cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by user (administrator) on PC-DE-USER on 01-04-2015 08:55:55
Running from C:\Users\user\Desktop
Loaded Profiles: user (Available profiles: user)
Platform: Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1 (X86) OS Language: Français (France)
Internet Explorer Version 7 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Agere Systems) C:\Windows\System32\agrsmsvc.exe
(NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
(Egis Incorporated) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
() C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\ACER\Mobility Center\MobilityService.exe
(NewTech InfoSystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
() C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(RealNetworks, Inc.) C:\Program Files\Online Games Manager\ogmservice.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Eastman Kodak Company) C:\Program Files\Kodak\KODAK Share Button App\Listener.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
() C:\Program Files\Cyberlink\Shared files\RichVideo.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5512912 2015-03-30] (Avast Software s.r.o.)
HKU\S-1-5-21-3770375004-2722446479-4232237514-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-3770375004-2722446479-4232237514-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\System32\acer.scr [83554304 2007-04-19] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (Avast Software s.r.o.)
ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll (Egis Incorporated)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\S-1-5-21-3770375004-2722446479-4232237514-1000\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-3770375004-2722446479-4232237514-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-3770375004-2722446479-4232237514-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com
HKU\S-1-5-21-3770375004-2722446479-4232237514-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3770375004-2722446479-4232237514-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-21-3770375004-2722446479-4232237514-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_frFR511
SearchScopes: HKU\S-1-5-21-3770375004-2722446479-4232237514-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files\PDF Architect\PDFIEHelper.dll [2013-04-08] (pdfforge GmbH)
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO: ShowBarObj Class -> {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} -> C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-03-05] (Egis)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-30] (Avast Software s.r.o.)
BHO: Programme d'aide de l'Assistant de connexion Windows Live -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-11-18] (Microsoft Corporation)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File []
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File []
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{E5C5E9FB-51FC-43A4-AC60-98C5DA45736E}: [NameServer] 192.168.1.1,80.10.246.2
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\qq9p16pm.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-31] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll [2011-03-09] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8051.1204 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2008-12-04] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin HKU\S-1-5-21-3770375004-2722446479-4232237514-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Extension: Adblock Plus - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\qq9p16pm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-19]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-06-19]
FF HKLM\...\Firefox\Extensions: [OKitSpace@Vittalia.es] - C:\Users\user\AppData\Roaming\okitspace\Firefox
FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2013-10-08]

Chrome:
=======
CHR StartupUrls: Default -> "https://google.fr/"
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-31]
CHR Extension: (Google Docs) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-31]
CHR Extension: (Google Drive) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-31]
CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-03-31]
CHR Extension: (Google Search) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-31]
CHR Extension: (Google Sheets) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-31]
CHR Extension: (Avast Online Security) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-31]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-31]
CHR Extension: (Google Wallet) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-31]
CHR Extension: (Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-31]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-30]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AeLookupSvc; C:\Windows\System32\aelupsvc.dll [24576 2006-11-02] (Microsoft Corporation) [File not signed]
R2 AgereModemAudio; C:\Windows\system32\agrsmsvc.exe [13312 2008-03-18] (Agere Systems) [File not signed]
S3 ALG; C:\Windows\System32\alg.exe [59392 2008-01-21] (Microsoft Corporation) [File not signed]
R3 Appinfo; C:\Windows\System32\appinfo.dll [33280 2008-01-21] (Microsoft Corporation) [File not signed]
R2 AudioEndpointBuilder; C:\Windows\System32\Audiosrv.dll [314368 2008-01-21] (Microsoft Corporation) [File not signed]
R2 Audiosrv; C:\Windows\System32\Audiosrv.dll [314368 2008-01-21] (Microsoft Corporation) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-03-30] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3205216 2015-03-30] (Avast Software)
R2 BFE; C:\Windows\System32\bfe.dll [328704 2008-01-21] (Microsoft Corporation) [File not signed]
R2 BITS; C:\Windows\System32\qmgr.dll [758272 2008-01-21] (Microsoft Corporation) [File not signed]
R2 Browser; C:\Windows\System32\browser.dll [81920 2008-01-21] (Microsoft Corporation) [File not signed]
R2 BUNAgentSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [16384 2008-03-03] (NewTech Infosystems, Inc.) [File not signed]
S3 CertPropSvc; C:\Windows\System32\certprop.dll [40448 2008-01-21] (Microsoft Corporation) [File not signed]
R2 CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [81504 2008-01-16] () [File not signed]
R2 CryptSvc; C:\Windows\system32\cryptsvc.dll [128000 2008-01-21] (Microsoft Corporation) [File not signed]
R2 DcomLaunch; C:\Windows\system32\rpcss.dll [547328 2008-01-21] (Microsoft Corporation) [File not signed]
S3 DFSR; C:\Windows\system32\DFSR.exe [2091520 2008-01-21] (Microsoft Corporation) [File not signed]
R2 Dhcp; C:\Windows\System32\dhcpcsvc.dll [204288 2008-01-21] (Microsoft Corporation) [File not signed]
R2 Dnscache; C:\Windows\System32\dnsrslvr.dll [86528 2008-01-21] (Microsoft Corporation) [File not signed]
S3 dot3svc; C:\Windows\System32\dot3svc.dll [175104 2008-01-21] (Microsoft Corporation) [File not signed]
R2 DPS; C:\Windows\system32\dps.dll [134656 2008-01-21] (Microsoft Corporation) [File not signed]
R3 EapHost; C:\Windows\System32\eapsvc.dll [57344 2008-01-21] (Microsoft Corporation) [File not signed]
S3 ehRecvr; C:\Windows\ehome\ehRecvr.exe [292352 2008-01-21] (Microsoft Corporation) [File not signed]
S3 ehSched; C:\Windows\ehome\ehsched.exe [131072 2006-11-02] (Microsoft Corporation) [File not signed]
S2 ehstart; C:\Windows\ehome\ehstart.dll [13312 2006-11-02] (Microsoft Corporation) [File not signed]
R2 EMDMgmt; C:\Windows\system32\emdmgmt.dll [565248 2008-06-26] (Microsoft Corporation) [File not signed]
R2 ETService; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [24576 2008-03-21] () [File not signed]
R2 Eventlog; C:\Windows\System32\wevtsvc.dll [1013760 2008-01-21] (Microsoft Corporation) [File not signed]
R2 EventSystem; C:\Windows\system32\es.dll [269312 2008-04-18] (Microsoft Corporation) [File not signed]
R3 fdPHost; C:\Windows\system32\fdPHost.dll [13312 2008-01-21] (Microsoft Corporation) [File not signed]
R2 FDResPub; C:\Windows\system32\fdrespub.dll [27648 2006-11-02] (Microsoft Corporation) [File not signed]
S3 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [36864 2008-01-21] (Microsoft Corporation) [File not signed]
R2 gpsvc; C:\Windows\System32\gpsvc.dll [574464 2008-01-21] (Microsoft Corporation) [File not signed]
R2 hidserv; C:\Windows\system32\hidserv.dll [25600 2006-11-02] (Microsoft Corporation) [File not signed]
S3 hkmsvc; C:\Windows\system32\kmsvc.dll [68096 2008-01-21] (Microsoft Corporation) [File not signed]
S3 idsvc; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [864256 2008-01-21] (Microsoft Corporation) [File not signed]
R2 IKEEXT; C:\Windows\System32\ikeext.dll [438272 2008-01-21] (Microsoft Corporation) [File not signed]
S3 IPBusEnum; C:\Windows\system32\ipbusenum.dll [74240 2008-01-21] (Microsoft Corporation) [File not signed]
R2 iphlpsvc; C:\Windows\System32\iphlpsvc.dll [188416 2008-01-21] (Microsoft Corporation) [File not signed]
R3 KeyIso; C:\Windows\system32\lsass.exe [9728 2008-01-21] (Microsoft Corporation) [File not signed]
R2 KtmRm; C:\Windows\system32\msdtckrm.dll [344576 2008-01-21] (Microsoft Corporation) [File not signed]
R2 LanmanServer; C:\Windows\system32\srvsvc.dll [122880 2008-01-21] (Microsoft Corporation) [File not signed]
R2 LanmanWorkstation; C:\Windows\System32\wkssvc.dll [160256 2008-01-21] (Microsoft Corporation) [File not signed]
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
S3 lltdsvc; C:\Windows\System32\lltdsvc.dll [188928 2008-01-21] (Microsoft Corporation) [File not signed]
R2 lmhosts; C:\Windows\System32\lmhsvc.dll [18944 2006-11-02] (Microsoft Corporation) [File not signed]
S4 Mcx2Svc; C:\Windows\system32\Mcx2Svc.dll [53760 2008-01-21] (Microsoft Corporation) [File not signed]
R2 MMCSS; C:\Windows\system32\mmcss.dll [45056 2008-01-21] (Microsoft Corporation) [File not signed]
R2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-12-06] () [File not signed]
R2 MpsSvc; C:\Windows\system32\mpssvc.dll [393216 2008-01-21] (Microsoft Corporation) [File not signed]
S3 MSDTC; C:\Windows\System32\msdtc.exe [105984 2008-01-21] (Microsoft Corporation) [File not signed]
S3 MSiSCSI; C:\Windows\system32\iscsiexe.dll [111616 2008-01-21] (Microsoft Corporation) [File not signed]
S3 msiserver; C:\Windows\System32\msiexec.exe [71680 2008-01-21] (Microsoft Corporation) [File not signed]
S3 napagent; C:\Windows\system32\qagentRT.dll [302080 2008-01-21] (Microsoft Corporation) [File not signed]
S3 Netlogon; C:\Windows\system32\lsass.exe [9728 2008-01-21] (Microsoft Corporation) [File not signed]
R3 Netman; C:\Windows\System32\netman.dll [274432 2008-01-21] (Microsoft Corporation) [File not signed]
R2 netprofm; C:\Windows\System32\netprofm.dll [237056 2008-01-21] (Microsoft Corporation) [File not signed]
S4 NetTcpPortSharing; C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [122880 2008-01-21] (Microsoft Corporation) [File not signed]
R2 NlaSvc; C:\Windows\System32\nlasvc.dll [168448 2008-01-21] (Microsoft Corporation) [File not signed]
R2 nsi; C:\Windows\system32\nsisvc.dll [18432 2008-01-21] (Microsoft Corporation) [File not signed]
R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [131072 2008-04-04] () [File not signed]
R2 ogmservice; C:\Program Files\Online Games Manager\ogmservice.exe [581568 2014-03-27] (RealNetworks, Inc.)
S3 p2pimsvc; C:\Windows\system32\p2psvc.dll [658944 2008-01-21] (Microsoft Corporation) [File not signed]
S3 p2psvc; C:\Windows\system32\p2psvc.dll [658944 2008-01-21] (Microsoft Corporation) [File not signed]
R2 PcaSvc; C:\Windows\System32\pcasvc.dll [37888 2008-01-21] (Microsoft Corporation) [File not signed]
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
S2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
S3 pla; C:\Windows\system32\pla.dll [1502208 2008-01-21] (Microsoft Corporation) [File not signed]
R2 PlugPlay; C:\Windows\system32\umpnpmgr.dll [221696 2008-01-21] (Microsoft Corporation) [File not signed]
S3 PNRPAutoReg; C:\Windows\system32\p2psvc.dll [658944 2008-01-21] (Microsoft Corporation) [File not signed]
S3 PNRPsvc; C:\Windows\system32\p2psvc.dll [658944 2008-01-21] (Microsoft Corporation) [File not signed]
R2 PolicyAgent; C:\Windows\System32\ipsecsvc.dll [361984 2008-06-19] (Microsoft Corporation) [File not signed]
R2 ProfSvc; C:\Windows\system32\profsvc.dll [153600 2008-01-21] (Microsoft Corporation) [File not signed]
S3 ProtectedStorage; C:\Windows\system32\lsass.exe [9728 2008-01-21] (Microsoft Corporation) [File not signed]
S3 QWAVE; C:\Windows\system32\qwave.dll [243712 2008-01-21] (Microsoft Corporation) [File not signed]
S3 RasAuto; C:\Windows\System32\rasauto.dll [90624 2008-01-21] (Microsoft Corporation) [File not signed]
R3 RasMan; C:\Windows\System32\rasmans.dll [260608 2008-01-21] (Microsoft Corporation) [File not signed]
S4 RemoteAccess; C:\Windows\System32\mprdim.dll [68608 2008-01-21] (Microsoft Corporation) [File not signed]
S3 RemoteRegistry; C:\Windows\system32\regsvc.dll [106496 2008-01-21] (Microsoft Corporation) [File not signed]
R2 RichVideo; C:\Program Files\Cyberlink\Shared files\RichVideo.exe [272024 2007-01-09] ()
S3 RpcLocator; C:\Windows\system32\locator.exe [7680 2006-11-02] (Microsoft Corporation) [File not signed]
R2 RpcSs; C:\Windows\system32\rpcss.dll [547328 2008-01-21] (Microsoft Corporation) [File not signed]
R2 SamSs; C:\Windows\system32\lsass.exe [9728 2008-01-21] (Microsoft Corporation) [File not signed]
S3 SCardSvr; C:\Windows\System32\SCardSvr.dll [95232 2008-01-21] (Microsoft Corporation) [File not signed]
R2 Schedule; C:\Windows\system32\schedsvc.dll [596992 2008-01-21] (Microsoft Corporation) [File not signed]
S3 SCPolicySvc; C:\Windows\System32\certprop.dll [40448 2008-01-21] (Microsoft Corporation) [File not signed]
S3 SDRSVC; C:\Windows\System32\SDRSVC.dll [104960 2008-01-21] (Microsoft Corporation) [File not signed]
R2 seclogon; C:\Windows\system32\seclogon.dll [19968 2008-01-21] (Microsoft Corporation) [File not signed]
R2 SENS; C:\Windows\System32\sens.dll [47104 2008-01-21] (Microsoft Corporation) [File not signed]
S3 SessionEnv; C:\Windows\system32\sessenv.dll [84992 2008-01-21] (Microsoft Corporation) [File not signed]
S4 SharedAccess; C:\Windows\System32\ipnathlp.dll [288256 2008-01-21] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\Windows\System32\shsvcs.dll [247296 2008-01-21] (Microsoft Corporation) [File not signed]
R2 slsvc; C:\Windows\system32\SLsvc.exe [2623488 2008-01-21] (Microsoft Corporation) [File not signed]
S3 SLUINotify; C:\Windows\system32\SLUINotify.dll [57856 2008-01-21] (Microsoft Corporation) [File not signed]
S3 SNMPTRAP; C:\Windows\System32\snmptrap.exe [12800 2006-11-02] (Microsoft Corporation) [File not signed]
R2 Spooler; C:\Windows\System32\spoolsv.exe [125952 2008-01-21] (Microsoft Corporation) [File not signed]
R3 SSDPSRV; C:\Windows\System32\ssdpsrv.dll [155648 2008-01-21] (Microsoft Corporation) [File not signed]
R3 SstpSvc; C:\Windows\system32\sstpsvc.dll [116736 2008-01-21] (Microsoft Corporation) [File not signed]
R2 stisvc; C:\Windows\System32\wiaservc.dll [452608 2008-01-21] (Microsoft Corporation) [File not signed]
S3 swprv; C:\Windows\System32\swprv.dll [310784 2008-01-21] (Microsoft Corporation) [File not signed]
R2 SysMain; C:\Windows\system32\sysmain.dll [574976 2008-01-21] (Microsoft Corporation) [File not signed]
R2 TabletInputService; C:\Windows\System32\TabSvc.dll [68096 2006-11-02] (Microsoft Corporation) [File not signed]
R3 TapiSrv; C:\Windows\System32\tapisrv.dll [242688 2008-01-21] (Microsoft Corporation) [File not signed]
S2 TBS; C:\Windows\System32\tbssvc.dll [56320 2008-01-21] (Microsoft Corporation) [File not signed]
R2 TermService; C:\Windows\System32\termsrv.dll [448512 2008-01-21] (Microsoft Corporation) [File not signed]
R2 Themes; C:\Windows\system32\shsvcs.dll [247296 2008-01-21] (Microsoft Corporation) [File not signed]
S3 THREADORDER; C:\Windows\system32\mmcss.dll [45056 2008-01-21] (Microsoft Corporation) [File not signed]
R2 TrkWks; C:\Windows\System32\trkwks.dll [75264 2008-01-21] (Microsoft Corporation) [File not signed]
S3 TrustedInstaller; C:\Windows\servicing\TrustedInstaller.exe [39424 2008-01-21] (Microsoft Corporation) [File not signed]
S3 UI0Detect; C:\Windows\system32\UI0Detect.exe [35840 2008-01-21] (Microsoft Corporation) [File not signed]
R2 upnphost; C:\Windows\System32\upnphost.dll [259072 2008-01-21] (Microsoft Corporation) [File not signed]
R2 UxSms; C:\Windows\System32\uxsms.dll [28672 2008-01-21] (Microsoft Corporation) [File not signed]
S3 vds; C:\Windows\System32\vds.exe [382976 2008-01-21] (Microsoft Corporation) [File not signed]
S3 VSS; C:\Windows\system32\vssvc.exe [1054720 2008-01-21] (Microsoft Corporation) [File not signed]
R2 W32Time; C:\Windows\system32\w32time.dll [282624 2008-01-21] (Microsoft Corporation) [File not signed]
R3 wcncsvc; C:\Windows\System32\wcncsvc.dll [412672 2008-01-21] (Microsoft Corporation) [File not signed]
S3 WcsPlugInService; C:\Windows\System32\WcsPlugInService.dll [32256 2006-11-02] (Microsoft Corporation) [File not signed]
S3 WdiServiceHost; C:\Windows\system32\wdi.dll [73728 2008-01-21] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\Windows\system32\wdi.dll [73728 2008-01-21] (Microsoft Corporation) [File not signed]
R2 WebClient; C:\Windows\System32\webclnt.dll [196608 2008-01-21] (Microsoft Corporation) [File not signed]
S3 Wecsvc; C:\Windows\system32\wecsvc.dll [145408 2008-01-21] (Microsoft Corporation) [File not signed]
S3 wercplsupport; C:\Windows\System32\wercplsupport.dll [62976 2008-01-21] (Microsoft Corporation) [File not signed]
R2 WerSvc; C:\Windows\System32\WerSvc.dll [125952 2008-09-18] (Microsoft Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
S3 WinHttpAutoProxySvc; C:\Windows\system32\winhttp.dll [376832 2008-01-21] (Microsoft Corporation) [File not signed]
R3 Winmgmt; C:\Windows\system32\wbem\WMIsvc.dll [161792 2008-01-21] (Microsoft Corporation) [File not signed]
S3 WinRM; C:\Windows\system32\WsmSvc.dll [745472 2008-01-21] (Microsoft Corporation) [File not signed]
R2 Wlansvc; C:\Windows\System32\wlansvc.dll [513536 2008-01-21] (Microsoft Corporation) [File not signed]
S3 wmiApSrv; C:\Windows\system32\wbem\WmiApSrv.exe [137728 2008-01-21] (Microsoft Corporation) [File not signed]
S3 WMPNetworkSvc; C:\Program Files\Windows Media Player\wmpnetwk.exe [896512 2008-01-21] (Microsoft Corporation) [File not signed]
S3 WPCSvc; C:\Windows\System32\wpcsvc.dll [140288 2008-01-21] (Microsoft Corporation) [File not signed]
R2 WPDBusEnum; C:\Windows\system32\wpdbusenum.dll [70144 2008-01-21] (Microsoft Corporation) [File not signed]
R2 wscsvc; C:\Windows\System32\wscsvc.dll [61440 2008-01-21] (Microsoft Corporation) [File not signed]
S2 WSearch; C:\Windows\system32\SearchIndexer.exe [439808 2008-05-27] (Microsoft Corporation) [File not signed]
R2 wuauserv; C:\Windows\system32\wuaueng.dll [1695232 2008-01-21] (Microsoft Corporation) [File not signed]
R2 wudfsvc; C:\Windows\System32\WUDFSvc.dll [55296 2008-01-21] (Microsoft Corporation) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 AFD; C:\Windows\system32\drivers\afd.sys [273920 2008-01-21] (Microsoft Corporation) [File not signed]
R3 AgereSoftModem; C:\Windows\System32\DRIVERS\AGRSM.sys [1202560 2008-02-29] (Agere Systems) [File not signed]
S4 AmdK7; C:\Windows\system32\drivers\amdk7.sys [41472 2008-01-21] (Microsoft Corporation) [File not signed]
S4 AmdK8; C:\Windows\system32\drivers\amdk8.sys [44032 2008-01-21] (Microsoft Corporation) [File not signed]
S3 AR9271; C:\Windows\System32\DRIVERS\athuw.sys [1763584 2011-07-28] (Atheros Communications, Inc.) [File not signed]
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24144 2015-03-30] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [73440 2015-03-30] (Avast Software s.r.o.)
R1 AswRdr; C:\Windows\system32\drivers\aswRdr.sys [55200 2015-03-30] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49904 2015-03-30] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [788272 2015-03-30] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427736 2015-03-30] (Avast Software s.r.o.)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57888 2015-03-30] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [208024 2015-03-30] ()
R3 AsyncMac; C:\Windows\System32\DRIVERS\asyncmac.sys [17408 2008-01-21] (Microsoft Corporation) [File not signed]
R3 b57nd60x; C:\Windows\System32\DRIVERS\b57nd60x.sys [210432 2008-03-28] (Broadcom Corporation) [File not signed]
R1 Beep; C:\Windows\system32\Drivers\Beep.sys [6144 2008-01-21] (Microsoft Corporation) [File not signed]
S4 blbdrive; C:\Windows\system32\drivers\blbdrive.sys [45568 2008-01-21] (Microsoft Corporation) [File not signed]
R3 bowser; C:\Windows\System32\DRIVERS\bowser.sys [69632 2008-01-21] (Microsoft Corporation) [File not signed]
S3 BrFiltLo; C:\Windows\system32\drivers\brfiltlo.sys [13568 2006-11-02] (Brother Industries, Ltd.) [File not signed]
S3 BrFiltUp; C:\Windows\system32\drivers\brfiltup.sys [5248 2006-11-02] (Brother Industries, Ltd.) [File not signed]
S4 Brserid; C:\Windows\system32\drivers\brserid.sys [71808 2006-11-02] (Brother Industries Ltd.) [File not signed]
S4 BrSerWdm; C:\Windows\system32\drivers\brserwdm.sys [62336 2006-11-02] (Brother Industries Ltd.) [File not signed]
S4 BrUsbMdm; C:\Windows\system32\drivers\brusbmdm.sys [12160 2006-11-02] (Brother Industries Ltd.) [File not signed]
S3 BrUsbSer; C:\Windows\system32\drivers\brusbser.sys [11904 2006-11-02] (Brother Industries Ltd.) [File not signed]
S4 BTHMODEM; C:\Windows\system32\drivers\bthmodem.sys [39936 2006-11-02] (Microsoft Corporation) [File not signed]
R4 cdfs; C:\Windows\System32\DRIVERS\cdfs.sys [70144 2008-01-21] (Microsoft Corporation) [File not signed]
R1 cdrom; C:\Windows\System32\DRIVERS\cdrom.sys [67072 2008-01-21] (Microsoft Corporation) [File not signed]
R3 circlass; C:\Windows\System32\DRIVERS\circlass.sys [35328 2008-01-21] (Microsoft Corporation) [File not signed]
R3 CmBatt; C:\Windows\System32\DRIVERS\CmBatt.sys [14208 2008-01-21] (Microsoft Corporation) [File not signed]
S4 Crusoe; C:\Windows\system32\drivers\crusoe.sys [40960 2008-01-21] (Microsoft Corporation) [File not signed]
R1 DfsC; C:\Windows\System32\Drivers\dfsc.sys [75264 2008-01-21] (Microsoft Corporation) [File not signed]
S3 drmkaud; C:\Windows\System32\drivers\drmkaud.sys [5632 2008-01-21] (Microsoft Corporation) [File not signed]
R3 DXGKrnl; C:\Windows\System32\drivers\dxgkrnl.sys [625152 2008-08-02] (Microsoft Corporation) [File not signed]
S3 E1G60; C:\Windows\System32\DRIVERS\E1G60I32.sys [118784 2008-01-21] (Intel Corporation) [File not signed]
S4 ErrDev; C:\Windows\system32\drivers\errdev.sys [6656 2008-01-21] (Microsoft Corporation) [File not signed]
S3 exfat; C:\Windows\system32\Drivers\exfat.sys [136192 2008-01-21] (Microsoft Corporation) [File not signed]
S3 fastfat; C:\Windows\system32\Drivers\fastfat.sys [143360 2008-01-21] (Microsoft Corporation) [File not signed]
S4 fdc; C:\Windows\System32\DRIVERS\fdc.sys [25088 2008-01-21] (Microsoft Corporation) [File not signed]
S3 Filetrace; C:\Windows\System32\drivers\filetrace.sys [27648 2008-01-21] (Microsoft Corporation) [File not signed]
S4 flpydisk; C:\Windows\System32\DRIVERS\flpydisk.sys [20480 2008-01-21] (Microsoft Corporation) [File not signed]
U1 Fs_Rec; C:\Windows\system32\Drivers\Fs_Rec.sys [12800 2008-01-21] (Microsoft Corporation) [File not signed]
R3 HdAudAddService; C:\Windows\System32\drivers\HdAudio.sys [235520 2006-11-02] (Microsoft Corporation) [File not signed]
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [53760 2008-01-21] (Microsoft Corporation) [File not signed]
S4 HidBth; C:\Windows\system32\drivers\hidbth.sys [29184 2006-11-02] (Microsoft Corporation) [File not signed]
R3 HidIr; C:\Windows\System32\DRIVERS\hidir.sys [21504 2008-01-21] (Microsoft Corporation) [File not signed]
R3 HidUsb; C:\Windows\System32\DRIVERS\hidusb.sys [12288 2008-01-21] (Microsoft Corporation) [File not signed]
R3 HTTP; C:\Windows\System32\drivers\HTTP.sys [401408 2008-01-21] (Microsoft Corporation) [File not signed]
R1 i8042prt; C:\Windows\System32\DRIVERS\i8042prt.sys [54784 2008-01-21] (Microsoft Corporation) [File not signed]
R3 intelppm; C:\Windows\System32\DRIVERS\intelppm.sys [41472 2008-01-21] (Microsoft Corporation) [File not signed]
R2 IpFilterDriver; C:\Windows\System32\DRIVERS\ipfltdrv.sys [47616 2008-01-21] (Microsoft Corporation) [File not signed]
S4 IPMIDRV; C:\Windows\system32\drivers\ipmidrv.sys [64512 2008-01-21] (Microsoft Corporation) [File not signed]
S3 IPNAT; C:\Windows\System32\DRIVERS\ipnat.sys [100864 2008-01-21] (Microsoft Corporation) [File not signed]
S3 IRENUM; C:\Windows\System32\drivers\irenum.sys [13312 2008-01-21] (Microsoft Corporation) [File not signed]
R3 JMCR; C:\Windows\System32\DRIVERS\jmcr.sys [81296 2008-04-21] (JMicron Technology Corp.) [File not signed]
R1 kbdhid; C:\Windows\System32\DRIVERS\kbdhid.sys [15872 2008-01-21] (Microsoft Corporation) [File not signed]
R2 lltdio; C:\Windows\System32\DRIVERS\lltdio.sys [47104 2008-01-21] (Microsoft Corporation) [File not signed]
R2 luafv; C:\Windows\system32\drivers\luafv.sys [84480 2008-01-21] (Microsoft Corporation) [File not signed]
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-03-31] (Malwarebytes Corporation)
R3 Modem; C:\Windows\System32\drivers\modem.sys [31744 2008-01-21] (Microsoft Corporation) [File not signed]
R3 monitor; C:\Windows\System32\DRIVERS\monitor.sys [41984 2008-01-21] (Microsoft Corporation) [File not signed]
R3 mouhid; C:\Windows\System32\DRIVERS\mouhid.sys [15872 2008-01-21] (Microsoft Corporation) [File not signed]
R3 mpsdrv; C:\Windows\System32\drivers\mpsdrv.sys [64000 2008-01-21] (Microsoft Corporation) [File not signed]
R3 MRxDAV; C:\Windows\system32\drivers\mrxdav.sys [110080 2008-01-21] (Microsoft Corporation) [File not signed]
R3 mrxsmb; C:\Windows\System32\DRIVERS\mrxsmb.sys [105472 2008-01-21] (Microsoft Corporation) [File not signed]
R3 mrxsmb10; C:\Windows\System32\DRIVERS\mrxsmb10.sys [212480 2008-08-27] (Microsoft Corporation) [File not signed]
R3 mrxsmb20; C:\Windows\System32\DRIVERS\mrxsmb20.sys [78848 2008-01-21] (Microsoft Corporation) [File not signed]
S3 MSKSSRV; C:\Windows\System32\drivers\MSKSSRV.sys [8192 2008-01-21] (Microsoft Corporation) [File not signed]
S3 MSPCLOCK; C:\Windows\System32\drivers\MSPCLOCK.sys [5888 2008-01-21] (Microsoft Corporation) [File not signed]
S3 MSPQM; C:\Windows\System32\drivers\MSPQM.sys [5504 2008-01-21] (Microsoft Corporation) [File not signed]
S3 MSTEE; C:\Windows\System32\drivers\MSTEE.sys [6016 2008-01-21] (Microsoft Corporation) [File not signed]
R3 NativeWifiP; C:\Windows\System32\DRIVERS\nwifi.sys [148480 2008-05-20] (Microsoft Corporation) [File not signed]
R3 NdisTapi; C:\Windows\System32\DRIVERS\ndistapi.sys [20992 2008-01-21] (Microsoft Corporation) [File not signed]
R3 Ndisuio; C:\Windows\System32\DRIVERS\ndisuio.sys [16896 2008-01-21] (Microsoft Corporation) [File not signed]
R3 NdisWan; C:\Windows\System32\DRIVERS\ndiswan.sys [121344 2008-01-21] (Microsoft Corporation) [File not signed]
R3 NDProxy; C:\Windows\system32\Drivers\NDProxy.sys [49664 2008-01-21] (Microsoft Corporation) [File not signed]
R1 NetBIOS; C:\Windows\System32\DRIVERS\netbios.sys [35840 2008-01-21] (Microsoft Corporation) [File not signed]
R1 netbt; C:\Windows\System32\DRIVERS\netbt.sys [184320 2008-01-21] (Microsoft Corporation) [File not signed]
R3 NETw5v32; C:\Windows\System32\DRIVERS\NETw5v32.sys [3658752 2008-04-28] (Intel Corporation) [File not signed]
R1 Npfs; C:\Windows\system32\Drivers\Npfs.sys [34816 2008-01-21] (Microsoft Corporation) [File not signed]
R1 nsiproxy; C:\Windows\System32\drivers\nsiproxy.sys [16384 2008-01-21] (Microsoft Corporation) [File not signed]
R2 NTIPPKernel; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [122368 2008-01-16] (Cyberlink Corp.) [File not signed]
S4 ntrigdigi; C:\Windows\system32\drivers\ntrigdigi.sys [20608 2006-11-02] (N-trig Innovative Technologies) [File not signed]
R1 Null; C:\Windows\system32\Drivers\Null.sys [4608 2008-01-21] (Microsoft Corporation) [File not signed]
R3 nvlddmkm; C:\Windows\System32\DRIVERS\nvlddmkm.sys [7451264 2008-12-29] (NVIDIA Corporation) [File not signed]
S4 ohci1394; C:\Windows\system32\drivers\ohci1394.sys [62080 2006-11-02] (Microsoft Corporation) [File not signed]
S4 Parport; C:\Windows\system32\drivers\parport.sys [79360 2006-11-02] (Microsoft Corporation) [File not signed]
S2 Parvdm; C:\Windows\system32\drivers\parvdm.sys [8704 2006-11-02] (Microsoft Corporation) [File not signed]
R2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [878080 2006-11-02] (Microsoft Corporation) [File not signed]
R3 PptpMiniport; C:\Windows\System32\DRIVERS\raspptp.sys [62976 2008-01-21] (Microsoft Corporation) [File not signed]
S4 Processor; C:\Windows\system32\drivers\processr.sys [40960 2008-01-21] (Microsoft Corporation) [File not signed]
R1 PSched; C:\Windows\System32\DRIVERS\pacer.sys [72192 2008-04-05] (Microsoft Corporation) [File not signed]
S3 QWAVEdrv; C:\Windows\system32\drivers\qwavedrv.sys [31232 2008-01-21] (Microsoft Corporation) [File not signed]
R1 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [11776 2008-01-21] (Microsoft Corporation) [File not signed]
R3 Rasl2tp; C:\Windows\System32\DRIVERS\rasl2tp.sys [76288 2008-01-21] (Microsoft Corporation) [File not signed]
R3 RasPppoe; C:\Windows\System32\DRIVERS\raspppoe.sys [41472 2008-01-21] (Microsoft Corporation) [File not signed]
R3 RasSstp; C:\Windows\System32\DRIVERS\rassstp.sys [69120 2008-01-21] (Microsoft Corporation) [File not signed]
R1 rdbss; C:\Windows\System32\DRIVERS\rdbss.sys [224768 2008-01-21] (Microsoft Corporation) [File not signed]
R1 RDPCDD; C:\Windows\System32\DRIVERS\RDPCDD.sys [6144 2008-01-21] (Microsoft Corporation) [File not signed]
S4 rdpdr; C:\Windows\system32\drivers\rdpdr.sys [248832 2008-01-21] (Microsoft Corporation) [File not signed]
R1 RDPENCDD; C:\Windows\System32\drivers\rdpencdd.sys [6144 2008-01-21] (Microsoft Corporation) [File not signed]
R2 rspndr; C:\Windows\System32\DRIVERS\rspndr.sys [60416 2008-01-21] (Microsoft Corporation) [File not signed]
S4 sdbus; C:\Windows\System32\DRIVERS\sdbus.sys [88576 2008-01-21] (Microsoft Corporation) [File not signed]
R2 secdrv; C:\Windows\system32\Drivers\secdrv.sys [20480 2006-11-02] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
S3 Serenum; C:\Windows\system32\drivers\serenum.sys [17920 2006-11-02] (Microsoft Corporation) [File not signed]
S4 Serial; C:\Windows\system32\drivers\serial.sys [83456 2006-11-02] (Microsoft Corporation) [File not signed]
S4 sermouse; C:\Windows\system32\drivers\sermouse.sys [19968 2008-01-21] (Microsoft Corporation) [File not signed]
S4 sffdisk; C:\Windows\system32\drivers\sffdisk.sys [13312 2008-01-21] (Microsoft Corporation) [File not signed]
S3 sffp_mmc; C:\Windows\system32\drivers\sffp_mmc.sys [12288 2008-01-21] (Microsoft Corporation) [File not signed]
S3 sffp_sd; C:\Windows\system32\drivers\sffp_sd.sys [11776 2008-01-21] (Microsoft Corporation) [File not signed]
S4 sfloppy; C:\Windows\system32\drivers\sfloppy.sys [13312 2006-11-02] (Microsoft Corporation) [File not signed]
R1 Smb; C:\Windows\System32\DRIVERS\smb.sys [66560 2008-01-21] (Microsoft Corporation) [File not signed]
R3 srv; C:\Windows\System32\DRIVERS\srv.sys [288768 2008-08-27] (Microsoft Corporation) [File not signed]
R3 srv2; C:\Windows\System32\DRIVERS\srv2.sys [144384 2008-01-21] (Microsoft Corporation) [File not signed]
R3 srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [98304 2008-01-21] (Microsoft Corporation) [File not signed]
R3 StillCam; C:\Windows\System32\DRIVERS\serscan.sys [9216 2008-01-21] (Microsoft Corporation) [File not signed]
R2 tcpipreg; C:\Windows\System32\drivers\tcpipreg.sys [30208 2008-01-21] (Microsoft Corporation) [File not signed]
S3 TDPIPE; C:\Windows\System32\drivers\tdpipe.sys [17920 2008-01-21] (Microsoft Corporation) [File not signed]
S3 TDTCP; C:\Windows\System32\drivers\tdtcp.sys [29184 2008-01-21] (Microsoft Corporation) [File not signed]
R1 tdx; C:\Windows\System32\DRIVERS\tdx.sys [71680 2008-01-21] (Microsoft Corporation) [File not signed]
S3 tssecsrv; C:\Windows\System32\DRIVERS\tssecsrv.sys [23552 2008-01-21] (Microsoft Corporation) [File not signed]
R3 tunmp; C:\Windows\System32\DRIVERS\tunmp.sys [15360 2008-01-21] (Microsoft Corporation) [File not signed]
R3 tunnel; C:\Windows\System32\DRIVERS\tunnel.sys [23040 2008-01-21] (Microsoft Corporation) [File not signed]
S4 udfs; C:\Windows\System32\DRIVERS\udfs.sys [226816 2008-01-21] (Microsoft Corporation) [File not signed]
R3 umbus; C:\Windows\System32\DRIVERS\umbus.sys [34816 2008-01-21] (Microsoft Corporation) [File not signed]
R3 usbccgp; C:\Windows\System32\DRIVERS\usbccgp.sys [73216 2008-02-05] (Microsoft Corporation) [File not signed]
S4 usbcir; C:\Windows\system32\drivers\usbcir.sys [68608 2006-11-02] (Microsoft Corporation) [File not signed]
R3 usbehci; C:\Windows\System32\DRIVERS\usbehci.sys [39424 2008-02-05] (Microsoft Corporation) [File not signed]
R3 usbhub; C:\Windows\System32\DRIVERS\usbhub.sys [194560 2008-02-05] (Microsoft Corporation) [File not signed]
S4 usbohci; C:\Windows\system32\drivers\usbohci.sys [19456 2006-11-02] (Microsoft Corporation) [File not signed]
S3 usbprint; C:\Windows\System32\DRIVERS\usbprint.sys [18944 2008-01-21] (Microsoft Corporation) [File not signed]
S3 usbscan; C:\Windows\System32\DRIVERS\usbscan.sys [35328 2008-01-21] (Microsoft Corporation) [File not signed]
S3 USBSTOR; C:\Windows\System32\DRIVERS\USBSTOR.SYS [55296 2008-01-21] (Microsoft Corporation) [File not signed]
R3 usbuhci; C:\Windows\System32\DRIVERS\usbuhci.sys [23552 2008-02-05] (Microsoft Corporation) [File not signed]
R3 usbvideo; C:\Windows\System32\Drivers\usbvideo.sys [134016 2008-01-21] (Microsoft Corporation) [File not signed]
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220240 2015-03-30] (Avast Software)
S3 vga; C:\Windows\System32\DRIVERS\vgapnp.sys [26112 2008-01-21] (Microsoft Corporation) [File not signed]
R1 VgaSave; C:\Windows\System32\drivers\vga.sys [25088 2008-01-21] (Microsoft Corporation) [File not signed]
S4 ViaC7; C:\Windows\system32\drivers\viac7.sys [41472 2008-01-21] (Microsoft Corporation) [File not signed]
S4 WacomPen; C:\Windows\system32\drivers\wacompen.sys [20608 2006-11-02] (Microsoft Corporation) [File not signed]
S3 Wanarp; C:\Windows\System32\DRIVERS\wanarp.sys [62464 2008-01-21] (Microsoft Corporation) [File not signed]
R1 Wanarpv6; C:\Windows\System32\DRIVERS\wanarp.sys [62464 2008-01-21] (Microsoft Corporation) [File not signed]
R3 winbondcir; C:\Windows\System32\DRIVERS\winbondcir.sys [43008 2007-03-28] (Winbond Electronics Corporation) [File not signed]
R3 WmiAcpi; C:\Windows\System32\DRIVERS\wmiacpi.sys [11264 2008-01-21] (Microsoft Corporation) [File not signed]
S3 WpdUsb; C:\Windows\System32\DRIVERS\wpdusb.sys [39936 2008-01-21] (Microsoft Corporation) [File not signed]
S4 ws2ifsl; C:\Windows\system32\drivers\ws2ifsl.sys [15872 2008-01-21] (Microsoft Corporation) [File not signed]
S3 WUDFRd; C:\Windows\System32\DRIVERS\WUDFRd.sys [83328 2008-01-21] (Microsoft Corporation) [File not signed]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl [61424 2008-05-09] (Cyberlink Corp.)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-01 08:55 - 2015-04-01 08:56 - 00043270 _____ () C:\Users\user\Desktop\FRST.txt
2015-04-01 08:55 - 2015-04-01 08:56 - 00000000 ____D () C:\FRST
2015-04-01 08:55 - 2015-04-01 08:54 - 01135104 _____ (Farbar) C:\Users\user\Desktop\FRST.exe
2015-04-01 08:54 - 2015-04-01 08:54 - 01135104 _____ (Farbar) C:\Users\user\Downloads\FRST.exe
2015-03-31 18:08 - 2015-03-31 18:08 - 00000000 ___RD () C:\Program Files\Skype
2015-03-31 18:08 - 2015-03-31 18:08 - 00000000 ____D () C:\Users\user\AppData\Local\Skype
2015-03-31 18:08 - 2015-03-31 18:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-03-31 18:08 - 2015-03-31 18:08 - 00000000 ____D () C:\Program Files\Common Files\Skype
2015-03-31 17:34 - 2015-03-31 17:35 - 00111021 _____ () C:\Users\user\Desktop\ZHPDiag.txt
2015-03-31 17:33 - 2015-03-31 17:33 - 00000512 _____ () C:\PhysicalDisk0_MBR.bin
2015-03-31 17:31 - 2015-03-31 17:31 - 00001732 _____ () C:\Users\user\Desktop\ZHPFix.lnk
2015-03-31 17:31 - 2015-03-31 17:31 - 00001609 _____ () C:\Users\user\Desktop\ZHPDiag.lnk
2015-03-31 17:31 - 2015-03-31 17:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
2015-03-31 17:29 - 2015-03-31 17:30 - 06876639 _____ (Nicolas Coolman ) C:\Users\user\Downloads\ZHPDiag2.exe
2015-03-31 17:25 - 2015-03-31 17:25 - 00000000 _____ () C:\Windows\setuperr.log
2015-03-31 17:25 - 2015-03-31 17:25 - 00000000 _____ () C:\Windows\setupact.log
2015-03-31 17:24 - 2015-04-01 08:40 - 00125734 _____ () C:\Windows\PFRO.log
2015-03-31 15:57 - 2015-03-31 15:57 - 00000753 _____ () C:\DelFix.txt
2015-03-31 15:53 - 2015-03-31 15:53 - 00001933 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-03-31 15:53 - 2015-03-31 15:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-03-31 15:49 - 2015-03-31 15:50 - 00000000 ____D () C:\Users\user\Desktop\MAINTENANCE
2015-03-31 15:46 - 2015-03-31 15:46 - 00880208 _____ (Google Inc.) C:\Users\user\Downloads\ChromeSetup.exe
2015-03-31 13:59 - 2015-03-31 17:33 - 00000000 ____D () C:\Program Files\ZHPDiag
2015-03-31 13:59 - 2015-03-31 17:32 - 00000000 ____D () C:\Users\user\AppData\Roaming\ZHP
2015-03-31 13:15 - 2015-03-31 13:15 - 00000822 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-03-31 13:15 - 2015-03-31 13:15 - 00000810 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-03-31 13:03 - 2015-03-31 13:03 - 00243592 _____ () C:\Users\user\Downloads\Firefox Setup Stub 36.0.4.exe
2015-03-31 09:33 - 2015-03-31 19:02 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-31 09:33 - 2015-03-31 09:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-31 09:33 - 2015-03-31 09:33 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-03-31 09:33 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-03-31 09:33 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-03-31 09:25 - 2015-03-31 09:33 - 00000000 ____D () C:\Users\user\AppData\Roaming\Malwarebytes
2015-03-31 09:25 - 2015-03-31 09:33 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-31 09:25 - 2015-03-31 09:33 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2015-03-31 09:25 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-03-30 15:29 - 2015-03-30 15:30 - 00000000 ____D () C:\Windows\system32\vbox
2015-03-30 15:24 - 2015-03-30 15:23 - 00291312 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-03-30 15:23 - 2015-03-30 15:23 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-03-30 15:06 - 2015-03-30 15:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
2015-03-30 15:06 - 2015-03-30 15:06 - 00000000 ____D () C:\Program Files\Defraggler
2015-03-30 10:43 - 2015-03-30 15:08 - 00000000 ____D () C:\Users\user\Desktop\Pièces jointes
2015-03-28 00:00 - 2015-03-28 00:00 - 00029829 _____ () C:\Users\user\Documents\Sans nom 1.odt
2015-03-27 23:15 - 2015-03-27 23:41 - 00014664 _____ () C:\Users\user\Documents\Sans nom 1800.odt
2015-03-27 09:01 - 2015-03-27 09:01 - 00000000 ____D () C:\Users\user\Desktop\FRAIS DE GESTION BANQUE
2015-03-26 11:01 - 2015-03-02 18:19 - 00000562 _____ () C:\Users\user\Documents\LOTS DU LOTO DU 28 MARS 2015.lnk
2015-03-25 23:17 - 2015-03-24 16:29 - 00624393 _____ () C:\Users\user\Desktop\subvention pour cartons lotos credit mutuel.odt
2015-03-23 10:06 - 2015-03-23 10:06 - 00000000 __SHD () C:\found.001
2015-03-20 17:57 - 2015-03-27 08:18 - 00012784 _____ () C:\Users\user\Documents\Sans nom 20.odt
2015-03-20 09:28 - 2015-03-27 23:44 - 00012177 _____ () C:\Users\user\Documents\Sans nom 100000.odt
2015-03-04 17:48 - 2015-03-27 21:34 - 00016147 _____ () C:\Users\user\Documents\Sans nom 1700.odt
2015-03-04 17:48 - 2015-03-04 17:48 - 00000562 _____ () C:\Users\user\Documents\Sans nom 1700.lnk
2015-03-04 06:58 - 2015-03-02 16:35 - 00000547 _____ () C:\Users\user\Documents\INSCRIPTONS DU LOTO DU 28 MARS 2015 - Copie.lnk
2015-03-02 20:16 - 2015-03-02 20:16 - 00014255 _____ () C:\Users\user\Documents\90.odt
2015-03-02 18:19 - 2015-03-28 19:23 - 00021356 _____ () C:\Users\user\Documents\Sans nom 2555.odt
2015-03-02 16:33 - 2015-03-28 18:36 - 00020688 _____ () C:\Users\user\Documents\Sans nom 2.odt

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-01 08:54 - 2013-03-27 17:01 - 00000416 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{E08724C8-2FE5-4B96-BCD8-F11A40754200}.job
2015-04-01 08:54 - 2012-11-23 21:04 - 00077032 _____ () C:\ProgramData\nvModes.001
2015-04-01 08:46 - 2014-01-22 14:08 - 00001002 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-01 08:45 - 2008-01-21 10:41 - 01470810 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-01 08:43 - 2014-12-31 19:01 - 01669721 _____ () C:\Windows\WindowsUpdate.log
2015-04-01 08:41 - 2012-11-23 20:49 - 00077032 _____ () C:\ProgramData\nvModes.dat
2015-04-01 08:41 - 2012-11-23 19:40 - 00001052 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-01 08:41 - 2012-11-16 14:54 - 00000000 _____ () C:\Windows\system32\LogConfigTemp.xml
2015-04-01 08:40 - 2009-01-10 18:23 - 00000147 _____ () C:\Windows\system32\agent.log
2015-04-01 08:40 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-01 08:40 - 2006-11-02 14:47 - 00004784 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-01 08:40 - 2006-11-02 14:47 - 00004784 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-31 22:03 - 2006-11-02 15:01 - 00032556 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-03-31 21:18 - 2012-11-23 19:40 - 00001056 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-31 18:10 - 2013-04-01 01:22 - 00000000 ____D () C:\Users\user\AppData\Roaming\Skype
2015-03-31 18:08 - 2013-04-01 01:22 - 00000000 ____D () C:\ProgramData\Skype
2015-03-31 17:59 - 2013-12-12 20:24 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-31 17:56 - 2014-01-22 14:08 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-03-31 17:56 - 2014-01-22 14:08 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-03-31 15:53 - 2012-11-16 15:31 - 00000000 ____D () C:\Users\user\AppData\Local\Google
2015-03-31 15:53 - 2009-01-10 17:45 - 00000000 ____D () C:\Program Files\Google
2015-03-30 15:24 - 2014-08-22 15:37 - 00024144 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-03-30 15:24 - 2013-06-19 16:48 - 00427736 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
2015-03-30 15:24 - 2013-06-19 16:48 - 00208024 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-03-30 15:24 - 2013-06-19 16:48 - 00073440 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-03-30 15:24 - 2013-06-19 16:48 - 00057888 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswTdi.sys
2015-03-30 15:24 - 2013-06-19 16:48 - 00055200 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr.sys
2015-03-30 15:24 - 2013-06-19 16:48 - 00049904 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-03-30 15:23 - 2013-06-19 16:48 - 00788272 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-03-30 14:45 - 2013-10-08 12:36 - 00000000 ____D () C:\Program Files\PDFCreator
2015-03-30 14:44 - 2013-06-18 20:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-03-30 14:43 - 2013-06-18 20:12 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-30 08:42 - 2013-04-13 18:12 - 00000000 ____D () C:\Windows\Minidump
2015-03-28 10:23 - 2013-06-19 19:59 - 00000000 ___RD () C:\Users\user\Desktop\RACOURCIS INTERNET
2015-03-27 23:41 - 2015-02-25 23:31 - 00000000 ____D () C:\Users\user\Documents\stock chamoy animations 2015
2015-03-27 23:39 - 2015-02-25 23:26 - 00000000 ____D () C:\Users\user\Documents\loto du 28 mars 2015
2015-03-03 14:03 - 2015-02-25 23:32 - 00000000 ____D () C:\Users\user\Documents\frais de tenue de compte 2015

==================== Files in the root of some directories =======

2012-11-27 22:03 - 2013-04-27 18:45 - 0000680 _____ () C:\Users\user\AppData\Local\d3d9caps.dat
2012-11-23 19:44 - 2015-02-28 16:55 - 0030208 _____ () C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-11-23 21:04 - 2015-04-01 08:54 - 0077032 _____ () C:\ProgramData\nvModes.001
2012-11-23 20:49 - 2015-04-01 08:41 - 0077032 _____ () C:\ProgramData\nvModes.dat

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-01 08:46

==================== End Of Log ============================

Publicité


Signaler le contenu de ce document

Publicité