Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x86) Version:06-05-2016 03 Exécuté par MOHAMED (administrateur) sur MOHAMED-PC (07-05-2016 06:39:28) Exécuté depuis C:\Users\MOHAMED\Desktop Profils chargés: MOHAMED (Profils disponibles: MOHAMED) Platform: Microsoft Windows 7 Professionnel Service Pack 1 (X86) Langue: Français (France) Internet Explorer Version 8 (Navigateur par défaut: Opera) Mode d'amorçage: Normal Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processus (Avec liste blanche) ================= (Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.) (ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe () C:\ProgramData\DatacardService\HWDeviceService.exe (Atheros Communications, Inc.) C:\Program Files\Jumpstart\jswpbapi.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe () C:\ProgramData\Modem HDM EC156\OnlineUpdate\ouc.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe ==================== Registre (Avec liste blanche) =========================== (Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [595480 2016-03-20] (Oracle Corporation) HKLM\...\Run: [jswtrayutil] => C:\Program Files\Jumpstart\jswtrayutil.exe [528384 2008-09-26] (Atheros Communications, Inc.) HKU\S-1-5-21-998902749-2816007284-3194843033-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6675672 2016-04-15] (Piriform Ltd) HKU\S-1-5-21-998902749-2816007284-3194843033-1000\...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner.exe [6675672 2016-04-15] (Piriform Ltd) HKU\S-1-5-21-998902749-2816007284-3194843033-1000\...\MountPoints2: F - F:\autorn.exe runcd.exe HKU\S-1-5-21-998902749-2816007284-3194843033-1000\...\MountPoints2: {84941c70-f8dd-11e5-b35b-001e37f62b45} - F:\AutoRun.exe HKU\S-1-5-21-998902749-2816007284-3194843033-1000\...\MountPoints2: {84941c74-f8dd-11e5-b35b-001e37f62b45} - F:\AutoRun.exe HKU\S-1-5-21-998902749-2816007284-3194843033-1000\...\MountPoints2: {a474abda-f91f-11e5-8cc8-001e37f62b45} - F:\AutoRun.exe HKU\S-1-5-21-998902749-2816007284-3194843033-1000\...\MountPoints2: {bd3dd0b0-f802-11e5-9d5d-001e37f62b45} - F:\AutoRun.exe HKU\S-1-5-21-998902749-2816007284-3194843033-1000\...\MountPoints2: {bd3dd0c1-f802-11e5-9d5d-001e37f62b45} - F:\AutoRun.exe HKU\S-1-5-21-998902749-2816007284-3194843033-1000\...\MountPoints2: {d564b953-13bf-11e6-8f10-001e37f62b45} - F:\AutoRun.exe HKU\S-1-5-21-998902749-2816007284-3194843033-1000\...\MountPoints2: {d564b958-13bf-11e6-8f10-001e37f62b45} - F:\AutoRun.exe HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2016-03-31] (Microsoft Corporation) ==================== Internet (Avec liste blanche) ==================== (Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.) Hosts: Il y a plus d'un élément dans hosts. Voir la section Hosts de Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{BB6449DA-325B-4807-9557-DA465F8CE959}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_77\bin\ssv.dll [2016-03-31] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-03-31] (Oracle Corporation) FireFox: ======== FF ProfilePath: C:\Users\MOHAMED\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1 FF NewTab: hxxp://www.hohosearch.com/?ts=AHEqA3ElAH4lAU..&v=20160409&uid=EF2CDDAFD1C58637F2EBC1D2B9BD1185&ptid=amz&mode=ffseng FF DefaultSearchEngine: hohosearch FF DefaultSearchEngine.US: data:text/plain,browser.search.defaultenginename.US=hohosearch FF SelectedSearchEngine: hohosearch FF Homepage: hxxp://www.hohosearch.com/?ts=AHEqA3ElAH4lAU..&v=20160409&uid=EF2CDDAFD1C58637F2EBC1D2B9BD1185&ptid=amz&mode=ffseng FF Keyword.URL: hxxp://www.hohosearch.com/chrome.php?uid=EF2CDDAFD1C58637F2EBC1D2B9BD1185&ptid=amz&ts=AHEqA3ElAH4lAU..&v=20160409&mode=ffexttoolbar&q= FF Plugin: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-03-31] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-03-31] (Oracle Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-04-26] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-04-26] (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN) FF SearchPlugin: C:\Users\MOHAMED\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\DD1B66D4.xml [2016-04-11] FF Extension: GsearchFinder - C:\Users\MOHAMED\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi [2016-04-09] Chrome: ======= CHR Profile: C:\Users\MOHAMED\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\MOHAMED\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-04-26] CHR Extension: (Google Drive) - C:\Users\MOHAMED\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-04-26] CHR Extension: (YouTube) - C:\Users\MOHAMED\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-04-26] CHR Extension: (Adblock Plus) - C:\Users\MOHAMED\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-04-26] CHR Extension: (Ad;Block Plus) - C:\Users\MOHAMED\AppData\Local\Google\Chrome\User Data\Default\Extensions\emmhkkhdlihokdnbjfhambemdfipjfhm [2016-04-26] CHR Extension: (Google Sheets) - C:\Users\MOHAMED\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-04-26] CHR Extension: (Google Docs hors connexion) - C:\Users\MOHAMED\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-26] CHR Extension: (Screencastify (Screen Video Recorder)) - C:\Users\MOHAMED\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmeijimgabbpbgpdklnllpncmdofkcpn [2016-05-04] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\MOHAMED\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-26] CHR Extension: (Gmail) - C:\Users\MOHAMED\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-04-26] Opera: ======= OPR Extension: (Adblock Plus) - C:\Users\MOHAMED\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2016-03-31] ==================== Services (Avec liste blanche) ======================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1982752 2016-02-23] (ESET) R2 HWDeviceService.exe; C:\ProgramData\DatacardService\HWDeviceService.exe [271712 2011-03-14] () R2 jswpbapi; C:\Program Files\Jumpstart\jswpbapi.exe [188416 2008-09-26] (Atheros Communications, Inc.) [Fichier non signé] S3 jswpsapi; C:\Program Files\Jumpstart\jswpsapi.exe [954368 2008-09-26] (Atheros Communications, Inc.) [Fichier non signé] S2 Modem HDM EC156. RunOuc; C:\Program Files\Modem HDM EC156\UpdateDog\ouc.exe [655712 2016-05-06] () R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation) S2 BugreportW; "C:\Program Files\SpeedSearchesbnd\Bugreportauclt.exe" {154DFF63-3402-4815-941A-AAD63AE8B428} [X] S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [X] ===================== Pilotes (Avec liste blanche) ========================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [206312 2016-02-23] (ESET) R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [154288 2016-02-23] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [146024 2016-02-23] (ESET) R2 ekbdflt; C:\Windows\System32\DRIVERS\ekbdflt.sys [111040 2016-02-23] (ESET) R1 epfw; C:\Windows\System32\DRIVERS\epfw.sys [152728 2016-02-23] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44608 2016-02-23] (ESET) R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [71488 2016-02-23] (ESET) S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [95616 2016-05-06] (Huawei Technologies Co., Ltd.) S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [27520 2016-05-06] (Huawei Technologies Co., Ltd.) S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [195072 2016-05-06] (Huawei Technologies Co., Ltd.) R1 ndisrd; C:\Windows\System32\DRIVERS\ndisrd.sys [37408 2014-08-14] (NT Kernel Resources) R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) S1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [108208 2016-03-04] (Oracle Corporation) R1 XQHDrv; C:\Windows\System32\DRIVERS\XQHDrv.sys [203424 2015-09-08] (BigNox Corporation) S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [X] S3 vmci; \SystemRoot\system32\DRIVERS\vmci.sys [X] S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X] U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-13] (Microsoft Corporation) ==================== NetSvcs (Avec liste blanche) =================== (Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.) ==================== Un mois - Créés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-05-07 06:39 - 2016-05-07 06:40 - 00011706 _____ C:\Users\MOHAMED\Desktop\FRST.txt 2016-05-07 06:39 - 2016-05-07 06:39 - 00000000 ____D C:\FRST 2016-05-07 06:36 - 2016-05-07 06:36 - 01730048 _____ (Farbar) C:\Users\MOHAMED\Desktop\FRST.exe 2016-05-07 06:34 - 2016-05-07 06:34 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\WindowsUpdateFixer 2016-05-07 06:31 - 2016-05-07 06:31 - 00001045 _____ C:\Users\Public\Desktop\WindowsUpdateFixer.lnk 2016-05-07 06:31 - 2016-05-07 06:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WindowsUpdateFixer 2016-05-07 06:31 - 2016-05-07 06:31 - 00000000 ____D C:\Program Files\WindowsUpdateFixer 2016-05-07 06:29 - 2016-05-07 06:30 - 00419184 _____ (Zerobyte Developments ) C:\Users\MOHAMED\Desktop\windowsupdatefixer_2.0.1.exe 2016-05-06 23:16 - 2016-05-06 23:16 - 00000000 ____D C:\Users\MOHAMED\Downloads\Fichiers de traduction de Camtasia Studio 8 2016-05-06 23:09 - 2016-05-06 23:09 - 00402856 _____ C:\Users\MOHAMED\Downloads\ar..aiman.rar 2016-05-06 23:09 - 2016-05-06 23:09 - 00000000 ____D C:\Users\MOHAMED\Downloads\ar..aiman 2016-05-06 23:02 - 2016-05-06 23:02 - 00001009 _____ C:\Users\Public\Desktop\Modem HDM EC156.lnk 2016-05-06 23:02 - 2016-05-06 23:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Modem HDM EC156 2016-05-06 23:01 - 2016-05-06 23:01 - 00861696 _____ (DiBcom SA) C:\Windows\system32\Drivers\mod7700.sys 2016-05-06 23:01 - 2016-05-06 23:01 - 00369152 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbwwan.sys 2016-05-06 23:01 - 2016-05-06 23:01 - 00199168 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys 2016-05-06 23:01 - 2016-05-06 23:01 - 00195072 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juwwanecm.sys 2016-05-06 23:01 - 2016-05-06 23:01 - 00102784 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwusbdev.sys 2016-05-06 23:01 - 2016-05-06 23:01 - 00095616 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcacm.sys 2016-05-06 23:01 - 2016-05-06 23:01 - 00076544 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jubusenum.sys 2016-05-06 23:01 - 2016-05-06 23:01 - 00067584 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcecm.sys 2016-05-06 23:01 - 2016-05-06 23:01 - 00027520 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juextctrl.sys 2016-05-06 23:01 - 2016-05-06 23:01 - 00025856 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys 2016-05-06 23:01 - 2016-05-06 23:01 - 00019200 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwupgrade.sys 2016-05-06 23:01 - 2016-05-06 23:01 - 00011136 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_usbenumfilter.sys 2016-05-06 15:53 - 2016-05-06 23:18 - 00000000 ____D C:\Users\MOHAMED\Documents\Camtasia Studio 2016-05-06 15:46 - 2016-05-06 15:46 - 00001086 _____ C:\Users\Public\Desktop\Camtasia Studio 8.lnk 2016-05-06 15:46 - 2016-05-06 15:46 - 00000000 ____D C:\ProgramData\TechSmith 2016-05-06 15:46 - 2016-05-06 15:46 - 00000000 ____D C:\ProgramData\regid.1995-08.com.techsmith 2016-05-06 15:46 - 2016-05-06 15:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith 2016-05-06 15:46 - 2016-05-06 15:46 - 00000000 ____D C:\Program Files\TechSmith 2016-05-06 15:46 - 2016-05-06 15:46 - 00000000 ____D C:\Program Files\QuickTime 2016-05-06 15:46 - 2016-05-06 15:46 - 00000000 ____D C:\Program Files\Common Files\TechSmith Shared 2016-05-06 15:30 - 2016-05-06 15:43 - 261137096 _____ C:\Users\MOHAMED\Downloads\camtasia.exe 2016-05-06 13:06 - 2016-05-06 19:19 - 00000977 _____ C:\Users\MOHAMED\Desktop\hosts.txt 2016-05-05 17:20 - 2016-05-06 23:14 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\CrashDumps 2016-05-04 20:40 - 2016-05-04 20:49 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\DriverCure 2016-05-04 20:39 - 2016-05-04 23:44 - 00000000 ____D C:\ProgramData\ParetoLogic 2016-05-04 20:39 - 2016-05-04 23:44 - 00000000 ____D C:\ProgramData\DriverCure 2016-05-04 20:39 - 2016-05-04 20:39 - 00000000 ____D C:\Program Files\ParetoLogic 2016-05-04 19:25 - 2016-05-04 19:25 - 00006391 _____ C:\Users\MOHAMED\Downloads\IPTV LINKS.rar 2016-05-04 19:23 - 2016-05-04 19:23 - 00002135 _____ C:\Users\MOHAMED\Downloads\Free IPTV Bein Sport.rar 2016-05-04 18:11 - 2016-05-04 18:11 - 01872288 _____ C:\Users\MOHAMED\Downloads\Fichiers de traduction de Camtasia Studio 8.rar 2016-05-04 17:56 - 2016-05-06 16:07 - 00000000 ____D C:\Users\MOHAMED\Downloads\تفعيل CA-STU-8-6 2016-05-04 17:30 - 2016-05-04 17:30 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\TechSmith 2016-05-04 17:28 - 2016-05-04 17:28 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\TechSmith 2016-05-04 15:56 - 2016-05-04 15:56 - 10737166 _____ C:\Users\MOHAMED\Downloads\Untitled Screencast (1).webm 2016-05-04 15:49 - 2016-05-04 15:49 - 09062040 ____R C:\Users\MOHAMED\Downloads\Untitled Screencast.mp4.webm 2016-05-04 15:39 - 2016-05-06 16:12 - 00000000 ____D C:\Users\MOHAMED\Desktop\Nouveau dossier 2016-05-04 12:06 - 2016-05-04 13:15 - 00000000 ___RD C:\Intel PROSet Wireless 2016-05-04 12:05 - 2016-05-04 12:05 - 00000000 ____D C:\ProgramData\Intel.sav 2016-05-03 21:47 - 2016-05-03 21:50 - 18715895 _____ C:\Users\MOHAMED\Downloads\77youtube - مقطع مؤثر عن الظلم - الشيخ يحيى المدغري.mp4 2016-05-03 20:17 - 2016-04-11 13:42 - 00006577 _____ C:\Users\MOHAMED\Downloads\IPTV.m3u 2016-05-03 19:32 - 2016-05-03 19:32 - 00002368 _____ C:\Users\MOHAMED\Desktop\IPTV.m3u 2016-04-30 21:58 - 2016-04-30 21:59 - 23672464 _____ C:\Users\MOHAMED\Downloads\77youtube - لحظة سقوط برميل من الطيران المروحي على حي بستان القصر في حلب بالقرب من مكان التصوير 29-4-2016.mp4 2016-04-30 18:59 - 2016-04-30 19:00 - 07500144 _____ C:\Users\MOHAMED\Downloads\77youtube - حلب تحترق يالله مالنا غيرك يا رب.mp4 2016-04-27 08:46 - 2016-04-27 08:46 - 00000925 _____ C:\Users\Public\Desktop\CCleaner.lnk 2016-04-27 08:46 - 2016-04-27 08:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2016-04-27 08:42 - 2016-04-27 08:47 - 00000000 ____D C:\Program Files\CCleaner 2016-04-26 23:51 - 2016-04-26 23:54 - 06079624 _____ C:\Users\MOHAMED\Downloads\Soundwrite.zip 2016-04-26 23:42 - 2016-04-26 23:42 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\Chronotron 2016-04-26 23:34 - 2016-04-27 08:26 - 00000000 ____D C:\Program Files\RelevantKnowledge 2016-04-26 23:34 - 2016-04-26 23:34 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\MP3 Speed 2016-04-26 23:34 - 2016-04-26 23:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge 2016-04-26 22:07 - 2016-04-26 22:07 - 00000000 ____D C:\ProgramData\ByteFence 2016-04-26 21:56 - 2016-04-26 23:50 - 00000000 ____D C:\Program Files\ByteFence 2016-04-26 20:20 - 2016-04-26 20:20 - 00000000 ____H C:\ProgramData\DP45977C.lfl 2016-04-26 19:52 - 2016-04-27 00:02 - 00000000 ___HD C:\Program Files\Temp 2016-04-26 18:57 - 2016-04-26 18:57 - 00000045 _____ C:\Windows\ENROLL.INI 2016-04-26 17:53 - 1998-09-15 14:53 - 00305152 _____ (IBM Corporation) C:\Windows\system32\setresae.dll 2016-04-26 17:53 - 1998-09-15 14:45 - 00305152 _____ (IBM Corporation) C:\Windows\system32\setresar.dll 2016-04-26 17:52 - 1998-09-16 15:29 - 00388608 _____ (IBM Corporation) C:\Windows\system32\setnote.cpl 2016-04-26 17:52 - 1997-12-05 20:23 - 00305152 _____ (IBM Corporation) C:\Windows\system32\setresuk.dll 2016-04-26 17:52 - 1997-11-28 16:28 - 00035328 _____ () C:\Windows\system32\Shellses.dll 2016-04-26 17:52 - 1997-11-21 15:13 - 00018944 _____ () C:\Windows\system32\Ibmwave.exe 2016-04-26 17:52 - 1997-10-02 20:02 - 00022528 _____ (Blue Sky Software Corp.) C:\Windows\system32\rhmmplay.dll 2016-04-26 17:18 - 1997-09-12 13:44 - 00299520 _____ (InstallShield Corporation, Inc.) C:\Windows\uninst.exe 2016-04-26 17:13 - 2016-04-26 17:13 - 00000000 __RSH C:\MSDOS.SYS 2016-04-26 17:13 - 2016-04-26 17:13 - 00000000 __RSH C:\IO.SYS 2016-04-26 17:07 - 2016-04-26 17:07 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\PowerISO 2016-04-26 15:55 - 2016-04-26 16:02 - 194543079 _____ C:\Users\MOHAMED\Downloads\IBM_ViaVoice bY kOtA .rar 2016-04-26 15:05 - 2016-04-26 15:05 - 00002239 _____ C:\Users\MOHAMED\Desktop\Lanceur d'applications Google Chrome.lnk 2016-04-26 15:05 - 2016-04-26 15:05 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome 2016-04-26 15:05 - 2016-04-26 15:05 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Applications Chrome 2016-04-26 15:02 - 2016-05-02 22:07 - 00002099 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-04-26 15:02 - 2016-05-02 22:07 - 00002087 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-04-26 14:59 - 2016-05-07 06:21 - 00001054 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-04-26 14:59 - 2016-05-06 23:04 - 00001058 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-04-26 14:59 - 2016-05-06 14:24 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\Google 2016-04-26 13:32 - 2016-04-26 13:32 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\OpenOffice 2016-04-26 13:30 - 2016-04-26 13:30 - 00001034 _____ C:\Users\Public\Desktop\OpenOffice 4.1.1.lnk 2016-04-26 13:30 - 2016-04-26 13:30 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1 2016-04-26 13:28 - 2016-04-26 13:29 - 00000000 ____D C:\Program Files\OpenOffice 4 2016-04-26 13:27 - 2016-04-26 13:27 - 00000000 ____D C:\Users\MOHAMED\Desktop\OpenOffice 4.1.1 (fr) Installation Files 2016-04-24 14:25 - 2016-04-24 14:25 - 00326669 _____ C:\Users\MOHAMED\Downloads\Channel Art Templates.zip 2016-04-24 14:17 - 2016-04-24 14:17 - 00000000 ____D C:\Users\MOHAMED\Documents\My Weblog Posts 2016-04-24 14:15 - 2016-04-24 14:17 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\Windows Live Writer 2016-04-24 14:15 - 2016-04-24 14:15 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\Windows Live