wat\WatAdminSvc.exe /run" [MS]
"ValidationTaskDeadline" -> (HIDDEN!) launches: "%SystemRoot%\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask"" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting
"QueueReporting" -> launches: "%windir%\system32\wermgr.exe -queuereporting" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Filtering Platform
"BfeOnServiceStartTypeChange" -> (HIDDEN!) launches: "%windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\WindowsBackup
"ConfigNotification" -> launches: "%systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION" [MS]
C:\Windows\System32\Tasks\Norton Internet Security
"Norton Error Analyzer" -> launches: "C:\Program Files\Norton Internet Security\Engine\19.5.0.145\SymErr.exe /analyze" ["Symantec Corporation"]
"Norton Error Processor" -> launches: "C:\Program Files\Norton Internet Security\Engine\19.5.0.145\SymErr.exe /submit" ["Symantec Corporation"]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\system32\NLAapi.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\system32\napinsp.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
000000000004\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
000000000005\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000006\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000007\LibraryPath = "%SystemRoot%\system32\wshbth.dll" [MS]
Transport Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 37
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" = "Norton Toolbar"
-> {HKLM...CLSID} = "Norton Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll" ["Symantec Corporation"]
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
AMD External Events Utility, AMD External Events Utility, "C:\Windows\system32\atiesrxx.exe" ["AMD"]
Hotspot Shield Monitoring Service, HssWd, "C:\Program Files\Hotspot Shield\bin\hsswd.exe -product HSS" [null data]
Hotspot Shield Routing Service, HssSrv, "C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe" ["AnchorFree Inc."]
Hotspot Shield Service, hshld, "C:\Program Files\Hotspot Shield\bin\openvpnas.exe" [null data]
Norton Internet Security, NIS, ""C:\Program Files\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe" /s "NIS" /m "C:\Program Files\Norton Internet Security\Engine\19.5.0.145\diMaster.dll" /prefetch:1" ["Symantec Corporation"]
---------- (launch time: 2012-02-15 02:32:36)
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer "No" at the
first message box and "Yes" at the second message box.
---------- (total run time: 54 seconds, including 18 seconds for message boxes)
تقريرعن سجلات النظام والاخطاء
====== سجل أخطاء النظام ======
Computer Name: 37L4247F27-08
Event Code: 7036
Message: دخلت الخدمة Plug and Play في حالة stopped.
Record Number: 5
Source Name: Service Control Manager
Time Written: 20101120215742.697406-000
Event Type: معلومات
User:
Computer Name: 37L4247F27-08
Event Code: 20010
Message: قام واحد أو أكثر من الأنظمة الفرعية الخاصة بأجهزة "التوصيل والتشغيل" بتغيير الحالة.
تم تمكين النظام الفرعي لتثبيت PlugPlay: 'false'
تم تمكين النظام الفرعي للتخزين المؤقت لـ PlugPlay: 'false'
Record Number: 4
Source Name: Microsoft-Windows-UserPnp
Time Written: 20101120215742.697406-000
Event Type: معلومات
User: NT AUTHORITY\SYSTEM
Computer Name: 37L4247F27-08
Event Code: 7036
Message: دخلت الخدمة Software Protection في حالة stopped.
Record Number: 3
Source Name: Service Control Manager
Time Written: 20101120215742.479005-000
Event Type: معلومات
User:
Computer Name: 37L4247F27-08
Event Code: 7036
Message: دخلت الخدمة Windows Event Log في حالة stopped.
Record Number: 2
Source Name: Service Control Manager
Time Written: 20101120215742.338605-000
Event Type: معلومات
User:
Computer Name: 37L4247F27-08
Event Code: 7036
Message: دخلت الخدمة Volume Shadow Copy في حالة stopped.
Record Number: 1
Source Name: Service Control Manager
Time Written: 20101120215742.323005-000
Event Type: معلومات
User:
===== سجل أخطاء البرامج =====
Computer Name: 37L4247F27-08
Event Code: 1001
Message: المستودع الذي يحتوي على أخطاء , النوع 0
اسم الحدث: PnPGenericDriverFound
الاستجابة: Not available
معرف ملف الخزانة: 0
توقيع المشكلة:
P1: x86
P2: USB\VID_04F2&PID_B029&REV_5166&MI_00
P3:
P4:
P5:
P6:
P7:
P8:
P9:
P10:
الملفات المرفقة:
قد تكون هذه الملفات متوفرة هنا:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x86_b27055788b56f686db33e36e75383dcf13cace3e_cab_06b55f8c
رمز التحليل:
إعادة البحث عن حل: 0
معرف التقرير: 10aa19b4-53d3-11e1-9058-920bcc496fe0
حالة التقرير: 6
Record Number: 5
Source Name: Windows Error Reporting
Time Written: 20120210103619.000000-000
Event Type: معلومات
User:
Computer Name: 37L4247F27-08
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20120210103611.000000-000
Event Type: معلومات
User:
Computer Name: 37L4247F27-08
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20120210103607.000000-000
Event Type: معلومات
User:
Computer Name: 37L4247F27-08
Event Code: 1531
Message: بدأ تشغيل خدمة ملف تعريف المستخدم بنجاح.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20120210103601.792125-000
Event Type: معلومات
User: NT AUTHORITY\SYSTEM
Computer Name: 37L4247F27-08
Event Code: 4625
Message: يمنع النظام الفرعي EventSystem إدخالات سجل الأحداث المتكررة لمدة 86400 ثانية. يمكن التحكم في مهلة المنع بواسطة قيمة REG_DWORD تسمى SuppressDuplicateDuration تحت مفتاح التسجيل التالي: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20120210103601.000000-000
Event Type: معلومات
User:
===== السجل الأمني =====
Computer Name: 37L4247F27-08
Event Code: 4735
Message: تم تغيير مجموعة محلية ذات تأمين ممكّن.
