Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04.03.2018
Ran by TAHER (administrator) on TITO (04-03-2018 07:44:54)
Running from C:\Users\TAHER\Desktop
Loaded Profiles: TAHER (Available Profiles: TAHER)
Platform: Windows 8.1 Pro (Update) (X64) Language: العربية (السعودية)‏
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ESET) C:\Program Files\ESET\ESET Security\egui.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [324352 2017-12-21] (ESET)
HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [4091960 2018-01-11] (Tonec Inc.)
HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10249048 2017-12-01] (Piriform Ltd)
HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
GroupPolicy: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{62857839-62F3-4A1A-A628-07796BA66EB4}: [NameServer],
Tcpip\..\Interfaces\{62857839-62F3-4A1A-A628-07796BA66EB4}: [DhcpNameServer]

Internet Explorer:
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> DefaultScope value is missing
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2017-12-14] (Internet Download Manager, Tonec Inc.)
BHO: No Name -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> No File
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2017-12-14] (Internet Download Manager, Tonec Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
Toolbar: HKLM-x32 - SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItIEAddin.dll [2007-05-16] (TechSmith Corporation)

FF DefaultProfile: g4k87b2p.default
FF ProfilePath: C:\Users\TAHER\AppData\Roaming\Mozilla\Firefox\Profiles\g4k87b2p.default [2018-03-03]
FF Session Restore: Mozilla\Firefox\Profiles\g4k87b2p.default -> is enabled.
FF Extension: (آدبلوك بلس) - C:\Users\TAHER\AppData\Roaming\Mozilla\Firefox\Profiles\g4k87b2p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-02-25]
FF HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Firefox\Extensions: [mozilla_cc3@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi
FF Extension: (No Name) - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2018-01-13]
FF HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-12-20] [Legacy]
FF HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\TAHER\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\TAHER\AppData\Roaming\IDM\idmmzcc5 [2017-12-12] [Legacy] [not signed]
FF HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2018-02-24] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2018-02-24] ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2018-02-20] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2018-02-20] (Google Inc.)

CHR DefaultSearchKeyword: Default -> lp
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default [2018-03-04]
CHR Extension: (ترجمة Google) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2018-02-20]
CHR Extension: (المستندات) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-20]
CHR Extension: (Google Drive) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-20]
CHR Extension: (Youtube) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-20]
CHR Extension: (آدبلوك بلس) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-02-20]
CHR Extension: (ZenMate VPN - Best Cyber Security & Unblock) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2018-03-03]
CHR Extension: (جداول البيانات) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-20]
CHR Extension: (مستندات Google في وضع عدم الاتصال) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-02-20]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2018-02-20]
CHR Extension: (Emoji Keyboard (2016) by EmojiOne™) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipdjnhgkpapgippgcgkfcbpdpcgifncb [2018-02-20]
CHR Extension: (InstaG Downloader) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnkdcmgmnegofdddphijckfagibepdlb [2018-03-01]
CHR Extension: (DotVPN – أفضل من الشبكة الخاصة الافتراضية.) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpiecbcckbofpmkkkdibbllpinceiihk [2018-02-20]
CHR Extension: (IDM Integration Module) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2018-03-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-02-20]
CHR Extension: (Gmail) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-02-20]
CHR Extension: (Chrome Media Router) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-02-20]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-01-13]
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-01-13]

OPR Extension: (ZenMate VPN - Best Cyber Security & Unblock) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\cnhbkkedmelfmalgjpkngiaoifpdfcnl [2018-02-22]
OPR Extension: (DotVPN — a better way to VPN) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\hiegahbgoabbpoieploedhfnobmpgbeg [2018-02-21]
OPR Extension: (LastPass: Free Password Manager) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\hnjalnkldgigidggphhmacmimbdlafdo [2017-12-15]
OPR Extension: (IDM Integration Module) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2018-03-03]
OPR Extension: (Adblock Plus) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2018-01-29]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 AeLookupSvc; C:\Windows\System32\aelupsvc.dll [214528 2014-11-21] (Microsoft Corporation) [File not signed]
S4 ApHidMonitorService; C:\Program Files\DellTPad\HidMonitorSvc.exe [87384 2015-09-16] (Alps Electric Co., Ltd.)
