OTL logfile created on: 07/01/2014 21:55:46 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Nath\Downloads Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy 1012,30 Mb Total Physical Memory | 85,17 Mb Available Physical Memory | 8,41% Memory free 1,99 Gb Paging File | 0,66 Gb Available in Paging File | 33,31% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 281,17 Gb Total Space | 231,41 Gb Free Space | 82,30% Space Free | Partition Type: NTFS Drive D: | 16,62 Gb Total Space | 1,77 Gb Free Space | 10,65% Space Free | Partition Type: NTFS Computer Name: NATH-HP | User Name: Nath | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - C:\Users\Nath\Downloads\OTL.exe (OldTimer Tools) PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareTray.exe () PRC - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareService.exe () PRC - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft) PRC - C:\Users\Nath\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company) PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation) PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - C:\Program Files\IDT\WDM\STacSV.exe (IDT, Inc.) PRC - C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe (Atheros) PRC - C:\Program Files\Bluetooth Suite\adminservice.exe (Atheros Commnucations) PRC - C:\Program Files\CyberLink\YouCam\YCMMirage.exe (CyberLink) PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) PRC - C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.) PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation) PRC - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) PRC - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company) PRC - c:\program files\windows defender\MpCmdRun.exe (Microsoft Corporation) PRC - C:\Program Files\IDT\WDM\aestsrv.exe (Andrea Electronics Corporation) [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - C:\Program Files\AVAST Software\Avast\libcef.dll () MOD - C:\Program Files\Mozilla Firefox\mozjs.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\zlib.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\pugixml.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\libssh2.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\boost_thread-vc100-mt-1_53.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\boost_system-vc100-mt-1_53.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\boost_locale-vc100-mt-1_53.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\boost_filesystem-vc100-mt-1_53.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\boost_date_time-vc100-mt-1_53.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\SQLite.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\RCF.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\Logger.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\HtmlFramework.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\Localization.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\DllStorage.dll () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareTray.exe () MOD - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareTrayDefaultSkin.dll () MOD - C:\Users\Nath\AppData\Roaming\Dropbox\bin\libcef.dll () MOD - C:\Users\Nath\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll () MOD - C:\Program Files\WinRAR\rarext.dll () MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll () [color=#E56717]========== Services (SafeList) ==========[/color] SRV - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (LavasoftAdAwareService11) -- C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareService.exe () SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (HP Support Assistant Service) -- C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company) SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.) SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies) SRV - (STacSV) -- C:\Program Files\IDT\WDM\STacSV.exe (IDT, Inc.) SRV - (ZAtheros Bt&Wlan Coex Agent) -- C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe (Atheros) SRV - (AtherosSvc) -- C:\Program Files\Bluetooth Suite\adminservice.exe (Atheros Commnucations) SRV - (sftvsa) -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) SRV - (sftlist) -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) SRV - (HPWMISVC) -- C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.) SRV - (IAStorDataMgrSvc) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) SRV - (GamesAppService) -- C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.) SRV - (HPClientSvc) -- C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company) SRV - (SwitchBoard) -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) SRV - (AESTFilters) -- C:\Program Files\IDT\WDM\aestsrv.exe (Andrea Electronics Corporation) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - (adfs) -- File not found DRV - (aswStm) -- C:\Windows\System32\drivers\aswstm.sys (AVAST Software) DRV - (aswSnx) -- C:\Windows\System32\drivers\aswSnx.sys (AVAST Software) DRV - (aswSP) -- C:\Windows\System32\drivers\aswSP.sys (AVAST Software) DRV - (aswVmm) -- C:\Windows\System32\drivers\aswVmm.sys () DRV - (aswRvrt) -- C:\Windows\System32\drivers\aswRvrt.sys () DRV - (aswRdr) -- C:\Windows\System32\drivers\aswRdr2.sys (AVAST Software) DRV - (aswMonFlt) -- C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software) DRV - (aswTdi) -- C:\Windows\System32\drivers\aswTdi.sys (AVAST Software) DRV - (Trufos) -- C:\Windows\System32\drivers\Trufos.sys (BitDefender S.R.L.) DRV - (gzflt) -- C:\Program Files\Lavasoft\Ad-Aware Antivirus\Antimalware Engine\2.6.0.0\gzflt.sys (BitDefender LLC) DRV - (igddim32) -- C:\Windows\System32\drivers\igddim32.sys (Intel Corporation) DRV - (STHDA) -- C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.) DRV - (BtFilter) -- C:\Windows\System32\drivers\btfilter.sys (Atheros) DRV - (BTATH_RCP) -- C:\Windows\System32\drivers\btath_rcp.sys (Atheros) DRV - (BTATH_LWFLT) -- C:\Windows\System32\drivers\btath_lwflt.sys (Atheros) DRV - (BTATH_HCRP) -- C:\Windows\System32\drivers\btath_hcrp.sys (Atheros) DRV - (AthBTPort) -- C:\Windows\System32\drivers\btath_flt.sys (Atheros) DRV - (BTATH_BUS) -- C:\Windows\System32\drivers\btath_bus.sys (Atheros) DRV - (btath_avdt) -- C:\Windows\System32\drivers\btath_avdt.sys (Atheros) DRV - (BTATH_A2DP) -- C:\Windows\System32\drivers\btath_a2dp.sys (Atheros) DRV - (Sftvol) -- C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation) DRV - (Sftredir) -- C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation) DRV - (Sftplay) -- C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation) DRV - (Sftfs) -- C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation) DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.) DRV - (RSUSBSTOR) -- C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.) DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation) DRV - (TsUsbGD) -- C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation) DRV - (clwvd) -- C:\Windows\System32\drivers\clwvd.sys (CyberLink Corporation) DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation) DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPNOT/8 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/HPNOT/8 IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{B737AC33-1B07-414A-8006-991128380625}: "URL" = http://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/709-111075-12437-3/4?mpre=http://www.ebay.fr/sch/i.html?_nkw={searchTerms} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPNOT/8 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ IE - HKCU\..\URLSearchHook: {ef79f67a-6ad7-4715-a0f8-932fca442023} - No CLSID value found IE - HKCU\..\SearchScopes,DefaultScope = IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPMTDF&pc=HPMTDF&src=IE-SearchBox IE - HKCU\..\SearchScopes\{B737AC33-1B07-414A-8006-991128380625}: "URL" = http://www.amazon.fr/s/ref=azs_osd_ieafr?ie=UTF-8&tag=hp-fr2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} IE - HKCU\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/709-111075-12437-3/4?mpre=http://www.ebay.fr/sch/i.html?_nkw={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultengine: "Google" FF - prefs.js..browser.search.order.1: "Google" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "www.google.com" FF - prefs.js..extensions.enabledAddons: %7B87934c42-161d-45bc-8cef-ef18abe2a30c%7D:3.8 FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:9.0.2011.70 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:26.0 FF - prefs.js..keyword.URL: "http://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_8&idate=__installtime__&hsimp=yhs-lavasoft&ent=bs&q=" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014/01/04 12:37:37 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 26.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 26.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.2.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.2.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 26.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 26.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 24.2.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 24.2.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2012/03/03 15:07:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Nath\AppData\Roaming\mozilla\Extensions [2014/01/06 13:56:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Nath\AppData\Roaming\mozilla\Firefox\Profiles\bimtdcmz.default\extensions [2013/12/26 16:21:07 | 000,000,000 | ---D | M] (Ad-Aware Security Add-on) -- C:\Users\Nath\AppData\Roaming\mozilla\Firefox\Profiles\bimtdcmz.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} [2014/01/06 13:57:00 | 000,002,808 | ---- | M] () -- C:\Users\Nath\AppData\Roaming\mozilla\firefox\profiles\bimtdcmz.default\searchplugins\Google.xml [2013/12/12 11:44:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\browser\extensions [2013/12/12 11:44:31 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2014/01/04 12:37:37 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: () CHR - default_search_provider: search_url = CHR - default_search_provider: suggest_url = CHR - homepage: CHR - Extension: No name found = C:\Users\Nath\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\ CHR - Extension: No name found = C:\Users\Nath\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: No name found = C:\Users\Nath\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\ CHR - Extension: No name found = C:\Users\Nath\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihoalmdehffjdbplmiacbnnakmggjbcn\2.2.10_0\ CHR - Extension: No name found = C:\Users\Nath\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2012/12/18 15:57:57 | 000,000,855 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 activate.adobe.com O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) O3 - HKLM\..\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft) O4 - HKLM..\Run: [AdAwareTray] C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareTray.exe () O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) O4 - HKLM..\Run: [GfxServiceInstall] C:\Windows\System32 [2014/01/07 21:42:11 | 000,000,000 | ---D | M] O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32 [2014/01/07 21:42:11 | 000,000,000 | ---D | M] O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32 [2014/01/07 21:42:11 | 000,000,000 | ---D | M] O4 - HKLM..\Run: [Persistence] C:\Windows\System32 [2014/01/07 21:42:11 | 000,000,000 | ---D | M] O4 - HKCU..\Run: [AdobeBridge] File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8 - Extra context menu item: Ajouter au fichier PDF existant - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Convertir au format PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BA290F6F-18C3-461E-B3FD-F305D5BB191B}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D0A21D97-3E65-419E-BE15-A9865E05FCB9}: DhcpNameServer = 192.168.1.254 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{ffc56c8a-8c8a-11e2-a11d-ec9a74631185}\Shell - "" = AutoRun O33 - MountPoints2\{ffc56c8a-8c8a-11e2-a11d-ec9a74631185}\Shell\AutoRun\command - "" = F:\NokiaPCIA_Autorun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) NetSvcs: FastUserSwitchingCompatibility - File not found NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation) NetSvcs: Nla - File not found NetSvcs: Ntmssvc - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: SRService - File not found NetSvcs: WmdmPmSp - File not found NetSvcs: LogonHours - File not found NetSvcs: PCAudit - File not found NetSvcs: helpsvc - File not found NetSvcs: uploadmgr - File not found MsConfig - StartUpReg: [b]Acrobat Assistant 8.0[/b] - hkey= - key= - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.) MsConfig - StartUpReg: [b]Adobe Acrobat Speed Launcher[/b] - hkey= - key= - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: [b]Adobe ARM[/b] - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: [b]AdobeAAMUpdater-1.0[/b] - hkey= - key= - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: [b]AdobeCS5.5ServiceManager[/b] - hkey= - key= - File not found MsConfig - StartUpReg: [b]AdobeCS5ServiceManager[/b] - hkey= - key= - C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: [b]APSDaemon[/b] - hkey= - key= - File not found MsConfig - StartUpReg: [b]AthBtTray[/b] - hkey= - key= - C:\Program Files\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations) MsConfig - StartUpReg: [b]AtherosBtStack[/b] - hkey= - key= - C:\Program Files\Bluetooth Suite\BtvStack.exe (Atheros Communications) MsConfig - StartUpReg: [b]CanonMyPrinter[/b] - hkey= - key= - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) MsConfig - StartUpReg: [b]CanonSolutionMenu[/b] - hkey= - key= - C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.) MsConfig - StartUpReg: [b]DAEMON Tools Lite[/b] - hkey= - key= - File not found MsConfig - StartUpReg: [b]HP Quick Launch[/b] - hkey= - key= - C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.) MsConfig - StartUpReg: [b]HPOSD[/b] - hkey= - key= - C:\Program Files\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.) MsConfig - StartUpReg: [b]IAStorIcon[/b] - hkey= - key= - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) MsConfig - StartUpReg: [b]iTunesHelper[/b] - hkey= - key= - File not found MsConfig - StartUpReg: [b]ROC_ROC_NT[/b] - hkey= - key= - File not found MsConfig - StartUpReg: [b]SetDefault[/b] - hkey= - key= - C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe (Hewlett-Packard Development Company, L.P.) MsConfig - StartUpReg: [b]Skype[/b] - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.) MsConfig - StartUpReg: [b]SunJavaUpdateSched[/b] - hkey= - key= - C:\Program Files\Common Files\Java\Java Update\jusched.exe (Oracle Corporation) MsConfig - StartUpReg: [b]SwitchBoard[/b] - hkey= - key= - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) MsConfig - StartUpReg: [b]SynTPEnh[/b] - hkey= - key= - File not found MsConfig - StartUpReg: [b]SysTrayApp[/b] - hkey= - key= - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.) MsConfig - StartUpReg: [b]vProt[/b] - hkey= - key= - File not found MsConfig - State: "startup" - 2 ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0 ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6 ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7 ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome ActiveX: {90B8F3F7-90EB-810A-9881-03C09FE40C81} - Internet Explorer ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding ActiveX: {A9C62D22-1976-A25B-9125-D2F9232D797D} - Offline Browsing Pack ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface ActiveX: {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} - msiexec /fu {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} /qn ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.) PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin CREATERESTOREPOINT Restore point Set: OTL Restore Point [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014/01/07 21:25:39 | 000,000,000 | ---D | C] -- C:\Users\Nath\Desktop\070114_Pour_Marie_Pascale [2014/01/07 21:09:21 | 000,000,000 | ---D | C] -- C:\AdwCleaner [2014/01/02 22:09:40 | 000,000,000 | ---D | C] -- C:\Users\Nath\AppData\Roaming\SketchUp [2014/01/02 22:08:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp 2013 [2014/01/02 22:07:24 | 000,000,000 | ---D | C] -- C:\ProgramData\SketchUp [2014/01/02 22:07:22 | 000,000,000 | ---D | C] -- C:\Program Files\SketchUp [2014/01/02 19:40:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Google [2014/01/02 19:40:16 | 000,000,000 | ---D | C] -- C:\Users\Nath\AppData\Roaming\Google [2013/12/29 10:13:18 | 000,000,000 | ---D | C] -- C:\Users\Nath\Documents\281213_Safia_Salaires [2013/12/28 13:00:33 | 000,064,168 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswstm.sys [2013/12/26 17:03:28 | 000,000,000 | ---D | C] -- C:\Users\Nath\AppData\Roaming\LavasoftStatistics [2013/12/26 16:23:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus [2013/12/26 16:21:22 | 000,000,000 | ---D | C] -- C:\Users\Nath\AppData\Local\adawarebp [2013/12/26 16:21:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Ad-Aware Browsing Protection [2013/12/26 16:19:32 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft [2013/12/26 16:18:46 | 000,000,000 | ---D | C] -- C:\Users\Nath\AppData\Roaming\Lavasoft [2013/12/26 16:16:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Lavasoft [2013/12/26 16:14:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft [2013/12/24 11:42:56 | 000,000,000 | ---D | C] -- C:\Users\Nath\Documents\Aroma_Zone [2013/12/23 23:05:32 | 000,000,000 | ---D | C] -- C:\Users\Nath\Desktop\Noemie_Cabinet [2013/12/22 08:47:53 | 000,000,000 | ---D | C] -- C:\Users\Nath\Documents\AA_CarteRadios [2013/12/22 08:45:13 | 000,000,000 | ---D | C] -- C:\Users\Nath\Documents\AA_Doc_Tablette_Samsoung [2013/12/22 08:43:36 | 000,000,000 | ---D | C] -- C:\Users\Nath\Desktop\Spa_Legislation_DD [2013/12/17 14:11:09 | 000,104,752 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys [2013/12/17 14:10:45 | 000,264,560 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswNdisFlt.sys [2013/12/12 15:05:30 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird [2013/12/12 11:43:59 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [23 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014/01/07 22:00:21 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin [2014/01/07 21:42:11 | 000,745,250 | ---- | M] () -- C:\Windows\System32\perfh00C.dat [2014/01/07 21:42:11 | 000,652,092 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2014/01/07 21:42:11 | 000,148,478 | ---- | M] () -- C:\Windows\System32\perfc00C.dat [2014/01/07 21:42:11 | 000,120,766 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2014/01/07 21:37:39 | 000,001,052 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2014/01/07 21:25:36 | 000,016,480 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2014/01/07 21:25:36 | 000,016,480 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2014/01/07 21:23:08 | 000,001,048 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2014/01/07 21:19:50 | 000,002,305 | ---- | M] () -- C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk [2014/01/07 21:18:16 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2014/01/07 21:17:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2014/01/07 21:17:36 | 796,102,656 | -HS- | M] () -- C:\hiberfil.sys [2014/01/07 19:34:33 | 000,014,623 | ---- | M] () -- C:\Users\Nath\AppData\Local\recently-used.xbel [2014/01/07 18:55:33 | 000,000,000 | ---- | M] () -- C:\Windows\DBLPOW16.DLL [2014/01/07 18:52:45 | 000,442,368 | ---- | M] (PERRENOUD) -- C:\Windows\Setup1.exe [2014/01/07 18:52:45 | 000,002,393 | ---- | M] () -- C:\Windows\ST6UNST.002 [2014/01/07 18:52:42 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\ST6UNST.EXE [2014/01/06 13:57:17 | 000,001,072 | ---- | M] () -- C:\Users\Nath\Desktop\Mozilla Firefox.lnk [2014/01/06 12:25:44 | 000,007,597 | ---- | M] () -- C:\Users\Nath\AppData\Local\Resmon.ResmonCfg [2014/01/05 09:32:03 | 000,278,398 | ---- | M] () -- C:\Users\Nath\Documents\050114_Les meilleurs vélos_2009 pliants.pdf [2014/01/05 09:29:44 | 000,083,955 | ---- | M] () -- C:\Users\Nath\Documents\050114_Vélo électrique Greencity Vélos Gironde - leboncoin.pdf [2014/01/04 12:41:04 | 000,002,047 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2014/01/02 22:08:51 | 000,003,120 | ---- | M] () -- C:\Windows\System32\ALLFSAF13a.ocx [2014/01/02 22:08:30 | 000,002,158 | ---- | M] () -- C:\Users\Public\Desktop\Style Builder 2013.lnk [2014/01/02 22:08:30 | 000,002,072 | ---- | M] () -- C:\Users\Public\Desktop\LayOut 2013.lnk [2014/01/02 22:08:30 | 000,001,987 | ---- | M] () -- C:\Users\Public\Desktop\SketchUp 2013.lnk [2014/01/02 08:59:44 | 000,672,251 | ---- | M] () -- C:\Users\Nath\Desktop\280911_dossier_creation_entreprise_2008.20222.rtf [2013/12/31 08:57:29 | 006,230,808 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2013/12/29 07:50:23 | 000,064,168 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswstm.sys [2013/12/28 12:59:10 | 000,775,952 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2013/12/28 12:59:10 | 000,410,528 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2013/12/28 12:59:10 | 000,180,248 | ---- | M] () -- C:\Windows\System32\drivers\aswVmm.sys [2013/12/28 12:59:10 | 000,049,944 | ---- | M] () -- C:\Windows\System32\drivers\aswRvrt.sys [2013/12/28 12:59:09 | 000,079,720 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr2.sys [2013/12/28 12:59:09 | 000,067,824 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2013/12/28 12:59:06 | 000,270,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2013/12/28 12:59:06 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2013/12/28 12:57:52 | 000,264,560 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswNdisFlt.sys [2013/12/28 12:42:31 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [2013/12/22 09:13:34 | 000,073,635 | ---- | M] () -- C:\Users\Nath\Desktop\071113_Bureau_Begles - leboncoin.pdf [2013/12/20 17:53:45 | 000,246,941 | ---- | M] () -- C:\Users\Nath\Desktop\conditions_générales_d_inscriptions_15es_Assises.pdf [2013/12/20 17:51:44 | 001,130,851 | ---- | M] () -- C:\Users\Nath\Desktop\programme_ASSISES_2014_191214.pdf [2013/12/19 14:11:31 | 000,056,080 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2013/12/19 14:11:28 | 000,104,752 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys [2013/12/18 21:34:20 | 000,000,316 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForNath.job [2013/12/17 09:40:12 | 003,161,100 | ---- | M] () -- C:\Users\Nath\Documents\13 12 10 Spagnolo CLR avec annexes.pdf [2013/12/15 22:24:20 | 003,187,719 | ---- | M] () -- C:\Users\Nath\Desktop\Talence_agenda21-2013-2014.pdf [2013/12/12 16:08:09 | 000,002,052 | ---- | M] () -- C:\Users\Nath\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk [2013/12/10 21:20:31 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2013/12/10 21:20:31 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [23 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014/01/07 22:00:21 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin [2014/01/07 19:34:33 | 000,014,623 | ---- | C] () -- C:\Users\Nath\AppData\Local\recently-used.xbel [2014/01/07 18:55:33 | 000,000,000 | ---- | C] () -- C:\Windows\DBLPOW16.DLL [2014/01/07 18:52:38 | 000,002,393 | ---- | C] () -- C:\Windows\ST6UNST.002 [2014/01/05 09:32:03 | 000,278,398 | ---- | C] () -- C:\Users\Nath\Documents\050114_Les meilleurs vélos_2009 pliants.pdf [2014/01/05 09:29:44 | 000,083,955 | ---- | C] () -- C:\Users\Nath\Documents\050114_Vélo électrique Greencity Vélos Gironde - leboncoin.pdf [2014/01/04 12:41:04 | 000,002,047 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2014/01/02 22:08:51 | 000,003,120 | ---- | C] () -- C:\Windows\System32\ALLFSAF13a.ocx [2014/01/02 22:08:30 | 000,002,158 | ---- | C] () -- C:\Users\Public\Desktop\Style Builder 2013.lnk [2014/01/02 22:08:30 | 000,002,072 | ---- | C] () -- C:\Users\Public\Desktop\LayOut 2013.lnk [2014/01/02 22:08:30 | 000,001,987 | ---- | C] () -- C:\Users\Public\Desktop\SketchUp 2013.lnk [2014/01/02 08:59:17 | 000,672,251 | ---- | C] () -- C:\Users\Nath\Desktop\280911_dossier_creation_entreprise_2008.20222.rtf [2013/12/31 08:56:56 | 006,230,808 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2013/12/26 16:23:25 | 000,002,305 | ---- | C] () -- C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk [2013/12/22 09:13:34 | 000,073,635 | ---- | C] () -- C:\Users\Nath\Desktop\071113_Bureau_Begles - leboncoin.pdf [2013/12/20 17:53:51 | 000,246,941 | ---- | C] () -- C:\Users\Nath\Desktop\conditions_générales_d_inscriptions_15es_Assises.pdf [2013/12/20 17:51:53 | 001,130,851 | ---- | C] () -- C:\Users\Nath\Desktop\programme_ASSISES_2014_191214.pdf [2013/12/17 09:39:26 | 003,161,100 | ---- | C] () -- C:\Users\Nath\Documents\13 12 10 Spagnolo CLR avec annexes.pdf [2013/12/15 22:23:18 | 003,187,719 | ---- | C] () -- C:\Users\Nath\Desktop\Talence_agenda21-2013-2014.pdf [2013/12/02 08:24:47 | 000,000,000 | ---- | C] () -- C:\ProgramData\2edbnrbn.fvv [2013/12/02 08:24:37 | 095,025,368 | ---- | C] () -- C:\ProgramData\2edbnrbn.bxx [2013/06/11 16:57:15 | 000,000,027 | ---- | C] () -- C:\Users\Nath\AppData\Roaming\Resize! preferences [2013/03/28 23:05:14 | 000,000,004 | -H-- | C] () -- C:\ProgramData\system_ee.dat [2013/03/18 15:37:54 | 000,180,248 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys [2013/03/18 15:37:53 | 000,049,944 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys [2013/01/14 11:25:43 | 000,006,656 | ---- | C] () -- C:\Users\Nath\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012/12/26 16:33:30 | 000,000,132 | ---- | C] () -- C:\Users\Nath\AppData\Roaming\Préfs Filtre IllExportation Adobe CS5 [2012/12/14 15:09:09 | 000,001,456 | ---- | C] () -- C:\Users\Nath\AppData\Local\Adobe Enregistrer pour le Web 12.0 Prefs [2012/11/22 20:40:31 | 000,007,597 | ---- | C] () -- C:\Users\Nath\AppData\Local\Resmon.ResmonCfg [2012/11/10 19:04:13 | 000,000,017 | ---- | C] () -- C:\Windows\System32\shortcut_ex.dat [2012/08/16 07:52:57 | 000,175,616 | ---- | C] () -- C:\Windows\System32\unrar.dll [2012/01/13 21:23:42 | 000,745,250 | ---- | C] () -- C:\Windows\System32\perfh00C.dat [2012/01/13 21:23:42 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat [2012/01/13 21:23:42 | 000,148,478 | ---- | C] () -- C:\Windows\System32\perfc00C.dat [2012/01/13 21:23:42 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat [color=#E56717]========== ZeroAccess Check ==========[/color] [2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012/01/04 09:59:38 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< %systemroot%\*. /mp /s >[/color] [color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color] [23 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] [color=#A23BEC]< %systemroot%\system32\drivers\​*.sys /lockedfiles >[/color] [color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color] Invalid Environment Variable: alluserprofile Invalid Environment Variable: alluserprofile [color=#A23BEC]< %appdata%\*. >[/color] [2013/12/04 18:16:51 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Adobe [2012/08/11 20:56:01 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Apple Computer [2012/03/02 18:58:51 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Atheros [2013/11/24 08:14:35 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\AVAST Software [2013/12/19 18:41:57 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\BitTorrent [2012/12/13 14:08:46 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Canon [2013/02/25 18:54:46 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2012/12/20 11:37:13 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\CyberLink [2012/11/26 21:52:45 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\DAEMON Tools Lite [2014/01/07 22:07:59 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Dropbox [2013/02/11 12:03:21 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\dvdcss [2014/01/07 20:49:46 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\FileZilla [2013/03/28 22:50:25 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\fltk.org [2014/01/02 19:40:16 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Google [2012/03/13 19:01:06 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Hewlett-Packard [2012/12/09 15:07:01 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\hpqlog [2012/03/02 18:58:03 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Identities [2012/03/13 20:46:19 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\IDT [2013/11/15 15:21:42 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\inkscape [2012/03/02 18:58:54 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Intel Corporation [2013/12/26 16:18:46 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Lavasoft [2013/12/26 17:03:28 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\LavasoftStatistics [2013/06/18 07:16:10 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\LibreOffice [2012/03/02 19:01:08 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Macromedia [2013/08/07 18:58:14 | 000,000,000 | --SD | M] -- C:\Users\Nath\AppData\Roaming\Microsoft [2012/03/03 15:07:42 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Mozilla [2013/09/30 15:30:50 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Scribus [2014/01/02 22:09:40 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\SketchUp [2012/11/26 21:52:41 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Skype [2013/06/15 22:53:15 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\SoftGrid Client [2013/05/29 10:46:43 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1 [2012/03/02 18:58:49 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Synaptics [2012/03/03 15:30:48 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Thunderbird [2012/03/02 19:27:17 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\TP [2013/08/31 18:38:32 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\vlc [2013/11/20 20:50:18 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\Windows Live Writer [2012/08/16 07:34:46 | 000,000,000 | ---D | M] -- C:\Users\Nath\AppData\Roaming\WinRAR [color=#A23BEC]< %appdata%\*.exe /s >[/color] [2013/05/25 01:47:30 | 027,776,968 | ---- | M] (Dropbox, Inc.) -- C:\Users\Nath\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013/05/25 01:48:34 | 000,229,288 | ---- | M] (Dropbox, Inc.) -- C:\Users\Nath\AppData\Roaming\Dropbox\bin\DropboxUninstaller.exe [2012/05/24 19:39:24 | 000,872,144 | ---- | M] (Dropbox, Inc.) -- C:\Users\Nath\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe [2013/05/27 11:59:50 | 000,053,632 | ---- | M] (Adobe Systems Inc.) -- C:\Users\Nath\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe [2013/12/20 16:37:46 | 000,514,352 | ---- | M] (Visicom Media Inc.) -- C:\Users\Nath\AppData\Roaming\Mozilla\Firefox\Profiles\bimtdcmz.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}\dtUser.exe [color=#A23BEC]< %systemdrive%\*. >[/color] [2012/03/02 18:58:00 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin [2012/03/23 11:53:41 | 000,000,000 | ---D | M] -- C:\443f94e72a2769d37df18f0054 [2014/01/07 21:15:09 | 000,000,000 | ---D | M] -- C:\AdwCleaner [2012/01/13 23:11:08 | 000,000,000 | -HSD | M] -- C:\boot [2014/01/07 21:17:35 | 000,000,000 | -HSD | M] -- C:\Config.Msi [2009/07/14 05:53:55 | 000,000,000 | -HSD | M] -- C:\Documents and Settings [2013/02/18 10:50:48 | 000,000,000 | ---D | M] -- C:\Données Ciel [2013/03/28 22:55:01 | 000,000,000 | -H-D | M] -- C:\ECS [2011/12/21 02:01:32 | 000,000,000 | -H-D | M] -- C:\HP [2011/12/21 01:41:06 | 000,000,000 | ---D | M] -- C:\Intel [2012/03/20 13:50:30 | 000,000,000 | ---D | M] -- C:\MoTemp [2012/03/03 15:13:26 | 000,000,000 | RH-D | M] -- C:\MSOCache [2009/07/14 03:37:05 | 000,000,000 | ---D | M] -- C:\PerfLogs [2014/01/07 21:14:21 | 000,000,000 | R--D | M] -- C:\Program Files [2014/01/07 21:17:34 | 000,000,000 | -H-D | M] -- C:\ProgramData [2012/03/02 18:54:08 | 000,000,000 | -HSD | M] -- C:\Recovery [2012/12/09 15:01:02 | 000,000,000 | ---D | M] -- C:\SWSetup [2014/01/07 22:01:17 | 000,000,000 | -HSD | M] -- C:\System Volume Information [2012/03/02 18:54:16 | 000,000,000 | -H-D | M] -- C:\SYSTEM.SAV [2012/03/02 18:52:38 | 000,000,000 | R--D | M] -- C:\Users [2014/01/07 18:55:33 | 000,000,000 | ---D | M] -- C:\Windows [color=#A23BEC]< %systemdrive%\*.exe >[/color] [color=#A23BEC]< %programfiles%\*. >[/color] [2013/09/30 13:16:06 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe [2011/12/21 01:42:48 | 000,000,000 | ---D | M] -- C:\Program Files\Atheros [2012/03/03 14:55:27 | 000,000,000 | ---D | M] -- C:\Program Files\AVAST Software [2011/12/21 01:44:17 | 000,000,000 | ---D | M] -- C:\Program Files\Bluetooth Suite [2012/11/07 10:12:41 | 000,000,000 | ---D | M] -- C:\Program Files\Canon [2012/11/07 09:48:39 | 000,000,000 | -H-D | M] -- C:\Program Files\CanonBJ [2012/03/03 15:46:47 | 000,000,000 | ---D | M] -- C:\Program Files\CCleaner [2013/02/18 10:46:56 | 000,000,000 | ---D | M] -- C:\Program Files\Ciel [2011/12/21 01:42:17 | 000,000,000 | ---D | M] -- C:\Program Files\Cisco [2014/01/06 13:57:42 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files [2011/12/21 01:56:47 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink [2012/03/02 20:37:46 | 000,000,000 | ---D | M] -- C:\Program Files\DVD Maker [2012/01/13 13:24:09 | 000,000,000 | ---D | M] -- C:\Program Files\Evernote [2012/03/02 18:52:26 | 000,000,000 | -HSD | M] -- C:\Program Files\Fichiers communs [2012/03/04 11:20:52 | 000,000,000 | ---D | M] -- C:\Program Files\FileZilla FTP Client [2013/09/30 13:40:50 | 000,000,000 | ---D | M] -- C:\Program Files\GIMP 2 [2014/01/02 19:48:47 | 000,000,000 | ---D | M] -- C:\Program Files\Google [2013/09/30 15:23:15 | 000,000,000 | ---D | M] -- C:\Program Files\gs [2012/12/09 15:10:13 | 000,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard [2012/01/13 13:33:54 | 000,000,000 | ---D | M] -- C:\Program Files\HP Games [2011/12/21 01:39:11 | 000,000,000 | ---D | M] -- C:\Program Files\IDT [2013/12/02 20:18:33 | 000,000,000 | ---D | M] -- C:\Program Files\Inkscape [2012/12/09 15:11:35 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information [2011/12/21 01:41:26 | 000,000,000 | ---D | M] -- C:\Program Files\Intel [2012/03/04 11:03:42 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer [2013/10/16 20:57:56 | 000,000,000 | ---D | M] -- C:\Program Files\Java [2012/08/16 07:53:40 | 000,000,000 | ---D | M] -- C:\Program Files\K-Lite Codec Pack [2013/12/26 16:21:58 | 000,000,000 | ---D | M] -- C:\Program Files\Lavasoft [2013/06/17 22:34:02 | 000,000,000 | ---D | M] -- C:\Program Files\LibreOffice 4.0 [2012/03/02 19:13:26 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft [2012/03/04 10:23:56 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Application Virtualization Client [2009/07/14 05:52:30 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Games [2012/03/03 15:18:59 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office [2012/03/04 11:04:58 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Silverlight [2012/01/13 13:43:05 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft SQL Server Compact Edition [2012/03/03 15:18:50 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio [2012/03/03 15:15:24 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio 8 [2012/03/04 22:49:57 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works [2012/03/19 17:46:12 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET [2013/12/12 11:44:31 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox [2013/12/12 18:05:23 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Maintenance Service [2013/12/12 16:08:01 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Thunderbird [2012/03/03 15:19:26 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild [2012/03/02 18:55:21 | 000,000,000 | R--D | M] -- C:\Program Files\Online Services [2011/12/21 01:39:18 | 000,000,000 | ---D | M] -- C:\Program Files\Realtek [2009/07/14 05:52:30 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies [2013/09/30 15:11:59 | 000,000,000 | ---D | M] -- C:\Program Files\Scribus 1.4.3 [2014/01/02 22:07:22 | 000,000,000 | ---D | M] -- C:\Program Files\SketchUp [2012/03/14 07:51:34 | 000,000,000 | R--D | M] -- C:\Program Files\Skype [2011/12/21 02:01:24 | 000,000,000 | ---D | M] -- C:\Program Files\SymSilent [2011/12/21 01:34:53 | 000,000,000 | ---D | M] -- C:\Program Files\Synaptics [2009/07/14 05:53:23 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information [2012/08/15 17:05:24 | 000,000,000 | ---D | M] -- C:\Program Files\VideoLAN [2012/01/13 13:24:32 | 000,000,000 | ---D | M] -- C:\Program Files\WildTangent Games [2012/03/02 20:37:46 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Defender [2012/01/13 13:44:29 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live [2012/03/02 20:37:46 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Mail [2012/03/02 20:37:46 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player [2012/03/02 18:52:26 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT [2012/03/02 20:37:46 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Photo Viewer [2010/11/20 22:33:48 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Portable Devices [2012/03/02 20:37:46 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Sidebar [2012/08/16 07:28:10 | 000,000,000 | ---D | M] -- C:\Program Files\WinRAR [color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color] [2012/01/13 21:37:18 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe [2010/11/20 22:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe [2012/01/13 21:37:18 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\explorer.exe [2012/01/13 21:37:18 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe [color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color] [2010/11/20 22:29:12 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll [2010/11/20 22:29:12 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll [color=#A23BEC]< MD5 for: USERINIT.EXE >[/color] [2010/11/20 22:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe [2010/11/20 22:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color] [2010/11/20 22:29:06 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe [2010/11/20 22:29:06 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe < End of report >