cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

ÿþOTL logfile created on: 09/11/2015 13:30:52 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\angel\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18053)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

5,89 Gb Total Physical Memory | 4,42 Gb Available Physical Memory | 74,93% Memory free
11,89 Gb Paging File | 9,90 Gb Available in Paging File | 83,27% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 673,30 Gb Total Space | 279,55 Gb Free Space | 41,52% Space Free | Partition Type: NTFS

Computer Name: MANON | User Name: angel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - C:\Users\angel\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\angel\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe (BitTorrent Inc.)
PRC - C:\Users\angel\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
PRC - C:\Program Files (x86)\Norton Internet Security\Engine\22.5.4.24\nis.exe (Symantec Corporation)
PRC - C:\Users\angel\AppData\Local\FluxSoftware\Flux\flux.exe (Flux Software LLC)
PRC - C:\Program Files (x86)\Samsung\SW Update\SWMAgent.exe (Samsung Electronics CO., LTD.)
PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
PRC - C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe (Samsung Electronics CO., LTD.)
PRC - C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe ()
PRC - C:\Program Files (x86)\Samsung\Settings\sSettings.exe (Samsung Electronics CO., LTD.)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe ()
PRC - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe (Intel Corporation)


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - C:\Program Files (x86)\Samsung\Settings\EasySettingsBase.dll ()
MOD - C:\Program Files (x86)\Samsung\Settings\CmdServer\WinCRT.dll ()
MOD - C:\Program Files (x86)\Samsung\Settings\EasyMovieEnhancer.dll ()
MOD - C:\Program Files (x86)\Samsung\Settings\EasySettingsCmdClient.dll ()
MOD - C:\Program Files (x86)\Samsung\Settings\EasySettingsAPI.dll ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\plugin\PServerPlugin.dll ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\featureController.dll ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\DeviceProfile.dll ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\eventsSender.dll ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\log4cplus.dll ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\libgsoap.dll ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\sqlite3.dll ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtGui4.dll ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtXml4.dll ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtCore4.dll ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\zlib1.dll ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtWebKit4.dll ()
MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\phonon4.dll ()


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe (McAfee, Inc.)
SRV:[b]64bit:[/b] - (DiagTrack) -- C:\Windows\SysNative\diagtrack.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (NcdAutoSetup) -- C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (WdNisSvc) -- C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Corporation)
SRV:[b]64bit:[/b] - (WinDefend) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV:[b]64bit:[/b] - (SynTPEnhService) -- C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe (Synaptics Incorporated)
SRV:[b]64bit:[/b] - (AudioEndpointBuilder) -- C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (SystemEventsBroker) -- C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (lfsvc) -- C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (LSM) -- C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (IEEtwCollectorService) -- C:\WINDOWS\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:[b]64bit:[/b] - (WSService) -- C:\Windows\SysNative\WSService.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (PrintNotify) -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (WEPHOSTSVC) -- C:\Windows\SysNative\wephostsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (EFS) -- C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (WiaRpc) -- C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (svsvc) -- C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (fhsvc) -- C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (BthHFSrv) -- C:\Windows\SysNative\BthHFSrv.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (NcaSvc) -- C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (vmicvss) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (vmictimesync) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (vmicshutdown) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (vmicrdv) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (vmickvpexchange) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (vmicheartbeat) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (vmicguestinterface) -- C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (smphost) -- C:\Windows\SysNative\smphost.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (Netlogon) -- C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (ScDeviceEnum) -- C:\Windows\SysNative\ScDeviceEnum.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (KeyIso) -- C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (TimeBroker) -- C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (netprofm) -- C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (NcbService) -- C:\Windows\SysNative\ncbservice.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (Wcmsvc) -- C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (VaultSvc) -- C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (DeviceAssociationService) -- C:\Windows\SysNative\das.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (BrokerInfrastructure) -- C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (wlidsvc) -- C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (DsmSvc) -- C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (AppReadiness) -- C:\Windows\SysNative\AppReadiness.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (AppXSvc) -- C:\Windows\SysNative\AppXDeploymentServer.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (workfolderssvc) -- C:\Windows\SysNative\workfolderssvc.dll (Microsoft Corporation)
SRV:[b]64bit:[/b] - (igfxCUIService1.0.0.0) -- C:\Windows\SysNative\igfxCUIService.exe (Intel Corporation)
SRV:[b]64bit:[/b] - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:[b]64bit:[/b] - (Intel(R) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel(R) Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes)
SRV - (NIS) -- C:\Program Files (x86)\Norton Internet Security\Engine\22.5.4.24\NIS.exe (Symantec Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (lfsvc) -- C:\Windows\SysWOW64\GeofenceMonitorService.dll (Microsoft Corporation)
SRV - (PrintNotify) -- C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV - (StorSvc) -- C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation)
SRV - (smphost) -- C:\Windows\SysWOW64\smphost.dll (Microsoft Corporation)
SRV - (cphs) -- C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (AtherosSvc) -- C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Qualcomm Atheros Commnucations)
SRV - (ZAtheros Bt and Wlan Coex Agent) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
SRV - (Easy Launcher) -- C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe (Samsung Electronics CO., LTD.)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
SRV - (NOBU) -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - (MBAMWebAccessControl) -- C:\Windows\SysNative\drivers\mwac.sys (Malwarebytes Corporation)
DRV:[b]64bit:[/b] - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes)
DRV:[b]64bit:[/b] - (SymNetS) -- C:\Windows\SysNative\drivers\NISx64\1605040.018\symnets.sys (Symantec Corporation)
DRV:[b]64bit:[/b] - (SRTSP) -- C:\Windows\SysNative\drivers\NISx64\1605040.018\srtsp64.sys (Symantec Corporation)
DRV:[b]64bit:[/b] - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:[b]64bit:[/b] - (SymELAM) -- C:\Windows\SysNative\drivers\NISx64\1605040.018\symelam.sys (Symantec Corporation)
DRV:[b]64bit:[/b] - (SymIRON) -- C:\Windows\SysNative\drivers\NISx64\1605040.018\ironx64.sys (Symantec Corporation)
DRV:[b]64bit:[/b] - (SymEFASI) -- C:\Windows\SysNative\drivers\NISx64\1605040.018\symefasi64.sys (Symantec Corporation)
DRV:[b]64bit:[/b] - (SRTSPX) -- C:\Windows\SysNative\drivers\NISx64\1605040.018\srtspx64.sys (Symantec Corporation)
DRV:[b]64bit:[/b] - (ccSet_NIS) -- C:\Windows\SysNative\drivers\NISx64\1605040.018\ccsetx64.sys (Symantec Corporation)
DRV:[b]64bit:[/b] - (WdBoot) -- C:\Windows\SysNative\drivers\WdBoot.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (WdFilter) -- C:\Windows\SysNative\drivers\WdFilter.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (WdNisDrv) -- C:\Windows\SysNative\drivers\WdNisDrv.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:[b]64bit:[/b] - (IDMWFP) -- C:\Windows\SysNative\drivers\idmwfp.sys (Tonec Inc.)
DRV:[b]64bit:[/b] - (USBXHCI) -- C:\Windows\SysNative\drivers\USBXHCI.SYS (Microsoft Corporation)
DRV:[b]64bit:[/b] - (ahcache) -- C:\Windows\SysNative\drivers\ahcache.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (USBHUB3) -- C:\Windows\SysNative\drivers\USBHUB3.SYS (Microsoft Corporation)
DRV:[b]64bit:[/b] - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (BthHFEnum) -- C:\Windows\SysNative\drivers\bthhfenum.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (CLFS) -- C:\Windows\SysNative\drivers\clfs.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (spaceport) -- C:\Windows\SysNative\drivers\spaceport.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (WFPLWFS) -- C:\Windows\SysNative\drivers\wfplwfs.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (wpcfltr) -- C:\Windows\SysNative\drivers\wpcfltr.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (netvsc) -- C:\Windows\SysNative\drivers\netvsc63.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (NdisImPlatform) -- C:\Windows\SysNative\drivers\NdisImPlatform.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (MsLldp) -- C:\Windows\SysNative\drivers\mslldp.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (Ndu) -- C:\Windows\SysNative\drivers\Ndu.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (ReFS) -- C:\WINDOWS\SysNative\drivers\refs.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (pdc) -- C:\Windows\SysNative\drivers\pdc.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (intelpep) -- C:\Windows\SysNative\drivers\intelpep.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (UCX01000) -- C:\Windows\SysNative\drivers\UCX01000.SYS (Microsoft Corporation)
DRV:[b]64bit:[/b] - (vpci) -- C:\Windows\SysNative\drivers\vpci.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (Wof) -- C:\WINDOWS\SysNative\drivers\wof.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (SerCx2) -- C:\Windows\SysNative\drivers\SerCx2.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (VerifierExt) -- C:\Windows\SysNative\drivers\VerifierExt.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (BthLEEnum) -- C:\Windows\SysNative\drivers\BthLEEnum.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (sdstor) -- C:\Windows\SysNative\drivers\sdstor.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (stornvme) -- C:\Windows\SysNative\drivers\stornvme.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (BasicRender) -- C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (GPIOClx0101) -- C:\Windows\SysNative\drivers\msgpioclx.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (intaud_WaveExtensible) -- C:\Windows\SysNative\drivers\intelaud.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (iwdbus) -- C:\Windows\SysNative\drivers\iwdbus.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:[b]64bit:[/b] - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:[b]64bit:[/b] - (amdkmpfd) -- C:\Windows\SysNative\drivers\amdkmpfd.sys (Advanced Micro Devices, Inc.)
DRV:[b]64bit:[/b] - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Qualcomm Atheros)
DRV:[b]64bit:[/b] - (ssudmdm) -- C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:[b]64bit:[/b] - (dg_ssudbus) -- C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:[b]64bit:[/b] - (condrv) -- C:\Windows\SysNative\drivers\condrv.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (Fs_Rec) -- C:\WINDOWS\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (dam) -- C:\Windows\SysNative\drivers\dam.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (acpiex) -- C:\Windows\SysNative\drivers\acpiex.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (TPM) -- C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (mvumis) -- C:\Windows\SysNative\drivers\mvumis.sys (Marvell Semiconductor, Inc.)
DRV:[b]64bit:[/b] - (msgpiowin32) -- C:\Windows\SysNative\drivers\msgpiowin32.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:[b]64bit:[/b] - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:[b]64bit:[/b] - (LSI_SSS) -- C:\Windows\SysNative\drivers\lsi_sss.sys (LSI Corporation)
DRV:[b]64bit:[/b] - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:[b]64bit:[/b] - (LSI_SAS3) -- C:\Windows\SysNative\drivers\lsi_sas3.sys (LSI Corporation)
DRV:[b]64bit:[/b] - (ADP80XX) -- C:\Windows\SysNative\drivers\adp80xx.sys (PMC-Sierra)
DRV:[b]64bit:[/b] - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:[b]64bit:[/b] - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:[b]64bit:[/b] - (3ware) -- C:\Windows\SysNative\drivers\3ware.sys (LSI)
DRV:[b]64bit:[/b] - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:[b]64bit:[/b] - (EhStorTcgDrv) -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (EhStorClass) -- C:\Windows\SysNative\drivers\EhStorClass.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:[b]64bit:[/b] - (VSTXRAID) -- C:\Windows\SysNative\drivers\VSTXRAID.SYS (VIA Corporation)
DRV:[b]64bit:[/b] - (UASPStor) -- C:\Windows\SysNative\drivers\uaspstor.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology, Inc.)
DRV:[b]64bit:[/b] - (storahci) -- C:\Windows\SysNative\drivers\storahci.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (SpbCx) -- C:\Windows\SysNative\drivers\SpbCx.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (SerCx) -- C:\Windows\SysNative\drivers\SerCx.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (UEFI) -- C:\Windows\SysNative\drivers\uefi.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (WpdUpFltr) -- C:\Windows\SysNative\drivers\WpdUpFltr.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (BasicDisplay) -- C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (HyperVideo) -- C:\Windows\SysNative\drivers\HyperVideo.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (mshidumdf) -- C:\Windows\SysNative\drivers\mshidumdf.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (acpitime) -- C:\Windows\SysNative\drivers\acpitime.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (acpipagr) -- C:\Windows\SysNative\drivers\acpipagr.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (BthAvrcpTg) -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (kdnic) -- C:\Windows\SysNative\drivers\kdnic.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (gencounter) -- C:\Windows\SysNative\drivers\vmgencounter.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (npsvctrig) -- C:\Windows\SysNative\drivers\npsvctrig.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (bthhfhid) -- C:\Windows\SysNative\drivers\BthhfHid.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (hyperkbd) -- C:\Windows\SysNative\drivers\hyperkbd.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (hidi2c) -- C:\Windows\SysNative\drivers\hidi2c.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (NdisVirtualBus) -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (FxPPM) -- C:\Windows\SysNative\drivers\fxppm.sys (Microsoft Corporation)
DRV:[b]64bit:[/b] - (bcmfn2) -- C:\Windows\SysNative\drivers\bcmfn2.sys (Windows (R) Win 7 DDK provider)
DRV:[b]64bit:[/b] - (iaStorAV) -- C:\Windows\SysNative\drivers\iaStorAV.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (RtlWlanu) -- C:\Windows\SysNative\drivers\RTWlanU.sys (Realtek Semiconductor Corporation )
DRV:[b]64bit:[/b] - (iaLPSSi_GPIO) -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (iaLPSSi_I2C) -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (RTL8168) -- C:\Windows\SysNative\drivers\Rt630x64.sys (Realtek )
DRV:[b]64bit:[/b] - (athr) -- C:\Windows\SysNative\drivers\athw8x.sys (Qualcomm Atheros Communications, Inc.)
DRV:[b]64bit:[/b] - (RadioHIDMini) -- C:\Windows\SysNative\drivers\RadioHIDMini.sys (Windows (R) Win 7 DDK provider)
DRV:[b]64bit:[/b] - (iaStorA) -- C:\Windows\SysNative\drivers\iaStorA.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:[b]64bit:[/b] - (CLVirtualDrive) -- C:\Windows\SysNative\drivers\CLVirtualDrive.sys (CyberLink)
DRV:[b]64bit:[/b] - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV:[b]64bit:[/b] - (RSUSBVSTOR) -- C:\Windows\SysNative\drivers\RtsUVStor.sys (Realtek Semiconductor Corp.)
DRV:[b]64bit:[/b] - (ccSet_NARA) -- C:\Windows\SysNative\drivers\NARAx64\0401000.00B\ccSetx64.sys (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64) -- C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\IPSDefs\20150710.001\IDSviA64.sys (Symantec Corporation)
DRV - (BHDrvx64) -- C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\BASHDefs\20150706.001\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) -- C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\VirusDefs\20150816.021\ex64.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.2.15\Definitions\VirusDefs\20150816.021\eng64.sys (Symantec Corporation)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {4C6B4EEC-05FF-4DA8-9174-CB11AA2F4B6C}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{4C6B4EEC-05FF-4DA8-9174-CB11AA2F4B6C}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {4C6B4EEC-05FF-4DA8-9174-CB11AA2F4B6C}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{4C6B4EEC-05FF-4DA8-9174-CB11AA2F4B6C}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://samsung13.msn.com
IE - HKCU\..\SearchScopes,DefaultScope = {4C6B4EEC-05FF-4DA8-9174-CB11AA2F4B6C}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKCU\..\SearchScopes\{4C6B4EEC-05FF-4DA8-9174-CB11AA2F4B6C}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.countryCode: "RE"
FF - prefs.js..browser.search.region: "RE"
FF - prefs.js..browser.search.searchengine.alias: "sweet-page"
FF - prefs.js..browser.search.searchengine.desc: "this is my first firefox searchEngine"
FF - prefs.js..browser.search.searchengine.iconURL: "http://www.sweet-page.com/favicon.ico"
FF - prefs.js..browser.search.searchengine.name: "sweet-page"
FF - prefs.js..browser.search.searchengine.ptid: "cor"
FF - prefs.js..browser.search.searchengine.uid: "HitachiXHTS547575A9E384_J2140020DT48GBDT48GBX"
FF - prefs.js..browser.search.searchengine.url: "http://www.sweet-page.com/web/?type=ds&ts=1443638472&z=af214d4e54ef575179b6d80gcz0z8cfqac5b6z7mfm&from=cor&uid=HitachiXHTS547575A9E384_J2140020DT48GBDT48GBX&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "sweet-page"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: %7B5384767E-00D9-40E9-B72F-9CC39D655D6F%7D:1.5.0.6.1-signed
FF - prefs.js..extensions.enabledAddons: %7B0b457cAA-602d-484a-8fe7-c1d894a011ba%7D:0.98.77
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:40.0
FF - user.js - File not found

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll ( Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.7: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3503.0728: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\angel\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{EBA722F5-038F-4CAF-9EE2-545A221628BC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.5.2.15\coFFPlgn\ [2015/11/08 20:36:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 40.0\extensions\\Components: c:\program files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 40.0\extensions\\Plugins: c:\program files (x86)\Mozilla Firefox\plugins

[2013/02/10 08:10:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\angel\AppData\Roaming\mozilla\Extensions
[2015/09/30 22:41:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\angel\AppData\Roaming\mozilla\Firefox\Profiles\c5r1ey2z.default\extensions
[2015/11/08 07:13:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\angel\AppData\Roaming\mozilla\Firefox\Profiles\xni9iy4s.default-1440417583496\extensions
[2015/11/08 07:13:09 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\angel\AppData\Roaming\mozilla\Firefox\Profiles\xni9iy4s.default-1440417583496\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2015/09/13 18:28:29 | 000,000,000 | ---D | M] (EPUBReader) -- C:\Users\angel\AppData\Roaming\mozilla\Firefox\Profiles\xni9iy4s.default-1440417583496\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2015/09/30 05:57:25 | 000,007,996 | ---- | M] () (No name found) -- C:\Users\angel\AppData\Roaming\mozilla\firefox\profiles\c5r1ey2z.default\extensions\{5eeaf6e5-69d2-4e0c-a3d0-00e220276550}.xpi
[2015/09/24 17:12:12 | 000,962,762 | ---- | M] () (No name found) -- C:\Users\angel\AppData\Roaming\mozilla\firefox\profiles\xni9iy4s.default-1440417583496\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2015/07/08 14:44:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2015/08/13 23:27:40 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[color=#E56717]========== Chrome ==========[/color]

CHR - Extension: No name found = C:\Users\angel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\angel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\angel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\angel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe\2015.5.4.11_0\
CHR - Extension: No name found = C:\Users\angel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\
CHR - Extension: No name found = C:\Users\angel\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif\1.0.5_0\
CHR - Extension: No name found = C:\Users\angel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\0.3.0.5_0\
CHR - Extension: No name found = C:\Users\angel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbpblocgmgfnpjjppndjkmgjaogfceg\0.98.80_0\
CHR - Extension: No name found = C:\Users\angel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.4.0.10_1\
CHR - Extension: No name found = C:\Users\angel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.2.0_0\
CHR - Extension: No name found = C:\Users\angel\AppData\Local\Google\Chrome\User Data\Default\Extensions\omnboajokiaedbefjfeeenchihbjdbdn\1.2.1.4_0\
CHR - Extension: No name found = C:\Users\angel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\

O1 HOSTS File: ([2015/09/13 08:27:15 | 000,001,144 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 108.162.204.254 www.t411.io
O1 - Hosts: 108.162.204.254 t411.io
O1 - Hosts: 108.162.204.254 forum.t411.io
O1 - Hosts: 108.162.204.254 www.forum.t411.io
O1 - Hosts: 46.246.117.194 http://tracker.t411.io
O1 - Hosts: 46.246.117.194 tracker.t411.io
O1 - Hosts: 108.162.203.254 wiki.t411.io
O1 - Hosts: 108.162.204.254 api.t411.io
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2:[b]64bit:[/b] - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\22.5.4.24\coieplg.dll (Symantec Corporation)
O2:[b]64bit:[/b] - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\22.5.4.24\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (no name) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - No CLSID value found.
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\22.5.4.24\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\22.5.4.24\coIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (TextAloud) - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\Program Files (x86)\TextAloud\TAForIE.dll ()
O4:[b]64bit:[/b] - HKLM..\Run: [BtTray] C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (Qualcomm Atheros)
O4:[b]64bit:[/b] - HKLM..\Run: [BtvStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Qualcomm Atheros Commnucations)
O4:[b]64bit:[/b] - HKLM..\Run: [Greenshot] C:\Program Files\Greenshot\Greenshot.exe (Greenshot)
O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\WINDOWS\SysNative\igfxtray.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [CLMLServer_For_P2G8] C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink)
O4 - HKLM..\Run: [CLVirtualDrive] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe (CyberLink Corp.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4 - HKLM..\Run: [Intel AppUp(SM) center] C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe (Intel Corporation)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Dropbox Update] C:\Users\angel\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.)
O4 - HKCU..\Run: [f.lux] C:\Users\angel\AppData\Local\FluxSoftware\Flux\flux.exe (Flux Software LLC)
O4 - Startup: C:\Users\angel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\angel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{35EEA3A6-000C-407E-809A-F055A4817543}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{83FF6AEB-B3D1-430F-B3D2-D431FDBC3517}: DhcpNameServer = 192.168.1.1
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:[b]64bit:[/b] lfsvc - C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
NetSvcs:[b]64bit:[/b] wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
NetSvcs:[b]64bit:[/b] DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs:[b]64bit:[/b] NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)

MsConfig:64bit - State: "services" - Reg Error: Key error.
MsConfig:64bit - State: "startup" - Reg Error: Key error.

SafeBootMin:[b]64bit:[/b] AppMgmt - Service
SafeBootMin:[b]64bit:[/b] Base - Driver Group
SafeBootMin:[b]64bit:[/b] BasicDisplay.sys - C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] BasicRender.sys - C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] Boot Bus Extender - Driver Group
SafeBootMin:[b]64bit:[/b] Boot file system - Driver Group
SafeBootMin:[b]64bit:[/b] BrokerInfrastructure - C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] EFS - C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] File system - Driver Group
SafeBootMin:[b]64bit:[/b] Filter - Driver Group
SafeBootMin:[b]64bit:[/b] HelpSvc - Service
SafeBootMin:[b]64bit:[/b] KeyIso - C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] LSM - C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] Netlogon - C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] PCI Configuration - Driver Group
SafeBootMin:[b]64bit:[/b] PNP Filter - Driver Group
SafeBootMin:[b]64bit:[/b] Primary disk - Driver Group
SafeBootMin:[b]64bit:[/b] sacsvr - Service
SafeBootMin:[b]64bit:[/b] SCSI Class - Driver Group
SafeBootMin:[b]64bit:[/b] System Bus Extender - Driver Group
SafeBootMin:[b]64bit:[/b] SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] TBS - Service
SafeBootMin:[b]64bit:[/b] vmms - Service
SafeBootMin:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:[b]64bit:[/b] {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootMin:[b]64bit:[/b] {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootMin:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: TBS - Service
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootMin: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet:[b]64bit:[/b] AppMgmt - Service
SafeBootNet:[b]64bit:[/b] Base - Driver Group
SafeBootNet:[b]64bit:[/b] BasicDisplay.sys - C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] BasicRender.sys - C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] Boot Bus Extender - Driver Group
SafeBootNet:[b]64bit:[/b] Boot file system - Driver Group
SafeBootNet:[b]64bit:[/b] BrokerInfrastructure - C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] EFS - C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] File system - Driver Group
SafeBootNet:[b]64bit:[/b] Filter - Driver Group
SafeBootNet:[b]64bit:[/b] HelpSvc - Service
SafeBootNet:[b]64bit:[/b] KeyIso - C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] LSM - C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] Messenger - Service
SafeBootNet:[b]64bit:[/b] NDIS Wrapper - Driver Group
SafeBootNet:[b]64bit:[/b] NetBIOSGroup - Driver Group
SafeBootNet:[b]64bit:[/b] NetDDEGroup - Driver Group
SafeBootNet:[b]64bit:[/b] Netlogon - C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] netprofm - C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] Network - Driver Group
SafeBootNet:[b]64bit:[/b] NetworkProvider - Driver Group
SafeBootNet:[b]64bit:[/b] PCI Configuration - Driver Group
SafeBootNet:[b]64bit:[/b] PNP Filter - Driver Group
SafeBootNet:[b]64bit:[/b] PNP_TDI - Driver Group
SafeBootNet:[b]64bit:[/b] Primary disk - Driver Group
SafeBootNet:[b]64bit:[/b] rdpencdd.sys - Driver
SafeBootNet:[b]64bit:[/b] rdsessmgr - Service
SafeBootNet:[b]64bit:[/b] sacsvr - Service
SafeBootNet:[b]64bit:[/b] SCSI Class - Driver Group
SafeBootNet:[b]64bit:[/b] SmartcardSimulator - Driver
SafeBootNet:[b]64bit:[/b] Streams Drivers - Driver Group
SafeBootNet:[b]64bit:[/b] System Bus Extender - Driver Group
SafeBootNet:[b]64bit:[/b] SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] TBS - Service
SafeBootNet:[b]64bit:[/b] TDI - Driver Group
SafeBootNet:[b]64bit:[/b] VaultSvc - C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] VirtualSmartcardReader - Driver
SafeBootNet:[b]64bit:[/b] vmms - Service
SafeBootNet:[b]64bit:[/b] Wcmsvc - C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] WudfUsbccidDriver - Driver
SafeBootNet:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:[b]64bit:[/b] {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:[b]64bit:[/b] {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:[b]64bit:[/b] {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:[b]64bit:[/b] {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:[b]64bit:[/b] {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:[b]64bit:[/b] {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootNet:[b]64bit:[/b] {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootNet:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdpencdd.sys - Driver
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: SmartcardSimulator - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TBS - Service
SafeBootNet: TDI - Driver Group
SafeBootNet: VirtualSmartcardReader - Driver
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootNet: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:[b]64bit:[/b] {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:[b]64bit:[/b] {66C64F22-FC60-4E6C-A6B5-F0D580E680CE} - C:\WINDOWS\System32\ie4uinit.exe -EnableTLS
ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:[b]64bit:[/b] {78E345F7-E976-3595-9C30-2458D6A8EC32} - .NET Framework
ActiveX:[b]64bit:[/b] {7D715857-A67C-4C2F-A929-038448584D63} - C:\WINDOWS\System32\ie4uinit.exe -DisableSSL3
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - U
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.155\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EC43E638-09F0-38CC-A585-72FCCDDF035C} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP

Drivers32:[b]64bit:[/b] msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:[b]64bit:[/b] VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\WINDOWS\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\WINDOWS\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.VP60 - C:\WINDOWS\SysWow64\vp6vfw.dll (EA.com/On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\SysWow64\vp6vfw.dll (EA.com/On2.com)
Drivers32: vidc.VP62 - C:\WINDOWS\SysWow64\vp6vfw.dll (EA.com/On2.com)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2015/11/09 13:29:10 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\angel\Desktop\OTL.exe
[2015/11/09 03:53:58 | 000,000,000 | ---D | C] -- C:\Users\angel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RegSeeker
[2015/11/09 03:53:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegSeeker
[2015/11/09 03:53:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RegSeeker
[2015/11/04 15:45:50 | 000,000,000 | ---D | C] -- C:\Users\angel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flux
[2015/11/04 15:45:47 | 000,000,000 | ---D | C] -- C:\Users\angel\AppData\Local\FluxSoftware
[2015/10/27 18:45:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2015/10/27 16:32:56 | 000,000,000 | ---D | C] -- C:\Users\angel\AppData\Local\Adobe
[2015/10/27 16:32:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2015/10/27 16:32:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2015/10/27 16:32:55 | 000,000,000 | ---D | C] -- C:\Users\angel\AppData\Roaming\Adobe
[2015/10/21 03:59:36 | 000,000,000 | ---D | C] -- C:\Users\angel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2015/10/18 09:58:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Zylom
[2015/10/18 09:58:00 | 000,000,000 | ---D | C] -- C:\Users\angel\AppData\Roaming\Zylom
[2015/10/18 09:57:52 | 000,000,000 | ---D | C] -- C:\Users\angel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zylom Games
[2015/10/18 09:57:49 | 000,000,000 | ---D | C] -- C:\Users\angel\AppData\Local\Zylom Games
[2015/10/15 03:54:35 | 001,290,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\appraiser.dll
[2015/10/15 03:54:35 | 000,766,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\generaltel.dll
[2015/10/15 03:54:35 | 000,699,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\invagent.dll
[2015/10/15 03:54:35 | 000,503,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\devinv.dll
[2015/10/15 03:54:34 | 001,163,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2015/10/15 03:54:34 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\acmigration.dll
[2015/10/15 03:54:34 | 000,035,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\CompatTelRunner.exe
[2015/10/14 09:44:46 | 004,710,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d2d1.dll
[2015/10/14 09:44:33 | 001,134,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\KernelBase.dll
[2015/10/14 09:44:33 | 000,686,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\advapi32.dll
[2015/10/14 09:43:58 | 007,457,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntoskrnl.exe
[2015/10/14 09:43:57 | 001,736,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll
[2015/10/14 09:43:57 | 001,658,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.efi
[2015/10/14 09:43:57 | 001,519,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winload.exe
[2015/10/14 09:43:57 | 001,487,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.efi
[2015/10/14 09:43:57 | 001,355,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winresume.exe
[2015/10/14 09:43:56 | 000,737,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fveapi.dll
[2015/10/14 09:43:50 | 000,669,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hhctrl.ocx
[2015/10/14 09:43:50 | 000,536,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\hhctrl.ocx
[2015/10/14 09:43:16 | 005,990,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2015/10/14 09:43:08 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript.dll
[2015/10/14 09:43:08 | 000,663,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript.dll
[2015/10/14 09:43:08 | 000,616,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieui.dll
[2015/10/14 09:43:08 | 000,489,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtmsft.dll
[2015/10/14 09:43:08 | 000,480,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieui.dll
[2015/10/14 09:43:08 | 000,315,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2015/10/14 09:43:07 | 002,126,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2015/10/14 09:43:07 | 000,801,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2015/10/14 09:43:07 | 000,720,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2015/10/14 09:43:07 | 000,585,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2015/10/14 09:43:07 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2015/10/14 09:43:07 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2015/10/14 09:43:06 | 002,052,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2015/10/14 09:43:06 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2015/10/14 09:43:06 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2015/10/14 09:43:06 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll
[2015/10/14 09:43:06 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll
[2015/10/14 09:42:14 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\NcdAutoSetup.dll
[2015/10/14 09:42:12 | 002,243,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wucltux.dll
[2015/10/14 09:42:12 | 000,891,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapi.dll
[2015/10/14 09:42:12 | 000,721,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapi.dll
[2015/10/14 09:42:12 | 000,409,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUSettingsProvider.dll
[2015/10/14 09:42:12 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuwebv.dll
[2015/10/14 09:42:12 | 000,136,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuauclt.exe
[2015/10/14 09:42:12 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuwebv.dll
[2015/10/14 09:42:12 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wudriver.dll
[2015/10/14 09:42:12 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wudriver.dll
[2015/10/14 09:42:12 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\wuapp.exe
[2015/10/14 09:42:12 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\wuapp.exe
[2015/10/14 09:42:07 | 000,984,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ucrtbase.dll
[2015/10/14 09:42:07 | 000,901,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ucrtbase.dll
[2015/10/14 09:42:07 | 000,066,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-private-l1-1-0.dll
[2015/10/14 09:42:07 | 000,063,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-private-l1-1-0.dll
[2015/10/14 09:42:07 | 000,022,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-math-l1-1-0.dll
[2015/10/14 09:42:07 | 000,020,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-math-l1-1-0.dll
[2015/10/14 09:42:07 | 000,019,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-multibyte-l1-1-0.dll
[2015/10/14 09:42:07 | 000,019,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-multibyte-l1-1-0.dll
[2015/10/14 09:42:07 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-string-l1-1-0.dll
[2015/10/14 09:42:07 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-string-l1-1-0.dll
[2015/10/14 09:42:07 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-stdio-l1-1-0.dll
[2015/10/14 09:42:07 | 000,017,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-stdio-l1-1-0.dll
[2015/10/14 09:42:07 | 000,016,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-runtime-l1-1-0.dll
[2015/10/14 09:42:07 | 000,016,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-runtime-l1-1-0.dll
[2015/10/14 09:42:07 | 000,015,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-convert-l1-1-0.dll
[2015/10/14 09:42:07 | 000,015,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-convert-l1-1-0.dll
[2015/10/14 09:42:07 | 000,014,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-time-l1-1-0.dll
[2015/10/14 09:42:07 | 000,014,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-time-l1-1-0.dll
[2015/10/14 09:42:07 | 000,013,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-filesystem-l1-1-0.dll
[2015/10/14 09:42:07 | 000,013,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-filesystem-l1-1-0.dll
[2015/10/14 09:42:07 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-process-l1-1-0.dll
[2015/10/14 09:42:07 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-process-l1-1-0.dll
[2015/10/14 09:42:07 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-heap-l1-1-0.dll
[2015/10/14 09:42:07 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-heap-l1-1-0.dll
[2015/10/14 09:42:07 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-conio-l1-1-0.dll
[2015/10/14 09:42:07 | 000,012,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-conio-l1-1-0.dll
[2015/10/14 09:42:07 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-utility-l1-1-0.dll
[2015/10/14 09:42:07 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-utility-l1-1-0.dll
[2015/10/14 09:42:07 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-locale-l1-1-0.dll
[2015/10/14 09:42:07 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-locale-l1-1-0.dll
[2015/10/14 09:42:07 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\api-ms-win-crt-environment-l1-1-0.dll
[2015/10/14 09:42:07 | 000,012,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\api-ms-win-crt-environment-l1-1-0.dll
[2012/09/18 15:15:49 | 002,258,432 | ---- | C] (Samsung Electronics) -- C:\ProgramData\MakeMarkerFile.exe

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

File not found -- C:\Users\angel\Desktop\Adèle Exarchopoulos et Tahar Rahim, dans
[2015/11/09 13:29:13 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\angel\Desktop\OTL.exe
[2015/11/09 13:28:19 | 001,827,432 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2015/11/09 13:28:19 | 000,813,388 | ---- | M] () -- C:\WINDOWS\SysNative\perfh00C.dat
[2015/11/09 13:28:19 | 000,723,514 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2015/11/09 13:28:19 | 000,159,948 | ---- | M] () -- C:\WINDOWS\SysNative\perfc00C.dat
[2015/11/09 13:28:19 | 000,136,128 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2015/11/09 13:25:25 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2015/11/09 05:24:29 | 000,001,208 | ---- | M] () -- C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-2678595623-4148133582-4009595467-1003UA.job
[2015/11/09 04:56:00 | 000,001,002 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2015/11/09 04:43:00 | 000,000,360 | ---- | M] () -- C:\WINDOWS\tasks\Xerox PhotoCafe Communicator.job
[2015/11/09 02:30:02 | 000,000,940 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-2678595623-4148133582-4009595467-1003UA.job
[2015/11/08 22:53:11 | 000,000,132 | ---- | M] () -- C:\Users\angel\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2015/11/08 20:50:38 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
[2015/11/08 20:33:44 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2015/11/08 20:33:40 | 767,926,271 | -HS- | M] () -- C:\hiberfil.sys
[2015/11/08 14:30:00 | 000,000,918 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-2678595623-4148133582-4009595467-1003Core.job
[2015/11/08 14:24:00 | 000,001,156 | ---- | M] () -- C:\WINDOWS\tasks\DropboxUpdateTaskUserS-1-5-21-2678595623-4148133582-4009595467-1003Core.job
[2015/11/08 10:50:00 | 000,000,870 | ---- | M] () -- C:\WINDOWS\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
[2015/11/07 22:03:00 | 000,001,456 | ---- | M] () -- C:\Users\angel\AppData\Local\Adobe Enregistrer pour le Web 12.0 Prefs
[2015/11/05 07:11:27 | 000,000,132 | ---- | M] () -- C:\Users\angel\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2015/11/01 21:38:22 | 000,346,808 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2015/11/01 21:38:06 | 714,470,814 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2015/10/27 18:52:04 | 000,192,216 | ---- | M] (Malwarebytes) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2015/10/26 15:44:37 | 000,085,821 | ---- | M] () -- C:\WINDOWS\SysNative\ScanResults.xml
[2015/10/26 15:37:34 | 000,000,464 | ---- | M] () -- C:\WINDOWS\SysNative\ScannerSettings
[2015/10/21 04:00:28 | 000,001,182 | ---- | M] () -- C:\Users\angel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2015/10/16 08:51:29 | 000,810,488 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2015/10/16 08:51:29 | 000,176,632 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl

[color=#E56717]========== Files Created - No Company Name ==========[/color]

File not found -- C:\Users\angel\Desktop\Adèle Exarchopoulos et Tahar Rahim, dans
[2015/11/05 07:11:27 | 000,000,132 | ---- | C] () -- C:\Users\angel\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2015/11/01 21:38:06 | 714,470,814 | ---- | C] () -- C:\WINDOWS\MEMORY.DMP
[2015/10/26 15:44:37 | 000,085,821 | ---- | C] () -- C:\WINDOWS\SysNative\ScanResults.xml
[2015/10/26 15:37:33 | 000,000,464 | ---- | C] () -- C:\WINDOWS\SysNative\ScannerSettings
[2015/10/22 18:28:03 | 000,001,002 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2015/10/01 00:07:09 | 000,000,290 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2015/09/30 22:43:02 | 000,000,102 | ---- | C] () -- C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
[2015/06/17 02:04:18 | 000,000,132 | ---- | C] () -- C:\Users\angel\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2015/06/11 17:10:10 | 000,001,456 | ---- | C] () -- C:\Users\angel\AppData\Local\Adobe Enregistrer pour le Web 12.0 Prefs
[2015/03/12 11:00:24 | 000,107,008 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2015/03/12 10:58:02 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2014/10/01 22:54:10 | 000,183,808 | ---- | C] () -- C:\WINDOWS\SysWow64\igdde32.dll
[2014/10/01 22:54:10 | 000,143,360 | ---- | C] () -- C:\WINDOWS\SysWow64\igdail32.dll
[2014/09/24 19:35:16 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014/07/22 01:04:58 | 000,204,952 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsvl.dat
[2014/07/22 01:04:58 | 000,157,144 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsva.dat
[2014/07/22 01:04:46 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysWow64\atipblag.dat
[2014/07/22 01:04:04 | 000,995,342 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_as32.exe
[2014/07/22 01:04:04 | 000,798,734 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_ld32.exe
[2014/07/22 01:03:42 | 000,123,392 | ---- | C] () -- C:\WINDOWS\SysWow64\amdhdl32.dll
[2012/09/18 15:15:49 | 000,003,196 | ---- | C] () -- C:\ProgramData\MakeMarkerFile.xml

[color=#E56717]========== ZeroAccess Check ==========[/color]


[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2015/08/27 06:43:09 | 022,372,152 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015/08/27 06:42:51 | 019,795,904 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2014/10/29 05:19:43 | 001,013,760 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2014/10/29 04:59:23 | 000,786,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2014/10/29 05:16:01 | 000,512,512 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== Custom Scans ==========[/color]

[color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
[2012/07/26 07:44:30 | 000,398,156 | RHS- | M] () -- C:\bootmgr
[2013/06/18 16:18:29 | 000,000,001 | -HS- | M] () -- C:\BOOTNXT
[2015/06/11 21:05:29 | 000,000,040 | -H-- | M] () -- C:\C006664FE25B
[2015/08/05 14:10:36 | 000,000,383 | ---- | M] () -- C:\ftconfig.ini
[2015/11/08 20:33:40 | 767,926,271 | -HS- | M] () -- C:\hiberfil.sys
[2015/11/08 20:33:44 | 2147,483,647 | -HS- | M] () -- C:\pagefile.sys
[2015/11/08 20:33:44 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

[color=#A23BEC]< %PROGRAMFILES%\*.* >[/color]
[2013/08/22 19:34:52 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini

[color=#A23BEC]< %PROGRAMFILES%\*. >[/color]
[2015/08/10 20:16:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\4KDownload
[2012/09/18 14:50:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AMD APP
[2014/11/07 10:11:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ATI Technologies
[2015/06/27 15:29:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ATTNaturalVoices
[2015/06/11 16:40:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Audacity
[2014/11/07 17:01:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Bluetooth Suite
[2015/10/07 15:54:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Calibre2
[2015/11/09 02:55:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
[2013/02/09 18:49:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Corel
[2012/09/18 15:12:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CyberLink
[2015/08/22 13:17:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Free Video to GIF Converter
[2015/06/03 18:20:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Google
[2015/06/27 19:42:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\InfraRecorder
[2014/07/02 08:43:54 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
[2012/09/18 15:16:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Intel
[2015/10/17 10:34:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
[2015/06/28 02:28:12 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\IVONA
[2014/06/25 13:13:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Karasoft
[2015/08/28 15:26:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\LLockeorTerminal
[2015/10/27 18:45:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2015/07/28 02:46:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ManyCam
[2014/07/02 08:43:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mattel Interactive
[2012/09/18 15:18:58 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office
[2015/08/14 16:53:01 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Silverlight
[2012/09/18 15:14:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2013/08/22 19:36:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
[2015/08/28 11:57:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox
[2015/08/14 16:53:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2014/11/07 09:39:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
[2015/06/27 15:36:43 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NeoSpeech
[2015/08/17 19:38:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Norton Internet Security
[2012/09/18 15:04:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Norton Online Backup ARA
[2015/07/19 18:26:48 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NortonInstaller
[2015/11/05 20:11:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Opera
[2015/11/08 14:30:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PhotoFiltre 7
[2013/10/12 23:56:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PhotoScape
[2014/09/25 12:19:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PokerStars.FR
[2012/09/18 15:10:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PopCap Games
[2012/09/18 14:11:58 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Qualcomm Atheros
[2013/11/24 08:49:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\RaidCall
[2012/09/18 14:53:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek
[2014/11/07 09:39:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
[2015/11/09 03:54:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\RegSeeker
[2012/09/18 15:16:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Samsung
[2015/06/17 15:02:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Scribble
[2015/06/17 19:06:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\SecondLifeViewer
[2015/07/03 19:30:16 | 000,000,000 | R--D | M] -- C:\Program Files (x86)\Skype
[2013/09/10 16:40:51 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\SRT3 V1.7
[2012/09/18 15:04:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Symantec
[2012/09/18 14:51:49 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp
[2015/06/27 15:26:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\TextAloud
[2015/08/28 15:26:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\TorqueeSShip
[2015/08/28 15:26:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\TorqueShipp
[2015/08/28 15:26:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\TorquoeSShIp
[2015/06/18 18:15:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\UnH Solutions
[2015/08/14 13:37:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
[2012/09/18 15:14:01 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live
[2015/03/13 04:40:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
[2015/03/13 04:40:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
[2015/03/13 04:40:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Multimedia Platform
[2013/08/22 19:36:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
[2015/03/13 04:40:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Viewer
[2015/03/13 04:40:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices
[2014/11/07 10:11:19 | 000,000,000 | -HSD | M] -- C:\Program Files (x86)\Windows Sidebar
[2013/08/22 19:36:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WindowsPowerShell
[2015/06/19 23:56:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WinRAR
[2012/09/18 15:15:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Xerox PhotoCafe

[color=#A23BEC]< MD5 for: AGP440.SYS >[/color]
[2013/08/22 16:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\WINDOWS\SysNative\drivers\AGP440.sys
[2013/08/22 16:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\machine.inf_amd64_36be84f8fc597ea3\AGP440.sys
[2013/08/22 16:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17238_none_ab0b455c927bd60f\AGP440.sys
[2015/07/10 14:30:50 | 000,063,328 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\drivers\AGP440.sys
[2015/07/10 14:30:50 | 000,063,328 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\DriverStore\FileRepository\machine.inf_amd64_c357541563097b98\AGP440.sys
[2015/07/10 14:30:50 | 000,063,328 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_10.0.10240.16384_none_c2135eea595e241e\AGP440.sys

[color=#A23BEC]< MD5 for: APPMGMTS.DLL >[/color]
[2013/08/22 18:55:04 | 000,086,064 | ---- | M] () MD5=1336BE8A8B1E8B8744D5217AE5FDD303 -- C:\Windows\WinSxS\amd64_microsoft-windows-g..oftwareinstallation_31bf3856ad364e35_6.3.9600.16384_none_728d486f3000a7ad\appmgmts.dll
[2015/03/13 06:03:19 | 000,087,855 | ---- | M] () MD5=5B2A9B5E87542C65457B527CC512AF25 -- C:\Windows\WinSxS\amd64_microsoft-windows-g..oftwareinstallation_31bf3856ad364e35_6.3.9600.17415_none_72d9e34b2fc71435\appmgmts.dll
[2013/08/22 19:00:05 | 000,071,466 | ---- | M] () MD5=9424C4C8AE9114A121553818824D33A3 -- C:\Windows\WinSxS\wow64_microsoft-windows-g..oftwareinstallation_31bf3856ad364e35_6.3.9600.16384_none_7ce1f2c1646169a8\appmgmts.dll
[2015/03/13 08:25:35 | 000,072,712 | ---- | M] () MD5=C73D54BF555388E7DF11A9C0AFC1F139 -- C:\Windows\WinSxS\wow64_microsoft-windows-g..oftwareinstallation_31bf3856ad364e35_6.3.9600.17415_none_7d2e8d9d6427d630\appmgmts.dll

[color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
[2013/08/22 16:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\WINDOWS\SysNative\drivers\atapi.sys
[2013/08/22 16:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\WINDOWS\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_64aa4354da84c2df\atapi.sys
[2013/08/22 16:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.3.9600.16384_none_cdf68824f580d510\atapi.sys
[2015/07/10 14:30:51 | 000,028,512 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\drivers\atapi.sys
[2015/07/10 14:30:51 | 000,028,512 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\DriverStore\FileRepository\mshdc.inf_amd64_5689072091519d03\atapi.sys
[2015/07/10 14:30:51 | 000,028,512 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_10.0.10240.16384_none_e53899c8bc371940\atapi.sys

[color=#A23BEC]< MD5 for: AUTOCHK.EXE >[/color]
[2014/09/24 19:35:20 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\SysWOW64\autochk.exe
[2014/09/24 19:35:20 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_76c6a414dd35029f\autochk.exe
[2014/09/24 19:34:54 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=387A1E98BE548E4F199343CBA01E9D6D -- C:\WINDOWS\SysNative\autochk.exe
[2014/09/24 19:34:54 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=387A1E98BE548E4F199343CBA01E9D6D -- C:\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_d2e53f98959273d5\autochk.exe
[2015/07/10 14:30:55 | 000,944,640 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\autochk.exe
[2015/07/10 14:30:55 | 000,944,640 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_10.0.10240.16384_none_e9f45ef85c6e6d93\autochk.exe

[color=#A23BEC]< MD5 for: BEEP.SYS >[/color]
[2013/08/22 15:40:24 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=EC19013E4CF87609534165DF897274D6 -- C:\WINDOWS\SysNative\drivers\beep.sys
[2013/08/22 15:40:24 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=EC19013E4CF87609534165DF897274D6 -- C:\Windows\WinSxS\amd64_microsoft-windows-beepsys_31bf3856ad364e35_6.3.9600.16384_none_b4df015ddb944ecf\beep.sys

[color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color]
[2015/03/13 06:01:25 | 000,087,190 | ---- | M] () MD5=1BF154F7BFAE2B9E0545FB09946C1817 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_42bfa1f94d79e1bb\explorer.exe
[2015/03/13 06:01:20 | 000,396,313 | ---- | M] () MD5=426AEABD8DD389A65A8EE92AB5936153 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17284_none_4272ee6f4db391ad\explorer.exe
[2015/03/13 08:25:23 | 000,107,122 | ---- | M] () MD5=52063502D4A2E28FEBEA781D0EE5C453 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_4d144c4b81daa3b6\explorer.exe
[2015/01/28 03:41:17 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=91E24273FCA076EA9E65DAFA98901225 -- C:\Windows\SysWOW64\explorer.exe
[2015/01/28 03:41:17 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=91E24273FCA076EA9E65DAFA98901225 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17667_none_4ce0410f82015c67\explorer.exe
[2014/11/18 11:56:11 | 000,219,647 | ---- | M] () MD5=B75E9C8434D53F8C187D352FA7F692D4 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17249_none_4cf7d9e381ef6297\explorer.exe
[2015/01/28 03:47:12 | 002,501,368 | ---- | M] (Microsoft Corporation) MD5=C10A66189DC8C090E7C84873EDCEBC88 -- C:\Windows\explorer.exe
[2015/01/28 03:47:12 | 002,501,368 | ---- | M] (Microsoft Corporation) MD5=C10A66189DC8C090E7C84873EDCEBC88 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17667_none_428b96bd4da09a6c\explorer.exe
[2014/11/18 10:40:26 | 000,270,403 | ---- | M] () MD5=C20A0C44E241606430009E7F126A1125 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17249_none_42a32f914d8ea09c\explorer.exe
[2015/03/13 08:25:15 | 000,338,943 | ---- | M] () MD5=E4FD740C3316F1D1C8322471553466C7 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17284_none_4cc798c1821453a8\explorer.exe

[color=#A23BEC]< MD5 for: HIDSERV.DLL >[/color]
[2015/03/13 06:03:56 | 000,004,284 | ---- | M] () MD5=2A8190AC5599446255EEADD6088C3BED -- C:\Windows\WinSxS\amd64_microsoft-windows-hid-user_31bf3856ad364e35_6.3.9600.16384_none_c76aa8785b65aeab\hidserv.dll
[2015/03/13 08:25:56 | 000,007,007 | ---- | M] () MD5=73A9A38CF4CBA7E4E742D493B3D672BC -- C:\Windows\WinSxS\wow64_microsoft-windows-hid-user_31bf3856ad364e35_6.3.9600.16384_none_d1bf52ca8fc670a6\hidserv.dll
[2014/10/29 05:59:46 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=AE71B1BC1A17000F7B8F9AB79D4668D4 -- C:\Windows\SysWOW64\hidserv.dll
[2014/10/29 05:59:46 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=AE71B1BC1A17000F7B8F9AB79D4668D4 -- C:\Windows\WinSxS\wow64_microsoft-windows-hid-user_31bf3856ad364e35_6.3.9600.17415_none_d20beda68f8cdd2e\hidserv.dll
[2014/10/29 06:44:23 | 000,033,792 | ---- | M] (Microsoft Corporation) MD5=EA85B5093DF7B5C3E80362B053740AE2 -- C:\WINDOWS\SysNative\hidserv.dll
[2014/10/29 06:44:23 | 000,033,792 | ---- | M] (Microsoft Corporation) MD5=EA85B5093DF7B5C3E80362B053740AE2 -- C:\Windows\WinSxS\amd64_microsoft-windows-hid-user_31bf3856ad364e35_6.3.9600.17415_none_c7b743545b2c1b33\hidserv.dll
[2015/07/10 14:30:53 | 000,034,304 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\hidserv.dll
[2015/07/10 14:30:53 | 000,034,304 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-hid-user_31bf3856ad364e35_10.0.10240.16384_none_deacba1c221bf2db\hidserv.dll

[color=#A23BEC]< MD5 for: IASTORV.SYS >[/color]
[2013/08/22 16:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\WINDOWS\SysNative\drivers\iaStorV.sys
[2013/08/22 16:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\WINDOWS\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_5069105fb236ae4b\iaStorV.sys
[2013/08/22 16:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\Windows\WinSxS\amd64_iastorv.inf_31bf3856ad364e35_6.3.9600.16384_none_9fcfb2835bbf0103\iaStorV.sys
[2015/07/10 14:30:50 | 000,412,000 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\drivers\iaStorV.sys
[2015/07/10 14:30:50 | 000,412,000 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\DriverStore\FileRepository\iastorv.inf_amd64_5069105fb236ae4b\iaStorV.sys
[2015/07/10 14:30:50 | 000,412,000 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_iastorv.inf_31bf3856ad364e35_10.0.10240.16384_none_b711c42722754533\iaStorV.sys

[color=#A23BEC]< MD5 for: IMM32.DLL >[/color]
[2015/03/13 06:08:31 | 000,027,353 | ---- | M] () MD5=16BF085E712ACC139C39C34CEB499D7A -- C:\Windows\WinSxS\amd64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.17031_none_4d4770654e3c4de8\imm32.dll
[2015/03/13 08:30:35 | 000,023,804 | ---- | M] () MD5=4E7419816FAD0942AEFB3B37F0D26A0D -- C:\Windows\WinSxS\wow64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.17031_none_579c1ab7829d0fe3\imm32.dll
[2014/10/29 05:59:49 | 000,141,312 | ---- | M] (Microsoft Corporation) MD5=59452E147C6A5D055E5EBCB6B8E99CB7 -- C:\Windows\SysWOW64\imm32.dll
[2014/10/29 05:59:49 | 000,141,312 | ---- | M] (Microsoft Corporation) MD5=59452E147C6A5D055E5EBCB6B8E99CB7 -- C:\Windows\WinSxS\wow64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.17415_none_57b5c34f828931f9\imm32.dll
[2014/10/29 08:00:23 | 000,210,744 | ---- | M] (Microsoft Corporation) MD5=DEB33D08FBF708CAAC08080054D4C7CC -- C:\WINDOWS\SysNative\imm32.dll
[2014/10/29 08:00:23 | 000,210,744 | ---- | M] (Microsoft Corporation) MD5=DEB33D08FBF708CAAC08080054D4C7CC -- C:\Windows\WinSxS\amd64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.17415_none_4d6118fd4e286ffe\imm32.dll
[2015/07/10 14:30:51 | 000,211,288 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\imm32.dll
[2015/07/10 14:30:51 | 000,211,288 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-imm32_31bf3856ad364e35_10.0.10240.16384_none_64568fc5151847a6\imm32.dll

[color=#A23BEC]< MD5 for: KERNEL32.DLL >[/color]
[2014/10/29 05:58:23 | 001,040,384 | ---- | M] (Microsoft Corporation) MD5=00DC86D9068D7E780407A8B66E2AFD9D -- C:\Windows\SysWOW64\kernel32.dll
[2014/10/29 05:58:23 | 001,040,384 | ---- | M] (Microsoft Corporation) MD5=00DC86D9068D7E780407A8B66E2AFD9D -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17415_none_8f1d8a7a5e69bda5\kernel32.dll
[2014/10/29 08:09:24 | 001,309,744 | ---- | M] (Microsoft Corporation) MD5=4F455778B6CDA2FD61D4F8B0A3E0543C -- C:\WINDOWS\SysNative\kernel32.dll
[2014/10/29 08:09:24 | 001,309,744 | ---- | M] (Microsoft Corporation) MD5=4F455778B6CDA2FD61D4F8B0A3E0543C -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17415_none_84c8e0282a08fbaa\kernel32.dll
[2015/03/13 08:31:00 | 000,121,316 | ---- | M] () MD5=63CF5E1D83272D55F2C1A7C752DEC7C9 -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17056_none_8ef3437c5e895224\kernel32.dll
[2015/03/13 07:15:21 | 000,149,635 | ---- | M] () MD5=DE0B6AADFB0BA5D0AABA9EAD2011D02C -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17056_none_849e992a2a289029\kernel32.dll
[2015/07/10 14:30:55 | 000,702,512 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\kernel32.dll
[2015/07/10 14:30:55 | 000,702,512 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_10.0.10240.16384_none_9bbe56eff0f8d352\kernel32.dll

[color=#A23BEC]< MD5 for: MSWSOCK.DLL >[/color]
[2015/03/13 08:03:55 | 000,089,664 | ---- | M] () MD5=91B386E48B823AE3047B924D104C4AE9 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.3.9600.16384_none_a911b7110142c502\mswsock.dll
[2014/10/29 05:06:17 | 000,286,208 | ---- | M] (Microsoft Corporation) MD5=98ECA44A09EFA23890205D2B5233FC96 -- C:\Windows\SysWOW64\mswsock.dll
[2014/10/29 05:06:17 | 000,286,208 | ---- | M] (Microsoft Corporation) MD5=98ECA44A09EFA23890205D2B5233FC96 -- C:\Windows\WinSxS\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.3.9600.17415_none_4d3fb66948abc054\mswsock.dll
[2014/10/29 05:29:43 | 000,339,456 | ---- | M] (Microsoft Corporation) MD5=B394EB3E443DCB195BC65B9A54CD8FE3 -- C:\WINDOWS\SysNative\mswsock.dll
[2014/10/29 05:29:43 | 000,339,456 | ---- | M] (Microsoft Corporation) MD5=B394EB3E443DCB195BC65B9A54CD8FE3 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.3.9600.17415_none_a95e51ed0109318a\mswsock.dll
[2015/03/15 10:27:17 | 000,073,881 | ---- | M] () MD5=DD9EB5415ED0BA50A6FDF18E77D58BA8 -- C:\Windows\WinSxS\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.3.9600.16384_none_4cf31b8d48e553cc\mswsock.dll
[2015/07/10 14:30:54 | 000,364,384 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\mswsock.dll
[2015/07/10 14:30:54 | 000,364,384 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_10.0.10240.16384_none_c053c8b4c7f90932\mswsock.dll

[color=#A23BEC]< MD5 for: NDIS.SYS >[/color]
[2015/07/15 01:59:47 | 001,113,944 | ---- | M] (Microsoft Corporation) MD5=97DC5967F65503213FD1F1B3E4A6F983 -- C:\WINDOWS\SysNative\drivers\ndis.sys
[2015/07/15 01:59:47 | 001,113,944 | ---- | M] (Microsoft Corporation) MD5=97DC5967F65503213FD1F1B3E4A6F983 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17933_none_4a48e22dfbdb75b0\ndis.sys
[2015/09/25 23:43:16 | 000,163,967 | ---- | M] () MD5=B799AF43B0B317395202AEF55957EEB1 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17199_none_4a0df531fc06cc28\ndis.sys
[2015/09/25 23:43:18 | 000,083,281 | ---- | M] () MD5=E47216FC1C4FCA5C1A9E3BBB79EA37FD -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17399_none_4a0df8fdfc06c676\ndis.sys
[2015/07/10 14:30:57 | 001,168,736 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\drivers\ndis.sys
[2015/07/10 14:30:57 | 001,168,736 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_10.0.10240.16384_none_6155efe3c2b95661\ndis.sys

[color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color]
[2014/10/29 05:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) MD5=02D117FC638B768BD1A15F8000B83EAE -- C:\WINDOWS\SysNative\netlogon.dll
[2014/10/29 05:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) MD5=02D117FC638B768BD1A15F8000B83EAE -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17415_none_eec2b22a0bb75b53\netlogon.dll
[2015/03/13 07:39:32 | 000,125,384 | ---- | M] () MD5=45C2C2EA335BD7FF360C7F006B915766 -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17041_none_ee9e39a60bd3552e\netlogon.dll
[2015/03/13 08:38:37 | 000,105,907 | ---- | M] () MD5=B25E2DE4078511EB1747FA0BDB6E4FC5 -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17041_none_f8f2e3f840341729\netlogon.dll
[2014/10/29 05:02:34 | 000,695,296 | ---- | M] (Microsoft Corporation) MD5=CCEC6CB98A00ECE7F5AFB9C0FC9427B3 -- C:\Windows\SysWOW64\netlogon.dll
[2014/10/29 05:02:34 | 000,695,296 | ---- | M] (Microsoft Corporation) MD5=CCEC6CB98A00ECE7F5AFB9C0FC9427B3 -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17415_none_f9175c7c40181d4e\netlogon.dll
[2015/07/10 14:30:56 | 000,836,096 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\netlogon.dll
[2015/07/10 14:30:56 | 000,836,096 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_10.0.10240.16384_none_05b828f1d2a732fb\netlogon.dll

[color=#A23BEC]< MD5 for: NTFS.SYS >[/color]
[2014/10/15 12:32:37 | 002,025,792 | ---- | M] (Microsoft Corporation) MD5=7F68063A5A0461E02BC860CE0E6BFDDC -- C:\WINDOWS\SysNative\drivers\ntfs.sys
[2014/10/15 12:32:37 | 002,025,792 | ---- | M] (Microsoft Corporation) MD5=7F68063A5A0461E02BC860CE0E6BFDDC -- C:\Windows\WinSxS\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.3.9600.17401_none_9782f367f0a48b42\ntfs.sys
[2015/03/13 07:29:54 | 000,378,139 | ---- | M] () MD5=E5D1987CD7FBB2169440CD9B8E2AB87E -- C:\Windows\WinSxS\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.3.9600.17238_none_976981ddf0b69628\ntfs.sys
[2015/07/10 14:30:56 | 002,117,472 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\drivers\ntfs.sys
[2015/07/10 14:30:56 | 002,117,472 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-ntfs_31bf3856ad364e35_10.0.10240.16384_none_ae719b6bb798e437\ntfs.sys

[color=#A23BEC]< MD5 for: NVSTOR.SYS >[/color]
[2013/08/22 16:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\WINDOWS\SysNative\drivers\nvstor.sys
[2013/08/22 16:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\WINDOWS\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_7ba65ba4b222e751\nvstor.sys
[2013/08/22 16:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.3.9600.16384_none_2a99233292f5aadb\nvstor.sys
[2015/07/10 14:30:51 | 000,166,240 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\drivers\nvstor.sys
[2015/07/10 14:30:51 | 000,166,240 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\DriverStore\FileRepository\nvraid.inf_amd64_3ee6d81b22b3ea66\nvstor.sys
[2015/07/10 14:30:51 | 000,166,240 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_10.0.10240.16384_none_41db34d659abef0b\nvstor.sys

[color=#A23BEC]< MD5 for: PROQUOTA.EXE >[/color]
[2014/10/29 06:20:00 | 000,032,256 | ---- | M] (Microsoft Corporation) MD5=864379396733031C99B64550358CAEBD -- C:\WINDOWS\SysNative\proquota.exe
[2014/10/29 06:20:00 | 000,032,256 | ---- | M] (Microsoft Corporation) MD5=864379396733031C99B64550358CAEBD -- C:\Windows\WinSxS\amd64_microsoft-windows-proquota_31bf3856ad364e35_6.3.9600.17415_none_18d1f2be66229ae5\proquota.exe
[2015/03/15 10:18:33 | 000,003,774 | ---- | M] () MD5=8FB27AE214469C91285EE90DADF94D78 -- C:\Windows\WinSxS\x86_microsoft-windows-proquota_31bf3856ad364e35_6.3.9600.16384_none_bc66bc5eadfebd27\proquota.exe
[2015/03/13 07:34:23 | 000,002,700 | ---- | M] () MD5=C76ABF6F332C8E55700EADCB3F0FE880 -- C:\Windows\WinSxS\amd64_microsoft-windows-proquota_31bf3856ad364e35_6.3.9600.16384_none_188557e2665c2e5d\proquota.exe
[2014/10/29 05:40:27 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=DF801B9FC4247EBFBFE07E5EC417C5B0 -- C:\Windows\SysWOW64\proquota.exe
[2014/10/29 05:40:27 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=DF801B9FC4247EBFBFE07E5EC417C5B0 -- C:\Windows\WinSxS\x86_microsoft-windows-proquota_31bf3856ad364e35_6.3.9600.17415_none_bcb3573aadc529af\proquota.exe

[color=#A23BEC]< MD5 for: QMGR.DLL >[/color]
[2014/10/29 05:43:34 | 000,933,376 | ---- | M] (Microsoft Corporation) MD5=48554994279BFE17A3D2B00076D0CB1A -- C:\WINDOWS\SysNative\qmgr.dll
[2014/10/29 05:43:34 | 000,933,376 | ---- | M] (Microsoft Corporation) MD5=48554994279BFE17A3D2B00076D0CB1A -- C:\Windows\WinSxS\amd64_microsoft-windows-bits-client_31bf3856ad364e35_6.3.9600.17415_none_149bbfd3cd2f7e88\qmgr.dll
[2015/03/13 05:45:25 | 000,297,501 | ---- | M] () MD5=C3D7BF1A7970C6765A8F6F7E42099FCE -- C:\Windows\WinSxS\amd64_microsoft-windows-bits-client_31bf3856ad364e35_6.3.9600.16384_none_144f24f7cd691200\qmgr.dll

[color=#A23BEC]< MD5 for: SCECLI.DLL >[/color]
[2015/03/13 08:37:52 | 000,042,572 | ---- | M] () MD5=22CDB04B964A8D34C42BB7ED150784F8 -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_3320ecb8e1733781\scecli.dll
[2015/03/13 07:38:34 | 000,045,911 | ---- | M] () MD5=878EBE290BED3EE6AC21BF4EE1458F67 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_28cc4266ad127586\scecli.dll
[2014/10/29 05:23:16 | 000,274,944 | ---- | M] (Microsoft Corporation) MD5=9A475B8F19A15BFDE8DF84E40ECAE8AA -- C:\WINDOWS\SysNative\scecli.dll
[2014/10/29 05:23:16 | 000,274,944 | ---- | M] (Microsoft Corporation) MD5=9A475B8F19A15BFDE8DF84E40ECAE8AA -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17415_none_2918dd42acd8e20e\scecli.dll
[2014/10/29 05:01:41 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\SysWOW64\scecli.dll
[2014/10/29 05:01:41 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17415_none_336d8794e139a409\scecli.dll
[2015/07/10 14:30:56 | 000,284,672 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\scecli.dll
[2015/07/10 14:30:56 | 000,284,672 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_10.0.10240.16384_none_400e540a73c8b9b6\scecli.dll

[color=#A23BEC]< MD5 for: SPOOLSV.EXE >[/color]
[2015/03/13 07:34:07 | 000,144,407 | ---- | M] () MD5=5E94BD87266C67420DCB3FF2516D8A9D -- C:\Windows\WinSxS\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.3.9600.17238_none_c743fb429553c1ab\spoolsv.exe
[2014/10/29 04:54:15 | 000,827,392 | ---- | M] (Microsoft Corporation) MD5=FCB156A6745631A67DEA61827061D483 -- C:\WINDOWS\SysNative\spoolsv.exe
[2014/10/29 04:54:15 | 000,827,392 | ---- | M] (Microsoft Corporation) MD5=FCB156A6745631A67DEA61827061D483 -- C:\Windows\WinSxS\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.3.9600.17415_none_c7569e0895463812\spoolsv.exe

[color=#A23BEC]< MD5 for: SVCHOST.EXE >[/color]
[2015/03/15 10:21:24 | 000,007,517 | ---- | M] () MD5=73AA583D4FB0F05C313B38C091D94804 -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_4a5b1e2820e75323\svchost.exe
[2015/03/13 07:39:50 | 000,007,559 | ---- | M] () MD5=CFE97816CBBEF783FD8634109F1877D2 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_a679b9abd944c459\svchost.exe
[2014/10/29 07:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\SysWOW64\svchost.exe
[2014/10/29 07:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_4aa7b90420adbfab\svchost.exe
[2014/10/29 08:11:20 | 000,038,792 | ---- | M] (Microsoft Corporation) MD5=E3A2AD05E24105B35E986CF9CB38EC47 -- C:\WINDOWS\SysNative\svchost.exe
[2014/10/29 08:11:20 | 000,038,792 | ---- | M] (Microsoft Corporation) MD5=E3A2AD05E24105B35E986CF9CB38EC47 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_a6c65487d90b30e1\svchost.exe
[2015/10/05 12:48:32 | 000,893,752 | ---- | M] (MalwareBytes) MD5=E9A75E4B409A01E52055CE7CCA7FF925 -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\svchost.exe
[2015/07/10 14:30:56 | 000,039,856 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\svchost.exe
[2015/07/10 14:30:56 | 000,039,856 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_10.0.10240.16384_none_bdbbcb4f9ffb0889\svchost.exe

[color=#A23BEC]< MD5 for: TERMSRV.DLL >[/color]
[2015/03/13 07:59:18 | 000,200,637 | ---- | M] () MD5=640B43E4063B00DD1769C93FEDBFD8B4 -- C:\Windows\WinSxS\amd64_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.3.9600.17095_none_7f53b5b72842754a\termsrv.dll
[2014/10/29 05:34:57 | 001,114,624 | ---- | M] (Microsoft Corporation) MD5=C50997E282576DA492EBA66B059D4196 -- C:\WINDOWS\SysNative\termsrv.dll
[2014/10/29 05:34:57 | 001,114,624 | ---- | M] (Microsoft Corporation) MD5=C50997E282576DA492EBA66B059D4196 -- C:\Windows\WinSxS\amd64_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.3.9600.17415_none_7faa3caf28018a5e\termsrv.dll

[color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
[2015/03/13 08:02:57 | 000,002,671 | ---- | M] () MD5=061AC3BD7ADC5DCBA6AC0F23895266F8 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_cce71a20a5a6fe7f\userinit.exe
[2015/03/15 10:26:50 | 000,004,269 | ---- | M] () MD5=1AE98168631581DE1343C3A87A6CBCA9 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_70c87e9ced498d49\userinit.exe
[2014/10/29 05:28:08 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=5C131534A3EA4A461A793FB507A8004F -- C:\WINDOWS\SysNative\userinit.exe
[2014/10/29 05:28:08 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=5C131534A3EA4A461A793FB507A8004F -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_cd33b4fca56d6b07\userinit.exe
[2014/10/29 05:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\SysWOW64\userinit.exe
[2014/10/29 05:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_71151978ed0ff9d1\userinit.exe
[2015/07/10 14:30:56 | 000,030,720 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\userinit.exe
[2015/07/10 14:30:56 | 000,030,720 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_10.0.10240.16384_none_e4292bc46c5d42af\userinit.exe

[color=#A23BEC]< MD5 for: VOLSNAP.SYS >[/color]
[2014/09/24 19:44:42 | 000,310,080 | ---- | M] (Microsoft Corporation) MD5=64CA2B4A49A8EAF495E435623ECCE7DB -- C:\WINDOWS\SysNative\drivers\volsnap.sys
[2014/09/24 19:44:42 | 000,310,080 | ---- | M] (Microsoft Corporation) MD5=64CA2B4A49A8EAF495E435623ECCE7DB -- C:\WINDOWS\SysNative\DriverStore\FileRepository\volume.inf_amd64_8687137d6e4faf5d\volsnap.sys
[2014/09/24 19:44:42 | 000,310,080 | ---- | M] (Microsoft Corporation) MD5=64CA2B4A49A8EAF495E435623ECCE7DB -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.3.9600.17215_none_06c1ae9bcfd2737b\volsnap.sys
[2015/07/10 14:30:51 | 000,378,720 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\drivers\volsnap.sys
[2015/07/10 14:30:51 | 000,378,720 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\DriverStore\FileRepository\volume.inf_amd64_b017de7f410d7e0a\volsnap.sys
[2015/07/10 14:30:51 | 000,378,720 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_10.0.10240.16384_none_1db7292f96c24571\volsnap.sys

[color=#A23BEC]< MD5 for: WININET.DLL >[/color]
[2014/11/18 10:42:48 | 000,500,207 | ---- | M] () MD5=0DEE2BC46A05991CEB5EE1BCFF67700E -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17207_none_05b0e0b484c70934\wininet.dll
[2015/09/13 11:22:21 | 000,217,045 | ---- | M] () MD5=17647FA5AEE841BBBFCAA4895CD7EE53 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17937_none_a949969acc9fa79a\wininet.dll
[2015/03/13 06:04:57 | 000,281,361 | ---- | M] () MD5=18657B28917AC11E8D14C441B98D9A36 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17631_none_05892a9284e42b37\wininet.dll
[2015/04/16 14:03:51 | 000,162,297 | ---- | M] () MD5=31E93A671DB46286530E39490BCDCB91 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17690_none_a970a792cc81386a\wininet.dll
[2014/11/18 12:29:26 | 000,429,069 | ---- | M] () MD5=379C8DAEF6ED0E80C87DF4FDD61B2C09 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17239_none_a995187ecc671745\wininet.dll
[2014/11/18 10:42:55 | 000,499,990 | ---- | M] () MD5=3B8170B7D017FE09186D8700B501CD48 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17239_none_05b3b40284c4887b\wininet.dll
[2015/05/16 11:47:12 | 000,239,417 | ---- | M] () MD5=45357D0C245C663DEF3CF18ADED0C7A7 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17728_none_a95e1f60cc907002\wininet.dll
[2015/08/14 20:54:04 | 000,282,034 | ---- | M] () MD5=47010C92B7B72D427EFF1502B2C70F23 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17905_none_05655ed084ff9989\wininet.dll
[2015/07/19 20:24:11 | 000,278,628 | ---- | M] () MD5=49ADDFFAB1D8EA9315823D2D66F0B187 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17842_none_0574743c84f39611\wininet.dll
[2014/11/18 12:29:12 | 000,427,483 | ---- | M] () MD5=519C645C1D27A7563C79CA890618B938 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17207_none_a9924530cc6997fe\wininet.dll
[2015/07/19 20:46:14 | 000,211,149 | ---- | M] () MD5=523FA1BC881932CAA8686B264BA3B814 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17842_none_a955d8b8cc9624db\wininet.dll
[2015/10/17 15:56:57 | 000,212,832 | ---- | M] () MD5=685A53313DA2CFE059DC854C145F2427 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.18036_none_05c99a1884b400dd\wininet.dll
[2015/05/16 11:28:19 | 000,318,756 | ---- | M] () MD5=74900A2ADA0D5347414E96EC3A270F8F -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17728_none_057cbae484ede138\wininet.dll
[2014/11/18 10:43:03 | 000,499,415 | ---- | M] () MD5=78A79794F4D389C45FFCDC55AE89DE58 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17351_none_05ab9aea84ca0a12\wininet.dll
[2014/11/18 12:29:40 | 000,430,337 | ---- | M] () MD5=8E40AAFEFDB9027AC0F38885EC30FEFF -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17351_none_a98cff66cc6c98dc\wininet.dll
[2015/09/13 11:09:00 | 000,228,404 | ---- | M] () MD5=96410BE4AD7B6203B26E615E086F7EBD -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17937_none_0568321e84fd18d0\wininet.dll
[2015/06/11 13:51:13 | 000,382,194 | ---- | M] () MD5=9DF188CA82BC185FABD3A4707CBD9895 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17801_none_057089dc84f71714\wininet.dll
[2015/02/12 16:35:31 | 000,059,876 | ---- | M] () MD5=B23BBE12AF200084BC77C83140046803 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17498_none_05a42cae84cf3ec6\wininet.dll
[2014/12/12 12:57:57 | 000,253,886 | ---- | M] () MD5=B2DC3CB5B3FAEB2C012BF1B22DBEFC6C -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17416_none_a97dbc6acc78cf96\wininet.dll
[2015/08/14 21:10:59 | 000,215,534 | ---- | M] () MD5=BBD7E73834068682F437EEB6186D53E8 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17905_none_a946c34ccca22853\wininet.dll
[2014/12/12 12:45:41 | 000,333,928 | ---- | M] () MD5=BDB363574A2F060164762ACBAEC5B613 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17416_none_059c57ee84d640cc\wininet.dll
[2015/06/11 14:05:34 | 000,286,789 | ---- | M] () MD5=D432C40F1EA5CF48D05503742240805B -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17801_none_a951ee58cc99a5de\wininet.dll
[2015/03/15 10:02:50 | 000,200,265 | ---- | M] () MD5=D594CB3F63B80335D5B7A9478C90C2AF -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17631_none_a96a8f0ecc86ba01\wininet.dll
[2015/09/10 19:31:21 | 002,011,136 | ---- | M] (Microsoft Corporation) MD5=D798AD4968F64AC7D80FFC1A7580ACD5 -- C:\Windows\SysWOW64\wininet.dll
[2015/09/10 19:31:21 | 002,011,136 | ---- | M] (Microsoft Corporation) MD5=D798AD4968F64AC7D80FFC1A7580ACD5 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.18053_none_a9ad4380cc547572\wininet.dll
[2015/10/17 19:17:53 | 000,190,941 | ---- | M] () MD5=D91594740AE26D36F47EBCBE573B6006 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.18036_none_a9aafe94cc568fa7\wininet.dll
[2015/02/12 16:44:41 | 000,003,879 | ---- | M] () MD5=DD9BB654041748399F4F03E4573A9EA8 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17498_none_a985912acc71cd90\wininet.dll
[2015/04/16 13:46:38 | 000,004,139 | ---- | M] () MD5=F3CE3F1A9A574391CFDD1CDAE092287E -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17690_none_058f431684dea9a0\wininet.dll
[2015/09/10 19:57:58 | 002,487,808 | ---- | M] (Microsoft Corporation) MD5=F6A075F2D69D9AFD14C6B79DF5C717D6 -- C:\WINDOWS\SysNative\wininet.dll
[2015/09/10 19:57:58 | 002,487,808 | ---- | M] (Microsoft Corporation) MD5=F6A075F2D69D9AFD14C6B79DF5C717D6 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.18053_none_05cbdf0484b1e6a8\wininet.dll
[2015/07/10 14:30:56 | 002,741,248 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\wininet.dll
[2015/07/10 14:30:56 | 002,741,248 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.10240.16384_none_4da1791f65f4f473\wininet.dll

[color=#A23BEC]< MD5 for: WININIT.EXE >[/color]
[2014/10/29 05:25:54 | 000,145,920 | ---- | M] (Microsoft Corporation) MD5=A570A64292214C43E0BA50E6A72A6380 -- C:\WINDOWS\SysNative\wininit.exe
[2014/10/29 05:25:54 | 000,145,920 | ---- | M] (Microsoft Corporation) MD5=A570A64292214C43E0BA50E6A72A6380 -- C:\Windows\WinSxS\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.3.9600.17415_none_21fdb3b5d80e199e\wininit.exe
[2015/03/13 08:06:38 | 000,026,215 | ---- | M] () MD5=DCF5C72FC1D8BE1165975F1339DC92DA -- C:\Windows\WinSxS\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.3.9600.16384_none_21b118d9d847ad16\wininit.exe
[2015/07/10 14:30:56 | 000,290,304 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\wininit.exe
[2015/07/10 14:30:56 | 000,290,304 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-wininit_31bf3856ad364e35_10.0.10240.16384_none_38f32a7d9efdf146\wininit.exe

[color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
[2015/03/13 08:06:42 | 000,100,951 | ---- | M] () MD5=A176623494AF009927242266EF51DCFB -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17031_none_60b45365a8c2ccdb\winlogon.exe
[2015/03/13 08:06:42 | 000,100,951 | ---- | M] () MD5=A176623494AF009927242266EF51DCFB -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17031_none_60b45365a8c2ccdb\winlogon.exe
[2015/10/05 12:48:32 | 000,893,752 | ---- | M] (MalwareBytes) MD5=E9A75E4B409A01E52055CE7CCA7FF925 -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
[2015/10/05 12:48:32 | 000,893,752 | ---- | M] (MalwareBytes) MD5=E9A75E4B409A01E52055CE7CCA7FF925 -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
[2014/10/29 05:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\WINDOWS\SysNative\winlogon.exe
[2014/10/29 05:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\WINDOWS\SysNative\winlogon.exe
[2014/10/29 05:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17415_none_60cdfbfda8aeeef1\winlogon.exe
[2014/10/29 05:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17415_none_60cdfbfda8aeeef1\winlogon.exe
[2015/07/10 14:30:56 | 000,578,048 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\winlogon.exe
[2015/07/10 14:30:56 | 000,578,048 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\winlogon.exe
[2015/07/10 14:30:56 | 000,578,048 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_10.0.10240.16384_none_77c372c56f9ec699\winlogon.exe
[2015/07/10 14:30:56 | 000,578,048 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_10.0.10240.16384_none_77c372c56f9ec699\winlogon.exe

[color=#A23BEC]< MD5 for: WS2_32.DLL >[/color]
[2014/10/29 07:05:15 | 000,321,248 | ---- | M] (Microsoft Corporation) MD5=34E71A52A1BFA68411CAECCFB6D72F8C -- C:\Windows\SysWOW64\ws2_32.dll
[2014/10/29 07:05:15 | 000,321,248 | ---- | M] (Microsoft Corporation) MD5=34E71A52A1BFA68411CAECCFB6D72F8C -- C:\Windows\WinSxS\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.17415_none_87a41025e9b6078a\ws2_32.dll
[2014/10/29 07:51:53 | 000,363,080 | ---- | M] (Microsoft Corporation) MD5=3A0B3B44C263DB1823360FF3E5C223CE -- C:\WINDOWS\SysNative\ws2_32.dll
[2014/10/29 07:51:53 | 000,363,080 | ---- | M] (Microsoft Corporation) MD5=3A0B3B44C263DB1823360FF3E5C223CE -- C:\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.17415_none_e3c2aba9a21378c0\ws2_32.dll
[2015/03/15 10:27:39 | 000,062,052 | ---- | M] () MD5=58D09EFD883813FC9709A9D98A7209DF -- C:\Windows\WinSxS\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.16384_none_87577549e9ef9b02\ws2_32.dll
[2015/03/13 08:04:32 | 000,065,749 | ---- | M] () MD5=F77C96590EA4741EB62B0FBC7A9FFFE8 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.16384_none_e37610cda24d0c38\ws2_32.dll
[2015/07/10 14:30:57 | 000,422,560 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\ws2_32.dll
[2015/07/10 14:30:57 | 000,422,560 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_10.0.10240.16384_none_fab8227169035068\ws2_32.dll

[color=#A23BEC]< HKEY_LOCAL_MACHINE\SYSTEM\Curr ?entControlSet\Control\Session Manager\SubSystems /s >[/color]

[color=#A23BEC]< %systemroot%\*. /mp /s >[/color]

[color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\system32\drivers\ ?*.sys /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\System32\config\* ?.sav >[/color]

[color=#A23BEC]< c:\$recycle.bin\*.* /s >[/color]
[2015/11/01 21:35:53 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2678595623-4148133582-4009595467-1003\$I87YONN
[2015/11/08 03:29:59 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2678595623-4148133582-4009595467-1003\$IAYUNAY.png
[2015/11/08 03:32:25 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2678595623-4148133582-4009595467-1003\$IJX0BXU.jpg
[2015/10/11 15:05:53 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2678595623-4148133582-4009595467-1003\$IQTY57J.pdf
[2014/11/07 16:51:07 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2678595623-4148133582-4009595467-1003\desktop.ini

< End of report >

Publicité


Signaler le contenu de ce document

Publicité