S3 DeviceAssociationService; C:\Windows\system32\das.dll [407040 2014-11-21] (Microsoft Corporation) [File not signed]
S3 dot3svc; C:\Windows\System32\dot3svc.dll [262144 2014-11-21] (Microsoft Corporation) [File not signed]
R2 DPS; C:\Windows\system32\dps.dll [174080 2014-11-21] (Microsoft Corporation) [File not signed]
S3 DsmSvc; C:\Windows\System32\DeviceSetupManager.dll [206848 2014-11-21] (Microsoft Corporation) [File not signed]
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [1940584 2017-12-21] (ESET)
R2 EventSystem; C:\Windows\system32\es.dll [516608 2014-11-21] (Microsoft Corporation) [File not signed]
S3 FDResPub; C:\Windows\system32\fdrespub.dll [34816 2014-11-21] (Microsoft Corporation) [File not signed]
S3 FoxitReaderService; C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [1659592 2017-02-24] (Foxit Software Inc.)
S3 hidserv; C:\Windows\SysWOW64\hidserv.dll [30720 2014-11-21] (Microsoft Corporation) [File not signed]
S3 KtmRm; C:\Windows\system32\msdtckrm.dll [373248 2014-11-21] (Microsoft Corporation) [File not signed]
S3 MSDTC; C:\Windows\System32\msdtc.exe [144384 2014-11-21] (Microsoft Corporation) [File not signed]
S3 Netman; C:\Windows\System32\netman.dll [266752 2014-11-21] (Microsoft Corporation) [File not signed]
S3 pla; C:\Windows\system32\pla.dll [1526784 2014-11-21] (Microsoft Corporation) [File not signed]
S3 RasAuto; C:\Windows\System32\rasauto.dll [102912 2014-11-21] (Microsoft Corporation) [File not signed]
S3 RasMan; C:\Windows\System32\rasmans.dll [542720 2017-08-06] (Microsoft Corporation) [File not signed]
R2 SENS; C:\Windows\System32\sens.dll [73728 2014-11-21] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\Windows\System32\shsvcs.dll [640000 2014-11-21] (Microsoft Corporation) [File not signed]
R3 SSDPSRV; C:\Windows\System32\ssdpsrv.dll [249344 2014-11-21] (Microsoft Corporation) [File not signed]
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [17920 2014-11-21] (Microsoft Corporation) [File not signed]
S3 svsvc; C:\Windows\system32\svsvc.dll [13312 2014-11-21] (Microsoft Corporation) [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 swprv; C:\Windows\System32\swprv.dll [706048 2014-11-21] (Microsoft Corporation) [File not signed]
S3 TabletInputService; C:\Windows\System32\TabSvc.dll [154112 2017-09-09] (Microsoft Corporation) [File not signed]
R2 Themes; C:\Windows\system32\themeservice.dll [59392 2014-11-21] (Microsoft Corporation) [File not signed]
S3 TrustedInstaller; C:\Windows\servicing\TrustedInstaller.exe [106496 2014-11-21] (Microsoft Corporation) [File not signed]
S3 UI0Detect; C:\Windows\system32\UI0Detect.exe [41984 2014-11-21] (Microsoft Corporation) [File not signed]
S3 upnphost; C:\Windows\System32\upnphost.dll [457728 2014-11-21] (Microsoft Corporation) [File not signed]
S3 vds; C:\Windows\System32\vds.exe [1313792 2014-11-21] (Microsoft Corporation) [File not signed]
R2 Wcmsvc; C:\Windows\System32\wcmsvc.dll [374784 2014-11-21] (Microsoft Corporation) [File not signed]
R3 WdiServiceHost; C:\Windows\system32\wdi.dll [95744 2014-11-21] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\Windows\system32\wdi.dll [95744 2014-11-21] (Microsoft Corporation) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
S3 WEPHOSTSVC; C:\Windows\system32\wephostsvc.dll [26112 2014-11-21] (Microsoft Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)
S3 WMPNetworkSvc; C:\Program Files\Windows Media Player\wmpnetwk.exe [1478144 2014-11-21] (Microsoft Corporation) [File not signed]
S3 WwanSvc; C:\Windows\System32\wwansvc.dll [513536 2014-11-21] (Microsoft Corporation) [File not signed]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [134368 2017-11-07] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [107328 2017-11-07] (ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15872 2018-02-19] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [180088 2017-11-07] (ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [50744 2017-11-07] (ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [81880 2017-11-07] (ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [106304 2017-11-07] (ESET)