العنوان:
معرّف الأمان: S-1-5-18
اسم الحساب: 37L4247F27-08$
مجال الحساب: WORKGROUP
معرّف تسجيل الدخول: 0x3e7
المجموعة:
معرّف الأمان: S-1-5-32-551
اسم المجموعة: Backup Operators
مجال المجموعة: Builtin
السمات التي تم تغييرها:
اسم حساب SAM: -
محفوظات معرّف الأمان: -
معلومات إضافية:
الامتيازات: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120210103527.394064-000
Event Type: تدقيق النجاح
User:
Computer Name: 37L4247F27-08
Event Code: 4731
Message: تم إنشاء مجموعة محلية ذات تأمين ممكّن.
العنوان:
معرّف الأمان: S-1-5-18
اسم الحساب: 37L4247F27-08$
مجال الحساب: WORKGROUP
معرّف تسجيل الدخول: 0x3e7
المجموعة الجديدة:
معرّف الأمان: S-1-5-32-551
اسم المجموعة: Backup Operators
مجال المجموعة: Builtin
السمات:
اسم حساب SAM: Backup Operators
محفوظات معرّف الأمان: -
معلومات إضافية:
الامتيازات: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120210103527.331664-000
Event Type: تدقيق النجاح
User:
Computer Name: 37L4247F27-08
Event Code: 4902
Message: تم إنشاء جدول نهج التدقيق لكل مستخدم.
عدد العناصر: 0
معرّف النهج: 0x2636c
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120210103526.380063-000
Event Type: تدقيق النجاح
User:
Computer Name: 37L4247F27-08
Event Code: 4624
Message: تم تسجيل دخول حساب بنجاح.
العنوان:
معرّف الأمان: S-1-0-0
اسم الحساب: -
مجال الحساب: -
معرّف تسجيل الدخول: 0x0
نوع تسجيل الدخول: 0
تسجيل الدخول الجديد:
معرّف الأمان: S-1-5-18
اسم الحساب: SYSTEM
مجال الحساب: NT AUTHORITY
معرّف تسجيل الدخول: 0x3e7
المعرّف الفريد العمومي لتسجيل الدخول: {00000000-0000-0000-0000-000000000000}
معلومات العملية:
معرّف العملية: 0x4
اسم العملية:
معلومات الشبكة:
اسم محطة العمل: -
عنوان الشبكة المصدر: -
المنفذ المصدر: -
معلومات المصادقة المفصّلة:
عملية تسجيل الدخول: -
حزمة المصادقة: -
الخدمات المنقولة: -
اسم الحزمة (NTLM فقط): -
طول المفتاح: 0
يتم تكوين هذا الحدث عند إنشاء جلسة عمل تسجيل دخول، كما يتم تكوينه على الكمبيوتر الذي تم الوصول إليه.
تشير حقول العناوين إلى حساب النظام المحلي الذي طالب بتسجيل الدخول. هذه عبارة عن خدمة بشكل عام (مثل خدمة "الخادم"، أو خدمة محلية مثل Winlogon.exe أو Services.exe).
يشير الحقل "نوع تسجيل الدخول" إلى نوع تسجيل الدخول الذي تم إجراؤه. أكثر أنواع تسجيل الدخول استخداماً هي 2 (محلي) و 3 (شبكة).
تشير حقول "تسجيل الدخول الجديد" إلى الحساب الذي تم إنشاء تسجيل الدخول له( الحساب الذي تم تسجيل الدخول إليه).
تشير حقول الشبكة إلى موقع تكوين طلب تسجيل دخول عن بُعد. لا يتوفر اسم محطة العمل دائماً وقد يُترك فارغاً في بعض الحالات.
توفر حقول معلومات المصادقة معلومات مفصّلة حول طلب تسجيل الدخول المحدد هذا.
- "معرّف تسجيل الدخول العمومي" عبارة عن معرّف فريد يمكن استخدامه للربط بين هذا الحدوث وحدث KDC.
- تشير "الخدمات المنقولة" إلى الخدمات الوسيطة التي شاركت في طلب تسجيل الدخول هذا.
- يشير "اسم الحزمة" إلى البروتوكول الثانوي الذي تم استخدامه من بين بروتوكولات NTLM.
