Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 18-10-2017 01 Ran by منير (administrator) on WERFLLAH (19-10-2017 21:52:15) Running from C:\Users\منير\Desktop Loaded Profiles: منير (Available Profiles: منير) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: العربية (السعودية)‏ Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ESET) C:\Program Files\ESET\ESET Security\ekrn.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe () C:\Program Files\Antirun\antirun.exe (Tonec Inc.) C:\Program Files\Internet Download Manager\IDMan.exe (TechSmith Corporation) C:\Program Files\TechSmith\Snagit 12\Snagit32.exe (ESET) C:\Program Files\ESET\ESET Security\egui.exe (Tonec Inc.) C:\Program Files\Internet Download Manager\IEMonitor.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (TechSmith Corporation) C:\Program Files\TechSmith\Snagit 12\SnagPriv.exe (TechSmith Corporation) C:\Program Files\TechSmith\Snagit 12\TscHelp.exe (Google Inc.) C:\Program Files\Google\Update\1.3.33.5\GoogleCrashHandler.exe (TechSmith Corporation) C:\Program Files\TechSmith\Snagit 12\SnagitEditor.exe (HUAWEI) C:\Program Files\Cela.C.M_HW\Cela.C.M.EXE (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Antirun] => C:\Program Files\Antirun\antirun.exe [641024 2011-12-13] () HKU\S-1-5-21-3139794459-3927556288-4145378674-1000\...\Run: [IDMan] => C:\Program Files\Internet Download Manager\IDMan.exe [3994736 2016-10-12] (Tonec Inc.) HKU\S-1-5-21-3139794459-3927556288-4145378674-1000\...\Run: [Internet Download Accelerator] => C:\Program Files\IDA\ida.exe -autorun Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snagit 12.lnk [2017-09-21] ShortcutTarget: Snagit 12.lnk -> C:\Program Files\TechSmith\Snagit 12\Snagit32.exe (TechSmith Corporation) GroupPolicy: Restriction ? <==== ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 62.240.32.5 62.68.42.2 Tcpip\..\Interfaces\{04BCD300-FABE-4578-B60B-D50A3888E9F3}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{0AC26475-E91C-4E24-B494-9444090870B1}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{249173E9-5D12-401A-9646-A896B8D1E6FD}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{37FCFF6E-8EDB-4020-918F-1AB07AB36CF9}: [DhcpNameServer] 62.240.32.5 62.68.42.2 Tcpip\..\Interfaces\{5F0384D5-9992-4991-879F-1ED6A81B3F08}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{5F299BF6-10C7-43AD-83FA-AAA125BA4745}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{D09ADE6F-0DAE-4BE5-BA46-E2B91FA7C94F}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{D5710367-1935-48EC-BA55-B21EB59103CF}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.com/?ilc=8 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yahoo.com/?ilc=8 SearchScopes: HKU\S-1-5-21-3139794459-3927556288-4145378674-1000 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=mkg028 BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files\Internet Download Manager\IDMIECC.dll [2016-09-06] (Internet Download Manager, Tonec Inc.) FireFox: ======== FF HKU\S-1-5-21-3139794459-3927556288-4145378674-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\منير\AppData\Roaming\IDM\idmmzcc5 FF Extension: (IDM CC) - C:\Users\منير\AppData\Roaming\IDM\idmmzcc5 [2017-10-19] [not signed] FF HKU\S-1-5-21-3139794459-3927556288-4145378674-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files\Internet Download Manager\idmmzcc2.xpi FF Extension: (IDM integration) - C:\Program Files\Internet Download Manager\idmmzcc2.xpi [2016-09-21] FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files\Yahoo!