Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-11-2017 Ran by salem (administrator) on ITTIHAD4EVER (12-11-2017 00:00:15) Running from C:\Users\salem\Desktop Loaded Profiles: salem (Available Profiles: salem) Platform: Windows 8.1 (Update) (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ESET) C:\Program Files\ESET\ESET Smart Security Premium\ekrn.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Nitro PDF Software) C:\Program Files (x86)\Nitro\Pro 9\NitroPDFDriverService9x64.exe () C:\Program Files (x86)\Nitro\Pro 9\Nitro_UpdateService.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek semiconductor) C:\Windows\RTFTrack.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (ESET) C:\Program Files\ESET\ESET Smart Security Premium\egui.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe (Microsoft Corporation) C:\Windows\System32\WWAHost.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [6340312 2013-07-19] (Realtek semiconductor) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [903384 2013-07-24] (Conexant Systems, Inc.) HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security Premium\ecmdS.exe [324216 2017-10-22] (ESET) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2152773553-1524527067-2441255551-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31682144 2015-03-25] (Skype Technologies S.A.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-05-30] ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 212.56.129.228 212.56.132.20 Tcpip\..\Interfaces\{445DE83C-5A0B-4CF0-BC44-AA1A62D9035B}: [DhcpNameServer] 212.56.129.228 212.56.132.20 Tcpip\..\Interfaces\{4D4D0C1F-3036-42AD-AD3D-421C14CF2693}: [DhcpNameServer] 212.56.129.228 212.56.132.20 Internet Explorer: ================== URLSearchHook: [S-1-5-21-2152773553-1524527067-2441255551-1001] ATTENTION => Default URLSearchHook is missing SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2152773553-1524527067-2441255551-1001 -> DefaultScope {224DA4F9-ECD3-4E3D-BCDD-B3C959C0ED72} URL = SearchScopes: HKU\S-1-5-21-2152773553-1524527067-2441255551-1001 -> {224DA4F9-ECD3-4E3D-BCDD-B3C959C0ED72} URL = BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2017-09-12] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2017-08-24] (Microsoft Corporation) BHO-x32: No Name -> {963C8283-AE7F-4AA6-9B3B-847A8FC62C5E} -> No File BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation) Toolbar: HKLM - VIPRE Search Guard Toolbar - {A924C17A-5E94-4E02-BED5-49720BA6F7FA} - No File Toolbar: HKLM-x32 - VIPRE Search Guard Toolbar - {A924C17A-5E94-4E02-BED5-49720BA6F7FA} - No File Handler: vipresg - {47BE2E5B-703B-444F-ABD3-05717D2191C6} - No File FireFox: ======== FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore => not found FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [No File] FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [No File] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2014-08-01] (Nitro PDF) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-04] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-06-04] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-07-19] (Microsoft Corporation) Chrome: ======= CHR DefaultProfile: Default CHR Profile: C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default [2017-11-11] CHR Extension: (Slides) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13] CHR Extension: (Docs) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13] CHR Extension: (Google Drive) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23] CHR Extension: (YouTube) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-03] CHR Extension: (TrafficLight) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfnpidifppmenkapgihekkeednfoenal [2017-09-19] CHR Extension: (Google Search) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29] CHR Extension: (uBlock Adblock Plus) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdecnmmdccnkogcidionikojplkjfgie [2017-10-22] CHR Extension: (Sheets) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13] CHR Extension: (Google Docs Offline) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17] CHR Extension: (Genesis Plus adblocker) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\jacihiikpacjaggdldhcdfjpbibbfjmh [2017-09-13] CHR Extension: (Perceptual Ad Highlighter) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\mahgiflleahghaapkboihnbhdplhnchp [2017-09-13] CHR Extension: (Chrome Web Store Payments) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-13] CHR Extension: (Gmail) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29] CHR Extension: (Chrome Media Router) - C:\Users\salem\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-28] ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S4 BcmBtRSupport; C:\windows\system32\BtwRSupportService.exe [2252504 2013-08-07] (Broadcom Corporation.) S4 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [976600 2013-09-05] (Broadcom Corporation.) R2 ekrn; C:\Program Files\ESET\ESET Smart Security Premium\ekrn.exe [2648184 2017-10-22] (ESET) S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation) S4 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed] S4 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation) S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [272864 2015-12-10] (Lenovo) R2 NitroDriverReadSpool9; C:\Program Files (x86)\Nitro\Pro 9\NitroPDFDriverService9x64.exe [230920 2014-08-01] (Nitro PDF Software) R2 NitroUpdateService; C:\Program Files (x86)\Nitro\Pro 9\Nitro_UpdateService.exe [418312 2014-08-01] () S4 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] () S4 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2014-05-30] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation) S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 bcbtums; C:\windows\system32\drivers\bcbtums.sys [186152 2016-09-14] (Broadcom Corporation.) R3 BCM43XX; C:\windows\system32\DRIVERS\bcmwl63a.sys [7549616 2014-02-25] (Broadcom Corporation) S3 dg_ssudbus; C:\windows\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.) R1 eamonm; C:\windows\System32\DRIVERS\eamonm.sys [132848 2017-10-22] (ESET) R0 edevmon; C:\windows\System32\DRIVERS\edevmon.sys [107344 2017-05-04] (ESET) S0 eelam; C:\windows\System32\DRIVERS\eelam.sys [15392 2017-10-22] (ESET) R1 ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [180088 2017-10-22] (ESET) R2 ekbdflt; C:\windows\system32\DRIVERS\ekbdflt.sys [50752 2017-05-04] (ESET) R1 epfw; C:\windows\system32\DRIVERS\epfw.sys [78192 2017-05-04] (ESET) R1 epfwwfp; C:\windows\system32\DRIVERS\epfwwfp.sys [102160 2017-10-22] (ESET) S3 ESETCleanersDriver; C:\windows\system32\Drivers\ESETCleanersDriver.sys [170280 2015-10-31] (ESET) R3 MEIx64; C:\windows\system32\DRIVERS\TeeDriverx64.sys [118272 2014-04-03] (Intel Corporation) S3 NETwNe64; C:\windows\system32\DRIVERS\NETwew00.sys [3344352 2013-07-08] (Intel Corporation) R3 rtsuvc; C:\windows\system32\DRIVERS\rtsuvc.sys [8247640 2013-07-19] (Realtek Semiconductor Corp.) S3 SmbDrvI; C:\windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-09-13] (Synaptics Incorporated) S3 ssudmdm; C:\windows\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.) U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [24688 2016-01-24] () S3 WdBoot; C:\windows\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation) S3 WdFilter; C:\windows\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation) S3 WdNisDrv; C:\windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation) S3 wsvd; C:\windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink) U0 Compbatt; no ImagePath U2 ERSvc; no ImagePath U2 NIHardwareService; no ImagePath U2 NVSvc; no ImagePath U2 Parvdm; no ImagePath U2 srService; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-11-12 00:00 - 2017-11-12 00:00 - 000013670 _____ C:\Users\salem\Desktop\FRST.txt 2017-11-12 00:00 - 2017-11-12 00:00 - 000000000 ____D C:\FRST 2017-11-11 23:57 - 2017-11-11 23:57 - 002392576 _____ (Farbar) C:\Users\salem\Desktop\FRST64.exe 2017-11-11 23:16 - 2017-11-11 23:16 - 000009486 ____R C:\Users\salem\Desktop\Pre_Scan_11_11_2017_23_16_44.txt 2017-11-11 23:16 - 2017-11-11 23:16 - 000009486 ____R C:\Pre_Scan_11_11_2017_23_16_44.txt 2017-11-11 23:16 - 2017-11-11 23:16 - 000001015 _____ C:\Users\salem\Desktop\Internet Explorer.lnk 2017-11-11 22:58 - 2017-11-11 23:16 - 000000000 ____D C:\Pre_Scan 2017-11-11 17:37 - 2017-11-11 17:37 - 000117152 _____ C:\Users\salem\Desktop\ZHPDiag.txt 2017-11-11 01:27 - 2017-11-11 01:27 - 002930560 _____ C:\Users\salem\Downloads\ZHPDiag3.exe 2017-11-10 21:31 - 2017-11-11 22:37 - 000000000 ____D C:\Users\salem\AppData\Roaming\vlc 2017-11-10 21:31 - 2017-11-10 21:31 - 000001097 _____ C:\Users\Public\Desktop\VLC media player.lnk 2017-11-10 21:31 - 2017-11-10 21:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2017-11-10 21:30 - 2017-11-10 21:30 - 000000000 ____D C:\Program Files (x86)\VideoLAN 2017-11-10 21:29 - 2017-11-10 21:29 - 030950664 _____ C:\Users\salem\Downloads\vlc-2.2.6-win32.exe 2017-11-10 21:26 - 2017-11-11 19:29 - 000000000 ____D C:\Users\salem\Desktop\New folder (5) 2017-11-09 23:07 - 2017-10-11 08:35 - 000143016 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe 2017-11-09 23:07 - 2017-10-10 16:21 - 000463872 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll 2017-11-09 23:07 - 2017-10-10 14:18 - 002023936 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe 2017-11-09 23:07 - 2017-10-10 14:18 - 001570304 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll 2017-11-09 23:07 - 2017-10-10 14:18 - 000670208 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll 2017-11-09 23:07 - 2017-10-10 14:18 - 000605184 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2017-11-09 23:07 - 2017-10-10 14:18 - 000603648 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll 2017-11-09 23:07 - 2017-10-10 14:18 - 000402944 _____ (Microsoft Corporation) C:\windows\system32\centel.dll 2017-11-09 23:07 - 2017-10-10 14:18 - 000370688 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll 2017-11-09 23:07 - 2017-10-10 14:18 - 000241664 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll 2017-11-09 23:07 - 2017-10-10 14:18 - 000181760 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll 2017-11-06 21:51 - 2017-11-06 21:59 - 000002062 _____ C:\Users\salem\Desktop\Rkill.txt 2017-11-02 19:26 - 2017-11-02 19:26 - 001674353 _____ C:\Users\salem\Desktop\Accountant Cover Letter Sample.pdf 2017-10-31 20:15 - 2017-10-31 20:16 - 008261584 _____ (Malwarebytes) C:\Users\salem\Downloads\adwcleaner_7.0.4.0.exe 2017-10-30 23:02 - 2017-10-31 22:46 - 000000000 ____D C:\ProgramData\Immunet 2017-10-30 23:02 - 2017-10-30 23:02 - 000000000 ____H C:\windows\system32\Drivers\Msft_Kernel_ImmunetNetworkMonitor_01009.Wdf 2017-10-30 23:01 - 2017-10-30 23:01 - 001120712 _____ (Cisco Systems, Inc.) C:\Users\salem\Downloads\ImmunetSetup.exe 2017-10-29 14:29 - 2017-10-29 15:04 - 000000000 ____D C:\Users\salem\Desktop\علاج فطومة 2017-10-27 22:08 - 2017-10-27 22:08 - 001209264 _____ (Loaris LLC) C:\Users\salem\Downloads\loaris-trojanremover.exe 2017-10-18 20:13 - 2017-10-05 08:17 - 000380248 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys 2017-10-18 20:13 - 2017-09-15 00:52 - 000986968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys 2017-10-18 20:13 - 2017-09-08 18:14 - 003084288 _____ (Microsoft Corporation) C:\windows\system32\msftedit.dll 2017-10-18 20:13 - 2017-09-08 17:50 - 002471424 _____ (Microsoft Corporation) C:\windows\SysWOW64\msftedit.dll 2017-10-18 20:13 - 2017-09-08 04:31 - 000685440 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll 2017-10-18 20:13 - 2017-09-08 04:28 - 000507176 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll 2017-10-18 20:13 - 2017-09-07 22:31 - 000022528 _____ (Microsoft Corporation) C:\windows\system32\mgmtapi.dll 2017-10-18 20:13 - 2017-09-07 20:20 - 000018944 _____ (Microsoft Corporation) C:\windows\SysWOW64\mgmtapi.dll 2017-10-18 20:13 - 2017-09-07 18:20 - 000513456 _____ C:\windows\SysWOW64\locale.nls 2017-10-18 20:13 - 2017-09-07 18:20 - 000513456 _____ C:\windows\system32\locale.nls 2017-10-18 20:13 - 2017-09-07 14:40 - 000995272 _____ (Microsoft Corporation) C:\windows\system32\ucrtbase.dll 2017-10-18 20:13 - 2017-09-07 14:40 - 000922432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ucrtbase.dll 2017-10-18 20:13 - 2017-09-07 00:07 - 000158552 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys 2017-10-18 20:13 - 2017-09-06 22:17 - 000461144 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys 2017-10-18 20:13 - 2017-09-06 22:17 - 000443224 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys 2017-10-18 20:13 - 2017-09-06 15:14 - 000166400 _____ (Microsoft Corporation) C:\windows\system32\regsvc.dll 2017-10-18 20:13 - 2017-08-11 02:39 - 002779136 _____ (Microsoft Corporation) C:\windows\system32\authui.dll 2017-10-18 20:13 - 2017-08-11 02:30 - 002464256 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll 2017-10-15 14:29 - 2017-10-15 14:29 - 000025965 _____ C:\Users\salem\Downloads\details cv (1).pdf 2017-10-14 01:23 - 2017-10-14 01:23 - 000000000 ____D C:\Users\salem\Documents\ViberDownloads 2017-10-14 01:12 - 2017-10-14 01:12 - 000000000 ____D C:\Users\salem\AppData\Local\Viber Media S.