- يشير "طول المفتاح" إلى طول مفتاح جلسة العمل الذي تم تكوينه. سيكون طول المفتاح 0 عند عدم طلب أية مفاتيح جلسات عمل.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120210103524.305259-000
Event Type: تدقيق النجاح
User:
Computer Name: 37L4247F27-08
Event Code: 4608
Message: يتم الآن بدء تشغيل Windows.
يتم تسجيل هذا الحدث عند بدء تشغيل LSASS.EXE وتهيئة نظام التدقيق.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120210103524.289659-000
Event Type: تدقيق النجاح
User:
===== تقرير انهيار البرامج =====
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:05:17 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,210
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17514_1cad2038b5de25c8c3d1da892fbc861dae7dcd4_0bf750ae\Report.wer
==================================================
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:02:45 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,210
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17514_a3e2af96656f2cead8092853be99ed724578ed_0ae90666\Report.wer
==================================================
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:05:00 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,210
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17514_abb47973de662f40821cb1040df7d2e228598_0e8f1093\Report.wer
==================================================
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:25:42 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,212
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17592_83b53f374aefaef6d5e880ed42a55ae1d85d1b3e_075e584c\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 21/03/33 04:02:57 م
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 1,978
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_15c512b4388c48b7bba116c3a8ffb3776f58432_0e841506\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:05:06 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_2319b632f84f9ac39c4cba611c574a9a5a44684_07db250d\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:22:33 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_59424622597a89f57e811ad5418c5f478fa6015_0a7b61fd\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:02:52 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_86ecfe54f94bdeed9dd7108390dc9dc34986f8d2_0d391998\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:25:53 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_8ad6d67d4583659451d42242d86ac57104fa5aa_08e66d23\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:22:33 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_a5eb16cd38b26381c3674e2ada38acebeaf1a8de_0af761fd\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:05:22 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_b78a526b4e84e316a402135e2a5a5c01228631e_0d1765a5\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:22:33 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_d738f8f2f0b83321a9c9247ba76a8291ec25918_0c77626a\Report.wer
==================================================
==================================================
Process File : QQPlayer_Setup_Arabic.exe
Event Name : مشكلة في توافق البرامج
Event Time : 18/03/33 04:35:12 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Users\windows 7\Desktop\QQPlayer_Setup_Arabic.exe
Report File Size : 2,058
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_QQPlayer_Setup_A_9c4e2ecbca2b857b758c46bfee1a205312dada7_0fcfbd55\Report.wer
==================================================
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:05:17 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,210
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17514_1cad2038b5de25c8c3d1da892fbc861dae7dcd4_0bf750ae\Report.wer
==================================================
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:02:45 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,210
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17514_a3e2af96656f2cead8092853be99ed724578ed_0ae90666\Report.wer
==================================================
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:05:00 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,210
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17514_abb47973de662f40821cb1040df7d2e228598_0e8f1093\Report.wer
==================================================
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:25:42 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,212
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17592_83b53f374aefaef6d5e880ed42a55ae1d85d1b3e_075e584c\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 21/03/33 04:02:57 م
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 1,978
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_15c512b4388c48b7bba116c3a8ffb3776f58432_0e841506\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:05:06 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_2319b632f84f9ac39c4cba611c574a9a5a44684_07db250d\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:22:33 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_59424622597a89f57e811ad5418c5f478fa6015_0a7b61fd\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:02:52 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_86ecfe54f94bdeed9dd7108390dc9dc34986f8d2_0d391998\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:25:53 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_8ad6d67d4583659451d42242d86ac57104fa5aa_08e66d23\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:22:33 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_a5eb16cd38b26381c3674e2ada38acebeaf1a8de_0af761fd\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:05:22 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_b78a526b4e84e316a402135e2a5a5c01228631e_0d1765a5\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:22:33 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_d738f8f2f0b83321a9c9247ba76a8291ec25918_0c77626a\Report.wer
==================================================
==================================================
Process File : QQPlayer_Setup_Arabic.exe
Event Name : مشكلة في توافق البرامج
Event Time : 18/03/33 04:35:12 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Users\windows 7\Desktop\QQPlayer_Setup_Arabic.exe
Report File Size : 2,058
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_QQPlayer_Setup_A_9c4e2ecbca2b857b758c46bfee1a205312dada7_0fcfbd55\Report.wer
==================================================
===== تقرير الشاشة الزرقاء =====
===== ===== ===== ===== ===== =====
اريد حلول للمشاكل وشكرا
نعم يا شباب الجهاز يعلق وحرارة الجهاز نارفي نار اريد حلول يا شباب تكفون
تقرير HijackThis
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 02:25:42 ص, on 15/02/12
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Zyzoom_Forum_Tools\zHijak.com
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.DLL
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: ScreenCannon.lnk = C:\Program Files\ScreenCannon\ScreenCannon.exe
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Hotspot Shield Service (hshld) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files\Hotspot Shield\bin\hsswd.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe
--
End of file - 3798 bytes
تقرير عن قائمة البرامج
====== معلومات نظام التشغيل ======
X86 WIN_7 7601 Service Pack 1
====== قائمة البرامج المثبتة ======
Adobe Flash Player 11 ActiveX
CCleaner
Hotspot Shield 2.24
Internet Download Manager
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Norton Internet Security
RefreshPC
Search-Results Toolbar
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
WinRAR 4.10 (32-بت)
Yahoo! Messenger
Your Uninstaller! 7
تقريرعن نقاط بدء التشغيل
"Silent Runners.vbs", revision 61,
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
Operating System: Windows 7 SP1
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"IDMan" = "C:\Program Files\Internet Download Manager\IDMan.exe /onboot" ["Tonec Inc."]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{0055C089-8582-441B-A0BF-17B458C2A3A8}\(Default) = "IDM Helper"
-> {HKLM...CLSID} = "IDM integration (IDMIEHlprObj Class)"
\InProcServer32\(Default) = "C:\Program Files\Internet Download Manager\IDMIECC.dll" ["Internet Download Manager, Tonec Inc."]
{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\(Default) = "Norton Identity Protection"
-> {HKLM...CLSID} = "Norton Identity Protection"
\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll" ["Symantec Corporation"]
{6D53EC84-6AAE-4787-AEEE-F4628F01010C}\(Default) = "Norton Vulnerability Protection"
-> {HKLM...CLSID} = "Norton Vulnerability Protection"
\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.DLL" ["Symantec Corporation"]
{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Hotspot Shield Class"
\InProcServer32\(Default) = "C:\Program Files\Hotspot Shield\HssIE\HssIE.dll" ["AnchorFree Inc."]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\
IDM Shell Extension\(Default) = "{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
-> {HKLM...CLSID} = "IDM Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Internet Download Manager\IDMShellExt.dll" ["Tonec Inc."]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
"{CDC95B92-E27C-4745-A8C5-64A52A78855D}" = "IDM Shell Extension"
-> {HKLM...CLSID} = "IDM Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Internet Download Manager\IDMShellExt.dll" ["Tonec Inc."]
HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}"
-> {HKLM...CLSID} = "IEContextMenu Class"
\InProcServer32\(Default) = ""C:\Program Files\Norton Internet Security\Engine\19.5.0.145\NavShExt.dll"" ["Symantec Corporation"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
HKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}"
-> {HKLM...CLSID} = "IEContextMenu Class"
\InProcServer32\(Default) = ""C:\Program Files\Norton Internet Security\Engine\19.5.0.145\NavShExt.dll"" ["Symantec Corporation"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" ["Alexander Roshal"]
Active Desktop and Wallpaper:
-----------------------------
Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Users\windows 7\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg"
Startup items in "windows 7" & "All Users" startup folders:
-----------------------------------------------------------
C:\Users\windows 7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
"ScreenCannon" -> shortcut to: "C:\Program Files\ScreenCannon\ScreenCannon.exe" [file not found]
Non-disabled Scheduled Tasks:
-----------------------------
C:\Users\windows 7\AppData\Local\Microsoft\Windows Sidebar\Settings.ini
C:\Windows\System32\Tasks
"Norton WSC Integration" -> (HIDDEN!) launches: ""C:\Program Files\Norton Internet Security\Engine\19.5.0.145\WSCStub.exe" /taskschd" ["Symantec Corporation"]
"Scheduled Update for Ask Toolbar" -> launches: "C:\Program Files\Ask.com\UpdateTask.exe" [file not found]
C:\Windows\System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client
"AD RMS Rights Policy Template Management (Manual)" -> launches: "{BF5CB148-7C77-4d8a-A53E-D81C70CF743C}"
-> {HKLM...CLSID} = "AD RMS Rights Policy Template Management (Manual) Task Handler"
\InProcServer32\(Default) = "C:\Windows\system32\msdrm.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience
"AitAgent" -> launches: "aitagent" [MS]
"ProgramDataUpdater" -> launches: "%windir%\system32\rundll32.exe aepdu.dll,AePduRunUpdate" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Autochk
"Proxy" -> launches: "%windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Bluetooth
"UninstallDeviceTask" -> launches: "BthUdTask.exe $(Arg0)" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\CertificateServicesClient
"SystemTask" -> launches: "{58fb76b9-ac85-4e55-ac04-427593b1d060}"
-> {HKLM...CLSID} = "Certificate Services Client Task Handler"
\InProcServer32\(Default) = "C:\Windows\system32\dimsjob.dll" [MS]
"UserTask" -> launches: "{58fb76b9-ac85-4e55-ac04-427593b1d060}"
-> {HKLM...CLSID} = "Certificate Services Client Task Handler"
\InProcServer32\(Default) = "C:\Windows\system32\dimsjob.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program
"Consolidator" -> launches: "%SystemRoot%\System32\wsqmcons.exe" [MS]
"KernelCeipTask" -> (HIDDEN!) launches: "{e7ed314f-2816-4c26-aeb5-54a34d02404c}"
-> {HKLM...CLSID} = "KernelCeipCustomHandler"
\InProcServer32\(Default) = "C:\Windows\System32\kernelceip.dll" [MS]
"UsbCeip" -> (HIDDEN!) launches: "{c27f6b1d-fe0b-45e4-9257-38799fa69bc8}"
-> {HKLM...CLSID} = "UsbCeip"
\InProcServer32\(Default) = "C:\Windows\System32\usbceip.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Defrag
