cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-11-2017
Ran by salem (administrator) on ITTIHAD4EVER (12-11-2017 00:00:15)
Running from C:\Users\salem\Desktop
Loaded Profiles: salem (Available Profiles: salem)
Platform: Windows 8.1 (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET Smart Security Premium\ekrn.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Nitro PDF Software) C:\Program Files (x86)\Nitro\Pro 9\NitroPDFDriverService9x64.exe
() C:\Program Files (x86)\Nitro\Pro 9\Nitro_UpdateService.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(ESET) C:\Program Files\ESET\ESET Smart Security Premium\egui.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [6340312 2013-07-19] (Realtek semiconductor)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [903384 2013-07-24] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security Premium\ecmdS.exe [324216 2017-10-22] (ESET)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2152773553-1524527067-2441255551-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31682144 2015-03-25] (Skype Technologies S.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-05-30]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 212.56.129.228 212.56.132.20
Tcpip\..\Interfaces\{445DE83C-5A0B-4CF0-BC44-AA1A62D9035B}: [DhcpNameServer] 212.56.129.228 212.56.132.20
Tcpip\..\Interfaces\{4D4D0C1F-3036-42AD-AD3D-421C14CF2693}: [DhcpNameServer] 212.56.129.228 212.56.132.20

Internet Explorer:
==================
URLSearchHook: [S-1-5-21-2152773553-1524527067-2441255551-1001] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2152773553-1524527067-2441255551-1001 -> DefaultScope {224DA4F9-ECD3-4E3D-BCDD-B3C959C0ED72} URL =
SearchScopes: HKU\S-1-5-21-2152773553-1524527067-2441255551-1001 -> {224DA4F9-ECD3-4E3D-BCDD-B3C959C0ED72} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2017-09-12] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2017-08-24] (Microsoft Corporation)
BHO-x32: No Name -> {963C8283-AE7F-4AA6-9B3B-847A8FC62C5E} -> No File
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
Toolbar: HKLM - VIPRE Search Guard Toolbar - {A924C17A-5E94-4E02-BED5-49720BA6F7FA} - No File
Toolbar: HKLM-x32 - VIPRE Search Guard Toolbar - {A924C17A-5E94-4E02-BED5-49720BA6F7FA} - No File
Handler: vipresg - {47BE2E5B-703B-444F-ABD3-05717D2191C6} - No File

FireFox:
========
FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore => not found
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2014-08-01] (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-04] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-04] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-07-19] (Microsoft Corporation)

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default [2017-11-11]
CHR Extension: (Slides) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Docs) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Google Drive) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23]
CHR Extension: (YouTube) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-03]
CHR Extension: (TrafficLight) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfnpidifppmenkapgihekkeednfoenal [2017-09-19]
CHR Extension: (Google Search) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (uBlock Adblock Plus) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdecnmmdccnkogcidionikojplkjfgie [2017-10-22]
CHR Extension: (Sheets) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
CHR Extension: (Google Docs Offline) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (Genesis Plus adblocker) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\jacihiikpacjaggdldhcdfjpbibbfjmh [2017-09-13]
CHR Extension: (Perceptual Ad Highlighter) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\mahgiflleahghaapkboihnbhdplhnchp [2017-09-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-13]
CHR Extension: (Gmail) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
CHR Extension: (Chrome Media Router) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-28]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 BcmBtRSupport; C:\windows\system32\BtwRSupportService.exe [2252504 2013-08-07] (Broadcom Corporation.)
S4 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [976600 2013-09-05] (Broadcom Corporation.)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security Premium\ekrn.exe [2648184 2017-10-22] (ESET)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
S4 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed]
S4 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [272864 2015-12-10] (Lenovo)
R2 NitroDriverReadSpool9; C:\Program Files (x86)\Nitro\Pro 9\NitroPDFDriverService9x64.exe [230920 2014-08-01] (Nitro PDF Software)
R2 NitroUpdateService; C:\Program Files (x86)\Nitro\Pro 9\Nitro_UpdateService.exe [418312 2014-08-01] ()
S4 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
S4 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2014-05-30] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 bcbtums; C:\windows\system32\drivers\bcbtums.sys [186152 2016-09-14] (Broadcom Corporation.)
