.
--------------------------\\\ Start Report Of HijackThis ---------------
.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:33:15 AM, on 8/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\Internet Download Manager\IDMan.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Windows Live\Messenger\msnmsgr.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\DOCUME~1\XPPRESP3\LOCALS~1\Temp\bntoz\runn.exe
D:\WINDOWS\system32\cmd.exe
D:\DOCUME~1\XPPRESP3\LOCALS~1\Temp\bntoz\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favorites
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [AVP] "D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" /minimized
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: ["D:\DOCUME~1\XPPRESP3\LOCALS~1\Temp\ir_ext_temp_0\AutoPlay\Docs\Zyzoom_all_windows_Activation.com"] "D:\DOCUME~1\XPPRESP3\LOCALS~1\Temp\ir_ext_temp_0\AutoPlay\Docs\Zyzoom_all_windows_Activation.com"
O4 - HKCU\..\Run: [IDMan] D:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - D:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: E?E - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com
O20 - AppInit_DLLs: D:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,D:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,D:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O20 - Winlogon Notify: Antiwpa - D:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
--
End of file - 5203 bytes
.
.
--------------------------\\\ End Report Of Of HijackThis ---------------
.
.
.
.
--------------------------\\\ Start Report Of Running Processes ---------------
.
==================================================
Process Name : smss.exe
ProcessID : 808
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Windows NT Session Manager
Company : Microsoft Corporation
Window Title :
File Size : 50,688
File Created Date : 18/06/25 06:56:58 ص
File Modified Date : 18/06/25 06:56:58 ص
Filename : D:\WINDOWS\System32\smss.exe
Base Address : 0x48580000
Created On : 14/08/29 08:21:11 ص
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 368 K
Mem Usage Peak : 448 K
Page Faults : 205
Pagefile Usage : 164 K
Pagefile Peak Usage : 260 K
File Attributes : A
==================================================
==================================================
Process Name : csrss.exe
ProcessID : 912
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Client Server Runtime Process
Company : Microsoft Corporation
Window Title :
File Size : 6,144
File Created Date : 18/06/25 06:56:50 ص
File Modified Date : 18/06/25 06:56:50 ص
Filename : D:\WINDOWS\system32\csrss.exe
Base Address : 0x4A680000
Created On : 14/08/29 08:21:14 ص
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 5004 K
Mem Usage Peak : 5016 K
Page Faults : 12712
Pagefile Usage : 1832 K
Pagefile Peak Usage : 1832 K
File Attributes : A
==================================================
==================================================
Process Name : winlogon.exe
ProcessID : 936
Priority : High
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Windows NT Logon Application
Company : Microsoft Corporation
Window Title :
File Size : 502,272
File Created Date : 18/06/25 06:56:58 ص
File Modified Date : 13/08/29 12:59:36 ص
Filename : D:\WINDOWS\system32\winlogon.exe
Base Address : 0x01000000
Created On : 14/08/29 08:21:14 ص
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 5092 K
Mem Usage Peak : 8952 K
Page Faults : 5852
Pagefile Usage : 4988 K
Pagefile Peak Usage : 5088 K
File Attributes : A
==================================================
==================================================
Process Name : services.exe
ProcessID : 980
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Services and Controller app
Company : Microsoft Corporation
Window Title :
File Size : 108,032
File Created Date : 18/06/25 06:56:56 ص
File Modified Date : 18/06/25 06:56:56 ص
Filename : D:\WINDOWS\system32\services.exe
Base Address : 0x01000000
Created On : 14/08/29 08:21:15 ص
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 4236 K
Mem Usage Peak : 4300 K
Page Faults : 1443
Pagefile Usage : 2100 K
Pagefile Peak Usage : 2260 K
File Attributes : A
==================================================
==================================================
Process Name : lsass.exe
ProcessID : 992
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : LSA Shell (Export Version)
Company : Microsoft Corporation
Window Title :
File Size : 13,312
File Created Date : 18/06/25 06:56:52 ص
File Modified Date : 18/06/25 06:56:52 ص
Filename : D:\WINDOWS\system32\lsass.exe
Base Address : 0x01000000
Created On : 14/08/29 08:21:15 ص
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 1440 K
Mem Usage Peak : 5760 K
Page Faults : 8628
Pagefile Usage : 3756 K