"ScheduledDefrag" -> launches: "%windir%\system32\defrag.exe -c" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Diagnosis
"Scheduled" -> (HIDDEN!) launches: "{c1f85ef8-bcc2-4606-bb39-70c523715eb3}"
-> {HKLM...CLSID} = "ScheduledDiagnosticCustomHandler"
\InProcServer32\(Default) = "C:\Windows\System32\sdiagschd.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\DiskDiagnostic
"Microsoft-Windows-DiskDiagnosticDataCollector" -> (HIDDEN!) launches: "%windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Location
"Notifications" -> launches: "%windir%\System32\LocationNotifications.exe" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance
"WinSAT" -> launches: "A9A33436-678B-4c9c-A211-7CC38785E79D"" [InProcServer32 entry not found]
C:\Windows\System32\Tasks\Microsoft\Windows\MemoryDiagnostic
"CorruptionDetector" -> (HIDDEN!) launches: "{190BA3F6-0205-4f46-B589-95C6822899D2}"
-> {HKLM...CLSID} = "MemoryDiagnosticCustomHandler"
\InProcServer32\(Default) = "C:\Windows\System32\memdiag.dll" [MS]
"DecompressionFailureDetector" -> (HIDDEN!) launches: "{190BA3F6-0205-4f46-B589-95C6822899D2}"
-> {HKLM...CLSID} = "MemoryDiagnosticCustomHandler"
\InProcServer32\(Default) = "C:\Windows\System32\memdiag.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\MobilePC
"HotStart" -> launches: "{06DA0625-9701-43da-BFD7-FBEEA2180A1E}"
-> {HKLM...CLSID} = "HotStart User Agent"
\InProcServer32\(Default) = "C:\Windows\System32\HotStartUserAgent.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\MUI
"Lpksetup" -> launches: "C:\Windows\System32\lpksetup.exe -v" [MS]
"LPRemove" -> launches: "%windir%\system32\lpremove.exe" [MS]
"Mcbuilder" -> launches: "C:\Windows\System32\mcbuilder.exe" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia
"SystemSoundsService" -> launches: "{2DEA658F-54C1-4227-AF9B-260AB5FC3543}"
-> {HKLM...CLSID} = "Microsoft PlaySoundService Class"
\InProcServer32\(Default) = "C:\Windows\System32\PlaySndSrv.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\NetTrace
"GatherNetworkInfo" -> launches: "%windir%\system32\gatherNetworkInfo.vbs" [null data]
C:\Windows\System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics
"AnalyzeSystem" -> launches: "%SystemRoot%\System32\powercfg.exe -energy -auto" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\RAC
"RacTask" -> (HIDDEN!) launches: "{42060D27-CA53-41f5-96E4-B1E8169308A6}"
-> {HKLM...CLSID} = "ReliabilityAnalysisCustomHandler"
\InProcServer32\(Default) = "C:\Windows\system32\RacEngn.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Ras
"MobilityManager" -> launches: "{c463a0fc-794f-4fdf-9201-01938ceacafa}"
-> {HKLM...CLSID} = "RasMobilityManager"
\InProcServer32\(Default) = "C:\Windows\system32\rasmbmgr.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Registry
"RegIdleBackup" -> (HIDDEN!) launches: "{ca767aa8-9157-4604-b64b-40747123d5f2}"
-> {HKLM...CLSID} = "RegistryIdleBackupHandler"
\InProcServer32\(Default) = "C:\Windows\System32\regidle.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\RemoteAssistance
"RemoteAssistanceTask" -> (HIDDEN!) launches: "%windir%\system32\RAServer.exe /offerraupdate" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\SideShow
"GadgetManager" -> launches: "{FF87090D-4A9A-4f47-879B-29A80C355D61}"
-> {HKLM...CLSID} = "GadgetsManager Class"
\InProcServer32\(Default) = "C:\Windows\System32\AuxiliaryDisplayServices.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\SystemRestore
"SR" -> launches: "%windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Task Manager
"Interactive" -> (HIDDEN!) launches: "{855fec53-d2e4-4999-9e87-3414e9cf0ff4}"
-> {HKLM...CLSID} = "RunTask"
\InProcServer32\(Default) = "C:\Windows\system32\wdc.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Tcpip
"IpAddressConflict1" -> launches: "%windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem" [MS]
"IpAddressConflict2" -> launches: "%windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\TextServicesFramework
"MsCtfMonitor" -> (HIDDEN!) launches: "{01575cfe-9a55-4003-a5e1-f38d1ebdcbe1}"
-> {HKLM...CLSID} = "MsCtfMonitor task handler"
\InProcServer32\(Default) = "C:\Windows\system32\MsCtfMonitor.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Time Synchronization
"SynchronizeTime" -> launches: "%windir%\system32\sc.exe start w32time task_started" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\UPnP
