• بادئ الموضوع بادئ الموضوع ahm_sha
  • تاريخ البدء تاريخ البدء
  • المشاهدات 1,896

ahm_sha

زيزوومي جديد
إنضم
14 ديسمبر 2008
المشاركات
24
مستوى التفاعل
2
النقاط
20
غير متصل
الرجاء من الاخوه الاعضاء مساعدتى

كل ما اسطب برنامج الحمايه يختفى التسطيب ومش عارف اعمل حمايه للجهاز

عندى مشكله فى tesk manger

ملفات الرجسترى


تقرير الجهاز

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


ارجو المساعد ه
 

اخي الغالي اول ماتشغل الجهاز استمر بالظغط على f8


اعد التشغيل وقبل ظهور شاشة الويندوز

اضغط باستمرار على زر f8


wh_62195183.png


ستاتيك شاشة فيهاا عدة خيارات اختر منهاا

safemode


wh_39783481.png



ثم اختر التالي

wh_12507056.png



wh_11747871.png



من الشاشة التالية اختر حساب الادمن او اي حساب تريد


wh_85829423.png



اخيرا اضغط موافق للدخول لسطح المكتب


wh_64184495.png
 

توقيع : صمت السكوت
اختى خلود انا بضغط على f8 ماتجيب معايا الوضع الامن
 
سطتبت الاداه على الوضع العادى

وده التقرير


System Report
*************
Run on Sun 12/14/2008 at 07:36 PM
Microsoft Windows XP [Version 5.1.2600]
Current user is an administrator
Running Processes:
\SystemRoot\System32\smss.exe [572]
\??\C:\WINDOWS\system32\csrss.exe [624]
\??\C:\WINDOWS\system32\winlogon.exe [648]
C:\WINDOWS\system32\services.exe [692]
C:\WINDOWS\system32\lsass.exe [704]
C:\WINDOWS\system32\svchost.exe [864]
C:\WINDOWS\system32\svchost.exe [944]
C:\WINDOWS\System32\svchost.exe [1040]
C:\WINDOWS\system32\svchost.exe [1136]
C:\WINDOWS\system32\svchost.exe [1172]
C:\WINDOWS\system32\spoolsv.exe [1448]
C:\WINDOWS\Explorer.EXE [148]
C:\Program Files\Internet Download Manager\IDMan.exe [228]
C:\Program Files\Internet Download Manager\IEMonitor.exe [1100]
C:\Program Files\Opera\opera.exe [1516]
C:\Program Files\Internet Explorer\IEXPLORE.EXE [1616]
C:\WINDOWS\system32\wuauclt.exe [1740]

Drivers - Running:
abp470n5
ACPI
AFD
atapi
audstub
Beep
Cdfs
Cdrom
Disk
dmio
dmload
Fastfat
Fdc
Fips
Flpydisk
FltMgr
Ftdisk
Gpc
HDAudBus
hidusb
HTTP
i8042prt
ialm
Imapi
intelppm
IpFilterDriver
IPSec
isapnp
Kbdclass
kmixer
KSecDD
mnmdd
monfilt
Mouclass
MountMgr
MRxDAV
MRxSmb
Msfs
mssmbios
MTsensor
Mup
NDIS
NdisTapi
Ndisuio
NdisWan
NDProxy
NetBIOS
NetBT
Npfs
Null
Parport
PartMgr
ParVdm
PCI
PCIIde
PptpMiniport
PSched
Ptilink
PxHelp20
RasAcd
Rasl2tp
RasPppoe
Raspti
Rdbss
RDPCDD
rdpdr
redbook
RTLE8023xp
serenum
Serial
Srv
swenum
sysaudio
Tcpip
TermDD
Update
usbehci
usbhub
usbuhci
VgaSave
VIAHdAudAddService
VolSnap
Wanarp
wdmaud

Drivers - Stopped:
Abiosdsk
abp480n5
ACPIEC
adpu160m
aec
Aha154x
aic78u2
aic78xx
AliIde
amsint
asc
asc3350p
asc3550
AsyncMac
Atdisk
Atmarpc
cbidf2k
cd20xrnt
Cdaudio
Changer
CmdIde
Cpqarray
dac960nt
dmboot
DMusic
dpti2o
drmkaud
hpn
i2omgmt
i2omp
ini910u
IntelIde
Ip6Fw
IpInIp
IpNat
IRENUM
lbrtfdc
Modem
mraid35x
MSKSSRV
MSPCLOCK
MSPQM
Ntfs
NwlnkFlt
NwlnkFwd
PCIDump
Pcmcia
PDCOMP
PDFRAME
PDRELI
PDRFRAME
perc2
perc2hib
ql1080
Ql10wnt
ql12160
ql1240
ql1280
RDPWD
Secdrv
Sfloppy
Simbad
Sparrow
splitter
sr
swmidi
symc810
symc8xx
sym_hi
sym_u3
TDPIPE
TDTCP
TosIde
Udfs
ultra
ViaIde
WDICA

Services - Running:
AudioSrv
BITS
Browser
CryptSvc
DcomLaunch
Dhcp
dmserver
Dnscache
ERSvc
Eventlog
EventSystem
FastUserSwitchingCompatibility
helpsvc
lanmanserver
lanmanworkstation
LmHosts
Netman
Nla
PlugPlay
PolicyAgent
ProtectedStorage
RasMan
RemoteRegistry
RpcSs
SamSs
Schedule
seclogon
SENS
ShellHWDetection
Spooler
SSDPSRV
TapiSrv
TermService
Themes
TrkWks
W32Time
WebClient
winmgmt
wuauserv
WZCSVC

Services - Stopped:
Alerter
AppMgmt
CiSvc
ClipSrv
COMSysApp
dmadmin
HidServ
HTTPFilter
ImapiService
Messenger
mnmsrvc
MSDTC
MSIServer
NetDDE
NetDDEdsdm
Netlogon
NtLmSsp
NtmsSvc
RasAuto
RDSessMgr
RemoteAccess
RpcLocator
RSVP
SCardSvr
SharedAccess
srservice
stisvc
SwPrv
SysmonLog
TlntSvr
upnphost
UPS
VSS
WmdmPmSN
Wmi
WmiApSrv
wscsvc
xmlprov

Files Created/Modified - 60 Days:

C:\
Dec 14 2008 7:34:16p 2,145,386,496 A.SH. "C:\PAGEFILE.SYS"
Dec 14 2008 2:14:12a 0 A.... "C:\CONFIG.SYS"
Dec 14 2008 2:14:12a 0 A.... "C:\AUTOEXEC.BAT"
Dec 14 2008 2:14:12a 0 A.SHR "C:\IO.SYS"
Dec 14 2008 2:14:12a 0 A.SHR "C:\MSDOS.SYS"

C:\WINDOWS\
Dec 14 2008 7:34:48p 2,048 A.S.. "C:\WINDOWS\bootstat.dat"
Dec 14 2008 2:38:08a 40,128 A.... "C:\WINDOWS\system32\perfc009.dat"
Dec 14 2008 2:38:08a 311,740 A.... "C:\WINDOWS\system32\perfh009.dat"
Dec 14 2008 2:15:56a 151,584 A.... "C:\WINDOWS\system32\FNTCACHE.DAT"
Dec 14 2008 2:11:38a 21,640 A.... "C:\WINDOWS\system32\emptyregdb.dat"
Nov 24 2008 4:32:44p 57,344 A.... "C:\WINDOWS\system32\ff_vfw.dll"
Oct 29 2008 12:35:56a 684,032 A.... "C:\WINDOWS\system32\divx.dll"
Dec 14 2008 2:14:58a 241,664 A..H. "C:\WINDOWS\repair\ntuser.dat"
Dec 14 2008 7:36:54p 0 A.... "C:\WINDOWS\temp\scsF.tmp"
Dec 14 2008 2:38:44p 110 A.... "C:\WINDOWS\ERDNT\CFrecovery.bat"
Dec 14 2008 7:34:18p 6 A..H. "C:\WINDOWS\Tasks\SA.DAT"
Dec 14 2008 7:34:24p 5,669 A.... "C:\WINDOWS\system32\drivers\gppqln.sys"
Oct 16 2008 8:25:34p 15,504 A.... "C:\WINDOWS\system32\drivers\mbam.sys"
Oct 16 2008 8:25:46p 38,496 A.... "C:\WINDOWS\system32\drivers\mbamswissarmy.sys"
Dec 14 2008 5:20:58p 109 A.... "C:\WINDOWS\system32\DirectX\websetup\filelist.dat"
Dec 14 2008 2:13:44a 86,327 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat"
Dec 14 2008 2:13:46a 2,722 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\OfflineOptions.htm"
Dec 14 2008 2:13:46a 13,050 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\OfflineDC.htm"
Dec 14 2008 2:13:46a 627 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Connection.htm"
Dec 14 2008 2:13:46a 30,494 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\pss_getting_worldwide_help.htm"
Dec 14 2008 2:40:08p 245,760 A.... "C:\WINDOWS\ERDNT\Hiv-backup\Users\00000001\NTUSER.DAT"
Dec 14 2008 2:40:08p 8,192 A.... "C:\WINDOWS\ERDNT\Hiv-backup\Users\00000002\UsrClass.dat"
Dec 14 2008 2:40:08p 245,760 A.... "C:\WINDOWS\ERDNT\Hiv-backup\Users\00000003\NTUSER.DAT"
Dec 14 2008 2:40:08p 8,192 A.... "C:\WINDOWS\ERDNT\Hiv-backup\Users\00000004\UsrClass.dat"
Dec 14 2008 2:40:08p 1,122,304 A.... "C:\WINDOWS\ERDNT\Hiv-backup\Users\00000005\NTUSER.DAT"
Dec 14 2008 2:40:08p 8,192 A.... "C:\WINDOWS\ERDNT\Hiv-backup\Users\00000006\UsrClass.dat"
Dec 14 2008 2:13:44a 2,843 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\confirm.htm"
Dec 14 2008 2:13:44a 16,167 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\rcstatus.htm"
Dec 14 2008 2:13:46a 2,317 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\RAHelp.htm"
Dec 14 2008 2:13:46a 2,981 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\RCMoreInfo.htm"
Dec 14 2008 2:13:46a 5,403 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\ConnIssue.htm"
Dec 14 2008 2:13:46a 1,633 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\LearnInternet.htm"
Dec 14 2008 2:13:44a 2,630 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\rcscreen1.htm"
Dec 14 2008 2:13:44a 4,437 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\rcscreen2.htm"
Dec 14 2008 2:13:44a 321 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\rcscreen3.htm"
Dec 14 2008 2:13:44a 3,332 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\rcConnection.htm"
Dec 14 2008 2:13:46a 4,374 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen4.htm"
Dec 14 2008 2:13:46a 14,765 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen5.htm"
Dec 14 2008 2:13:46a 30,465 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen6.htm"
Dec 14 2008 2:13:46a 3,282 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\ShieldsUpMsg.htm"
Dec 14 2008 2:13:46a 1,290 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen6_head.htm"
Dec 14 2008 2:13:46a 5,207 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcInviteStatus.htm"
Dec 14 2008 2:13:46a 8,096 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen7.htm"
Dec 14 2008 2:13:46a 7,662 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen8.htm"
Dec 14 2008 2:13:46a 8,445 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen9.htm"
Dec 14 2008 2:13:46a 4,805 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcDetails.htm"
Dec 14 2008 2:13:46a 3,425 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\escalationhelp.htm"
Dec 14 2008 2:13:46a 13,433 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Unsolicited\UnSolicitedRCUI.htm"

