هذا التقرير
.
--------------------------\\\ Start Report Of HijackThis ---------------
.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 05:35:34 ص, on 08/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe
C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\user\LOCALS~1\Temp\bntoz\runn.exe
C:\WINDOWS\system32\cmd.exe
C:\DOCUME~1\user\LOCALS~1\Temp\bntoz\HijackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:10081
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-725345543-1614895754-2147124373-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Administrator')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: Avira Premium Security Suite Firewall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe
O23 - Service: Avira Premium Security Suite MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe
O23 - Service: Avira Premium Security Suite Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
O23 - Service: Avira Premium Security Suite Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
O23 - Service: Avira Premium Security Suite WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Avira Premium Security Suite MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
--
End of file - 7278 bytes
.
.
--------------------------\\\ End Report Of Of HijackThis ---------------
.
.
.
.
--------------------------\\\ Start Report Of Running Processes ---------------
.
==================================================
Process Name : smss.exe
ProcessID : 796
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Windows NT Session Manager
Company : Microsoft Corporation
Window Title :
File Size : 50,688
File Created Date : 03/08/2004 07:26:58 م
File Modified Date : 03/08/2004 07:26:58 م
Filename : C:\WINDOWS\System32\smss.exe
Base Address : 0x48580000
Created On : 07/09/2008 05:33:40 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 44 K
Mem Usage Peak : 464 K
Page Faults : 226
Pagefile Usage : 184 K
Pagefile Peak Usage : 1672 K
File Attributes : A
==================================================
==================================================
Process Name : csrss.exe
ProcessID : 848
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Client Server Runtime Process
Company : Microsoft Corporation
Window Title :
File Size : 6,144
File Created Date : 03/08/2004 07:26:50 م
File Modified Date : 03/08/2004 07:26:50 م
Filename : C:\WINDOWS\system32\csrss.exe
Base Address : 0x4A680000
Created On : 07/09/2008 05:33:43 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 940 K
Mem Usage Peak : 8572 K
Page Faults : 43690
Pagefile Usage : 1752 K
Pagefile Peak Usage : 4896 K
File Attributes : A
==================================================
==================================================
Process Name : winlogon.exe
ProcessID : 876
Priority : High
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Windows NT Logon Application
Company : Microsoft Corporation
Window Title :
File Size : 502,272
File Created Date : 03/08/2004 07:26:58 م
File Modified Date : 03/08/2004 07:26:58 م
Filename : C:\WINDOWS\system32\winlogon.exe
Base Address : 0x01000000
Created On : 07/09/2008 05:33:45 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 3692 K
Mem Usage Peak : 15176 K
Page Faults : 12894
Pagefile Usage : 8200 K
Pagefile Peak Usage : 11232 K
File Attributes : A
==================================================
==================================================
Process Name : services.exe
ProcessID : 920
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Services and Controller app
Company : Microsoft Corporation
Window Title :
File Size : 108,032
File Created Date : 03/08/2004 07:26:56 م
File Modified Date : 03/08/2004 07:26:56 م
Filename : C:\WINDOWS\system32\services.exe
Base Address : 0x01000000
Created On : 07/09/2008 05:33:47 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 1840 K
Mem Usage Peak : 4472 K
Page Faults : 2764
Pagefile Usage : 2140 K
Pagefile Peak Usage : 2480 K
File Attributes : A
==================================================
==================================================
Process Name : lsass.exe
ProcessID : 932
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : LSA Shell (Export Version)
Company : Microsoft Corporation
Window Title :
File Size : 13,312
File Created Date : 03/08/2004 07:26:52 م
