Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:28-12-2015 Ran by riqdh (administrator) on RIQDH-PC (28-12-2015 10:55:22) Running from C:\Users\riqdh\Desktop Loaded Profiles: riqdh (Available Profiles: riqdh) Platform: Microsoft Windows 7 Alienware 2010 (X86) Language: English (United States) Internet Explorer Version 8 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe (Digital Wave Ltd.) C:\Program Files\Common Files\DVDVideoSoft\lib\app_updater.exe (TData.com) C:\Program Files\TDataDld\TData.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avpui.exe (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (MSI CO.,LTD.) C:\Program Files\MSI\Super-Charger\Super-Charger.exe (BitTorrent Inc.) C:\Users\riqdh\AppData\Roaming\uTorrent\uTorrent.exe (Tonec Inc.) C:\Program Files\Internet Download Manager\IDMan.exe (BitTorrent Inc.) C:\Users\riqdh\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe (BitTorrent Inc.) C:\Users\riqdh\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe (DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe (Tonec Inc.) C:\Program Files\Internet Download Manager\IEMonitor.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\klwtblfs.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Welcome Center] => C:\Windows\system32\rundll32.exe C:\Windows\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [248040 2010-02-18] (Sun Microsystems, Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10996328 2011-09-09] (Realtek Semiconductor) HKLM\...\Run: [Super-Charger] => C:\Program Files\MSI\Super-Charger\StartSuperCharger.exe [303104 2011-07-06] (MSI) HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2009-12-22] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [948672 2009-12-11] (Adobe Systems Incorporated) HKU\S-1-5-21-3564263586-645558907-3407407313-1000\...\Run: [uTorrent] => C:\Users\riqdh\AppData\Roaming\uTorrent\uTorrent.exe [2026520 2015-12-02] (BitTorrent Inc.) HKU\S-1-5-21-3564263586-645558907-3407407313-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd) HKU\S-1-5-21-3564263586-645558907-3407407313-1000\...\Run: [VkontakteDJ] => C:\Program Files\VkontakteDJ\VKontakteDJ.exe /H HKU\S-1-5-21-3564263586-645558907-3407407313-1000\...\Run: [IDMan] => C:\Program Files\Internet Download Manager\IDMan.exe [2745776 2009-01-23] (Tonec Inc.) HKU\S-1-5-21-3564263586-645558907-3407407313-1000\...\MountPoints2: {27c4e035-9c3d-11e5-bd42-8c89a5de4896} - H:\AutoRun.exe HKU\S-1-5-21-3564263586-645558907-3407407313-1000\...\MountPoints2: {27c4e044-9c3d-11e5-bd42-8c89a5de4896} - H:\AutoRun.exe HKU\S-1-5-21-3564263586-645558907-3407407313-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [413696 2009-07-13] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files\Internet Download Manager\IDMShellExt.dll [2015-08-14] (Tonec Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0 Tcpip\..\Interfaces\{71786CDC-5504-4D3C-B8CD-82AB44579E37}: [DhcpNameServer] 192.168.1.1 0.0.0.0 Internet Explorer: ================== HKU\S-1-5-21-3564263586-645558907-3407407313-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.fr/ SearchScopes: HKU\.DEFAULT -> {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKU\S-1-5-21-3564263586-645558907-3407407313-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://yandex.ru/search/?win=202&clid=2233245-169&text={searchTerms} SearchScopes: HKU\S-1-5-21-3564263586-645558907-3407407313-1000 -> 46B32E6CB31F051E3D6BE9F288CE429E URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKU\S-1-5-21-3564263586-645558907-3407407313-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://yandex.ru/search/?win=202&clid=2233245-169&text={searchTerms} SearchScopes: HKU\S-1-5-21-3564263586-645558907-3407407313-1000 -> {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files\Internet Download Manager\IDMIECC.dll [2015-12-08] (Internet Download Manager, Tonec Inc.) BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21] (Adobe Systems Incorporated) BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20] (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2015-12-25] (Kaspersky Lab ZAO) BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-04-20] (Kaspersky Lab ZAO) BHO: No Name -> {D5FEC983-01DB-414A-9456-AF95AC9ED7B5} -> No File BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2015-11-03] (Sun Microsystems, Inc.) BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20] (Kaspersky Lab ZAO) BHO: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll [2015-10-29] (DVDVideoSoft Ltd.) Toolbar: HKU\S-1-5-21-3564263586-645558907-3407407313-1000 -> No Name - {91397D20-1446-11D4-8AF4-0040CA1127B6} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab FireFox: ======== FF ProfilePath: C:\Users\riqdh\AppData\Roaming\Mozilla\Firefox\Profiles\i279kozu.default FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: mysites123 FF Homepage: hxxp://www.google.fr FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-11] () FF Plugin: @kaspersky.com/content_blocker -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com [2015-12-25] () FF Plugin: @kaspersky.com/online_banking -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com [2015-12-25] () FF Plugin: @kaspersky.com/virtual_keyboard -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2015-12-25] () FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF user.js: detected! => C:\Users\riqdh\AppData\Roaming\Mozilla\Firefox\Profiles\i279kozu.default\user.js [2015-12-26] FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2009-12-21] (Adobe Systems Inc.) FF SearchPlugin: C:\Users\riqdh\AppData\Roaming\Mozilla\Firefox\Profiles\i279kozu.default\searchplugins\mysites123.xml [2015-12-26] FF SearchPlugin: C:\Users\riqdh\AppData\Roaming\Mozilla\Firefox\Profiles\i279kozu.default\searchplugins\yandex.ru-033054.xml [2015-11-12] FF Extension: FirefixTab - C:\Users\riqdh\AppData\Roaming\Mozilla\Firefox\Profiles\i279kozu.default\extensions\deskCutv2@gmail.com [2015-12-26] [not signed] FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\riqdh\AppData\Roaming\Mozilla\Firefox\Profiles\i279kozu.default\extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900}.xpi [2015-06-16] [not signed] FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com [2015-12-25] [not signed] FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com [2015-12-25] [not signed] FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com [2015-12-25] [not signed] FF Extension: Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\anti_banner@kaspersky.com [2015-12-25] [not signed] FF Extension: Kaspersky URL Advisor - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\url_advisor@kaspersky.com [2015-12-25] [not signed] FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\content_blocker@kaspersky.com FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\virtual_keyboard@kaspersky.com FF HKLM\...\Firefox\Extensions: [url_advisor@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\url_advisor@kaspersky.com FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\anti_banner@kaspersky.com FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\FFExt\online_banking@kaspersky.com FF HKLM\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\riqdh\AppData\Roaming\Mozilla\Firefox\Profiles\i279kozu.default\extensions\deskCutv2@gmail.com FF HKU\S-1-5-21-3564263586-645558907-3407407313-1000\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files\Internet Download Manager\idmmzcc2.xpi FF Extension: No Name - C:\Program Files\Internet Download Manager\idmmzcc2.xpi [2015-12-09] [not signed] FF HKU\S-1-5-21-3564263586-645558907-3407407313-1000\...\Firefox\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\riqdh\AppData\Roaming\IDM\idmmzcc2 FF Extension: IDM CC - C:\Users\riqdh\AppData\Roaming\IDM\idmmzcc2 [2015-12-24] [not signed] FF HKU\S-1-5-21-3564263586-645558907-3407407313-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\riqdh\AppData\Roaming\IDM\idmmzcc5 FF Extension: IDM CC - C:\Users\riqdh\AppData\Roaming\IDM\idmmzcc5 [2015-12-24] [not signed] FF HKU\S-1-5-21-3564263586-645558907-3407407313-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files\Internet Download Manager\idmmzcc2.xpi Chrome: ======= CHR Profile: C:\Users\riqdh\AppData\Local\Google\Chrome\User Data\Default CHR HKLM\...\Chrome\Extension: [cncgohepihcekklokhbhiblhfcmipbdh] - hxxp://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho CHR HKLM\...