Format du document : text/plain
Prévisualisation
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018
Ran by TAHER (administrator) on TITO (09-04-2018 00:37:06)
Running from C:\Users\TAHER\Desktop
Loaded Profiles: TAHER (Available Profiles: TAHER)
Platform: Windows 8.1 Pro (Update) (X64) Language: العربية (السعودية)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
() C:\Program Files\Broadcom\CV\bin\UshUpgradeService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Broadcom Corporation) C:\Program Files\Broadcom\CV\bin\HostControlService.exe
(Broadcom Corporation) C:\Program Files\Broadcom\CV\bin\HostStorageService.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(ESET) C:\Program Files\ESET\ESET Security\egui.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [324352 2017-12-21] (ESET)
HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10249048 2017-12-01] (Piriform Ltd)
HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [4096056 2018-03-01] (Tonec Inc.)
HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
GroupPolicy: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{62857839-62F3-4A1A-A628-07796BA66EB4}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{62857839-62F3-4A1A-A628-07796BA66EB4}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Internet Explorer:
==================
URLSearchHook: [S-1-5-21-2422561113-3094125170-2170945475-1001] ATTENTION => Default URLSearchHook is missing
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2017-12-14] (Internet Download Manager, Tonec Inc.)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2017-12-14] (Internet Download Manager, Tonec Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
Toolbar: HKLM-x32 - SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItIEAddin.dll [2007-05-16] (TechSmith Corporation)
FireFox:
========
FF DefaultProfile: g4k87b2p.default
FF ProfilePath: C:\Users\TAHER\AppData\Roaming\Mozilla\Firefox\Profiles\g4k87b2p.default [2018-04-08]
FF user.js: detected! => C:\Users\TAHER\AppData\Roaming\Mozilla\Firefox\Profiles\g4k87b2p.default\user.js [2018-04-01]
FF Session Restore: Mozilla\Firefox\Profiles\g4k87b2p.default -> is enabled.
FF Extension: (آدبلوك بلس) - C:\Users\TAHER\AppData\Roaming\Mozilla\Firefox\Profiles\g4k87b2p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-02-25]
FF Extension: (TLS 1.3 gradual roll-out) - C:\Users\TAHER\AppData\Roaming\Mozilla\Firefox\Profiles\g4k87b2p.default\features\{1a1f6eed-fd84-4fed-be44-a866a0872c12}\tls13-rollout-bug1442042@mozilla.org.xpi [2018-04-08] [Legacy]
FF HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Firefox\Extensions: [mozilla_cc3@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi
FF Extension: (IDM Integration Module) - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2018-02-28]
FF HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-12-20] [Legacy]
FF HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\TAHER\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\TAHER\AppData\Roaming\IDM\idmmzcc5 [2017-12-12] [Legacy] [not signed]
FF HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2018-02-24] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2018-02-24] ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-02-20] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-02-20] (Google Inc.)
Chrome:
=======
CHR DefaultSearchKeyword: Default -> lp
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default [2018-04-09]
CHR Extension: (ترجمة Google) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2018-02-20]
CHR Extension: (المستندات) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-20]
CHR Extension: (Google Drive) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-20]
CHR Extension: (Youtube) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-20]
CHR Extension: (آدبلوك بلس) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-02-20]
CHR Extension: (ZenMate VPN - Best Cyber Security & Unblock) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2018-03-03]
CHR Extension: (جداول البيانات) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-20]
CHR Extension: (مستندات Google في وضع عدم الاتصال) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-02-20]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2018-03-29]
CHR Extension: (Emoji Keyboard (2016) by EmojiOne™) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipdjnhgkpapgippgcgkfcbpdpcgifncb [2018-02-20]
CHR Extension: (InstaG Downloader) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnkdcmgmnegofdddphijckfagibepdlb [2018-04-03]
CHR Extension: (DotVPN – أفضل من الشبكة الخاصة الافتراضية.) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpiecbcckbofpmkkkdibbllpinceiihk [2018-02-20]
CHR Extension: (IDM Integration Module) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2018-03-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Gmail) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-02-20]
CHR Extension: (Chrome Media Router) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-10]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-03-01]
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-03-01]
Opera:
=======
OPR Extension: (ZenMate VPN - Best Cyber Security & Unblock) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\cnhbkkedmelfmalgjpkngiaoifpdfcnl [2018-02-22]
OPR Extension: (DotVPN — a better way to VPN) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\hiegahbgoabbpoieploedhfnobmpgbeg [2018-02-21]
OPR Extension: (LastPass: Free Password Manager) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\hnjalnkldgigidggphhmacmimbdlafdo [2017-12-15]
OPR Extension: (IDM Integration Module) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2018-04-06]
OPR Extension: (Adblock Plus) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2018-01-29]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AeLookupSvc; C:\Windows\System32\aelupsvc.dll [214528 2014-11-21] (Microsoft Corporation) [File not signed]
S4 ApHidMonitorService; C:\Program Files\DellTPad\HidMonitorSvc.exe [87384 2015-09-16] (Alps Electric Co., Ltd.)
S3 DeviceAssociationService; C:\Windows\system32\das.dll [407040 2014-11-21] (Microsoft Corporation) [File not signed]
S3 dot3svc; C:\Windows\System32\dot3svc.dll [262144 2014-11-21] (Microsoft Corporation) [File not signed]
R2 DPS; C:\Windows\system32\dps.dll [174080 2014-11-21] (Microsoft Corporation) [File not signed]
S3 DsmSvc; C:\Windows\System32\DeviceSetupManager.dll [206848 2014-11-21] (Microsoft Corporation) [File not signed]
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [1940584 2017-12-21] (ESET)
R2 EventSystem; C:\Windows\system32\es.dll [516608 2014-11-21] (Microsoft Corporation) [File not signed]
S3 FDResPub; C:\Windows\system32\fdrespub.dll [34816 2014-11-21] (Microsoft Corporation) [File not signed]
S3 FoxitReaderService; C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [1659592 2017-02-24] (Foxit Software Inc.)
