من فضلك قم بتحديث الصفحة لمشاهدة المحتوى المخفي
تقرير أداة zoek
Zoek.exe v5.0.0.0 Updated 26-February-2015
Tool run by PC i7 on Fri 02/27/2015 at 7:45:06.22.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\PC i7\Downloads\برامج حماية\أداة Zoek\zoek.exe [Scan all users] [Deep Scan]
==== Older Logs ======================
C:\zoek-results2015-02-22-085816.log 100353 bytes
C:\zoek-results2015-02-26-184917.log 415 bytes
==== Running Processes ======================
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\IProsetMonitor.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
C:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\vssvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\SmartPCFixer\SmartPCFixer.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Ad Muncher\AdMunch.exe
C:\Users\PC i7\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\PC i7\Downloads\برامج حماية\أداة Zoek\zoek.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k swprv
==== System Specs ======================
Windows: Windows 7 Ultimate Edition Service Pack 1 (Build 7601)
Memory (RAM): 3570 MB
CPU Info: Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz
CPU Speed: 3462.7 MHz
Sound Card: سماعات (Realtek High Definition |
Realtek Digital Output (Realtek |
Realtek Digital Output(Optical) |
Display Adapters: ATI Radeon HD 5450 | ATI Radeon HD 5450 | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver
Monitors: 1x; Generic PnP Monitor |
Screen Resolution: 1440 X 900 - 32 bit
Network: Network Present
Network Adapters: Anchorfree HSS VPN Adapter #2 | Anchorfree HSS VPN Adapter | 802.11 USB Wireless LAN Card | Intel(R) 82579V Gigabit Network Connection
CD / DVD Drives: 2x (D: | L: | ) D: ATAPI iHAS324 B | L: EZBSYS ISO CDVD DRIVE
Ports: COM8 | COM9 LPT Port NOT Present.
Mouse: 5 Button Wheel Mouse Present
Hard Disks: C: 195.2GB | E: 376.0GB | F: 360.2GB | I: 2794.5GB
Hard Disks - Free: C: 77.9GB | E: 256.2GB | F: 204.0GB | I: 1314.6GB
Manufacturer *: Intel Corp.
BIOS Info: AT/AT COMPATIBLE | 12/22/11 | HPQOEM - 1072009
Time Zone: السعودية - التوقيت الرسمي
Motherboard *: Intel Corporation DH67CL
Country: ںéêêéè، ںéم© ï، ںé«مي§ï،
Language: ARA
==== System Specs (Software) ======================
Anti-Virus: Microsoft Security Essentials On-access scanning disabled (Outdated)
Anti-Virus: avast! Antivirus On-access scanning disabled (Outdated)
Anti-Spyware: Microsoft Security Essentials disabled (Outdated)
Anti-Spyware: Windows Defender disabled (Outdated)
Anti-Spyware: avast! Antivirus disabled (Outdated)
Default Browser: Google Chrome 40.0.2214.115
Internet Explorer Version: 11.0.9600.17633
Mozilla Firefox version: 31.0 (x86 ar)
Opera Browser version: 27.0.1689.76
Google Chrome version: 40.0.2214.115
Adobe Reader version: 11.0.10.32
Sun Java version: 1.7.0_25 (32-bit)
Flash Player version: 16.0.0.305
==== Files Recently Created / Modified ======================
====== C:\Windows ====
====== C:\Users\PCI7~1\AppData\Local\Temp ====
2015-02-26 07:00:15 875423375660681EBEA1781EDA926AD2 16896 ----a-w- C:\Users\PC i7\AppData\Local\Temp\SBLCopyF.EXE
====== Java Cache =====
====== C:\Windows\system32 =====
====== C:\Windows\system32\drivers =====
2015-02-11 09:18:40 F516F1167EFBBC5ABC90687C94497869 369968 ----a-w- C:\Windows\System32\drivers\cng.sys
2015-02-11 09:18:40 EF88BAC2B489D9C46F4E41ACF0219CD0 67520 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2015-02-11 09:18:40 49D70660EE8266988C1F99A0297A1430 136640 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
2015-02-22 11:29:04 -------- d-----w- C:\Program Files\Ad Muncher
2015-02-16 23:33:31 -------- d-----w- C:\Program Files\Sophos
2015-02-04 00:32:09 -------- d-----w- C:\Program Files\ABC Amber BlackBerry Converter
2015-02-04 00:25:35 -------- d-----w- C:\Program Files\ABC Amber PDF Converter
2015-02-02 20:55:17 -------- d-----w- C:\Program Files\AVI MPEG RM WMV Splitter
2015-02-02 20:52:39 -------- d-----w- C:\Program Files\Boilsoft Video Splitter
2015-02-02 20:48:28 -------- d-----w- C:\Program Files\Speed Video Splitter
2015-02-02 20:42:29 -------- d-----w- C:\Program Files\Ultra Video Splitter
======= C: =====
====== C:\Users\PC i7\AppData\Roaming ======
2015-02-25 04:47:58 -------- d-----w- C:\Users\PC i7\AppData\Roaming\Runscanner.net
2015-02-22 07:53:22 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Local\temp
2015-02-22 07:53:22 -------- d-----w- C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp
2015-02-22 07:53:22 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp
2015-02-22 07:53:22 -------- d-----w- C:\Users\fbwuserA8AC\AppData\Local\Temp
2015-02-22 07:53:22 -------- d-----w- C:\Users\fbwuser69FA\AppData\Local\Temp
2015-02-22 07:53:21 -------- d-----w- C:\Users\PC i7\AppData\Local\Temp
2015-02-22 07:53:21 -------- d-----w- C:\Users\fbwuser6463\AppData\Local\Temp
2015-02-22 07:53:21 -------- d-----w- C:\Users\Default\AppData\Local\Temp
2015-02-22 07:53:21 -------- d-----w- C:\Users\Default User\AppData\Local\Temp
2015-02-04 01:23:43 -------- d-----w- C:\Users\PC i7\AppData\Roaming\AmberBerry
2015-02-04 00:25:43 -------- d-----w- C:\Users\PC i7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ProcessText Group
2015-02-02 21:11:37 -------- d-----w- C:\Users\PC i7\AppData\Roaming\Xilisoft Corporation
2015-02-02 21:10:49 -------- d-----w- C:\Users\PC i7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Xilisoft
====== C:\Users\PC i7 ======
2015-02-25 04:47:02 3E5710600931E322F62B0DAA598C0AA5 2248504 ----a-w- C:\Users\PC i7\Downloads\runscanner.exe
