Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

virus in memory , mbr virus


  • Please log in to reply

#1
abd00

abd00

    New Member

  • Member
  • Pip
  • 2 posts
i hv node32 installed

node32 log file :

17/10/2011 11:50:03 ص Startup scanner boot sector MBR sector of the 1. physical disk Win32/Agent.TBV trojan unable to clean
17/10/2011 11:49:41 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
17/10/2011 11:49:29 ص Startup scanner file C:\Windows\KMService.exe a variant of Win32/HackKMS.A potentially unwanted application unable to clean
17/10/2011 11:49:25 ص Startup scanner file C:\Windows\AutoKMS\AutoKMS.exe a variant of Win32/HackKMS.B potentially unwanted application unable to clean

16/10/2011 10:30:47 م Startup scanner boot sector MBR sector of the 1. physical disk Win32/Agent.TBV trojan unable to clean abdelrahman-PC\abdelrahman

16/10/2011 10:30:15 م Real-time file system protection file C:\Windows\KMSEmulator.exe a variant of Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred on a new file created by the application: C:\Windows\AutoKMS\AutoKMS.exe.
06/09/2011 06:40:55 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
06/09/2011 01:03:15 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
06/09/2011 08:56:11 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/09/2011 08:24:25 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
05/09/2011 04:24:51 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
05/09/2011 04:12:50 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
05/09/2011 04:12:35 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
05/09/2011 04:12:26 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
05/09/2011 03:24:32 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
05/09/2011 03:00:57 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/09/2011 11:23:43 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/09/2011 07:25:17 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/09/2011 05:01:29 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
04/09/2011 11:40:55 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
04/09/2011 11:13:21 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
04/09/2011 08:26:13 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
04/09/2011 06:10:05 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
04/09/2011 06:10:05 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
04/09/2011 06:07:49 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
04/09/2011 02:07:02 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
04/09/2011 02:04:51 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
03/09/2011 07:51:52 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
03/09/2011 07:41:18 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
03/09/2011 07:38:31 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
02/09/2011 12:24:04 ص HTTP filter archive http://www.jenniporn...landing/landing HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
02/09/2011 12:22:36 ص HTTP filter archive http://www.jenniporn...landing/landing HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
01/09/2011 11:49:34 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
01/09/2011 07:50:13 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
01/09/2011 04:06:31 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
01/09/2011 03:51:49 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
01/09/2011 02:29:18 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
01/09/2011 12:46:51 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
01/09/2011 08:48:12 ص HTTP filter file http://www.toontuber.com/ JS/TrojanDownloader.Iframe.NKG trojan connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
01/09/2011 08:48:08 ص HTTP filter file http://www.toontuber.com/ JS/TrojanDownloader.Iframe.NKG trojan connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
01/09/2011 08:43:01 ص HTTP filter file http://www.toontuber.com/ JS/TrojanDownloader.Iframe.NKG trojan connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
01/09/2011 07:46:35 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
01/09/2011 12:48:06 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
31/08/2011 08:14:17 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
31/08/2011 08:13:48 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
31/08/2011 08:13:40 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
31/08/2011 03:44:06 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
31/08/2011 03:41:52 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
31/08/2011 02:23:27 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
31/08/2011 01:17:47 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
30/08/2011 04:04:21 ص HTTP filter archive http://siatreeparmul.hotbox.ru/ HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
30/08/2011 03:58:54 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
30/08/2011 03:58:54 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
29/08/2011 10:47:22 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
29/08/2011 10:47:22 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
29/08/2011 10:36:59 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
25/08/2011 10:23:00 ص HTTP filter archive http://vikedoleh.blogspot.com/ HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
25/08/2011 10:22:52 ص HTTP filter archive http://nukiles.blogspot.com/ HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
22/08/2011 12:06:05 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
21/08/2011 07:48:52 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
21/08/2011 07:48:52 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
21/08/2011 07:46:42 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
20/08/2011 12:47:56 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
20/08/2011 12:28:33 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
20/08/2011 12:26:21 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
19/08/2011 03:55:11 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
18/08/2011 02:23:02 ص Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
18/08/2011 01:01:43 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
17/08/2011 10:55:49 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\crossfire.exe.
17/08/2011 10:55:10 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\HGWC.exe.
17/08/2011 10:53:54 م Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
17/08/2011 10:28:09 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
17/08/2011 03:09:45 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
17/08/2011 03:07:34 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
17/08/2011 05:29:32 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
17/08/2011 05:29:31 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
17/08/2011 05:28:41 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
17/08/2011 03:37:54 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
17/08/2011 03:37:53 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
17/08/2011 03:28:54 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
17/08/2011 03:28:54 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
17/08/2011 03:22:40 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
16/08/2011 02:21:57 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
16/08/2011 06:30:38 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
16/08/2011 03:41:14 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
15/08/2011 07:39:45 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
15/08/2011 07:37:39 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
15/08/2011 04:13:18 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
15/08/2011 03:14:48 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
14/08/2011 02:40:54 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
14/08/2011 02:39:01 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
13/08/2011 06:16:05 م Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
13/08/2011 05:09:39 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
13/08/2011 04:55:06 م Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
13/08/2011 04:12:31 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
13/08/2011 04:12:01 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
13/08/2011 04:11:58 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
13/08/2011 03:03:22 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
13/08/2011 03:03:22 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
13/08/2011 03:01:24 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
13/08/2011 03:54:14 ص Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
13/08/2011 02:51:41 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
12/08/2011 09:11:09 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
12/08/2011 09:09:54 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
12/08/2011 01:13:19 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
12/08/2011 12:20:38 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
11/08/2011 11:22:08 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
11/08/2011 11:22:08 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
11/08/2011 05:33:54 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\MRT.exe.
11/08/2011 04:30:55 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
11/08/2011 04:30:55 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
11/08/2011 04:30:08 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
11/08/2011 03:24:39 ص Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
11/08/2011 02:59:43 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
11/08/2011 02:49:05 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\crossfire.exe.
11/08/2011 02:48:54 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\HGWC.exe.
11/08/2011 02:33:29 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\crossfire.exe.
11/08/2011 02:33:21 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\HGWC.exe.
11/08/2011 02:32:35 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\crossfire.exe.
11/08/2011 02:32:25 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\HGWC.exe.
11/08/2011 02:32:08 ص Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
11/08/2011 02:22:30 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\crossfire.exe.
11/08/2011 02:22:24 ص Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
11/08/2011 02:22:19 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\HGWC.exe.
11/08/2011 02:20:57 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\crossfire.exe.
11/08/2011 02:20:12 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\HGWC.exe.
11/08/2011 02:09:08 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
11/08/2011 02:00:33 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
10/08/2011 06:25:37 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
10/08/2011 05:05:43 م Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
10/08/2011 04:00:47 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
10/08/2011 04:00:32 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
10/08/2011 04:00:30 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
10/08/2011 02:49:37 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
10/08/2011 02:48:28 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
10/08/2011 02:54:47 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
10/08/2011 02:53:45 ص Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\conhost.exe.
10/08/2011 02:11:51 ص Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
10/08/2011 01:40:43 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
10/08/2011 01:31:06 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
10/08/2011 12:54:09 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
10/08/2011 12:54:09 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
10/08/2011 12:53:05 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
09/08/2011 06:13:27 م Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Windows\System32\conhost.exe.
09/08/2011 06:12:34 م Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Windows\System32\slui.exe.
09/08/2011 05:53:07 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
09/08/2011 05:15:01 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
09/08/2011 05:15:00 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
09/08/2011 05:12:26 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
09/08/2011 04:54:10 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
09/08/2011 03:09:07 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
09/08/2011 02:59:35 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
09/08/2011 02:18:29 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
08/08/2011 07:46:47 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
08/08/2011 04:46:52 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
08/08/2011 03:55:40 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
08/08/2011 12:46:16 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
08/08/2011 11:57:14 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
08/08/2011 11:47:46 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
08/08/2011 11:45:28 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
08/08/2011 02:44:08 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
08/08/2011 02:44:08 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
08/08/2011 02:42:36 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
07/08/2011 05:18:35 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
07/08/2011 03:04:57 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
07/08/2011 02:00:44 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
