Additional scan result of Farbar Recovery Scan Tool (x86) Version: 31-08-2016 Ran by windows (05-09-2016 21:18:58) Running from C:\Users\windows\Desktop Microsoft Windows 7 Ultimate Service Pack 1 (X86) (2016-02-14 11:27:18) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2744508499-2295875598-203414080-500 - Administrator - Disabled) Guest (S-1-5-21-2744508499-2295875598-203414080-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2744508499-2295875598-203414080-1002 - Limited - Enabled) windows (S-1-5-21-2744508499-2295875598-203414080-1000 - Administrator - Enabled) => C:\Users\windows ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: ESET Smart Security 9.0.375.1 (Disabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: ESET Smart Security 9.0.381.2 (Disabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834} FW: جدار الحماية الشخصي ESET (Disabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adblock Plus for IE (32-bit) (HKLM\...\{531F59C9-1C93-49B9-82D1-433761DB529C}) (Version: 1.5 - Eyeo GmbH) Adobe AIR (HKLM\...\Adobe AIR) (Version: 22.0.0.153 - Adobe Systems Incorporated) Adobe Flash Player 22 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 22.0.0.210 - Adobe Systems Incorporated) Adobe Flash Player 22 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated) Adobe Flash Player 22 PPAPI (HKLM\...\Adobe Flash Player PPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated) Adobe Shockwave Player 12.2 (HKLM\...\Adobe Shockwave Player) (Version: 12.2.4.194 - Adobe Systems, Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.21 - Piriform) ESET Smart Security (HKLM\...\{D3C4D87C-C7B1-4FA0-AF83-1ECC324684B1}) (Version: 9.0.375.1 - ESET, spol. s r.o.) f.lux (HKU\S-1-5-21-2744508499-2295875598-203414080-1000\...\Flux) (Version: - ) FastStone Capture 8.3 (HKLM\...\FastStone Capture) (Version: 8.3 - FastStone Soft) Foxit Reader (HKLM\...\Foxit Reader_is1) (Version: 5.4.4.1128 - Foxit Corporation) Google Chrome (HKLM\...\{14A4D1AE-4FA6-3F79-8BA3-AA3691641810}) (Version: 52.0.2743.116 - Google, Inc.) Google Earth (HKLM\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google) Google Talk Plugin (HKLM\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google) Google Update Helper (Version: 1.3.31.5 - Google Inc.) Hidden Intel Security True Key (HKLM\...\TrueKey) (Version: 4.6.129.1 - Intel Security) Internet Download Manager (HKLM\...\Internet Download Manager) (Version: - Tonec Inc.) Malwarebytes Anti-Malware النسخة 2.2.1.1043 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Maxthon Cloud Browser (HKLM\...\Maxthon3) (Version: 4.9.3.1000 - Maxthon International Limited) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.376.2 - McAfee, Inc.) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Mozilla Firefox 48.0.2 (x86 ar) (HKLM\...\Mozilla Firefox 48.0.2 (x86 ar)) (Version: 48.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 48.0.2.6079 - Mozilla) MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Opera Stable 39.0.2256.48 (HKLM\...\Opera 39.0.2256.48) (Version: 39.0.2256.48 - Opera Software) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden The KMPlayer (remove only) (HKLM\...\The KMPlayer) (Version: 3.9.0.124 - PandoraTV) UltraISO Premium V9.61 (HKLM\...\UltraISO_is1) (Version: - ) USB Disk Security (HKLM\...\USB Disk Security_is1) (Version: - ) Vista Shortcut Manager (HKLM\...\{47609E69-4C5E-48B1-A889-24C6B82B5C04}) (Version: 2.0 - Frameworkx) WinRAR archiver (HKLM\...\WinRAR archiver) (Version: - ) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2744508499-2295875598-203414080-1000_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Users\windows\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2744508499-2295875598-203414080-1000_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Users\windows\AppData\Local\Google\Update\1.3.31.5\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2744508499-2295875598-203414080-1000_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Users\windows\AppData\Local\Google\Update\1.3.31.5\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2744508499-2295875598-203414080-1000_Classes\CLSID\{39125640-8D80-11DC-A2FE-C5C455D89593}\InprocServer32 -> C:\Users\windows\AppData\Local\Google\Google Talk Plugin\googletalkax.dll (Google) CustomCLSID: HKU\S-1-5-21-2744508499-2295875598-203414080-1000_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Users\windows\AppData\Local\Google\Update\1.3.31.5\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2744508499-2295875598-203414080-1000_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\windows\AppData\Local\Google\Update\1.3.31.5\psuser.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-2744508499-2295875598-203414080-1000_Classes\CLSID\{AB9F4455-E591-4132-A386-0B91EAEDB96C}\InprocServer32 -> C:\Users\windows\AppData\Local\Google\Google Talk Plugin\o1dax.dll (Google) CustomCLSID: HKU\S-1-5-21-2744508499-2295875598-203414080-1000_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Users\windows\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-2744508499-2295875598-203414080-1000_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Users\windows\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-2744508499-2295875598-203414080-1000_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Users\windows\AppData\Local\Google\Update\1.3.31.5\GoogleUpdateOnDemand.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-2744508499-2295875598-203414080-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\windows\AppData\Local\Google\Update\1.3.31.5\psuser.dll (Google Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {18DCF796-2C42-45DC-9F58-1043F9ED025E} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\system32\Macromed\Flash\FlashUtil32_22_0_0_209_pepper.exe [2016-07-12] (Adobe Systems Incorporated) Task: {25A4873E-7C13-4CCD-B4C4-66556E5FFAE0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-08-25] (Adobe Systems Incorporated) Task: {26DF9417-9A7B-4A18-80F0-200AFF40FE5E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2744508499-2295875598-203414080-1000Core => C:\Users\windows\AppData\Local\Google\Update\GoogleUpdate.exe [2016-02-14] (Google Inc.) Task: {8207110F-6409-4699-A92F-B3A6B579EF3A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2016-04-24] (Google Inc.) Task: {9587A747-5902-4C3D-BC01-2333DD4A2531} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2016-03-01] (McAfee, Inc.) Task: {968A3B82-964D-4999-9010-C61F66A12729} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-08-05] (Piriform Ltd) Task: {9926462E-5306-4D68-8CA7-3CE641B746D4} - System32\Tasks\Opera scheduled Autoupdate 1458161281 => C:\Program Files\Opera developer\launcher.exe Task: {C30B35F9-2D1E-4D2D-A78A-CA55B513E912} - System32\Tasks\Opera scheduled Autoupdate 1461850227 => C:\Program Files\Opera\launcher.exe [2016-08-03] (Opera Software) Task: {DA454E4A-34C3-424F-B487-1DF0E9D1521E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2016-04-24] (Google Inc.) Task: {DB946DA6-8562-42A6-B0FC-63AAB5A02A26} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2744508499-2295875598-203414080-1000UA => C:\Users\windows\AppData\Local\Google\Update\GoogleUpdate.exe [2016-02-14] (Google Inc.) Task: {DD4268F8-1795-4E54-8A0B-22FF820B4C21} - System32\Tasks\Maxthon Update => C:\Program Files\Maxthon\Bin\MxEidolon.exe [2016-06-12] (Maxthon MxEidolo) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\system32\Macromed\Flash\FlashUtil32_22_0_0_209_pepper.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2744508499-2295875598-203414080-1000Core.job => C:\Users\windows\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2744508499-2295875598-203414080-1000UA.job => C:\Users\windows\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2016-02-14 13:47 - 2004-09-08 19:51 - 00121344 _____ () C:\Program Files\WinRAR\rarext.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\E617A003.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\E617A003.sys => ""="Driver" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2016-09-04 13:28 - 00000862 ____A C:\Windows\system32\Drivers\etc\hosts 0.0.0.1 mssplus.mcafee.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2744508499-2295875598-203414080-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\windows\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp DNS Servers: 8.8.8.8 - 8.8.4.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{C96B1191-47D6-4DF3-A1D5-34DA35AFE16C}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{00163C0A-E027-498C-9BAC-58B984C0C52D}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{29E930E1-1BB4-4622-9A29-5784B50E7D5E}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe FirewallRules: [{500D7495-65D1-4FA0-944A-3554796AA39E}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [{02AEFC17-48D8-431F-8938-1787AACCC2B4}] => (Allow) C:\Program Files\Maxthon\Bin\MxUp.exe FirewallRules: [{842A0283-7EF3-4152-BD9A-421877A1360D}] => (Allow) C:\Program Files\Maxthon\Bin\Maxthon.exe FirewallRules: [{D56158A4-9652-4237-ADD6-D4BF8E99DEDD}] => (Allow) C:\Program Files\Maxthon\Bin\MxUp.exe FirewallRules: [{1116315D-259B-40B9-B7F9-3A107270B01B}] => (Allow) C:\Program Files\Maxthon\Bin\Maxthon.exe ==================== Restore Points ========================= 25-08-2016 14:56:26 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 02-09-2016 04:09:30 نقطة التدقيق المجدولة 02-09-2016 14:46:41 مثبت الوحدات النمطية لـ Windows 02-09-2016 14:49:34 مثبت الوحدات النمطية لـ Windows 02-09-2016 14:50:56 مثبت الوحدات النمطية لـ Windows ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (09/05/2016 09:06:21 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (09/05/2016 03:44:31 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (09/05/2016 12:46:09 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. System errors: ============= Error: (09/05/2016 09:10:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: ‏‏فشل بدء تشغيل الخدمة خدمة Google Update (gupdate) بسبب الخطأ التالي: ‏‏لم تستجب الخدمة لبدء التشغيل أو لطلب عنصر التحكم في الوقت المناسب. Error: (09/05/2016 09:10:03 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: ‏‏تم الوصول إلى نهاية المهلة (30000 مللي ثانية) أثناء انتظار اتصال الخدمة خدمة Google Update (gupdate). Error: (09/05/2016 09:08:49 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: ‏‏لم يتم بدء تشغيل الخدمة 'WMPNetworkSvc' بشكلٍ صحيح لأن CoCreateInstance(CLSID_UPnPDeviceFinder)‎ واجه الخطأ '0x80004005'. تحقق من تشغيل خدمة UPnPHost ومن تثبيت مكون UPnPHost لـ Windows بشكلٍ صحيح. Error: (09/05/2016 09:07:06 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: ‏‏تم تعليق الخدمة Intel(R) Biometric and Context Agent Service عند بدء التشغيل. Error: (09/05/2016 09:06:11 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: ‏‏تم الوصول إلى نهاية المهلة (30000 مللي ثانية) أثناء انتظار استجابة معاملة من الخدمة MBAMService. Error: (09/05/2016 03:48:06 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: ‏‏فشل بدء تشغيل الخدمة خدمة Google Update (gupdate) بسبب الخطأ التالي: ‏‏لم تستجب الخدمة لبدء التشغيل أو لطلب عنصر التحكم في الوقت المناسب. Error: (09/05/2016 03:48:06 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: ‏‏تم الوصول إلى نهاية المهلة (30000 مللي ثانية) أثناء انتظار اتصال الخدمة خدمة Google Update (gupdate). Error: (09/05/2016 03:46:37 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: ‏‏فشل بدء تشغيل الخدمة Windows Media Player Network Sharing Service بسبب الخطأ التالي: ‏‏لم تستجب الخدمة لبدء التشغيل أو لطلب عنصر التحكم في الوقت المناسب. Error: (09/05/2016 03:46:37 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: ‏‏تم الوصول إلى نهاية المهلة (30000 مللي ثانية) أثناء انتظار اتصال الخدمة Windows Media Player Network Sharing Service. Error: (09/05/2016 03:45:10 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: ‏‏تم تعليق الخدمة Intel(R) Biometric and Context Agent Service عند بدء التشغيل. ==================== Memory info =========================== Processor: Intel(R) Pentium(R) 4 CPU 3.40GHz Percentage of memory in use: 74% Total physical RAM: 2012.49 MB Available physical RAM: 519.76 MB Total Virtual: 4024.98 MB Available Virtual: 2291.11 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:107.32 GB) (Free:77.8 GB) NTFS Drive d: () (Fixed) (Total:95.33 GB) (Free:54.79 GB) NTFS Drive e: () (Fixed) (Total:95.33 GB) (Free:83.1 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 41B941B8) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=107.3 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=95.3 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=95.3 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================