Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018 Ran by TAHER (administrator) on TITO (09-04-2018 00:37:06) Running from C:\Users\TAHER\Desktop Loaded Profiles: TAHER (Available Profiles: TAHER) Platform: Windows 8.1 Pro (Update) (X64) Language: العربية (السعودية)‏ Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ESET) C:\Program Files\ESET\ESET Security\ekrn.exe () C:\Program Files\Broadcom\CV\bin\UshUpgradeService.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Broadcom Corporation) C:\Program Files\Broadcom\CV\bin\HostControlService.exe (Broadcom Corporation) C:\Program Files\Broadcom\CV\bin\HostStorageService.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe (ESET) C:\Program Files\ESET\ESET Security\egui.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [324352 2017-12-21] (ESET) HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10249048 2017-12-01] (Piriform Ltd) HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [4096056 2018-03-01] (Tonec Inc.) HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1 GroupPolicy: Restriction <==== ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{62857839-62F3-4A1A-A628-07796BA66EB4}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{62857839-62F3-4A1A-A628-07796BA66EB4}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Internet Explorer: ================== URLSearchHook: [S-1-5-21-2422561113-3094125170-2170945475-1001] ATTENTION => Default URLSearchHook is missing BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2017-12-14] (Internet Download Manager, Tonec Inc.) BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2017-12-14] (Internet Download Manager, Tonec Inc.) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation) Toolbar: HKLM-x32 - SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItIEAddin.dll [2007-05-16] (TechSmith Corporation) FireFox: ======== FF DefaultProfile: g4k87b2p.default FF ProfilePath: C:\Users\TAHER\AppData\Roaming\Mozilla\Firefox\Profiles\g4k87b2p.default [2018-04-08] FF user.js: detected! => C:\Users\TAHER\AppData\Roaming\Mozilla\Firefox\Profiles\g4k87b2p.default\user.js [2018-04-01] FF Session Restore: Mozilla\Firefox\Profiles\g4k87b2p.default -> is enabled. FF Extension: (آدبلوك بلس) - C:\Users\TAHER\AppData\Roaming\Mozilla\Firefox\Profiles\g4k87b2p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-02-25] FF Extension: (TLS 1.3 gradual roll-out) - C:\Users\TAHER\AppData\Roaming\Mozilla\Firefox\Profiles\g4k87b2p.default\features\{1a1f6eed-fd84-4fed-be44-a866a0872c12}\tls13-rollout-bug1442042@mozilla.org.xpi [2018-04-08] [Legacy] FF HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Firefox\Extensions: [mozilla_cc3@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi FF Extension: (IDM Integration Module) - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2018-02-28] FF HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-12-20] [Legacy] FF HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\TAHER\AppData\Roaming\IDM\idmmzcc5 FF Extension: (IDM CC) - C:\Users\TAHER\AppData\Roaming\IDM\idmmzcc5 [2017-12-12] [Legacy] [not signed] FF HKU\S-1-5-21-2422561113-3094125170-2170945475-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2018-02-24] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2018-02-24] () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-19] (Foxit Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-02-20] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-02-20] (Google Inc.) Chrome: ======= CHR DefaultSearchKeyword: Default -> lp CHR Session Restore: Default -> is enabled. CHR Profile: C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default [2018-04-09] CHR