عبد العزيز فياز
زيزوومي جديد
- إنضم
- 26 فبراير 2011
- المشاركات
- 12
- مستوى التفاعل
- 0
- النقاط
- 20
غير متصل
قم بمتابعة الفيديو أدناه لمعرفة كيفية تثبيت موقعنا كتطبيق ويب على الشاشة الرئيسية.
ملاحظة: قد لا تكون هذه الميزة متاحة في بعض المتصفحات.
HitmanPro 3.7.9.232
www.hitmanpro.com
Computer name . . . . : DARULERS-A44CAB
Windows . . . . . . . : 5.1.3.2600.X86/2
User name . . . . . . : DARULERS-A44CAB\عبد العزيز الأمجدي
License . . . . . . . : Trial (30 days left)
Scan date . . . . . . : 2015-01-07 12:23:07
Scan mode . . . . . . : Normal
Scan duration . . . . : 8m 15s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : Yes
Threats . . . . . . . : 4
Traces . . . . . . . : 16
Objects scanned . . . : 497,343
Files scanned . . . . : 9,117
Remnants scanned . . : 61,731 files / 426,495 keys
Malware _____________________________________________________________________
C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\ARHome\Updater.exe -> Deleted
Size . . . . . . . : 187,472 bytes
Age . . . . . . . : 76.9 days (2014-10-22 14:19:24)
Entropy . . . . . : 6.5
SHA-256 . . . . . : 860346C77609B1D4356D5219CF4DC2B72F0F195C7F26EDC450EBA1AEE367A109
RSA Key Size . . . : 2048
Authenticode . . . : Valid
> Bitdefender . . . : Application.Generic.1003759
Fuzzy . . . . . . : 104.0
Startup
HKU\S-1-5-21-1454471165-1957994488-1801674531-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ArHome
HKU\S-1-5-21-1454471165-1957994488-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ArHome
References
HKU\S-1-5-21-1454471165-1957994488-1801674531-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\ARHome\Updater.exe
HKU\S-1-5-21-1454471165-1957994488-1801674531-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\ARHome\Updater.exe
C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\scope_dir\scope.exe -> Deleted
Size . . . . . . . : 82,512 bytes
Age . . . . . . . : 16.0 days (2014-12-22 11:21:54)
Entropy . . . . . : 6.4
SHA-256 . . . . . : 355E2DEBEE95B1BCAFABAA2C93B80AFA6024D7BA23BAD1FA5301E564DDE4F3BB
RSA Key Size . . . : 2048
Authenticode . . . : Valid
> Bitdefender . . . : Gen:Variant.Graftor.169175
Fuzzy . . . . . . : 105.0
Startup
HKU\S-1-5-21-1454471165-1957994488-1801674531-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\scope_dir
HKU\S-1-5-21-1454471165-1957994488-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\scope_dir
References
HKU\S-1-5-21-1454471165-1957994488-1801674531-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\scope_dir\scope.exe
HKU\S-1-5-21-1454471165-1957994488-1801674531-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\scope_dir\scope.exe
Forensic Cluster
-1.3s C:\WINDOWS\system32\GroupPolicy\
-1.3s C:\WINDOWS\system32\GroupPolicy\gpt.ini
-1.3s C:\WINDOWS\system32\GroupPolicy\Machine\
-1.3s C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol
-1.3s C:\WINDOWS\system32\GroupPolicy\User\
-1.2s C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\searchPlugins\
-1.0s C:\System Volume Information\_restore{2326D391-A7ED-4004-ABC0-491DFD3C12D6}\RP49\A0014138.pol
-1.0s C:\Documents and Settings\All Users\ntuser.pol
-0.7s C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\VolIE\
-0.4s C:\System Volume Information\_restore{2326D391-A7ED-4004-ABC0-491DFD3C12D6}\RP49\A0014151.ico
-0.4s C:\System Volume Information\_restore{2326D391-A7ED-4004-ABC0-491DFD3C12D6}\RP49\A0014152.manifest
-0.4s C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\VolIE\FoxPro_32.dll
-0.4s C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\VolIE\onload.js
-0.2s C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\scope_dir\
0.0s C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\scope_dir\scope.exe
1.3s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Mozilla Firefox\updates\last-update.log
3.0s C:\System Volume Information\_restore{2326D391-A7ED-4004-ABC0-491DFD3C12D6}\RP51\A0014311.exe
5.1s C:\System Volume Information\_restore{2326D391-A7ED-4004-ABC0-491DFD3C12D6}\RP49\A0014187.exe
6.4s C:\Program Files\Mozilla Firefox\uninstall\uninstall.update
7.7s C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\Mozilla\Firefox\Crash Reports\InstallTime20141126041045
7.9s C:\System Volume Information\_restore{2326D391-A7ED-4004-ABC0-491DFD3C12D6}\RP49\A0014188.ini
9.3s C:\System Volume Information\_restore{2326D391-A7ED-4004-ABC0-491DFD3C12D6}\RP49\A0014189.ini
10.9s C:\System Volume Information\_restore{2326D391-A7ED-4004-ABC0-491DFD3C12D6}\RP49\A0014190.exe
11.8s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\8058150DC3F62CF44C48B07A5893B27FD6092639
11.9s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\415ADD3BFA2110C54561A2D2628C2F6CF6F3455D
12.5s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Mozilla Firefox\active-update.xml
12.5s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Mozilla Firefox\updates.xml
15.0s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\90EE3CF66258DE9C9A1291A543C4542722FC76A8
15.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\25018D6F282D3F1797EF8F674691B6D60529255F
15.3s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\779B8AB09AE872411CD7AC54BC786105F075A291
15.3s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\A7C7D52919BE5C5FF3A548DE97C6724B3E4A9F81
17.4s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\4A516AB35AEF0B37CE3E3CF3556A298BBA82E8E3
17.5s C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\sessionstore-backups\upgrade.js-20141126041045
18.8s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\FEF699D62308938DBD9BA8468C650774383C683A
18.8s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\1A328E46B257B8C1599467042CB83585468C5345
18.8s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\679CEEF4DF21441CB278A820CD9BFCB5387309C2
21.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\813ACF1718075ED56539DADC4B374EA989FFFE7D
21.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\03C21EE2B4622EDDF71BCFD9512B9BFF83E69234
21.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\96BC25FE64102D2E2CC44D52AFD1CB998ADC166A
21.3s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\4315DA8FB5121D961C8EE6FF37818991E60D8201
21.3s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\01C384EBB27084C3D695F86E3D0529AFC12352B4
22.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\A9E14A7DDA5845DD1F8D36822BB098234B8199AD
22.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\CFE51EBEE272DF3F404FE56FA80CDB75300F3B03
22.7s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\46E5DEB177F68343AB097A7E82CE11C9CE327765
22.7s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\07F42ECDF61ACC05572F7158DBE2A1233DD39243
22.7s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\8891AD2FE738215ED74B9E741A01DA519EC4D4C0
23.1s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\811A091F81378ADA4ED48BEB8BFFD92626F80B38
23.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\0E58A190471AE6EEBC7660E22CCA59A604DB4BA6
23.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\39BEB9A416B91FFB92FF08B36C52C09E926819CC
23.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\2D4E28FA22D25680B4938A4BED985F85DF23DBB0
23.6s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\A1AC5035F9D9537AA235880E99AD2DFD76793988
23.6s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\D4AB47217286B7472D7BA16E4F63287563769757
23.6s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\3AD7AB86CF36D61FBD11333E61ABD1B885B3C126
26.8s C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\datareporting\
26.8s C:\Documents and Settings\عبد العزيز الأمجدي\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\datareporting\state.json
28.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\D0B790F0C486943CC5409CC6EBEC4CACB9012093
28.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\2991AA85D72116550B65466FDFD1CC42FD9D77FF
28.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\9106646583E7AEE22B803436B736D1C6AA06AF16
28.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\A18D00903D6D1857F8C0EE85DA2E85A066245D23
28.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\FA22D5DC270BA49762C5661B32B93837CC51001C
28.2s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\5463B6CD0AC3D9BA7F91C50F3DC7BC1ABC3C5CCB
28.5s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\38B6277350E8CA0BE0A574EA4689606F41E30226
29.3s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\826751FCC1C2734FB56ABC1A1AFE1C8C2326AFEF
29.7s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\C4FC6DCB5BFE5DABF20DFD7B3A453128416B6428
30.0s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\445A8B90CEAFF24EA896CDDD5F4DAA81AFAA7259
30.5s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\033DEF6E95D778B09CD141DCFBC821443728B5F1
31.3s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\BE23274D0554859A6F38EBB46E60F471A6D3C9D2
31.3s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\E10BB459CF0EFF3C0010D2FA5D0217DA9AF64782
31.4s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\A798F02BC60C21C6B2930E374C02509EFC55C3BA
31.9s C:\System Volume Information\_restore{2326D391-A7ED-4004-ABC0-491DFD3C12D6}\RP49\A0014193.exe
32.1s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\D13F5296654CBA66DADA4A61AA99EDD8D543E725
33.7s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\6A6C04DE2A923EECBA249B14C8870588AD1541EF
33.8s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\76C6652E8BDA42669C0D2797257C5ABDCAF48C83
36.3s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\BE790FBDEB19D6FADD9CC94355DEBFF72F6011CF
36.6s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\3A88321916042365280EA6E364D05EA9C18E6784
36.6s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\04055068BD630A5D10C9377EE829AC6EF947E37F
36.6s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\49B049F8728680802FBF741368AC35EA14DF4C62
36.6s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\991A03DFDB2967C57BCFC15B5D51724F64CECFAE
38.1s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\5BECC3E8C6627AE925C7C2E9B1F072F7AD1178F9
39.0s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\A0A3A330C3B776857411127D21FBF2B6129CD992
39.0s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\B26DC3B6BCC7E218F7200F20EB88C7AFFA520FA5
41.0s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\2BF0FFD006D0B03C0EB518C44428DFD64212A564
41.0s C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Application Data\Mozilla\Firefox\Profiles\nsswaarl.default\cache2\entries\6463187FA93FBE041D600EF204E83E31C304689F
C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Temp\uUItppu -> Deleted
Size . . . . . . . : 187,464 bytes
Age . . . . . . . : 76.9 days (2014-10-22 14:19:24)
Entropy . . . . . : 6.5
SHA-256 . . . . . : 58F34D01605174D6BAE860F160EAB96DC1089073628B850B277160500EF53CBE
RSA Key Size . . . : 2048
Authenticode . . . : Valid
> Bitdefender . . . : Trojan.GenericKD.1985544
Fuzzy . . . . . . : 103.0
C:\Documents and Settings\عبد العزيز الأمجدي\Local Settings\Temporary Internet Files\Content.IE5\OR49SXWD\8284b8[1].exe -> Deleted
Size . . . . . . . : 2,339,920 bytes
Age . . . . . . . : 16.0 days (2014-12-22 11:21:30)
Entropy . . . . . : 8.0
SHA-256 . . . . . : BCDA59A59565D964AFAC1F121723244D1469D5F1A2846B697E5691EE6F7D2D15
RSA Key Size . . . : 2048
Source URL . . . . : hxxp://www.colompia.info/3eac715/8284b8.exe
Authenticode . . . : Valid
> Bitdefender . . . : Gen:Variant.Zusy.113278
> Kaspersky . . . . : Trojan.Win32.Agent.idvs
Fuzzy . . . . . . : 108.0
Suspicious files ____________________________________________________________
C:\Program Files\eDirection\eDP.exe -> Deleted
Size . . . . . . . : 2,862,888 bytes
Age . . . . . . . : 55.9 days (2014-11-12 15:26:48)
Entropy . . . . . : 7.9
SHA-256 . . . . . : 60C051327F68705A5E7A8819A7E27BEB753065886982097F74CA67F459E35AD5
Product . . . . . : نظام الإشراف الإلكتروني
Publisher
Description . . . : نظام الإشراف الإلكتروني
Version . . . . . : 4.0.0.4
LanguageID . . . . : 1025
Fuzzy . . . . . . : 31.0
The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
The .rsrc (resources) section in this program is set to executable. This is an indication of malware infection.
Program contains PE structure anomalies. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
References
C:\Documents and Settings\All Users\قائمة ابدأ\البرامج\الإشراف الإلكتروني\الإشراف الألكتروني.lnk
C:\Documents and Settings\عبد العزيز الأمجدي\سطح المكتب\الإشراف الألكتروني.lnk
C:\Program Files\eDirection\RepPreview.dll -> Deleted
Size . . . . . . . : 666,894 bytes
Age . . . . . . . : 55.9 days (2014-11-12 15:26:49)
Entropy . . . . . : 7.9
SHA-256 . . . . . : 20DE925E77046D1FEBEEF519FC10F2F2A88C0F1FA8AE4FCE641F8A6088693D64
Fuzzy . . . . . . : 40.0
The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
File belongs to an identified security risk.
The .rsrc (resources) section in this program is set to executable. This is an indication of malware infection.
Program contains PE structure anomalies. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.