S3 ESETCleanersDriver; C:\Windows\system32\Drivers\ESETCleanersDriver.sys [181160 2017-12-10] (ESET)
R3 ETDSMBus; C:\Windows\System32\drivers\ETDSMBus.sys [32840 2017-07-11] (ELAN Microelectronic Corp.)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-07-17] (REALiX(tm))
S3 Impcd; C:\Windows\System32\drivers\Impcd.sys [158976 2015-11-29] (Intel Corporation) [File not signed]
S3 IUFileFilter; no ImagePath
S3 IURegProcessFilter; no ImagePath
S3 MsBridge; C:\Windows\system32\DRIVERS\bridge.sys [115712 2014-11-21] (Microsoft Corporation) [File not signed]
S3 NDProxy; C:\Windows\System32\Drivers\NDProxy.sys [72192 2018-01-02] (Microsoft Corporation) [File not signed]
R2 Ndu; C:\Windows\System32\drivers\Ndu.sys [103424 2014-11-21] (Microsoft Corporation) [File not signed]
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew01.sys [3354384 2015-09-16] (Intel Corporation)
R2 pmfilter; C:\Windows\system32\drivers\pmfilter.sys [67280 2013-09-18] (Windows (R) Win 7 DDK provider)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
S3 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [17408 2014-11-21] (Microsoft Corporation) [File not signed]
S3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2016-07-09] (Synaptics Incorporated)
S3 Wanarp; C:\Windows\system32\DRIVERS\wanarp.sys [80384 2018-01-02] (Microsoft Corporation) [File not signed]
R1 Wanarpv6; C:\Windows\system32\DRIVERS\wanarp.sys [80384 2018-01-02] (Microsoft Corporation) [File not signed]
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
S3 cpuz143; \??\C:\Windows\temp\cpuz143\cpuz143_x64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-04 07:44 - 2018-03-04 07:45 - 000017759 _____ C:\Users\TAHER\Desktop\FRST.txt
2018-03-04 07:44 - 2018-03-04 07:44 - 000000000 ____D C:\FRST
2018-03-04 07:36 - 2018-03-04 07:37 - 002403328 _____ (Farbar) C:\Users\TAHER\Desktop\FRST64.exe
2018-03-03 22:13 - 2018-03-03 22:13 - 000003024 _____ C:\Users\TAHER\Desktop\ZHPCleaner.txt
2018-03-03 20:55 - 2018-03-03 20:55 - 001618512 _____ C:\Users\TAHER\Downloads\EasyBCD 2.2.exe
2018-03-03 20:36 - 2018-03-03 20:37 - 015592502 _____ C:\Users\TAHER\Desktop\كيفية اقلاع من فلاشة بدون بوت.MP4
2018-03-03 20:34 - 2018-03-03 20:35 - 003094400 _____ C:\Users\TAHER\Desktop\ZHPCleaner.exe
2018-03-02 23:37 - 2018-03-02 23:37 - 000491406 _____ C:\Users\TAHER\Desktop\هبة.MP4
2018-03-02 12:58 - 2018-03-02 12:58 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-03-02 12:57 - 2018-03-02 12:57 - 000000876 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2018-03-02 12:57 - 2018-03-02 12:57 - 000000000 ____D C:\ProgramData\RogueKiller
2018-03-02 12:57 - 2018-03-02 12:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-03-02 12:57 - 2018-03-02 12:57 - 000000000 ____D C:\Program Files\RogueKiller
2018-03-02 07:31 - 2018-03-02 07:31 - 000003838 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1486325203
2018-03-02 07:31 - 2018-03-02 07:31 - 000001063 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
2018-02-27 23:51 - 2018-02-27 23:56 - 036465728 _____ (Adlice Software ) C:\Users\TAHER\Desktop\RogueKiller_setup_ref3.exe
2018-02-27 22:26 - 2018-02-27 22:26 - 003026304 _____ C:\Users\TAHER\Desktop\ZHPDiag3.exe
2018-02-27 21:06 - 2018-02-27 21:06 - 002602440 _____ C:\Users\TAHER\Desktop\لقد تخيلت أمامي كل الأوغاد لكي أضربك بمثل هذة القوه 😂 المهم ان كلامه مموتني ضحك عمال بيقولي اضربيني بحب أتضرب شوفي حاجبي متعور ازاي شوفي عيني مفتوحه ازاي واقوله بتحب تتضرب يقولي آه 😂😂😂 #الدرس_الأول.MP4
2018-02-25 23:35 - 2018-02-19 00:21 - 000000119 _____ C:\Users\TAHER\Desktop\serial.txt
2018-02-25 23:35 - 2018-02-19 00:19 - 004481960 _____ (NewSoftwares.net, Inc. ) C:\Users\TAHER\Desktop\folder-protect-en.exe
2018-02-24 20:12 - 2018-02-24 20:12 - 000000000 ____D C:\Windows\IObit