07/08/2011 01:58:41 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
06/08/2011 06:33:25 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
06/08/2011 05:34:47 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
06/08/2011 04:06:59 ص Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/08/2011 08:23:49 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/08/2011 08:14:16 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/08/2011 04:31:28 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
05/08/2011 03:04:20 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\crossfire.exe.
05/08/2011 03:04:12 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\HGWC.exe.
05/08/2011 03:02:13 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\crossfire.exe.
05/08/2011 03:02:05 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\HGWC.exe.
05/08/2011 02:55:14 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\crossfire.exe.
05/08/2011 02:55:05 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\HGWC.exe.
05/08/2011 02:37:26 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\crossfire.exe.
05/08/2011 02:37:12 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\HGWC.exe.
05/08/2011 11:32:47 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/08/2011 11:30:41 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
05/08/2011 04:28:49 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/08/2011 03:07:49 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/08/2011 02:33:46 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/08/2011 02:24:16 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/08/2011 12:48:23 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/08/2011 12:38:46 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/08/2011 12:38:46 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
05/08/2011 12:37:14 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
04/08/2011 06:04:15 م Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
04/08/2011 05:16:28 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
04/08/2011 05:14:31 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
04/08/2011 04:52:35 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
04/08/2011 04:51:14 ص Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
04/08/2011 03:14:11 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
04/08/2011 03:04:35 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
03/08/2011 02:07:11 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\crossfire.exe.
03/08/2011 02:07:02 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\HGWC.exe.
03/08/2011 01:58:24 م Real-time file system protection file C:\WINDOWS\KMSERVICE.EXE Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
03/08/2011 01:39:57 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\crossfire.exe.
03/08/2011 01:39:49 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\HGWC.exe.
03/08/2011 01:38:48 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\crossfire.exe.
03/08/2011 01:38:35 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\HGWC.exe.
03/08/2011 01:19:32 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
03/08/2011 01:10:02 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
03/08/2011 01:08:46 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
03/08/2011 01:27:08 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
03/08/2011 01:17:41 ص Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
02/08/2011 10:07:13 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
02/08/2011 09:57:41 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
02/08/2011 08:20:25 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
02/08/2011 06:32:19 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\crossfire.exe.
02/08/2011 06:32:06 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: D:\CrossFire\HGWC.exe.
02/08/2011 05:21:55 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
02/08/2011 05:21:54 م Real-time file system protection file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
02/08/2011 04:11:20 م Startup scanner file C:\Windows\KMService.exe Win32/HackKMS.A potentially unwanted application unable to clean
02/08/2011 03:38:53 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\rundll32.exe.
02/08/2011 03:38:14 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
02/08/2011 03:35:55 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
02/08/2011 03:35:44 م Real-time file system protection file C:\windows\kmservice.exe Win32/HackKMS.A potentially unwanted application unable to clean abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Program Files\Norton Security Scan\Engine\3.5.0.20\Nss.exe.
28/07/2011 11:00:53 ص Real-time file system protection file K:\Autorun.inf Win32/Peerfrag.HC worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\Windows\System32\svchost.exe.
28/07/2011 03:46:01 ص HTTP filter archive http://www.jenniporn...landing/landing HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
28/07/2011 03:46:00 ص HTTP filter archive http://www.jenniporn...landing/landing HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
28/07/2011 03:45:57 ص HTTP filter archive http://www.jenniporn...landing/landing HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
28/07/2011 03:45:51 ص HTTP filter archive http://www.jenniporn...landing/landing HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
28/07/2011 03:45:39 ص HTTP filter archive http://www.jenniporn...landing/landing HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
28/07/2011 03:45:34 ص HTTP filter archive http://www.jenniporn...landing/landing HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
28/07/2011 03:44:26 ص HTTP filter archive http://www.jenniporn...landing/landing HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
27/07/2011 08:45:43 م HTTP filter archive http://www.jenniporn...landing/landing HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
26/07/2011 11:54:51 ص Real-time file system protection file I:\New Folder .exe Win32/Agent.SBR trojan cleaned by deleting - quarantined abdelrahman-PC\abdelrahman Event occurred during an attempt to access the file by the application: C:\Windows\explorer.exe.
24/07/2011 11:08:07 م HTTP filter archive http://www.jenniporn...landing/landing HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.
23/07/2011 01:49:57 ص Real-time file system protection file I:\music.islamic_FoxYou.NeT\Music.exe a variant of Win32/AutoRun.VB.CN worm cleaned by deleting - quarantined abdelrahman-PC\abdelrahman Event occurred during an attempt to run the file by the application: C:\Windows\explorer.exe.
22/07/2011 10:45:26 م HTTP filter archive http://www.jenniporn...landing/landing HTML/ScrInject.B.Gen virus connection terminated - quarantined abdelrahman-PC\abdelrahman Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.




mbr ckecker log file :

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows 7 Ultimate Edition
Windows Information: Service Pack 1 (build 7601), 32-bit
Base Board Manufacturer: ASRock
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: To Be Filled By O.E.M.
System Product Name: To Be Filled By O.E.M.
Logical Drives Mask: 0x000003fc

Kernel Drivers (total 191):
0x82C19000 \SystemRoot\system32\ntoskrnl.exe
0x8301C000 \SystemRoot\system32\halmacpi.dll
0x80BBC000 \SystemRoot\system32\kdcom.dll
0x88816000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8889B000 \SystemRoot\system32\PSHED.dll
0x888AC000 \SystemRoot\system32\BOOTVID.dll
0x888B4000 \SystemRoot\system32\CLFS.SYS
0x888F6000 \SystemRoot\system32\CI.dll
0x889A1000 \SystemRoot\system32\drivers\Wdf01000.sys
0x88A12000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x88A20000 \SystemRoot\system32\drivers\ACPI.sys
0x88A68000 \SystemRoot\system32\drivers\WMILIB.SYS
0x88A71000 \SystemRoot\system32\drivers\msisadrv.sys
0x88A79000 \SystemRoot\system32\drivers\pci.sys
0x88AA3000 \SystemRoot\system32\drivers\vdrvroot.sys
0x88AAE000 \SystemRoot\System32\drivers\partmgr.sys
0x88ABF000 \SystemRoot\system32\drivers\volmgr.sys
0x88ACF000 \SystemRoot\System32\drivers\volmgrx.sys
0x88B1A000 \SystemRoot\system32\drivers\intelide.sys
0x88B21000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x88B2F000 \SystemRoot\System32\drivers\mountmgr.sys
0x88B45000 \SystemRoot\system32\drivers\vmbus.sys
0x88B6F000 \SystemRoot\system32\drivers\winhv.sys
0x88B81000 \SystemRoot\system32\drivers\atapi.sys
0x88B8A000 \SystemRoot\system32\drivers\ataport.SYS
0x88BAD000 \SystemRoot\system32\drivers\amdxata.sys
0x88BB6000 \SystemRoot\system32\drivers\fltmgr.sys
0x88BEA000 \SystemRoot\system32\drivers\fileinfo.sys
0x88800000 \SystemRoot\System32\Drivers\PxHelp20.sys
0x88C21000 \SystemRoot\System32\Drivers\Ntfs.sys
0x88D50000 \SystemRoot\System32\Drivers\msrpc.sys
0x88D7B000 \SystemRoot\System32\Drivers\ksecdd.sys
0x88D8E000 \SystemRoot\System32\Drivers\cng.sys
0x88DEB000 \SystemRoot\System32\drivers\pcw.sys
0x88DF9000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x88E02000 \SystemRoot\system32\drivers\ndis.sys
0x88EB9000 \SystemRoot\system32\drivers\NETIO.SYS
0x88EF7000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x8900F000 \SystemRoot\System32\drivers\tcpip.sys
0x89159000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8918A000 \SystemRoot\system32\drivers\vmstorfl.sys
0x89193000 \SystemRoot\system32\drivers\volsnap.sys
0x891D2000 \SystemRoot\System32\Drivers\spldr.sys
0x891DA000 \SystemRoot\System32\drivers\rdyboost.sys
0x89207000 \SystemRoot\System32\Drivers\mup.sys
0x89217000 \SystemRoot\System32\drivers\hwpolicy.sys
0x8921F000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x89251000 \SystemRoot\system32\DRIVERS\disk.sys
0x89262000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x892B9000 \SystemRoot\system32\drivers\cdrom.sys
0x892D8000 \SystemRoot\System32\Drivers\Null.SYS
0x892DF000 \SystemRoot\System32\Drivers\Beep.SYS
0x892E6000 \SystemRoot\system32\DRIVERS\ehdrv.sys
0x89305000 \SystemRoot\System32\drivers\vga.sys
0x89311000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x89332000 \SystemRoot\System32\drivers\watchdog.sys
0x8933F000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x89347000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8934F000 \SystemRoot\system32\drivers\rdprefmp.sys
0x89357000 \SystemRoot\System32\Drivers\Msfs.SYS
0x89362000 \SystemRoot\System32\Drivers\Npfs.SYS
0x89370000 \SystemRoot\system32\DRIVERS\tdx.sys
0x89387000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x89393000 \SystemRoot\system32\drivers\afd.sys
0x88F1C000 \SystemRoot\System32\DRIVERS\netbt.sys
0x893ED000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x88F4E000 \SystemRoot\system32\DRIVERS\pacer.sys
0x89000000 \SystemRoot\system32\DRIVERS\netbios.sys
0x88F6D000 \SystemRoot\system32\DRIVERS\serial.sys
0x88F87000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x88F9A000 \SystemRoot\system32\drivers\termdd.sys
0x88FAB000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x893F4000 \SystemRoot\system32\drivers\nsiproxy.sys
0x88FEC000 \SystemRoot\system32\drivers\mssmbios.sys
0x88C00000 \??\C:\Program Files\UltraISO\drivers\ISODrive.sys
0x88809000 \SystemRoot\System32\drivers\discache.sys
0x8F835000 \SystemRoot\system32\drivers\csc.sys
0x8F899000 \SystemRoot\System32\Drivers\dfsc.sys
0x8F8B1000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x8F8BF000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8F8E0000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x9081E000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x9113E000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x911F5000 \SystemRoot\System32\drivers\dxgmms1.sys
0x9122E000 \SystemRoot\system32\drivers\HDAudBus.sys
0x9124D000 \SystemRoot\system32\DRIVERS\Rt86win7.sys
0x9127E000 \SystemRoot\system32\drivers\usbuhci.sys
0x91289000 \SystemRoot\system32\drivers\USBPORT.SYS
0x912D4000 \SystemRoot\system32\drivers\usbehci.sys
0x912E3000 \SystemRoot\system32\DRIVERS\parport.sys
0x912FB000 \SystemRoot\system32\drivers\i8042prt.sys
0x91313000 \SystemRoot\system32\drivers\kbdclass.sys
0x91320000 \SystemRoot\system32\DRIVERS\serenum.sys
0x9132A000 \SystemRoot\system32\drivers\CompositeBus.sys
0x91337000 \SystemRoot\system32\DRIVERS\Epfwndis.sys
0x91352000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x91364000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x9137C000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x91387000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x913A9000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x913C1000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x913D8000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x913EF000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x90800000 \SystemRoot\system32\drivers\mouclass.sys
0x9080D000 \SystemRoot\system32\drivers\swenum.sys
0x8F8F2000 \SystemRoot\system32\drivers\ks.sys
0x9080F000 \SystemRoot\system32\drivers\umbus.sys
0x8F926000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8F96A000 \SystemRoot\system32\drivers\viahduaa.sys
0x8FAE9000 \SystemRoot\system32\drivers\portcls.sys
0x8FB18000 \SystemRoot\system32\drivers\drmk.sys
0x8FB31000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x93CA0000 \SystemRoot\System32\win32k.sys
0x91342000 \SystemRoot\System32\drivers\Dxapi.sys
0x8FB42000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8FB4F000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x8FB5A000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x8FB63000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x8FB74000 \SystemRoot\system32\DRIVERS\monitor.sys
0x93F00000 \SystemRoot\System32\TSDDD.dll
0x93F30000 \SystemRoot\System32\cdd.dll
0x8FB7F000 \SystemRoot\system32\drivers\hidusb.sys
0x8FB8A000 \SystemRoot\system32\drivers\HIDCLASS.SYS
0x913F9000 \SystemRoot\system32\drivers\HIDPARSE.SYS
0x9134C000 \SystemRoot\system32\drivers\USBD.SYS
0x8FB9D000 \SystemRoot\system32\drivers\luafv.sys
0x82004000 \SystemRoot\system32\DRIVERS\eamonm.sys
0x820AA000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x820B5000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x820CC000 \SystemRoot\system32\drivers\WudfPf.sys
0x820E6000 \SystemRoot\system32\DRIVERS\epfw.sys
0x82108000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x82118000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x8212B000 \SystemRoot\System32\Drivers\fastfat.SYS
0x82155000 \SystemRoot\system32\drivers\HTTP.sys
0x821DA000 \SystemRoot\system32\DRIVERS\bowser.sys
0x821F3000 \SystemRoot\System32\drivers\mpsdrv.sys
0x82205000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x82228000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x82263000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x8227E000 \SystemRoot\system32\DRIVERS\parvdm.sys
0x82285000 \SystemRoot\system32\DRIVERS\epfwwfp.sys
0x82293000 \SystemRoot\system32\DRIVERS\idmwfp.sys
0x822AC000 \SystemRoot\system32\drivers\peauth.sys
0x82343000 \SystemRoot\System32\Drivers\secdrv.SYS
0x823B7000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x823D8000 \SystemRoot\System32\drivers\tcpipreg.sys
0xAC405000 \SystemRoot\System32\DRIVERS\srv2.sys
0xAC455000 \SystemRoot\System32\DRIVERS\srv.sys
0xAC4A7000 \SystemRoot\system32\DRIVERS\nwifi.sys
0xAC4ED000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xAC4FD000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0x773A0000 \Windows\System32\ntdll.dll
0x47D80000 \Windows\System32\smss.exe
0x775E0000 \Windows\System32\apisetschema.dll
0x00F00000 \Windows\System32\autochk.exe
0x77530000 \Windows\System32\usp10.dll
0x77320000 \Windows\System32\comdlg32.dll
0x77520000 \Windows\System32\psapi.dll
0x77280000 \Windows\System32\advapi32.dll
0x77510000 \Windows\System32\nsi.dll
0x774F0000 \Windows\System32\imm32.dll
0x77230000 \Windows\System32\gdi32.dll
0x77160000 \Windows\System32\user32.dll
0x77120000 \Windows\System32\ws2_32.dll
0x77070000 \Windows\System32\msvcrt.dll
0x76F10000 \Windows\System32\ole32.dll
0x76E00000 \Windows\System32\urlmon.dll
0x76DB0000 \Windows\System32\Wldap32.dll
0x76D50000 \Windows\System32\difxapi.dll
0x774E0000 \Windows\System32\lpk.dll
0x76CA0000 \Windows\System32\rpcrt4.dll
0x76B80000 \Windows\System32\wininet.dll
0x76AF0000 \Windows\System32\clbcatq.dll
0x76A20000 \Windows\System32\msctf.dll
0x76990000 \Windows\System32\oleaut32.dll
0x767D0000 \Windows\System32\iertutil.dll
0x76770000 \Windows\System32\shlwapi.dll
0x76760000 \Windows\System32\normaliz.dll
0x765C0000 \Windows\System32\setupapi.dll
0x75970000 \Windows\System32\shell32.dll
0x75940000 \Windows\System32\imagehlp.dll
0x75860000 \Windows\System32\kernel32.dll
0x75840000 \Windows\System32\sechost.dll
0x757B0000 \Windows\System32\comctl32.dll
0x75790000 \Windows\System32\devobj.dll
0x75760000 \Windows\System32\cfgmgr32.dll
0x75640000 \Windows\System32\crypt32.dll
0x755F0000 \Windows\System32\KernelBase.dll
0x755C0000 \Windows\System32\wintrust.dll
0x755B0000 \Windows\System32\msasn1.dll

Processes (total 56):
0 System Idle Process
4 System
280 C:\Windows\System32\smss.exe
396 csrss.exe
448 C:\Windows\System32\wininit.exe
460 csrss.exe
496 C:\Windows\System32\services.exe
512 C:\Windows\System32\lsass.exe
520 C:\Windows\System32\lsm.exe
588 C:\Windows\System32\winlogon.exe
692 C:\Windows\System32\svchost.exe
768 C:\Windows\System32\svchost.exe
816 C:\Windows\System32\svchost.exe
912 C:\Windows\System32\svchost.exe
956 C:\Windows\System32\svchost.exe
1016 C:\Windows\System32\audiodg.exe
1148 C:\Windows\System32\svchost.exe
1284 C:\Windows\System32\svchost.exe
1440 C:\Windows\System32\spoolsv.exe
1468 C:\Windows\System32\svchost.exe
1624 C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
1688 C:\Program Files\ESET\ESET Smart Security\ekrn.exe
1720 C:\Windows\System32\svchost.exe
1784 C:\Windows\System32\srvany.exe
1884 C:\Windows\System32\taskhost.exe
1916 C:\Windows\KMService.exe
1924 C:\Windows\System32\conhost.exe
1940 C:\Windows\System32\dwm.exe
236 C:\Windows\explorer.exe
248 C:\Windows\Installer\MSIFF5F.tmp
1316 C:\Windows\System32\svchost.exe
1876 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
2168 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
2276 C:\Program Files\ESET\ESET Smart Security\egui.exe
2300 C:\Program Files\Common Files\Java\Java Update\jusched.exe
2312 C:\Program Files\Ad Muncher\AdMunch.exe
2568 C:\Program Files\Internet Download Manager\IDMan.exe
2576 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
2596 C:\Program Files\Skype\Phone\Skype.exe
2668 C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
2992 C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
3524 C:\Windows\System32\svchost.exe
3756 WUDFHost.exe
4048 C:\Program Files\Internet Download Manager\IEMonitor.exe
4088 C:\Windows\System32\SearchIndexer.exe
2396 C:\Program Files\Windows Media Player\wmpnetwk.exe
3728 C:\Windows\System32\svchost.exe
408 C:\Program Files\Mozilla Firefox\firefox.exe
3592 C:\Program Files\Nero\Update\NASvc.exe
464 C:\Windows\System32\svchost.exe
1216 C:\Program Files\Mozilla Firefox\plugin-container.exe
1176 C:\Windows\System32\SearchProtocolHost.exe
1392 C:\Windows\System32\SearchFilterHost.exe
996 C:\Users\abdelrahman\Downloads\Programs\MBRCheck.exe
3316 C:\Windows\System32\conhost.exe
1756 C:\Windows\System32\dllhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x0000000c`80737e00 (NTFS)
\\.\E: --> \\.\PhysicalDrive0 at offset 0x00000032`00d17a00 (NTFS)
\\.\F: --> \\.\PhysicalDrive0 at offset 0x00000044`c1007800 (NTFS)
\\.\G: --> \\.\PhysicalDrive0 at offset 0x0000005a`0178aa00 (NTFS)

PhysicalDrive0 Model Number: WDCWD5000AAKS-00WWPA0, Rev: 01.03B01

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


Done!


  • 0

Advertisements


#2
abd00

abd00

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
node report

Attached Files

  • Attached File  node.txt   435.58KB   80 downloads

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP