Commentaire : je suis infecte par cryptwall 3.0
je n'arrive pas a m'en débarrasser
Format du document : text/plain
Prévisualisation
Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version:28-11-2015
Exécuté par User (administrateur) sur USER-PC (29-11-2015 17:30:00)
Exécuté depuis C:\Users\User\Desktop
Profils chargés: User (Profils disponibles: Utilisateur & User)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Langue: Français (France)
Internet Explorer Version 8 (Navigateur par défaut: FF)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processus (Avec liste blanche) =================
(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Corporation) C:\Windows\System32\hpservice.exe
(AMD) C:\Windows\System32\atieclxx.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe
==================== Registre (Avec liste blanche) ===========================
(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-06-02] (IDT, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [104936 2008-07-18] (CyberLink)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2011-04-14] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [P2Go_Menu] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [210216 2008-06-13] (CyberLink Corp.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [20131121] => C:\Program Files\AVAST Software\Avast\setup\emupdate\cda890d7-153d-4d68-8938-3543cd035be9.exe /check
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7004376 2015-11-24] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-2764563167-543833164-3887117586-1003\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31280256 2015-04-17] (Skype Technologies S.A.)
HKU\S-1-5-21-2764563167-543833164-3887117586-1003\...\Policies\Explorer: [TaskbarNoNotification] 1
HKU\S-1-5-21-2764563167-543833164-3887117586-1003\...\Policies\Explorer: [HideSCAHealth] 1
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-11-24] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_grx.HTML [2015-11-23] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_grx.TXT [2015-11-23] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_kpr.HTML [2015-11-23] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_kpr.TXT [2015-11-23] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_qbx.HTML [2015-11-23] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_qbx.TXT [2015-11-23] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_vkf.HTML [2015-11-23] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_vkf.TXT [2015-11-23] ()
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EOS Utility.lnk [2014-09-16]
ShortcutTarget: EOS Utility.lnk -> C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe (Pas de fichier)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HELP_YOUR_FILES.HTML [2015-11-23] ()
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HELP_YOUR_FILES.PNG [2015-11-23] ()
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HELP_YOUR_FILES.TXT [2015-11-23] ()
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 - Capture d’écran et lancement.lnk [2015-05-15]
ShortcutTarget: OneNote 2010 - Capture d’écran et lancement.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_grx.HTML [2015-11-23] ()
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_grx.TXT [2015-11-23] ()
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_kpr.HTML [2015-11-23] ()
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_kpr.TXT [2015-11-23] ()
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_qbx.HTML [2015-11-23] ()
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_qbx.TXT [2015-11-23] ()
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_vkf.HTML [2015-11-23] ()
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_vkf.TXT [2015-11-23] ()
Startup: C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_vkf.HTML [2015-11-23] ()
Startup: C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_how_recover_vkf.TXT [2015-11-23] ()
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Avec liste blanche) ====================
(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)
ProxyEnable: [.DEFAULT] => Proxy est activé.
ProxyServer: [.DEFAULT] => http=127.0.0.1:53909;https=127.0.0.1:53909;
ProxyServer: [S-1-5-21-2764563167-543833164-3887117586-1003] => http=localhost:49161
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{34353C6B-5807-4878-A8D7-99C13A203C15}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{5BF9EBC6-8E95-457C-8214-2C01CC825ADC}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-2764563167-543833164-3887117586-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://fr.msn.com/?ocid=iehp
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-2764563167-543833164-3887117586-1003 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-2764563167-543833164-3887117586-1003 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2764563167-543833164-3887117586-1003 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-11-24] (AVAST Software)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-11-21] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-11-24] (AVAST Software)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-11-21] (Google Inc.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-11-21] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-11-21] (Google Inc.)
Toolbar: HKU\S-1-5-21-2764563167-543833164-3887117586-1003 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-11-21] (Google Inc.)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2014-02-03] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2014-02-03] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2014-02-03] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2014-02-03] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ghz0ct7q.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_10_3_162.dll [2011-02-24] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [Pas de fichier]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll [2013-09-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-28] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-28] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-28] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32.dll [Pas de fichier]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Pas de fichier]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll [2013-09-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll [Pas de fichier]
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll [Pas de fichier]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-09-04] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ghz0ct7q.default\searchplugins\19yhz.ho77 [2015-11-23]
FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ghz0ct7q.default\searchplugins\3344gaf8zm.5k9nj [2015-11-23]
FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ghz0ct7q.default\searchplugins\HELP_YOUR_FILES.PNG.ccc [2015-11-23]
FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ghz0ct7q.default\searchplugins\_how_recover_grx.HTML [2015-11-23]
FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ghz0ct7q.default\searchplugins\_how_recover_kpr.HTML [2015-11-23]
FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ghz0ct7q.default\searchplugins\_how_recover_kpr.TXT [2015-11-23]
FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ghz0ct7q.default\searchplugins\_how_recover_qbx.HTML [2015-11-23]
FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ghz0ct7q.default\searchplugins\_how_recover_vkf.HTML [2015-11-23]
FF SearchPlugin: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ghz0ct7q.default\searchplugins\_how_recover_vkf.TXT [2015-11-23]
FF Extension: a76cd07bf0d74ef995668faef6e290e4 - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ghz0ct7q.default\extensions\{a76cd07b-f0d7-4ef9-9566-8faef6e290e4} [2015-11-23] [non signé]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-10-08]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-11-24]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015-11-24]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\cfg [2015-08-18] <==== ATTENTION
Chrome:
=======
CHR dev: Chrome dev build détecté(e)! <======= ATTENTION
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM-x32\...\Chrome\Extension: [dfcfkhnlpcoafpoepljegijlkinbhjgb] - C:\Program Files (x86)\Magnet.TV\magnet-downloader10.crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-11-24]
==================== Services (Avec liste blanche) ========================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [174416 2015-11-24] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [127752 2015-11-24] (SurfRight B.V.)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2413056 2011-06-28] (Realsil Microelectronics Inc.) [Fichier non signé]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S4 Orange update Core Service; C:\Program Files (x86)\Orange\OrangeUpdate\Service\OUCore.exe [699912 2014-01-21] (Orange SA)
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
===================== Pilotes (Avec liste blanche) ==========================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-11-24] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-11-24] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-11-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-11-24] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-24] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-24] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [154256 2015-11-24] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-11-24] (AVAST Software)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2015-11-29] (Malwarebytes)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [8192 2005-03-29] ()
S3 RdpVideoMiniport; C:\Windows\System32\drivers\rdpvideominiport.sys [19456 2012-08-23] (Microsoft Corporation) [Fichier non signé]
S3 terminpt; C:\Windows\system32\drivers\terminpt.sys [29696 2012-08-23] (Microsoft Corporation) [Fichier non signé]
==================== NetSvcs (Avec liste blanche) ===================
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
==================== Un mois - Créés - fichiers et dossiers ========
(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)
2015-11-29 17:25 - 2015-11-29 17:30 - 00021176 _____ C:\Users\User\Desktop\FRST.txt
2015-11-29 17:25 - 2015-11-29 17:27 - 00026966 _____ C:\Users\User\Desktop\Addition.txt
2015-11-29 17:24 - 2015-11-29 17:24 - 02349056 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe
2015-11-29 17:18 - 2015-11-29 17:30 - 00000000 ____D C:\FRST
2015-11-29 09:12 - 2015-11-29 09:12 - 00266288 _____ C:\Windows\Minidump\112915-18798-01.dmp
2015-11-26 11:06 - 2015-11-26 11:08 - 284395520 _____ C:\Users\User\Desktop\kav_rescue_10(1).iso
2015-11-26 11:00 - 2015-11-26 11:00 - 00387584 _____ C:\Users\User\Downloads\rescue2usb.exe
2015-11-26 10:50 - 2015-11-26 10:50 - 00000000 ____D C:\Users\User\AppData\Roaming\CyberLink
2015-11-26 10:46 - 2015-11-26 10:50 - 284395520 _____ C:\Users\User\Downloads\kav_rescue_10.iso
2015-11-26 10:39 - 2015-11-26 10:48 - 640748392 _____ (Doctor Web, Ltd.) C:\Users\User\Downloads\drweb-livedisk-900-usb(2).exe
2015-11-26 09:49 - 2015-11-26 09:58 - 640748392 _____ (Doctor Web, Ltd.) C:\Users\User\Downloads\drweb-livedisk-900-usb(1).exe
2015-11-26 09:48 - 2015-11-26 09:57 - 640748392 _____ (Doctor Web, Ltd.) C:\Users\User\Downloads\drweb-livedisk-900-usb.exe
2015-11-26 09:34 - 2015-11-26 09:34 - 00001154 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-11-24 12:10 - 2015-11-24 12:08 - 00386096 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-11-24 12:09 - 2015-11-24 12:09 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\AVAST Software
2015-11-24 12:08 - 2015-11-24 12:08 - 01059656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-11-24 12:08 - 2015-11-24 12:08 - 00449992 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-11-24 12:08 - 2015-11-24 12:08 - 00273784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-11-24 12:08 - 2015-11-24 12:08 - 00154256 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-11-24 12:08 - 2015-11-24 12:08 - 00097648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-11-24 12:08 - 2015-11-24 12:08 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-11-24 12:08 - 2015-11-24 12:08 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-11-24 12:08 - 2015-11-24 12:08 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-11-24 12:08 - 2015-11-24 12:08 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-11-24 12:08 - 2015-11-24 12:08 - 00001929 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-11-24 12:08 - 2015-11-24 12:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-11-24 12:06 - 2015-11-24 12:06 - 00000000 ____D C:\Program Files\AVAST Software
2015-11-24 11:23 - 2015-11-24 11:23 - 00001948 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2015-11-24 11:23 - 2015-11-24 11:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2015-11-24 11:23 - 2015-11-24 11:23 - 00000000 ____D C:\Program Files\HitmanPro
2015-11-24 11:22 - 2015-11-24 12:04 - 00000000 ____D C:\ProgramData\HitmanPro
2015-11-24 08:31 - 2015-11-29 17:13 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-11-24 08:31 - 2015-11-24 08:31 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-11-24 08:31 - 2015-11-24 08:31 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-11-24 08:31 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-11-24 08:31 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-11-24 08:31 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2015-11-23 16:44 - 2015-11-23 16:44 - 02595510 _____ C:\Users\User\Desktop\HOWTO_RESTORE_FILES.bmp
2015-11-23 16:44 - 2015-11-23 16:44 - 00007307 _____ C:\Users\User\Desktop\HOWTO_RESTORE_FILES.HTML
2015-11-23 16:44 - 2015-11-23 16:44 - 00007307 _____ C:\Users\User\Desktop\_how_recover_vkf.HTML
2015-11-23 16:44 - 2015-11-23 16:44 - 00002588 _____ C:\Users\Utilisateur\Downloads\_how_recover_vkf.TXT
2015-11-23 16:44 - 2015-11-23 16:44 - 00002588 _____ C:\Users\Utilisateur\Documents\_how_recover_vkf.TXT
2015-11-23 16:44 - 2015-11-23 16:44 - 00002588 _____ C:\Users\Utilisateur\Desktop\_how_recover_vkf.TXT
2015-11-23 16:44 - 2015-11-23 16:44 - 00002588 _____ C:\Users\Utilisateur\AppData\Roaming\_how_recover_vkf.TXT
2015-11-23 16:44 - 2015-11-23 16:44 - 00002588 _____ C:\Users\Utilisateur\AppData\LocalLow\_how_recover_vkf.TXT
2015-11-23 16:44 - 2015-11-23 16:44 - 00002588 _____ C:\Users\Utilisateur\AppData\Local\_how_recover_vkf.TXT
2015-11-23 16:44 - 2015-11-23 16:44 - 00002588 _____ C:\Users\Utilisateur\AppData\_how_recover_vkf.TXT
2015-11-23 16:44 - 2015-11-23 16:44 - 00002588 _____ C:\Users\Utilisateur\_how_recover_vkf.TXT
2015-11-23 16:44 - 2015-11-23 16:44 - 00002588 _____ C:\Users\User\Downloads\_how_recover_vkf.TXT
2015-11-23 16:44 - 2015-11-23 16:44 - 00002588 _____ C:\Users\User\Desktop\HOWTO_RESTORE_FILES.TXT
2015-11-23 16:44 - 2015-11-23 16:44 - 00002588 _____ C:\Users\User\Desktop\_how_recover_vkf.TXT
2015-11-23 16:44 - 2015-11-23 16:44 - 00002588 _____ C:\Users\User\_how_recover_vkf.TXT
2015-11-23 16:42 - 2015-11-23 16:44 - 00048126 _____ C:\Users\Utilisateur\HELP_YOUR_FILES.PNG.ccc
2015-11-23 16:42 - 2015-11-23 16:44 - 00048126 _____ C:\Users\Utilisateur\Downloads\HELP_YOUR_FILES.PNG.ccc
2015-11-23 16:42 - 2015-11-23 16:44 - 00048126 _____ C:\Users\Utilisateur\Documents\HELP_YOUR_FILES.PNG.ccc
2015-11-23 16:42 - 2015-11-23 16:44 - 00048126 _____ C:\Users\Utilisateur\AppData\Roaming\HELP_YOUR_FILES.PNG.ccc
2015-11-23 16:42 - 2015-11-23 16:44 - 00048126 _____ C:\Users\Utilisateur\AppData\HELP_YOUR_FILES.PNG.ccc
2015-11-23 16:42 - 2015-11-23 16:42 - 00008908 _____ C:\Users\User\Desktop\HELP_YOUR_FILES.HTML
2015-11-23 16:42 - 2015-11-23 16:42 - 00004616 _____ C:\Users\User\Desktop\HELP_YOUR_FILES.TXT
2015-11-23 16:42 - 2015-11-23 16:42 - 00002924 _____ C:\Users\xb010rznhj.an3bg
2015-11-23 16:42 - 2015-11-23 16:42 - 00002924 _____ C:\Users\Utilisateur\Downloads\9ho1q1.fq34j
2015-11-23 16:42 - 2015-11-23 16:42 - 00002924 _____ C:\Users\Utilisateur\Documents\o2j1rg.6y1hw
2015-11-23 16:42 - 2015-11-23 16:42 - 00002924 _____ C:\Users\Utilisateur\Desktop\9fx93l1.59n4l
2015-11-23 16:42 - 2015-11-23 16:42 - 00002924 _____ C:\Users\Utilisateur\AppData\Roaming\9akkr.hbet2
2015-11-23 16:42 - 2015-11-23 16:42 - 00002924 _____ C:\Users\Utilisateur\AppData\4u74dn.80kc4
2015-11-23 16:42 - 2015-11-23 16:42 - 00002924 _____ C:\Users\Utilisateur\4c3r01n9vv.u0
2015-11-23 16:42 - 2015-11-23 16:42 - 00002924 _____ C:\Users\qxdz6x.tn7b
2015-11-23 16:42 - 2015-11-23 16:42 - 00002924 _____ C:\Users\h1iurw.1r
2015-11-23 16:42 - 2015-11-23 16:42 - 00002924 _____ C:\Users\ee8ymjks15.3a5
2015-11-23 16:41 - 2015-11-23 16:44 - 00048126 _____ C:\Users\Utilisateur\AppData\LocalLow\HELP_YOUR_FILES.PNG.ccc
2015-11-23 16:41 - 2015-11-23 16:44 - 00048126 _____ C:\Users\Utilisateur\AppData\Local\HELP_YOUR_FILES.PNG.ccc
2015-11-23 16:41 - 2015-11-23 16:41 - 00002924 _____ C:\Users\Utilisateur\AppData\LocalLow\vcml3l8j8.1h
2015-11-23 16:41 - 2015-11-23 16:41 - 00002924 _____ C:\Users\Utilisateur\AppData\Local\uggrq6bf.v6b9
2015-11-23 16:40 - 2015-11-23 16:44 - 00048126 _____ C:\Users\User\Downloads\HELP_YOUR_FILES.PNG.ccc
2015-11-23 16:40 - 2015-11-23 16:40 - 00002924 _____ C:\Users\User\Downloads\8a15jide3.ht956
2015-11-23 16:40 - 2015-11-23 16:40 - 00002924 _____ C:\Users\User\a1edt.08dw
2015-11-23 16:27 - 2015-11-23 16:44 - 00007307 _____ C:\Users\Utilisateur\Downloads\_how_recover_vkf.HTML
2015-11-23 16:27 - 2015-11-23 16:44 - 00007307 _____ C:\Users\Utilisateur\Documents\_how_recover_vkf.HTML
2015-11-23 16:27 - 2015-11-23 16:44 - 00007307 _____ C:\Users\Utilisateur\Desktop\_how_recover_vkf.HTML
2015-11-23 16:27 - 2015-11-23 16:44 - 00007307 _____ C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_vkf.HTML
2015-11-23 16:27 - 2015-11-23 16:44 - 00007307 _____ C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_vkf.HTML
2015-11-23 16:27 - 2015-11-23 16:44 - 00007307 _____ C:\Users\Utilisateur\AppData\Roaming\_how_recover_vkf.HTML
2015-11-23 16:27 - 2015-11-23 16:44 - 00007307 _____ C:\Users\Utilisateur\AppData\_how_recover_vkf.HTML
2015-11-23 16:27 - 2015-11-23 16:44 - 00007307 _____ C:\Users\Utilisateur\_how_recover_vkf.HTML
2015-11-23 16:27 - 2015-11-23 16:44 - 00002588 _____ C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_vkf.TXT
2015-11-23 16:27 - 2015-11-23 16:44 - 00002588 _____ C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_vkf.TXT
2015-11-23 16:26 - 2015-11-23 16:44 - 00007307 _____ C:\Users\Utilisateur\AppData\LocalLow\_how_recover_vkf.HTML
2015-11-23 16:25 - 2015-11-23 16:44 - 00007307 _____ C:\Users\Utilisateur\AppData\Local\_how_recover_vkf.HTML
2015-11-23 16:25 - 2015-11-23 16:44 - 00007307 _____ C:\Users\User\_how_recover_vkf.HTML
2015-11-23 16:24 - 2015-11-23 16:44 - 00007307 _____ C:\Users\User\Downloads\_how_recover_vkf.HTML
2015-11-23 16:23 - 2015-11-23 16:44 - 00048126 _____ C:\Users\User\Documents\HELP_YOUR_FILES.PNG.ccc
2015-11-23 16:23 - 2015-11-23 16:44 - 00007307 _____ C:\Users\User\Documents\_how_recover_vkf.HTML
2015-11-23 16:23 - 2015-11-23 16:44 - 00002588 _____ C:\Users\User\Documents\_how_recover_vkf.TXT
2015-11-23 16:23 - 2015-11-23 16:23 - 01372148 _____ C:\Users\User\Documents\uwt176.w1
2015-11-23 16:23 - 2015-11-23 16:23 - 00394700 _____ C:\Users\User\Desktop\895a25ru9.32
2015-11-23 16:23 - 2015-11-23 16:23 - 00326444 _____ C:\Users\User\Desktop\38za3bfacc.n18ot
2015-11-23 16:23 - 2015-11-23 16:23 - 00000604 _____ C:\Users\User\Documents\ozdfw9gj.oh51l
2015-11-23 16:23 - 2015-11-23 16:23 - 00000604 _____ C:\Users\User\Documents\ms0j8a.r0ix0
2015-11-23 16:23 - 2015-11-23 16:23 - 00000604 _____ C:\Users\User\Documents\gg2f8wkxlj.bo7yi
2015-11-23 16:23 - 2015-11-23 16:23 - 00000604 _____ C:\Users\User\Documents\cpw5aoqe.1l1kh
2015-11-23 16:23 - 2015-11-23 16:23 - 00000604 _____ C:\Users\User\Documents\2kj764b5na.7wg
2015-11-23 16:23 - 2015-11-23 16:23 - 00000588 _____ C:\Users\User\Desktop\39u0k.82
2015-11-23 16:23 - 2015-11-23 16:23 - 00000540 _____ C:\Users\User\Desktop\2b91gdu.nf9
2015-11-23 16:23 - 2015-11-23 16:23 - 00000524 _____ C:\Users\User\Desktop\pvj1i.soa8
2015-11-23 16:23 - 2015-11-23 16:23 - 00000508 _____ C:\Users\User\Desktop\lo689m9.u3
2015-11-23 16:23 - 2015-11-23 16:23 - 00000508 _____ C:\Users\User\Desktop\i0w9wze4kp.ip2s
2015-11-23 16:23 - 2015-11-23 16:23 - 00000508 _____ C:\Users\User\Desktop\51b54hky04.8l
2015-11-23 16:23 - 2015-11-23 16:23 - 00000492 _____ C:\Users\User\Desktop\ypu6s.r1
2015-11-23 15:08 - 2015-11-23 16:44 - 00007307 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_vkf.HTML
2015-11-23 15:08 - 2015-11-23 16:44 - 00002588 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_vkf.TXT
2015-11-23 15:08 - 2015-11-23 16:33 - 00007307 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_vkf.HTML
2015-11-23 15:08 - 2015-11-23 16:33 - 00007307 _____ C:\Users\User\AppData\Roaming\_how_recover_vkf.HTML
2015-11-23 15:08 - 2015-11-23 16:33 - 00007307 _____ C:\Users\User\AppData\_how_recover_vkf.HTML
2015-11-23 15:08 - 2015-11-23 16:33 - 00002588 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_vkf.TXT
2015-11-23 15:08 - 2015-11-23 16:33 - 00002588 _____ C:\Users\User\AppData\Roaming\_how_recover_vkf.TXT
2015-11-23 15:08 - 2015-11-23 16:33 - 00002588 _____ C:\Users\User\AppData\_how_recover_vkf.TXT
2015-11-23 15:07 - 2015-11-23 16:32 - 00007307 _____ C:\Users\User\AppData\LocalLow\_how_recover_vkf.HTML
2015-11-23 15:07 - 2015-11-23 16:32 - 00002588 _____ C:\Users\User\AppData\LocalLow\_how_recover_vkf.TXT
2015-11-23 14:57 - 2015-11-23 16:44 - 00007307 _____ C:\Users\User\AppData\Local\_how_recover_vkf.HTML
2015-11-23 14:57 - 2015-11-23 16:44 - 00002588 _____ C:\Users\User\AppData\Local\_how_recover_vkf.TXT
2015-11-23 14:57 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Public\Downloads\_how_recover_vkf.HTML
2015-11-23 14:57 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Public\_how_recover_vkf.HTML
2015-11-23 14:57 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Invité\AppData\Local\_how_recover_vkf.HTML
2015-11-23 14:57 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Invité\AppData\_how_recover_vkf.HTML
2015-11-23 14:57 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Invité\_how_recover_vkf.HTML
2015-11-23 14:57 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Public\Downloads\_how_recover_vkf.TXT
2015-11-23 14:57 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Public\_how_recover_vkf.TXT
2015-11-23 14:57 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Invité\AppData\Local\_how_recover_vkf.TXT
2015-11-23 14:57 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Invité\AppData\_how_recover_vkf.TXT
2015-11-23 14:57 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Invité\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Hudson\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\HomeGroupUser$\AppData\Local\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\HomeGroupUser$\AppData\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\HomeGroupUser$\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default\Downloads\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default\Documents\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default\Desktop\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default\AppData\Roaming\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default\AppData\Local\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default\AppData\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default User\Downloads\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default User\Documents\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default User\Desktop\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default User\AppData\Roaming\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default User\AppData\Local\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Default User\AppData\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Hudson\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\HomeGroupUser$\AppData\Local\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\HomeGroupUser$\AppData\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\HomeGroupUser$\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default\Downloads\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default\Documents\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default\Desktop\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default\AppData\Roaming\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default\AppData\Local\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default\AppData\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default User\Downloads\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default User\Documents\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default User\Desktop\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default User\AppData\Roaming\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default User\AppData\Local\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Default User\AppData\_how_recover_vkf.TXT
2015-11-23 14:56 - 2015-11-23 16:27 - 00007307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\_how_recover_vkf.HTML
2015-11-23 14:56 - 2015-11-23 16:27 - 00002588 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\_how_recover_vkf.TXT
2015-11-23 14:55 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Public\Documents\_how_recover_vkf.HTML
2015-11-23 14:55 - 2015-11-23 16:28 - 00007307 _____ C:\Users\Public\Desktop\_how_recover_vkf.HTML
2015-11-23 14:55 - 2015-11-23 16:28 - 00007307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\_how_recover_vkf.HTML
2015-11-23 14:55 - 2015-11-23 16:28 - 00007307 _____ C:\ProgramData\_how_recover_vkf.HTML
2015-11-23 14:55 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Public\Documents\_how_recover_vkf.TXT
2015-11-23 14:55 - 2015-11-23 16:28 - 00002588 _____ C:\Users\Public\Desktop\_how_recover_vkf.TXT
2015-11-23 14:55 - 2015-11-23 16:28 - 00002588 _____ C:\ProgramData\Microsoft\Windows\Start Menu\_how_recover_vkf.TXT
2015-11-23 14:55 - 2015-11-23 16:28 - 00002588 _____ C:\ProgramData\_how_recover_vkf.TXT
2015-11-23 14:55 - 2015-11-23 16:27 - 00007307 _____ C:\Users\Administrateur\AppData\Local\_how_recover_vkf.HTML
2015-11-23 14:55 - 2015-11-23 16:27 - 00007307 _____ C:\Users\Administrateur\AppData\_how_recover_vkf.HTML
2015-11-23 14:55 - 2015-11-23 16:27 - 00007307 _____ C:\Users\Administrateur\_how_recover_vkf.HTML
2015-11-23 14:55 - 2015-11-23 16:27 - 00002588 _____ C:\Users\Administrateur\AppData\Local\_how_recover_vkf.TXT
2015-11-23 14:55 - 2015-11-23 16:27 - 00002588 _____ C:\Users\Administrateur\AppData\_how_recover_vkf.TXT
2015-11-23 14:55 - 2015-11-23 16:27 - 00002588 _____ C:\Users\Administrateur\_how_recover_vkf.TXT
2015-11-23 14:54 - 2015-11-23 14:54 - 00002924 _____ C:\Users\User\AppData\pbkgm4r.2y
2015-11-23 14:52 - 2015-11-23 14:52 - 00007307 _____ C:\Program Files\_how_recover_vkf.HTML
2015-11-23 14:52 - 2015-11-23 14:52 - 00002588 _____ C:\Program Files\_how_recover_vkf.TXT
2015-11-23 14:51 - 2015-11-23 14:51 - 00007307 _____ C:\Program Files\Common Files\_how_recover_vkf.HTML
2015-11-23 14:51 - 2015-11-23 14:51 - 00002588 _____ C:\Program Files\Common Files\_how_recover_vkf.TXT
2015-11-23 14:50 - 2015-11-23 16:27 - 00007307 _____ C:\Users\_how_recover_vkf.HTML
2015-11-23 14:35 - 2015-11-23 14:35 - 00007307 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_kpr.HTML
2015-11-23 14:35 - 2015-11-23 14:35 - 00007307 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_kpr.HTML
2015-11-23 14:35 - 2015-11-23 14:35 - 00007307 _____ C:\Users\User\AppData\Roaming\_how_recover_kpr.HTML
2015-11-23 14:35 - 2015-11-23 14:35 - 00007307 _____ C:\Users\User\AppData\LocalLow\_how_recover_kpr.HTML
2015-11-23 14:35 - 2015-11-23 14:35 - 00007307 _____ C:\Users\User\AppData\_how_recover_kpr.HTML
2015-11-23 14:35 - 2015-11-23 14:35 - 00002924 _____ C:\Users\User\AppData\Roaming\k5vk8v3.1vfx3
2015-11-23 14:35 - 2015-11-23 14:35 - 00002924 _____ C:\Users\User\AppData\Roaming\fb35awo.72ma
2015-11-23 14:35 - 2015-11-23 14:35 - 00002924 _____ C:\Users\User\AppData\dkhu1joocm.vzp1r
2015-11-23 14:35 - 2015-11-23 14:35 - 00002588 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_kpr.TXT
2015-11-23 14:35 - 2015-11-23 14:35 - 00002588 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_kpr.TXT
2015-11-23 14:35 - 2015-11-23 14:35 - 00002588 _____ C:\Users\User\AppData\Roaming\_how_recover_kpr.TXT
2015-11-23 14:35 - 2015-11-23 14:35 - 00002588 _____ C:\Users\User\AppData\LocalLow\_how_recover_kpr.TXT
2015-11-23 14:34 - 2015-11-23 14:34 - 00002588 _____ C:\Users\User\AppData\Local\_how_recover_kpr.TXT
2015-11-23 14:33 - 2015-11-23 14:33 - 00002924 _____ C:\Users\User\AppData\LocalLow\z338ybk5e6.j01k1
2015-11-23 14:33 - 2015-11-23 14:33 - 00002924 _____ C:\Users\User\AppData\LocalLow\ve307.1a
2015-11-23 14:32 - 2015-11-23 14:32 - 00002924 _____ C:\Users\User\AppData\Local\tnik4e.4a
2015-11-23 14:32 - 2015-11-23 14:32 - 00002924 _____ C:\Users\User\AppData\Local\qhaqtwa6.9v
2015-11-23 14:32 - 2015-11-23 14:32 - 00002924 _____ C:\Users\User\AppData\Local\4c15vbu4u8.s96
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Public\h7sn9.42r3
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Public\Downloads\irra0z3.3urzm
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Public\Downloads\d9tuo240.uy9
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Public\Documents\v30bm.94dj
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Public\Documents\ocog1by.6i8k1
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Public\Desktop\jlop820.ep6o9
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Public\Desktop\687m4ibs.12jv
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Public\0on218i0.s301
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Invité\rtl1e.x02f
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Invité\lmk9h.9o1x
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Invité\AppData\Local\v7i1fm6.76
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Invité\AppData\Local\nl94jbe.1n
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Invité\AppData\bnpb1v5.wem7
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Invité\AppData\2jy1qv.7k
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Hudson\wcqko19.a83
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Hudson\0u7oi2yw0.v6n
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\HomeGroupUser$\gd2brx.0z
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\HomeGroupUser$\e68zn.th77
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\HomeGroupUser$\AppData\Local\x08579.3o
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\HomeGroupUser$\AppData\Local\1xiuw.07nm
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\HomeGroupUser$\AppData\j8nlc0h9.k23
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\HomeGroupUser$\AppData\9ed5d8224.ky56
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default\t6d3q38.9h
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default\Downloads\m5ttrhn3nn.0j
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default\Downloads\kz4nb.2s
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default\Documents\mc58ijo2.dhz7
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default\Documents\4xszj920.u4
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default\Desktop\egyc7z.y0i
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default\Desktop\dokbt6.y852
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default\AppData\zd3uzxe7.1k
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default\AppData\Roaming\vh8hakr8zu.b4d44
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default\AppData\Roaming\93bvpq.q4n2
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default\AppData\Local\wb29u37iz.s7q
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default\AppData\Local\ewjp2sgm8.9q
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default\AppData\kvkk6x96k.n8
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default\81gl95a3gz.4um3
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default User\Downloads\m5ttrhn3nn.0j
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default User\Downloads\kz4nb.2s
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default User\Documents\mc58ijo2.dhz7
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default User\Documents\4xszj920.u4
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default User\Desktop\egyc7z.y0i
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default User\Desktop\dokbt6.y852
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default User\AppData\zd3uzxe7.1k
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default User\AppData\Roaming\vh8hakr8zu.b4d44
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default User\AppData\Roaming\93bvpq.q4n2
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default User\AppData\Local\wb29u37iz.s7q
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default User\AppData\Local\ewjp2sgm8.9q
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Default User\AppData\kvkk6x96k.n8
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Administrateur\y34k1x8597.e7z1b
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Administrateur\AppData\vhjvo5j42m.e9
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Administrateur\AppData\Local\sdqcp1mb.syoe5
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Administrateur\AppData\Local\efc0wx9n.3u8s5
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Administrateur\AppData\60cawc0.8c5
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\Users\Administrateur\45nzk0n7.k72
2015-11-23 14:30 - 2015-11-23 14:30 - 00002924 _____ C:\ProgramData\52ex5yfzag.j5
2015-11-23 14:28 - 2015-11-23 14:34 - 00007307 _____ C:\Users\User\AppData\Local\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Public\Downloads\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Public\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Invité\AppData\Local\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Invité\AppData\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Invité\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Hudson\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\HomeGroupUser$\AppData\Local\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\HomeGroupUser$\AppData\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\HomeGroupUser$\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default\Downloads\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default\Documents\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default\Desktop\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default\AppData\Roaming\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default\AppData\Local\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default\AppData\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default User\Downloads\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default User\Documents\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default User\Desktop\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default User\AppData\Roaming\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default User\AppData\Local\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Default User\AppData\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00007307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\_how_recover_kpr.HTML
2015-11-23 14:28 - 2015-11-23 14:28 - 00002588 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_kpr.TXT
2015-11-23 14:28 - 2015-11-23 14:28 - 00002588 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_kpr.TXT
2015-11-23 14:28 - 2015-11-23 14:28 - 00002588 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_kpr.TXT
2015-11-23 14:28 - 2015-11-23 14:28 - 00002588 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_kpr.TXT
2015-11-23 14:28 - 2015-11-23 14:28 - 00002588 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\_how_recover_kpr.TXT
2015-11-23 14:27 - 2015-11-23 14:28 - 00007307 _____ C:\Users\Public\Documents\_how_recover_kpr.HTML
2015-11-23 14:27 - 2015-11-23 14:28 - 00007307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\_how_recover_kpr.HTML
2015-11-23 14:27 - 2015-11-23 14:28 - 00007307 _____ C:\ProgramData\_how_recover_kpr.HTML
2015-11-23 14:27 - 2015-11-23 14:28 - 00002588 _____ C:\ProgramData\Microsoft\Windows\Start Menu\_how_recover_kpr.TXT
2015-11-23 14:27 - 2015-11-23 14:27 - 00007307 _____ C:\Users\Public\Desktop\_how_recover_kpr.HTML
2015-11-23 14:27 - 2015-11-23 14:27 - 00007307 _____ C:\Users\Administrateur\AppData\Local\_how_recover_kpr.HTML
2015-11-23 14:27 - 2015-11-23 14:27 - 00007307 _____ C:\Users\Administrateur\AppData\_how_recover_kpr.HTML
2015-11-23 14:27 - 2015-11-23 14:27 - 00007307 _____ C:\Users\Administrateur\_how_recover_kpr.HTML
2015-11-23 14:27 - 2015-11-23 14:27 - 00002924 _____ C:\ProgramData\r5om3t.eps6
2015-11-23 14:27 - 2015-11-23 14:27 - 00002924 _____ C:\ProgramData\0052atf.iq8b1
2015-11-23 14:26 - 2015-11-23 14:26 - 00007307 _____ C:\Program Files\_how_recover_kpr.HTML
2015-11-23 14:26 - 2015-11-23 14:26 - 00002588 _____ C:\Program Files\_how_recover_kpr.TXT
2015-11-23 14:25 - 2015-11-23 14:25 - 00007307 _____ C:\Users\_how_recover_kpr.HTML
2015-11-23 14:25 - 2015-11-23 14:25 - 00007307 _____ C:\Program Files\Common Files\_how_recover_kpr.HTML
2015-11-23 14:25 - 2015-11-23 14:25 - 00002588 _____ C:\Program Files\Common Files\_how_recover_kpr.TXT
2015-11-23 14:22 - 2015-11-29 09:12 - 565976330 _____ C:\Windows\MEMORY.DMP
2015-11-23 14:15 - 2015-11-23 14:15 - 00007307 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_qbx.HTML
2015-11-23 14:15 - 2015-11-23 14:15 - 00007307 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_qbx.HTML
2015-11-23 14:15 - 2015-11-23 14:15 - 00007307 _____ C:\Users\User\AppData\Roaming\_how_recover_qbx.HTML
2015-11-23 14:15 - 2015-11-23 14:15 - 00007307 _____ C:\Users\User\AppData\LocalLow\_how_recover_qbx.HTML
2015-11-23 14:15 - 2015-11-23 14:15 - 00007307 _____ C:\Users\User\AppData\_how_recover_qbx.HTML
2015-11-23 14:15 - 2015-11-23 14:15 - 00002588 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_qbx.TXT
2015-11-23 14:15 - 2015-11-23 14:15 - 00002588 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_qbx.TXT
2015-11-23 14:12 - 2015-11-23 14:15 - 00007307 _____ C:\Users\User\AppData\Local\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Public\Downloads\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Public\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Invité\AppData\Local\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Invité\AppData\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Invité\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Hudson\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\HomeGroupUser$\AppData\Local\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\HomeGroupUser$\AppData\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\HomeGroupUser$\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default\Downloads\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default\Documents\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default\Desktop\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default\AppData\Roaming\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default\AppData\Local\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default\AppData\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default User\Downloads\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default User\Documents\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default User\Desktop\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default User\AppData\Roaming\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default User\AppData\Local\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Default User\AppData\_how_recover_qbx.HTML
2015-11-23 14:12 - 2015-11-23 14:12 - 00002588 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_qbx.TXT
2015-11-23 14:12 - 2015-11-23 14:12 - 00002588 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_qbx.TXT
2015-11-23 14:12 - 2015-11-23 14:12 - 00002588 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_qbx.TXT
2015-11-23 14:12 - 2015-11-23 14:12 - 00002588 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_qbx.TXT
2015-11-23 14:11 - 2015-11-23 14:12 - 00007307 _____ C:\Users\Public\Documents\_how_recover_qbx.HTML
2015-11-23 14:11 - 2015-11-23 14:12 - 00007307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\_how_recover_qbx.HTML
2015-11-23 14:11 - 2015-11-23 14:12 - 00007307 _____ C:\ProgramData\_how_recover_qbx.HTML
2015-11-23 14:11 - 2015-11-23 14:12 - 00002588 _____ C:\ProgramData\Microsoft\Windows\Start Menu\_how_recover_qbx.TXT
2015-11-23 14:11 - 2015-11-23 14:11 - 00007307 _____ C:\Users\Public\Desktop\_how_recover_qbx.HTML
2015-11-23 14:11 - 2015-11-23 14:11 - 00007307 _____ C:\Users\Administrateur\AppData\Local\_how_recover_qbx.HTML
2015-11-23 14:11 - 2015-11-23 14:11 - 00007307 _____ C:\Users\Administrateur\AppData\_how_recover_qbx.HTML
2015-11-23 14:11 - 2015-11-23 14:11 - 00007307 _____ C:\Users\Administrateur\_how_recover_qbx.HTML
2015-11-23 14:11 - 2015-11-23 14:11 - 00007307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\_how_recover_qbx.HTML
2015-11-23 14:11 - 2015-11-23 14:11 - 00002588 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\_how_recover_qbx.TXT
2015-11-23 14:09 - 2015-11-23 14:09 - 00007307 _____ C:\Program Files\_how_recover_qbx.HTML
2015-11-23 14:09 - 2015-11-23 14:09 - 00002588 _____ C:\Program Files\_how_recover_qbx.TXT
2015-11-23 14:07 - 2015-11-23 14:08 - 00007307 _____ C:\Program Files\Common Files\_how_recover_qbx.HTML
2015-11-23 14:07 - 2015-11-23 14:08 - 00002588 _____ C:\Program Files\Common Files\_how_recover_qbx.TXT
2015-11-23 14:07 - 2015-11-23 14:07 - 00007307 _____ C:\Users\_how_recover_qbx.HTML
2015-11-23 13:41 - 2015-11-23 13:41 - 00007307 _____ C:\Users\_how_recover_act.HTML
2015-11-23 13:41 - 2015-11-23 13:41 - 00007307 _____ C:\Program Files\Common Files\_how_recover_act.HTML
2015-11-23 13:41 - 2015-11-23 13:41 - 00002588 _____ C:\Program Files\Common Files\_how_recover_act.TXT
2015-11-23 13:39 - 2015-11-23 14:07 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\18D4267A.sys
2015-11-23 13:39 - 2015-11-23 13:39 - 00002924 _____ C:\Users\User\AppData\csth2s.js54e
2015-11-23 10:52 - 2015-11-23 10:52 - 00007307 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_grx.HTML
2015-11-23 10:52 - 2015-11-23 10:52 - 00007307 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_grx.HTML
2015-11-23 10:52 - 2015-11-23 10:52 - 00007307 _____ C:\Users\User\AppData\Roaming\_how_recover_grx.HTML
2015-11-23 10:52 - 2015-11-23 10:52 - 00007307 _____ C:\Users\User\AppData\_how_recover_grx.HTML
2015-11-23 10:52 - 2015-11-23 10:52 - 00002588 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_grx.TXT
2015-11-23 10:52 - 2015-11-23 10:52 - 00002588 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_grx.TXT
2015-11-23 10:51 - 2015-11-23 10:51 - 00007307 _____ C:\Users\User\AppData\LocalLow\_how_recover_grx.HTML
2015-11-23 10:25 - 2015-11-23 10:25 - 00806672 _____ C:\Users\User\Desktop\l4of16wg.273d1
2015-11-23 10:25 - 2015-11-23 10:25 - 00755888 _____ C:\Users\User\Desktop\t5521xi.t4
2015-11-23 10:25 - 2015-11-23 10:25 - 00721792 _____ C:\Users\User\Desktop\ue6tkgcg.b6
2015-11-23 10:25 - 2015-11-23 10:25 - 00551072 _____ C:\Users\User\Desktop\438p3.y01p2
2015-11-23 10:25 - 2015-11-23 10:25 - 00520860 _____ C:\Users\User\Desktop\4m4p2zq.71we
2015-11-23 10:25 - 2015-11-23 10:25 - 00489324 _____ C:\Users\User\Desktop\g979c.5z
2015-11-23 10:25 - 2015-11-23 10:25 - 00419500 _____ C:\Users\User\Desktop\6f6uxltx3.7o
2015-11-23 10:25 - 2015-11-23 10:25 - 00417324 _____ C:\Users\User\Desktop\4jp5pp.bp2f
2015-11-23 10:25 - 2015-11-23 10:25 - 00176172 _____ C:\Users\User\Desktop\ort0ufr.2q
2015-11-23 10:25 - 2015-11-23 10:25 - 00016732 _____ C:\Users\User\Desktop\u0yotnj.8ffa
2015-11-23 10:25 - 2015-11-23 10:25 - 00013916 _____ C:\Users\User\Desktop\cgvtkdq9y.k73a2
2015-11-23 10:24 - 2015-11-23 15:08 - 00048222 _____ C:\Users\User\AppData\Roaming\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:57 - 00048222 _____ C:\Users\User\AppData\Local\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:57 - 00048222 _____ C:\Users\Public\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:57 - 00048222 _____ C:\Users\Public\Downloads\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:57 - 00048222 _____ C:\Users\Public\Documents\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:57 - 00048222 _____ C:\Users\Invité\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:57 - 00048222 _____ C:\Users\Invité\AppData\Local\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:57 - 00048126 _____ C:\Users\User\AppData\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\Invité\AppData\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\Hudson\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\HomeGroupUser$\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\HomeGroupUser$\AppData\Local\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\HomeGroupUser$\AppData\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\Default\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\Default\Downloads\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\Default\Documents\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\Default\AppData\Roaming\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\Default\AppData\Local\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\Default\AppData\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\Default User\Downloads\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\Default User\Documents\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\Default User\AppData\Roaming\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\Default User\AppData\Local\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:56 - 00048222 _____ C:\Users\Default User\AppData\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:55 - 00048222 _____ C:\Users\Administrateur\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:55 - 00048222 _____ C:\Users\Administrateur\AppData\Local\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:55 - 00048222 _____ C:\Users\Administrateur\AppData\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:55 - 00048222 _____ C:\ProgramData\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:34 - 00048222 _____ C:\Users\User\AppData\LocalLow\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:12 - 00048190 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:12 - 00048190 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:12 - 00048190 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 14:12 - 00048190 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 10:24 - 00333132 _____ C:\ProgramData\f8e9tu.lqnj7
2015-11-23 10:24 - 2015-11-23 10:24 - 00180556 _____ C:\ProgramData\6ugkj.v6omr
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\User\AppData\Local\t12cue2mx.dyy9
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Public\Downloads\q7x97w.7n
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Public\Documents\e9r3au.g9add
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Public\Desktop\w7r183e.vrp6
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Public\0m4jz0.34
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Invité\ero4o.6e4o
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Invité\AppData\x4o80x08z.ahi7p
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Invité\AppData\Local\40gzmct.0k
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Hudson\svwz3m0.k9k9
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\HomeGroupUser$\AppData\Local\jjv9x0z2.a39i
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\HomeGroupUser$\AppData\4g31ortg2j.4aj
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\HomeGroupUser$\1bhzi.1mi
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default\gmgi7.rv5
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default\Downloads\rdc6i7.k4s52
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default\Documents\13715xag.a3a
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default\Desktop\aa82z6h3c.0lf8e
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default\AppData\Roaming\xr5vmk.7l06j
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\7gi0l1s5.66
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\bb12adg.bx0
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default\AppData\Local\yc4q8187.2xw
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default\AppData\52h9qzpq.662w
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default User\Downloads\rdc6i7.k4s52
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default User\Documents\13715xag.a3a
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default User\Desktop\aa82z6h3c.0lf8e
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default User\AppData\Roaming\xr5vmk.7l06j
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\7gi0l1s5.66
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\bb12adg.bx0
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default User\AppData\Local\yc4q8187.2xw
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Default User\AppData\52h9qzpq.662w
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Administrateur\AppData\Local\p14vc.6e
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Administrateur\AppData\5pe5jgvlz.3ab
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\Users\Administrateur\28f31rrw9.072p
2015-11-23 10:24 - 2015-11-23 10:24 - 00002924 _____ C:\ProgramData\orehqo41by.ydb0
2015-11-23 10:23 - 2015-11-23 10:23 - 00008524 _____ C:\950oq1.13qk
2015-11-23 10:22 - 2015-11-23 10:51 - 00007307 _____ C:\Users\User\AppData\Local\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Public\Downloads\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Public\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Invité\AppData\Local\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Invité\AppData\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Invité\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Hudson\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\HomeGroupUser$\AppData\Local\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\HomeGroupUser$\AppData\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\HomeGroupUser$\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default\Downloads\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default\Documents\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default\Desktop\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default\AppData\Roaming\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default\AppData\Local\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default\AppData\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default User\Downloads\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default User\Documents\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default User\Desktop\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default User\AppData\Roaming\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default User\AppData\Local\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Default User\AppData\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00007307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\_how_recover_grx.HTML
2015-11-23 10:22 - 2015-11-23 10:22 - 00002588 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\_how_recover_grx.TXT
2015-11-23 10:21 - 2015-11-23 16:42 - 00000000 ____D C:\Users\User\AppData\Roaming\2945522
2015-11-23 10:21 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Public\Documents\_how_recover_grx.HTML
2015-11-23 10:21 - 2015-11-23 10:22 - 00007307 _____ C:\Users\Public\Desktop\_how_recover_grx.HTML
2015-11-23 10:21 - 2015-11-23 10:22 - 00007307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\_how_recover_grx.HTML
2015-11-23 10:21 - 2015-11-23 10:22 - 00007307 _____ C:\ProgramData\_how_recover_grx.HTML
2015-11-23 10:21 - 2015-11-23 10:22 - 00002588 _____ C:\ProgramData\Microsoft\Windows\Start Menu\_how_recover_grx.TXT
2015-11-23 10:21 - 2015-11-23 10:21 - 00007307 _____ C:\Users\Administrateur\AppData\Local\_how_recover_grx.HTML
2015-11-23 10:21 - 2015-11-23 10:21 - 00007307 _____ C:\Users\Administrateur\AppData\_how_recover_grx.HTML
2015-11-23 10:21 - 2015-11-23 10:21 - 00007307 _____ C:\Users\Administrateur\_how_recover_grx.HTML
2015-11-19 11:00 - 2015-11-23 16:36 - 00000000 ____D C:\Users\User\Desktop\degats cuisine
2015-11-18 10:40 - 2015-11-23 15:08 - 00000000 ____D C:\Users\User\AppData\Roaming\Sun
2015-11-18 10:40 - 2015-11-23 14:57 - 00000000 ____D C:\Users\User\.oracle_jre_usage
2015-11-18 10:40 - 2015-11-23 14:56 - 00000000 ____D C:\ProgramData\Oracle
2015-11-17 19:45 - 2015-11-23 15:20 - 00015374 _____ C:\Users\User\Desktop\dif immo.docx.ccc
2015-11-16 16:48 - 2015-11-16 16:48 - 00014679 ____H C:\Users\User\Desktop\~WRL3090.tmp
2015-11-16 10:24 - 2015-11-23 16:23 - 00447854 _____ C:\Users\User\Desktop\pieces_jointes_16_11_2015 7.zip.ccc
2015-11-16 10:24 - 2015-11-23 16:23 - 00394334 _____ C:\Users\User\Desktop\pieces_jointes_16_11_2015 8.zip.ccc
2015-11-16 10:24 - 2015-11-23 16:23 - 00343614 _____ C:\Users\User\Desktop\pieces_jointes_16_11_2015 9.zip.ccc
2015-11-16 10:23 - 2015-11-23 16:23 - 00487486 _____ C:\Users\User\Desktop\pieces_jointes_16_11_2015 4.zip.ccc
2015-11-16 10:23 - 2015-11-23 16:23 - 00369438 _____ C:\Users\User\Desktop\pieces_jointes_16_11_2015 5.zip.ccc
2015-11-16 10:22 - 2015-11-23 16:23 - 00649998 _____ C:\Users\User\Desktop\pieces_jointes_16_11_2015 2.zip.ccc
2015-11-16 10:22 - 2015-11-23 16:23 - 00299406 _____ C:\Users\User\Desktop\pieces_jointes_16_11_2015 3.zip.ccc
2015-11-13 15:37 - 2015-11-23 15:08 - 00000000 ____D C:\Users\User\Desktop\creche
2015-11-13 15:35 - 2015-11-23 16:23 - 00000000 ____D C:\Users\User\Desktop\sommeil
2015-11-13 15:34 - 2015-11-23 16:44 - 00000000 ____D C:\Users\User\Desktop\portrait
2015-11-13 15:33 - 2015-11-23 16:44 - 00000000 ____D C:\Users\User\Desktop\repas
2015-11-13 15:33 - 2015-11-23 15:08 - 00000000 ____D C:\Users\User\Desktop\bain
2015-11-13 15:32 - 2015-11-23 16:44 - 00000000 ____D C:\Users\User\Desktop\sortie
2015-11-13 11:58 - 2015-11-23 16:44 - 00000000 ____D C:\Users\User\Desktop\parc
2015-11-13 11:26 - 2015-11-23 16:44 - 00000000 ____D C:\Users\User\Desktop\Photos
2015-11-12 19:57 - 2015-11-23 16:36 - 00000000 ____D C:\Users\User\Desktop\cyto heamo jb
2015-11-12 19:56 - 2015-11-23 16:37 - 00000000 ____D C:\Users\User\Desktop\labo docs
2015-11-12 19:54 - 2015-11-23 16:44 - 00000000 ____D C:\Users\User\Desktop\transcription
2015-11-12 14:59 - 2015-11-23 16:23 - 00016142 _____ C:\Users\User\Desktop\prime a la naissance.docx.ccc
2015-11-12 11:49 - 2015-11-23 16:23 - 15655966 _____ C:\Users\User\Desktop\pieces_jointes_12_11_2015.zip.ccc
2015-11-12 06:40 - 2015-11-23 16:44 - 00000000 ____D C:\Users\User\Desktop\sport
2015-11-12 06:28 - 2015-11-23 15:08 - 00000000 ____D C:\Users\User\Desktop\admin
2015-11-09 08:18 - 2015-11-23 15:20 - 00104190 _____ C:\Users\User\Desktop\div 2 001.jpg.ccc
2015-11-09 08:17 - 2015-11-23 15:20 - 00256526 _____ C:\Users\User\Desktop\div 1 001.jpg.ccc
==================== Un mois - Modifiés - fichiers et dossiers ========
(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)
2015-11-29 17:27 - 2009-07-14 04:20 - 00000000 ____D C:\Windows
2015-11-29 16:58 - 2013-10-15 18:53 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-29 16:19 - 2015-04-29 16:59 - 00000000 ____D C:\Users\User\AppData\Roaming\Skype
2015-11-29 14:43 - 2009-07-14 05:45 - 00018544 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-11-29 14:43 - 2009-07-14 05:45 - 00018544 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-11-29 14:34 - 2013-10-15 18:53 - 00001060 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-29 14:34 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-11-29 09:12 - 2013-11-21 14:23 - 00000000 ____D C:\Windows\Minidump
2015-11-26 11:27 - 2011-04-12 10:16 - 01650030 _____ C:\Windows\system32\perfh00C.dat
2015-11-26 11:27 - 2011-04-12 10:16 - 00453708 _____ C:\Windows\system32\perfc00C.dat
2015-11-26 11:27 - 2009-07-14 06:13 - 00006392 _____ C:\Windows\system32\PerfStringBackup.INI
2015-11-26 11:05 - 2015-02-14 23:44 - 00000000 ___SD C:\Users\User\Documents\Mes sources de données
2015-11-26 10:30 - 2015-01-05 21:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-26 09:34 - 2015-06-03 10:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-26 09:34 - 2015-01-05 21:55 - 00001166 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-11-26 08:44 - 2013-11-13 05:10 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-11-25 08:38 - 2014-07-07 22:06 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\Google
2015-11-24 12:09 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2015-11-24 12:06 - 2013-11-09 22:23 - 00000000 ____D C:\ProgramData\AVAST Software
2015-11-24 12:05 - 2014-08-18 12:10 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\Google
2015-11-24 08:31 - 2014-07-08 06:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-11-24 08:29 - 2010-05-19 16:46 - 00000000 ____D C:\Program Files (x86)\Java
2015-11-23 21:27 - 2013-10-15 17:50 - 00000000 ____D C:\Users\Utilisateur
2015-11-23 21:26 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2015-11-23 16:44 - 2015-04-29 17:05 - 00000000 ____D C:\Users\User\Tracing
2015-11-23 16:44 - 2015-01-04 10:39 - 00000000 ____D C:\Users\User\Documents\Blocs-notes OneNote
2015-11-23 16:44 - 2015-01-03 21:11 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] Dracula.Untold.2014.READNFO.FANSUB.VOSTFR.480p.WEBriP.XviD.AC3-NIKOo
2015-11-23 16:44 - 2015-01-03 21:10 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] The.Equalizer.2014.FRENCH.SUBFORCED.BRRip.XviD-VENUM
2015-11-23 16:44 - 2015-01-03 21:08 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] The.Hobbit.The.Desolation.of.Smaug.2013.EXTENDED.FRENCH.BDRip.XviD-GLUPS
2015-11-23 16:44 - 2015-01-03 21:07 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] X-Men.Days.of.Future.Past.2014.TRUEFRENCH.SUBFORCED.DVDRiP.XViD-FB
2015-11-23 16:44 - 2015-01-03 21:03 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] Dawn.of.the.Planet.of.the.Apes.2014.FRENCH.DVDRip.XviD-GLUPS
2015-11-23 16:44 - 2014-12-01 21:11 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] VA_-_Tomorrowland_2014_Music_Will_Unite_Us_Forever-3CD-2014-HB
2015-11-23 16:44 - 2014-12-01 21:04 - 00000000 ____D C:\Users\User\Downloads\Calvin Harris - Motion 2014
2015-11-23 16:44 - 2014-12-01 20:46 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] VA-House_2015-2CD-2014-MTC
2015-11-23 16:44 - 2014-12-01 20:39 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] Eminem • Shady XV 2CD [2014] 320
2015-11-23 16:44 - 2014-12-01 19:33 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] Predestination.2014.FRENCH.720p.BluRay.x264-LOST
2015-11-23 16:44 - 2014-12-01 19:28 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] Transformers.Age.Of.Extinction.2014.FRENCH.BRRip.XviD-DesTroY
2015-11-23 16:44 - 2014-12-01 19:28 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] One.Shot.2014.French.DVDRip.XviD-SVR
2015-11-23 16:44 - 2014-12-01 19:27 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] Gad.Elmaleh.Sans.Tambour.2014.FRENCH.DVDRip.AC3.x264-KRiNe
2015-11-23 16:44 - 2014-12-01 19:26 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] The.Maze.Runner.2014.TRUEFRENCH.BDRip.XviD-GLUPS
2015-11-23 16:44 - 2014-11-28 21:53 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] The Amazing Spider-Man 2 2014 FRENCH BRRiP XviD-CARPEDIEM
2015-11-23 16:44 - 2014-11-28 21:53 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] Teenage.Mutant.Ninja.Turtles.2014.FRENCH.BDRip.XviD-GLUPS
2015-11-23 16:44 - 2014-11-28 21:52 - 00000000 ____D C:\Users\User\Downloads\[www.Cpasbien.pe] The.Expendables.3.2014.THEATRiCAL.FRENCH.DVDRip.XviD-GLUPS
2015-11-23 16:44 - 2014-07-26 19:01 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\KalityWeb
2015-11-23 16:44 - 2014-07-08 08:51 - 00000000 ____D C:\Users\User\Documents\MedCalc
2015-11-23 16:44 - 2014-07-07 22:06 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\Torch
2015-11-23 16:44 - 2014-07-07 22:06 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\Comodo
2015-11-23 16:44 - 2014-05-06 13:39 - 00000000 ____D C:\Users\User\Downloads\FILMS
2015-11-23 16:44 - 2013-10-15 17:50 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\Media Center Programs
2015-11-23 16:44 - 2013-10-15 17:06 - 00000000 ____D C:\Users\Utilisateur\AppData\LocalLow\Orange
2015-11-23 16:44 - 2013-10-13 16:12 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\ElevatedDiagnostics
2015-11-23 16:44 - 2013-09-17 18:05 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\ATI
2015-11-23 16:44 - 2013-09-17 18:05 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\ATI
2015-11-23 16:44 - 2013-09-17 17:58 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\InstallShield
2015-11-23 16:44 - 2011-02-24 13:12 - 00000000 ____D C:\Users\Utilisateur\AppData\LocalLow\Adobe
2015-11-23 16:44 - 2010-05-20 10:43 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\Macromedia
2015-11-23 16:44 - 2010-05-20 10:21 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\CyberLink
2015-11-23 16:44 - 2010-05-20 10:12 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\Adobe
2015-11-23 16:44 - 2010-05-20 10:12 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\Adobe
2015-11-23 16:44 - 2010-05-20 09:53 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\Power2Go
2015-11-23 16:44 - 2010-05-19 16:45 - 00000000 ____D C:\Users\Utilisateur\AppData\LocalLow\Sun
2015-11-23 16:44 - 2010-05-19 15:49 - 00000000 ____D C:\Users\Utilisateur\AppData\Local\VirtualStore
2015-11-23 16:27 - 2013-09-20 07:46 - 03923534 _____ C:\Users\Utilisateur\Desktop\GC Agreement Starck & Beldo-Mongo - FINAL 2_1.pdf.ccc
2015-11-23 16:27 - 2010-05-19 16:43 - 00000000 ____D C:\Users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2015-11-23 16:24 - 2015-10-01 22:36 - 02847646 _____ C:\Users\User\Downloads\pieces_jointes_01_10_2015.zip.ccc
2015-11-23 16:24 - 2014-07-08 10:11 - 65909678 _____ C:\Users\User\Downloads\xlstat2013.zip.ccc
2015-11-23 16:24 - 2013-11-10 16:32 - 03338318 _____ C:\Users\User\Downloads\pieces jointes_10_11_2013.zip.ccc
2015-11-23 16:24 - 2013-10-30 20:51 - 02385742 _____ C:\Users\User\Downloads\pieces jointes_30_10_2013.zip.ccc
2015-11-23 16:24 - 2013-10-23 19:50 - 00052094 _____ C:\Users\User\Downloads\Tufts insurance verification.pdf.ccc
2015-11-23 16:24 - 2013-10-23 19:31 - 00541134 _____ C:\Users\User\Downloads\[Untitled] (2).pdf.ccc
2015-11-23 16:24 - 2013-10-23 19:31 - 00541134 _____ C:\Users\User\Downloads\[Untitled] (1).pdf.ccc
2015-11-23 16:24 - 2013-10-23 14:26 - 00099246 _____ C:\Users\User\Downloads\VALID UTR2 (3).xls.ccc
2015-11-23 16:24 - 2013-10-23 14:26 - 00099246 _____ C:\Users\User\Downloads\VALID UTR2 (2).xls.ccc
2015-11-23 16:24 - 2013-10-23 14:25 - 00099246 _____ C:\Users\User\Downloads\VALID UTR2.xls.ccc
2015-11-23 16:24 - 2013-10-22 18:59 - 00541134 _____ C:\Users\User\Downloads\[Untitled].pdf.ccc
2015-11-23 16:24 - 2013-10-18 08:54 - 00016958 _____ C:\Users\User\Downloads\pieces jointes_18_10_2013 (2).zip.ccc
2015-11-23 16:24 - 2013-10-18 08:53 - 02672894 _____ C:\Users\User\Downloads\pieces jointes_18_10_2013 (1).zip.ccc
2015-11-23 16:24 - 2013-10-18 08:52 - 01731310 _____ C:\Users\User\Downloads\pieces jointes_18_10_2013.zip.ccc
2015-11-23 16:23 - 2015-09-14 21:00 - 00125150 _____ C:\Users\User\Documents\bb creche.docx.ccc
2015-11-23 16:23 - 2015-08-13 13:18 - 00000590 ____H C:\Users\User\Desktop\~$brett.docx.ccc
2015-11-23 16:23 - 2015-06-30 17:35 - 00000590 ____H C:\Users\User\Desktop\~$cteur_Benoit_STARCK2[1].docx.ccc
2015-11-23 16:23 - 2015-06-08 13:43 - 00017022 _____ C:\Users\User\Desktop\TOM ET MARIE.xlsx.ccc
2015-11-23 16:23 - 2015-06-04 18:17 - 00014766 _____ C:\Users\User\Documents\Docteur_Benoit_STARCK2[1].docx.ccc
2015-11-23 16:23 - 2015-05-20 15:24 - 00175886 _____ C:\Users\User\Documents\poussette.docx.ccc
2015-11-23 16:23 - 2015-05-05 01:20 - 00000590 ____H C:\Users\User\Desktop\~$Planning bb.xlsx.ccc
2015-11-23 16:23 - 2015-04-14 20:40 - 00000590 ____H C:\Users\User\Desktop\~$PPORT CRP.doc.ccc
2015-11-23 16:23 - 2015-04-12 06:37 - 00000590 ____H C:\Users\User\Desktop\~$VALIDATION COAG.xlsx.ccc
2015-11-23 16:23 - 2015-04-10 12:11 - 00186382 _____ C:\Users\User\Documents\recu paiement pay pal.docx.ccc
2015-11-23 16:23 - 2015-03-06 13:19 - 00000590 ____H C:\Users\User\Desktop\~$nsieur Michiels.docx.ccc
2015-11-23 16:23 - 2015-02-21 19:25 - 00000590 ____H C:\Users\User\Documents\~$SULTATS MTX.docx.ccc
2015-11-23 16:23 - 2015-01-03 11:46 - 00345518 _____ C:\Users\User\Documents\mtxleguellec-2010[1].pdf.ccc
2015-11-23 16:23 - 2014-12-07 10:45 - 00000590 ____H C:\Users\User\Desktop\~$cueil données pour Revue de direction 2014 .doc.ccc
2015-11-23 16:23 - 2014-11-26 14:06 - 00000590 ____H C:\Users\User\Desktop\~$njour Madame.docx.ccc
2015-11-23 16:23 - 2014-11-18 21:35 - 00234174 _____ C:\Users\User\Documents\met article.docx.ccc
2015-11-23 16:23 - 2014-11-17 23:30 - 00000590 ____H C:\Users\User\Desktop\~$E LENVAL - Copie.docx.ccc
2015-11-23 16:23 - 2014-11-06 17:43 - 00000590 ____H C:\Users\User\Desktop\~$L AU LABORATOIRE POLYVALENT CHU LENVAL.docx.ccc
2015-11-23 16:23 - 2014-09-13 16:19 - 00000590 ____H C:\Users\User\Desktop\~$_alex2 - Copie.doc.ccc
2015-11-23 16:23 - 2014-08-27 06:52 - 00015310 _____ C:\Users\User\Documents\REGLES POUR LES GROUPES SANGUINS ET RAI.docx.ccc
2015-11-23 16:23 - 2014-08-27 06:52 - 00000590 ____H C:\Users\User\Documents\~$GLES POUR LES GROUPES SANGUINS ET RAI.docx.ccc
2015-11-23 16:23 - 2014-07-17 18:24 - 00000590 ____H C:\Users\User\Desktop\~$ Agreement Starck & Emclian.doc.ccc
2015-11-23 16:23 - 2014-04-15 06:09 - 00000590 ____H C:\Users\User\Desktop\~$ospectiveParentsRegForm_SurrogacyProgram.docx.ccc
2015-11-23 16:23 - 2014-04-15 06:08 - 00000590 ____H C:\Users\User\Desktop\~$ospectiveParentsRegForm_EggDonationProgram.doc.ccc
2015-11-23 16:23 - 2014-02-20 06:34 - 00080574 _____ C:\Users\User\Downloads\Courrier Clients Blue Line.pdf.ccc
2015-11-23 16:23 - 2014-02-05 13:45 - 03847086 _____ C:\Users\User\Downloads\OPTMQRimouskidefJMGiannoli.pdf.ccc
2015-11-23 16:23 - 2013-11-10 16:34 - 04024414 _____ C:\Users\User\Downloads\pieces jointes_10_11_2013 (8).zip.ccc
2015-11-23 16:23 - 2013-11-10 16:33 - 02599390 _____ C:\Users\User\Downloads\pieces jointes_10_11_2013 (7).zip.ccc
2015-11-23 16:23 - 2013-11-10 16:33 - 02599390 _____ C:\Users\User\Downloads\pieces jointes_10_11_2013 (6).zip.ccc
2015-11-23 16:23 - 2013-11-10 16:33 - 00762270 _____ C:\Users\User\Downloads\pieces jointes_10_11_2013 (5).zip.ccc
2015-11-23 16:23 - 2013-11-10 16:32 - 02706270 _____ C:\Users\User\Downloads\pieces jointes_10_11_2013 (4).zip.ccc
2015-11-23 16:23 - 2013-11-10 16:32 - 02270942 _____ C:\Users\User\Downloads\pieces jointes_10_11_2013 (3).zip.ccc
2015-11-23 16:23 - 2013-11-10 16:32 - 02209726 _____ C:\Users\User\Downloads\pieces jointes_10_11_2013 (2).zip.ccc
2015-11-23 16:23 - 2013-11-10 16:32 - 00762270 _____ C:\Users\User\Downloads\pieces jointes_10_11_2013 (1).zip.ccc
2015-11-23 16:23 - 2013-11-09 18:14 - 03253182 _____ C:\Users\User\Downloads\pieces jointes_09_11_2013.zip.ccc
2015-11-23 16:23 - 2013-10-23 19:51 - 00039150 _____ C:\Users\User\Downloads\Cycle Expense Report- Starck - October, 2013.pdf.ccc
2015-11-23 16:23 - 2013-10-23 08:38 - 00028590 _____ C:\Users\User\Downloads\duree de vie.xls.ccc
2015-11-23 16:23 - 2013-10-18 10:49 - 00000590 ____H C:\Users\User\Desktop\~$ocedure analytique paracetamol.doc.ccc
2015-11-23 15:08 - 2014-09-16 13:19 - 00000000 ____D C:\Users\User\AppData\Roaming\CANON INC
2015-11-23 15:08 - 2014-09-16 13:10 - 00000000 ____D C:\Users\User\AppData\Roaming\Canon_Inc_IC
2015-11-23 15:08 - 2014-09-16 13:09 - 00000000 ____D C:\Users\User\AppData\Roaming\canon
2015-11-23 15:08 - 2014-08-28 07:23 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-11-23 15:08 - 2014-08-27 22:35 - 00000000 ____D C:\Users\User\AppData\Roaming\WinRAR
2015-11-23 15:08 - 2014-07-08 08:51 - 00000000 ____D C:\Users\User\AppData\Roaming\MedCalc Software
2015-11-23 15:08 - 2014-01-05 10:03 - 00000000 ____D C:\Users\User\AppData\Roaming\vlc
2015-11-23 15:08 - 2014-01-04 19:37 - 00000000 ____D C:\Users\User\AppData\Roaming\uTorrent
2015-11-23 15:08 - 2013-12-15 08:49 - 00000000 ____D C:\Users\User\AppData\Roaming\Malwarebytes
2015-11-23 15:08 - 2013-11-11 18:45 - 00000000 ____D C:\Users\User\AppData\Roaming\Mozilla
2015-11-23 15:08 - 2013-10-16 07:00 - 00000000 ____D C:\Users\User\AppData\Roaming\Google
2015-11-23 15:08 - 2013-10-15 17:50 - 00000000 ____D C:\Users\User\AppData\Roaming\Media Center Programs
2015-11-23 15:08 - 2013-09-23 18:32 - 00000000 ____D C:\Users\User\AppData\Roaming\Orange
2015-11-23 15:08 - 2013-09-19 17:47 - 00000000 ____D C:\Users\User\AppData\Roaming\Macromedia
2015-11-23 15:08 - 2013-09-19 17:38 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2015-11-23 15:07 - 2015-10-20 20:01 - 00000000 ____D C:\Users\User\AppData\LocalLow\Oracle
2015-11-23 15:07 - 2015-08-14 17:09 - 00000000 ____D C:\Users\User\AppData\LocalLow\Unity
2015-11-23 15:07 - 2015-08-14 17:09 - 00000000 ____D C:\Users\User\AppData\Local\Unity
2015-11-23 15:07 - 2015-08-14 10:49 - 00000000 ____D C:\Users\User\AppData\LocalLow\Company
2015-11-23 15:07 - 2015-04-29 16:59 - 00000000 ____D C:\Users\User\AppData\Local\Skype
2015-11-23 15:07 - 2015-01-05 21:55 - 00000000 ____D C:\Users\User\AppData\Local\Mozilla
2015-11-23 15:07 - 2014-09-29 13:25 - 00000000 __SHD C:\Users\User\AppData\Local\Picture Style Editor
2015-11-23 15:07 - 2014-08-28 06:30 - 00000000 ____D C:\Users\User\AppData\Local\WinZip
2015-11-23 15:07 - 2014-07-08 10:06 - 00000000 ____D C:\Users\User\AppData\Local\Rocket
2015-11-23 15:07 - 2014-07-07 22:06 - 00000000 ____D C:\Users\User\AppData\LocalLow\{45DC3BD0-5B75-14DF-DB01-C3EBDA70BC4D}
2015-11-23 15:07 - 2014-07-07 22:06 - 00000000 ____D C:\Users\User\AppData\Local\Torch
2015-11-23 15:07 - 2014-07-07 22:06 - 00000000 ____D C:\Users\User\AppData\Local\Packages
2015-11-23 15:07 - 2013-11-11 18:47 - 00000000 ____D C:\Users\User\AppData\LocalLow\SIEN SA
2015-11-23 15:07 - 2013-11-09 22:25 - 00000000 ____D C:\Users\User\AppData\Roaming\AVAST Software
2015-11-23 15:07 - 2013-10-23 16:22 - 00000000 ____D C:\Users\User\AppData\LocalLow\Temp
2015-11-23 15:07 - 2013-09-24 12:26 - 00000000 ____D C:\Users\User\AppData\Roaming\ADDINSOFT
2015-11-23 15:07 - 2013-09-23 19:11 - 00000000 ____D C:\Users\User\AppData\LocalLow\Orange
2015-11-23 15:07 - 2013-09-19 18:24 - 00000000 ____D C:\Users\User\AppData\LocalLow\Adobe
2015-11-23 15:07 - 2013-09-19 17:47 - 00000000 ____D C:\Users\User\AppData\Roaming\Adobe
2015-11-23 15:07 - 2013-09-19 17:44 - 00000000 ____D C:\Users\User\AppData\LocalLow\Sun
2015-11-23 15:07 - 2013-09-19 17:40 - 00000000 ____D C:\Users\User\AppData\Roaming\ATI
2015-11-23 15:07 - 2013-09-19 17:39 - 00000000 ____D C:\Users\User\AppData\Local\Power2Go
2015-11-23 15:06 - 2013-11-27 14:17 - 00000000 ____D C:\Users\User\AppData\Local\Microsoft Games
2015-11-23 15:06 - 2013-09-24 12:06 - 00000000 ____D C:\Users\User\AppData\Local\Microsoft Help
2015-11-23 14:57 - 2015-10-06 22:08 - 00000000 ____D C:\Users\User\AppData\Local\Birds
2015-11-23 14:57 - 2015-08-14 19:02 - 00000000 ____D C:\Users\User\AppData\Local\CrashRpt
2015-11-23 14:57 - 2015-08-14 17:09 - 00000000 ____D C:\Users\Public\QiYi
2015-11-23 14:57 - 2014-09-16 13:28 - 00000000 ____D C:\Users\User\AppData\Local\CANON_INC
2015-11-23 14:57 - 2014-07-07 22:06 - 00000000 ____D C:\Users\User\AppData\Local\Comodo
2015-11-23 14:57 - 2014-07-07 22:06 - 00000000 ____D C:\Users\Invité\AppData\Local\Torch
2015-11-23 14:57 - 2014-07-07 22:06 - 00000000 ____D C:\Users\Invité\AppData\Local\Google
2015-11-23 14:57 - 2014-07-07 22:06 - 00000000 ____D C:\Users\Invité\AppData\Local\Comodo
2015-11-23 14:57 - 2014-07-07 22:06 - 00000000 ____D C:\Users\Invité
2015-11-23 14:57 - 2013-10-15 18:53 - 00000000 ____D C:\Users\User\AppData\Local\Google
2015-11-23 14:57 - 2013-09-19 19:51 - 00000000 ____D C:\Users\User\AppData\Local\ElevatedDiagnostics
2015-11-23 14:57 - 2013-09-19 18:24 - 00000000 ____D C:\Users\User\AppData\Local\Adobe
2015-11-23 14:57 - 2013-09-19 17:40 - 00000000 ____D C:\Users\User\AppData\Local\ATI
2015-11-23 14:57 - 2011-04-12 10:27 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-11-23 14:57 - 2010-05-20 10:21 - 00000000 ____D C:\Users\Public\CyberLink
2015-11-23 14:57 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-11-23 14:56 - 2015-08-14 10:48 - 00000000 ___HD C:\ProgramData\niu
2015-11-23 14:56 - 2015-04-29 16:59 - 00000000 ____D C:\ProgramData\Skype
2015-11-23 14:56 - 2015-04-29 16:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-11-23 14:56 - 2015-01-05 21:55 - 00000000 ____D C:\ProgramData\Mozilla
2015-11-23 14:56 - 2015-01-04 15:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Reader
2015-11-23 14:56 - 2014-08-28 07:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-11-23 14:56 - 2014-08-28 06:30 - 00000000 ____D C:\ProgramData\WinZip
2015-11-23 14:56 - 2014-08-28 06:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2015-11-23 14:56 - 2014-07-07 22:06 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch
2015-11-23 14:56 - 2014-07-07 22:06 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google
2015-11-23 14:56 - 2014-07-07 22:06 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo
2015-11-23 14:56 - 2014-07-07 22:06 - 00000000 ____D C:\Users\HomeGroupUser$
2015-11-23 14:56 - 2014-07-07 21:57 - 00000000 ____D C:\ProgramData\Package Cache
2015-11-23 14:56 - 2014-03-05 10:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-11-23 14:56 - 2014-02-08 04:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-11-23 14:56 - 2014-01-05 10:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-11-23 14:56 - 2013-10-15 18:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-11-23 14:56 - 2013-10-15 18:01 - 00000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2015-11-23 14:56 - 2013-10-15 18:01 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite
2015-11-23 14:56 - 2013-09-24 12:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-11-23 14:56 - 2013-09-24 12:06 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-23 14:56 - 2013-09-23 18:35 - 00000000 ____D C:\Users\Hudson\LOCALS~1
2015-11-23 14:56 - 2013-09-23 18:35 - 00000000 ____D C:\Users\Hudson
2015-11-23 14:56 - 2013-09-23 18:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Orange
2015-11-23 14:56 - 2013-09-23 18:34 - 00000000 ____D C:\ProgramData\Orange
2015-11-23 14:56 - 2013-09-17 17:59 - 00000000 ____D C:\ProgramData\Ralink Driver
2015-11-23 14:56 - 2013-09-17 17:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Renesas Electronics
2015-11-23 14:56 - 2011-04-12 10:27 - 00000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs
2015-11-23 14:56 - 2011-04-12 10:27 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs
2015-11-23 14:56 - 2010-05-19 16:47 - 00000000 ____D C:\ProgramData\Sun
2015-11-23 14:56 - 2010-05-19 16:43 - 00000000 ____D C:\ProgramData\Temp
2015-11-23 14:56 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-11-23 14:55 - 2015-08-15 21:36 - 00000000 ____D C:\ProgramData\Evwrovnuanai
2015-11-23 14:55 - 2015-08-14 10:45 - 00000000 ____D C:\ProgramData\IapnZQyaEs
2015-11-23 14:55 - 2015-04-29 17:53 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2015-11-23 14:55 - 2014-09-16 13:09 - 00000000 ____D C:\ProgramData\Canon_Inc_IC
2015-11-23 14:55 - 2014-07-07 22:06 - 00000000 ____D C:\Users\Administrateur\AppData\Local\Torch
2015-11-23 14:55 - 2014-07-07 22:06 - 00000000 ____D C:\Users\Administrateur\AppData\Local\Google
2015-11-23 14:55 - 2014-07-07 22:06 - 00000000 ____D C:\Users\Administrateur\AppData\Local\Comodo
2015-11-23 14:55 - 2014-07-07 22:06 - 00000000 ____D C:\Users\Administrateur
2015-11-23 14:55 - 2014-06-21 08:02 - 00000000 ____D C:\ProgramData\7908827E0BE38BC69876F5A41992B82E
2015-11-23 14:55 - 2013-12-17 22:17 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2015-11-23 14:55 - 2013-12-15 08:49 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-11-23 14:55 - 2013-10-21 06:42 - 00000000 ___HD C:\ProgramData\CanonBJ
2015-11-23 14:55 - 2013-10-15 19:24 - 00000000 ____D C:\ProgramData\Google
2015-11-23 14:55 - 2013-09-17 18:05 - 00000000 ____D C:\ProgramData\ATI
2015-11-23 14:55 - 2013-09-17 17:58 - 00000000 ____D C:\SWSetup
2015-11-23 14:55 - 2010-05-19 16:44 - 00000000 ____D C:\ProgramData\CyberLink
2015-11-23 14:55 - 2010-05-19 16:39 - 00000000 ____D C:\ProgramData\Adobe
2015-11-23 14:54 - 2013-11-21 08:25 - 00000000 ____D C:\AdwCleaner
2015-11-23 14:54 - 2013-10-15 18:26 - 00000000 ____D C:\e5e5785a3c279c551c923e652b1d
2015-11-23 14:54 - 2013-10-10 07:38 - 00000000 ____D C:\eb6e83959650fb653b87ff1f
2015-11-23 14:54 - 2013-09-24 12:06 - 00000000 __RHD C:\MSOCache
2015-11-23 14:54 - 2013-09-17 18:02 - 00000000 ____D C:\Intel
2015-11-23 14:54 - 2009-07-14 04:20 - 00000000 ____D C:\PerfLogs
2015-11-23 14:52 - 2014-08-28 06:30 - 00000000 ____D C:\Program Files\WinZip
2015-11-23 14:52 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2015-11-23 14:51 - 2014-03-05 09:56 - 00000000 ____D C:\Program Files\pilote
2015-11-23 14:51 - 2014-02-08 04:51 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-11-23 14:51 - 2014-01-05 10:02 - 00000000 ____D C:\Program Files\VideoLAN
2015-11-23 14:51 - 2013-10-15 19:24 - 00000000 ____D C:\Program Files\Google
2015-11-23 14:51 - 2013-10-15 18:59 - 00000000 ____D C:\Program Files\CCleaner
2015-11-23 14:51 - 2013-10-15 17:48 - 00000000 ____D C:\Program Files\IDT
2015-11-23 14:51 - 2013-09-24 12:07 - 00000000 ____D C:\Program Files\Microsoft Office
2015-11-23 14:51 - 2013-09-23 18:23 - 00000000 ____D C:\Program Files\Orange
2015-11-23 14:51 - 2013-09-17 18:02 - 00000000 ____D C:\Program Files\Common Files\Intel
2015-11-23 14:51 - 2013-09-17 18:00 - 00000000 ____D C:\Program Files\ATI Technologies
2015-11-23 14:51 - 2013-09-17 18:00 - 00000000 ____D C:\Program Files\ATI
2015-11-23 14:51 - 2013-09-17 17:49 - 00000000 ____D C:\Program Files\Hewlett-Packard
2015-11-23 14:51 - 2013-09-17 17:42 - 00000000 ____D C:\Program Files\Validity Sensors
2015-11-23 14:51 - 2011-04-12 10:28 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-23 14:51 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Portable Devices
2015-11-23 14:51 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2015-11-23 14:51 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender
2015-11-23 14:51 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-11-23 14:51 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\MSBuild
2015-11-23 14:51 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Microsoft Games
2015-11-23 14:51 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\DVD Maker
2015-11-23 14:51 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Windows NT
2015-11-23 14:51 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\System
2015-11-23 14:51 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2015-11-23 14:51 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Services
2015-11-23 14:51 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-11-23 14:50 - 2013-09-25 06:50 - 00000000 ____D C:\74e2c225c8d36dbb98c833c93c
2015-11-23 10:21 - 2015-10-06 22:38 - 00007566 _____ C:\AdwCleaner[C12].txt.ccc
2015-11-23 10:21 - 2015-10-06 22:37 - 00007086 _____ C:\AdwCleaner[S15].txt.ccc
2015-11-23 10:21 - 2015-10-06 22:33 - 00007022 _____ C:\AdwCleaner[S14].txt.ccc
2015-11-23 10:21 - 2015-08-24 07:52 - 00011534 _____ C:\AdwCleaner[C11].txt.ccc
2015-11-23 10:21 - 2015-08-23 20:53 - 00010910 _____ C:\AdwCleaner[S13].txt.ccc
2015-11-23 10:21 - 2015-08-20 12:10 - 00003902 _____ C:\AdwCleaner[C10].txt.ccc
2015-11-23 10:21 - 2015-08-20 12:08 - 00003694 _____ C:\AdwCleaner[S12].txt.ccc
2015-11-23 10:21 - 2015-08-17 22:27 - 00003806 _____ C:\AdwCleaner[C9].txt.ccc
2015-11-23 10:21 - 2015-08-17 22:26 - 00003582 _____ C:\AdwCleaner[S11].txt.ccc
2015-11-23 10:21 - 2015-08-15 21:28 - 00047694 _____ C:\AdwCleaner[C8].txt.ccc
2015-11-23 10:21 - 2015-08-15 21:26 - 00047854 _____ C:\AdwCleaner[S10].txt.ccc
2015-11-23 10:21 - 2014-06-21 13:51 - 00001182 _____ C:\ProgramData\RUNDLL32.EXE-2248-F.txt.ccc
2015-11-23 10:21 - 2014-06-21 13:41 - 00003470 _____ C:\ProgramData\RUNDLL32.EXE-2856-F.txt.ccc
2015-11-23 10:21 - 2014-06-21 13:40 - 00004222 _____ C:\ProgramData\RUNDLL32.EXE-2728-F.txt.ccc
2015-11-23 10:21 - 2014-06-21 11:02 - 00001630 _____ C:\ProgramData\RUNDLL32.EXE-2532-F.txt.ccc
2015-11-23 10:21 - 2014-06-21 10:46 - 00001710 _____ C:\ProgramData\RUNDLL32.EXE-2528-F.txt.ccc
2015-11-23 10:21 - 2014-06-21 09:44 - 00002190 _____ C:\ProgramData\RUNDLL32.EXE-2600-F.txt.ccc
2015-11-23 10:21 - 2014-06-21 09:39 - 00001006 _____ C:\ProgramData\RUNDLL32.EXE-252-F.txt.ccc
2015-11-23 10:21 - 2014-06-21 09:38 - 00000526 _____ C:\ProgramData\RUNDLL32.EXE-2584-F.txt.ccc
2015-11-23 10:21 - 2014-06-21 09:28 - 00003934 _____ C:\ProgramData\RUNDLL32.EXE-2180-F.txt.ccc
2015-11-23 10:21 - 2014-06-21 09:23 - 00001486 _____ C:\ProgramData\RUNDLL32.EXE-2736-F.txt.ccc
2015-11-23 10:21 - 2014-06-21 09:21 - 00001246 _____ C:\ProgramData\RUNDLL32.EXE-1868-F.txt.ccc
2015-11-23 10:21 - 2014-01-03 14:01 - 00002654 _____ C:\AdwCleaner[S9].txt.ccc
2015-11-23 10:21 - 2014-01-03 14:01 - 00002590 _____ C:\AdwCleaner[R16].txt.ccc
2015-11-23 10:21 - 2014-01-02 19:39 - 00002526 _____ C:\AdwCleaner[R15].txt.ccc
2015-11-23 10:21 - 2013-12-31 09:21 - 00002462 _____ C:\AdwCleaner[S8].txt.ccc
2015-11-23 10:21 - 2013-12-31 09:20 - 00002414 _____ C:\AdwCleaner[R14].txt.ccc
2015-11-23 10:21 - 2013-12-27 08:52 - 00002350 _____ C:\AdwCleaner[S7].txt.ccc
2015-11-23 10:21 - 2013-12-27 08:52 - 00002286 _____ C:\AdwCleaner[R13].txt.ccc
2015-11-23 10:21 - 2013-12-21 12:47 - 00002222 _____ C:\AdwCleaner[R12].txt.ccc
2015-11-23 10:21 - 2013-12-21 12:47 - 00002158 _____ C:\AdwCleaner[R11].txt.ccc
2015-11-23 10:21 - 2013-12-16 09:19 - 00002110 _____ C:\AdwCleaner[S6].txt.ccc
2015-11-23 10:21 - 2013-12-16 09:19 - 00002046 _____ C:\AdwCleaner[R10].txt.ccc
2015-11-23 10:21 - 2013-12-16 09:19 - 00001982 _____ C:\AdwCleaner[R9].txt.ccc
2015-11-23 10:21 - 2013-12-15 08:26 - 00002110 _____ C:\AdwCleaner[R8].txt.ccc
2015-11-23 10:21 - 2013-12-15 08:26 - 00002046 _____ C:\AdwCleaner[S5].txt.ccc
2015-11-23 10:21 - 2013-12-15 08:25 - 00002046 _____ C:\AdwCleaner[R7].txt.ccc
2015-11-23 10:21 - 2013-12-14 10:08 - 00001742 _____ C:\AdwCleaner[S4].txt.ccc
2015-11-23 10:21 - 2013-12-14 10:08 - 00001678 _____ C:\AdwCleaner[R6].txt.ccc
2015-11-23 10:21 - 2013-12-13 18:18 - 00001630 _____ C:\AdwCleaner[S3].txt.ccc
2015-11-23 10:21 - 2013-12-13 18:17 - 00001566 _____ C:\AdwCleaner[R5].txt.ccc
2015-11-23 10:21 - 2013-12-13 11:19 - 00001502 _____ C:\AdwCleaner[S2].txt.ccc
2015-11-23 10:21 - 2013-12-13 11:18 - 00001438 _____ C:\AdwCleaner[R4].txt.ccc
2015-11-23 10:21 - 2013-12-13 08:17 - 00001374 _____ C:\AdwCleaner[R3].txt.ccc
2015-11-23 10:21 - 2013-12-13 08:15 - 00002766 _____ C:\AdwCleaner[S1].txt.ccc
2015-11-23 10:21 - 2013-12-13 08:14 - 00003390 _____ C:\AdwCleaner[R2].txt.ccc
2015-11-23 10:21 - 2013-12-13 08:14 - 00001678 _____ C:\AdwCleaner[R1].txt.ccc
2015-11-21 15:25 - 2013-10-15 18:53 - 00000000 ____D C:\Program Files (x86)\Google
2015-11-18 10:40 - 2012-12-29 18:10 - 00278624 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2015-11-12 11:10 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2015-11-11 22:54 - 2014-09-16 13:10 - 00000000 ____D C:\Program Files (x86)\Canon
2015-11-06 10:16 - 2009-07-14 06:08 - 00032482 _____ C:\Windows\Tasks\SCHEDLGU.TXT
==================== Fichiers à la racine de certains dossiers =======
2015-11-23 14:26 - 2015-11-23 14:26 - 0007307 _____ () C:\Program Files\_how_recover_kpr.HTML
2015-11-23 14:26 - 2015-11-23 14:26 - 0002588 _____ () C:\Program Files\_how_recover_kpr.TXT
2015-11-23 14:09 - 2015-11-23 14:09 - 0007307 _____ () C:\Program Files\_how_recover_qbx.HTML
2015-11-23 14:09 - 2015-11-23 14:09 - 0002588 _____ () C:\Program Files\_how_recover_qbx.TXT
2015-11-23 14:52 - 2015-11-23 14:52 - 0007307 _____ () C:\Program Files\_how_recover_vkf.HTML
2015-11-23 14:52 - 2015-11-23 14:52 - 0002588 _____ () C:\Program Files\_how_recover_vkf.TXT
2015-11-23 13:41 - 2015-11-23 13:41 - 0007307 _____ () C:\Program Files\Common Files\_how_recover_act.HTML
2015-11-23 13:41 - 2015-11-23 13:41 - 0002588 _____ () C:\Program Files\Common Files\_how_recover_act.TXT
2015-11-23 14:25 - 2015-11-23 14:25 - 0007307 _____ () C:\Program Files\Common Files\_how_recover_kpr.HTML
2015-11-23 14:25 - 2015-11-23 14:25 - 0002588 _____ () C:\Program Files\Common Files\_how_recover_kpr.TXT
2015-11-23 14:07 - 2015-11-23 14:08 - 0007307 _____ () C:\Program Files\Common Files\_how_recover_qbx.HTML
2015-11-23 14:07 - 2015-11-23 14:08 - 0002588 _____ () C:\Program Files\Common Files\_how_recover_qbx.TXT
2015-11-23 14:51 - 2015-11-23 14:51 - 0007307 _____ () C:\Program Files\Common Files\_how_recover_vkf.HTML
2015-11-23 14:51 - 2015-11-23 14:51 - 0002588 _____ () C:\Program Files\Common Files\_how_recover_vkf.TXT
2015-11-23 14:35 - 2015-11-23 14:35 - 0002924 _____ () C:\Users\User\AppData\Roaming\fb35awo.72ma
2015-11-23 10:24 - 2015-11-23 15:08 - 0048222 _____ () C:\Users\User\AppData\Roaming\HELP_YOUR_FILES.PNG.ccc
2015-11-23 14:35 - 2015-11-23 14:35 - 0002924 _____ () C:\Users\User\AppData\Roaming\k5vk8v3.1vfx3
2015-04-14 17:28 - 2015-04-14 17:28 - 0004387 _____ () C:\Users\User\AppData\Roaming\kN54rSraF9H
2013-10-13 14:32 - 2013-10-13 14:34 - 0000004 _____ () C:\Users\User\AppData\Roaming\settings.ini
2015-04-14 17:28 - 2015-04-14 17:28 - 0004387 _____ () C:\Users\User\AppData\Roaming\TlCzHsT4
2014-01-04 19:39 - 2014-09-07 23:23 - 0000107 _____ () C:\Users\User\AppData\Roaming\WB.CFG
2015-11-23 10:52 - 2015-11-23 10:52 - 0007307 _____ () C:\Users\User\AppData\Roaming\_how_recover_grx.HTML
2015-11-23 14:35 - 2015-11-23 14:35 - 0007307 _____ () C:\Users\User\AppData\Roaming\_how_recover_kpr.HTML
2015-11-23 14:35 - 2015-11-23 14:35 - 0002588 _____ () C:\Users\User\AppData\Roaming\_how_recover_kpr.TXT
2015-11-23 14:15 - 2015-11-23 14:15 - 0007307 _____ () C:\Users\User\AppData\Roaming\_how_recover_qbx.HTML
2015-11-23 15:08 - 2015-11-23 16:33 - 0007307 _____ () C:\Users\User\AppData\Roaming\_how_recover_vkf.HTML
2015-11-23 15:08 - 2015-11-23 16:33 - 0002588 _____ () C:\Users\User\AppData\Roaming\_how_recover_vkf.TXT
2015-11-23 14:32 - 2015-11-23 14:32 - 0002924 _____ () C:\Users\User\AppData\Local\4c15vbu4u8.s96
2015-11-23 10:24 - 2015-11-23 14:57 - 0048222 _____ () C:\Users\User\AppData\Local\HELP_YOUR_FILES.PNG.ccc
2015-11-23 14:32 - 2015-11-23 14:32 - 0002924 _____ () C:\Users\User\AppData\Local\qhaqtwa6.9v
2015-11-23 10:24 - 2015-11-23 10:24 - 0002924 _____ () C:\Users\User\AppData\Local\t12cue2mx.dyy9
2015-11-23 14:32 - 2015-11-23 14:32 - 0002924 _____ () C:\Users\User\AppData\Local\tnik4e.4a
2015-11-23 10:22 - 2015-11-23 10:51 - 0007307 _____ () C:\Users\User\AppData\Local\_how_recover_grx.HTML
2015-11-23 14:28 - 2015-11-23 14:34 - 0007307 _____ () C:\Users\User\AppData\Local\_how_recover_kpr.HTML
2015-11-23 14:34 - 2015-11-23 14:34 - 0002588 _____ () C:\Users\User\AppData\Local\_how_recover_kpr.TXT
2015-11-23 14:12 - 2015-11-23 14:15 - 0007307 _____ () C:\Users\User\AppData\Local\_how_recover_qbx.HTML
2015-11-23 14:57 - 2015-11-23 16:44 - 0007307 _____ () C:\Users\User\AppData\Local\_how_recover_vkf.HTML
2015-11-23 14:57 - 2015-11-23 16:44 - 0002588 _____ () C:\Users\User\AppData\Local\_how_recover_vkf.TXT
2015-08-14 15:34 - 2015-08-14 15:34 - 0000000 _____ () C:\Users\User\AppData\Local\{CE0B62FC-9127-4D50-8307-F7ED876F4E87}
2014-06-08 17:53 - 2014-06-08 17:53 - 0000000 _____ () C:\Users\User\AppData\Local\{D8281CF3-DBE6-4C82-A28E-1322E4D7BC16}
2015-11-23 14:27 - 2015-11-23 14:27 - 0002924 _____ () C:\ProgramData\0052atf.iq8b1
2015-11-23 14:30 - 2015-11-23 14:30 - 0002924 _____ () C:\ProgramData\52ex5yfzag.j5
2015-11-23 10:24 - 2015-11-23 10:24 - 0180556 _____ () C:\ProgramData\6ugkj.v6omr
2015-11-23 10:24 - 2015-11-23 10:24 - 0333132 _____ () C:\ProgramData\f8e9tu.lqnj7
2015-11-23 10:24 - 2015-11-23 14:55 - 0048222 _____ () C:\ProgramData\HELP_YOUR_FILES.PNG.ccc
2015-11-23 10:24 - 2015-11-23 10:24 - 0002924 _____ () C:\ProgramData\orehqo41by.ydb0
2015-11-23 14:27 - 2015-11-23 14:27 - 0002924 _____ () C:\ProgramData\r5om3t.eps6
2014-06-21 09:21 - 2015-11-23 10:21 - 0001246 _____ () C:\ProgramData\RUNDLL32.EXE-1868-F.txt.ccc
2014-06-21 09:28 - 2015-11-23 10:21 - 0003934 _____ () C:\ProgramData\RUNDLL32.EXE-2180-F.txt.ccc
2014-06-21 13:51 - 2015-11-23 10:21 - 0001182 _____ () C:\ProgramData\RUNDLL32.EXE-2248-F.txt.ccc
2014-06-21 09:39 - 2015-11-23 10:21 - 0001006 _____ () C:\ProgramData\RUNDLL32.EXE-252-F.txt.ccc
2014-06-21 10:46 - 2015-11-23 10:21 - 0001710 _____ () C:\ProgramData\RUNDLL32.EXE-2528-F.txt.ccc
2014-06-21 11:02 - 2015-11-23 10:21 - 0001630 _____ () C:\ProgramData\RUNDLL32.EXE-2532-F.txt.ccc
2014-06-21 09:38 - 2015-11-23 10:21 - 0000526 _____ () C:\ProgramData\RUNDLL32.EXE-2584-F.txt.ccc
2014-06-21 09:44 - 2015-11-23 10:21 - 0002190 _____ () C:\ProgramData\RUNDLL32.EXE-2600-F.txt.ccc
2014-06-21 13:40 - 2015-11-23 10:21 - 0004222 _____ () C:\ProgramData\RUNDLL32.EXE-2728-F.txt.ccc
2014-06-21 09:23 - 2015-11-23 10:21 - 0001486 _____ () C:\ProgramData\RUNDLL32.EXE-2736-F.txt.ccc
2014-06-21 13:41 - 2015-11-23 10:21 - 0003470 _____ () C:\ProgramData\RUNDLL32.EXE-2856-F.txt.ccc
2015-11-23 10:21 - 2015-11-23 10:22 - 0007307 _____ () C:\ProgramData\_how_recover_grx.HTML
2015-11-23 14:27 - 2015-11-23 14:28 - 0007307 _____ () C:\ProgramData\_how_recover_kpr.HTML
2015-11-23 14:11 - 2015-11-23 14:12 - 0007307 _____ () C:\ProgramData\_how_recover_qbx.HTML
2015-11-23 14:55 - 2015-11-23 16:28 - 0007307 _____ () C:\ProgramData\_how_recover_vkf.HTML
2015-11-23 14:55 - 2015-11-23 16:28 - 0002588 _____ () C:\ProgramData\_how_recover_vkf.TXT
Fichiers à déplacer ou supprimer:
====================
C:\Users\User\AppData\Roaming\settings.ini
==================== Bamital & volsnap =================
(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)
C:\Windows\system32\winlogon.exe => Le fichier est signé numériquement
C:\Windows\system32\wininit.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\wininit.exe => Le fichier est signé numériquement
C:\Windows\explorer.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\Windows\system32\svchost.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\Windows\system32\services.exe => Le fichier est signé numériquement
C:\Windows\system32\User32.dll => Le fichier est signé numériquement
C:\Windows\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\Windows\system32\userinit.exe => Le fichier est signé numériquement
C:\Windows\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\Windows\system32\rpcss.dll => Le fichier est signé numériquement
C:\Windows\system32\dnsapi.dll => Le fichier est signé numériquement
C:\Windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\Windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement
LastRegBack: 2015-11-20 00:34
==================== Fin de FRST.txt ============================