Writer 2016-04-23 16:19 - 2016-04-23 16:29 - 34642915 _____ C:\Users\MOHAMED\Downloads\77youtube - فقه الصلاة منابر العلماء لـفضيلة الشيخ مصطفى العدوي.3gp 2016-04-22 13:49 - 2016-04-22 13:50 - 08270862 _____ C:\Users\MOHAMED\Downloads\77youtube - كلمات من ذهب للشيخ صالح الفوزان يوجهها للشيخ صالح المغامسي في منزله.mp4 2016-04-21 11:06 - 2016-04-22 10:50 - 00000001 _____ C:\Windows\system32\fr.html 2016-04-18 17:29 - 2016-04-26 20:23 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\ElevatedDiagnostics 2016-04-17 16:18 - 2016-04-17 16:19 - 12313895 _____ C:\Users\MOHAMED\Downloads\77youtube - أيها التاريخ عُدنا.mp4 2016-04-17 14:32 - 2016-04-17 14:32 - 00000000 ____D C:\Users\MOHAMED\Downloads\1449273086181 2016-04-16 12:31 - 2016-04-16 12:31 - 00001061 _____ C:\Users\MOHAMED\Desktop\Baidu WiFi Hotspot.lnk 2016-04-16 12:31 - 2016-04-16 12:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu WiFi Hotspot 2016-04-16 12:30 - 2016-04-16 12:32 - 00000000 ____D C:\Program Files\Baidu WiFiHotspot 2016-04-16 12:19 - 2016-04-16 12:19 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\Intel 2016-04-16 12:18 - 2016-04-16 12:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless 2016-04-16 12:17 - 2016-04-16 12:17 - 00000000 ____D C:\ProgramData\Intel 2016-04-16 12:17 - 2016-04-16 12:17 - 00000000 ____D C:\Program Files\Common Files\Intel 2016-04-16 12:17 - 2016-04-16 12:17 - 00000000 ____D C:\Program Files\Cisco 2016-04-16 12:16 - 2016-04-16 12:16 - 00000000 ____D C:\dell 2016-04-16 11:48 - 2016-05-06 13:27 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell 2016-04-16 11:42 - 2016-05-05 17:24 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\Deployment 2016-04-16 11:42 - 2016-04-16 11:42 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\Apps\2.0 2016-04-16 10:21 - 2016-04-18 17:29 - 00000375 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2016-04-16 10:12 - 2016-04-16 10:12 - 00031616 _____ (Connectify) C:\Windows\system32\Drivers\cfywlan1.sys 2016-04-16 10:11 - 2016-04-16 10:18 - 00000000 ____D C:\ProgramData\Connectify 2016-04-16 09:36 - 2015-02-03 03:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2016-04-16 09:36 - 2015-02-03 03:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-04-16 09:36 - 2015-02-03 03:16 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2016-04-16 09:36 - 2015-02-03 03:16 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2016-04-16 09:36 - 2015-02-03 03:16 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2016-04-16 09:36 - 2015-02-03 03:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 02135040 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2016-04-16 09:36 - 2015-02-03 03:12 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2016-04-16 09:36 - 2015-02-03 03:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2016-04-16 09:36 - 2015-02-03 03:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2016-04-16 09:36 - 2015-02-03 03:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2016-04-16 09:36 - 2015-02-03 03:11 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2016-04-16 09:36 - 2015-02-03 03:11 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2016-04-16 09:36 - 2015-02-03 03:11 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2016-04-16 09:36 - 2015-02-03 03:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2016-04-16 09:36 - 2015-02-03 03:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2016-04-16 09:36 - 2015-02-03 03:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2016-04-16 09:36 - 2015-02-03 03:11 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2016-04-16 09:36 - 2015-02-03 03:11 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2016-04-16 09:36 - 2015-02-03 03:11 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe 2016-04-16 09:36 - 2015-02-03 03:11 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2016-04-16 09:36 - 2015-02-03 03:10 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2016-04-16 09:36 - 2015-02-03 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2016-04-16 09:36 - 2015-02-03 03:09 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2016-04-16 09:36 - 2015-02-03 03:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2016-04-16 09:36 - 2015-02-03 03:08 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2016-04-16 09:36 - 2015-02-03 03:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2016-04-16 09:36 - 2015-02-03 03:00 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2016-04-16 09:36 - 2015-02-03 02:26 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2016-04-16 09:36 - 2015-01-30 23:56 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2016-04-16 09:36 - 2014-10-31 22:22 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2016-04-16 09:36 - 2014-06-28 00:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2016-04-16 09:36 - 2014-06-28 00:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2016-04-16 09:06 - 2016-04-26 20:47 - 00000000 ____D C:\Users\Public\Documents\Baidu 2016-04-16 09:06 - 2016-04-16 09:06 - 00000000 ____D C:\Users\Public\Documents\PC Faster 2016-04-16 09:06 - 2016-04-16 09:06 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\Baidu 2016-04-16 09:06 - 2016-04-16 09:06 - 00000000 ____D C:\ProgramData\PC Faster 2016-04-16 09:06 - 2014-08-14 09:18 - 00037408 _____ (NT Kernel Resources) C:\Windows\system32\Drivers\ndisrd.sys 2016-04-15 15:03 - 2016-04-15 15:03 - 02566078 _____ C:\Users\MOHAMED\Downloads\13018165_1593123014335831_1690274669_n.mp4 2016-04-15 14:31 - 2016-04-22 13:40 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\TSv 2016-04-15 14:31 - 2016-04-20 13:00 - 00000000 ____D C:\ProgramData\QwinpQ 2016-04-15 14:31 - 2016-04-15 14:31 - 00000000 ____D C:\Program Files\QQBrowser 2016-04-15 14:30 - 2016-04-26 15:01 - 00000000 ____D C:\Program Files\Google 2016-04-15 10:38 - 2016-05-06 23:21 - 00001002 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-04-15 10:38 - 2016-04-30 23:02 - 00001064 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job 2016-04-15 10:38 - 2016-04-15 10:38 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2016-04-15 10:38 - 2016-04-15 10:38 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2016-04-15 10:38 - 2016-04-15 10:38 - 00000000 ____D C:\Windows\system32\Macromed 2016-04-15 10:34 - 2016-04-15 10:40 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\Adobe 2016-04-13 23:22 - 2016-04-13 19:36 - 00001211 _____ C:\Users\MOHAMED\Desktop\Movie Maker.lnk 2016-04-13 19:40 - 2016-04-27 09:10 - 00000000 ____D C:\Users\MOHAMED\Tracing 2016-04-13 19:36 - 2016-04-13 19:36 - 00001211 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk 2016-04-13 19:36 - 2016-04-13 19:36 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live 2016-04-13 19:36 - 2016-04-13 19:36 - 00000000 ____D C:\Windows\fr 2016-04-13 19:36 - 2014-03-31 21:36 - 00049856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fssfltr.sys 2016-04-13 19:35 - 2016-04-13 19:35 - 00001280 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk 2016-04-13 19:34 - 2016-04-13 19:34 - 00001364 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk 2016-04-13 19:34 - 2016-04-13 19:34 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2016-04-13 19:31 - 2016-04-13 19:31 - 00002392 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk 2016-04-13 19:30 - 2016-04-13 19:30 - 00000000 ____D C:\Windows\PCHEALTH 2016-04-13 19:28 - 2016-04-13 19:36 - 00000000 ____D C:\Program Files\Windows Live 2016-04-13 19:27 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2016-04-13 19:27 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2016-04-13 19:27 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2016-04-13 19:27 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2016-04-13 19:26 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2016-04-13 19:25 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2016-04-13 19:24 - 2016-04-13 19:24 - 00000000 ___RD C:\Users\MOHAMED\OneDrive 2016-04-13 19:24 - 2016-04-13 19:24 - 00000000 ____D C:\Program Files\Microsoft OneDrive 2016-04-13 19:23 - 2016-04-13 19:23 - 00000000 ____D C:\ProgramData\Microsoft OneDrive 2016-04-13 19:22 - 2016-04-24 14:14 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\Windows Live 2016-04-13 19:22 - 2016-04-13 19:22 - 00000000 ____D C:\Program Files\Common Files\Windows Live 2016-04-13 18:50 - 2016-04-13 18:50 - 00000000 ____D C:\Users\MOHAMED\Documents\FlashIntegro 2016-04-13 18:50 - 2016-04-13 18:50 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\VideoEditor 2016-04-13 18:50 - 2016-04-13 18:50 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\FlashIntegro 2016-04-13 18:47 - 2016-04-13 19:13 - 00000000 ____D C:\Program Files\FlashIntegro 2016-04-13 18:47 - 2016-04-13 19:13 - 00000000 ____D C:\Program Files\Common Files\FlashIntegro 2016-04-13 18:47 - 2016-03-23 18:20 - 00088376 _____ (Flash-Integro LLC) C:\Windows\system32\mslvddsfilter2.ax 2016-04-13 18:47 - 2011-12-07 18:32 - 00216064 _____ ( ) C:\Windows\system32\Lagarith.dll 2016-04-13 18:47 - 2005-08-01 18:43 - 00245760 _____ () C:\Windows\system32\lame.ax 2016-04-13 18:47 - 2004-12-10 09:03 - 00438272 _____ (On2.com) C:\Windows\system32\vp6vfw.dll 2016-04-13 18:47 - 2004-09-06 15:06 - 00053248 _____ C:\Windows\system32\xvid.ax 2016-04-13 18:47 - 2004-07-03 20:08 - 00139264 _____ C:\Windows\system32\xvidvfw.dll 2016-04-13 18:47 - 2004-07-03 19:59 - 00524288 _____ C:\Windows\system32\xvidcore.dll 2016-04-13 18:47 - 2004-02-04 20:11 - 00081920 _____ (fccHandler) C:\Windows\system32\AC3ACM.acm 2016-04-13 18:47 - 2003-05-22 11:26 - 00638976 _____ (DivXNetworks, Inc.) C:\Windows\system32\divx.dll 2016-04-13 18:47 - 2003-05-22 11:26 - 00221215 _____ (DivXNetworks, Inc.) C:\Windows\system32\divxdec.ax 2016-04-13 18:47 - 2003-05-21 22:50 - 00261632 _____ (MainConcept) C:\Windows\system32\mcdvd_32.dll 2016-04-13 18:47 - 2003-05-21 22:50 - 00156910 _____ C:\Windows\WMSysPr8.prx 2016-04-13 18:47 - 2003-05-21 22:50 - 00082944 _____ (Voxware, Inc.) C:\Windows\system32\vct3216.acm 2016-04-13 18:47 - 2003-05-21 22:50 - 00038912 _____ (NCT Company) C:\Windows\system32\alf2cd.acm 2016-04-13 18:47 - 2003-05-21 22:50 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\msxml3a.dll 2016-04-13 18:47 - 2003-03-25 04:49 - 00098304 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\Windows\system32\L3CODECX.AX 2016-04-13 18:47 - 2002-08-19 23:41 - 00413760 _____ (Microsoft Corporation) C:\Windows\system32\mpg4c32.dll 2016-04-13 18:47 - 2000-03-14 19:55 - 00013239 _____ (SHARP Corporation) C:\Windows\system32\Scg726.acm 2016-04-13 11:57 - 2016-04-13 11:57 - 00028961 _____ C:\Users\MOHAMED\Downloads\93d37d53_o.jpeg 2016-04-11 22:45 - 2016-04-27 10:42 - 00000000 ____D C:\Program Files\SpeedSearchesbnd 2016-04-11 22:45 - 2016-04-11 22:45 - 00000000 ____D C:\Program Files\WinTsks 2016-04-11 22:45 - 2016-04-11 22:45 - 00000000 ____D C:\Program Files\WinSvces 2016-04-11 22:44 - 2016-04-11 22:45 - 00000000 ____D C:\Users\Public\Documents\dmp 2016-04-11 19:17 - 2016-04-11 19:17 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2016-04-10 18:49 - 2016-04-13 18:46 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\NCH Software 2016-04-10 18:48 - 2016-04-13 18:41 - 00000000 ____D C:\ProgramData\NCH Software 2016-04-10 18:48 - 2016-04-11 22:38 - 00000000 ____D C:\Program Files\NCH Software 2016-04-09 23:08 - 2016-04-09 23:09 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\HaiYuInst 2016-04-09 19:49 - 2016-04-09 19:49 - 00000000 ____D C:\Program Files\DIFX 2016-04-09 19:49 - 2015-09-08 08:16 - 00104096 _____ (BigNox Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys 2016-04-09 19:48 - 2016-04-09 19:58 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\Nox 2016-04-09 19:48 - 2016-04-09 19:58 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\Nox 2016-04-09 19:31 - 2016-04-09 19:31 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\BlueStacks 2016-04-09 17:21 - 2016-04-09 19:47 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\VMware 2016-04-09 17:15 - 2016-04-09 20:12 - 00000000 ____D C:\ProgramData\VMware 2016-04-09 17:10 - 2016-04-09 20:12 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\Andy 2016-04-09 16:34 - 2016-04-09 16:34 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\Macromedia 2016-04-09 16:34 - 2016-04-09 16:34 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\Adobe 2016-04-09 16:34 - 2016-04-09 16:34 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\Macromedia 2016-04-09 16:05 - 2016-04-09 16:05 - 00007597 _____ C:\Users\MOHAMED\AppData\Local\Resmon.ResmonCfg 2016-04-09 15:56 - 2016-04-09 16:10 - 00000000 ____D C:\ProgramData\BlueStacksSetup 2016-04-09 12:55 - 2016-04-09 12:56 - 00000000 ____D C:\Users\Public\Thunder Network 2016-04-09 12:55 - 2016-04-09 12:55 - 00000000 ____D C:\ProgramData\Thunder Network 2016-04-09 12:53 - 2016-04-10 09:42 - 00000000 _____ C:\hsrv.txt ==================== Un mois - Modifiés - fichiers et dossiers ======== (Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.) 2016-05-07 06:28 - 2009-07-14 04:34 - 00014368 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-05-07 06:28 - 2009-07-14 04:34 - 00014368 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-05-07 06:26 - 2016-03-31 21:29 - 00000000 ____D C:\Program Files\Opera 2016-05-07 06:24 - 2016-03-31 11:38 - 00000000 ____D C:\Windows\SoftwareDistribution-WinUpdFix-Old 2016-05-07 06:22 - 2009-07-14 02:37 - 00000000 ____D C:\Windows\inf 2016-05-07 06:21 - 2009-07-14 04:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-05-06 23:12 - 2016-03-31 18:41 - 01667292 _____ C:\Windows\system32\PerfStringBackup.INI 2016-05-06 23:12 - 2009-07-14 08:39 - 00747154 _____ C:\Windows\system32\perfh00C.dat 2016-05-06 23:12 - 2009-07-14 08:39 - 00149646 _____ C:\Windows\system32\perfc00C.dat 2016-05-06 23:07 - 2016-04-01 15:19 - 00000000 ____D C:\ProgramData\DatacardService 2016-05-06 23:02 - 2016-04-01 15:20 - 00000000 ____D C:\Program Files\Modem HDM EC156 2016-05-06 23:01 - 2016-04-01 15:21 - 01112288 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll 2016-05-06 23:01 - 2016-04-01 15:21 - 01112288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfCoInstaller01007.dll 2016-05-06 22:59 - 2016-03-31 22:18 - 00000000 ____D C:\ProgramData\TEMP 2016-05-06 20:19 - 2016-03-31 22:36 - 00000000 ____D C:\Users\MOHAMED\Desktop\Capture 2016-05-06 16:22 - 2016-04-02 23:23 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\vlc 2016-05-06 15:56 - 2009-07-14 02:37 - 00000000 ____D C:\Windows\system32\NDF 2016-05-06 15:47 - 2016-03-31 18:36 - 00000000 ____D C:\Users\MOHAMED 2016-05-06 14:25 - 2009-07-14 09:00 - 00000000 ___RD C:\Users\Public\Recorded TV 2016-05-06 14:25 - 2009-07-14 02:37 - 00000000 ____D C:\Windows\registration 2016-05-06 14:25 - 2009-07-14 02:37 - 00000000 ____D C:\Windows\AppCompat 2016-05-06 14:24 - 2016-04-01 15:21 - 00000000 ____D C:\ProgramData\Modem HDM EC156 2016-05-06 14:23 - 2016-03-31 18:58 - 00000000 ____D C:\Program Files\Intel 2016-05-06 13:18 - 2016-03-31 22:36 - 00000000 ____D C:\Users\MOHAMED\Desktop\PDF 2016-05-04 17:18 - 2008-04-03 00:07 - 00000000 ____D C:\Windows\Minidump 2016-05-04 16:23 - 2016-04-03 11:00 - 00000000 ____D C:\FFOutput 2016-04-27 10:44 - 2016-03-31 18:36 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\VirtualStore 2016-04-27 09:10 - 2016-03-31 12:34 - 00000000 ____D C:\Windows\Panther 2016-04-27 09:10 - 2009-07-14 02:37 - 00000000 ____D C:\Windows\ModemLogs 2016-04-27 00:02 - 2016-04-01 12:24 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2016-04-26 20:05 - 2016-03-31 22:24 - 00063568 _____ C:\Users\MOHAMED\AppData\Local\GDIPFONTCACHEV1.DAT 2016-04-26 19:55 - 2009-07-14 04:33 - 00294440 _____ C:\Windows\system32\FNTCACHE.DAT 2016-04-26 16:20 - 2016-03-31 21:28 - 00000000 ____D C:\Users\MOHAMED\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2016-04-26 16:20 - 2016-03-31 21:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2016-04-26 13:27 - 2009-07-14 02:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2016-04-16 14:39 - 2009-07-14 02:37 - 00000000 ____D C:\Windows\rescache 2016-04-16 12:19 - 2009-07-14 04:53 - 00000000 ____D C:\Users\Administrator 2016-04-16 09:45 - 2009-07-14 02:37 - 00000000 ____D C:\Windows\system32\Dism 2016-04-11 22:55 - 2016-03-31 22:41 - 00001791 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-04-11 22:55 - 2016-03-31 22:41 - 00001779 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-04-09 19:31 - 2009-07-14 02:37 - 00000000 __RHD C:\Users\Public\Libraries 2016-04-09 19:28 - 2016-03-31 22:41 - 00000000 ____D C:\Users\MOHAMED\AppData\Local\Mozilla 2016-04-09 13:16 - 2016-03-31 22:41 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== Fichiers à la racine de certains dossiers ======= 2016-04-09 23:08 - 2016-04-10 10:12 - 0001978 _____ () C:\Users\MOHAMED\AppData\Roaming\droid4xinstaller.log 2016-04-09 16:05 - 2016-04-09 16:05 - 0007597 _____ () C:\Users\MOHAMED\AppData\Local\Resmon.ResmonCfg 2016-04-26 20:20 - 2016-04-26 20:20 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ================= (Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.) C:\Windows\explorer.exe => Le fichier est signé numériquement C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement C:\Windows\system32\wininit.exe => Le fichier est signé numériquement C:\Windows\system32\svchost.exe => Le fichier est signé numériquement C:\Windows\system32\services.exe => Le fichier est signé numériquement C:\Windows\system32\User32.dll => Le fichier est signé numériquement C:\Windows\system32\userinit.exe => Le fichier est signé numériquement C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement LastRegBack: 2016-05-01 10:35 ==================== Fin de FRST.txt ============================