R3 BCM43XX; C:\windows\system32\DRIVERS\bcmwl63a.sys [7549616 2014-02-25] (Broadcom Corporation)
S3 dg_ssudbus; C:\windows\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R1 eamonm; C:\windows\System32\DRIVERS\eamonm.sys [132848 2017-10-22] (ESET)
R0 edevmon; C:\windows\System32\DRIVERS\edevmon.sys [107344 2017-05-04] (ESET)
S0 eelam; C:\windows\System32\DRIVERS\eelam.sys [15392 2017-10-22] (ESET)
R1 ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [180088 2017-10-22] (ESET)
R2 ekbdflt; C:\windows\system32\DRIVERS\ekbdflt.sys [50752 2017-05-04] (ESET)
R1 epfw; C:\windows\system32\DRIVERS\epfw.sys [78192 2017-05-04] (ESET)
R1 epfwwfp; C:\windows\system32\DRIVERS\epfwwfp.sys [102160 2017-10-22] (ESET)
S3 ESETCleanersDriver; C:\windows\system32\Drivers\ESETCleanersDriver.sys [170280 2015-10-31] (ESET)
R3 MEIx64; C:\windows\system32\DRIVERS\TeeDriverx64.sys [118272 2014-04-03] (Intel Corporation)
S3 NETwNe64; C:\windows\system32\DRIVERS\NETwew00.sys [3344352 2013-07-08] (Intel Corporation)
R3 rtsuvc; C:\windows\system32\DRIVERS\rtsuvc.sys [8247640 2013-07-19] (Realtek Semiconductor Corp.)
S3 SmbDrvI; C:\windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-09-13] (Synaptics Incorporated)
S3 ssudmdm; C:\windows\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [24688 2016-01-24] ()
S3 WdBoot; C:\windows\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
S3 WdFilter; C:\windows\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
S3 WdNisDrv; C:\windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
S3 wsvd; C:\windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
U0 Compbatt; no ImagePath
U2 ERSvc; no ImagePath
U2 NIHardwareService; no ImagePath
U2 NVSvc; no ImagePath
U2 Parvdm; no ImagePath
U2 srService; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-12 00:00 - 2017-11-12 00:00 - 000013670 _____ C:\Users\salem\Desktop\FRST.txt
2017-11-12 00:00 - 2017-11-12 00:00 - 000000000 ____D C:\FRST
2017-11-11 23:57 - 2017-11-11 23:57 - 002392576 _____ (Farbar) C:\Users\salem\Desktop\FRST64.exe
2017-11-11 23:16 - 2017-11-11 23:16 - 000009486 ____R C:\Users\salem\Desktop\Pre_Scan_11_11_2017_23_16_44.txt
2017-11-11 23:16 - 2017-11-11 23:16 - 000009486 ____R C:\Pre_Scan_11_11_2017_23_16_44.txt
2017-11-11 23:16 - 2017-11-11 23:16 - 000001015 _____ C:\Users\salem\Desktop\Internet Explorer.lnk
2017-11-11 22:58 - 2017-11-11 23:16 - 000000000 ____D C:\Pre_Scan
2017-11-11 17:37 - 2017-11-11 17:37 - 000117152 _____ C:\Users\salem\Desktop\ZHPDiag.txt
2017-11-11 01:27 - 2017-11-11 01:27 - 002930560 _____ C:\Users\salem\Downloads\ZHPDiag3.exe
2017-11-10 21:31 - 2017-11-11 22:37 - 000000000 ____D C:\Users\salem\AppData\Roaming\vlc
2017-11-10 21:31 - 2017-11-10 21:31 - 000001097 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-11-10 21:31 - 2017-11-10 21:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2017-11-10 21:30 - 2017-11-10 21:30 - 000000000 ____D C:\Program Files (x86)\VideoLAN
2017-11-10 21:29 - 2017-11-10 21:29 - 030950664 _____ C:\Users\salem\Downloads\vlc-2.2.6-win32.exe
2017-11-10 21:26 - 2017-11-11 19:29 - 000000000 ____D C:\Users\salem\Desktop\New folder (5)
2017-11-09 23:07 - 2017-10-11 08:35 - 000143016 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2017-11-09 23:07 - 2017-10-10 16:21 - 000463872 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2017-11-09 23:07 - 2017-10-10 14:18 - 002023936 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2017-11-09 23:07 - 2017-10-10 14:18 - 001570304 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2017-11-09 23:07 - 2017-10-10 14:18 - 000670208 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2017-11-09 23:07 - 2017-10-10 14:18 - 000605184 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2017-11-09 23:07 - 2017-10-10 14:18 - 000603648 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2017-11-09 23:07 - 2017-10-10 14:18 - 000402944 _____ (Microsoft Corporation) C:\windows\system32\centel.dll
2017-11-09 23:07 - 2017-10-10 14:18 - 000370688 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2017-11-09 23:07 - 2017-10-10 14:18 - 000241664 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2017-11-09 23:07 - 2017-10-10 14:18 - 000181760 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2017-11-06 21:51 - 2017-11-06 21:59 - 000002062 _____ C:\Users\salem\Desktop\Rkill.txt
2017-11-02 19:26 - 2017-11-02 19:26 - 001674353 _____ C:\Users\salem\Desktop\Accountant Cover Letter Sample.pdf
2017-10-31 20:15 - 2017-10-31 20:16 - 008261584 _____ (Malwarebytes) C:\Users\salem\Downloads\adwcleaner_7.0.4.0.exe
2017-10-30 23:02 - 2017-10-31 22:46 - 000000000 ____D C:\ProgramData\Immunet
2017-10-30 23:02 - 2017-10-30 23:02 - 000000000 ____H C:\windows\system32\Drivers\Msft_Kernel_ImmunetNetworkMonitor_01009.Wdf
2017-10-30 23:01 - 2017-10-30 23:01 - 001120712 _____ (Cisco Systems, Inc.) C:\Users\salem\Downloads\ImmunetSetup.exe
2017-10-29 14:29 - 2017-10-29 15:04 - 000000000 ____D C:\Users\salem\Desktop\علاج فطومة
2017-10-27 22:08 - 2017-10-27 22:08 - 001209264 _____ (Loaris LLC) C:\Users\salem\Downloads\loaris-trojanremover.exe
2017-10-18 20:13 - 2017-10-05 08:17 - 000380248 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2017-10-18 20:13 - 2017-09-15 00:52 - 000986968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2017-10-18 20:13 - 2017-09-08 18:14 - 003084288 _____ (Microsoft Corporation) C:\windows\system32\msftedit.dll
2017-10-18 20:13 - 2017-09-08 17:50 - 002471424 _____ (Microsoft Corporation) C:\windows\SysWOW64\msftedit.dll
2017-10-18 20:13 - 2017-09-08 04:31 - 000685440 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2017-10-18 20:13 - 2017-09-08 04:28 - 000507176 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2017-10-18 20:13 - 2017-09-07 22:31 - 000022528 _____ (Microsoft Corporation) C:\windows\system32\mgmtapi.dll
2017-10-18 20:13 - 2017-09-07 20:20 - 000018944 _____ (Microsoft Corporation) C:\windows\SysWOW64\mgmtapi.dll
2017-10-18 20:13 - 2017-09-07 18:20 - 000513456 _____ C:\windows\SysWOW64\locale.nls
2017-10-18 20:13 - 2017-09-07 18:20 - 000513456 _____ C:\windows\system32\locale.nls
2017-10-18 20:13 - 2017-09-07 14:40 - 000995272 _____ (Microsoft Corporation) C:\windows\system32\ucrtbase.dll
2017-10-18 20:13 - 2017-09-07 14:40 - 000922432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ucrtbase.dll
2017-10-18 20:13 - 2017-09-07 00:07 - 000158552 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2017-10-18 20:13 - 2017-09-06 22:17 - 000461144 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2017-10-18 20:13 - 2017-09-06 22:17 - 000443224 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2017-10-18 20:13 - 2017-09-06 15:14 - 000166400 _____ (Microsoft Corporation) C:\windows\system32\regsvc.dll