"UPnPHostConfig" -> launches: "sc.exe config upnphost start= auto" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\WDI
"ResolutionHost" -> (HIDDEN!) launches: "{900be39d-6be8-461a-bc4d-b0fa71f5ecb1}"
-> {HKLM...CLSID} = "DiagnosticInfrastructureCustomHandler"
\InProcServer32\(Default) = "C:\Windows\System32\wdi.dll" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Activation Technologies
"ValidationTask" -> (HIDDEN!) launches: "%SystemRoot%\system32\Wat\WatAdminSvc.exe /run" [MS]
"ValidationTaskDeadline" -> (HIDDEN!) launches: "%SystemRoot%\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask"" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Error Reporting
"QueueReporting" -> launches: "%windir%\system32\wermgr.exe -queuereporting" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\Windows Filtering Platform
"BfeOnServiceStartTypeChange" -> (HIDDEN!) launches: "%windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange" [MS]
C:\Windows\System32\Tasks\Microsoft\Windows\WindowsBackup
"ConfigNotification" -> launches: "%systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION" [MS]
C:\Windows\System32\Tasks\Norton Internet Security
"Norton Error Analyzer" -> launches: "C:\Program Files\Norton Internet Security\Engine\19.5.0.145\SymErr.exe /analyze" ["Symantec Corporation"]
"Norton Error Processor" -> launches: "C:\Program Files\Norton Internet Security\Engine\19.5.0.145\SymErr.exe /submit" ["Symantec Corporation"]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\system32\NLAapi.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\system32\napinsp.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
000000000004\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
000000000005\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000006\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000007\LibraryPath = "%SystemRoot%\system32\wshbth.dll" [MS]
Transport Service Providers
HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 37
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" = "Norton Toolbar"
-> {HKLM...CLSID} = "Norton Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Engine\19.5.0.145\coIEPlg.dll" ["Symantec Corporation"]
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
AMD External Events Utility, AMD External Events Utility, "C:\Windows\system32\atiesrxx.exe" ["AMD"]
Hotspot Shield Monitoring Service, HssWd, "C:\Program Files\Hotspot Shield\bin\hsswd.exe -product HSS" [null data]
Hotspot Shield Routing Service, HssSrv, "C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe" ["AnchorFree Inc."]
Hotspot Shield Service, hshld, "C:\Program Files\Hotspot Shield\bin\openvpnas.exe" [null data]
Norton Internet Security, NIS, ""C:\Program Files\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe" /s "NIS" /m "C:\Program Files\Norton Internet Security\Engine\19.5.0.145\diMaster.dll" /prefetch:1" ["Symantec Corporation"]
---------- (launch time: 2012-02-15 02:32:36)
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer "No" at the
first message box and "Yes" at the second message box.
---------- (total run time: 54 seconds, including 18 seconds for message boxes)
تقريرعن سجلات النظام والاخطاء
====== سجل أخطاء النظام ======
Computer Name: 37L4247F27-08
Event Code: 7036
Message: دخلت الخدمة Plug and Play في حالة stopped.
Record Number: 5
Source Name: Service Control Manager
Time Written: 20101120215742.697406-000
Event Type: معلومات
User:
Computer Name: 37L4247F27-08
Event Code: 20010
Message: قام واحد أو أكثر من الأنظمة الفرعية الخاصة بأجهزة "التوصيل والتشغيل" بتغيير الحالة.
تم تمكين النظام الفرعي لتثبيت PlugPlay: 'false'
تم تمكين النظام الفرعي للتخزين المؤقت لـ PlugPlay: 'false'
Record Number: 4
Source Name: Microsoft-Windows-UserPnp
Time Written: 20101120215742.697406-000
Event Type: معلومات
User: NT AUTHORITY\SYSTEM
Computer Name: 37L4247F27-08
Event Code: 7036
Message: دخلت الخدمة Software Protection في حالة stopped.
Record Number: 3
Source Name: Service Control Manager
Time Written: 20101120215742.479005-000
Event Type: معلومات
User:
Computer Name: 37L4247F27-08
Event Code: 7036
Message: دخلت الخدمة Windows Event Log في حالة stopped.
Record Number: 2
Source Name: Service Control Manager
Time Written: 20101120215742.338605-000
Event Type: معلومات
User:
Computer Name: 37L4247F27-08
Event Code: 7036
Message: دخلت الخدمة Volume Shadow Copy في حالة stopped.
