نظام التشغيل لدي وندوز 7
المتصفح كان 9 ونزلت 10 كمحاوله لحل المشكله لكنها استمرت
المشكله. عندما احاول فتح تبويب جديد في المتصفح او ظغط خيار السيتنق يعمل فريز البرنامج لمدة دقيقه تقريبآ ثم يعود للوضع الطبيعي. ايضآ اواجه مشكله في تشغيل المواقع التي تتطلب الجافا
وبشكل عام الاحظ بطئ في الجهاز بشكل عام
التقارير
الهايجاك
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:46:29 AM, on 4/19/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Uniblue\Powersuite\powersuite_monitor.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\PROGRAM FILES\HEWLETT-PACKARD\HP QUICK LAUNCH BUTTONS\QLBCTRL.EXE
C:\Users\dw\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\dw\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\dw\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\dw\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_7_700_169_ActiveX.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Windows\System32\MsSpellCheckingFacility.exe
C:\Zyzoom_Forum_Tools\zHijak.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Expat Shield Class - {3706EE7C-3CAD-445D-8A43-03EBC3B75908} - C:\Program Files\Expat Shield\HssIE\ExpatIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~1\IObit\AD024A~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [SynTPEnh] %programfiles%\synaptics\syntp\syntpenh.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Program Files\IObit\IObit Malware Fighter\IMF.exe" /autostart
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O4 - HKCU\..\Run: [Advanced SystemCare Ultimate] "C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [IDMan] C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IDMAN.EXE /onboot
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone:
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O15 - Trusted Zone:
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O15 - Trusted Zone: *.aramco.com
O15 - Trusted Zone:
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O16 - DPF: {6924091F-CD97-41E1-B1D4-D9079409D413} -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O16 - DPF: {7253A666-804A-1107-A4DC-00E04C504788} -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.7.0) -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O16 - DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A843A6B-1120-43D9-B899-DA3B5E8792D3}: NameServer = 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\..\{646DF79B-5658-48C4-B25F-99FAE898641F}: NameServer = 94.77.215.126,208.67.222.222
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0\ViProtocol.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Program Files\IObit\Advanced SystemCare Ultimate\ascsvc.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AdvancedSystemCareAntivirus (ASCAntivirusSrv) - IOBit - C:\Program Files\IObit\Advanced SystemCare Ultimate\ascavsvc.exe
O23 - Service: Ast Service - IOBit - (no file)
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: CDMA Device Service - Unknown owner - C:\Program Files\Samsung\USB Drivers\26_VIA_driver2\x86\VIAService.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Expat Shield Service (ExpatShieldService) - Unknown owner - C:\Program Files\Expat Shield\bin\openvpnas.exe
O23 - Service: Expat Shield Routing Service (ExpatSrv) - AnchorFree Inc. - C:\Program Files\Expat Shield\HssWPR\hsssrv.exe
O23 - Service: Expat Shield Tray Service (ExpatTrayService) - Unknown owner - C:\Program Files\Expat Shield\bin\ExpatTrayService.EXE
O23 - Service: Expat Shield Monitoring Service (ExpatWd) - Unknown owner - C:\Program Files\Expat Shield\bin\hsswd.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: RelevantKnowledge - Unknown owner - (no file)
O23 - Service: RtVOsdService Installer (RtVOsdService) - Realtek Semiconductor Corp. - C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Messenger Sharing Folders USN Journal Reader service (usnjsvc) - Unknown owner - C:\Program Files\Windows Live\Messenger\usnsvc.exe (file missing)
O23 - Service: vToolbarUpdater14.2.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
O23 - Service: Wyse PocketCloud (WysePocketCloud) - Unknown owner - C:\Program Files\Wyse\PocketCloud Windows Companion\PocketCloudService.exe
--
End of file - 13002 bytes
رن سكانر
Runscanner logfile
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
* = signed file
- = file not found
General info
------------
Computer name : 6E7NOON
Creation time : 4/19/2013 1:48:28 AM
Hosts <> 127.0.0.1 : 0
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 9.10.9200.16540
OS : Windows 7 Ultimate
OS Build : 7601
OS SP : Service Pack 1
RunScanner Version : 2.0.0.50
User Language : Arabic (Saudi Arabia)
User rights : Administrator
Windows folder : C:\Windows
Running processes
-----------------
* C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
* C:\Windows\System32\Macromed\Flash\FlashUtil32_11_7_700_169_ActiveX.exe (Adobe Systems Incorporated)
* C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCSvc.exe (IObit)
* C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCAvSvc.exe (IOBit)
* C:\Windows\System32\atieclxx.exe (AMD)
* C:\Windows\System32\atiesrxx.exe (AMD)
* C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe (Andrea Electronics Corporation)
* C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe (IObit)
* C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
* C:\Program Files\AVG\AVG2013\avgfws.exe (AVG Technologies CZ, s.r.o.)