S3 hidserv; C:\Windows\SysWOW64\hidserv.dll [30720 2014-11-21] (Microsoft Corporation) [File not signed]
R2 hostcontrolsvc; C:\Program Files\Broadcom\CV\bin\HostControlService.exe [1038336 2018-04-01] (Broadcom Corporation)
R2 hoststoragesvc; C:\Program Files\Broadcom\CV\bin\HostStorageService.exe [42496 2018-04-01] (Broadcom Corporation)
S3 IEEtwCollectorService; C:\Windows\system32\IEEtwCollector.exe [116224 2018-01-02] (Microsoft Corporation) [File not signed]
S3 KtmRm; C:\Windows\system32\msdtckrm.dll [373248 2014-11-21] (Microsoft Corporation) [File not signed]
S3 MSDTC; C:\Windows\System32\msdtc.exe [144384 2014-11-21] (Microsoft Corporation) [File not signed]
S3 Netman; C:\Windows\System32\netman.dll [266752 2014-11-21] (Microsoft Corporation) [File not signed]
S3 pla; C:\Windows\system32\pla.dll [1526784 2014-11-21] (Microsoft Corporation) [File not signed]
S3 RasAuto; C:\Windows\System32\rasauto.dll [102912 2014-11-21] (Microsoft Corporation) [File not signed]
S3 RasMan; C:\Windows\System32\rasmans.dll [542720 2017-08-06] (Microsoft Corporation) [File not signed]
R2 SENS; C:\Windows\System32\sens.dll [73728 2014-11-21] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\Windows\System32\shsvcs.dll [640000 2014-11-21] (Microsoft Corporation) [File not signed]
R3 SSDPSRV; C:\Windows\System32\ssdpsrv.dll [249344 2014-11-21] (Microsoft Corporation) [File not signed]
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [17920 2014-11-21] (Microsoft Corporation) [File not signed]
S3 svsvc; C:\Windows\system32\svsvc.dll [13312 2014-11-21] (Microsoft Corporation) [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R3 swprv; C:\Windows\System32\swprv.dll [706048 2014-11-21] (Microsoft Corporation) [File not signed]
S3 TabletInputService; C:\Windows\System32\TabSvc.dll [154112 2017-09-09] (Microsoft Corporation) [File not signed]
R2 Themes; C:\Windows\system32\themeservice.dll [59392 2014-11-21] (Microsoft Corporation) [File not signed]
S3 TrustedInstaller; C:\Windows\servicing\TrustedInstaller.exe [106496 2014-11-21] (Microsoft Corporation) [File not signed]
S3 UI0Detect; C:\Windows\system32\UI0Detect.exe [41984 2014-11-21] (Microsoft Corporation) [File not signed]
S3 upnphost; C:\Windows\System32\upnphost.dll [457728 2014-11-21] (Microsoft Corporation) [File not signed]
R2 ushupgradesvc; C:\Program Files\Broadcom\CV\bin\UshUpgradeService.exe [259584 2018-04-01] ()
S3 vds; C:\Windows\System32\vds.exe [1313792 2014-11-21] (Microsoft Corporation) [File not signed]
R2 Wcmsvc; C:\Windows\System32\wcmsvc.dll [374784 2014-11-21] (Microsoft Corporation) [File not signed]
R3 WdiServiceHost; C:\Windows\system32\wdi.dll [95744 2014-11-21] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\Windows\system32\wdi.dll [95744 2014-11-21] (Microsoft Corporation) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
S3 WEPHOSTSVC; C:\Windows\system32\wephostsvc.dll [26112 2014-11-21] (Microsoft Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)
S3 WMPNetworkSvc; C:\Program Files\Windows Media Player\wmpnetwk.exe [1478144 2014-11-21] (Microsoft Corporation) [File not signed]
S3 WwanSvc; C:\Windows\System32\wwansvc.dll [513536 2014-11-21] (Microsoft Corporation) [File not signed]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 cpuz143; C:\Windows\temp\cpuz143\cpuz143_x64.sys [48960 2018-04-03] (CPUID)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [134368 2017-11-07] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [107328 2017-11-07] (ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15872 2018-02-19] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [180088 2017-11-07] (ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [50744 2017-11-07] (ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [81880 2017-11-07] (ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [106304 2017-11-07] (ESET)