2015-02-22 11:29:05 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad Muncher
2015-02-22 11:29:04 -------- d-----w- C:\ProgramData\Ad Muncher
2015-02-22 11:28:09 EDD15222718345DEF9F12336BA2405D1 560760 ----a-w- C:\Users\PC i7\Downloads\AM-Install (1).exe
2015-02-16 23:34:56 -------- d-----w- C:\ProgramData\Sophos
2015-02-16 23:33:45 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2015-02-16 21:56:57 3BD59D6C407AB1F6DDD7C5D9BD727469 20447072 ----a-w- C:\Users\PC i7\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-04 00:25:43 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProcessText Group
2015-02-02 20:55:19 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVI MPEG RM WMV Splitter
2015-02-02 20:52:59 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boilsoft
2015-02-02 20:48:36 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speed Video Splitter
2015-02-02 20:42:37 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ultra Video Splitter
2015-02-02 15:08:06 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-02-02 15:06:09 -------- d-----w- C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
====== C: exe-files ==
2015-02-26 07:00:15 875423375660681EBEA1781EDA926AD2 16896 ----a-w- C:\Users\PC i7\AppData\Local\Temp\SBLCopyF.EXE
2015-02-25 04:47:02 3E5710600931E322F62B0DAA598C0AA5 2248504 ----a-w- C:\Users\PC i7\Downloads\runscanner.exe
2015-02-24 14:50:28 DF085A41E6CC782F9A50377776207D25 552056 ----a-w- C:\Program Files\Opera\27.0.1689.76\opera_crashreporter.exe
2015-02-24 14:50:28 CA887EFE4E19350205CCE381F68AFD86 2152056 ----a-w- C:\Program Files\Opera\27.0.1689.76\opera_autoupdate.exe
2015-02-24 14:50:28 5D165F4948BD6B8D8663FD6106B53A1D 51366008 ----a-w- C:\Program Files\Opera\27.0.1689.76\opera.exe
2015-02-24 14:50:28 150090FB932CC14ADEECCA3AB742B110 73336 ----a-w- C:\Program Files\Opera\27.0.1689.76\wow_helper.exe
2015-02-24 14:50:27 0DC4C0CF8A0545D1BB53DF8361CEA2CA 1284728 ----a-w- C:\Program Files\Opera\27.0.1689.76\installer.exe
2015-02-22 11:29:05 378BFB8DD2AB90552356732852E710BE 11384 ----a-w- C:\Program Files\Ad Muncher\AdMunch64.exe
2015-02-22 11:29:04 EDD15222718345DEF9F12336BA2405D1 560760 ----a-w- C:\Program Files\Ad Muncher\AdMunch.exe
2015-02-22 11:28:09 EDD15222718345DEF9F12336BA2405D1 560760 ----a-w- C:\Users\PC i7\Downloads\AM-Install (1).exe
2015-02-22 11:27:11 EDD15222718345DEF9F12336BA2405D1 560760 ----a-w- C:\Users\PC i7\Downloads\برامج حماية\AM-Install.exe
2015-02-21 23:24:18 AF6E966D1F38287EF4D33B246CCC3A33 1388274 ----a-w- C:\Users\PC i7\Downloads\برامج حماية\أداة JunkWare Removal Tool\JRT.exe
2015-02-21 23:23:08 4DB5909D450AE68CC11DC865B9B84F71 2126848 ----a-w- C:\Users\PC i7\Downloads\برامج حماية\اداة Adware Cleaner\adwcleaner_4.111.exe
2015-02-21 23:20:51 3BD59D6C407AB1F6DDD7C5D9BD727469 20447072 ----a-w- C:\Users\PC i7\Downloads\ـ ماالوير باايتس\mbam-setup-2.0.4.1028.exe
2015-02-21 23:18:47 1B28807E950FB1B2F4C9AAD546D6568A 1943800 ----a-w- C:\Users\PC i7\Downloads\برامج حماية\أداة RKILL\rkill.exe
2015-02-21 08:53:30 0D79D8B50657CB61C8AF00F7F6DEAC3C 5107877 ----a-w- C:\Users\PC i7\Downloads\برامج حماية\Dll-Files Fixer\dffsetup.exe
2015-02-21 08:53:29 FAC08E03DFC8644C553C721165449926 49664 ----a-w- C:\Users\PC i7\Downloads\برامج حماية\Dll-Files Fixer\Medicina - Instrucciones\Dll-Files Fixer Keygen.exe
=== C: other files ==
2015-02-22 21:22:59 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\PC i7\AppData\Local\Temp\avastBCLTMP\ffxtlbr@alnaddytoolbar.com.zip
2015-02-22 21:22:59 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\PC i7\AppData\Local\Temp\avastBCLTMP\epbmnbdplhcomkedpjfceakddnbgfjmf.zip
2015-02-22 21:22:59 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\PC i7\AppData\Local\Temp\avastBCLTMP\afproxy@anchorfree.com.zip
2015-02-22 21:22:59 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\PC i7\AppData\Local\Temp\avastBCLTMP\afext@anchorfree.com.zip
2015-02-22 21:22:59 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\PC i7\AppData\Local\Temp\avastBCLTMP\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}.zip
2015-02-22 19:23:13 1F35F95CD2641B7D6259D1BAA4D7F162 103860 ----a-w- C:\Users\PC i7\Downloads\locke_arabic-955710.zip
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-21-3402252242-812742155-1843706100-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="C:\Users\PC i7\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED"
"iCloudServices"="C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe"
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:
/build:7601"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:
/build:7601"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"
"TkBellExe"="C:\Program Files\Real\RealPlayer\update\realsched.exe -osboot"
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"MSC"="C:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey"
"Ad Muncher"="C:\Program Files\Ad Muncher\AdMunch.exe /bt"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="C:\Users\PC i7\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED"
"iCloudServices"="C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe"
==== Startup Registry Disabled ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GrooveMonitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GrooveMonitor"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^PC i7^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
"path"="C:\\Users\\PC i7\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Dropbox.lnk"
"backup"="C:\\Windows\\pss\\Dropbox.lnk.Startup"
"backupExtension"=".Startup"
