؟؟تعجب؟؟
زيزوومي جديد
- إنضم
- 20 نوفمبر 2008
- المشاركات
- 35
- مستوى التفاعل
- 0
- النقاط
- 40
- الإقامة
- sds
- الموقع الالكتروني
- www.zyzoom.org
غير متصل
من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
السلام عليكم
كيفكم إن شاء الله بخير
مشكلتي الا وهي أني أحس أن جهازي بطييييييييي مرههههههههه ويعنق كثيررررررررر
المهم هذا التقرير
وأعذروني على الازعاج والله يوفقكم دنيا واخره
كيفكم إن شاء الله بخير
مشكلتي الا وهي أني أحس أن جهازي بطييييييييي مرههههههههه ويعنق كثيررررررررر
المهم هذا التقرير
كود:
[FONT=Times New Roman]Deckard's System Scanner v20071014.68
Run by STE on 2009-01-02 01:03:41
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 2 Restore Point(s) --
2: 2009-01-01 22:05:19 UTC - RP42 - Deckard's System Scanner Restore Point
1: 2008-12-31 18:47:31 UTC - RP41 - نقطة اختبار النظام
Backed up registry hives.
Performed disk cleanup.
[COLOR=red]Total Physical Memory: 256 MiB (512 MiB recommended).[/COLOR]
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2009-01-02 01:07:05
Platform: Windows XP Service Pack 3 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
D:\AppServ\Apache2.2\bin\httpd.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Documents and Settings\tazebama.dl_
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\AppServ\MySQL\bin\mysqld.exe
C:\Program Files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
D:\AppServ\Apache2.2\bin\httpd.exe
C:\WINDOWS\system32\searchindexer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\STE\Local Settings\Temporary Internet Files\*******.IE5\3U4NJLWX\dss[1].exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [/FONT][URL="http://www.google.com/ie"][FONT=Times New Roman][COLOR=#b02c05]http://www.google.com/ie[/COLOR][/FONT][/URL]
[FONT=Times New Roman]R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [/FONT][URL="http://www.google.com/"][FONT=Times New Roman][COLOR=#b02c05]http://www.google.com[/COLOR][/FONT][/URL]
[FONT=Times New Roman]R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [/FONT][URL="http://www.google.com/"][FONT=Times New Roman][COLOR=#b02c05]http://www.google.com[/COLOR][/FONT][/URL]
[FONT=Times New Roman]R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [/FONT][URL="http://www.google.com/ie"][FONT=Times New Roman][COLOR=#b02c05]http://www.google.com/ie[/COLOR][/FONT][/URL]
[FONT=Times New Roman]R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [/FONT][URL="http://www.google.com/search?q=%s"][FONT=Times New Roman][COLOR=#b02c05]http://www.google.com/search?q=%s[/COLOR][/FONT][/URL]
[FONT=Times New Roman]R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [/FONT][URL="http://www.google.com/ie"][FONT=Times New Roman][COLOR=#b02c05]http://www.google.com/ie[/COLOR][/FONT][/URL]
[FONT=Times New Roman]R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = [/FONT][URL="http://www.google.com/ie"][FONT=Times New Roman][COLOR=#b02c05]http://www.google.com/ie[/COLOR][/FONT][/URL]
[FONT=Times New Roman]R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [/FONT][URL="http://www.google.com/ie"][FONT=Times New Roman][COLOR=#b02c05]http://www.google.com/ie[/COLOR][/FONT][/URL]
[FONT=Times New Roman]O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar2.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &تصدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - D:\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - D:\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى FLV بواسطة Internet Download Manager - D:\Internet Download Manager\IEGetVL.htm
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - [/FONT][URL="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227697779093"][FONT=Times New Roman][COLOR=#b02c05]http://update.microsoft.com/windowsu...?1227697779093[/COLOR][/FONT][/URL]
[FONT=Times New Roman]O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [/FONT][URL="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1227697898453"][FONT=Times New Roman][COLOR=#b02c05]http://update.microsoft.com/microsof...?1227697898453[/COLOR][/FONT][/URL]
[FONT=Times New Roman]O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - Winlogon Notify: DfLogon - C:\WINDOWS\system32\LogonDll.dll
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apache2.2 - Apache Software Foundation - D:\AppServ\Apache2.2\bin\httpd.exe
O23 - Service: DF5Serv - Faronics Corporation - C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: mysql - Unknown owner - D:\AppServ\MySQL\bin\mysqld.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 7028 bytes
-- File Associations -----------------------------------------------------------
[COLOR=red].cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*[/COLOR]
[COLOR=red].cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*[/COLOR]
[COLOR=red].scr - scrfile - shell\open\command - "%1" %*[/COLOR]
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 DeepFrz - c:\windows\system32\drivers\deepfrz.sys <Not Verified; Faronics Corporation; Deep Freeze 5>
R3 tapvpn (TAP VPN Adapter) - c:\windows\system32\drivers\tapvpn.sys <Not Verified; The OpenVPN Project; TAP-Win32 Virtual Network Driver>
S3 abp470n5 - c:\windows\system32\drivers\qphjko.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 AntiVirScheduler (Avira AntiVir Personal – Free Antivirus Scheduler) - "c:\program files\avira\antivir personaledition classic\sched.exe" <Not Verified; Avira GmbH; AntiVir Workstation>
R2 Apache2.2 - "d:\appserv\apache2.2\bin\httpd.exe" -k runservice <Not Verified; Apache Software Foundation; Apache HTTP Server>
R2 DF5Serv - c:\program files\faronics\deep freeze\install c-0\df5serv.exe <Not Verified; Faronics Corporation; Deep Freeze 5>
R2 mysql - d:\appserv\mysql\bin\mysqld --defaults-file=d:\appserv\mysql\my.ini mysql
R2 RichVideo (Cyberlink RichVideo Service(CRVS)) - "c:\program files\cyberlink\shared files\richvideo.exe" <Not Verified; ; RichVideo Module>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
Description: Microsoft PS/2 Mouse
Device ID: ACPI\PNP0F03\4&268D196D&0
Manufacturer: Microsoft
Name: Microsoft PS/2 Mouse
PNP Device ID: ACPI\PNP0F03\4&268D196D&0
Service: i8042prt
-- Files created between 2008-12-02 and 2009-01-02 -----------------------------
2009-01-02 00:43:43 0 drahs---- C:\WINDOWS\system32\wmdrtc32.dl_
2009-01-02 00:43:41 0 drahs---- C:\WINDOWS\system32\wmdrtc32.dll
2009-01-02 00:43:41 0 drahs---- C:\WINDOWS\system32\ntfsus.exe
2009-01-02 00:43:40 0 drahs---- C:\WINDOWS\system32\dnsq.dll
2008-12-31 17:44:43 0 d-------- C:\Documents and Settings\LocalService\Desktop
2008-12-31 15:43:43 0 d-------- C:\Program Files\No-IP
2008-12-31 00:18:31 0 d-------- C:\Documents and Settings\SYSTEM\Application Data
2008-12-31 00:18:31 0 d-------- C:\Documents and Settings\SYSTEM\Application Data\tazebama
2008-12-30 22:38:42 0 d-------- C:\Program Files\a-squared Anti-Malware
2008-12-30 22:03:50 0 d-------- C:\Program Files\AxBx
2008-12-29 20:14:52 155601 --a------ C:\zPharaoh.VIR
2008-12-29 20:14:52 237641 -r-hs---- C:\zPharaoh.exe
2008-12-29 20:14:50 0 d-------- C:\Documents and Settings\STE\Application Data\tazebama
2008-12-14 01:30:58 0 d-------- C:\Program Files\Hotspot Shield
2008-12-13 16:05:01 0 d-------- C:\Documents and Settings\STE\Application Data\Auslogics
2008-12-13 16:00:16 0 d-------- C:\Program Files\Auslogics
2008-12-13 15:59:44 0 d-------- C:\WINDOWS\system32\appmgmt
2008-12-13 03:26:39 0 d-------- C:\WINDOWS\system32\NtmsData
2008-12-13 03:24:08 1744 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-12-12 16:22:11 0 d-------- C:\Program Files\WinASO
2008-12-12 15:56:35 0 d-------- C:\Program Files\Common Files\xing shared
2008-12-12 15:33:06 0 d-------- C:\Documents and Settings\STE\Application Data\Google
2008-12-12 15:30:51 0 d-------- C:\Documents and Settings\All Users\Application Data\Google
2008-12-12 15:30:37 0 d-------- C:\Program Files\Google
2008-12-12 15:27:04 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-12-12 00:08:40 0 d-------- C:\Documents and Settings\All Users\Application Data\SWiSHMax2WorkFolder
2008-12-03 01:56:24 0 dr-h----- C:\Documents and Settings\STE\Recent
2008-12-02 15:21:49 0 d-------- C:\Documents and Settings\STE\Application Data\Windows Search
2008-12-02 15:14:11 0 d-------- C:\Program Files\Microsoft Silverlight
2008-12-02 15:13:39 0 d-------- C:\Documents and Settings\STE\Application Data\Windows Desktop Search
2008-12-02 15:12:02 0 d--h----- C:\WINDOWS\system32\GroupPolicy
2008-12-02 15:12:02 0 d-------- C:\Program Files\Windows Desktop Search
2008-12-02 15:09:34 0 d-------- C:\Program Files\Windows Media Connect 2
2008-12-02 14:55:18 0 d-------- C:\WINDOWS\system32\URTTemp
2008-12-02 13:30:03 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-12-02 01:44:22 0 d-------- C:\Documents and Settings\STE\Application Data\phpDesigner
2008-12-02 01:44:17 0 d-------- C:\Program Files\phpDesigner
2008-12-02 01:42:16 246639 --a------ C:\WINDOWS\unvise32.exe <Not Verified; MindVision Software; Installer VISE>
2008-12-02 01:42:07 0 d-------- C:\Program Files\Common Files\SWiSHzone.com
2008-12-02 01:40:22 0 d-------- C:\Program Files\SWiSH Max2
-- Find3M Report ---------------------------------------------------------------
2009-01-02 00:42:00 0 d-------- C:\Program Files\Windows NT
2009-01-01 13:34:54 225647 --a------ C:\WINDOWS\notepad.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2009-01-01 13:14:05 372079 --a------ C:\WINDOWS\system32\osk.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2009-01-01 13:14:05 225647 --a------ C:\WINDOWS\system32\notepad.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2009-01-01 13:14:05 210287 --a------ C:\WINDOWS\system32\narrator.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2009-01-01 13:14:05 299887 --a------ C:\WINDOWS\system32\mobsync.exe <Not Verified; Microsoft Corporation; Microsoft Synchronization Manager>
2009-01-01 13:14:05 229231 --a------ C:\WINDOWS\system32\magnify.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2009-01-01 13:13:37 695151 --a------ C:\WINDOWS\system32\spider.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2009-01-01 12:52:10 0 d-------- C:\Program Files\Movie Maker
2009-01-01 12:51:51 276335 -----n--- C:\WINDOWS\system32\winmine.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-12-31 16:54:35 213359 --a------ C:\WINDOWS\system32\sol.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-12-31 16:54:34 283503 --a------ C:\WINDOWS\system32\mshearts.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-12-31 16:54:34 211823 --a------ C:\WINDOWS\system32\freecell.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-12-31 16:54:28 545647 --a------ C:\WINDOWS\system32\cmd.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-12-31 16:54:24 295279 --a------ C:\WINDOWS\system32\sndvol32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-12-31 16:54:24 1357167 --a------ C:\WINDOWS\system32\ntbackup.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-12-31 16:54:24 236911 --a------ C:\WINDOWS\system32\charmap.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-12-31 16:54:23 288111 --a------ C:\WINDOWS\system32\sndrec32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-12-31 16:54:23 1190255 --a------ C:\WINDOWS\explorer.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-12-31 16:54:22 834415 --a------ C:\WINDOWS\system32\mstsc.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-12-31 16:54:22 499567 --a------ C:\WINDOWS\system32\mspaint.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-12-31 16:54:21 271215 --a------ C:\WINDOWS\system32\calc.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-12-31 00:18:13 0 d-------- C:\Documents and Settings\STE\Application Data\IDM
2008-12-29 20:56:29 229743 --a------ C:\WINDOWS\ST6UNST.EXE <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>
2008-12-29 20:20:38 309615 --a------ C:\WINDOWS\system32\AUTMGR32.EXE <Not Verified; Microsoft Corporation; Microsoft Remote Automation>
2008-12-29 20:18:31 0 d-------- C:\Documents and Settings\STE\Application Data\DMCache
2008-12-26 15:29:33 0 d-------- C:\Program Files\MSN Messenger
2008-12-26 15:29:33 0 d-------- C:\Program Files\Messenger Plus! Live
2008-12-12 15:56:35 0 d-------- C:\Program Files\Common Files
2008-12-12 15:56:08 0 d-------- C:\Program Files\Common Files\Real
2008-12-11 22:10:56 0 d-------- C:\Documents and Settings\STE\Application Data\Adobe
2008-12-06 00:24:24 1632 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-12-02 02:04:20 25258 --a------ C:\Documents and Settings\STE\Application Data\phpdesigner.xml
2008-11-29 21:47:44 0 d-------- C:\Documents and Settings\STE\Application Data\Paltalk
2008-11-29 21:47:36 0 d-------- C:\Program Files\Paltalk Messenger
2008-11-28 14:10:49 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-11-28 14:10:01 0 d-------- C:\Program Files\QuickTime
2008-11-28 14:05:51 0 d-------- C:\Program Files\Common Files\InstallShield
2008-11-28 13:46:11 0 d-------- C:\Documents and Settings\STE\Application Data\DivX
2008-11-28 13:44:20 0 d-------- C:\Documents and Settings\STE\Application Data\CyberLink
2008-11-28 12:10:14 0 d-------- C:\Documents and Settings\STE\Application Data\Mozilla
2008-11-28 03:43:46 0 d-------- C:\Documents and Settings\STE\Application Data\Real
2008-11-28 03:35:22 0 d-------- C:\Program Files\Microsoft Works
2008-11-26 20:32:22 0 d-------- C:\Program Files\Messenger
2008-11-26 20:29:27 0 d-------- C:\Program Files\MSXML 4.0
2008-11-26 00:24:42 7926561 -----n--- C:\Persi0.sys
2008-11-26 00:24:38 0 d-------- C:\Program Files\Faronics
2008-11-25 23:44:16 0 d-------- C:\Program Files\Common Files\Adobe
2008-11-25 19:44:05 0 d-------- C:\Program Files\Circle Developement
2008-11-25 19:24:26 0 d-------- C:\Program Files\Equis
2008-11-25 19:24:26 0 d-------- C:\Program Files\Common Files\Equis
2008-11-25 19:19:25 0 d-------- C:\Documents and Settings\STE\Application Data\WinRAR
2008-11-25 18:36:09 0 d-------- C:\Program Files\Internet Download Manager
2008-11-25 18:14:41 2048 --a-s---- C:\WINDOWS\bootstet.dat
2008-11-25 10:26:13 0 d-------- C:\Program Files\Web Publish
2008-11-24 23:45:47 0 d-------- C:\Documents and Settings\STE\Application Data\Macromedia
2008-11-24 23:12:04 26 --a------ C:\WINDOWS\system32\kakle.dll
2008-11-24 23:12:01 196608 --a------ C:\WINDOWS\system32\maag.dll <Not Verified; NCT Company Ltd.; NCTWMAFile2 ActiveX DLL>
2008-11-24 23:12:01 1212416 --a------ C:\WINDOWS\system32\ckll.dll <Not Verified; NCT Company Ltd.; NCTAudioInformation2 ActiveX DLL>
2008-11-24 23:12:01 1245184 --a------ C:\WINDOWS\system32\bkll.dll <Not Verified; NCT Company Ltd.; NCTRMFile ActiveX DLL>
2008-11-24 23:12:01 1986560 --a------ C:\WINDOWS\system32\akll.dll <Not Verified; NCT Company Ltd.; NCTAudioFile2 ActiveX DLL>
2008-11-24 23:12:01 2535424 --a------ C:\WINDOWS\system32\agsaamj.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioCompress3 Module>
2008-11-24 23:12:01 90112 --a------ C:\WINDOWS\system32\agsaami.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioFormatSettings3 Module>
2008-11-24 23:12:01 610304 --a------ C:\WINDOWS\system32\agsaamg.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioFile3 Module>
2008-11-24 23:12:01 372736 --a------ C:\WINDOWS\system32\agsaamc.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioFileWMA3 Module>
2008-11-24 23:12:00 0 d-------- C:\Program Files\Real_SC
2008-11-24 23:11:38 0 d-------- C:\Program Files\Yahoo!