2018-02-23 21:25 - 2018-02-23 21:25 - 011184566 _____ C:\Users\TAHER\Downloads\ccsetup540pro.rar
2018-02-23 12:01 - 2018-03-02 13:39 - 094580736 _____ C:\Windows\system32\config\SOFTWARE
2018-02-23 12:01 - 2018-03-02 13:39 - 000393216 _____ C:\Windows\system32\config\DEFAULT
2018-02-23 12:01 - 2018-03-02 13:39 - 000028672 _____ C:\Windows\system32\config\SAM
2018-02-23 12:01 - 2018-03-02 13:39 - 000024576 _____ C:\Windows\system32\config\SECURITY
2018-02-23 08:59 - 2018-02-23 08:59 - 002923520 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 002364928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcndmgr.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 002003456 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe
2018-02-23 08:59 - 2018-02-23 08:59 - 001695744 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 001562624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe
2018-02-23 08:59 - 2018-02-23 08:59 - 001292288 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2018-02-23 08:59 - 2018-02-23 08:59 - 001115648 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 001096192 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 001060352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2018-02-23 08:59 - 2018-02-23 08:59 - 000826368 _____ (Microsoft Corporation) C:\Windows\system32\pmcsnap.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000559616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2018-02-23 08:59 - 2018-02-23 08:59 - 000538624 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000477696 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000401408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-02-23 08:59 - 2018-02-23 08:59 - 000393728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000350208 _____ (Microsoft Corporation) C:\Windows\system32\mmcbase.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000311296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcbase.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000309760 _____ (Microsoft Corporation) C:\Windows\system32\compstui.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000289280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\compstui.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000276312 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2018-02-23 08:59 - 2018-02-23 08:59 - 000260096 _____ (Microsoft Corporation) C:\Windows\system32\ppcsnap.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000221184 _____ (Microsoft Corporation) C:\Windows\system32\prnntfy.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000202752 _____ (Microsoft Corporation) C:\Windows\system32\cic.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prnntfy.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000192512 _____ (Microsoft Corporation) C:\Windows\system32\puiapi.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiapi.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000163328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cic.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000128000 _____ (Microsoft Corporation) C:\Windows\system32\mmcshext.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000114688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcshext.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000053248 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2018-02-23 08:59 - 2018-02-23 08:59 - 000022824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\kbldfltr.sys
2018-02-23 08:46 - 2014-10-16 10:27 - 000027424 _____ (IObit) C:\Windows\system32\RegistryDefragBootTime.exe
2018-02-23 08:41 - 2018-02-25 08:13 - 000000000 ____D C:\ProgramData\ProductData
2018-02-23 08:40 - 2018-02-25 08:13 - 000000000 ____D C:\Program Files (x86)\IObit
2018-02-23 08:40 - 2018-02-23 08:41 - 000000000 ____D C:\Users\TAHER\AppData\LocalLow\IObit
