بلال مقداد

زيزوومي جديد
إنضم
6 مارس 2012
المشاركات
7
مستوى التفاعل
0
النقاط
0
غير متصل
بسم الله الرحمن الرحيم
عندي مشكلة يا جماعة مع انو جهازي جديد لاب توب
hp pavillion g6
ram 4 gb
ati 1gb
cpu core i5

وهاي الصور تم التقاطها من الشاشة الزرقاء التي تظهر
1
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

2
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
 

وهاي التقارير التي وجدت من البرنامج
1
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:21:44 ص, on 06/03/12
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16930)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Lock Folder XP\LFService.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\Integrator.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\Hotspot Shield\bin\openvpntray.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Zyzoom_Forum_Tools\zHijak.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [LFService] C:\Program Files (x86)\Lock Folder XP\LFService.exe -start
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\BlabLoOo\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: AntiCrash.lnk = C:\Program Files (x86)\Dachshund Software\AntiCrash\AntiCrash.exe
O8 - Extra context menu item: ت&صدير إلى Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{A41CFCA1-EC90-436F-953C-63D0F87E2D4B}: NameServer = 10.66.8.1
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Hotspot Shield Service (hshld) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8226 bytes

2
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي
 
3

QuickScan 32-bit v0.9.9.109
---------------------------
Scan date: Wed Mar 07 20:46:11 2012
Machine ID: BEE90D24



No infection found.
-------------------



Processes
---------
avast! Antivirus 2812 C:\Program Files\AVAST Software\Avast\AvastUI.exe
Dachshund Integrator 1696 C:\Windows\Integrator.exe
Firefox 6760 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Firefox 5248 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
IEMonitor Application 2628 C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
Internet Download Manager (IDM) 2728 C:\Program Files (x86)\Internet Download Manager\IDMan.exe
Java(TM) Platform SE Auto Updater 2 0 2624 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
LFService.exe 2328 C:\Program Files (x86)\Lock Folder XP\LFService.exe
openvpntray.exe 3948 C:\Program Files (x86)\Hotspot Shield\bin\openvpntray.exe
Windows Live Messenger 2884 C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
YCMMirag Application 3700 C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe


Network activity
----------------
Process firefox.exe (6760) connected on port 443 (HTTP over SSL) --> 69.171.228.14
Process firefox.exe (6760) connected on port 443 (HTTP over SSL) --> 209.85.147.139



Autoruns and critical files
---------------------------
AntiCrash.exe C:\Program Files (x86)\Dachshund Software\AntiCrash\AntiCrash.exe
avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastUI.exe
Catalyst® Control Center C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
Facebook Update C:\Users\BlabLoOo\AppData\Local\Facebook\Update\FacebookUpdate.exe
Internet Download Manager (IDM) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
Java(TM) Platform SE Auto Updater 2 0 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
LFService.exe C:\Program Files (x86)\Lock Folder XP\LFService.exe
Microsoft® Windows® Operating System C:\Program Files\Windows Sidebar\sidebar.exe
Mozilla Firefox C:\Program Files (x86)\Mozilla Firefox
Windows Live Messenger C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
(verified) Microsoft® Windows® Operating System C:\Windows\system32\userinit.exe


Browser plugins
---------------
avast! WebRep c:\program files\avast software\avast\aswwebrepie.dll
Bitdefender QuickScan C:\Users\BlabLoOo\AppData\Roaming\Mozilla\Firefox\Profiles\wdnmn2o5.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
Facebook Video Calling Plugin C:\Users\BlabLoOo\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
hssie.dll c:\program files (x86)\hotspot shield\hssie\hssie.dll
Internet Download Manager Module c:\program files (x86)\internet download manager\idmiecc.dll
Java(TM) Platform SE 6 U27 c:\program files (x86)\java\jre6\bin\jp2ssv.dll
Java(TM) Platform SE 6 U27 C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL
Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL
Microsoft Office 2010 c:\program files (x86)\microsoft office\office14\urlredir.dll
Microsoft® Windows® Operating System C:\Windows\system32\wshbth.dll
NPSWF32.dll C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
Windows® Internet Explorer C:\Windows\SysWOW64\ieframe.dll
(verified) Microsoft® Windows Live Login Helper c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll
(verified) Microsoft® Windows® Operating System C:\Windows\System32\mswsock.dll
(verified) Microsoft® Windows® Operating System C:\Windows\system32\napinsp.dll
(verified) Microsoft® Windows® Operating System C:\Windows\system32\NLAapi.dll
(verified) Microsoft® Windows® Operating System C:\Windows\system32\pnrpnsp.dll
(verified) Microsoft® Windows® Operating System C:\Windows\System32\winrnr.dll