\Shared\npYState.dll [No File] FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-17] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-17] (Google Inc.) Chrome: ======= CHR HomePage: Default -> msn.com CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC=__PARAM__&q={searchTerms} CHR DefaultSearchKeyword: Default -> bing.com CHR DefaultSuggestURL: Default -> hxxp://www.bing.com/osjson.aspx?FORM=__PARAM__DF&PC=__PARAM__&query={searchTerms} CHR Profile: C:\Users\منير\AppData\Local\Google\Chrome\User Data\Default [2017-10-19] CHR Extension: (المستندات) - C:\Users\منير\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-18] CHR Extension: (Google Drive) - C:\Users\منير\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-10-18] CHR Extension: (Youtube) - C:\Users\منير\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-10-18] CHR Extension: (Bing) - C:\Users\منير\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [2017-10-17] CHR Extension: (مستندات Google في وضع عدم الاتصال) - C:\Users\منير\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-10-17] CHR Extension: (IDM Integration Module) - C:\Users\منير\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2017-10-17] CHR Extension: (Chrome Web Store Payments) - C:\Users\منير\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-10-17] CHR Extension: (Gmail) - C:\Users\منير\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-10-18] CHR Extension: (Chrome Media Router) - C:\Users\منير\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-17] CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files\Internet Download Manager\IDMGCExt.crx [2016-10-01] CHR HKU\S-1-5-21-3139794459-3927556288-4145378674-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2069936 2017-08-09] (ESET) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4430792 2017-08-07] (Malwarebytes) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 bcm; C:\Windows\System32\DRIVERS\drxvi314.sys [324096 2010-06-18] (Beceem communications pvt ltd.) R3 bcmbusctr; C:\Windows\System32\DRIVERS\BcmBusCtr.sys [51072 2010-06-18] (Beceem communications pvt ltd.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [218176 2017-09-28] (DT Soft Ltd) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [113512 2017-08-09] (ESET) R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [90656 2017-03-09] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [139384 2017-03-09] (ESET) R2 ekbdflt; C:\Windows\System32\DRIVERS\ekbdflt.sys [43920 2017-03-09] (ESET) R1 epfw; C:\Windows\System32\DRIVERS\epfw.sys [69304 2017-03-09] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [52680 2017-03-09] (ESET) R1 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [86504 2017-03-09] (ESET) S3 hid7906; C:\Windows\System32\drivers\hid7906.sys [41272 2008-08-08] (Your Corporation) S3 hid8101; C:\Windows\System32\drivers\hid8101.sys [43192 2008-08-08] (Your Corporation) S3 hid8103; C:\Windows\System32\drivers\hid8103.sys [31140 2007-09-21] (Compuware Corporation) [File not signed] R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [221112 2017-10-19] (Malwarebytes) S2 SCRCAMHRDRV; C:\Windows\System32\DRIVERS\SCRCAMHRDRV.sys [233096 2012-10-11] (Windows (R) Server 2003 DDK provider) U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [24688 2017-05-12] () S3 h647906; system32\drivers\h647906.sys [X] S3 h648101; system32\drivers\h648101.sys [X] S3 h648103; system32\drivers\h648103.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-10-19 21:52 - 2017-10-19 21:54 - 000010413 _____ C:\Users\منير\Desktop\FRST.txt 2017-10-19 21:51 - 2017-10-19 21:52 - 000000000 ____D C:\FRST 2017-10-19 21:51 - 2017-10-19 21:45 - 001798656 _____ (Farbar) C:\Users\منير\Desktop\FRST.exe 2017-10-19 21:43 - 2017-10-19 21:43 - 001344696 _____ C:\Users\منير\Downloads\لم يتم تأكيده 398334.crdownload 2017-10-19 16:40 - 2017-10-19 16:43 - 000158826 _____ C:\Users\منير\Downloads\audioclip-1466467127000-38266.mp4 2017-10-19 14:51 - 2017-10-19 14:51 - 000003377 _____ C:\Users\منير\Desktop\ZHPFixReport.txt 2017-10-19 14:50 - 2017-10-19 14:50 - 000000000 ____D C:\Users\منير\Desktop\Quarantine 2017-10-19 14:49 - 2017-10-19 10:26 - 003067264 _____ (Nicolas Coolman) C:\Users\منير\Desktop\ZHPFix.exe 2017-10-19 10:27 - 2017-10-19 10:29 - 000006492 _____ C:\Users\منير\Desktop\مستند نصي