Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-10-2014
Ran by NASSER (administrator) on NASSER-PC on 30-10-2014 14:36:49
Running from C:\Users\NASSER\Downloads\Programs
Loaded Profile: NASSER (Available profiles: NASSER)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: العربية (السعودية)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe
(Apple Inc.) C:\Program Files\Common Files\Research in Motion\Tunnel Manager\mDNSResponder.exe
(Research In Motion Limited) C:\Program Files\Common Files\Research in Motion\Tunnel Manager\tunmgr.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.25.5\GoogleCrashHandler.exe
(Research In Motion Limited) C:\Program Files\Common Files\Research in Motion\USB Drivers\BbDevMgr.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
(Research In Motion Limited) C:\Program Files\Common Files\Research in Motion\USB Drivers\RIMBBLaunchAgent.exe
(Research In Motion Limited) C:\Program Files\Common Files\Research in Motion\Tunnel Manager\PeerManager.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Nokia) C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Nokia) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Tonec Inc.) C:\Program Files\Internet Download Manager\IDMan.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(BitTorrent Inc.) C:\Users\NASSER\AppData\Roaming\uTorrent\uTorrent.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Tonec Inc.) C:\Program Files\Internet Download Manager\IEMonitor.exe
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudDrive.exe
(Dropbox, Inc.) C:\Users\NASSER\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
() C:\Users\NASSER\Downloads\Programs\zoek.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Corporation) C:\Windows\System32\mshta.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2217256 2013-09-07] (Synaptics Incorporated)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12013272 2013-11-10] (Realtek Semiconductor)
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [267792 2013-01-17] (Research In Motion Limited)
HKLM\...\Run: [RIM PeerManager] => C:\Program Files\Common Files\Research In Motion\Tunnel Manager\PeerManager.exe [4265472 2013-04-26] (Research In Motion Limited)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-09-12] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKU\S-1-5-21-4238018866-1968395549-2816781118-1000\...\Run: [PC Suite Tray] => C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia)
HKU\S-1-5-21-4238018866-1968395549-2816781118-1000\...\Run: [ApplePhotoStreams] => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-08-14] (Apple Inc.)
HKU\S-1-5-21-4238018866-1968395549-2816781118-1000\...\Run: [IDMan] => C:\Program Files\Internet Download Manager\IDMan.exe [3821136 2013-12-16] (Tonec Inc.)
HKU\S-1-5-21-4238018866-1968395549-2816781118-1000\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-08-08] (Apple Inc.)
HKU\S-1-5-21-4238018866-1968395549-2816781118-1000\...\Run: [uTorrent] => C:\Users\NASSER\AppData\Roaming\uTorrent\uTorrent.exe [1385808 2014-10-25] (BitTorrent Inc.)
HKU\S-1-5-21-4238018866-1968395549-2816781118-1000\...\Run: [GoogleChromeAutoLaunch_B58F6E141947A1D149EF147DFA4CCB1B] => C:\Program Files\Google\Chrome\Application\chrome.exe [852808 2014-09-23] (Google Inc.)
HKU\S-1-5-21-4238018866-1968395549-2816781118-1000\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1562264 2014-07-25] (Samsung)
HKU\S-1-5-21-4238018866-1968395549-2816781118-1000\...\Run: [KiesPDLR.exe] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-07-25] (Samsung)
HKU\S-1-5-21-4238018866-1968395549-2816781118-1000\...\Run: [iCloudDrive] => C:\Program Files\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2014-08-15] (Apple Inc.)