2018-02-23 08:40 - 2018-02-23 08:40 - 000000000 ____D C:\ProgramData\{13CFD044-61E4-4EAC-AD61-02536D961216}
2018-02-23 08:39 - 2018-02-25 08:18 - 000000000 ____D C:\ProgramData\IObit
2018-02-23 08:39 - 2018-01-30 11:11 - 028866080 _____ (IObit ) C:\Users\TAHER\Downloads\Advanced SystemCare PRO
2018-02-23 08:38 - 2018-02-23 08:38 - 028829634 _____ C:\Users\TAHER\Downloads\Advanced SystemCare PRO
2018-02-21 17:28 - 2018-02-21 17:28 - 000001111 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6 (64 Bit).lnk
2018-02-21 17:26 - 2018-02-21 17:26 - 000001069 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk
2018-02-21 17:22 - 2018-02-21 17:22 - 000001583 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
2018-02-21 17:22 - 2018-02-21 17:22 - 000001409 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
2018-02-20 18:57 - 2018-02-20 18:57 - 004022328 _____ (Tonec Inc.) C:\Users\TAHER\Downloads\IDMan.exe.BAK
2018-02-20 18:14 - 2018-02-23 08:17 - 000002246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-02-20 18:14 - 2018-02-23 08:17 - 000002205 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-02-20 18:13 - 2018-02-20 18:13 - 000003274 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2018-02-20 18:13 - 2018-02-20 18:13 - 000003146 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2018-02-20 18:12 - 2018-02-20 18:13 - 001129816 _____ (Google Inc.) C:\Users\TAHER\Desktop\ChromeSetup_2.exe
2018-02-20 17:52 - 2018-02-20 17:53 - 000000000 ____D C:\ProgramData\Isolated Storage
2018-02-20 17:50 - 2018-02-25 08:19 - 000000000 ____D C:\ProgramData\Smarty Uninstaller 4
2018-02-20 17:50 - 2018-02-22 22:42 - 000001000 _____ C:\Users\TAHER\Desktop\Smarty Uninstaller 4.lnk
2018-02-20 17:50 - 2018-02-20 17:50 - 000003078 _____ C:\Windows\System32\Tasks\SmartyUninstallerLauncher
2018-02-20 17:50 - 2018-02-20 17:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smarty Uninstaller
2018-02-20 17:50 - 2018-02-20 17:50 - 000000000 ____D C:\Program Files\Smarty Uninstaller 4
2018-02-20 17:49 - 2018-02-20 17:49 - 006339263 _____ (OneSmarty ) C:\Users\TAHER\Desktop\SmartyUninstaller4.exe
2018-02-19 18:30 - 2018-02-19 18:30 - 004449914 _____ C:\Users\TAHER\Desktop\folder-protect.rar
2018-02-19 16:55 - 2018-02-19 16:55 - 000000000 ____D C:\Program Files\BCUninstaller
2018-02-18 23:07 - 2018-02-18 23:07 - 003019752 _____ (Marcin Szeniak ) C:\Users\TAHER\Desktop\BCUninstaller_4.3.1_setup.exe
2018-02-18 22:35 - 2017-12-11 19:01 - 000003650 __RSH C:\Windows\system32\Drivers\etc\hosts.bak
2018-02-18 18:47 - 2018-02-18 18:47 - 027747478 _____ C:\Users\TAHER\Desktop\خطوات توثيق حساب Ask.fm بالعلامة الزرقاء ● شرح بالتفصيل لحالتي الرفض والقبول وحل مشكلة الرفض 💙💙 ●.MP4
2018-02-18 02:51 - 2018-02-18 02:52 - 000000000 ____D C:\Users\TAHER\Desktop\برنامج مضاد لملفات التجسس
2018-02-17 22:12 - 2018-02-17 22:12 - 000000083 _____ C:\Windows\SysWOW64\_system.ini
2018-02-17 22:11 - 2018-02-17 22:11 - 000000000 ____D C:\ProgramData\Protect My Folders
2018-02-17 22:10 - 2018-02-17 22:11 - 000000000 ____D C:\Program Files\Protect My Folders
2018-02-17 22:10 - 2018-02-17 22:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Protect My Folders
2018-02-17 22:10 - 2015-03-03 19:25 - 000681064 _____ ( ) C:\Users\TAHER\Desktop\setup.exe
2018-02-17 22:10 - 2013-09-18 18:33 - 000067280 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\pmfilter.sys
2018-02-17 22:09 - 2018-02-17 22:09 - 000652104 _____ C:\Users\TAHER\Desktop\Protect My Folders V1.8 .rar
2018-02-17 18:05 - 2018-02-17 18:05 - 001391360 _____ (Kakasoft) C:\Users\TAHER\Downloads\lockdir.exe
2018-02-16 16:33 - 2018-02-16 16:33 - 001388833 _____ C:\Users\TAHER\Desktop\Heba A Refaie.MP4
2018-02-15 21:01 - 2018-02-15 21:02 - 044044399 _____ C:\Users\TAHER\Desktop\اصنع طاولة خرافية لحاسوبك و خزنة من ورق الكرتون - صدّقني ستعجبك كثيرا - YouTube.MP4
2018-02-14 18:32 - 2018-02-14 18:32 - 000155192 _____ C:\Users\TAHER\Desktop\1518600c3d584-9a5d-4686-a2d8-e405a4bfe2b1.mp4