"command"="C:\\Users\\PCI7~1\\AppData\\Roaming\\Dropbox\\bin\\Dropbox.exe /systemstartup"
"item"="Dropbox"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run-]
"Google Update"="\"C:\\Users\\PC i7\\AppData\\Local\\Google\\Update\\GoogleUpdate.exe\" /c"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-]
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"Adobe ARM"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe\""
"DivXUpdate"="\"C:\\Program Files\\DivX\\DivX Update\\DivXUpdate.exe\" /CHECKNOW"
"TkBellExe"="\"C:\\Program Files\\Real\\RealPlayer\\update\\realsched.exe\" -osboot"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\QTTask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
==== Other Scheduled Tasks ======================
"C:\Windows\system32\tasks\Adobe online update program" [C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe]
"C:\Windows\system32\tasks\Apple Diagnostics" [C:\Program Files\Common Files\Apple\Internet Services\EReporter.exe]
"C:\Windows\system32\tasks\DivX online update program" [C:\Program Files\DivX\DivX Update\DivXUpdate.exe]
"C:\Windows\system32\tasks\Google Updater and Installer" [C:\Users\PC i7\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-3402252242-812742155-1843706100-1000Core" [C:\Users\PC i7\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-3402252242-812742155-1843706100-1000UA" [C:\Users\PC i7\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\HP online update program" [C:\Program Files\HP\HP Software Update\HPWuSchd2.exe]
"C:\Windows\system32\tasks\Java Update Scheduler" [C:\Program Files\Common Files\Java\Java Update\jusched.exe]
"C:\Windows\system32\tasks\Opera scheduled Autoupdate 1411512278" [C:\Program Files\Opera\launcher.exe]
"C:\Windows\system32\tasks\Real Player online update program" [C:\Program Files\Real\RealPlayer\update\realsched.exe]
"C:\Windows\system32\tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-3402252242-812742155-1843706100-1000" [C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe]
"C:\Windows\system32\tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3402252242-812742155-1843706100-1000" [C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe]
"C:\Windows\system32\tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3402252242-812742155-1843706100-1000" [C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe]
"C:\Windows\system32\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3402252242-812742155-1843706100-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe]
"C:\Windows\system32\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3402252242-812742155-1843706100-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe]
"C:\Windows\system32\tasks\RealUpgradeLogonTaskS-1-5-21-3402252242-812742155-1843706100-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe]
"C:\Windows\system32\tasks\RealUpgradeScheduledTaskS-1-5-21-3402252242-812742155-1843706100-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe]
"C:\Windows\system32\tasks\SmartPCFixer Automatically Update" ["C:\Program Files\SmartPCFixer\update\update.EXE"]
"C:\Windows\system32\tasks\SmartPCFixer Scan Weekly" ["C:\Program Files\SmartPCFixer\SmartPCFixer.exe"]
"C:\Windows\system32\tasks\SmartPCFixer Startup" ["C:\Program Files\SmartPCFixer\SmartPCFixer.exe"]
"C:\Windows\system32\tasks\TuneUpUtilities_Task_BkGndMaintenance2013" [C:\Program Files\TuneUp Utilities 2014\OneClick.exe]
"C:\Windows\system32\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files\Apple Software Update\SoftwareUpdate.exe]
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [09/04/2013 09:31 PM]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"smartwebprinting@hp.com"="C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [05/17/2012 02:41 PM]
==== Firefox Extensions ======================
ProfilePath: C:\Users\PCI7~1\AppData\Roaming\Mozilla\Firefox\Profiles\o5ida13a.default
- Undetermined - C:\Users\PC i7\AppData\Roaming\Mozilla\Firefox\Profiles\o5ida13a.default\extensions\ffxtlbr@alnaddyToolbar.com
- 9b9d2aaaae264447a7a1633a32b19ddd - C:\Users\PC i7\AppData\Roaming\Mozilla\Firefox\Profiles\o5ida13a.default\extensions\{9b9d2aaa-ae26-4447-a7a1-633a32b19ddd}
- Undetermined - C:\Users\PC i7\AppData\Roaming\Mozilla\Firefox\Profiles\o5ida13a.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}
- Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- Undetermined - ffxtlbr@alnaddyToolbar.com
- Undetermined - {9b9d2aaa-ae26-4447-a7a1-633a32b19ddd}
- Undetermined - {113c6a96-cbc4-4248-bc8a-c05e9ec4b669}
- Undetermined - wrc@avast.com
- 9b9d2aaaae264447a7a1633a32b19ddd - %ProfilePath%\extensions\{9b9d2aaa-ae26-4447-a7a1-633a32b19ddd}
AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\PC i7\AppData\Roaming\Mozilla\Firefox\Profiles\o5ida13a.default
98137411B9C632095F919E2CE70B288A - C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll - Google Update
C62322C77D1AAB77B1CF1130FCC3673A - C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll - Shockwave Flash
0806948270D853B709CCBBF38AF167E4 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
9DF0C4F0CEF60158614EDD1B3AB441EE - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
559E8D42BE485208F1C4BB294D6840A4 - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 7.7.6
5D4279248A0E506CF007BD51EBF74CEA - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 7.7.6
F9DE379CE8A782530A4FA0B731F3A49B - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 7.7.6
049BD7AD3B94F24FA274ED1F7FC5871B - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 7.7.6