جديد ‫(4)‬.txt 2017-10-19 10:25 - 2017-10-19 10:26 - 003067264 _____ (Nicolas Coolman) C:\Users\منير\Downloads\ZHPFix.exe 2017-10-18 15:59 - 2017-10-18 15:59 - 000000000 ____D C:\Users\منير\Downloads\SalityKiller 2017-10-18 15:39 - 2017-10-18 15:58 - 000170498 _____ C:\Users\منير\Downloads\SalityKiller.rar 2017-10-18 11:26 - 2017-10-18 11:26 - 000000819 _____ C:\Users\منير\Desktop\ZHPDiag.lnk 2017-10-18 11:21 - 2017-10-18 11:20 - 002914176 _____ C:\Users\منير\Desktop\ZHPDiag3.exe 2017-10-18 11:18 - 2017-10-18 11:20 - 002914176 _____ C:\Users\منير\Downloads\ZHPDiag3.exe 2017-10-17 22:07 - 2017-10-17 22:52 - 013483168 _____ C:\Users\منير\Downloads\لم يتم تأكيده 873402.crdownload 2017-10-17 21:50 - 2017-10-17 21:50 - 000002221 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-10-17 21:50 - 2017-10-17 21:50 - 000002209 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-10-17 21:20 - 2017-10-18 10:12 - 000000000 ____D C:\Users\منير\AppData\Local\Google 2017-10-17 21:20 - 2017-10-17 21:49 - 000000000 ____D C:\Program Files\Google 2017-10-17 21:00 - 2017-10-17 21:04 - 000000520 _____ C:\Users\منير\Desktop\مواقع.txt 2017-10-17 19:13 - 2017-10-17 19:13 - 000000000 ____D C:\Users\منير\AppData\Local\ElevatedDiagnostics 2017-10-17 18:07 - 2017-10-17 18:07 - 000004608 _____ C:\Users\منير\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2017-10-16 19:13 - 2017-10-16 19:13 - 000288496 _____ C:\Windows\system32\FNTCACHE.DAT 2017-10-14 23:17 - 2017-10-14 23:17 - 000069400 _____ C:\Users\منير\AppData\Local\GDIPFONTCACHEV1.DAT 2017-10-14 14:30 - 2017-10-19 21:27 - 000221112 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2017-10-14 14:29 - 2017-10-14 14:29 - 000002028 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-10-14 14:29 - 2017-10-14 14:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-10-14 14:29 - 2017-10-04 13:15 - 000059904 _____ C:\Windows\system32\Drivers\mbae.sys 2017-10-14 14:28 - 2017-10-14 14:28 - 000000000 ____D C:\ProgramData\Malwarebytes 2017-10-14 14:28 - 2017-10-14 14:28 - 000000000 ____D C:\Program Files\Malwarebytes 2017-10-14 10:32 - 2017-10-14 10:32 - 000000000 ____D C:\Users\منير\AppData\Roaming\TechSmith 2017-10-13 10:49 - 2017-10-13 10:49 - 000000000 ____D C:\ProgramData\Mirillis 2017-10-13 10:46 - 2017-10-13 10:46 - 000001989 _____ C:\Users\Public\Desktop\Action!.lnk 2017-10-13 10:46 - 2017-10-13 10:46 - 000000000 ____D C:\Program Files\Mirillis 2017-10-11 20:30 - 2017-10-11 20:30 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2017-10-11 16:49 - 2017-10-11 16:49 - 124059592 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe 2017-10-11 16:35 - 2017-09-13 17:13 - 004001512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2017-10-11 16:35 - 2017-09-13 17:13 - 003945704 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-10-11 16:35 - 2017-09-13 17:13 - 000137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2017-10-11 16:35 - 2017-09-13 17:13 - 000067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2017-10-11 16:35 - 2017-09-13 17:10 - 001310528 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-10-11 16:35 - 2017-09-13 17:09 - 000830464 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2017-10-11 16:35 - 2017-09-13 17:09 - 000828928 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll 2017-10-11 16:35 - 2017-09-13 17:09 - 000428032 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll 2017-10-11 16:35 - 2017-09-13 17:09 - 000392704 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll 2017-10-11 16:35 - 2017-09-13 17:09 - 000083968 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll 2017-10-11 16:35 - 2017-09-13 17:09 - 000080896 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll 2017-10-11 16:35 - 2017-09-13 16:53 - 000271360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys 2017-10-11 16:35 - 2017-09-13 16:46 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-10-11 16:35 - 