Scan
----
MD5: 92b79a04e8d0a09107e63e4974330fe9 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
MD5: 6e3245df783e58375b3465f03274743e C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
MD5: b7f55e2ae978d3d34f7876ee5d689aae C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
MD5: d650e0bb24c1c4d796fd2e88e8fdfeff C:\Program Files (x86)\Dachshund Software\AntiCrash\AntiCrash.exe
MD5: 6b1dc08d22231c9e508a715f07fce7fb C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
MD5: 564bab77cd96ce0e3fd5bbcdded142df C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
MD5: 037fc5e0c45da0764efa199e00fd5ba5 C:\Program Files (x86)\Hotspot Shield\bin\lang\gui-eng.dll
MD5: 44452f7a09d00573dc6e714874257cc9 C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
MD5: 44c528f5fb662ab74fdfae1688ef35c6 C:\Program Files (x86)\Hotspot Shield\bin\openvpntray.exe
MD5: dd56e3271d8d63d655454b3f5c0f5c01 c:\program files (x86)\hotspot shield\hssie\hssie.dll
MD5: 2cfea9c337b699aca38487e8a7438f35 C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
MD5: 99424bf72e6df204be59b2d8772d34b7 C:\Program Files (x86)\Internet Download Manager\IDMan.exe
MD5: b4adff5f3e8a41ea0ffe3922fdce6c82 C:\Program Files (x86)\Internet Download Manager\idmcchandler.dll
MD5: 46ec6d0d65fd03d36f9b750d11c22639 c:\program files (x86)\internet download manager\idmiecc.dll
MD5: 706dd70fe7ea8b4362e7a4817ff6baf8 C:\Program Files (x86)\Internet Download Manager\idmmkb.dll
MD5: 6f158c6029d841a5f37708cc2bbf3362 c:\program files (x86)\java\jre6\bin\jp2ssv.dll
MD5: 41700402834f793a8c06731e5cfba62a C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
MD5: 90a680079de80935370e11e0585981d1 C:\Program Files (x86)\Lock Folder XP\LFService.exe
MD5: 6256684495c499b22dcdba266e4f2494 C:\Program Files (x86)\Messenger Plus! Live\Detoured.dll
MD5: c2348907692ca843916aa6ee247a9694 C:\Program Files (x86)\Messenger Plus! Live\MsgPlusLive.dll
MD5: 4ffbd864e5590e9fc69eb4912bde56cf C:\Program Files (x86)\Messenger Plus! Live\MsgPlusLiveRes.dll
MD5: cf60ab7b8b6710d8fb6e2561d8cfb38f C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
MD5: d102c2ce49f176a76cbe5bef4573f0fa C:\Program Files (x86)\Mozilla Firefox\extensions\afurladvisor@anchorfree.com\components\afurladvisor90.dll
MD5: 11cca710674739e3db8f7450a5b650b6 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
MD5: 87fe7afbf52ef4ffb15536e5db8055b3 C:\Program Files (x86)\Mozilla Firefox\freebl3.dll
MD5: c506b249c1dccb4f501b1fa40f86378a C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll
MD5: 3a3b3053cf68edd6b6d9413e0bc4a595 C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MD5: b4c9ca30e7a6c113e4c05eba214626d0 C:\Program Files (x86)\Mozilla Firefox\mozsqlite3.dll
MD5: 79edfc335aea6a3a7d4c1d20c3c9432a C:\Program Files (x86)\Mozilla Firefox\mozutils.dll
MD5: e9ba5ae52561b8f96e4bdc5706d10e5c C:\Program Files (x86)\Mozilla Firefox\nspr4.dll
MD5: 661347d17b175939accf63a8ff6404c0 C:\Program Files (x86)\Mozilla Firefox\nss3.dll
MD5: a6cf050b542c949b0208a0669287f7a2 C:\Program Files (x86)\Mozilla Firefox\nssckbi.dll
MD5: 7bb247a365f0b50292446299835c7d5d C:\Program Files (x86)\Mozilla Firefox\nssdbm3.dll
MD5: 0c6bfbb3715254dbc1b28cdda406e670 C:\Program Files (x86)\Mozilla Firefox\nssutil3.dll
MD5: 9d705f101657633ce52b194a68b9fbad C:\Program Files (x86)\Mozilla Firefox\plc4.dll
MD5: 74395aeefcf091f6b03cf6d04330b1ef C:\Program Files (x86)\Mozilla Firefox\plds4.dll
MD5: 0619c9e7a3682c54bd226a831897cd06 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
MD5: 29e7bd8b61184602a20f14a50b54c6ad C:\Program Files (x86)\Mozilla Firefox\smime3.dll
MD5: 97ef26a108e601128762e7c9bc09b80c C:\Program Files (x86)\Mozilla Firefox\softokn3.dll
MD5: 76f92c677c3dc3afcb441c2270f137fc C:\Program Files (x86)\Mozilla Firefox\ssl3.dll
MD5: 23777bb7976557948825e96e853d77e9 C:\Program Files (x86)\Mozilla Firefox\xpcom.dll
MD5: a66ab262a8f0715037ce3cceca984a39 C:\Program Files (x86)\Mozilla Firefox\xul.dll
MD5: 3c1fb549a48e51a2a7a2a2867154d27e C:\Program Files (x86)\Windows Live\Messenger\msgslang.14.0.8117.0416.dll
MD5: b7aa215e4b8fa6043b33379888ebba4d C:\Program Files (x86)\Windows Live\Messenger\MSIMG32.dll
MD5: 4fdeee42c2891d6cfca94fa37657f3ac C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
MD5: 3ad4eb3dee1d892029dd68d32b25b2cd C:\Program Files\AVAST Software\Avast\1025\Base.dll
MD5: 949a6b0be966907c74ed0b362cfee029 C:\Program Files\AVAST Software\Avast\1025\UILangRes.dll
MD5: 48d892b1b3adb0a6502095ab0014d368 C:\Program Files\AVAST Software\Avast\Aavm4h.dll
MD5: b14242184207da229a3ac25168ffc44a C:\Program Files\AVAST Software\Avast\AavmRpch.dll
MD5: a2bd807f592b29114d99bf6163829b41 C:\Program Files\AVAST Software\Avast\afwCore.dll
MD5: c7ffc3fbe4d3a1fa25edbee14db706a5 C:\Program Files\AVAST Software\Avast\afwCoreClient.dll
MD5: 38b82d65e0f8f29c2563cbe26bdce89b C:\Program Files\AVAST Software\Avast\afwGeoIP.dll
MD5: cd2c416b97e37ee0341feaf09a543a2e C:\Program Files\AVAST Software\Avast\afwRpc.dll
MD5: dae11f2140871dac907b5a7fe0dfc03e C:\Program Files\AVAST Software\Avast\afwServ.exe
MD5: ace9981252e1f262ac276b7615ef6feb C:\Program Files\AVAST Software\Avast\ashBase.dll
MD5: 96ffbb4c8e32325c1b49a393284f77ee C:\Program Files\AVAST Software\Avast\ashTask.dll
MD5: 53fa4e859b6440eaf6673e813caa7c4e C:\Program Files\AVAST Software\Avast\ashTaskEx.dll
MD5: 9ad6a0464da99fada8677f495ff84043 C:\Program Files\AVAST Software\Avast\aswAux.dll
MD5: 3992d00ea19fcde5710e31b1768efa20 C:\Program Files\AVAST Software\Avast\aswCmnBS.dll
MD5: a822e400eb848449368a2d6c99dee8e8 C:\Program Files\AVAST Software\Avast\aswCmnIS.dll
MD5: d662f9567979fcacac8301b6ce18971b C:\Program Files\AVAST Software\Avast\aswCmnOS.dll
MD5: 19c6484fd56c29dee30f1c6f8cbd374d C:\Program Files\AVAST Software\Avast\aswData.dll
MD5: dc9ec6dbb7b5ac6d1ec070df4e8ed903 C:\Program Files\AVAST Software\Avast\aswEngLdr.dll
MD5: fd2d867fe775cc5357cecf2f14515b61 C:\Program Files\AVAST Software\Avast\aswLog.dll
MD5: 464fdfa22c63d742de476a83042d53f9 C:\Program Files\AVAST Software\Avast\aswProperty.dll
MD5: acd4e66d0abdcd3e74a1673cdeb38fcc C:\Program Files\AVAST Software\Avast\aswSqLt.dll
MD5: f01e06906743d0bc93d51328f4cdb8ce C:\Program Files\AVAST Software\Avast\aswUtil.dll
MD5: 75d85bd73b985dd443ea640c0a907b4f c:\program files\avast software\avast\aswwebrepie.dll
MD5: d16c826f375a44802bf317982e81a7e2 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
MD5: e7cf222185411c6a3e68273c452b3283 C:\Program Files\AVAST Software\Avast\AvastUI.exe
MD5: d28f68d1b224e4b254fd5fcecc941340 C:\Program Files\AVAST Software\Avast\CommonRes.dll
MD5: fa97ad1885871c3184427138b7c1dd41 C:\Program Files\AVAST Software\Avast\snxhk.dll
MD5: a6b2ec3a2b6ad7c3f7b2f3495cade4c0 C:\Program Files\IDT\WDM\STacSV64.exe
MD5: fcc7c432fbf465c38fd5d940580ef9b7 C:\Users\BlabLoOo\AppData\Local\Facebook\Update\FacebookUpdate.exe