Record Number: 1
Source Name: Service Control Manager
Time Written: 20101120215742.323005-000
Event Type: معلومات
User:
===== سجل أخطاء البرامج =====
Computer Name: 37L4247F27-08
Event Code: 1001
Message: المستودع الذي يحتوي على أخطاء , النوع 0
اسم الحدث: PnPGenericDriverFound
الاستجابة: Not available
معرف ملف الخزانة: 0
توقيع المشكلة:
P1: x86
P2: USB\VID_04F2&PID_B029&REV_5166&MI_00
P3:
P4:
P5:
P6:
P7:
P8:
P9:
P10:
الملفات المرفقة:
قد تكون هذه الملفات متوفرة هنا:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x86_b27055788b56f686db33e36e75383dcf13cace3e_cab_06b55f8c
رمز التحليل:
إعادة البحث عن حل: 0
معرف التقرير: 10aa19b4-53d3-11e1-9058-920bcc496fe0
حالة التقرير: 6
Record Number: 5
Source Name: Windows Error Reporting
Time Written: 20120210103619.000000-000
Event Type: معلومات
User:
Computer Name: 37L4247F27-08
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20120210103611.000000-000
Event Type: معلومات
User:
Computer Name: 37L4247F27-08
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20120210103607.000000-000
Event Type: معلومات
User:
Computer Name: 37L4247F27-08
Event Code: 1531
Message: بدأ تشغيل خدمة ملف تعريف المستخدم بنجاح.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20120210103601.792125-000
Event Type: معلومات
User: NT AUTHORITY\SYSTEM
Computer Name: 37L4247F27-08
Event Code: 4625
Message: يمنع النظام الفرعي EventSystem إدخالات سجل الأحداث المتكررة لمدة 86400 ثانية. يمكن التحكم في مهلة المنع بواسطة قيمة REG_DWORD تسمى SuppressDuplicateDuration تحت مفتاح التسجيل التالي: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20120210103601.000000-000
Event Type: معلومات
User:
===== السجل الأمني =====
Computer Name: 37L4247F27-08
Event Code: 4735
Message: تم تغيير مجموعة محلية ذات تأمين ممكّن.
العنوان:
معرّف الأمان: S-1-5-18
اسم الحساب: 37L4247F27-08$
مجال الحساب: WORKGROUP
معرّف تسجيل الدخول: 0x3e7
المجموعة:
معرّف الأمان: S-1-5-32-551
اسم المجموعة: Backup Operators
مجال المجموعة: Builtin
السمات التي تم تغييرها:
اسم حساب SAM: -
محفوظات معرّف الأمان: -
معلومات إضافية:
الامتيازات: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120210103527.394064-000
Event Type: تدقيق النجاح
User:
Computer Name: 37L4247F27-08
Event Code: 4731
Message: تم إنشاء مجموعة محلية ذات تأمين ممكّن.
العنوان:
معرّف الأمان: S-1-5-18
اسم الحساب: 37L4247F27-08$
مجال الحساب: WORKGROUP
معرّف تسجيل الدخول: 0x3e7
المجموعة الجديدة:
معرّف الأمان: S-1-5-32-551
اسم المجموعة: Backup Operators
مجال المجموعة: Builtin
السمات:
اسم حساب SAM: Backup Operators
محفوظات معرّف الأمان: -
معلومات إضافية:
الامتيازات: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120210103527.331664-000
Event Type: تدقيق النجاح
User:
Computer Name: 37L4247F27-08
Event Code: 4902
Message: تم إنشاء جدول نهج التدقيق لكل مستخدم.
عدد العناصر: 0
معرّف النهج: 0x2636c
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120210103526.380063-000
Event Type: تدقيق النجاح
User:
Computer Name: 37L4247F27-08
Event Code: 4624
Message: تم تسجيل دخول حساب بنجاح.
العنوان:
معرّف الأمان: S-1-0-0
اسم الحساب: -
مجال الحساب: -
معرّف تسجيل الدخول: 0x0
نوع تسجيل الدخول: 0
تسجيل الدخول الجديد:
معرّف الأمان: S-1-5-18
اسم الحساب: SYSTEM
مجال الحساب: NT AUTHORITY
معرّف تسجيل الدخول: 0x3e7
المعرّف الفريد العمومي لتسجيل الدخول: {00000000-0000-0000-0000-000000000000}
معلومات العملية:
معرّف العملية: 0x4
اسم العملية:
معلومات الشبكة:
اسم محطة العمل: -
عنوان الشبكة المصدر: -
المنفذ المصدر: -
معلومات المصادقة المفصّلة:
عملية تسجيل الدخول: -
حزمة المصادقة: -
الخدمات المنقولة: -
اسم الحزمة (NTLM فقط): -
طول المفتاح: 0
يتم تكوين هذا الحدث عند إنشاء جلسة عمل تسجيل دخول، كما يتم تكوينه على الكمبيوتر الذي تم الوصول إليه.
تشير حقول العناوين إلى حساب النظام المحلي الذي طالب بتسجيل الدخول. هذه عبارة عن خدمة بشكل عام (مثل خدمة "الخادم"، أو خدمة محلية مثل Winlogon.exe أو Services.exe).
يشير الحقل "نوع تسجيل الدخول" إلى نوع تسجيل الدخول الذي تم إجراؤه. أكثر أنواع تسجيل الدخول استخداماً هي 2 (محلي) و 3 (شبكة).
تشير حقول "تسجيل الدخول الجديد" إلى الحساب الذي تم إنشاء تسجيل الدخول له( الحساب الذي تم تسجيل الدخول إليه).
تشير حقول الشبكة إلى موقع تكوين طلب تسجيل دخول عن بُعد. لا يتوفر اسم محطة العمل دائماً وقد يُترك فارغاً في بعض الحالات.