2018-02-13 20:59 - 2018-02-05 22:38 - 000835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-02-13 20:59 - 2018-02-05 22:38 - 000177648 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-02-13 20:29 - 2018-02-10 10:44 - 025740288 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-02-13 20:29 - 2018-02-10 09:19 - 002900480 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-02-13 20:29 - 2018-02-10 09:16 - 000577536 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-02-13 20:29 - 2018-02-10 09:16 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-02-13 20:29 - 2018-02-10 09:09 - 005782016 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-02-13 20:29 - 2018-02-10 09:06 - 000816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-02-13 20:29 - 2018-02-10 08:36 - 015283712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-02-13 20:29 - 2018-02-10 08:34 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-02-13 20:29 - 2018-02-10 08:32 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-02-13 20:29 - 2018-02-10 08:27 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-02-13 20:29 - 2018-02-10 08:20 - 020274176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-02-13 20:29 - 2018-02-10 08:14 - 001546240 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-02-13 20:29 - 2018-02-10 07:57 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-02-13 20:29 - 2018-02-10 07:54 - 002294272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-02-13 20:29 - 2018-02-10 07:49 - 000662528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-02-13 20:29 - 2018-02-10 07:35 - 004498944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-02-13 20:29 - 2018-02-10 07:33 - 013680640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-02-13 20:29 - 2018-02-10 07:27 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-02-13 20:29 - 2018-02-10 07:27 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-02-13 20:29 - 2018-02-10 07:14 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-02-13 20:29 - 2018-02-10 07:10 - 001314304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-02-13 20:29 - 2018-02-03 08:04 - 000686592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2018-02-13 20:29 - 2018-02-03 08:03 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2018-02-13 20:29 - 2018-02-03 01:53 - 007408984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-02-13 20:29 - 2018-01-21 13:54 - 000419160 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-02-13 20:29 - 2018-01-13 03:18 - 002452824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2018-02-13 20:29 - 2018-01-12 23:42 - 000376664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2018-02-13 20:29 - 2018-01-12 20:31 - 004690944 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
2018-02-13 20:29 - 2018-01-12 19:35 - 003553280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
2018-02-13 20:29 - 2018-01-11 20:19 - 000032384 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2018-02-13 20:29 - 2018-01-11 19:56 - 000504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2018-02-13 20:29 - 2018-01-11 19:07 - 000748032 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2018-02-13 20:29 - 2018-01-09 08:21 - 004168704 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-02-13 20:28 - 2018-02-10 09:06 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-02-13 20:28 - 2018-02-10 08:48 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-02-13 20:28 - 2018-02-10 08:47 - 000145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2018-02-13 20:28 - 2018-02-10 08:46 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-02-13 20:28 - 2018-02-10 08:41 - 001033216 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2018-02-13 20:28 - 2018-02-10 08:36 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-02-13 20:28 - 2018-02-10 08:02 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-02-13 20:28 - 2018-02-10 07:56 