2008-11-24 23:06:05 0 d-------- C:\Program Files\Real
2008-11-24 23:02:39 0 d-------- C:\Program Files\Windows Live
2008-11-24 22:55:32 0 d-------- C:\Documents and Settings\STE\Application Data\Talkback
2008-11-24 22:51:45 0 d-------- C:\Program Files\DivX
2008-11-24 22:38:28 0 d-------- C:\Program Files\Avira
2008-11-24 22:33:07 0 d-------- C:\Program Files\Golden Al-Wafi Translator
2008-11-24 22:24:17 0 d-------- C:\Program Files\CyberLink
2008-11-24 21:46:48 0 d-------- C:\Documents and Settings\STE\Application Data\GRETECH
2008-11-24 21:46:07 0 d-------- C:\Program Files\GRETECH
2008-11-24 21:45:25 0 d-------- C:\Program Files\ACD
2008-11-24 21:30:51 0 d-------- C:\Program Files\Common Files\ODBC
2008-11-24 21:30:47 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-11-24 21:30:07 62 --ahs---- C:\Documents and Settings\STE\Application Data\desktop.ini
2008-11-24 21:23:16 0 d-------- C:\Program Files\Microsoft.NET
2008-11-24 19:40:50 0 d-------- C:\Documents and Settings\STE\Application Data\Identities
2008-11-24 19:33:39 0 d-------- C:\Program Files\microsoft frontpage
2008-11-24 19:33:02 0 -rahs---- C:\MSDOS.SYS
2008-11-24 19:33:02 0 -rahs---- C:\IO.SYS
2008-11-24 19:33:02 0 --a------ C:\CONFIG.SYS
2008-11-24 19:33:02 0 --a------ C:\AUTOEXEC.BAT
2008-11-24 19:30:36 0 d--h----- C:\Program Files\WindowsUpdate
2008-11-24 19:30:29 0 d-------- C:\Program Files\Online Services
2008-11-24 19:29:33 0 d-------- C:\Program Files\Common Files\MSSoap
2008-11-24 19:28:08 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-11-24 19:27:18 0 d-------- C:\Program Files\MSN Gaming Zone
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [12/30/2008 10:48 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [12/29/2008 08:17 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"EnableLUA"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"NoDesktop"=0 (0x0)
"NoFileMenu"=0 (0x0)
"StartMenuLogoff"=0 (0x0)
"NoClose"=0 (0x0)
"NoStartMenuMorePrograms"=0 (0x0)
"NoUserNameInStartMenu"=0 (0x0)
"NoSetTaskbar"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [05/26/2008 10:19 PM 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DfLogon]
LogonDll.dll 08/08/2004 03:19 PM 49152 C:\WINDOWS\system32\LogonDll.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[COLOR=red]SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.[/COLOR]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\File system]
@="Driver Group"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\RpcSs]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\vgasave.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=C:\WINDOWS\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^STE^Start Menu^Programs^Startup^Yahoo! Widgets.lnk]
backup=C:\WINDOWS\pss\Yahoo! Widgets.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Auslogics BoostSpeed 4]
C:\Program Files\Auslogics\AusLogics BoostSpeed\boostspeed.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
"C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run-]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run-]
"UserFaultCheck"=%systemroot%\system32\dumprep 0 -u
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
-- End of Deckard's System Scanner: finished at 2009-01-02 01:09:00 ------------[/FONT]
وأعذروني على الازعاج والله يوفقكم دنيا واخره