HKU\S-1-5-21-4238018866-1968395549-2816781118-1000\...\MountPoints2: {04be3fae-1753-11e3-ac73-806e6f6e6963} - F:\SETUP.EXE
HKU\S-1-5-21-4238018866-1968395549-2816781118-1000\...\MountPoints2: {81345613-91ce-11e3-9013-0280486f8601} - F:\AutoRun.exe
HKU\S-1-5-21-4238018866-1968395549-2816781118-1000\...\MountPoints2: {8134561e-91ce-11e3-9013-0280486f8601} - F:\AutoRun.exe
HKU\S-1-5-21-4238018866-1968395549-2816781118-1000\...\MountPoints2: {81345633-91ce-11e3-9013-0280486f8601} - F:\AutoRun.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-09-08] (Microsoft Corporation)
Startup: C:\Users\NASSER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\NASSER\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files\Internet Download Manager\IDMShellExt.dll (Tonec Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8F203EB941B6CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = ar-SA
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1
FireFox:
========
FF ProfilePath: C:\Users\NASSER\AppData\Roaming\Mozilla\Firefox\Profiles\yi5c6eqa.default-1414513394811
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @lightspark.github.com/Lightspark;version=1 -> C:\Program Files\Lightspark 0.5.3-git\nplightsparkplugin.dll No File
FF Extension: Super Block Ads - C:\Program Files\Mozilla Firefox\distribution\bundles\
addon@Vonteera.com [2014-10-25]
FF HKCU\...\Firefox\Extensions: [
mozilla_cc@internetdownloadmanager.com] - C:\Users\NASSER\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\NASSER\AppData\Roaming\IDM\idmmzcc5 [2013-12-18]
FF HKCU\...\SeaMonkey\Extensions: [
mozilla_cc@internetdownloadmanager.com] - C:\Users\NASSER\AppData\Roaming\IDM\idmmzcc5
Chrome:
=======
CHR HomePage: Default -> hxxp://
CHR StartupUrls: Default -> "hxxp://
", "hxxp://
"
CHR Profile: C:\Users\NASSER\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Youtube) - C:\Users\NASSER\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-22]
CHR Extension: (Highlight to Search) - C:\Users\NASSER\AppData\Local\Google\Chrome\User Data\Default\Extensions\floipahigmmkfhkoapmnijnlnboniglg [2014-10-13]
CHR Extension: (IDM Integration Module) - C:\Users\NASSER\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn [2013-12-28]
CHR Extension: (Google Play) - C:\Users\NASSER\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2014-04-22]
CHR Extension: (Google Mail Checker) - C:\Users\NASSER\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-04-22]
CHR Extension: (Google Wallet) - C:\Users\NASSER\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-19]
CHR Extension: (Gmail) - C:\Users\NASSER\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-22]
CHR HKLM\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files\Internet Download Manager\IDMGCExt.crx [2013-12-15]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [1678040 2013-11-10] (Broadcom Corporation.)
R3 BlackBerry Device Manager; C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [585728 2013-02-06] (Research In Motion Limited) [File not signed]
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2013-10-19] (Macrovision Europe Ltd.) [File not signed]
R2 Mysql; C:\Program Files\MySQL\MySQL Server 5.5\my.ini [8916 2013-11-03] () [File not signed]
R2 RIM MDNS; C:\Program Files\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe [389632 2013-04-26] (Apple Inc.) [File not signed]
R2 RIM Tunnel Service; C:\Program Files\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe [1235456 2013-04-26] (Research In Motion Limited) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S0 amdkmafd; C:\Windows\System32\DRIVERS\amdkmafd.sys [15968 2013-09-07] (Advanced Micro Devices, Inc.)
R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [23720 2013-09-07] (Advanced Micro Devices, Inc.)
R3 athr; C:\Windows\System32\DRIVERS\athr.sys [3211264 2013-11-10] (Qualcomm Atheros Communications, Inc.)
S3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [174936 2013-11-10] (Broadcom Corporation.)
S3 btwampfl; C:\Windows\System32\DRIVERS\btwampfl.sys [144600 2013-11-10] (Broadcom Corporation.)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [30976 2014-10-28] ()
R3 rimvndis; C:\Windows\System32\Drivers\rimvndis6.sys [14336 2013-04-26] (Research in Motion Limited)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [27888 2013-09-07] (Synaptics Incorporated)
S1 BAPIDRV; system32\DRIVERS\BAPIDRV.sys [X]
S3 BprotectEx; \??\C:\Windows\System32\drivers\BprotectEx.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_cdcecm; system32\DRIVERS\ew_jucdcecm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [X]
S3 PCFApiUtil; \??\C:\Program Files\Baidu Security\PC Faster\3.7.0.0\PCFApiUtil.sys [X]
S3 RimUsb; System32\Drivers\RimUsb.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 taphss6; system32\DRIVERS\taphss6.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-30 14:35 - 2014-10-30 14:36 - 00000000 ____D () C:\FRST
2014-10-30 14:34 - 2014-10-30 14:34 - 00000419 _____ () C:\zoek-results.log
2014-10-30 14:32 - 2014-10-30 14:37 - 00000619 _____ () C:\runcheck.txt
2014-10-30 14:32 - 2014-10-30 14:32 - 00000000 ____D () C:\zoek_backup
2014-10-28 19:23 - 2014-10-28 19:23 - 00000000 ____D () C:\Users\NASSER\Desktop\بيانات Firefox القديمة
2014-10-28 19:13 - 2014-10-28 19:13 - 00164097 _____ () C:\Users\NASSER\Desktop\runscanner.run
2014-10-28 19:13 - 2014-10-28 19:13 - 00161094 _____ () C:\Users\NASSER\Desktop\التقارير.rar
2014-10-28 19:09 - 2014-10-28 19:09 - 00000000 ____D () C:\Users\NASSER\AppData\Roaming\Baidu
2014-10-28 18:37 - 2014-10-28 19:09 - 00000000 ____D () C:\ProgramData\Baidu
2014-10-28 18:37 - 2014-10-28 18:37 - 00000000 ____D () C:\Users\Public\Documents\Baidu
2014-10-28 18:26 - 2014-10-28 18:26 - 00030976 _____ () C:\Windows\system32\Drivers\hitmanpro37.sys
2014-10-28 18:19 - 2014-10-28 18:19 - 00000338 _____ () C:\Windows\system32\.crusader
2014-10-28 18:03 - 2014-10-28 18:20 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-10-28 14:26 - 2014-10-28 14:26 - 00000000 ____D () C:\ProgramData\Doctor Web
2014-10-28 14:15 - 2014-10-28 17:59 - 00000000 ____D () C:\Users\NASSER\Doctor Web
2014-10-28 13:44 - 2014-10-28 13:44 - 00002328 _____ () C:\Windows\patsearch.bin
2014-10-28 13:44 - 2014-10-28 13:44 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNew_01009.Wdf
2014-10-28 13:39 - 2014-10-28 13:39 - 01998336 _____ () C:\Users\NASSER\Downloads\adwcleaner_4.002.exe
2014-10-28 13:18 - 2014-10-28 19:04 - 00072666 _____ () C:\Windows\PFRO.log
2014-10-28 13:18 - 2014-10-28 19:04 - 00000372 _____ () C:\Windows\setupact.log
2014-10-28 13:18 - 2014-10-28 13:18 - 00000000 _____ () C:\Windows\setuperr.log
2014-10-28 13:12 - 2014-10-28 18:36 - 00000000 ____D () C:\AdwCleaner
2014-10-27 20:20 - 2014-10-27 20:43 - 00000000 ____D () C:\Users\NASSER\Desktop\10
2014-10-25 04:22 - 2014-10-25 04:22 - 00000240 _____ () C:\Users\NASSER\AppData\Local\563ipR.vbs
2014-10-19 01:55 - 2014-10-19 01:55 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-10-19 01:54 - 2014-10-19 01:54 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-10-19 01:54 - 2014-10-19 01:54 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-10-19 01:54 - 2014-10-19 01:54 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-10-19 01:54 - 2014-10-19 01:54 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-10-19 01:54 - 2014-10-19 01:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-10-19 00:40 - 2014-10-19 00:40 - 00000901 _____ () C:\Users\Public\Desktop\Mp3tag.lnk
2014-10-19 00:40 - 2014-10-19 00:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2014-10-19 00:13 - 2014-10-19 00:13 - 00001713 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-10-19 00:13 - 2014-10-19 00:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-10-19 00:11 - 2014-10-19 00:13 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2014-10-19 00:11 - 2014-10-19 00:13 - 00000000 ____D () C:\Program Files\iTunes