D937A4645EFF8CB4F123E3C899C052B2 - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 7.7.6
46A59E6F7F7C1679AC7C4655E055326D - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll - iTunes Application Detector
9419AA8A2799526EC32B473C2BB7A10D - C:\Program Files\Google\Picasa3\npPicasa3.dll - Picasa
0CA4180B21C6B728578F3B0433BB740E - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
893BF7D2261C56C24F813405D9D018E0 - C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll - Silverlight Plug-In
A3E631EA08C5137B682BC97BDF3EB114 - C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll - RIM Handheld Application Loader
3A9E1940B4459CC97FDCBB24FCB69004 - c:\program files\real\realplayer\Netscape6\nppl3260.dll - RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)
0FCEAA7D12B7B0BA825E5C770B1DCA48 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll - RealPlayer Download Plugin
5B92CB0A3EEE50F6B9AE036B4F9B0F0C - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin
BE126CB7049E89ED6F3038016668B502 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll - RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit)
EAC427FEF96A13058C1ACD17C38966CF - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll - RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit)
96B3689320E9B16EDF38B7A5001C35F0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll - RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit)
F8CB60A5ACA5D73807ECBD9942A8BCB7 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll - RealDownloader Plugin
ABCB4A6EAB701C629378255ABCB308E5 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U25
D7324EB1EDCB8990F8522DE0311359E9 - C:\Windows\system32\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.17
D49FBD712961D2FED3D4D529EBF597F8 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll - DivX Plus Web Player
10737B44923217BC0E67D26A9FC1F0AA - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll - RealNetworks(tm) Chrome Background Extension Plug-In (32-bit)
2645990C521342DCD08963D2DF6CD0D2 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll - RealPlayer(tm) HTML5VideoShim Plug-In (32-bit)
B938C1AE3ADCE166190895685B0BEB0D - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll - DivX VOD Helper Plug-in
8DA2ED6B04EA33F2EAE8BA883F903729 - C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrlui.dll - Microsoft® Silverlight
15E298B5EC5B89C5994A59863969D9FF - C:\Windows\system32\npmproxy.dll - Microsoft® Windows® Operating System
==== Chromium Look ======================
Google Chrome Version: 40.0.2214.115 (Up to date, latest Stable version: 40.0.2214.115)
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[01/11/2015 10:44 AM]
idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[08/14/2013 03:24 PM]
nneajnkjbffgblleaoojgaacokifdkhm - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx[07/26/2013 05:31 PM]
Google Slides - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek
Google Docs - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
Ultimate YouTube Downloader - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfkpkealncpcbfklpgnggcgjjdkbljop
YouTube - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
cechdibmaolglcdioefoikpknppdekpc - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\cechdibmaolglcdioefoikpknppdekpc
selector is not a valid CSS selector - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb
Google Search - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Youtube Downloader Videos - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpmoghpffdalmegdmkfneekjeoagcjfg
Google Sheets - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap
Best Youtube Downloader - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\goacemjobhmmbdlbbfjgifjcojdfnjfm
Avast Online Security - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
RealDownloader - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji
Twoo Notifications - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\mggafhpkgkfebnjfbiefbbbicikgchlf
Video download helper - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnkioblodjcgkdailhejgcocjkkoochj
nhgpbmbhocboaalioananelcgfahjpai - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhgpbmbhocboaalioananelcgfahjpai
Google Wallet - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Ad Block Popup Block Facebook AdBlock Youtube AdBlock - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\oelbagajmdgpkkogcimdjjjhknpnbkom
Instagram for Chrome - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\opnbmdkdflhjiclaoiiifmheknpccalb
Gmail - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== IE Start and Search Settings ======================
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="
"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="
"
==== HijackThis Entries ======================
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Ad Muncher] "C:\Program Files\Ad Muncher\AdMunch.exe" /bt
O4 - HKCU\..\Run: [uTorrent] "C:\Users\PC i7\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"
" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"
" /build:7601 (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى FLV بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel® PROSet Monitoring Service - Intel Corporation - C:\Windows\system32\IProsetMonitor.exe
O23 - Service: خدمة iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
==== C:\zoek_backup content ======================
C:\zoek_backup (files=744 folders=223 297655933 bytes)