\Chrome\Extension: [gehngeifmelphpllncobkmimphfkckne] - hxxp://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [mdeldjolamfbcgnndjmjjiinnhbnbnla] - hxxp://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files\Internet Download Manager\IDMGCExt.crx [2015-12-10] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AVP15.0.0; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.0\avp.exe [233552 2014-04-20] (Kaspersky Lab ZAO) R2 DigitalWave.Update.Service; C:\Program Files\Common Files\DVDVideoSoft\lib\app_updater.exe [382312 2015-10-29] (Digital Wave Ltd.) R5 sppsvc; C:\Windows\system32\sppsvc.exe [3179520 2009-07-13] (Microsoft Corporation) R2 TDataSvr; C:\Program Files\TDataDld\TData.exe [228072 2015-12-24] (TData.com) R2 Themes; C:\Windows\system32\themeservice.dll [37888 2009-08-01] (Microsoft Corporation) [File not signed] S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-13] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2015-11-03] (DT Soft Ltd) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [19984 2015-12-26] () R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135264 2014-02-20] (Kaspersky Lab ZAO) R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [112136 2015-12-25] (Kaspersky Lab ZAO) R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [34400 2014-04-10] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [644808 2015-12-25] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2014-02-25] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [24672 2014-03-28] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-08-08] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2014-03-25] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [145888 2014-03-26] (Kaspersky Lab ZAO) S0 sptd; C:\Windows\System32\Drivers\sptd.sys [715248 2015-11-03] (Duplex Secure Ltd.) S3 TrojanKillerDriver; C:\Windows\System32\DRIVERS\gtkdrv.sys [16128 2015-10-13] (Windows (R) Win 7 DDK provider) S3 ewusbmbb; system32\DRIVERS\ewusbwwan.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S3 NTIOLib_1_0_C; \??\E:\NTIOLib.sys [X] ========================== Drivers MD5 ======================= C:\Windows\system32\DRIVERS\1394ohci.sys 6D2ACA41739BFE8CB86EE8E85F29697D C:\Windows\System32\DRIVERS\ACPI.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\acpipmi.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\adp94xx.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\adpahci.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\adpu320.sys ==> MD5 is legit C:\Windows\system32\drivers\afd.sys DDC040FDB01EF1712A6B13E52AFB104C C:\Windows\system32\DRIVERS\agp440.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\djsvs.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\aliide.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\amdagp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\amdide.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\amdk8.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\amdppm.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\amdsata.sys 2101A86C25C154F8314B24EF49D7FBC2 C:\Windows\system32\DRIVERS\amdsbs.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\amdxata.sys B81C2B5616F6420A9941EA093A92B150 C:\Windows\system32\drivers\appid.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\arc.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\arcsas.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\atapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\athr.sys 76BAB0C824E2D05B940C4DD40A9B08BF C:\Windows\system32\DRIVERS\bxvbdx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\b57nd60x.sys ==> MD5 is legit C:\Windows\system32\Drivers\Beep.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bowser.sys FCAFAEF6798D7B51FF029F99A9898961 C:\Windows\system32\DRIVERS\BrFiltLo.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\BrFiltUp.sys ==> MD5 is legit C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\bthmodem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\circlass.sys ==> MD5 is legit C:\Windows\System32\CLFS.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\CmBatt.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\cmdide.sys ==> MD5 is legit C:\Windows\System32\Drivers\cng.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\compbatt.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\CompositeBus.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\crcdisk.sys ==> MD5 is legit C:\Windows\System32\drivers\csc.sys ==> MD5 is legit C:\Windows\System32\Drivers\dfsc.sys 8E09E52EE2E3CEB199EF3DD99CF9E3FB C:\Windows\System32\drivers\discache.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\disk.sys ==> MD5 is legit C:\Windows\System32\drivers\drmkaud.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\dtsoftbus01.sys 687AF6BB383885FF6A64071B189A7F3E C:\Windows\System32\drivers\dxgkrnl.sys 39806CFEDDCC55E686A49BCCD2972F23 C:\Windows\system32\DRIVERS\evbdx.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\elxstor.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\errdev.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\EsgScanner.sys 01CE484FF6D70A39479BC6D619DE7ED6 C:\Windows\system32\Drivers\exfat.sys ==> MD5 is legit C:\Windows\system32\Drivers\fastfat.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\fdc.sys ==> MD5 is legit C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\flpydisk.sys ==> MD5 is legitB C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit C:\Windows\system32\Drivers\Fs_Rec.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\fvevol.sys 5592F5DBA26282D24D2B080EB438A4D7 C:\Windows\system32\DRIVERS\gagp30kx.sys ==> MD5 is legit C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit C:\Windows\System32\drivers\HdAudio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\HidBatt.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\hidbth.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\hidir.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\HpSAMD.sys ==> MD5 is legit C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\i8042prt.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\iaStorV.sys 934AF4D7C5F457B9F0743F4299B77B67 C:\Windows\System32\DRIVERS\idmwfp.sys 4AE550739CEA807C1DDA9E3395615A09 C:\Windows\system32\DRIVERS\iirsp.sys ==> MD5 is legit C:\Windows\System32\drivers\RTKVHDA.sys D71E7E54E875FA7E95A61E117E67432F C:\Windows\System32\DRIVERS\intelide.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\IPMIDrv.sys ==> MD5 is legit C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\isapnp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\msiscsi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kl1.sys 6022F174CEB149650DCB5BE445A0E72A C:\Windows\System32\DRIVERS\klflt.sys 3EAA179537FF9A3C9071E868C07275FA C:\Windows\System32\DRIVERS\klhk.sys C02EC9EEE4E3CFEF82478B9C345F94FE C:\Windows\System32\DRIVERS\klif.sys 894A09BF826E79C1971ADE0121F2B607 C:\Windows\System32\DRIVERS\klim6.sys D1FC14342F8CAD20A0764305AD62483D C:\Windows\System32\DRIVERS\klkbdflt.sys 9C7132A2E609E0BACF2A54AC13C9BDCB C:\Windows\System32\DRIVERS\klmouflt.sys 035724BA6D5676B76FD3AFB66AB4F1E3 C:\Windows\System32\DRIVERS\klpd.sys EB0D72D2844C57F5F146D7A15B04FBF9 C:\Windows\System32\DRIVERS\kltdi.sys 3EA7D183499C7C5824AA13DA1A7CDA26 C:\Windows\System32\DRIVERS\kneps.sys E111A2947A4D26CC4A30D2BF2E7A8D69 C:\Windows\System32\Drivers\ksecdd.sys ==> MD5 is legit C:\Windows\System32\Drivers\ksecpkg.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_fc.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_sas.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_sas2.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\lsi_scsi.sys ==> MD5 is legit C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\megasas.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\MegaSR.sys ==> MD5 is legit C:\Windows\System32\drivers\modem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\mpio.sys ==> MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\mrxdav.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mrxsmb.sys F1B6AA08497EA86CA6EF6F7A08B0BFB8 C:\Windows\System32\DRIVERS\mrxsmb10.sys 5613358B4050F46F5A9832DA8050D6E4 C:\Windows\System32\DRIVERS\mrxsmb20.sys 25C9792778D80FEB4C8201E62281BFDF C:\Windows\system32\DRIVERS\msahci.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\msdsm.sys ==> MD5 is legit C:\Windows\system32\Drivers\Msfs.sys ==> MD5 is legit C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\msisadrv.sys ==> MD5 is legit C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit C:\Windows\system32\Drivers\MsRPC.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mssmbios.sys ==> MD5 is legit C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\MTConfig.sys ==> MD5 is legit C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit C:\Windows\System32\drivers\ndis.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit C:\Windows\system32\Drivers\NDProxy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\nfrd960.sys ==> MD5 is legit C:\Windows\system32\Drivers\Npfs.sys ==> MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit C:\Windows\system32\Drivers\Ntfs.sys 3795DCD21F740EE799FB7223234215AF C:\Windows\system32\Drivers\Null.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\nvlddmkm.sys B0881DDA5A8160422561FFAB7F0008B1 C:\Windows\system32\DRIVERS\nvraid.sys 3F3D04B1D08D43C16EA7963954EC768D C:\Windows\system32\DRIVERS\nvstor.sys C99F251A5DE63C6F129CF71933ACED0F C:\Windows\system32\DRIVERS\nv_agp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\ohci1394.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\parport.sys ==> MD5 is legit C:\Windows\System32\drivers\partmgr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\parvdm.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\pci.sys C858CB77C577780ECC456A892E7E7D0F C:\Windows\system32\DRIVERS\pciide.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\pcmcia.sys ==> MD5 is legit C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\processr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\ql2300.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\ql40xx.sys ==> MD5 is legit C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rdbss.sys 835D7E81BF517A3B72384BDCC85E1CE6 C:\Windows\System32\DRIVERS\rdpbus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\RDPCDD.sys 1E016846895B15A99F9A176A05029075 C:\Windows\System32\drivers\rdpdr.sys C5FF95883FFEF704D50C40D21CFB3AB5 C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit C:\Windows\system32\Drivers\RDPWD.sys 801371BA9782282892D00AADB08EE367 C:\Windows\System32\drivers\rdyboost.sys 4EA225BF1CF05E158853F30A99CA29A7 C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\Rt86win7.sys 5283B9A27FF230F2FF70D92451FF409A C:\Windows\system32\DRIVERS\vms3cap.sys 5423D8437051E89DD34749F242C98648 C:\Windows\system32\DRIVERS\sbp2port.sys 34EE0C44B724E3E4CE2EFF29126DE5B5 C:\Windows\System32\DRIVERS\scfilter.sys A95C54B2AC3CC9C73FCDF9E51A1D6B51 C:\Windows\system32\Drivers\secdrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\serenum.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\serial.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sermouse.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sffdisk.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sffp_mmc.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sffp_sd.sys A0708BBD07D245C06FF9DE549CA47185 C:\Windows\system32\DRIVERS\sfloppy.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sisagp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\SiSRaid2.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\sisraid4.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit C:\Windows\system32\Drivers\spldr.sys ==> MD5 is legit C:\Windows\System32\Drivers\sptd.sys 0C1DAD75274CB6E31F053CE3E08BF9C3 C:\Windows\System32\DRIVERS\srv.sys 50A83CA406C808BD35AC9141A0C7618F C:\Windows\System32\DRIVERS\srv2.sys DCE7E10FEAABD4CAE95948B3DE5340BB C:\Windows\System32\DRIVERS\srvnet.sys BD1433A32792FD0DC450479094FC435A C:\Windows\system32\DRIVERS\stexstor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vmstorfl.sys 957E346CA948668F2496A6CCF6FF82CC C:\Windows\system32\DRIVERS\storvsc.sys D5751969DC3E4B88BF482AC8EC9FE019 C:\Windows\System32\DRIVERS\swenum.sys ==> MD5 is legit C:\Windows\System32\drivers\tcpip.sys 2CC3D75488ABD3EC628BBB9A4FC84EFC C:\Windows\System32\DRIVERS\tcpip.sys 2CC3D75488ABD3EC628BBB9A4FC84EFC C:\Windows\System32\drivers\tcpipreg.sys E64444523ADD154F86567C469BC0B17F C:\Windows\System32\drivers\tdpipe.sys 1875C1490D99E70E449E3AFAE9FCBADF C:\Windows\System32\drivers\tdtcp.sys 7551E91EA999EE9A8E9C331D5A9C31F3 C:\Windows\System32\DRIVERS\tdx.sys CB39E896A2A83702D1737BFD402B3542 C:\Windows\System32\DRIVERS\termdd.sys C36F41EE20E6999DBF4B0425963268A5 C:\Windows\System32\DRIVERS\gtkdrv.sys 113384367C3999E084FE156B18C7625E C:\Windows\System32\DRIVERS\tssecsrv.sys 98AE6FA07D12CB4EC5CF4A9BFA5F4242 C:\Windows\System32\DRIVERS\tunnel.sys 3E461D890A97F9D4C168F5FDA36E1D00 C:\Windows\system32\DRIVERS\uagp35.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\udfs.sys 09CC3E16F8E5EE7168E01CF8FCBE061A C:\Windows\system32\DRIVERS\uliagpkx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\umbus.sys 049B3A50B3D646BAEEEE9EEC9B0668DC C:\Windows\system32\DRIVERS\umpass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\usbccgp.sys 8455C4ED038EFD09E99327F9D2D48FFA C:\Windows\system32\DRIVERS\usbcir.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\usbehci.sys 1C333BFD60F2FED2C7AD5DAF533CB742 C:\Windows\System32\DRIVERS\usbhub.sys EE6EF93CCFA94FAE8C6AB298273D8AE2 C:\Windows\system32\DRIVERS\usbohci.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\usbprint.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\USBSTOR.SYS D8889D56E0D27E57ED4591837FE71D27 C:\Windows\System32\DRIVERS\usbuhci.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vdrvroot.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit C:\Windows\System32\drivers\vga.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\vhdmp.sys 3BE6E1F3A4F1AFEC8CEE0D7883F93583 C:\Windows\system32\DRIVERS\viaagp.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\viac7.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\viaide.sys ==> MD5 is legit C:\Windows\system32\DRIVERS\vmbus.sys 379B349F65F453D2A6E75EA6B7448E49 C:\Windows\system32\DRIVERS\VMBusHID.sys EC2BBAB4B84D0738C6C83D2234DC36FE C:\Windows\System32\DRIVERS\volmgr.sys 384E5A2AA49934295171E499F86BA6F3 C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\volsnap.sys 58DF9D2481A56EDDE167E51B334D44FD C:\Windows\system32\DRIVERS\vsmraid.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwififlt.sys 7090D3436EEB4E7DA3373090A23448F7 C:\Windows\system32\DRIVERS\wacompen.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys 692A712062146E96D28BA0B7D75DE31B C:\Windows\System32\DRIVERS\wanarp.sys 692A712062146E96D28BA0B7D75DE31B C:\Windows\system32\DRIVERS\wd.sys ==> MD5 is legit C:\Windows\System32\drivers\Wdf01000.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\WinUsb.sys 30FC6E5448D0CBAAA95280EEEF7FEDAE C:\Windows\system32\DRIVERS\wmiacpi.sys ==> MD5 is legit C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit C:\Windows\System32\drivers\WudfPf.sys 6F9B6C0C93232CFF47D0F72D6DB1D21E C:\Windows\System32\DRIVERS\WUDFRd.sys F91FF1E51FCA30B3C3981DB7D5924252 ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Three Months Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-12-28 10:55 - 2015-12-28 10:55 - 00032561 _____ C:\Users\riqdh\Desktop\FRST.txt 2015-12-28 10:55 - 2015-12-28 10:55 - 00000000 ____D C:\FRST 2015-12-28 10:52 - 2015-12-28 10:52 - 01721856 _____ (Farbar) C:\Users\riqdh\Desktop\FRST.exe 2015-12-28 10:02 - 2015-12-28 10:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GridinSoft Anti-Malware 2015-12-28 09:51 - 2015-12-28 09:51 - 00000000 ____D C:\Users\riqdh\AppData\LocalLow\uTorrent 2015-12-27 11:28 - 2015-12-27 11:28 - 00029320 _____ C:\Users\riqdh\Desktop\windows-1256__ÇáÑÇÊÈ ÇáÔåÑí 2016.rar 2015-12-27 10:38 - 2015-12-27 10:38 - 00001077 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-12-27 10:38 - 2015-12-27 10:38 - 00001065 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-12-27 00:32 - 2015-12-27 00:32 - 00262144 _____ C:\Windows\system32\config\elam 2015-12-26 12:17 - 2015-12-28 10:04 - 00000000 ____D C:\Program Files\GridinSoft Anti-Malware 2015-12-26 12:17 - 2015-12-28 10:02 - 00001006 _____ C:\Users\Public\Desktop\GridinSoft Anti-Malware.lnk 2015-12-26 12:15 - 2015-10-18 19:17 - 01149440 _____ C:\Users\riqdh\Desktop\(x32bit.)-patch.exe 2015-12-26 12:15 - 2015-10-18 17:39 - 01148928 _____ C:\Users\riqdh\Desktop\64bit.-patch.exe 2015-12-26 12:15 - 2015-10-10 17:49 - 00000374 _____ C:\Users\riqdh\Desktop\redme.txt 2015-12-26 12:05 - 2015-10-18 16:08 - 74144648 _____ C:\Users\riqdh\Desktop\gsam-3.0.3-setup.exe 2015-12-26 12:02 - 2015-12-26 12:09 - 76264308 _____ C:\Users\riqdh\Desktop\GridinSoft Anti-Malware 3.0.3.29 - License (x32x64bit.) MrSzzS.zip 2015-12-26 11:57 - 2015-12-26 11:57 - 28849904 _____ C:\Users\riqdh\Downloads\GridinSoft Anti Malware 3_Downloader [1].exe 2015-12-26 11:52 - 2015-12-26 11:52 - 00000000 ____D C:\Program Files\TDataDld 2015-12-26 11:51 - 2015-12-26 11:52 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\mysites123 2015-12-26 11:48 - 2015-12-26 11:48 - 03041000 _____ (Adobe Systems Incorporated) C:\Users\riqdh\Desktop\GridinSoft+Anti+Malware+3_10924_i107782060_il345.exe 2015-12-26 11:47 - 2015-12-26 11:47 - 02716592 _____ (DWGPDF.net Inc. ) C:\Users\riqdh\Desktop\GridinSoft+Anti+Malware+3_10924_i107781493_il345.exe 2015-12-26 09:45 - 2015-12-26 09:45 - 00000000 ____D C:\ProgramData\GridinSoft 2015-12-26 09:41 - 2015-12-26 09:41 - 01104336 _____ C:\Users\riqdh\Desktop\Setup-TrojanKiller-DM.exe 2015-12-26 08:58 - 2015-12-26 08:58 - 00019984 _____ C:\Windows\system32\Drivers\EsgScanner.sys 2015-12-25 09:58 - 2015-12-25 10:32 - 00002236 _____ C:\Users\riqdh\Desktop\Protection bancaire.lnk 2015-12-25 09:57 - 2015-12-25 09:57 - 00001124 _____ C:\Users\Public\Desktop\Kaspersky Internet Security.lnk 2015-12-25 09:57 - 2015-12-25 09:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2015-12-25 09:56 - 2015-12-28 10:11 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2015-12-25 09:56 - 2015-12-25 09:56 - 00000000 ____D C:\Windows\ELAMBKUP 2015-12-25 