2017-09-09 01:47 - 000347344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-10-11 16:35 - 2017-09-08 17:14 - 001213672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2017-10-11 16:35 - 2017-09-08 17:10 - 001549824 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2017-10-11 16:35 - 2017-09-08 17:10 - 001363968 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll 2017-10-11 16:35 - 2017-09-08 17:10 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll 2017-10-11 16:35 - 2017-09-08 17:09 - 000306688 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2017-10-11 16:35 - 2017-09-08 16:50 - 002402304 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-10-11 16:35 - 2017-09-08 16:20 - 000640512 _____ (Microsoft Corporation) C:\Windows\system32\mswstr10.dll 2017-10-11 16:35 - 2017-09-08 16:20 - 000345088 _____ (Microsoft Corporation) C:\Windows\system32\msexcl40.dll 2017-10-11 16:35 - 2017-09-08 16:20 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\msjint40.dll 2017-10-11 16:35 - 2017-09-07 21:10 - 000499200 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-10-11 16:35 - 2017-09-07 21:04 - 020267008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-10-11 16:35 - 2017-09-07 21:03 - 002292736 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-10-11 16:35 - 2017-09-07 20:58 - 000663040 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-10-11 16:35 - 2017-09-07 20:52 - 000667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-10-11 16:35 - 2017-09-07 20:39 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-10-11 16:35 - 2017-09-07 20:37 - 000279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-10-11 16:35 - 2017-09-07 20:29 - 004547072 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-10-11 16:35 - 2017-09-07 20:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-10-11 16:35 - 2017-09-07 20:26 - 000694784 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-10-11 16:35 - 2017-09-07 20:26 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-10-11 16:35 - 2017-09-07 20:25 - 002058752 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-10-11 16:35 - 2017-09-07 20:25 - 001155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-10-11 16:35 - 2017-09-07 20:17 - 013677568 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-10-11 16:35 - 2017-09-07 20:01 - 002767872 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-10-11 16:35 - 2017-09-07 19:57 - 001316864 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-10-11 16:35 - 2017-09-07 17:12 - 002755072 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll 2017-10-11 16:35 - 2017-09-07 16:48 - 000313856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-10-11 16:35 - 2017-09-07 16:48 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys 2017-10-11 16:34 - 2017-09-13 17:09 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2017-10-11 16:34 - 2017-09-13 17:09 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2017-10-11 16:34 - 2017-09-13 17:09 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-10-11 16:34 - 2017-09-13 17:09 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2017-10-11 16:34 - 2017-09-13 17:09 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2017-10-11 16:34 - 2017-09-13 17:09 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2017-10-11 16:34 - 2017-09-13 17:09 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2017-10-11 16:34 - 2017-09-13 17:09 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2017-10-11 16:34 - 2017-09-13 17:09 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-10-11 16:34 - 2017-09-13 17:09 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2017-10-11 16:34 - 2017-09-13 17:09 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2017-10-11 16:34 - 2017-09-13 17:09 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2017-10-11 16:34 - 2017-09-13 17:09 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2017-10-11 