File Modified Date : 03/08/2004 07:26:52 م
Filename : C:\WINDOWS\system32\lsass.exe
Base Address : 0x01000000
Created On : 07/09/2008 05:33:48 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 2804 K
Mem Usage Peak : 6400 K
Page Faults : 84369
Pagefile Usage : 2784 K
Pagefile Peak Usage : 4096 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1088
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 03/08/2004 07:26:58 م
File Modified Date : 03/08/2004 07:26:58 م
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 07/09/2008 05:33:50 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 1772 K
Mem Usage Peak : 5164 K
Page Faults : 2170
Pagefile Usage : 3300 K
Pagefile Peak Usage : 23740 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1184
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 03/08/2004 07:26:58 م
File Modified Date : 03/08/2004 07:26:58 م
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 07/09/2008 05:33:51 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 1584 K
Mem Usage Peak : 4604 K
Page Faults : 1675
Pagefile Usage : 2028 K
Pagefile Peak Usage : 2108 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1444
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 03/08/2004 07:26:58 م
File Modified Date : 03/08/2004 07:26:58 م
Filename : C:\WINDOWS\System32\svchost.exe
Base Address : 0x01000000
Created On : 07/09/2008 05:33:51 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 11824 K
Mem Usage Peak : 26088 K
Page Faults : 61773
Pagefile Usage : 16120 K
Pagefile Peak Usage : 20776 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1604
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 03/08/2004 07:26:58 م
File Modified Date : 03/08/2004 07:26:58 م
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 07/09/2008 05:33:51 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 1172 K
Mem Usage Peak : 3852 K
Page Faults : 1790
Pagefile Usage : 1524 K
Pagefile Peak Usage : 1644 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1808
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 03/08/2004 07:26:58 م
File Modified Date : 03/08/2004 07:26:58 م
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 07/09/2008 05:33:52 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 1292 K
Mem Usage Peak : 4672 K
Page Faults : 1516
Pagefile Usage : 1900 K
Pagefile Peak Usage : 1944 K
File Attributes : A
==================================================
==================================================
Process Name : spoolsv.exe
ProcessID : 352
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
Description : Spooler SubSystem App
Company : Microsoft Corporation
Window Title :
File Size : 57,856
File Created Date : 03/08/2004 07:26:58 م
File Modified Date : 10/06/2005 11:53:32 م
Filename : C:\WINDOWS\system32\spoolsv.exe
Base Address : 0x01000000
Created On : 07/09/2008 05:33:55 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 1528 K
Mem Usage Peak : 6248 K
Page Faults : 2402
Pagefile Usage : 3664 K
Pagefile Peak Usage : 4448 K
File Attributes : A
==================================================
==================================================
Process Name : sched.exe
ProcessID : 492
Priority : Normal
Product Name : AntiVir Workstation
Version : 8.00.00.16
Description : Antivirus Scheduler
Company : Avira GmbH
Window Title :
File Size : 68,865
File Created Date : 10/07/2008 05:27:23 م
File Modified Date : 17/07/2008 10:08:14 م
Filename : C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
Base Address : 0x00400000
Created On : 07/09/2008 05:33:55 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 576 K
Mem Usage Peak : 4100 K
Page Faults : 10859
Pagefile Usage : 1800 K
Pagefile Peak Usage : 1832 K
File Attributes : A
==================================================
==================================================
Process Name : Explorer.EXE
ProcessID : 532
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)
Description : Windows Explorer
Company : Microsoft Corporation
Window Title :
File Size : 1,033,216
File Created Date : 03/08/2004 07:26:50 م
File Modified Date : 13/06/2007 10:23:07 ص
Filename : C:\WINDOWS\Explorer.EXE
Base Address : 0x01000000
Created On : 07/09/2008 05:33:56 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 3936 K
Mem Usage Peak : 20872 K