* C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
* C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
* C:\PROGRA~1\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
* C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
* C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
* C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
* C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
* C:\Windows\System32\csrss.exe (Microsoft Corporation)
* C:\Windows\System32\csrss.exe (Microsoft Corporation)
* C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Hewlett-Packard Development Company, L.P.)
* C:\Program Files\DivX\DivX Update\DivXUpdate.exe
* C:\Users\dw\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Users\dw\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Users\dw\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Users\dw\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
* C:\Program Files\Google\Update\1.3.21.135\GoogleCrashHandler.exe (Google Inc.)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\svchost.exe (Microsoft Corporation)
* C:\Windows\System32\taskhost.exe (Microsoft Corporation)
* C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
* C:\Program Files\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
* C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Company)
* C:\Program Files\Expat Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
* C:\Program Files\Expat Shield\bin\hsswd.exe
* C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
* C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
* C:\Program Files\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
* C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
* C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
* C:\Program Files\IObit\IObit Malware Fighter\IMF.exe (IObit)
* C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
* C:\Windows\System32\lsass.exe (Microsoft Corporation)
* C:\Windows\System32\lsm.exe (Microsoft Corporation)
* C:\Windows\System32\MsSpellCheckingFacility.exe (Microsoft Corporation)
* C:\Windows\System32\SearchIndexer.exe (Microsoft Corporation)
* C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
* C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corp.)
* C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
* C:\Program Files\Expat Shield\bin\openvpnas.exe
C:\Program Files\Wyse\PocketCloud Windows Companion\PocketCloudService.exe
* C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe ( Hewlett-Packard Development Company, L.P.)
* C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
* C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
C:\Program Files\Realtek\RtVOsd\RtVOsd.exe (Realtek Semiconductor Corp.)
C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe (Realtek Semiconductor Corp.)
* C:\Windows\System32\services.exe (Microsoft Corporation)
* C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
* C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
* C:\Windows\System32\taskeng.exe (Microsoft Corporation)
* C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
* C:\Program Files\Uniblue\Powersuite\powersuite_monitor.exe (Uniblue Systems Ltd)
C:\Program Files\Samsung\USB Drivers\26_VIA_driver2\x86\VIAService.exe
* C:\Program Files\AVG Secure Search\vprot.exe
* C:\Windows\explorer.exe (Microsoft Corporation)
* C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
* C:\Program Files\Windows Live\Mail\wlmail.exe (Microsoft Corporation)
* C:\Windows\System32\winlogon.exe (Microsoft Corporation)
* C:\Windows\System32\smss.exe (Microsoft Corporation)
* C:\Windows\System32\wininit.exe (Microsoft Corporation)
* C:\Windows\System32\wbem\WmiPrvSE.exe (Microsoft Corporation)
* C:\Windows\System32\wbem\WmiPrvSE.exe (Microsoft Corporation)
C:\Zyzoom_Forum_Tools\zyzoom.exe
Unrated items
-------------
002 * C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
002 * C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
002 C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe (DivX, LLC)
002 * C:\Program Files\DivX\DivX Update\DivXUpdate.exe
002 * C:\Program Files\IObit\IObit Malware Fighter\IMF.exe (IObit)
002 * C:\Program Files\Common Files\Java\Java Update\jusched.exe (Oracle Corporation)
002 * C:\Program Files\AVG Secure Search\vprot.exe
003 * C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCTray.exe (IObit)
010 * C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Acrobat Update Service)
010 * C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe® Flash® Player Update Service 11.7 r700)
010 * C:\Program Files\IObit\Advanced SystemCare Ultimate\ascsvc.exe (Advanced SystemCare Service)
010 * C:\Program Files\IObit\Advanced SystemCare Ultimate\ascavsvc.exe (Advanced SystemCare Ultimate Service)
010 * C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe (Andrea filters APO access service (32-bit))
010 * C:\Program Files\AVG\AVG2013\avgfws.exe (AVG Firewall Service)
010 * C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Identity Protection Service)
010 * C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Watchdog Service)
010 * C:\Program Files\Expat Shield\bin\ExpatTrayService.EXE (ExpatTrayService.EXE)
010 * C:\Program Files\Expat Shield\HssWPR\hsssrv.exe (hsssrv.exe)
010 * C:\Program Files\Expat Shield\bin\hsswd.exe (hsswd.exe)
010 * C:\Program Files\iPod\bin\iPodService.exe (iPodService Module (32-bit))
010 * C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (maintenanceservice.exe)
010 * C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (MobileDeviceService)
010 * C:\Program Files\Expat Shield\bin\openvpnas.exe (openvpnas.exe)
010 C:\Program Files\Wyse\PocketCloud Windows Companion\PocketCloudService.exe (PocketCloudService)
010 * C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService)
010 C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe (RtVOsdService)
010 * C:\Program Files\Skype\Updater\Updater.exe (Skype Updater Service)
010 * C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe (ToolbarU Application)
010 C:\Program Files\Samsung\USB Drivers\26_VIA_driver2\x86\VIAService.exe (VIA Telecom Service)
011 * C:\Windows\system32\DRIVERS\amdkmpfd.sys (AMD PCI Root Bus Lower Filter)
011 * C:\Windows\system32\DRIVERS\avgrkx86.sys (AVG Anti-Rootkit Driver)
011 * C:\Windows\system32\DRIVERS\avgldx86.sys (AVG AVI Loader Driver)
011 * C:\Windows\system32\DRIVERS\avgfwd6x.sys (AVG Filter Driver)
011 * C:\Windows\system32\DRIVERS\avglogx.sys (AVG Logging Driver)
011 * C:\Windows\system32\DRIVERS\avgtdix.sys (AVG Network connection watcher)
011 * C:\Windows\system32\DRIVERS\avgmfx86.sys (AVG Resident Shield Minifilter Driver)
011 * C:\Windows\system32\drivers\avgtpx86.sys (avgtpx86.sys)
011 * C:\Windows\system32\DRIVERS\avgidsdriverx.sys (IDS Application Activity Monitor Driver.)
011 * C:\Windows\system32\DRIVERS\avgidshx.sys (IDS Application Activity Monitor Helper Driver.)
011 * C:\Windows\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver.)
011 * C:\Windows\system32\DRIVERS\iusb3hcs.sys (Intel(R) USB 3.0 Host Controller Switch Driver)
011 * C:\Program Files\UltraISO\drivers\ISODrive.sys (ISO DVD/CD-ROM Device Driver)
011 C:\Windows\system32\drivers\pfc.sys (Padus(R) ASPI Shell)
011 * C:\Windows\system32\DRIVERS\netr28.sys (Ralink 802.11 Wireless Adapter Driver)
011 * C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_51755.sys (RapportCerberus32_51755.sys)
011 * C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys (RapportEI)
011 * c:\programdata\trusteer\rapport\store\exts\rapportms\baseline\rapportiaso.sys (RapportIaso)
011 * C:\Windows\System32\Drivers\RapportKELL.sys (RapportKE)
011 * C:\Windows\system32\DRIVERS\Rt86win7.sys (Realtek 8101E/8168/8169 NDIS 6.20 32-bit Driver )
011 * C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys (Registry Filter)
011 * C:\Windows\system32\DRIVERS\taphss.sys (TAP-Win32 Virtual Network Driver)
011 * C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\UrlFilter.sys (URL Filter)
031 GUID / CLSID not found {828030A1-22C1-4009-854F-8E305202313F}
031 GUID / CLSID not found {828030A1-22C1-4009-854F-8E305202313F}
031 * C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D}
031 * C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0\ViProtocol.dll {B658800C-F66E-4EF3-AB85-6C0C227862A9}
041 * C:\Program Files\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll {95B7759C-8C7F-4BF1-B163-73684A933233}
042 GUID / CLSID not found {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
042 GUID / CLSID not found {219C3416-8CB2-491a-A3C7-D9FCDDC9D600}
047 Zone: alipay.com :
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
047 Zone: alipay.com :
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
047 Zone: alisoft.com :
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
047 Zone: alisoft.com :
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
047 Zone: aramco.com : *.aramco.com
047 Zone: taobao.com :
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
047 Zone: taobao.com :
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
047 Zone:
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
052 GUID / CLSID not found {7E853D72-626A-48EC-A868-BA8D5E23E045}
052 * C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
052 * C:\PROGRA~1\IObit\AD024A~1\BROWER~1\ASCPLU~1.DLL (IObit) {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
052 * C:\Program Files\Expat Shield\HssIE\ExpatIE.dll (AnchorFree Inc.) {3706EE7C-3CAD-445D-8A43-03EBC3B75908}
052 * C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
052 * C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) {DBC80044-A445-435b-BC74-9C25C1C588A9}
052 * C:\Program Files\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll {95B7759C-8C7F-4BF1-B163-73684A933233}
060 GUID / CLSID not found {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
061 * C:\Program Files\AVG\AVG2013\avgse.dll (AVG Technologies CZ, s.r.o.) {9F97547E-4609-42C5-AE0C-81C61FFAEBC3}
061 C:\Program Files\DivX\DivX Plus Media Foundation Components\DivXPropertyHandler.dll (DivX, Inc.) {D8D1CE8C-B1EB-4E95-B63B-1531BA60E992}
061 C:\Program Files\DivX\DivX Plus Media Foundation Components\DivXThumbnailProvider.dll (DivX, Inc.) {83238FAE-D346-4E12-8734-D42F7554B3E6}
061 * C:\Program Files\iTunes\iTunesMiniPlayer.dll (Apple Inc.) {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}
061 * C:\Program Files\UltraISO\isoshell.dll (EZB Systems, Inc.) {AD392E40-428C-459F-961E-9B147782D099}
061 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
061 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
061 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79305-84BE-11CE-9641-444553540000}
061 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79306-84BE-11CE-9641-444553540000}
061 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79307-84BE-11CE-9641-444553540000}
062 * C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll (Adobe Systems, Inc.) {F9DB5320-233E-11D1-9F84-707F02C10627}
073 Adobe Flash Player Updater.job : C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
073 powersuite_monitor.job : C:\Program Files\Uniblue\Powersuite\powersuite_monitor.exe (Uniblue Systems Ltd)
073 ROC_JAN2013_TB_rmv.job : C:\Program Files\AVG Secure Search\PostInstall\ROC.exe
100 Start Page HKCU :
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
104 GUID / CLSID not found {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A}
104 GUID / CLSID not found {6924091F-CD97-41E1-B1D4-D9079409D413}
104 GUID / CLSID not found {7253A666-804A-1107-A4DC-00E04C504788}
104 * C:\Program Files\HP\Common\HPGMNRev.dll (Hewlett-Packard) {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
104 * C:\Program Files\Java\jre7\bin\jp2iexp.dll {8AD9C840-044E-11D1-B3E9-00805F499D93}
104 GUID / CLSID not found {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA}
104 GUID / CLSID not found {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9}
104 * C:\Program Files\Java\jre7\bin\jp2iexp.dll {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
104 * C:\Program Files\Java\jre7\bin\jp2iexp.dll {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
104 * C:\Program Files\Java\jre7\bin\jp2iexp.dll {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
104 * C:\Program Files\Java\jre7\bin\jp2iexp.dll {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
104 * C:\Program Files\Java\jre7\bin\jp2iexp.dll {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
104 GUID / CLSID not found {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
105 Download all links with IDM : C:\Program Files\Internet Download Manager\IEGetAll.htm