MD5: 84a393c2742c2d143e8b70b28b452e64 C:\Users\BlabLoOo\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
MD5: 9ebb2e95501396554e7eb414fff02a90 C:\Users\BlabLoOo\AppData\Roaming\IDM\idmmzcc5\components6\idmmzcc.dll
MD5: 0fdd622d4284fe7a102417be9963cac0 C:\Users\BlabLoOo\AppData\Roaming\Mozilla\Firefox\Profiles\wdnmn2o5.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
MD5: 47c071994c3f649f23d9cd075ac9304a C:\Windows\ehome\ehRecvr.exe
MD5: 0862495e0c825893db75ef44faea8e93 C:\Windows\Explorer.exe
MD5: e69fe1ceee067bb19788a9e13a329a76 C:\Windows\Integrator.exe
MD5: 5f3bdb02d64443efca7dd9248619c962 C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
MD5: 225e83f591113adec764afba0ab12593 C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
MD5: cb44e805bb7c0c9bc3b8a66a59bb300a C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
MD5: 0a58da99321d95944e796541a716cbf5 C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
MD5: ea93d50a341350321c96208f651408d0 C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
MD5: 61490bbf4d7c399bd42af6b63960fb92 C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
MD5: 267aff1ea665dbe422276601989efff3 C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
MD5: 792fc8e77dc71a5f095c32d3a5c78ea1 C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
MD5: 84cb9832f03a6aa1929636f5d9e7e298 C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
MD5: 3927fdfe073338428a24160e427e87a3 C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
MD5: 56b798396b5ad9fb064528b638a6008f C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
MD5: 77895ba5c5cdcfef66419a03b6a4cdad C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
MD5: 88955bce0a301ca342562be24415d9cc C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
MD5: 308823c5a58a4022fedd8f4db3f99a25 C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
MD5: 75959d7e5ef8fd7e7e17f40f63f3cc66 C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
MD5: 2ff5b43393e8f2c46135ac33e842b076 C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
MD5: a5750894aefe1d57cf8c460ea4065748 C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
MD5: b3758364d42bbdba18383f010fb7cfcd C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
MD5: 20f76c488929b6288733888bffe62f65 C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
MD5: 11e5a68a159bf13bcf0538bec894e0ce C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
MD5: 5cccf830959345f0b8bcc2a0dfac11b5 C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
MD5: daef44b6ff4aec4533bab3761310d4a5 C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
MD5: 62ad339f7420b022509edac1d9fd7ba1 C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
MD5: c13d2932297d3597fea7b6902efc117d C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
MD5: cdc1f7b46fc7b0b8c88df0cfbda2eb2c C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
MD5: 69ac43aae61eec7625726b377ccaaa13 C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
MD5: 5710b9bd7a3e4f716402b8119004eb48 C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
MD5: a2903ece1d115fea38bb07e01c122b5e C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
MD5: d1d438854a0760098954724194f90655 C:\Windows\system32\aticfx32.dll
MD5: 9b567635ffaabd68f2e9499f18fbc854 C:\Windows\system32\atiu9pag.dll
MD5: ca85b2a6efae1eba5d3357b05aedbb1e C:\Windows\system32\atiumdag.dll
MD5: 62390f4ace9e2b63e3ca26b7f7497897 C:\Windows\system32\DNSAPI.dll
MD5: a2b4e9f5102e9a8fbd7802774935a20b C:\Windows\system32\dwrite.dll
MD5: 2af58d15edc06ec6fdacce1f19482bbf C:\Windows\system32\explorer.exe
MD5: 8898c95862d03d16b2a06db4db6bb6b2 C:\Windows\system32\explorerframe.dll
MD5: 40ff3f0a670af600c340f951ce54c916 C:\Windows\system32\ieframe.DLL
MD5: de458985a693f2641130b98eab960e00 C:\Windows\system32\igdumd32.dll
MD5: c6595b078842e187c6587a285b43a565 C:\Windows\system32\inetcomm.dll
MD5: 9d3c9572f9ddcd99ff55528fcc49a293 C:\Windows\system32\MAGE.DLL
MD5: bd669749eaeff96773b5f8d0a43e0068 C:\Windows\System32\msxml3.dll
MD5: 9141fe8d904ce682a3bdcfae96bb04ef C:\Windows\system32\ntshrui.dll
MD5: 4d59a5b6ef0af6f9fdf3d157534380af C:\Windows\system32\OLEACC.dll
MD5: 71402c7923f6b7f8acb48e50f35463e7 C:\Windows\system32\SearchIndexer.exe
MD5: b4c246937bdb3e50b24698ee811074bf C:\Windows\system32\Secur32.dll
MD5: 0db04d84b06f760be7a852a8cfc20df2 C:\Windows\system32\SYSINFO.OCX
MD5: 25819a6361f10c30905b5d0fdb8dca42 C:\Windows\system32\t2embed.dll
MD5: 6d9b75275c3e3a5f51aef81affadb2b6 C:\Windows\System32\wcncsvc.dll
MD5: bb5ec38f8d4600119b4720bc5d4211f1 C:\Windows\System32\webclnt.dll
MD5: cc9bbcfc715fbedf7ae476106fe653e9 C:\Windows\System32\winhttp.dll
MD5: e702ed19c332c1f12c1403d100e2f4f3 C:\Windows\syswow64\CFGMGR32.dll
MD5: 6c9c05d5344b9ab80e9180fc859bc45a C:\Windows\syswow64\DEVOBJ.dll
MD5: 71dee5c097ad32d4e81e6ac39c35b948 C:\Windows\SysWOW64\drivers\lf40fs64.sys
MD5: 40ff3f0a670af600c340f951ce54c916 C:\Windows\SysWOW64\ieframe.dll
MD5: cdbb1c179ad891b373bffa307b07c78a C:\Windows\syswow64\iertutil.dll
MD5: 4ea99f1644627b1ebad99d0b93cdee1c C:\Windows\syswow64\kernel32.dll
MD5: 2bf12696f4ac8afcfc06ead6f8d2db4c C:\Windows\syswow64\KERNELBASE.dll
MD5: de3745a51b7ac7fedc356a83f76c8023 C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MD5: f8a61b2e713309b4616d107919bdab6e C:\Windows\syswow64\msvcrt.dll
MD5: db6dd54a93522ca3572d04b56c5db890 C:\Windows\SysWOW64\ntdll.dll
MD5: e2c2d8c982316c8abf800c6ce3f28fab C:\Windows\syswow64\ole32.dll
MD5: 705c210efc5564be49eb026bd7aff27a C:\Windows\syswow64\OLEAUT32.dll
MD5: b9980fcd160d1ec1422b111c74b56db2 C:\Windows\SysWOW64\quartz.dll
MD5: 83041697ae93aa4b783ae8746904edd2 C:\Windows\SysWOW64\schannel.dll
MD5: 11535b22cfcc1f4d16c8d11289682ba3 C:\Windows\syswow64\SHELL32.dll
MD5: 44a6fbe9877ca69bd8b3b16c0a20fe1e C:\Windows\syswow64\SspiCli.dll
MD5: e748da08bd88c515cf047f1ac8d1a643 C:\Windows\syswow64\urlmon.dll
MD5: 653109c31f7f190072c9e4df31154225 C:\Windows\syswow64\WININET.dll
MD5: 0b3595a4ff0b36d68e5fc67fd7d70fdc C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCP80.dll
MD5: c9564cf4976e7e96b4052737aa2492b4 C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll
MD5: 4c39358ebdd2ffcd9132a30e1ec31e16 C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCP90.dll
MD5: cdbe9690cf2b8409facad94fac9479c9 C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll
MD5: ca6ade4f7761bb15b3325356dc3b82bb C:\Windows\WinSxS\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll
MD5: fbfca1a574d47ee575448b719cbbf2e4 C:\Windows\WinSxS\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_49768ef57548175e\MFC90ENU.DLL
MD5: d3ead1cf16ba729a7f7c9a5d94aa7c05 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7600.16661_none_ebfb56996c72aefc\COMCTL32.dll
MD5: 4b8dd8541c0e26602005dd0137333615 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\COMCTL32.dll