16:34 - 2017-09-13 17:09 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2017-10-11 16:34 - 2017-09-13 17:08 - 001062912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-10-11 16:34 - 2017-09-13 17:08 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2017-10-11 16:34 - 2017-09-13 17:08 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2017-10-11 16:34 - 2017-09-13 17:08 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-10-11 16:34 - 2017-09-13 17:08 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-10-11 16:34 - 2017-09-13 17:08 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2017-10-11 16:34 - 2017-09-13 17:08 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2017-10-11 16:34 - 2017-09-13 17:08 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2017-10-11 16:34 - 2017-09-13 17:08 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2017-10-11 16:34 - 2017-09-13 16:50 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2017-10-11 16:34 - 2017-09-13 16:50 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2017-10-11 16:34 - 2017-09-13 16:50 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2017-10-11 16:34 - 2017-09-13 16:50 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2017-10-11 16:34 - 2017-09-13 16:50 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2017-10-11 16:34 - 2017-09-13 16:48 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2017-10-11 16:34 - 2017-09-13 16:46 - 000124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2017-10-11 16:34 - 2017-09-13 16:46 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-10-11 16:34 - 2017-09-13 16:46 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2017-10-11 16:34 - 2017-09-13 16:46 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2017-10-11 16:34 - 2017-09-13 16:46 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2017-10-11 16:34 - 2017-09-13 16:46 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2017-10-11 16:34 - 2017-09-08 17:09 - 001400320 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2017-10-11 16:34 - 2017-09-08 17:09 - 000666624 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2017-10-11 16:34 - 2017-09-08 17:09 - 000337408 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2017-10-11 16:34 - 2017-09-08 17:09 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2017-10-11 16:34 - 2017-09-08 17:09 - 000104448 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2017-10-11 16:34 - 2017-09-08 17:09 - 000059392 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2017-10-11 16:34 - 2017-09-08 17:09 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2017-10-11 16:34 - 2017-09-08 17:00 - 000427520 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2017-10-11 16:34 - 2017-09-08 17:00 - 000164352 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2017-10-11 16:34 - 2017-09-08 16:59 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2017-10-11 16:34 - 2017-09-08 16:59 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2017-10-11 16:34 - 2017-09-07 21:27 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-10-11 16:34 - 2017-09-07 21:26 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-10-11 16:34 - 2017-09-07 21:11 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-10-11 16:34 - 2017-09-07 21:10 - 000341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-10-11 16:34 - 2017-09-07 21:10 - 000047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-10-11 16:34 - 2017-09-07 21:09 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-10-11 16:34 - 2017-09-07 21:03 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-10-11 16:34 - 2017-09-07 21:02 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-10-11 16:34 - 2017-09-07 20:59 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-10-11 16:34 - 2017-09-07 20:58 - 000620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-10-11 16:34 - 2017-09-07 