à r.l 2017-10-14 01:12 - 2017-10-14 01:12 - 000000000 ____D C:\Users\salem\AppData\Local\cache ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-11-11 23:17 - 2013-08-22 15:45 - 000000006 ____H C:\windows\Tasks\SA.DAT 2017-11-11 23:14 - 2014-10-04 07:38 - 000003942 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{F4A1D82F-626F-48AE-A597-8E3984B4D806} 2017-11-11 22:34 - 2013-10-07 19:27 - 000866884 _____ C:\windows\system32\PerfStringBackup.INI 2017-11-11 22:34 - 2013-08-22 14:36 - 000000000 ____D C:\windows\Inf 2017-11-11 17:52 - 2016-01-24 16:13 - 000000000 ____D C:\Users\salem\AppData\Local\CrashDumps 2017-11-11 17:39 - 2015-10-24 16:56 - 000000000 ____D C:\Users\salem\AppData\Roaming\ZHP 2017-11-11 01:43 - 2017-04-12 17:44 - 000000000 ____D C:\Users\salem\AppData\Local\ZHP 2017-11-10 22:21 - 2014-10-04 07:07 - 000003600 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2152773553-1524527067-2441255551-1001 2017-11-09 23:22 - 2015-04-20 23:12 - 000000000 ____D C:\windows\system32\appraiser 2017-11-09 23:18 - 2013-08-22 16:20 - 000000000 ____D C:\windows\CbsTemp 2017-11-09 23:17 - 2014-10-06 12:59 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2017-11-09 23:17 - 2013-08-22 14:25 - 000000167 _____ C:\windows\win.ini 2017-11-06 20:55 - 2014-10-06 08:44 - 000002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-11-06 20:55 - 2014-10-06 08:44 - 000002214 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-11-04 18:23 - 2014-10-13 17:46 - 000000000 ____D C:\Users\salem\AppData\Roaming\Nitro PDF 2017-10-31 20:23 - 2013-08-22 14:25 - 000262144 ___SH C:\windows\system32\config\BBI 2017-10-29 14:33 - 2016-04-07 19:35 - 000000000 ____D C:\Users\salem\Desktop\table of content 2017-10-28 18:47 - 2014-10-04 06:59 - 000000000 ____D C:\Users\salem 2017-10-27 21:37 - 2013-08-22 16:36 - 000000000 ____D C:\windows\AppReadiness 2017-10-24 22:09 - 2017-06-04 14:29 - 000835568 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2017-10-24 22:09 - 2017-06-04 14:29 - 000177648 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-10-23 11:57 - 2013-08-22 16:36 - 000000000 ____D C:\windows\system32\NDF 2017-10-22 22:53 - 2016-10-07 21:31 - 000180088 _____ (ESET) C:\windows\system32\Drivers\ehdrv.sys 2017-10-22 22:53 - 2016-10-07 21:31 - 000132848 _____ (ESET) C:\windows\system32\Drivers\eamonm.sys 2017-10-22 22:53 - 2016-10-07 21:31 - 000102160 _____ (ESET) C:\windows\system32\Drivers\epfwwfp.sys 2017-10-22 22:53 - 2016-07-20 23:01 - 000015392 _____ (ESET) C:\windows\system32\Drivers\eelam.sys 2017-10-19 17:36 - 2013-08-22 16:36 - 000000000 ____D C:\windows\rescache ==================== Files in the root of some directories ======= 2014-10-27 16:18 - 2014-10-27 15:54 - 000003407 _____ () C:\Program Files (x86)\backup.wsi 2014-10-27 15:54 - 2014-10-27 15:54 - 000000146 _____ () C:\Program Files (x86)\backupInfo.oki 2014-10-27 15:54 - 2014-10-27 15:54 - 284712639 _____ () C:\Program Files (x86)\backup_000_001.0000 2014-10-27 15:54 - 2014-10-27 15:54 - 000196992 _____ () C:\Program Files (x86)\backup_000_001_0000.dsi 2014-10-27 15:54 - 2014-10-27 15:54 - 013591697 _____ () C:\Program Files (x86)\backup_000_002.0000 2014-10-27 15:54 - 2014-10-27 15:54 - 000131424 _____ () C:\Program Files (x86)\backup_000_002_0000.dsi 2014-10-27 15:54 - 2014-10-27 15:55 - 314605635 _____ () C:\Program Files (x86)\backup_000_003.0000 2014-10-27 15:55 - 2014-10-27 15:55 - 151434804 _____ () C:\Program Files (x86)\backup_000_003.0001 2014-10-27 15:55 - 2014-10-27 15:55 - 000196992 _____ () C:\Program Files (x86)\backup_000_003_0000.dsi 2014-10-27 15:55 - 2014-10-27 16:18 - 314574960 _____ () C:\Program Files (x86)\backup_000_005.0000 2014-10-27 15:55 - 2014-10-27 15:56 - 314577069 _____ () C:\Program Files (x86)\backup_000_005.0001 2014-10-27 15:56 - 2014-10-27 15:56 - 314600763 _____ () C:\Program Files (x86)\backup_000_005.0002 2014-10-27 15:56 - 2014-10-27 15:56 - 314606126 _____ () C:\Program Files (x86)\backup_000_005.0003 2014-10-27 15:56 - 2014-10-27 15:57 - 314588747 _____ () C:\Program Files (x86)\backup_000_005.0004 2014-10-27 15:57 - 2014-10-27 15:57 - 314586793 _____ () C:\Program Files (x86)\backup_000_005.0005 2014-10-27 15:57 - 2014-10-27 15:57 - 314576488 _____ () C:\Program Files (x86)\backup_000_005.0006 2014-10-27 15:57 - 2014-10-27 15:58 - 314589252 _____ () C:\Program Files (x86)\backup_000_005.0007 2014-10-27 15:58 - 2014-10-27 15:58 - 314572934 _____ () C:\Program Files (x86)\backup_000_005.0008 2014-10-27 15:58 - 2014-10-27 15:59 - 314584811 _____ () C:\Program Files (x86)\backup_000_005.0009 2014-10-27 15:59 - 2014-10-27 15:59 - 314622406 _____ () C:\Program Files (x86)\backup_000_005.0010 2014-10-27 15:59 - 2014-10-27 15:59 - 314612281 _____ () C:\Program Files (x86)\backup_000_005.0011 2014-10-27 15:59 - 2014-10-27 15:59 - 314588356 _____ () C:\Program Files (x86)\backup_000_005.0012 2014-10-27 15:59 - 2014-10-27 16:00 - 314594705 _____ () C:\Program Files (x86)\backup_000_005.0013 2014-10-27 16:00 - 2014-10-27 16:00 - 314586316 _____ () C:\Program Files (x86)\backup_000_005.0014 2014-10-27 16:00 - 2014-10-27 16:00 - 314587999 _____ () C:\Program Files (x86)\backup_000_005.0015 2014-10-27 16:00 - 2014-10-27 16:01 - 314597386 _____ () C:\Program Files (x86)\backup_000_005.0016 2014-10-27 16:01 - 2014-10-27 16:01 - 314598323 _____ () C:\Program Files (x86)\backup_000_005.0017 2014-10-27 16:01 - 2014-10-27 16:01 - 314635330 _____ () C:\Program Files (x86)\backup_000_005.0018 2014-10-27 16:01 - 2014-10-27 16:01 - 314596938 _____ () C:\Program Files (x86)\backup_000_005.0019 2014-10-27 16:01 - 2014-10-27 16:02 - 314619777 _____ () C:\Program Files (x86)\backup_000_005.0020 2014-10-27 16:02 - 2014-10-27 16:02 - 314584861 _____ () C:\Program Files (x86)\backup_000_005.0021 2014-10-27 16:02 - 2014-10-27 16:02 - 314579821 _____ () C:\Program Files (x86)\backup_000_005.0022 2014-10-27 16:02 - 2014-10-27 16:02 - 314585309 _____ () C:\Program Files (x86)\backup_000_005.0023 2014-10-27 16:02 - 2014-10-27 16:03 - 314596185 _____ () C:\Program Files (x86)\backup_000_005.0024 2014-10-27 16:03 - 2014-10-27 16:03 - 314608062 _____ () C:\Program Files (x86)\backup_000_005.0025 2014-10-27 16:03 - 2014-10-27 16:03 - 314606927 _____ () C:\Program Files (x86)\backup_000_005.0026 2014-10-27 16:03 - 2014-10-27 16:03 - 314573028 _____ () C:\Program Files (x86)\backup_000_005.0027 2014-10-27 16:03 - 2014-10-27 16:04 - 314578569 _____ () C:\Program Files (x86)\backup_000_005.0028 2014-10-27 16:04 - 2014-10-27 16:04 - 314591262 _____ () C:\Program Files (x86)\backup_000_005.0029 2014-10-27 16:04 - 2014-10-27 16:04 - 314583291 _____ () C:\Program Files (x86)\backup_000_005.0030 2014-10-27 16:04 - 2014-10-27 16:04 - 314588998 _____ () C:\Program Files (x86)\backup_000_005.0031 2014-10-27 16:04 - 2014-10-27 16:05 - 314582296 _____ () C:\Program Files (x86)\backup_000_005.0032 2014-10-27 16:05 - 2014-10-27 16:05 - 314578522 _____ () C:\Program Files (x86)\backup_000_005.0033 2014-10-27 16:05 - 2014-10-27 16:05 - 314580621 _____ () C:\Program Files (x86)\backup_000_005.0034 2014-10-27 16:05 - 2014-10-27 16:06 - 314595873 _____ () C:\Program Files (x86)\backup_000_005.0035 2014-10-27 16:06 - 2014-10-27 16:06 - 314617559 _____ () C:\Program Files (x86)\backup_000_005.0036 2014-10-27 16:06 - 2014-10-27 16:06 - 314590910 _____ () C:\Program Files (x86)\backup_000_005.0037 2014-10-27 16:06 - 2014-10-27 16:07 - 314586659 _____ () C:\Program Files (x86)\backup_000_005.0038 2014-10-27 16:07 - 2014-10-27 16:07 - 314581909 _____ () C:\Program Files (x86)\backup_000_005.0039 2014-10-27 16:07 - 2014-10-27 16:07 - 314577682 _____ () C:\Program Files (x86)\backup_000_005.0040 2014-10-27 16:07 - 2014-10-27 16:07 - 314607766 _____ () C:\Program Files (x86)\backup_000_005.0041 2014-10-27 16:07 - 2014-10-27 16:08 - 314615201 _____ () C:\Program Files (x86)\backup_000_005.0042 2014-10-27 16:08 - 2014-10-27 16:08 - 314607572 _____ () C:\Program Files (x86)\backup_000_005.0043 2014-10-27 16:08 - 2014-10-27 16:08 - 314614191 _____ () C:\Program Files (x86)\backup_000_005.0044 2014-10-27 16:08 - 2014-10-27 16:08 - 314630990 _____ () C:\Program Files (x86)\backup_000_005.0045 2014-10-27 16:08 - 2014-10-27 16:09 - 314614262 _____ () C:\Program Files (x86)\backup_000_005.0046 2014-10-27 16:09 - 2014-10-27 16:09 - 314622674 _____ () C:\Program Files (x86)\backup_000_005.0047 2014-10-27 16:09 - 2014-10-27 16:09 - 314587662 _____ () C:\Program Files (x86)\backup_000_005.0048 2014-10-27 16:09 - 2014-10-27 16:09 - 314625151 _____ () C:\Program Files (x86)\backup_000_005.0049 2014-10-27 16:09 - 2014-10-27 16:09 - 314625946 _____ () C:\Program Files (x86)\backup_000_005.0050 2014-10-27 16:09 - 2014-10-27 16:10 - 314607377 _____ () C:\Program Files (x86)\backup_000_005.0051 2014-10-27 16:10 - 2014-10-27 16:10 - 314582384 _____ () C:\Program Files (x86)\backup_000_005.0052 2014-10-27 16:10 - 2014-10-27 16:10 - 314598957 _____ () C:\Program Files (x86)\backup_000_005.0053 2014-10-27 16:10 - 2014-10-27 16:10 - 314618044 _____ () C:\Program Files (x86)\backup_000_005.0054 2014-10-27 16:10 - 2014-10-27 16:11 - 314626731 _____ () C:\Program Files (x86)\backup_000_005.0055 2014-10-27 16:11 - 2014-10-27 16:11 - 314625362 _____ () C:\Program Files (x86)\backup_000_005.0056 2014-10-27 16:11 - 2014-10-27 16:11 - 314580438 _____ () C:\Program Files (x86)\backup_000_005.0057 2014-10-27 16:11 - 2014-10-27 16:11 - 314595320 _____ () C:\Program Files (x86)\backup_000_005.0058 2014-10-27 16:11 - 2014-10-27 16:12 - 314597871 _____ () C:\Program Files (x86)\backup_000_005.0059 2014-10-27 16:12 - 2014-10-27 16:12 - 314616109 _____ () C:\Program Files (x86)\backup_000_005.0060 2014-10-27 16:12 - 2014-10-27 16:12 - 314578941 _____ () C:\Program Files (x86)\backup_000_005.0061 2014-10-27 16:12 - 2014-10-27 16:12 - 314585692 _____ () C:\Program Files (x86)\backup_000_005.0062 2014-10-27 16:12 - 2014-10-27 16:12 - 314609435 _____ () C:\Program Files (x86)\backup_000_005.0063 2014-10-27 16:12 - 2014-10-27 16:13 - 314628064 _____ () C:\Program Files (x86)\backup_000_005.0064 2014-10-27 16:13 - 2014-10-27 16:13 - 314592999 _____ () C:\Program Files (x86)\backup_000_005.0065 2014-10-27 16:13 - 2014-10-27 16:13 - 314585383 _____ () C:\Program Files (x86)\backup_000_005.0066 2014-10-27 16:13 - 2014-10-27 16:13 - 314630313 _____ () C:\Program Files (x86)\backup_000_005.0067 2014-10-27 16:13 - 2014-10-27 16:13 - 314612905 _____ () C:\Program Files (x86)\backup_000_005.0068 2014-10-27 16:13 - 2014-10-27 16:14 - 314576465 _____ () C:\Program Files (x86)\backup_000_005.0069 2014-10-27 16:14 - 2014-10-27 16:14 - 314609381 _____ () C:\Program Files (x86)\backup_000_005.0070 2014-10-27 16:14 - 2014-10-27 16:14 - 314619416 _____ () C:\Program Files (x86)\backup_000_005.0071 2014-10-27 16:14 - 2014-10-27 16:14 - 314634364 _____ () C:\Program Files (x86)\backup_000_005.0072 2014-10-27 16:14 - 2014-10-27 16:15 - 314597298 _____ () C:\Program Files (x86)\backup_000_005.0073 2014-10-27 16:15 - 2014-10-27 16:15 - 314594510 _____ () C:\Program Files (x86)\backup_000_005.0074 2014-10-27 16:15 - 2014-10-27 16:15 - 314619545 _____ () C:\Program Files (x86)\backup_000_005.0075 2014-10-27 16:15 - 2014-10-27 16:15 - 314613203 _____ () C:\Program Files (x86)\backup_000_005.0076 2014-10-27 16:15 - 2014-10-27 16:15 - 314621506 _____ () C:\Program Files (x86)\backup_000_005.0077 2014-10-27 16:15 - 2014-10-27 16:16 - 314585118 _____ () C:\Program Files (x86)\backup_000_005.0078 2014-10-27 16:16 - 2014-10-27 16:16 - 314576359 _____ () C:\Program Files (x86)\backup_000_005.0079 2014-10-27 16:16 - 2014-10-27 16:16 - 314585705 _____ () C:\Program Files (x86)\backup_000_005.0080 2014-10-27 16:16 - 2014-10-27 16:16 - 314617532 _____ () C:\Program Files (x86)\backup_000_005.0081 2014-10-27 16:16 - 2014-10-27 16:16 - 314605807 _____ () C:\Program Files (x86)\backup_000_005.0082 2014-10-27 16:16 - 2014-10-27 16:17 - 314574891 _____ () C:\Program Files (x86)\backup_000_005.0083 2014-10-27 16:17 - 2014-10-27 16:17 - 314625475 _____ () C:\Program Files (x86)\backup_000_005.0084 2014-10-27 16:17 - 2014-10-27 16:17 - 314634056 _____ () C:\Program Files (x86)\backup_000_005.0085 2014-10-27 16:17 - 2014-10-27 16:17 - 314604737 _____ () C:\Program Files (x86)\backup_000_005.0086 2014-10-27 16:17 - 2014-10-27 16:17 - 314586847 _____ () C:\Program Files (x86)\backup_000_005.0087 2014-10-27 16:17 - 2014-10-27 16:18 - 309170508 _____ () C:\Program Files (x86)\backup_000_005.0088 2014-10-27 16:18 - 2014-10-27 16:18 - 006557088 _____ () C:\Program Files (x86)\backup_000_005_0000.dsi 2014-05-30 18:39 - 2014-05-30 18:39 - 000000000 ____H () C:\ProgramData\DP45977C.lfl 2016-02-05 19:43 - 2016-02-05 19:43 - 000000265 _____ () C:\ProgramData\fontcacheev1.dat Files to move or delete: ==================== C:\ProgramData\fontcacheev1.dat ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\windows\system32\winlogon.exe => File is digitally signed C:\windows\system32\wininit.exe => File is digitally signed C:\windows\explorer.exe => File is digitally signed C:\windows\SysWOW64\explorer.exe => File is digitally signed C:\windows\system32\svchost.exe => File is digitally signed C:\windows\SysWOW64\svchost.exe => File is digitally signed C:\windows\system32\services.exe => File is digitally signed C:\windows\system32\User32.dll => File is digitally signed C:\windows\SysWOW64\User32.dll => File is digitally signed C:\windows\system32\userinit.exe => File is digitally signed C:\windows\SysWOW64\userinit.exe => File is digitally signed C:\windows\system32\rpcss.dll => File is digitally signed C:\windows\system32\dnsapi.dll => File is digitally signed C:\windows\SysWOW64\dnsapi.dll => File is digitally signed C:\windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-11-08 18:48 ==================== End of FRST.txt ============================