No file uploaded.

Scan finished - communication took 2 sec
Total traffic - 0.01 MB sent, 0.62 KB recvd
Scanned 347 files and modules - 25 seconds

==============================================================================
 
4
"Silent Runners.vbs", revision 61,
يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي

Operating System: Windows 7
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"Facebook Update" = ""C:\Users\BlabLoOo\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver" ["Facebook Inc."]
"IDMan" = "C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot" ["Tonec Inc."]
"msnmsgr" = ""C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background" [MS]
"Sidebar" = "C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" [MS]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"StartCCC" = ""C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun" ["Advanced Micro Devices, Inc."]
"LFService" = "C:\Program Files (x86)\Lock Folder XP\LFService.exe -start" [null data]
"avast" = ""C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui" ["AVAST Software"]
"SunJavaUpdateSched" = ""C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"" ["Sun Microsystems, Inc."]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{0055C089-8582-441B-A0BF-17B458C2A3A8}\(Default) = "IDM Helper"
-> {HKLM...CLSID} = "IDM integration (IDMIEHlprObj Class)"
\InProcServer32\(Default) = "C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll" ["Internet Download Manager, Tonec Inc."]

{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\(Default) = (no title provided)
-> {HKLM...CLSID} = "avast! WebRep"
\InProcServer32\(Default) = "C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll" ["AVAST Software"]

{9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)
-> {HKLM...CLSID} = "مساعد تسجيل الدخول إلى Windows Live"
\InProcServer32\(Default) = "C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]

{B4F3A835-0E21-4959-BA22-42B3008E02FF}\(Default) = "URLRedirectionBHO"
-> {HKLM...CLSID} = "Office Document Cache Handler"
\InProcServer32\(Default) = "C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL" [MS]

{DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Java(tm) Plug-In 2 SSV Helper"
\InProcServer32\(Default) = "C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll" ["Sun Microsystems, Inc."]

{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Hotspot Shield Class"
\InProcServer32\(Default) = "C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll" ["AnchorFree Inc."]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files (x86)\Microsoft Office\Office14\msohevi.dll" [MS]

"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\AVAST Software\Avast\ashShell.dll" ["AVAST Software"]

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
<<!>> "Userinit" = "userinit.exe" [MS]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\

{503739d0-4c5e-4cfd-b3ba-d881334f0df2}\(Default) = "VaultCredProvider"
-> {HKLM...CLSID} = "VaultCredProvider"
\InProcServer32\(Default) = "C:\Windows\System32\VaultCredProvider.dll" [file not found]

HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\

<<!>> deflate\CLSID = "{8f6b0360-b80d-11d0-a9b3-006097942311}"
-> {HKLM...CLSID} = "AP encoding/decoding Filters"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\urlmon.dll" [MS]

<<!>> gzip\CLSID = "{8f6b0360-b80d-11d0-a9b3-006097942311}"
-> {HKLM...CLSID} = "AP encoding/decoding Filters"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\urlmon.dll" [MS]

<<!>> text/xml\CLSID = "{807573E5-5146-11D5-A672-00B0D022E945}"
-> {HKLM...CLSID} = "Microsoft Office InfoPath XML Mime Filter"
\InProcServer32\(Default) = "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL" [MS]

HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\

<<!>> about\CLSID = "{3050F406-98B5-11CF-BB82-00AA00BDCE0B}"
-> {HKLM...CLSID} = "Microsoft HTML About Pluggable Protocol"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\mshtml.dll" [MS]

<<!>> cdl\CLSID = "{3dd53d40-7b8b-11D0-b013-00aa0059ce02}"
-> {HKLM...CLSID} = "CDL: Asychronous Pluggable Protocol Handler"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\urlmon.dll" [MS]

<<!>> dvd\CLSID = "{12D51199-0DB5-46FE-A120-47A3D7D937CC}"
-> {HKLM...CLSID} = "DVD: Pluggable Protocol"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\msvidctl.dll" [MS]

<<!>> file\CLSID = "{79eac9e7-baf9-11ce-8c82-00aa004ba90b}"
-> {HKLM...CLSID} = "file:, local: Asychronous Pluggable Protocol Handler"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\urlmon.dll" [MS]

<<!>> ftp\CLSID = "{79eac9e3-baf9-11ce-8c82-00aa004ba90b}"
-> {HKLM...CLSID} = "ftp: Asychronous Pluggable Protocol Handler"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\urlmon.dll" [MS]

<<!>> http\CLSID = "{79eac9e2-baf9-11ce-8c82-00aa004ba90b}"
-> {HKLM...CLSID} = "http: Asychronous Pluggable Protocol Handler"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\urlmon.dll" [MS]

<<!>> https\CLSID = "{79eac9e5-baf9-11ce-8c82-00aa004ba90b}"
-> {HKLM...CLSID} = "https: Asychronous Pluggable Protocol Handler"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\urlmon.dll" [MS]

<<!>> javascript\CLSID = "{3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}"
-> {HKLM...CLSID} = "Microsoft HTML Javascript Pluggable Protocol"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\mshtml.dll" [MS]

<<!>> livecall\CLSID = "{828030A1-22C1-4009-854F-8E305202313F}"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL" [MS]

<<!>> local\CLSID = "{79eac9e7-baf9-11ce-8c82-00aa004ba90b}"
-> {HKLM...CLSID} = "file:, local: Asychronous Pluggable Protocol Handler"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\urlmon.dll" [MS]

<<!>> mailto\CLSID = "{3050f3DA-98B5-11CF-BB82-00AA00BDCE0B}"
-> {HKLM...CLSID} = "Microsoft HTML Mailto Pluggable Protocol"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\mshtml.dll" [MS]

<<!>> mk\CLSID = "{79eac9e6-baf9-11ce-8c82-00aa004ba90b}"
-> {HKLM...CLSID} = "mk: Asychronous Pluggable Protocol Handler"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\urlmon.dll" [MS]

<<!>> ms-help\CLSID = "{314111c7-a502-11d2-bbca-00c04f8ec294}"
-> {HKLM...CLSID} = "HxProtocol Class"
\InProcServer32\(Default) = "C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll" [MS]

<<!>> msnim\CLSID = "{828030A1-22C1-4009-854F-8E305202313F}"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL" [MS]

<<!>> res\CLSID = "{3050F3BC-98B5-11CF-BB82-00AA00BDCE0B}"
-> {HKLM...CLSID} = "Microsoft HTML Resource Pluggable Protocol"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\mshtml.dll" [MS]

<<!>> tv\CLSID = "{CBD30858-AF45-11D2-B6D6-00C04FBBDE6E}"
-> {HKLM...CLSID} = "TV: Pluggable Protocol"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\msvidctl.dll" [MS]

<<!>> vbscript\CLSID = "{3050F3B2-98B5-11CF-BB82-00AA00BDCE0B}"
-> {HKLM...CLSID} = "Microsoft HTML Javascript Pluggable Protocol"
\InProcServer32\(Default) = "C:\Windows\SysWOW64\mshtml.dll" [MS]

HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\AVAST Software\Avast\ashShell.dll" ["AVAST Software"]

LFShlExt\(Default) = "{54170F36-B675-4678-8C69-0F4103DF6401}"
-> {HKLM...CLSID} = "LFShlExt Class"
\InProcServer32\(Default) = "C:\PROGRA~2\LOCKFO~1\LF37CO~1.DLL" [empty string]

WinRAR32\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext32.dll" ["Alexander Roshal"]

HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\

00avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\AVAST Software\Avast\ashShell.dll" ["AVAST Software"]

HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\

LFShlExt\(Default) = "{54170F36-B675-4678-8C69-0F4103DF6401}"
-> {HKLM...CLSID} = "LFShlExt Class"
\InProcServer32\(Default) = "C:\PROGRA~2\LOCKFO~1\LF37CO~1.DLL" [empty string]

WinRAR32\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext32.dll" ["Alexander Roshal"]

HKLM\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\

WinRAR32\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext32.dll" ["Alexander Roshal"]

HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\AVAST Software\Avast\ashShell.dll" ["AVAST Software"]

WinRAR32\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext32.dll" ["Alexander Roshal"]

HKLM\SOFTWARE\Classes\Folder\shellex\DragDropHandlers\

WinRAR32\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext32.dll" ["Alexander Roshal"]


Default executables:
--------------------

HKLM\SOFTWARE\Classes\.hta\(Default) = "htafile"
<<!>> HKLM\SOFTWARE\Classes\htafile\shell\open\command\(Default) = "C:\Windows\SysWOW64\mshta.exe "%1" %*" [MS]


Group Policies {GPedit.msc branch and setting}:
-----------------------------------------------

Note: detected settings may not have any effect.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\