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-02-13 20:28 - 2018-02-10 07:49 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-02-13 20:28 - 2018-02-10 07:35 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-02-13 20:28 - 2018-02-10 07:35 - 000128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2018-02-13 20:28 - 2018-02-10 07:35 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-02-13 20:28 - 2018-02-10 07:32 - 000880640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2018-02-13 20:28 - 2018-02-10 07:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-02-13 20:28 - 2018-02-10 07:08 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-02-13 20:28 - 2018-02-01 20:51 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-02-13 20:27 - 2018-01-21 13:09 - 000145080 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-02-13 20:27 - 2018-01-21 08:13 - 001994752 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-02-13 20:27 - 2018-01-21 08:13 - 001569280 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-02-13 20:27 - 2018-01-21 08:13 - 000749568 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-02-13 20:27 - 2018-01-21 08:13 - 000654336 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-02-13 20:27 - 2018-01-21 08:13 - 000604672 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-02-13 20:27 - 2018-01-21 08:13 - 000450048 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-02-13 20:27 - 2018-01-21 08:13 - 000378880 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-02-13 20:27 - 2018-01-21 08:13 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-02-13 20:27 - 2018-01-21 08:13 - 000236544 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-02-13 19:52 - 2018-01-25 19:20 - 000000000 ____D C:\Users\TAHER\Desktop\IDM 6.30.6 Kooretna By Mr-Rafiko
2018-02-13 19:51 - 2018-02-13 19:51 - 001431633 _____ C:\Users\TAHER\Desktop\IDM 6.30.6 [Kooretna] By Mr-Rafiko.rar
2018-02-10 21:08 - 2018-02-10 21:09 - 007319952 _____ (Tonec Inc.) C:\Users\TAHER\Downloads\idman630build6.exe
2018-02-09 19:35 - 2018-02-09 19:35 - 003174349 _____ C:\Users\TAHER\Desktop\How to force shutdown a ASUS laptop and enter the BIOS configuration- - YouTube.MP4
2018-02-09 11:37 - 2018-02-09 11:37 - 000152518 _____ C:\Users\TAHER\Desktop\1518139bcfbaf-deef-4be0-84e5-c4167be78557.mp4
2018-02-09 10:58 - 2018-02-09 10:58 - 000248396 _____ C:\Users\TAHER\Desktop\aaaa.MP4
2018-02-09 10:00 - 2018-02-09 10:00 - 001482794 _____ C:\Users\TAHER\Desktop\YouTube.MP4
2018-02-07 23:14 - 2018-02-07 23:15 - 021612690 _____ C:\Users\TAHER\Desktop\تداول فيديو لنساء يضربن شابا ويجبرنه على ارتداء -قميص نوم وطرحة- - YouTube.MP4
2018-02-05 02:18 - 2017-12-05 18:56 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scfilter.sys
2018-02-05 02:18 - 2017-12-05 18:52 - 000242176 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2018-02-05 02:18 - 2017-12-05 18:45 - 000194560 _____ (Microsoft Corporation) C:\Windows\system32\SCardSvr.dll
2018-02-05 02:18 - 2017-12-05 18:42 - 000079360 _____ (Microsoft Corporation) C:\Windows\system32\SCardDlg.dll
2018-02-05 02:18 - 2017-12-05 18:32 - 000169984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2018-02-05 02:18 - 2017-12-05 18:10 - 000361472 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe
2018-02-05 02:18 - 2017-12-05 18:02 - 000186880 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2018-02-05 02:18 - 2017-12-05 17:58 - 000132608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2018-02-05 02:18 - 2017-12-05 17:24 - 000165376 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\cdrom.sys
2018-02-05 02:18 - 2017-12-02 05:04 - 000082944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-02-05 02:18 - 2017-11-24 23:58 - 002608640 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2018-02-05 02:18 - 2017-11-24 23:56 - 000285184 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2018-02-05 02:18 - 2017-11-24 23:46 - 002170880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2018-02-05 02:18 - 2017-11-24 23:44 - 000236032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-04 07:37 - 2017-12-12 00:05 - 000000000 ____D C:\Users\TAHER\AppData\Roaming\IDM
