cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-05-2015 01
Ran by jeanfrançois (administrator) on PC-JF on 08-05-2015 00:26:55
Running from C:\Users\jeanfrançois\Downloads
Loaded Profiles: UpdatusUser & jeanfrançois & (Available profiles: UpdatusUser & jeanfrançois)
Platform: Windows 8.1 (X64) OS Language: Français (France)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
() C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusVibe\AsusVibe2.0.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\WerFault.exe
Failed to access process -> WWAHost.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWXConfigManager.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWXConfigManager.exe
(Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cleanmgr.exe
(Microsoft Corporation) C:\Users\jeanfrançois\AppData\Local\Temp\E2FC775A-34A7-4096-AA79-8C7327F692B1\DismHost.exe
(Microsoft Corporation) C:\Users\jeanfrançois\AppData\Local\Temp\25096B83-6C1E-4351-AB0C-47E7903A4887\DismHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OFFICE15\CSISYNCCLIENT.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13776088 2014-12-11] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1391472 2014-12-11] (Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40336 2014-12-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [3576784 2012-12-19] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-07] (Avast Software s.r.o.)
HKLM-x32\...\Run: [fst_fr_173] => [X]
HKLM-x32\...\Run: [stv_fr_4] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [335232 2015-04-10] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1605110704-1099241395-3047572257-1001\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516608 2014-10-29] (Microsoft Corporation)
HKU\S-1-5-21-1605110704-1099241395-3047572257-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516608 2014-10-29] (Microsoft Corporation)
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\...\Run: [AlcoholAutomount] => C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [2874048 2015-02-19] (Valve Corporation)
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\...\Run: [MyDriveConnect.exe] => C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe [473464 2014-03-17] (TomTom)
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\...\Run: [Google Update] => "C:\Users\jeanfrançois\AppData\Local\Google\Update\GoogleUpdate.exe" /c
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\...\Run: [OneDrive] => C:\Users\jeanfrançois\AppData\Local\Microsoft\OneDrive\OneDrive.exe [281248 2015-03-14] (Microsoft Corporation)
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7451928 2015-03-13] (Piriform Ltd)
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\...\MountPoints2: {45a21547-8d16-11e4-bef1-ac220bd87922} - "F:\AutoRun.exe"
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\...\MountPoints2: {6a76af4e-b16f-11e4-bef7-ac220bd87922} - "F:\startme.exe"
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\...\MountPoints2: {76d06d7f-5293-11e4-bed2-ac220bd87922} - "F:\startme.exe"
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\...\MountPoints2: {cfcab7bc-26b7-11e4-bec2-ac220bd87922} - "F:\Startme.exe"
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [AlcoholAutomount] => C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [2874048 2015-02-19] (Valve Corporation)
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [MyDriveConnect.exe] => C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe [473464 2014-03-17] (TomTom)
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Google Update] => "C:\Users\jeanfrançois\AppData\Local\Google\Update\GoogleUpdate.exe" /c
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [OneDrive] => C:\Users\jeanfrançois\AppData\Local\Microsoft\OneDrive\OneDrive.exe [281248 2015-03-14] (Microsoft Corporation)
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7451928 2015-03-13] (Piriform Ltd)
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {45a21547-8d16-11e4-bef1-ac220bd87922} - "F:\AutoRun.exe"
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {6a76af4e-b16f-11e4-bef7-ac220bd87922} - "F:\startme.exe"
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {76d06d7f-5293-11e4-bed2-ac220bd87922} - "F:\startme.exe"
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {cfcab7bc-26b7-11e4-bec2-ac220bd87922} - "F:\Startme.exe"
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Lancement rapide de SolidWorks 2013.lnk [2014-04-13]
ShortcutTarget: Lancement rapide de SolidWorks 2013.lnk -> C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe (Flexera Software, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Téléchargement en arrière-plan de SolidWorks.lnk [2014-04-13]
ShortcutTarget: Téléchargement en arrière-plan de SolidWorks.lnk -> C:\Program Files (x86)\Common Files\Gestionnaire d'installation SolidWorks\BackgroundDownloading\sldBgDwld.exe (Dassault Systèmes SolidWorks Corp.)
