cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

ÿþOTL logfile created on: 02/12/2015 09:17:32 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\bruno\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18098)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

3,93 Gb Total Physical Memory | 1,02 Gb Available Physical Memory | 26,00% Memory free
5,00 Gb Paging File | 1,06 Gb Available in Paging File | 21,17% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 457,38 Gb Total Space | 93,97 Gb Free Space | 20,55% Space Free | Partition Type: NTFS
Drive D: | 457,38 Gb Total Space | 331,16 Gb Free Space | 72,40% Space Free | Partition Type: NTFS
Drive F: | 931,48 Gb Total Space | 624,77 Gb Free Space | 67,07% Space Free | Partition Type: NTFS
Drive G: | 4,03 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: BRUNO | User Name: bruno | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2015/12/02 09:14:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\bruno\Downloads\OTL.exe
PRC - [2015/12/02 09:06:24 | 001,712,360 | ---- | M] () -- C:\ProgramData\653ac11b-b606-42c5-b357-bca0fd28d1cd\plugins\2\Plugin.exe
PRC - [2015/12/02 09:06:24 | 001,010,408 | ---- | M] () -- C:\ProgramData\653ac11b-b606-42c5-b357-bca0fd28d1cd\plugins\12\Plugin.exe
PRC - [2015/12/02 09:06:24 | 000,844,008 | ---- | M] () -- C:\ProgramData\653ac11b-b606-42c5-b357-bca0fd28d1cd\plugins\4\Plugin.exe
PRC - [2015/12/02 09:06:24 | 000,603,880 | ---- | M] () -- C:\ProgramData\653ac11b-b606-42c5-b357-bca0fd28d1cd\plugins\3\Plugin.exe
PRC - [2015/12/02 09:06:23 | 001,250,536 | ---- | M] () -- C:\ProgramData\653ac11b-b606-42c5-b357-bca0fd28d1cd\plugins\8\Plugin.exe
PRC - [2015/12/02 09:06:22 | 000,708,840 | ---- | M] () -- C:\ProgramData\653ac11b-b606-42c5-b357-bca0fd28d1cd\plugins\5\Plugin.exe
PRC - [2015/12/02 09:06:22 | 000,447,208 | ---- | M] () -- C:\ProgramData\653ac11b-b606-42c5-b357-bca0fd28d1cd\plugins\10\Plugin.exe
PRC - [2015/12/02 09:06:21 | 000,457,448 | ---- | M] () -- C:\ProgramData\653ac11b-b606-42c5-b357-bca0fd28d1cd\plugins\7\Plugin.exe
PRC - [2015/12/02 09:06:20 | 000,541,928 | ---- | M] () -- C:\Program Files (x86)\Common Files\653ac11b-b606-42c5-b357-bca0fd28d1cd\updater.exe
PRC - [2015/11/28 13:08:44 | 000,636,136 | ---- | M] () -- C:\ProgramData\653ac11b-b606-42c5-b357-bca0fd28d1cd\plugincontainer.exe
PRC - [2015/11/25 14:02:33 | 000,186,760 | ---- | M] () -- C:\Program Files (x86)\Photodex\ProShow Producer\scsiaccess.exe
PRC - [2015/11/07 05:36:36 | 000,811,848 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2015/11/04 14:07:52 | 000,065,752 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
PRC - [2015/11/04 07:13:54 | 009,626,328 | ---- | M] (Acer Cloud Technology) -- C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
PRC - [2015/11/04 07:04:59 | 002,860,760 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
PRC - [2015/10/12 08:28:44 | 001,433,216 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2015/10/12 08:28:42 | 001,773,696 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2015/10/08 18:14:01 | 000,336,896 | ---- | M] (BitTorrent Inc.) -- C:\Users\bruno\AppData\Roaming\uTorrent\updates\3.4.5_41202\utorrentie.exe
PRC - [2015/10/08 17:21:18 | 001,822,048 | ---- | M] (BitTorrent Inc.) -- C:\Users\bruno\AppData\Roaming\uTorrent\uTorrent.exe
PRC - [2015/09/17 13:27:19 | 000,245,576 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe
PRC - [2015/08/04 10:17:40 | 000,394,280 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe
PRC - [2015/07/21 22:39:28 | 000,349,728 | ---- | M] (WildTangent) -- C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
PRC - [2015/06/29 17:47:44 | 000,134,512 | ---- | M] (Dropbox, Inc.) -- C:\Users\bruno\AppData\Local\Dropbox\Update\DropboxUpdate.exe
PRC - [2014/10/29 02:05:25 | 000,315,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cmd.exe
PRC - [2014/03/25 12:33:28 | 000,991,848 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE
PRC - [2014/03/25 12:33:22 | 001,089,112 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
PRC - [2014/03/25 12:33:20 | 001,284,680 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
PRC - [2013/08/22 10:24:10 | 000,525,896 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
PRC - [2013/08/19 19:12:02 | 000,390,616 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2013/08/19 19:11:58 | 000,131,544 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
PRC - [2013/08/19 19:11:56 | 000,169,432 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
PRC - [2013/08/09 13:20:48 | 000,414,496 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012/10/23 09:25:06 | 002,744,960 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
PRC - [2012/07/14 00:27:00 | 000,769,432 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2015/12/02 09:06:24 | 001,010,408 | ---- | M] () -- C:\ProgramData\653ac11b-b606-42c5-b357-bca0fd28d1cd\plugins\12\Plugin.exe
MOD - [2015/12/02 09:06:24 | 000,603,880 | ---- | M] () -- C:\ProgramData\653ac11b-b606-42c5-b357-bca0fd28d1cd\plugins\3\Plugin.exe
MOD - [2015/12/02 09:06:24 | 000,511,720 | ---- | M] () -- C:\Users\bruno\AppData\Local\Temp\{1190486C-09DE-4171-9781-084236FEE458}.dll
MOD - [2015/12/02 09:06:21 | 000,457,448 | ---- | M] () -- C:\ProgramData\653ac11b-b606-42c5-b357-bca0fd28d1cd\plugins\7\Plugin.exe
MOD - [2015/11/26 10:14:08 | 000,015,064 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\MyService\1.0.0.1__2dfa3f50f0bed57d\MyService.dll
MOD - [2015/11/24 11:10:50 | 000,188,416 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\c8849d6fd3bee972ec451baea15949ca\UIAutomationTypes.ni.dll
MOD - [2015/11/16 19:56:54 | 000,654,000 | ---- | M] () -- C:\Program Files (x86)\Acer\abPhoto\sqlite3.dll
MOD - [2015/11/16 19:56:54 | 000,641,240 | ---- | M] () -- C:\Program Files (x86)\Acer\abPhoto\tag.dll
MOD - [2015/11/16 19:56:18 | 000,119,000 | ---- | M] () -- C:\Program Files (x86)\Acer\abPhoto\openldap.dll
MOD - [2015/11/16 19:55:12 | 000,202,456 | ---- | M] () -- C:\Program Files (x86)\Acer\abPhoto\curllib.dll
MOD - [2015/11/12 19:19:52 | 012,438,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\9b1531097c798aa059b87e8bff3f5591\System.Windows.Forms.ni.dll
MOD - [2015/11/12 19:11:28 | 007,787,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\9a349fb029581f4752d2c6cfcfeab816\System.Xml.ni.dll
MOD - [2015/11/12 19:11:25 | 001,873,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\d626184834dde3f4906aff139d4e5bbf\System.Xaml.ni.dll
MOD - [2015/11/12 19:11:24 | 012,897,280 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\4ee7f7e41d916e3f4ffa520ff42bdbd4\System.Windows.Forms.ni.dll
MOD - [2015/11/12 19:11:05 | 000,797,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\acb544a8de396ac6ada306f1480bebff\System.Runtime.Remoting.ni.dll
MOD - [2015/11/12 19:11:03 | 001,639,936 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\c98b70fea45b348a5283fad4dfa4b220\System.Drawing.ni.dll
MOD - [2015/11/12 19:06:11 | 000,967,680 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\d9961946cc4b6fb67e19cd2f8ce90a76\System.Configuration.ni.dll
MOD - [2015/11/12 19:06:11 | 000,463,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatioaec034ca#\e09d73263866a3b0472fd3a4d9aaccae\PresentationFramework.Aero2.ni.dll
MOD - [2015/11/12 19:06:10 | 018,753,024 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\2f55a37d0019f1ae3660755f160d73da\PresentationFramework.ni.dll
MOD - [2015/11/12 19:06:01 | 011,014,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\8cb954738fb5d385430c075e24483e71\PresentationCore.ni.dll
MOD - [2015/11/12 19:05:55 | 003,904,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\579202ba970d73dae32cc3a5c68af8e2\WindowsBase.ni.dll
MOD - [2015/11/12 19:05:51 | 006,982,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\257fa713928375c0ac9b9f24904e988f\System.Core.ni.dll
MOD - [2015/11/12 19:05:47 | 010,069,504 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\1a6b5095c4416a37f9ca4cf4436d1311\System.ni.dll
MOD - [2015/11/07 05:36:35 | 016,496,456 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\PepperFlash\pepflashplayer.dll
MOD - [2015/11/07 05:36:33 | 001,532,744 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libglesv2.dll
MOD - [2015/11/07 05:36:32 | 000,081,224 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\libegl.dll
MOD - [2015/11/04 14:07:52 | 000,013,016 | ---- | M] () -- C:\Program Files (x86)\Acer\AOP Framework\ServiceInterface.dll
MOD - [2015/11/04 14:01:22 | 000,277,856 | ---- | M] () -- C:\Program Files (x86)\Acer\AOP Framework\libcurl.dll
MOD - [2015/09/17 18:04:28 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\159c1674c74e3372bda64afddf88cb3b\System.Drawing.ni.dll
MOD - [2014/10/16 20:11:20 | 007,995,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\4976746d2f27ea6b60301a84d6c3e4be\System.ni.dll
MOD - [2014/08/31 10:42:32 | 011,500,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\5bd3374f05d46ba0563f44d032209f08\mscorlib.ni.dll
MOD - [2014/04/16 00:34:56 | 017,223,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\d03a3ddcd6a395878751c5e90fa16915\mscorlib.ni.dll
MOD - [2014/03/29 01:28:05 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_fr_b77a5c561934e089\mscorlib.resources.dll
MOD - [2013/07/30 18:11:44 | 000,088,648 | ---- | M] () -- C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext.dll
MOD - [2011/09/07 10:43:32 | 000,042,280 | ---- | M] () -- C:\Program Files (x86)\Hercules\Hercules HD Sunset\x86\WebCamKSProxyPlugin.ax


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2015/09/28 13:38:54 | 000,783,120 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MSC\McAPExe.exe -- (McAPExe)
SRV:[b]64bit:[/b] - [2015/09/01 21:40:40 | 000,368,584 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (MSK80Service)
SRV:[b]64bit:[/b] - [2015/09/01 21:40:40 | 000,368,584 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe -- (McProxy)
SRV:[b]64bit:[/b] - [2015/09/01 21:40:40 | 000,368,584 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe -- (mcpltsvc)
SRV:[b]64bit:[/b] - [2015/09/01 21:40:40 | 000,368,584 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe -- (McOobeSv2)
SRV:[b]64bit:[/b] - [2015/09/01 21:40:40 | 000,368,584 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV:[b]64bit:[/b] - [2015/09/01 21:40:40 | 000,368,584 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV:[b]64bit:[/b] - [2015/09/01 21:40:40 | 000,368,584 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (HomeNetSvc)
SRV:[b]64bit:[/b] - [2015/09/01 12:11:02 | 001,694,152 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\CSP\1.6.1180.0\McCSPServiceHost.exe -- (mccspsvc)
SRV:[b]64bit:[/b] - [2015/08/11 18:19:50 | 000,639,456 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\mcafee\VirusScan\mcods.exe -- (McODS)
SRV:[b]64bit:[/b] - [2015/08/10 18:18:42 | 000,376,264 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe -- (mfemms)
SRV:[b]64bit:[/b] - [2015/07/31 12:33:48 | 000,254,792 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)
SRV:[b]64bit:[/b] - [2015/07/31 12:30:48 | 000,232,656 | ---- | M] () [On_Demand | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV:[b]64bit:[/b] - [2015/07/22 14:52:08 | 001,633,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:[b]64bit:[/b] - [2015/07/16 19:58:34 | 000,074,752 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:[b]64bit:[/b] - [2015/07/07 10:39:32 | 000,366,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:[b]64bit:[/b] - [2015/07/07 10:39:32 | 000,023,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2015/05/30 20:36:24 | 000,230,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2015/05/12 14:19:37 | 000,294,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:[b]64bit:[/b] - [2015/05/07 16:21:51 | 000,522,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:[b]64bit:[/b] - [2015/02/21 00:49:18 | 000,780,800 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:[b]64bit:[/b] - [2014/10/31 05:51:25 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2014/10/29 04:59:51 | 003,460,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:[b]64bit:[/b] - [2014/10/29 04:50:12 | 002,987,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:[b]64bit:[/b] - [2014/10/29 03:42:19 | 000,026,112 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:[b]64bit:[/b] - [2014/10/29 03:42:03 | 000,041,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:[b]64bit:[/b] - [2014/10/29 03:34:51 | 000,067,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:[b]64bit:[/b] - [2014/10/29 03:33:55 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:[b]64bit:[/b] - [2014/10/29 03:29:22 | 000,121,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:[b]64bit:[/b] - [2014/10/29 02:57:05 | 000,324,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\BthHFSrv.dll -- (BthHFSrv)
SRV:[b]64bit:[/b] - [2014/10/29 02:48:20 | 000,166,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:[b]64bit:[/b] - [2014/10/29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:[b]64bit:[/b] - [2014/10/29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:[b]64bit:[/b] - [2014/10/29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:[b]64bit:[/b] - [2014/10/29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:[b]64bit:[/b] - [2014/10/29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:[b]64bit:[/b] - [2014/10/29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:[b]64bit:[/b] - [2014/10/29 02:43:27 | 000,524,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:[b]64bit:[/b] - [2014/10/29 02:27:21 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:[b]64bit:[/b] - [2014/10/29 02:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:[b]64bit:[/b] - [2014/10/29 02:24:37 | 000,131,072 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:[b]64bit:[/b] - [2014/10/29 02:22:40 | 000,062,464 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2014/10/29 02:20:03 | 000,262,656 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:[b]64bit:[/b] - [2014/10/29 02:19:20 | 000,550,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2014/10/29 02:16:17 | 000,154,112 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:[b]64bit:[/b] - [2014/10/29 02:13:24 | 000,374,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:[b]64bit:[/b] - [2014/10/29 02:13:02 | 000,260,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:[b]64bit:[/b] - [2014/10/29 02:12:36 | 000,407,040 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:[b]64bit:[/b] - [2014/10/29 02:12:22 | 000,270,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:[b]64bit:[/b] - [2014/10/29 02:11:10 | 001,639,424 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:[b]64bit:[/b] - [2014/10/29 02:05:09 | 000,206,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:[b]64bit:[/b] - [2014/10/29 01:48:52 | 000,562,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:[b]64bit:[/b] - [2014/10/29 01:46:48 | 001,348,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:[b]64bit:[/b] - [2014/10/29 01:35:51 | 001,668,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:[b]64bit:[/b] - [2013/05/11 17:45:54 | 000,822,232 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2013/05/11 17:45:38 | 000,733,696 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
SRV - [2015/12/02 09:06:20 | 000,541,928 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\653ac11b-b606-42c5-b357-bca0fd28d1cd\updater.exe -- (Update Mgr DiscoveryApp)
SRV - [2015/11/28 13:08:44 | 000,636,136 | ---- | M] () [Auto | Running] -- C:\ProgramData\653ac11b-b606-42c5-b357-bca0fd28d1cd\plugincontainer.exe -- (Service Mgr DiscoveryApp)
SRV - [2015/11/25 14:02:33 | 000,186,760 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Photodex\ProShow Producer\scsiaccess.exe -- (ScsiAccess)
SRV - [2015/11/04 07:04:59 | 002,860,760 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe -- (CCDMonitorService)
SRV - [2015/10/12 08:28:44 | 001,433,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2015/10/12 08:28:42 | 001,773,696 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2015/08/04 10:19:38 | 000,155,368 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe -- (McAfee SiteAdvisor Service)
SRV - [2015/07/21 22:39:32 | 000,209,952 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2015/07/21 22:39:28 | 000,349,728 | ---- | M] (WildTangent) [Auto | Running] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe -- (GamesAppIntegrationService)
SRV - [2015/07/09 12:14:04 | 000,327,296 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2015/05/07 16:05:40 | 000,367,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2014/10/29 04:50:12 | 002,987,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2014/10/29 02:51:55 | 000,017,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2014/10/29 02:04:45 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2013/08/19 19:12:02 | 000,390,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2013/08/19 19:11:58 | 000,131,544 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe -- (Intel(R)
SRV - [2013/08/19 19:11:56 | 000,169,432 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -- (jhi_service)
SRV - [2013/08/09 13:20:48 | 000,414,496 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2013/08/01 22:31:10 | 004,278,112 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2013/07/25 02:21:46 | 000,334,608 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- c:\PROGRA~1\COMMON~1\mcafee\actwiz\mcawfwk.exe -- (McAWFwk)
SRV - [2012/07/14 00:27:00 | 000,769,432 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2015/09/29 13:24:42 | 000,155,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2015/09/10 13:24:04 | 000,095,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d)
DRV:[b]64bit:[/b] - [2015/08/12 22:28:26 | 000,537,408 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfencbdc.sys -- (mfencbdc)
DRV:[b]64bit:[/b] - [2015/08/12 22:28:26 | 000,111,256 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mfencrk.sys -- (mfencrk)
DRV:[b]64bit:[/b] - [2015/08/10 13:38:44 | 000,839,376 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:[b]64bit:[/b] - [2015/08/10 13:38:44 | 000,495,856 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)
DRV:[b]64bit:[/b] - [2015/08/10 13:38:44 | 000,413,432 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeaack.sys -- (mfeaack)
DRV:[b]64bit:[/b] - [2015/08/10 13:38:44 | 000,349,096 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:[b]64bit:[/b] - [2015/08/10 13:38:44 | 000,244,024 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
DRV:[b]64bit:[/b] - [2015/08/10 13:38:44 | 000,082,072 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mfeelamk.sys -- (mfeelamk)
DRV:[b]64bit:[/b] - [2015/08/10 13:38:44 | 000,080,768 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)
DRV:[b]64bit:[/b] - [2015/07/07 10:40:12 | 000,044,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:[b]64bit:[/b] - [2015/07/07 10:40:05 | 000,270,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:[b]64bit:[/b] - [2015/07/07 10:40:05 | 000,114,520 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:[b]64bit:[/b] - [2015/05/19 13:59:02 | 000,207,208 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HipShieldK.sys -- (HipShieldK)
DRV:[b]64bit:[/b] - [2015/04/16 07:17:07 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:[b]64bit:[/b] - [2015/03/20 02:56:10 | 000,080,384 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:[b]64bit:[/b] - [2015/03/17 18:26:06 | 000,467,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:[b]64bit:[/b] - [2015/03/13 05:03:31 | 000,239,424 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2015/03/09 03:02:51 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:[b]64bit:[/b] - [2015/03/04 11:25:11 | 000,377,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:[b]64bit:[/b] - [2014/11/16 14:36:19 | 000,034,512 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\debutfilterx64.sys -- (debutfilter)
DRV:[b]64bit:[/b] - [2014/11/10 19:06:59 | 000,136,512 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:[b]64bit:[/b] - [2014/10/29 04:59:47 | 000,415,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:[b]64bit:[/b] - [2014/10/29 04:57:42 | 000,054,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:[b]64bit:[/b] - [2014/10/29 04:56:04 | 000,027,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2014/10/29 03:47:48 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDScan.sys -- (WSDScan)
DRV:[b]64bit:[/b] - [2014/10/29 03:46:43 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2014/10/29 03:46:09 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:[b]64bit:[/b] - [2014/10/29 03:45:54 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:[b]64bit:[/b] - [2014/10/29 03:45:39 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:[b]64bit:[/b] - [2014/10/29 03:45:16 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:[b]64bit:[/b] - [2014/10/15 09:32:36 | 000,921,920 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\refs.sys -- (ReFS)
DRV:[b]64bit:[/b] - [2014/10/13 03:43:17 | 000,086,336 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:[b]64bit:[/b] - [2014/10/13 03:43:17 | 000,039,744 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:[b]64bit:[/b] - [2014/10/07 07:54:45 | 000,189,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:[b]64bit:[/b] - [2014/10/07 07:44:39 | 000,069,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:[b]64bit:[/b] - [2014/08/15 01:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:[b]64bit:[/b] - [2014/05/24 16:32:47 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:[b]64bit:[/b] - [2014/03/13 13:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\wof.sys -- (Wof)
DRV:[b]64bit:[/b] - [2014/02/22 16:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:[b]64bit:[/b] - [2014/02/22 13:14:02 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:[b]64bit:[/b] - [2014/01/22 07:52:12 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudserd.sys -- (ssudserd)
DRV:[b]64bit:[/b] - [2014/01/22 07:52:10 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:[b]64bit:[/b] - [2014/01/22 07:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:[b]64bit:[/b] - [2013/10/26 02:54:32 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:[b]64bit:[/b] - [2013/10/05 16:25:54 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:[b]64bit:[/b] - [2013/09/14 15:06:57 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:[b]64bit:[/b] - [2013/08/22 20:11:03 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2013/08/22 14:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:[b]64bit:[/b] - [2013/08/22 14:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2013/08/22 13:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:[b]64bit:[/b] - [2013/08/22 13:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:[b]64bit:[/b] - [2013/08/22 13:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:[b]64bit:[/b] - [2013/08/22 13:40:24 | 000,040,664 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:[b]64bit:[/b] - [2013/08/22 13:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:[b]64bit:[/b] - [2013/08/22 13:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:[b]64bit:[/b] - [2013/08/22 12:39:58 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:[b]64bit:[/b] - [2013/08/22 12:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:[b]64bit:[/b] - [2013/08/22 12:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:[b]64bit:[/b] - [2013/08/22 12:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:[b]64bit:[/b] - [2013/08/22 12:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:[b]64bit:[/b] - [2013/08/22 12:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:[b]64bit:[/b] - [2013/08/22 12:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:[b]64bit:[/b] - [2013/08/22 12:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:[b]64bit:[/b] - [2013/08/22 12:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:[b]64bit:[/b] - [2013/08/22 12:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:[b]64bit:[/b] - [2013/08/22 12:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:[b]64bit:[/b] - [2013/08/22 12:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:[b]64bit:[/b] - [2013/08/22 12:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2013/08/22 12:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:[b]64bit:[/b] - [2013/08/22 12:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2013/08/22 12:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:[b]64bit:[/b] - [2013/08/22 09:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:[b]64bit:[/b] - [2013/08/19 19:11:56 | 000,099,288 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TeeDriverx64.sys -- (MEIx64)
DRV:[b]64bit:[/b] - [2013/08/13 00:25:46 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:[b]64bit:[/b] - [2013/08/10 01:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:[b]64bit:[/b] - [2013/08/08 09:27:54 | 000,329,944 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsUVStor.sys -- (RSUSBVSTOR)
DRV:[b]64bit:[/b] - [2013/07/30 19:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:[b]64bit:[/b] - [2013/07/30 02:24:22 | 000,150,104 | R--- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NARAx64\0405000.009\ccSetx64.sys -- (ccSet_NARA)
DRV:[b]64bit:[/b] - [2013/07/25 20:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:[b]64bit:[/b] - [2013/07/19 07:50:56 | 000,029,912 | ---- | M] (Realtek semiconductor corp) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\RtkIOAC60.sys -- (RtkIOAC60)
DRV:[b]64bit:[/b] - [2013/06/21 10:35:14 | 000,816,344 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
DRV:[b]64bit:[/b] - [2013/06/16 11:08:16 | 000,196,384 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:[b]64bit:[/b] - [2012/08/22 22:49:24 | 000,025,088 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cdrombus.sys -- (cdrombus)
DRV:[b]64bit:[/b] - [2011/07/07 12:09:04 | 002,754,432 | ---- | M] (NTK) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvtcam.sys -- (DCamUSBNovatek)
DRV:[b]64bit:[/b] - [2009/06/04 10:34:40 | 000,065,024 | ---- | M] (Guillemot Corp S.A.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\guillflt.sys -- (guillflt)
DRV:[b]64bit:[/b] - [2009/02/09 00:43:10 | 000,111,104 | ---- | M] (Guillemot Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hxctlflt.sys -- (hxctlflt)
DRV:[b]64bit:[/b] - [2005/09/23 21:18:34 | 000,261,120 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MarvinBus64.sys -- (MarvinBus)
DRV - [2015/08/04 10:20:20 | 000,037,960 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys -- (mfesapsn)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{28315CA3-561C-4A21-A3B0-9E473B29F6FA}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45}: "URL" = http://www.palikan.com/results.php?f=4&q={searchTerms}&a=plk_nxtad_15_48&cd=2XzuyEtN2Y1L1QzuyEyEzz0AyD0Bzzzy0A0DzzzytAyD0E0AtN0D0Tzu0StCyEtByEtN1L2XzutAtFtCyEtFtDtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StDzy0FtCyBtDtB0CtGyB0FyE0BtG0AtDyE0BtGyCtC0D0DtG0FyE0E0CyC0FtD0CtA0E0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0ByEyEtC0A0CyEtGtAzy0E0EtGyEyBtDyEtG0A0EyEtAtG0E0AyBzztB0B0B0C0EyCtBtC2QtN0A0LzutB&cr=646630259&ir=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{28315CA3-561C-4A21-A3B0-9E473B29F6FA}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.safefinder.com/?p=mKO_AwFzXIpYRaHp0IaqUJWvWn0uApsGfZndsXQvtnYy108FY94uYcmMFyUC7lJ6_Z8onmTufxbIeb_15FmXIcCKFxTLLNklj0HIuM7YZbnpbkBliJVy0OOajl9Dt7_45A33yK2oUPe9TwDTiY59sJe7f7i_gEDuQKuE2J4JxPYuHu1jf-1hMQYa9S2TtksIoRe7sVNEY6M3LN4xYkIorCfnMo68F8g,&q={searchTerms}
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.safefinder.com/?p=mKO_AwFzXIpYRaHp0IaqUJWvWn0uApsGfZndsXQvtnYy108FY94uYcmMFyUC7lJ6_Z8onmTufxbIeb_15FmXIcCKFxTLLNklj0HIuM7YZbnpbkBliJVy0OOajl9Dt7_45A33yK2oUPe9TwDTiY59sJe7f7i_gEDuQKuE2J4JxPYuHu1jf-1hMQYa9S2TtksIoRe7sVNEY6M3LN4xYkIorCfnMo68F8g,&q={searchTerms}
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.safefinder.com/?p=mKO_AwFzXIpYRaHp0IaqUJWvWn0uApsGfZndsXQvtnYy108FY94uYcmMFyUC7lJ6_Z8onmTufxbIeb_15FmXIcCKFxTLLNklj0HIuM7YZbnpbkBliJVy0OOajl9Dt7_45A33yK2oUPe9TwDTiY59sJe7f7i_gEDuQKuE2J4JxPYuHu1jf-1hMQYa9S2TtksIoRe7sVNEY6M3LN4xYkIorCfnMo68F8g,&q={searchTerms}
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.safefinder.com/?p=mKO_AwFzXIpYRaHp0IaqUJWvWn0uApsGfZndsXQvtnYy108FY94uYcmMFyUC7lJ6_Z8onmTufxbIeb_15FmXIcCKFxTLLNklj0HIuM7YZbnpbkBliJVy0OOajl9Dt7_45A33yK2oUPe9TwDTiY59sJe7f7i_gEDuQKuE2J4JxPYuHu1jf-1hMQYa9S2TtksIoRe7sVNEY6M3LN4xYkIorCfnMo68F8g,&q={searchTerms}
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.safefinder.com/?p=mKO_AwFzXIpYRaHp0IaqUJWvWn0uApsGfZndsXQvtnYy108FY94uYcmMFyUC7lJ6_Z8onmTufxbIeb_15FmXIcCKFxTLLNklj0HIuM7YZbnpbkBliJVy0OOajl9Dt7_45A33yK2oUPe9TwDTiY59sJe7f7i_gEDuQKuE2J4JxPYuHu1jf-1hMQYa9S2TtksIoRe7sVNEY6M3LN4xYkIorCfnMo68F8g,&q={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <-loopback>
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:49424;https=127.0.0.1:49424

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.safefinder.com/?p=mKO_AwFzXIpYRaHp0IaqUJWvWn0uApsGfZndsXQvtnYy108FY94uYcmMFyUC7lJ6_Z8onmTufxbIeb_15FmXIcCKFxTLLNklj0HIuM7YZbnpbkBliJVy0OOajl9Dt7_45A33yK2oUPe9TwDTiY59sJe7f7i_gEDuQKuE2J4JxPYuHu1jf-1hMQYa9S2TtksIoRe7sVNEY6M3LN4xYkIorCfnMo68F8g,&q={searchTerms}
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.safefinder.com/?p=mKO_AwFzXIpYRaHp0IaqUJWvWn0uApsGfZndsXQvtnYy108FY94uYcmMFyUC7lJ6_Z8onmTufxbIeb_15FmXIcCKFxTLLNklj0HIuM7YZbnpbkBliJVy0OOajl9Dt7_45A33yK2oUPe9TwDTiY59sJe7f7i_gEDuQKuE2J4JxPYuHu1jf-1hMQYa9S2TtksIoRe7sVNEY6M3LN4xYkIorCfnMo68F8g,&q={searchTerms}
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.safefinder.com/?p=mKO_AwFzXIpYRaHp0IaqUJWvWn0uApsGfZndsXQvtnYy108FY94uYcmMFyUC7lJ6_Z8onmTufxbIeb_15FmXIcCKFxTLLNklj0HIuM7YZbnpbkBliJVy0OOajl9Dt7_45A33yK2oUPe9TwDTiY59sJe7f7i_gEDuQKuE2J4JxPYuHu1jf-1hMQYa9S2TtksIoRe7sVNEY6M3LN4xYkIorCfnMo68F8g,&q={searchTerms}
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.safefinder.com/?p=mKO_AwFzXIpYRaHp0IaqUJWvWn0uApsGfZndsXQvtnYy108FY94uYcmMFyUC7lJ6_Z8onmTufxbIeb_15FmXIcCKFxTLLNklj0HIuM7YZbnpbkBliJVy0OOajl9Dt7_45A33yK2oUPe9TwDTiY59sJe7f7i_gEDuQKuE2J4JxPYuHu1jf-1hMQYa9S2TtksIoRe7sVNEY6M3LN4xYkIorCfnMo68F8g,&q={searchTerms}
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.safefinder.com/?p=mKO_AwFzXIpYRaHp0IaqUJWvWn0uApsGfZndsXQvtnYy108FY94uYcmMFyUC7lJ6_Z8onmTufxbIeb_15FmXIcCKFxTLLNklj0HIuM7YZbnpbkBliJVy0OOajl9Dt7_45A33yK2oUPe9TwDTiY59sJe7f7i_gEDuQKuE2J4JxPYuHu1jf-1hMQYa9S2TtksIoRe7sVNEY6M3LN4xYkIorCfnMo68F8g,&q={searchTerms}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <-loopback>
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:49424;https=127.0.0.1:49424

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\..\SearchScopes,DefaultScope = {79899F7B-E429-4B49-A98A-79572E7880C9}
IE - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\..\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45}: "URL" = http://www.palikan.com/results.php?f=4&q={searchTerms}&a=plk_nxtad_15_48&cd=2XzuyEtN2Y1L1QzuyEyEzz0AyD0Bzzzy0A0DzzzytAyD0E0AtN0D0Tzu0StCyEtByEtN1L2XzutAtFtCyEtFtDtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StDzy0FtCyBtDtB0CtGyB0FyE0BtG0AtDyE0BtGyCtC0D0DtG0FyE0E0CyC0FtD0CtA0E0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0ByEyEtC0A0CyEtGtAzy0E0EtGyEyBtDyEtG0A0EyEtAtG0E0AyBzztB0B0B0C0EyCtBtC2QtN0A0LzutB&cr=646630259&ir=
IE - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\..\SearchScopes\{79899F7B-E429-4B49-A98A-79572E7880C9}: "URL" = http://www.palikan.com/results.php?f=4&q={searchTerms}&a=plk_nxtad_15_48&cd=2XzuyEtN2Y1L1QzuyEyEzz0AyD0Bzzzy0A0DzzzytAyD0E0AtN0D0Tzu0StCyEtByEtN1L2XzutAtFtCyEtFtDtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2SyByB0CyDyDyDyC0BtGtD0BtByEtG0AtAtD0BtGtA0B0CzztGyByB0A0DtAtBtD0B0C0CyCtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0ByEyEtC0A0CyEtGtAzy0E0EtGyEyBtDyEtG0A0EyEtAtG0E0AyBzztB0B0B0C0EyCtBtC2QtN0A0LzutB&cr=1181405146&ir=
IE - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\..\SearchScopes\{C46192DC-D642-494B-A7C1-1AD49121E1CC}: "URL" = http://www.dregol.com/results.php?f=4&q={searchTerms}&a=drg_mlvi_15_24&cd=2XzuyEtN2Y1L1QzuyEyEzz0AyD0Bzzzy0A0DzzzytAyD0E0AtN0D0Tzu0StCtByDyEtN1L2XzutAtFtCtCtFtAtFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyCtA0B0E0D0FyD0DtGtByCyDtCtGyEyE0E0EtGtC0Azy0DtGtCzy0DyEyB0DtD0ByDyDtBzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0ByEyEtC0A0CyEtGtAzy0E0EtGyEyBtDyEtG0A0EyEtAtG0E0AyBzztB0B0B0C0EyCtBtC2QtN0A0LzutBtN1B2Z1V1T1S1NzuzztCtB&cr=1227800834&ir=
IE - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <-loopback>


[color=#E56717]========== FireFox ==========[/color]

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Web Player Plug-In,version=1.0.0: C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@photodex.com/PhotodexPresenter: C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll ( )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\bruno\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\bruno\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\bruno\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\bruno\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\bruno\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR [2015/08/30 10:22:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2015/08/30 10:22:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK [2015/10/29 17:08:43 | 000,000,000 | ---D | M]

[2015/03/31 09:23:14 | 000,034,072 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll

[color=#E56717]========== Chrome ==========[/color]

CHR - Extension: No name found = C:\Users\bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.9.4_0\
CHR - Extension: No name found = C:\Users\bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\
CHR - Extension: No name found = C:\Users\bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\4.0.0.0_0\
CHR - Extension: No name found = C:\Users\bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.1_0\
CHR - Extension: No name found = C:\Users\bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\iomcldcjbbobnjdjfiabhnkonmijgbpc\1.0.5805.20617_0\
CHR - Extension: No name found = C:\Users\bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\iomcldcjbbobnjdjfiabhnkonmijgbpc\1.0.5811.20675_0\
CHR - Extension: No name found = C:\Users\bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.2.0_0\
CHR - Extension: No name found = C:\Users\bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\

O1 HOSTS File: ([2013/08/22 14:25:41 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O2:[b]64bit:[/b] - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Glass Bottle) - {88803a01-4125-443b-b869-4062a160ceea} - C:\Program Files (x86)\Glass Bottle\Extensions\88803a01-4125-443b-b869-4062a160ceea.dll File not found
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Discovery App) - {ba32987d-db80-4ccb-a8bb-f812b5421c0f} - C:\Program Files (x86)\Discovery App\Extensions\ba32987d-db80-4ccb-a8bb-f812b5421c0f.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:[b]64bit:[/b] - HKLM..\Run: [CamserviceHDSunset] C:\Program Files (x86)\Hercules\Hercules HD Sunset\XtrCtrlEx.exe (Guillemot Corporation S.A.)
O4:[b]64bit:[/b] - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [abDocsDllLoader] C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe ()
O4 - HKLM..\Run: [CanonQuickMenu] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [fst_fr_311] File not found
O4 - HKLM..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Wondershare)
O4 - HKU\.DEFAULT..\Run: [abDocsDllLoader] C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe ()
O4 - HKU\S-1-5-18..\Run: [abDocsDllLoader] C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe ()
O4 - HKU\S-1-5-21-2179158368-4115444144-449989576-1001..\Run: [AcerPortal] C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe (Acer)
O4 - HKU\S-1-5-21-2179158368-4115444144-449989576-1001..\Run: [DAEMON Tools Pro Agent] C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-2179158368-4115444144-449989576-1001..\Run: [Dropbox Update] C:\Users\bruno\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc.)
O4 - HKU\S-1-5-21-2179158368-4115444144-449989576-1001..\Run: [GoogleChromeAutoLaunch_10A63B38CABCDC204E32EFA551673D7B] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKU\S-1-5-21-2179158368-4115444144-449989576-1001..\Run: [GoogleChromeAutoLaunch_D67B6E9C7DCDD0C293E6687C8BB1FC9B] C:\Users\bruno\AppData\Local\Chromium\Application\chrome.exe (The Chromium Authors)
O4 - HKU\S-1-5-21-2179158368-4115444144-449989576-1001..\Run: [Spotify Web Helper] C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-2179158368-4115444144-449989576-1001..\Run: [uTorrent] C:\Users\bruno\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O4 - Startup: C:\Users\bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\bruno\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Database Manager.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O7 - HKU\S-1-5-21-2179158368-4115444144-449989576-1001\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O8:[b]64bit:[/b] - Extra context menu item: &Envoyer à OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105 File not found
O8:[b]64bit:[/b] - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: &Envoyer à OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000 File not found
O9:[b]64bit:[/b] - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{851C1639-84A9-464F-A95C-7282616F255D}: DhcpNameServer = 192.168.1.254
O18:[b]64bit:[/b] - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:[b]64bit:[/b] - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~1\mcafee\msc\MCSNIE~1.DLL (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
O20 - AppInit_DLLs: (C:/PROGRA~3/{F1BD1~1/mome.dll) - C:/PROGRA~3/{F1BD1~1/mome.dll ()
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2014/10/08 17:37:32 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2014/02/25 04:12:57 | 000,000,000 | ---D | M] - F:\autorun -- [ NTFS ]
O32 - AutoRun File - [2012/11/02 21:39:44 | 000,000,059 | ---- | M] () - F:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010/06/24 15:51:57 | 000,000,075 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{41d59314-e5a3-11e4-8301-448a5b89ad89}\Shell - "" = AutoRun
O33 - MountPoints2\{41d59314-e5a3-11e4-8301-448a5b89ad89}\Shell\AutoRun\command - "" = "F:\.\Driver\DriverInstaller.exe" -eject
O33 - MountPoints2\{b09f1ba0-11ad-11e5-832e-448a5b89ad89}\Shell - "" = AutoRun
O33 - MountPoints2\{b09f1ba0-11ad-11e5-832e-448a5b89ad89}\Shell\AutoRun\command - "" = "H:\Startme.exe"
O33 - MountPoints2\{bfd6300e-e2eb-11e3-8256-448a5b89ad89}\Shell - "" = AutoRun
O33 - MountPoints2\{bfd6300e-e2eb-11e3-8256-448a5b89ad89}\Shell\AutoRun\command - "" = G:\Setup.exe -- [2010/06/24 15:51:57 | 000,443,156 | R--- | M] (City Interactive )
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:[b]64bit:[/b] lfsvc - C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
NetSvcs:[b]64bit:[/b] wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
NetSvcs:[b]64bit:[/b] DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs:[b]64bit:[/b] NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)


SafeBootMin:[b]64bit:[/b] AppMgmt - Service
SafeBootMin:[b]64bit:[/b] Base - Driver Group
SafeBootMin:[b]64bit:[/b] BasicDisplay.sys - C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] BasicRender.sys - C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] Boot Bus Extender - Driver Group
SafeBootMin:[b]64bit:[/b] Boot file system - Driver Group
SafeBootMin:[b]64bit:[/b] BrokerInfrastructure - C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] EFS - C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] File system - Driver Group
SafeBootMin:[b]64bit:[/b] Filter - Driver Group
SafeBootMin:[b]64bit:[/b] HelpSvc - Service
SafeBootMin:[b]64bit:[/b] KeyIso - C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] LSM - C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] MCODS - C:\Program Files\mcafee\VirusScan\mcods.exe (McAfee, Inc.)
SafeBootMin:[b]64bit:[/b] mcpltsvc - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SafeBootMin:[b]64bit:[/b] Netlogon - C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] PCI Configuration - Driver Group
SafeBootMin:[b]64bit:[/b] PNP Filter - Driver Group
SafeBootMin:[b]64bit:[/b] Primary disk - Driver Group
SafeBootMin:[b]64bit:[/b] sacsvr - Service
SafeBootMin:[b]64bit:[/b] SCSI Class - Driver Group
SafeBootMin:[b]64bit:[/b] System Bus Extender - Driver Group
SafeBootMin:[b]64bit:[/b] SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] TBS - Service
SafeBootMin:[b]64bit:[/b] vmms - Service
SafeBootMin:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:[b]64bit:[/b] {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootMin:[b]64bit:[/b] {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootMin:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: TBS - Service
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootMin: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet:[b]64bit:[/b] AppMgmt - Service
SafeBootNet:[b]64bit:[/b] Base - Driver Group
SafeBootNet:[b]64bit:[/b] BasicDisplay.sys - C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] BasicRender.sys - C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] Boot Bus Extender - Driver Group
SafeBootNet:[b]64bit:[/b] Boot file system - Driver Group
SafeBootNet:[b]64bit:[/b] BrokerInfrastructure - C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] EFS - C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] File system - Driver Group
SafeBootNet:[b]64bit:[/b] Filter - Driver Group
SafeBootNet:[b]64bit:[/b] HelpSvc - Service
SafeBootNet:[b]64bit:[/b] KeyIso - C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] LSM - C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] McMPFSvc - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] McNaiAnn - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] MCODS - C:\Program Files\mcafee\VirusScan\mcods.exe (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] mcpltsvc - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] Messenger - Service
SafeBootNet:[b]64bit:[/b] mfeaack - C:\Windows\SysNative\drivers\mfeaack.sys (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] mfeaack.sys - C:\Windows\SysNative\drivers\mfeaack.sys (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] mfeavfk - C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] mfeavfk.sys - C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] mfefire - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SafeBootNet:[b]64bit:[/b] mfefirek - C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] mfefirek.sys - C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] mfehidk - C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] mfehidk.sys - C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] mfemms - C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe ()
SafeBootNet:[b]64bit:[/b] mfencbdc - C:\Windows\SysNative\drivers\mfencbdc.sys (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] mfencbdc.sys - C:\Windows\SysNative\drivers\mfencbdc.sys (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] mfetdi2k - Service
SafeBootNet:[b]64bit:[/b] mfetdi2k.sys - Driver
SafeBootNet:[b]64bit:[/b] mfevtp - C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SafeBootNet:[b]64bit:[/b] NDIS Wrapper - Driver Group
SafeBootNet:[b]64bit:[/b] NetBIOSGroup - Driver Group
SafeBootNet:[b]64bit:[/b] NetDDEGroup - Driver Group
SafeBootNet:[b]64bit:[/b] Netlogon - C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] netprofm - C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] Network - Driver Group
SafeBootNet:[b]64bit:[/b] NetworkProvider - Driver Group
SafeBootNet:[b]64bit:[/b] PCI Configuration - Driver Group
SafeBootNet:[b]64bit:[/b] PNP Filter - Driver Group
SafeBootNet:[b]64bit:[/b] PNP_TDI - Driver Group
SafeBootNet:[b]64bit:[/b] Primary disk - Driver Group
SafeBootNet:[b]64bit:[/b] rdpencdd.sys - Driver
SafeBootNet:[b]64bit:[/b] rdsessmgr - Service
SafeBootNet:[b]64bit:[/b] sacsvr - Service
SafeBootNet:[b]64bit:[/b] SCSI Class - Driver Group
SafeBootNet:[b]64bit:[/b] SmartcardSimulator - Driver
SafeBootNet:[b]64bit:[/b] Streams Drivers - Driver Group
SafeBootNet:[b]64bit:[/b] System Bus Extender - Driver Group
SafeBootNet:[b]64bit:[/b] SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] TBS - Service
SafeBootNet:[b]64bit:[/b] TDI - Driver Group
SafeBootNet:[b]64bit:[/b] VaultSvc - C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] VirtualSmartcardReader - Driver
SafeBootNet:[b]64bit:[/b] vmms - Service
SafeBootNet:[b]64bit:[/b] Wcmsvc - C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] WudfUsbccidDriver - Driver
SafeBootNet:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:[b]64bit:[/b] {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:[b]64bit:[/b] {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:[b]64bit:[/b] {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:[b]64bit:[/b] {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:[b]64bit:[/b] {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:[b]64bit:[/b] {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootNet:[b]64bit:[/b] {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootNet:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: mfetdi2k - Service
SafeBootNet: mfetdi2k.sys - Driver
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdpencdd.sys - Driver
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: SmartcardSimulator - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TBS - Service
SafeBootNet: TDI - Driver Group
SafeBootNet: VirtualSmartcardReader - Driver
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootNet: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX:[b]64bit:[/b] {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:[b]64bit:[/b] {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
ActiveX:[b]64bit:[/b] {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:[b]64bit:[/b] {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:[b]64bit:[/b] {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:[b]64bit:[/b] {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:[b]64bit:[/b] {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:[b]64bit:[/b] {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:[b]64bit:[/b] {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:[b]64bit:[/b] {66C64F22-FC60-4E6C-A6B5-F0D580E680CE} - C:\Windows\System32\ie4uinit.exe -EnableTLS
ActiveX:[b]64bit:[/b] {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:[b]64bit:[/b] {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:[b]64bit:[/b] {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:[b]64bit:[/b] {78E345F7-E976-3595-9C30-2458D6A8EC32} - .NET Framework
ActiveX:[b]64bit:[/b] {7D715857-A67C-4C2F-A929-038448584D63} - C:\Windows\System32\ie4uinit.exe -DisableSSL3
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4340} - U
ActiveX:[b]64bit:[/b] {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:[b]64bit:[/b] {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
ActiveX:[b]64bit:[/b] {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:[b]64bit:[/b] {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:[b]64bit:[/b] {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:[b]64bit:[/b] {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:[b]64bit:[/b] {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:[b]64bit:[/b] >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.86\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker 2.6
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EC43E638-09F0-38CC-A585-72FCCDDF035C} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP

Drivers32:[b]64bit:[/b] msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:[b]64bit:[/b] VIDC.LAGS - lagarith.dll ( )
Drivers32:[b]64bit:[/b] vidc.XVID - xvidvfw.dll ()
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.LAGS - C:\Windows\SysWow64\lagarith.dll ( )
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2015/11/26 15:10:52 | 000,000,000 | ---D | C] -- C:\Users\bruno\AppData\Local\converter
[2015/11/26 14:46:16 | 000,000,000 | ---D | C] -- C:\Users\bruno\AppData\Local\MediaShow
[2015/11/26 13:57:55 | 000,000,000 | ---D | C] -- C:\Users\bruno\AppData\Local\Suite
[2015/11/26 13:57:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movavi Video Suite 15
[2015/11/26 13:57:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Movavi Video Suite 15
[2015/11/26 13:57:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Movavi Video Suite 15
[2015/11/26 11:11:23 | 000,000,000 | ---D | C] -- C:\Users\bruno\AppData\Local\Movavi
[2015/11/26 11:11:22 | 000,000,000 | ---D | C] -- C:\Users\bruno\AppData\Local\VideoEditor
[2015/11/26 11:11:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movavi Video Editor 11
[2015/11/26 11:11:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Movavi Video Editor 11
[2015/11/26 11:10:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Movavi Video Editor 11
[2015/11/26 10:12:47 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2015/11/25 16:20:36 | 000,000,000 | ---D | C] -- C:\Users\bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2015/11/25 14:37:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pinnacle Studio 16
[2015/11/25 14:35:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\653ac11b-b606-42c5-b357-bca0fd28d1cd
[2015/11/25 14:35:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Discovery App
[2015/11/25 14:35:30 | 000,000,000 | ---D | C] -- C:\ProgramData\653ac11b-b606-42c5-b357-bca0fd28d1cd
[2015/11/25 14:33:39 | 000,000,000 | ---D | C] -- C:\Users\bruno\AppData\Local\{DD55EB09-F9FD-87B1-9465-A259B00D5EC1}
[2015/11/25 14:32:59 | 000,968,816 | ---- | C] (Web Program soft ) -- C:\Users\bruno\Desktop\ProSGold_6_Crack_www_crackmania_net_.exe
[2015/11/25 14:30:07 | 000,968,816 | ---- | C] (Web Program soft ) -- C:\Users\bruno\Documents\ProSGold_6_Crack_www_crackmania_net_.exe
[2015/11/25 14:03:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProShow Producer
[2015/11/25 10:32:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProShow Gold
[2015/11/25 10:32:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Photodex Presenter
[2015/11/25 10:32:52 | 000,000,000 | ---D | C] -- C:\Users\bruno\AppData\Roaming\Netscape
[2015/11/25 10:32:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Photodex
[2015/11/25 10:32:24 | 000,000,000 | ---D | C] -- C:\Users\bruno\AppData\Roaming\Photodex
[2015/11/25 10:32:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Photodex
[2015/11/24 11:02:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
[2015/11/24 11:00:38 | 000,000,000 | ---D | C] -- C:\Users\bruno\Documents\psp
[2015/11/14 09:03:36 | 000,000,000 | ---D | C] -- C:\Users\bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2015/11/11 10:38:18 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2015/11/11 10:38:17 | 001,380,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll
[2015/11/11 10:38:17 | 000,558,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\untfs.dll
[2015/11/11 10:38:17 | 000,507,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\untfs.dll
[2015/11/11 10:38:17 | 000,445,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certcli.dll
[2015/11/11 10:38:17 | 000,397,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcryptprimitives.dll
[2015/11/11 10:38:17 | 000,340,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\bcryptprimitives.dll
[2015/11/11 10:38:17 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certcli.dll
[2015/11/11 10:38:17 | 000,155,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\tpm.sys
[2015/11/11 10:38:17 | 000,137,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2015/11/11 10:38:17 | 000,106,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncryptsslp.dll
[2015/11/11 10:38:17 | 000,091,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncryptsslp.dll
[2015/11/11 10:36:58 | 000,183,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AuthHost.exe
[2015/11/11 10:36:57 | 007,455,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2015/11/11 10:36:57 | 001,659,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2015/11/11 10:36:57 | 001,519,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2015/11/11 10:36:56 | 001,487,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2015/11/11 10:36:56 | 001,355,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe
[2015/11/11 10:36:54 | 002,243,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2015/11/11 10:36:54 | 000,891,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2015/11/11 10:36:54 | 000,721,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapi.dll
[2015/11/11 10:36:54 | 000,409,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUSettingsProvider.dll
[2015/11/11 10:36:54 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2015/11/11 10:36:54 | 000,136,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2015/11/11 10:36:54 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuwebv.dll
[2015/11/11 10:36:54 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2015/11/11 10:36:54 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wudriver.dll
[2015/11/11 10:36:54 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2015/11/11 10:36:54 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapp.exe
[2015/11/11 10:36:47 | 001,091,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll
[2015/11/11 10:36:47 | 000,477,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\puiobj.dll
[2015/11/11 10:36:47 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\puiobj.dll
[2015/11/11 10:36:40 | 005,990,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2015/11/11 10:36:40 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2015/11/11 10:36:40 | 000,663,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2015/11/11 10:36:39 | 000,801,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2015/11/11 10:36:39 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2015/11/11 10:36:39 | 000,720,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2015/11/11 10:36:39 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2015/11/11 10:36:39 | 000,585,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2015/11/11 10:35:49 | 000,136,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wfplwfs.sys
[2015/11/11 10:35:48 | 000,713,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll
[2015/11/11 10:35:48 | 000,561,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll
[2015/11/11 10:35:48 | 000,422,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL
[2015/11/11 10:35:48 | 000,272,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL
[2015/11/11 10:29:31 | 000,029,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aspnet_counters.dll
[2015/11/11 10:29:30 | 000,028,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\aspnet_counters.dll
[1995/09/20 16:16:38 | 000,456,976 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\dao3032.dll
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2015/12/02 09:21:04 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2015/12/02 09:07:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015/12/02 09:05:29 | 000,001,084 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/12/02 09:05:01 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2015/12/02 09:04:57 | 3379,838,976 | -HS- | M] () -- C:\hiberfil.sys
[2015/12/01 15:04:01 | 000,000,304 | ---- | M] () -- C:\Windows\tasks\Run_dregol.job
[2015/12/01 14:59:00 | 000,000,282 | ---- | M] () -- C:\Windows\tasks\Go_Palikan.job
[2015/12/01 14:32:46 | 000,001,088 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/12/01 09:59:04 | 000,000,271 | ---- | M] () -- C:\Users\bruno\AppData\Roaming\WB.CFG
[2015/11/30 13:08:27 | 001,824,010 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2015/11/30 13:08:27 | 000,811,108 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2015/11/30 13:08:27 | 000,722,278 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2015/11/30 13:08:27 | 000,159,206 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2015/11/30 13:08:27 | 000,135,394 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2015/11/27 11:03:39 | 000,002,174 | ---- | M] () -- C:\Users\bruno\Desktop\Chromium.lnk
[2015/11/26 13:57:48 | 000,001,095 | ---- | M] () -- C:\Users\Public\Desktop\Movavi Video Suite 15.lnk
[2015/11/26 11:11:17 | 000,001,136 | ---- | M] () -- C:\Users\Public\Desktop\Movavi Video Editor 11.lnk
[2015/11/26 11:10:38 | 000,004,943 | ---- | M] () -- C:\ProgramData\rxsmznjf.zcp
[2015/11/26 11:10:38 | 000,000,016 | ---- | M] () -- C:\ProgramData\mntemp
[2015/11/26 10:14:11 | 000,002,005 | ---- | M] () -- C:\Users\Public\Desktop\abPhoto.lnk
[2015/11/26 10:04:41 | 000,000,290 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2015/11/25 16:20:36 | 000,000,730 | ---- | M] () -- C:\Users\bruno\Desktop\WinRAR.lnk
[2015/11/25 14:37:44 | 000,000,349 | ---- | M] () -- C:\Users\Public\Documents\PCLECHAL.INI
[2015/11/25 14:34:14 | 053,400,987 | ---- | M] () -- C:\Users\bruno\Desktop\ProSGold_6_Crack_www_crackmania_net_.rar
[2015/11/25 14:33:00 | 000,968,816 | ---- | M] (Web Program soft ) -- C:\Users\bruno\Desktop\ProSGold_6_Crack_www_crackmania_net_.exe
[2015/11/25 14:30:07 | 000,968,816 | ---- | M] (Web Program soft ) -- C:\Users\bruno\Documents\ProSGold_6_Crack_www_crackmania_net_.exe
[2015/11/25 14:03:07 | 000,002,185 | ---- | M] () -- C:\Users\bruno\Application Data\Microsoft\Internet Explorer\Quick Launch\ProShow Producer.lnk
[2015/11/25 14:03:07 | 000,002,161 | ---- | M] () -- C:\Users\Public\Desktop\ProShow Producer.lnk
[2015/11/25 10:32:55 | 000,002,141 | ---- | M] () -- C:\Users\bruno\Application Data\Microsoft\Internet Explorer\Quick Launch\ProShow Gold.lnk
[2015/11/25 10:32:55 | 000,002,117 | ---- | M] () -- C:\Users\Public\Desktop\ProShow Gold.lnk
[2015/11/24 11:02:44 | 000,002,062 | ---- | M] () -- C:\Users\Public\Desktop\Google Slides.lnk
[2015/11/24 11:02:44 | 000,002,060 | ---- | M] () -- C:\Users\Public\Desktop\Google Sheets.lnk
[2015/11/24 11:02:44 | 000,002,050 | ---- | M] () -- C:\Users\Public\Desktop\Google Docs.lnk
[2015/11/24 11:02:07 | 000,001,071 | ---- | M] () -- C:\Users\bruno\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk
[2015/11/24 11:02:07 | 000,001,047 | ---- | M] () -- C:\Users\bruno\Desktop\PhotoScape.lnk
[2015/11/24 10:58:50 | 000,135,168 | -H-- | M] () -- C:\Users\bruno\Documents\photothumb.db
[2015/11/12 18:39:47 | 000,665,352 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2015/11/11 21:36:44 | 000,002,205 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2015/11/03 01:23:06 | 000,810,488 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2015/11/03 01:23:06 | 000,176,632 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2015/12/02 09:21:04 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2015/11/26 13:57:48 | 000,001,095 | ---- | C] () -- C:\Users\Public\Desktop\Movavi Video Suite 15.lnk
[2015/11/26 11:11:17 | 000,001,136 | ---- | C] () -- C:\Users\Public\Desktop\Movavi Video Editor 11.lnk
[2015/11/26 11:10:38 | 000,004,943 | ---- | C] () -- C:\ProgramData\rxsmznjf.zcp
[2015/11/26 11:10:38 | 000,000,016 | ---- | C] () -- C:\ProgramData\mntemp
[2015/11/26 10:14:11 | 000,002,005 | ---- | C] () -- C:\Users\Public\Desktop\abPhoto.lnk
[2015/11/26 10:04:41 | 000,000,290 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2015/11/25 16:20:36 | 000,000,730 | ---- | C] () -- C:\Users\bruno\Desktop\WinRAR.lnk
[2015/11/25 14:34:56 | 000,002,174 | ---- | C] () -- C:\Users\bruno\Desktop\Chromium.lnk
[2015/11/25 14:34:14 | 053,400,987 | ---- | C] () -- C:\Users\bruno\Desktop\ProSGold_6_Crack_www_crackmania_net_.rar
[2015/11/25 14:34:00 | 000,000,282 | ---- | C] () -- C:\Windows\tasks\Go_Palikan.job
[2015/11/25 14:03:07 | 000,002,185 | ---- | C] () -- C:\Users\bruno\Application Data\Microsoft\Internet Explorer\Quick Launch\ProShow Producer.lnk
[2015/11/25 14:03:07 | 000,002,161 | ---- | C] () -- C:\Users\Public\Desktop\ProShow Producer.lnk
[2015/11/25 10:32:55 | 000,002,141 | ---- | C] () -- C:\Users\bruno\Application Data\Microsoft\Internet Explorer\Quick Launch\ProShow Gold.lnk
[2015/11/25 10:32:55 | 000,002,117 | ---- | C] () -- C:\Users\Public\Desktop\ProShow Gold.lnk
[2015/11/24 11:02:44 | 000,002,062 | ---- | C] () -- C:\Users\Public\Desktop\Google Slides.lnk
[2015/11/24 11:02:44 | 000,002,060 | ---- | C] () -- C:\Users\Public\Desktop\Google Sheets.lnk
[2015/11/24 11:02:44 | 000,002,050 | ---- | C] () -- C:\Users\Public\Desktop\Google Docs.lnk
[2015/11/11 10:36:58 | 000,414,559 | ---- | C] () -- C:\Windows\SysNative\ApnDatabase.xml
[2015/06/11 19:13:41 | 000,005,018 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2015/06/11 19:13:41 | 000,000,088 | RHS- | C] () -- C:\ProgramData\B1B14BEA9A.sys
[2015/06/11 19:12:22 | 000,000,110 | ---- | C] () -- C:\Windows\wininit.ini
[2015/06/07 11:02:13 | 000,006,144 | ---- | C] () -- C:\Users\bruno\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2015/03/23 19:19:22 | 000,107,008 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
[2015/03/23 19:17:57 | 000,046,080 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2014/12/17 17:41:21 | 000,022,528 | ---- | C] () -- C:\Users\bruno\AppData\Local\dsisetup2966872.exe
[2014/12/09 15:12:33 | 000,002,278 | ---- | C] () -- C:\Windows\SysWow64\Cam122.ini
[2014/12/09 14:43:04 | 000,009,728 | ---- | C] () -- C:\Windows\SysWow64\HWLMSET2PS.dll
[2014/12/02 09:41:25 | 000,000,001 | ---- | C] () -- C:\Users\bruno\AppData\Local\DSI.DAT
[2014/12/02 09:41:24 | 000,022,528 | ---- | C] () -- C:\Users\bruno\AppData\Local\dsisetup37137502.exe
[2014/10/26 10:22:28 | 000,008,192 | -HS- | C] () -- C:\Windows\o2cLicStore.bin
[2014/06/21 16:52:12 | 000,038,544 | ---- | C] () -- C:\Users\bruno\AppData\Roaming\Valeurs séparées par une virgule.ADR
[2014/05/28 18:48:13 | 000,002,255 | ---- | C] () -- C:\Windows\SysWow64\WimBootCompress.ini
[2014/05/24 17:52:06 | 000,645,632 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2014/05/24 17:52:06 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2014/05/24 17:51:55 | 000,715,038 | ---- | C] () -- C:\Windows\unins000.exe
[2014/05/24 16:58:02 | 000,000,271 | ---- | C] () -- C:\Users\bruno\AppData\Roaming\WB.CFG
[2014/05/24 16:02:24 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2014/05/24 16:02:22 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2014/05/24 16:02:20 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
[2014/05/24 16:02:20 | 000,003,430 | ---- | C] () -- C:\Windows\unins000.dat
[2014/03/28 16:53:24 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2014/03/28 17:07:55 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2015/08/27 03:43:09 | 022,372,152 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015/08/27 03:42:51 | 019,795,904 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2014/10/29 02:19:43 | 001,013,760 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2014/10/29 01:59:23 | 000,786,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2014/10/29 02:16:01 | 000,512,512 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== LOP Check ==========[/color]

[2015/04/24 20:01:24 | 000,000,000 | ---D | M] -- C:\Users\annie\AppData\Roaming\Canon
[2014/05/24 21:48:59 | 000,000,000 | ---D | M] -- C:\Users\annie\AppData\Roaming\DAEMON Tools Pro
[2014/05/24 21:49:10 | 000,000,000 | ---D | M] -- C:\Users\annie\AppData\Roaming\Voxmobili
[2014/05/24 22:29:02 | 000,000,000 | ---D | M] -- C:\Users\annie\AppData\Roaming\WildTangent
[2015/01/19 18:08:29 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\.minecraft
[2014/05/24 12:50:28 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\acer
[2014/10/08 17:37:51 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\Autodesk
[2015/11/11 10:47:37 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\BTC
[2015/02/19 19:20:46 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\Canon
[2014/05/24 16:02:26 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\CDXReader
[2015/02/18 18:54:17 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\DAEMON Tools Pro
[2015/11/28 13:05:47 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\Dropbox
[2014/05/24 17:51:59 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\LavFilters
[2015/06/12 19:13:33 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\MAGIX
[2015/11/25 10:32:52 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\Netscape
[2015/11/25 14:02:20 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\Photodex
[2015/05/04 12:51:47 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\PhotoScape
[2015/06/08 18:04:14 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\Run_dregol
[2015/09/16 19:51:42 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\Spotify
[2015/12/02 09:26:10 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\uTorrent
[2014/05/24 21:43:13 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\Voxmobili
[2014/05/25 09:29:54 | 000,000,000 | ---D | M] -- C:\Users\bruno\AppData\Roaming\WildTangent

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Custom Scans ==========[/color]

[color=#A23BEC]< >[/color]
[2013/08/22 15:45:54 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2014/05/24 13:13:54 | 000,001,084 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2014/05/24 13:13:54 | 000,001,088 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2014/06/22 10:36:58 | 000,001,038 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2179158368-4115444144-449989576-1001Core1cf8dfd83600677.job
[2015/06/08 18:04:14 | 000,000,304 | ---- | C] () -- C:\Windows\Tasks\Run_dregol.job
[2015/07/18 12:50:21 | 000,001,156 | ---- | C] () -- C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2179158368-4115444144-449989576-1001Core1d0c14fecfbbbe2.job
[2015/11/25 14:34:00 | 000,000,282 | ---- | C] () -- C:\Windows\Tasks\Go_Palikan.job

[color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
[2013/06/18 13:18:29 | 000,000,001 | -HS- | M] () -- C:\BOOTNXT
[2003/08/06 09:33:36 | 000,000,756 | ---- | M] () -- C:\contact.ini
[2015/12/02 09:04:57 | 3379,838,976 | -HS- | M] () -- C:\hiberfil.sys
[2015/12/02 09:05:00 | 1140,850,688 | -HS- | M] () -- C:\pagefile.sys
[2015/12/02 09:21:04 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2015/12/02 09:05:01 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2 C:\*.tmp files -> C:\*.tmp -> ]

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

[color=#A23BEC]< %PROGRAMFILES%\*.* >[/color]
[2013/08/22 16:34:52 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini

[color=#A23BEC]< %PROGRAMFILES%\*. >[/color]
[2015/10/21 11:13:02 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Acer
[2014/03/28 16:51:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\AGEIA Technologies
[2014/10/26 10:17:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Anuman Interactive
[2014/07/21 18:30:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Browseri_Appe 1.2
[2015/02/04 19:41:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Canon
[2015/04/27 09:46:02 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Citrix
[2015/10/04 17:56:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\City Interactive
[2015/11/25 14:35:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
[2014/03/28 17:05:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CyberLink
[2014/05/24 16:32:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\DAEMON Tools Pro
[2014/05/24 17:51:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\DirectVobSub
[2015/11/25 14:35:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Discovery App
[2014/05/24 16:23:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\DivX
[2014/05/24 16:02:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\DSP-worx
[2014/05/24 17:52:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ffdshow
[2015/11/24 11:02:43 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Google
[2014/12/11 16:07:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\GPLGS
[2015/06/20 16:07:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Grand Theft Auto V
[2014/05/24 16:02:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Haali
[2014/12/11 16:48:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hercules
[2015/06/14 11:24:56 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
[2014/03/28 16:52:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Intel
[2015/10/14 19:33:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
[2014/09/12 17:56:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Java
[2015/03/17 19:35:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Jeux de cartes
[2014/05/24 17:51:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Lame For Audacity
[2015/07/15 10:07:58 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Luxand
[2015/06/12 18:09:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MAGIX
[2014/03/28 17:11:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\McAfee
[2013/10/04 09:04:58 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mcafee.com
[2014/05/24 20:33:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Analysis Services
[2014/03/28 17:03:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office
[2014/05/24 20:41:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SQL Server
[2015/04/23 10:53:43 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2014/05/30 10:21:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
[2015/04/30 16:39:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\monAlbumPhoto
[2015/11/26 11:11:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Movavi Video Editor 11
[2015/11/26 13:57:48 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Movavi Video Suite 15
[2015/06/07 10:57:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Movie Maker 2.6
[2015/04/17 14:02:03 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox
[2013/10/04 08:55:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
[2015/06/12 18:08:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSXML 4.0
[2015/06/06 11:30:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NCH Software
[2013/10/04 09:07:54 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Nero
[2014/03/28 17:03:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Norton Online Backup ARA
[2014/03/28 17:03:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NortonInstaller
[2014/03/28 16:51:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NVIDIA Corporation
[2014/05/24 12:45:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OEM
[2014/05/24 16:02:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OpenSource Flash Video Splitter
[2014/11/26 12:30:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Paint Shop Pro 5
[2014/08/31 10:29:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PC Sync
[2014/12/11 16:07:42 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PDF Creator
[2015/11/25 14:02:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Photodex
[2015/11/25 10:32:53 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Photodex Presenter
[2014/05/26 18:14:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PhotoInstrument
[2014/07/31 18:08:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PhotoScape
[2015/11/25 14:37:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Pinnacle
[2015/07/15 15:24:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Planetwide Games
[2015/02/18 18:54:45 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Plug In Digital
[2014/03/28 16:54:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek
[2013/10/04 08:55:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
[2015/06/20 16:11:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Rockstar Games
[2015/06/08 18:04:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Run_Dregol
[2015/10/14 17:57:33 | 000,000,000 | R--D | M] -- C:\Program Files (x86)\Skype
[2015/06/11 19:12:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\SmartSound Software
[2014/08/03 11:24:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Software
[2014/03/28 16:57:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Spotify
[2014/03/28 17:03:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Symantec
[2014/03/28 16:53:28 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp
[2015/06/13 11:29:02 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Total Video Converter
[2015/03/08 16:25:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\VideoLAN
[2015/06/13 13:53:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Virtual Piano
[2015/07/15 08:56:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\VirtualDJ
[2013/10/04 09:02:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WildGames
[2015/08/08 16:53:08 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WildTangent Games
[2015/08/29 20:00:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
[2015/04/23 10:53:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live
[2015/04/02 08:04:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
[2015/06/11 19:09:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Components
[2015/04/02 08:04:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
[2015/04/02 08:04:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Multimedia Platform
[2013/08/22 16:36:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
[2015/04/02 08:04:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Viewer
[2015/04/02 08:04:35 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices
[2013/08/22 16:36:30 | 000,000,000 | -HSD | M] -- C:\Program Files (x86)\Windows Sidebar
[2013/08/22 16:36:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WindowsPowerShell
[2015/06/09 19:18:00 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Wondershare
[2014/05/24 17:52:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Xvid

[color=#A23BEC]< MD5 for: AGP440.SYS >[/color]
[2014/06/03 18:12:18 | 000,000,012 | ---- | M] () MD5=06C6E29A8643D00197E214F3AA26A4B9 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.16384_none_aad14d4692a7dfee\AGP440.sys
[2013/08/22 13:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\Windows\SysNative\drivers\AGP440.sys
[2013/08/22 13:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_36be84f8fc597ea3\AGP440.sys
[2013/08/22 13:43:40 | 000,062,304 | ---- | M] (Microsoft Corporation) MD5=7DFAEBA9AD62D20102B576D5CAC45EC8 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17238_none_ab0b455c927bd60f\AGP440.sys
[2014/09/18 18:09:53 | 000,000,012 | ---- | M] () MD5=AC26F500DB64617F336315BB5A0FDBE1 -- C:\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_6.3.9600.17031_none_ab043f8a92822a60\AGP440.sys
[2015/07/10 11:30:50 | 000,063,328 | ---- | M] (Microsoft Corporation) MD5=EF09D07626820F7F89519514C17FE768 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\drivers\AGP440.sys
[2015/07/10 11:30:50 | 000,063,328 | ---- | M] (Microsoft Corporation) MD5=EF09D07626820F7F89519514C17FE768 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\DriverStore\FileRepository\machine.inf_amd64_c357541563097b98\AGP440.sys
[2015/07/10 11:30:50 | 000,063,328 | ---- | M] (Microsoft Corporation) MD5=EF09D07626820F7F89519514C17FE768 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_machine.inf_31bf3856ad364e35_10.0.10240.16384_none_c2135eea595e241e\AGP440.sys

[color=#A23BEC]< MD5 for: APPMGMTS.DLL >[/color]
[2013/08/22 15:55:04 | 000,086,064 | ---- | M] () MD5=1336BE8A8B1E8B8744D5217AE5FDD303 -- C:\Windows\WinSxS\amd64_microsoft-windows-g..oftwareinstallation_31bf3856ad364e35_6.3.9600.16384_none_728d486f3000a7ad\appmgmts.dll
[2015/04/02 15:35:50 | 000,087,855 | ---- | M] () MD5=5B2A9B5E87542C65457B527CC512AF25 -- C:\Windows\WinSxS\amd64_microsoft-windows-g..oftwareinstallation_31bf3856ad364e35_6.3.9600.17415_none_72d9e34b2fc71435\appmgmts.dll
[2013/08/22 16:00:05 | 000,071,466 | ---- | M] () MD5=9424C4C8AE9114A121553818824D33A3 -- C:\Windows\WinSxS\wow64_microsoft-windows-g..oftwareinstallation_31bf3856ad364e35_6.3.9600.16384_none_7ce1f2c1646169a8\appmgmts.dll
[2015/04/02 17:53:08 | 000,072,712 | ---- | M] () MD5=C73D54BF555388E7DF11A9C0AFC1F139 -- C:\Windows\WinSxS\wow64_microsoft-windows-g..oftwareinstallation_31bf3856ad364e35_6.3.9600.17415_none_7d2e8d9d6427d630\appmgmts.dll

[color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
[2013/08/22 13:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\SysNative\drivers\atapi.sys
[2013/08/22 13:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_64aa4354da84c2df\atapi.sys
[2013/08/22 13:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.3.9600.16384_none_cdf68824f580d510\atapi.sys
[2015/07/10 11:30:51 | 000,028,512 | ---- | M] (Microsoft Corporation) MD5=8921DF6060DB5C7700AA48CB12E9EA08 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\drivers\atapi.sys
[2015/07/10 11:30:51 | 000,028,512 | ---- | M] (Microsoft Corporation) MD5=8921DF6060DB5C7700AA48CB12E9EA08 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\DriverStore\FileRepository\mshdc.inf_amd64_5689072091519d03\atapi.sys
[2015/07/10 11:30:51 | 000,028,512 | ---- | M] (Microsoft Corporation) MD5=8921DF6060DB5C7700AA48CB12E9EA08 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_10.0.10240.16384_none_e53899c8bc371940\atapi.sys

[color=#A23BEC]< MD5 for: AUTOCHK.EXE >[/color]
[2014/06/03 18:16:02 | 000,028,249 | ---- | M] () MD5=0CBDE27FB26761852F7B22AFB8C51ACB -- C:\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.16384_none_d2b24d5495b82963\autochk.exe
[2014/02/22 12:24:36 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\SysWOW64\autochk.exe
[2014/02/22 12:24:36 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_76c6a414dd35029f\autochk.exe
[2014/02/22 13:17:06 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=387A1E98BE548E4F199343CBA01E9D6D -- C:\Windows\SysNative\autochk.exe
[2014/02/22 13:17:06 | 000,890,880 | ---- | M] (Microsoft Corporation) MD5=387A1E98BE548E4F199343CBA01E9D6D -- C:\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_d2e53f98959273d5\autochk.exe
[2014/06/03 19:35:53 | 000,023,596 | ---- | M] () MD5=83A4C9BE342BC296EC09492FF7594F13 -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.16384_none_7693b1d0dd5ab82d\autochk.exe
[2015/07/10 11:30:55 | 000,944,640 | ---- | M] (Microsoft Corporation) MD5=9A4DEDB0AFE7D254DA6F38F976ABB84E -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\autochk.exe
[2015/07/10 11:30:55 | 000,944,640 | ---- | M] (Microsoft Corporation) MD5=9A4DEDB0AFE7D254DA6F38F976ABB84E -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-autochk_31bf3856ad364e35_10.0.10240.16384_none_e9f45ef85c6e6d93\autochk.exe

[color=#A23BEC]< MD5 for: BEEP.SYS >[/color]
[2013/08/22 12:40:24 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=EC19013E4CF87609534165DF897274D6 -- C:\Windows\SysNative\drivers\beep.sys
[2013/08/22 12:40:24 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=EC19013E4CF87609534165DF897274D6 -- C:\Windows\WinSxS\amd64_microsoft-windows-beepsys_31bf3856ad364e35_6.3.9600.16384_none_b4df015ddb944ecf\beep.sys

[color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color]
[2015/04/02 15:34:53 | 000,087,190 | ---- | M] () MD5=1BF154F7BFAE2B9E0545FB09946C1817 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_42bfa1f94d79e1bb\explorer.exe
[2014/06/03 18:26:40 | 000,336,576 | ---- | M] () MD5=201E2AB1C87503398EFAE7D32AF29FFE -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16384_none_4273071d4db37533\explorer.exe
[2014/09/18 18:11:20 | 000,270,774 | ---- | M] () MD5=2195687491E604BA42961470EDA7660E -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17238_none_42acff334d876b54\explorer.exe
[2014/09/18 18:33:44 | 000,220,250 | ---- | M] () MD5=286928E00AD34E9F88EB5BFA52660A70 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17238_none_4d01a98581e82d4f\explorer.exe
[2014/06/03 19:13:34 | 000,015,546 | ---- | M] () MD5=347EFF7EC89C3EB4F72F2408E1C4E16D -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_4cfaa3b381ee81a0\explorer.exe
[2015/03/14 19:34:56 | 000,396,313 | ---- | M] () MD5=426AEABD8DD389A65A8EE92AB5936153 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17284_none_4272ee6f4db391ad\explorer.exe
[2014/06/03 19:13:31 | 000,238,918 | ---- | M] () MD5=5177BB4FECDDB9CDBCF10EF65916968D -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_4ceff22781f6788c\explorer.exe
[2015/04/02 17:53:02 | 000,107,122 | ---- | M] () MD5=52063502D4A2E28FEBEA781D0EE5C453 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_4d144c4b81daa3b6\explorer.exe
[2014/06/03 19:13:25 | 000,268,164 | ---- | M] () MD5=578A251C234E51BC6B9D684480EEB9DB -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16384_none_4cc7b16f8214372e\explorer.exe
[2014/09/18 18:11:18 | 000,271,249 | ---- | M] () MD5=667BC926C7CB889BF276A5FEA316CAEE -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_42adfbb14d868a5d\explorer.exe
[2014/06/03 18:26:47 | 000,169,957 | ---- | M] () MD5=6D919C26DCB567396CD2E119B8E4310E -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_42a5f9614d8dbfa5\explorer.exe
[2014/06/03 19:13:28 | 000,239,123 | ---- | M] () MD5=7B546CB045C2A84D26A8D2FE07F9F98C -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16408_none_4d2233dd81cfba29\explorer.exe
[2015/01/28 00:41:17 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=91E24273FCA076EA9E65DAFA98901225 -- C:\Windows\SysWOW64\explorer.exe
[2015/01/28 00:41:17 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=91E24273FCA076EA9E65DAFA98901225 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17667_none_4ce0410f82015c67\explorer.exe
[2015/01/28 00:47:12 | 002,501,368 | ---- | M] (Microsoft Corporation) MD5=C10A66189DC8C090E7C84873EDCEBC88 -- C:\Windows\explorer.exe
[2015/01/28 00:47:12 | 002,501,368 | ---- | M] (Microsoft Corporation) MD5=C10A66189DC8C090E7C84873EDCEBC88 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17667_none_428b96bd4da09a6c\explorer.exe
[2014/09/18 18:33:40 | 000,208,662 | ---- | M] () MD5=C131BC6F12417306A9C8469CA49110B1 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_4d02a60381e74c58\explorer.exe
[2014/06/03 18:26:43 | 000,284,534 | ---- | M] () MD5=D1EF5DE70183FB717B5FC4593A0E46BD -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16408_none_42cd898b4d6ef82e\explorer.exe
[2015/03/14 19:40:59 | 000,338,943 | ---- | M] () MD5=E4FD740C3316F1D1C8322471553466C7 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17284_none_4cc798c1821453a8\explorer.exe
[2014/06/03 18:26:45 | 000,283,735 | ---- | M] () MD5=FA98C5D746E7C9E0912E88AC44FF9926 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_429b47d54d95b691\explorer.exe

[color=#A23BEC]< MD5 for: HIDSERV.DLL >[/color]
[2015/04/02 15:36:10 | 000,004,284 | ---- | M] () MD5=2A8190AC5599446255EEADD6088C3BED -- C:\Windows\WinSxS\amd64_microsoft-windows-hid-user_31bf3856ad364e35_6.3.9600.16384_none_c76aa8785b65aeab\hidserv.dll
[2015/07/10 11:30:53 | 000,034,304 | ---- | M] (Microsoft Corporation) MD5=5576DF399CF2D3B63608F7F282151249 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\hidserv.dll
[2015/07/10 11:30:53 | 000,034,304 | ---- | M] (Microsoft Corporation) MD5=5576DF399CF2D3B63608F7F282151249 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-hid-user_31bf3856ad364e35_10.0.10240.16384_none_deacba1c221bf2db\hidserv.dll
[2015/04/02 17:53:17 | 000,007,007 | ---- | M] () MD5=73A9A38CF4CBA7E4E742D493B3D672BC -- C:\Windows\WinSxS\wow64_microsoft-windows-hid-user_31bf3856ad364e35_6.3.9600.16384_none_d1bf52ca8fc670a6\hidserv.dll
[2014/10/29 02:59:46 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=AE71B1BC1A17000F7B8F9AB79D4668D4 -- C:\Windows\SysWOW64\hidserv.dll
[2014/10/29 02:59:46 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=AE71B1BC1A17000F7B8F9AB79D4668D4 -- C:\Windows\WinSxS\wow64_microsoft-windows-hid-user_31bf3856ad364e35_6.3.9600.17415_none_d20beda68f8cdd2e\hidserv.dll
[2014/10/29 03:44:23 | 000,033,792 | ---- | M] (Microsoft Corporation) MD5=EA85B5093DF7B5C3E80362B053740AE2 -- C:\Windows\SysNative\hidserv.dll
[2014/10/29 03:44:23 | 000,033,792 | ---- | M] (Microsoft Corporation) MD5=EA85B5093DF7B5C3E80362B053740AE2 -- C:\Windows\WinSxS\amd64_microsoft-windows-hid-user_31bf3856ad364e35_6.3.9600.17415_none_c7b743545b2c1b33\hidserv.dll

[color=#A23BEC]< MD5 for: IASTORV.SYS >[/color]
[2015/07/10 11:30:50 | 000,412,000 | ---- | M] (Intel Corporation) MD5=4E69EE8F8E5DA036535D433C544AF9E2 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\drivers\iaStorV.sys
[2015/07/10 11:30:50 | 000,412,000 | ---- | M] (Intel Corporation) MD5=4E69EE8F8E5DA036535D433C544AF9E2 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\DriverStore\FileRepository\iastorv.inf_amd64_5069105fb236ae4b\iaStorV.sys
[2015/07/10 11:30:50 | 000,412,000 | ---- | M] (Intel Corporation) MD5=4E69EE8F8E5DA036535D433C544AF9E2 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_iastorv.inf_31bf3856ad364e35_10.0.10240.16384_none_b711c42722754533\iaStorV.sys
[2013/08/22 13:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\Windows\SysNative\drivers\iaStorV.sys
[2013/08/22 13:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_5069105fb236ae4b\iaStorV.sys
[2013/08/22 13:43:45 | 000,412,000 | ---- | M] (Intel Corporation) MD5=A2200C3033FA4EF249FC096A7A7D02A2 -- C:\Windows\WinSxS\amd64_iastorv.inf_31bf3856ad364e35_6.3.9600.16384_none_9fcfb2835bbf0103\iaStorV.sys

[color=#A23BEC]< MD5 for: IMM32.DLL >[/color]
[2014/06/03 18:36:36 | 000,016,138 | ---- | M] () MD5=0C36F98822D998BC7F2021B6FC99EBAE -- C:\Windows\WinSxS\amd64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.16384_none_4d147e214e620376\imm32.dll
[2015/04/02 15:37:10 | 000,027,353 | ---- | M] () MD5=16BF085E712ACC139C39C34CEB499D7A -- C:\Windows\WinSxS\amd64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.17031_none_4d4770654e3c4de8\imm32.dll
[2015/04/02 17:53:50 | 000,023,804 | ---- | M] () MD5=4E7419816FAD0942AEFB3B37F0D26A0D -- C:\Windows\WinSxS\wow64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.17031_none_579c1ab7829d0fe3\imm32.dll
[2014/10/29 02:59:49 | 000,141,312 | ---- | M] (Microsoft Corporation) MD5=59452E147C6A5D055E5EBCB6B8E99CB7 -- C:\Windows\SysWOW64\imm32.dll
[2014/10/29 02:59:49 | 000,141,312 | ---- | M] (Microsoft Corporation) MD5=59452E147C6A5D055E5EBCB6B8E99CB7 -- C:\Windows\WinSxS\wow64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.17415_none_57b5c34f828931f9\imm32.dll
[2015/07/10 11:30:51 | 000,211,288 | ---- | M] (Microsoft Corporation) MD5=BFE876E837A15B740FCEA4F4A844C7C9 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\imm32.dll
[2015/07/10 11:30:51 | 000,211,288 | ---- | M] (Microsoft Corporation) MD5=BFE876E837A15B740FCEA4F4A844C7C9 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-imm32_31bf3856ad364e35_10.0.10240.16384_none_64568fc5151847a6\imm32.dll
[2014/06/03 19:21:39 | 000,007,873 | ---- | M] () MD5=DC664D9FAD5B9C36BCFD052ECF2F4E67 -- C:\Windows\WinSxS\wow64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.16384_none_5769287382c2c571\imm32.dll
[2014/10/29 05:00:23 | 000,210,744 | ---- | M] (Microsoft Corporation) MD5=DEB33D08FBF708CAAC08080054D4C7CC -- C:\Windows\SysNative\imm32.dll
[2014/10/29 05:00:23 | 000,210,744 | ---- | M] (Microsoft Corporation) MD5=DEB33D08FBF708CAAC08080054D4C7CC -- C:\Windows\WinSxS\amd64_microsoft-windows-imm32_31bf3856ad364e35_6.3.9600.17415_none_4d6118fd4e286ffe\imm32.dll

[color=#A23BEC]< MD5 for: KERNEL32.DLL >[/color]
[2014/10/29 02:58:23 | 001,040,384 | ---- | M] (Microsoft Corporation) MD5=00DC86D9068D7E780407A8B66E2AFD9D -- C:\Windows\SysWOW64\kernel32.dll
[2014/10/29 02:58:23 | 001,040,384 | ---- | M] (Microsoft Corporation) MD5=00DC86D9068D7E780407A8B66E2AFD9D -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17415_none_8f1d8a7a5e69bda5\kernel32.dll
[2015/07/10 11:30:55 | 000,702,512 | ---- | M] (Microsoft Corporation) MD5=038B10C8E735FE667DA29B2E92A09B8A -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\kernel32.dll
[2015/07/10 11:30:55 | 000,702,512 | ---- | M] (Microsoft Corporation) MD5=038B10C8E735FE667DA29B2E92A09B8A -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_10.0.10240.16384_none_9bbe56eff0f8d352\kernel32.dll
[2014/06/03 19:21:47 | 000,082,041 | ---- | M] () MD5=0C7920D2233655CB99F2BAE78BCFD781 -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16521_none_8f0ed2145e7557c0\kernel32.dll
[2014/06/03 18:36:50 | 000,135,499 | ---- | M] () MD5=1381A386667228317DEA988ECEFC1D62 -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16441_none_84a486042a24d080\kernel32.dll
[2014/06/03 19:21:49 | 000,001,165 | ---- | M] () MD5=3A9C615755EFF9FB838D357A4D8D5E7C -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17031_none_8f03e1e25e7d9b8f\kernel32.dll
[2014/10/29 05:09:24 | 001,309,744 | ---- | M] (Microsoft Corporation) MD5=4F455778B6CDA2FD61D4F8B0A3E0543C -- C:\Windows\SysNative\kernel32.dll
[2014/10/29 05:09:24 | 001,309,744 | ---- | M] (Microsoft Corporation) MD5=4F455778B6CDA2FD61D4F8B0A3E0543C -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17415_none_84c8e0282a08fbaa\kernel32.dll
[2015/04/02 17:53:59 | 000,121,316 | ---- | M] () MD5=63CF5E1D83272D55F2C1A7C752DEC7C9 -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17056_none_8ef3437c5e895224\kernel32.dll
[2014/06/03 19:21:42 | 000,088,050 | ---- | M] () MD5=6E3A5D86925F7D2683C0058387E805B8 -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16384_none_8ed0ef9e5ea3511d\kernel32.dll
[2014/06/03 18:36:52 | 000,137,281 | ---- | M] () MD5=6F1E283E6740914BE8FBD75C900A9C27 -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16521_none_84ba27c22a1495c5\kernel32.dll
[2014/06/03 18:36:48 | 000,140,055 | ---- | M] () MD5=96A3F18D728E6EBC6907823DA9C3758F -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16384_none_847c454c2a428f22\kernel32.dll
[2014/06/03 18:36:49 | 000,135,626 | ---- | M] () MD5=A6C043CC1A2E443BF306B29AADCC89D0 -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16408_none_84d6c7ba29fe121d\kernel32.dll
[2014/06/03 18:36:54 | 000,038,194 | ---- | M] () MD5=DA27B6723C1D4A604310F46F50C005CB -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17031_none_84af37902a1cd994\kernel32.dll
[2014/06/03 19:21:43 | 000,084,833 | ---- | M] () MD5=DC9112C7954B5A42DF927DBA7B47FE92 -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16408_none_8f2b720c5e5ed418\kernel32.dll
[2015/04/02 15:37:25 | 000,149,635 | ---- | M] () MD5=DE0B6AADFB0BA5D0AABA9EAD2011D02C -- C:\Windows\WinSxS\amd64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.17056_none_849e992a2a289029\kernel32.dll
[2014/06/03 19:21:45 | 000,084,771 | ---- | M] () MD5=F28CE411799F15BC8F68102C79725B20 -- C:\Windows\WinSxS\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.3.9600.16441_none_8ef930565e85927b\kernel32.dll

[color=#A23BEC]< MD5 for: MSWSOCK.DLL >[/color]
[2015/07/10 11:30:54 | 000,364,384 | ---- | M] (Microsoft Corporation) MD5=6E887DD203D23FD46D3460A3DB67E0D0 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\mswsock.dll
[2015/07/10 11:30:54 | 000,364,384 | ---- | M] (Microsoft Corporation) MD5=6E887DD203D23FD46D3460A3DB67E0D0 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_10.0.10240.16384_none_c053c8b4c7f90932\mswsock.dll
[2015/04/02 17:45:08 | 000,089,664 | ---- | M] () MD5=91B386E48B823AE3047B924D104C4AE9 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.3.9600.16384_none_a911b7110142c502\mswsock.dll
[2014/10/29 02:06:17 | 000,286,208 | ---- | M] (Microsoft Corporation) MD5=98ECA44A09EFA23890205D2B5233FC96 -- C:\Windows\SysWOW64\mswsock.dll
[2014/10/29 02:06:17 | 000,286,208 | ---- | M] (Microsoft Corporation) MD5=98ECA44A09EFA23890205D2B5233FC96 -- C:\Windows\WinSxS\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.3.9600.17415_none_4d3fb66948abc054\mswsock.dll
[2014/10/29 02:29:43 | 000,339,456 | ---- | M] (Microsoft Corporation) MD5=B394EB3E443DCB195BC65B9A54CD8FE3 -- C:\Windows\SysNative\mswsock.dll
[2014/10/29 02:29:43 | 000,339,456 | ---- | M] (Microsoft Corporation) MD5=B394EB3E443DCB195BC65B9A54CD8FE3 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.3.9600.17415_none_a95e51ed0109318a\mswsock.dll
[2015/04/02 18:25:01 | 000,073,881 | ---- | M] () MD5=DD9EB5415ED0BA50A6FDF18E77D58BA8 -- C:\Windows\WinSxS\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.3.9600.16384_none_4cf31b8d48e553cc\mswsock.dll

[color=#A23BEC]< MD5 for: NDIS.SYS >[/color]
[2014/06/03 18:41:09 | 000,144,548 | ---- | M] () MD5=6FF1A14DC17A19F68C45B759E57F8F54 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.16405_none_4a6b5fcffbc14927\ndis.sys
[2014/06/03 18:41:11 | 000,140,607 | ---- | M] () MD5=7B886741BDAE33AC4F116DF991D1E3CB -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.16475_none_4a1fb05bfbfa0cbe\ndis.sys
[2014/06/03 18:41:08 | 000,141,699 | ---- | M] () MD5=975B2A08EFF9250B2504C01C77993ECC -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.16384_none_4a13de3ffc031231\ndis.sys
[2015/07/14 22:59:47 | 001,113,944 | ---- | M] (Microsoft Corporation) MD5=97DC5967F65503213FD1F1B3E4A6F983 -- C:\Windows\SysNative\drivers\ndis.sys
[2015/07/14 22:59:47 | 001,113,944 | ---- | M] (Microsoft Corporation) MD5=97DC5967F65503213FD1F1B3E4A6F983 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17933_none_4a48e22dfbdb75b0\ndis.sys
[2014/06/03 18:41:10 | 000,139,631 | ---- | M] () MD5=A4F977473222918A2BD275FB72DC4816 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.16408_none_4a6e60adfbbe952c\ndis.sys
[2015/10/08 09:10:22 | 000,163,967 | ---- | M] () MD5=B799AF43B0B317395202AEF55957EEB1 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17199_none_4a0df531fc06cc28\ndis.sys
[2015/07/10 11:30:57 | 001,168,736 | ---- | M] (Microsoft Corporation) MD5=C055015D9B573A7EDAF2B2948E687F36 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\drivers\ndis.sys
[2015/07/10 11:30:57 | 001,168,736 | ---- | M] (Microsoft Corporation) MD5=C055015D9B573A7EDAF2B2948E687F36 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_10.0.10240.16384_none_6155efe3c2b95661\ndis.sys
[2014/09/18 18:14:13 | 000,025,682 | ---- | M] () MD5=D2D6A481A75207BF24E9D48C61B7F012 -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17031_none_4a46d083fbdd5ca3\ndis.sys
[2015/10/08 09:10:23 | 000,083,281 | ---- | M] () MD5=E47216FC1C4FCA5C1A9E3BBB79EA37FD -- C:\Windows\WinSxS\amd64_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17399_none_4a0df8fdfc06c676\ndis.sys

[color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color]
[2014/10/29 02:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) MD5=02D117FC638B768BD1A15F8000B83EAE -- C:\Windows\SysNative\netlogon.dll
[2014/10/29 02:26:21 | 000,838,656 | ---- | M] (Microsoft Corporation) MD5=02D117FC638B768BD1A15F8000B83EAE -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17415_none_eec2b22a0bb75b53\netlogon.dll
[2014/06/03 19:24:32 | 000,058,552 | ---- | M] () MD5=35048C9600694C3BF01D644D1AAE62BE -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.16384_none_f8cac1a04051b0c6\netlogon.dll
[2015/04/02 17:38:55 | 000,125,384 | ---- | M] () MD5=45C2C2EA335BD7FF360C7F006B915766 -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17041_none_ee9e39a60bd3552e\netlogon.dll
[2015/07/10 11:30:56 | 000,836,096 | ---- | M] (Microsoft Corporation) MD5=5E9439E5FA71649335D8FB0090843062 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\netlogon.dll
[2015/07/10 11:30:56 | 000,836,096 | ---- | M] (Microsoft Corporation) MD5=5E9439E5FA71649335D8FB0090843062 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_10.0.10240.16384_none_05b828f1d2a732fb\netlogon.dll
[2015/04/02 17:57:17 | 000,105,907 | ---- | M] () MD5=B25E2DE4078511EB1747FA0BDB6E4FC5 -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17041_none_f8f2e3f840341729\netlogon.dll
[2014/10/29 02:02:34 | 000,695,296 | ---- | M] (Microsoft Corporation) MD5=CCEC6CB98A00ECE7F5AFB9C0FC9427B3 -- C:\Windows\SysWOW64\netlogon.dll
[2014/10/29 02:02:34 | 000,695,296 | ---- | M] (Microsoft Corporation) MD5=CCEC6CB98A00ECE7F5AFB9C0FC9427B3 -- C:\Windows\WinSxS\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17415_none_f9175c7c40181d4e\netlogon.dll
[2014/06/03 18:46:18 | 000,108,975 | ---- | M] () MD5=D817ED82C2A0E1CED9B396826F52F7CB -- C:\Windows\WinSxS\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.16384_none_ee76174e0bf0eecb\netlogon.dll

[color=#A23BEC]< MD5 for: NTFS.SYS >[/color]
[2014/06/03 18:41:37 | 000,079,923 | ---- | M] () MD5=5237125E4CEFA4B02A820998092A2DBA -- C:\Windows\WinSxS\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.3.9600.17031_none_97627c0bf0bcea79\ntfs.sys
[2015/07/10 11:30:56 | 002,117,472 | ---- | M] (Microsoft Corporation) MD5=5B3D91EB07785D0EDB19449D5C35E30A -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\drivers\ntfs.sys
[2015/07/10 11:30:56 | 002,117,472 | ---- | M] (Microsoft Corporation) MD5=5B3D91EB07785D0EDB19449D5C35E30A -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-ntfs_31bf3856ad364e35_10.0.10240.16384_none_ae719b6bb798e437\ntfs.sys
[2014/06/03 18:41:33 | 000,328,571 | ---- | M] () MD5=6986BA446666FDAFA2DBB95F9D8E0A23 -- C:\Windows\WinSxS\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.3.9600.16384_none_972f89c7f0e2a007\ntfs.sys
[2014/10/15 09:32:37 | 002,025,792 | ---- | M] (Microsoft Corporation) MD5=7F68063A5A0461E02BC860CE0E6BFDDC -- C:\Windows\SysNative\drivers\ntfs.sys
[2014/10/15 09:32:37 | 002,025,792 | ---- | M] (Microsoft Corporation) MD5=7F68063A5A0461E02BC860CE0E6BFDDC -- C:\Windows\WinSxS\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.3.9600.17401_none_9782f367f0a48b42\ntfs.sys
[2014/09/18 18:14:18 | 000,216,915 | ---- | M] () MD5=BBB0E3DE6DA1971DB7EC0C74B0F50310 -- C:\Windows\WinSxS\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.3.9600.17056_none_9751dda5f0c8a10e\ntfs.sys
[2015/04/02 17:33:41 | 000,378,139 | ---- | M] () MD5=E5D1987CD7FBB2169440CD9B8E2AB87E -- C:\Windows\WinSxS\amd64_microsoft-windows-ntfs_31bf3856ad364e35_6.3.9600.17238_none_976981ddf0b69628\ntfs.sys

[color=#A23BEC]< MD5 for: NVSTOR.SYS >[/color]
[2013/08/22 13:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\Windows\SysNative\drivers\nvstor.sys
[2013/08/22 13:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_7ba65ba4b222e751\nvstor.sys
[2013/08/22 13:43:32 | 000,168,288 | ---- | M] (NVIDIA Corporation) MD5=1F43ABFFAC3D6CA356851D517392966E -- C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.3.9600.16384_none_2a99233292f5aadb\nvstor.sys
[2015/07/10 11:30:51 | 000,166,240 | ---- | M] (NVIDIA Corporation) MD5=76F19EAE7A52CBAF7B8EC428BE6E0DA0 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\drivers\nvstor.sys
[2015/07/10 11:30:51 | 000,166,240 | ---- | M] (NVIDIA Corporation) MD5=76F19EAE7A52CBAF7B8EC428BE6E0DA0 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\DriverStore\FileRepository\nvraid.inf_amd64_3ee6d81b22b3ea66\nvstor.sys
[2015/07/10 11:30:51 | 000,166,240 | ---- | M] (NVIDIA Corporation) MD5=76F19EAE7A52CBAF7B8EC428BE6E0DA0 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_10.0.10240.16384_none_41db34d659abef0b\nvstor.sys

[color=#A23BEC]< MD5 for: PROQUOTA.EXE >[/color]
[2014/10/29 03:20:00 | 000,032,256 | ---- | M] (Microsoft Corporation) MD5=864379396733031C99B64550358CAEBD -- C:\Windows\SysNative\proquota.exe
[2014/10/29 03:20:00 | 000,032,256 | ---- | M] (Microsoft Corporation) MD5=864379396733031C99B64550358CAEBD -- C:\Windows\WinSxS\amd64_microsoft-windows-proquota_31bf3856ad364e35_6.3.9600.17415_none_18d1f2be66229ae5\proquota.exe
[2015/04/02 18:20:51 | 000,003,774 | ---- | M] () MD5=8FB27AE214469C91285EE90DADF94D78 -- C:\Windows\WinSxS\x86_microsoft-windows-proquota_31bf3856ad364e35_6.3.9600.16384_none_bc66bc5eadfebd27\proquota.exe
[2015/04/02 17:36:09 | 000,002,700 | ---- | M] () MD5=C76ABF6F332C8E55700EADCB3F0FE880 -- C:\Windows\WinSxS\amd64_microsoft-windows-proquota_31bf3856ad364e35_6.3.9600.16384_none_188557e2665c2e5d\proquota.exe
[2014/10/29 02:40:27 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=DF801B9FC4247EBFBFE07E5EC417C5B0 -- C:\Windows\SysWOW64\proquota.exe
[2014/10/29 02:40:27 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=DF801B9FC4247EBFBFE07E5EC417C5B0 -- C:\Windows\WinSxS\x86_microsoft-windows-proquota_31bf3856ad364e35_6.3.9600.17415_none_bcb3573aadc529af\proquota.exe

[color=#A23BEC]< MD5 for: QMGR.DLL >[/color]
[2014/10/29 02:43:34 | 000,933,376 | ---- | M] (Microsoft Corporation) MD5=48554994279BFE17A3D2B00076D0CB1A -- C:\Windows\SysNative\qmgr.dll
[2014/10/29 02:43:34 | 000,933,376 | ---- | M] (Microsoft Corporation) MD5=48554994279BFE17A3D2B00076D0CB1A -- C:\Windows\WinSxS\amd64_microsoft-windows-bits-client_31bf3856ad364e35_6.3.9600.17415_none_149bbfd3cd2f7e88\qmgr.dll
[2015/04/02 15:28:47 | 000,297,501 | ---- | M] () MD5=C3D7BF1A7970C6765A8F6F7E42099FCE -- C:\Windows\WinSxS\amd64_microsoft-windows-bits-client_31bf3856ad364e35_6.3.9600.16384_none_144f24f7cd691200\qmgr.dll

[color=#A23BEC]< MD5 for: SCECLI.DLL >[/color]
[2015/04/02 17:57:09 | 000,042,572 | ---- | M] () MD5=22CDB04B964A8D34C42BB7ED150784F8 -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_3320ecb8e1733781\scecli.dll
[2015/07/10 11:30:56 | 000,284,672 | ---- | M] (Microsoft Corporation) MD5=7DD59DB925AC2401D33B38152551153E -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\scecli.dll
[2015/07/10 11:30:56 | 000,284,672 | ---- | M] (Microsoft Corporation) MD5=7DD59DB925AC2401D33B38152551153E -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_10.0.10240.16384_none_400e540a73c8b9b6\scecli.dll
[2015/04/02 17:38:32 | 000,045,911 | ---- | M] () MD5=878EBE290BED3EE6AC21BF4EE1458F67 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_28cc4266ad127586\scecli.dll
[2014/10/29 02:23:16 | 000,274,944 | ---- | M] (Microsoft Corporation) MD5=9A475B8F19A15BFDE8DF84E40ECAE8AA -- C:\Windows\SysNative\scecli.dll
[2014/10/29 02:23:16 | 000,274,944 | ---- | M] (Microsoft Corporation) MD5=9A475B8F19A15BFDE8DF84E40ECAE8AA -- C:\Windows\WinSxS\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17415_none_2918dd42acd8e20e\scecli.dll
[2014/10/29 02:01:41 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\SysWOW64\scecli.dll
[2014/10/29 02:01:41 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\WinSxS\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17415_none_336d8794e139a409\scecli.dll

[color=#A23BEC]< MD5 for: SPOOLSV.EXE >[/color]
[2015/04/02 17:36:00 | 000,144,407 | ---- | M] () MD5=5E94BD87266C67420DCB3FF2516D8A9D -- C:\Windows\WinSxS\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.3.9600.17238_none_c743fb429553c1ab\spoolsv.exe
[2014/09/18 18:14:42 | 000,099,497 | ---- | M] () MD5=8CA60826DC34EB3177C1F84D7A05D6C4 -- C:\Windows\WinSxS\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.3.9600.16384_none_c70a032c957fcb8a\spoolsv.exe
[2014/10/29 01:54:15 | 000,827,392 | ---- | M] (Microsoft Corporation) MD5=FCB156A6745631A67DEA61827061D483 -- C:\Windows\SysNative\spoolsv.exe
[2014/10/29 01:54:15 | 000,827,392 | ---- | M] (Microsoft Corporation) MD5=FCB156A6745631A67DEA61827061D483 -- C:\Windows\WinSxS\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.3.9600.17415_none_c7569e0895463812\spoolsv.exe

[color=#A23BEC]< MD5 for: SVCHOST.EXE >[/color]
[2015/04/02 18:22:13 | 000,007,517 | ---- | M] () MD5=73AA583D4FB0F05C313B38C091D94804 -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_4a5b1e2820e75323\svchost.exe
[2015/07/10 11:30:56 | 000,039,856 | ---- | M] (Microsoft Corporation) MD5=A1AEAFC58DF7803B8AA2B09EA93C722F -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\svchost.exe
[2015/07/10 11:30:56 | 000,039,856 | ---- | M] (Microsoft Corporation) MD5=A1AEAFC58DF7803B8AA2B09EA93C722F -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_10.0.10240.16384_none_bdbbcb4f9ffb0889\svchost.exe
[2015/04/02 17:39:08 | 000,007,559 | ---- | M] () MD5=CFE97816CBBEF783FD8634109F1877D2 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_a679b9abd944c459\svchost.exe
[2014/10/29 04:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\SysWOW64\svchost.exe
[2014/10/29 04:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_4aa7b90420adbfab\svchost.exe
[2014/10/29 05:11:20 | 000,038,792 | ---- | M] (Microsoft Corporation) MD5=E3A2AD05E24105B35E986CF9CB38EC47 -- C:\Windows\SysNative\svchost.exe
[2014/10/29 05:11:20 | 000,038,792 | ---- | M] (Microsoft Corporation) MD5=E3A2AD05E24105B35E986CF9CB38EC47 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_a6c65487d90b30e1\svchost.exe

[color=#A23BEC]< MD5 for: TERMSRV.DLL >[/color]
[2014/06/03 18:53:52 | 000,000,012 | ---- | M] () MD5=215331662ED469004AD8AEFA69EB1DFF -- C:\Windows\WinSxS\amd64_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.3.9600.16384_none_7f5da1d3283b1dd6\termsrv.dll
[2015/04/02 17:42:53 | 000,200,637 | ---- | M] () MD5=640B43E4063B00DD1769C93FEDBFD8B4 -- C:\Windows\WinSxS\amd64_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.3.9600.17095_none_7f53b5b72842754a\termsrv.dll
[2014/07/10 20:39:40 | 000,160,809 | ---- | M] () MD5=AD8954261EED4AB66F8CFB0CAC218143 -- C:\Windows\WinSxS\amd64_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.3.9600.16389_none_7f62a34528369c89\termsrv.dll
[2014/10/29 02:34:57 | 001,114,624 | ---- | M] (Microsoft Corporation) MD5=C50997E282576DA492EBA66B059D4196 -- C:\Windows\SysNative\termsrv.dll
[2014/10/29 02:34:57 | 001,114,624 | ---- | M] (Microsoft Corporation) MD5=C50997E282576DA492EBA66B059D4196 -- C:\Windows\WinSxS\amd64_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.3.9600.17415_none_7faa3caf28018a5e\termsrv.dll

[color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
[2015/04/02 17:44:38 | 000,002,671 | ---- | M] () MD5=061AC3BD7ADC5DCBA6AC0F23895266F8 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_cce71a20a5a6fe7f\userinit.exe
[2015/04/02 18:24:47 | 000,004,269 | ---- | M] () MD5=1AE98168631581DE1343C3A87A6CBCA9 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_70c87e9ced498d49\userinit.exe
[2014/10/29 02:28:08 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=5C131534A3EA4A461A793FB507A8004F -- C:\Windows\SysNative\userinit.exe
[2014/10/29 02:28:08 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=5C131534A3EA4A461A793FB507A8004F -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_cd33b4fca56d6b07\userinit.exe
[2015/07/10 11:30:56 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=5F6D4F12EA33BFC0F0F8CEEAC332AB2B -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\userinit.exe
[2015/07/10 11:30:56 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=5F6D4F12EA33BFC0F0F8CEEAC332AB2B -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_10.0.10240.16384_none_e4292bc46c5d42af\userinit.exe
[2014/10/29 02:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\SysWOW64\userinit.exe
[2014/10/29 02:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_71151978ed0ff9d1\userinit.exe

[color=#A23BEC]< MD5 for: VOLSNAP.SYS >[/color]
[2014/06/03 19:05:28 | 000,039,272 | ---- | M] () MD5=1753D1D0C815FEFC99AB01F95DD9977A -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.3.9600.16523_none_06b4fa95cfdc3a92\volsnap.sys
[2014/09/18 18:29:31 | 000,031,490 | ---- | M] () MD5=50C79EDB89463E12CA94E0840DFD0932 -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.3.9600.17041_none_069d39e3cfee67a4\volsnap.sys
[2014/06/19 03:13:36 | 000,310,080 | ---- | M] (Microsoft Corporation) MD5=64CA2B4A49A8EAF495E435623ECCE7DB -- C:\Windows\SysNative\drivers\volsnap.sys
[2014/06/19 03:13:36 | 000,310,080 | ---- | M] (Microsoft Corporation) MD5=64CA2B4A49A8EAF495E435623ECCE7DB -- C:\Windows\SysNative\DriverStore\FileRepository\volume.inf_amd64_8687137d6e4faf5d\volsnap.sys
[2014/06/19 03:13:36 | 000,310,080 | ---- | M] (Microsoft Corporation) MD5=64CA2B4A49A8EAF495E435623ECCE7DB -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.3.9600.17215_none_06c1ae9bcfd2737b\volsnap.sys
[2015/07/10 11:30:51 | 000,378,720 | ---- | M] (Microsoft Corporation) MD5=823A237D871CD652C6BFD47BECB6810A -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\drivers\volsnap.sys
[2015/07/10 11:30:51 | 000,378,720 | ---- | M] (Microsoft Corporation) MD5=823A237D871CD652C6BFD47BECB6810A -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\DriverStore\FileRepository\volume.inf_amd64_b017de7f410d7e0a\volsnap.sys
[2015/07/10 11:30:51 | 000,378,720 | ---- | M] (Microsoft Corporation) MD5=823A237D871CD652C6BFD47BECB6810A -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_10.0.10240.16384_none_1db7292f96c24571\volsnap.sys
[2014/06/12 08:57:42 | 000,033,436 | ---- | M] () MD5=A24CC4ADEC9998D129FB7F5A1D1BA606 -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.3.9600.17031_none_06a809cfcfe64bb3\volsnap.sys
[2014/06/03 19:05:28 | 000,039,796 | ---- | M] () MD5=CF54BDF9D7A69E59A1D75728C893F1A5 -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.3.9600.16384_none_0675178bd00c0141\volsnap.sys

[color=#A23BEC]< MD5 for: WININET.DLL >[/color]
[2014/09/04 18:15:58 | 000,307,122 | ---- | M] () MD5=0218FED60D4EFCAFCBB63785BF6B4037 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17031_none_05ca0a1a84b38391\wininet.dll
[2015/10/30 23:17:06 | 002,487,808 | ---- | M] (Microsoft Corporation) MD5=033E70DEEE5FED5E9A3E197A2DB1A618 -- C:\Windows\SysNative\wininet.dll
[2015/10/30 23:17:06 | 002,487,808 | ---- | M] (Microsoft Corporation) MD5=033E70DEEE5FED5E9A3E197A2DB1A618 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.18098_none_05cf6e4484aecc29\wininet.dll
[2014/09/04 18:50:25 | 000,342,076 | ---- | M] () MD5=0AFB4327CF7BAEB08935FFBB29909F6D -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.16384_none_a98fba06cc6a349d\wininet.dll
[2015/09/17 18:38:52 | 000,217,045 | ---- | M] () MD5=17647FA5AEE841BBBFCAA4895CD7EE53 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17937_none_a949969acc9fa79a\wininet.dll
[2015/03/14 19:35:09 | 000,281,361 | ---- | M] () MD5=18657B28917AC11E8D14C441B98D9A36 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17631_none_05892a9284e42b37\wininet.dll
[2015/04/23 11:43:58 | 000,162,297 | ---- | M] () MD5=31E93A671DB46286530E39490BCDCB91 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17690_none_a970a792cc81386a\wininet.dll
[2015/07/10 11:30:56 | 002,741,248 | ---- | M] (Microsoft Corporation) MD5=32A862495B7C356B9895FDD0B9023C5F -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\wininet.dll
[2015/07/10 11:30:56 | 002,741,248 | ---- | M] (Microsoft Corporation) MD5=32A862495B7C356B9895FDD0B9023C5F -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.10240.16384_none_4da1791f65f4f473\wininet.dll
[2014/06/03 19:39:51 | 000,331,613 | ---- | M] () MD5=389A24548CD56019602607FB9EEF23F8 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.16412_none_a97e15a4cc786beb\wininet.dll
[2015/05/15 16:31:58 | 000,239,417 | ---- | M] () MD5=45357D0C245C663DEF3CF18ADED0C7A7 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17728_none_a95e1f60cc907002\wininet.dll
[2015/07/17 19:08:33 | 000,278,628 | ---- | M] () MD5=49ADDFFAB1D8EA9315823D2D66F0B187 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17842_none_0574743c84f39611\wininet.dll
[2015/07/17 19:18:23 | 000,211,149 | ---- | M] () MD5=523FA1BC881932CAA8686B264BA3B814 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17842_none_a955d8b8cc9624db\wininet.dll
[2014/10/23 17:41:46 | 000,235,179 | ---- | M] () MD5=6096501D1F4F82BEA0C4D5683106B3F2 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17278_none_a999306ecc636300\wininet.dll
[2015/11/22 20:56:46 | 000,000,487 | ---- | M] () MD5=677B830D40849BE45C252BF4EA1D6951 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.18053_none_a9ad4380cc547572\wininet.dll
[2015/10/15 09:56:47 | 000,212,832 | ---- | M] () MD5=685A53313DA2CFE059DC854C145F2427 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.18036_none_05c99a1884b400dd\wininet.dll
[2015/05/15 16:15:34 | 000,318,756 | ---- | M] () MD5=74900A2ADA0D5347414E96EC3A270F8F -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17728_none_057cbae484ede138\wininet.dll
[2014/06/03 18:30:03 | 000,478,680 | ---- | M] () MD5=7600F7650146FD1ECA959BE056152A4D -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.16384_none_05ae558a84c7a5d3\wininet.dll
[2014/11/20 18:53:45 | 000,499,415 | ---- | M] () MD5=78A79794F4D389C45FFCDC55AE89DE58 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17351_none_05ab9aea84ca0a12\wininet.dll
[2015/11/20 14:34:50 | 000,000,498 | ---- | M] () MD5=799F529E781FB4BD191B0DABDBEAE4DD -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.18053_none_05cbdf0484b1e6a8\wininet.dll
[2015/10/30 22:51:28 | 002,011,136 | ---- | M] (Microsoft Corporation) MD5=832CA97817B20B74E2D74A8154630311 -- C:\Windows\SysWOW64\wininet.dll
[2015/10/30 22:51:28 | 002,011,136 | ---- | M] (Microsoft Corporation) MD5=832CA97817B20B74E2D74A8154630311 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.18098_none_a9b0d2c0cc515af3\wininet.dll
[2014/06/03 18:30:08 | 000,478,759 | ---- | M] () MD5=842C1FB395CFFB676DC66DBB2EE18A2E -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.16438_none_059e290c84d4a995\wininet.dll
[2015/09/17 18:38:48 | 000,212,636 | ---- | M] () MD5=843C6280A5EAE4EC436E1144A49D970E -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17905_none_a946c34ccca22853\wininet.dll
[2014/11/20 19:04:45 | 000,430,337 | ---- | M] () MD5=8E40AAFEFDB9027AC0F38885EC30FEFF -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17351_none_a98cff66cc6c98dc\wininet.dll
[2014/10/23 17:32:21 | 000,315,272 | ---- | M] () MD5=90BEBDBAFBBDAC3AF477E2358F8BA9F5 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17278_none_05b7cbf284c0d436\wininet.dll
[2015/09/17 18:18:02 | 000,228,404 | ---- | M] () MD5=96410BE4AD7B6203B26E615E086F7EBD -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17937_none_0568321e84fd18d0\wininet.dll
[2015/06/18 21:16:30 | 000,382,194 | ---- | M] () MD5=9DF188CA82BC185FABD3A4707CBD9895 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17801_none_057089dc84f71714\wininet.dll
[2015/02/20 18:05:06 | 000,059,876 | ---- | M] () MD5=B23BBE12AF200084BC77C83140046803 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17498_none_05a42cae84cf3ec6\wininet.dll
[2014/12/11 16:43:07 | 000,253,886 | ---- | M] () MD5=B2DC3CB5B3FAEB2C012BF1B22DBEFC6C -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17416_none_a97dbc6acc78cf96\wininet.dll
[2015/09/17 18:18:00 | 000,281,824 | ---- | M] () MD5=B9631D28F5FDD2057DEED5EF7C1BD54F -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17905_none_05655ed084ff9989\wininet.dll
[2014/12/11 16:38:28 | 000,333,928 | ---- | M] () MD5=BDB363574A2F060164762ACBAEC5B613 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17416_none_059c57ee84d640cc\wininet.dll
[2014/09/04 18:50:28 | 000,229,501 | ---- | M] () MD5=CC12664DBD7CA68C750082A9368CD5F6 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17031_none_a9ab6e96cc56125b\wininet.dll
[2015/06/20 11:26:21 | 000,286,789 | ---- | M] () MD5=D432C40F1EA5CF48D05503742240805B -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17801_none_a951ee58cc99a5de\wininet.dll
[2015/03/14 19:44:41 | 000,200,265 | ---- | M] () MD5=D594CB3F63B80335D5B7A9478C90C2AF -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17631_none_a96a8f0ecc86ba01\wininet.dll
[2015/10/15 10:04:08 | 000,190,941 | ---- | M] () MD5=D91594740AE26D36F47EBCBE573B6006 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.18036_none_a9aafe94cc568fa7\wininet.dll
[2015/02/20 18:10:07 | 000,003,879 | ---- | M] () MD5=DD9BB654041748399F4F03E4573A9EA8 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17498_none_a985912acc71cd90\wininet.dll
[2014/06/03 19:39:54 | 000,331,603 | ---- | M] () MD5=E1F2CD824568D4B828A6E321A34822A6 -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.16438_none_a97f8d88cc77385f\wininet.dll
[2014/09/18 18:38:40 | 000,291,660 | ---- | M] () MD5=E95D91A9CAA671059F4B3CA92EA103DB -- C:\Windows\WinSxS\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17239_none_a995187ecc671745\wininet.dll
[2015/04/23 11:35:20 | 000,004,139 | ---- | M] () MD5=F3CE3F1A9A574391CFDD1CDAE092287E -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17690_none_058f431684dea9a0\wininet.dll
[2014/09/18 18:12:08 | 000,412,638 | ---- | M] () MD5=F3FB5E78787A6FDA806E520F5971F682 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.17239_none_05b3b40284c4887b\wininet.dll
[2014/06/03 18:30:06 | 000,478,753 | ---- | M] () MD5=FE25C20B43ADB6E9130A9355C4C8F633 -- C:\Windows\WinSxS\amd64_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_11.0.9600.16412_none_059cb12884d5dd21\wininet.dll

[color=#A23BEC]< MD5 for: WININIT.EXE >[/color]
[2014/10/29 02:25:54 | 000,145,920 | ---- | M] (Microsoft Corporation) MD5=A570A64292214C43E0BA50E6A72A6380 -- C:\Windows\SysNative\wininit.exe
[2014/10/29 02:25:54 | 000,145,920 | ---- | M] (Microsoft Corporation) MD5=A570A64292214C43E0BA50E6A72A6380 -- C:\Windows\WinSxS\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.3.9600.17415_none_21fdb3b5d80e199e\wininit.exe
[2015/07/10 11:30:56 | 000,290,304 | ---- | M] (Microsoft Corporation) MD5=CAAA293DD133160DF13D95CC48FC42B9 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\wininit.exe
[2015/07/10 11:30:56 | 000,290,304 | ---- | M] (Microsoft Corporation) MD5=CAAA293DD133160DF13D95CC48FC42B9 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-wininit_31bf3856ad364e35_10.0.10240.16384_none_38f32a7d9efdf146\wininit.exe
[2015/04/02 17:46:23 | 000,026,215 | ---- | M] () MD5=DCF5C72FC1D8BE1165975F1339DC92DA -- C:\Windows\WinSxS\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.3.9600.16384_none_21b118d9d847ad16\wininit.exe

[color=#A23BEC]< MD5 for: WININIT.INI >[/color]
[2015/06/11 19:12:22 | 000,000,110 | ---- | M] () MD5=F7DE9002BE1ED5D9F6B45F0057DE2A8C -- C:\Windows\wininit.ini

[color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
[2015/07/10 11:30:56 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=536B686D86402D254C59B5DE3A575F45 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\winlogon.exe
[2015/07/10 11:30:56 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=536B686D86402D254C59B5DE3A575F45 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\winlogon.exe
[2015/07/10 11:30:56 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=536B686D86402D254C59B5DE3A575F45 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_10.0.10240.16384_none_77c372c56f9ec699\winlogon.exe
[2015/07/10 11:30:56 | 000,578,048 | ---- | M] (Microsoft Corporation) MD5=536B686D86402D254C59B5DE3A575F45 -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_10.0.10240.16384_none_77c372c56f9ec699\winlogon.exe
[2015/04/02 17:46:25 | 000,100,951 | ---- | M] () MD5=A176623494AF009927242266EF51DCFB -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17031_none_60b45365a8c2ccdb\winlogon.exe
[2015/04/02 17:46:25 | 000,100,951 | ---- | M] () MD5=A176623494AF009927242266EF51DCFB -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17031_none_60b45365a8c2ccdb\winlogon.exe
[2014/06/03 18:59:32 | 000,089,459 | ---- | M] () MD5=E40DC8DF924E02F04F3620DBAC1ACE31 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.16384_none_60816121a8e88269\winlogon.exe
[2014/06/03 18:59:32 | 000,089,459 | ---- | M] () MD5=E40DC8DF924E02F04F3620DBAC1ACE31 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.16384_none_60816121a8e88269\winlogon.exe
[2014/10/29 02:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\Windows\SysNative\winlogon.exe
[2014/10/29 02:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\Windows\SysNative\winlogon.exe
[2014/10/29 02:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17415_none_60cdfbfda8aeeef1\winlogon.exe
[2014/10/29 02:22:52 | 000,572,416 | ---- | M] (Microsoft Corporation) MD5=EC498BAE1F0D3E0E401C963F8D76C437 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17415_none_60cdfbfda8aeeef1\winlogon.exe

[color=#A23BEC]< MD5 for: WS2_32.DLL >[/color]
[2015/07/10 11:30:57 | 000,422,560 | ---- | M] (Microsoft Corporation) MD5=0E49B1E08DF8484884A0092C48B933DB -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\System32\ws2_32.dll
[2015/07/10 11:30:57 | 000,422,560 | ---- | M] (Microsoft Corporation) MD5=0E49B1E08DF8484884A0092C48B933DB -- C:\$Windows.~BT\Sources\SafeOS\SafeOS.Mount\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_10.0.10240.16384_none_fab8227169035068\ws2_32.dll
[2014/10/29 04:05:15 | 000,321,248 | ---- | M] (Microsoft Corporation) MD5=34E71A52A1BFA68411CAECCFB6D72F8C -- C:\Windows\SysWOW64\ws2_32.dll
[2014/10/29 04:05:15 | 000,321,248 | ---- | M] (Microsoft Corporation) MD5=34E71A52A1BFA68411CAECCFB6D72F8C -- C:\Windows\WinSxS\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.17415_none_87a41025e9b6078a\ws2_32.dll
[2014/10/29 04:51:53 | 000,363,080 | ---- | M] (Microsoft Corporation) MD5=3A0B3B44C263DB1823360FF3E5C223CE -- C:\Windows\SysNative\ws2_32.dll
[2014/10/29 04:51:53 | 000,363,080 | ---- | M] (Microsoft Corporation) MD5=3A0B3B44C263DB1823360FF3E5C223CE -- C:\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.17415_none_e3c2aba9a21378c0\ws2_32.dll
[2015/04/02 18:25:11 | 000,062,052 | ---- | M] () MD5=58D09EFD883813FC9709A9D98A7209DF -- C:\Windows\WinSxS\x86_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.16384_none_87577549e9ef9b02\ws2_32.dll
[2015/04/02 17:45:26 | 000,065,749 | ---- | M] () MD5=F77C96590EA4741EB62B0FBC7A9FFFE8 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-ws232_31bf3856ad364e35_6.3.9600.16384_none_e37610cda24d0c38\ws2_32.dll

[color=#A23BEC]< HKEY_LOCAL_MACHINE\SYSTEM\Curr entControlSet\Control\Session Manager\SubSystems /s >[/color]

[color=#A23BEC]< %systemroot%\*. /mp /s >[/color]

[color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
[2015/10/30 23:09:39 | 012,854,272 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\system32\ieframe.dll

[color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\system32\drivers\ *.sys /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\System32\config\* .sav >[/color]

[color=#A23BEC]< c:\$recycle.bin\*.* /s >[/color]
[2014/06/03 20:27:27 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-19\desktop.ini
[2015/04/19 11:12:06 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I044LLE.JPG
[2015/04/19 11:12:31 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I0AAEAF.JPG
[2014/09/20 11:19:23 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I0XF70Z.mkv
[2015/02/07 18:27:06 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I28DVAA.x264-ROUGH
[2014/11/16 11:53:01 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I3NWCSQ.JPG
[2015/04/19 11:12:56 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I4ENESD.JPG
[2015/04/19 11:12:47 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I4QBWWM.JPG
[2015/06/06 12:26:19 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I596KJC.JPG
[2014/09/27 16:44:21 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I5EPMH6.JPG
[2015/04/19 11:12:47 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I6QVU1Q.JPG
[2015/02/21 18:11:51 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I6W43FP.JPG
[2015/02/21 13:37:34 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I7FK8TE.mkv
[2015/04/19 11:11:55 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I7QFVKF.JPG
[2015/04/19 11:13:18 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I8LVCJN.JPG
[2015/04/19 11:12:49 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I8PUZY4.JPG
[2015/04/19 11:13:29 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$I9YCYV3.JPG
[2015/06/06 12:26:17 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IANKRHC.JPG
[2015/04/19 11:11:56 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IC2XCZP.JPG
[2015/04/19 11:12:36 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$ICGHS8V.JPG
[2014/09/27 16:44:21 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IDV2H81.JPG
[2015/04/19 11:12:40 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IFNWUMI.JPG
[2014/09/27 16:44:21 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IGKKR0I.JPG
[2015/04/19 11:11:58 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$ILZPFD5.JPG
[2015/04/19 11:12:37 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IMH6NDA.JPG
[2015/04/19 11:12:07 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IO4TWD3.JPG
[2014/09/27 16:44:21 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IODOOXM.JPG
[2015/04/19 11:14:13 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IOHIWX6.JPG
[2015/04/19 11:12:46 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IPIF53S.JPG
[2015/04/19 11:12:21 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IQC6JAM.JPG
[2015/04/19 11:11:54 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$ISDK3DT.JPG
[2015/08/31 13:41:02 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IT23K02.lnk
[2015/04/19 11:11:57 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IUZXNII.JPG
[2015/04/19 11:12:59 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IWYZF25.JPG
[2015/04/19 11:15:16 | 000,000,544 | ---- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\$IXPVCUT.JPG
[2014/05/24 12:45:43 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1001\desktop.ini
[2014/05/24 13:33:29 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-1004\desktop.ini
[2014/03/28 16:37:44 | 000,000,129 | -HS- | M] () -- c:\$recycle.bin\S-1-5-21-2179158368-4115444144-449989576-500\desktop.ini

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 237 bytes -> C:\Users\bruno\SkyDrive:ms-properties

< End of report >

Publicité


Signaler le contenu de ce document

Publicité