من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
السلام عليكم ورحمة الله وبركاته:
جهازي يعلق ويهنق ويبطيء في فتح البرامج
لااجد سببا لذلك فبرامج الحماية ok
ولايوجد تعارضات
هناك طلبين من اخوتي ذوي الخبرة
استخلاص الخطأ من تقرير الهايجاك كيف يتم
ماهي مشكلة جهازي من خلال التقرير
التقرير:
.
--------------------------\\\ Start Report Of HijackThis ---------------
.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:50:15 م, on 17/08/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 SP3 (7.00.6000.20733)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Acer\eManager\anbmServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Acer\ePM\EPM-DM.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\bpk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\DOCUME~1\sarah\LOCALS~1\Temp\bntoz\runn.exe
C:\WINDOWS\system32\cmd.exe
C:\DOCUME~1\sarah\LOCALS~1\Temp\bntoz\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "%ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" /minimized
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [EPM-DM] C:\Acer\ePM\EPM-DM.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [bpk] C:\WINDOWS\system32\bpk.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: ت&صدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash ) -
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: Update Center (Windows Update Center) - Unknown owner - C:\WINDOWS\scvhost.exe (file missing)
--
End of file - 7238 bytes
.
.
--------------------------\\\ End Report Of Of HijackThis ---------------
.
.
.
.
--------------------------\\\ Start Report Of Running Processes ---------------
.
==================================================
Process Name : smss.exe
ProcessID : 636
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Windows NT Session Manager
Company : Microsoft Corporation
Window Title :
File Size : 50,688
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\System32\smss.exe
Base Address : 0x48580000
Created On : 15/08/1429 08:34:38 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 408 K
Mem Usage Peak : 428 K
Page Faults : 195
Pagefile Usage : 168 K
Pagefile Peak Usage : 1708 K
File Attributes : A
==================================================
==================================================
Process Name : csrss.exe
ProcessID : 688
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Client Server Runtime Process
Company : Microsoft Corporation
Window Title :
File Size : 6,144
File Created Date : 08/04/1429 10:42:16 ص
File Modified Date : 08/04/1429 10:42:16 ص
Filename : C:\WINDOWS\system32\csrss.exe
Base Address : 0x4A680000
Created On : 15/08/1429 08:34:40 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 4276 K
Mem Usage Peak : 4472 K
Page Faults : 105755
Pagefile Usage : 2000 K
Pagefile Peak Usage : 2000 K
File Attributes : A
==================================================
==================================================
Process Name : winlogon.exe
ProcessID : 712
Priority : High
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2113)
Description : Windows NT Logon Application
Company : Microsoft Corporation
Window Title :
File Size : 507,904
File Created Date : 08/04/1429 10:42:40 ص
File Modified Date : 08/04/1429 10:42:40 ص
Filename : C:\WINDOWS\system32\winlogon.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:40 م
Visible Windows : 0
Hidden Windows : 1
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 3704 K
Mem Usage Peak : 15928 K
Page Faults : 11065
Pagefile Usage : 7852 K
Pagefile Peak Usage : 8932 K
File Attributes : A
==================================================
==================================================
Process Name : services.exe
ProcessID : 756
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Services and Controller app
Company : Microsoft Corporation
Window Title :
File Size : 108,544
File Created Date : 08/04/1429 10:42:36 ص
File Modified Date : 08/04/1429 10:42:36 ص
Filename : C:\WINDOWS\system32\services.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:41 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 3460 K
Mem Usage Peak : 3624 K
Page Faults : 1506
Pagefile Usage : 1856 K
Pagefile Peak Usage : 2476 K
File Attributes : A
==================================================
==================================================
Process Name : lsass.exe
ProcessID : 768
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2113)
Description : LSA Shell (Export Version)
Company : Microsoft Corporation
Window Title :
File Size : 13,312
File Created Date : 08/04/1429 10:42:26 ص
File Modified Date : 08/04/1429 10:42:26 ص
Filename : C:\WINDOWS\system32\lsass.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:41 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 6448 K
Mem Usage Peak : 6476 K
Page Faults : 1848
Pagefile Usage : 4444 K
Pagefile Peak Usage : 4608 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 920
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:43 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 5292 K
Mem Usage Peak : 5348 K
Page Faults : 1510
Pagefile Usage : 6696 K
Pagefile Peak Usage : 26852 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1008
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:46 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 4564 K
Mem Usage Peak : 4588 K
Page Faults : 1294
Pagefile Usage : 5384 K
Pagefile Peak Usage : 5472 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1044
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\System32\svchost.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:46 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 21624 K
Mem Usage Peak : 23004 K
Page Faults : 10441
Pagefile Usage : 18604 K
Pagefile Peak Usage : 19704 K
File Attributes : A
==================================================
==================================================
Process Name : S24EvMon.exe
ProcessID : 1092
Priority : Normal
Product Name : Intel(R) PROSet/Wireless Service
Version : 11. 5. 1. 2
Description : Wireless Management Service
Company : Intel Corporation
Window Title :
File Size : 1,187,840
File Created Date : 26/02/1429 11:34:38 ص
File Modified Date : 26/02/1429 11:34:38 ص
Filename : C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:46 م
Visible Windows : 0
Hidden Windows : 4
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 13688 K
Mem Usage Peak : 13708 K
Page Faults : 3685
Pagefile Usage : 13548 K
Pagefile Peak Usage : 13604 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1208
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:47 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 3620 K
Mem Usage Peak : 3688 K
Page Faults : 1151
Pagefile Usage : 1400 K
Pagefile Peak Usage : 1484 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1256
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:48 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 4608 K
Mem Usage Peak : 4624 K
Page Faults : 1204
Pagefile Usage : 4628 K
Pagefile Peak Usage : 4676 K
File Attributes : A
==================================================
==================================================
Process Name : spoolsv.exe
ProcessID : 1284
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-0852)
Description : Spooler SubSystem App
Company : Microsoft Corporation
Window Title :
File Size : 57,856
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\system32\spoolsv.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:48 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 5492 K
Mem Usage Peak : 5516 K
Page Faults : 1893
Pagefile Usage : 6804 K
Pagefile Peak Usage : 7044 K
File Attributes : A
==================================================
==================================================
Process Name : sched.exe
ProcessID : 1324
Priority : Normal
Product Name : AntiVir Workstation
Version : 8.00.00.12
Description : Antivirus Scheduler
Company : Avira GmbH
Window Title :
File Size : 68,865
File Created Date : 08/08/1429 09:09:00 م
File Modified Date : 29/02/1429 09:00:08 ص
Filename : C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:48 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 528 K
Mem Usage Peak : 3564 K
Page Faults : 1352
Pagefile Usage : 1588 K
Pagefile Peak Usage : 1596 K
File Attributes : A
==================================================
==================================================
Process Name : anbmServ.exe
ProcessID : 1488
Priority : Normal
Product Name : Acer eManager for Notebook
Version : 3.0.5.8
Description : Service Program for Acer eManager
Company : OSA Technologies Inc.
Window Title :
File Size : 1,287,168
File Created Date : 01/07/1425 12:17:20 م
File Modified Date : 01/07/1425 12:17:20 م
Filename : C:\Acer\eManager\anbmServ.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:51 م
Visible Windows : 0
Hidden Windows : 2
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 5604 K
Mem Usage Peak : 5604 K
Page Faults : 2012
Pagefile Usage : 2596 K
Pagefile Peak Usage : 2596 K
File Attributes : A
==================================================
==================================================
Process Name : Explorer.EXE
ProcessID : 1756
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 6.00.2900.5512 (xpsp.080413-2105)
Description : Windows Explorer
Company : Microsoft Corporation
Window Title : Programs
File Size : 1,033,728
File Created Date : 08/04/1429 10:42:20 ص
File Modified Date : 08/04/1429 10:42:20 ص
Filename : C:\WINDOWS\Explorer.EXE
Base Address : 0x01000000
Created On : 15/08/1429 08:34:54 م
Visible Windows : 3
Hidden Windows : 42
User Name : SARAH-PC\sarah
Mem Usage : 34160 K
Mem Usage Peak : 60604 K
Page Faults : 2374879
Pagefile Usage : 57324 K
Pagefile Peak Usage : 61208 K
File Attributes : A
==================================================
==================================================
Process Name : avguard.exe
ProcessID : 1792
Priority : Normal
Product Name : AntiVir Workstation
Version : 8.00.01.15
Description : Antivirus On-Access Service
Company : Avira GmbH
Window Title :
File Size : 147,201
File Created Date : 08/08/1429 09:08:53 م
File Modified Date : 19/03/1429 12:34:49 م
Filename : C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:54 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 12316 K
Mem Usage Peak : 70820 K
Page Faults : 79974
Pagefile Usage : 75668 K
Pagefile Peak Usage : 731612 K
File Attributes : A
==================================================
==================================================
Process Name : AppleMobileDeviceService.exe
ProcessID : 1832
Priority : Normal
Product Name : Apple Mobile Device Service
Version : 2.0.28.0
Description : Apple Mobile Device Service
Company : Apple Inc.
Window Title :
File Size : 116,040
File Created Date : 07/07/1429 06:47:18 ص
File Modified Date : 07/07/1429 06:47:18 ص
Filename : C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:54 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 2424 K
Mem Usage Peak : 2436 K
Page Faults : 606
Pagefile Usage : 2208 K
Pagefile Peak Usage : 2224 K
File Attributes : A
==================================================
==================================================
Process Name : guard.exe
ProcessID : 1852
Priority : Normal
Product Name : AVG Anti-Spyware
Version : 7, 5, 1, 22
Description : AVG Anti-Spyware guard
Company : GRISOFT s.r.o.
Window Title :
File Size : 312,880
File Created Date : 14/05/1428 12:31:10 م
File Modified Date : 14/05/1428 12:31:10 م
Filename : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:54 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 1540 K
Mem Usage Peak : 49516 K
Page Faults : 24323
Pagefile Usage : 43344 K
Pagefile Peak Usage : 49648 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1880
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:54 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 3416 K
Mem Usage Peak : 3424 K
Page Faults : 906
Pagefile Usage : 2716 K
Pagefile Peak Usage : 2740 K
File Attributes : A
==================================================
==================================================
Process Name : EvtEng.exe
ProcessID : 1924
Priority : Normal
Product Name : Intel(R) PROSet/Wireless Event Log
Version : 11. 5. 1. 2
Description : Intel(R) PROSet/Wireless Event Log
Company : Intel Corporation
Window Title :
File Size : 823,296
File Created Date : 26/02/1429 11:55:56 ص
File Modified Date : 26/02/1429 11:55:56 ص
Filename : C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:54 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 13980 K
Mem Usage Peak : 14004 K
Page Faults : 3773
Pagefile Usage : 13844 K
Pagefile Peak Usage : 14328 K
File Attributes : A
==================================================
==================================================
Process Name : RegSrvc.exe
ProcessID : 2040
Priority : Normal
Product Name : Intel(R) PROSet/Wireless Registry Service
Version : 11. 5. 1. 2
Description : Intel(R) PROSet/Wireless Registry Service
Company : Intel Corporation
Window Title :
File Size : 483,328
File Created Date : 26/02/1429 11:30:12 ص
File Modified Date : 26/02/1429 11:30:12 ص
Filename : C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:55 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 3244 K
Mem Usage Peak : 3252 K
Page Faults : 827
Pagefile Usage : 4180 K
Pagefile Peak Usage : 4204 K
File Attributes : A
==================================================
==================================================
Process Name : wmiprvse.exe
ProcessID : 668
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2108)
Description : WMI
Company : Microsoft Corporation
Window Title :
File Size : 218,112
File Created Date : 09/07/1429 12:22:33 ص
File Modified Date : 08/04/1429 10:42:42 ص
Filename : C:\WINDOWS\system32\wbem\wmiprvse.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:35:05 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 5400 K
Mem Usage Peak : 5708 K
Page Faults : 1621
Pagefile Usage : 4992 K
Pagefile Peak Usage : 5796 K
File Attributes : A
==================================================
==================================================
Process Name : ZCfgSvc.exe
ProcessID : 1176
Priority : Normal
Product Name : ZeroCfgSvc Application
Version : 11. 5. 1. 2
Description : ZeroCfgSvc MFC Application
Company : Intel Corporation
Window Title :
File Size : 999,424
File Created Date : 26/02/1429 11:46:16 ص
File Modified Date : 26/02/1429 11:46:16 ص
Filename : C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:08 م
Visible Windows : 0
Hidden Windows : 5
User Name : SARAH-PC\sarah
Mem Usage : 15240 K
Mem Usage Peak : 15256 K
Page Faults : 21175
Pagefile Usage : 12128 K
Pagefile Peak Usage : 12208 K
File Attributes : A
==================================================
==================================================
Process Name : ifrmewrk.exe
ProcessID : 1184
Priority : Normal
Product Name : Intel(R) PROSet/Wireless
Version : 11. 5. 1. 2
Description : Intel Framework MFC Application
Company : Intel Corporation
Window Title :
File Size : 1,101,824
File Created Date : 26/02/1429 11:41:50 ص
File Modified Date : 26/02/1429 11:41:50 ص
Filename : C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:10 م
Visible Windows : 0
Hidden Windows : 7
User Name : SARAH-PC\sarah
Mem Usage : 18864 K
Mem Usage Peak : 18884 K
Page Faults : 23181
Pagefile Usage : 17844 K
Pagefile Peak Usage : 17872 K
File Attributes : A
==================================================
==================================================
Process Name : igfxtray.exe
ProcessID : 1472
Priority : Normal
Product Name : Intel(R) Common User Interface
Version : 3.0.0.2285
Description : igfxTray Module
Company : Intel Corporation
Window Title :
File Size : 155,648
File Created Date : 09/07/1429 02:10:58 ص
File Modified Date : 06/08/1424 11:37:36 ص
Filename : C:\WINDOWS\system32\igfxtray.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:11 م
Visible Windows : 0
Hidden Windows : 2
User Name : SARAH-PC\sarah
Mem Usage : 4380 K
Mem Usage Peak : 4392 K
Page Faults : 1152
Pagefile Usage : 1676 K
Pagefile Peak Usage : 2368 K
File Attributes : A
==================================================
==================================================
Process Name : hkcmd.exe
ProcessID : 1464
Priority : Normal
Product Name : Intel(R) Common User Interface
Version : 3.0.0.2285
Description : hkcmd Module
Company : Intel Corporation
Window Title :
File Size : 118,784
File Created Date : 09/07/1429 02:10:50 ص
File Modified Date : 06/08/1424 11:19:44 ص
Filename : C:\WINDOWS\system32\hkcmd.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:11 م
Visible Windows : 0
Hidden Windows : 18
User Name : SARAH-PC\sarah
Mem Usage : 4152 K
Mem Usage Peak : 4164 K
Page Faults : 1091
Pagefile Usage : 1732 K
Pagefile Peak Usage : 1820 K
File Attributes : A
==================================================
==================================================
Process Name : EPM-DM.exe
ProcessID : 1548
Priority : Normal
Product Name : Acer EPM Device Manager
Version : 2.35
Description : Acer EPM Device Manager
Company : Acer Inc
Window Title :
File Size : 163,840
File Created Date : 11/07/1429 07:54:11 م
File Modified Date : 14/09/1425 05:16:08 م
Filename : C:\Acer\ePM\EPM-DM.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:12 م
Visible Windows : 0
Hidden Windows : 2
User Name : SARAH-PC\sarah
Mem Usage : 3632 K
Mem Usage Peak : 3644 K
Page Faults : 986
Pagefile Usage : 2704 K
Pagefile Peak Usage : 2792 K
File Attributes : A
==================================================
==================================================
Process Name : rundll32.exe
ProcessID : 1716
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2105)
Description : Run a DLL as an App
Company : Microsoft Corporation
Window Title :
File Size : 33,280
File Created Date : 08/04/1429 10:42:34 ص
File Modified Date : 08/04/1429 10:42:34 ص
Filename : C:\WINDOWS\system32\rundll32.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:35:13 م
Visible Windows : 0
Hidden Windows : 3
User Name : SARAH-PC\sarah
Mem Usage : 4936 K
Mem Usage Peak : 4976 K
Page Faults : 242673
Pagefile Usage : 4052 K
Pagefile Peak Usage : 4244 K
File Attributes : A
==================================================
==================================================
Process Name : avgnt.exe
ProcessID : 1776
Priority : Normal
Product Name : AntiVir Workstation
Version : 8.00.00.07
Description : Antivirus System Tray Tool
Company : Avira GmbH
Window Title :
File Size : 262,401
File Created Date : 08/08/1429 09:08:53 م
File Modified Date : 05/02/1429 07:06:50 ص
Filename : C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:14 م
Visible Windows : 0
Hidden Windows : 5
User Name : SARAH-PC\sarah
Mem Usage : 2384 K
Mem Usage Peak : 53988 K
Page Faults : 67730
Pagefile Usage : 2468 K
Pagefile Peak Usage : 624332 K
File Attributes : A
==================================================
==================================================
Process Name : bpk.exe
ProcessID : 2084
Priority : Normal
Product Name :
Version :
Description :
Company :
Window Title :
File Size : 218,112
File Created Date : 03/08/1428 11:52:19 ص
File Modified Date : 03/08/1428 11:52:19 ص
Filename : C:\WINDOWS\system32\bpk.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:15 م
Visible Windows : 0
Hidden Windows : 6
User Name : SARAH-PC\sarah
Mem Usage : 6584 K
Mem Usage Peak : 6584 K
Page Faults : 1752
Pagefile Usage : 2752 K
Pagefile Peak Usage : 2792 K
File Attributes : A
==================================================
==================================================
Process Name : ctfmon.exe
ProcessID : 2164
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2105)
Description : CTF Loader
Company : Microsoft Corporation
Window Title :
File Size : 15,360
File Created Date : 08/04/1429 10:42:18 ص
File Modified Date : 08/04/1429 10:42:18 ص
Filename : C:\WINDOWS\system32\ctfmon.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:16 م
Visible Windows : 0
Hidden Windows : 5
User Name : SARAH-PC\sarah
Mem Usage : 13480 K
Mem Usage Peak : 13492 K
Page Faults : 2797255
Pagefile Usage : 11344 K
Pagefile Peak Usage : 11432 K
File Attributes : A
==================================================
==================================================
Process Name : IDMan.exe
ProcessID : 2200
Priority : Normal
Product Name : Internet Download Manager (IDM)
Version : 5.12.11.0
Description : Internet Download Manager (IDM)
Company : Tonec Inc.
Window Title :
File Size : 2,594,224
File Created Date : 07/05/1429 12:56:45 م
File Modified Date : 09/07/1429 07:16:01 ص
Filename : C:\Program Files\Internet Download Manager\IDMan.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:17 م
Visible Windows : 0
Hidden Windows : 7
User Name : SARAH-PC\sarah
Mem Usage : 10420 K
Mem Usage Peak : 10428 K
Page Faults : 4074
Pagefile Usage : 16164 K
Pagefile Peak Usage : 16268 K
File Attributes : A
==================================================
==================================================
Process Name : Dot1XCfg.exe
ProcessID : 3036
Priority : Normal
Product Name : Intel PROSet/Wireless
Version : 11. 5. 1. 2
Description : Intel 802.1x Server
Company : Intel Corporation
Window Title :
File Size : 688,128
File Created Date : 26/02/1429 11:37:38 ص
File Modified Date : 26/02/1429 11:37:38 ص
Filename : C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:31 م
Visible Windows : 0
Hidden Windows : 5
User Name : SARAH-PC\sarah
Mem Usage : 16676 K
Mem Usage Peak : 16688 K
Page Faults : 4409
Pagefile Usage : 14424 K
Pagefile Peak Usage : 14512 K
File Attributes : A
==================================================
==================================================
Process Name : IEMonitor.exe
ProcessID : 2744
Priority : Normal
Product Name : IEMonitor Application
Version : 5, 12, 8, 0
Description : Internet Download Manager agent for click monitoring in IE-based browsers
Company : Tonec Inc.
Window Title :
File Size : 251,312
File Created Date : 07/05/1429 12:56:41 م
File Modified Date : 11/02/1429 01:01:01 م
Filename : C:\Program Files\Internet Download Manager\IEMonitor.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:36:48 م
Visible Windows : 0
Hidden Windows : 3
User Name : SARAH-PC\sarah
Mem Usage : 5552 K
Mem Usage Peak : 5560 K
Page Faults : 1502
Pagefile Usage : 6164 K
Pagefile Peak Usage : 6176 K
File Attributes : A
==================================================
==================================================
Process Name : FIREFOX.EXE
ProcessID : 4036
Priority : Normal
Product Name : Firefox
Version : 1.8.1.16: 2008070205
Description : Firefox
Company : Mozilla Corporation
Window Title : زيزوووم للأمن والحمايه - Powered by vBulletin - Mozilla Firefox
File Size : 7,667,312
File Created Date : 09/07/1429 01:23:06 ص
File Modified Date : 14/07/1429 12:50:18 ص
Filename : C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
Base Address : 0x00400000
Created On : 15/08/1429 08:46:21 م
Visible Windows : 1
Hidden Windows : 14
User Name : SARAH-PC\sarah
Mem Usage : 34916 K
Mem Usage Peak : 36600 K
Page Faults : 13166
Pagefile Usage : 28184 K
Pagefile Peak Usage : 30092 K
File Attributes : A
==================================================
==================================================
Process Name : runn.exe
ProcessID : 3640
Priority : Normal
Product Name :
Version :
Description :
Company :
Window Title :
File Size : 71,680
File Created Date : 15/08/1429 05:50:03 م
File Modified Date : 23/01/1429 10:24:25 م
Filename : C:\DOCUME~1\sarah\LOCALS~1\Temp\bntoz\runn.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:50:04 م
Visible Windows : 0
Hidden Windows : 0
User Name : SARAH-PC\sarah
Mem Usage : 2124 K
Mem Usage Peak : 2132 K
Page Faults : 640
Pagefile Usage : 800 K
Pagefile Peak Usage : 804 K
File Attributes : A
==================================================
==================================================
Process Name : cmd.exe
ProcessID : 3672
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Windows Command Processor
Company : Microsoft Corporation
Window Title :
File Size : 389,120
File Created Date : 08/04/1429 10:42:16 ص
File Modified Date : 08/04/1429 10:42:16 ص
Filename : C:\WINDOWS\system32\cmd.exe
Base Address : 0x4AD00000
Created On : 15/08/1429 08:50:04 م
Visible Windows : 0
Hidden Windows : 1
User Name : SARAH-PC\sarah
Mem Usage : 2940 K
Mem Usage Peak : 3004 K
Page Faults : 847
Pagefile Usage : 2124 K
Pagefile Peak Usage : 2200 K
File Attributes : A
==================================================
==================================================
Process Name : wmiprvse.exe
ProcessID : 1276
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2108)
Description : WMI
Company : Microsoft Corporation
Window Title :
File Size : 218,112
File Created Date : 09/07/1429 12:22:33 ص
File Modified Date : 08/04/1429 10:42:42 ص
Filename : C:\WINDOWS\system32\wbem\wmiprvse.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:50:06 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 5832 K
Mem Usage Peak : 5832 K
Page Faults : 1489
Pagefile Usage : 6384 K
Pagefile Peak Usage : 6384 K
File Attributes : A
==================================================
==================================================
Process Name : CProcess.exe
ProcessID : 3604
Priority : Normal
Product Name : CurrProcess
Version : 1.11
Description : CurrProcess
Company : NirSoft
Window Title :
File Size : 35,840
File Created Date : 15/08/1429 05:50:03 م
File Modified Date : 08/06/1426 04:46:34 ص
Filename : C:\DOCUME~1\sarah\LOCALS~1\Temp\bntoz\CProcess.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:50:16 م
Visible Windows : 0
Hidden Windows : 0
User Name : SARAH-PC\sarah
Mem Usage : 2208 K
Mem Usage Peak : 2252 K
Page Faults : 1006
Pagefile Usage : 884 K
Pagefile Peak Usage : 1520 K
File Attributes : A
==================================================
.
.
--------------------------\\\ End Report Of Running Processes ---------------
.
.
.
.
--------------------------\\\ Windows XP Startup List ---------------
.
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
autocheck autochk *
autocheck autochk *
Auto Check Utility
Microsoft Corporation
5.01.2600.5512
c:\windows\system32\autochk.exe
HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms
rdpclip
rdpclip
RDP Clip Monitor
Microsoft Corporation
5.01.2600.5512
c:\windows\system32\rdpclip.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\userinit.exe
Userinit Logon Application
Microsoft Corporation
5.01.2600.5512
c:\windows\system32\userinit.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
Explorer.exe
Explorer.exe
Windows Explorer
Microsoft Corporation
6.00.2900.5512
c:\windows\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
!AVG Anti-Spyware
"%ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" /minimized
AVG Anti-Spyware
GRISOFT s.r.o.
7.05.0001.0043
c:\program files\grisoft\avg anti-spyware 7.5\zyzoom.exe
IntelZeroConfig
"C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
ZeroCfgSvc MFC Application
Intel Corporation
11.05.0001.0002
c:\program files\intel\wireless\bin\zcfgsvc.exe
IntelWireless
"C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
Intel Framework MFC Application
Intel Corporation
11.05.0001.0002
c:\program files\intel\wireless\bin\ifrmewrk.exe
igfxtray
C:\WINDOWS\system32\igfxtray.exe
igfxTray Module
Intel Corporation
3.00.0000.2285
c:\windows\system32\igfxtray.exe
igfxhkcmd
C:\WINDOWS\system32\hkcmd.exe
hkcmd Module
Intel Corporation
3.00.0000.2285
c:\windows\system32\hkcmd.exe
HotKeysCmds
C:\WINDOWS\system32\hkcmd.exe
hkcmd Module
Intel Corporation
3.00.0000.2285
c:\windows\system32\hkcmd.exe
EPM-DM
C:\Acer\ePM\EPM-DM.exe
Acer EPM Device Manager
Acer Inc
0.02.0003.0005
c:\acer\epm\epm-dm.exe
ePowerManagement
C:\Acer\ePM\ePM.exe boot
Acer ePowerManagement
Acer Value Labs, Taiwan
1.00.0005.0002
c:\acer\epm\epm.exe
BluetoothAuthenticationAgent
rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
Bluetooth Control Panel Applet
Microsoft Corporation
5.01.2600.5512
c:\windows\system32\bthprops.cpl
avgnt
"C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
Antivirus System Tray Tool
Avira GmbH
8.00.0000.0007
c:\program files\avira\antivir personaledition classic\avgnt.exe
bpk
C:\WINDOWS\system32\bpk.exe
c:\windows\system32\bpk.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
CTFMON.EXE
C:\WINDOWS\system32\ctfmon.exe
CTF Loader
Microsoft Corporation
5.01.2600.5512
c:\windows\system32\ctfmon.exe
IDMan
C:\Program Files\Internet Download Manager\IDMan.exe /onboot
Internet Download Manager (IDM)
Tonec Inc.
5.12.0011.0000
c:\program files\internet download manager\idman.exe
Task Scheduler
AppleSoftwareUpdate.job
C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task
Apple Software Update
Apple Inc.
2.01.0000.0110
c:\program files\apple software update\softwareupdate.exe
XoftSpySE 2.job
C:\Program Files\BrOnZ Patch Pro\XoftSpySE\XoftSpy.exe ShowReminders
Xoftspy
ParetoLogic
4.33.5259.0001
c:\program files\bronz patch pro\xoftspyse\xoftspy.exe
.
.
----------- End Report ---------------
جهازي يعلق ويهنق ويبطيء في فتح البرامج
لااجد سببا لذلك فبرامج الحماية ok
ولايوجد تعارضات
هناك طلبين من اخوتي ذوي الخبرة
استخلاص الخطأ من تقرير الهايجاك كيف يتم
ماهي مشكلة جهازي من خلال التقرير
التقرير:
.
--------------------------\\\ Start Report Of HijackThis ---------------
.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:50:15 م, on 17/08/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 SP3 (7.00.6000.20733)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Acer\eManager\anbmServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Acer\ePM\EPM-DM.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\bpk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\DOCUME~1\sarah\LOCALS~1\Temp\bntoz\runn.exe
C:\WINDOWS\system32\cmd.exe
C:\DOCUME~1\sarah\LOCALS~1\Temp\bntoz\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "%ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" /minimized
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [EPM-DM] C:\Acer\ePM\EPM-DM.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [bpk] C:\WINDOWS\system32\bpk.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: ت&صدير إلى Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash ) -
يجب عليك
تسجيل الدخول
او
تسجيل لمشاهدة الرابط المخفي
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: Update Center (Windows Update Center) - Unknown owner - C:\WINDOWS\scvhost.exe (file missing)
--
End of file - 7238 bytes
.
.
--------------------------\\\ End Report Of Of HijackThis ---------------
.
.
.
.
--------------------------\\\ Start Report Of Running Processes ---------------
.
==================================================
Process Name : smss.exe
ProcessID : 636
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Windows NT Session Manager
Company : Microsoft Corporation
Window Title :
File Size : 50,688
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\System32\smss.exe
Base Address : 0x48580000
Created On : 15/08/1429 08:34:38 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 408 K
Mem Usage Peak : 428 K
Page Faults : 195
Pagefile Usage : 168 K
Pagefile Peak Usage : 1708 K
File Attributes : A
==================================================
==================================================
Process Name : csrss.exe
ProcessID : 688
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Client Server Runtime Process
Company : Microsoft Corporation
Window Title :
File Size : 6,144
File Created Date : 08/04/1429 10:42:16 ص
File Modified Date : 08/04/1429 10:42:16 ص
Filename : C:\WINDOWS\system32\csrss.exe
Base Address : 0x4A680000
Created On : 15/08/1429 08:34:40 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 4276 K
Mem Usage Peak : 4472 K
Page Faults : 105755
Pagefile Usage : 2000 K
Pagefile Peak Usage : 2000 K
File Attributes : A
==================================================
==================================================
Process Name : winlogon.exe
ProcessID : 712
Priority : High
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2113)
Description : Windows NT Logon Application
Company : Microsoft Corporation
Window Title :
File Size : 507,904
File Created Date : 08/04/1429 10:42:40 ص
File Modified Date : 08/04/1429 10:42:40 ص
Filename : C:\WINDOWS\system32\winlogon.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:40 م
Visible Windows : 0
Hidden Windows : 1
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 3704 K
Mem Usage Peak : 15928 K
Page Faults : 11065
Pagefile Usage : 7852 K
Pagefile Peak Usage : 8932 K
File Attributes : A
==================================================
==================================================
Process Name : services.exe
ProcessID : 756
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Services and Controller app
Company : Microsoft Corporation
Window Title :
File Size : 108,544
File Created Date : 08/04/1429 10:42:36 ص
File Modified Date : 08/04/1429 10:42:36 ص
Filename : C:\WINDOWS\system32\services.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:41 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 3460 K
Mem Usage Peak : 3624 K
Page Faults : 1506
Pagefile Usage : 1856 K
Pagefile Peak Usage : 2476 K
File Attributes : A
==================================================
==================================================
Process Name : lsass.exe
ProcessID : 768
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2113)
Description : LSA Shell (Export Version)
Company : Microsoft Corporation
Window Title :
File Size : 13,312
File Created Date : 08/04/1429 10:42:26 ص
File Modified Date : 08/04/1429 10:42:26 ص
Filename : C:\WINDOWS\system32\lsass.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:41 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 6448 K
Mem Usage Peak : 6476 K
Page Faults : 1848
Pagefile Usage : 4444 K
Pagefile Peak Usage : 4608 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 920
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:43 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 5292 K
Mem Usage Peak : 5348 K
Page Faults : 1510
Pagefile Usage : 6696 K
Pagefile Peak Usage : 26852 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1008
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:46 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 4564 K
Mem Usage Peak : 4588 K
Page Faults : 1294
Pagefile Usage : 5384 K
Pagefile Peak Usage : 5472 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1044
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\System32\svchost.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:46 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 21624 K
Mem Usage Peak : 23004 K
Page Faults : 10441
Pagefile Usage : 18604 K
Pagefile Peak Usage : 19704 K
File Attributes : A
==================================================
==================================================
Process Name : S24EvMon.exe
ProcessID : 1092
Priority : Normal
Product Name : Intel(R) PROSet/Wireless Service
Version : 11. 5. 1. 2
Description : Wireless Management Service
Company : Intel Corporation
Window Title :
File Size : 1,187,840
File Created Date : 26/02/1429 11:34:38 ص
File Modified Date : 26/02/1429 11:34:38 ص
Filename : C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:46 م
Visible Windows : 0
Hidden Windows : 4
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 13688 K
Mem Usage Peak : 13708 K
Page Faults : 3685
Pagefile Usage : 13548 K
Pagefile Peak Usage : 13604 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1208
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:47 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 3620 K
Mem Usage Peak : 3688 K
Page Faults : 1151
Pagefile Usage : 1400 K
Pagefile Peak Usage : 1484 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1256
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:48 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 4608 K
Mem Usage Peak : 4624 K
Page Faults : 1204
Pagefile Usage : 4628 K
Pagefile Peak Usage : 4676 K
File Attributes : A
==================================================
==================================================
Process Name : spoolsv.exe
ProcessID : 1284
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-0852)
Description : Spooler SubSystem App
Company : Microsoft Corporation
Window Title :
File Size : 57,856
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\system32\spoolsv.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:48 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 5492 K
Mem Usage Peak : 5516 K
Page Faults : 1893
Pagefile Usage : 6804 K
Pagefile Peak Usage : 7044 K
File Attributes : A
==================================================
==================================================
Process Name : sched.exe
ProcessID : 1324
Priority : Normal
Product Name : AntiVir Workstation
Version : 8.00.00.12
Description : Antivirus Scheduler
Company : Avira GmbH
Window Title :
File Size : 68,865
File Created Date : 08/08/1429 09:09:00 م
File Modified Date : 29/02/1429 09:00:08 ص
Filename : C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:48 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 528 K
Mem Usage Peak : 3564 K
Page Faults : 1352
Pagefile Usage : 1588 K
Pagefile Peak Usage : 1596 K
File Attributes : A
==================================================
==================================================
Process Name : anbmServ.exe
ProcessID : 1488
Priority : Normal
Product Name : Acer eManager for Notebook
Version : 3.0.5.8
Description : Service Program for Acer eManager
Company : OSA Technologies Inc.
Window Title :
File Size : 1,287,168
File Created Date : 01/07/1425 12:17:20 م
File Modified Date : 01/07/1425 12:17:20 م
Filename : C:\Acer\eManager\anbmServ.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:51 م
Visible Windows : 0
Hidden Windows : 2
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 5604 K
Mem Usage Peak : 5604 K
Page Faults : 2012
Pagefile Usage : 2596 K
Pagefile Peak Usage : 2596 K
File Attributes : A
==================================================
==================================================
Process Name : Explorer.EXE
ProcessID : 1756
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 6.00.2900.5512 (xpsp.080413-2105)
Description : Windows Explorer
Company : Microsoft Corporation
Window Title : Programs
File Size : 1,033,728
File Created Date : 08/04/1429 10:42:20 ص
File Modified Date : 08/04/1429 10:42:20 ص
Filename : C:\WINDOWS\Explorer.EXE
Base Address : 0x01000000
Created On : 15/08/1429 08:34:54 م
Visible Windows : 3
Hidden Windows : 42
User Name : SARAH-PC\sarah
Mem Usage : 34160 K
Mem Usage Peak : 60604 K
Page Faults : 2374879
Pagefile Usage : 57324 K
Pagefile Peak Usage : 61208 K
File Attributes : A
==================================================
==================================================
Process Name : avguard.exe
ProcessID : 1792
Priority : Normal
Product Name : AntiVir Workstation
Version : 8.00.01.15
Description : Antivirus On-Access Service
Company : Avira GmbH
Window Title :
File Size : 147,201
File Created Date : 08/08/1429 09:08:53 م
File Modified Date : 19/03/1429 12:34:49 م
Filename : C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:54 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 12316 K
Mem Usage Peak : 70820 K
Page Faults : 79974
Pagefile Usage : 75668 K
Pagefile Peak Usage : 731612 K
File Attributes : A
==================================================
==================================================
Process Name : AppleMobileDeviceService.exe
ProcessID : 1832
Priority : Normal
Product Name : Apple Mobile Device Service
Version : 2.0.28.0
Description : Apple Mobile Device Service
Company : Apple Inc.
Window Title :
File Size : 116,040
File Created Date : 07/07/1429 06:47:18 ص
File Modified Date : 07/07/1429 06:47:18 ص
Filename : C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:54 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 2424 K
Mem Usage Peak : 2436 K
Page Faults : 606
Pagefile Usage : 2208 K
Pagefile Peak Usage : 2224 K
File Attributes : A
==================================================
==================================================
Process Name : guard.exe
ProcessID : 1852
Priority : Normal
Product Name : AVG Anti-Spyware
Version : 7, 5, 1, 22
Description : AVG Anti-Spyware guard
Company : GRISOFT s.r.o.
Window Title :
File Size : 312,880
File Created Date : 14/05/1428 12:31:10 م
File Modified Date : 14/05/1428 12:31:10 م
Filename : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:54 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 1540 K
Mem Usage Peak : 49516 K
Page Faults : 24323
Pagefile Usage : 43344 K
Pagefile Peak Usage : 49648 K
File Attributes : A
==================================================
==================================================
Process Name : svchost.exe
ProcessID : 1880
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Generic Host Process for Win32 Services
Company : Microsoft Corporation
Window Title :
File Size : 14,336
File Created Date : 08/04/1429 10:42:38 ص
File Modified Date : 08/04/1429 10:42:38 ص
Filename : C:\WINDOWS\system32\svchost.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:34:54 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 3416 K
Mem Usage Peak : 3424 K
Page Faults : 906
Pagefile Usage : 2716 K
Pagefile Peak Usage : 2740 K
File Attributes : A
==================================================
==================================================
Process Name : EvtEng.exe
ProcessID : 1924
Priority : Normal
Product Name : Intel(R) PROSet/Wireless Event Log
Version : 11. 5. 1. 2
Description : Intel(R) PROSet/Wireless Event Log
Company : Intel Corporation
Window Title :
File Size : 823,296
File Created Date : 26/02/1429 11:55:56 ص
File Modified Date : 26/02/1429 11:55:56 ص
Filename : C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:54 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 13980 K
Mem Usage Peak : 14004 K
Page Faults : 3773
Pagefile Usage : 13844 K
Pagefile Peak Usage : 14328 K
File Attributes : A
==================================================
==================================================
Process Name : RegSrvc.exe
ProcessID : 2040
Priority : Normal
Product Name : Intel(R) PROSet/Wireless Registry Service
Version : 11. 5. 1. 2
Description : Intel(R) PROSet/Wireless Registry Service
Company : Intel Corporation
Window Title :
File Size : 483,328
File Created Date : 26/02/1429 11:30:12 ص
File Modified Date : 26/02/1429 11:30:12 ص
Filename : C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:34:55 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 3244 K
Mem Usage Peak : 3252 K
Page Faults : 827
Pagefile Usage : 4180 K
Pagefile Peak Usage : 4204 K
File Attributes : A
==================================================
==================================================
Process Name : wmiprvse.exe
ProcessID : 668
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2108)
Description : WMI
Company : Microsoft Corporation
Window Title :
File Size : 218,112
File Created Date : 09/07/1429 12:22:33 ص
File Modified Date : 08/04/1429 10:42:42 ص
Filename : C:\WINDOWS\system32\wbem\wmiprvse.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:35:05 م
Visible Windows : 0
Hidden Windows : 0
User Name : NT AUTHORITY\SYSTEM
Mem Usage : 5400 K
Mem Usage Peak : 5708 K
Page Faults : 1621
Pagefile Usage : 4992 K
Pagefile Peak Usage : 5796 K
File Attributes : A
==================================================
==================================================
Process Name : ZCfgSvc.exe
ProcessID : 1176
Priority : Normal
Product Name : ZeroCfgSvc Application
Version : 11. 5. 1. 2
Description : ZeroCfgSvc MFC Application
Company : Intel Corporation
Window Title :
File Size : 999,424
File Created Date : 26/02/1429 11:46:16 ص
File Modified Date : 26/02/1429 11:46:16 ص
Filename : C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:08 م
Visible Windows : 0
Hidden Windows : 5
User Name : SARAH-PC\sarah
Mem Usage : 15240 K
Mem Usage Peak : 15256 K
Page Faults : 21175
Pagefile Usage : 12128 K
Pagefile Peak Usage : 12208 K
File Attributes : A
==================================================
==================================================
Process Name : ifrmewrk.exe
ProcessID : 1184
Priority : Normal
Product Name : Intel(R) PROSet/Wireless
Version : 11. 5. 1. 2
Description : Intel Framework MFC Application
Company : Intel Corporation
Window Title :
File Size : 1,101,824
File Created Date : 26/02/1429 11:41:50 ص
File Modified Date : 26/02/1429 11:41:50 ص
Filename : C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:10 م
Visible Windows : 0
Hidden Windows : 7
User Name : SARAH-PC\sarah
Mem Usage : 18864 K
Mem Usage Peak : 18884 K
Page Faults : 23181
Pagefile Usage : 17844 K
Pagefile Peak Usage : 17872 K
File Attributes : A
==================================================
==================================================
Process Name : igfxtray.exe
ProcessID : 1472
Priority : Normal
Product Name : Intel(R) Common User Interface
Version : 3.0.0.2285
Description : igfxTray Module
Company : Intel Corporation
Window Title :
File Size : 155,648
File Created Date : 09/07/1429 02:10:58 ص
File Modified Date : 06/08/1424 11:37:36 ص
Filename : C:\WINDOWS\system32\igfxtray.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:11 م
Visible Windows : 0
Hidden Windows : 2
User Name : SARAH-PC\sarah
Mem Usage : 4380 K
Mem Usage Peak : 4392 K
Page Faults : 1152
Pagefile Usage : 1676 K
Pagefile Peak Usage : 2368 K
File Attributes : A
==================================================
==================================================
Process Name : hkcmd.exe
ProcessID : 1464
Priority : Normal
Product Name : Intel(R) Common User Interface
Version : 3.0.0.2285
Description : hkcmd Module
Company : Intel Corporation
Window Title :
File Size : 118,784
File Created Date : 09/07/1429 02:10:50 ص
File Modified Date : 06/08/1424 11:19:44 ص
Filename : C:\WINDOWS\system32\hkcmd.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:11 م
Visible Windows : 0
Hidden Windows : 18
User Name : SARAH-PC\sarah
Mem Usage : 4152 K
Mem Usage Peak : 4164 K
Page Faults : 1091
Pagefile Usage : 1732 K
Pagefile Peak Usage : 1820 K
File Attributes : A
==================================================
==================================================
Process Name : EPM-DM.exe
ProcessID : 1548
Priority : Normal
Product Name : Acer EPM Device Manager
Version : 2.35
Description : Acer EPM Device Manager
Company : Acer Inc
Window Title :
File Size : 163,840
File Created Date : 11/07/1429 07:54:11 م
File Modified Date : 14/09/1425 05:16:08 م
Filename : C:\Acer\ePM\EPM-DM.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:12 م
Visible Windows : 0
Hidden Windows : 2
User Name : SARAH-PC\sarah
Mem Usage : 3632 K
Mem Usage Peak : 3644 K
Page Faults : 986
Pagefile Usage : 2704 K
Pagefile Peak Usage : 2792 K
File Attributes : A
==================================================
==================================================
Process Name : rundll32.exe
ProcessID : 1716
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2105)
Description : Run a DLL as an App
Company : Microsoft Corporation
Window Title :
File Size : 33,280
File Created Date : 08/04/1429 10:42:34 ص
File Modified Date : 08/04/1429 10:42:34 ص
Filename : C:\WINDOWS\system32\rundll32.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:35:13 م
Visible Windows : 0
Hidden Windows : 3
User Name : SARAH-PC\sarah
Mem Usage : 4936 K
Mem Usage Peak : 4976 K
Page Faults : 242673
Pagefile Usage : 4052 K
Pagefile Peak Usage : 4244 K
File Attributes : A
==================================================
==================================================
Process Name : avgnt.exe
ProcessID : 1776
Priority : Normal
Product Name : AntiVir Workstation
Version : 8.00.00.07
Description : Antivirus System Tray Tool
Company : Avira GmbH
Window Title :
File Size : 262,401
File Created Date : 08/08/1429 09:08:53 م
File Modified Date : 05/02/1429 07:06:50 ص
Filename : C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:14 م
Visible Windows : 0
Hidden Windows : 5
User Name : SARAH-PC\sarah
Mem Usage : 2384 K
Mem Usage Peak : 53988 K
Page Faults : 67730
Pagefile Usage : 2468 K
Pagefile Peak Usage : 624332 K
File Attributes : A
==================================================
==================================================
Process Name : bpk.exe
ProcessID : 2084
Priority : Normal
Product Name :
Version :
Description :
Company :
Window Title :
File Size : 218,112
File Created Date : 03/08/1428 11:52:19 ص
File Modified Date : 03/08/1428 11:52:19 ص
Filename : C:\WINDOWS\system32\bpk.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:15 م
Visible Windows : 0
Hidden Windows : 6
User Name : SARAH-PC\sarah
Mem Usage : 6584 K
Mem Usage Peak : 6584 K
Page Faults : 1752
Pagefile Usage : 2752 K
Pagefile Peak Usage : 2792 K
File Attributes : A
==================================================
==================================================
Process Name : ctfmon.exe
ProcessID : 2164
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2105)
Description : CTF Loader
Company : Microsoft Corporation
Window Title :
File Size : 15,360
File Created Date : 08/04/1429 10:42:18 ص
File Modified Date : 08/04/1429 10:42:18 ص
Filename : C:\WINDOWS\system32\ctfmon.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:16 م
Visible Windows : 0
Hidden Windows : 5
User Name : SARAH-PC\sarah
Mem Usage : 13480 K
Mem Usage Peak : 13492 K
Page Faults : 2797255
Pagefile Usage : 11344 K
Pagefile Peak Usage : 11432 K
File Attributes : A
==================================================
==================================================
Process Name : IDMan.exe
ProcessID : 2200
Priority : Normal
Product Name : Internet Download Manager (IDM)
Version : 5.12.11.0
Description : Internet Download Manager (IDM)
Company : Tonec Inc.
Window Title :
File Size : 2,594,224
File Created Date : 07/05/1429 12:56:45 م
File Modified Date : 09/07/1429 07:16:01 ص
Filename : C:\Program Files\Internet Download Manager\IDMan.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:17 م
Visible Windows : 0
Hidden Windows : 7
User Name : SARAH-PC\sarah
Mem Usage : 10420 K
Mem Usage Peak : 10428 K
Page Faults : 4074
Pagefile Usage : 16164 K
Pagefile Peak Usage : 16268 K
File Attributes : A
==================================================
==================================================
Process Name : Dot1XCfg.exe
ProcessID : 3036
Priority : Normal
Product Name : Intel PROSet/Wireless
Version : 11. 5. 1. 2
Description : Intel 802.1x Server
Company : Intel Corporation
Window Title :
File Size : 688,128
File Created Date : 26/02/1429 11:37:38 ص
File Modified Date : 26/02/1429 11:37:38 ص
Filename : C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:35:31 م
Visible Windows : 0
Hidden Windows : 5
User Name : SARAH-PC\sarah
Mem Usage : 16676 K
Mem Usage Peak : 16688 K
Page Faults : 4409
Pagefile Usage : 14424 K
Pagefile Peak Usage : 14512 K
File Attributes : A
==================================================
==================================================
Process Name : IEMonitor.exe
ProcessID : 2744
Priority : Normal
Product Name : IEMonitor Application
Version : 5, 12, 8, 0
Description : Internet Download Manager agent for click monitoring in IE-based browsers
Company : Tonec Inc.
Window Title :
File Size : 251,312
File Created Date : 07/05/1429 12:56:41 م
File Modified Date : 11/02/1429 01:01:01 م
Filename : C:\Program Files\Internet Download Manager\IEMonitor.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:36:48 م
Visible Windows : 0
Hidden Windows : 3
User Name : SARAH-PC\sarah
Mem Usage : 5552 K
Mem Usage Peak : 5560 K
Page Faults : 1502
Pagefile Usage : 6164 K
Pagefile Peak Usage : 6176 K
File Attributes : A
==================================================
==================================================
Process Name : FIREFOX.EXE
ProcessID : 4036
Priority : Normal
Product Name : Firefox
Version : 1.8.1.16: 2008070205
Description : Firefox
Company : Mozilla Corporation
Window Title : زيزوووم للأمن والحمايه - Powered by vBulletin - Mozilla Firefox
File Size : 7,667,312
File Created Date : 09/07/1429 01:23:06 ص
File Modified Date : 14/07/1429 12:50:18 ص
Filename : C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
Base Address : 0x00400000
Created On : 15/08/1429 08:46:21 م
Visible Windows : 1
Hidden Windows : 14
User Name : SARAH-PC\sarah
Mem Usage : 34916 K
Mem Usage Peak : 36600 K
Page Faults : 13166
Pagefile Usage : 28184 K
Pagefile Peak Usage : 30092 K
File Attributes : A
==================================================
==================================================
Process Name : runn.exe
ProcessID : 3640
Priority : Normal
Product Name :
Version :
Description :
Company :
Window Title :
File Size : 71,680
File Created Date : 15/08/1429 05:50:03 م
File Modified Date : 23/01/1429 10:24:25 م
Filename : C:\DOCUME~1\sarah\LOCALS~1\Temp\bntoz\runn.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:50:04 م
Visible Windows : 0
Hidden Windows : 0
User Name : SARAH-PC\sarah
Mem Usage : 2124 K
Mem Usage Peak : 2132 K
Page Faults : 640
Pagefile Usage : 800 K
Pagefile Peak Usage : 804 K
File Attributes : A
==================================================
==================================================
Process Name : cmd.exe
ProcessID : 3672
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2111)
Description : Windows Command Processor
Company : Microsoft Corporation
Window Title :
File Size : 389,120
File Created Date : 08/04/1429 10:42:16 ص
File Modified Date : 08/04/1429 10:42:16 ص
Filename : C:\WINDOWS\system32\cmd.exe
Base Address : 0x4AD00000
Created On : 15/08/1429 08:50:04 م
Visible Windows : 0
Hidden Windows : 1
User Name : SARAH-PC\sarah
Mem Usage : 2940 K
Mem Usage Peak : 3004 K
Page Faults : 847
Pagefile Usage : 2124 K
Pagefile Peak Usage : 2200 K
File Attributes : A
==================================================
==================================================
Process Name : wmiprvse.exe
ProcessID : 1276
Priority : Normal
Product Name : Microsoft® Windows® Operating System
Version : 5.1.2600.5512 (xpsp.080413-2108)
Description : WMI
Company : Microsoft Corporation
Window Title :
File Size : 218,112
File Created Date : 09/07/1429 12:22:33 ص
File Modified Date : 08/04/1429 10:42:42 ص
Filename : C:\WINDOWS\system32\wbem\wmiprvse.exe
Base Address : 0x01000000
Created On : 15/08/1429 08:50:06 م
Visible Windows : 0
Hidden Windows : 0
User Name :
Mem Usage : 5832 K
Mem Usage Peak : 5832 K
Page Faults : 1489
Pagefile Usage : 6384 K
Pagefile Peak Usage : 6384 K
File Attributes : A
==================================================
==================================================
Process Name : CProcess.exe
ProcessID : 3604
Priority : Normal
Product Name : CurrProcess
Version : 1.11
Description : CurrProcess
Company : NirSoft
Window Title :
File Size : 35,840
File Created Date : 15/08/1429 05:50:03 م
File Modified Date : 08/06/1426 04:46:34 ص
Filename : C:\DOCUME~1\sarah\LOCALS~1\Temp\bntoz\CProcess.exe
Base Address : 0x00400000
Created On : 15/08/1429 08:50:16 م
Visible Windows : 0
Hidden Windows : 0
User Name : SARAH-PC\sarah
Mem Usage : 2208 K
Mem Usage Peak : 2252 K
Page Faults : 1006
Pagefile Usage : 884 K
Pagefile Peak Usage : 1520 K
File Attributes : A
==================================================
.
.
--------------------------\\\ End Report Of Running Processes ---------------
.
.
.
.
--------------------------\\\ Windows XP Startup List ---------------
.
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
autocheck autochk *
autocheck autochk *
Auto Check Utility
Microsoft Corporation
5.01.2600.5512
c:\windows\system32\autochk.exe
HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms
rdpclip
rdpclip
RDP Clip Monitor
Microsoft Corporation
5.01.2600.5512
c:\windows\system32\rdpclip.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\userinit.exe
Userinit Logon Application
Microsoft Corporation
5.01.2600.5512
c:\windows\system32\userinit.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
Explorer.exe
Explorer.exe
Windows Explorer
Microsoft Corporation
6.00.2900.5512
c:\windows\explorer.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
!AVG Anti-Spyware
"%ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" /minimized
AVG Anti-Spyware
GRISOFT s.r.o.
7.05.0001.0043
c:\program files\grisoft\avg anti-spyware 7.5\zyzoom.exe
IntelZeroConfig
"C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
ZeroCfgSvc MFC Application
Intel Corporation
11.05.0001.0002
c:\program files\intel\wireless\bin\zcfgsvc.exe
IntelWireless
"C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
Intel Framework MFC Application
Intel Corporation
11.05.0001.0002
c:\program files\intel\wireless\bin\ifrmewrk.exe
igfxtray
C:\WINDOWS\system32\igfxtray.exe
igfxTray Module
Intel Corporation
3.00.0000.2285
c:\windows\system32\igfxtray.exe
igfxhkcmd
C:\WINDOWS\system32\hkcmd.exe
hkcmd Module
Intel Corporation
3.00.0000.2285
c:\windows\system32\hkcmd.exe
HotKeysCmds
C:\WINDOWS\system32\hkcmd.exe
hkcmd Module
Intel Corporation
3.00.0000.2285
c:\windows\system32\hkcmd.exe
EPM-DM
C:\Acer\ePM\EPM-DM.exe
Acer EPM Device Manager
Acer Inc
0.02.0003.0005
c:\acer\epm\epm-dm.exe
ePowerManagement
C:\Acer\ePM\ePM.exe boot
Acer ePowerManagement
Acer Value Labs, Taiwan
1.00.0005.0002
c:\acer\epm\epm.exe
BluetoothAuthenticationAgent
rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
Bluetooth Control Panel Applet
Microsoft Corporation
5.01.2600.5512
c:\windows\system32\bthprops.cpl
avgnt
"C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
Antivirus System Tray Tool
Avira GmbH
8.00.0000.0007
c:\program files\avira\antivir personaledition classic\avgnt.exe
bpk
C:\WINDOWS\system32\bpk.exe
c:\windows\system32\bpk.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
CTFMON.EXE
C:\WINDOWS\system32\ctfmon.exe
CTF Loader
Microsoft Corporation
5.01.2600.5512
c:\windows\system32\ctfmon.exe
IDMan
C:\Program Files\Internet Download Manager\IDMan.exe /onboot
Internet Download Manager (IDM)
Tonec Inc.
5.12.0011.0000
c:\program files\internet download manager\idman.exe
Task Scheduler
AppleSoftwareUpdate.job
C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task
Apple Software Update
Apple Inc.
2.01.0000.0110
c:\program files\apple software update\softwareupdate.exe
XoftSpySE 2.job
C:\Program Files\BrOnZ Patch Pro\XoftSpySE\XoftSpy.exe ShowReminders
Xoftspy
ParetoLogic
4.33.5259.0001
c:\program files\bronz patch pro\xoftspyse\xoftspy.exe
.
.
----------- End Report ---------------