Startup: C:\Users\jeanfrançois\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Envoyer à OneNote.lnk [2014-01-05]
ShortcutTarget: Envoyer à OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (No File)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll [2012-09-27] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll [2012-09-27] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll [2012-09-27] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-05-07] (Avast Software s.r.o.)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp&ts=1399364395&from=tugs&uid=TOSHIBAXMQ01ABD050_63RIFXE7SXX63RIFXE7S
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1399364395&from=tugs&uid=TOSHIBAXMQ01ABD050_63RIFXE7SXX63RIFXE7S&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp&ts=1399364395&from=tugs&uid=TOSHIBAXMQ01ABD050_63RIFXE7SXX63RIFXE7S
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?type=ds&ts=1399364395&from=tugs&uid=TOSHIBAXMQ01ABD050_63RIFXE7SXX63RIFXE7S&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1605110704-1099241395-3047572257-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus13.msn.com
HKU\S-1-5-21-1605110704-1099241395-3047572257-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
HKU\S-1-5-21-1605110704-1099241395-3047572257-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus13.msn.com
HKU\S-1-5-21-1605110704-1099241395-3047572257-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\Software\Microsoft\Internet Explorer\Main,Search Page = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=c2205a95c7230ef1c619d8e6ee2634c2&text={searchTerms}
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=c2205a95c7230ef1c619d8e6ee2634c2&text={searchTerms}
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Page = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=c2205a95c7230ef1c619d8e6ee2634c2&text={searchTerms}
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=c2205a95c7230ef1c619d8e6ee2634c2&text={searchTerms}
URLSearchHook: [S-1-5-21-1605110704-1099241395-3047572257-1002] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: HKU\S-1-5-21-1605110704-1099241395-3047572257-1002 - (No Name) - {0633EE93-D776-472f-A0FF-E1416B8B2E3D} - No File
URLSearchHook: [S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 - (No Name) - {0633EE93-D776-472f-A0FF-E1416B8B2E3D} - No File
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1399364395&from=tugs&uid=TOSHIBAXMQ01ABD050_63RIFXE7SXX63RIFXE7S&q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=tele0101&cd=2XzuyEtN2Y1L1Qzu0A0CtBtBtD0B0DzzyBzytBtBtAyCtA0AtN0D0Tzu0SyByDtBtN1L2XzutBtFtBtFtCyDtFtCyDzytBtN1L1CzutDzytDtCtG1T&cr=83404713&ir=
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1399364395&from=tugs&uid=TOSHIBAXMQ01ABD050_63RIFXE7SXX63RIFXE7S&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1399364395&from=tugs&uid=TOSHIBAXMQ01ABD050_63RIFXE7SXX63RIFXE7S&q={searchTerms}
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1605110704-1099241395-3047572257-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3C} URL = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=c2205a95c7230ef1c619d8e6ee2634c2&text={searchTerms}
SearchScopes: HKU\S-1-5-21-1605110704-1099241395-3047572257-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3C} URL = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=c2205a95c7230ef1c619d8e6ee2634c2&text={searchTerms}
SearchScopes: HKU\S-1-5-21-1605110704-1099241395-3047572257-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3D} URL = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=c2205a95c7230ef1c619d8e6ee2634c2&text=
SearchScopes: HKU\S-1-5-21-1605110704-1099241395-3047572257-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1399364395&from=tugs&uid=TOSHIBAXMQ01ABD050_63RIFXE7SXX63RIFXE7S&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1605110704-1099241395-3047572257-1002 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL =
SearchScopes: HKU\S-1-5-21-1605110704-1099241395-3047572257-1002 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3C} URL = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=c2205a95c7230ef1c619d8e6ee2634c2&text={searchTerms}
SearchScopes: HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3C} URL = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=c2205a95c7230ef1c619d8e6ee2634c2&text={searchTerms}
SearchScopes: HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3D} URL = http://yamdex.net/?searchid=1&l10n=ru&fromsearch=1&imsid=c2205a95c7230ef1c619d8e6ee2634c2&text=
SearchScopes: HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://istart.webssearches.com/web/?type=ds&ts=1399364395&from=tugs&uid=TOSHIBAXMQ01ABD050_63RIFXE7SXX63RIFXE7S&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL =
SearchScopes: HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-18] (Avast Software s.r.o.)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-02-10] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-27] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-18] (Avast Software s.r.o.)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-01-21] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-27] (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-03-12] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1399364395&from=tugs&uid=TOSHIBAXMQ01ABD050_63RIFXE7SXX63RIFXE7S

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-27] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll No File
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-05-07] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-05-07] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2014-04-06] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1605110704-1099241395-3047572257-1002: @tools.google.com/Google Update;version=3 -> C:\Users\jeanfrançois\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll No File
FF Plugin HKU\S-1-5-21-1605110704-1099241395-3047572257-1002: @tools.google.com/Google Update;version=9 -> C:\Users\jeanfrançois\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll No File
FF Plugin HKU\S-1-5-21-1605110704-1099241395-3047572257-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\jeanfrançois\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-12-05] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-1605110704-1099241395-3047572257-1002: sony.com/MediaGoDetector -> C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll [2014-07-10] (Sony Network Entertainment International LLC)
FF Plugin HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @tools.google.com/Google Update;version=3 -> C:\Users\jeanfrançois\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll No File
FF Plugin HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @tools.google.com/Google Update;version=9 -> C:\Users\jeanfrançois\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll No File
FF Plugin HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\jeanfrançois\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-12-05] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-1605110704-1099241395-3047572257-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: sony.com/MediaGoDetector -> C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll [2014-07-10] (Sony Network Entertainment International LLC)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-01]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com", "hxxp://feed.snapdo.com/?publisher=AdKnowledgeYB&dpid=AdKnowledgeYB&co=FR&userid=2030c5fb-5dcf-4edc-b340-9135d29c0f59&searchtype=hp&installDate=05/04/2013", "hxxp://istart.webssearches.com/?type=hp&ts=1399364395&from=tugs&uid=TOSHIBAXMQ01ABD050_63RIFXE7SXX63RIFXE7S", "hxxp://istart.webssearches.com/?type=hppp&ts=1399364603&from=tugs&uid=TOSHIBAXMQ01ABD050_63RIFXE7SXX63RIFXE7S"
CHR Profile: C:\Users\jeanfrançois\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\jeanfrançois\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-07]
CHR Extension: (YouTube) - C:\Users\jeanfrançois\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-07]
CHR Extension: (Google Search) - C:\Users\jeanfrançois\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-07]
CHR Extension: (Avast SafePrice) - C:\Users\jeanfrançois\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-05-07]
CHR Extension: (AdBlock) - C:\Users\jeanfrançois\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-05-07]
CHR Extension: (Bookmark Manager) - C:\Users\jeanfrançois\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-05-08]
CHR Extension: (Avast Online Security) - C:\Users\jeanfrançois\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-05-07]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\jeanfrançois\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-07]
CHR Extension: (Google Play Books) - C:\Users\jeanfrançois\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2015-05-07]
CHR Extension: (Google Wallet) - C:\Users\jeanfrançois\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-07]
CHR Extension: (Gmail) - C:\Users\jeanfrançois\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-07]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswwebrepchrome-sp.crx [2014-08-16]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-18]
CHR HKLM-x32\...\Chrome\Extension: [ihenkjeihefokohmemphikjnjbmegdik] - "C:\Program Files (x86)\Sony\Media Go\MediaGoDetector.crx" [Not Found]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [72192 2012-12-19] () [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-05-07] (Avast Software s.r.o.)
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1429504 2015-03-05] (Microsoft Corporation)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-03-12] (WildTangent)
R2 HPSLPSVC; C:\Users\jeanfrançois\AppData\Local\Temp\7zS261B\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed]
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2014-04-13] (SolidWorks) [File not signed]
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
S3 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
S2 MATLAB License Server; "H:\matlab\etc\win64\lmgrd.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-05-07] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-05-07] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-05-07] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-05-07] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-05-07] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-05-07] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-05-07] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-05-07] ()
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3837440 2013-08-14] (Qualcomm Atheros Communications, Inc.)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-06-28] (ASUS Corporation)
U3 axscsidrv; C:\Windows\System32\Drivers\axscsidrv.sys [293888 2014-01-28] (Alcohol Soft Development Team)
S3 ggsomc; C:\Windows\System32\drivers\ggsomc.sys [30424 2014-11-04] (Sony Mobile Communications)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-08] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-01-28] (Duplex Secure Ltd.)
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 usbrndis6; C:\Windows\System32\drivers\usb80236.sys [20992 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation)
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-08 00:26 - 2015-05-08 00:27 - 00000000 ____D () C:\FRST
2015-05-08 00:26 - 2015-05-08 00:26 - 00037163 _____ () C:\Users\jeanfrançois\Downloads\FRST.txt
2015-05-08 00:23 - 2015-05-08 00:23 - 02102272 _____ (Farbar) C:\Users\jeanfrançois\Downloads\FRST64.exe
2015-05-08 00:19 - 2015-05-08 00:19 - 00136408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-05-08 00:18 - 2015-05-08 00:18 - 00001120 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-08 00:18 - 2015-05-08 00:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-08 00:18 - 2015-05-08 00:18 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-08 00:18 - 2015-05-08 00:18 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-08 00:18 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-05-08 00:18 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-05-08 00:18 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-05-08 00:16 - 2015-05-08 00:17 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\jeanfrançois\Downloads\mbam-setup-2.1.6.1022.exe
2015-05-07 23:48 - 2015-05-07 23:48 - 00093360 _____ () C:\WINDOWS\PFRO.log
2015-05-07 19:36 - 2015-05-07 19:37 - 00000000 ____D () C:\Program Files (x86)\Google
2015-05-07 19:35 - 2015-05-07 19:37 - 00000000 ____D () C:\Users\jeanfrançois\AppData\Local\Google
2015-05-07 19:32 - 2015-05-07 19:37 - 00002279 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-07 19:32 - 2015-05-07 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-05-07 19:31 - 2015-05-07 23:51 - 00001088 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-07 19:31 - 2015-05-07 21:41 - 00001092 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-07 19:31 - 2015-05-07 19:36 - 00004064 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-07 19:31 - 2015-05-07 19:36 - 00003828 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-07 19:14 - 2015-05-07 19:14 - 00364472 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\aswBoot.exe
2015-05-07 19:14 - 2015-05-07 19:14 - 00043112 _____ (Avast Software s.r.o.) C:\WINDOWS\avastSS.scr
2015-05-07 19:04 - 2015-05-07 23:49 - 00002472 _____ () C:\WINDOWS\Tasks\f26721a6-9c6e-4460-a003-55ca458a8038-5.job
2015-05-07 19:04 - 2015-05-07 19:04 - 00005476 _____ () C:\WINDOWS\System32\Tasks\f26721a6-9c6e-4460-a003-55ca458a8038-5
2015-05-07 19:04 - 2015-05-07 19:04 - 00002472 _____ () C:\WINDOWS\Tasks\f26721a6-9c6e-4460-a003-55ca458a8038-5_user.job
2015-05-07 19:04 - 2015-05-07 19:04 - 00001036 _____ () C:\WINDOWS\Tasks\Ujfea4AgKSiL.job
2015-05-07 19:02 - 2015-05-08 00:02 - 00003164 _____ () C:\WINDOWS\Tasks\f26721a6-9c6e-4460-a003-55ca458a8038-1-6.job
2015-05-07 19:02 - 2015-05-07 23:49 - 00003164 _____ () C:\WINDOWS\Tasks\f26721a6-9c6e-4460-a003-55ca458a8038-1-7.job
2015-05-07 19:02 - 2015-05-07 19:02 - 00006168 _____ () C:\WINDOWS\System32\Tasks\f26721a6-9c6e-4460-a003-55ca458a8038-1-7
2015-05-07 19:02 - 2015-05-07 19:02 - 00006168 _____ () C:\WINDOWS\System32\Tasks\f26721a6-9c6e-4460-a003-55ca458a8038-1-6
2015-05-07 19:01 - 2015-05-08 00:01 - 00005544 _____ () C:\WINDOWS\Tasks\f26721a6-9c6e-4460-a003-55ca458a8038-6.job
2015-05-07 19:01 - 2015-05-07 23:49 - 00005208 _____ () C:\WINDOWS\Tasks\f26721a6-9c6e-4460-a003-55ca458a8038-7.job
2015-05-07 19:01 - 2015-05-07 19:01 - 00008548 _____ () C:\WINDOWS\System32\Tasks\f26721a6-9c6e-4460-a003-55ca458a8038-6
2015-05-07 19:01 - 2015-05-07 19:01 - 00008212 _____ () C:\WINDOWS\System32\Tasks\f26721a6-9c6e-4460-a003-55ca458a8038-7
2015-05-07 19:00 - 2015-05-07 23:51 - 00000290 __RSH () C:\ProgramData\ntuser.pol
2015-05-07 19:00 - 2015-05-07 23:49 - 00004184 _____ () C:\WINDOWS\Tasks\f26721a6-9c6e-4460-a003-55ca458a8038-3.job
2015-05-07 19:00 - 2015-05-07 19:00 - 00007188 _____ () C:\WINDOWS\System32\Tasks\f26721a6-9c6e-4460-a003-55ca458a8038-3
2015-05-07 19:00 - 2015-05-07 19:00 - 00002138 _____ () C:\WINDOWS\Tasks\f26721a6-9c6e-4460-a003-55ca458a8038-10_user.job
2015-05-07 19:00 - 2015-05-07 19:00 - 00000008 __RSH () C:\Users\jeanfrançois\ntuser.pol
2015-05-07 15:41 - 2015-05-07 15:41 - 00000000 ____D () C:\Users\jeanfrançois\AppData\Local\4A Games
2015-05-07 09:04 - 2015-04-24 23:32 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcResources.dll
2015-05-07 09:04 - 2015-04-10 02:34 - 02256896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-05-07 09:04 - 2015-04-10 02:11 - 01943040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-05-07 09:04 - 2015-03-05 01:09 - 01429504 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-05-05 09:05 - 2015-05-07 23:48 - 00000308 _____ () C:\WINDOWS\setupact.log
2015-05-05 09:05 - 2015-05-05 09:05 - 00000000 _____ () C:\WINDOWS\setuperr.log
2015-05-05 08:59 - 2015-03-20 03:56 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2015-05-05 08:59 - 2015-03-11 03:49 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdbinst.exe
2015-05-05 08:59 - 2015-03-11 03:09 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdbinst.exe
2015-05-01 17:00 - 2015-04-02 00:22 - 02985984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2015-05-01 17:00 - 2015-04-02 00:20 - 04417536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2015-05-01 17:00 - 2015-04-01 05:45 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2015-05-01 17:00 - 2015-04-01 04:31 - 01207296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2015-05-01 17:00 - 2015-03-13 02:29 - 00410017 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-05-01 15:20 - 2015-05-01 16:21 - 00050617 _____ () C:\Users\jeanfrançois\Desktop\cv.odt
2015-04-27 15:36 - 2015-04-27 15:36 - 00000000 ____D () C:\Users\jeanfrançois\modelio
2015-04-27 15:36 - 2015-04-27 15:36 - 00000000 ____D () C:\Users\jeanfrançois\.eclipse
2015-04-27 15:33 - 2015-04-27 15:34 - 00000000 ____D () C:\Program Files (x86)\Modelio Free Edition 1.2.2
2015-04-27 15:33 - 2015-04-27 15:33 - 00001838 ____N () C:\Users\Public\Desktop\Modelio Free Edition 1.2.2.lnk
2015-04-27 15:33 - 2015-04-27 15:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Modelio Free Edition 1.2.2
2015-04-27 14:29 - 2015-04-27 14:29 - 00000723 ____N () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MATLAB R2014b.lnk
2015-04-27 14:28 - 2015-05-07 23:49 - 00000512 _____ () C:\WINDOWS\Tasks\MATLAB R2014b Startup Accelerator.job
2015-04-27 14:28 - 2015-04-27 14:28 - 00003680 _____ () C:\WINDOWS\System32\Tasks\MATLAB R2014b Startup Accelerator
2015-04-27 14:28 - 2015-04-27 14:28 - 00000000 ____D () C:\ProgramData\MathWorks
2015-04-27 14:04 - 2015-04-27 14:04 - 00561576 _____ (Oracle Corporation) C:\Users\jeanfrançois\Downloads\chromeinstall-8u45.exe
2015-04-27 13:42 - 2015-04-27 13:58 - 179146839 _____ () C:\Users\jeanfrançois\Downloads\modelio-open-201502191121-win32.win32.x86_64.zip
2015-04-23 10:45 - 2015-04-03 02:35 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
2015-04-23 10:45 - 2015-04-03 02:14 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
2015-04-23 10:45 - 2015-03-17 19:26 - 00467776 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-04-23 10:45 - 2015-03-14 04:03 - 04179968 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-04-23 10:45 - 2015-03-13 04:02 - 00316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys
2015-04-23 10:45 - 2015-03-13 03:11 - 02162176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2015-04-23 10:45 - 2015-03-13 02:39 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2015-04-23 10:45 - 2015-03-09 04:02 - 00057856 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-04-23 10:45 - 2015-03-06 04:47 - 01696256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2015-04-23 10:45 - 2015-03-04 03:32 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2015-04-23 10:45 - 2015-03-04 03:12 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2015-04-23 10:45 - 2015-01-30 02:53 - 02819584 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2015-04-23 10:44 - 2015-03-13 06:03 - 00239424 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-04-23 10:44 - 2015-03-13 06:03 - 00154432 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2015-04-23 10:44 - 2015-03-13 04:59 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-04-23 10:44 - 2015-03-13 04:38 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2015-04-23 10:44 - 2015-03-06 05:08 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll
2015-04-23 10:44 - 2015-03-06 04:43 - 01969664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll
2015-04-23 10:44 - 2015-02-18 01:19 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2015-04-23 10:44 - 2015-02-13 04:22 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-04-23 10:44 - 2015-02-13 03:46 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-04-19 21:30 - 2015-05-01 16:56 - 00000000 ___RD () C:\Users\jeanfrançois\Downloads\Microsoft.SkypeApp_kzf8qxf38zg5c!App
2015-04-19 14:20 - 2015-04-19 14:20 - 00005872 _____ () C:\Users\jeanfrançois\AppData\Roaming\Ujfea4AgKSiL
2015-04-19 01:47 - 2015-04-19 01:47 - 00000000 ____D () C:\Users\jeanfrançois\AppData\Roaming\MK10
2015-04-18 15:57 - 2015-04-18 15:57 - 00000943 ____N () C:\Users\Public\Desktop\Mortal Kombat X.lnk
2015-04-17 09:59 - 2015-04-17 09:59 - 00277575 _____ () C:\Users\jeanfrançois\Downloads\Mortal.Kombat.X.incl.2DLC.FRENCH-Mephisto.torrent
2015-04-17 09:47 - 2015-04-17 09:47 - 00014336 _____ () C:\Users\jeanfrançois\Downloads\daredevil.french.dvdrip.xvid.t411.avi.torrent
2015-04-17 09:46 - 2015-04-17 09:46 - 00014636 _____ () C:\Users\jeanfrançois\Downloads\Hunger.Games.La.Revolte.Part.1.2014.FRENCH.DVDRip.XviD-SVR.torrent
2015-04-17 00:06 - 2015-04-17 00:06 - 00113856 _____ () C:\Users\jeanfrançois\Downloads\hunger-games-la-revolte-partie-1-truefrench-dvdrip-2014.torrent
2015-04-16 23:59 - 2015-04-16 23:59 - 00113348 _____ () C:\Users\jeanfrançois\Downloads\hunger-games-la-revolte-partie-1-french-dvdrip-2014.torrent
2015-04-15 10:50 - 2015-01-06 05:01 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2015-04-15 10:50 - 2015-01-06 04:59 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2015-04-15 10:50 - 2015-01-06 03:12 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascfg.dll
2015-04-15 10:50 - 2015-01-06 03:02 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rascfg.dll
2015-04-15 10:30 - 2015-03-23 23:59 - 07476032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-04-15 10:30 - 2015-03-23 23:59 - 01733952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-04-15 10:30 - 2015-03-23 23:59 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2015-04-15 10:30 - 2015-03-23 23:58 - 01498872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-04-15 10:30 - 2015-03-23 23:45 - 00257216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2015-04-15 10:30 - 2015-03-20 06:12 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2015-04-15 10:30 - 2015-03-20 06:10 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-04-15 10:30 - 2015-03-20 06:10 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-04-15 10:30 - 2015-03-20 05:17 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\tracerpt.exe
2015-04-15 10:30 - 2015-03-20 04:41 - 00369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tracerpt.exe
2015-04-15 10:30 - 2015-03-20 04:40 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2015-04-15 10:30 - 2015-03-20 04:16 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2015-04-15 10:30 - 2015-03-13 06:32 - 24980480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-04-15 10:30 - 2015-03-13 06:08 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-04-15 10:30 - 2015-03-13 06:07 - 02886144 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-04-15 10:30 - 2015-03-13 05:53 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-04-15 10:30 - 2015-03-13 05:50 - 06025216 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-04-15 10:30 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-04-15 10:30 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-04-15 10:30 - 2015-03-13 05:26 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-04-15 10:30 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-04-15 10:30 - 2015-03-13 05:17 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-04-15 10:30 - 2015-03-13 05:16 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-04-15 10:30 - 2015-03-13 05:08 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-04-15 10:30 - 2015-03-13 05:07 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-04-15 10:30 - 2015-03-13 05:00 - 14397440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-04-15 10:30 - 2015-03-13 04:58 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2015-04-15 10:30 - 2015-03-13 04:50 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-04-15 10:30 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-04-15 10:30 - 2015-03-13 04:45 - 02358784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-04-15 10:30 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-04-15 10:30 - 2015-03-13 04:37 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
2015-04-15 10:30 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-04-15 10:30 - 2015-03-13 04:33 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-04-15 10:30 - 2015-03-13 04:22 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-04-15 10:30 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-04-15 10:30 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-04-15 10:30 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-04-15 10:30 - 2015-02-21 01:49 - 00780800 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2015-04-15 10:29 - 2015-03-23 00:45 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-04-15 10:29 - 2015-03-23 00:09 - 01111552 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-04-15 10:29 - 2015-03-23 00:09 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-04-15 10:29 - 2015-03-23 00:09 - 00769024 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-04-15 10:29 - 2015-03-23 00:09 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-04-15 10:29 - 2015-03-23 00:09 - 00419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-04-15 10:29 - 2015-03-23 00:09 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-04-15 10:29 - 2015-03-14 10:54 - 00133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-04-15 10:29 - 2015-03-14 03:56 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-04-15 10:29 - 2015-03-14 03:56 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-04-15 10:29 - 2015-03-14 03:51 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wu.upgrade.ps.dll
2015-04-15 10:29 - 2015-03-14 03:37 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-04-15 10:29 - 2015-03-14 03:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-04-15 10:29 - 2015-03-14 02:22 - 03678720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-04-15 10:29 - 2015-03-14 02:12 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-04-15 10:29 - 2015-03-14 02:12 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-04-15 10:29 - 2015-03-14 02:09 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-04-15 10:29 - 2015-03-14 02:08 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-04-15 10:29 - 2015-03-14 02:08 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-04-15 10:29 - 2015-03-14 02:06 - 02373632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-04-15 10:29 - 2015-03-14 02:06 - 00891392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-04-15 10:29 - 2015-03-14 02:02 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-04-15 10:29 - 2015-03-14 02:02 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-04-15 10:29 - 2015-03-14 01:59 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-04-15 10:29 - 2015-03-14 01:59 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-04-15 10:29 - 2015-03-04 12:25 - 00377152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2015-04-15 10:29 - 2015-03-04 05:04 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clfsw32.dll
2015-04-15 10:29 - 2015-03-04 04:19 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clfsw32.dll
2015-04-15 10:29 - 2015-02-24 10:32 - 00991552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2015-04-14 11:34 - 2015-04-29 15:56 - 00030140 _____ () C:\Users\jeanfrançois\Downloads\PROJET.xlsx
2015-04-13 18:29 - 2015-05-08 00:12 - 01395841 _____ () C:\WINDOWS\WindowsUpdate.log
2015-04-11 18:01 - 2015-04-11 18:01 - 03956930 _____ () C:\Users\jeanfrançois\Downloads\Dragonball-Xenoverse-manuelfr.rar
2015-04-11 17:57 - 2015-04-11 17:57 - 00000000 ____D () C:\Users\jeanfrançois\AppData\Roaming\Steam
2015-04-11 17:57 - 2015-04-11 17:57 - 00000000 ____D () C:\Users\jeanfrançois\AppData\Local\BANDAI NAMCO Games
2015-04-11 17:54 - 2015-04-11 17:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dragonball Xenoverse
2015-04-10 23:18 - 2015-04-10 23:18 - 00012980 _____ () C:\Users\jeanfrançois\Downloads\Dragonball.Xenoverse-CODEX.torrent
2015-04-10 23:12 - 2015-04-10 23:12 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2015-04-10 23:10 - 2015-04-10 23:11 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab
2015-04-10 23:07 - 2015-04-10 23:07 - 00027653 _____ () C:\Users\jeanfrançois\Downloads\La French 2014 FRENCH 1080p AC3 x264-LKZeR.mkv.torrent

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-08 00:25 - 2013-12-30 15:11 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1605110704-1099241395-3047572257-1002
2015-05-08 00:20 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-05-08 00:15 - 2014-01-05 18:27 - 00005072 _____ () C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for PC-JF-jeanfrançois pc-jf
2015-05-08 00:11 - 2014-08-14 01:50 - 00001118 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1605110704-1099241395-3047572257-1002UA.job
2015-05-08 00:06 - 2014-12-04 11:34 - 00000000 ____D () C:\Users\jeanfrançois\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Applications Chrome
2015-05-08 00:04 - 2014-10-25 02:02 - 00000000 __RDO () C:\Users\jeanfrançois\SkyDrive
2015-05-08 00:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-05-07 23:49 - 2014-05-06 10:20 - 00003146 _____ () C:\WINDOWS\Tasks\26459eb6-b3d8-428b-a1af-ec8faad6aed4-3.job
2015-05-07 23:49 - 2014-05-06 10:19 - 00003146 _____ () C:\WINDOWS\Tasks\ddab96e5-7b8c-4f61-822d-01ea8ef62b38-3.job
2015-05-07 23:49 - 2014-01-02 12:57 - 00000000 ____D () C:\Users\jeanfrançois
2015-05-07 23:48 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-05-07 23:46 - 2013-11-14 09:32 - 00005430 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-05-07 23:46 - 2013-11-14 09:13 - 01073004 _____ () C:\WINDOWS\system32\perfh00C.dat
2015-05-07 23:46 - 2013-11-14 09:13 - 00240172 _____ () C:\WINDOWS\system32\perfc00C.dat
2015-05-07 19:35 - 2014-01-15 14:54 - 00000000 ____D () C:\Users\jeanfrançois\AppData\Local\Deployment
2015-05-07 19:35 - 2013-12-30 15:00 - 00000062 _____ () C:\Users\jeanfrançois\AppData\Roaming\sp_data.sys
2015-05-07 19:15 - 2014-01-01 17:05 - 00003924 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-05-07 19:14 - 2014-08-16 23:15 - 00029168 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-05-07 19:14 - 2014-01-01 17:05 - 01047320 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-05-07 19:14 - 2014-01-01 17:05 - 00442264 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-05-07 19:14 - 2014-01-01 17:05 - 00272248 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-05-07 19:14 - 2014-01-01 17:05 - 00137288 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-05-07 19:14 - 2014-01-01 17:05 - 00093528 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-05-07 19:14 - 2014-01-01 17:05 - 00089944 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-05-07 19:14 - 2014-01-01 17:05 - 00065736 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-05-07 19:00 - 2014-01-02 13:31 - 00002143 ____R () C:\Users\jeanfrançois\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnеt Ехplоrеr.lnk
2015-05-07 19:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\GroupPolicy
2015-05-07 19:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\GroupPolicy
2015-05-07 18:59 - 2014-05-06 10:34 - 00002332 ____R () C:\Users\jeanfrançois\Desktop\Gооglе Сhrоmе.lnk
2015-05-07 18:59 - 2014-05-06 10:34 - 00000000 ____D () C:\Users\jeanfrançois\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-05-07 15:40 - 2014-04-13 17:01 - 00000000 ____D () C:\Users\jeanfrançois\AppData\Roaming\NVIDIA
2015-05-07 10:53 - 2014-08-18 11:54 - 00533504 ___SH () C:\Users\jeanfrançois\Downloads\Thumbs.db
2015-05-07 09:08 - 2013-08-22 15:25 - 00786432 ___SH () C:\WINDOWS\system32\config\BBI
2015-05-07 09:05 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-05-04 17:32 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2015-05-04 13:49 - 2014-05-06 10:13 - 00000000 ____D () C:\Users\jeanfrançois\AppData\Roaming\uTorrent
2015-05-01 15:35 - 2015-03-20 20:53 - 00000000 ____D () C:\Users\jeanfrançois\Documents\CV LEttre de motivation établissement
2015-05-01 15:10 - 2013-12-30 14:59 - 00000000 ____D () C:\Users\jeanfrançois\AppData\Local\VirtualStore
2015-04-29 21:57 - 2014-04-04 08:37 - 00069632 ___SH () C:\Users\jeanfrançois\Documents\Thumbs.db
2015-04-29 17:23 - 2014-12-04 17:02 - 00000000 ____D () C:\Users\jeanfrançois\Documents\projet
2015-04-27 15:33 - 2013-09-10 08:18 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-04-27 14:13 - 2014-04-21 18:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-04-27 14:12 - 2014-04-21 18:48 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-04-27 14:12 - 2014-01-12 17:24 - 00000000 ____D () C:\ProgramData\Oracle
2015-04-27 14:11 - 2014-01-12 17:22 - 00000000 ____D () C:\Program Files (x86)\Java
2015-04-24 09:08 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-04-24 08:46 - 2013-08-22 16:44 - 00532616 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-04-24 08:43 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2015-04-23 10:49 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\AdvancedInstallers
2015-04-23 08:58 - 2013-12-30 14:59 - 00000000 ____D () C:\Users\jeanfrançois\AppData\Local\Packages
2015-04-18 23:18 - 2014-03-12 01:46 - 00073728 ___SH () C:\Users\jeanfrançois\Desktop\Thumbs.db
2015-04-18 15:59 - 2014-09-22 21:57 - 00000000 ____D () C:\ProgramData\Package Cache
2015-04-18 15:57 - 2014-12-30 03:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mephisto
2015-04-17 12:22 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppCompat
2015-04-16 01:37 - 2014-01-01 18:11 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-04-16 01:24 - 2014-01-01 18:11 - 128913832 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-04-16 01:20 - 2014-05-08 15:07 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-15 10:46 - 2014-12-11 11:11 - 00000000 ____D () C:\WINDOWS\system32\appraiser
2015-04-15 10:46 - 2014-07-13 13:17 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2015-04-14 13:19 - 2015-04-01 18:10 - 00000000 ____D () C:\Users\jeanfrançois\Documents\FIFA 14
2015-04-11 17:39 - 2014-10-01 10:44 - 00000000 ____D () C:\Users\jeanfrançois\AppData\Roaming\vlc

==================== Files in the root of some directories =======

2014-02-09 20:51 - 2014-02-09 20:51 - 0000021 _____ () C:\Users\jeanfrançois\AppData\Roaming\my_intel.sys
2013-12-30 15:00 - 2015-05-07 19:35 - 0000062 _____ () C:\Users\jeanfrançois\AppData\Roaming\sp_data.sys
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\jeanfrançois\AppData\Roaming\Ujfea4AgKSiL
2014-09-22 22:08 - 2014-09-22 22:08 - 0000000 ___SH () C:\Users\jeanfrançois\AppData\Local\LumaEmu
2013-12-30 15:46 - 2014-10-30 16:08 - 0007622 _____ () C:\Users\jeanfrançois\AppData\Local\resmon.resmoncfg
2015-04-02 10:45 - 2015-04-02 10:45 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2013-04-26 01:15 - 2012-09-07 13:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd
2013-04-26 01:15 - 2009-07-22 12:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
2013-04-26 01:15 - 2012-09-07 13:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS

Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
C:\ProgramData\SetStretch.VBS


Some content of TEMP:
====================
C:\Users\jeanfrançois\AppData\Local\Temp\8868.exe
C:\Users\jeanfrançois\AppData\Local\Temp\mytmpinstaller.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-30 09:00

==================== End Of Log ============================

Publicité


Signaler le contenu de ce document

Publicité