"NoActiveDesktop" = (REG_DWORD) dword:0x00000001
{unrecognized setting}

"NoActiveDesktopChanges" = (REG_DWORD) dword:0x00000001
{unrecognized setting}

"ForceActiveDesktopOn" = (REG_DWORD) dword:0x00000000
{unrecognized setting}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Users\BlabLoOo\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg"


Windows Portable Device AutoPlay Handlers
-----------------------------------------

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\

ASHAshampoo_Burning_Studio_10BURNONARRIVAL\
"Provider" = "Ashampoo Burning Studio 10"
"InvokeProgID" = "Ashampoo.BurningStudio10"
"InvokeVerb" = "autoplay-burn"
HKLM\SOFTWARE\Classes\Ashampoo.BurningStudio10\shell\autoplay-burn\Command\(Default) = ""C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 10\burningstudio10.exe" -autoplay -selectdrive "%l"" ["Ashampoo"]

ASHAshampoo_Burning_Studio_10COPYONARRIVAL\
"Provider" = "Ashampoo Burning Studio 10"
"InvokeProgID" = "Ashampoo.BurningStudio10"
"InvokeVerb" = "autoplay-copy"
HKLM\SOFTWARE\Classes\Ashampoo.BurningStudio10\shell\autoplay-copy\Command\(Default) = ""C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 10\burningstudio10.exe" -autoplay -selectdrive "%l" -copy" ["Ashampoo"]

ASHAshampoo_Burning_Studio_10RIPONARRIVAL\
"Provider" = "Ashampoo Burning Studio 10"
"InvokeProgID" = "Ashampoo.BurningStudio10"
"InvokeVerb" = "autoplay-rip"
HKLM\SOFTWARE\Classes\Ashampoo.BurningStudio10\shell\autoplay-rip\Command\(Default) = ""C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 10\burningstudio10.exe" -autoplay -selectdrive "%l" -rip" ["Ashampoo"]

QMPPlayCDAudioOnArrival\
"Provider" = "QQPlayer"
"InvokeProgID" = "QQPlayer.disk"
"InvokeVerb" = "open"
HKLM\SOFTWARE\Classes\QQPlayer.disk\shell\open\command\(Default) = ""C:\Program Files (x86)\Tencent\QQPlayer\QQPlayer.exe" /disk "%1"" ["Tencent"]

QMPPlayDVDMovieOnArrival\
"Provider" = "QQPlayer"
"InvokeProgID" = "QQPlayer.disk"
"InvokeVerb" = "open"
HKLM\SOFTWARE\Classes\QQPlayer.disk\shell\open\command\(Default) = ""C:\Program Files (x86)\Tencent\QQPlayer\QQPlayer.exe" /disk "%1"" ["Tencent"]

QMPPlayMediaFilesOnArrival\
"Provider" = "QQPlayer"
"InvokeProgID" = "QQPlayer.dir"
"InvokeVerb" = "open"
HKLM\SOFTWARE\Classes\QQPlayer.dir\shell\open\command\(Default) = ""C:\Program Files (x86)\Tencent\QQPlayer\QQPlayer.exe" /dir "%1"" ["Tencent"]

QMPPlaySVCDMovieOnArrival\
"Provider" = "QQPlayer"
"InvokeProgID" = "QQPlayer.disk"
"InvokeVerb" = "open"
HKLM\SOFTWARE\Classes\QQPlayer.disk\shell\open\command\(Default) = ""C:\Program Files (x86)\Tencent\QQPlayer\QQPlayer.exe" /disk "%1"" ["Tencent"]

QMPPlayVCDMovieOnArrival\
"Provider" = "QQPlayer"
"InvokeProgID" = "QQPlayer.disk"
"InvokeVerb" = "open"
HKLM\SOFTWARE\Classes\QQPlayer.disk\shell\open\command\(Default) = ""C:\Program Files (x86)\Tencent\QQPlayer\QQPlayer.exe" /disk "%1"" ["Tencent"]


Startup items in "BlabLoOo" & "All Users" startup folders:
----------------------------------------------------------

C:\Users\BlabLoOo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
"AntiCrash" -> shortcut to: "C:\Program Files (x86)\Dachshund Software\AntiCrash\AntiCrash.exe" [null data]


Windows Sidebar Gadgets:
------------------------

C:\Users\BlabLoOo\AppData\Local\Microsoft\Windows Sidebar\Settings.ini
"C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CCalendar.Gadget"
"C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CCPU.Gadget"
"C:%5CProgram%20Files%5CWindows%20Sidebar%5CGadgets%5CWeather.Gadget"
"C:%5CProgram%20Files%5CWindows%20Sidebar%5CShared%20Gadgets%5CaswSidebar.gadget"


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\system32\NLAapi.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000004\LibraryPath = "%SystemRoot%\system32\napinsp.dll" [MS]
000000000005\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
000000000006\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
000000000007\LibraryPath = "%SystemRoot%\system32\wshbth.dll" [MS]

