Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:20-07-2015 Ran by Hibatoullah (administrator) on HIBATOULLAH on 24-07-2015 09:01:32 Running from C:\Users\Hibatoullah\Desktop Loaded Profiles: Hibatoullah (Available Profiles: Hibatoullah) Platform: Windows 8.1 Single Language (X64) OS Language: Français (France) Internet Explorer Version 11 (Default browser: Opera) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe () C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe (Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Flexera Software, Inc.) C:\Program Files (x86)\ArcGIS\License10.1\bin\lmgrd.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe (Flexera Software, Inc.) C:\Program Files (x86)\ArcGIS\License10.1\bin\lmgrd.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe () C:\Program Files (x86)\My Connection\BackgroundService\ServiceManager.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\ProgramData\MobileBrServ\mbbService.exe () C:\ProgramData\Modem HDM EC156\OnlineUpdate\ouc.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.2\bin\pg_ctl.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\pg_ctl.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.2\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.2\bin\postgres.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (Flexera Software, Inc.) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ESRI) C:\Program Files (x86)\ArcGIS\License10.1\bin\ARCGIS.exe () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\Taskmgr.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Oracle Corporation) C:\Program Files (x86)\NetBeans 8.0.2\bin\netbeans.exe (Oracle Corporation) C:\Program Files (x86)\Java\jdk1.7.0_40\jre\bin\java.exe (Oracle Corporation) C:\Program Files (x86)\Java\jdk1.7.0_40\bin\java.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.3\bin\postgres.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7199448 2013-09-02] (Realtek Semiconductor) HKLM\...\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe [2758200 2013-10-14] (Hewlett-Packard) HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [155704 2013-10-14] (Hewlett-Packard) HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [155704 2013-10-14] (Hewlett-Packard) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [258048 2015-07-18] (apple ins.) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3730344 2015-07-07] (AVG Technologies CZ, s.r.o.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2417350805-2748143230-3866523379-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\_CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2015-06-13] () CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://startpage.partycz.com HKU\S-1-5-21-2417350805-2748143230-3866523379-1001\Software\Microsoft\Internet Explorer\Main,Start Page = www.wana.ma URLSearchHook: HKU\S-1-5-21-2417350805-2748143230-3866523379-1001 - (No Name) - {4c60e5ab-5c68-4c59-abaa-885010b24b32} - No File SearchScopes: HKLM -> {94F7EAB6-000F-44AE-B1BC-43B454FC1C6C} URL = http://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 -> {94F7EAB6-000F-44AE-B1BC-43B454FC1C6C} URL = http://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre6\bin\ssv.dll [2015-06-28] (Sun Microsystems, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2015-06-28] (Sun Microsystems, Inc.) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-08-19] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-08-19] (Oracle Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard) Tcpip\Parameters: [DhcpNameServer] 192.168.1.4 192.168.1.2 8.8.8.8 Tcpip\..\Interfaces\{F228D933-03E6-494B-BE12-3A766ECFBB50}: [DhcpNameServer] 192.168.1.4 192.168.1.2 8.8.8.8 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-14] () FF Plugin: @java.com/DTPlugin,version=1.6.0_45 -> C:\Windows\system32\npdeployJava1.dll [2015-06-28] (Sun Microsystems, Inc.) FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll [2015-06-28] (Sun Microsystems, Inc.) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-06-19] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-14] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-08-19] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-08-19] (Oracle Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-06-19] (Adobe Systems) FF Plugin HKU\.DEFAULT: @unity3d.com/UnityPlayer,version=1.0 -> C:\Windows\system32\config\systemprofile\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File Chrome: ======= CHR Profile: C:\Users\Hibatoullah\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Hibatoullah\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-13] CHR Extension: (Chrome Web Store Payments) - C:\Users\Hibatoullah\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-13] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [680112 2015-06-09] (Adobe Systems Incorporated) R2 ArcGIS License Manager; C:\Program Files (x86)\ArcGIS\License10.1\bin\lmgrd.exe [1408904 2012-01-05] (Flexera Software, Inc.) R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3518376 2015-07-07] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [314304 2015-07-07] (AVG Technologies CZ, s.r.o.) S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation) R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-10-14] () [File not signed] R2 CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-09-05] (CyberLink) R2 CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-09-05] (CyberLink) R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-10-08] (Hewlett-Packard Development Company, L.P.) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () R2 IAM Aegean Modem Device Helper; C:\Program Files (x86)\My Connection\BackgroundService\ServiceManager.exe [53312 2012-03-14] () R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation) S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239184 2014-02-15] () S2 Modem HDM EC156. RunOuc; C:\Program Files (x86)\Modem HDM EC156\UpdateDog\ouc.exe [657504 2012-11-12] () R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [87552 2013-10-14] (Softex Inc.) [File not signed] R2 postgresql-x64-9.2; C:\Program Files\PostgreSQL\9.2\bin\pg_ctl.exe [88576 2014-10-20] (PostgreSQL Global Development Group) [File not signed] R2 postgresql-x64-9.3; C:\Program Files\PostgreSQL\9.3\bin\pg_ctl.exe [89088 2014-10-20] (PostgreSQL Global Development Group) [File not signed] R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [289496 2013-08-23] (Realtek Semiconductor) S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-08-26] (Microsoft Corporation) S3 wampapache; c:\wamp\bin\apache\apache2.4.4\bin\httpd.exe [24576 2013-06-23] (Apache Software Foundation) [File not signed] S3 wampmysqld; c:\wamp\bin\mysql\mysql5.6.12\bin\mysqld.exe [12867584 2013-06-23] () [File not signed] S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AlcatelOTnet; C:\Windows\system32\DRIVERS\AlcatelOTUsbnet.sys [138752 2011-06-20] (TCT International Mobile Ltd) S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21152 2015-03-27] (AVG Technologies CZ, s.r.o.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [162784 2015-03-11] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [293296 2015-06-26] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [253408 2015-05-12] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [259040 2015-06-16] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [226784 2015-06-10] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.) R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [295400 2015-06-15] (AVG Technologies CZ, s.r.o.) S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation) S3 mpfilt; C:\Windows\SysWOW64\drivers\mpfilt.sys [10588 2010-05-17] () [File not signed] S3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [290520 2013-08-26] (Realtek Semiconductor Corp.) R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1204424 2013-12-02] (Ralink Technology, Corp.) R2 Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [142120 2007-04-27] (SafeNet, Inc.) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-09-20] (Synaptics Incorporated) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-09-20] (Synaptics Incorporated) U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] () S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation) R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-22] (Hewlett-Packard Development Company, L.P.) S1 rsutils; system32\DRIVERS\rsutils.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-24 09:01 - 2015-07-24 09:02 - 00021303 _____ C:\Users\Hibatoullah\Desktop\FRST.txt 2015-07-24 09:01 - 2015-07-24 09:01 - 00000000 ____D C:\FRST 2015-07-24 08:59 - 2015-07-24 08:59 - 00001295 _____ C:\Users\Hibatoullah\Desktop\RapportMalwarebytes.txt 2015-07-24 07:04 - 2015-07-24 07:01 - 02135552 _____ (Farbar) C:\Users\Hibatoullah\Desktop\FRST64.exe 2015-07-24 07:01 - 2015-07-24 07:01 - 02135552 _____ (Farbar) C:\Users\Hibatoullah\Downloads\FRST64.exe 2015-07-24 03:55 - 2015-07-24 03:55 - 00001291 _____ C:\Users\Hibatoullah\Desktop\Revo Uninstaller.lnk 2015-07-24 03:55 - 2015-07-24 03:55 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2015-07-24 03:50 - 2015-07-24 03:52 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Hibatoullah\Downloads\revosetup (1).exe 2015-07-24 03:04 - 2015-07-24 03:04 - 00000582 _____ C:\Windows\PFRO.log 2015-07-24 03:04 - 2015-07-24 03:04 - 00000116 _____ C:\Windows\setupact.log 2015-07-24 03:04 - 2015-07-24 03:04 - 00000000 _____ C:\Windows\setuperr.log 2015-07-23 23:07 - 2015-07-23 23:07 - 00000953 _____ C:\Users\Hibatoullah\Desktop\ZHPFixReport.txt 2015-07-23 21:57 - 2015-07-23 21:58 - 00000000 ____D C:\Program Files (x86)\ZHPFix 2015-07-23 21:57 - 2015-07-23 21:57 - 00001872 _____ C:\Users\Public\Desktop\ZHPFix.lnk 2015-07-23 21:57 - 2015-07-23 21:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP 2015-07-23 21:56 - 2015-07-23 21:56 - 03522334 _____ (Nicolas Coolman ) C:\Users\Hibatoullah\Downloads\ZHPFix.exe 2015-07-23 12:33 - 2015-07-23 12:35 - 00000000 ____D C:\Users\Hibatoullah\Documents\NetBeansProjects 2015-07-23 03:45 - 2015-07-24 02:59 - 00001580 _____ C:\Users\Hibatoullah\Desktop\ZHPCleaner.txt 2015-07-22 23:56 - 2015-07-22 23:57 - 05189024 _____ C:\Windows\system32\FNTCACHE.DAT 2015-07-22 23:30 - 2015-07-24 08:37 - 00391755 _____ C:\Windows\WindowsUpdate.log 2015-07-22 23:22 - 2015-07-24 08:18 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-07-22 23:22 - 2015-07-22 23:22 - 00001125 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2015-07-22 23:22 - 2015-07-22 23:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-07-22 23:22 - 2015-07-22 23:22 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-07-22 23:22 - 2015-07-22 23:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2015-07-22 23:22 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-07-22 23:22 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-07-22 23:22 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-07-22 23:21 - 2015-07-22 23:21 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Hibatoullah\Downloads\mbam-setup-2.1.8.1057.exe 2015-07-22 23:08 - 2015-07-22 23:08 - 00001481 _____ C:\Users\Hibatoullah\Desktop\JRT.txt 2015-07-22 22:47 - 2015-07-22 22:47 - 01798288 _____ (Malwarebytes Corporation) C:\Users\Hibatoullah\Downloads\JRT (1).exe 2015-07-22 18:12 - 2015-07-22 18:13 - 02248704 _____ C:\Users\Hibatoullah\Downloads\AdwCleaner.exe 2015-07-22 09:49 - 2015-07-22 09:49 - 00000000 ____D C:\Users\Hibatoullah\.android 2015-07-21 18:36 - 2015-07-21 18:36 - 00000386 _____ C:\Windows\Tasks\AdobeFlashRelax21183643 Updater.job 2015-07-21 09:25 - 2015-07-14 15:14 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-07-21 09:25 - 2015-07-14 15:14 - 00301056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2015-07-21 09:25 - 2015-07-14 15:14 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2015-07-21 09:25 - 2015-07-14 15:13 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-07-20 13:56 - 2015-07-20 13:56 - 01242417 _____ C:\Users\Hibatoullah\Downloads\javaee-6_0-fr-spec.zip 2015-07-20 10:05 - 2015-07-20 10:05 - 00000358 _____ C:\Windows\Tasks\0715avtUpdateInfo.job 2015-07-20 10:05 - 2015-07-20 10:05 - 00000000 ____D C:\ProgramData\Avg_Update_0715avt 2015-07-19 16:47 - 2015-07-19 16:47 - 00189792 _____ (Sysinternals) C:\Windows\PSEXESVC.exe 2015-07-19 16:37 - 2015-07-24 03:04 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-07-19 11:45 - 2015-07-19 11:45 - 00000000 ____D C:\Users\Hibatoullah\Downloads\PSTools 2015-07-19 11:40 - 2015-07-19 11:40 - 01686759 _____ C:\Users\Hibatoullah\Downloads\PSTools.zip 2015-07-19 11:20 - 2015-07-19 11:20 - 00065232 _____ (Malwarebytes) C:\Users\Hibatoullah\Downloads\regassassin_1-03_en_64708.exe 2015-07-19 11:16 - 2015-07-19 11:16 - 00004510 _____ C:\Users\Hibatoullah\AppData\Roaming\CamStudio.cfg 2015-07-19 11:16 - 2015-07-19 11:16 - 00000408 _____ C:\Users\Hibatoullah\AppData\Roaming\CamShapes.ini 2015-07-19 11:16 - 2015-07-19 11:16 - 00000408 _____ C:\Users\Hibatoullah\AppData\Roaming\CamLayout.ini 2015-07-19 11:16 - 2015-07-19 11:16 - 00000046 _____ C:\Users\Hibatoullah\AppData\Roaming\Camdata.ini 2015-07-19 11:14 - 2015-07-19 11:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7 2015-07-19 11:14 - 2015-07-19 11:14 - 00000000 ____D C:\Program Files (x86)\CamStudio 2.7 2015-07-19 11:12 - 2015-07-19 11:13 - 03099532 _____ (CamStudio Open Source ) C:\Users\Hibatoullah\Downloads\camstudio_2-7-2-r316_fr_10618.exe 2015-07-19 08:51 - 2015-07-19 08:51 - 01918512 _____ (Mister Group ) C:\Users\Hibatoullah\Downloads\SystemExplorerSetup_642 (1).exe 2015-07-19 07:29 - 2015-07-19 07:29 - 04354084 _____ (Safer Networking Limited ) C:\Users\Hibatoullah\Downloads\spybotsd13.exe 2015-07-19 06:50 - 2015-07-19 06:50 - 01918512 _____ (Mister Group ) C:\Users\Hibatoullah\Downloads\SystemExplorerSetup_642.exe 2015-07-18 00:59 - 2015-07-18 00:59 - 00000390 _____ C:\Windows\Tasks\SystemHealthy1805949_Administrator.job 2015-07-15 19:06 - 2015-07-15 19:06 - 00009120 _____ C:\Users\Hibatoullah\AppData\Local\recently-used.xbel 2015-07-15 19:03 - 2015-07-15 19:04 - 00000000 ____D C:\Users\Hibatoullah\Desktop\Tri9i 2015-07-15 14:23 - 2015-07-15 14:32 - 40347640 _____ (Summitsoft Corporation) C:\Users\Hibatoullah\Downloads\LDS_Trial_setup3.5.2.exe 2015-07-15 12:30 - 2015-06-15 23:39 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-07-15 12:30 - 2015-06-15 23:38 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-07-15 12:30 - 2015-06-15 23:26 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-07-15 12:30 - 2015-06-15 23:24 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-07-15 12:30 - 2015-06-15 23:02 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2015-07-15 12:30 - 2015-06-15 22:58 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-07-15 12:30 - 2015-06-15 22:57 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-07-15 12:30 - 2015-06-15 22:56 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2015-07-15 12:30 - 2015-06-15 22:55 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-07-15 12:30 - 2015-06-15 22:49 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2015-07-15 12:30 - 2015-06-15 22:41 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-07-15 12:30 - 2015-06-15 22:38 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-07-15 12:30 - 2015-06-15 22:36 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-07-15 12:30 - 2015-06-15 22:17 - 02880000 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2015-07-15 12:30 - 2015-06-15 22:16 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-07-15 12:30 - 2015-06-15 22:15 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-07-15 12:30 - 2015-06-15 22:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-07-15 12:30 - 2015-06-15 22:04 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-07-15 12:30 - 2015-06-15 22:03 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-07-15 12:30 - 2015-06-15 21:52 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-07-15 12:30 - 2015-06-15 21:47 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2015-07-15 12:30 - 2015-06-15 21:44 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-07-15 12:30 - 2015-06-15 21:43 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-07-15 12:30 - 2015-06-15 21:42 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2015-07-15 12:30 - 2015-06-15 21:41 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-07-15 12:30 - 2015-06-15 21:37 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2015-07-15 12:30 - 2015-06-15 21:32 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2015-07-15 12:30 - 2015-06-15 21:31 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-07-15 12:30 - 2015-06-15 21:30 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-07-15 12:30 - 2015-06-15 21:30 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-07-15 12:30 - 2015-06-15 21:17 - 01048576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll 2015-07-15 12:30 - 2015-06-15 21:07 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-07-15 12:30 - 2015-06-15 21:02 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-07-15 12:26 - 2015-07-09 20:51 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-07-15 12:26 - 2015-07-09 19:40 - 00359936 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-07-15 12:26 - 2015-07-09 17:03 - 03701760 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-07-15 12:26 - 2015-07-09 16:54 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-07-15 12:26 - 2015-07-09 16:53 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-07-15 12:26 - 2015-07-09 16:50 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2015-07-15 12:26 - 2015-07-09 16:50 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-07-15 12:26 - 2015-07-09 16:48 - 00891904 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-07-15 12:26 - 2015-07-09 16:46 - 02229248 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-07-15 12:26 - 2015-07-09 16:38 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-07-15 12:26 - 2015-07-09 16:37 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-07-15 12:26 - 2015-07-09 16:35 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-07-15 12:26 - 2015-07-09 16:34 - 00721920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-07-15 12:26 - 2015-07-01 23:08 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-07-15 12:26 - 2015-07-01 22:14 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-07-15 12:26 - 2015-06-29 23:43 - 00026288 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2015-07-15 12:26 - 2015-06-29 16:07 - 01145856 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-07-15 12:26 - 2015-06-29 16:07 - 01084928 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-07-15 12:26 - 2015-06-29 16:07 - 00764928 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-07-15 12:26 - 2015-06-29 16:07 - 00433152 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-07-15 12:26 - 2015-06-29 16:07 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-07-15 12:26 - 2015-06-28 06:07 - 00442712 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-07-15 12:26 - 2015-06-28 06:07 - 00178008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-07-15 12:26 - 2015-06-28 06:06 - 01311960 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2015-07-15 12:26 - 2015-06-28 06:06 - 00332120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-07-15 12:26 - 2015-06-27 17:42 - 00747520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2015-07-15 12:26 - 2015-06-27 04:13 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2015-07-15 12:26 - 2015-06-27 04:12 - 00401408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2015-07-15 12:26 - 2015-06-27 04:12 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2015-07-15 12:26 - 2015-06-27 04:08 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-07-15 12:26 - 2015-06-27 04:08 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-07-15 12:26 - 2015-06-27 03:40 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2015-07-15 12:26 - 2015-06-27 03:14 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-07-15 12:26 - 2015-06-27 03:05 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-07-15 12:26 - 2015-06-27 03:00 - 00989184 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-07-15 12:26 - 2015-06-27 02:53 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2015-07-15 12:26 - 2015-06-27 02:26 - 00802816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-07-15 12:26 - 2015-06-27 00:21 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-07-15 12:26 - 2015-06-27 00:21 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-07-15 12:26 - 2015-06-25 03:31 - 04177920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-07-15 12:26 - 2015-06-15 23:41 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2015-07-15 12:26 - 2015-06-15 23:24 - 03320320 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2015-07-15 12:26 - 2015-06-15 22:16 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe 2015-07-15 12:26 - 2015-06-15 22:09 - 03607552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2015-07-15 12:26 - 2015-06-15 21:50 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2015-07-15 12:26 - 2015-06-15 20:57 - 02460160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2015-07-15 12:26 - 2015-05-30 22:18 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll 2015-07-15 12:26 - 2015-05-30 20:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll 2015-07-15 12:26 - 2015-05-30 20:35 - 00911360 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2015-07-15 12:26 - 2015-05-11 19:17 - 01201664 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys 2015-07-15 12:26 - 2015-05-07 18:50 - 22292672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-07-15 12:26 - 2015-05-07 18:00 - 03109376 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2015-07-15 12:26 - 2015-05-07 17:53 - 19734960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2015-07-15 12:26 - 2015-05-07 17:12 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2015-07-15 12:26 - 2015-05-07 16:21 - 00522240 _____ (Microsoft Corporation) C:\Windows\system32\GeofenceMonitorService.dll 2015-07-15 12:26 - 2015-05-07 16:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GeofenceMonitorService.dll 2015-07-15 12:26 - 2015-05-03 16:09 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2015-07-15 12:26 - 2015-05-03 15:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2015-07-15 12:26 - 2015-05-03 15:55 - 00971776 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2015-07-15 12:26 - 2015-05-03 15:49 - 00811008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2015-07-15 12:26 - 2015-05-03 01:39 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-07-15 12:26 - 2015-05-02 00:33 - 00410739 _____ C:\Windows\system32\ApnDatabase.xml 2015-07-15 12:26 - 2015-04-30 00:22 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\WiFiDisplay.dll 2015-07-15 12:26 - 2015-04-25 03:25 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2015-07-15 12:26 - 2015-04-23 16:47 - 03084288 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll 2015-07-15 12:26 - 2015-04-23 16:16 - 02471424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll 2015-07-15 12:26 - 2014-11-04 20:25 - 00059712 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\kbdclass.sys 2015-07-15 12:26 - 2014-11-04 20:25 - 00051008 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\mouclass.sys 2015-07-15 12:26 - 2014-11-04 07:55 - 00026112 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\sermouse.sys 2015-07-15 12:26 - 2014-11-04 07:54 - 00108544 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\i8042prt.sys 2015-07-15 12:26 - 2014-11-04 07:54 - 00032256 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\kbdhid.sys 2015-07-15 12:26 - 2014-11-04 07:54 - 00030208 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\mouhid.sys 2015-07-15 12:25 - 2015-07-02 22:21 - 19877376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-07-15 12:25 - 2015-07-02 21:50 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-07-15 12:25 - 2015-07-02 21:49 - 25193984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-07-15 12:25 - 2015-07-02 21:23 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-07-15 12:25 - 2015-07-02 21:19 - 12855296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-07-15 12:25 - 2015-07-02 20:55 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-07-15 12:25 - 2015-07-02 20:20 - 14453248 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-07-15 12:25 - 2015-07-02 19:59 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-07-15 12:15 - 2015-07-15 12:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2015-07-15 12:14 - 2015-07-15 12:14 - 00000000 ____D C:\Program Files (x86)\VideoLAN 2015-07-15 12:10 - 2015-05-11 17:34 - 00332800 _____ (Microsoft Corporation) C:\Windows\system32\fhcpl.dll 2015-07-15 12:09 - 2015-06-11 04:49 - 01380600 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-07-15 12:09 - 2015-06-10 17:13 - 01097216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2015-07-15 12:09 - 2015-04-28 14:13 - 00513480 _____ C:\Windows\SysWOW64\locale.nls 2015-07-15 12:09 - 2015-04-28 14:13 - 00513480 _____ C:\Windows\system32\locale.nls 2015-07-15 12:07 - 2015-07-15 12:07 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software 2015-07-15 12:07 - 2015-07-15 12:07 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software 2015-07-15 12:04 - 2015-06-16 06:36 - 01661576 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2015-07-15 12:04 - 2015-06-16 06:36 - 01212248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2015-07-15 12:01 - 2015-07-15 12:09 - 28849904 _____ C:\Users\Hibatoullah\Downloads\vlc-2.2.1-win32.exe 2015-07-15 11:53 - 2015-05-07 17:47 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll 2015-07-15 11:49 - 2015-05-12 14:19 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerServer.dll 2015-07-15 11:49 - 2015-05-03 16:07 - 07784448 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll 2015-07-15 11:49 - 2015-05-03 15:57 - 05264384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll 2015-07-14 17:56 - 2015-07-14 17:56 - 00000000 ____D C:\Users\Hibatoullah\Downloads\bootstrap-3.3.5 2015-07-14 17:55 - 2015-07-14 17:55 - 03319631 _____ C:\Users\Hibatoullah\Downloads\bootstrap-3.3.5.zip 2015-07-14 17:55 - 2015-07-14 17:55 - 00255138 _____ C:\Users\Hibatoullah\Downloads\bootstrap-sass-3.3.5.tar.gz 2015-07-14 17:52 - 2015-07-14 17:53 - 00000000 ____D C:\Users\Hibatoullah\Downloads\bootstrap-5.5.23.jar 2015-07-14 17:51 - 2015-07-14 17:51 - 00265519 _____ C:\Users\Hibatoullah\Downloads\bootstrap-3.3.5-dist.zip 2015-07-14 17:22 - 2015-07-14 17:22 - 00000000 _____ C:\Users\Hibatoullah\Downloads\téléchargement (1) 2015-07-14 17:21 - 2015-07-14 17:21 - 00000000 _____ C:\Users\Hibatoullah\Downloads\téléchargement 2015-07-13 14:34 - 2015-07-13 14:34 - 00000000 ____D C:\Users\Hibatoullah\Downloads\img 2015-07-13 14:28 - 2015-07-13 14:28 - 00010257 _____ C:\Users\Hibatoullah\Downloads\img.7z 2015-07-13 13:57 - 2015-07-13 13:57 - 00000000 ____D C:\Users\Hibatoullah\Downloads\cc 2015-07-13 10:44 - 2015-07-13 10:44 - 00036292 _____ C:\Users\Hibatoullah\Downloads\cc.7z 2015-07-12 22:38 - 2015-07-23 09:53 - 00103192 _____ C:\Users\Hibatoullah\Desktop\ZHPDiag.txt 2015-07-12 19:45 - 2015-07-24 08:58 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d043a7a07fefb5.job 2015-07-12 19:45 - 2015-07-24 08:16 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d043a79f0149b6.job 2015-07-12 19:45 - 2015-07-16 20:52 - 00004072 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1d043a7a07fefb5 2015-07-12 19:45 - 2015-07-16 20:52 - 00003836 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1d043a79f0149b6 2015-07-12 19:45 - 2015-07-12 19:45 - 00931408 _____ (Google Inc.) C:\Users\Hibatoullah\Downloads\ChromeSetup.exe 2015-07-11 17:56 - 2015-07-11 18:02 - 166897320 _____ C:\Users\Hibatoullah\Downloads\fmu8nt5i.exe 2015-07-11 17:40 - 2015-07-11 22:24 - 00000000 ____D C:\ProgramData\RogueKiller 2015-07-11 17:40 - 2015-07-11 17:40 - 00037624 _____ C:\Windows\system32\Drivers\TrueSight.sys 2015-07-11 17:39 - 2015-07-11 17:41 - 51116856 _____ (AVG Technologies) C:\Users\Hibatoullah\Downloads\avg_tuht_stf_fr_2015_604_1dayslp2.exe 2015-07-11 17:33 - 2015-07-11 17:33 - 05633250 _____ (Swearware) C:\Users\Hibatoullah\Downloads\ComboFix (1).exe 2015-07-11 17:14 - 2015-07-11 17:15 - 05633250 _____ (Swearware) C:\Users\Hibatoullah\Downloads\ComboFix.exe 2015-07-11 09:23 - 2015-07-23 09:44 - 01844736 _____ C:\Users\Hibatoullah\ZHPDiag3.exe 2015-07-11 09:23 - 2015-07-11 09:23 - 00000000 ____D C:\Users\Hibatoullah\AppData\Roaming\AVG2015 2015-07-11 09:22 - 2015-07-24 02:49 - 01861120 _____ C:\Users\Hibatoullah\ZHPCleaner.exe 2015-07-11 09:22 - 2015-07-23 09:45 - 00000883 _____ C:\Users\Hibatoullah\Desktop\ZHPDiag.lnk 2015-07-11 09:22 - 2015-07-15 12:07 - 00001002 _____ C:\Users\Public\Desktop\AVG 2015.lnk 2015-07-11 09:22 - 2015-07-15 12:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2015-07-11 09:21 - 2015-07-24 02:51 - 00000893 _____ C:\Users\Hibatoullah\Desktop\ZHPCleaner.lnk 2015-07-11 09:21 - 2015-07-14 18:55 - 00000000 ____D C:\ProgramData\AVG2015 2015-07-11 09:21 - 2015-07-11 17:55 - 00000000 ____D C:\Program Files (x86)\AVG 2015-07-11 09:21 - 2015-07-11 09:21 - 00000000 ___HD C:\$AVG 2015-07-11 08:26 - 2015-07-11 08:26 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Hibatoullah\Downloads\tdsskiller.exe 2015-07-11 08:23 - 2015-07-11 08:24 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\Hibatoullah\Downloads\rkill.exe 2015-07-11 07:13 - 2015-07-22 22:18 - 00000000 ____D C:\AdwCleaner 2015-07-11 06:55 - 2015-07-11 06:55 - 02248704 _____ C:\Users\Hibatoullah\Downloads\adwcleaner_4.208.exe 2015-07-11 06:55 - 2015-07-11 06:55 - 00000150 __RSH C:\rising.ini 2015-07-10 11:06 - 2015-07-11 10:10 - 00000000 ____D C:\Users\Hibatoullah\AppData\Local\Avg2015 2015-07-07 07:30 - 2015-07-07 07:30 - 00000000 ___HD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup (Disabled by Starter) 2015-07-07 07:20 - 2015-07-07 07:20 - 00734286 _____ C:\Users\Hibatoullah\Downloads\Starter.zip 2015-07-07 07:15 - 2015-07-07 07:15 - 03007700 _____ C:\Users\Hibatoullah\Downloads\revouninstaller.zip 2015-07-07 07:03 - 2015-07-07 07:03 - 00200310 _____ C:\Users\Hibatoullah\Downloads\ccleaner-enhancer_4-3_fr_331106.zip 2015-07-07 06:44 - 2015-07-07 06:45 - 04635400 _____ (AVG Technologies) C:\Users\Hibatoullah\Downloads\avg_avct_stb_all_2015_5577_ppc-avc-welcomecmp4 (1).exe 2015-07-07 06:43 - 2015-07-07 06:43 - 05481336 _____ (Avast Software s.r.o.) C:\Users\Hibatoullah\Downloads\avast_free_antivirus_setup_online_cnet.exe 2015-07-07 06:43 - 2015-07-07 06:43 - 00000000 ____D C:\ProgramData\AhnLab 2015-07-07 06:42 - 2015-07-07 06:42 - 01142616 _____ (RaMMicHaeL) C:\Users\Hibatoullah\Downloads\unchecky_setup.exe 2015-07-07 06:38 - 2015-07-07 06:41 - 87110520 _____ (AhnLab, Inc.) C:\Users\Hibatoullah\Downloads\AhnLab V3 Internet Security 8.0.exe 2015-07-07 05:35 - 2015-07-07 05:35 - 00001047 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Dreamweaver CC 2015.lnk 2015-07-07 05:09 - 2015-07-07 05:11 - 00000000 ____D C:\Users\Hibatoullah\Desktop\Protection PC 2015-07-07 04:39 - 2015-07-07 04:39 - 00001190 _____ C:\Windows\SysWOW64\ServiceConfig.xml 2015-07-07 01:03 - 2015-07-07 01:09 - 00000000 ____D C:\Program Files\Unlocker 2015-07-07 01:03 - 2015-07-07 01:03 - 00000000 ____D C:\Users\Hibatoullah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker 2015-07-07 01:02 - 2015-07-07 01:03 - 00402911 _____ C:\Users\Hibatoullah\Downloads\Unlocker1.9.2.exe 2015-07-07 01:00 - 2015-07-07 01:32 - 00000138 _____ C:\Windows\SysWOW64\IEnvSetting.xml 2015-07-06 16:33 - 2015-07-06 16:33 - 00068989 _____ C:\Users\Hibatoullah\Downloads\notescc1_année5-7-15.xlsx 2015-07-06 16:18 - 2015-07-06 16:18 - 00085807 _____ C:\Users\Hibatoullah\Downloads\2emeAnnéeNotes5-7-15.xlsx 2015-07-06 16:12 - 2015-07-07 00:43 - 00000000 ____D C:\Windows\Minidump 2015-07-06 11:21 - 2015-07-06 11:21 - 00000000 ___RD C:\Users\Hibatoullah\Creative Cloud Files 2015-07-06 10:34 - 2015-07-06 10:35 - 03219600 _____ (El Desaparecido - SosVirus.net - UsbFix.net) C:\Users\Hibatoullah\Downloads\UsbFix_2015_7.979.exe 2015-07-05 22:52 - 2015-07-05 22:52 - 00000017 _____ C:\Users\Hibatoullah\AppData\Local\resmon.resmoncfg 2015-07-05 22:50 - 2015-07-05 22:50 - 00059180 _____ C:\Users\Hibatoullah\Downloads\notification-area-cleaner-x64.zip 2015-07-05 14:46 - 2015-07-05 14:50 - 00901502 _____ C:\Users\Hibatoullah\Documents\cc_20150705_144617.reg 2015-07-05 03:34 - 2015-07-24 02:59 - 00000000 ____D C:\Users\Hibatoullah\AppData\Roaming\ZHP 2015-07-05 03:25 - 2015-07-05 03:28 - 01845248 _____ C:\Users\Hibatoullah\Downloads\ZHPCleaner.exe 2015-07-05 03:21 - 2015-07-05 03:22 - 02952814 _____ (Malwarebytes Corporation) C:\Users\Hibatoullah\Downloads\JRT.exe 2015-07-05 03:19 - 2015-07-05 03:21 - 01836544 _____ C:\Users\Hibatoullah\Downloads\ZHPDiag3.exe 2015-07-05 00:47 - 2015-07-05 17:59 - 00000000 ____D C:\Windows\SysWOW64\%APPDATA% 2015-07-05 00:13 - 2015-07-05 00:13 - 00012220 _____ C:\Users\Hibatoullah\Downloads\note au eleves.xlsx 2015-07-04 22:53 - 2015-07-04 22:53 - 00000000 ____D C:\Users\Hibatoullah\Desktop\Innovation 2015-07-04 00:25 - 2015-07-04 00:25 - 00000000 ____D C:\ProgramData\Avg_Update_0615pit 2015-07-04 00:15 - 2015-07-11 09:22 - 00000000 ____D C:\Program Files\Common Files\AV 2015-07-04 00:14 - 2015-07-04 00:14 - 00000000 ____D C:\Users\Hibatoullah\AppData\Roaming\TuneUp Software 2015-07-03 20:49 - 2015-07-07 05:41 - 00000000 ____D C:\ProgramData\boost_interprocess 2015-07-03 20:39 - 2015-07-03 20:39 - 00001252 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk 2015-07-03 20:39 - 2015-07-03 20:39 - 00001240 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2015-07-03 20:26 - 2015-07-03 20:27 - 00674480 _____ (Adobe Systems Incorporated) C:\Users\Hibatoullah\Downloads\CreativeCloudSet-Up.exe 2015-07-03 17:29 - 2015-07-03 17:29 - 00001695 _____ C:\Internet Explorer.lnk 2015-07-03 17:26 - 2015-07-03 17:26 - 00000438 _____ C:\Windows\SysWOW64\WSCConfig.xml 2015-07-03 12:15 - 2015-07-03 12:15 - 00085557 _____ C:\Users\Hibatoullah\Downloads\jquery.txt 2015-07-03 12:15 - 2015-07-03 12:15 - 00023712 _____ C:\Users\Hibatoullah\Downloads\codecss.txt 2015-07-03 12:15 - 2015-07-03 12:15 - 00006750 _____ C:\Users\Hibatoullah\Downloads\jscript.txt 2015-07-03 11:44 - 2015-07-03 11:44 - 00007154 _____ C:\Users\Hibatoullah\Downloads\code.txt 2015-07-02 12:11 - 2015-07-02 12:11 - 00000380 _____ C:\Windows\Tasks\HPCeeScheduleForHibatoullah.job 2015-07-02 02:18 - 2015-07-02 02:18 - 00255804 _____ C:\Windows\system32\ScanResults.xml 2015-07-02 02:07 - 2015-07-02 02:07 - 00000464 _____ C:\Windows\system32\ScannerSettings 2015-07-01 20:46 - 2015-07-02 22:58 - 00000000 ____D C:\Users\Hibatoullah\Desktop\Test 2015-07-01 10:48 - 2015-07-05 11:08 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-07-01 10:33 - 2015-07-01 10:33 - 00084706 _____ C:\Users\Hibatoullah\Downloads\build-impl.xml 2015-07-01 02:16 - 2015-07-01 02:16 - 00000000 ____D C:\Users\Hibatoullah\Downloads\facebook-hibatoullahlaachrate 2015-07-01 02:15 - 2015-07-01 02:16 - 02573894 _____ C:\Users\Hibatoullah\Downloads\facebook-hibatoullahlaachrate.zip 2015-06-30 21:57 - 2015-07-07 05:23 - 00000000 ____D C:\ProgramData\STOPzilla! 2015-06-30 21:57 - 2015-06-30 21:57 - 00000000 ____D C:\Program Files (x86)\iS3 2015-06-30 21:54 - 2015-06-30 21:55 - 02042328 _____ (iS3, Inc.) C:\Users\Hibatoullah\Downloads\STOPzillaPRO_Downloader.exe 2015-06-30 19:41 - 2015-06-30 19:41 - 00000320 _____ C:\Users\Hibatoullah\Downloads\wms 2015-06-30 16:06 - 2015-06-30 16:06 - 00021173 _____ C:\Users\Hibatoullah\Downloads\bootstrap-5.5.23.jar.zip 2015-06-30 15:47 - 2015-01-18 22:26 - 00539003 _____ C:\postgresql-9.3-1102.jdbc3.jar 2015-06-30 15:23 - 2015-06-30 21:38 - 00000814 _____ C:\Users\Hibatoullah\Downloads\etapes.txt 2015-06-30 12:53 - 2015-06-30 13:00 - 00000000 ____D C:\Users\Hibatoullah\Glassfish4.1 2015-06-30 11:30 - 2015-06-30 11:34 - 176634313 _____ (Oracle Corporation.) C:\Users\Hibatoullah\Downloads\java_ee_sdk-7-jdk7-windows-x64.exe 2015-06-30 02:15 - 2015-06-30 02:30 - 10447328 _____ C:\Users\Hibatoullah\Downloads\Antivirus_Free_Edition_x64.exe 2015-06-30 02:14 - 2015-06-30 02:14 - 00162208 _____ C:\Users\Hibatoullah\Downloads\Antivirus_Free_Edition.exe 2015-06-30 02:13 - 2015-06-30 02:21 - 232025968 _____ C:\Users\Hibatoullah\Downloads\avira_antivirus_fr-fr.exe 2015-06-30 02:12 - 2015-06-30 02:12 - 17128866 _____ C:\Users\Hibatoullah\Downloads\KAV100720_ENU_DOWN_331020_10.rar 2015-06-30 02:11 - 2015-07-24 08:50 - 00000000 ____D C:\ProgramData\MFAData 2015-06-30 02:11 - 2015-06-30 02:11 - 00000000 ____D C:\Users\Hibatoullah\AppData\Local\MFAData 2015-06-30 02:07 - 2015-06-30 02:07 - 04635400 _____ (AVG Technologies) C:\Users\Hibatoullah\Downloads\avg_avct_stb_all_2015_5577_ppc-avc-welcomecmp4.exe 2015-06-30 01:55 - 2015-06-30 01:55 - 00000000 _____ C:\autoexec.bat 2015-06-30 01:51 - 2015-06-30 01:51 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\Hibatoullah\Downloads\SpyHunter-Installer (1).exe 2015-06-30 01:50 - 2015-06-30 01:50 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\Hibatoullah\Downloads\SpyHunter-Installer.exe 2015-06-29 18:30 - 2014-05-18 12:08 - 60164745 _____ C:\geoserver.war 2015-06-29 17:56 - 2015-06-29 18:06 - 00000000 __SHD C:\KRECYCLE 2015-06-29 13:49 - 2015-06-29 13:50 - 21707524 _____ C:\Users\Hibatoullah\postgis_2_1_pg93.exe 2015-06-29 12:53 - 2015-07-01 10:26 - 00082780 _____ C:\Users\Hibatoullah\Desktop\build-impl.xml 2015-06-29 11:47 - 2015-06-29 11:47 - 00000000 ____D C:\Users\Hibatoullah\Downloads\ROUTE500_1-1_SHP_LAMB93_D001_2012-11-21 2015-06-29 11:45 - 2015-06-29 11:45 - 06913435 _____ C:\Users\Hibatoullah\Downloads\ROUTE500_1-1_SHP_LAMB93_D001_2012-11-21.7z 2015-06-29 11:35 - 2015-06-29 11:35 - 01813958 _____ C:\Users\Hibatoullah\Downloads\data.tar.gz 2015-06-29 10:45 - 2015-07-07 14:27 - 00000000 ____D C:\Users\Hibatoullah\Desktop\Stage MDinaBus 2015-06-29 10:11 - 2015-06-29 10:45 - 159725906 _____ C:\Users\Hibatoullah\Downloads\netbeans-7.4-javaee-windows (1).exe 2015-06-29 01:44 - 2015-06-29 01:44 - 00000000 ____D C:\Users\Hibatoullah\.m2 2015-06-29 01:33 - 2015-06-29 01:33 - 00000000 ____D C:\Users\Hibatoullah\AppData\Roaming\NetBeans 2015-06-29 01:33 - 2015-06-29 01:33 - 00000000 ____D C:\Users\Hibatoullah\AppData\Local\NetBeans 2015-06-29 01:23 - 2015-06-30 13:06 - 00000000 ____D C:\Users\Hibatoullah\.netbeans-derby 2015-06-29 01:14 - 2015-06-29 01:14 - 00002106 _____ C:\Users\Public\Desktop\NetBeans IDE 8.0.2.lnk 2015-06-29 01:14 - 2015-06-29 01:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetBeans 2015-06-29 01:10 - 2015-06-29 01:24 - 00000000 ____D C:\Program Files (x86)\NetBeans 8.0.2 2015-06-28 23:20 - 2015-06-30 12:42 - 00000000 ____D C:\Users\Hibatoullah\.nbi 2015-06-28 21:46 - 2015-06-28 21:46 - 02796270 _____ C:\Users\Hibatoullah\Downloads\PV.rar 2015-06-28 19:46 - 2015-06-29 01:59 - 21659315 _____ C:\Users\Hibatoullah\Downloads\les rapports PFE (1).rar.opdownload 2015-06-28 19:44 - 2015-06-28 19:57 - 334865203 _____ C:\Users\Hibatoullah\Downloads\les rapports PFE.rar 2015-06-28 18:38 - 2015-06-28 18:38 - 00196528 _____ (Sun Microsystems, Inc.) C:\Windows\system32\javaws.exe 2015-06-28 18:38 - 2015-06-28 18:38 - 00172976 _____ (Sun Microsystems, Inc.) C:\Windows\system32\javaw.exe 2015-06-28 18:38 - 2015-06-28 18:38 - 00172976 _____ (Sun Microsystems, Inc.) C:\Windows\system32\java.exe 2015-06-28 16:53 - 2015-06-28 21:32 - 00000000 ____D C:\Users\Hibatoullah\Desktop\PV 2015-06-27 02:47 - 2015-06-27 02:47 - 00000000 ____D C:\Users\Hibatoullah\Downloads\bin 2015-06-27 02:43 - 2015-06-28 18:37 - 00000000 ____D C:\Program Files\Java 2015-06-27 02:42 - 2015-06-27 02:43 - 11488176 _____ C:\Users\Hibatoullah\Downloads\bin.zip 2015-06-27 02:14 - 2015-06-27 02:17 - 62866856 _____ C:\Users\Hibatoullah\Downloads\jdk-6u45-windows-x64.exe 2015-06-27 02:14 - 2015-06-27 02:15 - 17355184 _____ (Sun Microsystems, Inc.) C:\Users\Hibatoullah\Downloads\jre-6u45-windows-x64.exe 2015-06-27 02:07 - 2015-06-27 02:07 - 17282992 _____ (Sun Microsystems, Inc.) C:\Users\Hibatoullah\Downloads\jre-6u43-windows-x64.exe 2015-06-27 01:00 - 2015-06-27 01:00 - 00000000 ____D C:\Users\Hibatoullah\Documents\eclipse-jee-mars-R-win32-x86_64 2015-06-27 01:00 - 2015-06-26 23:39 - 282533464 _____ C:\Users\Hibatoullah\Documents\eclipse-jee-mars-R-win32-x86_64.zip 2015-06-27 00:19 - 2015-06-27 00:21 - 62735272 _____ C:\Users\Hibatoullah\Downloads\jdk-6u43-windows-x64.exe 2015-06-26 23:24 - 2015-06-26 23:24 - 00000108 _____ C:\Users\Hibatoullah\.asadminpass 2015-06-26 23:13 - 2015-06-26 23:15 - 56426918 _____ (Oracle Corporation.) C:\Users\Hibatoullah\Downloads\glassfish-3.1.2-windows.exe 2015-06-26 23:12 - 2015-06-27 02:18 - 15935124 _____ (Oracle Corporation.) C:\Users\Hibatoullah\Downloads\glassfish-3.1-windows.exe.opdownload 2015-06-26 09:49 - 2015-06-26 09:49 - 00293296 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys 2015-06-26 02:12 - 2015-07-23 00:30 - 00001904 _____ C:\Users\Hibatoullah\Desktop\notes stage.txt 2015-06-25 22:49 - 2015-06-25 22:49 - 00000000 ____D C:\Users\Hibatoullah\Downloads\eclipse-java-luna-R-win32 2015-06-25 22:12 - 2015-06-25 22:12 - 03340204 _____ C:\Users\Hibatoullah\Downloads\lo-oo-ressources-linguistiques-fr-v5.3.oxt 2015-06-25 16:32 - 2015-06-25 16:33 - 03270973 _____ C:\Users\Hibatoullah\Downloads\primefaces-5.2.jar 2015-06-25 11:46 - 2015-06-25 11:50 - 00000000 ____D C:\Users\Hibatoullah\Desktop\Documentation GeoServer 2015-06-25 11:10 - 2015-06-25 11:24 - 62468326 _____ C:\Users\Hibatoullah\Downloads\geoserver-2.7.1.exe 2015-06-25 02:14 - 2015-06-25 02:14 - 00102774 _____ C:\Users\Hibatoullah\Downloads\EHTP éthique.pptx 2015-06-24 02:03 - 2015-06-24 02:04 - 17647887 _____ C:\Users\Hibatoullah\Downloads\fatawa-bnotaimia.zip 2015-06-24 01:39 - 2015-06-28 19:08 - 00000000 ____D C:\Users\Hibatoullah\Desktop\Islam ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-24 09:00 - 2014-07-31 18:23 - 00001002 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-07-24 09:00 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\system32\sru 2015-07-24 08:37 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\AppReadiness 2015-07-24 05:08 - 2014-05-14 15:03 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2417350805-2748143230-3866523379-1001 2015-07-24 04:33 - 2014-05-14 19:12 - 00003972 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{D7076F65-A74D-4119-89D5-DA753B190B15} 2015-07-24 03:53 - 2014-08-24 17:07 - 03690496 ___SH C:\Users\Hibatoullah\Downloads\Thumbs.db 2015-07-24 03:03 - 2013-08-22 14:25 - 00262144 ___SH C:\Windows\system32\config\BBI 2015-07-24 02:49 - 2014-05-14 14:57 - 00000000 ____D C:\Users\Hibatoullah 2015-07-23 12:11 - 2014-09-03 10:28 - 00000000 ____D C:\Users\Hibatoullah\AppData\Roaming\vlc 2015-07-23 11:07 - 2015-01-22 13:37 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log 2015-07-22 23:56 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\Help 2015-07-22 22:21 - 2015-06-09 06:38 - 00005912 _____ C:\Windows\NvConfig.dat 2015-07-21 11:17 - 2014-10-11 21:32 - 00000000 ____D C:\Users\Hibatoullah\.gimp-2.8 2015-07-21 10:02 - 2013-08-22 16:20 - 00000000 ____D C:\Windows\CbsTemp 2015-07-20 23:48 - 2013-08-22 14:25 - 00262144 ___SH C:\Windows\system32\config\ELAM 2015-07-19 09:54 - 2014-08-01 10:46 - 00161840 _____ C:\Users\Hibatoullah\AppData\Local\GDIPFONTCACHEV1.DAT 2015-07-18 00:59 - 2015-02-25 20:29 - 00000000 ____D C:\Program Files\CCleaner 2015-07-18 00:30 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\rescache 2015-07-17 23:50 - 2014-08-04 10:15 - 00000000 ____D C:\Users\Hibatoullah\AppData\Local\Adobe 2015-07-16 21:01 - 2014-07-31 18:23 - 00003890 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-07-16 21:00 - 2014-05-19 10:50 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2015-07-16 20:58 - 2014-12-24 22:55 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-07-15 20:15 - 2014-12-10 23:17 - 00000000 ____D C:\Windows\system32\appraiser 2015-07-15 20:15 - 2014-08-10 12:52 - 00000000 ___SD C:\Windows\system32\CompatTel 2015-07-15 20:15 - 2013-08-22 16:36 - 00000000 ___RD C:\Windows\ToastData 2015-07-15 20:15 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\WinStore 2015-07-15 16:18 - 2014-10-18 21:47 - 00000000 ____D C:\Users\Hibatoullah\.thumbnails 2015-07-15 15:19 - 2014-05-15 10:58 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-07-15 15:01 - 2014-05-31 20:44 - 00000000 ____D C:\Windows\system32\MRT 2015-07-15 14:10 - 2015-04-05 20:09 - 00000000 ___SD C:\Windows\SysWOW64\GWX 2015-07-15 14:10 - 2015-04-05 20:09 - 00000000 ___SD C:\Windows\system32\GWX 2015-07-15 12:04 - 2014-08-06 17:08 - 00000000 ____D C:\Users\Hibatoullah\AppData\Local\AVG 2015-07-14 22:52 - 2014-07-16 15:19 - 00003862 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1405520337 2015-07-14 22:52 - 2014-07-16 15:18 - 00001070 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2015-07-14 22:52 - 2014-07-16 15:18 - 00000000 ____D C:\Program Files (x86)\Opera 2015-07-14 11:05 - 2013-11-03 01:47 - 00856046 _____ C:\Windows\system32\perfh00C.dat 2015-07-14 11:05 - 2013-11-03 01:47 - 00179194 _____ C:\Windows\system32\perfc00C.dat 2015-07-14 11:05 - 2013-08-26 07:09 - 01993672 _____ C:\Windows\system32\PerfStringBackup.INI 2015-07-13 22:10 - 2014-11-13 10:21 - 00792568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-07-13 22:10 - 2014-11-13 10:21 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-13 16:43 - 2015-01-14 11:27 - 00000000 ____D C:\Users\Hibatoullah\.qgis2 2015-07-12 19:45 - 2014-09-09 22:34 - 00000000 ____D C:\Program Files (x86)\Google 2015-07-12 02:03 - 2013-08-22 14:25 - 52690944 _____ C:\Windows\system32\config\SYSTEM_tureg_old 2015-07-12 02:03 - 2013-08-22 14:25 - 133431296 _____ C:\Windows\system32\config\SOFTWARE_tureg_old 2015-07-12 02:03 - 2013-08-22 14:25 - 00262144 _____ C:\Windows\system32\config\SECURITY_tureg_old 2015-07-12 02:02 - 2013-08-22 14:25 - 00786432 _____ C:\Windows\system32\config\DEFAULT_tureg_old 2015-07-12 02:02 - 2013-08-22 14:25 - 00262144 _____ C:\Windows\system32\config\SAM_tureg_old 2015-07-11 21:23 - 2014-08-06 17:05 - 00000000 ____D C:\Users\Hibatoullah\AppData\Roaming\Skype 2015-07-11 21:23 - 2014-05-15 10:58 - 00000000 ____D C:\Users\Hibatoullah\AppData\Local\Microsoft Help 2015-07-11 21:23 - 2013-08-26 07:57 - 00000000 ____D C:\Windows\Panther 2015-07-11 17:55 - 2014-08-06 17:08 - 00000000 ____D C:\Users\Hibatoullah\AppData\Roaming\AVG 2015-07-11 17:51 - 2014-08-06 17:07 - 00000000 ____D C:\ProgramData\AVG 2015-07-11 12:34 - 2014-02-26 22:40 - 00000000 ____D C:\ProgramData\Temp 2015-07-11 09:22 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\ELAMBKUP 2015-07-11 08:34 - 2014-09-17 16:47 - 00000000 ____D C:\Users\Hibatoullah\AppData\Local\Downloaded Installations 2015-07-07 05:33 - 2014-05-14 14:58 - 00000000 ____D C:\Users\Hibatoullah\AppData\Roaming\Adobe 2015-07-07 05:32 - 2015-01-08 11:42 - 00000000 ____D C:\Program Files\Adobe 2015-07-07 05:28 - 2015-04-30 09:40 - 00000000 ____D C:\ProgramData\Package Cache 2015-07-07 03:29 - 2014-08-11 22:11 - 00000000 ____D C:\Users\Hibatoullah\AppData\Roaming\All2Chat 2015-07-07 01:00 - 2015-06-23 00:27 - 00000031 _____ C:\Windows\SysWOW64\Local.pak 2015-07-06 11:22 - 2014-05-19 10:49 - 00000000 ____D C:\ProgramData\Adobe 2015-07-06 09:54 - 2015-05-25 22:06 - 00000000 ____D C:\UsbFix 2015-07-05 14:37 - 2014-05-15 11:27 - 00000000 ____D C:\Users\Hibatoullah\Documents\Youcam 2015-07-03 20:35 - 2014-05-19 10:50 - 00000000 ____D C:\Program Files (x86)\Adobe 2015-07-03 08:43 - 2014-05-31 20:44 - 130333168 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-07-01 17:08 - 2015-01-19 00:23 - 00017352 _____ C:\Users\Hibatoullah\Documents\pgadmin.log 2015-07-01 12:24 - 2014-05-14 18:07 - 00000000 ____D C:\Program Files\Bitdefender 2015-06-30 22:02 - 2015-06-12 22:02 - 00070144 _____ C:\Windows\SysWOW64\tasks.dll 2015-06-30 02:54 - 2014-05-14 18:07 - 00000000 ____D C:\ProgramData\Bitdefender 2015-06-30 02:53 - 2014-05-14 15:05 - 00000000 ____D C:\Program Files\Common Files\Bitdefender 2015-06-29 13:50 - 2015-04-13 20:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PostGIS 2.1 bundle for PostgreSQL x64 9.3 2015-06-29 01:20 - 2015-04-14 14:41 - 00000000 ____D C:\Program Files (x86)\Apache Software Foundation 2015-06-28 19:10 - 2015-02-16 00:15 - 00014336 ___SH C:\Users\Hibatoullah\Documents\Thumbs.db 2015-06-28 19:08 - 2015-05-23 23:50 - 00000000 ____D C:\Users\Hibatoullah\Desktop\Rapport SI 2015-06-28 18:39 - 2014-10-07 14:03 - 00000000 ____D C:\Users\Hibatoullah\AppData\Local\Windows Live 2015-06-28 18:38 - 2015-05-29 02:42 - 00545200 _____ (Sun Microsystems, Inc.) C:\Windows\system32\npdeployJava1.dll 2015-06-28 18:38 - 2015-05-29 02:42 - 00526768 _____ (Sun Microsystems, Inc.) C:\Windows\system32\deployJava1.dll 2015-06-26 11:23 - 2014-12-19 12:06 - 00000000 ____D C:\Users\Hibatoullah\AppData\Local\Eclipse 2015-06-25 22:48 - 2015-05-19 20:25 - 00000000 ____D C:\Users\Hibatoullah\Downloads\a D. avril 2015 2015-06-25 20:36 - 2014-12-14 21:52 - 00000000 ____D C:\ProgramData\FLEXnet 2015-06-24 23:55 - 2013-08-22 16:36 - 00000000 ____D C:\Windows\system32\NDF 2015-06-24 10:22 - 2015-03-25 11:46 - 00000000 ____D C:\Workspace 2015-06-24 10:19 - 2015-05-28 22:29 - 00000000 ____D C:\Users\Hibatoullah\Desktop\eclipse 2015-06-24 01:46 - 2015-06-22 22:50 - 00000000 ____D C:\Users\Hibatoullah\Desktop\Etudes 2015-06-24 01:28 - 2014-12-14 20:23 - 00000000 ____D C:\Des installs ==================== Files in the root of some directories ======= 2015-07-19 11:16 - 2015-07-19 11:16 - 0000046 _____ () C:\Users\Hibatoullah\AppData\Roaming\Camdata.ini 2015-07-19 11:16 - 2015-07-19 11:16 - 0000408 _____ () C:\Users\Hibatoullah\AppData\Roaming\CamLayout.ini 2015-07-19 11:16 - 2015-07-19 11:16 - 0000408 _____ () C:\Users\Hibatoullah\AppData\Roaming\CamShapes.ini 2015-07-19 11:16 - 2015-07-19 11:16 - 0004510 _____ () C:\Users\Hibatoullah\AppData\Roaming\CamStudio.cfg 2015-01-09 00:54 - 2015-05-26 11:31 - 0000115 _____ () C:\Users\Hibatoullah\AppData\Roaming\LogFile.txt 2015-06-12 11:03 - 2015-06-12 11:03 - 0000099 _____ () C:\Users\Hibatoullah\AppData\Local\fusioncache.dat 2015-07-15 19:06 - 2015-07-15 19:06 - 0009120 _____ () C:\Users\Hibatoullah\AppData\Local\recently-used.xbel 2015-07-05 22:52 - 2015-07-05 22:52 - 0000017 _____ () C:\Users\Hibatoullah\AppData\Local\resmon.resmoncfg 2015-01-01 16:12 - 2015-01-01 16:12 - 0000000 _____ () C:\Users\Hibatoullah\AppData\Local\{3EDCFF25-ABA1-4CD1-ACF1-D60BCB6FDCAF} 2014-11-30 15:23 - 2014-11-30 15:23 - 0000000 _____ () C:\Users\Hibatoullah\AppData\Local\{EBC605F1-C9D0-463E-9B79-C11251042AC5} 2014-09-11 18:50 - 2014-09-11 18:50 - 0000153 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc Files to move or delete: ==================== C:\Users\Hibatoullah\postgis_2_1_pg93.exe C:\Users\Hibatoullah\postgresql_92.exe C:\Users\Hibatoullah\postgresql_93.exe C:\Users\Hibatoullah\ZHPCleaner.exe C:\Users\Hibatoullah\ZHPDiag3.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-07-18 00:25 ==================== End of log ============================