Rapport de ZHPDiag v1.3.5.121 par Nicolas Coolman, Update du 23/02/2013 Run by coco at 23/02/2013 20:28:59 State : Version à jour. High Elevated Privileges : OK UAC : Deactivate by program ---\\ Web Browser MSIE: Internet Explorer v9.0.8112.16421 ---\\ Windows Product Information ~ Langage: Français Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601) Windows Server License Manager Script : OK ~ Windows(R) 7, OEM_SLP channel System Locked Preinstallation (OEM_SLP) : OK Windows ID Activation : OK ~ Windows Partial Key : BWX77 Windows License : OK ~ Windows Remaining Initializations Number : 4 Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ System Information ~ Processor: AMD64 Family 16 Model 6 Stepping 3, AuthenticAMD ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 2811 MB (55% free) System Restore: Activé (Enable) System drive C: has 46 GB (39%) free of 116 GB ---\\ Logged in mode ~ Computer Name: ORDI ~ User Name: coco ~ All Users Names: HomeGroupUser$, coco, Administrateur, ~ Unselected Option: None Logged in as Administrator ---\\ Environnement Variables ~ System Unit : C:\ ~ %AppData% : C:\Users\coco\AppData\Roaming\ ~ %Desktop% : C:\Users\coco\Desktop\ ~ %Favorites% : C:\Users\coco\Favorites\ ~ %LocalAppData% : C:\Users\coco\AppData\Local\ ~ %StartMenu% : C:\Users\coco\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ DOS/Devices C:\ Hard drive, Flash drive, Thumb drive (Free 46 Go of 116 Go) D:\ Hard drive, Flash drive, Thumb drive (Free 109 Go of 116 Go) E:\ CD-ROM drive (Not Inserted) Q:\ Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go) ---\\ Security Center & Tools Informations [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ~ Scan Security Center in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808] [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024] [MD5.435E9C764E1EF70058580996452BE6A2] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.09/01/2013 - 02:12:03.) -- C:\Windows\System32\wininet.dll [1392128] [MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.20/11/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656] [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448] [MD5.1C7857B62DE5994A75B054A9FD4C3825] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/12/2011 - 04:59:24.) -- C:\Windows\system32\Drivers\AFD.sys [498688] [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128] [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160] [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456] [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400] [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368] [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472] [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224] [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208] [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632] [MD5.E453ACF4E7D44E5530B5D5F2B9CA8563] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.31/08/2012 - 19:19:35.) -- C:\Windows\system32\Drivers\ntfs.sys [1659760] [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280] [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536] [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184] [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296] [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808] ~ Scan Generic Processes in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 2/9530 ~ Mes musiques (My Musics) : 6/623 ~ Mes Videos (My Videos) : 1/18 ~ Mes Favoris (My Favorites) : 1/54 ~ Mes Documents (My Documents) : 2/4886 ~ Mon Bureau (My Desktop) : 4/30 ~ Menu demarrer (Programs) : 1/27 ~ Scan Hidden Files in 00mn 08s ---\\ Processus lancés [MD5.86E69581356CA45167EA6986B6E29087] - (.TOSHIBA CORPORATION - ConfigFree Task Tray Menu.) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe [304560] [PID.4020] [MD5.05973FB5F863CDB65852D88ADB383A33] - (.TOSHIBA - TOSHIBA Online Product Information.) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [4581280] [PID.3200] [MD5.1FAA54E9FFEA6FD3E0CEAD951CDDFEF6] - (.TOSHIBA CORPORATION - KeNotify MFC Application.) -- C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34160] [PID.4120] [MD5.80D632DC81BDF6E58630D8FA329FAE54] - (.TOSHIBA CORPORATION. - Pas de description.) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2454840] [PID.4220] [MD5.3CB07566302BCEEB898DE270A0BEC175] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352] [PID.4416] [MD5.083649EF692A066880C9326020915AFE] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [4297136] [PID.4444] [MD5.8A07221789D46B2EA7DFCA2BC807572A] - (.TOSHIBA CORPORATION - ConfigFree Switch Manager Process.) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe [62848] [PID.3252] [MD5.6C8C001EF62CEFA7E333AF8D0AAED564] - (.Microsoft Corporation - Microsoft Office Word.) -- C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.exe [409696] [PID.2696] [MD5.ED48AD981F026087F485403A3C2B0897] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [5696512] [PID.740] [MD5.8FA553E9AE69808D99C164733A0F9590] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44808] [PID.1240] [MD5.3927397AC60D943DAF8808AFFED582B7] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65192] [PID.1716] [MD5.4DE2EE2A5186D74BABC4E7F60D2AE989] - (.Realsil Microelectronics Inc. - Realtek Card Reader Icon Tool..) -- C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [1811456] [PID.1768] [MD5.C3CDDD18F43D44AB713CF8C4916F7696] - (.Microsoft Corporation - Microsoft Application Virtualization Virtua.) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [219496] [PID.1804] [MD5.13693B6354DD6E72DC5131DA7D764B90] - (.Microsoft Corporation - Microsoft Application Virtualization Client.) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [508776] [PID.2416] [MD5.72794D112CBAFF3BC0C29BF7350D4741] - (.Microsoft Corporation - Microsoft Office Client Virtualization Serv.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.exe [822624] [PID.3040] [MD5.CAB0EEAF5295FC96DDD3E19DCE27E131] - (.TOSHIBA CORPORATION - ConfigFree Service Process.) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [46448] [PID.3684] ~ Scan Processes Running in 00mn 00s ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2) C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Preferences G0 - GCSP: Preference [User Data\Default][HomePage] http://www.google.com G1 - GCS: Preference [User Data\Default] None ~ Scan Google Browser in 00mn 00s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) P2 - FPN: [HKCU] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Users\coco\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll P2 - FPN: [HKCU] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Users\coco\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll ~ Scan Firefox Browser in 00mn 00s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R3 - URLSearchHook: FCToolbarURLSearchHook Class [64Bits] - {b843a48a-b70f-45cd-a15a-6c2b30c2c11e} . (...) (No version) -- C:\Program Files (x86)\Gamers Unite! Snag Bar\Helper.dll R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1 ~ Scan IE Browser in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Scan Proxy management in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Scan Keys in 00mn 00s ---\\ Redirection du fichier Hosts (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Scan Hosts File in 00mn 00s ~ Nombre de lignes (Lines number): 21 ---\\ Browser Helper Objects de navigateur (O2) O2 - BHO: AcroIEHelperStub [64Bits] - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: FCTBPos00Pos [64Bits] - {26A7CA19-7D58-411D-B2DA-F1B0324CBFFC} . (.Pas de propriétaire - FreeCause Toolbar.) -- C:\Program Files (x86)\Gamers Unite! Snag Bar\Toolbar.dll O2 - BHO: avast! WebRep [64Bits] - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - avast! WebRep Plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\ O2 - BHO: Windows Live Messenger Companion Helper [64Bits] - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} . (.Microsoft Corporation - Windows Live Messenger Companion Core.) -- C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O2 - BHO: SkypeIEPluginBHO [64Bits] - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Skype Technologies S.A. - Skype add-on for IE.) -- C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O2 - BHO: TOSHIBA Media Controller Plug-in [64Bits] - {F3C88694-EFFA-4d78-B409-54B7B2535B14} . (. - TOSHIBA Media Controller Plug-in.) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll ~ Scan BHO in 00mn 00s ---\\ Internet Explorer Toolbars (O3) O3 - Toolbar: (no name) [64Bits] - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Clé orpheline ~ Scan Toolbar in 00mn 00s ---\\ Applications démarrées par registre & par dossier (O4) O4 - HKLM\..\Run: [TosNC] C:\Program Files (x86)\Toshiba\BulletinBoard\TosNcCore.exe (.not file.) O4 - HKLM\..\Run: [TosReelTimeMonitor] C:\Program Files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (.not file.) O4 - HKLM\..\Run: [Toshiba TEMPRO] . (.Toshiba Europe GmbH - Toshiba TEMPRO.) -- C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe O4 - HKLM\..\Run: [RtHDVBg] . (.Realtek Semiconductor - HD Audio Background Process.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe O4 - HKLM\..\Run: [TPwrMain] C:\Program Files (x86)\TOSHIBA\Power Saver\TPwrMain.exe (.not file.) O4 - HKLM\..\Run: [SmoothView] C:\Program Files (x86)\Toshiba\SmoothView\SmoothView.exe (.not file.) O4 - HKLM\..\Run: [00TCrdMain] C:\Program Files (x86)\TOSHIBA\FlashCards\TCrdMain.exe (.not file.) O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.) O4 - HKLM\..\Run: [TosSENotify] . (.TOSHIBA Corporation - Pas de description.) -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe O4 - HKLM\..\Run: [SmartFaceVWatcher] C:\Program Files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe (.not file.) O4 - HKLM\..\Run: [TosVolRegulator] . (.TOSHIBA Corporation - Toshiba Volume Regulator.) -- C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe O4 - HKLM\..\Run: [Toshiba Registration] . (.Toshiba Europe GmbH - Toshiba Notebook Registration Reminder.) -- C:\Program Files\Toshiba\Registration\ToshibaReminder.exe O4 - HKCU\..\Run: [TOSHIBA Online Product Information] . (.TOSHIBA - TOSHIBA Online Product Information.) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe O4 - HKCU\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\coco\AppData\Local\Google\Update\GoogleUpdate.exe O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe O4 - HKLM\..\Wow6432Node\Run: [SVPWUTIL] . (.TOSHIBA - SVPWUTIL Application.) -- C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe O4 - HKLM\..\Wow6432Node\Run: [KeNotify] . (.TOSHIBA CORPORATION - KeNotify MFC Application.) -- C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe O4 - HKLM\..\Wow6432Node\Run: [TWebCamera] . (.TOSHIBA CORPORATION. - Pas de description.) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe O4 - HKLM\..\Wow6432Node\Run: [ToshibaServiceStation] . (.TOSHIBA Corporation - TOSHIBA Service Station.) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe O4 - HKLM\..\Wow6432Node\Run: [avast] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastUI.exe O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] . (.TOSHIBA - TOSHIBA Online Product Information.) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-21-4125327599-2493812685-2951380254-1000\..\Run: [TOSHIBA Online Product Information] . (.TOSHIBA - TOSHIBA Online Product Information.) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe O4 - HKUS\S-1-5-21-4125327599-2493812685-2951380254-1000\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe O4 - HKUS\S-1-5-21-4125327599-2493812685-2951380254-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe O4 - HKUS\S-1-5-21-4125327599-2493812685-2951380254-1000\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\coco\AppData\Local\Google\Update\GoogleUpdate.exe O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe ~ Scan Application in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\TaskBar: Google Chrome.lnk . (.Google Inc..) -- C:\Users\coco\AppData\Local\Google\Chrome\Application\chrome.exe O4 - GS\TaskBar: Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\TaskBar: Toshiba Assist.lnk . (...) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Assist\TInTouch.exe (.not file.) O4 - GS\TaskBar: TOSHIBA Bulletin Board.lnk . (...) -- C:\Program Files (x86)\TOSHIBA\BulletinBoard\TosBulletinBoard.exe (.not file.) O4 - GS\TaskBar: TosReelTime.lnk . (...) -- C:\Program Files (x86)\TOSHIBA\ReelTime\TosReelTime.exe (.not file.) O4 - GS\TaskBar: Windows Explorer.lnk . (.Microsoft Corporation.) -- C:\Windows\explorer.exe O4 - GS\TaskBar: Windows Media Player.lnk . (...) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 (.not file.) O4 - GS\Programs: Internet Explorer (64-bit).lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\Programs: Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\Programs: SocialReviver_ The way YOU want Facebook to be!.lnk . (...) -- C:\Users\coco\AppData\Local\Google\Chrome\Application\chrome.exe --app= (.not file.) O4 - GS\Desktop: AD-R.lnk . (...) -- C:\Program Files (x86)\Ad-Remover\main.exe O4 - GS\Desktop: Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\Desktop: WordBiz.lnk . (...) -- C:\Program Files (x86)\WordBiz\WordBiz.exe O4 - GS\QuickLaunch: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\QuickLaunch: Microsoft Office Outlook.lnk . (...) -- C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE /recycle (.not file.) ~ Scan Global Startup in 00mn 00s ---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5) O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no ~ Scan IE Control Panel in 00mn 00s ---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll O10 - WLSP:\000000000009\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll ~ Scan Winsock in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{00B5CE8A-AAF7-4F2A-8089-B7882196E6FB}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{A6EFCD3B-E876-4096-827F-EB0998B6D535}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{00B5CE8A-AAF7-4F2A-8089-B7882196E6FB}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{A6EFCD3B-E876-4096-827F-EB0998B6D535}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{00B5CE8A-AAF7-4F2A-8089-B7882196E6FB}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{A6EFCD3B-E876-4096-827F-EB0998B6D535}: DhcpNameServer = 192.168.1.1 192.168.1.1 ~ Scan Domain in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) -- O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll ~ Scan Protocole Additionnel in 00mn 00s ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. ~ Scan SSODL in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\System32\atiesrxx.exe O23 - Service: avast! Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) . (.TOSHIBA CORPORATION - ConfigFree Service Process.) - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe O23 - Service: ConfigFree Service (ConfigFree Service) . (.TOSHIBA CORPORATION - ConfigFree Service Process.) - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: IconMan_R (IconMan_R) . (.Realsil Microelectronics Inc. - Realtek Card Reader Icon Tool..) - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) . (.TOSHIBA Corporation - TDCSrv Application.) - C:\Windows\system32\TODDSrv.exe O23 - Service: TOSHIBA Power Saver (TosCoSrv) . (.TOSHIBA Corporation - TOSHIBA Power Saver.) - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe O23 - Service: (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) ~ Scan Services in 00mn 06s ---\\ Enumération Active Desktop & MHTML Editor (O24) O24 - Default MHTML Editor: Last - .(...) - (.not file.) ~ Scan Desktop Component in 00mn 00s ---\\ BootExecute (O34) O34 - HKLM BootExecute: (autocheck autochk *) - File not found ~ Scan Keys in 00mn 00s ---\\ Tâches planifiées en automatique (O39) O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4125327599-2493812685-2951380254-1000Core.job O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4125327599-2493812685-2951380254-1000UA.job [MD5.7F19838AC317C34FCED020BE529AF71E] [APT] [avast! Emergency Update] (.AVAST Software.) -- C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [MD5.86E69581356CA45167EA6986B6E29087] [APT] [ConfigFree Startup Programs] (.TOSHIBA CORPORATION.) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe [MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskUserS-1-5-21-4125327599-2493812685-2951380254-1000Core] (.Google Inc..) -- C:\Users\coco\AppData\Local\Google\Update\GoogleUpdate.exe [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskUserS-1-5-21-4125327599-2493812685-2951380254-1000UA] (.Google Inc..) -- C:\Users\coco\AppData\Local\Google\Update\GoogleUpdate.exe [MD5.0C6B092D61E33E70E71A6A4F42A81B11] [APT] [{0AF9C54D-CFEB-4F13-85BD-1F14B5A6F3C7}] (...) -- C:\Program Files (x86)\WordBiz\WordBiz.exe [MD5.00000000000000000000000000000000] [APT] [{29C71422-35CA-4EE5-BA80-C159627D1108}] (...) -- C:\Program Files (x86)\Bouygues Telecom\Internet 3G+\Bouygues.exe (.not file.) ~ Scan Scheduled Task in 00mn 01s ---\\ Composants installés (ActiveSetup Installed Components) (O40) O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll O40 - ASIC: Internet Explorer [64Bits] - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe O40 - ASIC: Browsing Enhancements [64Bits] - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll O40 - ASIC: Windows Desktop Update [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll ~ Scan Active Setup in 00mn 00s ---\\ Pilotes lancés au démarrage (O41) O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys O41 - Driver: (aswRdr) . (.AVAST Software - avast! WFP Redirect Driver.) - C:\Windows\system32\Drivers\aswrdr2.sys O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\system32\DRIVERS\blbdrive.sys O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\drivers\cdrom.sys O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys ~ Scan Drivers in 00mn 00s ---\\ Logiciels installés (O42) O42 - Logiciel: ATI Catalyst Install Manager - (.ATI Technologies, Inc..) [HKLM][64Bits] -- {B6DB58D2-E7E8-5B0F-65F8-B76713C0AF75} O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM][64Bits] -- Adobe AIR O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM][64Bits] -- {A2BCA9F1-566C-4805-97D1-7FDC93386723} O42 - Logiciel: Adobe Flash Player 11 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Reader X (10.1.5) - Français - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1036-7B44-AA1000000001} O42 - Logiciel: Bejeweled 2 Deluxe - (.WildTangent.) [HKLM][64Bits] -- WT083929 O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM][64Bits] -- {8BD785CF-30C7-4182-B250-0D5FCE78D4DD} O42 - Logiciel: Chuzzle Deluxe - (.WildTangent.) [HKLM][64Bits] -- WT083877 O42 - Logiciel: Complément Messenger - (.Microsoft Corporation.) [HKLM][64Bits] -- {6E5324C1-84FC-4F76-9A3A-C65E07F80EE6} O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} O42 - Logiciel: Diner Dash 2 Restaurant Rescue - (.WildTangent.) [HKLM][64Bits] -- WT083916 O42 - Logiciel: FATE - (.WildTangent.) [HKLM][64Bits] -- WT083945 O42 - Logiciel: Gamers Unite! Snag Bar - (.Pas de propriétaire.) [HKLM][64Bits] -- Gamers Unite! Snag Bar O42 - Logiciel: Google Chrome - (.Google Inc..) [HKCU][64Bits] -- Google Chrome O42 - Logiciel: Google Drive - (.Google, Inc..) [HKLM][64Bits] -- {7A21C722-F259-4976-B7AA-6658E5FDEDAF} O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} O42 - Logiciel: Internet 3G+ Bouygues Telecom - (.Pas de propriétaire.) [HKLM][64Bits] -- {93D34EE3-99B3-4DB1-8B0A-0A657466F90D} O42 - Logiciel: Java(TM) 6 Update 20 - (.Sun Microsystems, Inc..) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83216020FF} O42 - Logiciel: Jeux WildTangent - (.WildTangent.) [HKLM][64Bits] -- WildTangent toshiba Master Uninstall O42 - Logiciel: Jewel Quest II - (.WildTangent.) [HKLM][64Bits] -- WT083910 O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM][64Bits] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4} O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} O42 - Logiciel: MSVCRT_amd64 - (.Microsoft.) [HKLM][64Bits] -- {D0B44725-3666-492D-BEF6-587A14BD9BD9} O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM][64Bits] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71} O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM][64Bits] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC} O42 - Logiciel: Malwarebytes Anti-Malware version 1.70.0.1100 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes' Anti-Malware_is1 O42 - Logiciel: Mesh Runtime - (.Microsoft Corporation.) [HKLM][64Bits] -- {8C6D6116-B724-4810-8F2D-D047E6B7D68E} O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} O42 - Logiciel: Penguins! - (.WildTangent.) [HKLM][64Bits] -- WT083958 O42 - Logiciel: Photo Service - powered by myphotobook - (.myphotobook GmbH.) [HKLM][64Bits] -- eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1 O42 - Logiciel: Photo Service - powered by myphotobook - (.myphotobook GmbH.) [HKLM][64Bits] -- {9DA0961E-FCFE-EEF2-04AA-32631F7CEC9E} O42 - Logiciel: Plants vs. Zombies - (.WildTangent.) [HKLM][64Bits] -- WT083925 O42 - Logiciel: PlayReady PC Runtime amd64 - (.Microsoft Corporation.) [HKLM][64Bits] -- {BCA9334F-B6C9-4F65-9A73-AC5A329A4D04} O42 - Logiciel: Polar Bowler - (.WildTangent.) [HKLM][64Bits] -- WT083959 O42 - Logiciel: Realtek Ethernet Controller Driver For Windows 7 - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} O42 - Logiciel: Realtek USB 2.0 Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {96AE7E41-E34E-47D0-AC07-1091A8127911} O42 - Logiciel: Realtek WLAN Driver - (.REALTEK Semiconductor Corp..) [HKLM][64Bits] -- {9D3D8C60-A55F-4fed-B2B9-173001290E16} O42 - Logiciel: Ricochet Xtreme - (.WildTangent.) [HKLM][64Bits] -- WTA-5555c188-972a-4890-8ba6-4bfe1b23fba0 O42 - Logiciel: Skype Toolbars - (.Skype Technologies S.A..) [HKLM][64Bits] -- {981029E0-7FC9-4CF3-AB39-6F133621921A} O42 - Logiciel: Skype™ 5.10 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8} O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey O42 - Logiciel: TOSHIBA Assist - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {C2A276E3-154E-44DC-AAF1-FFDD7FD30E35} O42 - Logiciel: TOSHIBA Bulletin Board - (.TOSHIBA Corporation.) [HKLM][64Bits] -- InstallShield_{C14518AF-1A0F-4D39-8011-69BAA01CD380} O42 - Logiciel: TOSHIBA Bulletin Board - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {C14518AF-1A0F-4D39-8011-69BAA01CD380} O42 - Logiciel: TOSHIBA ConfigFree - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {E0FAA369-B0E3-48B8-9447-4873103B0012} O42 - Logiciel: TOSHIBA Disc Creator - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {5DA0E02F-970B-424B-BF41-513A5018E4C0} O42 - Logiciel: TOSHIBA Face Recognition - (.TOSHIBA Corporation.) [HKLM][64Bits] -- InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F} O42 - Logiciel: TOSHIBA Face Recognition - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {F67FA545-D8E5-4209-86B1-AEE045D1003F} O42 - Logiciel: TOSHIBA Flash Cards Support Utility - (.Nom de votre société.) [HKLM][64Bits] -- InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E} O42 - Logiciel: TOSHIBA Flash Cards Support Utility - (.Nom de votre société.) [HKLM][64Bits] -- {620BBA5E-F848-4D56-8BDA-584E44584C5E} O42 - Logiciel: TOSHIBA HDD/SSD Alert - (.TOSHIBA Corporation.) [HKLM][64Bits] -- InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38} O42 - Logiciel: TOSHIBA HDD/SSD Alert - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {D4322448-B6AF-4316-B859-D8A0E84DCB38} O42 - Logiciel: TOSHIBA Hardware Setup - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3} O42 - Logiciel: TOSHIBA Hardware Setup - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {5279374D-87FE-4879-9385-F17278EBB9D3} O42 - Logiciel: TOSHIBA Media Controller - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {983CD6FE-8320-4B80-A8F6-0D0366E0AA22} O42 - Logiciel: TOSHIBA Media Controller Plug-in - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {F26FDF57-483E-42C8-A9C9-EEE1EDB256E0} O42 - Logiciel: TOSHIBA Mot de passe responsable - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE} O42 - Logiciel: TOSHIBA Online Product Information - (.TOSHIBA.) [HKLM][64Bits] -- {2290A680-4083-410A-ADCC-7092C67FC052} O42 - Logiciel: TOSHIBA Recovery Media Creator - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {B65BBB06-1F8E-48F5-8A54-B024A9E15FDF} O42 - Logiciel: TOSHIBA Recovery Media Creator Reminder - (.TOSHIBA.) [HKLM][64Bits] -- InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492} O42 - Logiciel: TOSHIBA ReelTime - (.TOSHIBA Corporation.) [HKLM][64Bits] -- InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C} O42 - Logiciel: TOSHIBA ReelTime - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {24811C12-F4A9-4D0F-8494-A7B8FE46123C} O42 - Logiciel: TOSHIBA Service Station - (.TOSHIBA.) [HKLM][64Bits] -- {AC6569FA-6919-442A-8552-073BE69E247A} O42 - Logiciel: TOSHIBA Supervisor Password - (.TOSHIBA CORPORATION.) [HKLM][64Bits] -- {51B4E156-14A5-4904-9AE4-B1AA2A0E46BE} O42 - Logiciel: TOSHIBA Value Added Package - (.TOSHIBA Corporation.) [HKLM][64Bits] -- InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E} O42 - Logiciel: TOSHIBA Web Camera Application - (.TOSHIBA Corporation.) [HKLM][64Bits] -- {5E6F6CF3-BACC-4144-868C-E14622C658F3} O42 - Logiciel: TRORMCLauncher - (.Pas de propriétaire.) [HKLM][64Bits] -- InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600} O42 - Logiciel: Toshiba Manuals - (.TOSHIBA.) [HKLM][64Bits] -- {90FF4432-21B7-4AF6-BA6E-FB8C1FED9173} O42 - Logiciel: Toshiba TEMPRO - (.Toshiba Europe GmbH.) [HKLM][64Bits] -- {DBB7021A-3437-446F-ACE5-7261644A972C} O42 - Logiciel: Utility Common Driver - (.TOSHIBA.) [HKLM][64Bits] -- InstallShield_{12688FD7-CB92-4A5B-BEE4-5C8E0574434F} O42 - Logiciel: Utility Common Driver - (.TOSHIBA.) [HKLM][64Bits] -- {12688FD7-CB92-4A5B-BEE4-5C8E0574434F} O42 - Logiciel: WildTangent ORB Game Console - (.WildTangent.) [HKLM][64Bits] -- TOSHIBA Game Console O42 - Logiciel: WordBiz version 1.8 - (.Internet Scrabble Club.) [HKLM][64Bits] -- Internet Scrabble Club_is1 O42 - Logiciel: Zuma Deluxe - (.WildTangent.) [HKLM][64Bits] -- WT083890 O42 - Logiciel: avast! Free Antivirus v7.0.1474.0 - (.AVAST Software.) [HKLM][64Bits] -- avast O42 - Logiciel: neroxml - (.Nero AG.) [HKLM][64Bits] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B} ---\\ HKCU & HKLM Software Keys [HKCU\Software\ATI] [HKCU\Software\Ad-Remover] [HKCU\Software\Adobe] [HKCU\Software\AppDataLow\Software\FCTB000062781] [HKCU\Software\AppDataLow\Software\Freecause] [HKCU\Software\AppDataLow\Software\Microsoft] [HKCU\Software\AppDataLow\Software] [HKCU\Software\AppDataLow] [HKCU\Software\Avast Software] [HKCU\Software\Bouygues] [HKCU\Software\Classes] [HKCU\Software\Clients] [HKCU\Software\Google] [HKCU\Software\Hewlett-Packard] [HKCU\Software\HookNetwork] [HKCU\Software\IM Providers] [HKCU\Software\JavaSoft] [HKCU\Software\Macromedia] [HKCU\Software\Malwarebytes' Anti-Malware] [HKCU\Software\MozillaPlugins] [HKCU\Software\Nero] [HKCU\Software\Netscape] [HKCU\Software\ODBC] [HKCU\Software\Policies] [HKCU\Software\Realtek] [HKCU\Software\Skype] [HKCU\Software\Synaptics] [HKCU\Software\TOSHIBA] [HKCU\Software\WildTangent] [HKCU\Software\Wow6432Node] [HKCU\Software\ZebHelpProcess Helper] [HKLM\Software\AMD] [HKLM\Software\ATI Technologies] [HKLM\Software\ATI] [HKLM\Software\Audible] [HKLM\Software\BrowserChoice] [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\Cyberlink] [HKLM\Software\DTS] [HKLM\Software\Huawei technologies] [HKLM\Software\InstalledOptions] [HKLM\Software\Intel] [HKLM\Software\Macromedia] [HKLM\Software\McAfee.com] [HKLM\Software\McAfee] [HKLM\Software\MozillaPlugins] [HKLM\Software\ODBC] [HKLM\Software\Policies] [HKLM\Software\RTLSetup] [HKLM\Software\Realtek Semiconductor Corp.] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\SRS Labs] [HKLM\Software\SiteAdvisor] [HKLM\Software\SonicFocus] [HKLM\Software\Sonic] [HKLM\Software\Synaptics] [HKLM\Software\TOSHIBA] [HKLM\Software\Toshiba Tempro] [HKLM\Software\Waves Audio] [HKLM\Software\WildTangent] [HKLM\Software\Wow6432Node\ATI Technologies] [HKLM\Software\Wow6432Node\ATI] [HKLM\Software\Wow6432Node\AVAST Software] [HKLM\Software\Wow6432Node\Adobe] [HKLM\Software\Wow6432Node\AdwCleaner] [HKLM\Software\Wow6432Node\Audible] [HKLM\Software\Wow6432Node\Bouygues] [HKLM\Software\Wow6432Node\COMPAL] [HKLM\Software\Wow6432Node\Classes] [HKLM\Software\Wow6432Node\Clients] [HKLM\Software\Wow6432Node\Google] [HKLM\Software\Wow6432Node\Intel] [HKLM\Software\Wow6432Node\Internet 3G+ Bouygues Telecom] [HKLM\Software\Wow6432Node\JavaSoft] [HKLM\Software\Wow6432Node\JreMetrics] [HKLM\Software\Wow6432Node\KasperskyLab] [HKLM\Software\Wow6432Node\Macromedia] [HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware] [HKLM\Software\Wow6432Node\McAfeeInstaller] [HKLM\Software\Wow6432Node\McAfee] [HKLM\Software\Wow6432Node\MozillaPlugins] [HKLM\Software\Wow6432Node\Mozilla] [HKLM\Software\Wow6432Node\Nero] [HKLM\Software\Wow6432Node\ODBC] [HKLM\Software\Wow6432Node\Policies] [HKLM\Software\Wow6432Node\Realtek Semiconductor Corp.] [HKLM\Software\Wow6432Node\Realtek] [HKLM\Software\Wow6432Node\RegisteredApplications] [HKLM\Software\Wow6432Node\RtWLan] [HKLM\Software\Wow6432Node\Skype] [HKLM\Software\Wow6432Node\TOSHIBA CORPORATION] [HKLM\Software\Wow6432Node\TOSHIBA] [HKLM\Software\Wow6432Node\WildTangent] [HKLM\Software\Wow6432Node] ~ Scan Softwares in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 22/02/2013 - 19:49:11 - [91,318] ----D C:\Program Files (x86)\Ad-Remover O43 - CFD: 01/10/2011 - 13:26:49 - [159,003] ----D C:\Program Files (x86)\Adobe O43 - CFD: 15/09/2010 - 02:02:59 - [88,055] ----D C:\Program Files (x86)\ATI Technologies O43 - CFD: 20/01/2011 - 13:51:00 - [0,021] ----D C:\Program Files (x86)\Bouygues Telecom O43 - CFD: 13/10/2012 - 07:27:30 - [396,969] ----D C:\Program Files (x86)\Common Files O43 - CFD: 12/06/2012 - 14:35:48 - [5,075] ----D C:\Program Files (x86)\Gamers Unite! Snag Bar O43 - CFD: 25/01/2013 - 19:58:41 - [37,745] ----D C:\Program Files (x86)\Google O43 - CFD: 11/07/2012 - 00:12:56 - [137,586] --H-D C:\Program Files (x86)\InstallShield Installation Information O43 - CFD: 01/12/2012 - 07:46:03 - [16,040] ----D C:\Program Files (x86)\Internet 3G+ Bouygues Telecom O43 - CFD: 22/02/2013 - 16:11:42 - [5,256] ----D C:\Program Files (x86)\Internet Explorer O43 - CFD: 31/08/2010 - 17:29:26 - [86,366] ----D C:\Program Files (x86)\Java O43 - CFD: 09/02/2013 - 11:52:26 - [12,283] ----D C:\Program Files (x86)\Malwarebytes' Anti-Malware O43 - CFD: 23/10/2012 - 22:00:16 - [28,909] ----D C:\Program Files (x86)\Microsoft O43 - CFD: 26/02/2012 - 15:37:49 - [12,399] ----D C:\Program Files (x86)\Microsoft Application Virtualization Client O43 - CFD: 13/08/2011 - 21:47:23 - [431,715] ----D C:\Program Files (x86)\Microsoft Office O43 - CFD: 21/07/2012 - 00:09:02 - [36,641] ----D C:\Program Files (x86)\Microsoft Silverlight O43 - CFD: 31/08/2010 - 17:57:18 - [1,745] ----D C:\Program Files (x86)\Microsoft SQL Server Compact Edition O43 - CFD: 13/08/2011 - 21:51:23 - [0,014] ----D C:\Program Files (x86)\Microsoft Visual Studio O43 - CFD: 05/01/2011 - 21:54:30 - [3,554] ----D C:\Program Files (x86)\Microsoft Works O43 - CFD: 27/12/2010 - 23:18:17 - [7,789] ----D C:\Program Files (x86)\Microsoft.NET O43 - CFD: 14/07/2009 - 06:32:38 - [0,025] ----D C:\Program Files (x86)\MSBuild O43 - CFD: 23/12/2010 - 21:28:01 - [0] ----D C:\Program Files (x86)\MSXML 4.0 O43 - CFD: 23/10/2012 - 21:54:53 - [0] ----D C:\Program Files (x86)\Nero O43 - CFD: 31/08/2010 - 17:50:25 - [26,129] ----D C:\Program Files (x86)\Photo-Service O43 - CFD: 15/09/2010 - 02:17:25 - [15,061] ----D C:\Program Files (x86)\Realtek O43 - CFD: 18/02/2011 - 16:38:23 - [5,757] ----D C:\Program Files (x86)\Realtek WLAN Driver O43 - CFD: 14/07/2009 - 06:32:38 - [37,357] ----D C:\Program Files (x86)\Reference Assemblies O43 - CFD: 13/10/2012 - 07:27:30 - [24,550] R---D C:\Program Files (x86)\Skype O43 - CFD: 15/09/2010 - 02:06:29 - [0] --H-D C:\Program Files (x86)\Temp O43 - CFD: 15/09/2010 - 02:25:46 - [219,652] ----D C:\Program Files (x86)\TOSHIBA O43 - CFD: 24/02/2011 - 18:21:42 - [543,527] ----D C:\Program Files (x86)\TOSHIBA Games O43 - CFD: 31/08/2010 - 17:54:23 - [10,895] ----D C:\Program Files (x86)\Toshiba TEMPRO O43 - CFD: 14/07/2009 - 05:57:06 - [0] --H-D C:\Program Files (x86)\Uninstall Information O43 - CFD: 14/07/2009 - 16:24:08 - [0,500] ----D C:\Program Files (x86)\Windows Defender O43 - CFD: 12/07/2012 - 20:51:16 - [169,845] ----D C:\Program Files (x86)\Windows Live O43 - CFD: 03/08/2012 - 17:32:35 - [5,895] ----D C:\Program Files (x86)\Windows Mail O43 - CFD: 03/08/2012 - 17:32:35 - [4,791] ----D C:\Program Files (x86)\Windows Media Player O43 - CFD: 14/07/2009 - 06:32:38 - [11,632] ----D C:\Program Files (x86)\Windows NT O43 - CFD: 03/08/2012 - 17:32:35 - [4,213] ----D C:\Program Files (x86)\Windows Photo Viewer O43 - CFD: 03/08/2012 - 17:32:35 - [0,181] ----D C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 03/08/2012 - 17:32:35 - [5,945] ----D C:\Program Files (x86)\Windows Sidebar O43 - CFD: 16/07/2011 - 17:47:28 - [8,837] ----D C:\Program Files (x86)\WordBiz O43 - CFD: 23/02/2013 - 20:29:12 - [15,144] ----D C:\Program Files (x86)\ZHPDiag O43 - CFD: 01/10/2011 - 13:26:54 - [3,797] ----D C:\Program Files (x86)\Common Files\Adobe O43 - CFD: 31/08/2010 - 17:50:23 - [30,668] ----D C:\Program Files (x86)\Common Files\Adobe AIR O43 - CFD: 24/12/2010 - 21:40:32 - [0,095] ----D C:\Program Files (x86)\Common Files\DESIGNER O43 - CFD: 15/09/2010 - 02:05:55 - [2,009] ----D C:\Program Files (x86)\Common Files\InstallShield O43 - CFD: 31/08/2010 - 17:31:00 - [1,175] ----D C:\Program Files (x86)\Common Files\Java O43 - CFD: 05/01/2011 - 18:52:52 - [0,784] ----D C:\Program Files (x86)\Common Files\mcafee O43 - CFD: 12/07/2012 - 20:49:04 - [265,651] ----D C:\Program Files (x86)\Common Files\microsoft shared O43 - CFD: 23/10/2012 - 21:55:57 - [0,108] ----D C:\Program Files (x86)\Common Files\Nero O43 - CFD: 26/12/2011 - 09:53:11 - [0,551] ----D C:\Program Files (x86)\Common Files\PctelEapPeer Authentication O43 - CFD: 14/07/2009 - 04:20:08 - [0,003] ----D C:\Program Files (x86)\Common Files\Services O43 - CFD: 13/10/2012 - 07:27:30 - [2,056] ----D C:\Program Files (x86)\Common Files\Skype O43 - CFD: 14/07/2009 - 04:20:08 - [39,200] ----D C:\Program Files (x86)\Common Files\SpeechEngines O43 - CFD: 03/08/2012 - 17:32:35 - [42,254] ----D C:\Program Files (x86)\Common Files\System O43 - CFD: 31/08/2010 - 17:54:56 - [0] ----D C:\Program Files (x86)\Common Files\Windows Live O43 - CFD: 31/08/2010 - 17:54:12 - [8,619] ----D C:\Program Files (x86)\Common Files\Wise Installation Wizard O43 - CFD: 22/02/2013 - 15:59:55 - [28,414] ----D C:\ProgramData\Adobe O43 - CFD: 14/07/2009 - 06:08:56 - [0] --H-D C:\ProgramData\Application Data O43 - CFD: 15/09/2010 - 02:05:01 - [0,000] ----D C:\ProgramData\ATI O43 - CFD: 25/01/2013 - 19:34:18 - [36,173] ----D C:\ProgramData\AVAST Software O43 - CFD: 26/12/2011 - 09:53:16 - [0,006] ----D C:\ProgramData\Bouygues Telecom O43 - CFD: 21/12/2010 - 23:12:43 - [0] --H-D C:\ProgramData\Bureau O43 - CFD: 14/07/2009 - 06:08:56 - [0] --H-D C:\ProgramData\Desktop O43 - CFD: 14/07/2009 - 06:08:56 - [0] --H-D C:\ProgramData\Documents O43 - CFD: 21/12/2010 - 23:12:43 - [0] --H-D C:\ProgramData\Favoris O43 - CFD: 14/07/2009 - 06:08:56 - [0] --H-D C:\ProgramData\Favorites O43 - CFD: 21/01/2011 - 10:31:36 - [0,009] ----D C:\ProgramData\IsolatedStorage O43 - CFD: 05/01/2011 - 21:13:26 - [15,472] ----D C:\ProgramData\Malwarebytes O43 - CFD: 05/01/2011 - 18:52:52 - [0,014] ----D C:\ProgramData\McAfee O43 - CFD: 21/12/2010 - 23:12:43 - [0] --H-D C:\ProgramData\Menu Démarrer O43 - CFD: 10/02/2013 - 17:16:27 - [-1735,619] -S--D C:\ProgramData\Microsoft O43 - CFD: 22/02/2013 - 15:50:53 - [0,060] ----D C:\ProgramData\Microsoft Help O43 - CFD: 21/12/2010 - 23:12:43 - [0] --H-D C:\ProgramData\Modèles O43 - CFD: 23/10/2012 - 21:53:41 - [2,200] ----D C:\ProgramData\Nero O43 - CFD: 13/10/2012 - 07:27:29 - [40,198] ----D C:\ProgramData\Skype O43 - CFD: 14/07/2009 - 06:08:56 - [0] --H-D C:\ProgramData\Start Menu O43 - CFD: 31/08/2010 - 17:31:01 - [0,000] ----D C:\ProgramData\Sun O43 - CFD: 14/07/2009 - 06:08:56 - [0] --H-D C:\ProgramData\Templates O43 - CFD: 15/09/2010 - 02:24:31 - [35,715] ----D C:\ProgramData\Toshiba O43 - CFD: 21/01/2011 - 10:31:36 - [0,003] ----D C:\ProgramData\TOSHIBA Tempro O43 - CFD: 21/12/2010 - 23:13:21 - [0,002] ----D C:\ProgramData\ToshibaEurope O43 - CFD: 05/10/2011 - 08:30:08 - [0] ----D C:\ProgramData\VirtualizedApplications O43 - CFD: 15/09/2010 - 02:09:47 - [2,158] ----D C:\ProgramData\vista32 O43 - CFD: 15/09/2010 - 02:09:47 - [3,146] ----D C:\ProgramData\vista64 O43 - CFD: 24/12/2010 - 21:51:08 - [26,557] ----D C:\ProgramData\Wild Tangent O43 - CFD: 24/02/2011 - 18:23:15 - [543,354] ----D C:\ProgramData\WildTangent O43 - CFD: 15/09/2010 - 02:10:49 - [2,117] ----D C:\ProgramData\win7_32 O43 - CFD: 15/09/2010 - 02:10:49 - [3,069] ----D C:\ProgramData\win7_64 O43 - CFD: 15/09/2010 - 02:09:47 - [0,055] ----D C:\ProgramData\xp O43 - CFD: 23/02/2011 - 12:10:06 - [0,213] ----D C:\Users\coco\AppData\Roaming\Adobe O43 - CFD: 21/12/2010 - 23:22:11 - [0] ----D C:\Users\coco\AppData\Roaming\ATI O43 - CFD: 21/01/2011 - 12:21:51 - [0,002] ----D C:\Users\coco\AppData\Roaming\Bouygues Telecom O43 - CFD: 21/12/2010 - 23:21:25 - [0] ----D C:\Users\coco\AppData\Roaming\Identities O43 - CFD: 18/01/2011 - 07:58:58 - [0] ----D C:\Users\coco\AppData\Roaming\InstallShield O43 - CFD: 31/08/2010 - 17:50:24 - [614,718] ----D C:\Users\coco\AppData\Roaming\Macromedia O43 - CFD: 05/01/2011 - 21:30:52 - [2,021] ----D C:\Users\coco\AppData\Roaming\Malwarebytes O43 - CFD: 14/07/2009 - 16:35:05 - [0] ----D C:\Users\coco\AppData\Roaming\Media Center Programs O43 - CFD: 04/10/2011 - 21:48:51 - [20,392] -S--D C:\Users\coco\AppData\Roaming\Microsoft O43 - CFD: 05/08/2012 - 13:43:50 - [2,418] ----D C:\Users\coco\AppData\Roaming\Nero O43 - CFD: 11/07/2012 - 01:07:47 - [1,995] ----D C:\Users\coco\AppData\Roaming\Skype O43 - CFD: 11/07/2012 - 01:01:51 - [0,014] ----D C:\Users\coco\AppData\Roaming\skypePM O43 - CFD: 13/07/2012 - 13:23:45 - [1,414] ----D C:\Users\coco\AppData\Roaming\SoftGrid Client O43 - CFD: 20/01/2011 - 16:53:36 - [3,854] ----D C:\Users\coco\AppData\Roaming\Toshiba O43 - CFD: 24/12/2010 - 21:41:44 - [0] ----D C:\Users\coco\AppData\Roaming\TP O43 - CFD: 24/12/2010 - 21:50:03 - [0,001] ----D C:\Users\coco\AppData\Roaming\WildTangent O43 - CFD: 18/01/2011 - 07:58:43 - [0] ----D C:\Users\coco\AppData\Roaming\WinBatch O43 - CFD: 19/01/2011 - 18:18:26 - [0,000] ----D C:\Users\coco\AppData\Roaming\Windows Live Writer O43 - CFD: 18/02/2011 - 16:57:51 - [14,652] ----D C:\Users\coco\AppData\Local\Adobe O43 - CFD: 21/12/2010 - 23:12:54 - [0] ----D C:\Users\coco\AppData\Local\Application Data O43 - CFD: 02/06/2012 - 18:43:12 - [1,487] ----D C:\Users\coco\AppData\Local\Apps O43 - CFD: 21/12/2010 - 23:22:11 - [0,066] ----D C:\Users\coco\AppData\Local\ATI O43 - CFD: 20/01/2011 - 13:55:21 - [0,737] ----D C:\Users\coco\AppData\Local\Bouygues Telecom O43 - CFD: 02/06/2012 - 18:45:20 - [0] ----D C:\Users\coco\AppData\Local\Deployment O43 - CFD: 09/02/2013 - 01:01:58 - [0] ----D C:\Users\coco\AppData\Local\Diagnostics O43 - CFD: 02/10/2012 - 15:06:33 - [0] ----D C:\Users\coco\AppData\Local\ElevatedDiagnostics O43 - CFD: 25/01/2013 - 19:58:45 - [1776,310] ----D C:\Users\coco\AppData\Local\Google O43 - CFD: 21/12/2010 - 23:12:54 - [0] ----D C:\Users\coco\AppData\Local\Historique O43 - CFD: 10/02/2013 - 17:16:27 - [1558,896] ----D C:\Users\coco\AppData\Local\Microsoft O43 - CFD: 26/12/2011 - 00:12:12 - [0,237] ----D C:\Users\coco\AppData\Local\Microsoft Games O43 - CFD: 05/10/2011 - 13:08:56 - [0,149] ----D C:\Users\coco\AppData\Local\Microsoft Help O43 - CFD: 04/10/2012 - 15:53:57 - [0,169] ----D C:\Users\coco\AppData\Local\MigWiz O43 - CFD: 05/08/2012 - 13:52:50 - [0,001] ----D C:\Users\coco\AppData\Local\Nero_AG O43 - CFD: 09/02/2013 - 11:51:54 - [0] ----D C:\Users\coco\AppData\Local\Programs O43 - CFD: 24/12/2010 - 21:41:35 - [0,723] ----D C:\Users\coco\AppData\Local\SoftGrid Client O43 - CFD: 23/02/2013 - 20:26:22 - [722,277] ----D C:\Users\coco\AppData\Local\Temp O43 - CFD: 21/12/2010 - 23:12:54 - [0] ----D C:\Users\coco\AppData\Local\Temporary Internet Files O43 - CFD: 24/12/2010 - 18:41:53 - [0,001] ----D C:\Users\coco\AppData\Local\Toshiba O43 - CFD: 21/12/2010 - 23:36:24 - [0,001] ----D C:\Users\coco\AppData\Local\TOSHIBA_Corporation O43 - CFD: 23/02/2011 - 12:11:57 - [10,131] ----D C:\Users\coco\AppData\Local\VirtualStore O43 - CFD: 23/10/2012 - 12:40:38 - [0,082] ----D C:\Users\coco\AppData\Local\Windows Live O43 - CFD: 19/01/2011 - 18:17:58 - [0,618] ----D C:\Users\coco\AppData\Local\Windows Live Writer O43 - CFD: 01/12/2012 - 09:33:28 - [0] ----D C:\Users\coco\AppData\Local\{00665E2F-E4B3-42D9-BB84-AC8AD2A204F1} O43 - CFD: 05/01/2011 - 18:21:47 - [0] ----D C:\Users\coco\AppData\Local\{02D41F8B-072A-4122-B13F-A3A1D43D5807} O43 - CFD: 24/07/2012 - 20:40:27 - [0] ----D C:\Users\coco\AppData\Local\{03666ECE-F1F6-499D-A690-C8D135957F43} O43 - CFD: 18/12/2011 - 20:04:53 - [0] ----D C:\Users\coco\AppData\Local\{05965270-5A88-4B3A-82AC-8878CC9793C2} O43 - CFD: 27/07/2012 - 16:59:55 - [0] ----D C:\Users\coco\AppData\Local\{05C105F1-51E2-4670-A07F-B5D9429DFC45} O43 - CFD: 21/01/2011 - 10:48:14 - [0] ----D C:\Users\coco\AppData\Local\{064FB3CE-763D-4365-8838-82C11C43B00F} O43 - CFD: 23/12/2010 - 21:24:27 - [0] ----D C:\Users\coco\AppData\Local\{06CFD808-F87D-4AF3-986F-6FF44269E547} O43 - CFD: 18/07/2012 - 09:59:52 - [0] ----D C:\Users\coco\AppData\Local\{06E42B79-BAF0-4BA5-BF75-F08AAF7C600E} O43 - CFD: 31/01/2012 - 07:28:28 - [0] ----D C:\Users\coco\AppData\Local\{07B36860-E3D7-4FDA-BDDB-E5989050D0C7} O43 - CFD: 05/10/2011 - 08:09:25 - [0] ----D C:\Users\coco\AppData\Local\{0895B0AC-13CB-42C7-918B-F647223524A9} O43 - CFD: 12/02/2012 - 21:14:13 - [0] ----D C:\Users\coco\AppData\Local\{08E0EF70-77C1-4134-885B-1166F019BED2} O43 - CFD: 26/07/2012 - 23:47:44 - [0] ----D C:\Users\coco\AppData\Local\{095D03E4-05DC-4A52-92FD-9239F8226343} O43 - CFD: 18/12/2011 - 20:05:26 - [0] ----D C:\Users\coco\AppData\Local\{09B04F7D-6A7B-4344-9AE9-A730686D1F45} O43 - CFD: 24/12/2010 - 11:23:51 - [0] ----D C:\Users\coco\AppData\Local\{0B8DC771-A175-4ECE-A15C-BC301AE5AF93} O43 - CFD: 20/07/2012 - 10:04:48 - [0] ----D C:\Users\coco\AppData\Local\{0CD38180-FE8B-4388-95B4-6A2BD7338BF2} O43 - CFD: 11/12/2011 - 23:29:45 - [0] ----D C:\Users\coco\AppData\Local\{0D07EDE6-CA17-41E2-A952-D67921CD3675} O43 - CFD: 06/08/2012 - 08:27:30 - [0] ----D C:\Users\coco\AppData\Local\{0F57CC72-8F52-4578-97C8-37F797305221} O43 - CFD: 14/10/2012 - 07:51:46 - [0] ----D C:\Users\coco\AppData\Local\{0FA69271-9305-4713-AA86-4198D8A243DB} O43 - CFD: 15/08/2012 - 09:00:50 - [0] ----D C:\Users\coco\AppData\Local\{149A8FAA-ADDF-4491-842C-81A7482970F5} O43 - CFD: 26/01/2013 - 18:11:40 - [0] ----D C:\Users\coco\AppData\Local\{1571E4EE-79BD-44D4-9177-C2091B4B8634} O43 - CFD: 27/01/2013 - 10:46:30 - [0] ----D C:\Users\coco\AppData\Local\{1693D7F5-9397-478E-AAB7-C2CA34B8AF25} O43 - CFD: 19/10/2011 - 10:12:25 - [0] ----D C:\Users\coco\AppData\Local\{17FEBAF9-4726-4EE9-8B7D-27F70EB4064C} O43 - CFD: 25/07/2012 - 22:26:31 - [0] ----D C:\Users\coco\AppData\Local\{18C1A19A-B4B3-4C4C-8B43-1894E0DB340F} O43 - CFD: 12/07/2012 - 20:00:29 - [0] ----D C:\Users\coco\AppData\Local\{18DB8321-08B7-4AF1-8427-F57DBDCBA4FC} O43 - CFD: 18/01/2011 - 20:51:38 - [0] ----D C:\Users\coco\AppData\Local\{1A593A58-17A4-47AA-80D1-5BD5EA06F76A} O43 - CFD: 30/01/2012 - 22:50:23 - [0] ----D C:\Users\coco\AppData\Local\{1B4104A7-381B-474B-BEEF-CE56FCD56BB8} O43 - CFD: 20/11/2011 - 11:37:05 - [0] ----D C:\Users\coco\AppData\Local\{1BD55B76-D053-4DED-B3C2-F66F579EA055} O43 - CFD: 12/10/2012 - 11:31:32 - [0] ----D C:\Users\coco\AppData\Local\{1D3D32FA-D9DA-40BC-95B4-868EAE06F5D3} O43 - CFD: 05/12/2012 - 09:46:25 - [0] ----D C:\Users\coco\AppData\Local\{1DB3E5E7-5042-42BC-9EC0-99CF04D9A8EA} O43 - CFD: 13/01/2011 - 22:09:25 - [0] ----D C:\Users\coco\AppData\Local\{1F1326FF-ECE0-4884-AF0B-C10729CB6887} O43 - CFD: 22/02/2011 - 00:20:53 - [0] ----D C:\Users\coco\AppData\Local\{20C22260-3421-49CA-AE88-E4ED57280298} O43 - CFD: 11/08/2012 - 18:06:31 - [0] ----D C:\Users\coco\AppData\Local\{20D8EDB4-2BA7-42C4-A6A6-757092706ABC} O43 - CFD: 20/08/2012 - 17:45:05 - [0] ----D C:\Users\coco\AppData\Local\{21E4518E-7BF1-4806-A8E4-E95E88F0364B} O43 - CFD: 14/10/2012 - 19:52:20 - [0] ----D C:\Users\coco\AppData\Local\{258DE0EB-3BF9-4B3E-8F19-2F978774371D} O43 - CFD: 01/12/2012 - 21:34:22 - [0] ----D C:\Users\coco\AppData\Local\{26B1E72A-2CA6-4DAE-BFC1-31E871471FC1} O43 - CFD: 27/07/2012 - 16:59:37 - [0] ----D C:\Users\coco\AppData\Local\{2714374D-3F33-4428-92E8-93A20790E2CA} O43 - CFD: 04/08/2012 - 18:52:30 - [0] ----D C:\Users\coco\AppData\Local\{27FE92C2-8CD1-4E68-929D-FC40CAABB3F4} O43 - CFD: 08/04/2012 - 17:29:24 - [0] ----D C:\Users\coco\AppData\Local\{286B780F-C61E-468B-BE42-CC0851F9F57A} O43 - CFD: 28/10/2012 - 14:22:18 - [0] ----D C:\Users\coco\AppData\Local\{28988432-00D2-486F-9893-DBA8523A2AD7} O43 - CFD: 04/12/2012 - 21:43:44 - [0] ----D C:\Users\coco\AppData\Local\{297597F1-50DD-4EC7-B584-8F02BCC23F4F} O43 - CFD: 09/02/2013 - 10:20:03 - [0] ----D C:\Users\coco\AppData\Local\{2A6812DB-96F1-4D4C-BCA4-E0E97D4B6B69} O43 - CFD: 20/11/2011 - 13:17:48 - [0] ----D C:\Users\coco\AppData\Local\{2B0C5F99-6E0B-4328-A0FD-E38842735066} O43 - CFD: 12/02/2012 - 21:13:48 - [0] ----D C:\Users\coco\AppData\Local\{2BD27DE8-A8FE-4D7D-9E58-D21C2B038014} O43 - CFD: 10/02/2013 - 22:21:13 - [0] ----D C:\Users\coco\AppData\Local\{2EBD6990-A2D0-4073-A610-A2A4446DA414} O43 - CFD: 30/11/2012 - 09:32:25 - [0] ----D C:\Users\coco\AppData\Local\{2EBF9754-DE45-4E95-A5E4-979B39E88C9A} O43 - CFD: 02/12/2012 - 09:35:12 - [0] ----D C:\Users\coco\AppData\Local\{30A1E89A-D325-4069-A286-164EC39EAE45} O43 - CFD: 10/06/2011 - 23:11:06 - [0] ----D C:\Users\coco\AppData\Local\{3665747A-F7AD-4AC0-A0C0-C02D9011B473} O43 - CFD: 27/12/2011 - 01:22:15 - [0] ----D C:\Users\coco\AppData\Local\{369D792A-68CE-4516-8393-D37B0ADDD4BF} O43 - CFD: 16/07/2011 - 14:24:21 - [0] ----D C:\Users\coco\AppData\Local\{36ADCBA0-5B84-4F11-8960-70D014DCF115} O43 - CFD: 07/08/2012 - 20:32:17 - [0] ----D C:\Users\coco\AppData\Local\{370B209E-4385-49EF-BA2A-6CC84B037C91} O43 - CFD: 12/09/2012 - 15:01:12 - [0] ----D C:\Users\coco\AppData\Local\{37C4495F-0610-4FA3-8726-1A4105DAFB94} O43 - CFD: 17/01/2011 - 20:29:55 - [0] ----D C:\Users\coco\AppData\Local\{384E7A71-6FC3-48CE-98AC-842E1020AC06} O43 - CFD: 22/02/2013 - 15:33:44 - [0] ----D C:\Users\coco\AppData\Local\{39A732FD-A936-43AE-BC35-87A09C8C80BC} O43 - CFD: 03/08/2012 - 16:16:19 - [0] ----D C:\Users\coco\AppData\Local\{3BFFEC47-1687-45B8-8827-EDAA3E9AFC61} O43 - CFD: 26/07/2011 - 15:28:01 - [0] ----D C:\Users\coco\AppData\Local\{3DA6EAE1-7653-45BA-A2E4-CBAA67A1817F} O43 - CFD: 06/06/2011 - 17:48:38 - [0] ----D C:\Users\coco\AppData\Local\{3E5A43B5-58B3-4800-97F4-BCED73CDC47F} O43 - CFD: 26/12/2011 - 09:50:33 - [0] ----D C:\Users\coco\AppData\Local\{3E718F5D-D4C5-4B28-926F-A6204D434D49} O43 - CFD: 12/11/2011 - 20:21:38 - [0] ----D C:\Users\coco\AppData\Local\{3F3F9A40-0409-4E44-B820-B38CC1F9E978} O43 - CFD: 08/08/2012 - 08:33:01 - [0] ----D C:\Users\coco\AppData\Local\{3FF4A037-2453-4A6F-B585-C542521618BB} O43 - CFD: 04/08/2012 - 06:50:42 - [0] ----D C:\Users\coco\AppData\Local\{4027C639-03CA-44D5-869F-F15B1181567C} O43 - CFD: 19/10/2011 - 22:20:06 - [0] ----D C:\Users\coco\AppData\Local\{406006E5-19D1-45B2-8219-DCBEA81674DA} O43 - CFD: 22/01/2011 - 09:56:04 - [0] ----D C:\Users\coco\AppData\Local\{4106CA37-3907-48AE-A66A-D65050B97807} O43 - CFD: 20/01/2011 - 08:08:13 - [0] ----D C:\Users\coco\AppData\Local\{410F691C-AE97-445E-9936-DC986897C280} O43 - CFD: 29/11/2012 - 21:30:32 - [0] ----D C:\Users\coco\AppData\Local\{41991EC6-7E84-4C81-933C-B8CB0E06168A} O43 - CFD: 26/02/2012 - 15:27:22 - [0] ----D C:\Users\coco\AppData\Local\{42ECC704-1AA9-420B-A54F-6EAFACC6A677} O43 - CFD: 19/07/2012 - 10:01:22 - [0] ----D C:\Users\coco\AppData\Local\{444C35BF-49A5-44F3-8DC9-48452F27E142} O43 - CFD: 19/01/2011 - 15:13:38 - [0] ----D C:\Users\coco\AppData\Local\{44ED80A0-E4BF-4A53-AEA4-38FC26D6E37C} O43 - CFD: 07/06/2011 - 17:36:54 - [0] ----D C:\Users\coco\AppData\Local\{451ED180-C760-4DE0-857D-ECA323C10349} O43 - CFD: 03/03/2011 - 09:14:51 - [0] ----D C:\Users\coco\AppData\Local\{452AAFA7-84FD-4C0C-B8AB-EC70635CC244} O43 - CFD: 01/10/2011 - 13:17:31 - [0] ----D C:\Users\coco\AppData\Local\{45C68B35-8A7C-4C30-9710-1C95B9C6D39A} O43 - CFD: 24/10/2012 - 18:51:35 - [0] ----D C:\Users\coco\AppData\Local\{463CBAAD-8D7B-4010-86A5-0E8DBCD24511} O43 - CFD: 27/12/2011 - 10:06:42 - [0] ----D C:\Users\coco\AppData\Local\{4957CAF9-5574-460A-8275-5E4992941B5E} O43 - CFD: 18/02/2011 - 13:36:15 - [0] ----D C:\Users\coco\AppData\Local\{49C59680-574D-4D51-B37B-6C8339DB50A2} O43 - CFD: 31/01/2012 - 07:28:00 - [0] ----D C:\Users\coco\AppData\Local\{4A7906B1-591C-4AA9-8E20-8E8D0C393E07} O43 - CFD: 13/06/2012 - 16:35:03 - [0] ----D C:\Users\coco\AppData\Local\{4AAF5856-74A6-4B1F-96FA-5FFBD264679C} O43 - CFD: 25/12/2011 - 23:19:58 - [0] ----D C:\Users\coco\AppData\Local\{4ABB881A-A52A-4E47-81D0-BA377C674A46} O43 - CFD: 26/02/2012 - 16:05:42 - [0] ----D C:\Users\coco\AppData\Local\{4ABC3F14-0EBC-4982-9EA1-527A7A39E162} O43 - CFD: 05/10/2011 - 15:40:28 - [0] ----D C:\Users\coco\AppData\Local\{4BD9B7FF-3282-40A4-93B9-3C6118197014} O43 - CFD: 19/02/2012 - 13:49:46 - [0] ----D C:\Users\coco\AppData\Local\{4D02FFEC-65F5-4985-A8DA-644CD6C9C34D} O43 - CFD: 10/07/2012 - 23:55:16 - [0] ----D C:\Users\coco\AppData\Local\{4DD81843-49D0-4582-BD69-179CBB72669C} O43 - CFD: 05/01/2011 - 18:21:36 - [0] ----D C:\Users\coco\AppData\Local\{4E8C3D86-FFB0-4DFB-BEAB-8FFDD941B421} O43 - CFD: 21/07/2012 - 10:08:20 - [0] ----D C:\Users\coco\AppData\Local\{4ED8148D-EC88-4835-A511-8D89100F527D} O43 - CFD: 25/12/2011 - 23:42:03 - [0] ----D C:\Users\coco\AppData\Local\{4ED8A375-F320-4B71-A389-15DAEAFAA46E} O43 - CFD: 27/12/2011 - 09:28:27 - [0] ----D C:\Users\coco\AppData\Local\{4F908E65-46E2-4A67-987C-4BA421B8EF6A} O43 - CFD: 03/12/2012 - 21:41:36 - [0] ----D C:\Users\coco\AppData\Local\{5059AAC5-A84A-4E7D-A0D2-FCF6C83B0950} O43 - CFD: 13/06/2011 - 01:30:11 - [0] ----D C:\Users\coco\AppData\Local\{50E90BBB-54C0-467F-8C4B-AC69C80A41D4} O43 - CFD: 17/01/2011 - 20:43:07 - [0] ----D C:\Users\coco\AppData\Local\{5111FB53-CCB6-4C6E-AFED-1394D63EA954} O43 - CFD: 24/12/2010 - 21:18:02 - [0] ----D C:\Users\coco\AppData\Local\{52234450-B255-436E-9305-8F9E08393EBE} O43 - CFD: 21/02/2011 - 23:39:44 - [0] ----D C:\Users\coco\AppData\Local\{527879FD-6513-4917-B6C9-B8015C707995} O43 - CFD: 21/02/2011 - 18:14:52 - [0] ----D C:\Users\coco\AppData\Local\{52A9DD91-0E7F-49AB-9B8E-5283E44A8040} O43 - CFD: 31/10/2011 - 00:01:42 - [0] ----D C:\Users\coco\AppData\Local\{542FF929-2BA2-4526-8C01-517D431CAE68} O43 - CFD: 04/12/2012 - 09:43:09 - [0] ----D C:\Users\coco\AppData\Local\{543D987B-B9D4-4970-82E6-08FF98DBF3F6} O43 - CFD: 20/11/2011 - 11:37:32 - [0] ----D C:\Users\coco\AppData\Local\{550F66EF-7C5E-4F66-A7D5-BBDF2D077C17} O43 - CFD: 02/06/2012 - 13:43:46 - [0] ----D C:\Users\coco\AppData\Local\{585AE7E0-2BDD-4F5E-B3E7-AA76EFA8B9B3} O43 - CFD: 24/10/2012 - 06:49:34 - [0] ----D C:\Users\coco\AppData\Local\{5A3103D2-BBC8-44B1-9F82-D6AE47658D19} O43 - CFD: 06/10/2011 - 10:55:54 - [0] ----D C:\Users\coco\AppData\Local\{5A5F4B3E-DE73-4B71-8E5D-B72C0F871599} O43 - CFD: 18/10/2011 - 09:12:26 - [0] ----D C:\Users\coco\AppData\Local\{5BF66CE4-D99D-447A-9544-E1DB7554BC44} O43 - CFD: 23/10/2012 - 17:42:23 - [0] ----D C:\Users\coco\AppData\Local\{5C97D66A-B526-4EAA-8839-D17E70FFA129} O43 - CFD: 12/11/2011 - 20:43:36 - [0] ----D C:\Users\coco\AppData\Local\{5D1DE0C2-384D-44E9-8320-9D0E567096FC} O43 - CFD: 15/08/2012 - 18:01:16 - [0] ----D C:\Users\coco\AppData\Local\{5E01BEDF-479E-47BA-85B5-CC8A32C48577} O43 - CFD: 06/08/2012 - 20:30:43 - [0] ----D C:\Users\coco\AppData\Local\{5FA70BFE-7BC8-4408-9534-F962DCE97387} O43 - CFD: 07/08/2012 - 08:31:18 - [0] ----D C:\Users\coco\AppData\Local\{6019FB6E-51A9-49B1-9A44-C9CD1002AF9E} O43 - CFD: 20/07/2012 - 10:04:28 - [0] ----D C:\Users\coco\AppData\Local\{60B64A36-CAFA-4661-8C3C-B114B8DED425} O43 - CFD: 21/02/2011 - 23:26:41 - [0] ----D C:\Users\coco\AppData\Local\{61AB918D-ABDC-42D8-B574-BA47A3C3C2CE} O43 - CFD: 13/07/2012 - 08:53:18 - [0] ----D C:\Users\coco\AppData\Local\{62736B7A-7E68-4161-9605-9CD7F2DB97C8} O43 - CFD: 19/10/2012 - 09:08:44 - [0] ----D C:\Users\coco\AppData\Local\{664641F3-A4CC-4DC5-A7AB-1F710DE03D41} O43 - CFD: 25/03/2012 - 22:47:40 - [0] ----D C:\Users\coco\AppData\Local\{67576601-74CD-45FF-A14D-59355CB0B575} O43 - CFD: 09/08/2012 - 18:23:19 - [0] ----D C:\Users\coco\AppData\Local\{67934D3F-1C8F-4BB7-88C1-E2E9B9A950C9} O43 - CFD: 25/12/2010 - 10:58:25 - [0] ----D C:\Users\coco\AppData\Local\{683AC7A2-33E5-4447-9694-D4CD7F54BDAF} O43 - CFD: 12/07/2012 - 20:00:16 - [0] ----D C:\Users\coco\AppData\Local\{6867FF24-9505-4436-8786-92721CE4E121} O43 - CFD: 22/01/2011 - 10:15:50 - [0] ----D C:\Users\coco\AppData\Local\{687BA6AF-80ED-47F0-9F1D-CD8A4F88BDC3} O43 - CFD: 05/08/2012 - 20:24:41 - [0] ----D C:\Users\coco\AppData\Local\{6947D1AA-A6DA-4191-930A-A5348204EDEE} O43 - CFD: 23/02/2013 - 17:32:20 - [0] ----D C:\Users\coco\AppData\Local\{6A01DCDA-A757-4D5F-9AFD-0C89385D0404} O43 - CFD: 02/09/2011 - 09:08:44 - [0] ----D C:\Users\coco\AppData\Local\{6A3514C5-DA6E-4498-B8DE-BB1432861A8C} O43 - CFD: 21/01/2011 - 10:30:29 - [0] ----D C:\Users\coco\AppData\Local\{6DC631A8-AF87-41AB-AB03-CEE67EB73E2E} O43 - CFD: 17/10/2012 - 13:23:31 - [0] ----D C:\Users\coco\AppData\Local\{6E0B67AC-0BBA-4866-BC0A-95159E18F702} O43 - CFD: 22/11/2012 - 10:59:00 - [0] ----D C:\Users\coco\AppData\Local\{6E3B4D40-E157-48AC-BCF9-4CCB89364F19} O43 - CFD: 06/08/2012 - 20:30:31 - [0] ----D C:\Users\coco\AppData\Local\{6F3D1858-EC4C-4C78-A453-1C0BAFC3C53A} O43 - CFD: 03/10/2011 - 19:27:39 - [0] ----D C:\Users\coco\AppData\Local\{70770212-6F22-4007-B3A8-1D9AA78BC6D9} O43 - CFD: 19/02/2012 - 14:00:18 - [0] ----D C:\Users\coco\AppData\Local\{70AABDDB-D81D-4D1C-B999-323EA06226E0} O43 - CFD: 21/02/2011 - 19:14:30 - [0] ----D C:\Users\coco\AppData\Local\{71520E0B-7415-41F4-A9B2-48BB784DD703} O43 - CFD: 17/10/2011 - 17:11:32 - [0] ----D C:\Users\coco\AppData\Local\{71DA8166-41CE-48CE-8E51-D4C1692F4709} O43 - CFD: 22/02/2011 - 11:25:00 - [0] ----D C:\Users\coco\AppData\Local\{71EABF66-16E4-47CA-846D-C7C4159A4F89} O43 - CFD: 07/08/2012 - 20:32:06 - [0] ----D C:\Users\coco\AppData\Local\{72148477-5748-4D56-9111-9003E1B25E38} O43 - CFD: 18/10/2011 - 09:13:01 - [0] ----D C:\Users\coco\AppData\Local\{73CA76EE-C129-4FF7-8EB7-52D4AC3D04AB} O43 - CFD: 13/06/2012 - 23:09:37 - [0] ----D C:\Users\coco\AppData\Local\{743DBB77-C871-4152-B5A5-EEFE2F4EB953} O43 - CFD: 20/01/2011 - 22:51:07 - [0] ----D C:\Users\coco\AppData\Local\{74430D5A-20E4-4400-BFEF-D55F68B31879} O43 - CFD: 18/10/2011 - 07:20:46 - [0] ----D C:\Users\coco\AppData\Local\{748422D0-401C-43C6-AEB5-2C6EDFEE1CDF} O43 - CFD: 20/10/2011 - 09:10:17 - [0] ----D C:\Users\coco\AppData\Local\{7701AEDA-D467-4699-AA43-8BBEF7A10DE7} O43 - CFD: 17/10/2011 - 22:26:41 - [0] ----D C:\Users\coco\AppData\Local\{78612DF3-1414-40F8-BDC1-864307DCC039} O43 - CFD: 20/11/2011 - 13:18:16 - [0] ----D C:\Users\coco\AppData\Local\{79EA5554-BDD2-49D3-B676-D11DD02B2B77} O43 - CFD: 27/12/2010 - 23:11:13 - [0] ----D C:\Users\coco\AppData\Local\{7BA9C294-75D6-42A6-8799-BF24D047A958} O43 - CFD: 25/10/2012 - 18:53:25 - [0] ----D C:\Users\coco\AppData\Local\{7DE14EA0-E906-4FF9-BFBD-481E9ABBCA86} O43 - CFD: 07/08/2012 - 08:31:33 - [0] ----D C:\Users\coco\AppData\Local\{7EF8F454-7639-462D-954D-1FD00876A4C6} O43 - CFD: 05/06/2012 - 17:43:36 - [0] ----D C:\Users\coco\AppData\Local\{803ED3BE-0112-4F16-BCED-17805BA59CD1} O43 - CFD: 19/10/2012 - 21:09:04 - [0] ----D C:\Users\coco\AppData\Local\{8154AB33-C417-461F-B0EB-0CF8B698D70F} O43 - CFD: 09/02/2013 - 22:20:37 - [0] ----D C:\Users\coco\AppData\Local\{8170E2B2-1C47-4595-8C5F-CEF335D59BB9} O43 - CFD: 24/02/2011 - 17:43:03 - [0] ----D C:\Users\coco\AppData\Local\{8301D436-BF24-427C-94F2-A5D58757E673} O43 - CFD: 02/10/2012 - 11:19:18 - [0] ----D C:\Users\coco\AppData\Local\{8406671D-4B2F-42EE-9A5A-F846191D0DDC} O43 - CFD: 29/01/2013 - 10:22:49 - [0] ----D C:\Users\coco\AppData\Local\{84E7382F-4837-4EAE-A5BD-22DE595FDA7B} O43 - CFD: 12/06/2011 - 00:40:44 - [0] ----D C:\Users\coco\AppData\Local\{850794AF-5395-4232-972B-E0BB43F9DB5D} O43 - CFD: 04/10/2011 - 17:58:12 - [0] ----D C:\Users\coco\AppData\Local\{86F3F915-28D4-4079-B5E5-BC4C65A2A06E} O43 - CFD: 22/12/2010 - 22:54:54 - [0] ----D C:\Users\coco\AppData\Local\{87BD060C-7C20-4400-AC21-94CE706E708E} O43 - CFD: 07/05/2012 - 12:31:05 - [0] ----D C:\Users\coco\AppData\Local\{87F8DCC3-F491-47C8-B93B-1FA826C7CB66} O43 - CFD: 18/01/2011 - 08:43:32 - [0] ----D C:\Users\coco\AppData\Local\{8AC17C67-8DBA-488C-9A95-B78553243E8C} O43 - CFD: 29/01/2013 - 11:26:59 - [0] ----D C:\Users\coco\AppData\Local\{8B4563CC-20B9-4754-9837-E38FF354C38E} O43 - CFD: 19/02/2012 - 14:00:47 - [0] ----D C:\Users\coco\AppData\Local\{8B8992C9-55E2-4ED6-9F59-EF1BB1AB9381} O43 - CFD: 21/07/2012 - 10:09:30 - [0] ----D C:\Users\coco\AppData\Local\{8B8E556B-45D3-45EE-9DD6-BE480424A16F} O43 - CFD: 06/12/2012 - 12:07:40 - [0] ----D C:\Users\coco\AppData\Local\{8C92FB3B-249B-4410-B844-3AEB726523F1} O43 - CFD: 19/10/2011 - 08:54:45 - [0] ----D C:\Users\coco\AppData\Local\{8DB23CC4-FF96-4706-BFED-A2D15DB135C8} O43 - CFD: 16/10/2012 - 23:27:57 - [0] ----D C:\Users\coco\AppData\Local\{8E6E8833-354D-4738-A802-7D1DAD41D294} O43 - CFD: 06/12/2012 - 00:07:04 - [0] ----D C:\Users\coco\AppData\Local\{900A2893-9322-45D4-BAB5-A76E6A1335B2} O43 - CFD: 14/07/2012 - 07:13:30 - [0] ----D C:\Users\coco\AppData\Local\{914AC4C3-5B8A-4D8F-BE4D-825EF46EBB8A} O43 - CFD: 17/07/2011 - 00:16:54 - [0] ----D C:\Users\coco\AppData\Local\{941202C2-2760-49E4-9410-27EFEDA674EC} O43 - CFD: 19/10/2011 - 06:59:45 - [0] ----D C:\Users\coco\AppData\Local\{943954E4-89AE-438B-9D0F-FE1EF042675C} O43 - CFD: 09/04/2012 - 08:29:57 - [0] ----D C:\Users\coco\AppData\Local\{9476085C-53D9-4DBA-B24D-C8E20AEDBB74} O43 - CFD: 18/07/2012 - 22:00:37 - [0] ----D C:\Users\coco\AppData\Local\{949B960D-4A0D-4353-B30A-B95ED9A8F873} O43 - CFD: 20/07/2012 - 22:06:08 - [0] ----D C:\Users\coco\AppData\Local\{96110EED-8832-4C20-9A0D-35C8B9568011} O43 - CFD: 12/06/2011 - 12:41:16 - [0] ----D C:\Users\coco\AppData\Local\{964BF15E-0595-4364-ADBD-049057DB03CA} O43 - CFD: 13/10/2012 - 07:08:06 - [0] ----D C:\Users\coco\AppData\Local\{97033614-7917-4204-9052-2CC658F511E8} O43 - CFD: 11/11/2011 - 23:13:22 - [0] ----D C:\Users\coco\AppData\Local\{971A0E2D-335E-413F-AB50-9E542A5A6E19} O43 - CFD: 24/08/2011 - 14:44:34 - [0] ----D C:\Users\coco\AppData\Local\{9782A986-410D-49BB-845D-B6443D5A0E06} O43 - CFD: 03/06/2012 - 09:01:35 - [0] ----D C:\Users\coco\AppData\Local\{980F251D-5EDD-4F64-9073-17D290312A8D} O43 - CFD: 24/12/2012 - 16:01:25 - [0] ----D C:\Users\coco\AppData\Local\{991C476A-794A-4811-908C-00658E74423E} O43 - CFD: 05/06/2012 - 17:42:55 - [0] ----D C:\Users\coco\AppData\Local\{992404AF-42BE-48D9-B0D2-DC3A10B2339C} O43 - CFD: 05/10/2011 - 08:09:40 - [0] ----D C:\Users\coco\AppData\Local\{99612931-6BDF-4879-BA74-14955D269CC6} O43 - CFD: 23/04/2011 - 19:35:04 - [0] ----D C:\Users\coco\AppData\Local\{9969F110-5443-4E80-86F3-0BE9F90539A3} O43 - CFD: 11/07/2012 - 23:20:14 - [0] ----D C:\Users\coco\AppData\Local\{9BECB97E-12E6-4BCF-857B-D07572785873} O43 - CFD: 23/02/2011 - 10:50:35 - [0] ----D C:\Users\coco\AppData\Local\{9F0A3E97-FD2C-4DFF-AEFE-2C1BAD24C54F} O43 - CFD: 04/06/2011 - 19:34:28 - [0] ----D C:\Users\coco\AppData\Local\{9F3B5C5F-97D4-4AD6-A3A9-4D19BDA66DBE} O43 - CFD: 26/12/2011 - 22:00:41 - [0] ----D C:\Users\coco\AppData\Local\{A1953FEA-B2AB-45C6-A3F9-EB939640032E} O43 - CFD: 28/11/2012 - 14:31:26 - [0] ----D C:\Users\coco\AppData\Local\{A23FF8EB-56D6-44B0-A86F-D1027407DC75} O43 - CFD: 26/07/2012 - 23:47:59 - [0] ----D C:\Users\coco\AppData\Local\{A244DC42-A6A1-44C4-9F88-15C0EF4E98E4} O43 - CFD: 21/01/2011 - 10:21:07 - [0] ----D C:\Users\coco\AppData\Local\{A2B19E95-AC70-448E-A2A2-364C17B3DAEB} O43 - CFD: 12/06/2012 - 13:26:36 - [0] ----D C:\Users\coco\AppData\Local\{A30F55E0-8B1F-4A80-833C-E2F30688987B} O43 - CFD: 20/01/2011 - 20:08:27 - [0] ----D C:\Users\coco\AppData\Local\{A3AA3A2C-938C-4A30-830D-5181CBEFA786} O43 - CFD: 29/03/2012 - 06:33:50 - [0] ----D C:\Users\coco\AppData\Local\{A4DD5D32-84E3-432A-9A93-9886A1F577DA} O43 - CFD: 02/09/2011 - 09:08:23 - [0] ----D C:\Users\coco\AppData\Local\{A4E19E33-C090-439C-ADEA-260CA84B8970} O43 - CFD: 22/01/2011 - 10:05:31 - [0] ----D C:\Users\coco\AppData\Local\{A5CB41BF-03E8-40BC-AB76-F947CE69CB1A} O43 - CFD: 25/01/2013 - 18:52:47 - [0] ----D C:\Users\coco\AppData\Local\{A5EFF85C-954A-49EF-BD63-88C5B8C29329} O43 - CFD: 26/01/2013 - 09:02:32 - [0] ----D C:\Users\coco\AppData\Local\{A69340B1-9D77-4B7E-89E0-B7C1895FE089} O43 - CFD: 13/10/2012 - 19:08:59 - [0] ----D C:\Users\coco\AppData\Local\{A7A7E935-C299-47DD-BA2D-BA4D3AA1F641} O43 - CFD: 17/10/2011 - 22:26:53 - [0] ----D C:\Users\coco\AppData\Local\{A97FA968-48C2-4D0E-A454-6FCCE8DE326A} O43 - CFD: 20/10/2011 - 07:20:19 - [0] ----D C:\Users\coco\AppData\Local\{AA7EB689-3EFC-40F4-8881-F13DB5CBBC2D} O43 - CFD: 21/10/2012 - 17:47:31 - [0] ----D C:\Users\coco\AppData\Local\{ABEDE48E-1068-4DA1-9DE8-2E0B4B320FA2} O43 - CFD: 01/10/2011 - 13:17:05 - [0] ----D C:\Users\coco\AppData\Local\{ACC32215-7A08-4618-B5B5-1CC82C27DA28} O43 - CFD: 12/02/2012 - 15:30:53 - [0] ----D C:\Users\coco\AppData\Local\{AE4C5EFD-354C-45C6-B768-D06038E0B3BC} O43 - CFD: 21/02/2011 - 19:13:44 - [0] ----D C:\Users\coco\AppData\Local\{AFEB2FD1-47DE-4996-A88E-B833CBD9293D} O43 - CFD: 05/08/2012 - 20:24:53 - [0] ----D C:\Users\coco\AppData\Local\{B0C037EA-EC0E-4990-84E8-8C2993E1F375} O43 - CFD: 12/02/2012 - 15:30:19 - [0] ----D C:\Users\coco\AppData\Local\{B20F8053-F4E3-4213-A9F7-5D8F6B54A51F} O43 - CFD: 23/08/2012 - 21:33:57 - [0] ----D C:\Users\coco\AppData\Local\{B211AD0A-EBF5-4AFC-A1FE-AB29B2848D34} O43 - CFD: 15/10/2012 - 22:12:01 - [0] ----D C:\Users\coco\AppData\Local\{B23E2D10-0DC1-44E9-9C6D-DEE7E7118B15} O43 - CFD: 14/08/2012 - 22:00:08 - [0] ----D C:\Users\coco\AppData\Local\{B2A2AF50-2D06-4C68-AE21-4B0BC14815B4} O43 - CFD: 13/08/2011 - 21:34:14 - [0] ----D C:\Users\coco\AppData\Local\{B2F7CD0F-99CF-40D3-92A2-DD1E1F8E62B6} O43 - CFD: 03/08/2012 - 16:15:31 - [0] ----D C:\Users\coco\AppData\Local\{B53970C2-27E9-404D-BEDE-392B2F3719ED} O43 - CFD: 25/07/2012 - 22:26:48 - [0] ----D C:\Users\coco\AppData\Local\{B585CEFA-9092-43FA-BE91-1D9D38B0C9A2} O43 - CFD: 04/08/2012 - 06:50:21 - [0] ----D C:\Users\coco\AppData\Local\{B678A8B6-213B-4DF5-980C-F28696AA7E64} O43 - CFD: 27/12/2011 - 09:28:49 - [0] ----D C:\Users\coco\AppData\Local\{B6814DB6-424A-4EC3-92B1-A38841DFD182} O43 - CFD: 25/05/2012 - 07:24:27 - [0] ----D C:\Users\coco\AppData\Local\{B6818087-784C-4890-9522-DE2766C2C6A4} O43 - CFD: 18/07/2012 - 22:00:26 - [0] ----D C:\Users\coco\AppData\Local\{B7CCF85D-3D43-4346-9F27-1F7072F72450} O43 - CFD: 25/07/2012 - 10:25:46 - [0] ----D C:\Users\coco\AppData\Local\{B7E6E765-60B9-4A0B-A6A2-E35901533C2B} O43 - CFD: 10/07/2012 - 15:56:37 - [0] ----D C:\Users\coco\AppData\Local\{B86A9F77-796F-41BF-A28F-08122B2B9E43} O43 - CFD: 20/10/2011 - 09:09:53 - [0] ----D C:\Users\coco\AppData\Local\{B8E5D9AB-B02B-4FFE-A578-68E96F95484E} O43 - CFD: 26/02/2011 - 13:42:48 - [0] ----D C:\Users\coco\AppData\Local\{B961D703-4248-45A0-A258-35AAAAC0310E} O43 - CFD: 26/03/2012 - 12:42:47 - [0] ----D C:\Users\coco\AppData\Local\{BAD49985-1821-4D00-AD13-E8B0B8AB79BB} O43 - CFD: 20/10/2012 - 10:19:36 - [0] ----D C:\Users\coco\AppData\Local\{BB608BBA-6C94-47FE-B601-B084D993A9B8} O43 - CFD: 08/02/2013 - 21:21:02 - [0] ----D C:\Users\coco\AppData\Local\{BC2ACA23-203A-4623-9A20-8FE336565FE9} O43 - CFD: 22/07/2012 - 07:56:53 - [0] ----D C:\Users\coco\AppData\Local\{BC8A7938-BE24-4184-BD94-BC3653A014A2} O43 - CFD: 29/11/2012 - 09:29:06 - [0] ----D C:\Users\coco\AppData\Local\{BEE17003-1BDB-43B6-90FD-2103ED9BD2F8} O43 - CFD: 06/01/2013 - 09:51:12 - [0] ----D C:\Users\coco\AppData\Local\{BF9D8FD9-930D-4D8A-92E7-5BB6A061679E} O43 - CFD: 03/03/2011 - 21:15:26 - [0] ----D C:\Users\coco\AppData\Local\{C1062D9D-FFDD-4778-9A16-32A924F6010D} O43 - CFD: 01/03/2011 - 14:28:42 - [0] ----D C:\Users\coco\AppData\Local\{C30A276C-9AD5-455B-8850-F107EE059AE0} O43 - CFD: 25/02/2011 - 08:29:57 - [0] ----D C:\Users\coco\AppData\Local\{C74C42E4-F954-4616-BA7A-3D0E6FF69D20} O43 - CFD: 11/12/2011 - 23:11:08 - [0] ----D C:\Users\coco\AppData\Local\{C96A8C8A-66E7-405D-9881-A39E928B669C} O43 - CFD: 19/02/2012 - 13:50:06 - [0] ----D C:\Users\coco\AppData\Local\{CB656CBA-3CE7-4350-95CC-00F0C7051981} O43 - CFD: 26/07/2012 - 11:46:27 - [0] ----D C:\Users\coco\AppData\Local\{CBDC80F4-5DFA-4AA1-A7C3-C606997DF519} O43 - CFD: 18/01/2011 - 23:04:57 - [0] ----D C:\Users\coco\AppData\Local\{CCF68133-189D-4462-ACA8-2A70A97E5C15} O43 - CFD: 16/08/2012 - 09:25:31 - [0] ----D C:\Users\coco\AppData\Local\{CD29D8BF-500C-4BA2-9A30-727E0927DB04} O43 - CFD: 12/07/2012 - 21:11:57 - [0] ----D C:\Users\coco\AppData\Local\{CDE95986-0D68-4F34-BAF6-6ECA7D4570F0} O43 - CFD: 24/12/2012 - 22:41:44 - [0] ----D C:\Users\coco\AppData\Local\{CE27BBCD-4700-44D4-A3EA-23FD91C3CC26} O43 - CFD: 16/08/2012 - 09:50:04 - [0] ----D C:\Users\coco\AppData\Local\{D03D9F7E-DF25-49E1-A1BE-7C8C3602869D} O43 - CFD: 14/08/2012 - 15:51:51 - [0] ----D C:\Users\coco\AppData\Local\{D1F29A48-6053-482A-8D43-FDB98945A8B2} O43 - CFD: 19/07/2012 - 22:01:48 - [0] ----D C:\Users\coco\AppData\Local\{D417852D-161C-44C2-8073-76E39682C2A8} O43 - CFD: 08/08/2012 - 08:33:13 - [0] ----D C:\Users\coco\AppData\Local\{D59E1C2C-AB40-4943-B1CE-94C3C2035FBF} O43 - CFD: 16/10/2012 - 11:06:41 - [0] ----D C:\Users\coco\AppData\Local\{D75C4C50-B03E-4BCE-813E-BE29A67CD1A0} O43 - CFD: 15/08/2011 - 14:29:18 - [0] ----D C:\Users\coco\AppData\Local\{D8866868-8689-43D5-ADE4-6E3A2727AD96} O43 - CFD: 11/08/2012 - 18:06:52 - [0] ----D C:\Users\coco\AppData\Local\{D8CFD923-880A-43F2-AF2D-2FCCD4A217D3} O43 - CFD: 30/11/2012 - 21:33:00 - [0] ----D C:\Users\coco\AppData\Local\{D904B01A-B68C-47AC-95C9-B42B2EFB0D25} O43 - CFD: 28/07/2012 - 07:31:38 - [0] ----D C:\Users\coco\AppData\Local\{D94B8D85-4199-43E3-8302-5184A8E094DF} O43 - CFD: 07/01/2013 - 19:59:06 - [0] ----D C:\Users\coco\AppData\Local\{D9711652-16EF-45B4-ACB9-B8F720C55F8D} O43 - CFD: 19/07/2012 - 22:02:32 - [0] ----D C:\Users\coco\AppData\Local\{D9C79163-C32E-4C3D-BDB3-14449CA0B376} O43 - CFD: 30/01/2012 - 22:49:55 - [0] ----D C:\Users\coco\AppData\Local\{DBF214C7-1DBC-4E21-A843-1600EE8CCB3E} O43 - CFD: 23/08/2012 - 09:33:13 - [0] ----D C:\Users\coco\AppData\Local\{DCA7AC15-F3A3-456A-A2D8-DE134E92015C} O43 - CFD: 26/01/2013 - 09:50:17 - [0] ----D C:\Users\coco\AppData\Local\{DDCB9C94-1DF7-4B5B-9F9F-2C84BD1306AB} O43 - CFD: 11/06/2011 - 09:42:58 - [0] ----D C:\Users\coco\AppData\Local\{DE971AEA-9B97-473A-83B6-6DE8141AD75E} O43 - CFD: 24/10/2011 - 18:25:30 - [0] ----D C:\Users\coco\AppData\Local\{E0475B53-9F01-4E28-9452-9EE536EE1B31} O43 - CFD: 22/07/2012 - 07:56:14 - [0] ----D C:\Users\coco\AppData\Local\{E1172412-CD91-4733-A234-6B203464B470} O43 - CFD: 24/07/2012 - 20:40:56 - [0] ----D C:\Users\coco\AppData\Local\{E14815BA-954E-4E5D-A064-F09B4C2DDF54} O43 - CFD: 15/10/2012 - 07:53:06 - [0] ----D C:\Users\coco\AppData\Local\{E18FD49D-3155-40BE-B121-F442F6E8A00A} O43 - CFD: 20/10/2012 - 22:21:25 - [0] ----D C:\Users\coco\AppData\Local\{E2B244DB-BAD7-4E97-942F-95CBDED3773B} O43 - CFD: 25/10/2012 - 06:52:38 - [0] ----D C:\Users\coco\AppData\Local\{E32E6C67-2464-4FDC-A27C-B54185E0FB21} O43 - CFD: 04/10/2012 - 14:47:43 - [0] ----D C:\Users\coco\AppData\Local\{E386B8B5-BBF8-408C-8B01-AF51CA44573D} O43 - CFD: 11/08/2012 - 18:06:42 - [0] ----D C:\Users\coco\AppData\Local\{E459F1C7-2D15-42A5-A5A9-4DB974E28E33} O43 - CFD: 18/10/2011 - 07:45:10 - [0] ----D C:\Users\coco\AppData\Local\{E56034AC-0257-445C-93B6-FDC7B54F772E} O43 - CFD: 02/08/2012 - 17:57:47 - [0] ----D C:\Users\coco\AppData\Local\{E60738A2-0C38-4CB2-80A8-FC4ECD36FF11} O43 - CFD: 28/07/2012 - 07:31:59 - [0] ----D C:\Users\coco\AppData\Local\{E84335B6-1D44-4C7A-B0BC-1998AE028285} O43 - CFD: 23/10/2012 - 05:41:38 - [0] ----D C:\Users\coco\AppData\Local\{E901A6D2-9433-4E9A-915B-80D40DC36C0D} O43 - CFD: 03/12/2012 - 09:39:50 - [0] ----D C:\Users\coco\AppData\Local\{E9B6D078-BFC8-4541-9A85-63010C8763F2} O43 - CFD: 20/02/2013 - 11:41:28 - [0] ----D C:\Users\coco\AppData\Local\{E9BFEE19-912C-441E-9762-D457CF6DBE9A} O43 - CFD: 26/07/2012 - 11:46:42 - [0] ----D C:\Users\coco\AppData\Local\{E9D5CEC1-D835-4F0D-BA21-F8A6DA160BB0} O43 - CFD: 12/06/2012 - 22:39:28 - [0] ----D C:\Users\coco\AppData\Local\{EA7BFEE9-4BBD-4FB9-8B3C-CE34AFBD9796} O43 - CFD: 13/07/2012 - 08:53:41 - [0] ----D C:\Users\coco\AppData\Local\{ED28F896-A8E7-42A5-805E-20BE94350C32} O43 - CFD: 14/06/2012 - 06:36:09 - [0] ----D C:\Users\coco\AppData\Local\{EDC25DFE-7773-4A71-A81C-6311F84F8751} O43 - CFD: 26/12/2011 - 11:00:06 - [0] ----D C:\Users\coco\AppData\Local\{EE569075-3EE8-448E-AFB0-4A873F8A9D68} O43 - CFD: 13/06/2012 - 06:17:42 - [0] ----D C:\Users\coco\AppData\Local\{EEE1665C-CCA8-4DF1-A8F1-266934757247} O43 - CFD: 24/08/2011 - 14:43:41 - [0] ----D C:\Users\coco\AppData\Local\{EF5D4FE3-5698-4332-9378-4DD71AF847EC} O43 - CFD: 06/10/2011 - 10:56:27 - [0] ----D C:\Users\coco\AppData\Local\{EFE34E1B-1E50-4CEC-97C6-BE1B62DF6ECD} O43 - CFD: 28/11/2012 - 18:13:19 - [0] ----D C:\Users\coco\AppData\Local\{F00E3C0B-7C6F-4292-951A-EBC09C8EFF5B} O43 - CFD: 17/07/2011 - 12:31:44 - [0] ----D C:\Users\coco\AppData\Local\{F05BF9A4-423E-4BCC-AA00-86499A6306E8} O43 - CFD: 26/01/2013 - 10:52:24 - [0] ----D C:\Users\coco\AppData\Local\{F0CB331E-2A32-4ADC-A585-7D2E94A066AE} O43 - CFD: 11/07/2012 - 23:20:45 - [0] ----D C:\Users\coco\AppData\Local\{F1D7F7B1-C8CA-4714-94B8-F2147A2F9C7D} O43 - CFD: 11/08/2012 - 18:06:20 - [0] ----D C:\Users\coco\AppData\Local\{F29154CE-1736-493D-A168-AA22BB9BC49A} O43 - CFD: 05/10/2011 - 15:40:48 - [0] ----D C:\Users\coco\AppData\Local\{F2E1A902-E0C2-4B88-8190-1D755C086BE4} O43 - CFD: 19/10/2011 - 08:54:33 - [0] ----D C:\Users\coco\AppData\Local\{F648A3F4-3713-4474-BC98-E954B85DEEA6} O43 - CFD: 09/03/2011 - 12:26:54 - [0] ----D C:\Users\coco\AppData\Local\{F79C42D1-0FAE-4CF4-8E80-DA114F9710D8} O43 - CFD: 07/06/2011 - 08:21:28 - [0] ----D C:\Users\coco\AppData\Local\{F883727E-CDC2-4F45-A2B8-F01BC52DA0B3} O43 - CFD: 07/07/2011 - 07:09:13 - [0] ----D C:\Users\coco\AppData\Local\{F8D880B3-4BA2-4226-82DA-AE3572ED4AA2} O43 - CFD: 24/10/2011 - 18:25:02 - [0] ----D C:\Users\coco\AppData\Local\{FB10DCF0-A6C1-489E-97E9-4FF50B31FBAB} O43 - CFD: 13/06/2012 - 14:04:24 - [0] ----D C:\Users\coco\AppData\Local\{FB324371-C3E0-46DD-981C-D7DECB347C39} O43 - CFD: 24/12/2010 - 18:39:53 - [0] ----D C:\Users\coco\AppData\Local\{FB58888A-6CD9-4F8B-ACEB-72CFAE797BA7} O43 - CFD: 15/09/2012 - 17:16:12 - [0] ----D C:\Users\coco\AppData\Local\{FDFDE4F0-BF51-4E7E-9F07-3E4D9CFCBF59} O43 - CFD: 20/07/2012 - 22:05:53 - [0] ----D C:\Users\coco\AppData\Local\{FE681670-8E86-427C-83A0-0318D717B8AB} O43 - CFD: 10/02/2013 - 10:20:49 - [0] ----D C:\Users\coco\AppData\Local\{FEC12386-8AC3-46F6-8BBB-1E0C724F7281} O43 - CFD: 11/12/2011 - 23:29:26 - [0] ----D C:\Users\coco\AppData\Local\{FF2F6B2E-C27D-4741-A814-C0EC0AD69DAC} O43 - CFD: 30/10/2011 - 18:57:52 - [0] ----D C:\Users\coco\AppData\Local\{FF9EDB15-0810-4DE8-AC87-2D851B4B4F08} O43 - CFD: 02/12/2012 - 21:36:41 - [0] ----D C:\Users\coco\AppData\Local\{FFC5C7EB-638E-4BCB-AD2B-5F6BA56A0781} O43 - CFD: 14/07/2009 - 05:54:32 - [0,014] R---D C:\Users\coco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 03/08/2012 - 17:42:29 - [0,000] R---D C:\Users\coco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 12/06/2012 - 14:35:48 - [0,002] ----D C:\Users\coco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gamers Unite! Snag Bar O43 - CFD: 25/01/2013 - 19:58:02 - [0,002] ----D C:\Users\coco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 14/07/2009 - 05:49:38 - [0,001] R---D C:\Users\coco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 14/10/2012 - 07:56:36 - [0,000] R---D C:\Users\coco\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup ~ Scan Program Folder in 00mn 08s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.0F1DC21BE655AC350CE86EB801184D3D] - 23/02/2013 - 17:34:34 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1524220] O44 - LFC:[MD5.188581A1D4BC69D82E26F2C494564349] - 23/02/2013 - 17:29:39 ---A- . (...) -- C:\Windows\setupact.log [56019] O44 - LFC:[MD5.359E7BA1775C3D701AE6010EF5BFCB08] - 23/02/2013 - 17:29:36 -S-A- . (...) -- C:\Windows\bootstat.dat [67584] O44 - LFC:[MD5.83C094836FBC86E2AA900B12674EDB54] - 22/02/2013 - 19:52:43 ---A- . (...) -- C:\Ad-Report-CLEAN[1].txt [5496] O44 - LFC:[MD5.8E5FC3A251FC58E3BFB2AF805BCC58D1] - 22/02/2013 - 18:46:50 ---A- . (...) -- C:\AdwCleaner[S1].txt [1847] O44 - LFC:[MD5.18DA5458EC6AE53FBA7462B247C01E39] - 22/02/2013 - 16:14:34 . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\System32\FNTCACHE.DAT [46080] O44 - LFC:[MD5.18DA5458EC6AE53FBA7462B247C01E39] - 22/02/2013 - 16:14:34 ---A- . (...) -- C:\Windows\SysNative\FNTCACHE.DAT [310456] O44 - LFC:[MD5.84501FA9F264D9FDA45540E846D96C1D] - 22/02/2013 - 15:43:58 ---A- . (...) -- C:\Windows\SysNative\PerfStringBackup.INI [1573966] O44 - LFC:[MD5.E2EF5A75A557DEAF3D1E7F7AF440F0A3] - 22/02/2013 - 15:43:58 ---A- . (...) -- C:\Windows\SysNative\perfc009.dat [106816] O44 - LFC:[MD5.475AB5FA63B7D040ADEA7EB0297BFCBA] - 22/02/2013 - 15:43:58 ---A- . (...) -- C:\Windows\SysNative\perfc00C.dat [131182] O44 - LFC:[MD5.21CD6D07C3CF20A463C242B4D9BE761D] - 22/02/2013 - 15:43:58 ---A- . (...) -- C:\Windows\SysNative\perfh009.dat [616694] O44 - LFC:[MD5.CC052DF007082029A4BF4186078FD928] - 22/02/2013 - 15:43:58 ---A- . (...) -- C:\Windows\SysNative\perfh00C.dat [705166] O44 - LFC:[MD5.84501FA9F264D9FDA45540E846D96C1D] - 22/02/2013 - 15:43:58 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1573966] O44 - LFC:[MD5.73B06EBD688CC9D4F241E83186D7422A] - 29/01/2013 - 11:25:22 ---A- . (...) -- C:\Windows\PFRO.log [13706] O44 - LFC:[MD5.2ED72B3F76C9368ABC01464DA64DB7AE] - 26/01/2013 - 08:48:18 ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\SysNative\atmlib.dll [46080] O44 - LFC:[MD5.2ED72B3F76C9368ABC01464DA64DB7AE] - 26/01/2013 - 08:48:18 ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\System32\atmlib.dll [46080] O44 - LFC:[MD5.CB2ABB2DA1E9C977302A78D86D4AE3B0] - 26/01/2013 - 08:48:15 ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\SysNative\atmfd.dll [367616] O44 - LFC:[MD5.CB2ABB2DA1E9C977302A78D86D4AE3B0] - 26/01/2013 - 08:48:15 ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\System32\atmfd.dll [367616] ~ Scan Files in 00mn 04s ---\\ Derniers fichiers créés dans Windows Prefetcher (O45) O45 - LFCP:[MD5.FCEB1E5ECE2F63E95DF8F83B17335FF6] - 10/02/2013 - 09:19:14 ---A- - C:\Windows\Prefetch\AgCx_S1_S-1-5-21-4125327599-2493812685-2951380254-1000.snp.db O45 - LFCP:[MD5.C3C29465D47EEC3B65337FD67AEC10E1] - 10/02/2013 - 09:21:44 ---A- - C:\Windows\Prefetch\AgCx_SC3_0F505F11CA827533.db O45 - LFCP:[MD5.F5A0E03911D164DF5D6AEACC78E9C7C4] - 11/02/2013 - 01:43:55 ---A- - C:\Windows\Prefetch\AgCx_SC1.db.trx O45 - LFCP:[MD5.8EC88ED865D6EA6237254467FC7900CF] - 11/02/2013 - 01:44:55 ---A- - C:\Windows\Prefetch\AgCx_SC1.db O45 - LFCP:[MD5.01DCDCD5821BD3CC7E0626E7EBB914DC] - 20/02/2013 - 11:40:09 ---A- - C:\Windows\Prefetch\NTOSBOOT-B00DFAAD.pf O45 - LFCP:[MD5.72C00916A0D0D2F3F534CC2F1A182CB0] - 22/02/2013 - 16:17:12 ---A- - C:\Windows\Prefetch\AgCx_SC4.db O45 - LFCP:[MD5.3BD23513BAFE1FCEF958948A3903097B] - 22/02/2013 - 17:14:44 ---A- - C:\Windows\Prefetch\CHROME.EXE-84541960.pf O45 - LFCP:[MD5.9B341EBC8BADC5A307E895496F8C1CCD] - 22/02/2013 - 17:18:45 ---A- - C:\Windows\Prefetch\VSSVC.EXE-B8AFC319.pf O45 - LFCP:[MD5.068F242A1AD8190E6CAAA725201EFF9A] - 22/02/2013 - 17:18:46 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-7CFEDEA3.pf O45 - LFCP:[MD5.CA1523598B6F34A8CF39686EC7F6FF92] - 22/02/2013 - 18:43:32 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-87432CEE.pf O45 - LFCP:[MD5.B279289EA97877098F08C3757B8D2A2B] - 22/02/2013 - 18:43:41 ---A- - C:\Windows\Prefetch\ADWCLEANER0 (1).EXE-DD03CD23.pf O45 - LFCP:[MD5.EC8DE06D5B4548E9D4657172EA934130] - 22/02/2013 - 18:53:29 ---A- - C:\Windows\Prefetch\CFSWMGR.EXE-70F2F9B4.pf O45 - LFCP:[MD5.5AFAF4B23F3F45B13293F541EB96D9CA] - 22/02/2013 - 18:53:40 ---A- - C:\Windows\Prefetch\AVASTEMUPDATE.EXE-6EF4B603.pf O45 - LFCP:[MD5.FF0F3CA739916951F6AEA68CF307C609] - 22/02/2013 - 19:49:11 ---A- - C:\Windows\Prefetch\AD-R.EXE-35F9600F.pf O45 - LFCP:[MD5.3979F26D4A01A046C63B43A2DF86E468] - 22/02/2013 - 19:49:21 ---A- - C:\Windows\Prefetch\MAIN.EXE-18FD4E94.pf O45 - LFCP:[MD5.C1D5E2093398737A6753693847FF99F5] - 22/02/2013 - 19:50:23 ---A- - C:\Windows\Prefetch\ERUNT.EXE-D6A15A5B.pf O45 - LFCP:[MD5.CB0BCAB914B62C9CC58579C7BFCBAF4B] - 22/02/2013 - 19:55:30 ---A- - C:\Windows\Prefetch\SEARCHINDEXER.EXE-4A6353B9.pf O45 - LFCP:[MD5.97D59E4F6B7291D3FA82B4AE9FB96716] - 22/02/2013 - 19:55:32 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-3AB35CA7.pf O45 - LFCP:[MD5.A1F9B5357B7A6E424BCD7346DA902C83] - 22/02/2013 - 19:55:52 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-DE9673F9.pf O45 - LFCP:[MD5.7FE61FB34C944BAEBB3EA1EF55EBE934] - 22/02/2013 - 20:00:16 ---A- - C:\Windows\Prefetch\NOTEPAD.EXE-D8414F97.pf O45 - LFCP:[MD5.900644FDF84AD04865B7BE0D0F0AF49D] - 22/02/2013 - 20:25:26 ---A- - C:\Windows\Prefetch\REGSVR32.EXE-D5170E12.pf O45 - LFCP:[MD5.3C1BF7312201DC023F6D89BA30A56732] - 22/02/2013 - 20:25:35 ---A- - C:\Windows\Prefetch\MBAM.EXE-80210E2F.pf O45 - LFCP:[MD5.D20197C296B746836BBCAA0369176672] - 22/02/2013 - 21:27:30 ---A- - C:\Windows\Prefetch\SETUP.EXE-F8BE8604.pf O45 - LFCP:[MD5.48D1C9B09B94FA164024237F84F1E7DB] - 22/02/2013 - 21:27:35 ---A- - C:\Windows\Prefetch\25.0.1364.97_24.0.1312.57_CHR-1DC44244.pf O45 - LFCP:[MD5.05CAC6B86B568225539E18F58B580048] - 22/02/2013 - 21:27:41 ---A- - C:\Windows\Prefetch\SETUP.EXE-D7C575AD.pf O45 - LFCP:[MD5.DFE3486C63FDAC90F28DAD6B0FF7ED5D] - 22/02/2013 - 21:55:31 ---A- - C:\Windows\Prefetch\NOTEPAD.EXE-86E0E9B9.pf O45 - LFCP:[MD5.960A8E6D950257FD76E68451486E358C] - 22/02/2013 - 22:04:36 ---A- - C:\Windows\Prefetch\LOGONUI.EXE-09140401.pf O45 - LFCP:[MD5.16F730099DB56D896147C7EC68C88AE6] - 22/02/2013 - 22:04:58 ---A- - C:\Windows\Prefetch\PfSvPerfStats.bin O45 - LFCP:[MD5.3A65A0F70E0B29B9E6CCE36785D81149] - 23/02/2013 - 17:30:42 ---A- - C:\Windows\Prefetch\MSNMSGR.EXE-D22CE80C.pf O45 - LFCP:[MD5.9F1A7EC323C5BD2EFA3716BEE48E6ACB] - 23/02/2013 - 17:30:42 ---A- - C:\Windows\Prefetch\RUNONCE.EXE-0E293DD6.pf O45 - LFCP:[MD5.A32520186509DE73F44AF34B1855FCC0] - 23/02/2013 - 17:30:42 ---A- - C:\Windows\Prefetch\SIDEBAR.EXE-FA75EA61.pf O45 - LFCP:[MD5.6B839F1B03611194FF619008DF24A124] - 23/02/2013 - 17:30:42 ---A- - C:\Windows\Prefetch\TOPI.EXE-139542E9.pf O45 - LFCP:[MD5.A5FAA154C0D58F90178903D912C86E06] - 23/02/2013 - 17:30:46 ---A- - C:\Windows\Prefetch\TCRDKBB.EXE-BD533577.pf O45 - LFCP:[MD5.ED3873872356D6E893AE7DB0DB647987] - 23/02/2013 - 17:30:50 ---A- - C:\Windows\Prefetch\CLISTART.EXE-0F58A398.pf O45 - LFCP:[MD5.2A0DA90C442583356DF40943BA6E23D0] - 23/02/2013 - 17:30:52 ---A- - C:\Windows\Prefetch\SVPWUTIL.EXE-76108559.pf O45 - LFCP:[MD5.9E5DDFE0BF9B176EBDF7CA5555D2FF33] - 23/02/2013 - 17:30:53 ---A- - C:\Windows\Prefetch\KENOTIFY.EXE-E6F3D900.pf O45 - LFCP:[MD5.7CB38D999557BF1E1EDD9C45A0D4DBD0] - 23/02/2013 - 17:30:54 ---A- - C:\Windows\Prefetch\TWEBCAMERA.EXE-82879EEF.pf O45 - LFCP:[MD5.BE7FF21B42546E76AE4D187CE9F61253] - 23/02/2013 - 17:30:56 ---A- - C:\Windows\Prefetch\SYNTPHELPER.EXE-0A20AAC4.pf O45 - LFCP:[MD5.A6399A68F7B6DC9A1579B9C97482A7A7] - 23/02/2013 - 17:31:05 ---A- - C:\Windows\Prefetch\TOSHIBASERVICESTATION.EXE-92A6EAE9.pf O45 - LFCP:[MD5.3CA2D0F9FCCAD353A640B4B568747B72] - 23/02/2013 - 17:31:06 ---A- - C:\Windows\Prefetch\AVASTUI.EXE-56B29A08.pf O45 - LFCP:[MD5.A086E14E1B31EA33D401116367388773] - 23/02/2013 - 17:31:07 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-007FEA55.pf O45 - LFCP:[MD5.8F84C08FA2DC58188527DE83B59B0186] - 23/02/2013 - 17:31:40 ---A- - C:\Windows\Prefetch\CVTRES.EXE-2B9D810D.pf O45 - LFCP:[MD5.ED8AC822087593DE33B1833F290D00A0] - 23/02/2013 - 17:31:41 ---A- - C:\Windows\Prefetch\CSC.EXE-BE9AC2DF.pf O45 - LFCP:[MD5.EFDF1C1EFA93DD096E31E8C755681D22] - 23/02/2013 - 17:31:55 ---A- - C:\Windows\Prefetch\ADOBEARM.EXE-7105D3A2.pf O45 - LFCP:[MD5.7C3BE236BF1EC6CCD8F85E26EC6469B6] - 23/02/2013 - 17:31:56 ---A- - C:\Windows\Prefetch\READER_SL.EXE-B1C62096.pf O45 - LFCP:[MD5.D68192D29337AF1F1FA942FB25A1C6E6] - 23/02/2013 - 17:31:59 ---A- - C:\Windows\Prefetch\CCC.EXE-B637C9BF.pf O45 - LFCP:[MD5.42CD817D93C6D63049A09E6FA40671E2] - 23/02/2013 - 17:32:10 ---A- - C:\Windows\Prefetch\TMACHINFO.EXE-2FCB5A05.pf O45 - LFCP:[MD5.26A9DEF6E8EA0375544F92AEDB28D155] - 23/02/2013 - 17:32:14 ---A- - C:\Windows\Prefetch\MSCORSVW.EXE-C3C515BD.pf O45 - LFCP:[MD5.3616D236FDCA519FB2375AE4ADC08A14] - 23/02/2013 - 17:32:15 ---A- - C:\Windows\Prefetch\MSCORSVW.EXE-57D17DAF.pf O45 - LFCP:[MD5.214A27F65FFA80A3B3856C51F83BEF03] - 23/02/2013 - 17:32:21 ---A- - C:\Windows\Prefetch\CFIWMXSVCS64.EXE-E079CBBA.pf O45 - LFCP:[MD5.536C244B610986503265DE5E87AD0EED] - 23/02/2013 - 17:32:26 ---A- - C:\Windows\Prefetch\CFSVCS.EXE-35E839CF.pf O45 - LFCP:[MD5.425D6BFBCFC80F213C7B500A064DC3BE] - 23/02/2013 - 17:32:34 ---A- - C:\Windows\Prefetch\TOSSENOTIFY.EXE-BC36C1CB.pf O45 - LFCP:[MD5.35B8AF18D379F8A170438C24E7F18DFA] - 23/02/2013 - 17:32:34 ---A- - C:\Windows\Prefetch\TOSSMARTSRV.EXE-BCFE7888.pf O45 - LFCP:[MD5.CE23222898EA873A0BD052E1C7F75450] - 23/02/2013 - 17:32:41 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-05F624AB.pf O45 - LFCP:[MD5.71E413DA7B5CD29322D9005829798AD0] - 23/02/2013 - 17:32:53 ---A- - C:\Windows\Prefetch\WMPNETWK.EXE-D9F2A96F.pf O45 - LFCP:[MD5.C9612D0C3F73E82303644C1066267805] - 23/02/2013 - 17:33:46 ---A- - C:\Windows\Prefetch\AVAST.SETUP-B1D66586.pf O45 - LFCP:[MD5.C3C13F4DF61513CE1CB0724668C85F01] - 23/02/2013 - 17:33:51 ---A- - C:\Windows\Prefetch\WMIADAP.EXE-F8DFDFA2.pf O45 - LFCP:[MD5.E0B4073AC915BAC8F1B4F9FC26F0B332] - 23/02/2013 - 17:34:08 ---A- - C:\Windows\Prefetch\TRUSTEDINSTALLER.EXE-3CC531E5.pf O45 - LFCP:[MD5.549E313EE356F54158D00F1906B1DBE2] - 23/02/2013 - 17:42:48 ---A- - C:\Windows\Prefetch\WERMGR.EXE-0F2AC88C.pf O45 - LFCP:[MD5.C8EACA4530C36C57976B4446FDA33D47] - 23/02/2013 - 17:42:58 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-02CC9EFF.pf O45 - LFCP:[MD5.73CBB1D7FE3027AE741672E7F95528D0] - 23/02/2013 - 17:44:54 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-E7777CC4.pf O45 - LFCP:[MD5.6A5B3948D5590A9F6D6F7D98D3CBF773] - 23/02/2013 - 17:56:23 ---A- - C:\Windows\Prefetch\Layout.ini O45 - LFCP:[MD5.A143122D804E28E88EACDC43B3B8E26F] - 23/02/2013 - 17:56:32 ---A- - C:\Windows\Prefetch\DEFRAG.EXE-588F90AD.pf O45 - LFCP:[MD5.AEAA32DAC9107790CCF7FBC6FE0E5A7C] - 23/02/2013 - 17:56:34 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-7AC6742A.pf O45 - LFCP:[MD5.D1010EDD63A57FBFC869366333F7E3B5] - 23/02/2013 - 17:59:26 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-411A328D.pf O45 - LFCP:[MD5.277451300A2DDFB5DD7E013A41FC7F45] - 23/02/2013 - 18:10:34 ---A- - C:\Windows\Prefetch\FLASHUTIL32_11_6_602_168_ACTI-4F52498D.pf O45 - LFCP:[MD5.1F63F3CBD9139FF720FFA84B28688F35] - 23/02/2013 - 18:16:54 ---A- - C:\Windows\Prefetch\SPLWOW64.EXE-297C4568.pf O45 - LFCP:[MD5.2EE02AFEC7F6C83C0FA301D65885306E] - 23/02/2013 - 18:16:54 ---A- - C:\Windows\Prefetch\WINWORD.EXE-CEA9B574.pf O45 - LFCP:[MD5.3746FD3EBDE09732801BEB86DECF6D91] - 23/02/2013 - 18:16:58 ---A- - C:\Windows\Prefetch\PRINTISOLATIONHOST.EXE-E0CD10A9.pf O45 - LFCP:[MD5.7E27117DB03811E742ED049A0AE8CF99] - 23/02/2013 - 18:24:21 ---A- - C:\Windows\Prefetch\IEXPLORE.EXE-4B6C9213.pf O45 - LFCP:[MD5.00636C598AC6EF23C3702B6217FECA5D] - 23/02/2013 - 18:32:57 ---A- - C:\Windows\Prefetch\WMIPRVSE.EXE-1628051C.pf O45 - LFCP:[MD5.6029CB139059DC674BE31B92AE6CF154] - 23/02/2013 - 18:43:01 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-76936ED5.pf O45 - LFCP:[MD5.121AE47184025358E509E90847909123] - 23/02/2013 - 18:48:10 ---A- - C:\Windows\Prefetch\ZHPDIAG2.TMP-207659A4.pf O45 - LFCP:[MD5.8F57EE70B4B74251FEFCE66DC67FA909] - 23/02/2013 - 18:49:23 ---A- - C:\Windows\Prefetch\ZHPDIAG2.TMP-552F8BC4.pf O45 - LFCP:[MD5.B6DD5C0D2B2CB02E7D7157C57471B483] - 23/02/2013 - 18:55:56 ---A- - C:\Windows\Prefetch\ZHPDIAG2.TMP-21D0F047.pf O45 - LFCP:[MD5.53412627F0B696D5CC9F29B747F68787] - 23/02/2013 - 18:55:59 ---A- - C:\Windows\Prefetch\ZHPDIAG2.TMP-2B761A0F.pf O45 - LFCP:[MD5.07FB88BD5907C8C58BB5596AED33B16C] - 23/02/2013 - 19:42:54 ---A- - C:\Windows\Prefetch\MYSTIFY.SCR-0667C0AF.pf O45 - LFCP:[MD5.C45D00B7219E8B9254535C455A3B25BA] - 23/02/2013 - 19:50:49 ---A- - C:\Windows\Prefetch\AgGlUAD_S-1-5-21-4125327599-2493812685-2951380254-1000.db O45 - LFCP:[MD5.E49F34CF0F3479ABC3755578D13CCBB1] - 23/02/2013 - 19:50:50 ---A- - C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-4125327599-2493812685-2951380254-1000.db O45 - LFCP:[MD5.AB5C4AF8CCE8188A6406087C76FB431F] - 23/02/2013 - 20:05:52 ---A- - C:\Windows\Prefetch\AgGlGlobalHistory.db O45 - LFCP:[MD5.9C866AF9DCB28F9C5F67A11F6522A90A] - 23/02/2013 - 20:05:52 ---A- - C:\Windows\Prefetch\AgRobust.db O45 - LFCP:[MD5.D9960CAD6F364453EFF01A5B47FAC409] - 23/02/2013 - 20:05:53 ---A- - C:\Windows\Prefetch\AgGlFaultHistory.db O45 - LFCP:[MD5.F3E263C1F1518D339DC7268341595741] - 23/02/2013 - 20:05:53 ---A- - C:\Windows\Prefetch\AgGlFgAppHistory.db O45 - LFCP:[MD5.6F356D520EDD63BCFAAF0A2BA6290630] - 23/02/2013 - 20:21:00 ---A- - C:\Windows\Prefetch\GOOGLEUPDATE.EXE-B95715F5.pf O45 - LFCP:[MD5.6A15A0D2FDF4707B7A0428D3C2471F8C] - 23/02/2013 - 20:21:10 ---A- - C:\Windows\Prefetch\TASKENG.EXE-48D4E289.pf O45 - LFCP:[MD5.90E092F33270C3AB5D88C509C670250C] - 23/02/2013 - 20:21:47 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-7238F31D.pf O45 - LFCP:[MD5.D853DCC13EACCB0FBC16BBECFAFCB79A] - 23/02/2013 - 20:21:58 ---A- - C:\Windows\Prefetch\ZHPDIAG2.TMP-237E0769.pf O45 - LFCP:[MD5.9EAC5E4D0D9FD6005D18F20360B7943B] - 23/02/2013 - 20:21:59 ---A- - C:\Windows\Prefetch\AUDIODG.EXE-BDFD3029.pf O45 - LFCP:[MD5.6A2FEC80DF2EC94926B5B137161BD9B3] - 23/02/2013 - 20:22:02 ---A- - C:\Windows\Prefetch\ZHPDIAG2.EXE-39EBF2E8.pf O45 - LFCP:[MD5.014D49C78346254C33D9D85888C4E601] - 23/02/2013 - 20:22:02 ---A- - C:\Windows\Prefetch\ZHPDIAG2.TMP-3FD0FC02.pf O45 - LFCP:[MD5.469F89AF5788503E9E35637E0B580619] - 23/02/2013 - 20:22:18 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-5E46FA0D.pf O45 - LFCP:[MD5.A9FCA0C1B6B7EF4F28956EA82DD64972] - 23/02/2013 - 20:22:22 ---A- - C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-77482212.pf O45 - LFCP:[MD5.38C7EBCDD4797D961B96240A84B138FF] - 23/02/2013 - 20:22:22 ---A- - C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf O45 - LFCP:[MD5.4F7D63C504086BAEE2BDB13B8FF76FDB] - 23/02/2013 - 20:23:12 ---A- - C:\Windows\Prefetch\MPCMDRUN.EXE-F401FBB4.pf O45 - LFCP:[MD5.21FB0C4B2AC2F442ABB791A0DD1AA933] - 23/02/2013 - 20:24:13 ---A- - C:\Windows\Prefetch\SPPSVC.EXE-B0F8131B.pf O45 - LFCP:[MD5.3C3994C88A982E0729444CEE9F15C307] - 23/02/2013 - 20:24:49 ---A- - C:\Windows\Prefetch\SCHTASKS.EXE-AD598958.pf O45 - LFCP:[MD5.34B1DDCA03D1D75975BFCD5FB151DA15] - 23/02/2013 - 20:26:00 ---A- - C:\Windows\Prefetch\GOOGLEUPDATE.EXE-EAED6EBB.pf O45 - LFCP:[MD5.C378A12B9D08F016E6C0D2B5BEA5BBB9] - 23/02/2013 - 20:26:00 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-80F4A784.pf O45 - LFCP:[MD5.CB8FF8BC0C3D1C58FEDD1252141E6C7B] - 23/02/2013 - 20:26:17 ---A- - C:\Windows\Prefetch\WERFAULT.EXE-37549B7E.pf O45 - LFCP:[MD5.B2D6E01129D5B5F7F316EBEEBE3E8C36] - 23/02/2013 - 20:26:40 ---A- - C:\Windows\Prefetch\CONSENT.EXE-531BD9EA.pf O45 - LFCP:[MD5.6828D06163495252BB7FD95E099020C9] - 23/02/2013 - 20:26:42 ---A- - C:\Windows\Prefetch\ZHPHEP.EXE-EBD3B8D7.pf O45 - LFCP:[MD5.82AC281F1BDE2F3E9CC1A36DE3A477B9] - 23/02/2013 - 20:26:44 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-766398D2.pf O45 - LFCP:[MD5.5E78AFEFE5C467229EC15BFA9C4667AA] - 23/02/2013 - 20:26:52 ---A- - C:\Windows\Prefetch\ZHPDIAG.EXE-0D117CAF.pf O45 - LFCP:[MD5.1AD941C72A5C2551C0022AE28F4347CA] - 23/02/2013 - 20:29:02 ---A- - C:\Windows\Prefetch\CMD.EXE-AC113AA8.pf O45 - LFCP:[MD5.02153314C66B4179B4D858529720B5FC] - 23/02/2013 - 20:29:02 ---A- - C:\Windows\Prefetch\CONHOST.EXE-1F3E9D7E.pf O45 - LFCP:[MD5.9B849D313479FDCB4193ADE3EACC317F] - 23/02/2013 - 20:29:02 ---A- - C:\Windows\Prefetch\CSCRIPT.EXE-0FB3F22C.pf O45 - LFCP:[MD5.333CA7289C591A7BFBD75BA598F0CE4A] - 23/02/2013 - 20:29:11 ---A- - C:\Windows\Prefetch\PV.EXE-34B75B82.pf O45 - LFCP:[MD5.A26F8CABFE1BCF920B40067764A3A78A] - 23/02/2013 - 20:29:11 ---A- - C:\Windows\Prefetch\WMIPRVSE.EXE-6768A320.pf O45 - LFCP:[MD5.F60586E4AA0A74A6883D64E0B45B92CD] - 23/02/2013 - 20:29:34 ---A- - C:\Windows\Prefetch\SUBINACL.EXE-AB0CE9D9.pf ~ Scan Prefetcher in 00mn 01s ---\\ Déni du service (Local Security Authority) (O48) O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corp. - LiveSSP.) -- C:\Windows\System32\livessp.dll ~ Scan Keys in 00mn 00s ---\\ Contrôle du Safe Boot (CSB) (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys ~ Scan CSB in 00mn 00s ---\\ MountPoints2 Shell Key (O51) O51 - MPSK:{00cc1726-24a2-11e0-a8f5-806e6f6e6963}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{4b254f27-2570-11e0-a8bc-806e6f6e6963}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{54d72348-2494-11e0-ae6a-806e6f6e6963}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{586286c5-2492-11e0-b00a-88ae1de82028}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{5d3a45c4-c068-11df-abcd-806e6f6e6963}\AutoRun\command. (...) -- E:\SETUP.exe (.not file.) O51 - MPSK:{744dfc93-41a5-11e0-b15d-88ae1de82028}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{765a7dcb-2606-11e0-a849-88ae1de82028}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) O51 - MPSK:{c8cf0598-2540-11e0-a8bb-88ae1de82028}\AutoRun\command. (...) -- F:\AutoRun.exe (.not file.) ~ Scan Keys in 00mn 00s ---\\ Trojan Driver Search Data (HKLM) (O52) O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm ~ Scan Keys in 00mn 00s ---\\ ShareTools MSconfig StartupReg (O53) (None) ---\\ Microsoft Control Security Providers (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll ~ Scan Keys in 00mn 00s ---\\ Microsoft Windows Policies System (O55) O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0 O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ Scan Keys in 00mn 00s ---\\ Microsoft Windows Policies Explorer (O56) O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0 ~ Scan Keys in 00mn 00s ---\\ Liste des Drivers Système (O58) O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088] O58 - SDL:[MD5.75B8EF2A089127E8A3B38F46CC366D79] - 30/03/2010 - 00:46:30 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\SysWOW64\drivers\mbamswissarmy.sys [38224] ~ Scan Drivers in 00mn 00s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC:Last File Created 20/02/2013 - 11:40:34 ---A- C:\Users\coco\AppData\Roaming\Microsoft\MSN Messenger\sqmnoopt01.sqm [320] O61 - LFC:Last File Created 20/02/2013 - 11:46:57 -SHA- C:\Users\coco\AppData\Roaming\Microsoft\Protect\S-1-5-21-4125327599-2493812685-2951380254-1000\fe6d8cb9-0c64-4908-9ed3-7da45d09ded7 [468] O61 - LFC:Last File Created 20/02/2013 - 11:46:58 -SHA- C:\Users\coco\AppData\Roaming\Microsoft\Protect\S-1-5-21-4125327599-2493812685-2951380254-1000\Preferred [24] O61 - LFC:Last File Created 20/02/2013 - 12:19:48 ---A- C:\Users\coco\AppData\Roaming\Microsoft\MSN Messenger\sqmnoopt02.sqm [416] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Extensions\external_extensions.json [99] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\am.pak [338841] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ar.pak [326501] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\bg.pak [410379] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\bn.pak [512743] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ca.pak [247140] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\cs.pak [248015] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\da.pak [224511] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\de.pak [208797] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\el.pak [446913] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\en-GB.pak [206764] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\en-US.pak [206847] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\es-419.pak [247539] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\es.pak [253526] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\et.pak [215886] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\fa.pak [348222] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\fi.pak [232109] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\fil.pak [251790] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\fr.pak [261140] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\gu.pak [487990] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\he.pak [279989] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\hi.pak [506303] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\hr.pak [231729] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\hu.pak [258389] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\id.pak [222799] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\it.pak [241743] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ja.pak [296419] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\kn.pak [562306] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ko.pak [250214] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\lt.pak [243189] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\lv.pak [245708] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ml.pak [655327] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\mr.pak [494628] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ms.pak [179897] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\nb.pak [224818] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\nl.pak [240398] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\pl.pak [245734] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\pt-BR.pak [238225] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\pt-PT.pak [244055] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ro.pak [255190] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ru.pak [391798] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\sk.pak [257754] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\sl.pak [226816] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\sr.pak [377695] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\sv.pak [225931] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\sw.pak [204104] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ta.pak [587339] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\te.pak [544807] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\th.pak [505804] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\tr.pak [245094] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\uk.pak [386448] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\vi.pak [283593] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\zh-CN.pak [200967] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\zh-TW.pak [201870] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\PepperFlash\manifest.json [2054] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\VisualElements\logo.png [5228] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\VisualElements\smalllogo.png [11251] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\VisualElements\splash-620x300.png [12428] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\chrome_100_percent.pak [990399] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\chrome_touch_100_percent.pak [1002389] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\d3dcompiler_43.dll [2106216] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\d3dx9_43.dll [1998168] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\default_apps\docs.crx [4578] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\default_apps\drive.crx [25561] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\default_apps\external_extensions.json [982] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\default_apps\gmail.crx [24040] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\default_apps\search.crx [26392] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\default_apps\youtube.crx [23668] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\nacl_irt_x86_32.nexe [5688489] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\nacl_irt_x86_64.nexe [6069578] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\resources.pak [5064775] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\secondarytile.png [2455] O61 - LFC:Last File Created 21/02/2013 - 04:21:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\xinput1_3.dll [81768] O61 - LFC:Last File Created 21/02/2013 - 06:22:43 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\chrome.dll [43873744] O61 - LFC:Last File Created 21/02/2013 - 06:22:44 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\chrome_frame_helper.dll [57296] O61 - LFC:Last File Created 21/02/2013 - 06:22:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\chrome_frame_helper.exe [82896] O61 - LFC:Last File Created 21/02/2013 - 06:22:46 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\chrome_launcher.exe [86992] O61 - LFC:Last File Created 21/02/2013 - 06:22:47 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\delegate_execute.exe [890832] O61 - LFC:Last File Created 21/02/2013 - 06:22:48 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\ffmpegsumo.dll [1552848] O61 - LFC:Last File Created 21/02/2013 - 06:22:49 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\icudt.dll [9962960] O61 - LFC:Last File Created 21/02/2013 - 06:22:50 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\libegl.dll [124368] O61 - LFC:Last File Created 21/02/2013 - 06:22:51 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\libglesv2.dll [596944] O61 - LFC:Last File Created 21/02/2013 - 06:22:52 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\am.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:22:53 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ar.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:22:54 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\bg.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:22:55 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\bn.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:22:56 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ca.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:22:57 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\cs.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:22:58 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\da.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:22:58 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\de.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:22:59 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\el.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:00 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\en-GB.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:01 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\en-US.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:02 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\es-419.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:03 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\es.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:04 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\et.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:05 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\fa.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:06 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\fi.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:06 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\fil.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:07 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\fr.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:08 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\gu.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:09 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\he.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:10 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\hi.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:11 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\hr.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:12 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\hu.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:13 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\id.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:13 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\it.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:14 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ja.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:15 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\kn.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:16 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ko.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:17 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\lt.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:18 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\lv.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:19 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ml.dll [9680] O61 - LFC:Last File Created 21/02/2013 - 06:23:19 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\mr.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:20 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ms.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:21 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\nb.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:22 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\nl.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:23 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\pl.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:24 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\pt-BR.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:25 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\pt-PT.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:26 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ro.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:26 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ru.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:27 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\sk.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:28 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\sl.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:29 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\sr.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:30 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\sv.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:31 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\sw.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:32 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\ta.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:33 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\te.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:33 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\th.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:34 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\tr.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:35 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\uk.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:36 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\vi.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:37 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\zh-CN.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:38 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Locales\zh-TW.dll [9168] O61 - LFC:Last File Created 21/02/2013 - 06:23:39 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\metro_driver.dll [931792] O61 - LFC:Last File Created 21/02/2013 - 06:23:40 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\nacl64.exe [1006032] O61 - LFC:Last File Created 21/02/2013 - 06:23:40 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\npchrome_frame.dll [1887696] O61 - LFC:Last File Created 21/02/2013 - 06:23:42 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\pdf.dll [4050896] O61 - LFC:Last File Created 21/02/2013 - 06:23:43 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\PepperFlash\pepflashplayer.dll [12637136] O61 - LFC:Last File Created 21/02/2013 - 06:23:44 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\ppgooglenaclpluginchrome.dll [459728] O61 - LFC:Last File Created 21/02/2013 - 06:23:46 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\chrome.exe [1274320] O61 - LFC:Last File Created 21/02/2013 - 22:45:00 ---A- C:\Users\coco\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\25.0.1364.97\25.0.1364.97_24.0.1312.57_chrome_updater.exe [8004960] O61 - LFC:Last File Created 22/02/2013 - 15:54:22 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old [267] O61 - LFC:Last File Created 22/02/2013 - 15:55:10 ----- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\cfbf9dd3ed978b23c1976cf9c7fe11bc [1283570] O61 - LFC:Last File Created 22/02/2013 - 15:55:24 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Archived History [2826240] O61 - LFC:Last File Created 22/02/2013 - 15:55:25 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Archived History-journal [16384] O61 - LFC:Last File Created 22/02/2013 - 15:55:34 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old [268] O61 - LFC:Last File Created 22/02/2013 - 15:55:42 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\History Index 2012-11 [1368064] O61 - LFC:Last File Created 22/02/2013 - 16:00:16 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Bookmarks.bak [30275] O61 - LFC:Last File Created 22/02/2013 - 16:00:32 ----- C:\Users\coco\AppData\Local\Temp\CRX_75DAF8CB7768\crl-set [264352] O61 - LFC:Last File Created 22/02/2013 - 16:00:32 ----- C:\Users\coco\AppData\Local\Temp\CRX_75DAF8CB7768\manifest.json [34] O61 - LFC:Last File Created 22/02/2013 - 16:00:32 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Certificate Revocation Lists [264352] O61 - LFC:Last File Created 22/02/2013 - 16:10:27 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_get3.adobe.com_0.localstorage [3072] O61 - LFC:Last File Created 22/02/2013 - 16:10:27 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_get3.adobe.com_0.localstorage-journal [3608] O61 - LFC:Last File Created 22/02/2013 - 16:10:42 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Last Session [19383] O61 - LFC:Last File Created 22/02/2013 - 16:11:08 ---A- C:\Users\coco\AppData\Roaming\Microsoft\MSN Messenger\sqmnoopt03.sqm [548] O61 - LFC:Last File Created 22/02/2013 - 16:44:06 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Extension State\000157.sst [196] O61 - LFC:Last File Created 22/02/2013 - 16:44:06 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Extension State\CURRENT [16] O61 - LFC:Last File Created 22/02/2013 - 16:44:06 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Extension State\MANIFEST-000156 [860] O61 - LFC:Last File Created 22/02/2013 - 16:44:08 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG [269] O61 - LFC:Last File Created 22/02/2013 - 16:44:19 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Managed Mode Settings [8] O61 - LFC:Last File Created 22/02/2013 - 16:44:55 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Bookmarks [30275] O61 - LFC:Last File Created 22/02/2013 - 16:45:09 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000091.sst [145] O61 - LFC:Last File Created 22/02/2013 - 16:45:09 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Session Storage\CURRENT [16] O61 - LFC:Last File Created 22/02/2013 - 16:45:09 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Session Storage\MANIFEST-000088 [456] O61 - LFC:Last File Created 22/02/2013 - 16:45:10 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG [766] O61 - LFC:Last File Created 22/02/2013 - 16:49:26 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Login Data [32768] O61 - LFC:Last File Created 22/02/2013 - 16:49:26 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal [10792] O61 - LFC:Last File Created 22/02/2013 - 16:49:50 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity [555] O61 - LFC:Last File Created 22/02/2013 - 16:53:02 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Favicons [2422784] O61 - LFC:Last File Created 22/02/2013 - 16:53:02 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal [16384] O61 - LFC:Last File Created 22/02/2013 - 16:53:02 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\History Index 2013-02 [1163264] O61 - LFC:Last File Created 22/02/2013 - 16:53:03 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\History Index 2013-02-journal [16384] O61 - LFC:Last File Created 22/02/2013 - 17:44:25 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Top Sites [589824] O61 - LFC:Last File Created 22/02/2013 - 17:44:25 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Top Sites-journal [16384] O61 - LFC:Last File Created 22/02/2013 - 18:20:26 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Cookies [417792] O61 - LFC:Last File Created 22/02/2013 - 18:20:26 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal [16384] O61 - LFC:Last File Created 22/02/2013 - 18:23:04 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Safe Browsing Download [1648300] O61 - LFC:Last File Created 22/02/2013 - 18:23:05 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Safe Browsing Bloom [8009664] O61 - LFC:Last File Created 22/02/2013 - 18:23:05 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Safe Browsing Bloom Prefix Set [1555800] O61 - LFC:Last File Created 22/02/2013 - 18:23:05 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Safe Browsing Csd Whitelist [134512] O61 - LFC:Last File Created 22/02/2013 - 18:23:05 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Safe Browsing Download Whitelist [19780] O61 - LFC:Last File Created 22/02/2013 - 18:23:34 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies [6144] O61 - LFC:Last File Created 22/02/2013 - 18:23:34 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies-journal [4640] O61 - LFC:Last File Created 22/02/2013 - 18:30:54 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Web Data [46469120] O61 - LFC:Last File Created 22/02/2013 - 18:30:55 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal [16384] O61 - LFC:Last File Created 22/02/2013 - 18:44:24 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_icmlaeflemplmjndnaapfdbbnpncnbda_0.localstorage [121856] O61 - LFC:Last File Created 22/02/2013 - 18:44:24 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_icmlaeflemplmjndnaapfdbbnpncnbda_0.localstorage-journal [16384] O61 - LFC:Last File Created 22/02/2013 - 18:46:33 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Current Tabs [35028] O61 - LFC:Last File Created 22/02/2013 - 18:46:34 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\History [2920448] O61 - LFC:Last File Created 22/02/2013 - 18:46:34 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache [28074] O61 - LFC:Last File Created 22/02/2013 - 18:46:34 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\History-journal [16384] O61 - LFC:Last File Created 22/02/2013 - 18:46:34 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Sync Data\SyncData.sqlite3 [68251648] O61 - LFC:Last File Created 22/02/2013 - 18:46:34 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Sync Data\SyncData.sqlite3-journal [16384] O61 - LFC:Last File Created 22/02/2013 - 18:46:34 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Visited Links [131072] O61 - LFC:Last File Created 22/02/2013 - 18:46:34 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Local State [23568] O61 - LFC:Last File Created 22/02/2013 - 18:46:35 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Current Session [155392] O61 - LFC:Last File Created 22/02/2013 - 18:46:35 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt [5] O61 - LFC:Last File Created 22/02/2013 - 18:46:38 ---A- C:\Users\coco\AppData\Roaming\Microsoft\Office\Word12.pip [1684] O61 - LFC:Last File Created 22/02/2013 - 18:46:50 ---A- C:\Users\coco\AppData\Local\Google\Chrome\User Data\Default\Preferences [76553] O61 - LFC:Last File Created 22/02/2013 - 18:52:18 ---A- C:\Users\coco\AppData\Roaming\Microsoft\MSN Messenger\sqmnoopt04.sqm [320] O61 - LFC:Last File Created 22/02/2013 - 19:49:26 ---A- C:\Users\coco\AppData\Roaming\Microsoft\Office\Recent\Nouveau Document Microsoft Office Word.LNK [1166] O61 - LFC:Last File Created 22/02/2013 - 19:49:49 ----- C:\Users\coco\AppData\Local\Temp\~DF2EA41AE14BE5D8CD.TMP [16384] O61 - LFC:Last File Created 22/02/2013 - 19:53:23 ---A- C:\Users\coco\AppData\Roaming\Microsoft\MSN Messenger\sqmnoopt05.sqm [416] O61 - LFC:Last File Created 22/02/2013 - 20:29:18 ---A- C:\Users\coco\AppData\Roaming\Microsoft\Office\Recent\Nouveau Document Microsoft Office Word (2).LNK [1186] O61 - LFC:Last File Created 22/02/2013 - 21:27:25 ---A- C:\Users\coco\AppData\Local\Temp\CR_07A35.tmp\SETUP_PATCH.PACKED.7Z [28478] O61 - LFC:Last File Created 22/02/2013 - 21:27:29 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Installer\setup.exe [1629648] O61 - LFC:Last File Created 22/02/2013 - 21:34:15 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\25.0.1364.97\Installer\chrome.7z [119850088] O61 - LFC:Last File Created 22/02/2013 - 21:34:45 ---A- C:\Users\coco\AppData\Local\Google\Chrome\Application\VisualElementsManifest.xml [396] O61 - LFC:Last File Created 22/02/2013 - 21:55:21 ---A- C:\Users\coco\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2013-02-22 (20-30-00).txt [2148] O61 - LFC:Last File Created 22/02/2013 - 22:03:37 --HA- C:\Users\coco\AppData\Local\IconCache.db [3726701] O61 - LFC:Last File Created 22/02/2013 - 22:04:03 ---A- C:\Users\coco\AppData\Local\TOSHIBA_Corporation\ToshibaServiceStation.exe_Url_lidkhntuzcqftx1osnwucx1afj3bgluo\2.1.3834.17763\user.config [311] O61 - LFC:Last File Created 22/02/2013 - 22:04:10 ---A- C:\Users\coco\AppData\Roaming\Microsoft\MSN Messenger\sqmnoopt06.sqm [548] O61 - LFC:Last File Created 23/02/2013 - 17:30:28 ----- C:\Users\coco\AppData\Local\Windows Live\uxcore_msnmsgr_00.etl [4096] O61 - LFC:Last File Created 23/02/2013 - 17:31:56 ---A- C:\Users\coco\AppData\Local\ATI\ACE\Manifest.Bin [32089] O61 - LFC:Last File Created 23/02/2013 - 17:31:56 ---A- C:\Users\coco\AppData\Local\ATI\ACE\Manifest.xml [23698] O61 - LFC:Last File Created 23/02/2013 - 18:05:52 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\863244884c13f5f32b09296c582fbdd7 [1078] O61 - LFC:Last File Created 23/02/2013 - 18:05:52 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\cc1cadc55dcfeab42c71ddc651b9fe75 [1210] O61 - LFC:Last File Created 23/02/2013 - 18:05:53 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\78529f8901b92f0cd38ca25e572561b4 [838] O61 - LFC:Last File Created 23/02/2013 - 18:05:53 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\b0d04a379326cc971538f3ecc6e4945d [1078] O61 - LFC:Last File Created 23/02/2013 - 18:05:54 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\313c238dc888c75cb26d7ff7a7f4b20d [1078] O61 - LFC:Last File Created 23/02/2013 - 18:05:54 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\8ac482009c24f4e3c08ceab6ad53837b [15949] O61 - LFC:Last File Created 23/02/2013 - 18:05:56 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\4d112a27a725b7d2d9e7487c4c114214 [1210] O61 - LFC:Last File Created 23/02/2013 - 18:05:59 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\8ac482009c24f4e3c08ceab6ad53837b.transformed [18011] O61 - LFC:Last File Created 23/02/2013 - 18:06:00 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\0b12654c5711f7cde49ae8c25f3da38c [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:00 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\7f26d2753138a5ebec0c48f6ece74ecb [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:02 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\26082a533fcc92d401bc2561cd0ec0ed [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:02 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\e451021fc5c21df4aac3dabe09e5aa56 [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:03 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\5d5ae10d9dbf6c32b9e724ee97183bb1 [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:09 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\a20e8ebab148d9d1cfe60526563c913e [434] O61 - LFC:Last File Created 23/02/2013 - 18:06:13 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\45871bd28c8dbfbcc709dfea23e79db8 [822] O61 - LFC:Last File Created 23/02/2013 - 18:06:13 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\946f8b91f4c2038513723ed0309837da [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:13 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\a979131310e0571b43ae6013f1b1271c [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:13 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\bf4eb04660a6d757badf2b5a87ce1664 [170] O61 - LFC:Last File Created 23/02/2013 - 18:06:13 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\c55aafcdfbc1b6c879184ff7c971e100 [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:13 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\e317a556707197fcc3cea7c5baa6355b [822] O61 - LFC:Last File Created 23/02/2013 - 18:06:14 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\336bc4e68681b52d6f56a2b42c26f92b [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:14 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\7cde12a35df366d4aa534b69b453c92e [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:15 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\019297370dd04ff1c46d01cfc859e6aa [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:15 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\2079d31e92813551c2cb0156526d49e6 [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:15 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\5c0fdd894ec6e7d8f1c82473519d4c40 [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:15 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\665dd649699b9f8bec71b76234520468 [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:16 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\19c29f5d453bb833f7bb6688c807d4b4 [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:16 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\86c6104962061240b99f7e101b33edb0 [1032] O61 - LFC:Last File Created 23/02/2013 - 18:06:16 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\991da48f15dc91020b5b839ffbcc1ec4 [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:16 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\af684ac0d2d5530df5c289fe5a957df2 [1078] O61 - LFC:Last File Created 23/02/2013 - 18:06:16 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\f0097b7e4ba2bcce49b73ed0745e00d4 [1078] O61 - LFC:Last File Created 23/02/2013 - 18:16:43 ---A- C:\Users\coco\AppData\Local\Temp\2843305.od [134] O61 - LFC:Last File Created 23/02/2013 - 18:16:43 ---A- C:\Users\coco\AppData\Local\Temp\CVR6299.tmp.cvr [0] O61 - LFC:Last File Created 23/02/2013 - 18:16:51 ---A- C:\Users\coco\AppData\Local\Temp\~DF289911A826BE4156.TMP [16384] O61 - LFC:Last File Created 23/02/2013 - 18:24:13 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\1627ab36256594aa1e39d13b3ecfd053 [44] O61 - LFC:Last File Created 23/02/2013 - 18:48:25 ---A- C:\Users\coco\AppData\Local\Temp\Low\FCTB000062781\cache-coco\tbshot.toolbar.bmp [95382] O61 - LFC:Last File Created 23/02/2013 - 18:59:04 ---A- C:\Users\coco\AppData\Roaming\Microsoft\Office\Recent\Bureau.LNK [874] O61 - LFC:Last File Created 23/02/2013 - 18:59:04 ---A- C:\Users\coco\AppData\Roaming\Microsoft\Office\Recent\ordi.LNK [994] O61 - LFC:Last File Created 23/02/2013 - 18:59:04 --H-- C:\Users\coco\AppData\Roaming\Microsoft\Office\Recent\index.dat [1027] O61 - LFC:Last File Created 23/02/2013 - 18:59:05 ---A- C:\Users\coco\AppData\Roaming\Microsoft\Word\Enregistrement automatique deordi.asd [350720] O61 - LFC:Last File Created 23/02/2013 - 19:42:46 ---A- C:\Users\coco\AppData\Local\ATI\ACE\Profiles.xml [13451] O61 - LFC:Last File Created 23/02/2013 - 20:15:13 ---A- C:\Users\coco\AppData\Roaming\Toshiba\ReelTime\Backup\ReelTimeMonitorData.dat [8202] O61 - LFC:Last File Created 23/02/2013 - 20:30:13 ---A- C:\Users\coco\AppData\Roaming\Toshiba\ReelTime\ReelTimeMonitorData.dat [8292] ~ Scan Files in 09mn 12s ---\\ Liste des outils de nettoyage (O63) O63 - Logiciel: Ad-Remover par C_XX - (.C_XX.) [HKLM] -- Ad-Remover O63 - Logiciel: ZHPDiag 1.3.5 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 ~ Scan ADS in 00mn 00s ---\\ Liste des services Legacy (O64) O64 - Services: CurCS - 27/07/2010 - C:\Windows\System32\DRIVERS\atikmdag.sys (amdkmdag) .(.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) - LEGACY_AMDKMDAG O64 - Services: CurCS - 07/10/2009 - C:\Windows\System32\DRIVERS\amdsata.sys (amdsata) .(.Advanced Micro Devices - AHCI 1.2 Device Driver.) - LEGACY_AMDSATA O64 - Services: CurCS - 30/10/2012 - C:\Windows\System32\Drivers\aswFsBlk.sys (aswFsBlk) .(.AVAST Software - avast! File System Access Blocking Driver.) - LEGACY_ASWFSBLK O64 - Services: CurCS - 30/10/2012 - C:\Windows\system32\drivers\aswMonFlt.sys (aswMonFlt) .(.AVAST Software - avast! File System Minifilter for Windows 2.) - LEGACY_ASWMONFLT O64 - Services: CurCS - 15/10/2012 - C:\Windows\system32\Drivers\aswrdr2.sys (aswRdr) .(.AVAST Software - avast! WFP Redirect Driver.) - LEGACY_ASWRDR O64 - Services: CurCS - 30/10/2012 - C:\Windows\System32\Drivers\aswSnx.sys (aswSnx) .(.AVAST Software - avast! Virtualization Driver.) - LEGACY_ASWSNX O64 - Services: CurCS - 30/10/2012 - C:\Windows\System32\Drivers\aswSP.sys (aswSP) .(.AVAST Software - avast! self protection module.) - LEGACY_ASWSP O64 - Services: CurCS - 30/10/2012 - C:\Windows\System32\Drivers\aswTdi.sys (aswTdi) .(.AVAST Software - avast! TDI Filter Driver.) - LEGACY_ASWTDI O64 - Services: CurCS - 22/03/2010 - C:\Windows\System32\DRIVERS\LPCFilter.sys (LPCFilter) .(.COMPAL ELECTRONIC INC. - LPCFilter.) - LEGACY_LPCFILTER O64 - Services: CurCS - 10/06/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV ~ Scan Services in 00mn 00s ---\\ File Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\coco\AppData\Local\Google\Chrome\Application\chrome.exe O67 - Shell Spawning: <.bat> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe O67 - Shell Spawning: <.cmd> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKCR\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKCR\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\coco\AppData\Local\Google\Chrome\Application\chrome.exe O67 - Shell Spawning: <.js> [HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe ~ Scan Keys in 00mn 00s ---\\ Start Menu Internet (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\coco\AppData\Local\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe ~ Scan Keys in 00mn 00s ---\\ Search Browser Infection (O69) O69 - SBI: SearchScopes [HKCU] ${searchCLSID} - (@ieframe.dll,-12512) - http://search.live.com O69 - SBI: SearchScopes [HKCU] {797CAF26-A0BD-47D4-AF61-C9C308EB3ADE} - (eBay) - http://rover.ebay.com O69 - SBI: SearchScopes [HKCU] {F1E02B1B-D360-467E-AA5A-CDA48D1D6740} [DefaultScope] - (Web Search) - http://ws.infospace.com ~ Scan Keys in 00mn 00s ---\\ Crack & Keygen Files (O82) C:\Users\coco\Documents\ZZ CIEL F.EGO\Keygen-ciel la solution\keygen.exe C:\Users\coco\Documents\ZZ CIEL F.EGO\Keygen-ciel la solution\keygen.exe ~ Scan Files in 02mn 05s ---\\ Recherche des services démarrés par Svchost (O83) O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [236032] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [777728] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [853504] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [679424] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [99328] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [344064] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [64512] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [359424] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [316928] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [680960] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [2428952] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [849920] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [370688] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [569344] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [30720] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70656] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [156672] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [67584] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [242688] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [121856] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136704] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1110016] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [90624] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84480] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [209920] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [44544] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864] ~ Scan Services in 00mn 01s ---\\ Recherche particuliere à la racine de certains dossiers (O84) [MD5.B3772E8F389CCC70A059350DAA5AD804] [SPRF][11/07/2012] (...) -- C:\ProgramData\ezsidmv.dat [56] [MD5.A4354D5C44121304E5561B8449B7EE91] [SPRF][12/11/2010] (.Microsoft Corporation - Barre d'outils Bing.) -- C:\Users\coco\AppData\Local\Temp\MSN5E5E.exe [469768] [MD5.BC0D93D7AEC1A9CD84EF1EE0092A83A7] [SPRF][20/02/2008] (...) -- C:\Users\coco\AppData\Local\Temp\ResetDevice.exe [7168] [MD5.295D9171F5404DA955D20A0F9248C4DE] [SPRF][02/12/2009] (...) -- C:\Users\coco\AppData\Local\Temp\SysConfig.dat [321] [MD5.719AF0A81B65A4AEB4BA7BD6644BB1A7] [SPRF][22/12/2010] (...) -- C:\Users\coco\AppData\Local\Temp\WLM2011Installer.exe [1289216] [MD5.64281AF23447705DAB84E1A198D920C7] [SPRF][22/12/2010] (.Microsoft Corporation - Windows Live Installer.) -- C:\Users\coco\AppData\Local\Temp\WLM_2011.exe [1289576] [MD5.D41D8CD98F00B204E9800998ECF8427E] [SPRF][22/12/2010] (...) -- C:\Users\coco\AppData\Local\Temp\zpqoxex_.dll [0] [MD5.970E08471401B7C03788DC850C682574] [SPRF][03/08/2012] (...) -- C:\Users\coco\AppData\Local\Temp\{2447FF39-3232-4DAF-B4EE-9855B40B059D}-21.0.1180.60_20.0.1132.57_chrome_updater.exe [15973] [MD5.CAD865F3F2C95B578BE7DF6F0AAEC079] [SPRF][04/08/2012] (...) -- C:\Users\coco\AppData\Local\Temp\{D6E77080-5E5D-423E-93AC-3F6DBC5EE616}-21.0.1180.60_20.0.1132.57_chrome_updater.exe [1189125] [MD5.A079519FFD3857560FA11EFBA92C0474] [SPRF][22/02/2013] (...) -- C:\Users\coco\Desktop\adwcleaner0 (1).exe [587671] [MD5.D8EB82F85F04147BA4F5AC41128DF5EE] [SPRF][24/10/2012] (.Pas de propriétaire - This package provides the Texas Instruments USB 3.0 XHCI Hos.) -- C:\Users\coco\Desktop\sp57873.exe [1196640] [MD5.98FBE98D57147D393B4A23FE744C9A93] [SPRF][23/02/2013] (.Nicolas Coolman - ZHPDiag.) -- C:\Users\coco\Desktop\ZHPDiag2.exe [5402780] ~ Scan Files in 00mn 00s ---\\ Firewall Active Exception List (FirewallRules) (O87) O87 - FAEL: "WMPNSS-In-UDP-NoScope" |In - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-Out-UDP-NoScope" |Out - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-In-UDP" |In - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-Out-UDP" |Out - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "NetPres-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.) O87 - FAEL: "NetPres-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.) O87 - FAEL: "NetPres-WSD-In-UDP" |In - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.) O87 - FAEL: "NetPres-WSD-Out-UDP" |Out - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.) O87 - FAEL: "NetPres-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.) O87 - FAEL: "NetPres-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.) O87 - FAEL: "{D4368A79-2750-4765-91AD-84FD8A143832}" |In - Public - P6 - TRUE | .(...) -- C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe (.not file.) O87 - FAEL: "{802A0C95-BFCB-4376-AB0E-A528F762FF69}" |In - Public - P17 - TRUE | .(...) -- C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe (.not file.) O87 - FAEL: "{95E17011-030B-4EBB-A095-459C7E48EEA8}" | In - None - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe O87 - FAEL: "{60648F35-2BEC-4A29-9157-80678D6ADA62}" |Out - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "{AA451CC6-AB35-4BEC-9C9D-E6F33F36CB82}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "{358282F8-3460-44B3-B64D-AA2E2F38F63F}" |Out - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "{3EB73856-CC7E-4D39-A44D-0211F86843E9}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "{2A90DC9E-A767-4C93-B0C9-A6518DE9979F}" | In - Public - P6 - TRUE | .(.FreeCause Inc. - FreeCause Vista TroubleShooter application.) -- C:\Program Files (x86)\Gamers Unite! Snag Bar\TroubleShooter.exe O87 - FAEL: "{B2E4B838-AC51-4E03-B9E2-A007298EDD91}" | In - Public - P17 - TRUE | .(.FreeCause Inc. - FreeCause Vista TroubleShooter application.) -- C:\Program Files (x86)\Gamers Unite! Snag Bar\TroubleShooter.exe O87 - FAEL: "{EAD00333-B7A1-4E33-A2D1-2A99760B4CE2}" | In - Public - P6 - TRUE | .(.FreeCause Inc. - FreeCause Toolbar updater application.) -- C:\Program Files (x86)\Gamers Unite! Snag Bar\ToolbarUpdate.exe O87 - FAEL: "{E28987C4-BC0E-4D52-AB20-20A082C1B340}" | In - Public - P17 - TRUE | .(.FreeCause Inc. - FreeCause Toolbar updater application.) -- C:\Program Files (x86)\Gamers Unite! Snag Bar\ToolbarUpdate.exe ~ Scan Firewall in 00mn 01s ---\\ Scan Additionnel (O88) Database Version : v2.10854 - (23/02/2013) Clés trouvées (Keys found) : 13 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 0 Fichiers trouvés (Files found) : 0 [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] =>Toolbar.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =>Toolbar.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =>Toolbar.Agent [HKLM\Software\Classes\Installer\Features\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent [HKLM\Software\Classes\Installer\Products\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Classes\Installer\Features\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Classes\Installer\Products\0E9201899CF73FC4BA93F631631229A1] =>Toolbar.Agent [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{981029E0-7FC9-4CF3-AB39-6F133621921A}] =>Toolbar.Agent [HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] =>Toolbar.Bing [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] =>Toolbar.Bing ~ Scan Additionnel in 00mn 16s ---\\ Recherche détournement de DNS routeur (O89) (None) ---\\ Product Upgrade Codes (O90) O90 - PUC: "00004159070000000000000000F01FEC" . (.Microsoft Office 2010.) -- C:\Windows\Installer\{95140000-0070-0000-0000-0000000FF1CE}\oobeicon.exe O90 - PUC: "0146DDDD9B2C7CB7A339D051A50EE752" . (.Catalyst Control Center InstallProxy.) -- C:\Windows\Installer\{DDDD6410-C2B9-7BC7-3A93-0D155AE07E25}\ARPPRODUCTICON.exe O90 - PUC: "076CFAAAB965F2A4284B2449E5D03EFE" . (.Windows Live Writer.) -- C:\Windows\Installer\{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}\ApplicationIcon.ico O90 - PUC: "0868F3CCA8A21B5985E4AEB4EDD07F38" . (.ccc-utility64.) -- C:\Windows\Installer\{CC3F8680-2A8A-95B1-584E-EA4BDE0DF783}\ARPPRODUCTICON.exe O90 - PUC: "0E9201899CF73FC4BA93F631631229A1" . (.Skype Toolbars.) -- C:\Windows\Installer\{981029E0-7FC9-4CF3-AB39-6F133621921A}\IconUninstallIco O90 - PUC: "11F12B5E3396B0E42AC597363E0CD711" . (.Windows Live Messenger.) -- C:\Windows\Installer\{E5B21F11-6933-4E0B-A25C-7963E3C07D11}\MsblIco.Exe O90 - PUC: "1C4235E6CF4867F4A9A36CE5708FE06E" . (.Complément Messenger.) -- C:\Windows\Installer\{6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}\CompanionIcon O90 - PUC: "1D034B0FAA6BD374B960AAD30DF10D8B" . (.Microsoft SQL Server 2005 Compact Edition [ENU].) -- C:\Windows\Installer\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}\ProductIcon O90 - PUC: "1F079377ABE54744DAEEE13A0B5A4929" . (.TOSHIBA Recovery Media Creator Reminder.) -- C:\Windows\Installer\{773970F1-5EBA-4474-ADEE-1EA3B0A59492}\ARPPRODUCTICON.exe O90 - PUC: "21C118429A4FF0D448497A8BEF6421C3" . (.TOSHIBA ReelTime.) -- C:\Windows\Installer\{24811C12-F4A9-4D0F-8494-A7B8FE46123C}\ARPPRODUCTICON.exe O90 - PUC: "227C12A7952F67947BAA66855EDFDEFA" . (.Google Drive.) -- C:\Windows\Installer\{7A21C722-F259-4976-B7AA-6658E5FDEDAF}\DriveIcon O90 - PUC: "2A7527EE2A93F2D4D9CA9F2FB5A81E8D" . (.Skype™ 5.10.) -- C:\Windows\Installer\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}\SkypeIcon.exe O90 - PUC: "2D85BD6B8E7EF0B5568F7B76310CFA57" . (.ATI Catalyst Install Manager.) -- C:\Windows\Installer\{B6DB58D2-E7E8-5B0F-65F8-B76713C0AF75}\ARPPRODUCTICON.exe O90 - PUC: "36CC6A5FDEB2D419405E712074E176D5" . (.ccc-core-static.) -- C:\Windows\Installer\{F5A6CC63-2BED-914D-04E5-1702471E675D}\ARPPRODUCTICON.exe O90 - PUC: "39171C0491CBF9BC53AD4AF4B9A625F0" . (.Catalyst Control Center Graphics Previews Common.) -- C:\Windows\Installer\{40C17193-BC19-CB9F-35DA-A44F9B6A520F}\ARPPRODUCTICON.exe O90 - PUC: "545AF76F5E8D9024681BEA0E541D00F3" . (.TOSHIBA Face Recognition.) -- C:\Windows\Installer\{F67FA545-D8E5-4209-86B1-AEE045D1003F}\ARPPRODUCTICON.exe O90 - PUC: "54FFA2B3E2C1445E4A089AAC34CF9877" . (.Catalyst Control Center Localization All.) -- C:\Windows\Installer\{3B2AFF45-1C2E-E544-A480-A9CA43FC8977}\ARPPRODUCTICON.exe O90 - PUC: "60BBB56BE8F15F84A8450B429A1EF5FD" . (.TOSHIBA Recovery Media Creator.) -- C:\Windows\Installer\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}\ARPPRODUCTICON.exe O90 - PUC: "651E4B155A414094A94E1BAAA2E064EB" . (.TOSHIBA Supervisor Password.) -- C:\Windows\Installer\{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}\ARPPRODUCTICON.exe O90 - PUC: "68AB67CA7DA76301B744AA0100000010" . (.Adobe Reader X (10.1.5) - Français.) -- C:\Windows\Installer\{AC76BA86-7AD7-1036-7B44-AA1000000001}\SC_Reader.ico O90 - PUC: "75FDF62FE3848C249A9CEE1EDE2B650E" . (.TOSHIBA Media Controller Plug-in.) -- C:\Windows\Installer\{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}\ARPPRODUCTICON.exe O90 - PUC: "7DF8862129BCB5A4EB4EC5E8504734F4" . (.Utility Common Driver.) -- C:\Windows\Installer\{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}\ARPPRODUCTICON.exe O90 - PUC: "8442234DFA6B61348B958D0A8ED4BC83" . (.TOSHIBA HDD/SSD Alert.) -- C:\Windows\Installer\{D4322448-B6AF-4316-B859-D8A0E84DCB38}\ARPPRODUCTICON.exe O90 - PUC: "8FFFC660FB2109346A37579FE5FF81E8" . (.TOSHIBA Value Added Package.) -- C:\Windows\Installer\{066CFFF8-12BF-4390-A673-75F95EFF188E}\ARPPRODUCTICON.exe O90 - PUC: "963AAF0E3E0B8B844974843701B30021" . (.TOSHIBA ConfigFree.) -- C:\Windows\Installer\{E0FAA369-B0E3-48B8-9447-4873103B0012}\ARPPRODUCTICON.exe O90 - PUC: "9E107CC9BF97BE9109C73337D0D64905" . (.Catalyst Control Center Graphics Previews Vista.) -- C:\Windows\Installer\{9CC701E9-79FB-19EB-907C-33730D6D9450}\ARPPRODUCTICON.exe O90 - PUC: "A0BC5702F62DAAD44B42059792B634AB" . (.Windows Live FolderShare.) -- C:\Windows\Installer\{2075CB0A-D26F-4DAA-B424-5079296B43BA}\FolderShare48x48.ico O90 - PUC: "D4739725EF78978439581F2787BE9B3D" . (.TOSHIBA Hardware Setup.) -- C:\Windows\Installer\{5279374D-87FE-4879-9385-F17278EBB9D3}\ARPPRODUCTICON.exe O90 - PUC: "D7314F9862C648A4DB8BE2A5B47BE100" . (.Microsoft Silverlight.) -- c:\Windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ARPIcon O90 - PUC: "E5ABB026848F65D4B8AD85E44485C4E5" . (.TOSHIBA Flash Cards Support Utility.) -- C:\Windows\Installer\{620BBA5E-F848-4D56-8BDA-584E44584C5E}\ARPPRODUCTICON.exe O90 - PUC: "E8D7C56ED681B484EB8AED0F33C16E00" . (.TRORMCLauncher.) -- C:\Windows\Installer\{E65C7D8E-186D-484B-BEA8-DEF0331CE600}\ARPPRODUCTICON.exe O90 - PUC: "F20E0AD5B079B424FB1415A305814E0C" . (.TOSHIBA Disc Creator.) -- C:\Windows\Installer\{5DA0E02F-970B-424B-BF41-513A5018E4C0}\ARPPRODUCTICON.exe O90 - PUC: "FA81541CF0A193D4081196AB0AC13D08" . (.TOSHIBA Bulletin Board.) -- C:\Windows\Installer\{C14518AF-1A0F-4D39-8011-69BAA01CD380}\ARPPRODUCTICON.exe O90 - PUC: "FC587DB87C0328142B05D0F5EC874DDD" . (.Catalyst Control Center - Branding.) -- C:\Windows\Installer\{8BD785CF-30C7-4182-B250-0D5FCE78D4DD}\ARPPRODUCTICON.exe ~ Scan Files in 00mn 00s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SR - | Auto 18/12/2012 65192 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe SR - | Auto 27/07/2010 203264 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe SR - | Auto 30/10/2012 44808 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe SR - | Auto 28/01/2010 249200 | (cfWiMAXService) . (.TOSHIBA CORPORATION.) - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe SR - | Auto 10/03/2009 46448 | (ConfigFree Service) . (.TOSHIBA CORPORATION.) - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe SS - | Demand 30/09/2010 246520 | (GameConsoleService) . (.WildTangent, Inc..) - C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe SS - | Auto 25/01/2013 136176 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 25/01/2013 136176 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SR - | Auto 27/08/2010 1811456 | (IconMan_R) . (.Realsil Microelectronics Inc..) - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe SS - | Auto 13/07/2012 160944 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe SS - | Demand 11/05/2010 124368 | (TemproMonitoringService) . (.Toshiba Europe GmbH.) - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe SR - | Demand 01/07/2010 51576 | (TMachInfo) . (.TOSHIBA Corporation.) - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe SR - | Auto 28/07/2009 140632 | (TODDSrv) . (.TOSHIBA Corporation.) - C:\Windows\system32\TODDSrv.exe SR - | Auto 25/05/2010 489384 | (TosCoSrv) . (.TOSHIBA Corporation.) - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe SR - | Demand 05/02/2010 137560 | (TOSHIBA HDD SSD Alert Service) . (.TOSHIBA Corporation.) - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Scan Services in 00mn 03s ---\\ Recherche Master Boot Record Infection (MBR)(O80) Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net ~ Scan MBR in 00mn 02s ---\\ Recherche Master Boot Record Infection (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by coco at 23/02/2013 20:41:31 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ Scan MBR in 00mn 04s End of the scan (1755 lines in 12mn 31s)(2)