Transport Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 11


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

AMD External Events Utility, AMD External Events Utility, "C:\Windows\system32\atiesrxx.exe" [file not found]
Application Experience, AeLookupSvc, "C:\Windows\system32\svchost.exe -k netsvcs" {"C:\Windows\System32\aelupsvc.dll" [file not found]}
Application Information, Appinfo, "C:\Windows\system32\svchost.exe -k netsvcs" {"C:\Windows\System32\appinfo.dll" [file not found]}
Audio Service, STacSV, "C:\Program Files\IDT\WDM\STacSV64.exe" ["IDT, Inc."]
avast! Antivirus, avast! Antivirus, ""C:\Program Files\AVAST Software\Avast\AvastSvc.exe"" ["AVAST Software"]
avast! Firewall, avast! Firewall, ""C:\Program Files\AVAST Software\Avast\afwServ.exe"" ["AVAST Software"]
Background Intelligent Transfer Service, BITS, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\qmgr.dll" [file not found]}
Base Filtering Engine, BFE, "C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork" {"C:\Windows\System32\bfe.dll" [file not found]}
Bluetooth Support Service, bthserv, "C:\Windows\system32\svchost.exe -k bthsvcs" {"C:\Windows\system32\bthserv.dll" [file not found]}
CNG Key Isolation, KeyIso, "C:\Windows\system32\lsass.exe" [file not found]
Computer Browser, Browser, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\browser.dll" [file not found]}
DCOM Server Process Launcher, DcomLaunch, "C:\Windows\system32\svchost.exe -k DcomLaunch" {"C:\Windows\system32\rpcss.dll" [file not found]}
Desktop Window Manager Session Manager, UxSms, "C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\uxsms.dll" [file not found]}
Diagnostic Policy Service, DPS, "C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork" {"C:\Windows\system32\dps.dll" [file not found]}
Distributed Link Tracking Client, TrkWks, "C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\trkwks.dll" [file not found]}
DNS Client, Dnscache, "C:\Windows\system32\svchost.exe -k NetworkService" {"C:\Windows\System32\dnsrslvr.dll" [file not found]}
Extensible Authentication Protocol, EapHost, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\eapsvc.dll" [file not found]}
Group Policy Client, gpsvc, "C:\Windows\system32\svchost.exe -k netsvcs" {"C:\Windows\System32\gpsvc.dll" [file not found]}
Hotspot Shield Monitoring Service, HssWd, "C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -product HSS" [null data]
Hotspot Shield Routing Service, HssSrv, "C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe" ["AnchorFree Inc."]
Hotspot Shield Service, hshld, "C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe" [null data]
IKE and AuthIP IPsec Keying Modules, IKEEXT, "C:\Windows\system32\svchost.exe -k netsvcs" {"C:\Windows\System32\ikeext.dll" [file not found]}
IP Helper, iphlpsvc, "C:\Windows\System32\svchost.exe -k NetSvcs" {"C:\Windows\System32\iphlpsvc.dll" [file not found]}
Multimedia Class Scheduler, MMCSS, "C:\Windows\system32\svchost.exe -k netsvcs" {"C:\Windows\system32\mmcss.dll" [file not found]}
Network Connections, Netman, "C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\netman.dll" [file not found]}
Network Location Awareness, NlaSvc, "C:\Windows\System32\svchost.exe -k NetworkService" {"C:\Windows\System32\nlasvc.dll" [file not found]}
Network Store Interface Service, nsi, "C:\Windows\system32\svchost.exe -k LocalService" {"C:\Windows\system32\nsisvc.dll" [file not found]}
Offline Files, CscService, "C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\cscsvc.dll" [file not found]}
Plug and Play, PlugPlay, "C:\Windows\system32\svchost.exe -k DcomLaunch" {"C:\Windows\system32\umpnpmgr.dll" [file not found]}
Power, Power, "C:\Windows\system32\svchost.exe -k DcomLaunch" {"C:\Windows\system32\umpo.dll" [file not found]}
Print Spooler, Spooler, "C:\Windows\System32\spoolsv.exe" [file not found]
Program Compatibility Assistant Service, PcaSvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\pcasvc.dll" [file not found]}
Remote Procedure Call (RPC), RpcSs, "C:\Windows\system32\svchost.exe -k rpcss" {"C:\Windows\system32\rpcss.dll" [file not found]}
RPC Endpoint Mapper, RpcEptMapper, "C:\Windows\system32\svchost.exe -k RPCSS" {"C:\Windows\System32\RpcEpMap.dll" [file not found]}
Security Accounts Manager, SamSs, "C:\Windows\system32\lsass.exe" [file not found]
Security Center, wscsvc, "C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted" {"C:\Windows\System32\wscsvc.dll" [file not found]}
Server, LanmanServer, "C:\Windows\system32\svchost.exe -k netsvcs" {"C:\Windows\system32\srvsvc.dll" [file not found]}
SSDP Discovery, SSDPSRV, "C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation" {"C:\Windows\System32\ssdpsrv.dll" [file not found]}
Superfetch, SysMain, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\system32\sysmain.dll" [file not found]}
Task Scheduler, Schedule, "C:\Windows\system32\svchost.exe -k netsvcs" {"C:\Windows\system32\schedsvc.dll" [file not found]}
TCP/IP NetBIOS Helper, lmhosts, "C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted" {"C:\Windows\System32\lmhsvc.dll" [file not found]}
Themes, Themes, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\system32\themeservice.dll" [file not found]}
User Profile Service, ProfSvc, "C:\Windows\system32\svchost.exe -k netsvcs" {"C:\Windows\system32\profsvc.dll" [file not found]}
Windows Audio, AudioSrv, "C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted" {"C:\Windows\System32\Audiosrv.dll" [file not found]}
Windows Audio Endpoint Builder, AudioEndpointBuilder, "C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\Audiosrv.dll" [file not found]}
Windows Defender, WinDefend, "C:\Windows\System32\svchost.exe -k secsvcs" {"C:\Program Files (x86)\Windows Defender\mpsvc.dll" [file not found]}
Windows Driver Foundation - User-mode Driver Framework, wudfsvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\WUDFSvc.dll" [file not found]}
Windows Error Reporting Service, WerSvc, "C:\Windows\System32\svchost.exe -k WerSvcGroup" {"C:\Windows\System32\WerSvc.dll" [file not found]}
Windows Event Log, eventlog, "C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted" {"C:\Windows\System32\wevtsvc.dll" [file not found]}
Windows Firewall, MpsSvc, "C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork" {"C:\Windows\system32\mpssvc.dll" [file not found]}
Windows Font Cache Service, FontCache, "C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation" {"C:\Windows\system32\FntCache.dll" [file not found]}
Windows Image Acquisition (WIA), stisvc, "C:\Windows\system32\svchost.exe -k imgsvc" {"C:\Windows\System32\wiaservc.dll" [file not found]}
Windows Management Instrumentation, Winmgmt, "C:\Windows\system32\svchost.exe -k netsvcs" {"C:\Windows\system32\wbem\WMIsvc.dll" [file not found]}
Windows Update, wuauserv, "C:\Windows\system32\svchost.exe -k netsvcs" {"C:\Windows\system32\wuaueng.dll" [file not found]}
WLAN AutoConfig, Wlansvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\wlansvc.dll" [file not found]}
Workstation, LanmanWorkstation, "C:\Windows\System32\svchost.exe -k NetworkService" {"C:\Windows\System32\wkssvc.dll" [file not found]}


Keyboard Driver Filters:
------------------------

HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\
<<!>> "UpperFilters" = <<!>> "kbdclass" [file not found]


Print Monitors:
---------------

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\
Local Port\Driver = "localspl.dll" [file not found]
Microsoft Shared Fax Monitor\Driver = "FXSMON.DLL" [file not found]
Standard TCP/IP Port\Driver = "tcpmon.dll" [file not found]
USB Monitor\Driver = "usbmon.dll" [file not found]
WSD Port\Driver = "WSDMon.dll" [file not found]


---------- (launch time: 2012-03-07 20:59:09)
<<!>>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer "No" at the
first message box and "Yes" at the second message box.
---------- (total run time: 29 seconds, including 3 seconds for message boxes)




5



====== سجل أخطاء النظام ======

Computer Name: BlabLoOo-PC
Event Code: 11
Message: The driver detected a controller error on \Device\Harddisk1\DR4.
Record Number: 615
Source Name: Disk
Time Written: 20120226185438.882753-000
Event Type: Error
User:

Computer Name: BlabLoOo-PC
Event Code: 11
Message: The driver detected a controller error on \Device\Harddisk1\DR4.
Record Number: 613
Source Name: Disk
Time Written: 20120226185438.367952-000
Event Type: Error
User:

Computer Name: BlabLoOo-PC
Event Code: 3
Message: A command sent to the adapter has timed out. The adapter did not respond.
Record Number: 597
Source Name: BTHUSB
Time Written: 20120226184941.220410-000
Event Type: Warning
User:

Computer Name: 37L4247E29-32
Event Code: 219
Message: The driver \Driver\tunnel failed to load for the device ROOT\*ISATAP\0000.
Record Number: 309
Source Name: Microsoft-Windows-Kernel-PnP
Time Written: 20120226163127.195185-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: 37L4247E29-32
Event Code: 3
Message: A command sent to the adapter has timed out. The adapter did not respond.
Record Number: 295
Source Name: BTHUSB
Time Written: 20120226163112.406359-000
Event Type: Warning
User:



===== سجل أخطاء البرامج =====

Computer Name: BlabLoOo-PC
Event Code: 6001
Message: The winlogon notification subscriber <GPClient> failed a notification event.
Record Number: 118
Source Name: Microsoft-Windows-Winlogon
Time Written: 20120226174707.000000-000
Event Type: Warning
User:

Computer Name: BlabLoOo-PC
Event Code: 1008
Message: The Windows Search Service is starting up and attempting to remove the old search index {Reason: Full Index Reset}.

