cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

ÿþOTL logfile created on: 01/07/2015 23:22:37 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\bbouje\Downloads
Professional (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17842)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

969,24 Mb Total Physical Memory | 76,18 Mb Available Physical Memory | 7,86% Memory free
2,70 Gb Paging File | 1,35 Gb Available in Paging File | 49,96% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 117,09 Gb Total Space | 93,97 Gb Free Space | 80,25% Space Free | Partition Type: NTFS
Drive D: | 115,70 Gb Total Space | 115,23 Gb Free Space | 99,60% Space Free | Partition Type: NTFS
Drive F: | 561,02 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: BAIDAOUI | User Name: bbouje | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2015/07/01 23:21:54 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\bbouje\Downloads\OTL.exe
PRC - [2015/06/20 07:46:07 | 000,813,896 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2015/06/12 09:25:00 | 000,082,112 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2015/05/16 03:12:55 | 000,244,040 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.3.27.5\GoogleCrashHandler.exe
PRC - [2015/05/06 15:52:06 | 000,406,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\GWX\GWX.exe
PRC - [2015/01/28 01:41:17 | 002,207,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2014/10/29 05:18:49 | 000,067,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhostex.exe
PRC - [2014/10/29 03:05:25 | 000,315,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cmd.exe
PRC - [2014/10/29 02:59:34 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dasHost.exe
PRC - [2014/10/29 02:59:18 | 000,299,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2014/06/12 01:52:31 | 001,669,081 | RHS- | M] () -- C:\Windows\winevrst\poolcnst.exe
PRC - [2014/06/03 20:00:17 | 000,025,088 | RHS- | M] () -- C:\Windows\winevrst\hotsks.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2015/06/20 07:46:06 | 015,003,976 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\43.0.2357.130\PepperFlash\pepflashplayer.dll
MOD - [2015/06/20 07:46:04 | 001,281,864 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\43.0.2357.130\libglesv2.dll
MOD - [2015/06/20 07:46:04 | 000,080,712 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\43.0.2357.130\libegl.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV - [2015/06/12 09:25:00 | 000,082,112 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2015/05/25 15:07:17 | 000,977,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\diagtrack.dll -- (DiagTrack)
SRV - [2015/02/21 01:24:23 | 000,667,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsm.dll -- (LSM)
SRV - [2015/02/04 01:52:12 | 000,284,488 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV - [2015/02/04 01:52:12 | 000,022,200 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2014/12/06 03:23:49 | 000,194,048 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV - [2014/10/31 05:12:14 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2014/10/29 05:18:09 | 000,076,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\KeyboardFilterSvc.dll -- (MsKeyboardFilter)
SRV - [2014/10/29 05:13:19 | 002,948,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\WSService.dll -- (WSService)
SRV - [2014/10/29 05:06:52 | 002,472,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\spool\drivers\w32x86\3\PrintConfig.dll -- (PrintNotify)
SRV - [2014/10/29 03:57:59 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wephostsvc.dll -- (WEPHOSTSVC)
SRV - [2014/10/29 03:57:46 | 000,028,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\efssvc.dll -- (EFS)
SRV - [2014/10/29 03:52:18 | 000,052,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wiarpc.dll -- (WiaRpc)
SRV - [2014/10/29 03:51:55 | 000,017,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2014/10/29 03:51:28 | 000,010,752 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\svsvc.dll -- (svsvc)
SRV - [2014/10/29 03:47:57 | 000,098,304 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\fhsvc.dll -- (fhsvc)
SRV - [2014/10/29 03:33:49 | 000,187,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2014/10/29 03:23:51 | 000,250,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\BthHFSrv.dll -- (BthHFSrv)
SRV - [2014/10/29 03:17:53 | 000,142,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\NcaSvc.dll -- (NcaSvc)
SRV - [2014/10/29 03:14:41 | 000,423,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicvss)
SRV - [2014/10/29 03:14:41 | 000,423,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmictimesync)
SRV - [2014/10/29 03:14:41 | 000,423,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicshutdown)
SRV - [2014/10/29 03:14:41 | 000,423,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicrdv)
SRV - [2014/10/29 03:14:41 | 000,423,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmickvpexchange)
SRV - [2014/10/29 03:14:41 | 000,423,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicheartbeat)
SRV - [2014/10/29 03:14:41 | 000,423,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicguestinterface)
SRV - [2014/10/29 03:04:45 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\smphost.dll -- (smphost)
SRV - [2014/10/29 03:03:04 | 000,207,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV - [2014/10/29 03:02:21 | 000,103,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV - [2014/10/29 03:01:27 | 000,046,592 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\keyiso.dll -- (KeyIso)
SRV - [2014/10/29 02:59:46 | 000,177,664 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\TimeBrokerServer.dll -- (TimeBroker)
SRV - [2014/10/29 02:59:06 | 000,436,224 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netprofmsvc.dll -- (netprofm)
SRV - [2014/10/29 02:57:20 | 000,126,464 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\ncbservice.dll -- (NcbService)
SRV - [2014/10/29 02:55:58 | 000,305,152 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wcmsvc.dll -- (Wcmsvc)
SRV - [2014/10/29 02:55:34 | 000,209,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\vaultsvc.dll -- (VaultSvc)
SRV - [2014/10/29 02:55:15 | 000,312,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\das.dll -- (DeviceAssociationService)
SRV - [2014/10/29 02:54:57 | 000,206,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\bisrv.dll -- (BrokerInfrastructure)
SRV - [2014/10/29 02:54:38 | 001,245,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wlidsvc.dll -- (wlidsvc)
SRV - [2014/10/29 02:53:11 | 000,367,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2014/10/29 02:50:55 | 000,167,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\DeviceSetupManager.dll -- (DsmSvc)
SRV - [2014/10/29 02:47:09 | 001,845,248 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2014/10/29 02:45:46 | 000,064,512 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV - [2014/10/29 02:40:35 | 000,425,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AppReadiness.dll -- (AppReadiness)
SRV - [2014/10/29 02:38:57 | 001,175,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AppXDeploymentServer.dll -- (AppXSvc)
SRV - [2014/10/29 02:30:24 | 001,269,248 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\workfolderssvc.dll -- (workfolderssvc)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2015/04/16 08:22:42 | 000,259,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\USBXHCI.SYS -- (USBXHCI)
DRV - [2015/03/20 03:47:40 | 000,065,536 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\ahcache.sys -- (ahcache)
DRV - [2015/03/17 19:15:09 | 000,376,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\USBHUB3.SYS -- (USBHUB3)
DRV - [2015/03/09 03:18:05 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\bthhfenum.sys -- (BthHFEnum)
DRV - [2015/03/04 12:05:35 | 000,279,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\clfs.sys -- (CLFS)
DRV - [2015/02/04 01:51:14 | 000,227,136 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\System32\Drivers\WdFilter.sys -- (WdFilter)
DRV - [2015/02/04 01:51:14 | 000,084,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\WdNisDrv.sys -- (WdNisDrv)
DRV - [2015/02/04 01:51:08 | 000,038,392 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\WdBoot.sys -- (WdBoot)
DRV - [2014/10/29 05:12:35 | 000,069,440 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\wfplwfs.sys -- (WFPLWFS)
DRV - [2014/10/29 05:12:15 | 000,362,304 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\spaceport.sys -- (spaceport)
DRV - [2014/10/29 05:10:54 | 000,045,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\wpcfltr.sys -- (wpcfltr)
DRV - [2014/10/29 05:10:13 | 000,022,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2014/10/29 05:10:05 | 000,091,792 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\vmbus.sys -- (vmbus)
DRV - [2014/10/29 05:10:05 | 000,044,688 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\vmstorfl.sys -- (storflt)
DRV - [2014/10/29 04:01:33 | 000,026,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2014/10/29 04:01:08 | 000,071,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\netvsc63.sys -- (netvsc)
DRV - [2014/10/29 04:00:54 | 000,109,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV - [2014/10/29 04:00:52 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mslldp.sys -- (MsLldp)
DRV - [2014/10/29 04:00:32 | 000,090,112 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\Drivers\Ndu.sys -- (Ndu)
DRV - [2014/10/13 04:47:56 | 000,076,096 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\pdc.sys -- (pdc)
DRV - [2014/10/13 04:47:55 | 000,036,160 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\intelpep.sys -- (intelpep)
DRV - [2014/10/07 06:13:01 | 000,163,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\UCX01000.SYS -- (UCX01000)
DRV - [2014/08/15 01:35:51 | 000,122,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\msgpioclx.sys -- (GPIOClx0101)
DRV - [2014/03/18 09:59:50 | 000,120,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\SerCx2.sys -- (SerCx2)
DRV - [2014/03/18 09:59:37 | 000,142,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\VerifierExt.sys -- (VerifierExt)
DRV - [2014/03/18 09:59:37 | 000,064,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\sdstor.sys -- (sdstor)
DRV - [2014/03/18 09:59:36 | 000,047,960 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\stornvme.sys -- (stornvme)
DRV - [2014/03/18 09:59:36 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\BasicRender.sys -- (BasicRender)
DRV - [2014/03/18 09:38:12 | 000,019,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\kbldfltr.sys -- (kbldfltr)
DRV - [2014/03/18 09:37:57 | 000,030,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\terminpt.sys -- (terminpt)
DRV - [2014/03/13 12:12:46 | 000,138,584 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\wof.sys -- (Wof)
DRV - [2013/08/22 08:13:53 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\condrv.sys -- (condrv)
DRV - [2013/08/22 07:35:21 | 000,053,088 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\Drivers\dam.sys -- (dam)
DRV - [2013/08/22 07:35:20 | 000,061,280 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\acpiex.sys -- (acpiex)
DRV - [2013/08/22 07:34:52 | 000,133,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\tpm.sys -- (TPM)
DRV - [2013/08/22 07:33:32 | 000,058,208 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\mvumis.sys -- (mvumis)
DRV - [2013/08/22 07:33:31 | 000,033,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\msgpiowin32.sys -- (msgpiowin32)
DRV - [2013/08/22 07:33:30 | 000,068,960 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV - [2013/08/22 07:33:29 | 000,069,472 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\lsi_sss.sys -- (LSI_SSS)
DRV - [2013/08/22 07:33:26 | 000,086,368 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\3ware.sys -- (3ware)
DRV - [2013/08/22 07:33:25 | 000,773,472 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\adp80xx.sys -- (ADP80XX)
DRV - [2013/08/22 07:33:25 | 000,100,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV - [2013/08/22 07:33:24 | 000,073,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\EhStorClass.sys -- (EhStorClass)
DRV - [2013/08/22 07:33:01 | 000,276,832 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV - [2013/08/22 07:32:57 | 000,090,976 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\storahci.sys -- (storahci)
DRV - [2013/08/22 07:32:57 | 000,059,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\SpbCx.sys -- (SpbCx)
DRV - [2013/08/22 07:32:57 | 000,058,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\SerCx.sys -- (SerCx)
DRV - [2013/08/22 07:32:57 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\uaspstor.sys -- (UASPStor)
DRV - [2013/08/22 07:32:38 | 000,031,584 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\Drivers\cnghwassist.sys -- (cnghwassist)
DRV - [2013/08/22 07:24:56 | 000,023,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\uefi.sys -- (UEFI)
DRV - [2013/08/22 07:24:36 | 000,023,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV - [2013/08/22 07:20:22 | 000,042,304 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\storvsc.sys -- (storvsc)
DRV - [2013/08/22 06:11:56 | 000,013,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\pnpmem.sys -- (PNPMEM)
DRV - [2013/08/22 06:11:04 | 000,043,520 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\BasicDisplay.sys -- (BasicDisplay)
DRV - [2013/08/22 06:10:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\HyperVideo.sys -- (HyperVideo)
DRV - [2013/08/22 06:10:37 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mshidumdf.sys -- (mshidumdf)
DRV - [2013/08/22 06:10:28 | 000,008,704 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\acpitime.sys -- (acpitime)
DRV - [2013/08/22 06:10:21 | 000,009,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\acpipagr.sys -- (acpipagr)
DRV - [2013/08/22 06:10:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\npsvctrig.sys -- (npsvctrig)
DRV - [2013/08/22 06:10:01 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV - [2013/08/22 06:09:59 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\kdnic.sys -- (kdnic)
DRV - [2013/08/22 06:09:57 | 000,006,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\vms3cap.sys -- (s3cap)
DRV - [2013/08/22 06:09:50 | 000,011,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\vmgencounter.sys -- (gencounter)
DRV - [2013/08/22 06:09:37 | 000,023,808 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BthhfHid.sys -- (bthhfhid)
DRV - [2013/08/22 06:09:23 | 000,064,000 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\winusb.sys -- (WinUsb)
DRV - [2013/08/22 06:09:09 | 000,012,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\hyperkbd.sys -- (hyperkbd)
DRV - [2013/08/22 06:09:03 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2013/08/22 06:09:01 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\hidi2c.sys -- (hidi2c)
DRV - [2013/08/22 06:09:01 | 000,018,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2013/08/22 06:08:37 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\dmvsc.sys -- (dmvsc)
DRV - [2013/08/22 06:08:06 | 000,013,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV - [2013/08/22 03:58:35 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\fxppm.sys -- (FxPPM)
DRV - [2013/08/13 01:25:32 | 000,016,088 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\bcmfn2.sys -- (bcmfn2)
DRV - [2013/08/10 02:39:44 | 000,524,784 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\iaStorAV.sys -- (iaStorAV)
DRV - [2013/07/23 23:18:30 | 000,061,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\iaioi2c.sys -- (iaioi2c)
DRV - [2013/07/23 23:18:30 | 000,022,016 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\iaiogpio.sys -- (GPIO)
DRV - [2013/06/18 14:21:30 | 000,379,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\e1i6332.sys -- (e1iexpress)
DRV - [2008/07/29 04:45:00 | 000,904,192 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\athrusb.sys -- (athrusb)
DRV - [2007/05/16 18:43:14 | 000,871,936 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\athru6.sys -- (athrusb6)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1432409643&z=12766bf7907bf5acab1a764g0z2cco7z6eft8q2z2e&from=wpc&uid=WDCXWD2500AAJS-60M0A0_WD-WMAV2J90604406044
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1432409643&z=12766bf7907bf5acab1a764g0z2cco7z6eft8q2z2e&from=wpc&uid=WDCXWD2500AAJS-60M0A0_WD-WMAV2J90604406044&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1432409643&z=12766bf7907bf5acab1a764g0z2cco7z6eft8q2z2e&from=wpc&uid=WDCXWD2500AAJS-60M0A0_WD-WMAV2J90604406044&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSE1
IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1432409643&z=12766bf7907bf5acab1a764g0z2cco7z6eft8q2z2e&from=wpc&uid=WDCXWD2500AAJS-60M0A0_WD-WMAV2J90604406044
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSE1
IE - HKCU\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKCU\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[color=#E56717]========== FireFox ==========[/color]

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.45.2: C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.45.2: C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)


[2015/03/31 10:23:10 | 000,034,072 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll

[color=#E56717]========== Chrome ==========[/color]

CHR - Extension: No name found = C:\Users\bbouje\AppData\Local\Google\Chrome\User Data\Default\Extensions\aolcffalbhpnojekmimmelebjchjmmgn\142\
CHR - Extension: No name found = C:\Users\bbouje\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_1\
CHR - Extension: No name found = C:\Users\bbouje\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_1\
CHR - Extension: No name found = C:\Users\bbouje\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiigcfcddhjmneikmajnkkljnmgbdomp\242\
CHR - Extension: No name found = C:\Users\bbouje\AppData\Local\Google\Chrome\User Data\Default\Extensions\lajondecmobodlejlcjllhojikagldgd\161\
CHR - Extension: No name found = C:\Users\bbouje\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\0.3.0.5_0\
CHR - Extension: No name found = C:\Users\bbouje\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\
CHR - Extension: No name found = C:\Users\bbouje\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_1\

O1 HOSTS File: ([2013/08/22 08:13:55 | 000,000,824 | ---- | M]) - C:\Windows\System32\Drivers\etc\hosts
O2 - BHO: (Skype for Business Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (GReatSave4U) - {A652EB23-4CF2-4B27-BEBF-AC7C08577A83} - C:\Program Files\GReatSave4U\9ySXpnLPWJbldn.dll File not found
O2 - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (GReatiSaVe44U) - {D2140B44-FB69-485C-9645-00F04CBCB843} - C:\Program Files\GReatiSaVe44U\Ru5qbqhiAPBEsA.dll File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKCU..\Run: [GoogleChromeAutoLaunch_6B458DB915D74EEF136186E00F0FB12C] C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Envoyer à OneNote - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xporter vers Microsoft Excel - C:\Program Files\Microsoft Office\Office15\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Cliquer pour appeler Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Cliquer pour appeler Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7A8D7516-503F-4D06-87D5-57A7CFCABBE7}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O27 - HKLM IFEO\SppExtComObj.exe: Debugger - C:\Windows\System32\SppExtComObjPatcher.exe ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/08/22 10:16:34 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2015/07/01 00:17:58 | 000,000,000 | ---D | C] -- C:\Users\bbouje\AppData\Local\Diagnostics
[2015/06/27 13:20:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2015/06/27 13:20:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2015/06/27 13:20:11 | 000,096,352 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2015/06/27 13:19:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2015/06/27 13:19:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2015/06/27 13:19:13 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2015/06/23 19:55:02 | 000,000,000 | ---D | C] -- C:\Users\bbouje\Desktop\oeuvre litteraire
[2015/06/13 12:17:02 | 003,532,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2015/06/13 12:06:27 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rgb9rast.dll
[2015/06/13 12:01:23 | 002,749,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll
[2015/06/13 12:01:23 | 001,920,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
[2015/06/13 12:01:23 | 000,699,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
[2015/06/13 12:01:23 | 000,391,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
[2015/06/13 12:01:20 | 000,259,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\USBXHCI.SYS
[2015/06/13 12:01:08 | 000,901,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aeinv.dll
[2015/06/13 12:01:08 | 000,878,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\appraiser.dll
[2015/06/13 12:01:08 | 000,621,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\invagent.dll
[2015/06/13 12:01:08 | 000,571,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\generaltel.dll
[2015/06/13 12:01:08 | 000,333,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\devinv.dll
[2015/06/13 12:01:08 | 000,202,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aepdu.dll
[2015/06/13 12:01:08 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aepic.dll
[2015/06/13 12:01:08 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\acmigration.dll
[2015/06/13 11:59:30 | 002,483,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msftedit.dll
[2015/06/13 11:59:22 | 004,305,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2015/06/13 11:59:21 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9diag.dll
[2015/06/13 11:59:20 | 000,689,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2015/06/13 11:59:20 | 000,341,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2015/06/13 11:59:19 | 002,052,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2015/06/13 11:59:19 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2015/06/13 11:59:19 | 000,327,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2015/06/13 11:59:19 | 000,285,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2015/06/13 11:59:19 | 000,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2015/06/13 11:59:02 | 000,977,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\diagtrack.dll
[2015/06/13 11:59:02 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UtcResources.dll
[2015/06/13 11:56:22 | 001,018,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIAutomationCore.dll
[2015/06/13 11:39:04 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\puiobj.dll
[2015/06/12 14:12:36 | 000,000,000 | ---D | C] -- C:\ProgramData\IsolatedStorage
[2015/06/12 14:12:35 | 000,000,000 | ---D | C] -- C:\Users\bbouje\AppData\Roaming\IsolatedStorage
[2015/06/12 14:12:13 | 000,000,000 | ---D | C] -- C:\Users\bbouje\AppData\Roaming\DigitalVolcano
[2015/06/12 10:03:45 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2015/06/10 00:44:16 | 000,000,000 | ---D | C] -- C:\Users\bbouje\AppData\Local\VirtualStore
[2015/06/06 20:07:38 | 000,000,000 | ---D | C] -- C:\Program Files\ExsTraSSavinngs
[2015/06/06 20:07:36 | 000,000,000 | ---D | C] -- C:\Program Files\ExastraSavinGso
[2015/06/06 20:07:34 | 000,000,000 | ---D | C] -- C:\Program Files\ExstoraSavings
[2015/06/06 20:06:57 | 000,000,000 | ---D | C] -- C:\ProgramData\jalpfcnfkdahgaokfejdbhgjphliloje
[2015/06/06 20:06:50 | 000,000,000 | ---D | C] -- C:\Program Files\RootsSearch
[2015/06/06 20:05:24 | 000,000,000 | ---D | C] -- C:\Program Files\ExestraSeaviNgS
[2015/06/06 20:05:09 | 000,000,000 | ---D | C] -- C:\Program Files\ExstraSavvings
[2015/06/04 18:13:55 | 000,000,000 | ---D | C] -- C:\Users\bbouje\AppData\Local\GWX
[2015/06/02 21:19:38 | 000,000,000 | ---D | C] -- C:\Program Files\Reddit Liquid Streams
[2015/06/02 21:18:35 | 000,000,000 | ---D | C] -- C:\Program Files\GRReattSave4U
[2015/06/02 20:58:17 | 000,000,000 | ---D | C] -- C:\Program Files\TampaFunc

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2015/07/01 23:17:01 | 000,001,082 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/07/01 22:59:03 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015/07/01 21:30:48 | 000,001,078 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/07/01 21:30:12 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2015/07/01 21:30:09 | 813,056,000 | -HS- | M] () -- C:\hiberfil.sys
[2015/07/01 21:30:09 | 108,652,298 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2015/07/01 19:58:51 | 000,000,024 | ---- | M] () -- C:\Users\bbouje\AppData\Roaming\appdataFr25.bin
[2015/06/29 23:46:10 | 000,006,485 | ---- | M] () -- C:\Users\bbouje\Desktop\Etat Seval Formateur 2015-06-28.pdf
[2015/06/29 23:46:10 | 000,004,875 | ---- | M] () -- C:\Users\bbouje\Desktop\Etat Seval Groupe 2015-06-28.pdf
[2015/06/29 21:30:01 | 000,000,518 | ---- | M] () -- C:\Windows\tasks\Bidaily Synchronize Task[pr].job
[2015/06/29 21:04:58 | 000,801,196 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2015/06/29 21:04:58 | 000,722,278 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2015/06/29 21:04:58 | 000,158,648 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2015/06/29 21:04:58 | 000,135,394 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2015/06/27 13:19:35 | 000,096,352 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2015/06/27 01:12:55 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_LocationProvider_01_11_00.Wdf
[2015/06/23 17:59:26 | 000,002,207 | ---- | M] () -- C:\Users\bbouje\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2015/06/23 14:20:27 | 000,002,413 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2015/06/20 05:02:45 | 000,792,568 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2015/06/20 05:02:45 | 000,178,168 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2015/06/13 16:06:31 | 000,473,008 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2015/06/29 23:46:41 | 000,006,485 | ---- | C] () -- C:\Users\bbouje\Desktop\Etat Seval Formateur 2015-06-28.pdf
[2015/06/29 23:46:41 | 000,004,875 | ---- | C] () -- C:\Users\bbouje\Desktop\Etat Seval Groupe 2015-06-28.pdf
[2015/06/27 01:12:55 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_LocationProvider_01_11_00.Wdf
[2015/06/13 11:56:19 | 000,410,336 | ---- | C] () -- C:\Windows\System32\ApnDatabase.xml
[2015/06/12 10:03:37 | 108,652,298 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2015/06/07 12:40:43 | 000,000,024 | ---- | C] () -- C:\Users\bbouje\AppData\Roaming\appdataFr25.bin
[2015/05/23 21:37:26 | 000,000,000 | ---- | C] () -- C:\Users\bbouje\AppData\Local\Temp.dat
[2015/05/17 12:21:07 | 000,000,496 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2015/05/07 23:07:25 | 000,107,008 | ---- | C] () -- C:\Windows\System32\OEMLicense.dll
[2015/05/07 23:07:00 | 000,075,264 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2015/05/07 23:06:39 | 000,046,080 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2015/05/06 12:12:07 | 000,365,568 | ---- | C] () -- C:\Windows\System32\ZSHP1020.EXE
[2015/05/06 12:12:07 | 000,169,472 | ---- | C] () -- C:\Windows\System32\ZLhp1020.DLL
[2015/05/06 11:44:14 | 000,000,877 | ---- | C] () -- C:\Users\bbouje\Documents.lnk
[2015/05/06 11:38:58 | 000,012,288 | ---- | C] () -- C:\Windows\System32\SppExtComObjHook.dll
[2015/05/06 11:38:58 | 000,004,096 | ---- | C] () -- C:\Windows\System32\SppExtComObjPatcher.exe
[2015/05/06 11:35:46 | 000,473,008 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/06/22 15:27:58 | 000,050,745 | ---- | C] () -- C:\Windows\System32\srms.dat
[2014/03/18 10:00:23 | 000,262,335 | ---- | C] () -- C:\Windows\System32\dfpinc.dat
[2014/03/18 09:59:50 | 000,002,255 | ---- | C] () -- C:\Windows\System32\WimBootCompress.ini
[2014/03/18 09:25:51 | 000,801,196 | ---- | C] () -- C:\Windows\System32\perfh00C.dat
[2014/03/18 09:25:51 | 000,350,772 | ---- | C] () -- C:\Windows\System32\perfi00C.dat
[2014/03/18 09:25:51 | 000,158,648 | ---- | C] () -- C:\Windows\System32\perfc00C.dat
[2014/03/18 09:25:51 | 000,040,528 | ---- | C] () -- C:\Windows\System32\perfd00C.dat
[2013/08/22 10:19:09 | 000,722,278 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2013/08/22 10:19:09 | 000,296,742 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2013/08/22 10:19:09 | 000,135,394 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2013/08/22 10:19:09 | 000,033,362 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2013/08/22 10:17:31 | 000,000,389 | ---- | C] () -- C:\Windows\System32\AutoWorkplace.exe.config
[2013/08/22 10:17:30 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2013/08/22 10:17:29 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2013/08/22 09:24:03 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2013/08/22 01:57:03 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2013/08/22 01:52:39 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2013/08/22 01:52:35 | 001,520,828 | ---- | C] () -- C:\Windows\System32\WpcNBModel.bin
[2013/08/22 01:52:35 | 000,526,068 | ---- | C] () -- C:\Windows\System32\staticurllist.bin
[2013/08/22 01:50:57 | 000,008,192 | ---- | C] () -- C:\Windows\System32\settings.dat

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2015/05/23 21:34:49 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015/02/12 19:34:06 | 019,731,824 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2014/10/29 02:59:23 | 000,786,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2014/10/29 02:57:29 | 000,407,552 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >

Publicité


Signaler le contenu de ce document

Publicité