توفر حقول معلومات المصادقة معلومات مفصّلة حول طلب تسجيل الدخول المحدد هذا.
- "معرّف تسجيل الدخول العمومي" عبارة عن معرّف فريد يمكن استخدامه للربط بين هذا الحدوث وحدث KDC.
- تشير "الخدمات المنقولة" إلى الخدمات الوسيطة التي شاركت في طلب تسجيل الدخول هذا.
- يشير "اسم الحزمة" إلى البروتوكول الثانوي الذي تم استخدامه من بين بروتوكولات NTLM.
- يشير "طول المفتاح" إلى طول مفتاح جلسة العمل الذي تم تكوينه. سيكون طول المفتاح 0 عند عدم طلب أية مفاتيح جلسات عمل.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120210103524.305259-000
Event Type: تدقيق النجاح
User:
Computer Name: 37L4247F27-08
Event Code: 4608
Message: يتم الآن بدء تشغيل Windows.
يتم تسجيل هذا الحدث عند بدء تشغيل LSASS.EXE وتهيئة نظام التدقيق.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120210103524.289659-000
Event Type: تدقيق النجاح
User:
===== تقرير انهيار البرامج =====
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:05:17 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,210
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17514_1cad2038b5de25c8c3d1da892fbc861dae7dcd4_0bf750ae\Report.wer
==================================================
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:02:45 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,210
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17514_a3e2af96656f2cead8092853be99ed724578ed_0ae90666\Report.wer
==================================================
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:05:00 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,210
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17514_abb47973de662f40821cb1040df7d2e228598_0e8f1093\Report.wer
==================================================
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:25:42 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,212
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17592_83b53f374aefaef6d5e880ed42a55ae1d85d1b3e_075e584c\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 21/03/33 04:02:57 م
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 1,978
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_15c512b4388c48b7bba116c3a8ffb3776f58432_0e841506\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:05:06 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_2319b632f84f9ac39c4cba611c574a9a5a44684_07db250d\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:22:33 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_59424622597a89f57e811ad5418c5f478fa6015_0a7b61fd\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:02:52 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_86ecfe54f94bdeed9dd7108390dc9dc34986f8d2_0d391998\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:25:53 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_8ad6d67d4583659451d42242d86ac57104fa5aa_08e66d23\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:22:33 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_a5eb16cd38b26381c3674e2ada38acebeaf1a8de_0af761fd\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:05:22 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_b78a526b4e84e316a402135e2a5a5c01228631e_0d1765a5\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:22:33 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_d738f8f2f0b83321a9c9247ba76a8291ec25918_0c77626a\Report.wer
==================================================
==================================================
Process File : QQPlayer_Setup_Arabic.exe
Event Name : مشكلة في توافق البرامج
Event Time : 18/03/33 04:35:12 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Users\windows 7\Desktop\QQPlayer_Setup_Arabic.exe
Report File Size : 2,058
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_QQPlayer_Setup_A_9c4e2ecbca2b857b758c46bfee1a205312dada7_0fcfbd55\Report.wer
==================================================
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:05:17 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,210
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17514_1cad2038b5de25c8c3d1da892fbc861dae7dcd4_0bf750ae\Report.wer
==================================================
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:02:45 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,210
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17514_a3e2af96656f2cead8092853be99ed724578ed_0ae90666\Report.wer
==================================================
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:05:00 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,210
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17514_abb47973de662f40821cb1040df7d2e228598_0e8f1093\Report.wer
==================================================
==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 18/03/33 03:25:42 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,212
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17592_83b53f374aefaef6d5e880ed42a55ae1d85d1b3e_075e584c\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 21/03/33 04:02:57 م
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 1,978
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_15c512b4388c48b7bba116c3a8ffb3776f58432_0e841506\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:05:06 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_2319b632f84f9ac39c4cba611c574a9a5a44684_07db250d\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:22:33 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_59424622597a89f57e811ad5418c5f478fa6015_0a7b61fd\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:02:52 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_86ecfe54f94bdeed9dd7108390dc9dc34986f8d2_0d391998\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:25:53 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_8ad6d67d4583659451d42242d86ac57104fa5aa_08e66d23\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:22:33 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_a5eb16cd38b26381c3674e2ada38acebeaf1a8de_0af761fd\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:05:22 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_b78a526b4e84e316a402135e2a5a5c01228631e_0d1765a5\Report.wer
==================================================
==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 18/03/33 03:22:33 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,092
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_d738f8f2f0b83321a9c9247ba76a8291ec25918_0c77626a\Report.wer
==================================================
==================================================
Process File : QQPlayer_Setup_Arabic.exe
Event Name : مشكلة في توافق البرامج
Event Time : 18/03/33 04:35:12 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Users\windows 7\Desktop\QQPlayer_Setup_Arabic.exe
Report File Size : 2,058
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_QQPlayer_Setup_A_9c4e2ecbca2b857b758c46bfee1a205312dada7_0fcfbd55\Report.wer
==================================================
===== تقرير الشاشة الزرقاء =====
===== ===== ===== ===== ===== =====
اريد حلول للمشاكل وشكرا
