Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-07-2014 01 Ran by R4 Bulldozer (administrator) on LUC-PC on 18-07-2014 06:21:55 Running from C:\Users\R4 Bulldozer\Desktop Platform: Microsoft Windows 7 Édition Familiale Premium Service Pack 1 (X86) OS Language: Français (France) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\vsserv.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Devguru Co., Ltd.) C:\Windows\System32\dgdersvc.exe (Google Inc.) C:\Program Files\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Teruten) C:\Windows\System32\FsUsbExService.Exe () C:\Program Files\Canon\IJPLM\ijplmsvc.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe (Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.) C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.) C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\bdagent.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (CANON INC.) C:\Program Files\Canon\Solution Menu EX\CNSEUPDT.EXE (Microsoft Corporation) C:\Program Files\Windows Media Player\wmprph.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_14_0_0_145_ActiveX.exe (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2565520 2011-03-14] (CANON INC.) HKLM\...\Run: [CanonSolutionMenuEx] => C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [1612920 2011-08-04] (CANON INC.) HKLM\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.) HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [1835288 2014-06-17] (Bitdefender) HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC) HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [VDownloader] => C:\Program Files\VDownloader\VDownloader.exe [881664 2014-05-10] (Vitzo) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation) HKU\.DEFAULT\...\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [482904 2014-06-17] (Bitdefender) HKU\.DEFAULT\...\Run: [Bitdefender Wallet] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [901608 2014-06-17] (Bitdefender) HKU\.DEFAULT\...\Run: [Bitdefender Agent de l'application Wallet] => C:\Program Files\Bitdefender\Bitdefender\bdapppassmgr.exe [614744 2014-06-17] (Bitdefender) HKU\S-1-5-21-1097962039-962867081-3370767552-1000\...\Run: [KiesTrayAgent] => [X] HKU\S-1-5-21-1097962039-962867081-3370767552-1000\...\Run: [Google Update] => C:\Users\R4 Bulldozer\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-12-06] (Google Inc.) HKU\S-1-5-21-1097962039-962867081-3370767552-1000\...\MountPoints2: {d0a16ca7-089b-11e0-870e-806e6f6e6963} - D:\Autorun\Autorun.exe ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://orange.fr/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://fr.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {288ED107-EC1C-4D86-B379-6A3A0D16C973 URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=tugumsd&cd=2XzuyEtN2Y1L1QzutAtDzzyD0Azy0BtAtD0B0E0BtC0C0BtDtN0D0Tzu0CyCyEzytN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu2Z2Y1N2Y1H1B1Q&cr=2007657291&ir= SearchScopes: HKLM - {71634C80-ACD5-3B1F-730F-7A05C33ED981} URL = BHO: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll (Bitdefender) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: IEExtension.VDownloaderBHO -> {7b523e7c-f096-4e36-a0cb-7efeb5c675c1} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll (Adblock Plus) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Hosts: 127.0.0.1 localhost Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\R4 Bulldozer\AppData\Roaming\Mozilla\Firefox\Profiles\90euniz0.default-1372177977531 FF Homepage: hxxp://www.orange.fr/portail FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.60.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\R4 Bulldozer\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\R4 Bulldozer\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\R4 Bulldozer\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\R4 Bulldozer\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\R4 Bulldozer\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: vitzo.com/VDownloader - C:\Program Files\VDownloader\Addons\npVDownloader.dll (Vitzo Limited) FF user.js: detected! => C:\Users\R4 Bulldozer\AppData\Roaming\Mozilla\Firefox\Profiles\90euniz0.default-1372177977531\user.js FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Users\R4 Bulldozer\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\R4 Bulldozer\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF SearchPlugin: C:\Users\R4 Bulldozer\AppData\Roaming\Mozilla\Firefox\Profiles\90euniz0.default-1372177977531\searchplugins\amazon.xml FF HKLM\...\Firefox\Extensions: [ffpwdman@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\ffpwdman FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\ffpwdman [2013-09-14] FF HKLM\...\Firefox\Extensions: [support@vdownloader.com] - C:\Program Files\VDownloader\Addons\FireFox FF Extension: VDownloader - C:\Program Files\VDownloader\Addons\FireFox [2014-02-15] ========================== Services (Whitelisted) ================= R2 dgdersvc; C:\Windows\system32\dgdersvc.exe [95568 2010-07-30] (Devguru Co., Ltd.) R2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [138192 2011-02-07] () R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2006-12-14] (Hewlett-Packard Company) [File not signed] R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S3 NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [262144 2006-12-23] (Nero AG) [File not signed] R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [54424 2014-04-04] (Bitdefender) R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [1251296 2014-06-17] (Bitdefender) ==================== Drivers (Whitelisted) ==================== R3 amdkmdag; C:\Windows\System32\DRIVERS\atipmdag.sys [5315584 2010-05-22] (ATI Technologies Inc.) R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [12400 2007-12-17] () R0 aswKbd; C:\Windows\system32\Drivers\aswKbd.sys [21576 2013-03-07] (AVAST Software) R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [778032 2014-02-05] (BitDefender) R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [242504 2012-11-02] (BitDefender) R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [516936 2014-02-05] (BitDefender) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [90704 2011-11-14] (BitDefender LLC) S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [66832 2013-12-02] (BitDefender SRL) R1 bdselfpr; C:\Program Files\Bitdefender\Bitdefender\bdselfpr.sys [135600 2013-07-26] (BitDefender LLC) S3 camfilt2; C:\Windows\System32\DRIVERS\camfilt2.sys [94208 2007-06-13] (Guillemot Corporation) R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [42072 2010-11-18] () R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [165744 2013-10-08] (BitDefender LLC) R3 hxctlflt; C:\Windows\System32\DRIVERS\hxctlflt.sys [99968 2009-02-09] (Guillemot Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-07-18] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] () R2 npf; C:\Windows\System32\drivers\npf.sys [50704 2010-01-27] (CACE Technologies, Inc.) R3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10371072 2007-07-17] (Sonix Co. Ltd.) R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [360376 2013-10-08] (BitDefender S.R.L.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-18 06:21 - 2014-07-18 06:21 - 00014596 _____ () C:\Users\R4 Bulldozer\Desktop\FRST.txt 2014-07-18 06:21 - 2014-07-18 06:21 - 00003677 _____ () C:\Users\R4 Bulldozer\Desktop\RKreport_SCN_07182014_062107.log 2014-07-18 06:12 - 2014-07-18 06:12 - 00003698 _____ () C:\Users\R4 Bulldozer\Desktop\RKreport_DEL_07182014_060713.log 2014-07-18 05:58 - 2014-07-18 05:58 - 04770904 _____ () C:\Users\R4 Bulldozer\Desktop\RogueKiller.exe 2014-07-17 20:15 - 2014-07-18 06:22 - 00000000 ____D () C:\FRST 2014-07-17 20:15 - 2014-07-17 20:15 - 01077248 _____ (Farbar) C:\Users\R4 Bulldozer\Desktop\FRST.exe 2014-07-17 19:47 - 2014-07-17 20:14 - 63042752 _____ (Online Media Technologies Ltd. ) C:\Users\R4 Bulldozer\Downloads\AVSVideoConverter.exe 2014-07-17 19:37 - 2014-07-17 19:37 - 00004868 _____ () C:\Users\R4 Bulldozer\Documents\Mon film.wlmp1.wlmp 2014-07-17 19:20 - 2014-07-17 19:20 - 00003584 _____ () C:\Users\R4 Bulldozer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-17 18:50 - 2014-07-17 18:50 - 00005468 _____ () C:\Users\R4 Bulldozer\Documents\MONT2E DU BALLON EN 1098.wlmp 2014-07-16 20:33 - 2014-07-17 06:26 - 00002119 _____ () C:\Users\R4 Bulldozer\Desktop\Tweaking.com - Windows Repair (All in One).lnk 2014-07-16 20:33 - 2014-07-16 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com 2014-07-16 10:32 - 2014-07-16 10:32 - 00000000 ___RD () C:\Users\R4 Bulldozer\Documents\VEHICULES 2014-07-16 04:20 - 2014-07-16 04:20 - 00000000 ____D () C:\Users\R4 Bulldozer\AppData\Local\Genesis_07160220 2014-07-16 04:15 - 2014-07-16 04:15 - 00000000 ____D () C:\Users\R4 Bulldozer\AppData\Roaming\Obvious Idea 2014-07-16 04:15 - 2014-07-16 04:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Easy Photo Uploader 2014-07-16 04:15 - 2014-07-16 04:15 - 00000000 ____D () C:\Program Files\EasyPhotoUploader 2014-07-15 21:41 - 2014-07-15 21:41 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-LUC-PC-Microsoft-Windows 7-Édition-Familiale-Premium-(32-bit).dat 2014-07-15 21:41 - 2014-07-15 21:41 - 00000000 ____D () C:\RegBackup 2014-07-15 21:37 - 2014-07-15 21:37 - 00000000 ____D () C:\Program Files\Tweaking.com 2014-07-15 21:32 - 2014-07-15 21:36 - 09494344 _____ () C:\Users\R4 Bulldozer\Desktop\tweaking.com_windows_repair_aio_setup.exe 2014-07-15 20:16 - 2014-07-15 20:52 - 06010880 _____ () C:\Program Files\GUT22DD.tmp 2014-07-15 20:16 - 2014-07-15 20:52 - 00000000 ____D () C:\Program Files\GUM22DC.tmp 2014-07-15 20:13 - 2014-07-15 20:16 - 00895120 _____ (Google Inc.) C:\Users\R4 Bulldozer\Downloads\GoogleEarthSetup.exe 2014-07-15 03:42 - 2014-07-15 03:46 - 00000500 _____ () C:\Users\R4 Bulldozer\AppData\Roaming\Microsoft\Windows\Start Menu\Portail Orange mail, mon compte, actu.website 2014-07-15 03:27 - 2014-07-16 04:41 - 00000000 ____D () C:\ProgramData\PC1Data 2014-07-15 03:27 - 2014-07-15 03:27 - 04954384 _____ (PC Cleaners) C:\ProgramData\pclunst.exe 2014-07-14 02:27 - 2014-07-18 06:13 - 00029160 _____ () C:\Windows\system32\Drivers\TrueSight.sys 2014-07-14 02:27 - 2014-07-15 04:49 - 00000000 ____D () C:\ProgramData\RogueKiller 2014-07-13 17:53 - 2014-07-15 04:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-07-13 17:53 - 2014-07-13 17:53 - 00004534 _____ () C:\Windows\system32\jupdate-1.7.0_60-b19.log 2014-07-13 17:53 - 2014-07-13 17:53 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-07-13 17:53 - 2014-05-07 15:02 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-07-13 17:53 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-07-13 17:53 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-07-13 17:53 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-07-13 09:28 - 2014-07-13 09:28 - 00001935 _____ () C:\Users\R4 Bulldozer\Desktop\ZHPFix.lnk 2014-07-13 09:28 - 2014-07-13 09:28 - 00001808 _____ () C:\Users\R4 Bulldozer\Desktop\ZHPDiag.lnk 2014-07-13 09:25 - 2014-07-13 09:27 - 06857900 _____ (Nicolas Coolman ) C:\Users\R4 Bulldozer\Downloads\ZHPDiag2.exe 2014-07-13 06:33 - 2014-07-13 06:36 - 01348263 _____ () C:\Users\R4 Bulldozer\Downloads\adwcleaner_3.215.exe 2014-07-10 03:40 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-07-10 03:39 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-07-10 03:39 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-10 03:39 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-10 03:39 - 2014-06-19 01:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-07-10 03:39 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-10 03:39 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-10 03:39 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-07-10 03:39 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-07-10 03:39 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-10 03:39 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-10 03:39 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-10 03:39 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-10 03:39 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-10 03:39 - 2014-06-19 01:23 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-07-10 03:39 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-07-10 03:39 - 2014-06-19 01:16 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-07-10 03:39 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-10 03:39 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-10 03:39 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-10 03:39 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-10 03:39 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-10 03:39 - 2014-06-19 00:52 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-10 03:39 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-10 03:39 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-07-10 03:39 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-10 03:39 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-10 03:39 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-10 03:39 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-10 03:39 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-07-10 03:01 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-07-10 03:01 - 2014-06-18 02:52 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-10 03:00 - 2014-06-30 03:40 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-10 03:00 - 2014-06-30 03:36 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-07-10 03:00 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-10 03:00 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-07-10 03:00 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-07-10 03:00 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-07-10 03:00 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-07-10 03:00 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-07-10 03:00 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-07-10 03:00 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-07-10 03:00 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-10 02:59 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-06-29 18:24 - 2014-07-18 03:11 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-29 18:23 - 2014-07-15 04:49 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2014-06-29 18:23 - 2014-06-29 18:23 - 00001062 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-06-29 18:23 - 2014-06-29 18:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-06-29 18:23 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-29 18:23 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-28 06:07 - 2014-06-28 06:07 - 00007775 _____ () C:\Users\R4 Bulldozer\Documents\Mon film.wlmpj.wlmp ==================== One Month Modified Files and Folders ======= 2014-07-18 06:22 - 2014-07-18 06:21 - 00014596 _____ () C:\Users\R4 Bulldozer\Desktop\FRST.txt 2014-07-18 06:22 - 2014-07-17 20:15 - 00000000 ____D () C:\FRST 2014-07-18 06:21 - 2014-07-18 06:21 - 00003677 _____ () C:\Users\R4 Bulldozer\Desktop\RKreport_SCN_07182014_062107.log 2014-07-18 06:16 - 2014-02-01 03:41 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1097962039-962867081-3370767552-1000UA.job 2014-07-18 06:13 - 2014-07-14 02:27 - 00029160 _____ () C:\Windows\system32\Drivers\TrueSight.sys 2014-07-18 06:12 - 2014-07-18 06:12 - 00003698 _____ () C:\Users\R4 Bulldozer\Desktop\RKreport_DEL_07182014_060713.log 2014-07-18 05:58 - 2014-07-18 05:58 - 04770904 _____ () C:\Users\R4 Bulldozer\Desktop\RogueKiller.exe 2014-07-18 05:55 - 2013-01-07 17:31 - 00000000 ____D () C:\Users\R4 Bulldozer\AppData\Local\CrashDumps 2014-07-18 05:37 - 2014-01-11 13:39 - 00001002 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-18 05:35 - 2013-07-15 20:48 - 00001058 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-18 03:48 - 2013-10-22 07:52 - 01116411 ____N () C:\Windows\WindowsUpdate.log 2014-07-18 03:11 - 2014-06-29 18:24 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-17 20:15 - 2014-07-17 20:15 - 01077248 _____ (Farbar) C:\Users\R4 Bulldozer\Desktop\FRST.exe 2014-07-17 20:14 - 2014-07-17 19:47 - 63042752 _____ (Online Media Technologies Ltd. ) C:\Users\R4 Bulldozer\Downloads\AVSVideoConverter.exe 2014-07-17 19:41 - 2014-02-15 10:21 - 00000000 ____D () C:\Program Files\VDownloader 2014-07-17 19:37 - 2014-07-17 19:37 - 00004868 _____ () C:\Users\R4 Bulldozer\Documents\Mon film.wlmp1.wlmp 2014-07-17 19:20 - 2014-07-17 19:20 - 00003584 _____ () C:\Users\R4 Bulldozer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-17 18:59 - 2009-07-14 06:34 - 00024832 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-17 18:59 - 2009-07-14 06:34 - 00024832 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-17 18:56 - 2010-12-15 17:46 - 01670292 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-17 18:52 - 2013-07-15 20:48 - 00001054 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-17 18:52 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-17 18:51 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\TAPI 2014-07-17 18:50 - 2014-07-17 18:50 - 00005468 _____ () C:\Users\R4 Bulldozer\Documents\MONT2E DU BALLON EN 1098.wlmp 2014-07-17 12:00 - 2010-12-15 17:43 - 00000000 ____D () C:\Users\R4 Bulldozer 2014-07-17 12:00 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration 2014-07-17 11:44 - 2013-05-18 13:15 - 00000000 ____D () C:\ProgramData\CanonIJPLM 2014-07-17 11:44 - 2011-06-03 17:01 - 00000000 ____D () C:\Users\R4 Bulldozer\AppData\Roaming\SoftGrid Client 2014-07-17 08:16 - 2014-02-01 03:41 - 00001054 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1097962039-962867081-3370767552-1000Core.job 2014-07-17 06:26 - 2014-07-16 20:33 - 00002119 _____ () C:\Users\R4 Bulldozer\Desktop\Tweaking.com - Windows Repair (All in One).lnk 2014-07-16 20:33 - 2014-07-16 20:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com 2014-07-16 10:32 - 2014-07-16 10:32 - 00000000 ___RD () C:\Users\R4 Bulldozer\Documents\VEHICULES 2014-07-16 04:41 - 2014-07-15 03:27 - 00000000 ____D () C:\ProgramData\PC1Data 2014-07-16 04:20 - 2014-07-16 04:20 - 00000000 ____D () C:\Users\R4 Bulldozer\AppData\Local\Genesis_07160220 2014-07-16 04:15 - 2014-07-16 04:15 - 00000000 ____D () C:\Users\R4 Bulldozer\AppData\Roaming\Obvious Idea 2014-07-16 04:15 - 2014-07-16 04:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Easy Photo Uploader 2014-07-16 04:15 - 2014-07-16 04:15 - 00000000 ____D () C:\Program Files\EasyPhotoUploader 2014-07-16 04:08 - 2014-05-13 15:48 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-07-15 21:41 - 2014-07-15 21:41 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-LUC-PC-Microsoft-Windows 7-Édition-Familiale-Premium-(32-bit).dat 2014-07-15 21:41 - 2014-07-15 21:41 - 00000000 ____D () C:\RegBackup 2014-07-15 21:37 - 2014-07-15 21:37 - 00000000 ____D () C:\Program Files\Tweaking.com 2014-07-15 21:36 - 2014-07-15 21:32 - 09494344 _____ () C:\Users\R4 Bulldozer\Desktop\tweaking.com_windows_repair_aio_setup.exe 2014-07-15 20:52 - 2014-07-15 20:16 - 06010880 _____ () C:\Program Files\GUT22DD.tmp 2014-07-15 20:52 - 2014-07-15 20:16 - 00000000 ____D () C:\Program Files\GUM22DC.tmp 2014-07-15 20:16 - 2014-07-15 20:13 - 00895120 _____ (Google Inc.) C:\Users\R4 Bulldozer\Downloads\GoogleEarthSetup.exe 2014-07-15 04:49 - 2014-07-14 02:27 - 00000000 ____D () C:\ProgramData\RogueKiller 2014-07-15 04:49 - 2014-07-13 17:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-07-15 04:49 - 2014-06-29 18:23 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2014-07-15 04:49 - 2014-05-16 04:24 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-07-15 04:49 - 2014-02-15 10:21 - 00000000 ____D () C:\Program Files\WinPcap 2014-07-15 04:49 - 2014-02-13 19:38 - 00000000 ____D () C:\Program Files\ZHPDiag 2014-07-15 04:49 - 2014-01-10 05:24 - 00000000 ____D () C:\Program Files\Adblock Plus for IE 2014-07-15 04:49 - 2013-09-14 18:06 - 00000000 ____D () C:\Program Files\Xvid 2014-07-15 04:49 - 2013-09-14 18:06 - 00000000 ____D () C:\Program Files\OpenSource Flash Video Splitter 2014-07-15 04:49 - 2013-06-14 15:46 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack 2014-07-15 04:49 - 2012-12-19 19:01 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-15 04:49 - 2012-12-19 18:18 - 00000000 ____D () C:\Program Files\Microsoft Works 2014-07-15 04:49 - 2011-06-03 16:49 - 00000000 ____D () C:\Program Files\Microsoft Application Virtualization Client 2014-07-15 04:49 - 2010-12-17 19:33 - 00000000 ____D () C:\Program Files\Microsoft Picture It! 10 2014-07-15 04:49 - 2010-12-17 18:03 - 00000000 ____D () C:\Program Files\WinRAR 2014-07-15 04:49 - 2010-12-17 18:01 - 00000000 ____D () C:\Program Files\CCleaner 2014-07-15 04:49 - 2009-07-14 11:01 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-15 04:49 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Photo Viewer 2014-07-15 04:49 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Defender 2014-07-15 04:49 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\com 2014-07-15 04:49 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers 2014-07-15 03:46 - 2014-07-15 03:42 - 00000500 _____ () C:\Users\R4 Bulldozer\AppData\Roaming\Microsoft\Windows\Start Menu\Portail Orange mail, mon compte, actu.website 2014-07-15 03:27 - 2014-07-15 03:27 - 04954384 _____ (PC Cleaners) C:\ProgramData\pclunst.exe 2014-07-13 18:13 - 2014-02-13 19:38 - 00000000 ____D () C:\Users\R4 Bulldozer\AppData\Roaming\ZHP 2014-07-13 18:12 - 2014-06-13 22:04 - 00000040 _____ () C:\Users\R4 2014-07-13 17:57 - 2013-10-19 07:35 - 00000000 ____D () C:\ProgramData\Oracle 2014-07-13 17:53 - 2014-07-13 17:53 - 00004534 _____ () C:\Windows\system32\jupdate-1.7.0_60-b19.log 2014-07-13 17:53 - 2014-07-13 17:53 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-07-13 17:53 - 2013-12-31 12:14 - 00000000 ____D () C:\Program Files\Java 2014-07-13 09:28 - 2014-07-13 09:28 - 00001935 _____ () C:\Users\R4 Bulldozer\Desktop\ZHPFix.lnk 2014-07-13 09:28 - 2014-07-13 09:28 - 00001808 _____ () C:\Users\R4 Bulldozer\Desktop\ZHPDiag.lnk 2014-07-13 09:28 - 2014-02-13 19:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP 2014-07-13 09:27 - 2014-07-13 09:25 - 06857900 _____ (Nicolas Coolman ) C:\Users\R4 Bulldozer\Downloads\ZHPDiag2.exe 2014-07-13 06:46 - 2014-02-14 10:02 - 00000000 ____D () C:\AdwCleaner 2014-07-13 06:36 - 2014-07-13 06:33 - 01348263 _____ () C:\Users\R4 Bulldozer\Downloads\adwcleaner_3.215.exe 2014-07-11 22:40 - 2014-01-11 13:39 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-07-11 22:40 - 2014-01-11 13:39 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-07-11 03:57 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-07-11 03:19 - 2009-07-14 06:33 - 00402856 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-11 03:18 - 2014-05-01 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-11 03:18 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\fr-FR 2014-07-11 03:01 - 2013-08-14 23:14 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-11 03:01 - 2012-12-19 18:24 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-06-30 03:40 - 2014-07-10 03:00 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-30 03:36 - 2014-07-10 03:00 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-29 19:19 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Web 2014-06-29 18:23 - 2014-06-29 18:23 - 00001062 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-06-29 18:23 - 2014-06-29 18:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-06-29 18:23 - 2013-10-20 18:35 - 00000000 ____D () C:\Users\R4 Bulldozer\AppData\Roaming\Malwarebytes 2014-06-29 18:23 - 2013-10-20 18:35 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-29 15:28 - 2014-05-13 05:33 - 00000000 ____D () C:\Windows\Minidump 2014-06-28 06:07 - 2014-06-28 06:07 - 00007775 _____ () C:\Users\R4 Bulldozer\Documents\Mon film.wlmpj.wlmp 2014-06-20 21:39 - 2014-07-10 03:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-06-19 02:16 - 2014-07-10 03:39 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-19 01:56 - 2014-07-10 03:39 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-19 01:56 - 2014-07-10 03:39 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-06-19 01:38 - 2014-07-10 03:39 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-19 01:37 - 2014-07-10 03:39 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-19 01:36 - 2014-07-10 03:39 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-06-19 01:35 - 2014-07-10 03:39 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-06-19 01:32 - 2014-07-10 03:39 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-19 01:28 - 2014-07-10 03:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-19 01:28 - 2014-07-10 03:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-19 01:25 - 2014-07-10 03:39 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-19 01:23 - 2014-07-10 03:39 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-19 01:23 - 2014-07-10 03:39 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-06-19 01:22 - 2014-07-10 03:39 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-06-19 01:16 - 2014-07-10 03:39 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-06-19 01:12 - 2014-07-10 03:39 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-19 01:06 - 2014-07-10 03:40 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-06-19 01:01 - 2014-07-10 03:39 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-19 00:59 - 2014-07-10 03:39 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-19 00:58 - 2014-07-10 03:39 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-19 00:52 - 2014-07-10 03:39 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-19 00:52 - 2014-07-10 03:39 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-19 00:49 - 2014-07-10 03:39 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-19 00:46 - 2014-07-10 03:39 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-06-19 00:45 - 2014-07-10 03:39 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-19 00:35 - 2014-07-10 03:39 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-19 00:13 - 2014-07-10 03:39 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-19 00:09 - 2014-07-10 03:39 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-19 00:07 - 2014-07-10 03:39 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-06-18 03:51 - 2014-07-10 03:01 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-06-18 02:52 - 2014-07-10 03:01 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys Files to move or delete: ==================== C:\ProgramData\pclunst.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-18 00:25 ==================== End Of Log ============================