20:58 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-10-11 16:34 - 2017-09-07 20:58 - 000104960 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-10-11 16:34 - 2017-09-07 20:49 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-10-11 16:34 - 2017-09-07 20:44 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2017-10-11 16:34 - 2017-09-07 20:44 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-10-11 16:34 - 2017-09-07 20:43 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-10-11 16:34 - 2017-09-07 20:40 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-10-11 16:34 - 2017-09-07 20:36 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-10-11 16:34 - 2017-09-07 19:57 - 000710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-10-11 16:34 - 2017-09-07 16:48 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys 2017-10-08 22:07 - 2017-10-08 22:43 - 000000000 ____D C:\Users\منير\Documents\Snagit طوابع 2017-10-04 03:16 - 2017-10-15 00:04 - 000099840 ___SH C:\Users\منير\Thumbs.db 2017-10-02 22:44 - 2017-10-02 22:44 - 000000923 _____ C:\Users\منير\Documents\hosts.txt 2017-10-02 11:20 - 2017-10-02 11:20 - 000000000 ____D C:\Users\منير\AppData\Roaming\Mirillis 2017-10-02 11:18 - 2017-10-13 10:56 - 000000000 ____D C:\Users\منير\AppData\Local\Mirillis 2017-10-02 11:18 - 2017-10-02 11:18 - 000000000 ____D C:\Users\منير\Documents\Action! 2017-10-02 11:16 - 2017-10-13 10:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mirillis 2017-09-29 17:33 - 2017-08-19 17:10 - 003209216 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2017-09-29 17:33 - 2017-08-19 17:10 - 000103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2017-09-29 17:33 - 2017-08-19 17:10 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2017-09-29 17:33 - 2017-08-19 16:57 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2017-09-29 17:33 - 2017-08-19 16:57 - 000023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2017-09-29 17:33 - 2017-08-14 19:35 - 000827904 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2017-09-29 17:33 - 2017-08-14 19:35 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll 2017-09-29 17:33 - 2017-08-13 23:36 - 000920064 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2017-09-29 17:33 - 2017-08-13 23:36 - 000134656 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2017-09-29 17:33 - 2017-08-13 23:35 - 000031744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2017-09-29 17:33 - 2017-08-13 23:35 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2017-09-29 14:20 - 2017-09-29 14:20 - 000000000 ____D C:\Windows\system32\dllcache 2017-09-28 15:39 - 2017-09-28 15:39 - 000000000 ____D C:\Users\منير\AppData\Roaming\DAEMON Tools Lite 2017-09-28 15:37 - 2017-09-28 15:37 - 000000000 ____D C:\ProgramData\DAEMON Tools Lite 2017-09-23 23:26 - 2017-09-25 18:18 - 000000000 ____D C:\Users\منير\Documents\Snagit Stamps 2017-09-22 21:43 - 2017-09-22 21:43 - 000000000 ____D C:\Users\منير\AppData\Roaming\Macromedia 2017-09-22 21:43 - 2017-09-22 21:43 - 000000000 ____D C:\Users\منير\AppData\Local\ApplicationHistory 2017-09-22 16:44 - 2017-09-22 16:44 - 000000000 ____D C:\Users\منير\AppData\Roaming\GameCards 2017-09-22 16:37 - 2017-09-22 16:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hamed 2017-09-22 16:23 - 2017-09-22 16:23 - 000000000 ____D C:\Users\منير\AppData\Roaming\Hamed 2017-09-21 18:30 - 2017-09-21 18:30 - 000000000 ____D C:\ProgramData\regid.1995-08.com.techsmith 2017-09-21 18:30 - 2017-09-21 18:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith 2017-09-21 18:29 - 2017-09-21 18:29 - 000000000 ____D C:\Program Files\Common Files\TechSmith Shared 2017-09-21 18:28 - 2017-09-21 18:29 - 000000000 ____D C:\ProgramData\TechSmith 2017-09-21 18:28 - 2017-09-21 18:28 - 000000000 ____D C:\Program Files\TechSmith 2017-09-21 18:26 - 2017-09-21 18:27 - 000000000 ____D C:\ProgramData\Package Cache ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-10-19 