Malwarebytes Anti-Malware 1.75.0.1300
Database version: v2014.03.08.01
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
HP :: HP-49CD5491BF5C [administrator]
07/05/1435 09:34:05 ص
mbam-log-2014-03-08 (09-34-05).txt
Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 321830
Time elapsed: 36 minute(s), 34 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 8
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} (PUP.Optional.Spigot) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Object Browser (PUP.Optional.ObjectBrowser.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Goobzo\YouTube Accelerator (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
HKCU\Software\Show-Password (PUP.Optional.ShowPassword.A) -> Quarantined and deleted successfully.
HKCU\Software\AppDataLow\Software\Crossrider (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
HKCU\Software\Goobzo\Language\YouTubeAccelerator (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Object Browser (PUP.Optional.ObjectBrowser.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Goobzo\YouTube Accelerator (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
Folders Detected: 14
C:\Documents and Settings\HP\Local Settings\Application Data\Slick Savings (PUP.Optional.Spigot.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\OpenCandy (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\OpenCandy\5307534261D844B98D3A414747DA7563 (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\OpenCandy\61F79F82777D40AE82D4F1AE285117E2 (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\OpenCandy\686FBBC4E1834BD9A4C49B8DB7B760CE (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\OpenCandy\8D22BD5CA22447ECBAEE47D4BF5F941C (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\OpenCandy\931FCE397914449ABFBA57BFE4829C4F (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\newnext.me (PUP.Optional.NextLive.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\newnext.me\cache (PUP.Optional.NextLive.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\LNG (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Log (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008 (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
Files Detected: 64
C:\Documents and Settings\HP\Application Data\OpenCandy\686FBBC4E1834BD9A4C49B8DB7B760CE\hao123inst-saudi.exe (PUP.Optional.Hao123.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\OpenCandy\686FBBC4E1834BD9A4C49B8DB7B760CE\hao123inst-saudi_p1v1.exe (PUP.Optional.Hao123.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\OpenCandy\8D22BD5CA22447ECBAEE47D4BF5F941C\Mobogenie_Setup_2.1.35_507.exe (PUP.Optional.NextLive.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\OpenCandy\931FCE397914449ABFBA57BFE4829C4F\hao123inst-saudi.exe (PUP.Optional.Hao123.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\OpenCandy\931FCE397914449ABFBA57BFE4829C4F\hao123inst-saudi_p1v1.exe (PUP.Optional.Hao123.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Local Settings\Application Data\Mobogenie\Version\OldVersion\Mobogenie2.1.36.zip (PUP.Optional.NextLive.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\My Documents\pal_install_a4650_r131001_p127000.exe (PUP.Optional.Spigot.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\My Documents\Downloads\setup.exe (PUP.Optional.Outbrowse) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\My Documents\Downloads\لم يتم تأكيده 136113.crdownload (PUP.Optional.BundleInstaller.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\My Documents\Downloads\لم يتم تأكيده 446262.crdownload (PUP.Optional.BundleInstaller.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\My Documents\Downloads\لم يتم تأكيده 469544.crdownload (PUP.Optional.BundleInstaller.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\My Documents\Downloads\لم يتم تأكيده 58302.crdownload (PUP.Optional.BundleInstaller.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\My Documents\Downloads\لم يتم تأكيده 788665.crdownload (PUP.Optional.BundleInstaller.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\My Documents\Downloads\لم يتم تأكيده 881603.crdownload (PUP.Optional.BundleInstaller.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\My Documents\Downloads\لم يتم تأكيده 883984.crdownload (PUP.Optional.BundleInstaller.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\My Documents\Downloads\لم يتم تأكيده 899624.crdownload (PUP.Optional.BundleInstaller.A) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP189\A0162845.exe (PUP.Optional.Hao123.A) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP191\A0163037.exe (PUP.Optional.WeatherAlerts.A) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP191\A0163046.dll (PUP.Optional.Fortunitas.A) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP192\A0165171.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{CFFE93F5-0B4D-4797-9FA8-AE802FE92E27}\RP206\A0185607.exe (PUP.Optional.OpenCandy.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\logs.dat (Bifrose.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Local Settings\Application Data\Slick Savings\coupons.crx (PUP.Optional.Spigot.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\OpenCandy\5307534261D844B98D3A414747DA7563\Mobogenie_Setup_2.1.27_507.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\OpenCandy\61F79F82777D40AE82D4F1AE285117E2\Mobogenie_Setup_2.1.27_507.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\newnext.me\nengine.cookie (PUP.Optional.NextLive.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP\Application Data\newnext.me\cache\spark.bin (PUP.Optional.NextLive.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\config.xml (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\va_conf.dat (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\engine_1148_svchost.log (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\engine_3884_testlsp.log (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\engine_3968_YouTubeAcceleratorService.log (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\helper_3884_testlsp.log (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\ipc_3884_testlsp.log (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\LspCommTest.zip (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\testlsp_3884.log (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\YouTubeAcceleratorService_3968.log (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_3004.log (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\now_accelerating.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\acceleration_not_supported.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\activation_expired.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\activation_offline.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\blank.html (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\dl_update.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\exiting.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\hd_disabled.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\itunesmessage.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\noupdates.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\oem_video_accelerator.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\olddriver.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\premium_now_accelerating.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\premium_video_accelerator.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\restart.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\silenttestfailed.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\silenttestsucceeded.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\test.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trialexp_video_accelerator.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trial_now_accelerating.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trial_video_accelerator.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\tweetmessage.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\update.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\va_off.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\va_on.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\video_accelerator.mht (PUP.Optional.YouTubeAccelerator.A) -> Quarantined and deleted successfully.
(end)
______________________________________________
GetSystemInfo
وبعدين ؟