C:\Program Files\
Dec 14 2008 2:14:22a 293,503 A.... "C:\Program Files\iColorFolder\uninstall.exe"
Dec 14 2008 2:23:20a 114,522 A.... "C:\Program Files\Winamp\UninstWA.exe"
Dec 14 2008 2:23:44a 20 A.... "C:\Program Files\WinRAR\rarnew.dat"
Dec 14 2008 2:23:44a 22 A.... "C:\Program Files\WinRAR\zipnew.dat"
Dec 14 2008 2:25:16a 207,020 A.... "C:\Program Files\K-Lite Codec Pack\unins000.dat"
Dec 14 2008 2:24:54a 833,981 A.... "C:\Program Files\K-Lite Codec Pack\unins000.exe"
Oct 28 2008 5:45:02p 109,568 A.... "C:\Program Files\Opera\opera.exe"
Oct 28 2008 5:45:20p 3,704,320 A.... "C:\Program Files\Opera\opera.dll"
Oct 28 2008 5:45:20p 20,480 A.... "C:\Program Files\Opera\OUniAnsi.dll"
Oct 28 2008 5:45:20p 36,864 A.... "C:\Program Files\Opera\spellcheck.dll"
Dec 14 2008 2:02:40p 4,741 A.... "C:\Program Files\Ultra Mobile 3GP Video Converter\unins000.dat"
Dec 14 2008 2:02:34p 667,914 A.... "C:\Program Files\Ultra Mobile 3GP Video Converter\unins000.exe"
Dec 14 2008 2:09:08p 1,915 A.... "C:\Program Files\Ultra Mobile 3GP Video Converter\savedata.dll"
Dec 14 2008 2:08:40p 3,700 A.... "C:\Program Files\Gold Wave Editor\unins000.dat"
Dec 14 2008 2:08:30p 695,578 A.... "C:\Program Files\Gold Wave Editor\unins000.exe"
Oct 22 2008 12:30:18p 1,362,944 A.... "C:\Program Files\Gold Wave Editor\GoldWaveEditor.exe"
Oct 22 2008 12:37:06p 49 A.... "C:\Program Files\Gold Wave Editor\lame.dll"
Dec 14 2008 5:44:02p 8,491 A.... "C:\Program Files\Malwarebytes' Anti-Malware\unins000.dat"
Dec 14 2008 5:43:36p 688,784 A.... "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Oct 16 2008 8:25:32p 65,168 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbam.dll"
Oct 16 2008 8:25:32p 378,344 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbam-dor.exe"
Oct 16 2008 8:25:32p 1,408,656 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe"
Oct 16 2008 8:25:36p 73,360 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll"
Oct 16 2008 8:25:44p 77,968 A.... "C:\Program Files\Malwarebytes' Anti-Malware\zlib.dll"
Oct 16 2008 8:25:42p 44,688 A.... "C:\Program Files\Malwarebytes' Anti-Malware\ssubtmr6.dll"
Oct 16 2008 8:25:38p 468,624 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe"
Oct 16 2008 8:25:38p 242,320 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe"
Nov 10 2008 5:43:26p 1,527,808 A.... "C:\Program Files\K-Lite Codec Pack\Tools\mediainfo.dll"
Nov 22 2008 6:45:16p 1,196,032 A.... "C:\Program Files\K-Lite Codec Pack\Tools\graphstudio.exe"
Oct 16 2008 12:44:20p 15,423 A.... "C:\Program Files\K-Lite Codec Pack\Info\faq.htm"
Oct 16 2008 12:44:16p 4,544 A.... "C:\Program Files\K-Lite Codec Pack\Info\faq_dxva.htm"
Nov 25 2008 4:36:36p 4,034,724 A.... "C:\Program Files\K-Lite Codec Pack\ffdshow\libavcodec.dll"
Nov 24 2008 6:10:00p 547,065 A.... "C:\Program Files\K-Lite Codec Pack\ffdshow\libmplayer.dll"
Nov 24 2008 7:03:20p 52,224 A.... "C:\Program Files\K-Lite Codec Pack\ffdshow\ff_liba52.dll"
Nov 24 2008 7:03:30p 172,032 A.... "C:\Program Files\K-Lite Codec Pack\ffdshow\ff_libdts.dll"
Nov 24 2008 7:04:02p 405,504 A.... "C:\Program Files\K-Lite Codec Pack\ffdshow\ff_libfaad2.dll"
Nov 24 2008 7:04:14p 143,360 A.... "C:\Program Files\K-Lite Codec Pack\ffdshow\ff_libmad.dll"
Nov 24 2008 7:05:18p 56,832 A.... "C:\Program Files\K-Lite Codec Pack\ffdshow\ff_unrar.dll"
Nov 24 2008 6:10:06p 161,044 A.... "C:\Program Files\K-Lite Codec Pack\ffdshow\libmpeg2_ff.dll"
Nov 24 2008 7:04:38p 135,168 A.... "C:\Program Files\K-Lite Codec Pack\ffdshow\ff_samplerate.dll"
Nov 24 2008 4:17:06p 93,184 A.... "C:\Program Files\K-Lite Codec Pack\ffdshow\ff_wmv9.dll"
Nov 23 2008 11:56:54p 4,517,888 A.... "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe"
Nov 10 2008 8:25:42p 5,099,520 A.... "C:\Program Files\K-Lite Codec Pack\Media Player Classic\mpciconlib.dll"
Oct 22 2008 1:47:44p 991,232 A.... "C:\Program Files\K-Lite Codec Pack\Filters\vsfilter.dll"
Dec 14 2008 2:32:46a 130,329 A.... "C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
Oct 28 2008 5:48:02p 448,363 A.... "C:\Program Files\Opera\Skin\standard_skin.zip"
Oct 28 2008 5:48:02p 679 A.... "C:\Program Files\Opera\Skin\windows_skin.zip"
Dec 14 2008 12:52:44p 29 A.... "C:\Program Files\Yahoo!\Messenger\ystats_B.dat"
Nov 26 2008 7:15:32p 225,280 A.... "C:\Program Files\Alwil Software\Avast4\Aavm4h.dll"
Nov 26 2008 7:19:02p 188,416 A.... "C:\Program Files\Alwil Software\Avast4\AavmGuih.dll"
Nov 26 2008 7:15:26p 20,992 A.... "C:\Program Files\Alwil Software\Avast4\AavmRpch.dll"
Nov 26 2008 7:15:42p 35,840 A.... "C:\Program Files\Alwil Software\Avast4\AhResMai.dll"
Nov 26 2008 7:17:12p 32,768 A.... "C:\Program Files\Alwil Software\Avast4\ahResMes.dll"
Nov 26 2008 7:16:50p 53,248 A.... "C:\Program Files\Alwil Software\Avast4\AhResNS.dll"
Nov 26 2008 7:18:40p 29,696 A.... "C:\Program Files\Alwil Software\Avast4\AhResOut.dll"
Nov 26 2008 7:17:06p 33,280 A.... "C:\Program Files\Alwil Software\Avast4\ahResP2P.dll"
Nov 26 2008 7:19:12p 43,008 A.... "C:\Program Files\Alwil Software\Avast4\AhResStd.dll"
Oct 29 2008 11:16:18p 610,304 A.... "C:\Program Files\K-Lite Codec Pack\Real\Rpplugins\rput3260.dll"
Dec 14 2008 12:50:22p 0 A.... "C:\Program Files\Yahoo!\Messenger\Cache\0ujJrQ6wD5C8sS2v5bqVRQ--.ProfileMap.dat.tmp"
Dec 14 2008 2:51:46p 159,792 A.... "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll"

Files with hidden attributes:

Program Folders:
C:\Program Files\
Acoustica MP3 Audio Mixer
Alwil Software
Common Files
ComPlus Applications
Gold Wave Editor
GRETECH
iColorFolder
InstallShield Installation Information
Intel
Internet Download Manager
Internet Explorer
K-Lite Codec Pack
Malwarebytes' Anti-Malware
microsoft frontpage
Movie Maker
MSN Gaming Zone
NetMeeting
Online Services
Opera
Outlook Express
Realtek
Ultra Mobile 3GP Video Converter
Uninstall Information
VIA
Winamp
Windows Media Player
Windows NT
WindowsUpdate
WinRAR
xerox
Yahoo!
C:\Program Files\Common Files\
delet
InstallShield
Microsoft Shared
MSSoap
ODBC
Services
SpeechEngines
System

Add/Remove Programs:
Acoustica MP3 Audio Mixer
CPL All-in-One
Gold Wave Editor v10.2.2
GOM Player
Intel(R) Graphics Media Accelerator Driver
HijackThis 2.0.2
iColorFolder
VIA Platform Device Manager
Internet Download Manager
High Definition Audio Driver Package - KB888111
K-Lite Mega Codec Pack 4.3.4
Malwarebytes' Anti-Malware
Ultra Mobile 3GP Video Converter 3.2.0529
Winamp (remove only)
WinRAR archiver
Yahoo! Messenger
Platform
FIFA 09
Microsoft Visual C++ 2005 Redistributable
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Opera 9.62

Run Values:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"IDMan"="C:\\Program Files\\Internet Download Manager\\IDMan.exe /onboot"

Bot Check:
SERVICE_NAME: wscsvc
DISPLAY_NAME : Security Center
START_TYPE : 3 DEMAND_START

SERVICE_NAME: sharedaccess
DISPLAY_NAME : Windows Firewall/Internet Connection Sharing (ICS)
START_TYPE : 3 DEMAND_START

SERVICE_NAME: wuauserv
DISPLAY_NAME : Automatic Updates
START_TYPE : 2 AUTO_START

SERVICE_NAME: srservice
DISPLAY_NAME : System Restore Service
START_TYPE : 2 AUTO_START

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole]
"EnableDCOM"="Y"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=dword:00000001
"DisableRegistryTools"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"restrictanonymous"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"WaitToKillServiceTimeout"="1000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"SfcDisable"=dword:00000000
"Shell"="Explorer.exe"
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shell extensions]​

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters]
"TransportBindName"="
 
الحين ارفع تقرير جديد للهاجيك
 
توقيع : KoNaMi
اخي التقرير المطلوب بالوضع الامن
 
اذا دخلوا الكبار يخرجوا الصغار

بأذن الله مادام الاخ الاستاذ مااااكس موجود ان شاء الله تنحل المشكلة


 
توقيع : KoNaMi
الجهاز مابيدخل على الوضع الامن

كل مايدخل يعمل ريستارت ومابشتغل​
 
طيب اخي استخدم هذه الاداة

يجب عليك تسجيل الدخول او تسجيل لمشاهدة الرابط المخفي


بعدها اعد التشغيل بالوضع الامن
 
عودة
أعلى