21:45 - 2009-07-14 06:34 - 000030080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-10-19 21:45 - 2009-07-14 06:34 - 000030080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-10-19 21:27 - 2009-07-14 06:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2017-10-19 16:37 - 2017-04-25 21:55 - 000000000 ____D C:\Users\منير\AppData\Roaming\ZHP 2017-10-19 16:03 - 2017-08-21 18:53 - 000000000 ____D C:\Users\منير\AppData\Roaming\DMCache 2017-10-18 17:30 - 2009-07-14 04:04 - 000000219 _____ C:\Windows\system.ini 2017-10-18 15:33 - 2017-08-21 18:53 - 000000000 ____D C:\Users\منير\AppData\Roaming\IDM 2017-10-18 11:48 - 2017-05-14 00:07 - 000000000 ____D C:\Users\منير\AppData\Local\ZHP 2017-10-18 09:54 - 2017-05-31 13:16 - 000000000 ____D C:\Users\منير\Downloads\Video 2017-10-17 17:59 - 2017-08-19 17:23 - 000000000 ____D C:\Users\منير\AppData\Roaming\MPC-HC 2017-10-17 14:47 - 2017-08-23 20:15 - 000000000 ____D C:\Program Files\UltraISO 2017-10-16 19:13 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\inf 2017-10-15 00:05 - 2017-04-17 21:33 - 000000000 ____D C:\Users\منير 2017-10-12 16:54 - 2010-11-21 15:37 - 000682428 _____ C:\Windows\system32\perfh00C.dat 2017-10-12 16:54 - 2010-11-21 15:37 - 000478928 _____ C:\Windows\system32\perfh001.dat 2017-10-12 16:54 - 2010-11-21 15:37 - 000130100 _____ C:\Windows\system32\perfc00C.dat 2017-10-12 16:54 - 2010-11-21 15:37 - 000094722 _____ C:\Windows\system32\perfc001.dat 2017-10-12 16:54 - 2010-11-20 23:01 - 002155436 _____ C:\Windows\system32\PerfStringBackup.INI 2017-10-12 13:23 - 2017-07-18 10:45 - 000002144 _____ C:\Users\منير\Desktop\مستند نصي جديد ‫(3)‬.txt 2017-10-12 12:10 - 2017-05-29 13:28 - 000000000 ____D C:\Users\منير\AppData\Local\CrashDumps 2017-10-11 19:59 - 2017-06-09 12:10 - 000000564 _____ C:\Users\منير\Desktop\مستند نصي جديد ‫(2)‬.txt 2017-10-11 16:58 - 2017-04-19 16:13 - 000000000 ____D C:\Windows\system32\MRT 2017-10-11 16:44 - 2017-04-19 16:13 - 124059592 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-10-08 14:28 - 2009-07-14 06:53 - 000032570 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2017-10-01 14:20 - 2017-05-31 13:16 - 000000000 ____D C:\Users\منير\Downloads\Compressed 2017-09-28 15:37 - 2017-08-17 16:06 - 000218176 _____ (DT Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys 2017-09-25 22:13 - 2017-04-24 02:37 - 000000000 ____D C:\Users\منير\Desktop\Picosmos Capture 2017-09-22 21:41 - 2017-09-05 01:31 - 000000000 ____D C:\Users\منير\AppData\Local\WhatsApp 2017-09-22 21:41 - 2017-09-05 01:05 - 000000000 ____D C:\Users\منير\AppData\Roaming\WhatsApp 2017-09-22 21:41 - 2017-08-21 18:53 - 000000000 ____D C:\Program Files\Internet Download Manager 2017-09-22 21:41 - 2017-05-04 11:50 - 000000000 ____D C:\Program Files\Notepad++ 2017-09-22 21:41 - 2017-04-26 10:46 - 000000000 ____D C:\Users\منير\AppData\Local\AvgSetupLog 2017-09-22 21:41 - 2017-04-20 11:04 - 000000000 ____D C:\Users\منير\AppData\Local\SquirrelTemp 2017-09-22 21:41 - 2009-07-14 04:37 - 000000000 ____D C:\Windows\system32\Msdtc 2017-09-21 18:28 - 2017-09-18 01:11 - 000000000 ____D C:\Users\منير\AppData\Local\TechSmith 2017-09-21 17:42 - 2017-09-17 03:18 - 000000000 ____D C:\Users\منير\Documents\Snagit ==================== Files in the root of some directories ======= 2017-10-17 18:07 - 2017-10-17 18:07 - 000004608 _____ () C:\Users\منير\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2017-04-19 15:06 - 2017-05-12 00:19 - 000007649 _____ () C:\Users\منير\AppData\Local\Resmon.ResmonCfg 2017-07-27 18:37 - 2016-07-31 15:11 - 000000302 _____ () C:\ProgramData\Clen Temp.bat 2017-07-27 18:37 - 2016-08-09 18:10 - 000000316 _____ () C:\ProgramData\Clen Temp.reg Files to move or delete: ==================== C:\ProgramData\Clen Temp.bat C:\ProgramData\Clen Temp.reg ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-08-22 14:23 ==================== End of FRST.txt ============================