2017-10-18 20:13 - 2017-08-11 02:39 - 002779136 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2017-10-18 20:13 - 2017-08-11 02:30 - 002464256 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2017-10-15 14:29 - 2017-10-15 14:29 - 000025965 _____ C:\Users\salem\Downloads\details cv (1).pdf
2017-10-14 01:23 - 2017-10-14 01:23 - 000000000 ____D C:\Users\salem\Documents\ViberDownloads
2017-10-14 01:12 - 2017-10-14 01:12 - 000000000 ____D C:\Users\salem\AppData\Local\Viber Media S.à r.l
2017-10-14 01:12 - 2017-10-14 01:12 - 000000000 ____D C:\Users\salem\AppData\Local\cache

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-11 23:17 - 2013-08-22 15:45 - 000000006 ____H C:\windows\Tasks\SA.DAT
2017-11-11 23:14 - 2014-10-04 07:38 - 000003942 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{F4A1D82F-626F-48AE-A597-8E3984B4D806}
2017-11-11 22:34 - 2013-10-07 19:27 - 000866884 _____ C:\windows\system32\PerfStringBackup.INI
2017-11-11 22:34 - 2013-08-22 14:36 - 000000000 ____D C:\windows\Inf
2017-11-11 17:52 - 2016-01-24 16:13 - 000000000 ____D C:\Users\salem\AppData\Local\CrashDumps
2017-11-11 17:39 - 2015-10-24 16:56 - 000000000 ____D C:\Users\salem\AppData\Roaming\ZHP
2017-11-11 01:43 - 2017-04-12 17:44 - 000000000 ____D C:\Users\salem\AppData\Local\ZHP
2017-11-10 22:21 - 2014-10-04 07:07 - 000003600 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2152773553-1524527067-2441255551-1001
2017-11-09 23:22 - 2015-04-20 23:12 - 000000000 ____D C:\windows\system32\appraiser
2017-11-09 23:18 - 2013-08-22 16:20 - 000000000 ____D C:\windows\CbsTemp
2017-11-09 23:17 - 2014-10-06 12:59 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2017-11-09 23:17 - 2013-08-22 14:25 - 000000167 _____ C:\windows\win.ini
2017-11-06 20:55 - 2014-10-06 08:44 - 000002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-11-06 20:55 - 2014-10-06 08:44 - 000002214 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-11-04 18:23 - 2014-10-13 17:46 - 000000000 ____D C:\Users\salem\AppData\Roaming\Nitro PDF
2017-10-31 20:23 - 2013-08-22 14:25 - 000262144 ___SH C:\windows\system32\config\BBI
2017-10-29 14:33 - 2016-04-07 19:35 - 000000000 ____D C:\Users\salem\Desktop\table of content
2017-10-28 18:47 - 2014-10-04 06:59 - 000000000 ____D C:\Users\salem
2017-10-27 21:37 - 2013-08-22 16:36 - 000000000 ____D C:\windows\AppReadiness
2017-10-24 22:09 - 2017-06-04 14:29 - 000835568 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2017-10-24 22:09 - 2017-06-04 14:29 - 000177648 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-10-23 11:57 - 2013-08-22 16:36 - 000000000 ____D C:\windows\system32\NDF
2017-10-22 22:53 - 2016-10-07 21:31 - 000180088 _____ (ESET) C:\windows\system32\Drivers\ehdrv.sys
2017-10-22 22:53 - 2016-10-07 21:31 - 000132848 _____ (ESET) C:\windows\system32\Drivers\eamonm.sys
2017-10-22 22:53 - 2016-10-07 21:31 - 000102160 _____ (ESET) C:\windows\system32\Drivers\epfwwfp.sys
2017-10-22 22:53 - 2016-07-20 23:01 - 000015392 _____ (ESET) C:\windows\system32\Drivers\eelam.sys
2017-10-19 17:36 - 2013-08-22 16:36 - 000000000 ____D C:\windows\rescache

==================== Files in the root of some directories =======

2014-10-27 16:18 - 2014-10-27 15:54 - 000003407 _____ () C:\Program Files (x86)\backup.wsi
2014-10-27 15:54 - 2014-10-27 15:54 - 000000146 _____ () C:\Program Files (x86)\backupInfo.oki
2014-10-27 15:54 - 2014-10-27 15:54 - 284712639 _____ () C:\Program Files (x86)\backup_000_001.0000
2014-10-27 15:54 - 2014-10-27 15:54 - 000196992 _____ () C:\Program Files (x86)\backup_000_001_0000.dsi
2014-10-27 15:54 - 2014-10-27 15:54 - 013591697 _____ () C:\Program Files (x86)\backup_000_002.0000
2014-10-27 15:54 - 2014-10-27 15:54 - 000131424 _____ () C:\Program Files (x86)\backup_000_002_0000.dsi
2014-10-27 15:54 - 2014-10-27 15:55 - 314605635 _____ () C:\Program Files (x86)\backup_000_003.0000
2014-10-27 15:55 - 2014-10-27 15:55 - 151434804 _____ () C:\Program Files (x86)\backup_000_003.0001
2014-10-27 15:55 - 2014-10-27 15:55 - 000196992 _____ () C:\Program Files (x86)\backup_000_003_0000.dsi
2014-10-27 15:55 - 2014-10-27 16:18 - 314574960 _____ () C:\Program Files (x86)\backup_000_005.0000
2014-10-27 15:55 - 2014-10-27 15:56 - 314577069 _____ () C:\Program Files (x86)\backup_000_005.0001
2014-10-27 15:56 - 2014-10-27 15:56 - 314600763 _____ () C:\Program Files (x86)\backup_000_005.0002
2014-10-27 15:56 - 2014-10-27 15:56 - 314606126 _____ () C:\Program Files (x86)\backup_000_005.0003
2014-10-27 15:56 - 2014-10-27 15:57 - 314588747 _____ () C:\Program Files (x86)\backup_000_005.0004
2014-10-27 15:57 - 2014-10-27 15:57 - 314586793 _____ () C:\Program Files (x86)\backup_000_005.0005
2014-10-27 15:57 - 2014-10-27 15:57 - 314576488 _____ () C:\Program Files (x86)\backup_000_005.0006
2014-10-27 15:57 - 2014-10-27 15:58 - 314589252 _____ () C:\Program Files (x86)\backup_000_005.0007
2014-10-27 15:58 - 2014-10-27 15:58 - 314572934 _____ () C:\Program Files (x86)\backup_000_005.0008
2014-10-27 15:58 - 2014-10-27 15:59 - 314584811 _____ () C:\Program Files (x86)\backup_000_005.0009
2014-10-27 15:59 - 2014-10-27 15:59 - 314622406 _____ () C:\Program Files (x86)\backup_000_005.0010
2014-10-27 15:59 - 2014-10-27 15:59 - 314612281 _____ () C:\Program Files (x86)\backup_000_005.0011
2014-10-27 15:59 - 2014-10-27 15:59 - 314588356 _____ () C:\Program Files (x86)\backup_000_005.0012
2014-10-27 15:59 - 2014-10-27 16:00 - 314594705 _____ () C:\Program Files (x86)\backup_000_005.0013
2014-10-27 16:00 - 2014-10-27 16:00 - 314586316 _____ () C:\Program Files (x86)\backup_000_005.0014
2014-10-27 16:00 - 2014-10-27 16:00 - 314587999 _____ () C:\Program Files (x86)\backup_000_005.0015
2014-10-27 16:00 - 2014-10-27 16:01 - 314597386 _____ () C:\Program Files (x86)\backup_000_005.0016
2014-10-27 16:01 - 2014-10-27 16:01 - 314598323 _____ () C:\Program Files (x86)\backup_000_005.0017
2014-10-27 16:01 - 2014-10-27 16:01 - 314635330 _____ () C:\Program Files (x86)\backup_000_005.0018
2014-10-27 16:01 - 2014-10-27 16:01 - 314596938 _____ () C:\Program Files (x86)\backup_000_005.0019
2014-10-27 16:01 - 2014-10-27 16:02 - 314619777 _____ () C:\Program Files (x86)\backup_000_005.0020
2014-10-27 16:02 - 2014-10-27 16:02 - 314584861 _____ () C:\Program Files (x86)\backup_000_005.0021
2014-10-27 16:02 - 2014-10-27 16:02 - 314579821 _____ () C:\Program Files (x86)\backup_000_005.0022
2014-10-27 16:02 - 2014-10-27 16:02 - 314585309 _____ () C:\Program Files (x86)\backup_000_005.0023
2014-10-27 16:02 - 2014-10-27 16:03 - 314596185 _____ () C:\Program Files (x86)\backup_000_005.0024
2014-10-27 16:03 - 2014-10-27 16:03 - 314608062 _____ () C:\Program Files (x86)\backup_000_005.0025
2014-10-27 16:03 - 2014-10-27 16:03 - 314606927 _____ () C:\Program Files (x86)\backup_000_005.0026