09:56 - 2015-12-25 09:56 - 00000000 ____D C:\Program Files\Kaspersky Lab 2015-12-25 09:55 - 2015-12-25 10:29 - 00644808 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2015-12-25 09:55 - 2015-12-25 10:29 - 00112136 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2015-12-25 09:55 - 2014-04-10 17:25 - 00034400 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klhk.sys 2015-12-25 09:47 - 2015-12-25 09:47 - 297451693 _____ C:\Windows\MEMORY.DMP 2015-12-25 09:47 - 2015-12-25 09:47 - 00153312 _____ C:\Windows\Minidump\122515-17113-01.dmp 2015-12-25 09:47 - 2015-12-25 09:47 - 00000000 ____D C:\Windows\Minidump 2015-12-24 12:39 - 2015-12-26 02:43 - 1477545478 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.io ] Dragon.Blade.2015.FRENCH.SUBFORCED.BRRip.x264.AC3-KiKi.mkv 2015-12-24 09:03 - 2015-12-24 09:03 - 00000000 ____D C:\Users\riqdh\Downloads\[ www.CpasBien.io ] The.Martian.2015.FRENCH.DVDRip.XViD.AC3-FUNKKY 2015-12-24 08:39 - 2015-12-28 10:11 - 00000000 ____D C:\Program Files\Mozilla Firefox 2015-12-21 10:16 - 2015-12-23 12:01 - 1461975376 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.pw ] Mad.Max.Fury.Road.2015.FRENCH.BDRip.XviD-GLUPS.avi 2015-12-21 07:40 - 2015-12-21 07:40 - 00000000 ____D C:\Users\riqdh\Downloads\Extraction.2016.FRENCH.DVDRip.XviD.AC3-Q7 2015-12-20 08:15 - 2015-12-20 08:15 - 00001830 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ÇáãÑÔÏ Ýí ÇáÑíÇÖíÇÊ.lnk 2015-12-20 08:15 - 2015-12-20 08:15 - 00001824 _____ C:\ProgramData\Microsoft\Windows\Start Menu\ÇáãÑÔÏ Ýí ÇáÑíÇÖíÇÊ.lnk 2015-12-20 08:15 - 2015-12-20 08:15 - 00001818 _____ C:\Users\Public\Desktop\ÇáãÑÔÏ Ýí ÇáÑíÇÖíÇÊ.lnk 2015-12-20 08:15 - 2015-12-20 08:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Math_5AP 2015-12-20 08:15 - 2015-12-20 08:15 - 00000000 ____D C:\Program Files\Math_5AP 2015-12-20 07:46 - 2015-12-20 07:48 - 18740720 _____ C:\Users\riqdh\Desktop\math.5AP.rar 2015-12-20 07:02 - 2015-12-20 09:40 - 1466402820 ____R C:\Users\riqdh\Downloads\[ www.Cpasbien.pw ] Exodus.Gods.and.Kings.2014.FRENCH.DVDRip.XviD-FUZION.avi 2015-12-18 05:20 - 2015-12-10 00:53 - 00124992 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys 2015-12-17 09:03 - 2015-12-17 09:08 - 00000000 ____D C:\Users\riqdh\Desktop\Boukeur 14 12 2006 -2- 2015-12-17 08:57 - 2015-12-17 09:01 - 00000000 ____D C:\Users\riqdh\Desktop\Boubkeur 14 12 2006 -1- 2015-12-17 08:38 - 2015-12-17 08:39 - 00000000 ____D C:\Users\riqdh\Desktop\Boubkeur 26 01 2001 2015-12-15 10:53 - 2015-12-15 10:53 - 00000000 ____D C:\Users\riqdh\Desktop\photos 2015-12-15 06:20 - 2015-12-15 06:21 - 86765036 _____ C:\Users\riqdh\Desktop\كل ما فعله رياض محرز ضد تشيلسي Mahrez Vs CheIsea.avi 2015-12-14 10:51 - 2015-12-15 05:59 - 1468088335 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.pw ] Monsters.Dark.Continent.2014.TRUEFRENCH.BDRiP.XViD-AViTECH.avi 2015-12-14 10:41 - 2015-12-14 10:43 - 00000000 ____D C:\Users\riqdh\Downloads\Turbo.Kid.2015.FRENCH.BDRiP.XViD-FUNKKY 2015-12-14 10:38 - 2015-12-14 10:38 - 00000000 ____D C:\Users\riqdh\Downloads\Heist.2015.TRUEFRENCH.DVDRiP.XViD-AViTECH 2015-12-11 09:22 - 2015-12-12 10:14 - 1469038592 ____R C:\Users\riqdh\Downloads\Southpaw.2015.FRENCH.BDRiP.XViD-AViTECH.www.Cpasbien.pw.avi 2015-12-11 09:20 - 2015-12-11 10:42 - 735627777 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.io ] Riot.2015.TRUEFRENCH.DVDRiP.XviD-Slay3R.avi 2015-12-11 09:06 - 2015-12-11 09:06 - 00000000 ____D C:\Users\riqdh\Desktop\starsat 2015-12-11 08:07 - 2015-12-20 10:01 - 00000000 ____D C:\Users\riqdh\Desktop\Geant 2 Tuner New_V1.46_20151127 2015-12-11 07:06 - 2015-12-11 07:06 - 00000000 ____D C:\ProgramData\IDM 2015-12-07 22:07 - 2015-12-11 07:34 - 1514645752 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.io ] War.Room.2015.FRENCH.BDRip.XviD-ViVi.avi 2015-12-07 22:07 - 2015-12-07 22:07 - 00000000 ____D C:\Users\riqdh\Downloads\The.Secret.Society.Of.Souptown.2015.TRUEFRENCH.DVDRip.XviD-UTT 2015-12-07 11:31 - 2015-12-07 14:17 - 808494989 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.io ] Halo.The.Fall.of.Reach.2015.FRENCH.BDRip.XviD-ViVi.avi 2015-12-07 11:29 - 2015-12-07 11:31 - 00000000 ____D C:\Users\riqdh\Downloads\Maze.Runner.The.Scorch.Trials.2015.TRUEFRENCH.BDRiP.XViD-AViTECH 2015-12-07 11:29 - 2015-12-07 11:29 - 00000000 ____D C:\Users\riqdh\Downloads\[ www.CpasBien.io ] The.Transporter.Refueled.2015.FRENCH.BDRiP.XViD-AViTECH 2015-12-07 10:31 - 2015-12-07 10:31 - 00000000 ____D C:\Windows\system32\config\s 2015-12-06 11:58 - 2015-12-06 11:58 - 00000000 ____D C:\Users\Default\AppData\Roaming\AVAST Software 2015-12-06 11:58 - 2015-12-06 11:58 - 00000000 ____D C:\Users\Default\AppData\Roaming\Adobe 2015-12-06 11:58 - 2015-12-06 11:58 - 00000000 ____D C:\Users\Default User\AppData\Roaming\AVAST Software 2015-12-06 11:58 - 2015-12-06 11:58 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Adobe 2015-12-06 11:37 - 2015-12-06 11:57 - 00000000 ____D C:\Users\riqdh\Desktop\امتحان الرياضيات 2013 المسيلة 2015-12-06 10:07 - 2015-12-06 10:07 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf 2015-12-06 10:07 - 2015-12-06 10:07 - 00000000 ____D C:\ProgramData\MobiConnect 2015-12-06 10:07 - 2012-08-19 16:37 - 01112288 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll 2015-12-06 10:07 - 2012-08-19 16:37 - 01112288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfCoInstaller01007.dll 2015-12-06 10:06 - 2015-12-06 10:29 - 00000000 ____D C:\ProgramData\DatacardService 2015-12-04 11:19 - 2015-12-28 10:42 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\vlc 2015-12-04 11:18 - 2015-12-26 11:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2015-12-04 11:14 - 2015-12-26 11:58 - 00000984 _____ C:\Users\Public\Desktop\VLC media player.lnk 2015-12-04 10:49 - 2014-11-01 10:42 - 15802152 _____ (Fathi Zidan) C:\Users\riqdh\Desktop\Algerian newspapers 1.0.exe 2015-12-04 10:45 - 2015-12-04 10:45 - 00000000 ____D C:\Program Files\VID_187C&PID_0600 2015-12-04 10:19 - 2015-12-25 10:33 - 00000000 ____D C:\Program Files\Common Files\AV 2015-11-27 09:43 - 2015-12-20 08:17 - 00000000 ____D C:\Users\riqdh\Desktop\exislam5p1tr 2015-11-27 09:43 - 2015-12-06 11:54 - 00000000 ____D C:\Users\riqdh\Desktop\exhg5p1tr 2015-11-27 09:43 - 2015-12-06 11:54 - 00000000 ____D C:\Users\riqdh\Desktop\excivil5p1tr 2015-11-27 09:37 - 2015-11-27 09:38 - 05119512 _____ C:\Users\riqdh\Downloads\exmath5p1tr.rar 2015-11-27 01:29 - 2015-11-27 01:29 - 00052938 _____ C:\Users\riqdh\Downloads\اختبارات السنة الخامسة ابتدائي في جميع المواد مع الحلول للفصل الاول.rar 2015-11-26 07:46 - 2015-11-26 08:42 - 737976320 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.io ] 400.Days.2015.TRUEFRENCH.SUBFORCED.DVDRIP.XVid-LYS.avi 2015-11-25 06:30 - 2015-11-25 08:12 - 734302208 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.io ] 2047.Sights.Of.Death.2014.FRENCH.BDRiP.XViD-AViTECH.avi 2015-11-25 06:28 - 2015-11-25 08:22 - 738820096 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.io ] 10.000.Days.2014.STV.TRUEFRENCH.DVDRip.XviD.avi 2015-11-25 04:30 - 2015-11-25 05:45 - 734373888 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.io ] Momentum.2015.TRUEFRENCH.BDRiP.XViD-AViTECH.avi 2015-11-24 12:14 - 2015-11-24 12:15 - 00000000 ____D C:\Users\riqdh\Desktop\اختبارات 2015-11-24 11:51 - 2015-11-24 11:54 - 00000000 ____D C:\Users\riqdh\Desktop\Polyphene - Best Of 2014 2015-11-24 11:24 - 2015-12-28 09:51 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\DMCache 2015-11-24 11:24 - 2015-12-26 11:53 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\IDM 2015-11-24 11:24 - 2015-12-24 11:35 - 00000000 ____D C:\Program Files\Internet Download Manager 2015-11-24 11:24 - 2015-11-24 11:24 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager 2015-11-24 11:24 - 2015-11-24 11:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager 2015-11-24 11:19 - 2015-11-24 11:53 - 00000000 ____D C:\Users\riqdh\Desktop\polyphen 2015-11-24 10:58 - 2015-12-06 11:57 - 00000000 ____D C:\Users\riqdh\Desktop\الرياضيات 2015-11-24 10:57 - 2015-11-24 10:57 - 00252718 _____ C:\Users\riqdh\Downloads\الرياضيات(1).rar 2015-11-24 10:55 - 2015-11-24 10:56 - 03425781 _____ C:\Users\riqdh\Downloads\امتحان الرياضيات 2013 المسيلة.rar 2015-11-24 10:51 - 2015-11-24 10:51 - 00161308 _____ C:\Users\riqdh\Downloads\تقويم الفصل الأول س5.rar 2015-11-24 10:48 - 2015-11-24 10:50 - 03157923 _____ C:\Users\riqdh\Downloads\امتحان اللغة العربية - 2013 المسيلة.rar 2015-11-24 09:08 - 2015-11-25 05:07 - 1521547344 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.io ] Hitman.Agent.47.2015.FRENCH.BRRIP.XviD.AC3-ShowFr.avi 2015-11-24 09:07 - 2015-11-25 03:34 - 1471285261 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.io ] Ant.Man.2015.FRENCH.DVDRip.XViD.AC3-FUNKKY.avi 2015-11-23 12:20 - 2015-11-23 12:20 - 22846798 _____ C:\Users\riqdh\Desktop\Algeria got talent mdr.تموت ضحك.avi 2015-11-22 23:00 - 2015-11-22 23:17 - 215193992 _____ C:\Users\riqdh\Downloads\vpsupd4.exe 2015-11-20 10:58 - 2013-01-14 19:33 - 00000000 ____D C:\Users\riqdh\Desktop\LAN_Broadcom_15.0.7.1_Win7x86x64 2015-11-19 03:12 - 2015-11-19 10:57 - 00000000 ____D C:\Users\riqdh\Desktop\New folder (2) 2015-11-19 02:35 - 2015-11-19 02:37 - 00000000 ____D C:\Program Files\Common Files\65ad47d7-2e27-4a5c-b238-26643fdaeb98 2015-11-19 02:32 - 2015-11-19 02:35 - 00000000 ____D C:\ProgramData\65ad47d7-2e27-4a5c-b238-26643fdaeb98 2015-11-19 02:24 - 2015-11-19 02:24 - 00160376 _____ C:\Users\riqdh\Downloads\الفرنسية.rar 2015-11-19 02:23 - 2015-11-19 02:24 - 00307328 _____ C:\Users\riqdh\Downloads\الجغرافيا.rar 2015-11-19 02:23 - 2015-11-19 02:23 - 00780835 _____ C:\Users\riqdh\Downloads\التربية العلمية و التكنولوجية.rar 2015-11-19 02:23 - 2015-11-19 02:23 - 00138108 _____ C:\Users\riqdh\Downloads\التربية المدنية.rar 2015-11-19 02:23 - 2015-11-19 02:23 - 00098225 _____ C:\Users\riqdh\Downloads\التاريخ.rar 2015-11-19 02:22 - 2015-11-19 02:22 - 00272474 _____ C:\Users\riqdh\Downloads\اللغة العربية.rar 2015-11-19 02:22 - 2015-11-19 02:22 - 00179353 _____ C:\Users\riqdh\Downloads\التربية الاسلامية.rar 2015-11-19 02:21 - 2015-11-19 02:21 - 00252718 _____ C:\Users\riqdh\Downloads\الرياضيات.rar 2015-11-16 11:50 - 2015-11-16 11:50 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\Media Player Classic 2015-11-16 10:29 - 2015-11-17 10:12 - 1473195753 ____R C:\Users\riqdh\Downloads\[ www.Cpasbien.pw ] Icetastrophe.2015.FRENCH.BDRiP.x264.AC3-STVFRV.mkv 2015-11-16 07:26 - 2015-11-16 07:30 - 01726173 _____ C:\Users\riqdh\Downloads\Gx6107_Cool_1030TILLEULUM_v2.44_Update_07252015_RVfpC.rar 2015-11-15 10:56 - 2015-11-16 09:55 - 1170131364 ____R C:\Users\riqdh\Downloads\[ www.Cpasbien.pw ] Firequake.2015.FRENCH.BDRip.x264.AC3-STVFRV.mkv 2015-11-14 12:09 - 2015-10-27 19:51 - 00000000 ____D C:\Users\riqdh\Desktop\مغارة 2015-11-14 12:05 - 2015-11-14 12:07 - 02746064 _____ C:\Users\riqdh\Downloads\{733B18A8-A6DD-4844-BCA0-C91D77FF072C}.rar 2015-11-14 11:25 - 2015-12-14 12:08 - 00000000 ____D C:\Users\riqdh\AppData\Local\ElevatedDiagnostics 2015-11-14 09:35 - 2015-11-16 10:29 - 1468989440 ____R C:\Users\riqdh\Downloads\[ www.Cpasbien.pw ] Chappie.2015.FRENCH.BRRip.XviD.AC3-S.V.avi 2015-11-14 09:32 - 2015-11-15 10:52 - 1466116096 ____R C:\Users\riqdh\Downloads\[ www.Cpasbien.pw ] Jupiter.Ascending.2015.FRENCH.DVDRip.XviD-GLUPS.avi 2015-11-14 09:30 - 2015-11-17 10:12 - 1466349568 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.pw ] Air.2015.FRENCH.BDRip.XviD.AC3-GLUPS.avi 2015-11-14 09:29 - 2015-11-15 10:41 - 1472330140 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.pw ] Tomorrowland.2015.TRUEFRENCH.BDRip.XviD-EXTREME.avi 2015-11-12 03:34 - 2009-11-25 11:47 - 01130824 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2015-11-12 03:34 - 2009-11-25 11:47 - 00297808 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll 2015-11-12 03:34 - 2009-11-25 11:47 - 00295264 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe 2015-11-12 03:34 - 2009-11-25 11:47 - 00099176 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll 2015-11-12 03:34 - 2009-11-25 11:47 - 00049472 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll 2015-11-12 03:31 - 2015-11-12 03:33 - 00000000 ____D C:\Users\riqdh\AppData\LocalLow\Yandex 2015-11-12 03:31 - 2015-11-12 03:33 - 00000000 ____D C:\Users\riqdh\AppData\Local\Yandex 2015-11-12 03:30 - 2015-11-12 03:33 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\Yandex 2015-11-12 03:30 - 2015-11-12 03:30 - 00000000 ____D C:\Users\riqdh\AppData\Local\Xpom 2015-11-12 03:30 - 2015-11-12 03:30 - 00000000 ____D C:\Users\riqdh\AppData\Local\Nichrome 2015-11-12 03:30 - 2015-11-12 03:30 - 00000000 ____D C:\Users\riqdh\AppData\Local\Chromium 2015-11-12 03:25 - 2015-12-25 00:28 - 00000000 ____D C:\Program Files\VkontakteDJ 2015-11-11 10:48 - 2015-12-14 11:11 - 00000000 ____D C:\Users\riqdh\Desktop\New folder 2015-11-11 10:12 - 2015-11-11 10:12 - 00010532 _____ C:\Users\riqdh\Downloads\french-4am-1trim3.rar 2015-11-11 10:11 - 2015-11-11 10:11 - 00010390 _____ C:\Users\riqdh\Downloads\french-4am-1trim2.rar 2015-11-11 00:43 - 2015-11-11 00:43 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2015-11-10 08:47 - 2015-11-10 08:47 - 00008654 _____ C:\Users\riqdh\HELP_DECRYPT.HTML 2015-11-10 08:47 - 2015-11-10 08:47 - 00008654 _____ C:\Users\HELP_DECRYPT.HTML 2015-11-10 08:47 - 2015-11-10 08:47 - 00004270 _____ C:\Users\riqdh\HELP_DECRYPT.TXT 2015-11-10 08:47 - 2015-11-10 08:47 - 00004270 _____ C:\Users\HELP_DECRYPT.TXT 2015-11-10 07:58 - 2015-11-10 07:58 - 00008654 _____ C:\Users\riqdh\AppData\Roaming\HELP_DECRYPT.HTML 2015-11-10 07:58 - 2015-11-10 07:58 - 00008654 _____ C:\Users\riqdh\AppData\LocalLow\HELP_DECRYPT.HTML 2015-11-10 07:58 - 2015-11-10 07:58 - 00008654 _____ C:\Users\riqdh\AppData\Local\HELP_DECRYPT.HTML 2015-11-10 07:58 - 2015-11-10 07:58 - 00008654 _____ C:\Users\riqdh\AppData\HELP_DECRYPT.HTML 2015-11-10 07:58 - 2015-11-10 07:58 - 00004270 _____ C:\Users\riqdh\AppData\Roaming\HELP_DECRYPT.TXT 2015-11-10 07:58 - 2015-11-10 07:58 - 00004270 _____ C:\Users\riqdh\AppData\LocalLow\HELP_DECRYPT.TXT 2015-11-10 07:58 - 2015-11-10 07:58 - 00004270 _____ C:\Users\riqdh\AppData\Local\HELP_DECRYPT.TXT 2015-11-10 07:58 - 2015-11-10 07:58 - 00004270 _____ C:\Users\riqdh\AppData\HELP_DECRYPT.TXT 2015-11-10 07:56 - 2015-11-10 07:56 - 00008654 _____ C:\ProgramData\HELP_DECRYPT.HTML 2015-11-10 07:56 - 2015-11-10 07:56 - 00004270 _____ C:\ProgramData\HELP_DECRYPT.TXT 2015-11-10 07:54 - 2015-11-10 21:31 - 00000000 ___HD C:\f5f99413 2015-11-07 20:32 - 2014-08-23 10:46 - 02205600 _____ C:\Users\riqdh\Desktop\Examens 5 AP.rar 2015-11-07 20:31 - 2014-08-23 09:44 - 06133319 _____ C:\Users\riqdh\Desktop\5 emme annee.exe 2015-11-07 19:41 - 2015-11-11 02:15 - 1497447860 ____R C:\Users\riqdh\Downloads\[ www.Cpasbien.pw ] Interstellar.2014.TRUEFRENCH.BRRip.XviD-Slay3R.avi 2015-11-06 21:04 - 2015-12-24 10:31 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\dvdcss 2015-11-06 20:34 - 2015-11-06 20:50 - 1283270976 _____ C:\Users\riqdh\Desktop\La guerre d'Algérie de 1954 à 1962 comme vous n'avez jamais vu auparavant !!!.avi 2015-11-06 19:21 - 2015-11-19 02:32 - 00001260 _____ C:\Users\Public\Desktop\Free YouTube Download.lnk 2015-11-06 19:16 - 2015-11-12 03:30 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\Opera Software 2015-11-06 19:16 - 2015-11-06 19:23 - 00000000 ____D C:\Users\riqdh\AppData\Local\Opera Software 2015-11-06 19:11 - 2015-11-06 19:19 - 39228592 _____ (DVDVideoSoft Ltd. ) C:\Users\riqdh\Downloads\FreeYouTubeDownload.exe 2015-11-06 17:58 - 2015-11-06 19:23 - 00000000 ____D C:\Program Files\Opera 2015-11-06 17:53 - 2015-11-19 02:32 - 00001199 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2015-11-06 17:53 - 2015-11-19 02:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2015-11-06 17:53 - 2015-11-19 02:32 - 00000000 ____D C:\Program Files\DVDVideoSoft 2015-11-06 17:53 - 2015-11-19 02:31 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\RPEng 2015-11-06 17:53 - 2015-11-19 02:31 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2015-11-06 17:53 - 2015-11-06 19:21 - 00000000 ____D C:\Program Files\FreeCodecPack 2015-11-06 17:53 - 2015-11-06 17:53 - 00002272 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk 2015-11-06 17:51 - 2015-12-27 11:08 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\DVDVideoSoft 2015-11-06 17:12 - 2015-11-06 17:12 - 00040704 _____ C:\Users\riqdh\Downloads\math+sujet(2).rar 2015-11-06 17:12 - 2015-11-06 17:12 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\WinRAR 2015-11-05 12:19 - 2015-11-06 17:12 - 00040704 _____ C:\Users\riqdh\Downloads\math+sujet.rar 2015-11-05 12:19 - 2015-11-06 17:12 - 00040704 _____ C:\Users\riqdh\Downloads\arab+sujet.rar 2015-11-05 11:19 - 2015-11-05 11:19 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2015-11-05 10:27 - 2015-11-05 21:43 - 1472826560 ____R C:\Users\riqdh\Downloads\[ www.CpasBien.pw ] Avengers.Age.of.Ultron.2015.TRUEFRENCH.WEBRip.MD.XviD-SVR.avi 2015-11-05 10:18 - 2015-11-06 19:05 - 1349012885 ____R C:\Users\riqdh\Downloads\Self.Less.2015.FRENCH.FRENCH.BDRip.x264.AC3-ViVi-www.Cpasbien.pw.mkv 2015-11-04 20:56 - 2015-11-04 20:56 - 00000000 ____D C:\Users\riqdh\AppData\Local\Macromedia 2015-11-04 20:55 - 2015-12-28 10:51 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-11-04 20:55 - 2015-12-11 08:51 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-11-04 20:22 - 2015-11-04 20:22 - 00243992 _____ C:\Users\riqdh\Downloads\Firefox Setup Stub 42.0.exe 2015-11-04 20:19 - 2015-11-04 20:19 - 00000000 ____D C:\ProgramData\Mozilla 2015-11-04 20:18 - 2015-12-28 09:49 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2015-11-04 18:01 - 2015-11-12 00:30 - 00000000 ____D C:\Windows\system32\vbox 2015-11-04 13:23 - 2015-12-25 09:50 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\AVAST Software 2015-11-04 13:23 - 2015-11-04 13:25 - 50063360 _____ C:\Program Files\GUT735C.tmp 2015-11-04 13:23 - 2015-11-04 13:23 - 00000000 ____D C:\Program Files\GUM735B.tmp 2015-11-04 12:45 - 2015-12-25 09:50 - 00000000 ____D C:\ProgramData\AVAST Software 2015-11-04 12:25 - 2015-11-04 12:25 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\Macromedia 2015-11-04 12:24 - 2015-11-05 11:23 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\Adobe 2015-11-04 11:49 - 2015-11-10 07:59 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\Mozilla 2015-11-04 11:49 - 2015-11-10 07:58 - 00000000 ____D C:\Users\riqdh\AppData\Local\Mozilla 2015-11-04 11:49 - 2015-11-04 11:49 - 00000000 _____ C:\Windows\nsreg.dat 2015-11-04 11:38 - 2015-11-04 11:38 - 00000000 __SHD C:\found.000 2015-11-03 20:53 - 2015-11-03 20:53 - 00002753 _____ C:\Users\riqdh\Desktop\Microsoft Office Word 2007.lnk 2015-11-03 20:53 - 2015-11-03 20:53 - 00002711 _____ C:\Users\riqdh\Desktop\Microsoft Office Excel 2007.lnk 2015-11-03 20:51 - 2014-09-30 15:11 - 00889952 _____ (NirSoft) C:\Users\riqdh\Desktop\WNetWatcher.exe 2015-11-03 20:50 - 2015-11-03 20:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2015-11-03 20:49 - 2015-11-03 20:49 - 00000000 ____D C:\Program Files\Microsoft Works 2015-11-03 20:48 - 2015-11-03 20:48 - 00000000 ____D C:\Windows\PCHEALTH 2015-11-03 20:48 - 2015-11-03 20:48 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 2015-11-03 20:48 - 2015-11-03 20:48 - 00000000 ____D C:\Program Files\Common Files\DESIGNER 2015-11-03 20:46 - 2015-11-03 20:48 - 00000000 ____D C:\Program Files\Microsoft Office 2015-11-03 20:46 - 2015-11-03 20:46 - 00000000 ____D C:\Users\riqdh\AppData\Local\Microsoft Help 2015-11-03 20:46 - 2015-11-03 20:46 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 8 2015-11-03 20:44 - 2015-11-03 20:44 - 00001896 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk 2015-11-03 20:43 - 2015-11-03 20:44 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\DAEMON Tools Lite 2015-11-03 20:43 - 2015-11-03 20:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite 2015-11-03 20:43 - 2015-11-03 20:43 - 00242240 _____ (DT Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys 2015-11-03 20:43 - 2015-11-03 20:43 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite 2015-11-03 20:43 - 2015-11-03 20:43 - 00000000 ____D C:\Program Files\DAEMON Tools Lite 2015-11-03 20:41 - 2015-11-03 20:41 - 00715248 _____ (Duplex Secure Ltd.) C:\Windows\system32\Drivers\sptd.sys 2015-11-03 20:35 - 2015-11-12 03:30 - 00000000 ____D C:\Users\riqdh\AppData\Local\Google 2015-11-03 20:35 - 2015-11-04 20:12 - 00000000 ____D C:\Program Files\Google 2015-11-03 20:34 - 2015-11-10 08:00 - 00000000 ____D C:\ProgramData\Alwil Software 2015-11-03 20:33 - 2015-11-07 09:09 - 00000000 ____D C:\ProgramData\Adobe 2015-11-03 20:33 - 2015-11-03 20:33 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk 2015-11-03 20:33 - 2015-11-03 20:33 - 00001984 _____ C:\Users\Public\Desktop\Adobe Reader 9.lnk 2015-11-03 20:33 - 2015-11-03 20:33 - 00000000 ____D C:\Program Files\Common Files\Adobe 2015-11-03 20:33 - 2015-11-03 20:33 - 00000000 ____D C:\Program Files\Adobe 2015-11-03 20:31 - 2015-12-11 08:51 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-11-03 20:31 - 2015-11-05 11:23 - 00000000 ____D C:\Users\riqdh\AppData\Local\Adobe 2015-11-03 20:31 - 2015-11-03 20:33 - 00000000 ____D C:\Users\riqdh\AppData\Local\NOS 2015-11-03 20:30 - 2015-11-03 20:30 - 00000813 _____ C:\Users\riqdh\Desktop\µTorrent.lnk 2015-11-03 20:30 - 2015-11-03 20:30 - 00000793 _____ C:\Users\riqdh\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2015-11-03 20:29 - 2015-12-28 10:55 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\uTorrent 2015-11-03 20:29 - 2015-11-03 20:29 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-11-03 20:29 - 2015-11-03 20:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-11-03 20:29 - 2015-11-03 20:29 - 00000000 ____D C:\Program Files\WinRAR 2015-11-03 20:25 - 2015-11-03 20:25 - 00000000 ____D C:\Program Files\DIFX 2015-11-03 19:59 - 2011-06-09 22:34 - 00100896 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst32.dll 2015-11-03 19:59 - 2011-06-09 22:34 - 00080416 _____ C:\Windows\system32\RtNicProp32.dll 2015-11-03 19:53 - 2015-11-03 19:53 - 00002029 _____ C:\Users\Public\Desktop\Super-Charger.lnk 2015-11-03 19:53 - 2015-11-03 19:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI 2015-11-03 19:53 - 2015-11-03 19:53 - 00000000 ____D C:\Program Files\MSI 2015-11-03 19:52 - 2015-11-03 19:52 - 00000000 ____D C:\Windows\system32\RTCOM 2015-11-03 19:51 - 2015-11-03 19:52 - 00000000 ___HD C:\Program Files\Temp 2015-11-03 19:51 - 2011-09-13 02:34 - 03665704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHDA.sys 2015-11-03 19:51 - 2011-09-06 23:37 - 04228200 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO.dll 2015-11-03 19:51 - 2011-09-05 18:16 - 02270824 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkPgExt.dll 2015-11-03 19:51 - 2011-09-05 01:06 - 00081000 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoInst.dll 2015-11-03 19:51 - 2011-08-31 23:08 - 01510912 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes.dat 2015-11-03 19:51 - 2011-08-31 03:12 - 01698408 ____R (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll 2015-11-03 19:51 - 2011-08-23 01:00 - 00357712 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT.dll 2015-11-03 19:51 - 2011-08-18 22:54 - 01313384 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApoApi.dll 2015-11-03 19:51 - 2011-08-05 09:39 - 00413696 _____ (DTS) C:\Windows\system32\DTSU2PLFX32.dll 2015-11-03 19:51 - 2011-08-05 09:39 - 00390656 _____ (DTS) C:\Windows\system32\DTSU2PGFX32.dll 2015-11-03 19:51 - 2011-08-05 09:39 - 00327168 _____ (DTS) C:\Windows\system32\DTSU2PREC32.dll 2015-11-03 19:51 - 2011-07-27 08:54 - 01836376 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll 2015-11-03 19:51 - 2011-07-27 08:54 - 01725784 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib.dll 2015-11-03 19:51 - 2011-06-30 00:14 - 01497704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSndMgr.cpl 2015-11-03 19:51 - 2011-06-26 22:53 - 03327320 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek.dll 2015-11-03 19:51 - 2011-06-13 19:13 - 00178624 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo2.dll 2015-11-03 19:51 - 2011-05-30 17:42 - 01509480 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL.dll 2015-11-03 19:51 - 2011-05-30 17:42 - 01292904 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL.dll 2015-11-03 19:51 - 2011-05-30 17:42 - 01220200 _____ (DTS) C:\Windows\system32\DTSBoostDLL.dll 2015-11-03 19:51 - 2011-05-30 17:42 - 00654952 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL.dll 2015-11-03 19:51 - 2011-05-30 17:42 - 00631400 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL.dll 2015-11-03 19:51 - 2011-05-30 17:42 - 00601704 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL.dll 2015-11-03 19:51 - 2011-05-30 17:42 - 00458344 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL.dll 2015-11-03 19:51 - 2011-05-30 17:42 - 00389736 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL.dll 2015-11-03 19:51 - 2011-05-30 17:42 - 00375400 _____ (DTS) C:\Windows\system32\DTSLimiterDLL.dll 2015-11-03 19:51 - 2011-05-30 17:42 - 00218728 _____ (DTS) C:\Windows\system32\DTSGFXAPONS.dll 2015-11-03 19:51 - 2011-05-30 17:42 - 00218728 _____ (DTS) C:\Windows\system32\DTSGFXAPO.dll 2015-11-03 19:51 - 2011-05-30 17:42 - 00218216 _____ (DTS) C:\Windows\system32\DTSLFXAPO.dll 2015-11-03 19:51 - 2011-05-04 23:24 - 01740352 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO.dll 2015-11-03 19:51 - 2011-05-04 22:14 - 00214368 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK.dll 2015-11-03 19:51 - 2011-05-04 22:14 - 00074080 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM.dll 2015-11-03 19:51 - 2011-05-04 22:14 - 00068960 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO.dll 2015-11-03 19:51 - 2011-05-01 22:27 - 03296600 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP32A.dll 2015-11-03 19:51 - 2011-05-01 22:27 - 00345944 _____ (Dolby Laboratories) C:\Windows\system32\R4EED32A.dll 2015-11-03 19:51 - 2011-05-01 22:27 - 00103256 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL32A.dll 2015-11-03 19:51 - 2011-05-01 22:27 - 00088408 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA32A.dll 2015-11-03 19:51 - 2011-05-01 22:27 - 00061272 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG32A.dll 2015-11-03 19:51 - 2011-03-16 20:16 - 01379760 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll 2015-11-03 19:51 - 2011-03-07 01:03 - 00134584 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll 2015-11-03 19:51 - 2010-11-07 15:31 - 00359768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP32A.dll 2015-11-03 19:51 - 2010-11-07 15:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT32.dll 2015-11-03 19:51 - 2010-11-07 15:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA32.dll 2015-11-03 19:51 - 2010-11-07 15:31 - 00170840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED32A.dll 2015-11-03 19:51 - 2010-11-07 15:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL32A.dll 2015-11-03 19:51 - 2010-11-07 15:31 - 00064856 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG32A.dll 2015-11-03 19:51 - 2010-10-02 21:45 - 00259928 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll 2015-11-03 19:51 - 2010-09-26 17:34 - 00232792 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll 2015-11-03 19:51 - 2010-07-22 00:37 - 00175200 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTACap.dll 2015-11-03 19:51 - 2010-05-06 01:35 - 00252760 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll 2015-11-03 19:51 - 2009-12-03 23:43 - 00132368 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO.dll 2015-11-03 19:51 - 2009-11-23 17:55 - 00345328 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSXT.dll 2015-11-03 19:51 - 2009-11-23 17:55 - 00185584 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSHD.dll 2015-11-03 19:51 - 2009-11-23 17:55 - 00173296 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP360.dll 2015-11-03 19:51 - 2009-11-23 17:55 - 00140528 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW.dll 2015-11-03 19:51 - 2009-11-18 02:42 - 01783056 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesLib.dll 2015-11-03 19:51 - 2009-11-17 02:13 - 00096160 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTARen.dll 2015-11-03 19:50 - 2015-12-28 09:55 - 00730320 _____ C:\Windows\system32\PerfStringBackup.INI 2015-11-03 19:50 - 2015-12-04 10:45 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2015-11-03 19:50 - 2015-11-03 19:59 - 00000000 ____D C:\Program Files\Realtek 2015-11-03 19:50 - 2015-11-03 19:50 - 00000000 ____D C:\Program Files\Intel 2015-11-03 19:50 - 2011-06-09 22:34 - 00394856 _____ (Realtek ) C:\Windows\system32\Drivers\Rt86win7.sys 2015-11-03 19:50 - 2010-06-17 12:02 - 00053248 _____ (Windows XP Bundled build C-Centric Single User) C:\Windows\system32\CSVer.dll 2015-11-03 19:48 - 2015-11-06 19:23 - 00001413 _____ C:\Users\riqdh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-11-03 19:48 - 2015-11-03 19:48 - 00000000 ____D C:\Users\riqdh\AppData\Local\BuildAGadget Content 2015-11-03 19:47 - 2015-11-03 19:47 - 00411368 _____ (Sun Microsystems, Inc.) C:\Windows\system32\deployJava1.dll 2015-11-03 19:47 - 2015-11-03 19:47 - 00153376 _____ (Sun Microsystems, Inc.) C:\Windows\system32\javaws.exe 2015-11-03 19:47 - 2015-11-03 19:47 - 00145184 _____ (Sun Microsystems, Inc.) C:\Windows\system32\javaw.exe 2015-11-03 19:47 - 2015-11-03 19:47 - 00145184 _____ (Sun Microsystems, Inc.) C:\Windows\system32\java.exe 2015-11-03 19:47 - 2015-11-03 19:47 - 00000000 ____D C:\ProgramData\Sun 2015-11-03 19:47 - 2015-11-03 19:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack 2015-11-03 19:47 - 2015-11-03 19:47 - 00000000 ____D C:\Program Files\VideoLAN 2015-11-03 19:47 - 2015-11-03 19:47 - 00000000 ____D C:\Program Files\K-Lite Codec Pack 2015-11-03 19:47 - 2015-11-03 19:47 - 00000000 ____D C:\Program Files\Java 2015-11-03 19:47 - 2015-11-03 19:47 - 00000000 ____D C:\Program Files\Common Files\Java 2015-11-03 19:47 - 2010-04-16 10:00 - 00085504 _____ C:\Windows\system32\ff_vfw.dll 2015-11-03 19:47 - 2010-04-16 10:00 - 00000038 _____ C:\Windows\avisplitter.ini 2015-11-03 19:47 - 2010-03-15 01:31 - 00165376 _____ C:\Windows\system32\unrar.dll 2015-11-03 19:47 - 2010-01-17 07:18 - 00151552 _____ (fccHandler) C:\Windows\system32\ac3acm.acm 2015-11-03 19:47 - 2009-05-29 13:37 - 00205824 _____ C:\Windows\system32\xvidvfw.dll 2015-11-03 19:47 - 2009-05-29 13:31 - 00881664 _____ C:\Windows\system32\xvidcore.dll 2015-11-03 19:47 - 2008-10-03 04:30 - 00000414 _____ C:\Windows\system32\lame_acm.xml 2015-11-03 19:47 - 2008-09-24 10:41 - 00839680 _____ (hxxp://www.mp3dev.org/) C:\Windows\system32\lameACM.acm 2015-11-03 19:47 - 2007-07-10 08:10 - 00000547 _____ C:\Windows\system32\ff_vfw.dll.manifest 2015-11-03 19:47 - 2004-01-25 08:18 - 00217088 _____ (www.helixcommunity.org) C:\Windows\system32\yv12vfw.dll 2015-11-03 19:46 - 2015-11-10 07:59 - 00000000 ____D C:\Users\riqdh\AppData\LocalLow\Sun 2015-11-03 19:46 - 2015-11-03 19:46 - 00000000 ____D C:\Windows\system32\Macromed 2015-11-03 19:46 - 2015-11-03 19:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2015-11-03 19:46 - 2015-11-03 19:46 - 00000000 ____D C:\Program Files\7-Zip 2015-11-03 19:46 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2015-11-03 19:46 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2015-11-03 19:46 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2015-11-03 19:46 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2015-11-03 19:46 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2015-11-03 19:46 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2015-11-03 19:46 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2015-11-03 19:46 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2015-11-03 19:46 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2015-11-03 19:46 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2015-11-03 19:46 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2015-11-03 19:46 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2015-11-03 19:46 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2015-11-03 19:46 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2015-11-03 19:46 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2015-11-03 19:46 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2015-11-03 19:46 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2015-11-03 19:46 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2015-11-03 19:46 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2015-11-03 19:46 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2015-11-03 19:46 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2015-11-03 19:46 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2015-11-03 19:46 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2015-11-03 19:46 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2015-11-03 19:46 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll 2015-11-03 19:46 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2015-11-03 19:46 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2015-11-03 19:46 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2015-11-03 19:46 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2015-11-03 19:46 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2015-11-03 19:46 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2015-11-03 19:46 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2015-11-03 19:46 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2015-11-03 19:46 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2015-11-03 19:46 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2015-11-03 19:46 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2015-11-03 19:46 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2015-11-03 19:46 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2015-11-03 19:46 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2015-11-03 19:46 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2015-11-03 19:46 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2015-11-03 19:46 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2015-11-03 19:46 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2015-11-03 19:46 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2015-11-03 19:46 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2015-11-03 19:46 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2015-11-03 19:46 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2015-11-03 19:46 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2015-11-03 19:46 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2015-11-03 19:46 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2015-11-03 19:46 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2015-11-03 19:46 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2015-11-03 19:46 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2015-11-03 19:46 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2015-11-03 19:46 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2015-11-03 19:46 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2015-11-03 19:46 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2015-11-03 19:46 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2015-11-03 19:46 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2015-11-03 19:46 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2015-11-03 19:46 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2015-11-03 19:46 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2015-11-03 19:46 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2015-11-03 19:46 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2015-11-03 19:46 