S3 ESETCleanersDriver; C:\Windows\system32\Drivers\ESETCleanersDriver.sys [181160 2017-12-10] (ESET)
R3 ETDSMBus; C:\Windows\System32\drivers\ETDSMBus.sys [32840 2017-07-11] (ELAN Microelectronic Corp.)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-07-17] (REALiX(tm))
S3 Impcd; C:\Windows\System32\drivers\Impcd.sys [158976 2015-11-29] (Intel Corporation) [File not signed]
S3 MsBridge; C:\Windows\system32\DRIVERS\bridge.sys [115712 2014-11-21] (Microsoft Corporation) [File not signed]
S3 NDProxy; C:\Windows\System32\Drivers\NDProxy.sys [72192 2018-01-02] (Microsoft Corporation) [File not signed]
R2 Ndu; C:\Windows\System32\drivers\Ndu.sys [103424 2014-11-21] (Microsoft Corporation) [File not signed]
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew01.sys [3354384 2015-09-16] (Intel Corporation)
R2 pmfilter; C:\Windows\system32\drivers\pmfilter.sys [67280 2013-09-18] (Windows (R) Win 7 DDK provider)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
S3 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [17408 2014-11-21] (Microsoft Corporation) [File not signed]
S3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2016-07-09] (Synaptics Incorporated)
S3 Wanarp; C:\Windows\system32\DRIVERS\wanarp.sys [80384 2018-01-02] (Microsoft Corporation) [File not signed]
R1 Wanarpv6; C:\Windows\system32\DRIVERS\wanarp.sys [80384 2018-01-02] (Microsoft Corporation) [File not signed]
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
S4 IMFMBRProtect; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\IMFMBRProtect.sys [X]
S4 IMFSafeBox; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\IMFSafeBox.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-09 00:33 - 2018-04-09 00:33 - 000032821 _____ C:\Users\TAHER\Desktop\Addition.txt
2018-04-09 00:32 - 2018-04-09 00:37 - 000018804 _____ C:\Users\TAHER\Desktop\FRST.txt
2018-04-09 00:31 - 2018-04-09 00:37 - 000000000 ____D C:\FRST
2018-04-09 00:08 - 2018-04-09 00:08 - 002403328 _____ (Farbar) C:\Users\TAHER\Desktop\FRST64.exe
2018-04-08 11:35 - 2018-04-08 11:35 - 000566128 _____ (Malwarebytes) C:\Users\TAHER\Desktop\mbam-clean-2.3.0.1001.exe
2018-04-08 11:30 - 2018-04-08 11:30 - 000002201 _____ C:\Users\TAHER\Desktop\yyyyyyyyy.txt
2018-04-04 07:36 - 2018-04-04 07:37 - 036501736 _____ (Adlice Software ) C:\Users\TAHER\Desktop\RogueKiller_setup_ref3.exe
2018-04-03 21:39 - 2018-04-03 21:39 - 000000000 ____D C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705}
2018-04-03 19:00 - 2018-04-03 19:00 - 046075904 _____ C:\Users\TAHER\Downloads\Malwarebytes Anti-malware.msi
2018-04-03 18:55 - 2018-04-03 18:55 - 011115196 _____ C:\Users\TAHER\Desktop\-₪-« حصري Malwarebytes Anti-malware + مفعل تلقائيا مدى الحياة »-₪- - YouTube.MP4
2018-04-03 17:55 - 2018-04-03 17:55 - 000002878 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (TAHER)
2018-04-03 00:08 - 2018-04-03 00:09 - 072135408 _____ (Malwarebytes ) C:\Users\TAHER\Desktop\mb3-setup-consumer-3.4.5.2467-1.0.342-1.0.4576.exe
2018-04-01 15:55 - 2018-04-08 11:37 - 000010793 _____ C:\Windows\system32\CVFirmwareUpgradeLog.txt
2018-04-01 15:55 - 2018-04-01 15:55 - 000583296 _____ (Broadcom Corporation) C:\Windows\system32\bipdll.dll
2018-04-01 15:55 - 2018-04-01 15:55 - 000471040 _____ (Broadcom) C:\Windows\system32\cvproppage.dll
2018-04-01 15:55 - 2018-04-01 15:55 - 000060512 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\cvusbdrv.sys
2018-04-01 15:55 - 2018-04-01 15:55 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_cvusbdrv_01009.Wdf
2018-04-01 15:55 - 2018-04-01 15:55 - 000000000 ____D C:\ProgramData\Broadcom
2018-04-01 15:55 - 2018-04-01 15:55 - 000000000 ____D C:\Program Files\Broadcom
2018-04-01 15:36 - 2018-04-08 11:36 - 094580736 _____ C:\Windows\system32\config\SOFTWARE
2018-04-01 15:36 - 2018-04-08 11:36 - 000393216 _____ C:\Windows\system32\config\DEFAULT
2018-04-01 15:36 - 2018-04-08 11:36 - 000028672 _____ C:\Windows\system32\config\SAM
2018-04-01 15:36 - 2018-04-08 11:36 - 000024576 _____ C:\Windows\system32\config\SECURITY
2018-04-01 15:36 - 2018-04-01 15:36 - 094580736 _____ C:\Windows\system32\config\SOFTWARE.iodefrag.bak
2018-04-01 15:36 - 2018-04-01 15:36 - 004792320 _____ C:\Windows\system32\config\DRIVERS.iodefrag.bak
2018-04-01 15:36 - 2018-04-01 15:36 - 000393216 _____ C:\Windows\system32\config\DEFAULT.iodefrag.bak
2018-04-01 15:36 - 2018-04-01 15:36 - 000028672 _____ C:\Windows\system32\config\SAM.iodefrag.bak
2018-04-01 15:36 - 2018-04-01 15:36 - 000024576 _____ C:\Windows\system32\config\SECURITY.iodefrag.bak
2018-04-01 15:36 - 2018-04-01 15:36 - 000000000 ____H C:\asc_rdflag
2018-04-01 14:30 - 2018-04-06 08:04 - 000000000 ____D C:\Program Files (x86)\IObit
2018-04-01 14:30 - 2018-04-03 21:43 - 000000000 ____D C:\Users\TAHER\AppData\Roaming\IObit
2018-04-01 14:23 - 2018-04-01 14:24 - 040337336 _____ (IObit ) C:\Users\TAHER\Desktop\IObit-Malware-Fighter-Setup-beta.exe
2018-04-01 14:10 - 2018-04-01 14:10 - 000154814 _____ C:\Users\TAHER\Desktop\ZHPDiag.txt
2018-03-31 07:35 - 2018-04-01 14:51 - 000003840 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1486325203
2018-03-31 07:35 - 2018-03-31 07:35 - 000001063 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
2018-03-27 20:03 - 2018-03-27 20:03 - 006480880 _____ C:\Windows\system32\FNTCACHE.DAT
2018-03-27 19:57 - 2018-03-27 20:00 - 000000000 ____D C:\AdwCleaner
2018-03-27 19:57 - 2018-03-27 19:57 - 008222496 _____ (Malwarebytes) C:\Users\TAHER\Desktop\adwcleaner_7.0.8.0.exe
2018-03-27 19:26 - 2018-03-27 19:26 - 000000845 _____ C:\DelFix.txt
2018-03-26 22:59 - 2018-03-26 23:00 - 000313366 _____ C:\Users\TAHER\Downloads\WindowsUpdate.diagcab
2018-03-19 21:24 - 2018-03-19 21:24 - 001250816 _____ C:\Users\TAHER\Downloads\MicrosoftEasyFix50202.msi
2018-03-17 23:50 - 2018-03-17 23:51 - 000000000 ____D C:\Users\TAHER\Downloads\Tech tool store tools
2018-03-17 23:50 - 2018-03-17 23:50 - 000000000 ____D C:\ProgramData\Tech Tool Store
2018-03-15 06:15 - 2018-03-02 20:55 - 000834552 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-03-15 06:15 - 2018-03-02 20:55 - 000179704 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-03-14 20:50 - 2018-02-14 23:45 - 000145024 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-03-14 20:50 - 2018-02-13 16:20 - 001994752 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-03-14 20:50 - 2018-02-13 16:20 - 001560064 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-03-14 20:50 - 2018-02-13 16:20 - 000740864 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-03-14 20:50 - 2018-02-13 16:20 - 000655872 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-03-14 20:50 - 2018-02-13 16:20 - 000600576 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-03-14 20:50 - 2018-02-13 16:20 - 000451072 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-03-14 20:50 - 2018-02-13 16:20 - 000380928 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-03-14 20:50 - 2018-02-13 16:20 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-03-14 20:50 - 2018-02-13 16:20 - 000237568 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-09 00:23 - 2017-05-09 02:37 - 000003902 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{9EF4CA9D-8A4B-4D65-904A-E9E4C19D26D5}
2018-04-08 23:42 - 2015-10-21 21:05 - 000000000 ____D C:\Users\TAHER\AppData\Local\CrashDumps
2018-04-08 23:39 - 2018-01-03 14:29 - 000000000 ____D C:\KMPlayer
2018-04-08 22:53 - 2016-11-18 17:57 - 000000000 ____D C:\Users\TAHER\AppData\LocalLow\Mozilla
2018-04-08 20:58 - 2017-12-12 00:05 - 000000000 ____D C:\Users\TAHER\AppData\Roaming\DMCache
2018-04-08 17:21 - 2013-08-22 17:20 - 000000000 ____D C:\Windows\CbsTemp
2018-04-08 12:44 - 2015-09-14 02:22 - 000003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2422561113-3094125170-2170945475-1001
2018-04-08 11:37 - 2013-08-22 16:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-04-07 16:11 - 2017-06-27 10:33 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-04-06 09:39 - 2017-06-27 10:33 - 000000954 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-04-06 09:39 - 2017-06-27 10:33 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-04-06 09:37 - 2018-01-03 14:29 - 000000614 _____ C:\Users\TAHER\Desktop\KMPlayer.lnk
2018-04-04 23:40 - 2015-09-14 02:15 - 000000000 ____D C:\Users\TAHER
2018-04-03 22:27 - 2018-02-23 08:41 - 000000000 ____D C:\ProgramData\ProductData
2018-04-03 21:39 - 2018-02-23 08:39 - 000000000 ____D C:\ProgramData\IObit
2018-04-03 00:09 - 2017-12-12 00:05 - 000000000 ____D C:\Users\TAHER\AppData\Roaming\IDM
2018-04-01 15:55 - 2013-08-22 15:36 - 000000000 ____D C:\Windows\Inf
2018-04-01 15:35 - 2013-08-22 15:25 - 000262144 ___SH C:\Windows\system32\config\BBI
2018-04-01 14:51 - 2017-12-13 06:41 - 000004132 _____ C:\Windows\System32\Tasks\CCleaner Update
2018-04-01 14:33 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\system32\NDF
2018-04-01 14:31 - 2018-02-23 08:40 - 000000000 ____D C:\Users\TAHER\AppData\LocalLow\IObit
2018-04-01 14:10 - 2015-09-18 03:41 - 000000000 ____D C:\Users\TAHER\AppData\Roaming\ZHP
2018-03-31 07:35 - 2017-02-05 22:06 - 000000000 ____D C:\Program Files (x86)\Opera
2018-03-27 19:27 - 2015-09-15 20:09 - 000000000 ____D C:\Program Files\CCleaner
2018-03-24 20:23 - 2015-10-12 17:35 - 000009132 _____ C:\Users\TAHER\Desktop\tt.m3u
2018-03-21 15:20 - 2018-02-20 18:14 - 000002246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-03-21 15:20 - 2018-02-20 18:14 - 000002205 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-03-17 21:27 - 2017-04-22 07:28 - 000002932 _____ C:\Windows\wininit.ini
2018-03-15 06:38 - 2015-09-14 21:08 - 000000000 ____D C:\Windows\system32\appraiser
2018-03-15 06:15 - 2015-09-14 13:15 - 000000000 ____D C:\Windows\system32\MRT
2018-03-15 06:12 - 2017-10-12 15:02 - 130364688 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-03-15 06:12 - 2015-09-14 13:14 - 130364688 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-03-14 02:40 - 2017-03-01 23:49 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager
2018-03-13 21:12 - 2018-01-27 19:54 - 000000000 ____D C:\Users\TAHER\Documents\Adobe
2018-03-13 21:11 - 2017-12-12 00:05 - 000001041 _____ C:\Users\TAHER\Desktop\Internet Download Manager.lnk
==================== Files in the root of some directories =======
2017-12-11 06:43 - 2017-12-11 06:43 - 000000260 _____ () C:\ProgramData\fontcacheev1.dat
Some files in TEMP:
====================
2018-04-06 09:36 - 2018-04-06 09:37 - 036711176 _____ (PandoraTV) C:\Users\TAHER\AppData\Local\Temp\KMP_4.2.2.9.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-04-05 16:52
==================== End of FRST.txt ============================