cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

ÿþOTL logfile created on: 28/09/2016 20:43:25 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\HP\Desktop
Professional (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18350)
Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy

2,98 Gb Total Physical Memory | 1,48 Gb Available Physical Memory | 49,76% Memory free
3,48 Gb Paging File | 1,67 Gb Available in Paging File | 48,04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 214,84 Gb Total Space | 188,70 Gb Free Space | 87,83% Space Free | Partition Type: NTFS
Drive D: | 250,57 Gb Total Space | 250,44 Gb Free Space | 99,95% Space Free | Partition Type: NTFS

Computer Name: PCSTORE | User Name: HP | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2016/09/28 20:37:42 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\HP\Desktop\OTL.exe
PRC - [2016/09/17 12:18:46 | 000,295,512 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\update\realsched.exe
PRC - [2016/09/14 01:38:40 | 000,967,496 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2016/08/08 08:22:10 | 007,833,096 | ---- | M] (Realtek Semiconductor) -- C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe
PRC - [2016/08/08 08:22:08 | 001,058,312 | ---- | M] (Realtek Semiconductor) -- C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
PRC - [2016/08/08 08:22:08 | 000,272,128 | ---- | M] (Realtek Semiconductor) -- C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe
PRC - [2016/07/18 21:38:34 | 000,422,912 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2016/07/18 21:38:16 | 000,236,544 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2016/06/23 14:11:58 | 001,999,832 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2016/06/10 15:10:26 | 005,589,152 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2016/04/06 01:54:37 | 002,412,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2016/03/31 14:16:28 | 000,220,776 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
PRC - [2016/03/22 08:45:37 | 000,097,080 | ---- | M] (Baidu Inc.) -- C:\Program Files\baidu\Baidu Browser\sparkservice.exe
PRC - [2014/11/22 02:05:56 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dasHost.exe
PRC - [2014/11/22 02:05:49 | 000,070,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2014/11/22 02:05:49 | 000,067,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhostex.exe
PRC - [2014/06/02 16:12:15 | 001,216,520 | ---- | M] (TorchMedia Inc.) -- C:\Users\HP\AppData\Local\Torch\Update\TorchCrashHandler.exe
PRC - [2011/11/29 02:53:03 | 000,255,208 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\YouCam\YouCamService.exe
PRC - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2009/08/16 20:36:06 | 000,955,392 | ---- | M] (SFX TEAM) -- C:\Program Files\SuperCopier2\SuperCopier2.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2016/09/14 01:38:52 | 001,806,152 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\53.0.2785.116\libglesv2.dll
MOD - [2016/09/14 01:38:51 | 000,094,024 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\53.0.2785.116\libegl.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV - [2016/08/08 08:22:08 | 000,272,128 | ---- | M] (Realtek Semiconductor) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe -- (RtkAudioService)
SRV - [2016/07/18 21:38:16 | 000,236,544 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2016/06/23 14:11:58 | 001,999,832 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2016/04/06 02:05:53 | 000,438,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicvss)
SRV - [2016/04/06 02:05:53 | 000,438,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmictimesync)
SRV - [2016/04/06 02:05:53 | 000,438,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicshutdown)
SRV - [2016/04/06 02:05:53 | 000,438,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicrdv)
SRV - [2016/04/06 02:05:53 | 000,438,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmickvpexchange)
SRV - [2016/04/06 02:05:53 | 000,438,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicheartbeat)
SRV - [2016/04/06 02:05:53 | 000,438,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicguestinterface)
SRV - [2016/04/06 02:03:32 | 000,305,152 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wcmsvc.dll -- (Wcmsvc)
SRV - [2016/04/06 02:02:14 | 000,105,984 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV - [2016/04/06 02:01:55 | 000,667,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsm.dll -- (LSM)
SRV - [2016/04/06 02:01:09 | 000,425,984 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AppReadiness.dll -- (AppReadiness)
SRV - [2016/04/06 02:01:06 | 000,167,424 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\DeviceSetupManager.dll -- (DsmSvc)
SRV - [2016/04/06 01:55:44 | 000,193,536 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV - [2016/04/06 01:54:37 | 001,175,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AppXDeploymentServer.dll -- (AppXSvc)
SRV - [2016/04/06 01:54:00 | 001,273,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\workfolderssvc.dll -- (workfolderssvc)
SRV - [2016/04/06 01:52:40 | 002,473,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\spool\drivers\w32x86\3\PrintConfig.dll -- (PrintNotify)
SRV - [2016/04/06 01:52:27 | 000,064,512 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV - [2016/04/06 01:52:15 | 000,284,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV - [2016/04/06 01:52:15 | 000,022,224 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2016/04/06 01:52:06 | 000,207,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV - [2016/04/06 01:51:56 | 000,367,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2016/03/31 14:16:28 | 000,220,776 | ---- | M] (Synaptics Incorporated) [Auto | Running] -- C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe -- (SynTPEnhService)
SRV - [2016/03/22 08:45:39 | 001,372,472 | ---- | M] (Baidu.com, Inc.) [On_Demand | Stopped] -- C:\Program Files\Baidu\SparkUpdate\Sparkupdate.exe -- (SparkUpdater)
SRV - [2016/03/22 08:45:37 | 000,097,080 | ---- | M] (Baidu Inc.) [Auto | Running] -- C:\Program Files\baidu\Baidu Browser\sparkservice.exe -- (SparkSvc)
SRV - [2015/12/17 05:40:16 | 000,147,624 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/11/22 03:08:34 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2014/11/22 02:06:24 | 001,845,248 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2014/11/22 02:06:24 | 000,126,464 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\ncbservice.dll -- (NcbService)
SRV - [2014/11/22 02:06:23 | 000,187,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2014/11/22 02:06:09 | 000,142,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\NcaSvc.dll -- (NcaSvc)
SRV - [2014/11/22 02:06:09 | 000,052,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wiarpc.dll -- (WiaRpc)
SRV - [2014/11/22 02:06:08 | 000,436,224 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netprofmsvc.dll -- (netprofm)
SRV - [2014/11/22 02:06:01 | 002,948,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\WSService.dll -- (WSService)
SRV - [2014/11/22 02:06:00 | 000,209,408 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\vaultsvc.dll -- (VaultSvc)
SRV - [2014/11/22 02:05:59 | 001,245,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wlidsvc.dll -- (wlidsvc)
SRV - [2014/11/22 02:05:59 | 000,028,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\efssvc.dll -- (EFS)
SRV - [2014/11/22 02:05:59 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wephostsvc.dll -- (WEPHOSTSVC)
SRV - [2014/11/22 02:05:59 | 000,017,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2014/11/22 02:05:56 | 000,312,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\das.dll -- (DeviceAssociationService)
SRV - [2014/11/22 02:05:56 | 000,206,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\bisrv.dll -- (BrokerInfrastructure)
SRV - [2014/11/22 02:05:56 | 000,098,304 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\fhsvc.dll -- (fhsvc)
SRV - [2014/11/22 02:05:56 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\smphost.dll -- (smphost)
SRV - [2014/11/22 02:05:53 | 000,177,664 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\TimeBrokerServer.dll -- (TimeBroker)
SRV - [2014/11/22 02:05:53 | 000,010,752 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\svsvc.dll -- (svsvc)
SRV - [2014/11/22 02:05:49 | 000,076,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\KeyboardFilterSvc.dll -- (MsKeyboardFilter)
SRV - [2014/11/22 02:05:49 | 000,046,592 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\keyiso.dll -- (KeyIso)
SRV - [2014/11/22 02:05:46 | 000,250,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\BthHFSrv.dll -- (BthHFSrv)
SRV - [2014/06/02 16:12:15 | 001,216,520 | ---- | M] (TorchMedia Inc.) [Auto | Running] -- C:\Users\HP\AppData\Local\Torch\Update\TorchCrashHandler.exe -- (TorchCrashHandler)
SRV - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2016/07/20 06:27:26 | 000,791,296 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\Rt630x86.sys -- (RTL8168)
DRV - [2016/07/18 22:39:18 | 024,549,888 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\atikmdag.sys -- (amdkmdag)
DRV - [2016/07/18 21:32:18 | 000,385,536 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\atikmpag.sys -- (amdkmdap)
DRV - [2016/06/23 14:31:52 | 000,206,496 | ---- | M] (ESET) [File_System | System | Running] -- C:\Windows\System32\Drivers\eamonm.sys -- (eamonm)
DRV - [2016/06/23 14:31:52 | 000,156,320 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\System32\Drivers\ehdrv.sys -- (ehdrv)
DRV - [2016/06/23 14:31:52 | 000,141,472 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\Drivers\epfwwfpr.sys -- (epfwwfpr)
DRV - [2016/06/23 14:31:52 | 000,014,976 | ---- | M] (ESET) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\eelam.sys -- (eelam)
DRV - [2016/05/03 04:07:28 | 003,292,968 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\athwb.sys -- (athr)
DRV - [2016/04/14 12:34:00 | 000,029,792 | ---- | M] (HP) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\WirelessButtonDriver86.sys -- (WirelessButtonDriver86)
DRV - [2016/04/06 02:05:53 | 000,091,824 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\vmbus.sys -- (vmbus)
DRV - [2016/04/06 02:05:53 | 000,050,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV - [2016/04/06 02:05:53 | 000,041,776 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\storvsc.sys -- (storvsc)
DRV - [2016/04/06 02:05:53 | 000,026,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\dmvsc.sys -- (dmvsc)
DRV - [2016/04/06 02:05:53 | 000,018,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2016/04/06 02:05:53 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\hyperkbd.sys -- (hyperkbd)
DRV - [2016/04/06 02:05:53 | 000,010,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\vmgencounter.sys -- (gencounter)
DRV - [2016/04/06 02:05:53 | 000,006,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\vms3cap.sys -- (s3cap)
DRV - [2016/04/06 02:01:47 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\fxppm.sys -- (FxPPM)
DRV - [2016/04/06 02:01:40 | 000,109,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV - [2016/04/06 02:00:47 | 000,122,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\msgpioclx.sys -- (GPIOClx0101)
DRV - [2016/04/06 01:55:25 | 000,279,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\clfs.sys -- (CLFS)
DRV - [2016/04/06 01:53:40 | 000,365,912 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\spaceport.sys -- (spaceport)
DRV - [2016/04/06 01:52:54 | 000,377,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\USBHUB3.SYS -- (USBHUB3)
DRV - [2016/04/06 01:52:54 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\winusb.sys -- (WinUsb)
DRV - [2016/04/06 01:52:44 | 000,131,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\tpm.sys -- (TPM)
DRV - [2016/04/06 01:52:15 | 000,233,304 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\Drivers\WdFilter.sys -- (WdFilter)
DRV - [2016/04/06 01:52:15 | 000,084,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\WdNisDrv.sys -- (WdNisDrv)
DRV - [2016/04/06 01:52:15 | 000,038,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\WdBoot.sys -- (WdBoot)
DRV - [2016/04/06 01:51:42 | 000,259,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\USBXHCI.SYS -- (USBXHCI)
DRV - [2016/04/06 01:51:30 | 000,065,536 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\ahcache.sys -- (ahcache)
DRV - [2016/04/06 01:51:26 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\bthhfenum.sys -- (BthHFEnum)
DRV - [2016/04/06 01:50:38 | 000,076,096 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\pdc.sys -- (pdc)
DRV - [2016/04/06 01:50:38 | 000,069,440 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\wfplwfs.sys -- (WFPLWFS)
DRV - [2016/04/06 01:50:38 | 000,051,520 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\Drivers\dam.sys -- (dam)
DRV - [2016/04/06 01:50:38 | 000,036,160 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\intelpep.sys -- (intelpep)
DRV - [2016/04/06 01:50:12 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\vwifimp.sys -- (vwifimp)
DRV - [2016/01/19 14:47:18 | 000,513,040 | ---- | M] (Qualcomm Atheros) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\btfilter.sys -- (BtFilter)
DRV - [2015/03/19 17:13:42 | 000,072,904 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\amd_sata.sys -- (amd_sata)
DRV - [2015/03/19 17:13:42 | 000,020,680 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\amd_xata.sys -- (amd_xata)
DRV - [2014/11/22 02:06:27 | 000,138,584 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\wof.sys -- (Wof)
DRV - [2014/11/22 02:06:25 | 000,022,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2014/11/22 02:06:24 | 000,045,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\wpcfltr.sys -- (wpcfltr)
DRV - [2014/11/22 02:06:09 | 000,090,112 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\Drivers\Ndu.sys -- (Ndu)
DRV - [2014/11/22 02:06:09 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mslldp.sys -- (MsLldp)
DRV - [2014/11/22 02:05:47 | 000,026,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2014/11/22 02:05:46 | 000,163,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\UCX01000.SYS -- (UCX01000)
DRV - [2014/11/22 02:05:46 | 000,071,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\netvsc63.sys -- (netvsc)
DRV - [2014/11/22 02:05:46 | 000,044,688 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\vmstorfl.sys -- (storflt)
DRV - [2014/11/22 01:58:37 | 000,120,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\SerCx2.sys -- (SerCx2)
DRV - [2014/11/22 01:58:31 | 000,186,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\BthLEEnum.sys -- (BthLEEnum)
DRV - [2014/11/22 01:58:31 | 000,142,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\VerifierExt.sys -- (VerifierExt)
DRV - [2014/11/22 01:58:31 | 000,064,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\sdstor.sys -- (sdstor)
DRV - [2014/11/22 01:58:31 | 000,047,960 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\stornvme.sys -- (stornvme)
DRV - [2014/11/22 01:58:31 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\BasicRender.sys -- (BasicRender)
DRV - [2014/11/22 01:45:43 | 000,019,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\kbldfltr.sys -- (kbldfltr)
DRV - [2014/11/22 01:45:34 | 000,030,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\terminpt.sys -- (terminpt)
DRV - [2013/10/24 05:59:40 | 000,015,080 | ---- | M] (Advanced Micro Devices, INC.) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\AmdAS4.sys -- (AmdAS4)
DRV - [2013/08/22 07:13:53 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\condrv.sys -- (condrv)
DRV - [2013/08/22 06:35:20 | 000,061,280 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\acpiex.sys -- (acpiex)
DRV - [2013/08/22 06:33:32 | 000,058,208 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\mvumis.sys -- (mvumis)
DRV - [2013/08/22 06:33:31 | 000,033,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\msgpiowin32.sys -- (msgpiowin32)
DRV - [2013/08/22 06:33:30 | 000,068,960 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV - [2013/08/22 06:33:29 | 000,069,472 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\lsi_sss.sys -- (LSI_SSS)
DRV - [2013/08/22 06:33:26 | 000,086,368 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\3ware.sys -- (3ware)
DRV - [2013/08/22 06:33:25 | 000,773,472 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\adp80xx.sys -- (ADP80XX)
DRV - [2013/08/22 06:33:25 | 000,100,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV - [2013/08/22 06:33:24 | 000,073,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\EhStorClass.sys -- (EhStorClass)
DRV - [2013/08/22 06:33:01 | 000,276,832 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV - [2013/08/22 06:32:57 | 000,090,976 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\storahci.sys -- (storahci)
DRV - [2013/08/22 06:32:57 | 000,059,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\SpbCx.sys -- (SpbCx)
DRV - [2013/08/22 06:32:57 | 000,058,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\SerCx.sys -- (SerCx)
DRV - [2013/08/22 06:32:57 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\uaspstor.sys -- (UASPStor)
DRV - [2013/08/22 06:32:38 | 000,031,584 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\Drivers\cnghwassist.sys -- (cnghwassist)
DRV - [2013/08/22 06:24:56 | 000,023,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\uefi.sys -- (UEFI)
DRV - [2013/08/22 06:24:36 | 000,023,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV - [2013/08/22 05:11:04 | 000,043,520 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\BasicDisplay.sys -- (BasicDisplay)
DRV - [2013/08/22 05:10:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\HyperVideo.sys -- (HyperVideo)
DRV - [2013/08/22 05:10:37 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mshidumdf.sys -- (mshidumdf)
DRV - [2013/08/22 05:10:28 | 000,008,704 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\acpitime.sys -- (acpitime)
DRV - [2013/08/22 05:10:21 | 000,009,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\acpipagr.sys -- (acpipagr)
DRV - [2013/08/22 05:10:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\npsvctrig.sys -- (npsvctrig)
DRV - [2013/08/22 05:10:01 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV - [2013/08/22 05:09:59 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\kdnic.sys -- (kdnic)
DRV - [2013/08/22 05:09:37 | 000,023,808 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BthhfHid.sys -- (bthhfhid)
DRV - [2013/08/22 05:09:03 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2013/08/22 05:09:01 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\hidi2c.sys -- (hidi2c)
DRV - [2013/08/22 05:08:06 | 000,013,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV - [2013/08/13 00:25:32 | 000,016,088 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\bcmfn2.sys -- (bcmfn2)
DRV - [2013/08/10 01:39:44 | 000,524,784 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\iaStorAV.sys -- (iaStorAV)
DRV - [2013/07/23 22:18:30 | 000,061,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\iaioi2c.sys -- (iaioi2c)
DRV - [2013/07/23 22:18:30 | 000,022,016 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\iaiogpio.sys -- (GPIO)
DRV - [2013/07/22 14:40:40 | 000,023,432 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2011/04/14 04:47:40 | 000,027,760 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\clwvd.sys -- (clwvd)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2548920966-1427726137-118028679-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/ar-eg/?ocid=iehp
IE - HKU\S-1-5-21-2548920966-1427726137-118028679-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr-FR
IE - HKU\S-1-5-21-2548920966-1427726137-118028679-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D4 FB 21 7D 20 10 D2 01 [binary data]
IE - HKU\S-1-5-21-2548920966-1427726137-118028679-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = 06 F6 E0 96 D3 10 D2 01 [binary data]
IE - HKU\S-1-5-21-2548920966-1427726137-118028679-1001\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = Reg Error: Value error.
IE - HKU\S-1-5-21-2548920966-1427726137-118028679-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2548920966-1427726137-118028679-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKU\S-1-5-21-2548920966-1427726137-118028679-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.countryCode: "TN"
FF - prefs.js..browser.search.region: "TN"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:43.0.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.3.51: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.3.51: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\TorchVLC: C:\Users\HP\AppData\Local\Torch\Plugins\Video\VLC\npvlc.dll (VideoLAN)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 43.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 43.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2016/09/17 12:38:11 | 000,000,000 | ---D | M]

[2016/09/16 14:44:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HP\AppData\Roaming\mozilla\Extensions
[2016/09/16 16:22:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\HP\AppData\Roaming\mozilla\Firefox\Profiles\6nsegef8.default\extensions
[2016/09/16 16:22:57 | 000,023,373 | ---- | M] () (No name found) -- C:\Users\HP\AppData\Roaming\mozilla\firefox\profiles\6nsegef8.default\extensions\firefox-hotfix@mozilla.org.xpi
[2016/09/16 14:30:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\browser\extensions
[2016/09/16 14:30:18 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2016/07/16 00:23:00 | 000,034,072 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll

[color=#E56717]========== Chrome ==========[/color]

CHR - Extension: No name found = C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aabphieoeglldhhckihphcoikecljdnh\12.41.10.16382_0\
CHR - Extension: No name found = C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbogdmdefihhljhfeiklfiedefalcde\3.0.5_0\
CHR - Extension: No name found = C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\
CHR - Extension: No name found = C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\goppbgmjnldonmjemebdmcjfefbgoloh\1.0.0_0\
CHR - Extension: No name found = C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.0_0\
CHR - Extension: No name found = C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
CHR - Extension: No name found = C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5316.725.0.15_0\

O1 HOSTS File: ([2013/08/22 07:13:55 | 000,000,824 | ---- | M]) - C:\Windows\System32\Drivers\etc\hosts
O2 - BHO: (Skype for Business Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\MICROS~1\Office15\GROOVEEX.DLL (Microsoft Corporation)
O4 - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [YouCam Service] C:\Program Files\CyberLink\YouCam\YouCamService.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-2548920966-1427726137-118028679-1001..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe (SFX TEAM)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DSCAutomationHostEnabled = 2
O8 - Extra context menu item: &Envoyer à OneNote - res://C:\Program Files\MICROS~1\Office15\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\Program Files\MICROS~1\Office15\EXCEL.EXE/3000 File not found
O9 - Extra Button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Cliquer pour appeler Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Cliquer pour appeler Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9 - Extra Button: Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains: eset.com ([help] http in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5B33206B-ABB6-4500-8E78-A81C27A77148}: DhcpNameServer = 41.226.4.222 0.0.0.0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BEB72798-326E-49A5-8A4C-6B775E629307}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O27 - HKLM IFEO\OSppSvc.exe: Debugger - C:\Windows\KMS-R@1nHook.exe ()
O27 - HKLM IFEO\SppExtComObj.exe: Debugger - C:\Windows\KMS-R@1nHook.exe ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/08/22 09:16:34 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: hkmsvc - File not found
NetSvcs: wlidsvc - C:\Windows\System32\wlidsvc.dll (Microsoft Corporation)
NetSvcs: lfsvc - C:\Windows\System32\GeofenceMonitorService.dll (Microsoft Corporation)
NetSvcs: DsmSvc - C:\Windows\System32\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs: NcaSvc - C:\Windows\System32\NcaSvc.dll (Microsoft Corporation)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: MsKeyboardFilter - C:\Windows\System32\KeyboardFilterSvc.dll (Microsoft Corporation)


SafeBootMin: Base - Driver Group
SafeBootMin: BasicDisplay.sys - C:\Windows\System32\Drivers\BasicDisplay.sys (Microsoft Corporation)
SafeBootMin: BasicRender.sys - C:\Windows\System32\Drivers\BasicRender.sys (Microsoft Corporation)
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: BrokerInfrastructure - C:\Windows\System32\bisrv.dll (Microsoft Corporation)
SafeBootMin: EFS - C:\Windows\System32\efssvc.dll (Microsoft Corporation)
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: iaioi2c.sys - C:\Windows\System32\Drivers\iaioi2c.sys (Intel Corporation)
SafeBootMin: KeyIso - C:\Windows\System32\keyiso.dll (Microsoft Corporation)
SafeBootMin: LSM - C:\Windows\System32\lsm.dll (Microsoft Corporation)
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: SystemEventsBroker - C:\Windows\System32\SystemEventsBrokerServer.dll (Microsoft Corporation)
SafeBootMin: TBS - Service
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootMin: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet: Base - Driver Group
SafeBootNet: BasicDisplay.sys - C:\Windows\System32\Drivers\BasicDisplay.sys (Microsoft Corporation)
SafeBootNet: BasicRender.sys - C:\Windows\System32\Drivers\BasicRender.sys (Microsoft Corporation)
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: BrokerInfrastructure - C:\Windows\System32\bisrv.dll (Microsoft Corporation)
SafeBootNet: EFS - C:\Windows\System32\efssvc.dll (Microsoft Corporation)
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: KeyIso - C:\Windows\System32\keyiso.dll (Microsoft Corporation)
SafeBootNet: LSM - C:\Windows\System32\lsm.dll (Microsoft Corporation)
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: netprofm - C:\Windows\System32\netprofmsvc.dll (Microsoft Corporation)
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdpencdd.sys - Driver
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: SmartcardSimulator - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: SystemEventsBroker - C:\Windows\System32\SystemEventsBrokerServer.dll (Microsoft Corporation)
SafeBootNet: TBS - Service
SafeBootNet: TDI - Driver Group
SafeBootNet: VaultSvc - C:\Windows\System32\vaultsvc.dll (Microsoft Corporation)
SafeBootNet: VirtualSmartcardReader - Driver
SafeBootNet: vmms - Service
SafeBootNet: Wcmsvc - C:\Windows\System32\wcmsvc.dll (Microsoft Corporation)
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootNet: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {66C64F22-FC60-4E6C-A6B5-F0D580E680CE} - C:\Windows\System32\ie4uinit.exe -EnableTLS
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {7D715857-A67C-4C2F-A929-038448584D63} - C:\Windows\System32\ie4uinit.exe -DisableSSL3
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files\Google\Chrome\Application\53.0.2785.116\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {DB3BE7C6-0F16-3E06-8C14-1595ECE2A4E1} - .NET Framework
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

[color=#E56717]========== Files/Folders - Created Within 60 Days ==========[/color]