Pagefile Peak Usage : 3916 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1148
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 18/06/25 06:56:58 ص
File Modified Date : 18/06/25 06:56:58 ص
Filename : D:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 14/08/29 08:21:15 ص
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 4984 K
Mem Usage Peak : 5048 K
Page Faults : 1508
Pagefile Usage : 3160 K
Pagefile Peak Usage : 23408 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1232
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 18/06/25 06:56:58 ص
File Modified Date : 18/06/25 06:56:58 ص
Filename : D:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 14/08/29 08:21:15 ص
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 4232 K
Mem Usage Peak : 4244 K
Page Faults : 1387
Pagefile Usage : 1856 K
Pagefile Peak Usage : 1896 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1356
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 18/06/25 06:56:58 ص
File Modified Date : 18/06/25 06:56:58 ص
Filename : D:\WINDOWS\System32\svchost.exe
Base Address : 0x01000000
Created On : 14/08/29 08:21:15 ص
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 23428 K
Mem Usage Peak : 36412 K
Page Faults : 31760
Pagefile Usage : 13664 K
Pagefile Peak Usage : 21256 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1576
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 18/06/25 06:56:58 ص
File Modified Date : 18/06/25 06:56:58 ص
Filename : D:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 14/08/29 08:21:16 ص
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 3928 K
Mem Usage Peak : 3936 K
Page Faults : 1061
Pagefile Usage : 1592 K
Pagefile Peak Usage : 1616 K
File Attributes : A
==================================================
==================================================
Process Name : spoolsv.exe
ProcessID : 1792
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Spooler SubSystem App
Company : Microsoft Corporation
Window Title :
File Size : 57,856
File Created Date : 18/06/25 06:56:58 ص
File Modified Date : 18/06/25 06:56:58 ص
Filename : D:\WINDOWS\system32\spoolsv.exe
Base Address : 0x01000000
Created On : 14/08/29 08:21:18 ص
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 4784 K
Mem Usage Peak : 4852 K
Page Faults : 1665
Pagefile Usage : 3248 K
Pagefile Peak Usage : 3548 K
File Attributes : A
==================================================
==================================================
Process Name : Explorer.EXE
ProcessID : 188
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
Description : Windows Explorer
Company : Microsoft Corporation
Window Title : Program Manager
File Size : 1,032,192
File Created Date : 18/06/25 06:56:50 ص
File Modified Date : 18/06/25 06:56:50 ص
Filename : D:\WINDOWS\Explorer.EXE
Base Address : 0x01000000
Created On : 14/08/29 08:21:21 ص
Visible Windows : 2
Hidden Windows : 33
User Name : USER\XPPRESP3
Mem Usage : 13484 K
Mem Usage Peak : 27032 K
Page Faults : 152093
Pagefile Usage : 19892 K
Pagefile Peak Usage : 22572 K
File Attributes : A
==================================================
==================================================
Process Name : zyzoom.exe
ProcessID : 256
Priority : Normal
Product Name : AVG Anti-Spyware
Version : 7, 5, 1, 43
Description : AVG Anti-Spyware
Company : GRISOFT s.r.o.
Window Title :
File Size : 6,731,312
File Created Date : 10/08/29 02:38:03 ص
File Modified Date : 23/10/28 01:50:42 ص
Filename : D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe
Base Address : 0x00400000
Created On : 14/08/29 08:21:22 ص
Visible Windows : 0
Hidden Windows : 23
User Name : USER\XPPRESP3
Mem Usage : 44584 K
Mem Usage Peak : 57780 K
Page Faults : 96051
Pagefile Usage : 53628 K
Pagefile Peak Usage : 67236 K
File Attributes : A
==================================================
==================================================
Process Name : realsched.exe
ProcessID : 260
Priority : Normal
Product Name : RealPlayer (32-bit)
Version : 0.1.1.45
Description : RealNetworks Scheduler
Company : RealNetworks, Inc.
Window Title :
File Size : 185,896
File Created Date : 09/08/29 10:54:22 م
File Modified Date : 09/08/29 10:54:24 م
Filename : D:\Program Files\Common Files\Real\Update_OB\realsched.exe
Base Address : 0x00400000
Created On : 14/08/29 08:21:22 ص
Visible Windows : 0
Hidden Windows : 1
User Name : USER\XPPRESP3
Mem Usage : 188 K
Mem Usage Peak : 2872 K
Page Faults : 17578
Pagefile Usage : 1084 K
Pagefile Peak Usage : 1232 K
File Attributes : A
==================================================
==================================================
Process Name : IDMan.exe
ProcessID : 268
Priority : Normal
Product Name : Internet Download Manager (IDM)
Version : 5.12.11.0
Description : Internet Download Manager (IDM)
Company : Tonec Inc.
