cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

ÿþOTL logfile created on: 08/04/2015 19:49:28 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\remy\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17690)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

7,89 Gb Total Physical Memory | 4,94 Gb Available Physical Memory | 62,59% Memory free
9,14 Gb Paging File | 5,81 Gb Available in Paging File | 63,57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 372,60 Gb Total Space | 204,60 Gb Free Space | 54,91% Space Free | Partition Type: NTFS
Drive D: | 537,80 Gb Total Space | 536,96 Gb Free Space | 99,85% Space Free | Partition Type: NTFS
Drive F: | 28,92 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: TANUKI | User Name: remy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - C:\Users\remy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Glary Utilities 5\Integrator.exe (Glarysoft Ltd)
PRC - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
PRC - C:\Program Files (x86)\Mobile Partner\Mobile Partner.exe ()
PRC - C:\ProgramData\DatacardService\DCSHelper.exe (Huawei Technologies Co., Ltd.)
PRC - C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe ()
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files\ASUS\P4G\InsOnWMI.exe (ASUS)
PRC - C:\Program Files\ASUS\P4G\InsOnSrv.exe (ASUS)
PRC - C:\Program Files\ASUS\ASUS VivoBook\vivokey.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - C:\Program Files (x86)\Glary Utilities 5\zlib1.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\Mobile Partner.exe ()
MOD - C:\Program Files (x86)\Mobile Partner\ConnectMgrUIPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\NetInfoUIExPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\DiagnosisPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\MenuMgrPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\ToolBarMgrPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\NetConnectPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\StatusBarMgrPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\LayoutPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\XFramePlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\DeviceMgrUIPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\SMSUIPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\AddrBookUIPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\NotifyServicePlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\DialupUIPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\core.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\sdk.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\OSCall.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\CallLogSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\SmsAppPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\SmsSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\CallSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\NetInfoSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\STKSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\AddrBookPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\CallAppPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\USSDSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\DeviceAppPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\AddrBookSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\DeviceSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\ATR2SMgr.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\NetSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\XCodec.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\PluginContainer.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\DialUpPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\NDISPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\Proxy.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\NetConnectSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\DataServicePlugin.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\OSDialup.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\OSNDIS.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\OSAdapt.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\AtCodec.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\OSPowerMgr.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\Common.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\Trace.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\LiveUpdateInterface.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\NDISAPI.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\QtGui4.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\QtXml4.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\QtCore4.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\tdpcvoice.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\Win7Support.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\plugins\imageformats\qtiff4.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\plugins\imageformats\qmng4.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\plugins\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\plugins\imageformats\qico4.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\libgcc_s_dw2-1.dll ()
MOD - C:\Program Files (x86)\Mobile Partner\mingwm10.dll ()


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - (McOobeSv2) -- C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe /McCoreSvc File not found
SRV:[b]64bit:[/b] - (WdNisSvc) -- C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Corporation)
SRV:[b]64bit:[/b] - (WinDefend) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV:[b]64bit:[/b] - (AudioEndpointBuilder) -- C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (IEEtwCollectorService) -- C:\WINDOWS\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:[b]64bit:[/b] - (WSService) -- C:\Windows\SysNative\WSService.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (PrintNotify) -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (WEPHOSTSVC) -- C:\Windows\SysNative\wephostsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (EFS) -- C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (WiaRpc) -- C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (svsvc) -- C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (fhsvc) -- C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (BthHFSrv) -- C:\Windows\SysNative\BthHFSrv.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (LSM) -- C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (NcaSvc) -- C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (vmicvss) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (vmictimesync) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (vmicshutdown) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (vmicrdv) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (vmickvpexchange) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (vmicheartbeat) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (vmicguestinterface) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (smphost) -- C:\Windows\SysNative\smphost.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (Netlogon) -- C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (SystemEventsBroker) -- C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (ScDeviceEnum) -- C:\Windows\SysNative\ScDeviceEnum.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (KeyIso) -- C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (TimeBroker) -- C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (netprofm) -- C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (NcbService) -- C:\Windows\SysNative\ncbservice.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (Wcmsvc) -- C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (VaultSvc) -- C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (DeviceAssociationService) -- C:\Windows\SysNative\das.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (BrokerInfrastructure) -- C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (wlidsvc) -- C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (lfsvc) -- C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (DsmSvc) -- C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (NcdAutoSetup) -- C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (AppReadiness) -- C:\Windows\SysNative\AppReadiness.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (AppXSvc) -- C:\Windows\SysNative\AppXDeploymentServer.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (workfolderssvc) -- C:\Windows\SysNative\workfolderssvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (ExpressCache) -- C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe (Condusiv Technologies)
SRV:[b]64bit:[/b] - (DptfPolicyCriticalService) -- C:\Windows\SysNative\DptfPolicyCriticalService.exe (Intel Corporation)
SRV:[b]64bit:[/b] - (DptfPolicyLpmService) -- C:\Windows\SysNative\DptfPolicyLpmService.exe (Intel Corporation)
SRV:[b]64bit:[/b] - (DptfParticipantProcessorService) -- C:\Windows\SysNative\DptfParticipantProcessorService.exe (Intel Corporation)
SRV:[b]64bit:[/b] - (DptfPolicyConfigTDPService) -- C:\Windows\SysNative\DptfPolicyConfigTDPService.exe (Intel Corporation)
SRV:[b]64bit:[/b] - (Intel(R) -- C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe (Intel(R) Corporation)
SRV:[b]64bit:[/b] - (ASUS InstantOn) -- C:\Program Files\ASUS\P4G\InsOnSrv.exe (ASUS)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (PrintNotify) -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV - (StorSvc) -- C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation)
SRV - (smphost) -- C:\Windows\SysWOW64\smphost.dll (Microsoft Corporation)
SRV - (lfsvc) -- C:\Windows\SysWOW64\GeofenceMonitorService.dll (Microsoft Corporation)
SRV - (iumsvc) -- C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe ()
SRV - (cphs) -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (AtherosSvc) -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Windows (R) Win 7 DDK provider)
SRV - (ZAtheros Bt and Wlan Coex Agent) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
SRV - (HWDeviceService64.exe) -- C:\ProgramData\DatacardService\HWDeviceService64.exe ()
SRV - (Mobile Partner. RunOuc) -- C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe ()
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
SRV - (Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUSTek Computer Inc.)
SRV - (ATKGFNEXSrv) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - (MBAMSwissArmy) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys (Malwarebytes Corporation)
DRV:[b]64bit:[/b] - (WdFilter) -- C:\Windows\SysNative\drivers\WdFilter.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (WdNisDrv) -- C:\Windows\SysNative\drivers\WdNisDrv.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (WdBoot) -- C:\Windows\SysNative\drivers\WdBoot.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (ahcache) -- C:\Windows\SysNative\drivers\ahcache.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (spaceport) -- C:\Windows\SysNative\drivers\spaceport.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (WFPLWFS) -- C:\Windows\SysNative\drivers\wfplwfs.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (wpcfltr) -- C:\Windows\SysNative\drivers\wpcfltr.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (WSDScan) -- C:\Windows\SysNative\drivers\WSDScan.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (BthHFEnum) -- C:\Windows\SysNative\drivers\bthhfenum.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (netvsc) -- C:\Windows\SysNative\drivers\netvsc63.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (NdisImPlatform) -- C:\Windows\SysNative\drivers\NdisImPlatform.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (MsLldp) -- C:\Windows\SysNative\drivers\mslldp.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (Ndu) -- C:\Windows\SysNative\drivers\Ndu.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (ReFS) -- C:\WINDOWS\SysNative\drivers\refs.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (pdc) -- C:\Windows\SysNative\drivers\pdc.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (intelpep) -- C:\Windows\SysNative\drivers\intelpep.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (USBHUB3) -- C:\Windows\SysNative\drivers\USBHUB3.SYS (Microsoft Corporation)
DRV:[b]64bit:[/b] - (USBXHCI) -- C:\Windows\SysNative\drivers\USBXHCI.SYS (Microsoft Corporation)
DRV:[b]64bit:[/b] - (UCX01000) -- C:\Windows\SysNative\drivers\UCX01000.SYS (Microsoft Corporation)
DRV:[b]64bit:[/b] - (vpci) -- C:\Windows\SysNative\drivers\vpci.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (Hamachi) -- C:\Windows\SysNative\drivers\Hamdrv.sys (LogMeIn Inc.)
DRV:[b]64bit:[/b] - (GPIOClx0101) -- C:\Windows\SysNative\drivers\msgpioclx.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (mfencrk) -- C:\Windows\SysNative\drivers\mfencrk.sys (McAfee, Inc.)
DRV:[b]64bit:[/b] - (GUBootStartup) -- C:\Windows\SysNative\drivers\GUBootStartup.sys (Glarysoft Ltd)
DRV:[b]64bit:[/b] - (BootDefragDriver) -- C:\Windows\SysNative\drivers\BootDefragDriver.sys (Glarysoft Ltd)
DRV:[b]64bit:[/b] - (mfeelamk) -- C:\Windows\SysNative\drivers\mfeelamk.sys (McAfee, Inc.)
DRV:[b]64bit:[/b] - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:[b]64bit:[/b] - (CLFS) -- C:\Windows\SysNative\drivers\clfs.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (xusb22) -- C:\Windows\SysNative\drivers\xusb22.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (Wof) -- C:\WINDOWS\SysNative\drivers\wof.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (sdstor) -- C:\Windows\SysNative\drivers\sdstor.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (BasicRender) -- C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (ssudserd) -- C:\Windows\SysNative\drivers\ssudserd.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:[b]64bit:[/b] - (ssudmdm) -- C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:[b]64bit:[/b] - (dg_ssudbus) -- C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:[b]64bit:[/b] - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV:[b]64bit:[/b] - (intaud_WaveExtensible) -- C:\Windows\SysNative\drivers\intelaud.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (iwdbus) -- C:\Windows\SysNative\drivers\iwdbus.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (stornvme) -- C:\Windows\SysNative\drivers\stornvme.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (VerifierExt) -- C:\Windows\SysNative\drivers\VerifierExt.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (ATP) -- C:\Windows\SysNative\drivers\AsusTP.sys (ASUS Corporation)
DRV:[b]64bit:[/b] - (hwusb_wwanecm) -- C:\Windows\SysNative\drivers\ew_wwanecm.sys (Huawei Technologies Co., Ltd.)
DRV:[b]64bit:[/b] - (hwusb_cdcacm) -- C:\Windows\SysNative\drivers\ew_cdcacm.sys (Huawei Technologies Co., Ltd.)
DRV:[b]64bit:[/b] - (BthLEEnum) -- C:\Windows\SysNative\drivers\BthLEEnum.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (huawei_enumerator) -- C:\Windows\SysNative\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV:[b]64bit:[/b] - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Qualcomm Atheros)
DRV:[b]64bit:[/b] - (BTATH_A2DP) -- C:\Windows\SysNative\drivers\btath_a2dp.sys (Qualcomm Atheros)
DRV:[b]64bit:[/b] - (BTATH_HCRP) -- C:\Windows\SysNative\drivers\btath_hcrp.sys (Qualcomm Atheros)
DRV:[b]64bit:[/b] - (BTATH_RCP) -- C:\Windows\SysNative\drivers\btath_rcp.sys (Qualcomm Atheros)
DRV:[b]64bit:[/b] - (btath_avdt) -- C:\Windows\SysNative\drivers\btath_avdt.sys (Qualcomm Atheros)
DRV:[b]64bit:[/b] - (AthBTPort) -- C:\Windows\SysNative\drivers\btath_flt.sys (Qualcomm Atheros)
DRV:[b]64bit:[/b] - (BTATH_LWFLT) -- C:\Windows\SysNative\drivers\btath_lwflt.sys (Qualcomm Atheros)
DRV:[b]64bit:[/b] - (BTATH_BUS) -- C:\Windows\SysNative\drivers\btath_bus.sys (Qualcomm Atheros)
DRV:[b]64bit:[/b] - (excsd) -- C:\Windows\SysNative\drivers\excsd.sys (Condusiv Technologies)
DRV:[b]64bit:[/b] - (excfs) -- C:\Windows\SysNative\drivers\excfs.sys (Condusiv Technologies)
DRV:[b]64bit:[/b] - (athr) -- C:\Windows\SysNative\drivers\athwbx.sys (Qualcomm Atheros Communications, Inc.)
DRV:[b]64bit:[/b] - (SerCx2) -- C:\Windows\SysNative\drivers\SerCx2.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (MEIx64) -- C:\Windows\SysNative\drivers\TeeDriverx64.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (DptfManager) -- C:\Windows\SysNative\drivers\DptfManager.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (DptfDevProc) -- C:\Windows\SysNative\drivers\DptfDevProc.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (DptfDevPch) -- C:\Windows\SysNative\drivers\DptfDevPch.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (DptfDevDram) -- C:\Windows\SysNative\drivers\DptfDevDram.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (HIDSwitch) -- C:\Windows\SysNative\drivers\AsHIDSwitch64.sys (ASUS)
DRV:[b]64bit:[/b] - (plctrl) -- C:\Program Files\ASUS\P4G\plctrl.sys (Windows (R) Win 7 DDK provider)
DRV:[b]64bit:[/b] - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (condrv) -- C:\Windows\SysNative\drivers\condrv.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (Fs_Rec) -- C:\WINDOWS\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (dam) -- C:\Windows\SysNative\drivers\dam.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (acpiex) -- C:\Windows\SysNative\drivers\acpiex.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (TPM) -- C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (mvumis) -- C:\Windows\SysNative\drivers\mvumis.sys (Marvell Semiconductor, Inc.)
DRV:[b]64bit:[/b] - (msgpiowin32) -- C:\Windows\SysNative\drivers\msgpiowin32.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:[b]64bit:[/b] - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:[b]64bit:[/b] - (LSI_SSS) -- C:\Windows\SysNative\drivers\lsi_sss.sys (LSI Corporation)
DRV:[b]64bit:[/b] - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:[b]64bit:[/b] - (LSI_SAS3) -- C:\Windows\SysNative\drivers\lsi_sas3.sys (LSI Corporation)
DRV:[b]64bit:[/b] - (ADP80XX) -- C:\Windows\SysNative\drivers\adp80xx.sys (PMC-Sierra)
DRV:[b]64bit:[/b] - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:[b]64bit:[/b] - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:[b]64bit:[/b] - (3ware) -- C:\Windows\SysNative\drivers\3ware.sys (LSI)
DRV:[b]64bit:[/b] - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:[b]64bit:[/b] - (EhStorTcgDrv) -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (EhStorClass) -- C:\Windows\SysNative\drivers\EhStorClass.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:[b]64bit:[/b] - (VSTXRAID) -- C:\Windows\SysNative\drivers\VSTXRAID.SYS (VIA Corporation)
DRV:[b]64bit:[/b] - (UASPStor) -- C:\Windows\SysNative\drivers\uaspstor.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology, Inc.)
DRV:[b]64bit:[/b] - (storahci) -- C:\Windows\SysNative\drivers\storahci.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (SpbCx) -- C:\Windows\SysNative\drivers\SpbCx.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (SerCx) -- C:\Windows\SysNative\drivers\SerCx.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (UEFI) -- C:\Windows\SysNative\drivers\uefi.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (WpdUpFltr) -- C:\Windows\SysNative\drivers\WpdUpFltr.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (BasicDisplay) -- C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (HyperVideo) -- C:\Windows\SysNative\drivers\HyperVideo.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (mshidumdf) -- C:\Windows\SysNative\drivers\mshidumdf.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (acpitime) -- C:\Windows\SysNative\drivers\acpitime.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (acpipagr) -- C:\Windows\SysNative\drivers\acpipagr.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (BthAvrcpTg) -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (kdnic) -- C:\Windows\SysNative\drivers\kdnic.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (gencounter) -- C:\Windows\SysNative\drivers\vmgencounter.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (npsvctrig) -- C:\Windows\SysNative\drivers\npsvctrig.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (bthhfhid) -- C:\Windows\SysNative\drivers\BthhfHid.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (hyperkbd) -- C:\Windows\SysNative\drivers\hyperkbd.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (hidi2c) -- C:\Windows\SysNative\drivers\hidi2c.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (NdisVirtualBus) -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (FxPPM) -- C:\Windows\SysNative\drivers\fxppm.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (RTL8168) -- C:\Windows\SysNative\drivers\Rt630x64.sys (Realtek )
DRV:[b]64bit:[/b] - (bcmfn2) -- C:\Windows\SysNative\drivers\bcmfn2.sys (Windows (R) Win 7 DDK provider)
DRV:[b]64bit:[/b] - (iaStorAV) -- C:\Windows\SysNative\drivers\iaStorAV.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (iaStorA) -- C:\Windows\SysNative\drivers\iaStorA.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (iaLPSSi_GPIO) -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (iaLPSSi_I2C) -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (RSUSBVSTOR) -- C:\Windows\SysNative\drivers\RtsUVStor.sys (Realtek Semiconductor Corp.)
DRV:[b]64bit:[/b] - (AgereSoftModem) -- C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp)
DRV:[b]64bit:[/b] - (NETwNs64) -- C:\Windows\SysNative\drivers\Netwsw00.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (e1iexpress) -- C:\Windows\SysNative\drivers\e1i63x64.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (AiCharger) -- C:\Windows\SysNative\drivers\AiCharger.sys (ASUSTek Computer Inc.)
DRV:[b]64bit:[/b] - (ew_hwusbdev) -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV:[b]64bit:[/b] - (ew_usbenumfilter) -- C:\Windows\SysNative\drivers\ew_usbenumfilter.sys (Huawei Technologies Co., Ltd.)
DRV:[b]64bit:[/b] - (kbfiltr) -- C:\Windows\SysNative\drivers\kbfiltr.sys ( )
DRV - (ATKWMIACPIIO) -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys (ASUSTek Computer Inc.)
DRV - (ASMMAP64) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = https://www.google.com/
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = https://www.google.com/
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = https://www.google.com/
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = https://www.google.com/
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.google.com/
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchMigratedDefaultName = google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchMigratedDefaultURL = https://www.google.com/
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = https://www.google.com/
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = https://www.google.com/
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = https://www.google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = https://www.google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = https://www.google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = https://www.google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchMigratedDefaultName = google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchMigratedDefaultURL = https://www.google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = https://www.google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = https://www.google.com/
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchMigratedDefaultName = google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchMigratedDefaultURL = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = https://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[color=#E56717]========== FireFox ==========[/color]

FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.31.2: C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2: C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)



[color=#E56717]========== Chrome ==========[/color]

CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\remy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\remy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\remy\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\
CHR - Extension: No name found = C:\Users\remy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\
CHR - Extension: No name found = C:\Users\remy\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.12_0\
CHR - Extension: No name found = C:\Users\remy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\
CHR - Extension: No name found = C:\Users\remy\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = C:\Users\remy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\0.3.0.2_0\
CHR - Extension: No name found = C:\Users\remy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\
CHR - Extension: No name found = C:\Users\remy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\

O1 HOSTS File: ([2013/08/22 15:25:41 | 000,000,824 | RHS- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:[b]64bit:[/b] - HKLM..\Run: [DptfPolicyLpmServiceHelper] C:\Windows\SysNative\DptfPolicyLpmServiceHelper.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\SysNative\hkcmd.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\WINDOWS\SysNative\igfxtray.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [Logitech Download Assistant] C:\WINDOWS\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKCU..\Run: [EPSON678D2A (Epson Stylus Photo PX730)] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHQE.EXE /FU "C:\Users\remy\AppData\Local\Temp\E_SFF1B.tmp" /EF "HKCU" File not found
O4 - HKCU..\Run: [GUDelayStartup] C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe (Glarysoft Ltd)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - Startup: C:\Users\remy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\remy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: BtvStack = "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" (Qualcomm®Atheros®)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0813DE78-F7A5-46C0-8060-432F8894CDF9}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D388D334-3A40-4746-9CDA-A3A32FCA022A}: NameServer = 82.138.105.78 82.138.79.78
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EF211E0D-7B90-45F8-B4B4-DB9EE254DC57}: NameServer = 82.138.105.78 82.138.79.78
O18:[b]64bit:[/b] - Protocol\Filter\application/x-mfe-ipt - No CLSID value found
O18 - Protocol\Filter\application/x-mfe-ipt - No CLSID value found
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - File not found
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\WINDOWS\SysNative\igfxdev.dll (Intel Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/10/28 09:32:22 | 000,150,608 | R--- | M] () - F:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008/10/01 08:42:34 | 000,000,045 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{81c153cf-da14-11e4-844c-54271e757d6e}\Shell - "" = AutoRun
O33 - MountPoints2\{81c153cf-da14-11e4-844c-54271e757d6e}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2013/10/28 09:32:22 | 000,150,608 | R--- | M] ()
O33 - MountPoints2\{e6f2a87e-d7c2-11e4-8447-54271e757d6f}\Shell - "" = AutoRun
O33 - MountPoints2\{e6f2a87e-d7c2-11e4-8447-54271e757d6f}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2013/10/28 09:32:22 | 000,150,608 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (BootDefrag.exe)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:[b]64bit:[/b] lfsvc - C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
NetSvcs:[b]64bit:[/b] wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
NetSvcs:[b]64bit:[/b] DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs:[b]64bit:[/b] NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)


SafeBootMin:[b]64bit:[/b] AppMgmt - Service
SafeBootMin:[b]64bit:[/b] Base - Driver Group
SafeBootMin:[b]64bit:[/b] BasicDisplay.sys - C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] BasicRender.sys - C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] Boot Bus Extender - Driver Group
SafeBootMin:[b]64bit:[/b] Boot file system - Driver Group
SafeBootMin:[b]64bit:[/b] BrokerInfrastructure - C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] EFS - C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] File system - Driver Group
SafeBootMin:[b]64bit:[/b] Filter - Driver Group
SafeBootMin:[b]64bit:[/b] HelpSvc - Service
SafeBootMin:[b]64bit:[/b] KeyIso - C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] LSM - C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] MCODS -
SafeBootMin:[b]64bit:[/b] Netlogon - C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] PCI Configuration - Driver Group
SafeBootMin:[b]64bit:[/b] PNP Filter - Driver Group
SafeBootMin:[b]64bit:[/b] Primary disk - Driver Group
SafeBootMin:[b]64bit:[/b] sacsvr - Service
SafeBootMin:[b]64bit:[/b] SCSI Class - Driver Group
SafeBootMin:[b]64bit:[/b] System Bus Extender - Driver Group
SafeBootMin:[b]64bit:[/b] SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] TBS - Service
SafeBootMin:[b]64bit:[/b] vga.sys - Driver
SafeBootMin:[b]64bit:[/b] vgasave.sys - Driver
SafeBootMin:[b]64bit:[/b] vmms - Service
SafeBootMin:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:[b]64bit:[/b] {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootMin:[b]64bit:[/b] {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootMin:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MCODS -
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: TBS - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: vgasave.sys - Driver
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootMin: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet:[b]64bit:[/b] AppMgmt - Service
SafeBootNet:[b]64bit:[/b] Base - Driver Group
SafeBootNet:[b]64bit:[/b] BasicDisplay.sys - C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] BasicRender.sys - C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] Boot Bus Extender - Driver Group
SafeBootNet:[b]64bit:[/b] Boot file system - Driver Group
SafeBootNet:[b]64bit:[/b] BrokerInfrastructure - C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] EFS - C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] File system - Driver Group
SafeBootNet:[b]64bit:[/b] Filter - Driver Group
SafeBootNet:[b]64bit:[/b] HelpSvc - Service
SafeBootNet:[b]64bit:[/b] KeyIso - C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] LSM - C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] Messenger - Service
SafeBootNet:[b]64bit:[/b] mfefire - Driver
SafeBootNet:[b]64bit:[/b] mfefirek - Driver
SafeBootNet:[b]64bit:[/b] mfefirek.sys - Driver
SafeBootNet:[b]64bit:[/b] mfehidk - Driver
SafeBootNet:[b]64bit:[/b] mfehidk.sys - Driver
SafeBootNet:[b]64bit:[/b] mfevtp - Driver
SafeBootNet:[b]64bit:[/b] NDIS Wrapper - Driver Group
SafeBootNet:[b]64bit:[/b] NetBIOSGroup - Driver Group
SafeBootNet:[b]64bit:[/b] NetDDEGroup - Driver Group
SafeBootNet:[b]64bit:[/b] Netlogon - C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] netprofm - C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] Network - Driver Group
SafeBootNet:[b]64bit:[/b] NetworkProvider - Driver Group
SafeBootNet:[b]64bit:[/b] PCI Configuration - Driver Group
SafeBootNet:[b]64bit:[/b] PNP Filter - Driver Group
SafeBootNet:[b]64bit:[/b] PNP_TDI - Driver Group
SafeBootNet:[b]64bit:[/b] Primary disk - Driver Group
SafeBootNet:[b]64bit:[/b] rdpencdd.sys - Driver
SafeBootNet:[b]64bit:[/b] rdsessmgr - Service
SafeBootNet:[b]64bit:[/b] sacsvr - Service
SafeBootNet:[b]64bit:[/b] SCSI Class - Driver Group
SafeBootNet:[b]64bit:[/b] SmartcardSimulator - Driver
SafeBootNet:[b]64bit:[/b] Streams Drivers - Driver Group
SafeBootNet:[b]64bit:[/b] System Bus Extender - Driver Group
SafeBootNet:[b]64bit:[/b] SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] TBS - Service
SafeBootNet:[b]64bit:[/b] TDI - Driver Group
SafeBootNet:[b]64bit:[/b] VaultSvc - C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] vga.sys - Driver
SafeBootNet:[b]64bit:[/b] vgasave.sys - Driver
SafeBootNet:[b]64bit:[/b] VirtualSmartcardReader - Driver
SafeBootNet:[b]64bit:[/b] vmms - Service
SafeBootNet:[b]64bit:[/b] Wcmsvc - C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] WudfUsbccidDriver - Driver
SafeBootNet:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:[b]64bit:[/b] {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:[b]64bit:[/b] {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:[b]64bit:[/b] {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:[b]64bit:[/b] {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:[b]64bit:[/b] {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:[b]64bit:[/b] {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootNet:[b]64bit:[/b] {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootNet:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: mfefire - Driver
SafeBootNet: mfefirek - Driver
SafeBootNet: mfefirek.sys - Driver
SafeBootNet: mfehidk - Driver
SafeBootNet: mfehidk.sys - Driver
SafeBootNet: mfevtp - Driver
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdpencdd.sys - Driver
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: SmartcardSimulator - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TBS - Service
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: vgasave.sys - Driver
SafeBootNet: VirtualSmartcardReader - Driver
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootNet: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:[b]64bit:[/b] {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:[b]64bit:[/b] {78E345F7-E976-3595-9C30-2458D6A8EC32} - .NET Framework
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - U
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.118\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EC43E638-09F0-38CC-A585-72FCCDDF035C} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP

Drivers32:[b]64bit:[/b] msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:[b]64bit:[/b] VIDC.CFHD - CFHD.dll (CineForm Inc.)
Drivers32:[b]64bit:[/b] VIDC.FICV - ficvdec_x64.dll ()
Drivers32:[b]64bit:[/b] VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32:[b]64bit:[/b] vidc.tsc2 - C:\WINDOWS\SysWOW64\tsc2_codec64.dll (TechSmith Corporation)
Drivers32:[b]64bit:[/b] vidc.tscc - C:\WINDOWS\SysWOW64\tsccvid64.dll (TechSmith Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: VIDC.CFHD - C:\WINDOWS\SysWow64\CFHD.dll (CineForm Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FICV - C:\WINDOWS\SysWow64\ficvdec_x86.dll ()
Drivers32: VIDC.FPS1 - C:\WINDOWS\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.tsc2 - C:\Windows\SysWOW64\tsc2_codec32.dll (TechSmith Corporation)
Drivers32: vidc.tscc - C:\Windows\SysWOW64\tsccvid.dll (TechSmith Corporation)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2015/04/04 22:18:26 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\remy\Desktop\OTL.exe
[2015/03/31 19:35:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Mobile Partner
[2015/03/31 19:35:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mobile Partner
[2015/03/31 19:34:19 | 001,490,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WdfCoInstaller01007.dll
[2015/03/31 19:34:19 | 001,490,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdfCoInstaller01007.dll
[2015/03/31 19:34:19 | 000,456,704 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\SysNative\drivers\ewusbwwan.sys
[2015/03/31 19:34:19 | 000,376,704 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\SysNative\drivers\ew_wwanecm.sys
[2015/03/31 19:34:19 | 000,246,272 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\SysNative\drivers\ew_juwwanecm.sys
[2015/03/31 19:34:19 | 000,226,176 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\SysNative\drivers\ewusbmdm.sys
[2015/03/31 19:34:19 | 000,121,728 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\SysNative\drivers\ew_cdcacm.sys
[2015/03/31 19:34:19 | 000,110,592 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\SysNative\drivers\ew_jucdcacm.sys
[2015/03/31 19:34:19 | 000,109,568 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\SysNative\drivers\ew_hwusbdev.sys
[2015/03/31 19:34:19 | 000,091,648 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\SysNative\drivers\ew_jubusenum.sys
[2015/03/31 19:34:19 | 000,077,312 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\SysNative\drivers\ew_jucdcecm.sys
[2015/03/31 19:34:19 | 000,032,768 | ---- | C] (Huawei Tech. Co., Ltd.) -- C:\WINDOWS\SysNative\drivers\ewdcsc.sys
[2015/03/31 19:34:19 | 000,030,720 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\SysNative\drivers\ew_juextctrl.sys
[2015/03/31 19:34:19 | 000,022,016 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\SysNative\drivers\ew_hwupgrade.sys
[2015/03/31 19:34:19 | 000,014,976 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\SysNative\drivers\ew_usbenumfilter.sys
[2015/03/31 19:33:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mobile Partner
[2015/03/31 19:32:57 | 000,000,000 | ---D | C] -- C:\ProgramData\DatacardService
[2015/03/29 16:23:39 | 000,943,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\appraiser.dll
[2015/03/29 16:23:39 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\acmigration.dll
[2015/03/29 16:23:38 | 001,107,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2015/03/29 16:23:38 | 000,760,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\invagent.dll
[2015/03/29 16:23:38 | 000,677,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2015/03/29 16:23:38 | 000,414,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2015/03/29 16:23:37 | 000,227,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2015/03/11 17:52:57 | 000,933,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\calc.exe
[2015/03/11 17:52:57 | 000,816,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\calc.exe
[2015/03/11 17:52:53 | 000,264,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdFilter.sys
[2015/03/11 17:52:53 | 000,044,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdBoot.sys
[2015/03/11 17:52:52 | 000,114,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\WdNisDrv.sys
[2015/03/11 17:52:51 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winshfhc.dll
[2015/03/11 17:52:51 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\winshfhc.dll
[2015/03/11 17:52:26 | 000,723,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SHCore.dll
[2015/03/11 17:52:26 | 000,560,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SHCore.dll
[2015/03/11 17:52:22 | 000,347,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\photowiz.dll
[2015/03/11 17:52:22 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\photowiz.dll
[2015/03/11 17:52:21 | 003,097,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msftedit.dll
[2015/03/11 17:52:21 | 002,484,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msftedit.dll
[2015/03/11 17:52:21 | 000,358,912 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysNative\atmfd.dll
[2015/03/11 17:52:21 | 000,301,056 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\atmfd.dll
[2015/03/11 17:52:21 | 000,044,032 | ---- | C] (Adobe Systems) -- C:\WINDOWS\SysNative\atmlib.dll
[2015/03/11 17:52:21 | 000,035,840 | ---- | C] (Adobe Systems) -- C:\WINDOWS\SysWow64\atmlib.dll
[2015/03/11 17:52:20 | 004,298,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_47.dll
[2015/03/11 17:52:20 | 002,257,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2015/03/11 17:52:20 | 001,943,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dwmcore.dll
[2015/03/11 17:52:20 | 001,091,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\localspl.dll
[2015/03/11 17:52:20 | 000,864,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\win32spl.dll
[2015/03/11 17:52:19 | 003,551,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_47.dll
[2015/03/11 17:52:19 | 001,488,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfc42u.dll
[2015/03/11 17:52:19 | 001,464,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfc42.dll
[2015/03/11 17:52:19 | 001,230,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfc42u.dll
[2015/03/11 17:52:19 | 001,204,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfc42.dll
[2015/03/11 17:52:19 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\atlthunk.dll
[2015/03/11 17:52:18 | 007,472,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2015/03/11 17:52:18 | 002,773,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2015/03/11 17:52:18 | 002,459,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2015/03/11 17:52:18 | 001,733,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll
[2015/03/11 17:52:18 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\StorageContextHandler.dll
[2015/03/11 17:52:18 | 000,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\StorageContextHandler.dll
[2015/03/11 17:52:17 | 000,971,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WSShared.dll
[2015/03/11 17:52:17 | 000,811,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WSShared.dll
[2015/03/11 17:52:17 | 000,274,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2015/03/11 17:52:17 | 000,210,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2015/03/11 17:52:16 | 003,547,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpcorets.dll
[2015/03/11 17:52:16 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rdpudd.dll
[2015/03/11 17:52:15 | 000,203,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ubpm.dll
[2015/03/11 17:52:13 | 000,346,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\eappcfg.dll
[2015/03/11 17:52:13 | 000,339,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\eapphost.dll
[2015/03/11 17:52:13 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\eapp3hst.dll
[2015/03/11 17:52:13 | 000,278,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\eappcfg.dll
[2015/03/11 17:52:13 | 000,266,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\eapphost.dll
[2015/03/11 17:52:13 | 000,250,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\eapp3hst.dll
[2015/03/11 17:52:12 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\eappgnui.dll
[2015/03/11 17:52:12 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\eappgnui.dll
[2015/03/11 17:52:09 | 006,035,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2015/03/11 17:52:07 | 002,125,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2015/03/11 17:52:07 | 000,584,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2015/03/11 17:52:07 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iepeers.dll
[2015/03/11 17:52:06 | 002,052,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2015/03/11 17:52:06 | 000,816,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
[2015/03/11 17:52:06 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll
[2015/03/11 17:52:06 | 000,801,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2015/03/11 17:52:06 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2015/03/11 17:52:06 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iepeers.dll
[2015/03/11 17:52:06 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2015/03/11 17:52:06 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll
[2015/03/11 17:52:06 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2015/03/11 17:52:06 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll
[2015/03/11 17:52:05 | 002,865,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2015/03/11 17:52:05 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2015/03/11 17:52:05 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2015/03/11 17:52:05 | 000,664,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
[2015/03/11 17:52:04 | 000,402,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WMPhoto.dll
[2015/03/11 17:52:04 | 000,357,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\WMPhoto.dll
[2015/03/11 17:52:03 | 001,763,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WindowsCodecs.dll
[2015/03/11 17:52:01 | 002,501,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2015/03/11 17:52:01 | 002,207,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\explorer.exe
[2015/03/11 17:52:01 | 001,090,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll
[2015/03/11 17:52:01 | 000,791,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MrmCoreR.dll
[2015/03/11 17:52:01 | 000,046,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\LockScreenContentServer.exe
[2015/03/11 17:51:55 | 001,384,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msctf.dll
[2015/03/10 19:51:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache
[2015/03/09 19:54:09 | 000,129,752 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2015/03/09 19:54:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2015/03/09 19:53:56 | 000,093,400 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbamchameleon.sys
[2015/03/09 19:53:56 | 000,064,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mwac.sys
[2015/03/09 19:53:56 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2015/03/09 19:53:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2015/04/08 19:51:04 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2015/04/08 19:51:02 | 000,000,000 | -HS- | M] () -- C:\DkHyperbootSync
[2015/04/08 19:29:00 | 000,001,090 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2015/04/08 17:32:23 | 001,824,010 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2015/04/08 17:32:23 | 000,819,776 | ---- | M] () -- C:\WINDOWS\SysNative\perfh00C.dat
[2015/04/08 17:32:23 | 000,729,902 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2015/04/08 17:32:23 | 000,162,356 | ---- | M] () -- C:\WINDOWS\SysNative\perfc00C.dat
[2015/04/08 17:32:23 | 000,138,536 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2015/04/08 17:26:45 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2015/04/08 17:26:19 | 000,000,344 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize 5.job
[2015/04/08 17:25:17 | 000,001,086 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2015/04/08 17:24:46 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2015/04/07 20:26:33 | 000,000,552 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Product InstallerIdle.job
[2015/04/04 22:18:20 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\remy\Desktop\OTL.exe
[2015/04/03 17:00:28 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2015/03/31 19:35:31 | 000,001,057 | ---- | M] () -- C:\Users\Public\Desktop\Mobile Partner.lnk
[2015/03/24 19:03:44 | 002,619,706 | ---- | M] () -- C:\Users\remy\Desktop\IMG_0154.JPG
[2015/03/24 17:24:43 | 003,066,069 | ---- | M] () -- C:\Users\remy\Desktop\IMG_0153.JPG
[2015/03/24 17:24:23 | 003,766,583 | ---- | M] () -- C:\Users\remy\Desktop\IMG_0152.JPG
[2015/03/20 23:19:36 | 000,009,728 | ---- | M] () -- C:\Users\remy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2015/03/15 11:15:17 | 000,001,146 | ---- | M] () -- C:\Users\remy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2015/03/11 20:47:57 | 000,377,648 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2015/03/11 19:51:11 | 001,094,074 | ---- | M] () -- C:\Users\remy\Desktop\TheCampingMod_2.1f.jar
[2015/03/11 04:38:24 | 000,227,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2015/03/11 00:08:59 | 000,677,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2015/03/11 00:08:56 | 000,760,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\invagent.dll
[2015/03/11 00:08:54 | 001,107,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2015/03/11 00:08:54 | 000,943,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\appraiser.dll
[2015/03/11 00:08:54 | 000,414,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2015/03/11 00:08:53 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\acmigration.dll
[2015/03/10 20:27:33 | 000,487,379 | ---- | M] () -- C:\Users\remy\Documents\1420905582-uhc.png
[2015/03/10 20:24:26 | 000,001,545 | ---- | M] () -- C:\Users\remy\Documents\Goldenapple.png
[2015/03/09 19:54:03 | 000,001,080 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2015/04/08 19:51:02 | 000,000,000 | -HS- | C] () -- C:\DkHyperbootSync
[2015/04/04 22:23:56 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2015/03/31 19:35:31 | 000,001,057 | ---- | C] () -- C:\Users\Public\Desktop\Mobile Partner.lnk
[2015/03/28 21:04:44 | 003,066,069 | ---- | C] () -- C:\Users\remy\Desktop\IMG_0153.JPG
[2015/03/28 21:04:43 | 002,619,706 | ---- | C] () -- C:\Users\remy\Desktop\IMG_0154.JPG
[2015/03/28 21:04:26 | 003,766,583 | ---- | C] () -- C:\Users\remy\Desktop\IMG_0152.JPG
[2015/03/11 20:13:33 | 000,000,295 | ---- | C] () -- C:\Users\remy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Corbeille.lnk
[2015/03/11 19:51:21 | 001,094,074 | ---- | C] () -- C:\Users\remy\Desktop\TheCampingMod_2.1f.jar
[2015/03/11 17:52:27 | 000,396,419 | ---- | C] () -- C:\WINDOWS\SysNative\ApnDatabase.xml
[2015/03/10 20:27:32 | 000,487,379 | ---- | C] () -- C:\Users\remy\Documents\1420905582-uhc.png
[2015/03/10 20:24:25 | 000,001,545 | ---- | C] () -- C:\Users\remy\Documents\Goldenapple.png
[2015/03/09 19:54:03 | 000,001,080 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2015/03/04 11:50:15 | 000,107,008 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2015/03/04 11:48:40 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2015/02/15 17:05:38 | 001,681,920 | ---- | C] () -- C:\Users\remy\ZHPCleaner.exe
[2014/12/08 18:34:02 | 000,000,000 | ---- | C] () -- C:\Users\remy\ipconfig
[2014/10/28 22:29:03 | 000,000,290 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014/09/21 19:37:42 | 000,009,728 | ---- | C] () -- C:\Users\remy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/08/28 23:42:24 | 000,008,144 | ---- | C] () -- C:\Users\remy\AppData\Roaming\TheHunterSettings_live.bin
[2014/08/28 23:39:38 | 000,000,039 | ---- | C] () -- C:\Users\remy\AppData\Roaming\TheHunterSettings_steam_live.cfg
[2014/07/22 23:56:52 | 000,000,132 | ---- | C] () -- C:\Users\remy\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2014/07/11 19:19:44 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014/07/02 19:43:12 | 000,000,383 | ---- | C] () -- C:\Users\remy\RecentPlaces.lnk
[2014/04/09 07:44:46 | 000,314,656 | ---- | C] () -- C:\WINDOWS\SysWow64\NvIFROpenGL.dll
[2014/01/24 05:09:20 | 000,004,606 | ---- | C] () -- C:\WINDOWS\SysWow64\DptfInvalidPolicyRemover.ini
[2014/01/24 05:01:21 | 000,280,064 | ---- | C] () -- C:\WINDOWS\SysWow64\igdmd32.dll
[2014/01/24 05:01:17 | 000,182,272 | ---- | C] () -- C:\WINDOWS\SysWow64\igdde32.dll
[2014/01/24 05:01:17 | 000,142,848 | ---- | C] () -- C:\WINDOWS\SysWow64\igdail32.dll
[2013/12/13 06:09:56 | 000,024,576 | ---- | C] () -- C:\ProgramData\SetStretch.exe
[2013/12/13 06:09:56 | 000,000,256 | ---- | C] () -- C:\ProgramData\SetStretch.cmd
[2013/12/13 06:09:56 | 000,000,103 | ---- | C] () -- C:\ProgramData\SetStretch.VBS
[2013/09/02 14:03:40 | 000,001,536 | ---- | C] () -- C:\WINDOWS\SysWow64\IusEventLog.dll
[2013/08/22 17:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013/08/22 17:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013/08/22 16:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013/08/22 09:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013/08/22 01:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013/08/22 01:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
[2013/05/28 22:22:48 | 000,641,024 | ---- | C] () -- C:\WINDOWS\SysWow64\ficvdec_x86.dll

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2014/08/28 23:35:55 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2015/02/12 19:40:58 | 022,291,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015/02/12 19:34:06 | 019,731,824 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2014/10/29 03:19:43 | 001,013,760 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2014/10/29 02:59:23 | 000,786,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2014/10/29 03:16:01 | 000,512,512 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== Custom Scans ==========[/color]

[color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
[2014/07/22 13:31:19 | 000,000,112 | -H-- | M] () -- C:\51357E9D286C
[2013/12/13 13:37:21 | 000,398,356 | RHS- | M] () -- C:\bootmgr
[2013/06/18 14:18:29 | 000,000,001 | -HS- | M] () -- C:\BOOTNXT
[2014/07/22 13:31:19 | 000,000,040 | -H-- | M] () -- C:\D8896291B9A8
[2015/04/08 19:51:02 | 000,000,000 | -HS- | M] () -- C:\DkHyperbootSync
[2015/02/15 19:41:37 | 000,000,000 | ---- | M] () -- C:\essai.txt
[2015/04/03 17:26:45 | 000,003,540 | ---- | M] () -- C:\IFRToolLog.txt
[2015/04/08 17:24:44 | 1342,177,280 | -HS- | M] () -- C:\pagefile.sys
[2015/02/15 21:29:47 | 000,000,512 | ---- | M] () -- C:\PhysicalDisk0_MBR.bin
[2015/04/08 19:51:04 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2015/03/09 20:26:20 | 000,001,271 | ---- | M] () -- C:\rapport mbam.txt
[2015/04/08 17:24:46 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

[color=#A23BEC]< %PROGRAMFILES%\*.* >[/color]
[2013/08/22 17:34:52 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini

[color=#A23BEC]< %PROGRAMFILES%\*. >[/color]
[2014/04/09 07:45:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AGEIA Technologies
[2015/01/27 01:57:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update
[2015/01/07 00:18:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ASUS
[2014/08/09 22:23:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Audacity
[2014/04/09 07:52:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bluetooth Suite
[2014/07/17 18:35:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bonjour
[2014/12/12 23:13:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CineForm
[2015/03/02 01:20:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
[2014/04/09 08:05:43 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CyberLink
[2015/04/04 10:18:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Glary Utilities 5
[2015/01/27 02:19:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Google
[2014/12/12 23:13:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\GoPro
[2014/10/26 23:25:27 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
[2014/04/09 08:07:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Intel
[2015/03/11 20:46:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
[2015/03/02 01:19:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Java
[2015/03/04 23:45:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\LOLReplay
[2015/03/09 19:54:01 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014/12/31 20:10:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mcedit
[2015/03/10 19:59:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office
[2013/08/22 17:36:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
[2015/02/01 02:36:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Minecraft
[2015/03/31 19:35:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mobile Partner
[2014/07/22 16:12:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Movies
[2013/12/13 12:48:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
[2015/03/10 19:51:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSECache
[2015/02/15 15:15:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mumble
[2014/04/09 07:45:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NVIDIA Corporation
[2014/07/22 00:08:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OpenOffice 4
[2015/01/27 02:06:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Opera
[2015/02/10 22:16:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PhotoFiltre 7
[2014/10/27 13:22:43 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PopCap Games
[2014/04/09 07:51:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Qualcomm Atheros
[2014/12/12 23:17:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\QuickTime
[2015/01/30 21:19:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\R.G. Mechanics
[2014/04/09 07:51:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek
[2013/12/13 12:48:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
[2014/12/21 11:15:16 | 000,000,000 | R--D | M] -- C:\Program Files (x86)\Skype
[2014/07/20 16:46:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Sony
[2015/02/16 19:44:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Steam
[2014/09/21 19:03:43 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\TechSmith
[2014/04/09 07:48:25 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp
[2014/07/11 17:21:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WildTangent Games
[2015/03/11 20:46:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
[2015/03/06 02:02:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
[2015/03/06 02:02:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
[2015/03/06 02:02:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Multimedia Platform
[2013/08/22 17:36:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
[2015/03/06 02:02:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Viewer
[2015/03/06 02:02:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices
[2013/08/22 17:36:30 | 000,000,000 | -HSD | M] -- C:\Program Files (x86)\Windows Sidebar
[2013/08/22 17:36:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WindowsPowerShell
[2015/02/15 21:27:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ZHPDiag

[color=#A23BEC]< MD5 for: AGP440.SYS >[/color]
[2014/07/27 20:17:31 | 000,000,012 | ---- | M] () MD5=06C6E29A8643D00197E214F3AA26A4B9 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.16384_none_aad14d4692a7dfee\AGP440.sys
[2013/08/22 14:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\WINDOWS\SysNative\drivers\AGP440.sys
[2013/08/22 14:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\machine.inf_amd64_36be84f8fc597ea3\AGP440.sys
[2013/08/22 14:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17238_none_ab0b455c927bd60f\AGP440.sys
[2014/10/05 16:08:56 | 000,000,012 | ---- | M] () MD5=AC26F500DB64617F336315BB5A0FDBE1 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17031_none_ab043f8a92822a60\AGP440.sys

[color=#A23BEC]< MD5 for: APPMGMTS.DLL >[/color]
[2013/08/22 16:55:04 | 000,086,064 | ---- | M] () MD5=1336BE8A8B1E8B8744D5217AE5FDD303 -- C:\Windows\WinSxS\amd64_microsoft-windows-g..oftwareinstallation_31bf3856ad364e35_6.3.9600.16384_none_728d486f3000a7ad\appmgmts.dll
[2015/03/08 19:16:55 | 000,087,855 | ---- | M] () MD5=5B2A9B5E87542C65457B527CC512AF25 -- C:\Windows\WinSxS\amd64_microsoft-windows-g..oftwareinstallation_31bf3856ad364e35_6.3.9600.17415_none_72d9e34b2fc71435\appmgmts.dll
[2013/08/22 17:00:05 | 000,071,466 | ---- | M] () MD5=9424C4C8AE9114A121553818824D33A3 -- C:\Windows\WinSxS\wow64_microsoft-windows-g..oftwareinstallation_31bf3856ad364e35_6.3.9600.16384_none_7ce1f2c1646169a8\appmgmts.dll
[2015/03/08 19:50:51 | 000,072,712 | ---- | M] () MD5=C73D54BF555388E7DF11A9C0AFC1F139 -- C:\Windows\WinSxS\wow64_microsoft-windows-g..oftwareinstallation_31bf3856ad364e35_6.3.9600.17415_none_7d2e8d9d6427d630\appmgmts.dll

[color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
[2013/08/22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\WINDOWS\SysNative\drivers\atapi.sys
[2013/08/22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\WINDOWS\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_64aa4354da84c2df\atapi.sys
[2013/08/22 14:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.3.9600.16384_none_cdf68824f580d510\atapi.sys

[color=#A23BEC]< MD5 for: AUTOCHK.EXE >[/color]
[2014/07/27 20:23:29 | 000,028,249 | ---- | M] () MD5=0CBDE27FB26761852F7B22AFB8C51ACB -- C:\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.16384_none_d2b24d5495b82963\autochk.exe
[2014/02/22 13:24:36 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\SysWOW64\autochk.exe
[2014/02/22 13:24:36 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_76c6a414dd35029f\autochk.exe
[2014/02/22 14:17:06 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=387A1E98BE548E4F199343CBA01E9D6D -- C:\WINDOWS\SysNative\autochk.exe
[2014/02/22 14:17:06 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=387A1E98BE548E4F199343CBA01E9D6D -- C:\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_d2e53f98959273d5\autochk.exe
[2014/07/27 22:37:38 | 000,023,596 | ---- | M] () MD5=83A4C9BE342BC296EC09492FF7594F13 -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.16384_none_7693b1d0dd5ab82d\autochk.exe

[color=#A23BEC]< MD5 for: BEEP.SYS >[/color]
[2013/08/22 13:40:24 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=EC19013E4CF87609534165DF897274D6 -- C:\WINDOWS\SysNative\drivers\beep.sys
[2013/08/22 13:40:24 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=EC19013E4CF87609534165DF897274D6 -- C:\Windows\WinSxS\amd64_microsoft-windows-beepsys_31bf3856ad364e35_6.3.9600.16384_none_b4df015ddb944ecf\beep.sys

[color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color]
[2015/03/15 03:20:00 | 000,087,190 | ---- | M] () MD5=1BF154F7BFAE2B9E0545FB09946C1817 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_42bfa1f94d79e1bb\explorer.exe
[2014/07/27 20:39:20 | 000,336,576 | ---- | M] () MD5=201E2AB1C87503398EFAE7D32AF29FFE -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16384_none_4273071d4db37533\explorer.exe
[2014/10/05 16:11:23 | 000,270,774 | ---- | M] () MD5=2195687491E604BA42961470EDA7660E -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17238_none_42acff334d876b54\explorer.exe
[2014/10/05 16:42:38 | 000,220,250 | ---- | M] () MD5=286928E00AD34E9F88EB5BFA52660A70 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17238_none_4d01a98581e82d4f\explorer.exe
[2014/07/27 22:01:04 | 000,015,546 | ---- | M] () MD5=347EFF7EC89C3EB4F72F2408E1C4E16D -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_4cfaa3b381ee81a0\explorer.exe
[2015/03/08 19:15:39 | 000,395,976 | ---- | M] () MD5=45DD8FAA7B53ABD29BCB9BACABFFC818 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17284_none_4272ee6f4db391ad\explorer.exe
[2014/07/27 22:01:00 | 000,238,918 | ---- | M] () MD5=5177BB4FECDDB9CDBCF10EF65916968D -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_4ceff22781f6788c\explorer.exe
[2015/03/15 03:25:33 | 000,107,122 | ---- | M] () MD5=52063502D4A2E28FEBEA781D0EE5C453 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_4d144c4b81daa3b6\explorer.exe
[2014/07/27 22:00:51 | 000,268,164 | ---- | M] () MD5=578A251C234E51BC6B9D684480EEB9DB -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16384_none_4cc7b16f8214372e\explorer.exe
[2014/10/05 16:11:18 | 000,271,249 | ---- | M] () MD5=667BC926C7CB889BF276A5FEA316CAEE -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_42adfbb14d868a5d\explorer.exe
[2014/07/27 20:39:30 | 000,169,957 | ---- | M] () MD5=6D919C26DCB567396CD2E119B8E4310E -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_42a5f9614d8dbfa5\explorer.exe
[2014/07/27 22:00:55 | 000,239,123 | ---- | M] () MD5=7B546CB045C2A84D26A8D2FE07F9F98C -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16408_none_4d2233dd81cfba29\explorer.exe
[2015/01/28 01:41:17 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=91E24273FCA076EA9E65DAFA98901225 -- C:\Windows\SysWOW64\explorer.exe
[2015/01/28 01:41:17 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=91E24273FCA076EA9E65DAFA98901225 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17667_none_4ce0410f82015c67\explorer.exe
[2015/03/08 19:50:45 | 000,338,811 | ---- | M] () MD5=9E110FC1BA4AB7CB5F2F9D27DB534223 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17284_none_4cc798c1821453a8\explorer.exe
[2015/01/28 01:47:12 | 002,501,368 | ---- | M] (Microsoft Corporation) MD5=C10A66189DC8C090E7C84873EDCEBC88 -- C:\Windows\explorer.exe
[2015/01/28 01:47:12 | 002,501,368 | ---- | M] (Microsoft Corporation) MD5=C10A66189DC8C090E7C84873EDCEBC88 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17667_none_428b96bd4da09a6c\explorer.exe
[2014/10/05 16:42:33 | 000,208,662 | ---- | M] () MD5=C131BC6F12417306A9C8469CA49110B1 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_4d02a60381e74c58\explorer.exe
[2014/07/27 20:39:23 | 000,284,534 | ---- | M] () MD5=D1EF5DE70183FB717B5FC4593A0E46BD -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16408_none_42cd898b4d6ef82e\explorer.exe
[2014/07/27 20:39:27 | 000,283,735 | ---- | M] () MD5=FA98C5D746E7C9E0912E88AC44FF9926 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_429b47d54d95b691\explorer.exe

[color=#A23BEC]< MD5 for: HIDSERV.DLL >[/color]
[2015/03/08 19:17:20 | 000,004,284 | ---- | M] () MD5=2A8190AC5599446255EEADD6088C3BED -- C:\Windows\WinSxS\amd64_microsoft-windows-hid-user_31bf3856ad364e35_6.3.9600.16384_none_c76aa8785b65aeab\hidserv.dll
[2015/03/08 19:51:05 | 000,007,007 | ---- | M] () MD5=73A9A38CF4CBA7E4E742D493B3D672BC -- C:\Windows\WinSxS\wow64_microsoft-windows-hid-user_31bf3856ad364e35_6.3.9600.16384_none_d1bf52ca8fc670a6\hidserv.dll
[2014/10/29 03:59:46 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=AE71B1BC1A17000F7B8F9AB79D4668D4 -- C:\Windows\SysWOW64\hidserv.dll
[2014/10/29 03:59:46 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=AE71B1BC1A17000F7B8F9AB79D4668D4 -- C:\Windows\WinSxS\wow64_microsoft-windows-hid-user_31bf3856ad364e35_6.3.9600.17415_none_d20beda68f8cdd2e\hidserv.dll
[2014/10/29 04:44:23 | 000,033,792 | ---- | M] (Microsoft Corporation) MD5=EA85B5093DF7B5C3E80362B053740AE2 -- C:\WINDOWS\SysNative\hidserv.dll
[2014/10/29 04:44:23 | 000,033,792 | ---- | M] (Microsoft Corporation) MD5=EA85B5093DF7B5C3E80362B053740AE2 -- C:\Windows\WinSxS\amd64_microsoft-windows-hid-user_31bf3856ad364e35_6.3.9600.17415_none_c7b743545b2c1b33\hidserv.dll

[color=#A23BEC]< MD5 for: IASTORV.SYS >[/color]
[2013/08/22 14:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\WINDOWS\SysNative\drivers\iaStorV.sys
[2013/08/22 14:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_5069105fb236ae4b\iaStorV.sys
[2013/08/22 14:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\Windows\WinSxS\amd64_iastorv.inf_31bf3856ad364e35_6.3.9600.16384_none_9fcfb2835bbf0103\iaStorV.sys

[color=#A23BEC]< MD5 for: IMM32.DLL >[/color]
[2014/07/27 20:55:44 | 000,016,138 | ---- | M] () MD5=0C36F98822D998BC7F2021B6FC99EBAE -- C:\Windows\WinSxS\amd64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.16384_none_4d147e214e620376\imm32.dll
[2015/03/08 19:18:39 | 000,027,353 | ---- | M] () MD5=16BF085E712ACC139C39C34CEB499D7A -- C:\Windows\WinSxS\amd64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.17031_none_4d4770654e3c4de8\imm32.dll
[2015/03/08 19:51:41 | 000,023,804 | ---- | M] () MD5=4E7419816FAD0942AEFB3B37F0D26A0D -- C:\Windows\WinSxS\wow64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.17031_none_579c1ab7829d0fe3\imm32.dll
[2014/10/29 03:59:49 | 000,141,312 | ---- | M] (Microsoft Corporation) MD5=59452E147C6A5D055E5EBCB6B8E99CB7 -- C:\Windows\SysWOW64\imm32.dll
[2014/10/29 03:59:49 | 000,141,312 | ---- | M] (Microsoft Corporation) MD5=59452E147C6A5D055E5EBCB6B8E99CB7 -- C:\Windows\WinSxS\wow64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.17415_none_57b5c34f828931f9\imm32.dll
[2014/07/27 22:13:04 | 000,007,873 | ---- | M] () MD5=DC664D9FAD5B9C36BCFD052ECF2F4E67 -- C:\Windows\WinSxS\wow64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.16384_none_5769287382c2c571\imm32.dll
[2014/10/29 06:00:23 | 000,210,744 | ---- | M] (Microsoft Corporation) MD5=DEB33D08FBF708CAAC08080054D4C7CC -- C:\WINDOWS\SysNative\imm32.dll
[2014/10/29 06:00:23 | 000,210,744 | ---- | M] (Microsoft Corporation) MD5=DEB33D08FBF708CAAC08080054D4C7CC -- C:\Windows\WinSxS\amd64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.17415_none_4d6118fd4e286ffe\imm32.dll

[color=#A23BEC]< MD5 for: KERNEL32.DLL >[/color]
[2014/10/29 03:58:23 | 001,040,384 | ---- | M] (Microsoft Corporation) MD5=00DC86D9068D7E780407A8B66E2AFD9D -- C:\Windows\SysWOW64\kernel32.dll
[2014/10/29 03:58:23 | 001,040,384 | ---- | M] (Microsoft Corporation) MD5=00DC86D9068D7E780407A8B66E2AFD9D -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17415_none_8f1d8a7a5e69bda5\kernel32.dll
[2014/07/27 22:13:25 | 000,082,041 | ---- | M] () MD5=0C7920D2233655CB99F2BAE78BCFD781 -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16521_none_8f0ed2145e7557c0\kernel32.dll
[2014/07/27 20:56:17 | 000,135,499 | ---- | M] () MD5=1381A386667228317DEA988ECEFC1D62 -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16441_none_84a486042a24d080\kernel32.dll
[2014/07/27 22:13:29 | 000,001,165 | ---- | M] () MD5=3A9C615755EFF9FB838D357A4D8D5E7C -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17031_none_8f03e1e25e7d9b8f\kernel32.dll
[2014/10/29 06:09:24 | 001,309,744 | ---- | M] (Microsoft Corporation) MD5=4F455778B6CDA2FD61D4F8B0A3E0543C -- C:\WINDOWS\SysNative\kernel32.dll
[2014/10/29 06:09:24 | 001,309,744 | ---- | M] (Microsoft Corporation) MD5=4F455778B6CDA2FD61D4F8B0A3E0543C -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17415_none_84c8e0282a08fbaa\kernel32.dll
[2015/03/08 19:51:57 | 000,121,316 | ---- | M] () MD5=63CF5E1D83272D55F2C1A7C752DEC7C9 -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17056_none_8ef3437c5e895224\kernel32.dll
[2014/07/27 22:13:19 | 000,088,050 | ---- | M] () MD5=6E3A5D86925F7D2683C0058387E805B8 -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16384_none_8ed0ef9e5ea3511d\kernel32.dll
[2014/07/27 20:56:19 | 000,137,281 | ---- | M] () MD5=6F1E283E6740914BE8FBD75C900A9C27 -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16521_none_84ba27c22a1495c5\kernel32.dll
[2014/07/27 20:56:14 | 000,140,055 | ---- | M] () MD5=96A3F18D728E6EBC6907823DA9C3758F -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16384_none_847c454c2a428f22\kernel32.dll
[2014/07/27 20:56:16 | 000,135,626 | ---- | M] () MD5=A6C043CC1A2E443BF306B29AADCC89D0 -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16408_none_84d6c7ba29fe121d\kernel32.dll
[2014/07/27 20:56:22 | 000,038,194 | ---- | M] () MD5=DA27B6723C1D4A604310F46F50C005CB -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17031_none_84af37902a1cd994\kernel32.dll
[2014/07/27 22:13:21 | 000,084,833 | ---- | M] () MD5=DC9112C7954B5A42DF927DBA7B47FE92 -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16408_none_8f2b720c5e5ed418\kernel32.dll
[2015/03/08 19:18:55 | 000,149,635 | ---- | M] () MD5=DE0B6AADFB0BA5D0AABA9EAD2011D02C -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17056_none_849e992a2a289029\kernel32.dll
[2014/07/27 22:13:23 | 000,084,771 | ---- | M] () MD5=F28CE411799F15BC8F68102C79725B20 -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16441_none_8ef930565e85927b\kernel32.dll

[color=#A23BEC]< MD5 for: MSWSOCK.DLL >[/color]
[2015/03/08 19:38:38 | 000,089,664 | ---- | M] () MD5=91B386E48B823AE3047B924D104C4AE9 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.3.9600.16384_none_a911b7110142c502\mswsock.dll
[2014/10/29 03:06:17 | 000,286,208 | ---- | M] (Microsoft Corporation) MD5=98ECA44A09EFA23890205D2B5233FC96 -- C:\Windows\SysWOW64\mswsock.dll
[2014/10/29 03:06:17 | 000,286,208 | ---- | M] (Microsoft Corporation) MD5=98ECA44A09EFA23890205D2B5233FC96 -- C:\Windows\WinSxS\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.3.9600.17415_none_4d3fb66948abc054\mswsock.dll
[2014/10/29 03:29:43 | 000,339,456 | ---- | M] (Microsoft Corporation) MD5=B394EB3E443DCB195BC65B9A54CD8FE3 -- C:\WINDOWS\SysNative\mswsock.dll
[2014/10/29 03:29:43 | 000,339,456 | ---- | M] (Microsoft Corporation) MD5=B394EB3E443DCB195BC65B9A54CD8FE3 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.3.9600.17415_none_a95e51ed0109318a\mswsock.dll
[2015/03/08 20:19:19 | 000,073,881 | ---- | M] () MD5=DD9EB5415ED0BA50A6FDF18E77D58BA8 -- C:\Windows\WinSxS\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.3.9600.16384_none_4cf31b8d48e553cc\mswsock.dll

[color=#A23BEC]< MD5 for: NDIS.SYS >[/color]
[2015/02/05 22:24:44 | 001,113,920 | ---- | M] (Microsoft Corporation) MD5=6D3A2565E01B3E4B0F1BEDB0D4B00B3F -- C:\WINDOWS\SysNative\drivers\ndis.sys
[2015/02/05 22:24:44 | 001,113,920 | ---- | M] (Microsoft Corporation) MD5=6D3A2565E01B3E4B0F1BEDB0D4B00B3F -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17673_none_4a1d9ccbfbfbedff\ndis.sys
[2014/07/27 21:03:54 | 000,144,548 | ---- | M] () MD5=6FF1A14DC17A19F68C45B759E57F8F54 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.16405_none_4a6b5fcffbc14927\ndis.sys
[2014/07/27 21:03:57 | 000,140,607 | ---- | M] () MD5=7B886741BDAE33AC4F116DF991D1E3CB -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.16475_none_4a1fb05bfbfa0cbe\ndis.sys
[2014/07/27 21:03:52 | 000,141,699 | ---- | M] () MD5=975B2A08EFF9250B2504C01C77993ECC -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.16384_none_4a13de3ffc031231\ndis.sys
[2015/03/15 03:22:16 | 000,080,695 | ---- | M] () MD5=9C48968B0344AD63559D0D080DA66103 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17399_none_4a0df8fdfc06c676\ndis.sys
[2014/07/27 21:03:56 | 000,139,631 | ---- | M] () MD5=A4F977473222918A2BD275FB72DC4816 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.16408_none_4a6e60adfbbe952c\ndis.sys
[2015/03/08 19:25:33 | 000,162,319 | ---- | M] () MD5=A627B5D38300791075615FF3C8BB3991 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17199_none_4a0df531fc06cc28\ndis.sys
[2014/10/05 16:24:05 | 000,025,682 | ---- | M] () MD5=D2D6A481A75207BF24E9D48C61B7F012 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17031_none_4a46d083fbdd5ca3\ndis.sys

[color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color]
[2014/10/29 03:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) MD5=02D117FC638B768BD1A15F8000B83EAE -- C:\WINDOWS\SysNative\netlogon.dll
[2014/10/29 03:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) MD5=02D117FC638B768BD1A15F8000B83EAE -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17415_none_eec2b22a0bb75b53\netlogon.dll
[2014/07/27 22:18:12 | 000,058,552 | ---- | M] () MD5=35048C9600694C3BF01D644D1AAE62BE -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.16384_none_f8cac1a04051b0c6\netlogon.dll
[2015/03/08 19:31:18 | 000,125,384 | ---- | M] () MD5=45C2C2EA335BD7FF360C7F006B915766 -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17041_none_ee9e39a60bd3552e\netlogon.dll
[2015/03/08 19:56:11 | 000,105,907 | ---- | M] () MD5=B25E2DE4078511EB1747FA0BDB6E4FC5 -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17041_none_f8f2e3f840341729\netlogon.dll
[2014/10/29 03:02:34 | 000,695,296 | ---- | M] (Microsoft Corporation) MD5=CCEC6CB98A00ECE7F5AFB9C0FC9427B3 -- C:\Windows\SysWOW64\netlogon.dll
[2014/10/29 03:02:34 | 000,695,296 | ---- | M] (Microsoft Corporation) MD5=CCEC6CB98A00ECE7F5AFB9C0FC9427B3 -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17415_none_f9175c7c40181d4e\netlogon.dll
[2014/07/27 21:13:36 | 000,108,975 | ---- | M] () MD5=D817ED82C2A0E1CED9B396826F52F7CB -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.16384_none_ee76174e0bf0eecb\netlogon.dll

[color=#A23BEC]< MD5 for: NTFS.SYS >[/color]
[2014/07/27 21:04:39 | 000,079,923 | ---- | M] () MD5=5237125E4CEFA4B02A820998092A2DBA -- C:\Windows\WinSxS\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.3.9600.17031_none_97627c0bf0bcea79\ntfs.sys
[2014/07/27 21:04:33 | 000,328,571 | ---- | M] () MD5=6986BA446666FDAFA2DBB95F9D8E0A23 -- C:\Windows\WinSxS\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.3.9600.16384_none_972f89c7f0e2a007\ntfs.sys
[2014/10/15 10:32:37 | 002,025,792 | ---- | M] (Microsoft Corporation) MD5=7F68063A5A0461E02BC860CE0E6BFDDC -- C:\WINDOWS\SysNative\drivers\ntfs.sys
[2014/10/15 10:32:37 | 002,025,792 | ---- | M] (Microsoft Corporation) MD5=7F68063A5A0461E02BC860CE0E6BFDDC -- C:\Windows\WinSxS\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.3.9600.17401_none_9782f367f0a48b42\ntfs.sys
[2014/10/05 16:24:11 | 000,216,915 | ---- | M] () MD5=BBB0E3DE6DA1971DB7EC0C74B0F50310 -- C:\Windows\WinSxS\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.3.9600.17056_none_9751dda5f0c8a10e\ntfs.sys
[2015/03/08 19:26:24 | 000,378,139 | ---- | M] () MD5=E5D1987CD7FBB2169440CD9B8E2AB87E -- C:\Windows\WinSxS\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.3.9600.17238_none_976981ddf0b69628\ntfs.sys

[color=#A23BEC]< MD5 for: NVSTOR.SYS >[/color]
[2013/08/22 14:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\WINDOWS\SysNative\drivers\nvstor.sys
[2013/08/22 14:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\WINDOWS\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_7ba65ba4b222e751\nvstor.sys
[2013/08/22 14:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.3.9600.16384_none_2a99233292f5aadb\nvstor.sys

[color=#A23BEC]< MD5 for: PROQUOTA.EXE >[/color]
[2014/10/29 04:20:00 | 000,032,256 | ---- | M] (Microsoft Corporation) MD5=864379396733031C99B64550358CAEBD -- C:\WINDOWS\SysNative\proquota.exe
[2014/10/29 04:20:00 | 000,032,256 | ---- | M] (Microsoft Corporation) MD5=864379396733031C99B64550358CAEBD -- C:\Windows\WinSxS\amd64_microsoft-windows-proquota_31bf3856ad364e35_6.3.9600.17415_none_18d1f2be66229ae5\proquota.exe
[2015/03/08 20:15:04 | 000,003,774 | ---- | M] () MD5=8FB27AE214469C91285EE90DADF94D78 -- C:\Windows\WinSxS\x86_microsoft-windows-proquota_31bf3856ad364e35_6.3.9600.16384_none_bc66bc5eadfebd27\proquota.exe
[2015/03/08 19:28:36 | 000,002,700 | ---- | M] () MD5=C76ABF6F332C8E55700EADCB3F0FE880 -- C:\Windows\WinSxS\amd64_microsoft-windows-proquota_31bf3856ad364e35_6.3.9600.16384_none_188557e2665c2e5d\proquota.exe
[2014/10/29 03:40:27 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=DF801B9FC4247EBFBFE07E5EC417C5B0 -- C:\Windows\SysWOW64\proquota.exe
[2014/10/29 03:40:27 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=DF801B9FC4247EBFBFE07E5EC417C5B0 -- C:\Windows\WinSxS\x86_microsoft-windows-proquota_31bf3856ad364e35_6.3.9600.17415_none_bcb3573aadc529af\proquota.exe

[color=#A23BEC]< MD5 for: QMGR.DLL >[/color]
[2014/10/29 03:43:34 | 000,933,376 | ---- | M] (Microsoft Corporation) MD5=48554994279BFE17A3D2B00076D0CB1A -- C:\WINDOWS\SysNative\qmgr.dll
[2014/10/29 03:43:34 | 000,933,376 | ---- | M] (Microsoft Corporation) MD5=48554994279BFE17A3D2B00076D0CB1A -- C:\Windows\WinSxS\amd64_microsoft-windows-bits-client_31bf3856ad364e35_6.3.9600.17415_none_149bbfd3cd2f7e88\qmgr.dll
[2015/03/08 19:07:44 | 000,297,501 | ---- | M] () MD5=C3D7BF1A7970C6765A8F6F7E42099FCE -- C:\Windows\WinSxS\amd64_microsoft-windows-bits-client_31bf3856ad364e35_6.3.9600.16384_none_144f24f7cd691200\qmgr.dll

[color=#A23BEC]< MD5 for: SCECLI.DLL >[/color]
[2015/03/08 19:56:02 | 000,042,572 | ---- | M] () MD5=22CDB04B964A8D34C42BB7ED150784F8 -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_3320ecb8e1733781\scecli.dll
[2015/03/08 19:30:59 | 000,045,911 | ---- | M] () MD5=878EBE290BED3EE6AC21BF4EE1458F67 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_28cc4266ad127586\scecli.dll
[2014/10/29 03:23:16 | 000,274,944 | ---- | M] (Microsoft Corporation) MD5=9A475B8F19A15BFDE8DF84E40ECAE8AA -- C:\WINDOWS\SysNative\scecli.dll
[2014/10/29 03:23:16 | 000,274,944 | ---- | M] (Microsoft Corporation) MD5=9A475B8F19A15BFDE8DF84E40ECAE8AA -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17415_none_2918dd42acd8e20e\scecli.dll
[2014/10/29 03:01:41 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\SysWOW64\scecli.dll
[2014/10/29 03:01:41 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17415_none_336d8794e139a409\scecli.dll

[color=#A23BEC]< MD5 for: SPOOLSV.EXE >[/color]
[2015/03/08 19:28:26 | 000,144,407 | ---- | M] () MD5=5E94BD87266C67420DCB3FF2516D8A9D -- C:\Windows\WinSxS\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.3.9600.17238_none_c743fb429553c1ab\spoolsv.exe
[2014/10/05 16:24:50 | 000,099,497 | ---- | M] () MD5=8CA60826DC34EB3177C1F84D7A05D6C4 -- C:\Windows\WinSxS\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.3.9600.16384_none_c70a032c957fcb8a\spoolsv.exe
[2014/10/29 02:54:15 | 000,827,392 | ---- | M] (Microsoft Corporation) MD5=FCB156A6745631A67DEA61827061D483 -- C:\WINDOWS\SysNative\spoolsv.exe
[2014/10/29 02:54:15 | 000,827,392 | ---- | M] (Microsoft Corporation) MD5=FCB156A6745631A67DEA61827061D483 -- C:\Windows\WinSxS\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.3.9600.17415_none_c7569e0895463812\spoolsv.exe

[color=#A23BEC]< MD5 for: SVCHOST.EXE >[/color]
[2014/11/21 07:12:42 | 000,761,656 | ---- | M] (MalwareBytes) MD5=625BB08813743947985B0DEEFC35ED12 -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\svchost.exe
[2015/03/08 20:16:30 | 000,007,517 | ---- | M] () MD5=73AA583D4FB0F05C313B38C091D94804 -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_4a5b1e2820e75323\svchost.exe
[2014/10/18 19:02:01 | 000,518,144 | ---- | M] (SteelWerX) MD5=A46842C9B0C567A5A9584E83A163560C -- C:\AdsFix\svchost.exe
[2015/03/08 19:31:27 | 000,007,559 | ---- | M] () MD5=CFE97816CBBEF783FD8634109F1877D2 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_a679b9abd944c459\svchost.exe
[2014/10/29 05:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\SysWOW64\svchost.exe
[2014/10/29 05:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_4aa7b90420adbfab\svchost.exe
[2014/10/29 06:11:20 | 000,038,792 | ---- | M] (Microsoft Corporation) MD5=E3A2AD05E24105B35E986CF9CB38EC47 -- C:\WINDOWS\SysNative\svchost.exe
[2014/10/29 06:11:20 | 000,038,792 | ---- | M] (Microsoft Corporation) MD5=E3A2AD05E24105B35E986CF9CB38EC47 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_a6c65487d90b30e1\svchost.exe

[color=#A23BEC]< MD5 for: TERMSRV.DLL >[/color]
[2015/03/08 19:35:48 | 000,200,637 | ---- | M] () MD5=640B43E4063B00DD1769C93FEDBFD8B4 -- C:\Windows\WinSxS\amd64_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.3.9600.17095_none_7f53b5b72842754a\termsrv.dll
[2014/07/27 21:26:44 | 000,160,809 | ---- | M] () MD5=AD8954261EED4AB66F8CFB0CAC218143 -- C:\Windows\WinSxS\amd64_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.3.9600.16384_none_7f5da1d3283b1dd6\termsrv.dll
[2014/07/27 21:26:45 | 000,160,809 | ---- | M] () MD5=AD8954261EED4AB66F8CFB0CAC218143 -- C:\Windows\WinSxS\amd64_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.3.9600.16389_none_7f62a34528369c89\termsrv.dll
[2014/10/29 03:34:57 | 001,114,624 | ---- | M] (Microsoft Corporation) MD5=C50997E282576DA492EBA66B059D4196 -- C:\WINDOWS\SysNative\termsrv.dll
[2014/10/29 03:34:57 | 001,114,624 | ---- | M] (Microsoft Corporation) MD5=C50997E282576DA492EBA66B059D4196 -- C:\Windows\WinSxS\amd64_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.3.9600.17415_none_7faa3caf28018a5e\termsrv.dll

[color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
[2015/03/08 19:38:02 | 000,002,671 | ---- | M] () MD5=061AC3BD7ADC5DCBA6AC0F23895266F8 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_cce71a20a5a6fe7f\userinit.exe
[2015/03/08 20:19:05 | 000,004,269 | ---- | M] () MD5=1AE98168631581DE1343C3A87A6CBCA9 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_70c87e9ced498d49\userinit.exe
[2014/10/29 03:28:08 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=5C131534A3EA4A461A793FB507A8004F -- C:\WINDOWS\SysNative\userinit.exe
[2014/10/29 03:28:08 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=5C131534A3EA4A461A793FB507A8004F -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_cd33b4fca56d6b07\userinit.exe
[2014/10/29 03:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\SysWOW64\userinit.exe
[2014/10/29 03:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_71151978ed0ff9d1\userinit.exe

[color=#A23BEC]< MD5 for: VOLSNAP.SYS >[/color]
[2014/07/27 21:46:12 | 000,043,661 | ---- | M] () MD5=0BEEEDD2D3CD2A33EDD3C32B89881486 -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.3.9600.16384_none_0675178bd00c0141\volsnap.sys
[2014/07/27 21:46:12 | 000,043,446 | ---- | M] () MD5=462507EFFF00135C173E059BF0AE287B -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.3.9600.16523_none_06b4fa95cfdc3a92\volsnap.sys
[2014/10/05 16:34:31 | 000,031,490 | ---- | M] () MD5=50C79EDB89463E12CA94E0840DFD0932 -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.3.9600.17041_none_069d39e3cfee67a4\volsnap.sys
[2014/06/19 04:13:36 | 000,310,080 | ---- | M] (Microsoft Corporation) MD5=64CA2B4A49A8EAF495E435623ECCE7DB -- C:\WINDOWS\SysNative\drivers\volsnap.sys
[2014/06/19 04:13:36 | 000,310,080 | ---- | M] (Microsoft Corporation) MD5=64CA2B4A49A8EAF495E435623ECCE7DB -- C:\WINDOWS\SysNative\DriverStore\FileRepository\volume.inf_amd64_8687137d6e4faf5d\volsnap.sys
[2014/06/19 04:13:36 | 000,310,080 | ---- | M] (Microsoft Corporation) MD5=64CA2B4A49A8EAF495E435623ECCE7DB -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.3.9600.17215_none_06c1ae9bcfd2737b\volsnap.sys
[2014/07/27 21:46:13 | 000,033,436 | ---- | M] () MD5=A24CC4ADEC9998D129FB7F5A1D1BA606 -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.3.9600.17031_none_06a809cfcfe64bb3\volsnap.sys

[color=#A23BEC]< MD5 for: WININET.DLL >[/color]
[2014/10/05 16:56:07 | 000,337,112 | ---- | M] () MD5=00BC54C202D7169DB62EB8C53E3D43E4 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.16384_none_a98fba06cc6a349d\wininet.dll
[2014/09/04 20:09:48 | 000,307,122 | ---- | M] () MD5=0218FED60D4EFCAFCBB63785BF6B4037 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17031_none_05ca0a1a84b38391\wininet.dll
[2015/03/15 03:20:19 | 000,281,361 | ---- | M] () MD5=18657B28917AC11E8D14C441B98D9A36 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17631_none_05892a9284e42b37\wininet.dll
[2014/12/20 23:31:17 | 000,432,455 | ---- | M] () MD5=21ADB1E0449E22F5E601E134BF9A2EDD -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17351_none_a98cff66cc6c98dc\wininet.dll
[2015/02/20 03:28:25 | 002,358,784 | ---- | M] (Microsoft Corporation) MD5=36F99BD8A0F09BDBB7850A138845A014 -- C:\WINDOWS\SysNative\wininet.dll
[2015/02/20 03:28:25 | 002,358,784 | ---- | M] (Microsoft Corporation) MD5=36F99BD8A0F09BDBB7850A138845A014 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17690_none_058f431684dea9a0\wininet.dll
[2014/12/20 22:39:58 | 000,504,640 | ---- | M] () MD5=436C8B13E0360DC7644C2EA006BF97C0 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17351_none_05ab9aea84ca0a12\wininet.dll
[2014/10/05 16:13:10 | 000,471,669 | ---- | M] () MD5=54A890173C5390077B6E413893E2FB2F -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.16412_none_059cb12884d5dd21\wininet.dll
[2014/10/19 17:55:47 | 000,235,179 | ---- | M] () MD5=6096501D1F4F82BEA0C4D5683106B3F2 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17278_none_a999306ecc636300\wininet.dll
[2014/10/05 16:13:04 | 000,469,769 | ---- | M] () MD5=6CC92B81EA245F779F51F51A55BB0245 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.16384_none_05ae558a84c7a5d3\wininet.dll
[2014/10/05 16:13:17 | 000,471,662 | ---- | M] () MD5=708AE2360F04B87657D0148A3BD2F51C -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.16438_none_059e290c84d4a995\wininet.dll
[2014/02/28 11:32:50 | 000,412,448 | ---- | M] () MD5=7543AC96175E699143B39EFC89CAB162 -- C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\WININET.dll
[2014/10/19 17:44:49 | 000,315,272 | ---- | M] () MD5=90BEBDBAFBBDAC3AF477E2358F8BA9F5 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17278_none_05b7cbf284c0d436\wininet.dll
[2014/10/05 16:56:11 | 000,335,497 | ---- | M] () MD5=A3EE6AC24B4FE87B1125A46FD5DC0290 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.16412_none_a97e15a4cc786beb\wininet.dll
[2015/02/13 21:30:00 | 000,059,876 | ---- | M] () MD5=B23BBE12AF200084BC77C83140046803 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17498_none_05a42cae84cf3ec6\wininet.dll
[2014/12/20 23:31:30 | 000,253,886 | ---- | M] () MD5=B2DC3CB5B3FAEB2C012BF1B22DBEFC6C -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17416_none_a97dbc6acc78cf96\wininet.dll
[2014/12/20 22:40:07 | 000,333,928 | ---- | M] () MD5=BDB363574A2F060164762ACBAEC5B613 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17416_none_059c57ee84d640cc\wininet.dll
[2014/09/04 20:31:50 | 000,229,501 | ---- | M] () MD5=CC12664DBD7CA68C750082A9368CD5F6 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17031_none_a9ab6e96cc56125b\wininet.dll
[2015/03/15 03:29:44 | 000,200,265 | ---- | M] () MD5=D594CB3F63B80335D5B7A9478C90C2AF -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17631_none_a96a8f0ecc86ba01\wininet.dll
[2015/02/13 21:42:01 | 000,003,879 | ---- | M] () MD5=DD9BB654041748399F4F03E4573A9EA8 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17498_none_a985912acc71cd90\wininet.dll
[2014/10/05 16:56:20 | 000,291,660 | ---- | M] () MD5=E95D91A9CAA671059F4B3CA92EA103DB -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17239_none_a995187ecc671745\wininet.dll
[2015/02/20 03:01:25 | 001,888,256 | ---- | M] (Microsoft Corporation) MD5=EA6EA6912F27F05C61D8D747517EB47E -- C:\Windows\SysWOW64\wininet.dll
[2015/02/20 03:01:25 | 001,888,256 | ---- | M] (Microsoft Corporation) MD5=EA6EA6912F27F05C61D8D747517EB47E -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17690_none_a970a792cc81386a\wininet.dll
[2014/10/05 16:13:22 | 000,412,638 | ---- | M] () MD5=F3FB5E78787A6FDA806E520F5971F682 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17239_none_05b3b40284c4887b\wininet.dll
[2014/10/05 16:56:16 | 000,335,494 | ---- | M] () MD5=FE3374D6585EBE89594F3BEFBA32F05F -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.16438_none_a97f8d88cc77385f\wininet.dll

[color=#A23BEC]< MD5 for: WININIT.EXE >[/color]
[2014/10/18 19:02:01 | 000,518,144 | ---- | M] (SteelWerX) MD5=A46842C9B0C567A5A9584E83A163560C -- C:\AdsFix\wininit.exe
[2014/10/29 03:25:54 | 000,145,920 | ---- | M] (Microsoft Corporation) MD5=A570A64292214C43E0BA50E6A72A6380 -- C:\WINDOWS\SysNative\wininit.exe
[2014/10/29 03:25:54 | 000,145,920 | ---- | M] (Microsoft Corporation) MD5=A570A64292214C43E0BA50E6A72A6380 -- C:\Windows\WinSxS\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.3.9600.17415_none_21fdb3b5d80e199e\wininit.exe
[2015/03/08 19:40:08 | 000,026,215 | ---- | M] () MD5=DCF5C72FC1D8BE1165975F1339DC92DA -- C:\Windows\WinSxS\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.3.9600.16384_none_21b118d9d847ad16\wininit.exe

[color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
[2014/10/18 19:01:51 | 000,038,400 | ---- | M] () MD5=098D1E9C1B749142F999973C794BE54D -- C:\AdsFix\winlogon.exe
[2014/10/18 19:01:51 | 000,038,400 | ---- | M] () MD5=098D1E9C1B749142F999973C794BE54D -- C:\AdsFix\winlogon.exe
[2014/11/21 07:12:42 | 000,761,656 | ---- | M] (MalwareBytes) MD5=625BB08813743947985B0DEEFC35ED12 -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
[2014/11/21 07:12:42 | 000,761,656 | ---- | M] (MalwareBytes) MD5=625BB08813743947985B0DEEFC35ED12 -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
[2015/03/08 19:40:10 | 000,100,951 | ---- | M] () MD5=A176623494AF009927242266EF51DCFB -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17031_none_60b45365a8c2ccdb\winlogon.exe
[2015/03/08 19:40:10 | 000,100,951 | ---- | M] () MD5=A176623494AF009927242266EF51DCFB -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17031_none_60b45365a8c2ccdb\winlogon.exe
[2014/07/27 21:37:06 | 000,089,459 | ---- | M] () MD5=E40DC8DF924E02F04F3620DBAC1ACE31 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.16384_none_60816121a8e88269\winlogon.exe
[2014/07/27 21:37:06 | 000,089,459 | ---- | M] () MD5=E40DC8DF924E02F04F3620DBAC1ACE31 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.16384_none_60816121a8e88269\winlogon.exe
[2014/10/29 03:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\WINDOWS\SysNative\winlogon.exe
[2014/10/29 03:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\WINDOWS\SysNative\winlogon.exe
[2014/10/29 03:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17415_none_60cdfbfda8aeeef1\winlogon.exe
[2014/10/29 03:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17415_none_60cdfbfda8aeeef1\winlogon.exe

[color=#A23BEC]< MD5 for: WS2_32.DLL >[/color]
[2014/10/29 05:05:15 | 000,321,248 | ---- | M] (Microsoft Corporation) MD5=34E71A52A1BFA68411CAECCFB6D72F8C -- C:\Windows\SysWOW64\ws2_32.dll
[2014/10/29 05:05:15 | 000,321,248 | ---- | M] (Microsoft Corporation) MD5=34E71A52A1BFA68411CAECCFB6D72F8C -- C:\Windows\WinSxS\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.17415_none_87a41025e9b6078a\ws2_32.dll
[2014/10/29 05:51:53 | 000,363,080 | ---- | M] (Microsoft Corporation) MD5=3A0B3B44C263DB1823360FF3E5C223CE -- C:\WINDOWS\SysNative\ws2_32.dll
[2014/10/29 05:51:53 | 000,363,080 | ---- | M] (Microsoft Corporation) MD5=3A0B3B44C263DB1823360FF3E5C223CE -- C:\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.17415_none_e3c2aba9a21378c0\ws2_32.dll
[2015/03/08 20:19:33 | 000,062,052 | ---- | M] () MD5=58D09EFD883813FC9709A9D98A7209DF -- C:\Windows\WinSxS\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.16384_none_87577549e9ef9b02\ws2_32.dll
[2015/03/08 19:39:00 | 000,065,749 | ---- | M] () MD5=F77C96590EA4741EB62B0FBC7A9FFFE8 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.16384_none_e37610cda24d0c38\ws2_32.dll

[color=#A23BEC]< HKEY_LOCAL_MACHINE\SYSTEM\Curr ?entControlSet\Control\Session Manager\SubSystems /s >[/color]

[color=#A23BEC]< %systemroot%\*. /mp /s >[/color]

[color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\system32\drivers\ ?*.sys /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\System32\config\* ?.sav >[/color]

[color=#A23BEC]< c:\$recycle.bin\*.* /s >[/color]
[2015/03/17 22:18:49 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-19\desktop.ini
[2015/04/03 17:27:00 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$I21DNS7.lnk
[2015/04/03 17:27:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$I3PV2HM.lnk
[2015/04/03 17:27:00 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$I6D2CM2.lnk
[2015/04/03 17:27:02 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$I6HE9JQ.lnk
[2015/04/05 15:06:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$I7QZ4R6.txt
[2015/04/03 17:27:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$I9CKPX7.lnk
[2015/04/03 17:27:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IC6GAR0.lnk
[2015/04/03 17:27:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IDEI5Y4.lnk
[2015/04/03 17:27:02 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IF5TN5H.lnk
[2015/04/03 17:27:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IF9IGY2.lnk
[2015/04/03 17:27:02 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IGK7YZS.lnk
[2015/04/03 17:27:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IH14NHY.lnk
[2015/04/03 17:27:00 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IHNGSU1.lnk
[2015/04/03 17:27:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$II9MZBZ.lnk
[2015/04/03 17:27:00 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IIY7TY4.lnk
[2015/04/03 17:27:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$ILSSP5C.lnk
[2015/04/03 17:27:02 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IMLO4HI.lnk
[2015/04/03 17:27:00 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IOW8284.lnk
[2015/04/03 17:27:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$ISOQYCU.lnk
[2015/04/03 17:27:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$ITCQRJ4.lnk
[2015/04/03 17:27:00 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IU4PEL4.lnk
[2015/04/03 17:27:02 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IVCOSOY.lnk
[2015/04/03 17:27:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IWQGY5M.lnk
[2015/04/03 17:27:00 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IYPKDE2.lnk
[2015/04/03 17:27:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$IYU0375.lnk
[2015/03/17 00:05:25 | 000,000,375 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$R21DNS7.lnk
[2015/03/15 12:54:02 | 000,004,367 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$R3PV2HM.lnk
[2015/03/10 21:33:17 | 000,000,319 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$R6D2CM2.lnk
[2015/03/06 20:55:54 | 000,003,264 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$R6HE9JQ.lnk
[2015/03/04 02:15:16 | 000,075,779 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$R7QZ4R6.txt
[2015/03/06 15:31:23 | 000,000,551 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$R9CKPX7.lnk
[2015/03/14 22:19:07 | 000,000,541 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RC6GAR0.lnk
[2015/03/15 01:56:13 | 000,004,426 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RDEI5Y4.lnk
[2015/03/10 21:33:00 | 000,000,531 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RF5TN5H.lnk
[2015/03/15 21:00:55 | 000,000,546 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RF9IGY2.lnk
[2015/03/22 17:16:14 | 000,000,571 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RGK7YZS.lnk
[2015/03/11 00:18:37 | 000,004,508 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RH14NHY.lnk
[2015/03/10 21:17:01 | 000,000,556 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RHNGSU1.lnk
[2015/03/20 09:00:55 | 000,004,508 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RI9MZBZ.lnk
[2015/03/24 20:24:09 | 000,001,113 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RIY7TY4.lnk
[2015/03/20 00:16:22 | 000,004,426 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RLSSP5C.lnk
[2015/03/10 20:32:32 | 000,000,449 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RMLO4HI.lnk
[2015/03/24 20:24:03 | 000,001,113 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$ROW8284.lnk
[2015/03/15 23:48:14 | 000,004,508 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RSOQYCU.lnk
[2015/03/11 19:00:12 | 000,000,587 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RTCQRJ4.lnk
[2015/03/15 11:10:20 | 000,000,571 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RU4PEL4.lnk
[2015/03/17 00:05:25 | 000,000,226 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RVCOSOY.lnk
[2015/03/15 01:51:58 | 000,004,618 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RWQGY5M.lnk
[2015/03/15 12:16:04 | 000,000,594 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RYPKDE2.lnk
[2015/03/15 01:51:47 | 000,004,559 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\$RYU0375.lnk
[2015/03/04 02:16:32 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1001\desktop.ini
[2015/03/04 01:41:36 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-1374178662-1023869762-4103191597-1002\desktop.ini

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 233 bytes -> C:\Users\remy\SkyDrive:ms-properties

< End of report >

Publicité


Signaler le contenu de ce document

Publicité