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2015-11-03 19:46 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2015-11-03 19:46 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2015-11-03 19:46 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2015-11-03 19:46 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2015-11-03 19:46 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2015-11-03 19:46 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2015-11-03 19:46 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2015-11-03 19:46 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2015-11-03 19:46 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2015-11-03 19:46 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2015-11-03 19:46 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2015-11-03 19:46 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2015-11-03 19:46 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2015-11-03 19:46 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2015-11-03 19:46 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2015-11-03 19:46 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2015-11-03 19:46 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2015-11-03 19:46 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2015-11-03 19:45 - 2015-11-10 08:47 - 00000000 ____D C:\Users\riqdh 2015-11-03 19:45 - 2015-11-04 17:41 - 00108824 _____ C:\Users\riqdh\AppData\Local\GDIPFONTCACHEV1.DAT 2015-11-03 19:45 - 2015-11-03 19:45 - 00000020 ___SH C:\Users\riqdh\ntuser.ini 2015-11-03 19:45 - 2015-11-03 19:45 - 00000000 _SHDL C:\Users\riqdh\My Documents 2015-11-03 19:45 - 2015-11-03 19:45 - 00000000 _SHDL C:\Users\riqdh\Documents\My Videos 2015-11-03 19:45 - 2015-11-03 19:45 - 00000000 _SHDL C:\Users\riqdh\Documents\My Pictures 2015-11-03 19:45 - 2015-11-03 19:45 - 00000000 _SHDL C:\Users\riqdh\Documents\My Music 2015-11-03 19:45 - 2009-07-13 23:48 - 00000000 ____D C:\Users\riqdh\AppData\Roaming\Media Center Programs 2015-11-03 19:40 - 2015-11-03 19:40 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2015-11-03 19:40 - 2015-11-03 19:40 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk 2015-11-03 19:34 - 2015-11-03 19:45 - 00000000 ____D C:\Windows\Panther 2015-11-03 19:21 - 2015-12-26 10:31 - 00000000 ____D C:\Windows.old 2015-11-02 09:37 - 2015-11-10 07:56 - 00000000 ____D C:\AdwCleaner 2015-10-31 11:39 - 2015-11-01 10:33 - 00000233 _____ C:\prefs.js 2015-10-31 11:39 - 2015-11-01 10:33 - 00000000 ____D C:\searchplugins 2015-10-31 11:01 - 2015-10-31 11:01 - 00000000 ____D C:\Intel 2015-10-31 10:55 - 2015-10-31 10:55 - 00000000 __RHD C:\MSOCache 2015-10-31 10:39 - 2015-11-10 07:56 - 00000000 ____D C:\9e3613890f1c6ec52a53a1e58b9ca3 2015-10-31 10:31 - 2015-11-03 19:34 - 00008480 __RSH C:\BOOTSECT.BAK 2015-10-31 10:31 - 2009-07-13 17:38 - 00383562 __RSH C:\bootmgr 2015-10-13 06:59 - 2015-10-13 06:59 - 00016128 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\gtkdrv.sys ==================== Three Months Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-12-28 10:55 - 2009-07-13 18:37 - 00000000 ____D C:\Windows 2015-12-28 10:50 - 2009-07-13 20:34 - 00009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-12-28 10:50 - 2009-07-13 20:34 - 00009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-12-28 09:55 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\inf 2015-12-28 09:49 - 2009-07-13 20:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-12-06 10:13 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\system32\NDF ==================== Files in the root of some directories ======= 2015-11-04 13:23 - 2015-11-04 13:25 - 50063360 _____ () C:\Program Files\GUT735C.tmp 2015-11-12 03:24 - 2015-12-24 11:53 - 0002357 _____ () C:\Users\riqdh\AppData\Roaming\dj.log 2015-11-10 07:58 - 2015-11-10 07:58 - 0008654 _____ () C:\Users\riqdh\AppData\Roaming\HELP_DECRYPT.HTML 2015-11-10 07:58 - 2015-11-10 07:58 - 0045988 _____ () C:\Users\riqdh\AppData\Roaming\HELP_DECRYPT.PNG 2015-11-10 07:58 - 2015-11-10 07:58 - 0004270 _____ () C:\Users\riqdh\AppData\Roaming\HELP_DECRYPT.TXT 2015-11-10 07:58 - 2015-11-10 07:58 - 0008654 _____ () C:\Users\riqdh\AppData\Roaming\Microsoft\HELP_DECRYPT.HTML 2015-11-10 07:58 - 2015-11-10 07:58 - 0045988 _____ () C:\Users\riqdh\AppData\Roaming\Microsoft\HELP_DECRYPT.PNG 2015-11-10 07:58 - 2015-11-10 07:58 - 0004270 _____ () C:\Users\riqdh\AppData\Roaming\Microsoft\HELP_DECRYPT.TXT 2015-11-10 07:58 - 2015-11-10 07:58 - 0008654 _____ () C:\Users\riqdh\AppData\Local\HELP_DECRYPT.HTML 2015-11-10 07:58 - 2015-11-10 07:58 - 0045988 _____ () C:\Users\riqdh\AppData\Local\HELP_DECRYPT.PNG 2015-11-10 07:58 - 2015-11-10 07:58 - 0004270 _____ () C:\Users\riqdh\AppData\Local\HELP_DECRYPT.TXT 2015-11-10 07:56 - 2015-11-10 07:56 - 0008654 _____ () C:\ProgramData\HELP_DECRYPT.HTML 2015-11-10 07:56 - 2015-11-10 07:56 - 0045988 _____ () C:\ProgramData\HELP_DECRYPT.PNG 2015-11-10 07:56 - 2015-11-10 07:56 - 0004270 _____ () C:\ProgramData\HELP_DECRYPT.TXT Some files in TEMP: ==================== C:\Users\riqdh\AppData\Local\Temp\GoogleUpdateSetup_1.3.21.169.exe C:\Users\riqdh\AppData\Local\Temp\SPTDinst-x64.exe C:\Users\riqdh\AppData\Local\Temp\vkontaktedj_update_7.exe C:\Users\riqdh\AppData\Local\Temp\vlc-2.0.2-win32.exe C:\Users\riqdh\AppData\Local\Temp\yandex-elements.exe C:\Users\riqdh\AppData\Local\Temp\YandexWorking.exe ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe [2010-05-30 04:44] - [2010-06-05 01:17] - 2617344 ____A (Microsoft Corporation) 10BD5421DA8D1F8FAE6E53A7F963F901 C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed ==================== BCD ================================ Windows Boot Manager -------------------- identifier {bootmgr} device partition=C: description Windows Boot Manager locale en-US inherit {globalsettings} default {current} resumeobject {a2f03e27-7ffd-11e5-9506-a60415897db7} displayorder {current} toolsdisplayorder {memdiag} timeout 30 Windows Boot Loader ------------------- identifier {a2f03e25-7ffd-11e5-9506-a60415897db7} device ramdisk=[C:]\Recovery\a2f03e25-7ffd-11e5-9506-a60415897db7\Winre.wim,{a2f03e26-7ffd-11e5-9506-a60415897db7} path \windows\system32\winload.exe description Windows Recovery Environment inherit {bootloadersettings} osdevice ramdisk=[C:]\Recovery\a2f03e25-7ffd-11e5-9506-a60415897db7\Winre.wim,{a2f03e26-7ffd-11e5-9506-a60415897db7} systemroot \windows nx OptIn winpe Yes Windows Boot Loader ------------------- identifier {current} device partition=C: path \Windows\system32\winload.exe description Windows 7 Alienware locale en-US inherit {bootloadersettings} recoverysequence {a2f03e29-7ffd-11e5-9506-a60415897db7} recoveryenabled No osdevice partition=C: systemroot \Windows resumeobject {a2f03e27-7ffd-11e5-9506-a60415897db7} nx OptIn bootstatuspolicy IgnoreAllFailures Windows Boot Loader ------------------- identifier {a2f03e29-7ffd-11e5-9506-a60415897db7} device ramdisk=[C:]\Recovery\a2f03e29-7ffd-11e5-9506-a60415897db7\Winre.wim,{a2f03e2a-7ffd-11e5-9506-a60415897db7} path \windows\system32\winload.exe description Windows Recovery Environment inherit {bootloadersettings} osdevice ramdisk=[C:]\Recovery\a2f03e29-7ffd-11e5-9506-a60415897db7\Winre.wim,{a2f03e2a-7ffd-11e5-9506-a60415897db7} systemroot \windows nx OptIn winpe Yes Resume from Hibernate --------------------- identifier {a2f03e27-7ffd-11e5-9506-a60415897db7} device partition=C: path \Windows\system32\winresume.exe description Windows Resume Application locale en-US inherit {resumeloadersettings} filedevice partition=C: filepath \hiberfil.sys pae Yes debugoptionenabled No Windows Memory Tester --------------------- identifier {memdiag} device partition=C: path \boot\memtest.exe description Windows Memory Diagnostic locale en-US inherit {globalsettings} badmemoryaccess Yes EMS Settings ------------ identifier {emssettings} bootems Yes Debugger Settings ----------------- identifier {dbgsettings} debugtype Serial debugport 1 baudrate 115200 RAM Defects ----------- identifier {badmemory} Global Settings --------------- identifier {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Boot Loader Settings -------------------- identifier {bootloadersettings} inherit {globalsettings} {hypervisorsettings} Hypervisor Settings ------------------- identifier {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 Resume Loader Settings ---------------------- identifier {resumeloadersettings} inherit {globalsettings} Device options -------------- identifier {a2f03e26-7ffd-11e5-9506-a60415897db7} description Ramdisk Options ramdisksdidevice partition=C: ramdisksdipath \Recovery\a2f03e25-7ffd-11e5-9506-a60415897db7\boot.sdi Device options -------------- identifier {a2f03e2a-7ffd-11e5-9506-a60415897db7} description Ramdisk Options ramdisksdidevice partition=C: ramdisksdipath \Recovery\a2f03e29-7ffd-11e5-9506-a60415897db7\boot.sdi LastRegBack: 2015-12-20 08:35 ==================== End of FRST.txt ============================