2018-03-04 07:07 - 2017-05-09 02:37 - 000003902 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{9EF4CA9D-8A4B-4D65-904A-E9E4C19D26D5}
2018-03-03 23:38 - 2017-12-12 00:05 - 000000000 ____D C:\Users\TAHER\AppData\Roaming\DMCache
2018-03-03 22:15 - 2013-08-22 15:36 - 000000000 ____D C:\Windows\Inf
2018-03-03 22:14 - 2015-10-21 21:05 - 000000000 ____D C:\Users\TAHER\AppData\Local\CrashDumps
2018-03-03 22:13 - 2015-09-18 03:41 - 000000000 ____D C:\Users\TAHER\AppData\Roaming\ZHP
2018-03-03 22:13 - 2015-09-15 20:09 - 000000000 ____D C:\Program Files\CCleaner
2018-03-03 22:08 - 2017-04-08 09:46 - 000000000 ____D C:\Users\TAHER\AppData\Local\ZHP
2018-03-03 18:56 - 2016-11-18 17:57 - 000000000 ____D C:\Users\TAHER\AppData\LocalLow\Mozilla
2018-03-02 17:05 - 2018-01-03 14:29 - 000000000 ____D C:\KMPlayer
2018-03-02 15:19 - 2015-09-14 02:22 - 000003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2422561113-3094125170-2170945475-1001
2018-03-02 13:47 - 2017-02-05 22:06 - 000000000 ____D C:\Program Files (x86)\Opera
2018-03-02 13:42 - 2013-08-22 16:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-02-25 23:35 - 2015-09-14 02:15 - 000000000 ____D C:\Users\TAHER
2018-02-24 18:32 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\rescache
2018-02-24 06:40 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-02-24 06:40 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\system32\Macromed
2018-02-23 12:01 - 2015-10-22 13:39 - 094580736 _____ C:\Windows\system32\config\SOFTWARE.iodefrag.bak
2018-02-23 12:01 - 2015-10-22 13:39 - 000393216 _____ C:\Windows\system32\config\DEFAULT.iodefrag.bak
2018-02-23 12:01 - 2015-10-22 13:39 - 000028672 _____ C:\Windows\system32\config\SAM.iodefrag.bak
2018-02-23 12:01 - 2015-10-22 13:39 - 000024576 _____ C:\Windows\system32\config\SECURITY.iodefrag.bak
2018-02-23 11:43 - 2013-08-22 17:36 - 000000000 ___RD C:\Windows\ToastData
2018-02-23 09:00 - 2013-08-22 17:20 - 000000000 ____D C:\Windows\CbsTemp
2018-02-20 18:14 - 2015-09-15 14:48 - 000000000 ____D C:\Program Files (x86)\Google
2018-02-20 18:07 - 2013-08-22 15:25 - 000262144 ___SH C:\Windows\system32\config\BBI
2018-02-19 18:08 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\system32\NDF
2018-02-19 16:27 - 2017-01-17 09:15 - 000015872 _____ (ESET) C:\Windows\system32\Drivers\eelam.sys
2018-02-13 20:55 - 2017-03-01 23:49 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager
2018-02-13 20:51 - 2015-09-14 21:08 - 000000000 ____D C:\Windows\system32\appraiser
2018-02-13 20:47 - 2015-09-14 13:15 - 000000000 ____D C:\Windows\system32\MRT
2018-02-13 20:39 - 2017-10-12 15:02 - 130067560 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-02-13 20:39 - 2015-09-14 13:14 - 130067560 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-02-13 20:21 - 2017-12-12 00:05 - 000001041 _____ C:\Users\TAHER\Desktop\Internet Download Manager.lnk
2018-02-13 16:19 - 2017-06-27 10:33 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-02-13 16:19 - 2017-06-27 10:33 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-02-12 22:46 - 2017-12-13 06:41 - 000004130 _____ C:\Windows\System32\Tasks\CCleaner Update
2018-02-10 19:59 - 2017-06-27 10:33 - 000000954 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-02-10 19:59 - 2017-04-22 07:28 - 000002726 _____ C:\Windows\wininit.ini
2018-02-09 10:46 - 2018-01-03 14:29 - 000000614 _____ C:\Users\TAHER\Desktop\KMPlayer.lnk

==================== Files in the root of some directories =======

2017-12-11 06:43 - 2017-12-11 06:43 - 000000260 _____ () C:\ProgramData\fontcacheev1.dat

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-02-24 17:58

==================== End of FRST.txt ============================