Page Faults : 53292
Pagefile Usage : 14104 K
Pagefile Peak Usage : 14108 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 700
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 03/08/2004 07:26:58 م
File Modified Date : 03/08/2004 07:26:58 م
Filename : C:\WINDOWS\System32\svchost.exe
Base Address : 0x01000000
Created On : 07/09/2008 05:33:58 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 3392 K
Mem Usage Peak : 8196 K
Page Faults : 4834
Pagefile Usage : 5420 K
Pagefile Peak Usage : 5708 K
File Attributes : A
==================================================
==================================================
Process Name : avfwsvc.exe
ProcessID : 756
Priority : Normal
Product Name : AntiVir Workstation
Version : 7.29.35.6
Description : Firewall NT service process
Company : Avira GmbH
Window Title :
File Size : 344,321
File Created Date : 10/07/2008 05:27:20 م
File Modified Date : 17/07/2008 10:08:09 م
Filename : C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe
Base Address : 0x00400000
Created On : 07/09/2008 05:33:58 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 1104 K
Mem Usage Peak : 53704 K
Page Faults : 35906
Pagefile Usage : 1872 K
Pagefile Peak Usage : 765136 K
File Attributes : A
==================================================
==================================================
Process Name : avguard.exe
ProcessID : 1000
Priority : Normal
Product Name : AntiVir Workstation
Version : 8.00.01.27
Description : Antivirus On-Access Service
Company : Avira GmbH
Window Title :
File Size : 149,761
File Created Date : 10/07/2008 05:27:20 م
File Modified Date : 15/08/2008 04:39:58 ص
Filename : C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
Base Address : 0x00400000
Created On : 07/09/2008 05:34:00 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 11268 K
Mem Usage Peak : 73312 K
Page Faults : 225764
Pagefile Usage : 76560 K
Pagefile Peak Usage : 1020480 K
File Attributes : A
==================================================
==================================================
Process Name : avesvc.exe
ProcessID : 1356
Priority : Normal
Product Name : AntiVir Workstation
Version : 8.00.02.00
Description : Antivirus Engine Service
Company : Avira GmbH
Window Title :
File Size : 41,217
File Created Date : 10/07/2008 05:27:20 م
File Modified Date : 17/07/2008 10:08:09 م
Filename : C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe
Base Address : 0x00400000
Created On : 07/09/2008 05:34:00 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 11400 K
Mem Usage Peak : 71168 K
Page Faults : 163266
Pagefile Usage : 56444 K
Pagefile Peak Usage : 1227588 K
File Attributes : A
==================================================
==================================================
Process Name : MDM.EXE
ProcessID : 1560
Priority : Normal
Product Name : Microsoft® Visual Studio .NET
Version : 7.00.9466
Description : Machine Debug Manager
Company : Microsoft Corporation
Window Title :
File Size : 322,120
File Created Date : 19/06/2003 08:25:00 م
File Modified Date : 19/06/2003 08:25:00 م
Filename : C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
Base Address : 0x00400000
Created On : 07/09/2008 05:34:01 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 392 K
Mem Usage Peak : 3012 K
Page Faults : 907
Pagefile Usage : 1080 K
Pagefile Peak Usage : 1092 K
File Attributes : A
==================================================
==================================================
Process Name : nvsvc32.exe
ProcessID : 1840
Priority : Normal
Product Name : NVIDIA Driver Helper Service, Version 77.72
Version : 6.14.10.7772
Description : NVIDIA Driver Helper Service, Version 77.72
Company : NVIDIA Corporation
Window Title :
File Size : 127,043
File Created Date : 08/03/2008 02:25:21 ص
File Modified Date : 15/06/2005 08:20:00 م
Filename : C:\WINDOWS\system32\nvsvc32.exe
Base Address : 0x00400000
Created On : 07/09/2008 05:34:01 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 1612 K
Mem Usage Peak : 4516 K
Page Faults : 3149
Pagefile Usage : 2052 K
Pagefile Peak Usage : 2452 K
File Attributes : A
==================================================
==================================================
Process Name : HPZipm12.exe
ProcessID : 1952
Priority : Normal
Product Name : HP PML
Version : 10, 1, 1, 5
Description : PML Driver
Company : HP
Window Title :
File Size : 69,632
File Created Date : 30/06/2008 08:53:50 م
File Modified Date : 03/03/2006 06:03:10 م
Filename : C:\WINDOWS\system32\HPZipm12.exe
Base Address : 0x00400000
Created On : 07/09/2008 05:34:02 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 212 K
Mem Usage Peak : 1908 K
Page Faults : 532
Pagefile Usage : 656 K
Pagefile Peak Usage : 656 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 2004
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 03/08/2004 07:26:58 م
File Modified Date : 03/08/2004 07:26:58 م
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 07/09/2008 05:34:02 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 148 K
Mem Usage Peak : 4244 K
Page Faults : 1146
Pagefile Usage : 2504 K
Pagefile Peak Usage : 2596 K
File Attributes : A
==================================================
==================================================
Process Name : SearchIndexer.exe
ProcessID : 1828
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 7.0.6001.16503 (longhorn(wmbla).080526-2159)
Description : Microsoft Windows Search Indexer
Company : Microsoft Corporation
Window Title :
File Size : 439,808
File Created Date : 26/05/2008 07:18:44 م
File Modified Date : 26/05/2008 07:18:44 م
Filename : C:\WINDOWS\system32\SearchIndexer.exe
Base Address : 0x01000000
Created On : 07/09/2008 05:34:03 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 9048 K
Mem Usage Peak : 15272 K
Page Faults : 15020
Pagefile Usage : 18856 K
Pagefile Peak Usage : 22580 K
File Attributes :
==================================================
==================================================
Process Name : avgnt.exe
ProcessID : 1724
Priority : Normal
Product Name : AntiVir Workstation
Version : 8.00.70.02
Description : Antivirus System Tray Tool
Company : Avira GmbH
Window Title :
File Size : 266,497
File Created Date : 10/07/2008 05:27:20 م
File Modified Date : 17/07/2008 10:08:09 م
Filename : C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe
Base Address : 0x00400000
Created On : 07/09/2008 05:34:10 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 1312 K
Mem Usage Peak : 57272 K
Page Faults : 136767
Pagefile Usage : 3252 K
Pagefile Peak Usage : 954628 K
File Attributes : A
==================================================
==================================================
Process Name : ctfmon.exe
ProcessID : 1784
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : CTF Loader
Company : Microsoft Corporation
Window Title :
File Size : 15,360
File Created Date : 03/08/2004 07:26:50 م
File Modified Date : 03/08/2004 07:26:50 م
Filename : C:\WINDOWS\system32\ctfmon.exe
Base Address : 0x00400000
Created On : 07/09/2008 05:34:11 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 440 K
Mem Usage Peak : 3868 K
Page Faults : 1492
Pagefile Usage : 1028 K
Pagefile Peak Usage : 1032 K
File Attributes : A
==================================================
==================================================
Process Name : WasherSvc.exe
ProcessID : 844
Priority : Normal
Product Name : Window Washer
Version : 6,5,0,1093
Description : Window Washer Engine
Company : Webroot Software, Inc.
Window Title :
File Size : 388,936
File Created Date : 08/06/2008 04:43:16 م
File Modified Date : 09/08/2007 10:56:26 ص
Filename : C:\Program Files\Webroot\Washer\WasherSvc.exe
Base Address : 0x00040000
Created On : 07/09/2008 05:34:13 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 416 K
Mem Usage Peak : 4532 K
Page Faults : 1253
Pagefile Usage : 3516 K
Pagefile Peak Usage : 3568 K
File Attributes : A
==================================================
==================================================
Process Name : avmailc.exe
ProcessID : 2532
Priority : Normal
Product Name : AntiVir Workstation
Version : 8.00.00.42
Description : Antivirus MailScanner Service
Company : Avira GmbH
Window Title :
File Size : 164,097
File Created Date : 10/07/2008 05:27:21 م
File Modified Date : 17/07/2008 10:08:09 م
Filename : C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe
Base Address : 0x00400000
Created On : 07/09/2008 05:34:23 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 128 K
Mem Usage Peak : 7368 K
Page Faults : 2651
Pagefile Usage : 4504 K
Pagefile Peak Usage : 4568 K
File Attributes : A
==================================================
==================================================
Process Name : AVWEBGRD.EXE
ProcessID : 2588
Priority : Normal
Product Name : AntiVir Workstation
Version : 8.0.15.0
Description : AntiVir WebGuard Service
Company : Avira GmbH
Window Title :
File Size : 258,305
File Created Date : 10/07/2008 05:27:21 م
File Modified Date : 17/07/2008 10:08:10 م
Filename : C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE
Base Address : 0x00400000
Created On : 07/09/2008 05:34:23 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 3208 K
Mem Usage Peak : 6264 K
Page Faults : 10162
Pagefile Usage : 3436 K
Pagefile Peak Usage : 3820 K
File Attributes : A
==================================================
==================================================
Process Name : alg.exe
ProcessID : 3608
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Application Layer Gateway Service
Company : Microsoft Corporation
Window Title :
File Size : 44,544
File Created Date : 03/08/2004 07:26:48 م
File Modified Date : 03/08/2004 07:26:48 م
Filename : C:\WINDOWS\System32\alg.exe
Base Address : 0x01000000
Created On : 07/09/2008 05:34:31 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 420 K
Mem Usage Peak : 3776 K
Page Faults : 1057
Pagefile Usage : 1336 K
Pagefile Peak Usage : 1348 K
File Attributes : A
==================================================
==================================================
Process Name : cafe.exe
ProcessID : 2792
Priority : Normal
Product Name : cafe
Version : 1.3.31.0
Description :
Company : cafe
Window Title :
File Size : 2,308,936
File Created Date : 29/06/2008 03:46:12 م
File Modified Date : 29/06/2008 03:46:12 م
Filename : D:\Program Files\cafe\cafe.exe
Base Address : 0x00400000
Created On : 07/09/2008 06:59:43 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 7148 K
Mem Usage Peak : 50848 K
Page Faults : 164250
Pagefile Usage : 30908 K
Pagefile Peak Usage : 38268 K
File Attributes : A
==================================================
==================================================
Process Name : cafeAgent.exe
ProcessID : 2448
Priority : Normal
Product Name : cafe
Version : 1.3.31.0
Description :
Company : cafe
Window Title :
File Size : 145,736
File Created Date : 29/06/2008 03:46:27 م
File Modified Date : 29/06/2008 03:46:27 م
Filename : d:\Program Files\cafe\cafeAgent.exe
Base Address : 0x00400000
Created On : 07/09/2008 06:59:50 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 1644 K
Mem Usage Peak : 7704 K
Page Faults : 10846
Pagefile Usage : 2892 K
Pagefile Peak Usage : 2916 K
File Attributes : A
==================================================
==================================================
Process Name : csrss.exe
ProcessID : 4400
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Client Server Runtime Process
Company : Microsoft Corporation
Window Title :
File Size : 6,144
File Created Date : 03/08/2004 07:26:50 م
File Modified Date : 03/08/2004 07:26:50 م
Filename : C:\WINDOWS\system32\csrss.exe
Base Address : 0x4A680000
Created On : 08/09/2008 05:31:21 ص
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 3740 K
Mem Usage Peak : 5284 K
Page Faults : 4835
Pagefile Usage : 1248 K
Pagefile Peak Usage : 4340 K
File Attributes : A
==================================================
==================================================
Process Name : winlogon.exe
ProcessID : 2152
Priority : High
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Windows NT Logon Application
Company : Microsoft Corporation
Window Title :
File Size : 502,272
File Created Date : 03/08/2004 07:26:58 م
File Modified Date : 03/08/2004 07:26:58 م
Filename : C:\WINDOWS\system32\winlogon.exe
Base Address : 0x01000000
Created On : 08/09/2008 05:31:21 ص
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 2624 K
Mem Usage Peak : 11812 K
Page Faults : 5739
Pagefile Usage : 4212 K
Pagefile Peak Usage : 6828 K
File Attributes : A
==================================================
==================================================
Process Name : Explorer.EXE
ProcessID : 4340
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)
Description : Windows Explorer
Company : Microsoft Corporation
Window Title : Program Manager
File Size : 1,033,216
File Created Date : 03/08/2004 07:26:50 م
File Modified Date : 13/06/2007 10:23:07 ص
Filename : C:\WINDOWS\Explorer.EXE
Base Address : 0x01000000
Created On : 08/09/2008 05:31:27 ص
Visible Windows : 2
Hidden Windows : 25
User Name : GIGABYTE\user
Mem Usage : 19252 K
Mem Usage Peak : 19264 K
Page Faults : 8160
Pagefile Usage : 13096 K
Pagefile Peak Usage : 13104 K
File Attributes : A
==================================================
==================================================
Process Name : avgnt.exe
ProcessID : 5076
Priority : Normal
Product Name : AntiVir Workstation
Version : 8.00.70.02
Description : Antivirus System Tray Tool
Company : Avira GmbH
Window Title :
File Size : 266,497
File Created Date : 10/07/2008 05:27:20 م
File Modified Date : 17/07/2008 10:08:09 م
Filename : C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe
Base Address : 0x00400000
Created On : 08/09/2008 05:31:30 ص
Visible Windows : 0
Hidden Windows : 5
User Name : GIGABYTE\user
Mem Usage : 6912 K
Mem Usage Peak : 56904 K
Page Faults : 70649
Pagefile Usage : 3232 K
Pagefile Peak Usage : 944696 K
File Attributes : A
==================================================
==================================================
Process Name : ctfmon.exe
ProcessID : 5192
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : CTF Loader
Company : Microsoft Corporation
Window Title :
File Size : 15,360
File Created Date : 03/08/2004 07:26:50 م
File Modified Date : 03/08/2004 07:26:50 م
Filename : C:\WINDOWS\system32\ctfmon.exe
Base Address : 0x00400000
Created On : 08/09/2008 05:31:30 ص
Visible Windows : 0
Hidden Windows : 5
User Name : GIGABYTE\user
Mem Usage : 3356 K
Mem Usage Peak : 3360 K
Page Faults : 952
Pagefile Usage : 1004 K
Pagefile Peak Usage : 1016 K
File Attributes : A
==================================================
==================================================
Process Name : iexplore.exe
ProcessID : 4588
Priority : Normal
Product Name : Windows® Internet Explorer
Version : 7.00.6000.16705 (vista_gdr.080618-1506)
Description : Internet Explorer
Company : Microsoft Corporation
Window Title : جهازي بطيء جدا حتى بعد الفورمات - زيزوووم للأمن والحمايه - Windows Internet Explorer
File Size : 625,664
File Created Date : 02/06/2008 10:15:46 ص
File Modified Date : 23/06/2008 09:20:52 ص
Filename : C:\Program Files\Internet Explorer\iexplore.exe
Base Address : 0x00400000
Created On : 08/09/2008 05:32:37 ص
Visible Windows : 1
Hidden Windows : 36
User Name : GIGABYTE\user
Mem Usage : 62136 K
Mem Usage Peak : 62868 K
Page Faults : 62527
Pagefile Usage : 47544 K
Pagefile Peak Usage : 47992 K
File Attributes : A
==================================================
==================================================
Process Name : runn.exe
ProcessID : 3856
Priority : Normal
Product Name :
Version :
Description :
Company :
Window Title :
File Size : 71,680
File Created Date : 08/09/2008 02:35:30 ص
File Modified Date : 31/01/2008 10:24:25 م
Filename : C:\DOCUME~1\user\LOCALS~1\Temp\bntoz\runn.exe
Base Address : 0x00400000
Created On : 08/09/2008 05:35:30 ص
Visible Windows : 0
Hidden Windows : 0
User Name : GIGABYTE\user
Mem Usage : 2220 K
Mem Usage Peak : 2240 K
Page Faults : 639
Pagefile Usage : 716 K
Pagefile Peak Usage : 784 K
File Attributes : A
==================================================
==================================================
Process Name : cmd.exe
ProcessID : 6052
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Windows Command Processor
Company : Microsoft Corporation
Window Title :
File Size : 388,608
File Created Date : 03/08/2004 07:26:50 م
File Modified Date : 03/08/2004 07:26:50 م
Filename : C:\WINDOWS\system32\cmd.exe
Base Address : 0x4AD00000
Created On : 08/09/2008 05:35:30 ص
Visible Windows : 0
Hidden Windows : 1
User Name : GIGABYTE\user
Mem Usage : 2968 K
Mem Usage Peak : 3036 K
Page Faults : 841
Pagefile Usage : 2088 K
Pagefile Peak Usage : 2164 K
File Attributes : A
==================================================
==================================================
Process Name : SearchProtocolHost.exe
ProcessID : 3312
Priority : Below Normal
Product Name : Microsoft® Windows® Operating System
Version : 7.0.6001.16503 (longhorn(wmbla).080526-2159)
Description : Microsoft Windows Search Protocol Host
Company : Microsoft Corporation
Window Title :
File Size : 184,832
File Created Date : 26/05/2008 07:18:18 م
File Modified Date : 26/05/2008 07:18:18 م
Filename : C:\WINDOWS\system32\SearchProtocolHost.exe
Base Address : 0x01000000
Created On : 08/09/2008 05:35:30 ص
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 5432 K
Mem Usage Peak : 5432 K
Page Faults : 1394
Pagefile Usage : 3740 K
Pagefile Peak Usage : 3740 K
File Attributes :
==================================================
==================================================
Process Name : SearchFilterHost.exe
ProcessID : 4636
Priority : Below Normal
Product Name : Microsoft® Windows® Operating System
Version : 7.0.6001.16503 (longhorn(wmbla).080526-2159)
Description : Microsoft Windows Search Filter Host
Company : Microsoft Corporation
Window Title :
File Size : 87,552
File Created Date : 26/05/2008 07:17:56 م
File Modified Date : 26/05/2008 07:17:56 م
Filename : C:\WINDOWS\system32\SearchFilterHost.exe
Base Address : 0x01000000
Created On : 08/09/2008 05:35:31 ص
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 3632 K
Mem Usage Peak : 3632 K
Page Faults : 923
Pagefile Usage : 2464 K
Pagefile Peak Usage : 2464 K
File Attributes :
==================================================
==================================================
Process Name : wmiprvse.exe
ProcessID : 4252
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : WMI
Company : Microsoft Corporation
Window Title :
File Size : 218,112
File Created Date : 02/06/2008 10:13:52 ص
File Modified Date : 03/08/2004 07:26:58 م
Filename : C:\WINDOWS\system32\wbem\wmiprvse.exe
Base Address : 0x01000000
Created On : 08/09/2008 05:35:31 ص
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 5684 K
Mem Usage Peak : 5684 K
Page Faults : 1457
Pagefile Usage : 2952 K
Pagefile Peak Usage : 2952 K
File Attributes : A
==================================================
==================================================
Process Name : CProcess.exe
ProcessID : 4484
Priority : Normal
Product Name : CurrProcess
Version : 1.11
Description : CurrProcess
Company : NirSoft
Window Title :
File Size : 35,840
File Created Date : 08/09/2008 02:35:30 ص
File Modified Date : 14/07/2005 04:46:34 ص
Filename : C:\DOCUME~1\user\LOCALS~1\Temp\bntoz\CProcess.exe
Base Address : 0x00400000
Created On : 08/09/2008 05:35:34 ص
Visible Windows : 0
Hidden Windows : 0
User Name : GIGABYTE\user
Mem Usage : 2236 K
Mem Usage Peak : 2312 K
Page Faults : 941
Pagefile Usage : 932 K
Pagefile Peak Usage : 1012 K
File Attributes : A
==================================================
.
.
--------------------------\\\ End Report Of Running Processes ---------------
.
.
.
.
--------------------------\\\ Windows XP Startup List ---------------
.
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
autocheck autochk *
autocheck autochk *
Auto Check Utility
Microsoft Corporation
5.01.2600.2180
c:\windows\system32\autochk.exe
HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms
rdpclip
rdpclip
RDP Clip Monitor
Microsoft Corporation
5.01.2600.2180
c:\windows\system32\rdpclip.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\userinit.exe
Userinit Logon Application
Microsoft Corporation
5.01.2600.2180
c:\windows\system32\userinit.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
Explorer.exe
Explorer.exe
Windows Explorer
Microsoft Corporation
6.00.2900.3156
c:\windows\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Alcmtr
ALCMTR.EXE
Realtek Azalia Audio - Event Monitor
Realtek Semiconductor Corp.
1.06.0000.0002
c:\windows\alcmtr.exe
avgnt
"C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" /min
Antivirus System Tray Tool
Avira GmbH
8.00.0070.0002
c:\program files\avira\avira premium security suite\avgnt.exe
NvCplDaemon
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
NVIDIA Display Properties Extension
NVIDIA Corporation
6.14.0010.7772
c:\windows\system32\nvcpl.dll
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
CTFMON.EXE
C:\WINDOWS\system32\ctfmon.exe
CTF Loader
Microsoft Corporation
5.01.2600.2180
c:\windows\system32\ctfmon.exe
Task Scheduler
AppleSoftwareUpdate.job
C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task
Apple Software Update
Apple Inc.
2.01.0000.0110
c:\program files\apple software update\softwareupdate.exe
.
.
----------- End Report ---------------