2014-10-19 00:11 - 2014-10-19 00:11 - 00000000 ____D () C:\Program Files\iPod
2014-10-14 01:22 - 2014-10-14 01:23 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-10-14 01:22 - 2014-10-14 01:22 - 00001949 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-10-14 01:09 - 2014-08-19 20:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-14 01:09 - 2014-08-19 01:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-14 01:09 - 2014-08-19 01:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-14 01:09 - 2014-08-19 00:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-14 01:09 - 2014-08-19 00:57 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-14 01:09 - 2014-08-19 00:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-14 01:09 - 2014-08-19 00:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-14 01:09 - 2014-08-19 00:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-14 01:09 - 2014-08-19 00:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-14 01:09 - 2014-08-19 00:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-14 01:09 - 2014-08-19 00:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-14 01:09 - 2014-08-19 00:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-14 01:09 - 2014-08-19 00:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-14 01:09 - 2014-08-19 00:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-14 01:09 - 2014-08-19 00:36 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-14 01:09 - 2014-08-19 00:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-14 01:09 - 2014-08-19 00:30 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-14 01:09 - 2014-08-19 00:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-14 01:09 - 2014-08-19 00:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-14 01:09 - 2014-08-19 00:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-14 01:09 - 2014-08-19 00:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-14 01:09 - 2014-08-19 00:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-14 01:09 - 2014-08-19 00:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-14 01:09 - 2014-08-19 00:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-14 01:09 - 2014-08-19 00:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-14 01:09 - 2014-08-19 00:08 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-14 01:09 - 2014-08-19 00:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-14 01:09 - 2014-08-18 23:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-14 01:09 - 2014-08-18 23:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-14 01:09 - 2014-08-18 23:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-14 00:58 - 2014-07-01 01:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-10-14 00:58 - 2014-06-06 09:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-10-14 00:58 - 2014-03-10 00:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-10-14 00:58 - 2014-03-10 00:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-10-14 00:42 - 2014-07-07 04:40 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-10-14 00:42 - 2014-07-07 04:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-10-14 00:38 - 2014-08-23 04:46 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-10-14 00:38 - 2014-08-23 03:42 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-14 00:38 - 2014-06-03 12:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-10-14 00:38 - 2014-06-03 12:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-14 00:38 - 2014-06-03 12:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-10-14 00:38 - 2014-06-03 12:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-10-14 00:27 - 2014-06-16 04:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-10-14 00:27 - 2014-06-16 04:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-10-14 00:27 - 2014-06-16 04:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-10-14 00:20 - 2014-07-14 04:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-10-14 00:09 - 2014-05-14 19:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-10-14 00:09 - 2014-05-14 19:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-10-14 00:09 - 2014-05-14 19:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-10-14 00:09 - 2014-05-14 19:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-10-14 00:09 - 2014-05-14 19:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-10-14 00:09 - 2014-05-14 19:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-10-14 00:09 - 2014-05-14 19:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-10-14 00:08 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-10-14 00:08 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-10-13 01:18 - 2014-10-13 01:18 - 00005715 _____ () C:\Users\NASSER\Desktop\Readme.txt
2014-10-12 00:34 - 2014-10-12 00:37 - 00000716 _____ () C:\Users\NASSER\Desktop\1436.txt
2014-10-09 12:35 - 2014-10-25 04:22 - 00000000 ____D () C:\Users\NASSER\AppData\Roaming\miaul
2014-10-09 11:47 - 2014-10-09 13:04 - 00000000 ____D () C:\Users\NASSER\AppData\Roaming\Audacity
2014-10-09 11:37 - 2014-10-09 11:37 - 00001064 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Sound Editor.lnk
2014-10-09 11:37 - 2014-10-09 11:37 - 00001052 _____ () C:\Users\Public\Desktop\WavePad Sound Editor.lnk
2014-10-09 11:37 - 2014-10-09 11:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
2014-10-07 13:29 - 2014-10-28 19:06 - 00000000 ___RD () C:\Users\NASSER\iCloudDrive
2014-10-07 13:29 - 2014-10-07 13:29 - 00000000 ____D () C:\Windows\Tasks\360Disabled
2014-10-07 13:29 - 2014-10-07 13:29 - 00000000 ____D () C:\Users\NASSER\AppData\Local\Apple Inc
2014-10-07 13:22 - 2014-10-12 00:11 - 00000000 ____D () C:\Program Files\360
2014-10-07 12:11 - 2014-10-19 01:01 - 00000000 ____D () C:\Users\NASSER\AppData\Roaming\Mp3tag
2014-10-07 12:11 - 2014-10-19 00:40 - 00000000 ____D () C:\Program Files\Mp3tag
2014-10-07 11:54 - 2014-10-07 11:54 - 00000000 ____D () C:\Users\NASSER\AppData\Roaming\dBpoweramp
2014-10-07 11:52 - 2014-10-07 11:52 - 05199808 _____ () C:\Windows\system32\SpoonUninstall.exe
2014-10-07 11:51 - 2014-10-07 11:51 - 25782208 _____ () C:\Users\NASSER\Downloads\dMC-R15.1-Ref-Trial.exe
2014-10-07 11:50 - 2014-10-07 11:50 - 00000000 ____D () C:\Users\NASSER\AppData\Roaming\SPK
2014-10-07 11:50 - 2014-10-07 11:50 - 00000000 ____D () C:\Users\NASSER\AppData\Roaming\Fixs
2014-10-07 10:54 - 2014-10-07 10:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-30 14:36 - 2013-09-19 12:18 - 00002089 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-30 14:36 - 2013-09-19 12:17 - 00000830 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-30 14:36 - 2013-09-19 12:17 - 00000826 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-30 14:35 - 2013-09-11 04:47 - 00000000 ____D () C:\Users\NASSER\AppData\Roaming\uTorrent
2014-10-30 14:30 - 2013-09-09 01:49 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-30 14:30 - 2013-09-07 03:21 - 02072951 _____ () C:\Windows\WindowsUpdate.log
2014-10-28 19:14 - 2009-07-14 07:34 - 00014224 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-28 19:14 - 2009-07-14 07:34 - 00014224 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-28 19:10 - 2013-09-07 03:36 - 02146070 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-28 19:07 - 2013-09-09 00:04 - 00000000 ___RD () C:\Users\NASSER\Dropbox
2014-10-28 19:07 - 2013-09-09 00:00 - 00000000 ____D () C:\Users\NASSER\AppData\Roaming\Dropbox