Record Number: 102
Source Name: Microsoft-Windows-Search
Time Written: 20120226174636.000000-000
Event Type: Warning
User:

Computer Name: 37L4247E29-32
Event Code: 257
Message: The Cryptographic Services service failed to initialize the Catalog Database. The ESENT error was: -546.
Record Number: 8
Source Name: Microsoft-Windows-CAPI2
Time Written: 20120226162851.787712-000
Event Type: Error
User:

Computer Name: 37L4247E29-32
Event Code: 412
Message: Catalog Database (376) Catalog Database: Unable to read the header of logfile C:\Windows\system32\CatRoot2\edb.log. Error -546.
Record Number: 6
Source Name: ESENT
Time Written: 20120226162851.000000-000
Event Type: Error
User:

Computer Name: 37L4247E29-32
Event Code: 412
Message: Catalog Database (376) Catalog Database: Unable to read the header of logfile C:\Windows\system32\CatRoot2\edb.log. Error -546.
Record Number: 5
Source Name: ESENT
Time Written: 20120226162851.000000-000
Event Type: Error
User:



===== السجل الأمني =====

Computer Name: 37L4247E29-32
Event Code: 4735
Message: A security-enabled local group was changed.

Subject:
Security ID: S-1-5-18
Account Name: 37L4247E29-32$
Account Domain: WORKGROUP
Logon ID: 0x3e7

Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin

Changed Attributes:
SAM Account Name: -
SID History: -

Additional Information:
Privileges: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120226162818.138453-000
Event Type: Audit Success
User:

Computer Name: 37L4247E29-32
Event Code: 4731
Message: A security-enabled local group was created.

Subject:
Security ID: S-1-5-18
Account Name: 37L4247E29-32$
Account Domain: WORKGROUP
Logon ID: 0x3e7

New Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin

Attributes:
SAM Account Name: Backup Operators
SID History: -

Additional Information:
Privileges: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120226162818.138453-000
Event Type: Audit Success
User:

Computer Name: 37L4247E29-32
Event Code: 4902
Message: The Per-user audit policy table was created.

Number of Elements: 0
Policy ID: 0x3055a
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120226162817.670453-000
Event Type: Audit Success
User:

Computer Name: 37L4247E29-32
Event Code: 4624
Message: An account was successfully logged on.

Subject:
Security ID: S-1-0-0
Account Name: -
Account Domain: -
Logon ID: 0x0

Logon Type: 0

New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x4
Process Name:

Network Information:
Workstation Name: -
Source Network Address: -
Source Port: -

Detailed Authentication Information:
Logon Process: -
Authentication Package: -
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120226162815.408449-000
Event Type: Audit Success
User:

Computer Name: 37L4247E29-32
Event Code: 4608
Message: Windows is starting up.

This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120226162815.283648-000
Event Type: Audit Success
User:



===== تقرير انهيار البرامج =====

==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 12/04/33 12:12:09 م
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,212
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17592_ad33aed08e3e963537e69ce01e5c4ad645a3257_09fc3310\Report.wer
==================================================

==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 13/04/33 08:08:26 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,212
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17592_ad33aed08e3e963537e69ce01e5c4ad645a3257_13882377\Report.wer
==================================================

==================================================
Process File : zyzoom.exe
Event Name : Stopped responding and was closed
Event Time : 14/04/33 08:58:59 م
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Zyzoom_Forum_Tools\zyzoom.exe
Report File Size : 3,382
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Critical_zyzoom.exe_76a46a3fec9aa766b65f91a57329e9d2fe97ef_108d8729\Report.wer
==================================================

==================================================
Process File : WerFault.exe
Event Name : Shut down unexpectedly
Event Time : 12/04/33 11:59:36 م
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\WerFault.exe
Report File Size : 3,908
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0b998313\Report.wer
==================================================

==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 12/04/33 12:12:58 م
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,090
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.3.7600.16385_e850df5e6bc1763e44c1bb17586e9115d812e3_038ce030\Report.wer
==================================================

==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 13/04/33 08:09:36 ص
User Name : All Users
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,090
Report File Path : C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\NonCritical_7.3.7600.16385_e850df5e6bc1763e44c1bb17586e9115d812e3_099d0d77\Report.wer
==================================================

==================================================
Process File : iexplore.exe
Event Name : Webpage display problem
Event Time : 13/04/33 08:32:22 ص
User Name : BlabLoOo
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Program Files (x86)\Internet Explorer\iexplore.exe
Report File Size : 2,016
Report File Path : C:\Users\BlabLoOo\AppData\Local\Microsoft\Windows\WER\ReportArchive\NonCritical_iexplore.exe_510173a20b29abc48a32cefde827793d78ede9_07a5f150\Report.wer
==================================================

==================================================
Process File : iexplore.exe
Event Name : Webpage display problem
Event Time : 12/04/33 12:15:54 م
User Name : BlabLoOo
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Program Files (x86)\Internet Explorer\iexplore.exe
Report File Size : 2,016
Report File Path : C:\Users\BlabLoOo\AppData\Local\Microsoft\Windows\WER\ReportArchive\NonCritical_iexplore.exe_510173a20b29abc48a32cefde827793d78ede9_0db78ed6\Report.wer
==================================================

==================================================
Process File : iexplore.exe
Event Name : Webpage display problem
Event Time : 13/04/33 08:50:25 م
User Name : BlabLoOo
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Program Files (x86)\Internet Explorer\iexplore.exe
Report File Size : 2,016
Report File Path : C:\Users\BlabLoOo\AppData\Local\Microsoft\Windows\WER\ReportArchive\NonCritical_iexplore.exe_510173a20b29abc48a32cefde827793d78ede9_14204e84\Report.wer
==================================================

==================================================
Process File : iexplore.exe
Event Name : Webpage display problem
Event Time : 12/04/33 07:03:20 م
User Name : BlabLoOo
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Program Files (x86)\Internet Explorer\iexplore.exe
Report File Size : 2,016
Report File Path : C:\Users\BlabLoOo\AppData\Local\Microsoft\Windows\WER\ReportArchive\NonCritical_iexplore.exe_510173a20b29abc48a32cefde827793d78ede9_14608f3b\Report.wer
==================================================

==================================================
Process File : iexplore.exe
Event Name : Webpage display problem
Event Time : 12/04/33 08:07:00 م
User Name : BlabLoOo
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Program Files (x86)\Internet Explorer\iexplore.exe
Report File Size : 2,016
Report File Path : C:\Users\BlabLoOo\AppData\Local\Microsoft\Windows\WER\ReportArchive\NonCritical_iexplore.exe_510173a20b29abc48a32cefde827793d78ede9_14aad65a\Report.wer
==================================================

==================================================
Process File : iexplore.exe
Event Name : Webpage display problem
Event Time : 12/04/33 09:11:42 م
User Name : BlabLoOo
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Program Files (x86)\Internet Explorer\iexplore.exe
Report File Size : 2,016
Report File Path : C:\Users\BlabLoOo\AppData\Local\Microsoft\Windows\WER\ReportArchive\NonCritical_iexplore.exe_510173a20b29abc48a32cefde827793d78ede9_14ee44d6\Report.wer
==================================================

==================================================
Process File : iexplore.exe
Event Name : Webpage display problem
Event Time : 12/04/33 11:51:31 م
User Name : BlabLoOo
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Program Files (x86)\Internet Explorer\iexplore.exe
Report File Size : 2,016
Report File Path : C:\Users\BlabLoOo\AppData\Local\Microsoft\Windows\WER\ReportArchive\NonCritical_iexplore.exe_510173a20b29abc48a32cefde827793d78ede9_1798771f\Report.wer
==================================================

==================================================
Process File : iexplore.exe
Event Name : Webpage display problem
Event Time : 14/04/33 12:13:05 ص
User Name : BlabLoOo
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Program Files (x86)\Internet Explorer\iexplore.exe
Report File Size : 2,016
Report File Path : C:\Users\BlabLoOo\AppData\Local\Microsoft\Windows\WER\ReportArchive\NonCritical_iexplore.exe_510173a20b29abc48a32cefde827793d78ede9_1d21c1a4\Report.wer
==================================================

==================================================
Process File : iexplore.exe
Event Name : Webpage display problem
Event Time : 11/04/33 08:14:19 م
User Name : BlabLoOo
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Program Files (x86)\Internet Explorer\iexplore.exe
Report File Size : 2,016
Report File Path : C:\Users\BlabLoOo\AppData\Local\Microsoft\Windows\WER\ReportArchive\NonCritical_iexplore.exe_ab869f26d17219fd175556834ca3ab7f1e414e_17296020\Report.wer
==================================================

==================================================
Process File : iexplore.exe
Event Name : Webpage display problem
Event Time : 12/04/33 02:07:51 م
User Name : BlabLoOo
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Program Files (x86)\Internet Explorer\iexplore.exe
Report File Size : 2,016
Report File Path : C:\Users\BlabLoOo\AppData\Local\Microsoft\Windows\WER\ReportArchive\NonCritical_iexplore.exe_ab869f26d17219fd175556834ca3ab7f1e414e_19ea1343\Report.wer
==================================================

==================================================
Process File : iexplore.exe
Event Name : Webpage display problem
Event Time : 14/04/33 01:22:33 ص
User Name : BlabLoOo
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Program Files (x86)\Internet Explorer\iexplore.exe
Report File Size : 2,016
Report File Path : C:\Users\BlabLoOo\AppData\Local\Microsoft\Windows\WER\ReportArchive\NonCritical_iexplore.exe_ab869f26d17219fd175556834ca3ab7f1e414e_1d615fa9\Report.wer
==================================================

==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 12/04/33 12:12:09 م
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,212
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17592_ad33aed08e3e963537e69ce01e5c4ad645a3257_09fc3310\Report.wer
==================================================

==================================================
Process File : TrustedInstaller.exe
Event Name : CbsPackageServicingFailure2
Event Time : 13/04/33 08:08:26 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\servicing\TrustedInstaller.exe
Report File Size : 2,212
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17592_ad33aed08e3e963537e69ce01e5c4ad645a3257_13882377\Report.wer
==================================================

==================================================
Process File : zyzoom.exe
Event Name : Stopped responding and was closed
Event Time : 14/04/33 08:58:59 م
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Zyzoom_Forum_Tools\zyzoom.exe
Report File Size : 3,382
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_zyzoom.exe_76a46a3fec9aa766b65f91a57329e9d2fe97ef_108d8729\Report.wer
==================================================

==================================================
Process File : WerFault.exe
Event Name : Shut down unexpectedly
Event Time : 12/04/33 11:59:36 م
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\WerFault.exe
Report File Size : 3,908
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0b998313\Report.wer
==================================================

==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 12/04/33 12:12:58 م
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,090
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.3.7600.16385_e850df5e6bc1763e44c1bb17586e9115d812e3_038ce030\Report.wer
==================================================

==================================================
Process File : svchost.exe
Event Name : Windows Update installation problem
Event Time : 13/04/33 08:09:36 ص
User Name :
Exception Code :
Exception Offset :
Fault Module Name :
Fault Module Version:
Process Path : C:\Windows\System32\svchost.exe
Report File Size : 2,090
Report File Path : C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.3.7600.16385_e850df5e6bc1763e44c1bb17586e9115d812e3_099d0d77\Report.wer
==================================================




===== تقرير الشاشة الزرقاء =====

==================================================
Dump File : 030512-19968-01.dmp
Crash Time : 12/04/33 11:58:32 م
Bug Check String : APC_INDEX_MISMATCH
Bug Check Code : 0x00000001
Parameter 1 : 00000000`7719fa8a
Parameter 2 : 00000000`00000000
Parameter 3 : 00000000`0000ffff
Parameter 4 : fffff880`0b93fc60
Caused By Driver : nsiproxy.sys
Caused By Address : nsiproxy.sys+7e34c60
File Description :
Product Name :
Company :
File Version :
Processor : x64
Computer Name :
Full Path : C:\Windows\Minidump\030512-19968-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 320,302
==================================================




6




====== معلومات نظام التشغيل ======

X64 WIN_7 7600


====== قائمة البرامج المثبتة ======

Adobe Flash Player 11 Plugin
AntiCrash 3.6.1
Ashampoo Burning Studio 10 v.10.0.10
avast! Internet Security
Catalyst Control Center
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
Catalyst Control Center Profiles Mobile
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
CyberLink YouCam
CyberLink YouCam
Debugging Tools for Windows
Facebook Video Calling 1.1.1.1
Hotspot Shield 2.24
HyperCam 2
IDT Audio
Intel(R) Display Audio Driver
Internet Download Manager
Java Auto Updater
Java(TM) 6 Update 27
Lock Folder XP
Messenger Plus! Live
Microsoft Choice Guard
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (Arabic) 2010
Microsoft Office Excel MUI (Arabic) 2010
Microsoft Office Groove MUI (Arabic) 2010
Microsoft Office InfoPath MUI (Arabic) 2010
Microsoft Office OneNote MUI (Arabic) 2010
Microsoft Office Outlook MUI (Arabic) 2010
Microsoft Office PowerPoint MUI (Arabic) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (Arabic) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proofing (Arabic) 2010
Microsoft Office Publisher MUI (Arabic) 2010
Microsoft Office Shared MUI (Arabic) 2010
Microsoft Office Word MUI (Arabic) 2010
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 9.0.1 (x86 ar)
MSVCRT
PX Profile Update
Realtek Ethernet Controller Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
Skype™ 5.3
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2553323) 32-Bit Edition
Update for Microsoft Outlook Social Connector (KB2583935)
Update for Microsoft Outlook Social Connector (KB2583935)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Messenger
أداة التحميل Windows Live Upload Tool
مساعد تسجيل الدخول إلى Windows Live
 
من اضافة وازالة البرامج احذف التالي (( لا تنسى اغلاق المتصفحات ))

Hotspot Shield 2.24

ثم

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


ثم

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


وشوف اش يصير معاك​
 
شكرا كتير لك اخي البارون
سوف ارد عليك بعد كم يوم لانها الشاشة الزرقاء لا تحصل دائما وانما في الاسبوع مرة متل هيك
وكمان كتير بتشكرك وان شاءالله ما بتحصل :)
 
نفس مشكلتي ياريت ازا لقيت حل الها انك اتفيدني ومشكور الك
 
توقيع : اسمي
اخي البارون اجدتني الشاشة الزرقاء مرة تانية وهاي التقرير الها


===== تقرير الشاشة الزرقاء =====

==================================================
Dump File : 032812-19141-01.dmp
Crash Time : 05/05/33 06:51:04 م
Bug Check String : SYSTEM_THREAD_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000007e
Parameter 1 : ffffffff`c0000005
Parameter 2 : fffff800`02cdef18
Parameter 3 : fffff880`031a1988
Parameter 4 : fffff880`031a11f0
Caused By Driver :
Caused By Address :
File Description :
Product Name :
Company :
File Version :
Processor : x64
Computer Name :
Full Path : C:\Windows\Minidump\032812-19141-01.dmp
Processors Count : 4
Major Version : 15
Minor Version : 7600
Dump File Size : 262,144
==================================================

ارجو المساعدة يا ريت اعرف من شو المشكلة
 
مكتوب انه نظام الاستثناء لم يتم التعامل معها !!
اعمل التالي كما في شرح
 
توقيع : format
مشكور اخي على الشرح بس انا عملت قبل هيك هادة الشئ وعالفاضي ما نفع
المشكلة انو انا لو نزلت اي نسخة ويندوز 7 سواء كانت التميت او هوم بريميوم او انتربرايس او الخ ....
المكشلة هيا هيا الشاشة الزرقاء بتطلعلي في كل نسخة
وهي كمان توضيح بالصور ومن تصويري
6f7c061785a2590e87610d382d913c15.jpg




4af9199ed83325b80eb54d1e00edd0a2.jpg
 
عودة
أعلى