==== EOF on Fri 02/27/2015 at 7:51:54.98 ======================
ولكن المشكلة موجودة
Zoek.exe v5.0.0.0 Updated 26-February-2015
Tool run by PC i7 on Fri 02/27/2015 at 7:45:06.22.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\PC i7\Downloads\برامج حماية\أداة Zoek\zoek.exe [Scan all users] [Deep Scan]
==== Older Logs ======================
C:\zoek-results2015-02-22-085816.log 100353 bytes
C:\zoek-results2015-02-26-184917.log 415 bytes
==== Running Processes ======================
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\IProsetMonitor.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
C:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\vssvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\SmartPCFixer\SmartPCFixer.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Ad Muncher\AdMunch.exe
C:\Users\PC i7\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\PC i7\Downloads\برامج حماية\أداة Zoek\zoek.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k swprv
==== System Specs ======================
Windows: Windows 7 Ultimate Edition Service Pack 1 (Build 7601)
Memory (RAM): 3570 MB
CPU Info: Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz
CPU Speed: 3462.7 MHz
Sound Card: سماعات (Realtek High Definition |
Realtek Digital Output (Realtek |
Realtek Digital Output(Optical) |
Display Adapters: ATI Radeon HD 5450 | ATI Radeon HD 5450 | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver
Monitors: 1x; Generic PnP Monitor |
Screen Resolution: 1440 X 900 - 32 bit
Network: Network Present
Network Adapters: Anchorfree HSS VPN Adapter #2 | Anchorfree HSS VPN Adapter | 802.11 USB Wireless LAN Card | Intel(R) 82579V Gigabit Network Connection
CD / DVD Drives: 2x (D: | L: | ) D: ATAPI iHAS324 B | L: EZBSYS ISO CDVD DRIVE
Ports: COM8 | COM9 LPT Port NOT Present.
Mouse: 5 Button Wheel Mouse Present
Hard Disks: C: 195.2GB | E: 376.0GB | F: 360.2GB | I: 2794.5GB
Hard Disks - Free: C: 77.9GB | E: 256.2GB | F: 204.0GB | I: 1314.6GB
Manufacturer *: Intel Corp.
BIOS Info: AT/AT COMPATIBLE | 12/22/11 | HPQOEM - 1072009
Time Zone: السعودية - التوقيت الرسمي
Motherboard *: Intel Corporation DH67CL
Country: ںéêêéè، ںéم© ï، ںé«مي§ï،
Language: ARA
==== System Specs (Software) ======================
Anti-Virus: Microsoft Security Essentials On-access scanning disabled (Outdated)
Anti-Virus: avast! Antivirus On-access scanning disabled (Outdated)
Anti-Spyware: Microsoft Security Essentials disabled (Outdated)
Anti-Spyware: Windows Defender disabled (Outdated)
Anti-Spyware: avast! Antivirus disabled (Outdated)
Default Browser: Google Chrome 40.0.2214.115
Internet Explorer Version: 11.0.9600.17633
Mozilla Firefox version: 31.0 (x86 ar)
Opera Browser version: 27.0.1689.76
Google Chrome version: 40.0.2214.115
Adobe Reader version: 11.0.10.32
Sun Java version: 1.7.0_25 (32-bit)
Flash Player version: 16.0.0.305
==== Files Recently Created / Modified ======================
====== C:\Windows ====
====== C:\Users\PCI7~1\AppData\Local\Temp ====
2015-02-26 07:00:15 875423375660681EBEA1781EDA926AD2 16896 ----a-w- C:\Users\PC i7\AppData\Local\Temp\SBLCopyF.EXE
====== Java Cache =====
====== C:\Windows\system32 =====
====== C:\Windows\system32\drivers =====
2015-02-11 09:18:40 F516F1167EFBBC5ABC90687C94497869 369968 ----a-w- C:\Windows\System32\drivers\cng.sys
2015-02-11 09:18:40 EF88BAC2B489D9C46F4E41ACF0219CD0 67520 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2015-02-11 09:18:40 49D70660EE8266988C1F99A0297A1430 136640 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
2015-02-22 11:29:04 -------- d-----w- C:\Program Files\Ad Muncher
2015-02-16 23:33:31 -------- d-----w- C:\Program Files\Sophos
2015-02-04 00:32:09 -------- d-----w- C:\Program Files\ABC Amber BlackBerry Converter
2015-02-04 00:25:35 -------- d-----w- C:\Program Files\ABC Amber PDF Converter
2015-02-02 20:55:17 -------- d-----w- C:\Program Files\AVI MPEG RM WMV Splitter
2015-02-02 20:52:39 -------- d-----w- C:\Program Files\Boilsoft Video Splitter
2015-02-02 20:48:28 -------- d-----w- C:\Program Files\Speed Video Splitter
2015-02-02 20:42:29 -------- d-----w- C:\Program Files\Ultra Video Splitter
======= C: =====
====== C:\Users\PC i7\AppData\Roaming ======
2015-02-25 04:47:58 -------- d-----w- C:\Users\PC i7\AppData\Roaming\Runscanner.net
2015-02-22 07:53:22 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Local\temp
2015-02-22 07:53:22 -------- d-----w- C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp
2015-02-22 07:53:22 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp
2015-02-22 07:53:22 -------- d-----w- C:\Users\fbwuserA8AC\AppData\Local\Temp
2015-02-22 07:53:22 -------- d-----w- C:\Users\fbwuser69FA\AppData\Local\Temp
2015-02-22 07:53:21 -------- d-----w- C:\Users\PC i7\AppData\Local\Temp
2015-02-22 07:53:21 -------- d-----w- C:\Users\fbwuser6463\AppData\Local\Temp
2015-02-22 07:53:21 -------- d-----w- C:\Users\Default\AppData\Local\Temp
2015-02-22 07:53:21 -------- d-----w- C:\Users\Default User\AppData\Local\Temp
2015-02-04 01:23:43 -------- d-----w- C:\Users\PC i7\AppData\Roaming\AmberBerry
2015-02-04 00:25:43 -------- d-----w- C:\Users\PC i7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ProcessText Group
2015-02-02 21:11:37 -------- d-----w- C:\Users\PC i7\AppData\Roaming\Xilisoft Corporation
2015-02-02 21:10:49 -------- d-----w- C:\Users\PC i7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Xilisoft
====== C:\Users\PC i7 ======
2015-02-25 04:47:02 3E5710600931E322F62B0DAA598C0AA5 2248504 ----a-w- C:\Users\PC i7\Downloads\runscanner.exe
2015-02-22 11:29:05 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad Muncher
2015-02-22 11:29:04 -------- d-----w- C:\ProgramData\Ad Muncher
2015-02-22 11:28:09 EDD15222718345DEF9F12336BA2405D1 560760 ----a-w- C:\Users\PC i7\Downloads\AM-Install (1).exe
2015-02-16 23:34:56 -------- d-----w- C:\ProgramData\Sophos
2015-02-16 23:33:45 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2015-02-16 21:56:57 3BD59D6C407AB1F6DDD7C5D9BD727469 20447072 ----a-w- C:\Users\PC i7\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-04 00:25:43 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProcessText Group
2015-02-02 20:55:19 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVI MPEG RM WMV Splitter
2015-02-02 20:52:59 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boilsoft
2015-02-02 20:48:36 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speed Video Splitter
2015-02-02 20:42:37 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ultra Video Splitter
2015-02-02 15:08:06 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-02-02 15:06:09 -------- d-----w- C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
====== C: exe-files ==
2015-02-26 07:00:15 875423375660681EBEA1781EDA926AD2 16896 ----a-w- C:\Users\PC i7\AppData\Local\Temp\SBLCopyF.EXE
2015-02-25 04:47:02 3E5710600931E322F62B0DAA598C0AA5 2248504 ----a-w- C:\Users\PC i7\Downloads\runscanner.exe
2015-02-24 14:50:28 DF085A41E6CC782F9A50377776207D25 552056 ----a-w- C:\Program Files\Opera\27.0.1689.76\opera_crashreporter.exe
2015-02-24 14:50:28 CA887EFE4E19350205CCE381F68AFD86 2152056 ----a-w- C:\Program Files\Opera\27.0.1689.76\opera_autoupdate.exe
2015-02-24 14:50:28 5D165F4948BD6B8D8663FD6106B53A1D 51366008 ----a-w- C:\Program Files\Opera\27.0.1689.76\opera.exe
2015-02-24 14:50:28 150090FB932CC14ADEECCA3AB742B110 73336 ----a-w- C:\Program Files\Opera\27.0.1689.76\wow_helper.exe
2015-02-24 14:50:27 0DC4C0CF8A0545D1BB53DF8361CEA2CA 1284728 ----a-w- C:\Program Files\Opera\27.0.1689.76\installer.exe
2015-02-22 11:29:05 378BFB8DD2AB90552356732852E710BE 11384 ----a-w- C:\Program Files\Ad Muncher\AdMunch64.exe
2015-02-22 11:29:04 EDD15222718345DEF9F12336BA2405D1 560760 ----a-w- C:\Program Files\Ad Muncher\AdMunch.exe
2015-02-22 11:28:09 EDD15222718345DEF9F12336BA2405D1 560760 ----a-w- C:\Users\PC i7\Downloads\AM-Install (1).exe
2015-02-22 11:27:11 EDD15222718345DEF9F12336BA2405D1 560760 ----a-w- C:\Users\PC i7\Downloads\برامج حماية\AM-Install.exe
2015-02-21 23:24:18 AF6E966D1F38287EF4D33B246CCC3A33 1388274 ----a-w- C:\Users\PC i7\Downloads\برامج حماية\أداة JunkWare Removal Tool\JRT.exe
2015-02-21 23:23:08 4DB5909D450AE68CC11DC865B9B84F71 2126848 ----a-w- C:\Users\PC i7\Downloads\برامج حماية\اداة Adware Cleaner\adwcleaner_4.111.exe
2015-02-21 23:20:51 3BD59D6C407AB1F6DDD7C5D9BD727469 20447072 ----a-w- C:\Users\PC i7\Downloads\ـ ماالوير باايتس\mbam-setup-2.0.4.1028.exe
2015-02-21 23:18:47 1B28807E950FB1B2F4C9AAD546D6568A 1943800 ----a-w- C:\Users\PC i7\Downloads\برامج حماية\أداة RKILL\rkill.exe
2015-02-21 08:53:30 0D79D8B50657CB61C8AF00F7F6DEAC3C 5107877 ----a-w- C:\Users\PC i7\Downloads\برامج حماية\Dll-Files Fixer\dffsetup.exe
2015-02-21 08:53:29 FAC08E03DFC8644C553C721165449926 49664 ----a-w- C:\Users\PC i7\Downloads\برامج حماية\Dll-Files Fixer\Medicina - Instrucciones\Dll-Files Fixer Keygen.exe
=== C: other files ==
2015-02-22 21:22:59 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\PC i7\AppData\Local\Temp\avastBCLTMP\ffxtlbr@alnaddytoolbar.com.zip
2015-02-22 21:22:59 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\PC i7\AppData\Local\Temp\avastBCLTMP\epbmnbdplhcomkedpjfceakddnbgfjmf.zip
2015-02-22 21:22:59 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\PC i7\AppData\Local\Temp\avastBCLTMP\afproxy@anchorfree.com.zip
2015-02-22 21:22:59 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\PC i7\AppData\Local\Temp\avastBCLTMP\afext@anchorfree.com.zip
2015-02-22 21:22:59 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\PC i7\AppData\Local\Temp\avastBCLTMP\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}.zip
2015-02-22 19:23:13 1F35F95CD2641B7D6259D1BAA4D7F162 103860 ----a-w- C:\Users\PC i7\Downloads\locke_arabic-955710.zip
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-21-3402252242-812742155-1843706100-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="C:\Users\PC i7\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED"
"iCloudServices"="C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe"
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"
"TkBellExe"="C:\Program Files\Real\RealPlayer\update\realsched.exe -osboot"
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"MSC"="C:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey"
"Ad Muncher"="C:\Program Files\Ad Muncher\AdMunch.exe /bt"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="C:\Users\PC i7\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED"
"iCloudServices"="C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe"
==== Startup Registry Disabled ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GrooveMonitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GrooveMonitor"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^PC i7^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
"path"="C:\\Users\\PC i7\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Dropbox.lnk"
"backup"="C:\\Windows\\pss\\Dropbox.lnk.Startup"
"backupExtension"=".Startup"
"command"="C:\\Users\\PCI7~1\\AppData\\Roaming\\Dropbox\\bin\\Dropbox.exe /systemstartup"
"item"="Dropbox"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run-]
"Google Update"="\"C:\\Users\\PC i7\\AppData\\Local\\Google\\Update\\GoogleUpdate.exe\" /c"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-]
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"Adobe ARM"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe\""
"DivXUpdate"="\"C:\\Program Files\\DivX\\DivX Update\\DivXUpdate.exe\" /CHECKNOW"
"TkBellExe"="\"C:\\Program Files\\Real\\RealPlayer\\update\\realsched.exe\" -osboot"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\QTTask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
==== Other Scheduled Tasks ======================
"C:\Windows\system32\tasks\Adobe online update program" [C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe]
"C:\Windows\system32\tasks\Apple Diagnostics" [C:\Program Files\Common Files\Apple\Internet Services\EReporter.exe]
"C:\Windows\system32\tasks\DivX online update program" [C:\Program Files\DivX\DivX Update\DivXUpdate.exe]
"C:\Windows\system32\tasks\Google Updater and Installer" [C:\Users\PC i7\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-3402252242-812742155-1843706100-1000Core" [C:\Users\PC i7\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-3402252242-812742155-1843706100-1000UA" [C:\Users\PC i7\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\HP online update program" [C:\Program Files\HP\HP Software Update\HPWuSchd2.exe]
"C:\Windows\system32\tasks\Java Update Scheduler" [C:\Program Files\Common Files\Java\Java Update\jusched.exe]
"C:\Windows\system32\tasks\Opera scheduled Autoupdate 1411512278" [C:\Program Files\Opera\launcher.exe]
"C:\Windows\system32\tasks\Real Player online update program" [C:\Program Files\Real\RealPlayer\update\realsched.exe]
"C:\Windows\system32\tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-3402252242-812742155-1843706100-1000" [C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe]
"C:\Windows\system32\tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3402252242-812742155-1843706100-1000" [C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe]
"C:\Windows\system32\tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3402252242-812742155-1843706100-1000" [C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe]
"C:\Windows\system32\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3402252242-812742155-1843706100-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe]
"C:\Windows\system32\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3402252242-812742155-1843706100-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe]
"C:\Windows\system32\tasks\RealUpgradeLogonTaskS-1-5-21-3402252242-812742155-1843706100-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe]
"C:\Windows\system32\tasks\RealUpgradeScheduledTaskS-1-5-21-3402252242-812742155-1843706100-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe]
"C:\Windows\system32\tasks\SmartPCFixer Automatically Update" ["C:\Program Files\SmartPCFixer\update\update.EXE"]
"C:\Windows\system32\tasks\SmartPCFixer Scan Weekly" ["C:\Program Files\SmartPCFixer\SmartPCFixer.exe"]
"C:\Windows\system32\tasks\SmartPCFixer Startup" ["C:\Program Files\SmartPCFixer\SmartPCFixer.exe"]
"C:\Windows\system32\tasks\TuneUpUtilities_Task_BkGndMaintenance2013" [C:\Program Files\TuneUp Utilities 2014\OneClick.exe]
"C:\Windows\system32\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files\Apple Software Update\SoftwareUpdate.exe]
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [09/04/2013 09:31 PM]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"smartwebprinting@hp.com"="C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [05/17/2012 02:41 PM]
==== Firefox Extensions ======================
ProfilePath: C:\Users\PCI7~1\AppData\Roaming\Mozilla\Firefox\Profiles\o5ida13a.default
- Undetermined - C:\Users\PC i7\AppData\Roaming\Mozilla\Firefox\Profiles\o5ida13a.default\extensions\ffxtlbr@alnaddyToolbar.com
- 9b9d2aaaae264447a7a1633a32b19ddd - C:\Users\PC i7\AppData\Roaming\Mozilla\Firefox\Profiles\o5ida13a.default\extensions\{9b9d2aaa-ae26-4447-a7a1-633a32b19ddd}
- Undetermined - C:\Users\PC i7\AppData\Roaming\Mozilla\Firefox\Profiles\o5ida13a.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}
- Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- Undetermined - ffxtlbr@alnaddyToolbar.com
- Undetermined - {9b9d2aaa-ae26-4447-a7a1-633a32b19ddd}
- Undetermined - {113c6a96-cbc4-4248-bc8a-c05e9ec4b669}
- Undetermined - wrc@avast.com
- 9b9d2aaaae264447a7a1633a32b19ddd - %ProfilePath%\extensions\{9b9d2aaa-ae26-4447-a7a1-633a32b19ddd}
AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\PC i7\AppData\Roaming\Mozilla\Firefox\Profiles\o5ida13a.default
98137411B9C632095F919E2CE70B288A - C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll - Google Update
C62322C77D1AAB77B1CF1130FCC3673A - C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll - Shockwave Flash
0806948270D853B709CCBBF38AF167E4 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
9DF0C4F0CEF60158614EDD1B3AB441EE - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
559E8D42BE485208F1C4BB294D6840A4 - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 7.7.6
5D4279248A0E506CF007BD51EBF74CEA - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 7.7.6
F9DE379CE8A782530A4FA0B731F3A49B - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 7.7.6
049BD7AD3B94F24FA274ED1F7FC5871B - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 7.7.6
D937A4645EFF8CB4F123E3C899C052B2 - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 7.7.6
46A59E6F7F7C1679AC7C4655E055326D - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll - iTunes Application Detector
9419AA8A2799526EC32B473C2BB7A10D - C:\Program Files\Google\Picasa3\npPicasa3.dll - Picasa
0CA4180B21C6B728578F3B0433BB740E - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
893BF7D2261C56C24F813405D9D018E0 - C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll - Silverlight Plug-In
A3E631EA08C5137B682BC97BDF3EB114 - C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll - RIM Handheld Application Loader
3A9E1940B4459CC97FDCBB24FCB69004 - c:\program files\real\realplayer\Netscape6\nppl3260.dll - RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)
0FCEAA7D12B7B0BA825E5C770B1DCA48 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll - RealPlayer Download Plugin
5B92CB0A3EEE50F6B9AE036B4F9B0F0C - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin
BE126CB7049E89ED6F3038016668B502 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll - RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit)
EAC427FEF96A13058C1ACD17C38966CF - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll - RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit)
96B3689320E9B16EDF38B7A5001C35F0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll - RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit)
F8CB60A5ACA5D73807ECBD9942A8BCB7 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll - RealDownloader Plugin
ABCB4A6EAB701C629378255ABCB308E5 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U25
D7324EB1EDCB8990F8522DE0311359E9 - C:\Windows\system32\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.17
D49FBD712961D2FED3D4D529EBF597F8 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll - DivX Plus Web Player
10737B44923217BC0E67D26A9FC1F0AA - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll - RealNetworks(tm) Chrome Background Extension Plug-In (32-bit)
2645990C521342DCD08963D2DF6CD0D2 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll - RealPlayer(tm) HTML5VideoShim Plug-In (32-bit)
B938C1AE3ADCE166190895685B0BEB0D - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll - DivX VOD Helper Plug-in
8DA2ED6B04EA33F2EAE8BA883F903729 - C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrlui.dll - Microsoft® Silverlight
15E298B5EC5B89C5994A59863969D9FF - C:\Windows\system32\npmproxy.dll - Microsoft® Windows® Operating System
==== Chromium Look ======================
Google Chrome Version: 40.0.2214.115 (Up to date, latest Stable version: 40.0.2214.115)
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[01/11/2015 10:44 AM]
idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[08/14/2013 03:24 PM]
nneajnkjbffgblleaoojgaacokifdkhm - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx[07/26/2013 05:31 PM]
Google Slides - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek
Google Docs - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
Ultimate YouTube Downloader - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfkpkealncpcbfklpgnggcgjjdkbljop
YouTube - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
cechdibmaolglcdioefoikpknppdekpc - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\cechdibmaolglcdioefoikpknppdekpc
selector is not a valid CSS selector - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb
Google Search - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Youtube Downloader Videos - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpmoghpffdalmegdmkfneekjeoagcjfg
Google Sheets - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap
Best Youtube Downloader - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\goacemjobhmmbdlbbfjgifjcojdfnjfm
Avast Online Security - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
RealDownloader - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji
Twoo Notifications - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\mggafhpkgkfebnjfbiefbbbicikgchlf
Video download helper - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnkioblodjcgkdailhejgcocjkkoochj
nhgpbmbhocboaalioananelcgfahjpai - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhgpbmbhocboaalioananelcgfahjpai
Google Wallet - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Ad Block Popup Block Facebook AdBlock Youtube AdBlock - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\oelbagajmdgpkkogcimdjjjhknpnbkom
Instagram for Chrome - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\opnbmdkdflhjiclaoiiifmheknpccalb
Gmail - PC i7\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== IE Start and Search Settings ======================
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
==== HijackThis Entries ======================
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Ad Muncher] "C:\Program Files\Ad Muncher\AdMunch.exe" /bt
O4 - HKCU\..\Run: [uTorrent] "C:\Users\PC i7\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"
يجب عليك تسجيل الدخول أو التسجيل لمشاهدة الرابط المخفي
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: تحميل الكل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى FLV بواسطة Internet Download Manager - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: بحث - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel® PROSet Monitoring Service - Intel Corporation - C:\Windows\system32\IProsetMonitor.exe
O23 - Service: خدمة iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
==== C:\zoek_backup content ======================
C:\zoek_backup (files=744 folders=223 297655933 bytes)
==== EOF on Fri 02/27/2015 at 7:51:54.98 ======================
ولكن المشكلة موجودة