105 Download FLV video content with IDM : C:\Program Files\Internet Download Manager\IEGetVL.htm
105 Download with IDM : C:\Program Files\Internet Download Manager\IEExt.htm
120 NameServer {4A843A6B-1120-43D9-B899-DA3B5E8792D3} : 8.8.8.8
120 NameServer {646DF79B-5658-48C4-B25F-99FAE898641F} : 94.77.215.126,208.67.222.222
170 {ccc41083-ac08-11e0-9c27-00c0ca2660fd} : H:\AutoRun.exe
170 G : G:\AutoRun.exe TMM80
170 H : H:\AutoRun.exe
173 * C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCExtMenu.dll {9486A9B2-D787-4eca-A25C-4A0086BB4154}
173 * C:\Program Files\AVG\AVG2013\avgse.dll (AVG Technologies CZ, s.r.o.) {9F97547E-4609-42C5-AE0C-81C61FFAEBC3}
173 C:\Program Files\MyPhoneExplorer\DLL\ShellMgr.dll (F.J. Wechselberger) {A372C6DF-7A85-41B1-B3B0-D1E24073DCBF}
173 * C:\Program Files\Trademanager\AliIMExt.dll (Alibaba software (Shanghai) Corporation.) {0DE1378D-F811-40E6-B60A-1CC56F57D3E9}
173 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
173 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
221 * C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCExtMenu.dll {9486A9B2-D787-4eca-A25C-4A0086BB4154}
221 * C:\Program Files\AVG\AVG2013\avgse.dll (AVG Technologies CZ, s.r.o.) {9F97547E-4609-42C5-AE0C-81C61FFAEBC3}
221 C:\Program Files\MyPhoneExplorer\DLL\ShellMgr.dll (F.J. Wechselberger) {A372C6DF-7A85-41B1-B3B0-D1E24073DCBF}
221 * C:\Program Files\Trademanager\AliIMExt.dll (Alibaba software (Shanghai) Corporation.) {0DE1378D-F811-40E6-B60A-1CC56F57D3E9}
221 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
221 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
225 * C:\Program Files\AVG\AVG2013\avgse.dll (AVG Technologies CZ, s.r.o.) {9F97547E-4609-42C5-AE0C-81C61FFAEBC3}
225 * C:\Program Files\AVG\AVG2013\avgse.dll (AVG Technologies CZ, s.r.o.) {9F97547E-4609-42C5-AE0C-81C61FFAEBC3}
225 * C:\Program Files\UltraISO\isoshell.dll (EZB Systems, Inc.) {AD392E40-428C-459F-961E-9B147782D099}
225 * C:\Program Files\UltraISO\isoshell.dll (EZB Systems, Inc.) {AD392E40-428C-459F-961E-9B147782D099}
225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
225 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
227 * C:\Program Files\IObit\Advanced SystemCare Ultimate\ASCExtMenu.dll {9486A9B2-D787-4eca-A25C-4A0086BB4154}
227 * C:\Program Files\UltraISO\isoshell.dll (EZB Systems, Inc.) {AD392E40-428C-459F-961E-9B147782D099}
227 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
227 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79304-84BE-11CE-9641-444553540000}
231 * C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll (Adobe Systems, Inc.) PDF Column Info
241 GUID / CLSID not found {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}
241 GUID / CLSID not found {BBACC218-34EA-4666-9D7A-C78F2274A524}
241 GUID / CLSID not found {F241C880-6982-4CE5-8CF7-7085BA96DA5A}
251 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
251 C:\PROGRA~1\WINZIP\WZSHLSTB.DLL (WinZip Computing, Inc.) {E0D79305-84BE-11CE-9641-444553540000}
Missing files
-------------
010 C:\Program Files\Windows Live\Messenger\usnsvc.exe
011 C:\Windows\system32\drivers\dgderdrv.sys
011 C:\Windows\system32\drivers\MsgPlusDriver.sys
011 C:\Windows\system32\drivers\ntkvpn.sys
011 C:\Windows\system32\drivers\ntkvpnMP.sys
011 C:\Windows\system32\drivers\Synth3dVsc.sys
011 C:\Windows\system32\drivers\tsusbhub.sys
011 C:\Windows\system32\drivers\VGPU.sys
====== سجل أخطاء النظام ======
Computer Name: 6E7NooN
Event Code: 7001
Message: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 305881
Source Name: Service Control Manager
Time Written: 20121012204945.844039-000
Event Type: Error
User:
Computer Name: 6E7NooN
Event Code: 7001
Message: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 305878
Source Name: Service Control Manager
Time Written: 20121012203234.133973-000
Event Type: Error
User:
Computer Name: 6E7NooN
Event Code: 7001
Message: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 305876
Source Name: Service Control Manager
Time Written: 20121012203228.241965-000
Event Type: Error
User:
Computer Name: 6E7NooN
Event Code: 1014
Message: Name resolution for the name talk.google.com timed out after none of the configured DNS servers responded.
Record Number: 305875
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20121012203057.075538-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: 6E7NooN
Event Code: 7001
Message: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Record Number: 305857
Source Name: Service Control Manager
Time Written: 20121012194818.817978-000
Event Type: Error
User:
===== سجل أخطاء البرامج =====
Computer Name: 6E7NooN
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
7 user registry handles leaked from \Registry\User\S-1-5-21-3668072191-2361732937-1622430930-1000:
Process 624 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3668072191-2361732937-1622430930-1000
Process 624 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3668072191-2361732937-1622430930-1000
Process 1388 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3668072191-2361732937-1622430930-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 624 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3668072191-2361732937-1622430930-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 1388 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3668072191-2361732937-1622430930-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Process 624 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3668072191-2361732937-1622430930-1000\Software\Microsoft\SystemCertificates\My
Process 624 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3668072191-2361732937-1622430930-1000\Software\Microsoft\SystemCertificates\CA
Record Number: 26323
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20111128001754.631915-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: 6E7NooN
Event Code: 3036
Message: The content source <csc://{S-1-5-21-3668072191-2361732937-1622430930-1000}/> cannot be accessed.
Context: Application, SystemIndex Catalog
Details:
The object was not found. (HRESULT : 0x80041201) (0x80041201)
Record Number: 26315
Source Name: Microsoft-Windows-Search
Time Written: 20111127194001.000000-000
Event Type: Warning
User:
Computer Name: 6E7NooN
Event Code: 8194
Message: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied.
. This is often caused by incorrect security settings in either the writer or requestor process.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {14798b17-32cc-4700-b625-18a956141fee}
Record Number: 26288
Source Name: VSS
Time Written: 20111122181943.000000-000
Event Type: Error
User:
Computer Name: 6E7NooN
Event Code: 3036
Message: The content source <csc://{S-1-5-21-3668072191-2361732937-1622430930-1000}/> cannot be accessed.
Context: Application, SystemIndex Catalog
Details:
The object was not found. (HRESULT : 0x80041201) (0x80041201)
Record Number: 26283
Source Name: Microsoft-Windows-Search
Time Written: 20111122145812.000000-000
Event Type: Warning
User:
Computer Name: 6E7NooN
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
5 user registry handles leaked from \Registry\User\S-1-5-21-3668072191-2361732937-1622430930-1000:
Process 624 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3668072191-2361732937-1622430930-1000
Process 624 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3668072191-2361732937-1622430930-1000
Process 624 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3668072191-2361732937-1622430930-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 624 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3668072191-2361732937-1622430930-1000\Software\Microsoft\SystemCertificates\My
Process 624 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3668072191-2361732937-1622430930-1000\Software\Microsoft\SystemCertificates\CA
Record Number: 26255
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20111122132706.386381-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
===== السجل الأمني =====
Computer Name: 6E7NooN
Event Code: 5033
Message: The Windows Firewall Driver started successfully.
Record Number: 47663
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120319155400.336078-000
Event Type: Audit Success
User:
Computer Name: 6E7NooN
Event Code: 4672
Message: Special privileges assigned to new logon.
Subject:
Security ID:S-1-5-18
Account Name:SYSTEM
Account Domain:NT AUTHORITY
Logon ID:0x3e7
Privileges:SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 47662
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120319155358.926076-000
Event Type: Audit Success
User:
Computer Name: 6E7NooN
Event Code: 4624
Message: An account was successfully logged on.
Subject:
Security ID:S-1-5-18
Account Name:6E7NOON$
Account Domain:WORKGROUP
Logon ID:0x3e7
Logon Type:5
New Logon:
Security ID:S-1-5-18
Account Name:SYSTEM
Account Domain:NT AUTHORITY
Logon ID:0x3e7
Logon GUID:{00000000-0000-0000-0000-000000000000}
Process Information:
Process ID:0x2cc
Process Name:C:\Windows\System32\services.exe
Network Information:
Workstation Name:
Source Network Address:-
Source Port:-
Detailed Authentication Information:
Logon Process:Advapi
Authentication Package:Negotiate
Transited Services:-
Package Name (NTLM only):-
Key Length:0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 47661
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120319155358.926076-000
Event Type: Audit Success
User:
Computer Name: 6E7NooN
Event Code: 5056
Message: A cryptographic self test was performed.
Subject:
Security ID:S-1-5-18
Account Name:6E7NOON$
Account Domain:WORKGROUP
Logon ID:0x3e7
Module:ncrypt.dll
Return Code:0x0
Record Number: 47660
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120319155356.044471-000
Event Type: Audit Success
User:
Computer Name: 6E7NooN
Event Code: 4672
Message: Special privileges assigned to new logon.
Subject:
Security ID:S-1-5-18
Account Name:SYSTEM
Account Domain:NT AUTHORITY
Logon ID:0x3e7
Privileges:SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 47659
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120319155353.829267-000
Event Type: Audit Success
User:
===== تقرير انهيار البرامج =====
===== تقرير الشاشة الزرقاء =====
====== معلومات نظام التشغيل ======
X86 WIN_7 7601 Service Pack 1
====== قائمة البرامج المثبتة ======
Update for Microsoft Office 2007 (KB2508958)
Adobe Acrobat 4.0
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.6)
Advanced SystemCare Ultimate 6
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Install Manager
AVG 2013
AVG 2013
AVG 2013
AVG Security Toolbar
D3DX10
DivX Setup
Expat Shield 2.24
Free Alarm Clock 2.7.0
Google Earth
Google Earth Pro
Google Update Helper
Hewlett-Packard ACLM.NET v1.1.0.0
Hotfix for Microsoft .NET Framework 4 Client Profile (KB2461678)
HP Customer Experience Enhancements
HP Product Detection
HP Product Detection
HP Quick Launch Buttons
HP Support Assistant
Intel(R) Control Center
Intel(R) Rapid Storage Technology
Internet Download Manager
IObit Malware Fighter
iTunes
Java 7 Update 21
Java Auto Updater
Java(TM) 6 Update 12
Java(TM) 6 Update 17
Java(TM) 6 Update 31
Java(TM) 6 Update 7
JavaFX 2.1.1
JDownloader 2.0
Junk Mail filter update
ManyCam 2.6.55 (remove only)
Media Player Classic - Home Cinema v1.5.0.2827
Messenger Plus!
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Primary Interoperability Assemblies 2005
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Mobily Connect Card
Movie Maker
Movie Maker
Mozilla Firefox 19.0.2 (x86 en-US)
Mozilla Maintenance Service
MpcStar 5.3
MSVCRT
MSVCRT110
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MyPhoneExplorer
Paltalk Messenger 10.2
Photo Common
Photo Gallery
Photo Gallery
PocketCloud Windows Companion
PowerDVD
Protected Folder
QLBCASL
QuickTime
Ralink RT3090 802.11b/g/n WiFi Adapter
Rapport
Rapport
Realtek High Definition Audio Driver
Registry Mechanic 10.0
Revo Uninstaller 1.94
RtVOsd
Samsung Kies
Samsung Kies
SAMSUNG USB Driver for Mobile Phones
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
Skype™ 6.3
Smart Defrag 2
Synaptics Pointing Device Driver
TradeManager 2012
UltraISO Premium V9.36
Uniblue Powersuite
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2768021) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VC80CRTRedist - 8.0.50727.6195
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VLC media player 1.1.11
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Family Safety
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mail
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer
Windows Live Writer
Windows Live Writer Resources
WinRAR archiver
WinZip
ولكم جزيل الشكر