Extension: (ترجمة Google) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2018-02-20] CHR Extension: (المستندات) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-20] CHR Extension: (Google Drive) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-20] CHR Extension: (Youtube) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-20] CHR Extension: (آدبلوك بلس) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-02-20] CHR Extension: (ZenMate VPN - Best Cyber Security & Unblock) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2018-03-03] CHR Extension: (جداول البيانات) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-20] CHR Extension: (مستندات Google في وضع عدم الاتصال) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-02-20] CHR Extension: (LastPass: Free Password Manager) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2018-03-29] CHR Extension: (Emoji Keyboard (2016) by EmojiOne™) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipdjnhgkpapgippgcgkfcbpdpcgifncb [2018-02-20] CHR Extension: (InstaG Downloader) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnkdcmgmnegofdddphijckfagibepdlb [2018-04-03] CHR Extension: (DotVPN – أفضل من الشبكة الخاصة الافتراضية.) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpiecbcckbofpmkkkdibbllpinceiihk [2018-02-20] CHR Extension: (IDM Integration Module) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2018-03-06] CHR Extension: (Chrome Web Store Payments) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03] CHR Extension: (Gmail) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-02-20] CHR Extension: (Chrome Media Router) - C:\Users\TAHER\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-10] CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-03-01] CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2018-03-01] Opera: ======= OPR Extension: (ZenMate VPN - Best Cyber Security & Unblock) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\cnhbkkedmelfmalgjpkngiaoifpdfcnl [2018-02-22] OPR Extension: (DotVPN — a better way to VPN) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\hiegahbgoabbpoieploedhfnobmpgbeg [2018-02-21] OPR Extension: (LastPass: Free Password Manager) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\hnjalnkldgigidggphhmacmimbdlafdo [2017-12-15] OPR Extension: (IDM Integration Module) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2018-04-06] OPR Extension: (Adblock Plus) - C:\Users\TAHER\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2018-01-29] ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AeLookupSvc; C:\Windows\System32\aelupsvc.dll [214528 2014-11-21] (Microsoft Corporation) [File not signed] S4 ApHidMonitorService; C:\Program Files\DellTPad\HidMonitorSvc.exe [87384 2015-09-16] (Alps Electric Co., Ltd.) S3 DeviceAssociationService; C:\Windows\system32\das.dll [407040 2014-11-21] (Microsoft Corporation) [File not signed] S3 dot3svc; C:\Windows\System32\dot3svc.dll [262144 2014-11-21] (Microsoft Corporation) [File not signed] R2 DPS; C:\Windows\system32\dps.dll [174080 2014-11-21] (Microsoft Corporation) [File not signed] S3 DsmSvc; C:\Windows\System32\DeviceSetupManager.dll [206848 2014-11-21] (Microsoft Corporation) [File not signed] R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [1940584 2017-12-21] (ESET) R2 EventSystem; C:\Windows\system32\es.dll [516608 2014-11-21] (Microsoft Corporation) [File not signed] S3 FDResPub; C:\Windows\system32\fdrespub.dll [34816 2014-11-21] (Microsoft Corporation) [File not signed] S3 FoxitReaderService; C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [1659592 2017-02-24] (Foxit Software Inc.) S3 hidserv; C:\Windows\SysWOW64\hidserv.dll [30720 2014-11-21] (Microsoft Corporation) [File not signed] R2 hostcontrolsvc; C:\Program Files\Broadcom\CV\bin\HostControlService.exe [1038336 2018-04-01] (Broadcom Corporation) R2 hoststoragesvc; C:\Program Files\Broadcom\CV\bin\HostStorageService.exe [42496 2018-04-01] (Broadcom Corporation) S3 IEEtwCollectorService; C:\Windows\system32\IEEtwCollector.exe [116224 2018-01-02] (Microsoft Corporation) [File not signed] S3 KtmRm; C:\Windows\system32\msdtckrm.dll [373248 2014-11-21] (Microsoft Corporation) [File not signed] S3 MSDTC; C:\Windows\System32\msdtc.exe [144384 2014-11-21] (Microsoft Corporation) [File not signed] S3 Netman; C:\Windows\System32\netman.dll [266752 2014-11-21] (Microsoft Corporation) [File not signed] S3 pla; C:\Windows\system32\pla.dll [1526784 2014-11-21] (Microsoft Corporation) [File not signed] S3 RasAuto; C:\Windows\System32\rasauto.dll [102912 2014-11-21] (Microsoft Corporation) [File not signed] S3 RasMan; C:\Windows\System32\rasmans.dll [542720 2017-08-06] (Microsoft Corporation) [File not signed] R2 SENS; C:\Windows\System32\sens.dll [73728 2014-11-21] (Microsoft Corporation) [File not signed] R2 ShellHWDetection; C:\Windows\System32\shsvcs.dll [640000 2014-11-21] (Microsoft Corporation) [File not signed] R3 SSDPSRV; C:\Windows\System32\ssdpsrv.dll [249344 2014-11-21] (Microsoft Corporation) [File not signed] S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [17920 2014-11-21] (Microsoft Corporation) [File not signed] S3 svsvc; C:\Windows\system32\svsvc.dll [13312 2014-11-21] (Microsoft Corporation) [File not signed] S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] R3 swprv; C:\Windows\System32\swprv.dll [706048 2014-11-21] (Microsoft Corporation) [File not signed] S3 TabletInputService; C:\Windows\System32\TabSvc.dll [154112 2017-09-09] (Microsoft Corporation) [File not signed] R2 Themes; C:\Windows\system32\themeservice.dll [59392 2014-11-21] (Microsoft Corporation) [File not signed] S3 TrustedInstaller; C:\Windows\servicing\TrustedInstaller.exe [106496 2014-11-21] (Microsoft Corporation) [File not signed] S3 UI0Detect; C:\Windows\system32\UI0Detect.exe [41984 2014-11-21] (Microsoft Corporation) [File not signed] S3 upnphost; C:\Windows\System32\upnphost.dll [457728 2014-11-21] (Microsoft Corporation) [File not signed] R2 ushupgradesvc; C:\Program Files\Broadcom\CV\bin\UshUpgradeService.exe [259584 2018-04-01] () S3 vds; C:\Windows\System32\vds.exe [1313792 2014-11-21] (Microsoft Corporation) [File not signed] R2 Wcmsvc; C:\Windows\System32\wcmsvc.dll [374784 2014-11-21] (Microsoft Corporation) [File not signed] R3 WdiServiceHost; C:\Windows\system32\wdi.dll [95744 2014-11-21] (Microsoft Corporation) [File not signed] R3 WdiSystemHost; C:\Windows\system32\wdi.dll [95744 2014-11-21] (Microsoft Corporation) [File not signed] S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation) S3 WEPHOSTSVC; C:\Windows\system32\wephostsvc.dll [26112 2014-11-21] (Microsoft Corporation) [File not signed] S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation) S3 WMPNetworkSvc; C:\Program Files\Windows Media Player\wmpnetwk.exe [1478144 2014-11-21] (Microsoft Corporation) [File not signed] S3 WwanSvc; C:\Windows\System32\wwansvc.dll [513536 2014-11-21] (Microsoft Corporation) [File not signed] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 cpuz143; C:\Windows\temp\cpuz143\cpuz143_x64.sys [48960 2018-04-03] (CPUID) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [134368 2017-11-07] (ESET) R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [107328 2017-11-07] (ESET) S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15872 2018-02-19] (ESET) R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [180088 2017-11-07] (ESET) R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [50744 2017-11-07] (ESET) R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [81880 2017-11-07] (ESET) R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [106304 2017-11-07] (ESET) S3 ESETCleanersDriver; C:\Windows\system32\Drivers\ESETCleanersDriver.sys [181160 2017-12-10] (ESET) R3 ETDSMBus; C:\Windows\System32\drivers\ETDSMBus.sys [32840 2017-07-11] (ELAN Microelectronic Corp.) R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-07-17] (REALiX(tm)) S3 Impcd; C:\Windows\System32\drivers\Impcd.sys [158976 2015-11-29] (Intel Corporation) [File not signed] S3 MsBridge; C:\Windows\system32\DRIVERS\bridge.sys [115712 2014-11-21] (Microsoft Corporation) [File not signed] S3 NDProxy; C:\Windows\System32\Drivers\NDProxy.sys [72192 2018-01-02] (Microsoft Corporation) [File not signed] R2 Ndu; C:\Windows\System32\drivers\Ndu.sys [103424 2014-11-21] (Microsoft Corporation) [File not signed] R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew01.sys [3354384 2015-09-16] (Intel Corporation) R2 pmfilter; C:\Windows\system32\drivers\pmfilter.sys [67280 2013-09-18] (Windows (R) Win 7 DDK provider) R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2013-09-30] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] () S3 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [17408 2014-11-21] (Microsoft Corporation) [File not signed] S3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2016-07-09] (Synaptics Incorporated) S3 Wanarp; C:\Windows\system32\DRIVERS\wanarp.sys [80384 2018-01-02] (Microsoft Corporation) [File not signed] R1 Wanarpv6; C:\Windows\system32\DRIVERS\wanarp.sys [80384 2018-01-02] (Microsoft Corporation) [File not signed] S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation) S4 IMFMBRProtect; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\IMFMBRProtect.sys [X] S4 IMFSafeBox; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\IMFSafeBox.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-04-09 00:33 - 2018-04-09 00:33 - 000032821 _____ C:\Users\TAHER\Desktop\Addition.txt 2018-04-09 00:32 - 2018-04-09 00:37 - 000018804 _____ C:\Users\TAHER\Desktop\FRST.txt 2018-04-09 00:31 - 2018-04-09 00:37 - 000000000 ____D C:\FRST 2018-04-09 00:08 - 2018-04-09 00:08 - 002403328 _____ (Farbar) C:\Users\TAHER\Desktop\FRST64.exe 2018-04-08 11:35 - 2018-04-08 11:35 - 000566128 _____ (Malwarebytes) C:\Users\TAHER\Desktop\mbam-clean-2.3.0.1001.exe 2018-04-08 11:30 - 2018-04-08 11:30 - 000002201 _____ C:\Users\TAHER\Desktop\yyyyyyyyy.txt 2018-04-04 07:36 - 2018-04-04 07:37 - 036501736 _____ (Adlice Software ) C:\Users\TAHER\Desktop\RogueKiller_setup_ref3.exe 2018-04-03 21:39 - 2018-04-03 21:39 - 000000000 ____D C:\ProgramData\{BE2ACE5C-32B7-4777-9BDF-ECF87CDAB705} 2018-04-03 19:00 - 2018-04-03 19:00 - 046075904 _____ C:\Users\TAHER\Downloads\Malwarebytes Anti-malware.msi 2018-04-03 18:55 - 2018-04-03 18:55 - 011115196 _____ C:\Users\TAHER\Desktop\-₪-« حصري Malwarebytes Anti-malware + مفعل تلقائيا مدى الحياة »-₪- - YouTube.MP4 2018-04-03 17:55 - 2018-04-03 17:55 - 000002878 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (TAHER) 2018-04-03 00:08 - 2018-04-03 00:09 - 072135408 _____ (Malwarebytes ) C:\Users\TAHER\Desktop\mb3-setup-consumer-3.4.5.2467-1.0.342-1.0.4576.exe 2018-04-01 15:55 - 2018-04-08 11:37 - 000010793 _____ C:\Windows\system32\CVFirmwareUpgradeLog.txt 2018-04-01 15:55 - 2018-04-01 15:55 - 000583296 _____ (Broadcom Corporation) C:\Windows\system32\bipdll.dll 2018-04-01 15:55 - 2018-04-01 15:55 - 000471040 _____ (Broadcom) C:\Windows\system32\cvproppage.dll 2018-04-01 15:55 - 2018-04-01 15:55 - 000060512 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\cvusbdrv.sys 2018-04-01 15:55 - 2018-04-01 15:55 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_cvusbdrv_01009.Wdf 2018-04-01 15:55 - 2018-04-01 15:55 - 000000000 ____D C:\ProgramData\Broadcom 2018-04-01 15:55 - 2018-04-01 15:55 - 000000000 ____D C:\Program Files\Broadcom 2018-04-01 15:36 - 2018-04-08 11:36 - 094580736 _____ C:\Windows\system32\config\SOFTWARE 2018-04-01 15:36 - 2018-04-08 11:36 - 000393216 _____ C:\Windows\system32\config\DEFAULT 2018-04-01 15:36 - 2018-04-08 11:36 - 000028672 _____ C:\Windows\system32\config\SAM 2018-04-01 15:36 - 2018-04-08 11:36 - 000024576 _____ C:\Windows\system32\config\SECURITY 2018-04-01 15:36 - 2018-04-01 15:36 - 094580736 _____ C:\Windows\system32\config\SOFTWARE.iodefrag.bak 2018-04-01 15:36 - 2018-04-01 15:36 - 004792320 _____ C:\Windows\system32\config\DRIVERS.iodefrag.bak 2018-04-01 15:36 - 2018-04-01 15:36 - 000393216 _____ C:\Windows\system32\config\DEFAULT.iodefrag.bak 2018-04-01 15:36 - 2018-04-01 15:36 - 000028672 _____ C:\Windows\system32\config\SAM.iodefrag.bak 2018-04-01 15:36 - 2018-04-01 15:36 - 000024576 _____ C:\Windows\system32\config\SECURITY.iodefrag.bak 2018-04-01 15:36 - 2018-04-01 15:36 - 000000000 ____H C:\asc_rdflag 2018-04-01 14:30 - 2018-04-06 08:04 - 000000000 ____D C:\Program Files (x86)\IObit 2018-04-01 14:30 - 2018-04-03 21:43 - 000000000 ____D C:\Users\TAHER\AppData\Roaming\IObit 2018-04-01 14:23 - 2018-04-01 14:24 - 040337336 _____ (IObit ) C:\Users\TAHER\Desktop\IObit-Malware-Fighter-Setup-beta.exe 2018-04-01 14:10 - 2018-04-01 14:10 - 000154814 _____ C:\Users\TAHER\Desktop\ZHPDiag.txt 2018-03-31 07:35 - 2018-04-01 14:51 - 000003840 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1486325203 2018-03-31 07:35 - 2018-03-31 07:35 - 000001063 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk 2018-03-27 20:03 - 2018-03-27 20:03 - 006480880 _____ C:\Windows\system32\FNTCACHE.DAT 2018-03-27 19:57 - 2018-03-27 20:00 - 000000000 ____D C:\AdwCleaner 2018-03-27 19:57 - 2018-03-27 19:57 - 008222496 _____ (Malwarebytes) C:\Users\TAHER\Desktop\adwcleaner_7.0.8.0.exe 2018-03-27 19:26 - 2018-03-27 19:26 - 000000845 _____ C:\DelFix.txt 2018-03-26 22:59 - 2018-03-26 23:00 - 000313366 _____ C:\Users\TAHER\Downloads\WindowsUpdate.diagcab 2018-03-19 21:24 - 2018-03-19 21:24 - 001250816 _____ C:\Users\TAHER\Downloads\MicrosoftEasyFix50202.msi 2018-03-17 23:50 - 2018-03-17 23:51 - 000000000 ____D C:\Users\TAHER\Downloads\Tech tool store tools 2018-03-17 23:50 - 2018-03-17 23:50 - 000000000 ____D C:\ProgramData\Tech Tool Store 2018-03-15 06:15 - 2018-03-02 20:55 - 000834552 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2018-03-15 06:15 - 2018-03-02 20:55 - 000179704 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2018-03-14 20:50 - 2018-02-14 23:45 - 000145024 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2018-03-14 20:50 - 2018-02-13 16:20 - 001994752 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2018-03-14 20:50 - 2018-02-13 16:20 - 001560064 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2018-03-14 20:50 - 2018-02-13 16:20 - 000740864 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2018-03-14 20:50 - 2018-02-13 16:20 - 000655872 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2018-03-14 20:50 - 2018-02-13 16:20 - 000600576 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2018-03-14 20:50 - 2018-02-13 16:20 - 000451072 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2018-03-14 20:50 - 2018-02-13 16:20 - 000380928 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2018-03-14 20:50 - 2018-02-13 16:20 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2018-03-14 20:50 - 2018-02-13 16:20 - 000237568 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-04-09 00:23 - 2017-05-09 02:37 - 000003902 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{9EF4CA9D-8A4B-4D65-904A-E9E4C19D26D5} 2018-04-08 23:42 - 2015-10-21 21:05 - 000000000 ____D C:\Users\TAHER\AppData\Local\CrashDumps 2018-04-08 23:39 - 2018-01-03 14:29 - 000000000 ____D C:\KMPlayer 2018-04-08 22:53 - 2016-11-18 17:57 - 000000000 ____D C:\Users\TAHER\AppData\LocalLow\Mozilla 2018-04-08 20:58 - 2017-12-12 00:05 - 000000000 ____D C:\Users\TAHER\AppData\Roaming\DMCache 2018-04-08 17:21 - 2013-08-22 17:20 - 000000000 ____D C:\Windows\CbsTemp 2018-04-08 12:44 - 2015-09-14 02:22 - 000003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2422561113-3094125170-2170945475-1001 2018-04-08 11:37 - 2013-08-22 16:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2018-04-07 16:11 - 2017-06-27 10:33 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2018-04-06 09:39 - 2017-06-27 10:33 - 000000954 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2018-04-06 09:39 - 2017-06-27 10:33 - 000000000 ____D C:\Program Files\Mozilla Firefox 2018-04-06 09:37 - 2018-01-03 14:29 - 000000614 _____ C:\Users\TAHER\Desktop\KMPlayer.lnk 2018-04-04 23:40 - 2015-09-14 02:15 - 000000000 ____D C:\Users\TAHER 2018-04-03 22:27 - 2018-02-23 08:41 - 000000000 ____D C:\ProgramData\ProductData 2018-04-03 21:39 - 2018-02-23 08:39 - 000000000 ____D C:\ProgramData\IObit 2018-04-03 00:09 - 2017-12-12 00:05 - 000000000 ____D C:\Users\TAHER\AppData\Roaming\IDM 2018-04-01 15:55 - 2013-08-22 15:36 - 000000000 ____D C:\Windows\Inf 2018-04-01 15:35 - 2013-08-22 15:25 - 000262144 ___SH C:\Windows\system32\config\BBI 2018-04-01 14:51 - 2017-12-13 06:41 - 000004132 _____ C:\Windows\System32\Tasks\CCleaner Update 2018-04-01 14:33 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\system32\NDF 2018-04-01 14:31 - 2018-02-23 08:40 - 000000000 ____D C:\Users\TAHER\AppData\LocalLow\IObit 2018-04-01 14:10 - 2015-09-18 03:41 - 000000000 ____D C:\Users\TAHER\AppData\Roaming\ZHP 2018-03-31 07:35 - 2017-02-05 22:06 - 000000000 ____D C:\Program Files (x86)\Opera 2018-03-27 19:27 - 2015-09-15 20:09 - 000000000 ____D C:\Program Files\CCleaner 2018-03-24 20:23 - 2015-10-12 17:35 - 000009132 _____ C:\Users\TAHER\Desktop\tt.m3u 2018-03-21 15:20 - 2018-02-20 18:14 - 000002246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2018-03-21 15:20 - 2018-02-20 18:14 - 000002205 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2018-03-17 21:27 - 2017-04-22 07:28 - 000002932 _____ C:\Windows\wininit.ini 2018-03-15 06:38 - 2015-09-14 21:08 - 000000000 ____D C:\Windows\system32\appraiser 2018-03-15 06:15 - 2015-09-14 13:15 - 000000000 ____D C:\Windows\system32\MRT 2018-03-15 06:12 - 2017-10-12 15:02 - 130364688 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe 2018-03-15 06:12 - 2015-09-14 13:14 - 130364688 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2018-03-14 02:40 - 2017-03-01 23:49 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager 2018-03-13 21:12 - 2018-01-27 19:54 - 000000000 ____D C:\Users\TAHER\Documents\Adobe 2018-03-13 21:11 - 2017-12-12 00:05 - 000001041 _____ C:\Users\TAHER\Desktop\Internet Download Manager.lnk ==================== Files in the root of some directories ======= 2017-12-11 06:43 - 2017-12-11 06:43 - 000000260 _____ () C:\ProgramData\fontcacheev1.dat Some files in TEMP: ==================== 2018-04-06 09:36 - 2018-04-06 09:37 - 036711176 _____ (PandoraTV) C:\Users\TAHER\AppData\Local\Temp\KMP_4.2.2.9.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2018-04-05 16:52 ==================== End of FRST.txt ============================