2014-10-27 16:03 - 2014-10-27 16:03 - 314573028 _____ () C:\Program Files (x86)\backup_000_005.0027
2014-10-27 16:03 - 2014-10-27 16:04 - 314578569 _____ () C:\Program Files (x86)\backup_000_005.0028
2014-10-27 16:04 - 2014-10-27 16:04 - 314591262 _____ () C:\Program Files (x86)\backup_000_005.0029
2014-10-27 16:04 - 2014-10-27 16:04 - 314583291 _____ () C:\Program Files (x86)\backup_000_005.0030
2014-10-27 16:04 - 2014-10-27 16:04 - 314588998 _____ () C:\Program Files (x86)\backup_000_005.0031
2014-10-27 16:04 - 2014-10-27 16:05 - 314582296 _____ () C:\Program Files (x86)\backup_000_005.0032
2014-10-27 16:05 - 2014-10-27 16:05 - 314578522 _____ () C:\Program Files (x86)\backup_000_005.0033
2014-10-27 16:05 - 2014-10-27 16:05 - 314580621 _____ () C:\Program Files (x86)\backup_000_005.0034
2014-10-27 16:05 - 2014-10-27 16:06 - 314595873 _____ () C:\Program Files (x86)\backup_000_005.0035
2014-10-27 16:06 - 2014-10-27 16:06 - 314617559 _____ () C:\Program Files (x86)\backup_000_005.0036
2014-10-27 16:06 - 2014-10-27 16:06 - 314590910 _____ () C:\Program Files (x86)\backup_000_005.0037
2014-10-27 16:06 - 2014-10-27 16:07 - 314586659 _____ () C:\Program Files (x86)\backup_000_005.0038
2014-10-27 16:07 - 2014-10-27 16:07 - 314581909 _____ () C:\Program Files (x86)\backup_000_005.0039
2014-10-27 16:07 - 2014-10-27 16:07 - 314577682 _____ () C:\Program Files (x86)\backup_000_005.0040
2014-10-27 16:07 - 2014-10-27 16:07 - 314607766 _____ () C:\Program Files (x86)\backup_000_005.0041
2014-10-27 16:07 - 2014-10-27 16:08 - 314615201 _____ () C:\Program Files (x86)\backup_000_005.0042
2014-10-27 16:08 - 2014-10-27 16:08 - 314607572 _____ () C:\Program Files (x86)\backup_000_005.0043
2014-10-27 16:08 - 2014-10-27 16:08 - 314614191 _____ () C:\Program Files (x86)\backup_000_005.0044
2014-10-27 16:08 - 2014-10-27 16:08 - 314630990 _____ () C:\Program Files (x86)\backup_000_005.0045
2014-10-27 16:08 - 2014-10-27 16:09 - 314614262 _____ () C:\Program Files (x86)\backup_000_005.0046
2014-10-27 16:09 - 2014-10-27 16:09 - 314622674 _____ () C:\Program Files (x86)\backup_000_005.0047
2014-10-27 16:09 - 2014-10-27 16:09 - 314587662 _____ () C:\Program Files (x86)\backup_000_005.0048
2014-10-27 16:09 - 2014-10-27 16:09 - 314625151 _____ () C:\Program Files (x86)\backup_000_005.0049
2014-10-27 16:09 - 2014-10-27 16:09 - 314625946 _____ () C:\Program Files (x86)\backup_000_005.0050
2014-10-27 16:09 - 2014-10-27 16:10 - 314607377 _____ () C:\Program Files (x86)\backup_000_005.0051
2014-10-27 16:10 - 2014-10-27 16:10 - 314582384 _____ () C:\Program Files (x86)\backup_000_005.0052
2014-10-27 16:10 - 2014-10-27 16:10 - 314598957 _____ () C:\Program Files (x86)\backup_000_005.0053
2014-10-27 16:10 - 2014-10-27 16:10 - 314618044 _____ () C:\Program Files (x86)\backup_000_005.0054
2014-10-27 16:10 - 2014-10-27 16:11 - 314626731 _____ () C:\Program Files (x86)\backup_000_005.0055
2014-10-27 16:11 - 2014-10-27 16:11 - 314625362 _____ () C:\Program Files (x86)\backup_000_005.0056
2014-10-27 16:11 - 2014-10-27 16:11 - 314580438 _____ () C:\Program Files (x86)\backup_000_005.0057
2014-10-27 16:11 - 2014-10-27 16:11 - 314595320 _____ () C:\Program Files (x86)\backup_000_005.0058
2014-10-27 16:11 - 2014-10-27 16:12 - 314597871 _____ () C:\Program Files (x86)\backup_000_005.0059
