محمد خالد جمال
زيزوومى متألق
- إنضم
- 5 أبريل 2010
- المشاركات
- 307
- مستوى التفاعل
- 18
- النقاط
- 400
غير متصل
من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
السلام عليكم
انا جهازي جنني اولا جربت عليه كل انواع الويندوز و حجات مضمونه و نسخ نضيفة من زيزوم هنا بس للاسف مش عارف فين المشكله و دلوقتي لما اعمل boot من اي اسطوانه علشان انزل نسخه جديده تظهرلي رساله تقول
no emulation system type 00
حاولت اخرج منها معرفتش لازم اعمل ريستارت
فمش عارف افرمت ول حاجه
و تاني شيء ازاي اقدر احدد نوع نواة الجهاز بتاعي يعني انزل عليه 32 ول 64 مش عارف ايهم يناسب جهازي بس انا بنزل 64 هل ممكن يكون دا السبب ؟ و دي صورة
و جهازي على حد علمي خالي من اي ملفات ضارة و بفحصة بشكل دوري و شغال حاليا بكاسبر و محدث و عملتله فحص بأكثر من برنامج اخر كله تمام
و دي التقرار المطلوبه
الرن سكانر
[/URL]
دا تقرير الهايجاك
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:02:17 PM, on 11/3/2014
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Users\mohamed khaled\AppData\Roaming\BitTorrent\BitTorrent.exe
C:\Program Files\Wondershare\MobileGo for Android\MobileGoService.exe
C:\Program Files (x86)\TechSmith\Snagit 11\Snagit32.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
D:\vmware\vmware-tray.exe
C:\Program Files\Wondershare\MobileGo for Android\FileTransfer.exe
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\TechSmith\Snagit 11\TSCHelp.exe
C:\Program Files (x86)\TechSmith\Snagit 11\SnagPriv.exe
C:\Program Files (x86)\TechSmith\Snagit 11\snagiteditor.exe
C:\Program Files\Wondershare\MobileGo for Android\adb.exe
C:\Users\mohamed khaled\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\mohamed khaled\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\mohamed khaled\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\mohamed khaled\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\mohamed khaled\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\mohamed khaled\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Users\mohamed khaled\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Zyzoom_Forum_Tools\zHijak.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [vmware-tray.exe] "D:\vmware\vmware-tray.exe"
O4 - HKLM\..\Run: [FileTransferForMobileGo] C:\Program Files\Wondershare\MobileGo for Android\FileTransfer.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\mohamed khaled\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [BitTorrent] "C:\Users\mohamed khaled\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: MobileGo Service.lnk = C:\Program Files\Wondershare\MobileGo for Android\MobileGoService.exe
O4 - Global Startup: Snagit 11.lnk = C:\Program Files (x86)\TechSmith\Snagit 11\Snagit32.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
(HKLM)
O15 - ESC Trusted Zone:
(HKLM)
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - D:\vmware\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: VMware Workstation Server (VMwareHostd) - Unknown owner - D:\vmware\vmware-hostd.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12841 bytes
تقرير البرامج
====== ??????? ???? ??????? ======
X64 WIN_7 7600
====== ????? ??????? ??????? ======
Adobe Flash Player 15 Plugin
Adobe Reader X (10.1.1)
Avira
Avira
Avira Free Antivirus
FormatFactory 2.60
Internet Download Manager
Kaspersky Internet Security 2013
Kaspersky Internet Security 2013
K-Lite Codec Pack 7.9.0 (Full)
Malwarebytes Anti-Malware version 2.0.3.1025
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MiniTool Partition Wizard Home Edition 8.1.1
MiniTool Power Data Recovery
Mozilla Firefox 19.0.2 (x86 en-US)
Mozilla Maintenance Service
Nero 7 Essentials
PowerISO
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Snagit 11
tools-freebsd
tools-linux
VLC media player
VMware Workstation
WinRAR 5.11 (32-??)
Wondershare MobileGo for Android ( Version 5.3.1 )
تقرير سجلات النظام و الاخطاء
====== ??? ????? ?????? ======
Computer Name: mohamedkhaled
Event Code: 6008
Message: The previous system shutdown at 10:41:57 PM on ?11/?2/?2014 was unexpected.
Record Number: 7463
Source Name: EventLog
Time Written: 20141103064353.000000-000
Event Type: Error
User:
Computer Name: mohamedkhaled
Event Code: 41
Message: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Record Number: 7440
Source Name: Microsoft-Windows-Kernel-Power
Time Written: 20141103064322.300013-000
Event Type: Critical
User: NT AUTHORITY\SYSTEM
Computer Name: mohamedkhaled
Event Code: 1014
Message: Name resolution for the name ssld.oes.avira.com timed out after none of the configured DNS servers responded.
Record Number: 7433
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20141103063055.614119-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: mohamedkhaled
Event Code: 1014
Message: Name resolution for the name dns.msftncsi.com timed out after none of the configured DNS servers responded.
Record Number: 7421
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20141103061616.503572-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: mohamedkhaled
Event Code: 1014
Message: Name resolution for the name dns.msftncsi.com timed out after none of the configured DNS servers responded.
Record Number: 7406
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20141103043109.761380-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
===== ??? ????? ??????? =====
Computer Name: mohamedkhaled
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
5 user registry handles leaked from \Registry\User\S-1-5-21-3351383752-1542105771-4285025494-1000:
Process 4212 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 4212 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 4212 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 4212 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 4212 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Record Number: 2063
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20141103232531.861696-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: mohamedkhaled
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
5 user registry handles leaked from \Registry\User\S-1-5-21-3351383752-1542105771-4285025494-1000:
Process 4328 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 4328 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 4328 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 4328 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 4328 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Record Number: 2030
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20141103214923.576865-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: mohamedkhaled
Event Code: 3036
Message: The content source <csc://{S-1-5-21-3351383752-1542105771-4285025494-1000}/> cannot be accessed.
Context: Application, SystemIndex Catalog
Details:
The URL was already processed during this update. If you received this message while processing alerts, then the alerts are redundant, or else Modify should be used instead of Add. (HRESULT : 0x80040d0d) (0x80040d0d)
Record Number: 2021
Source Name: Microsoft-Windows-Search
Time Written: 20141103213947.000000-000
Event Type: Warning
User:
Computer Name: mohamedkhaled
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
5 user registry handles leaked from \Registry\User\S-1-5-21-3351383752-1542105771-4285025494-1000:
Process 4528 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 4528 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 4528 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 4528 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 4528 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Record Number: 1970
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20141103164326.783745-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: mohamedkhaled
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
20 user registry handles leaked from \Registry\User\S-1-5-21-3351383752-1542105771-4285025494-1000:
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Microsoft\SystemCertificates\Root
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Microsoft\SystemCertificates\trust
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Microsoft\SystemCertificates\My
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Microsoft\SystemCertificates\CA
Process 1948 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 1948 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Policies\Microsoft\SystemCertificates
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Policies\Microsoft\SystemCertificates
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Policies\Microsoft\SystemCertificates
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Policies\Microsoft\SystemCertificates
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 1948 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 1948 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 1948 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
Record Number: 1887
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20141103065534.997217-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
===== ????? ?????? =====
Computer Name: mohamedkhaled
Event Code: 5061
Message: Cryptographic operation.
Subject:
Security ID: S-1-5-18
Account Name: MOHAMEDKHALED$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: RSA
Key Name: {E1EAEC4A-5FF6-4353-AD34-ABE78718F30C}
Key Type: Machine key.
Cryptographic Operation:
Operation: Open Key.
Return Code: 0x0
Record Number: 7017
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20141103041301.611141-000
Event Type: Audit Success
User:
Computer Name: mohamedkhaled
Event Code: 5058
Message: Key file operation.
Subject:
Security ID: S-1-5-18
Account Name: MOHAMEDKHALED$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: Not Available.
Key Name: {E1EAEC4A-5FF6-4353-AD34-ABE78718F30C}
Key Type: Machine key.
Key File Operation Information:
File Path: C:\ProgramData\Microsoft\Crypto\Keys\d1b0241a1bfd376a0881c0f3b4e669c8_ac5e46ee-eeaa-4999-b136-97ceb67f1732
Operation: Read persisted key from file.
Return Code: 0x0
Record Number: 7016
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20141103041301.610141-000
Event Type: Audit Success
User:
Computer Name: mohamedkhaled
Event Code: 5061
Message: Cryptographic operation.
Subject:
Security ID: S-1-5-19
Account Name: LOCAL SERVICE
Account Domain: NT AUTHORITY
Logon ID: 0x3e5
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: RSA
Key Name: a09b86fc-0d16-4a13-afd0-329032b03d67
Key Type: Machine key.
Cryptographic Operation:
Operation: Open Key.
Return Code: 0x0
Record Number: 7015
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20141103041251.218547-000
Event Type: Audit Success
User:
Computer Name: mohamedkhaled
Event Code: 5058
Message: Key file operation.
Subject:
Security ID: S-1-5-19
Account Name: LOCAL SERVICE
Account Domain: NT AUTHORITY
Logon ID: 0x3e5
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: Not Available.
Key Name: a09b86fc-0d16-4a13-afd0-329032b03d67
Key Type: Machine key.
Key File Operation Information:
File Path: C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f61d3368c0cea22a555db69bbd08dfd0_ac5e46ee-eeaa-4999-b136-97ceb67f1732
Operation: Read persisted key from file.
Return Code: 0x0
Record Number: 7014
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20141103041251.218547-000
Event Type: Audit Success
User:
Computer Name: mohamedkhaled
Event Code: 1102
Message: The audit log was cleared.
Subject:
Security ID: S-1-5-21-3351383752-1542105771-4285025494-1000
Account Name: mohamed khaled
Domain Name: mohamedkhaled
Logon ID: 0x16b17
Record Number: 7013
Source Name: Microsoft-Windows-Eventlog
Time Written: 20141103040756.859710-000
Event Type: Audit Success
User:
===== ????? ?????? ??????? =====
===== ????? ?????? ??????? =====
==================================================
Dump File : 110214-39889-01.dmp
Crash Time : 11/2/2014 10:43:59 PM
Bug Check String : IRQL_NOT_LESS_OR_EQUAL
Bug Check Code : 0x0000000a
Parameter 1 : 00000000`00000000
Parameter 2 : 00000000`00000002
Parameter 3 : 00000000`00000001
Parameter 4 : fffff800`02cc418c
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+71f00
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : x64
Computer Name :
Full Path : C:\Windows\Minidump\110214-39889-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 7600
Dump File Size : 286,760
==================================================
يا ريت تساعدوني لاني بحتاج جهازي في دراستي و اصبح حاله بيعطلني و جزاكم الله كل خير
انا جهازي جنني اولا جربت عليه كل انواع الويندوز و حجات مضمونه و نسخ نضيفة من زيزوم هنا بس للاسف مش عارف فين المشكله و دلوقتي لما اعمل boot من اي اسطوانه علشان انزل نسخه جديده تظهرلي رساله تقول
no emulation system type 00
حاولت اخرج منها معرفتش لازم اعمل ريستارت
فمش عارف افرمت ول حاجه
و تاني شيء ازاي اقدر احدد نوع نواة الجهاز بتاعي يعني انزل عليه 32 ول 64 مش عارف ايهم يناسب جهازي بس انا بنزل 64 هل ممكن يكون دا السبب ؟ و دي صورة

و جهازي على حد علمي خالي من اي ملفات ضارة و بفحصة بشكل دوري و شغال حاليا بكاسبر و محدث و عملتله فحص بأكثر من برنامج اخر كله تمام
و دي التقرار المطلوبه
الرن سكانر
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
دا تقرير الهايجاك
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:02:17 PM, on 11/3/2014
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Users\mohamed khaled\AppData\Roaming\BitTorrent\BitTorrent.exe
C:\Program Files\Wondershare\MobileGo for Android\MobileGoService.exe
C:\Program Files (x86)\TechSmith\Snagit 11\Snagit32.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
D:\vmware\vmware-tray.exe
C:\Program Files\Wondershare\MobileGo for Android\FileTransfer.exe
C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\TechSmith\Snagit 11\TSCHelp.exe
C:\Program Files (x86)\TechSmith\Snagit 11\SnagPriv.exe
C:\Program Files (x86)\TechSmith\Snagit 11\snagiteditor.exe
C:\Program Files\Wondershare\MobileGo for Android\adb.exe
C:\Users\mohamed khaled\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\mohamed khaled\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\mohamed khaled\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\mohamed khaled\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\mohamed khaled\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\mohamed khaled\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Zyzoom_Forum_Tools\zyzoom.exe
C:\Users\mohamed khaled\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Zyzoom_Forum_Tools\zHijak.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [vmware-tray.exe] "D:\vmware\vmware-tray.exe"
O4 - HKLM\..\Run: [FileTransferForMobileGo] C:\Program Files\Wondershare\MobileGo for Android\FileTransfer.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\mohamed khaled\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [BitTorrent] "C:\Users\mohamed khaled\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: MobileGo Service.lnk = C:\Program Files\Wondershare\MobileGo for Android\MobileGoService.exe
O4 - Global Startup: Snagit 11.lnk = C:\Program Files (x86)\TechSmith\Snagit 11\Snagit32.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsocklib.dll
O15 - ESC Trusted Zone:
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O15 - ESC Trusted Zone:
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O15 - ESC Trusted Zone:
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O15 - ESC Trusted Zone:
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Service Host (Avira.OE.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - D:\vmware\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: VMware Workstation Server (VMwareHostd) - Unknown owner - D:\vmware\vmware-hostd.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12841 bytes
تقرير البرامج
====== ??????? ???? ??????? ======
X64 WIN_7 7600
====== ????? ??????? ??????? ======
Adobe Flash Player 15 Plugin
Adobe Reader X (10.1.1)
Avira
Avira
Avira Free Antivirus
FormatFactory 2.60
Internet Download Manager
Kaspersky Internet Security 2013
Kaspersky Internet Security 2013
K-Lite Codec Pack 7.9.0 (Full)
Malwarebytes Anti-Malware version 2.0.3.1025
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MiniTool Partition Wizard Home Edition 8.1.1
MiniTool Power Data Recovery
Mozilla Firefox 19.0.2 (x86 en-US)
Mozilla Maintenance Service
Nero 7 Essentials
PowerISO
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Snagit 11
tools-freebsd
tools-linux
VLC media player
VMware Workstation
WinRAR 5.11 (32-??)
Wondershare MobileGo for Android ( Version 5.3.1 )
تقرير سجلات النظام و الاخطاء
====== ??? ????? ?????? ======
Computer Name: mohamedkhaled
Event Code: 6008
Message: The previous system shutdown at 10:41:57 PM on ?11/?2/?2014 was unexpected.
Record Number: 7463
Source Name: EventLog
Time Written: 20141103064353.000000-000
Event Type: Error
User:
Computer Name: mohamedkhaled
Event Code: 41
Message: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Record Number: 7440
Source Name: Microsoft-Windows-Kernel-Power
Time Written: 20141103064322.300013-000
Event Type: Critical
User: NT AUTHORITY\SYSTEM
Computer Name: mohamedkhaled
Event Code: 1014
Message: Name resolution for the name ssld.oes.avira.com timed out after none of the configured DNS servers responded.
Record Number: 7433
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20141103063055.614119-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: mohamedkhaled
Event Code: 1014
Message: Name resolution for the name dns.msftncsi.com timed out after none of the configured DNS servers responded.
Record Number: 7421
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20141103061616.503572-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: mohamedkhaled
Event Code: 1014
Message: Name resolution for the name dns.msftncsi.com timed out after none of the configured DNS servers responded.
Record Number: 7406
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20141103043109.761380-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
===== ??? ????? ??????? =====
Computer Name: mohamedkhaled
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
5 user registry handles leaked from \Registry\User\S-1-5-21-3351383752-1542105771-4285025494-1000:
Process 4212 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 4212 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 4212 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 4212 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 4212 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Record Number: 2063
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20141103232531.861696-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: mohamedkhaled
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
5 user registry handles leaked from \Registry\User\S-1-5-21-3351383752-1542105771-4285025494-1000:
Process 4328 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 4328 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 4328 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 4328 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 4328 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Record Number: 2030
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20141103214923.576865-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: mohamedkhaled
Event Code: 3036
Message: The content source <csc://{S-1-5-21-3351383752-1542105771-4285025494-1000}/> cannot be accessed.