2014-10-28 19:04 - 2009-07-14 07:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-28 19:02 - 2014-06-24 14:48 - 00000000 ____D () C:\Program Files\iBrowse
2014-10-28 19:02 - 2013-09-07 03:34 - 00000000 ____D () C:\Users\NASSER\AppData\Roaming\DMCache
2014-10-28 18:45 - 2013-09-07 03:34 - 00000000 ____D () C:\Users\NASSER\Downloads\Compressed
2014-10-28 18:36 - 2013-09-07 03:25 - 00000000 ____D () C:\Users\NASSER
2014-10-28 18:30 - 2009-07-14 07:33 - 01888920 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-28 18:06 - 2013-09-07 05:31 - 00185128 _____ () C:\Users\NASSER\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-28 13:49 - 2014-09-19 16:46 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-10-28 13:12 - 2013-09-07 03:34 - 00000000 ____D () C:\Users\NASSER\AppData\Roaming\IDM
2014-10-25 08:18 - 2009-07-14 05:37 - 00000000 ____D () C:\Windows\rescache
2014-10-25 04:22 - 2014-03-19 05:23 - 00004744 __RSH () C:\ProgramData\ntuser.pol
2014-10-19 01:55 - 2013-09-19 08:34 - 00000000 ____D () C:\ProgramData\Oracle
2014-10-19 01:54 - 2013-09-19 08:33 - 00000000 ____D () C:\Program Files\Java
2014-10-19 01:38 - 2013-09-07 05:42 - 00000000 ____D () C:\Program Files\MyFree Codec
2014-10-19 01:36 - 2013-09-07 05:24 - 00000000 ____D () C:\Program Files\The KMPlayer
2014-10-19 01:35 - 2013-09-07 05:27 - 00000000 ____D () C:\Program Files\Bonjour
2014-10-19 00:11 - 2014-09-13 15:59 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-10-19 00:11 - 2013-09-07 05:27 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-10-14 05:05 - 2009-07-14 05:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-10-14 01:23 - 2013-10-19 11:32 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-10-14 01:22 - 2013-10-19 11:42 - 00000000 ____D () C:\ProgramData\Adobe
2014-10-14 01:22 - 2013-10-19 11:34 - 00000000 ____D () C:\Program Files\Adobe
2014-10-14 01:12 - 2009-07-14 05:37 - 00000000 ____D () C:\Windows\system32\ar-SA
2014-10-14 01:05 - 2013-09-07 04:30 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-13 04:33 - 2009-07-14 05:37 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-10-13 02:40 - 2014-01-29 23:36 - 00000000 ____D () C:\Users\NASSER\Downloads\ip
2014-10-13 02:07 - 2013-09-07 03:34 - 00000000 ____D () C:\Users\NASSER\Downloads\Video
2014-10-13 01:38 - 2014-04-01 20:47 - 00000000 ____D () C:\Users\NASSER\AppData\Roaming\iFunbox_UserCache
2014-10-13 01:18 - 2013-09-07 05:24 - 07446008 _____ (深圳创想天空科技有限公司) C:\Users\NASSER\Desktop\iTools.exe
2014-10-07 13:39 - 2013-09-09 01:58 - 00000000 ____D () C:\Users\NASSER\AppData\Roaming\Adobe
2014-10-07 13:30 - 2013-09-07 06:07 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-07 13:29 - 2014-02-10 00:01 - 00000000 ____D () C:\Users\NASSER\AppData\Local\8A417C1C-21F4-4E29-8566-7F6D9CE46689.aplzod
2014-10-07 13:29 - 2013-09-07 05:30 - 00000000 ____D () C:\Users\NASSER\AppData\Roaming\Apple Computer
2014-10-07 10:53 - 2013-09-09 01:49 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-10-07 10:53 - 2013-09-09 01:49 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
Some content of TEMP:
====================
C:\Users\NASSER\AppData\Local\Temp\7za.exe
C:\Users\NASSER\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpwy9j6o.dll
C:\Users\NASSER\AppData\Local\Temp\hijackthis.exe
C:\Users\NASSER\AppData\Local\Temp\NirCmd.exe
C:\Users\NASSER\AppData\Local\Temp\PEVZ.EXE
C:\Users\NASSER\AppData\Local\Temp\remove.exe
C:\Users\NASSER\AppData\Local\Temp\sed.exe
C:\Users\NASSER\AppData\Local\Temp\shortcut.exe
C:\Users\NASSER\AppData\Local\Temp\swreg.exe
C:\Users\NASSER\AppData\Local\Temp\swxcacls.exe
C:\Users\NASSER\AppData\Local\Temp\wget.exe
C:\Users\NASSER\AppData\Local\Temp\zoek-delete.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-28 13:04
==================== End Of Log ============================