2014-10-27 16:12 - 2014-10-27 16:12 - 314616109 _____ () C:\Program Files (x86)\backup_000_005.0060
2014-10-27 16:12 - 2014-10-27 16:12 - 314578941 _____ () C:\Program Files (x86)\backup_000_005.0061
2014-10-27 16:12 - 2014-10-27 16:12 - 314585692 _____ () C:\Program Files (x86)\backup_000_005.0062
2014-10-27 16:12 - 2014-10-27 16:12 - 314609435 _____ () C:\Program Files (x86)\backup_000_005.0063
2014-10-27 16:12 - 2014-10-27 16:13 - 314628064 _____ () C:\Program Files (x86)\backup_000_005.0064
2014-10-27 16:13 - 2014-10-27 16:13 - 314592999 _____ () C:\Program Files (x86)\backup_000_005.0065
2014-10-27 16:13 - 2014-10-27 16:13 - 314585383 _____ () C:\Program Files (x86)\backup_000_005.0066
2014-10-27 16:13 - 2014-10-27 16:13 - 314630313 _____ () C:\Program Files (x86)\backup_000_005.0067
2014-10-27 16:13 - 2014-10-27 16:13 - 314612905 _____ () C:\Program Files (x86)\backup_000_005.0068
2014-10-27 16:13 - 2014-10-27 16:14 - 314576465 _____ () C:\Program Files (x86)\backup_000_005.0069
2014-10-27 16:14 - 2014-10-27 16:14 - 314609381 _____ () C:\Program Files (x86)\backup_000_005.0070
2014-10-27 16:14 - 2014-10-27 16:14 - 314619416 _____ () C:\Program Files (x86)\backup_000_005.0071
2014-10-27 16:14 - 2014-10-27 16:14 - 314634364 _____ () C:\Program Files (x86)\backup_000_005.0072
2014-10-27 16:14 - 2014-10-27 16:15 - 314597298 _____ () C:\Program Files (x86)\backup_000_005.0073
2014-10-27 16:15 - 2014-10-27 16:15 - 314594510 _____ () C:\Program Files (x86)\backup_000_005.0074
2014-10-27 16:15 - 2014-10-27 16:15 - 314619545 _____ () C:\Program Files (x86)\backup_000_005.0075
2014-10-27 16:15 - 2014-10-27 16:15 - 314613203 _____ () C:\Program Files (x86)\backup_000_005.0076
2014-10-27 16:15 - 2014-10-27 16:15 - 314621506 _____ () C:\Program Files (x86)\backup_000_005.0077
2014-10-27 16:15 - 2014-10-27 16:16 - 314585118 _____ () C:\Program Files (x86)\backup_000_005.0078
2014-10-27 16:16 - 2014-10-27 16:16 - 314576359 _____ () C:\Program Files (x86)\backup_000_005.0079
2014-10-27 16:16 - 2014-10-27 16:16 - 314585705 _____ () C:\Program Files (x86)\backup_000_005.0080
2014-10-27 16:16 - 2014-10-27 16:16 - 314617532 _____ () C:\Program Files (x86)\backup_000_005.0081
2014-10-27 16:16 - 2014-10-27 16:16 - 314605807 _____ () C:\Program Files (x86)\backup_000_005.0082
2014-10-27 16:16 - 2014-10-27 16:17 - 314574891 _____ () C:\Program Files (x86)\backup_000_005.0083
2014-10-27 16:17 - 2014-10-27 16:17 - 314625475 _____ () C:\Program Files (x86)\backup_000_005.0084
2014-10-27 16:17 - 2014-10-27 16:17 - 314634056 _____ () C:\Program Files (x86)\backup_000_005.0085
2014-10-27 16:17 - 2014-10-27 16:17 - 314604737 _____ () C:\Program Files (x86)\backup_000_005.0086
2014-10-27 16:17 - 2014-10-27 16:17 - 314586847 _____ () C:\Program Files (x86)\backup_000_005.0087
2014-10-27 16:17 - 2014-10-27 16:18 - 309170508 _____ () C:\Program Files (x86)\backup_000_005.0088
2014-10-27 16:18 - 2014-10-27 16:18 - 006557088 _____ () C:\Program Files (x86)\backup_000_005_0000.dsi
2014-05-30 18:39 - 2014-05-30 18:39 - 000000000 ____H () C:\ProgramData\DP45977C.lfl
2016-02-05 19:43 - 2016-02-05 19:43 - 000000265 _____ () C:\ProgramData\fontcacheev1.dat

Files to move or delete:
====================
C:\ProgramData\fontcacheev1.dat


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-11-08 18:48

==================== End of FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité