Logfile of random's system information tool 1.09 (written by random/random) Run by Anthony at 2014-04-08 23:30:20 Microsoft Windows 7 Édition Intégrale Service Pack 1 System drive C: has 508 GB (56%) free of 904 GB Total RAM: 4000 MB (53% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 23:36:58, on 08/04/2014 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v10.0 (10.00.9200.16843) Boot mode: Safe mode with network support Running processes: C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_168.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_168.exe C:\Program Files (x86)\eMule\emule.exe C:\Program Files (x86)\Hotspot Shield\bin\HSSCP.exe C:\Program Files (x86)\FastStone Capture\FSCapture.exe C:\Users\Anthony\Desktop\RSIT.exe C:\Program Files (x86)\trend micro\Anthony.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8555;https=127.0.0.1:8555 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O1 - Hosts: 127.0.0.3 www.anchorfree.net O1 - Hosts: 127.0.0.2 www.mefeedia.com O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O2 - BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll O2 - BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll O2 - BHO: PrivDogExtension - {FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} - C:\Program Files (x86)\AdTrustMedia\PrivDog\1.8.0.15\trustedads.dll O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O4 - HKLM\..\Run: [DFX] C:\Program Files (x86)\DFX\DFX.exe -startup O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe O4 - HKLM\..\Run: [SysMetrix] C:\Program Files (x86)\SysMetrix\SysMetrix.exe O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe O4 - HKLM\..\Run: [AntiLogger] "C:\Program Files (x86)\AntiLogger\AntiLogger.exe" /minimized O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [HOSTS Anti-Adware_PUPs] C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe /boot O4 - HKLM\..\Run: [tvncontrol] "C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave O4 - HKLM\..\Run: [PrivDogService] "C:\Program Files (x86)\AdTrustMedia\PrivDog\1.8.0.15\trustedadssvc.exe" O4 - HKCU\..\Run: [L09FXLRD_7369752] "C:\Program Files (x86)\Microsoft Etudes\Microsoft Encarta 2009 - Études DVD\EDICT.EXE" -m O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot O4 - HKCU\..\Run: [ctfmon.exe] "C:\Windows\system32\ctfmon.exe" O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe O4 - HKCU\..\Run: [f.lux] "C:\Users\Anthony\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow O4 - HKCU\..\Run: [Speccy] "C:\Program Files\Speccy\Speccy64.exe" /totray O4 - HKCU\..\Run: [Google Update] "C:\Users\Anthony\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [EPSON SX430 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE /FU "C:\Users\Anthony\AppData\Local\Temp\E_S8756.tmp" /EF "HKCU" O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE RÉSEAU') O4 - Startup: AutorunsDisabled O4 - Startup: FastStone Capture.lnk = C:\Program Files (x86)\FastStone Capture\FSCapture.exe O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files (x86)\Secunia\PSI\psi_tray.exe O4 - Global Startup: Start GeekBuddy.lnk = C:\Program Files\COMODO\GeekBuddy\launcher.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Télécharger avec Internet Download Manager - C:\Program Files (x86)\Internet Download Manager\IEExt.htm O8 - Extra context menu item: Télécharger tous les liens avec Internet Download Manager - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe O9 - Extra button: PrivDog - {2F5C139F-79BD-4C84-A95A-E7140525BC55} - C:\Program Files (x86)\AdTrustMedia\PrivDog\1.8.0.15\trustedads.dll O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe O9 - Extra 'Tools' menuitem: Classic IE9 Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE9_32.exe O9 - Extra button: (no name) - {64964764-1101-4bbd-8891-B56B1A53B9B3} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files (x86)\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - ESC Trusted Zone: http://*.connectify.me O15 - ESC Trusted Zone: http://*.fastspring.com O15 - ESC Trusted Zone: http://*.connectify.me (HKLM) O15 - ESC Trusted Zone: http://*.fastspring.com (HKLM) O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Service de la passerelle de la couche Application (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (AudioSrv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: COMODO LPS Launcher (CLPSLauncher) - Comodo Security Solutions, Inc. - C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe O23 - Service: COMODO Internet Security Helper Service (CmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Client DHCP (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Client DNS (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Service de stratégie de diagnostic (DPS) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (eventlog) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: GeekBuddyRSP Server (GeekBuddyRSP) - Comodo Security Solutions, Inc. - C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: HDD Information Service (HDDSvc) - AltrixSoft (http://www.altrixsoft.com/) - C:\Program Files (x86)\Common Files\AltrixSoft\HDDInfoService\HDDSvc.exe O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: HOSTS Anti-PUPs - Unknown owner - (no file) O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\Windows\system32\HPSIsvc.exe (file missing) O23 - Service: Hotspot Shield Service (hshld) - AnchorFree Inc. - C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: Station de travail (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: Ma-Config Agent (MaConfigAgent) - Unknown owner - C:\Program Files\ma-config.com\MaConfigAgent.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: Pare-feu Windows (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - (no file) O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\netprofm.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - Unknown owner - C:\Windows\SysWow64\perfhost.exe O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013.SP4\RpcAgentSrv.exe O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\PSIA.exe O23 - Service: Secunia Update Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\sua.exe O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Partage de connexion Internet (ICS) (SharedAccess) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: Spouleur d’impression (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppuinotify.dll,-103 (sppuinotify) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Acquisition d’image Windows (WIA) (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe O23 - Service: @%SystemRoot%\System32\uxtuneup.dll,-4096 (UxTuneUp) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Service de configuration automatique WLAN (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: Centre de sécurité (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe O23 - Service: Windows Update (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe -- End of file - 21185 bytes ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2969443300-2759968393-1142833870-1000Core.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2969443300-2759968393-1142833870-1000UA.job C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 831262d9-91a1-40af-962a-0e403937a053.job =========Mozilla firefox========= ProfilePath - C:\Users\Anthony\AppData\Roaming\Mozilla\Firefox\Profiles\31ptt34g.default-1347994869486 prefs.js - "browser.search.useDBForOrder" - true "{F003DA68-8256-4b37-A6C4-350FA04494DF}"=C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt "quickprint@hp.com"=C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 13.0.0.168 Plugin "Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_168.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer] "Description"=Adobe Shockwave Player "Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin] "Description"=Google Earth in your browser "Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=disabled [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nullsoft.com/winampDetector;version=1] "Description"=Winamp Detector "Path"=C:\Program Files (x86)\Winamp Detect\npwachk.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader] "Description"=Handles PDFs in-place in Firefox "Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll C:\Program Files (x86)\Mozilla Firefox\extensions\ afurladvisor@anchorfree.com C:\Users\Anthony\AppData\Roaming\Mozilla\Firefox\Profiles\31ptt34g.default-1347994869486\extensions\ antidote7_win_firefox_103@druide.com csfire@cs.kuleuven.be donottrackplus@abine.com FirefoxAddon@similarWeb.com foxyproxy@eric.h.jung ich@maltegoetz.de isreaditlater@ideashower.com mintrayr@tn123.ath.cx myipms@myip.ms perspectives@cmu.edu PrivDog@AdTrustMedia.com securebrowsing@m86security.com {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} {0b457cAA-602d-484a-8fe7-c1d894a011ba} {5384767E-00D9-40E9-B72F-9CC39D655D6F} {8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} {b9db16a4-6edc-47ec-a1f4-b86292ed211d} {bee6eb20-01e0-ebd1-da83-080329fb9a3a} C:\Users\Anthony\AppData\Roaming\Mozilla\Firefox\Profiles\31ptt34g.default-1347994869486\searchplugins\ web-search-powered-by-google.xml wot-safe-search.xml yahoo.xml {688B6F2A-6679-4CEB-A689-3D7DC9DD441E}.xml ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}] IDM integration (IDMIEHlprObj Class) - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2014-02-03 401944] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}] ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2013-04-13 611840] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}] Logitech SetPoint - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2013-07-31 364824] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}] ClassicIE9BHO Class - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll [2013-04-13 385024] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}] Hotspot Shield Class - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll [2013-01-03 233288] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB16E5C3-A9E2-47A2-8EFC-319E775E62CC}] PrivDog Extension - C:\Program Files (x86)\AdTrustMedia\PrivDog\1.8.0.15\trustedads.dll [2013-11-15 744616] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2013-04-13 611840] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "DFX"=C:\Program Files (x86)\DFX\DFX.exe [2013-06-22 1274840] "ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-06-25 322208] "HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016] "SysMetrix"=C:\Program Files (x86)\SysMetrix\SysMetrix.exe [2011-03-22 2625536] "ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2012-06-19 174752] "AntiLogger"=C:\Program Files (x86)\AntiLogger\AntiLogger.exe [2014-03-18 19318696] "EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2010-10-12 979328] "Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-12-21 959904] "HOSTS Anti-Adware_PUPs"=C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe [2014-04-08 302961] ""= [] "HPUsageTrackingLEDM"=C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe [2009-08-04 30264] "SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-03-04 224128] "TrojanScanner"=C:\Program Files (x86)\Trojan Remover\Trjscan.exe [2013-07-19 1655568] "tvncontrol"=C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2014-03-20 2327248] "PrivDogService"=C:\Program Files (x86)\AdTrustMedia\PrivDog\1.8.0.15\trustedadssvc.exe [2013-11-15 525480] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "L09FXLRD_7369752"=C:\Program Files (x86)\Microsoft Etudes\Microsoft Encarta 2009 - Études DVD\EDICT.EXE [2008-05-28 351000] "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584] "IDMan"=C:\Program Files (x86)\Internet Download Manager\IDMan.exe [2014-03-16 3825232] "ctfmon.exe"=C:\Windows\system32\ctfmon.exe [2009-07-14 8704] "Rainlendar2"=C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe [2014-03-16 2611808] "f.lux"=C:\Users\Anthony\AppData\Local\FluxSoftware\Flux\flux.exe [2013-10-24 1017224] "Speccy"=C:\Program Files\Speccy\Speccy64.exe [2014-01-24 6809880] "Google Update"=C:\Users\Anthony\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-25 116648] "EPSON SX430 Series"=C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [2011-01-20 232448] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Secunia PSI Tray.lnk - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe Start GeekBuddy.lnk - C:\Program Files (x86)\COMODO\GeekBuddy\launcher.exe C:\Users\Anthony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup AutorunsDisabled FastStone Capture.lnk - C:\Program Files (x86)\FastStone Capture\FSCapture.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=0 "ConsentPromptBehaviorUser"=3 "EnableLUA"=0 "EnableUIADesktopToggle"=0 "PromptOnSecureDesktop"=0 "dontdisplaylastusername"=1 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=221 "NoInstrumentation"=1 "NoStartMenuPinnedList"=0 "NoSharedDocuments"=1 "NoUserNameInStartMenu"=0 "NoSecurityTab"=1 "NoRecentDocsNetHood"=1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "ForceActiveDesktopOn"=0 "NoRecentDocsNetHood"=1 "NoInstrumentation"=1 "NoSecurityTab"=1 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "vidc.uyvy"=msyuv.dll "vidc.yuy2"=msyuv.dll "vidc.yvyu"=msyuv.dll "vidc.iyuv"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "vidc.yvu9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm "vidc.cvid"=iccvid.dll "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "aux1"=wdmaud.drv ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 month====== 2014-04-10 00:43:57 ----D---- C:\Users\Anthony\AppData\Roaming\Hotspot Shield 2014-04-10 00:32:15 ----D---- C:\Users\Anthony\AppData\Roaming\ESET 2014-04-08 23:13:03 ----A---- C:\PureRa.txt 2014-04-08 23:01:14 ----A---- C:\Windows\ntbtlog.txt 2014-04-08 17:58:44 ----SD---- C:\ProgramData\Shared Space 2014-04-08 17:58:17 ----D---- C:\Program Files (x86)\AdTrustMedia 2014-04-08 17:58:16 ----D---- C:\ProgramData\Adtrustmedia 2014-04-08 17:58:15 ----D---- C:\ProgramData\Comodo Downloader 2014-04-07 23:47:33 ----D---- C:\Windows\SysWOW64\Hotspot Shield 2014-04-07 23:46:34 ----D---- C:\themes 2014-04-07 23:35:37 ----D---- C:\translations 2014-04-07 23:35:37 ----A---- C:\cmdstat.dll 2014-04-07 23:35:36 ----D---- C:\cis 2014-04-07 23:35:36 ----A---- C:\7za.dll 2014-04-07 23:35:35 ----A---- C:\cmdinstall.exe 2014-04-07 23:35:35 ----A---- C:\cmdhtml.dll 2014-04-06 22:31:42 ----A---- C:\Windows\SysWOW64\CielComponent.ini 2014-04-05 22:22:34 ----D---- C:\CIEL 2014-04-05 22:20:01 ----D---- C:\Program Files (x86)\Common Files\MSSoap 2014-04-05 22:20:01 ----D---- C:\Program Files (x86)\Common Files\Ciel 2014-04-05 22:19:43 ----D---- C:\ProgramData\Ciel 2014-04-05 22:19:43 ----D---- C:\Program Files (x86)\Ciel 2014-04-05 22:19:43 ----D---- C:\Données Ciel 2014-04-05 14:06:07 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-04-05 13:53:05 ----A---- C:\Windows\LeaguePad Setup Log.txt 2014-04-05 13:49:37 ----D---- C:\Program Files (x86)\RADsoft 2014-04-05 13:49:36 ----D---- C:\Users\Anthony\AppData\Roaming\RADsoft 2014-04-05 13:44:42 ----D---- C:\Users\Anthony\AppData\Roaming\SmarTips 2014-04-05 13:40:58 ----D---- C:\Program Files (x86)\SmarTips 2014-04-05 13:29:15 ----A---- C:\Windows\APSO.INI 2014-04-05 13:29:14 ----D---- C:\APSOWIN 2014-04-05 13:29:14 ----A---- C:\Windows\UnDeployV.exe 2014-04-05 13:28:15 ----D---- C:\Program Files (x86)\Statfoot32Sha 2014-04-02 17:08:06 ----D---- C:\Users\Anthony\AppData\Roaming\Simply Super Software 2014-04-02 17:05:22 ----D---- C:\ProgramData\Simply Super Software 2014-04-02 17:05:22 ----D---- C:\Program Files (x86)\Trojan Remover 2014-03-30 20:02:14 ----D---- C:\Program Files (x86)\Mozilla Firefox 2014-03-28 18:15:58 ----D---- C:\Users\Anthony\AppData\Roaming\Comodo 2014-03-27 23:42:54 ----D---- C:\Program Files (x86)\Common Files\Java 2014-03-27 23:33:31 ----D---- C:\Program Files (x86)\CDBurnerXP 2014-03-25 20:22:38 ----A---- C:\Windows\SysWOW64\guard32.dll 2014-03-25 20:22:26 ----A---- C:\Windows\SysWOW64\cmdvrt32.dll 2014-03-25 20:22:24 ----A---- C:\Windows\SysWOW64\cmdkbd32.dll 2014-03-24 13:14:31 ----HDC---- C:\ProgramData\{D9418335-6363-40BC-A6DD-4AFE587F6C2C} 2014-03-24 12:20:57 ----D---- C:\ProgramData\Hotspot Shield 2014-03-24 12:20:44 ----D---- C:\Program Files (x86)\Hotspot Shield 2014-03-14 20:46:03 ----A---- C:\Windows\SysWOW64\uxtuneup.dll 2014-03-14 20:42:44 ----A---- C:\Windows\SysWOW64\authuitu.dll 2014-03-12 22:49:49 ----A---- C:\Windows\SysWOW64\msrating.dll 2014-03-12 22:49:49 ----A---- C:\Windows\SysWOW64\ieui.dll 2014-03-12 22:49:48 ----A---- C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-03-12 22:49:48 ----A---- C:\Windows\SysWOW64\iesysprep.dll 2014-03-12 22:49:48 ----A---- C:\Windows\SysWOW64\iesetup.dll 2014-03-12 22:49:48 ----A---- C:\Windows\SysWOW64\iernonce.dll 2014-03-12 22:49:47 ----A---- C:\Windows\SysWOW64\iertutil.dll 2014-03-12 22:49:46 ----A---- C:\Windows\SysWOW64\msfeeds.dll 2014-03-12 22:49:45 ----A---- C:\Windows\SysWOW64\jscript.dll 2014-03-12 22:49:44 ----A---- C:\Windows\SysWOW64\urlmon.dll 2014-03-12 22:49:44 ----A---- C:\Windows\SysWOW64\jscript9.dll 2014-03-12 22:49:42 ----A---- C:\Windows\SysWOW64\wininet.dll 2014-03-12 22:49:42 ----A---- C:\Windows\SysWOW64\jsproxy.dll 2014-03-12 22:49:41 ----A---- C:\Windows\SysWOW64\ieframe.dll 2014-03-12 22:49:39 ----A---- C:\Windows\SysWOW64\mshtml.dll 2014-03-12 21:17:13 ----A---- C:\Windows\SysWOW64\wer.dll 2014-03-12 21:12:22 ----A---- C:\Windows\SysWOW64\qedit.dll 2014-03-12 21:12:21 ----A---- C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-12 20:56:31 ----D---- C:\ProgramData\Hewlett-Packard 2014-03-12 20:50:13 ----D---- C:\Program Files (x86)\Hewlett-Packard 2014-03-12 20:39:39 ----D---- C:\ProgramData\HPSSUPPLY 2014-03-12 20:36:45 ----D---- C:\LJP1100_P1560_P1600_Full_Solution 2014-03-12 19:05:58 ----D---- C:\LJP1100_P1560_P1600_SI_Utility 2014-03-12 19:05:19 ----D---- C:\ProgramData\HP 2014-03-12 19:04:53 ----D---- C:\Program Files (x86)\HP 2014-03-12 17:16:14 ----D---- C:\Program Files (x86)\Common Files\SWF Studio 2014-03-11 23:50:05 ----D---- C:\Program Files (x86)\Faronics 2014-03-09 21:25:03 ----D---- C:\ProgramData\VS Revo Group 2014-03-09 20:24:11 ----D---- C:\Users\Anthony\AppData\Roaming\SUPERAntiSpyware.com 2014-03-09 20:23:43 ----D---- C:\ProgramData\SUPERAntiSpyware.com ======List of files/folders modified in the last 1 month====== 2014-04-10 00:59:42 ----D---- C:\Windows\Tasks 2014-04-10 00:42:48 ----D---- C:\Windows\winsxs 2014-04-08 23:36:58 ----D---- C:\Program Files (x86)\trend micro 2014-04-08 23:33:13 ----D---- C:\Windows\Temp 2014-04-08 23:13:03 ----D---- C:\Windows\SoftwareDistribution 2014-04-08 23:01:14 ----D---- C:\Windows 2014-04-08 18:25:59 ----D---- C:\Users\Anthony\AppData\Roaming\DMCache 2014-04-08 18:19:18 ----D---- C:\Program Files (x86)\Last.fm 2014-04-08 18:17:39 ----D---- C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs 2014-04-08 18:08:46 ----D---- C:\Program Files (x86)\SysMetrix 2014-04-08 18:00:37 ----SHD---- C:\Windows\Installer 2014-04-08 18:00:34 ----SHD---- C:\System Volume Information 2014-04-08 18:00:21 ----D---- C:\ProgramData\COMODO 2014-04-08 18:00:09 ----D---- C:\Windows\inf 2014-04-08 17:58:44 ----HD---- C:\ProgramData 2014-04-08 17:58:35 ----D---- C:\Windows\SysWOW64 2014-04-08 17:58:35 ----D---- C:\Windows\System32 2014-04-08 17:58:17 ----D---- C:\Program Files (x86) 2014-04-08 17:58:17 ----D---- C:\Program Files 2014-04-08 17:43:47 ----D---- C:\Users\Anthony\AppData\Roaming\IDM 2014-04-08 17:22:20 ----D---- C:\Users\Anthony\AppData\Roaming\uTorrent 2014-04-08 06:30:06 ----D---- C:\Program Files (x86)\Common Files\COMODO 2014-04-08 00:15:05 ----D---- C:\Users\Anthony\AppData\Roaming\Wise Registry Cleaner 2014-04-08 00:07:44 ----D---- C:\ProgramData\Intel 2014-04-08 00:07:33 ----D---- C:\Program Files (x86)\AntiLogger 2014-04-08 00:07:19 ----RSD---- C:\Windows\Fonts 2014-04-08 00:07:17 ----D---- C:\Windows\registration 2014-04-07 23:21:11 ----HD---- C:\Program Files (x86)\InstallShield Installation Information 2014-04-07 22:33:23 ----D---- C:\Windows\Prefetch 2014-04-06 23:17:46 ----AD---- C:\ProgramData\TEMP 2014-04-05 22:21:22 ----D---- C:\Windows\Downloaded Installations 2014-04-05 22:20:01 ----D---- C:\Program Files (x86)\Common Files 2014-04-05 14:06:14 ----D---- C:\Users\Anthony\AppData\Roaming\Malwarebytes 2014-04-05 14:06:14 ----D---- C:\ProgramData\Malwarebytes 2014-04-05 13:56:05 ----D---- C:\Program Files (x86)\LeaguePad 2014-04-05 13:53:03 ----A---- C:\Windows\iun6002.exe 2014-04-04 19:32:58 ----D---- C:\Users\Anthony\AppData\Roaming\Notepad++ 2014-04-04 13:00:43 ----D---- C:\Windows\Minidump 2014-04-03 07:35:08 ----D---- C:\Windows\rescache 2014-04-03 02:14:26 ----D---- C:\Users\Anthony\AppData\Roaming\Winamp 2014-04-02 14:43:14 ----D---- C:\ProgramData\ZGuideTVDotNet 2014-03-30 20:49:27 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 00:31:42 ----D---- C:\AdwCleaner 2014-03-23 19:41:34 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-22 16:07:07 ----SD---- C:\Users\Anthony\AppData\Roaming\Microsoft 2014-03-16 21:23:42 ----D---- C:\Program Files (x86)\Internet Download Manager 2014-03-15 14:38:13 ----D---- C:\Program Files (x86)\X-Setup Pro 2014-03-14 21:21:45 ----D---- C:\Users\Anthony\AppData\Roaming\Wise Disk Cleaner 2014-03-14 21:21:30 ----D---- C:\Windows\Help 2014-03-14 21:16:36 ----D---- C:\Windows\debug 2014-03-14 21:16:34 ----D---- C:\Windows\Panther 2014-03-14 21:10:22 ----D---- C:\Users\Anthony\AppData\Roaming\TuneUp Software 2014-03-14 21:10:21 ----D---- C:\ProgramData\TuneUp Software 2014-03-14 16:25:55 ----D---- C:\ProgramData\EPSON 2014-03-12 22:58:26 ----D---- C:\Program Files (x86)\Microsoft Silverlight 2014-03-12 22:55:52 ----D---- C:\Program Files (x86)\Internet Explorer 2014-03-12 22:51:05 ----D---- C:\ProgramData\Microsoft Help 2014-03-12 14:15:07 ----D---- C:\Program Files (x86)\VS Revo Group 2014-03-11 14:24:26 ----D---- C:\Program Files (x86)\S.P.D 2014-03-11 14:14:58 ----D---- C:\Windows\pss 2014-03-11 13:54:49 ----D---- C:\Program Files (x86)\Comodo 2014-03-10 00:51:12 ----D---- C:\ProgramData\Licenses ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [] R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys [] R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys [] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [] R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664] R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [] R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [] R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [] R1 HssDRV6;Hotspot Shield Routing Driver 6; C:\Windows\system32\DRIVERS\hssdrv6.sys [] R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [] R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [] R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [] R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [] R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [] R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [] R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [] R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [] R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [] R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [] R3 taphss6;Anchorfree HSS VPN Adapter; C:\Windows\system32\DRIVERS\taphss6.sys [] S1 AntiLog32;AntiLog32; \??\C:\Windows\system32\drivers\AntiLog64.sys [] S1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536] S1 CFRMD;CFRMD; C:\Windows\system32\DRIVERS\CFRMD.sys [] S1 HMD;COMODO livePCsupport Hardware Monitor Driver; C:\Windows\system32\DRIVERS\hmd.sys [] S1 mbamchameleon;mbamchameleon; \??\C:\Windows\system32\drivers\mbamchameleon.sys [] S1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416] S2 IDMWFP;IDMWFP; C:\Windows\system32\DRIVERS\idmwfp.sys [] S2 Sentinel64;Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [] S3 b06diag;Broadcom NetXtreme II Diag Driver; C:\Windows\system32\drivers\bxdiaga.sys [] S3 BFN7x64;Bigfoot Networks Killer Gaming Service; C:\Windows\system32\drivers\Xeno7x64.sys [] S3 BS_DEF;BS_DEF; \??\C:\Windows\BS_DEF.sys [2013-12-12 21048] S3 bxfcoe;bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [] S3 bxois;bxois; C:\Windows\system32\drivers\bxois.sys [] S3 cpuz136;cpuz136; \??\C:\Users\Anthony\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [] S3 DFX11_1;DFX Audio Enhancer 11.1; C:\Windows\system32\drivers\dfx11_1x64.sys [] S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver; C:\Windows\System32\Drivers\EtronHub3.sys [] S3 EtronSTOR;Etron Enhance USB BOT/UASP Mass Storage Driver; C:\Windows\System32\Drivers\EtronSTOR.sys [] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver; C:\Windows\System32\Drivers\EtronXHCI.sys [] S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [] S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [] S3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [] S3 ioatdma1;ioatdma1; C:\Windows\System32\Drivers\qd162x64.sys [] S3 ioatdma2;Intel(R) QuickData Technology device ver.2; C:\Windows\System32\Drivers\qd262x64.sys [] S3 iusb3hub;Intel(R) USB 3.0 Hub Driver; C:\Windows\system32\drivers\iusb3hub.sys [] S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver; C:\Windows\system32\drivers\iusb3xhc.sys [] S3 keycrypt;keycrypt; C:\Windows\SysWOW64\drivers\keycrypt.sys [] S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [] S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [] S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [] S3 mvusbews;USB EWS Device; C:\Windows\System32\Drivers\mvusbews.sys [] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\drivers\nusb3hub.sys [] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\drivers\nusb3xhc.sys [] S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\SysWOW64\drivers\pccsmcfd.sys [] S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [] S3 PSI;PSI; C:\Windows\system32\DRIVERS\psi_mf.sys [] S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [] S3 Revoflt;Revoflt; C:\Windows\system32\DRIVERS\revoflt.sys [] S3 rtsuvc;Realtek USB2.0 PC Camera; C:\Windows\system32\DRIVERS\rtsuvc.sys [] S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [] S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [] S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [] S3 tap0901;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [] S3 taphss;Anchorfree HSS Adapter; C:\Windows\system32\DRIVERS\taphss.sys [] S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [] S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [] S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [] S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [] S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [] S3 VGPU;VGPU; C:\Windows\SysWOW64\drivers\VGPU.sys [] S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [] S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [] S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2013-10-11 144152] S2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432] S2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2011-11-21 80512] S2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896] S2 CLPSLauncher;COMODO LPS Launcher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [2014-03-20 70352] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088] S2 CmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2014-03-25 6812400] S2 GeekBuddyRSP;GeekBuddyRSP Server; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2014-03-20 2327248] S2 HP LaserJet Service;HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2009-06-24 136704] S2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [] S2 hshld;Hotspot Shield Service; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [2014-03-24 977704] S2 HssWd;Hotspot Shield Monitoring Service; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [2014-03-24 555304] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-11-21 15720] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-02-13 731648] S2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-03-12 366552] S2 MaConfigAgent;Ma-Config Agent; C:\Program Files\ma-config.com\MaConfigAgent.exe [2014-01-20 2818896] S2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-04-03 1809720] S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-04-03 857912] S2 Secunia PSI Agent;Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [2012-11-26 1225312] S2 Secunia Update Agent;Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [2012-11-26 659040] S2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-02-05 4915040] S2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 20992] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-23 257712] S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2014-03-25 2264280] S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2013-11-07 279000] S3 HDDSvc;HDD Information Service; C:\Program Files (x86)\Common Files\AltrixSoft\HDDInfoService\HDDSvc.exe [2010-12-23 458488] S3 HssTrayService;Hotspot Shield Tray Service; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [2014-03-24 78512] S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752] S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-02-13 820184] S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2013-06-13 357144] S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-03-30 119408] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 SandraAgentSrv;SiSoftware Deployment Agent Service; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013.SP4\RpcAgentSrv.exe [2008-10-02 71832] S4 AppMgmt;Gestion d’applications; C:\Windows\system32\svchost.exe [2009-07-14 20992] S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808] S4 CscService;Fichiers hors connexion; C:\Windows\System32\svchost.exe [2009-07-14 20992] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856] S4 PeerDistSvc;BranchCache; C:\Windows\System32\svchost.exe [2009-07-14 20992] S4 UmRdpService;Redirecteur de port du mode utilisateur des services Bureau à distance; C:\Windows\System32\svchost.exe [2009-07-14 20992] -----------------EOF-----------------