OTL logfile created on: 13/10/2013 17:32:47 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\ELLAFI KAMEL\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16686) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 3,73 Gb Total Physical Memory | 2,41 Gb Available Physical Memory | 64,75% Memory free 7,46 Gb Paging File | 5,66 Gb Available in Paging File | 75,95% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 282,99 Gb Total Space | 158,44 Gb Free Space | 55,99% Space Free | Partition Type: NTFS Computer Name: ELLAFIKAMEL-PC | User Name: ELLAFI KAMEL | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - C:\Users\ELLAFI KAMEL\Downloads\OTL (1).exe (OldTimer Tools) PRC - C:\Program Files (x86)\ooVoo\ooVoo.exe (ooVoo LLC) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) PRC - C:\Users\ELLAFI KAMEL\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation) PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.) PRC - C:\Users\ELLAFI KAMEL\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (Facebook) PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe () PRC - C:\ProgramData\Dim@net\OnlineUpdate\ouc.exe () PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org) PRC - C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe (CyberLink Corp.) PRC - C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe (CyberLink Corp.) PRC - C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe () PRC - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated) PRC - C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (NTI Corporation) PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated) PRC - C:\ProgramData\DatacardService\DCSHelper.exe (Huawei Technologies Co., Ltd.) PRC - C:\Downloads\vspdfprsrv.exe () PRC - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\764054efc88f51b54c8d7e44df26b671\System.Data.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5aa44bce7933e4de09d935848f868a4b\System.Drawing.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\09db78d6068543df01862a023aca785a\System.Xml.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5d22a30e587e2cac106b81fb351e7c08\System.ni.dll () MOD - C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\8c20095bd7d46cdfa7933eb258a07daa\Accessibility.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll () MOD - C:\Users\ELLAFI KAMEL\AppData\Local\Facebook\Messenger\2.1.4814.0\libcef.dll () MOD - C:\Users\ELLAFI KAMEL\AppData\Local\Facebook\Messenger\2.1.4814.0\CefSharp.dll () MOD - C:\Users\ELLAFI KAMEL\AppData\Local\Facebook\Messenger\2.1.4814.0\CefSharp.WinForms.dll () MOD - C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll () MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll () MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll () MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll () MOD - C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\CLNetMediaDMA.dll () MOD - C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe () MOD - C:\Downloads\vspdfprsrv.exe () MOD - C:\Downloads\expertpdfcore140.bpl () MOD - C:\Downloads\bblite140.bpl () MOD - C:\Downloads\visage140.bpl () MOD - C:\Downloads\vsmisc140.bpl () MOD - C:\Downloads\TMSlite140.bpl () MOD - C:\Downloads\vsgdi.dll () MOD - C:\Downloads\PKIECtrl140.bpl () MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll () MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_fr_b77a5c561934e089\mscorlib.resources.dll () MOD - C:\Downloads\js32.dll () [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV:[b]64bit:[/b] - (NisSrv) -- c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) SRV:[b]64bit:[/b] - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) SRV:[b]64bit:[/b] - (ePowerSvc) -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated) SRV:[b]64bit:[/b] - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD) SRV:[b]64bit:[/b] - (Live Updater Service) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated) SRV:[b]64bit:[/b] - (CxAudMsg) -- C:\Windows\SysNative\CxAudMsg64.exe (Conexant Systems Inc.) SRV:[b]64bit:[/b] - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation) SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies) SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) SRV - (RealNetworks Downloader Resolver Service) -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe () SRV - (Dim@net. RunOuc) -- C:\Program Files (x86)\Dim@net\UpdateDog\ouc.exe () SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.) SRV - (EgisTec Ticket Service) -- C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. ) SRV - (GREGService) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated) SRV - (NTI IScheduleSvc) -- C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (NTI Corporation) SRV - (HWDeviceService64.exe) -- C:\ProgramData\DatacardService\HWDeviceService64.exe () SRV - (GamesAppService) -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.) SRV - (NOBU) -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG) DRV:[b]64bit:[/b] - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG) DRV:[b]64bit:[/b] - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation) DRV:[b]64bit:[/b] - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG) DRV:[b]64bit:[/b] - (NisDrv) -- C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation) DRV:[b]64bit:[/b] - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.) DRV:[b]64bit:[/b] - (ew_usbenumfilter) -- C:\Windows\SysNative\drivers\ew_usbenumfilter.sys (Huawei Technologies Co., Ltd.) DRV:[b]64bit:[/b] - (huawei_cdcacm) -- C:\Windows\SysNative\drivers\ew_jucdcacm.sys (Huawei Technologies Co., Ltd.) DRV:[b]64bit:[/b] - (huawei_enumerator) -- C:\Windows\SysNative\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.) DRV:[b]64bit:[/b] - (ewusbmbb) -- C:\Windows\SysNative\drivers\ewusbwwan.sys (Huawei Technologies Co., Ltd.) DRV:[b]64bit:[/b] - (ew_hwusbdev) -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.) DRV:[b]64bit:[/b] - (hwdatacard) -- C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.) DRV:[b]64bit:[/b] - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation) DRV:[b]64bit:[/b] - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation) DRV:[b]64bit:[/b] - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:[b]64bit:[/b] - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV:[b]64bit:[/b] - (Netaapl) -- C:\Windows\SysNative\drivers\netaapl64.sys (Apple Inc.) DRV:[b]64bit:[/b] - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:[b]64bit:[/b] - (mwlPSDVDisk) -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.) DRV:[b]64bit:[/b] - (mwlPSDFilter) -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.) DRV:[b]64bit:[/b] - (mwlPSDNServ) -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.) DRV:[b]64bit:[/b] - (NTIDrvr) -- C:\Windows\SysNative\drivers\NTIDrvr.sys (NTI Corporation) DRV:[b]64bit:[/b] - (UBHelper) -- C:\Windows\SysNative\drivers\UBHelper.sys (NTI Corporation) DRV:[b]64bit:[/b] - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:[b]64bit:[/b] - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:[b]64bit:[/b] - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.) DRV:[b]64bit:[/b] - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.) DRV:[b]64bit:[/b] - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.) DRV:[b]64bit:[/b] - (CnxtHdAudService) -- C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.) DRV:[b]64bit:[/b] - (L1C) -- C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.) DRV:[b]64bit:[/b] - (usbfilter) -- C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices) DRV:[b]64bit:[/b] - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:[b]64bit:[/b] - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated) DRV:[b]64bit:[/b] - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.) DRV:[b]64bit:[/b] - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:[b]64bit:[/b] - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:[b]64bit:[/b] - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:[b]64bit:[/b] - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:[b]64bit:[/b] - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:[b]64bit:[/b] - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:[b]64bit:[/b] - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKCU\..\SearchScopes,DefaultScope = IE - HKCU\..\SearchScopes\{0B3FBB26-5C63-40EF-90B5-0886374DF97B}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=OVO2&o=APN10379&src=kw&q={searchTerms}&locale=&apn_ptnrs=^ABE&apn_dtid=^YYYYYY^YY^FR&apn_uid=87174c5b-b525-4506-b518-8c423afcf6af&apn_sauid=809A6268-CD7A-4166-B4B2-817D130BEAD3 IE - HKCU\..\SearchScopes\{2FFDFB67-770A-4F89-87AC-4D96BF8F4B39}: "URL" = http://search.softonic.com/MON00013/tb_v1?q={searchTerms}&SearchSource=4&cc= IE - HKCU\..\SearchScopes\{8A244612-A1F7-11E0-95C0-E71F4824019B}: "URL" = http://badoo.com/startpage/?source=bsb&q={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1 FF - prefs.js..browser.search.selectedEngine: "Hola Search" FF - user.js - File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.1.18: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.1.18: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll () FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\ELLAFI KAMEL\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\ELLAFI KAMEL\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\ELLAFI KAMEL\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Users\ELLAFI KAMEL\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DAC3F861-B30D-40dd-9166-F4E75327FAC7}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/03/28 23:22:04 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/03/28 23:22:04 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/09/07 15:18:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ELLAFI KAMEL\AppData\Roaming\mozilla\Extensions [2013/10/03 14:00:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ELLAFI KAMEL\AppData\Roaming\mozilla\Firefox\Profiles\nv98ki4c.default\Extensions [2013/09/13 12:27:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\Extensions [2013/09/07 15:00:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions [2013/09/07 15:00:51 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [ArcadeMovieService] C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe (CyberLink Corp.) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [vspdfprsrv.exe] C:\Downloads\vspdfprsrv.exe () O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.) O4 - HKCU..\Run: [Badoo Desktop] C:\ProgramData\Badoo\Badoo Desktop\1.6.55.1183\Badoo.Desktop.exe File not found O4 - HKCU..\Run: [Facebook Update] C:\Users\ELLAFI KAMEL\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files (x86)\ooVoo\oovoo.exe (ooVoo LLC) O4 - HKCU..\Run: [SkyDrive] C:\Users\ELLAFI KAMEL\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation) O4 - HKCU..\RunOnce: [Uninstall C:\Users\ELLAFI KAMEL\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ELLAFI KAMEL\AppData\Local\Microsoft\SkyDrive\17.0.2003.1112\amd64" File not found O4 - HKCU..\RunOnce: [Uninstall C:\Users\ELLAFI KAMEL\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ELLAFI KAMEL\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64" File not found O4 - HKCU..\RunOnce: [Uninstall C:\Users\ELLAFI KAMEL\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ELLAFI KAMEL\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\amd64" File not found O4 - HKCU..\RunOnce: [Uninstall C:\Users\ELLAFI KAMEL\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\amd64] C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\ELLAFI KAMEL\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\amd64" File not found O4 - Startup: C:\Users\ELLAFI KAMEL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk = C:\Users\ELLAFI KAMEL\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (Facebook) O4 - Startup: C:\Users\ELLAFI KAMEL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{41B2E757-6E99-416A-9B8E-7B4CECBE0113}: NameServer = 196.203.82.4 8.8.8.8 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{483FA58C-2444-4FC7-9788-B60456CAFD24}: NameServer = 196.203.82.4 8.8.8.8 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6180DE57-765C-40C6-BCB8-525842CB7D7B}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{90EF465D-D6BD-48CF-A1ED-33B50623BEF6}: DhcpNameServer = 172.20.2.39 172.20.2.10 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E7D4A097-BDEF-458F-95EC-15D228775D7B}: NameServer = 196.203.80.4 196.203.82.4 O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msdaipp - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msdaipp\oledb - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-itss - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\mso-offdap - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\mso-offdap11 - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18:[b]64bit:[/b] - Protocol\Filter\text/xml - No CLSID value found O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{695da155-3c0c-11e2-8aec-dc0ea11e1874}\Shell - "" = AutoRun O33 - MountPoints2\{695da155-3c0c-11e2-8aec-dc0ea11e1874}\Shell\AutoRun\command - "" = E:\.\Setup.exe AUTORUN=1 O33 - MountPoints2\{a15e5587-ee7e-11e2-bf56-dc0ea11e1874}\Shell - "" = AutoRun O33 - MountPoints2\{a15e5587-ee7e-11e2-bf56-dc0ea11e1874}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{f7732ec9-3feb-11e2-b945-74de2bfa06c3}\Shell - "" = AutoRun O33 - MountPoints2\{f7732ec9-3feb-11e2-b945-74de2bfa06c3}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{f7732f63-3feb-11e2-b945-001e101f82a0}\Shell - "" = AutoRun O33 - MountPoints2\{f7732f63-3feb-11e2-b945-001e101f82a0}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{f7733109-3feb-11e2-b945-001e101f82a0}\Shell - "" = AutoRun O33 - MountPoints2\{f7733109-3feb-11e2-b945-001e101f82a0}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{f7733129-3feb-11e2-b945-001e101f82a0}\Shell - "" = AutoRun O33 - MountPoints2\{f7733129-3feb-11e2-b945-001e101f82a0}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{f773313d-3feb-11e2-b945-001e101f82a0}\Shell - "" = AutoRun O33 - MountPoints2\{f773313d-3feb-11e2-b945-001e101f82a0}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{f77331ea-3feb-11e2-b945-001e101f82a0}\Shell - "" = AutoRun O33 - MountPoints2\{f77331ea-3feb-11e2-b945-001e101f82a0}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\E\Shell - "" = AutoRun O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk - - File not found MsConfig:64bit - StartUpFolder: C:^Users^ELLAFI KAMEL^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Messenger.lnk - - File not found MsConfig:64bit - StartUpReg: [b]Adobe ARM[/b] - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) MsConfig:64bit - StartUpReg: [b]APSDaemon[/b] - hkey= - key= - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) MsConfig:64bit - StartUpReg: [b]b235738ed751274fa34b9f4a53aa34a5[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]BackupManagerTray[/b] - hkey= - key= - C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation) MsConfig:64bit - StartUpReg: [b]iTunesHelper[/b] - hkey= - key= - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) MsConfig:64bit - StartUpReg: [b]LManager[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]mcui_exe[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]msnmsgr[/b] - hkey= - key= - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation) MsConfig:64bit - StartUpReg: [b]Norton Online Backup[/b] - hkey= - key= - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation) MsConfig:64bit - StartUpReg: [b]Power Management[/b] - hkey= - key= - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated) MsConfig:64bit - StartUpReg: [b]StartCCC[/b] - hkey= - key= - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) MsConfig:64bit - StartUpReg: [b]SuiteTray[/b] - hkey= - key= - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.) MsConfig:64bit - StartUpReg: [b]SunJavaUpdateSched[/b] - hkey= - key= - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) MsConfig:64bit - StartUpReg: [b]SweetIM[/b] - hkey= - key= - File not found MsConfig:64bit - State: "startup" - Reg Error: Key error. MsConfig:64bit - State: "bootini" - Reg Error: Key error. ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX:[b]64bit:[/b] {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX:[b]64bit:[/b] {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX:[b]64bit:[/b] {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Dossiers Web ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP Drivers32:[b]64bit:[/b] msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.) PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin CREATERESTOREPOINT Restore point Set: OTL Restore Point [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013/10/13 15:26:39 | 000,000,000 | ---D | C] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Malwarebytes [2013/10/13 15:26:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013/10/13 15:26:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2013/10/13 15:25:53 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2013/10/13 15:25:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2013/10/13 15:05:42 | 000,000,000 | ---D | C] -- C:\_OTL [2013/10/13 12:59:35 | 000,000,000 | ---D | C] -- C:\AdwCleaner [2013/10/13 12:50:46 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\davclnt.dll [2013/10/13 12:50:40 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidclass.sys [2013/10/13 12:50:40 | 000,032,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidparse.sys [2013/10/13 12:50:25 | 005,549,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe [2013/10/13 12:50:24 | 000,878,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll [2013/10/13 12:50:22 | 003,969,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe [2013/10/13 12:50:22 | 003,914,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe [2013/10/13 12:50:22 | 000,859,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdh.dll [2013/10/13 12:50:20 | 000,619,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdh.dll [2013/10/13 12:50:18 | 001,732,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll [2013/10/13 12:50:15 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll [2013/10/13 12:50:12 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2013/10/13 12:50:12 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2013/10/13 12:50:12 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2013/10/13 12:50:12 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2013/10/13 12:50:11 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [2013/10/13 12:49:33 | 000,124,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll [2013/10/13 12:49:33 | 000,102,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll [2013/10/13 12:49:23 | 000,461,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scavengeui.dll [2013/09/23 23:03:48 | 000,000,000 | ---D | C] -- C:\Users\ELLAFI KAMEL\Documents\CV et lettres des motivations [2013/09/19 23:30:57 | 000,000,000 | ---D | C] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Nico Mak Computing [2013/09/14 16:40:17 | 000,000,000 | ---D | C] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\ATI [2013/09/14 16:40:17 | 000,000,000 | ---D | C] -- C:\Users\ELLAFI KAMEL\AppData\Local\ATI [2013/09/14 16:40:17 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI [2012/02/07 20:04:05 | 054,739,704 | R--- | C] (GAMS Development Corporation ) -- C:\Program Files (x86)\Gams 22.5-32.exe [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013/10/13 17:38:51 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin [2013/10/13 17:22:01 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013/10/13 17:01:00 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-873202680-1230237582-1217159388-1000UA.job [2013/10/13 16:33:11 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/10/13 16:33:11 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/10/13 16:26:59 | 000,704,714 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat [2013/10/13 16:26:59 | 000,616,242 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013/10/13 16:26:59 | 000,130,988 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat [2013/10/13 16:26:59 | 000,106,622 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013/10/13 16:26:58 | 001,549,936 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013/10/13 16:16:50 | 000,454,104 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013/10/13 16:16:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013/10/13 16:16:10 | 3003,305,984 | -HS- | M] () -- C:\hiberfil.sys [2013/10/13 16:03:10 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-873202680-1230237582-1217159388-1000UA.job [2013/10/13 16:01:08 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-873202680-1230237582-1217159388-1000Core.job [2013/10/13 15:26:15 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2013/10/13 15:01:00 | 000,000,310 | ---- | M] () -- C:\Windows\tasks\Registry Optimizer_DEFAULT.job [2013/10/13 12:29:31 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-873202680-1230237582-1217159388-1000Core.job [2013/10/10 13:04:23 | 000,000,318 | ---- | M] () -- C:\Windows\tasks\Registry Optimizer_UPDATES.job [2013/10/09 14:23:01 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2013/10/09 14:23:01 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2013/10/08 13:09:02 | 000,002,411 | ---- | M] () -- C:\Users\ELLAFI KAMEL\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [2013/10/08 13:09:02 | 000,002,409 | ---- | M] () -- C:\Users\ELLAFI KAMEL\Desktop\Google Chrome.lnk [2013/09/19 23:30:20 | 000,001,861 | ---- | M] () -- C:\Users\Public\Desktop\ooVoo.lnk [2013/09/17 15:38:19 | 000,051,017 | ---- | M] () -- C:\Users\ELLAFI KAMEL\Documents\caf haithem.pdf [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013/10/13 15:26:15 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2013/10/13 13:45:36 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin [2013/10/03 14:09:43 | 000,454,104 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013/09/19 23:31:13 | 000,000,310 | ---- | C] () -- C:\Windows\tasks\Registry Optimizer_DEFAULT.job [2013/09/19 23:31:10 | 000,000,318 | ---- | C] () -- C:\Windows\tasks\Registry Optimizer_UPDATES.job [2013/09/17 15:38:14 | 000,051,017 | ---- | C] () -- C:\Users\ELLAFI KAMEL\Documents\caf haithem.pdf [2013/09/13 11:54:28 | 000,001,799 | ---- | C] () -- C:\Users\ELLAFI KAMEL\AppData\Local\recently-used.xbel [2012/11/15 00:47:42 | 000,257,972 | ---- | C] () -- C:\Program Files (x86)\monocalendar-0.7.2.win32.installer.exe [2012/04/06 11:01:47 | 000,000,382 | ---- | C] () -- C:\Windows\ODBC.INI [2012/02/06 21:23:56 | 001,578,010 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2012/02/01 23:51:20 | 000,000,238 | ---- | C] () -- C:\Windows\wininit.ini [2011/12/11 07:30:04 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2011/10/19 05:19:59 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [color=#E56717]========== ZeroAccess Check ==========[/color] [2009/07/14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2013/07/26 04:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 03:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< >[/color] [color=#A23BEC]< %systemroot%\*. /mp /s >[/color] [color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color] [2013/08/10 05:58:05 | 013,761,024 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\system32\ieframe.dll [1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] [color=#A23BEC]< %systemroot%\system32\drivers\​*.sys /lockedfiles >[/color] [color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color] Invalid Environment Variable: alluserprofile Invalid Environment Variable: alluserprofile [color=#A23BEC]< %appdata%\*. >[/color] [2012/02/02 18:21:15 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Adobe [2013/07/06 02:26:27 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Apple Computer [2013/09/14 16:40:17 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\ATI [2013/01/04 23:15:11 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Avira [2012/04/19 21:37:04 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\CyberLink [2013/09/13 12:30:15 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Expert PDF 7 [2013/09/13 12:36:39 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Free-PDF-to-Word.com [2012/02/02 03:51:11 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Identities [2011/10/19 06:13:03 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Macromedia [2013/10/13 15:26:39 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Malwarebytes [2010/11/21 09:16:41 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Media Center Programs [2013/02/06 21:47:42 | 000,000,000 | --SD | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Microsoft [2013/09/07 15:18:10 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Mozilla [2013/09/19 23:30:57 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Nico Mak Computing [2012/02/01 23:56:27 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\ooVoo Details [2013/04/06 18:17:00 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\OpenOffice.org [2013/01/04 23:17:24 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\PowerCinema [2013/06/11 23:28:15 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Real [2013/03/28 23:23:14 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\RealNetworks [2013/10/13 13:16:57 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Skype [2012/02/08 21:42:24 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\SoftGrid Client [2012/12/07 00:15:55 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Temp [2013/05/09 15:33:41 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Thinstall [2012/02/06 21:25:59 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\TP [2013/08/28 21:31:46 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\vlc [2012/03/27 23:43:15 | 000,000,000 | ---D | M] -- C:\Users\ELLAFI KAMEL\AppData\Roaming\WinRAR [color=#A23BEC]< %appdata%\*.exe /s >[/color] [2011/10/19 06:11:53 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe [2013/03/29 00:31:20 | 000,659,096 | ---- | M] (RealNetworks, Inc.) -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Real\RealPlayer\setup\AU_setup20130309.exe [2013/06/11 23:28:24 | 000,470,096 | ---- | M] (RealNetworks, Inc.) -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Real\Update\temp\~Upg0\rnupgagent.exe [2013/06/30 23:30:13 | 000,470,096 | ---- | M] (RealNetworks, Inc.) -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Real\Update\temp\~Upg2\rnupgagent.exe [2013/07/21 16:48:10 | 000,470,096 | ---- | M] (RealNetworks, Inc.) -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Real\Update\temp\~Upg3\rnupgagent.exe [2013/09/07 14:11:56 | 000,470,608 | ---- | M] (RealNetworks, Inc.) -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Real\Update\temp\~Upg4\rnupgagent.exe [2013/09/07 14:11:56 | 000,470,608 | ---- | M] (RealNetworks, Inc.) -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.60\agent\rnupgagent.exe [2013/09/07 17:13:13 | 000,776,368 | ---- | M] (RealNetworks, Inc.) -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.60\agent\stub_exe\RealPlayer_fr.exe [2013/05/09 15:35:03 | 000,008,704 | ---- | M] () -- C:\Users\ELLAFI KAMEL\AppData\Roaming\Thinstall\GLArab.com HTTP Proxy\40000024e00003i\http_tv.exe [color=#A23BEC]< %systemdrive%\*. >[/color] [2012/02/28 01:42:39 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin [2013/10/13 16:12:37 | 000,000,000 | ---D | M] -- C:\AdwCleaner [2011/12/11 07:20:25 | 000,000,000 | -H-D | M] -- C:\book [2009/07/14 07:08:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2013/09/13 12:24:36 | 000,000,000 | ---D | M] -- C:\Downloads [2012/02/06 21:50:52 | 000,000,000 | RH-D | M] -- C:\MSOCache [2012/02/02 03:50:14 | 000,000,000 | -H-D | M] -- C:\OEM [2009/07/14 05:20:08 | 000,000,000 | ---D | M] -- C:\PerfLogs [2013/10/13 13:06:30 | 000,000,000 | ---D | M] -- C:\Program Files [2013/10/13 15:25:53 | 000,000,000 | R--D | M] -- C:\Program Files (x86) [2013/10/13 15:26:04 | 000,000,000 | -H-D | M] -- C:\ProgramData [2012/02/02 03:47:02 | 000,000,000 | -HSD | M] -- C:\Recovery [2013/07/06 23:56:56 | 000,000,000 | -H-D | M] -- C:\SkyDriveTemp [2013/10/13 17:39:44 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2012/02/02 03:47:10 | 000,000,000 | R--D | M] -- C:\Users [2013/10/03 14:10:10 | 000,000,000 | ---D | M] -- C:\Windows [2013/10/13 15:05:42 | 000,000,000 | ---D | M] -- C:\_OTL [color=#A23BEC]< %systemdrive%\*.exe >[/color] [color=#A23BEC]< %programfiles%\*. >[/color] [2011/12/11 07:58:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Acer [2011/10/19 05:15:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Acer Games [2011/10/19 06:13:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe [2011/12/11 07:26:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AMD APP [2012/10/12 19:38:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update [2012/08/17 01:56:42 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Athan [2011/12/11 07:26:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ATI Technologies [2013/01/04 23:08:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Avira [2012/10/12 19:36:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bonjour [2013/04/11 06:17:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files [2011/12/11 07:48:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Cyberlink [2012/12/06 23:53:01 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Dim@net [2011/12/11 07:36:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\EgisTec IPS [2011/12/11 07:36:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\EgisTec MyWinLocker [2011/12/11 07:34:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\EgisTec MyWinLockerSuite [2011/12/11 07:37:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\EgisTec Shredder [2013/09/13 12:36:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Free PDF to Word Converter [2012/02/07 20:09:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\GAMS22.5 [2013/03/17 22:07:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Google [2012/06/20 00:58:54 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information [2013/09/13 11:11:42 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer [2013/09/02 21:22:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iTunes [2012/06/30 16:51:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Java [2013/10/13 15:26:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2013/01/04 22:26:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft [2012/04/06 10:57:56 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office [2013/03/17 15:06:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Security Client [2013/07/17 03:17:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Silverlight [2013/03/16 17:33:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SkyDrive [2011/10/19 05:47:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition [2012/02/08 22:25:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Visual Studio [2012/02/07 19:28:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Visual Studio 8 [2012/02/11 03:00:01 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Works [2012/02/07 19:32:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET [2012/11/15 00:48:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MonoCalendar [2013/09/13 12:27:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox [2013/09/07 15:01:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Maintenance Service [2012/02/08 22:26:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild [2011/12/11 07:40:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NTI [2013/09/19 23:30:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ooVoo [2013/04/04 21:35:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OpenOffice.org 3 [2013/04/04 21:31:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OpenOffice.org 3.4.1 (fr) Installation Files [2012/06/30 16:53:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Oracle [2013/04/05 01:21:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Quantum GIS Lisboa [2013/03/29 00:36:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Real [2013/03/28 23:22:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\RealNetworks [2011/10/19 04:37:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek [2009/07/14 07:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies [2013/10/13 13:16:23 | 000,000,000 | R--D | M] -- C:\Program Files (x86)\Skype [2011/10/19 06:03:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Symantec [2009/07/14 06:57:06 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Uninstall Information [2012/02/27 18:24:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\VideoLAN [2011/10/19 04:47:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WildTangent Games [2013/07/11 17:43:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender [2012/04/13 21:08:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live [2011/12/11 16:10:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail [2011/12/11 16:10:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player [2009/07/14 07:32:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT [2011/12/11 16:10:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Viewer [2010/11/21 05:31:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices [2011/12/11 16:10:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Sidebar [2012/03/27 23:42:43 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WinRAR [color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color] [2011/07/14 07:30:29 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe [2011/07/14 07:30:29 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe [2011/07/14 07:30:29 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe [2011/07/14 07:30:29 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe [2010/11/21 05:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe [2011/07/14 07:30:29 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe [2011/07/14 07:30:29 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe [2010/11/21 05:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe [color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color] [2010/11/21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\SysNative\netlogon.dll [2010/11/21 05:24:01 | 000,695,808 | ---- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll [2010/11/21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\SysWOW64\netlogon.dll [2010/11/21 05:24:09 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll [color=#A23BEC]< MD5 for: USERINIT.EXE >[/color] [2010/11/21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe [2010/11/21 05:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe [2010/11/21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe [2010/11/21 05:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color] [2010/11/21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe [2010/11/21 05:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe [2013/04/04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe [color=#E56717]========== Files - Unicode (All) ==========[/color] [2013/09/19 13:17:28 | 098,352,290 | ---- | M] ()(C:\Windows\SysWow64\????) -- C:\Windows\SysWow64\㤇Ḽ‘ [2013/09/19 13:17:28 | 098,352,290 | ---- | C] ()(C:\Windows\SysWow64\????) -- C:\Windows\SysWow64\㤇Ḽ‘ [2012/10/22 17:39:23 | 004,787,767 | ---- | M] ()(C:\Users\ELLAFI KAMEL\Desktop\01 - ?????.MP3) -- C:\Users\ELLAFI KAMEL\Desktop\01 - مهاجر.MP3 [2012/10/22 17:37:22 | 004,787,767 | ---- | C] ()(C:\Users\ELLAFI KAMEL\Desktop\01 - ?????.MP3) -- C:\Users\ELLAFI KAMEL\Desktop\01 - مهاجر.MP3 < End of report >