Window Title :
File Size : 2,594,224
File Created Date : 13/02/29 02:04:06 م
File Modified Date : 22/05/29 05:16:58 م
Filename : D:\Program Files\Internet Download Manager\IDMan.exe
Base Address : 0x00400000
Created On : 14/08/29 08:21:22 ص
Visible Windows : 0
Hidden Windows : 5
User Name : USER\XPPRESP3
Mem Usage : 6680 K
Mem Usage Peak : 12652 K
Page Faults : 12559
Pagefile Usage : 4984 K
Pagefile Peak Usage : 7820 K
File Attributes : A
==================================================
==================================================
Process Name : guard.exe
ProcessID : 328
Priority : Normal
Product Name : AVG Anti-Spyware
Version : 7, 5, 1, 22
Description : AVG Anti-Spyware guard
Company : GRISOFT s.r.o.
Window Title :
File Size : 312,880
File Created Date : 14/05/28 12:31:10 م
File Modified Date : 14/05/28 12:31:10 م
Filename : D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
Base Address : 0x00400000
Created On : 14/08/29 08:21:24 ص
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 17752 K
Mem Usage Peak : 49668 K
Page Faults : 149968
Pagefile Usage : 45020 K
Pagefile Peak Usage : 57236 K
File Attributes : A
==================================================
==================================================
Process Name : alg.exe
ProcessID : 1384
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Application Layer Gateway Service
Company : Microsoft Corporation
Window Title :
File Size : 44,544
File Created Date : 18/06/25 06:56:48 ص
File Modified Date : 18/06/25 06:56:48 ص
Filename : D:\WINDOWS\System32\alg.exe
Base Address : 0x01000000
Created On : 14/08/29 08:21:53 ص
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 3584 K
Mem Usage Peak : 3592 K
Page Faults : 960
Pagefile Usage : 1236 K
Pagefile Peak Usage : 1256 K
File Attributes : A
==================================================
==================================================
Process Name : IEXPLORE.EXE
ProcessID : 1284
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
Description : Internet Explorer
Company : Microsoft Corporation
Window Title :
File Size : 93,184
File Created Date : 09/08/29 03:44:11 م
File Modified Date : 18/06/25 09:56:52 ص
Filename : D:\Program Files\Internet Explorer\IEXPLORE.EXE
Base Address : 0x00400000
Created On : 14/08/29 05:38:44 م
Visible Windows : 0
Hidden Windows : 5
User Name : USER\XPPRESP3
Mem Usage : 16120 K
Mem Usage Peak : 63672 K
Page Faults : 781860
Pagefile Usage : 20284 K
Pagefile Peak Usage : 56044 K
File Attributes : A
==================================================
==================================================
Process Name : msnmsgr.exe
ProcessID : 2628
Priority : Normal
Product Name : Messenger
Version : 8.5.1302.1018
Description : Windows Live Messenger
Company : Microsoft Corporation
Window Title :
File Size : 5,724,184
File Created Date : 07/10/28 08:34:02 ص
File Modified Date : 07/10/28 08:34:02 ص
Filename : D:\Program Files\Windows Live\Messenger\msnmsgr.exe
Base Address : 0x00400000
Created On : 14/08/29 09:11:50 م
Visible Windows : 1
Hidden Windows : 19
User Name : USER\XPPRESP3
Mem Usage : 3608 K
Mem Usage Peak : 23752 K
Page Faults : 18094
Pagefile Usage : 9460 K
Pagefile Peak Usage : 11660 K
File Attributes : A
==================================================
==================================================
Process Name : iexplore.exe
ProcessID : 2432
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
Description : Internet Explorer
Company : Microsoft Corporation
Window Title : المشكله كيفيه جعل الويندوز اصلي - الصفحة 4 - زيزوووم للأمن والحمايه - Microsoft Internet Explorer
File Size : 93,184
File Created Date : 09/08/29 03:44:11 م
File Modified Date : 18/06/25 09:56:52 ص
Filename : D:\Program Files\Internet Explorer\iexplore.exe
Base Address : 0x00400000
Created On : 14/08/29 11:35:52 م
Visible Windows : 2
Hidden Windows : 37
User Name : USER\XPPRESP3
Mem Usage : 4956 K
Mem Usage Peak : 36020 K
Page Faults : 30396
Pagefile Usage : 21916 K
Pagefile Peak Usage : 22284 K
File Attributes : A
==================================================
==================================================
Process Name : runn.exe
ProcessID : 1192
Priority : Normal
Product Name :
Version :
Description :
Company :
Window Title :
File Size : 71,680
File Created Date : 14/08/29 09:33:11 م
File Modified Date : 23/01/29 10:24:26 م
Filename : D:\DOCUME~1\XPPRESP3\LOCALS~1\Temp\bntoz\runn.exe
Base Address : 0x00400000
Created On : 15/08/29 12:33:11 ص
Visible Windows : 0
Hidden Windows : 0
User Name : USER\XPPRESP3
Mem Usage : 2064 K
Mem Usage Peak : 2076 K
Page Faults : 641
Pagefile Usage : 676 K
Pagefile Peak Usage : 752 K
File Attributes : A
==================================================
==================================================
Process Name : cmd.exe
ProcessID : 3968
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : Windows Command Processor
Company : Microsoft Corporation
Window Title :
File Size : 388,608
File Created Date : 18/06/25 06:56:50 ص
File Modified Date : 18/06/25 06:56:50 ص
Filename : D:\WINDOWS\system32\cmd.exe
Base Address : 0x4AD00000
Created On : 15/08/29 12:33:12 ص
Visible Windows : 0
Hidden Windows : 1
User Name : USER\XPPRESP3
Mem Usage : 3104 K
Mem Usage Peak : 3172 K
Page Faults : 898
Pagefile Usage : 2088 K
Pagefile Peak Usage : 2164 K
File Attributes : A
==================================================
==================================================
Process Name : wmiprvse.exe
ProcessID : 3372
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Description : WMI
Company : Microsoft Corporation
Window Title :
File Size : 218,112
File Created Date : 09/08/29 03:42:07 م
File Modified Date : 18/06/25 09:56:58 ص
Filename : D:\WINDOWS\system32\wbem\wmiprvse.exe
Base Address : 0x01000000
Created On : 15/08/29 12:33:14 ص
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 5648 K
Mem Usage Peak : 5648 K
Page Faults : 1472
Pagefile Usage : 2952 K
Pagefile Peak Usage : 2952 K
File Attributes : A
==================================================
==================================================
Process Name : CProcess.exe
ProcessID : 3876
Priority : Normal
Product Name : CurrProcess
Version : 1.11
Description : CurrProcess
Company : NirSoft
Window Title :
File Size : 35,840
File Created Date : 14/08/29 09:33:11 م
File Modified Date : 08/06/26 04:46:34 ص
Filename : D:\DOCUME~1\XPPRESP3\LOCALS~1\Temp\bntoz\CProcess.exe
Base Address : 0x00400000
Created On : 15/08/29 12:33:15 ص
Visible Windows : 0
Hidden Windows : 0
User Name : USER\XPPRESP3
Mem Usage : 2208 K
Mem Usage Peak : 2216 K
Page Faults : 756
Pagefile Usage : 960 K
Pagefile Peak Usage : 964 K
File Attributes : A
==================================================
.
.
--------------------------\\\ End Report Of Running Processes ---------------
.
.
.
.
--------------------------\\\ Windows XP Startup List ---------------
.
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
autocheck autochk *
autocheck autochk *
Auto Check Utility
Microsoft Corporation
5.01.2600.2180
d:\windows\system32\autochk.exe
HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms
rdpclip
rdpclip
RDP Clip Monitor
Microsoft Corporation
5.01.2600.2180
d:\windows\system32\rdpclip.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
D:\WINDOWS\system32\userinit.exe
D:\WINDOWS\system32\userinit.exe
Userinit Logon Application
Microsoft Corporation
5.01.2600.2180
d:\windows\system32\userinit.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
Explorer.exe
Explorer.exe
Windows Explorer
Microsoft Corporation
6.00.2900.2180
d:\windows\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
AVP
"D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
Kaspersky Anti-Virus
Kaspersky Lab
8.00.0000.0357
d:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe
!AVG Anti-Spyware
"D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" /minimized
AVG Anti-Spyware
GRISOFT s.r.o.
7.05.0001.0043
d:\program files\grisoft\avg anti-spyware 7.5\zyzoom.exe
TkBellExe
"D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
RealNetworks Scheduler
RealNetworks, Inc.
0.01.0001.0045
d:\program files\common files\real\update_ob\realsched.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
"D:\DOCUME~1\XPPRESP3\LOCALS~1\Temp\ir_ext_temp_0\AutoPlay\Docs\Zyzoom_all_windows_Activation.com"
"D:\DOCUME~1\XPPRESP3\LOCALS~1\Temp\ir_ext_temp_0\AutoPlay\Docs\Zyzoom_all_windows_Activation.com"
d:\documents and settings\xppresp3\local settings\temp\ir_ext_temp_0\autoplay\docs\zyzoom_all_windows_activation.com
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
IDMan
D:\Program Files\Internet Download Manager\IDMan.exe /onboot
Internet Download Manager (IDM)
Tonec Inc.
5.12.0011.0000
d:\program files\internet download manager\idman.exe
.
.
----------- End Report ---------------