[2016/09/28 20:37:39 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\HP\Desktop\OTL.exe
[2016/09/22 08:53:10 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EPSON
[2016/09/22 08:53:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
[2016/09/22 08:51:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Printers
[2016/09/22 08:47:20 | 000,080,198 | ---- | C] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\E_SL2389.DLL
[2016/09/22 08:47:13 | 000,000,000 | ---D | C] -- C:\Program Files\EPSON
[2016/09/20 14:48:52 | 000,000,000 | ---D | C] -- C:\Users\HP\Documents\Modèles Office personnalisés
[2016/09/18 18:21:12 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Local\Diagnostics
[2016/09/17 21:10:19 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2016/09/17 13:21:53 | 003,292,968 | ---- | C] (Qualcomm Atheros Communications, Inc.) -- C:\Windows\System32\drivers\athwb.sys
[2016/09/17 13:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2016/09/17 13:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2016/09/17 13:19:56 | 000,385,536 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\atikmpag.sys
[2016/09/17 13:19:51 | 024,549,888 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\atikmdag.sys
[2016/09/17 13:19:25 | 000,275,848 | ---- | C] (Advanced Micro Devices) -- C:\Windows\System32\drivers\amdacpksd.sys
[2016/09/17 13:19:24 | 000,294,912 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\ATIODE.exe
[2016/09/17 13:19:24 | 000,236,544 | ---- | C] (AMD) -- C:\Windows\System32\atiesrxx.exe
[2016/09/17 13:19:24 | 000,045,056 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\ATIODCLI.exe
[2016/09/17 13:19:23 | 000,422,912 | ---- | C] (AMD) -- C:\Windows\System32\atieclxx.exe
[2016/09/17 13:19:21 | 000,385,536 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atiapfxx.exe
[2016/09/17 13:19:20 | 000,117,760 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\mantle32.dll
[2016/09/17 13:19:20 | 000,092,160 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\mantleaxl32.dll
[2016/09/17 13:19:19 | 000,139,208 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiuxpag.dll
[2016/09/17 13:19:19 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\detoured.dll
[2016/09/17 13:19:18 | 009,221,224 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiumdva.dll
[2016/09/17 13:19:03 | 007,162,760 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiumdag.dll
[2016/09/17 13:18:57 | 000,123,776 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiu9pag.dll
[2016/09/17 13:18:56 | 000,231,424 | ---- | C] (AMD) -- C:\Windows\System32\atitmmxx.dll
[2016/09/17 13:18:56 | 000,101,376 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atisamu32.dll
[2016/09/17 13:18:55 | 026,624,000 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atioglxx.dll
[2016/09/17 13:18:34 | 000,159,232 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atigktxx.dll
[2016/09/17 13:18:34 | 000,093,184 | ---- | C] (AMD) -- C:\Windows\System32\atimuixx.dll
[2016/09/17 13:18:34 | 000,092,328 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atimpc32.dll
[2016/09/17 13:18:34 | 000,091,136 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atiglpxx.dll
[2016/09/17 13:18:18 | 009,020,880 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\atidxx32.dll
[2016/09/17 13:18:01 | 000,442,368 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atidemgy.dll
[2016/09/17 13:17:59 | 001,252,608 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\aticfx32.dll
[2016/09/17 13:17:54 | 000,052,224 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticalrt.dll
[2016/09/17 13:17:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Temp
[2016/09/17 13:17:35 | 014,302,720 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticaldd.dll
[2016/09/17 13:17:34 | 000,000,000 | ---D | C] -- C:\Program Files\InstallShield Installation Information
[2016/09/17 13:17:34 | 000,000,000 | ---D | C] -- C:\ProgramData\install_clap
[2016/09/17 13:17:30 | 000,976,384 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\atiadlxx.dll
[2016/09/17 13:17:30 | 000,049,152 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\aticalcl.dll
[2016/09/17 13:17:26 | 000,043,520 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\drivers\ati2erec.dll
[2016/09/17 13:17:16 | 007,075,840 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdvlk32.dll
[2016/09/17 13:17:14 | 000,092,328 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdpcom32.dll
[2016/09/17 13:17:14 | 000,038,400 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdmmcl.dll
[2016/09/17 13:17:09 | 006,938,624 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdmantle32.dll
[2016/09/17 13:17:05 | 000,609,792 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\amdlvr32.dll
[2016/09/17 13:17:04 | 000,125,288 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\amdhcp32.dll
[2016/09/17 13:17:03 | 000,124,776 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdave32.dll
[2016/09/17 13:16:42 | 000,670,208 | ---- | C] (AMD) -- C:\Windows\System32\coinst_16.30.dll
[2016/09/17 13:16:41 | 001,820,160 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\System32\amfrt32.dll
[2016/09/17 13:16:39 | 021,623,808 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\System32\amdocl12cl.dll
[2016/09/17 13:16:30 | 000,050,176 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\System32\amdmcl32.dll
[2016/09/17 13:15:17 | 000,000,000 | ---D | C] -- C:\Program Files\HP
[2016/09/17 13:15:11 | 000,029,792 | ---- | C] (HP) -- C:\Windows\System32\drivers\WirelessButtonDriver86.sys
[2016/09/17 13:15:08 | 000,023,432 | ---- | C] (Hewlett-Packard Company) -- C:\Windows\System32\drivers\HpqKbFiltr.sys
[2016/09/17 12:59:46 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2016/09/17 12:38:11 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2016/09/17 12:26:51 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
[2016/09/17 12:25:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2016/09/17 12:24:15 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2016/09/17 12:24:15 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server
[2016/09/17 12:22:48 | 000,052,840 | ---- | C] (Synaptics Incorporated) -- C:\Windows\System32\drivers\Smb_driver_Intel_Aux.sys
[2016/09/17 12:22:48 | 000,050,280 | ---- | C] (Synaptics Incorporated) -- C:\Windows\System32\drivers\SynRMIHID_Aux.sys
[2016/09/17 12:22:48 | 000,049,256 | ---- | C] (Synaptics Incorporated) -- C:\Windows\System32\drivers\Smb_driver_AMDASF_Aux.sys
[2016/09/17 12:22:45 | 001,629,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WdfCoInstaller01011.dll
[2016/09/17 12:22:20 | 000,236,136 | ---- | C] (Synaptics Incorporated) -- C:\Windows\System32\SynTPCo45.dll
[2016/09/17 12:19:37 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services
[2016/09/17 12:19:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2016/09/17 12:19:03 | 000,201,872 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll
[2016/09/17 12:18:50 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2016/09/17 12:18:50 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2016/09/17 12:18:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
[2016/09/17 12:18:49 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2016/09/17 12:18:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2016/09/17 12:18:38 | 000,000,000 | ---D | C] -- C:\Program Files\Real
[2016/09/17 12:18:24 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2016/09/17 12:18:07 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2016/09/17 12:17:58 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SuperCopier2
[2016/09/17 12:17:58 | 000,000,000 | ---D | C] -- C:\Program Files\SuperCopier2
[2016/09/17 12:17:45 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\Real
[2016/09/17 12:17:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\SRSLabs
[2016/09/17 12:17:41 | 000,000,000 | ---D | C] -- C:\Windows\System32\RTCOM
[2016/09/17 12:17:41 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2016/09/17 12:16:50 | 072,520,720 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RCoRes.dat
[2016/09/17 12:16:49 | 002,830,592 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RTSndMgr.cpl
[2016/09/17 12:16:35 | 000,357,160 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSXT.dll
[2016/09/17 12:16:35 | 000,150,560 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSWOW.dll
[2016/09/17 12:16:34 | 001,074,056 | ---- | C] (Synopsys, Inc.) -- C:\Windows\System32\SRRPTR.dll
[2016/09/17 12:16:34 | 000,401,056 | ---- | C] (Synopsys, Inc.) -- C:\Windows\System32\SRAPO.dll
[2016/09/17 12:16:34 | 000,341,152 | ---- | C] (Synopsys, Inc.) -- C:\Windows\System32\SRCOM.dll
[2016/09/17 12:16:33 | 002,385,592 | ---- | C] (DTS, Inc.) -- C:\Windows\System32\sltech32.dll
[2016/09/17 12:16:33 | 002,105,640 | ---- | C] (DTS, Inc.) -- C:\Windows\System32\slcnt32.dll
[2016/09/17 12:16:33 | 000,232,760 | ---- | C] (TODO: <Company name>) -- C:\Windows\System32\slprp32.dll
[2016/09/17 12:16:32 | 000,957,056 | ---- | C] (DTS, Inc.) -- C:\Windows\System32\sl3apo32.dll
[2016/09/17 12:16:31 | 002,904,072 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkPgExt.dll
[2016/09/17 12:16:29 | 002,020,872 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoInstII.dll
[2016/09/17 12:16:29 | 000,022,160 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoLDR.dll
[2016/09/17 12:16:28 | 002,433,592 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkApoApi.dll
[2016/09/17 12:16:27 | 000,371,816 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEP32A.dll
[2016/09/17 12:16:27 | 000,181,232 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEED32A.dll
[2016/09/17 12:16:27 | 000,088,280 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEL32A.dll
[2016/09/17 12:16:27 | 000,074,384 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEG32A.dll
[2016/09/17 12:16:25 | 002,775,200 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RltkAPO.dll
[2016/09/17 12:16:25 | 000,307,240 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DHT32.dll
[2016/09/17 12:16:25 | 000,307,240 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DAA32.dll
[2016/09/17 12:15:30 | 001,519,272 | ---- | C] (Conexant Systems Inc.) -- C:\Windows\System32\CX32APO.dll
[2016/09/17 12:15:30 | 001,451,616 | ---- | C] (Conexant Systems Inc.) -- C:\Windows\System32\CX32Proxy.dll
[2016/09/17 12:15:30 | 000,370,032 | ---- | C] (Conexant Systems, Inc.) -- C:\Windows\System32\Caf32APO2.dll
[2016/09/17 12:15:30 | 000,101,328 | ---- | C] (Real Sound Lab SIA) -- C:\Windows\System32\CONEQMSAPOGUILibrary.dll
[2016/09/17 12:15:30 | 000,098,016 | ---- | C] (Conexant Systems, Inc.) -- C:\Windows\System32\Caf32api.dll
[2016/09/17 12:15:27 | 000,105,656 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTARen.dll
[2016/09/17 12:15:26 | 000,532,896 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTACap.dll
[2016/09/17 12:14:42 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\PC Faster
[2016/09/17 12:14:02 | 000,072,904 | ---- | C] (Advanced Micro Devices) -- C:\Windows\System32\drivers\amd_sata.sys
[2016/09/17 12:14:02 | 000,020,680 | ---- | C] (Advanced Micro Devices) -- C:\Windows\System32\drivers\amd_xata.sys
[2016/09/17 12:13:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Baidu
[2016/09/17 12:13:50 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2016/09/17 12:13:50 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2016/09/17 12:13:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu Browser
[2016/09/17 12:13:31 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Baidu
[2016/09/17 12:13:31 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\Baidu
[2016/09/17 12:13:29 | 000,000,000 | ---D | C] -- C:\Program Files\baidu
[2016/09/17 12:13:04 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\vlc
[2016/09/17 12:11:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2016/09/17 12:11:07 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2016/09/17 12:09:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2016/09/17 12:07:11 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\Ashampoo
[2016/09/17 12:06:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp
[2016/09/17 12:06:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
[2016/09/17 12:06:14 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\Todae
[2016/09/17 12:06:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PX Storage Engine
[2016/09/17 12:05:45 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\Winamp
[2016/09/17 12:05:45 | 000,000,000 | ---D | C] -- C:\Program Files\Winamp
[2016/09/17 12:05:34 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2016/09/17 12:05:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2016/09/17 12:05:33 | 000,791,296 | ---- | C] (Realtek ) -- C:\Windows\System32\drivers\Rt630x86.sys
[2016/09/17 12:05:31 | 000,085,616 | ---- | C] (Realtek Semiconductor Corporation) -- C:\Windows\System32\RtNicProp32.dll
[2016/09/17 12:05:28 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2016/09/17 12:05:23 | 000,015,080 | ---- | C] (Advanced Micro Devices, INC.) -- C:\Windows\System32\drivers\AmdAS4.sys
[2016/09/17 12:04:44 | 000,000,000 | ---D | C] -- C:\ProgramData\page
[2016/09/17 12:04:44 | 000,000,000 | ---D | C] -- C:\Program Files\Ashampoo
[2016/09/17 12:04:22 | 000,513,040 | ---- | C] (Qualcomm Atheros) -- C:\Windows\System32\drivers\btfilter.sys
[2016/09/17 12:02:54 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Local\Microsoft Help
[2016/09/17 12:02:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2016/09/17 11:52:14 | 000,000,000 | R--D | C] -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2016/09/17 11:52:14 | 000,000,000 | R--D | C] -- C:\Users\HP\Searches
[2016/09/17 11:52:14 | 000,000,000 | R--D | C] -- C:\Users\HP\Contacts
[2016/09/17 11:52:14 | 000,000,000 | R--D | C] -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2016/09/17 11:52:14 | 000,000,000 | -H-D | C] -- C:\Users\HP\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2016/09/17 11:52:07 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Local\VirtualStore
[2016/09/17 11:52:01 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Local\Packages
[2016/09/17 11:52:01 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\Adobe
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\Voisinage réseau
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\Voisinage d'impression
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\AppData\Local\Temporary Internet Files
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\SendTo
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\Recent
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\Modèles
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\Documents\Mes vidéos
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\Documents\Mes images
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\Mes documents
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\Menu Démarrer
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\Documents\Ma musique
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\Local Settings
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\AppData\Local\Historique
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\Cookies
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\Application Data
[2016/09/17 11:51:54 | 000,000,000 | -HSD | C] -- C:\Users\HP\AppData\Local\Application Data
[2016/09/17 11:51:53 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Local\Temp
[2016/09/17 11:51:53 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Local\Microsoft
[2016/09/17 11:51:52 | 000,000,000 | --SD | C] -- C:\Users\HP\AppData\Roaming\Microsoft
[2016/09/17 11:51:52 | 000,000,000 | R--D | C] -- C:\Users\HP\Videos
[2016/09/17 11:51:52 | 000,000,000 | R--D | C] -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2016/09/17 11:51:52 | 000,000,000 | R--D | C] -- C:\Users\HP\Saved Games
[2016/09/17 11:51:52 | 000,000,000 | R--D | C] -- C:\Users\HP\Pictures
[2016/09/17 11:51:52 | 000,000,000 | R--D | C] -- C:\Users\HP\Music
[2016/09/17 11:51:52 | 000,000,000 | R--D | C] -- C:\Users\HP\Links
[2016/09/17 11:51:52 | 000,000,000 | R--D | C] -- C:\Users\HP\Favorites
[2016/09/17 11:51:52 | 000,000,000 | R--D | C] -- C:\Users\HP\Downloads
[2016/09/17 11:51:52 | 000,000,000 | R--D | C] -- C:\Users\HP\Documents
[2016/09/17 11:51:52 | 000,000,000 | R--D | C] -- C:\Users\HP\Desktop
[2016/09/17 11:51:52 | 000,000,000 | R--D | C] -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2016/09/17 11:51:52 | 000,000,000 | R--D | C] -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2016/09/17 11:51:52 | 000,000,000 | -H-D | C] -- C:\Users\HP\AppData
[2016/09/17 11:51:52 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2016/09/17 11:51:06 | 000,000,000 | ---D | C] -- C:\Windows\CSC
[2016/09/17 11:49:09 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2016/09/17 11:21:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Modèles
[2016/09/17 11:21:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Mes vidéos
[2016/09/17 11:21:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Mes images
[2016/09/17 11:21:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Menu Démarrer
[2016/09/17 11:21:04 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Ma musique
[2016/09/17 11:21:04 | 000,000,000 | -HSD | C] -- C:\Program Files\Fichiers communs
[2016/09/17 11:21:04 | 000,000,000 | -HSD | C] -- C:\ProgramData\Bureau
[2016/09/17 11:12:28 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2016/09/17 11:11:19 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2016/09/16 22:19:44 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\WinRAR
[2016/09/16 19:28:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2016/09/16 19:28:51 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET
[2016/09/16 19:28:40 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2016/09/16 18:46:58 | 000,406,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2016/09/16 17:52:27 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2016/09/16 16:12:02 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Local\MSfree Inc
[2016/09/16 15:19:35 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\CyberLink
[2016/09/16 15:19:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Synaptics
[2016/09/16 15:19:22 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\Synaptics
[2016/09/16 15:03:08 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\AVG
[2016/09/16 14:59:30 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\TuneUp Software
[2016/09/16 14:50:22 | 000,000,000 | -H-D | C] -- C:\$AVG
[2016/09/16 14:48:55 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Local\MFAData
[2016/09/16 14:48:55 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2016/09/16 14:47:53 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2016/09/16 14:47:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Avg
[2016/09/16 14:47:53 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2016/09/16 14:46:26 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Local\AvgSetupLog
[2016/09/16 14:46:26 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Local\Avg
[2016/09/16 14:41:44 | 000,000,000 | ---D | C] -- C:\ProgramData\TorchCrashHandler
[2016/09/16 14:41:30 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
[2016/09/16 14:36:56 | 000,000,000 | ---D | C] -- C:\Users\HP\Documents\Youcam
[2016/09/16 14:36:55 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Local\CyberLink
[2016/09/16 14:36:19 | 000,027,760 | ---- | C] (CyberLink Corporation) -- C:\Windows\System32\drivers\clwvd.sys
[2016/09/16 14:36:15 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam 5
[2016/09/16 14:32:04 | 000,000,000 | ---D | C] -- C:\Program Files\CyberLink
[2016/09/16 14:31:44 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Roaming\Mozilla
[2016/09/16 14:31:44 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Local\Mozilla
[2016/09/16 14:30:33 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2016/09/16 14:28:22 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2016/09/16 14:28:16 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Local\Torch
[2016/09/16 14:28:02 | 000,000,000 | ---D | C] -- C:\Users\HP\AppData\Local\Google

[color=#E56717]========== Files - Modified Within 60 Days ==========[/color]

[2016/09/28 20:41:00 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2016/09/28 20:37:42 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\HP\Desktop\OTL.exe
[2016/09/28 18:06:18 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2016/09/28 18:05:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2016/09/26 11:54:45 | 000,812,350 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2016/09/26 11:54:45 | 000,722,476 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2016/09/26 11:54:45 | 000,159,412 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2016/09/26 11:54:45 | 000,135,592 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2016/09/26 11:45:41 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2016/09/26 11:45:35 | 2562,179,072 | -HS- | M] () -- C:\hiberfil.sys
[2016/09/22 08:53:15 | 000,001,996 | ---- | M] () -- C:\Users\HP\Desktop\Guide de résolution des bourrages papier EPLN3000.lnk
[2016/09/22 08:53:10 | 000,002,003 | ---- | M] () -- C:\Users\HP\Desktop\Guide de référence EPLN3000.lnk
[2016/09/22 08:52:34 | 000,012,921 | ---- | M] () -- C:\Windows\EPSTPLOG.BAK
[2016/09/22 08:47:01 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2016/09/22 08:47:01 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2016/09/22 08:45:46 | 000,177,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\typelib.dll
[2016/09/22 08:45:46 | 000,169,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ole2disp.dll
[2016/09/22 08:45:46 | 000,153,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ole2nls.dll
[2016/09/22 08:45:46 | 000,042,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ole2.dll
[2016/09/22 08:45:46 | 000,027,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\compobj.dll
[2016/09/22 08:45:46 | 000,004,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\storage.dll
[2016/09/22 08:45:42 | 000,127,213 | ---- | M] () -- C:\Windows\System32\ega.cpi
[2016/09/22 08:45:42 | 000,024,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\OLESVR.DLL
[2016/09/22 08:45:41 | 000,047,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\USER.EXE
[2016/09/22 08:45:41 | 000,046,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pmspl.dll
[2016/09/22 08:45:41 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\GDI.EXE
[2016/09/22 08:45:41 | 000,021,232 | ---- | M] () -- C:\Windows\System32\graphics.pro
[2016/09/22 08:45:41 | 000,013,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\TOOLHELP.DLL
[2016/09/22 08:45:41 | 000,009,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\lzexpand.dll
[2016/09/22 08:45:41 | 000,009,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ver.dll
[2016/09/22 08:45:41 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win.com
[2016/09/22 08:45:40 | 000,536,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntvdm.exe
[2016/09/22 08:45:40 | 000,256,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\winhelp.exe
[2016/09/22 08:45:40 | 000,221,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\lanman.drv
[2016/09/22 08:45:40 | 000,062,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\graftabl.com
[2016/09/22 08:45:40 | 000,039,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DDEML.DLL
[2016/09/22 08:45:40 | 000,032,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\COMMDLG.DLL
[2016/09/22 08:45:40 | 000,028,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\DRWATSON.EXE
[2016/09/22 08:45:40 | 000,018,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sysedit.exe
[2016/09/22 08:45:40 | 000,018,832 | ---- | M] () -- C:\Windows\System32\v7vga.rom
[2016/09/22 08:45:40 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ntvdmd.dll
[2016/09/22 08:45:40 | 000,009,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WIFEMAN.DLL
[2016/09/22 08:45:40 | 000,005,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SHELL.DLL
[2016/09/22 08:45:39 | 000,108,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netapi.dll
[2016/09/22 08:45:39 | 000,027,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ctl3dv2.dll
[2016/09/22 08:45:39 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vdmredir.dll
[2016/09/22 08:45:39 | 000,005,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WINNLS.DLL
[2016/09/22 08:45:37 | 000,092,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\krnl386.exe
[2016/09/22 08:45:37 | 000,068,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MMSYSTEM.DLL
[2016/09/22 08:45:37 | 000,028,420 | ---- | M] () -- C:\Windows\System32\bios1.rom
[2016/09/22 08:45:36 | 000,082,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\olecli.dll
[2016/09/22 08:45:36 | 000,012,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WFWNET.DRV
[2016/09/22 08:45:36 | 000,010,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\COMM.drv
[2016/09/22 08:45:36 | 000,008,191 | ---- | M] () -- C:\Windows\System32\bios4.rom
[2016/09/22 08:45:31 | 000,032,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System\COMMDLG.DLL
[2016/09/22 08:45:31 | 000,024,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System\OLESVR.DLL
[2016/09/22 08:45:31 | 000,009,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System\lzexpand.dll
[2016/09/22 08:45:31 | 000,009,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System\ver.dll
[2016/09/22 08:45:31 | 000,005,532 | ---- | M] (Microsoft Corporation) -- C:\Windows\System\stdole.tlb
[2016/09/22 08:45:31 | 000,005,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System\SHELL.DLL
[2016/09/22 08:45:30 | 000,082,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\System\olecli.dll
[2016/09/22 08:45:30 | 000,068,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System\MMSYSTEM.DLL
[2016/09/22 08:45:30 | 000,012,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\System\WFWNET.DRV
[2016/09/22 08:43:08 | 000,000,025 | ---- | M] () -- C:\Windows\CDEEPLN3000.ini
[2016/09/20 15:04:34 | 003,535,176 | ---- | M] () -- C:\Users\HP\Desktop\modele-cv-photo-centree.rtf
[2016/09/18 18:05:39 | 000,002,280 | ---- | M] () -- C:\Users\HP\Desktop\Youtube.lnk
[2016/09/18 18:05:39 | 000,002,260 | ---- | M] () -- C:\Users\HP\Desktop\Free Music.lnk
[2016/09/18 18:05:39 | 000,002,260 | ---- | M] () -- C:\Users\HP\Desktop\Free Games.lnk
[2016/09/18 18:05:38 | 000,002,284 | ---- | M] () -- C:\Users\HP\Desktop\Facebook.lnk
[2016/09/17 13:21:22 | 000,000,000 | ---- | M] () -- C:\Windows\System32\spu_storage.bin
[2016/09/17 13:00:09 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01011.Wdf
[2016/09/17 12:19:39 | 000,001,254 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2016/09/17 12:19:03 | 000,201,872 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll
[2016/09/17 12:18:50 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2016/09/17 12:18:50 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2016/09/17 12:18:49 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2016/09/17 12:15:12 | 000,002,013 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2016/09/17 12:13:40 | 000,002,143 | ---- | M] () -- C:\Users\Public\Desktop\Google.lnk
[2016/09/17 12:13:39 | 000,002,159 | ---- | M] () -- C:\Users\Public\Desktop\Facebook.lnk
[2016/09/17 12:13:39 | 000,002,111 | ---- | M] () -- C:\Users\Public\Desktop\Baidu Browser.lnk
[2016/09/17 12:12:46 | 000,001,044 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2016/09/17 12:06:35 | 000,001,464 | ---- | M] () -- C:\Users\HP\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2016/09/17 12:06:24 | 000,000,953 | ---- | M] () -- C:\Users\Public\Desktop\Winamp.lnk
[2016/09/17 12:06:20 | 000,001,185 | ---- | M] () -- C:\Users\HP\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 9.lnk
[2016/09/17 12:06:20 | 000,001,161 | ---- | M] () -- C:\Users\Public\Desktop\Ashampoo Burning Studio 9.lnk
[2016/09/17 12:00:42 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2016/09/17 11:51:04 | 000,004,608 | ---- | M] () -- C:\Windows\KMS-R@1nHook.exe
[2016/09/17 11:51:04 | 000,003,584 | ---- | M] () -- C:\Windows\KMS-R@1nHook.dll
[2016/09/17 11:18:50 | 000,062,461 | ---- | M] () -- C:\Windows\System32\license.rtf
[2016/09/16 18:31:51 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_LocationProvider_01_11_00.Wdf
[2016/09/16 18:12:42 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
[2016/09/16 15:20:35 | 000,002,247 | ---- | M] () -- C:\Users\HP\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2016/09/16 15:18:31 | 000,473,080 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2016/09/16 14:42:09 | 000,001,375 | ---- | M] () -- C:\Users\HP\Desktop\Torch.lnk
[2016/09/16 14:41:40 | 000,001,179 | ---- | M] () -- C:\Users\HP\Application Data\Microsoft\Internet Explorer\Quick Launch\Torch.lnk
[2016/09/16 14:36:15 | 000,002,103 | ---- | M] () -- C:\Users\Public\Desktop\CyberLink YouCam 5.lnk
[2016/09/16 14:34:14 | 000,002,151 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2016/09/16 14:30:35 | 000,001,121 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2016/08/08 08:22:14 | 001,074,056 | ---- | M] (Synopsys, Inc.) -- C:\Windows\System32\SRRPTR.dll
[2016/08/08 08:22:14 | 000,401,056 | ---- | M] (Synopsys, Inc.) -- C:\Windows\System32\SRAPO.dll
[2016/08/08 08:22:14 | 000,357,160 | ---- | M] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSXT.dll
[2016/08/08 08:22:14 | 000,341,152 | ---- | M] (Synopsys, Inc.) -- C:\Windows\System32\SRCOM.dll
[2016/08/08 08:22:14 | 000,150,560 | ---- | M] (SRS Labs, Inc.) -- C:\Windows\System32\SRSWOW.dll
[2016/08/08 08:22:12 | 002,385,592 | ---- | M] (DTS, Inc.) -- C:\Windows\System32\sltech32.dll
[2016/08/08 08:22:12 | 002,105,640 | ---- | M] (DTS, Inc.) -- C:\Windows\System32\slcnt32.dll
[2016/08/08 08:22:12 | 000,957,056 | ---- | M] (DTS, Inc.) -- C:\Windows\System32\sl3apo32.dll
[2016/08/08 08:22:12 | 000,232,760 | ---- | M] (TODO: <Company name>) -- C:\Windows\System32\slprp32.dll
[2016/08/08 08:22:10 | 002,904,072 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkPgExt.dll
[2016/08/08 08:22:10 | 002,830,592 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RTSndMgr.cpl
[2016/08/08 08:22:08 | 002,433,592 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkApoApi.dll
[2016/08/08 08:22:08 | 002,020,872 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoInstII.dll
[2016/08/08 08:22:08 | 000,371,816 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEP32A.dll
[2016/08/08 08:22:08 | 000,181,232 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEED32A.dll
[2016/08/08 08:22:08 | 000,088,280 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEL32A.dll
[2016/08/08 08:22:08 | 000,074,384 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEG32A.dll
[2016/08/08 08:22:08 | 000,022,160 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoLDR.dll
[2016/08/08 08:22:06 | 072,520,720 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RCoRes.dat
[2016/08/08 08:22:06 | 006,766,090 | ---- | M] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2016/08/08 08:22:06 | 002,775,200 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RltkAPO.dll
[2016/08/08 08:22:06 | 000,307,240 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DHT32.dll
[2016/08/08 08:22:06 | 000,307,240 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DAA32.dll
[2016/08/08 08:21:48 | 001,519,272 | ---- | M] (Conexant Systems Inc.) -- C:\Windows\System32\CX32APO.dll
[2016/08/08 08:21:48 | 001,451,616 | ---- | M] (Conexant Systems Inc.) -- C:\Windows\System32\CX32Proxy.dll
[2016/08/08 08:21:48 | 000,370,032 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\Caf32APO2.dll
[2016/08/08 08:21:48 | 000,101,328 | ---- | M] (Real Sound Lab SIA) -- C:\Windows\System32\CONEQMSAPOGUILibrary.dll
[2016/08/08 08:21:48 | 000,098,016 | ---- | M] (Conexant Systems, Inc.) -- C:\Windows\System32\Caf32api.dll
[2016/08/08 08:21:48 | 000,005,604 | ---- | M] () -- C:\Windows\System32\cxapo.lncs
[2016/08/08 08:21:48 | 000,000,736 | ---- | M] () -- C:\Windows\System32\cxapo.prop
[2016/08/08 08:21:46 | 000,532,896 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTACap.dll
[2016/08/08 08:21:46 | 000,105,656 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTARen.dll

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2016/09/22 08:53:15 | 000,001,996 | ---- | C] () -- C:\Users\HP\Desktop\Guide de résolution des bourrages papier EPLN3000.lnk
[2016/09/22 08:53:10 | 000,002,003 | ---- | C] () -- C:\Users\HP\Desktop\Guide de référence EPLN3000.lnk
[2016/09/22 08:47:13 | 000,000,182 | ---- | C] () -- C:\Windows\System32\EBPPORT.DAT
[2016/09/22 08:47:08 | 000,012,921 | ---- | C] () -- C:\Windows\EPSTPLOG.BAK
[2016/09/22 08:47:01 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2016/09/22 08:47:01 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2016/09/22 08:43:08 | 000,000,025 | ---- | C] () -- C:\Windows\CDEEPLN3000.ini
[2016/09/20 14:49:08 | 003,535,176 | ---- | C] () -- C:\Users\HP\Desktop\modele-cv-photo-centree.rtf
[2016/09/17 13:21:22 | 000,000,000 | ---- | C] () -- C:\Windows\System32\spu_storage.bin
[2016/09/17 13:19:25 | 000,149,008 | ---- | C] () -- C:\Windows\System32\samu_krnl_ci.sbin
[2016/09/17 13:19:25 | 000,138,832 | ---- | C] () -- C:\Windows\System32\samu_krnl_isv_ci.sbin
[2016/09/17 13:19:25 | 000,112,336 | ---- | C] () -- C:\Windows\System32\kapp_si.sbin
[2016/09/17 13:19:24 | 000,241,664 | ---- | C] () -- C:\Windows\System32\dgtrayicon.exe
[2016/09/17 13:19:24 | 000,117,808 | ---- | C] () -- C:\Windows\System32\kapp_ci.sbin
[2016/09/17 13:19:24 | 000,016,827 | ---- | C] () -- C:\Windows\System32\AMDKernelEvents.man
[2016/09/17 13:19:21 | 000,192,000 | ---- | C] () -- C:\Windows\System32\atieah32.exe
[2016/09/17 13:19:19 | 000,223,744 | ---- | C] () -- C:\Windows\System32\GameManager32.dll
[2016/09/17 13:19:19 | 000,217,088 | ---- | C] () -- C:\Windows\System32\hsa-thunk.dll
[2016/09/17 13:17:14 | 000,378,144 | ---- | C] () -- C:\Windows\System32\amdmiracast.dll
[2016/09/17 13:17:04 | 000,204,800 | ---- | C] () -- C:\Windows\System32\amdgfxinfo32.dll
[2016/09/17 13:17:04 | 000,164,352 | ---- | C] () -- C:\Windows\System32\amdhdl32.dll
[2016/09/17 13:17:03 | 000,890,373 | ---- | C] () -- C:\Windows\System32\amdicdxx.dat
[2016/09/17 13:17:03 | 000,737,410 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2016/09/17 13:17:03 | 000,204,952 | ---- | C] () -- C:\Windows\System32\ativvsvl.dat
[2016/09/17 13:17:02 | 000,322,996 | ---- | C] () -- C:\Windows\System32\ativvaxy_vi.dat
[2016/09/17 13:17:02 | 000,322,736 | ---- | C] () -- C:\Windows\System32\ativvaxy_vi_nd.dat
[2016/09/17 13:17:02 | 000,270,912 | ---- | C] () -- C:\Windows\System32\ativvaxy_stn_nd.dat
[2016/09/17 13:17:02 | 000,260,720 | ---- | C] () -- C:\Windows\System32\ativvaxy_FJ_nd.dat
[2016/09/17 13:17:02 | 000,157,144 | ---- | C] () -- C:\Windows\System32\ativvsva.dat
[2016/09/17 13:17:01 | 000,368,672 | ---- | C] () -- C:\Windows\System32\ativvaxy_el_nd.dat
[2016/09/17 13:17:01 | 000,266,816 | ---- | C] () -- C:\Windows\System32\ativvaxy_cz_nd.dat
[2016/09/17 13:17:01 | 000,260,980 | ---- | C] () -- C:\Windows\System32\ativvaxy_FJ.dat
[2016/09/17 13:17:01 | 000,234,292 | ---- | C] () -- C:\Windows\System32\ativvaxy_cik.dat
[2016/09/17 13:17:01 | 000,234,032 | ---- | C] () -- C:\Windows\System32\ativvaxy_cik_nd.dat
[2016/09/17 13:17:00 | 003,471,376 | ---- | C] () -- C:\Windows\System32\atiumdva.cap
[2016/09/17 13:17:00 | 000,177,280 | ---- | C] () -- C:\Windows\System32\ativce03.dat
[2016/09/17 13:17:00 | 000,175,584 | ---- | C] () -- C:\Windows\System32\amde31a.dat
[2016/09/17 13:17:00 | 000,166,624 | ---- | C] () -- C:\Windows\System32\amde34b.dat
[2016/09/17 13:17:00 | 000,166,624 | ---- | C] () -- C:\Windows\System32\amde34a.dat
[2016/09/17 13:17:00 | 000,100,816 | ---- | C] () -- C:\Windows\System32\ativce02.dat
[2016/09/17 13:16:50 | 000,731,440 | ---- | C] () -- C:\Windows\System32\atiapfxx.blb
[2016/09/17 13:16:11 | 000,000,144 | ---- | C] () -- C:\Windows\System32\amd-vulkan32.json
[2016/09/17 13:00:09 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01011.Wdf
[2016/09/17 12:19:39 | 000,001,254 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2016/09/17 12:18:00 | 000,001,868 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DTS Audio Control.lnk
[2016/09/17 12:16:55 | 000,005,604 | ---- | C] () -- C:\Windows\System32\cxapo.lncs
[2016/09/17 12:16:55 | 000,000,736 | ---- | C] () -- C:\Windows\System32\cxapo.prop
[2016/09/17 12:16:54 | 006,766,090 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2016/09/17 12:15:12 | 000,002,457 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2016/09/17 12:15:12 | 000,002,013 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2016/09/17 12:13:39 | 000,002,159 | ---- | C] () -- C:\Users\Public\Desktop\Facebook.lnk
[2016/09/17 12:13:39 | 000,002,143 | ---- | C] () -- C:\Users\Public\Desktop\Google.lnk
[2016/09/17 12:13:39 | 000,002,111 | ---- | C] () -- C:\Users\Public\Desktop\Baidu Browser.lnk
[2016/09/17 12:11:20 | 000,001,044 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2016/09/17 12:06:35 | 000,001,464 | ---- | C] () -- C:\Users\HP\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2016/09/17 12:06:24 | 000,000,953 | ---- | C] () -- C:\Users\Public\Desktop\Winamp.lnk
[2016/09/17 12:06:20 | 000,001,185 | ---- | C] () -- C:\Users\HP\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 9.lnk
[2016/09/17 12:06:20 | 000,001,161 | ---- | C] () -- C:\Users\Public\Desktop\Ashampoo Burning Studio 9.lnk
[2016/09/17 12:00:42 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2016/09/17 11:52:01 | 000,001,470 | ---- | C] () -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2016/09/17 11:51:53 | 000,001,259 | ---- | C] () -- C:\Users\HP\Application Data\Microsoft\Internet Explorer\Quick Launch\Control Panel.lnk
[2016/09/17 11:51:53 | 000,001,158 | ---- | C] () -- C:\Users\HP\Application Data\Microsoft\Internet Explorer\Quick Launch\Server Manager.lnk
[2016/09/17 11:51:53 | 000,000,369 | ---- | C] () -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
[2016/09/17 11:51:53 | 000,000,369 | ---- | C] () -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
[2016/09/17 11:51:53 | 000,000,352 | ---- | C] () -- C:\Users\HP\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2016/09/17 11:51:53 | 000,000,334 | ---- | C] () -- C:\Users\HP\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2016/09/17 11:51:04 | 000,004,608 | ---- | C] () -- C:\Windows\KMS-R@1nHook.exe
[2016/09/17 11:51:04 | 000,003,584 | ---- | C] () -- C:\Windows\KMS-R@1nHook.dll
[2016/09/17 11:19:39 | 2562,179,072 | -HS- | C] () -- C:\hiberfil.sys
[2016/09/17 11:11:24 | 268,435,456 | -HS- | C] () -- C:\swapfile.sys
[2016/09/16 18:31:51 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_LocationProvider_01_11_00.Wdf
[2016/09/16 18:12:42 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
[2016/09/16 14:43:18 | 000,002,284 | ---- | C] () -- C:\Users\HP\Desktop\Facebook.lnk
[2016/09/16 14:43:18 | 000,002,280 | ---- | C] () -- C:\Users\HP\Desktop\Youtube.lnk
[2016/09/16 14:43:18 | 000,002,260 | ---- | C] () -- C:\Users\HP\Desktop\Free Music.lnk
[2016/09/16 14:43:18 | 000,002,260 | ---- | C] () -- C:\Users\HP\Desktop\Free Games.lnk
[2016/09/16 14:41:40 | 000,001,400 | ---- | C] () -- C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk
[2016/09/16 14:41:40 | 000,001,375 | ---- | C] () -- C:\Users\HP\Desktop\Torch.lnk
[2016/09/16 14:41:40 | 000,001,179 | ---- | C] () -- C:\Users\HP\Application Data\Microsoft\Internet Explorer\Quick Launch\Torch.lnk
[2016/09/16 14:36:15 | 000,002,103 | ---- | C] () -- C:\Users\Public\Desktop\CyberLink YouCam 5.lnk
[2016/09/16 14:30:35 | 000,001,133 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2016/09/16 14:30:35 | 000,001,121 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2016/09/16 14:29:52 | 000,002,247 | ---- | C] () -- C:\Users\HP\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2016/09/16 14:29:52 | 000,002,163 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[2016/09/16 14:29:52 | 000,002,151 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2016/09/16 14:28:31 | 000,001,096 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2016/09/16 14:28:27 | 000,001,092 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2016/04/06 02:07:39 | 000,001,315 | ---- | C] () -- C:\Windows\DfsrAdmin.exe.config
[2016/04/06 02:07:39 | 000,001,311 | ---- | C] () -- C:\Windows\System32\DfsMgmt.dll.config
[2016/04/06 02:07:39 | 000,000,764 | ---- | C] () -- C:\Windows\System32\dsac.exe.config
[2016/04/06 02:07:35 | 000,001,702 | ---- | C] () -- C:\Windows\System32\StorageMgmt.dll.config
[2016/04/06 02:07:35 | 000,001,151 | ---- | C] () -- C:\Windows\System32\ClusterUpdateUI.exe.config
[2016/04/06 02:07:35 | 000,001,048 | ---- | C] () -- C:\Windows\System32\SetupNfsIdMap.exe.config
[2016/04/06 02:07:35 | 000,000,989 | ---- | C] () -- C:\Windows\System32\NfsConfigGuide.exe.config
[2016/04/06 02:07:35 | 000,000,940 | ---- | C] () -- C:\Windows\System32\ProvisionShare.exe.config
[2016/04/06 02:07:35 | 000,000,933 | ---- | C] () -- C:\Windows\System32\ProvisionStorage.exe.config
[2016/04/04 03:16:10 | 000,812,350 | ---- | C] () -- C:\Windows\System32\perfh00C.dat
[2016/04/04 03:16:10 | 000,350,772 | ---- | C] () -- C:\Windows\System32\perfi00C.dat
[2016/04/04 03:16:10 | 000,159,412 | ---- | C] () -- C:\Windows\System32\perfc00C.dat
[2016/04/04 03:16:10 | 000,040,528 | ---- | C] () -- C:\Windows\System32\perfd00C.dat
[2014/11/22 02:06:15 | 000,046,080 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2014/11/22 02:06:09 | 000,075,264 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2014/11/22 02:06:01 | 000,107,008 | ---- | C] () -- C:\Windows\System32\OEMLicense.dll
[2014/11/22 02:05:53 | 000,050,745 | ---- | C] () -- C:\Windows\System32\srms.dat
[2014/11/22 01:58:51 | 000,262,335 | ---- | C] () -- C:\Windows\System32\dfpinc.dat
[2014/11/22 01:58:36 | 000,002,255 | ---- | C] () -- C:\Windows\System32\WimBootCompress.ini

[color=#E56717]========== ZeroAccess Check ==========[/color]


[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2016/04/06 01:54:37 | 019,794,896 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2016/04/06 02:06:51 | 000,671,232 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2016/04/06 02:06:51 | 000,367,104 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[color=#E56717]========== LOP Check ==========[/color]


[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Custom Scans ==========[/color]

[color=#A23BEC]< %ALLUSERSPROFILE%\Application Data\*. >[/color]

[color=#A23BEC]< %ALLUSERSPROFILE%\Application Data\*.exe /s >[/color]

[color=#A23BEC]< %APPDATA%\*. >[/color]
[2016/09/17 11:52:01 | 000,000,000 | ---D | M] -- C:\Users\HP\AppData\Roaming\Adobe
[2016/09/17 12:07:12 | 000,000,000 | ---D | M] -- C:\Users\HP\AppData\Roaming\Ashampoo
[2016/09/16 15:03:08 | 000,000,000 | ---D | M] -- C:\Users\HP\AppData\Roaming\AVG
[2016/09/17 12:15:15 | 000,000,000 | ---D | M] -- C:\Users\HP\AppData\Roaming\Baidu
[2016/09/22 09:04:53 | 000,000,000 | --SD | M] -- C:\Users\HP\AppData\Roaming\Microsoft
[2016/09/16 14:44:08 | 000,000,000 | ---D | M] -- C:\Users\HP\AppData\Roaming\Mozilla
[2016/09/16 14:25:25 | 000,000,000 | ---D | M] -- C:\Users\HP\AppData\Roaming\Real
[2016/09/16 15:19:22 | 000,000,000 | ---D | M] -- C:\Users\HP\AppData\Roaming\Synaptics
[2016/09/17 12:06:14 | 000,000,000 | ---D | M] -- C:\Users\HP\AppData\Roaming\Todae
[2016/09/16 14:59:30 | 000,000,000 | ---D | M] -- C:\Users\HP\AppData\Roaming\TuneUp Software
[2016/09/17 12:16:24 | 000,000,000 | ---D | M] -- C:\Users\HP\AppData\Roaming\vlc
[2016/09/17 12:07:51 | 000,000,000 | ---D | M] -- C:\Users\HP\AppData\Roaming\Winamp
[2016/09/16 22:19:44 | 000,000,000 | ---D | M] -- C:\Users\HP\AppData\Roaming\WinRAR

[color=#A23BEC]< %APPDATA%\*.exe /s >[/color]
[2016/09/17 12:14:10 | 000,532,792 | ---- | M] () -- C:\Users\HP\AppData\Roaming\Baidu\Spark\SysData\ExtApp\SnapImg\screensnapshot.exe
[2016/09/16 14:25:26 | 000,701,192 | ---- | M] (RealNetworks, Inc.) -- C:\Users\HP\AppData\Roaming\Real\Update\temp\~Upg0\rnupgagent.exe
[2016/09/16 18:26:55 | 000,701,192 | ---- | M] (RealNetworks, Inc.) -- C:\Users\HP\AppData\Roaming\Real\Update\temp\~Upg1\rnupgagent.exe
[2016/09/28 18:20:40 | 000,701,192 | ---- | M] (RealNetworks, Inc.) -- C:\Users\HP\AppData\Roaming\Real\Update\temp\~Upg3\rnupgagent.exe
[2016/09/16 14:25:26 | 000,701,192 | ---- | M] (RealNetworks, Inc.) -- C:\Users\HP\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.04\agent\rnupgagent.exe
[2016/09/16 15:20:21 | 001,331,568 | ---- | M] (RealNetworks, Inc.) -- C:\Users\HP\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.04\agent\stub_exe\RealTimes-RealPlayer.exe

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

[color=#A23BEC]< MD5 for: AGP440.SYS >[/color]
[2016/04/06 02:04:51 | 000,055,640 | ---- | M] (Microsoft Corporation) MD5=3F1C800A9092153FA159BA5909E31E2D -- C:\Windows\System32\Drivers\AGP440.sys
[2016/04/06 02:04:51 | 000,055,640 | ---- | M] (Microsoft Corporation) MD5=3F1C800A9092153FA159BA5909E31E2D -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_06963485bbb97e9f\AGP440.sys
[2016/04/06 02:04:51 | 000,055,640 | ---- | M] (Microsoft Corporation) MD5=3F1C800A9092153FA159BA5909E31E2D -- C:\Windows\WinSxS\x86_machine.inf_31bf3856ad364e35_6.3.9600.18087_none_4eb57f5eda47f68a\AGP440.sys
[2013/08/22 06:33:26 | 000,056,160 | ---- | M] (Microsoft Corporation) MD5=7A706DCF874214097A30694D3B686866 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_01c2385c3a22f281\AGP440.sys
[2013/08/22 06:33:26 | 000,056,160 | ---- | M] (Microsoft Corporation) MD5=7A706DCF874214097A30694D3B686866 -- C:\Windows\WinSxS\x86_machine.inf_31bf3856ad364e35_6.3.9600.17238_none_4eeca9d8da1e64d9\AGP440.sys

[color=#A23BEC]< MD5 for: ALG.EXE >[/color]
[2014/11/22 02:06:09 | 000,074,752 | ---- | M] (Microsoft Corporation) MD5=0AF4D02BFF152C2E9700E5E2990814A0 -- C:\Windows\System32\alg.exe
[2014/11/22 02:06:09 | 000,074,752 | ---- | M] (Microsoft Corporation) MD5=0AF4D02BFF152C2E9700E5E2990814A0 -- C:\Windows\WinSxS\x86_microsoft-windows-alg_31bf3856ad364e35_6.3.9600.17415_none_3dd5b183767e8b02\alg.exe

[color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
[2013/08/22 06:33:25 | 000,023,392 | ---- | M] (Microsoft Corporation) MD5=72FCAE2CE6DFEAB2AB072435017F3417 -- C:\Windows\System32\Drivers\atapi.sys
[2013/08/22 06:33:25 | 000,023,392 | ---- | M] (Microsoft Corporation) MD5=72FCAE2CE6DFEAB2AB072435017F3417 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_74136ef4a48e4644\atapi.sys
[2013/08/22 06:33:25 | 000,023,392 | ---- | M] (Microsoft Corporation) MD5=72FCAE2CE6DFEAB2AB072435017F3417 -- C:\Windows\WinSxS\x86_mshdc.inf_31bf3856ad364e35_6.3.9600.16384_none_71d7eca13d2363da\atapi.sys

[color=#A23BEC]< MD5 for: CDROM.SYS >[/color]
[2013/08/22 02:59:12 | 000,124,928 | ---- | M] (Microsoft Corporation) MD5=E2FC132D48EA4E8B04432C33EFB77801 -- C:\Windows\System32\Drivers\cdrom.sys
[2013/08/22 02:59:12 | 000,124,928 | ---- | M] (Microsoft Corporation) MD5=E2FC132D48EA4E8B04432C33EFB77801 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_x86_9aa051086f0faf61\cdrom.sys
[2013/08/22 02:59:12 | 000,124,928 | ---- | M] (Microsoft Corporation) MD5=E2FC132D48EA4E8B04432C33EFB77801 -- C:\Windows\WinSxS\x86_cdrom.inf_31bf3856ad364e35_6.3.9600.16384_none_f4492069bf60ff88\cdrom.sys

[color=#A23BEC]< MD5 for: CSRSS.EXE >[/color]
[2013/08/22 07:13:53 | 000,015,544 | ---- | M] (Microsoft Corporation) MD5=F6813ACED98856C0D843CCD01FF1ED7C -- C:\Windows\System32\csrss.exe
[2013/08/22 07:13:53 | 000,015,544 | ---- | M] (Microsoft Corporation) MD5=F6813ACED98856C0D843CCD01FF1ED7C -- C:\Windows\WinSxS\x86_microsoft-windows-csrss_31bf3856ad364e35_6.3.9600.16384_none_ed83a85effaf438a\csrss.exe

[color=#A23BEC]< MD5 for: CTFMON.EXE >[/color]
[2014/11/22 02:06:16 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=BE80808B5FE1D9C9351653EEC814A75A -- C:\Windows\System32\ctfmon.exe
[2014/11/22 02:06:16 | 000,009,728 | ---- | M] (Microsoft Corporation) MD5=BE80808B5FE1D9C9351653EEC814A75A -- C:\Windows\WinSxS\x86_microsoft-windows-t..cesframework-ctfmon_31bf3856ad364e35_6.3.9600.17415_none_321cec36abf18bed\ctfmon.exe

[color=#A23BEC]< MD5 for: DISK.SYS >[/color]
[2013/08/22 06:25:37 | 000,083,808 | ---- | M] (Microsoft Corporation) MD5=832BDA661E26792B5512FC641A177F26 -- C:\Windows\System32\DriverStore\FileRepository\disk.inf_x86_cfb9941d14f555d3\disk.sys
[2013/08/22 06:25:37 | 000,083,808 | ---- | M] (Microsoft Corporation) MD5=832BDA661E26792B5512FC641A177F26 -- C:\Windows\WinSxS\x86_disk.inf_31bf3856ad364e35_6.3.9600.16384_none_8e66466b8fc61898\disk.sys
[2016/04/06 01:53:32 | 000,083,800 | ---- | M] (Microsoft Corporation) MD5=F00C2CE2F5BB0FFCC726EB75A6047294 -- C:\Windows\System32\Drivers\disk.sys
[2016/04/06 01:53:32 | 000,083,800 | ---- | M] (Microsoft Corporation) MD5=F00C2CE2F5BB0FFCC726EB75A6047294 -- C:\Windows\System32\DriverStore\FileRepository\disk.inf_x86_57dcd63e20c57ab0\disk.sys
[2016/04/06 01:53:32 | 000,083,800 | ---- | M] (Microsoft Corporation) MD5=F00C2CE2F5BB0FFCC726EB75A6047294 -- C:\Windows\WinSxS\x86_disk.inf_31bf3856ad364e35_6.3.9600.18203_none_8ebb960b8f8655d4\disk.sys

[color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color]
[2014/11/22 02:06:13 | 002,207,488 | ---- | M] (Microsoft Corporation) MD5=4B37A33F4F5237BF02E537F8D12D1129 -- C:\Windows\WinSxS\x86_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_e6a10675951c7085\explorer.exe
[2016/04/06 01:54:37 | 002,412,576 | ---- | M] (Microsoft Corporation) MD5=97A7A0521E059D242907EFB73A844F29 -- C:\Windows\explorer.exe
[2016/04/06 01:54:37 | 002,412,576 | ---- | M] (Microsoft Corporation) MD5=97A7A0521E059D242907EFB73A844F29 -- C:\Windows\WinSxS\x86_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.18231_none_e6874ae19530625e\explorer.exe

[color=#A23BEC]< MD5 for: I8042PRT.SYS >[/color]
[2013/08/22 05:10:59 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=5043E69532392A43549E5D41E22638AA -- C:\Windows\System32\DriverStore\FileRepository\keyboard.inf_x86_c2d4dcdf2cb651ad\i8042prt.sys
[2013/08/22 05:10:59 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=5043E69532392A43549E5D41E22638AA -- C:\Windows\System32\DriverStore\FileRepository\msmouse.inf_x86_16deb415d1e5e5e9\i8042prt.sys
[2013/08/22 05:10:59 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=5043E69532392A43549E5D41E22638AA -- C:\Windows\WinSxS\x86_keyboard.inf_31bf3856ad364e35_6.3.9600.17393_none_2be24b61f49b9df7\i8042prt.sys
[2013/08/22 05:10:59 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=5043E69532392A43549E5D41E22638AA -- C:\Windows\WinSxS\x86_msmouse.inf_31bf3856ad364e35_6.3.9600.17393_none_e2c7e905edfde4cb\i8042prt.sys
[2016/04/06 01:50:38 | 000,083,456 | ---- | M] (Microsoft Corporation) MD5=7A708934CC652100A94944EC808C3916 -- C:\Windows\System32\Drivers\i8042prt.sys
[2016/04/06 01:50:38 | 000,083,456 | ---- | M] (Microsoft Corporation) MD5=7A708934CC652100A94944EC808C3916 -- C:\Windows\System32\DriverStore\FileRepository\keyboard.inf_x86_4d81882fbc2cefe3\i8042prt.sys
[2016/04/06 01:50:38 | 000,083,456 | ---- | M] (Microsoft Corporation) MD5=7A708934CC652100A94944EC808C3916 -- C:\Windows\System32\DriverStore\FileRepository\keyboard.inf_x86_a9462f4e972c1311\i8042prt.sys
[2016/04/06 01:50:38 | 000,083,456 | ---- | M] (Microsoft Corporation) MD5=7A708934CC652100A94944EC808C3916 -- C:\Windows\System32\DriverStore\FileRepository\msmouse.inf_x86_5d617691cc4275c7\i8042prt.sys
[2016/04/06 01:50:38 | 000,083,456 | ---- | M] (Microsoft Corporation) MD5=7A708934CC652100A94944EC808C3916 -- C:\Windows\System32\DriverStore\FileRepository\msmouse.inf_x86_817ea0f16f07ef07\i8042prt.sys
[2016/04/06 01:50:38 | 000,083,456 | ---- | M] (Microsoft Corporation) MD5=7A708934CC652100A94944EC808C3916 -- C:\Windows\WinSxS\x86_keyboard.inf_31bf3856ad364e35_6.3.9600.17480_none_2bea1c55f4963328\i8042prt.sys
[2016/04/06 01:50:38 | 000,083,456 | ---- | M] (Microsoft Corporation) MD5=7A708934CC652100A94944EC808C3916 -- C:\Windows\WinSxS\x86_keyboard.inf_31bf3856ad364e35_6.3.9600.17808_none_2c48a59df44e12f4\i8042prt.sys
[2016/04/06 01:50:38 | 000,083,456 | ---- | M] (Microsoft Corporation) MD5=7A708934CC652100A94944EC808C3916 -- C:\Windows\WinSxS\x86_msmouse.inf_31bf3856ad364e35_6.3.9600.17480_none_e2cfb9f9edf879fc\i8042prt.sys
[2016/04/06 01:50:38 | 000,083,456 | ---- | M] (Microsoft Corporation) MD5=7A708934CC652100A94944EC808C3916 -- C:\Windows\WinSxS\x86_msmouse.inf_31bf3856ad364e35_6.3.9600.17808_none_e32e4341edb059c8\i8042prt.sys

[color=#A23BEC]< MD5 for: IASTORV.SYS >[/color]
[2013/08/22 06:33:29 | 000,333,664 | ---- | M] (Intel Corporation) MD5=D2E7F3611BB8F1C2661B8F7858D33A35 -- C:\Windows\System32\Drivers\iaStorV.sys
[2013/08/22 06:33:29 | 000,333,664 | ---- | M] (Intel Corporation) MD5=D2E7F3611BB8F1C2661B8F7858D33A35 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_5069105fb236ae4b\iaStorV.sys
[2013/08/22 06:33:29 | 000,333,664 | ---- | M] (Intel Corporation) MD5=D2E7F3611BB8F1C2661B8F7858D33A35 -- C:\Windows\WinSxS\x86_iastorv.inf_31bf3856ad364e35_6.3.9600.16384_none_43b116ffa3618fcd\iaStorV.sys

[color=#A23BEC]< MD5 for: INTELIDE.SYS >[/color]
[2013/08/22 06:33:29 | 000,016,736 | ---- | M] (Microsoft Corporation) MD5=B0F92A795C7E48E2C5F908265C655458 -- C:\Windows\System32\Drivers\intelide.sys
[2013/08/22 06:33:29 | 000,016,736 | ---- | M] (Microsoft Corporation) MD5=B0F92A795C7E48E2C5F908265C655458 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_74136ef4a48e4644\intelide.sys
[2013/08/22 06:33:29 | 000,016,736 | ---- | M] (Microsoft Corporation) MD5=B0F92A795C7E48E2C5F908265C655458 -- C:\Windows\WinSxS\x86_mshdc.inf_31bf3856ad364e35_6.3.9600.16384_none_71d7eca13d2363da\intelide.sys

[color=#A23BEC]< MD5 for: MOUNTMGR.SYS >[/color]
[2016/04/06 01:56:03 | 000,082,776 | ---- | M] (Microsoft Corporation) MD5=9188982A1BBBA9BA12CFA349D08B3825 -- C:\Windows\System32\Drivers\mountmgr.sys
[2016/04/06 01:56:03 | 000,082,776 | ---- | M] (Microsoft Corporation) MD5=9188982A1BBBA9BA12CFA349D08B3825 -- C:\Windows\WinSxS\x86_microsoft-windows-m..pointmanager-minwin_31bf3856ad364e35_6.3.9600.17936_none_65335a0de8b15c59\mountmgr.sys
[2014/11/22 02:05:47 | 000,082,752 | ---- | M] (Microsoft Corporation) MD5=D742BD8CD00C15FD775355B02EA89D3A -- C:\Windows\WinSxS\x86_microsoft-windows-m..pointmanager-minwin_31bf3856ad364e35_6.3.9600.17393_none_64ef6e43e8e4c910\mountmgr.sys

[color=#A23BEC]< MD5 for: MRXSMB.SYS >[/color]
[2016/04/06 01:56:35 | 000,328,192 | ---- | M] (Microsoft Corporation) MD5=0DE0757B9D883EF9469E29CC9C8149D7 -- C:\Windows\WinSxS\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.3.9600.18154_none_145170246c9ee982\mrxsmb.sys
[2014/11/22 02:05:49 | 000,330,752 | ---- | M] (Microsoft Corporation) MD5=6FFD467F3BF3E3044E9B212CCD488DE1 -- C:\Windows\WinSxS\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.3.9600.17401_none_14849b5c6c78ef9c\mrxsmb.sys
[2016/04/06 02:05:25 | 000,328,192 | ---- | M] (Microsoft Corporation) MD5=82DDB4CB5FBC23C1F889BA6ADFA89145 -- C:\Windows\WinSxS\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.3.9600.18123_none_1470df9e6c877c58\mrxsmb.sys
[2016/04/06 01:53:26 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=8F4479CAB37AA3C762BE8800626A976C -- C:\Windows\WinSxS\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.3.9600.18192_none_14242fe06cc12698\mrxsmb.sys
[2016/04/06 01:55:16 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=AD93F81E49B6DD37ABDFDDC8AAC03291 -- C:\Windows\WinSxS\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.3.9600.17630_none_14632f1a6c922466\mrxsmb.sys
[2016/05/18 12:54:43 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=BF1B3D06A527F184DCEF944457B8FCAA -- C:\Windows\System32\Drivers\mrxsmb.sys
[2016/05/18 12:54:43 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=BF1B3D06A527F184DCEF944457B8FCAA -- C:\Windows\WinSxS\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.3.9600.18298_none_142a33826cbbbbc9\mrxsmb.sys
[2016/05/18 12:54:43 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=BF1B3D06A527F184DCEF944457B8FCAA -- C:\Windows\WinSxS\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.3.9600.18341_none_145942fe6c997bda\mrxsmb.sys
[2016/04/06 02:03:39 | 000,328,192 | ---- | M] (Microsoft Corporation) MD5=D3CEDBCC4EF55892005D5CBD6A25CE15 -- C:\Windows\WinSxS\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.3.9600.18002_none_14857d466c782df8\mrxsmb.sys
[2016/04/06 01:50:12 | 000,333,312 | ---- | M] (Microsoft Corporation) MD5=E11D4B798CF0FF9F739CD9BDC552FF08 -- C:\Windows\WinSxS\x86_microsoft-windows-smbminirdr_31bf3856ad364e35_6.3.9600.17111_none_1479c5be6c811418\mrxsmb.sys

[color=#A23BEC]< MD5 for: MRXSMB10.SYS >[/color]
[2016/04/06 01:55:16 | 000,229,376 | ---- | M] (Microsoft Corporation) MD5=29C97522D8585C441D0B18D0E99FDBA3 -- C:\Windows\WinSxS\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.3.9600.17630_none_1d764d6e66e362c8\mrxsmb10.sys
[2016/05/18 12:54:43 | 000,229,376 | ---- | M] (Microsoft Corporation) MD5=410A8BC044F144403F4ACF5CDEE49870 -- C:\Windows\System32\Drivers\mrxsmb10.sys
[2016/05/18 12:54:43 | 000,229,376 | ---- | M] (Microsoft Corporation) MD5=410A8BC044F144403F4ACF5CDEE49870 -- C:\Windows\WinSxS\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.3.9600.18298_none_1d3d51d6670cfa2b\mrxsmb10.sys
[2016/05/18 12:54:43 | 000,229,376 | ---- | M] (Microsoft Corporation) MD5=410A8BC044F144403F4ACF5CDEE49870 -- C:\Windows\WinSxS\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.3.9600.18341_none_1d6c615266eaba3c\mrxsmb10.sys
[2016/04/06 01:53:26 | 000,229,376 | ---- | M] (Microsoft Corporation) MD5=7C25AC0150ADD25121170A3EC8DFC147 -- C:\Windows\WinSxS\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.3.9600.18154_none_1d648e7866f027e4\mrxsmb10.sys
[2016/04/06 01:53:26 | 000,229,376 | ---- | M] (Microsoft Corporation) MD5=7C25AC0150ADD25121170A3EC8DFC147 -- C:\Windows\WinSxS\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.3.9600.18192_none_1d374e34671264fa\mrxsmb10.sys
[2014/11/22 02:16:50 | 000,227,840 | ---- | M] (Microsoft Corporation) MD5=F37F40422662235AB5768C303E829602 -- C:\Windows\WinSxS\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.3.9600.17041_none_1d6c726866eaa926\mrxsmb10.sys

[color=#A23BEC]< MD5 for: MRXSMB20.SYS >[/color]
[2016/04/06 01:56:35 | 000,153,088 | ---- | M] (Microsoft Corporation) MD5=2ACFD27D491EB9C7CA69A001E79348DC -- C:\Windows\WinSxS\x86_microsoft-windows-smb20-minirdr_31bf3856ad364e35_6.3.9600.18154_none_1f9af88aa5475b55\mrxsmb20.sys
[2016/04/06 01:55:16 | 000,154,112 | ---- | M] (Microsoft Corporation) MD5=497159F6F6EB7D0FA93B2605AFECC293 -- C:\Windows\WinSxS\x86_microsoft-windows-smb20-minirdr_31bf3856ad364e35_6.3.9600.17630_none_1facb780a53a9639\mrxsmb20.sys
[2016/04/06 02:05:25 | 000,153,088 | ---- | M] (Microsoft Corporation) MD5=97F04201317BEDEC4D58B9FEFADB5A34 -- C:\Windows\WinSxS\x86_microsoft-windows-smb20-minirdr_31bf3856ad364e35_6.3.9600.18123_none_1fba6804a52fee2b\mrxsmb20.sys
[2014/11/22 02:05:49 | 000,156,160 | ---- | M] (Microsoft Corporation) MD5=99980368B0A2230F5FE76986AF6AF935 -- C:\Windows\WinSxS\x86_microsoft-windows-smb20-minirdr_31bf3856ad364e35_6.3.9600.17385_none_1f7ba3a4a55ea92c\mrxsmb20.sys
[2016/04/06 01:53:26 | 000,153,088 | ---- | M] (Microsoft Corporation) MD5=99B8335E854F37AD8C67D274B662FF1A -- C:\Windows\WinSxS\x86_microsoft-windows-smb20-minirdr_31bf3856ad364e35_6.3.9600.18192_none_1f6db846a569986b\mrxsmb20.sys
[2016/05/18 12:54:43 | 000,153,088 | ---- | M] (Microsoft Corporation) MD5=C955B81F7554162ACDFD086E64E19289 -- C:\Windows\System32\Drivers\mrxsmb20.sys
[2016/05/18 12:54:43 | 000,153,088 | ---- | M] (Microsoft Corporation) MD5=C955B81F7554162ACDFD086E64E19289 -- C:\Windows\WinSxS\x86_microsoft-windows-smb20-minirdr_31bf3856ad364e35_6.3.9600.18298_none_1f73bbe8a5642d9c\mrxsmb20.sys
[2016/05/18 12:54:43 | 000,153,088 | ---- | M] (Microsoft Corporation) MD5=C955B81F7554162ACDFD086E64E19289 -- C:\Windows\WinSxS\x86_microsoft-windows-smb20-minirdr_31bf3856ad364e35_6.3.9600.18341_none_1fa2cb64a541edad\mrxsmb20.sys
[2016/04/06 02:03:39 | 000,153,088 | ---- | M] (Microsoft Corporation) MD5=D4260E0D129D2F3589B32C3799C88874 -- C:\Windows\WinSxS\x86_microsoft-windows-smb20-minirdr_31bf3856ad364e35_6.3.9600.18002_none_1fcf05aca5209fcb\mrxsmb20.sys

[color=#A23BEC]< MD5 for: NDIS.SYS >[/color]
[2014/11/22 02:05:47 | 000,869,696 | ---- | M] (Microsoft Corporation) MD5=1812DA4DD3FF480C88346AC3ACAD8C04 -- C:\Windows\WinSxS\x86_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17399_none_edef5d7a43a95540\ndis.sys
[2016/04/06 01:52:25 | 000,869,720 | ---- | M] (Microsoft Corporation) MD5=652B4A1A844B80504375C6FDB28293A4 -- C:\Windows\System32\Drivers\ndis.sys
[2016/04/06 01:52:25 | 000,869,720 | ---- | M] (Microsoft Corporation) MD5=652B4A1A844B80504375C6FDB28293A4 -- C:\Windows\WinSxS\x86_microsoft-windows-ndis-minwin_31bf3856ad364e35_6.3.9600.17933_none_ee2a46aa437e047a\ndis.sys

[color=#A23BEC]< MD5 for: NETLOGON.DLL >[/color]
[2016/05/18 12:54:43 | 000,696,832 | ---- | M] (Microsoft Corporation) MD5=3A1B7B111ECAF58414B82EAB67EDB060 -- C:\Windows\System32\netlogon.dll
[2016/05/18 12:54:43 | 000,696,832 | ---- | M] (Microsoft Corporation) MD5=3A1B7B111ECAF58414B82EAB67EDB060 -- C:\Windows\WinSxS\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.18295_none_924d7cb2539ae8f8\netlogon.dll
[2014/11/22 02:05:49 | 000,695,296 | ---- | M] (Microsoft Corporation) MD5=CCEC6CB98A00ECE7F5AFB9C0FC9427B3 -- C:\Windows\WinSxS\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.17415_none_92a416a65359ea1d\netlogon.dll
[2016/04/06 01:53:07 | 000,696,320 | ---- | M] (Microsoft Corporation) MD5=F8CA80130D66F44446C259ECBDE21AC3 -- C:\Windows\WinSxS\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.3.9600.18170_none_925e1932538f353c\netlogon.dll

[color=#A23BEC]< MD5 for: NVSTOR.SYS >[/color]
[2013/08/22 06:33:33 | 000,141,664 | ---- | M] (NVIDIA Corporation) MD5=8BC42FC48C9DB301025D7A5C6B20ECD9 -- C:\Windows\System32\Drivers\nvstor.sys
[2013/08/22 06:33:33 | 000,141,664 | ---- | M] (NVIDIA Corporation) MD5=8BC42FC48C9DB301025D7A5C6B20ECD9 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_7ba65ba4b222e751\nvstor.sys
[2013/08/22 06:33:33 | 000,141,664 | ---- | M] (NVIDIA Corporation) MD5=8BC42FC48C9DB301025D7A5C6B20ECD9 -- C:\Windows\WinSxS\x86_nvraid.inf_31bf3856ad364e35_6.3.9600.16384_none_ce7a87aeda9839a5\nvstor.sys

[color=#A23BEC]< MD5 for: RASACD.SYS >[/color]
[2014/11/22 02:06:07 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=D94D03BA0A61AAF5A5E008BF33BD2519 -- C:\Windows\System32\Drivers\rasacd.sys
[2014/11/22 02:06:07 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=D94D03BA0A61AAF5A5E008BF33BD2519 -- C:\Windows\WinSxS\x86_microsoft-windows-rasautodial_31bf3856ad364e35_6.3.9600.17415_none_a4c65e1980b32129\rasacd.sys

[color=#A23BEC]< MD5 for: SCECLI.DLL >[/color]
[2016/04/06 02:00:21 | 000,214,528 | ---- | M] (Microsoft Corporation) MD5=8CBE793298A3BC2D03765299FFA2BE83 -- C:\Windows\System32\scecli.dll
[2016/04/06 02:00:21 | 000,214,528 | ---- | M] (Microsoft Corporation) MD5=8CBE793298A3BC2D03765299FFA2BE83 -- C:\Windows\WinSxS\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17547_none_ccdbd474f491f480\scecli.dll
[2014/11/22 02:05:59 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\WinSxS\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17415_none_ccfa41bef47b70d8\scecli.dll

[color=#A23BEC]< MD5 for: SERVICES.EXE >[/color]
[2016/04/06 01:55:36 | 000,333,624 | ---- | M] (Microsoft Corporation) MD5=9E597749A44C4A39948917B5F30DE1CC -- C:\Windows\System32\services.exe
[2016/04/06 01:55:36 | 000,333,624 | ---- | M] (Microsoft Corporation) MD5=9E597749A44C4A39948917B5F30DE1CC -- C:\Windows\WinSxS\x86_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.3.9600.17794_none_d3adaada1844fee1\services.exe
[2014/11/22 02:05:49 | 000,334,120 | ---- | M] (Microsoft Corporation) MD5=A49A7FF0A8CF7C4BC9864B7F89B7F8DA -- C:\Windows\WinSxS\x86_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.3.9600.17415_none_d40524d21803413b\services.exe

[color=#A23BEC]< MD5 for: SMSS.EXE >[/color]
[2014/11/22 01:58:31 | 000,105,896 | ---- | M] (Microsoft Corporation) MD5=1C8CDF81449BF9EA8FD88EAB3A2CCD1E -- C:\Windows\System32\smss.exe
[2014/11/22 01:58:31 | 000,105,896 | ---- | M] (Microsoft Corporation) MD5=1C8CDF81449BF9EA8FD88EAB3A2CCD1E -- C:\Windows\WinSxS\x86_microsoft-windows-smss-minwin_31bf3856ad364e35_6.3.9600.17031_none_13338d0e043f4d0f\smss.exe

[color=#A23BEC]< MD5 for: SPOOLSV.EXE >[/color]
[2016/04/06 01:50:38 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=04C3CA76D6D3258C08029680E45D8170 -- C:\Windows\WinSxS\x86_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.3.9600.17480_none_6ae7519edd260bc0\spoolsv.exe
[2014/11/22 02:06:11 | 000,560,128 | ---- | M] (Microsoft Corporation) MD5=A0A1DAC8B002E75AF4E09A369E877CB2 -- C:\Windows\WinSxS\x86_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.3.9600.17415_none_6b380284dce8c6dc\spoolsv.exe
[2016/04/06 02:02:25 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=C6081D760153CA3027BBB38BCBBDF104 -- C:\Windows\System32\spoolsv.exe
[2016/04/06 02:02:25 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=C6081D760153CA3027BBB38BCBBDF104 -- C:\Windows\WinSxS\x86_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.3.9600.17797_none_6ae3896add27d087\spoolsv.exe

[color=#A23BEC]< MD5 for: STORPORT.SYS >[/color]
[2014/11/22 02:05:59 | 000,312,128 | ---- | M] (Microsoft Corporation) MD5=9521DBE6CCFBEB8B23F4E7258E5D41C3 -- C:\Windows\WinSxS\x86_microsoft-windows-storport_31bf3856ad364e35_6.3.9600.17383_none_bc1afc1e4bc97b5b\storport.sys
[2016/04/06 01:53:40 | 000,318,296 | ---- | M] (Microsoft Corporation) MD5=A97C50B093B02F891903526D1AB70F65 -- C:\Windows\WinSxS\x86_microsoft-windows-storport_31bf3856ad364e35_6.3.9600.18217_none_bc6a940c4b8d399a\storport.sys
[2016/04/06 01:54:19 | 000,318,296 | ---- | M] (Microsoft Corporation) MD5=D83AB76F85ED4C5BB5AC578F3D5F7FBD -- C:\Windows\System32\Drivers\storport.sys
[2016/04/06 01:54:19 | 000,318,296 | ---- | M] (Microsoft Corporation) MD5=D83AB76F85ED4C5BB5AC578F3D5F7FBD -- C:\Windows\WinSxS\x86_microsoft-windows-storport_31bf3856ad364e35_6.3.9600.18229_none_bc61c4b44b938839\storport.sys

[color=#A23BEC]< MD5 for: SVCHOST.EXE >[/color]
[2014/11/22 02:05:49 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\System32\svchost.exe
[2014/11/22 02:05:49 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_4aa7b90420adbfab\svchost.exe

[color=#A23BEC]< MD5 for: TCPIP.SYS >[/color]
[2016/04/06 02:05:28 | 001,852,248 | ---- | M] (Microsoft Corporation) MD5=0A4DE8D675A23C14646A10BDE02F012F -- C:\Windows\System32\Drivers\tcpip.sys
[2016/04/06 02:05:28 | 001,852,248 | ---- | M] (Microsoft Corporation) MD5=0A4DE8D675A23C14646A10BDE02F012F -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.18124_none_47fe850581cf6782\tcpip.sys
[2016/04/06 01:50:38 | 001,856,320 | ---- | M] (Microsoft Corporation) MD5=358AF13F5C4E69312FA1283B2657274A -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17485_none_47bec24181ff0653\tcpip.sys
[2014/11/22 02:05:47 | 001,856,320 | ---- | M] (Microsoft Corporation) MD5=43E1B4CBACC5B8B269C5775A219FD58E -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17415_none_480a71b581c642bc\tcpip.sys
[2016/04/06 02:01:31 | 001,855,296 | ---- | M] (Microsoft Corporation) MD5=C9054DD51656636CF9A04850EDA4DC32 -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17676_none_47ca964381f5fe07\tcpip.sys

[color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
[2014/11/22 02:05:49 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\System32\userinit.exe
[2014/11/22 02:05:49 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_71151978ed0ff9d1\userinit.exe

[color=#A23BEC]< MD5 for: WIN32K.SYS >[/color]
[2016/05/18 12:53:49 | 003,492,864 | ---- | M] (Microsoft Corporation) MD5=2A104155E36799D610C191128166AE35 -- C:\Windows\WinSxS\x86_microsoft-windows-win32k_31bf3856ad364e35_6.3.9600.18302_none_4de78f7db5e1800a\win32k.sys
[2016/04/06 01:50:12 | 003,497,472 | ---- | M] (Microsoft Corporation) MD5=3BC326564DF499A563E178F80D4FF2D6 -- C:\Windows\WinSxS\x86_microsoft-windows-win32k_31bf3856ad364e35_6.3.9600.17114_none_4dded321b5e7baba\win32k.sys
[2016/04/06 01:57:17 | 003,515,392 | ---- | M] (Microsoft Corporation) MD5=B0EE1B5045CE10A854E6B108289769F2 -- C:\Windows\WinSxS\x86_microsoft-windows-win32k_31bf3856ad364e35_6.3.9600.18228_none_4dd7ef7bb5ec52cf\win32k.sys
[2014/11/22 02:06:16 | 003,558,400 | ---- | M] (Microsoft Corporation) MD5=D151F4D0C50A25A8DCBD32C11E4531E9 -- C:\Windows\WinSxS\x86_microsoft-windows-win32k_31bf3856ad364e35_6.3.9600.17393_none_4d875743b6297b39\win32k.sys
[2016/06/16 17:37:20 | 003,492,864 | ---- | M] (Microsoft Corporation) MD5=E2A2340854C1F07478740E01B59C79CF -- C:\Windows\System32\win32k.sys
[2016/06/16 17:37:20 | 003,492,864 | ---- | M] (Microsoft Corporation) MD5=E2A2340854C1F07478740E01B59C79CF -- C:\Windows\WinSxS\x86_microsoft-windows-win32k_31bf3856ad364e35_6.3.9600.18340_none_4dba4f39b603bd20\win32k.sys
[2016/04/06 02:05:40 | 003,520,000 | ---- | M] (Microsoft Corporation) MD5=EF305B7A55D01CF26C929C2A658829BA -- C:\Windows\WinSxS\x86_microsoft-windows-win32k_31bf3856ad364e35_6.3.9600.18167_none_4dabad9bb60dac15\win32k.sys
[2016/04/06 01:56:29 | 003,520,000 | ---- | M] (Microsoft Corporation) MD5=F7FB93A84CC3426240C6D4F8166844E9 -- C:\Windows\WinSxS\x86_microsoft-windows-win32k_31bf3856ad364e35_6.3.9600.18123_none_4dd2ec23b5f0d6f5\win32k.sys

[color=#A23BEC]< MD5 for: WININIT.EXE >[/color]
[2016/04/06 01:52:49 | 000,115,712 | ---- | M] (Microsoft Corporation) MD5=8A60D4136E37C3CCB1ECAE90D11618F4 -- C:\Windows\System32\wininit.exe
[2016/04/06 01:52:49 | 000,115,712 | ---- | M] (Microsoft Corporation) MD5=8A60D4136E37C3CCB1ECAE90D11618F4 -- C:\Windows\WinSxS\x86_microsoft-windows-wininit_31bf3856ad364e35_6.3.9600.18083_none_c59149ca1feb5e56\wininit.exe
[2014/11/22 02:05:49 | 000,115,712 | ---- | M] (Microsoft Corporation) MD5=DC02677945BDABD6B0C6A29914AA21EF -- C:\Windows\WinSxS\x86_microsoft-windows-wininit_31bf3856ad364e35_6.3.9600.17415_none_c5df18321fb0a868\wininit.exe

[color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
[2016/04/06 01:53:15 | 000,465,408 | ---- | M] (Microsoft Corporation) MD5=2022624E358053908CB81B4E02245B8F -- C:\Windows\System32\winlogon.exe
[2016/04/06 01:53:15 | 000,465,408 | ---- | M] (Microsoft Corporation) MD5=2022624E358053908CB81B4E02245B8F -- C:\Windows\WinSxS\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.18188_none_04669569f087af83\winlogon.exe
[2016/04/06 01:52:49 | 000,465,920 | ---- | M] (Microsoft Corporation) MD5=C7B38F105DFDD3231314EDDF7012D8AA -- C:\Windows\WinSxS\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.18083_none_04619211f08c33a9\winlogon.exe
[2014/11/22 02:06:00 | 000,465,408 | ---- | M] (Microsoft Corporation) MD5=E36FB29A2158B7D5DCA0F4E08DE75442 -- C:\Windows\WinSxS\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17415_none_04af6079f0517dbb\winlogon.exe

[color=#A23BEC]< %systemroot%\*. /mp /s >[/color]

[color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\system32\drivers\*.sys /lockedfiles >[/color]
[2016/06/23 14:31:52 | 000,206,496 | ---- | M] (ESET)[b] Unable to obtain MD5[/b] -- C:\Windows\system32\drivers\eamonm.sys
[2016/06/23 14:31:52 | 000,014,976 | ---- | M] (ESET)[b] Unable to obtain MD5[/b] -- C:\Windows\system32\drivers\eelam.sys
[2016/06/23 14:31:52 | 000,156,320 | ---- | M] (ESET)[b] Unable to obtain MD5[/b] -- C:\Windows\system32\drivers\ehdrv.sys
[2016/06/23 14:31:52 | 000,141,472 | ---- | M] (ESET)[b] Unable to obtain MD5[/b] -- C:\Windows\system32\drivers\epfwwfpr.sys

[color=#A23BEC]< %systemroot%\System32\config\*.sav >[/color]

[color=#A23BEC]< >[/color]
[2013/08/22 08:23:44 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2016/09/16 14:28:27 | 000,001,092 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2016/09/16 14:28:31 | 000,001,096 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

[color=#A23BEC]< >[/color]

[color=#E56717]========== Files - Unicode (All) ==========[/color]
[2016/09/22 10:40:02 | 000,015,186 | ---- | M] ()(C:\Users\HP\Desktop\Microsoft Word ???1.docx) -- C:\Users\HP\Desktop\Microsoft Word EDA1.docx
[2016/09/22 10:40:00 | 000,015,186 | ---- | C] ()(C:\Users\HP\Desktop\Microsoft Word ???1.docx) -- C:\Users\HP\Desktop\Microsoft Word EDA1.docx

< End of report >

Publicité


Signaler le contenu de ce document

Publicité