Context: Application, SystemIndex Catalog
Details:
The URL was already processed during this update. If you received this message while processing alerts, then the alerts are redundant, or else Modify should be used instead of Add. (HRESULT : 0x80040d0d) (0x80040d0d)
Record Number: 2021
Source Name: Microsoft-Windows-Search
Time Written: 20141103213947.000000-000
Event Type: Warning
User:
Computer Name: mohamedkhaled
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
5 user registry handles leaked from \Registry\User\S-1-5-21-3351383752-1542105771-4285025494-1000:
Process 4528 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 4528 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 4528 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 4528 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 4528 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Record Number: 1970
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20141103164326.783745-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: mohamedkhaled
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
20 user registry handles leaked from \Registry\User\S-1-5-21-3351383752-1542105771-4285025494-1000:
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Microsoft\SystemCertificates\Root
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Microsoft\SystemCertificates\trust
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Microsoft\SystemCertificates\My
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Microsoft\SystemCertificates\CA
Process 1948 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 1948 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary\Scanner
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Policies\Microsoft\SystemCertificates
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Policies\Microsoft\SystemCertificates
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Policies\Microsoft\SystemCertificates
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Policies\Microsoft\SystemCertificates
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 1948 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 1948 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 1948 (\Device\HarddiskVolume2\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Ahead\Nero Home\MediaLibrary
Process 1884 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3351383752-1542105771-4285025494-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
Record Number: 1887
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20141103065534.997217-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
===== ????? ?????? =====
Computer Name: mohamedkhaled
Event Code: 5061
Message: Cryptographic operation.
Subject:
Security ID: S-1-5-18
Account Name: MOHAMEDKHALED$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: RSA
Key Name: {E1EAEC4A-5FF6-4353-AD34-ABE78718F30C}
Key Type: Machine key.
Cryptographic Operation:
Operation: Open Key.
Return Code: 0x0
Record Number: 7017
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20141103041301.611141-000
Event Type: Audit Success
User:
Computer Name: mohamedkhaled
Event Code: 5058
Message: Key file operation.
Subject:
Security ID: S-1-5-18
Account Name: MOHAMEDKHALED$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: Not Available.
Key Name: {E1EAEC4A-5FF6-4353-AD34-ABE78718F30C}
Key Type: Machine key.
Key File Operation Information:
File Path: C:\ProgramData\Microsoft\Crypto\Keys\d1b0241a1bfd376a0881c0f3b4e669c8_ac5e46ee-eeaa-4999-b136-97ceb67f1732
Operation: Read persisted key from file.
Return Code: 0x0
Record Number: 7016
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20141103041301.610141-000
Event Type: Audit Success
User:
Computer Name: mohamedkhaled
Event Code: 5061
Message: Cryptographic operation.
Subject:
Security ID: S-1-5-19
Account Name: LOCAL SERVICE
Account Domain: NT AUTHORITY
Logon ID: 0x3e5
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: RSA
Key Name: a09b86fc-0d16-4a13-afd0-329032b03d67
Key Type: Machine key.
Cryptographic Operation:
Operation: Open Key.
Return Code: 0x0
Record Number: 7015
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20141103041251.218547-000
Event Type: Audit Success
User:
Computer Name: mohamedkhaled
Event Code: 5058
Message: Key file operation.
Subject:
Security ID: S-1-5-19
Account Name: LOCAL SERVICE
Account Domain: NT AUTHORITY
Logon ID: 0x3e5
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: Not Available.
Key Name: a09b86fc-0d16-4a13-afd0-329032b03d67
Key Type: Machine key.
Key File Operation Information:
File Path: C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f61d3368c0cea22a555db69bbd08dfd0_ac5e46ee-eeaa-4999-b136-97ceb67f1732
Operation: Read persisted key from file.
Return Code: 0x0
Record Number: 7014
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20141103041251.218547-000
Event Type: Audit Success
User:
Computer Name: mohamedkhaled
Event Code: 1102
Message: The audit log was cleared.
Subject:
Security ID: S-1-5-21-3351383752-1542105771-4285025494-1000
Account Name: mohamed khaled
Domain Name: mohamedkhaled
Logon ID: 0x16b17
Record Number: 7013
Source Name: Microsoft-Windows-Eventlog
Time Written: 20141103040756.859710-000
Event Type: Audit Success
User:
===== ????? ?????? ??????? =====
===== ????? ?????? ??????? =====
==================================================
Dump File : 110214-39889-01.dmp
Crash Time : 11/2/2014 10:43:59 PM
Bug Check String : IRQL_NOT_LESS_OR_EQUAL
Bug Check Code : 0x0000000a
Parameter 1 : 00000000`00000000
Parameter 2 : 00000000`00000002
Parameter 3 : 00000000`00000001
Parameter 4 : fffff800`02cc418c
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+71f00
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
Processor : x64
Computer Name :
Full Path : C:\Windows\Minidump\110214-39889-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 7600
Dump File Size : 286,760
==================================================
يا ريت تساعدوني لاني بحتاج جهازي في دراستي و اصبح حاله بيعطلني و جزاكم الله كل خير

التعديل الأخير: