Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017 Ran by iNjeCtor (administrator) on INJECTOR-PC (23-03-2017 18:06:10) Running from C:\Users\iNjeCtor\Desktop Loaded Profiles: iNjeCtor (Available Profiles: iNjeCtor & Pu) Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Copyright 2017.) C:\Program Files (x86)\MalwareFox AntiMalware\ZAM.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Copyright 2017.) C:\Program Files (x86)\MalwareFox AntiMalware\ZAM.exe (company) C:\Program Files\Seed4.Me VPN\bin\Seed4.Me_VPN.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16776192 2017-02-04] (Realtek Semiconductor) HKLM\...\Run: [ZAM] => C:\Program Files (x86)\MalwareFox AntiMalware\ZAM.exe [14459120 2017-03-22] (Copyright 2017.) HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-599157185-2341742093-3697436756-1000\...\Run: [Seed4Me] => C:\Program Files\Seed4.Me VPN\bin\Seed4.Me_VPN.exe [23909200 2017-02-01] (company) HKU\S-1-5-21-599157185-2341742093-3697436756-1000\...\Run: [Memory Cleaner] => C:\Users\iNjeCtor\AppData\Roaming\KoshyJohn.com\MemClean\MemClean.exe [810088 2016-01-04] (KoshyJohn.com) BootExecute: autocheck autochk * sdnclean64.exe GroupPolicy: Restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 10.192.0.1 Tcpip\..\Interfaces\{11D31F7F-F9D9-41FF-B7A9-DB9B1A8DE596}: [DhcpNameServer] 10.192.0.1 Tcpip\..\Interfaces\{C093634B-74D6-434E-A2F1-9FD627FFC00B}: [DhcpNameServer] 10.192.0.1 Internet Explorer: ================== HKU\S-1-5-21-599157185-2341742093-3697436756-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/fr-fr/?ocid=iehp BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office16\URLREDIR.DLL [2015-07-31] (Microsoft Corporation) BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation) Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: 9ldxjkpg.default FF ProfilePath: C:\Users\iNjeCtor\AppData\Roaming\Mozilla\Firefox\Profiles\9ldxjkpg.default [2017-03-23] FF Extension: (IE Tab +) - C:\Users\iNjeCtor\AppData\Roaming\Mozilla\Firefox\Profiles\9ldxjkpg.default\Extensions\coralietab@mozdev.org [2017-02-09] FF Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\iNjeCtor\AppData\Roaming\Mozilla\Firefox\Profiles\9ldxjkpg.default\Extensions\firefox@zenmate.com.xpi [2017-02-10] FF Extension: (Adblock Plus) - C:\Users\iNjeCtor\AppData\Roaming\Mozilla\Firefox\Profiles\9ldxjkpg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-02-21] FF HKU\S-1-5-21-599157185-2341742093-3697436756-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => not found FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll [2017-03-17] () FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll [2017-03-17] () FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-07-31] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-06] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-06] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-07-31] (Microsoft Corporation) FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2017-01-03] Chrome: ======= CHR Profile: C:\Users\iNjeCtor\AppData\Local\Google\Chrome\User Data\Default [2017-03-22] CHR Extension: (Google Slides) - C:\Users\iNjeCtor\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-02-06] CHR Extension: (Google Docs) - C:\Users\iNjeCtor\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-06] CHR Extension: (Google Drive) - C:\Users\iNjeCtor\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-02-06] CHR Extension: (YouTube) - C:\Users\iNjeCtor\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-06] CHR Extension: (ZenMate VPN - Sécurité internet & Unblock) - C:\Users\iNjeCtor\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2017-03-15] CHR Extension: (Google Sheets) - C:\Users\iNjeCtor\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-02-06] CHR Extension: (Google Docs hors connexion) - C:\Users\iNjeCtor\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-02-08] CHR Extension: (IE Tab) - C:\Users\iNjeCtor\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd [2017-02-25] CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\iNjeCtor\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09] CHR Extension: (Gmail) - C:\Users\iNjeCtor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-06] CHR Extension: (Chrome Media Router) - C:\Users\iNjeCtor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-06] CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx Opera: ======= StartMenuInternet: (HKLM) OperaStable - C:\Program Files\Opera\Launcher.exe ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.) R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2836296 2016-12-14] (ESET) S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] () R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10351856 2016-12-15] (TeamViewer GmbH) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2016-12-20] (Microsoft Corporation) R2 wuauserv; C:\Windows\system32\wuaueng2.dll [2607104 2016-05-13] (Microsoft Corporation) [File not signed] R2 ZAMSvc; C:\Program Files (x86)\MalwareFox AntiMalware\ZAM.exe [14459120 2017-03-22] (Copyright 2017.) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [132272 2016-12-13] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [180544 2016-12-13] (ESET) R1 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [70960 2016-12-13] (ESET) R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-02-04] (REALiX(tm)) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation) R1 ZAM; C:\Windows\System32\drivers\zam64.sys [203680 2017-03-22] (Zemana Ltd.) R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard64.sys [203680 2017-03-22] (Zemana Ltd.) S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-03-23 18:06 - 2017-03-23 18:06 - 00012678 _____ C:\Users\iNjeCtor\Desktop\FRST.txt 2017-03-23 18:06 - 2017-03-23 18:06 - 00000000 ____D C:\FRST 2017-03-23 18:05 - 2017-03-23 18:05 - 02424832 _____ (Farbar) C:\Users\iNjeCtor\Desktop\FRST64.exe 2017-03-23 18:02 - 2017-03-23 18:02 - 00105843 _____ C:\Users\iNjeCtor\Downloads\Discussion WhatsApp avec Ismahane arroubi.txt 2017-03-23 15:23 - 2017-03-23 15:32 - 00001328 _____ C:\Users\iNjeCtor\Desktop\ZHPCleaner.txt 2017-03-23 15:13 - 2017-03-23 15:14 - 00000844 _____ C:\Users\iNjeCtor\Desktop\ZHPCleaner.lnk 2017-03-23 15:12 - 2017-03-23 15:12 - 02752512 _____ C:\Users\iNjeCtor\Downloads\ZHPCleaner.exe 2017-03-23 14:58 - 2017-03-23 16:10 - 00002898 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (iNjeCtor) 2017-03-23 14:57 - 2017-03-22 21:46 - 04031440 _____ C:\Users\iNjeCtor\Desktop\adwcleaner_6.044.exe 2017-03-23 14:56 - 2017-03-23 14:56 - 04031440 _____ C:\Users\iNjeCtor\Downloads\adwcleaner_6.044(1).exe 2017-03-23 03:23 - 2017-03-23 03:23 - 00000000 ____D C:\Users\Pu\AppData\Roaming\Macromedia 2017-03-23 01:56 - 2017-03-23 01:57 - 00114164 _____ C:\Users\iNjeCtor\Desktop\ZHPDiag.txt 2017-03-23 01:47 - 2017-03-23 15:32 - 00000000 ____D C:\Users\iNjeCtor\AppData\Roaming\ZHP 2017-03-23 01:47 - 2017-03-23 01:47 - 00000834 _____ C:\Users\iNjeCtor\Desktop\ZHPDiag.lnk 2017-03-23 01:45 - 2017-03-23 01:46 - 02712064 _____ C:\Users\iNjeCtor\Downloads\ZHPDiag3.exe 2017-03-23 01:42 - 2017-03-23 01:47 - 00000000 ____D C:\KVRT_Data 2017-03-23 01:37 - 2017-03-23 01:39 - 110191072 _____ (Kaspersky Lab ZAO) C:\Users\iNjeCtor\Downloads\KVRT.exe 2017-03-23 01:03 - 2017-03-23 03:26 - 00000000 ____D C:\Users\Pu\AppData\Roaming\vlc 2017-03-23 01:03 - 2017-03-23 01:03 - 00111128 _____ C:\Users\Pu\AppData\Local\GDIPFONTCACHEV1.DAT 2017-03-23 01:02 - 2017-03-23 01:04 - 00000000 ____D C:\Users\Pu\AppData\Roaming\TrueCrypt 2017-03-23 01:01 - 2017-03-23 01:01 - 00000000 ____D C:\Users\Pu\AppData\Local\Zemana 2017-03-23 01:01 - 2017-03-23 01:01 - 00000000 ____D C:\Users\Pu\AppData\Local\Wolf of Webstreet OPC Private Limited 2017-03-22 22:14 - 2017-03-23 18:06 - 00139720 _____ C:\Windows\ZAM.krnl.trace 2017-03-22 22:14 - 2017-03-23 18:06 - 00023059 _____ C:\Windows\ZAM_Guard.krnl.trace 2017-03-22 22:14 - 2017-03-22 22:15 - 01968976 _____ (SecureAge Technology) C:\Users\iNjeCtor\Downloads\SecureAPlusSetup.exe 2017-03-22 22:14 - 2017-03-22 22:14 - 00203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zamguard64.sys 2017-03-22 22:14 - 2017-03-22 22:14 - 00203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zam64.sys 2017-03-22 22:14 - 2017-03-22 22:14 - 00001193 _____ C:\Users\Public\Desktop\MalwareFox AntiMalware.lnk 2017-03-22 22:14 - 2017-03-22 22:14 - 00000000 ____D C:\Users\iNjeCtor\AppData\Local\Wolf of Webstreet OPC Private Limited 2017-03-22 22:14 - 2017-03-22 22:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MalwareFox AntiMalware 2017-03-22 22:14 - 2017-03-22 22:14 - 00000000 ____D C:\Program Files (x86)\MalwareFox AntiMalware 2017-03-22 22:13 - 2017-03-22 22:13 - 00000000 ____D C:\Users\iNjeCtor\AppData\Local\Zemana 2017-03-22 22:11 - 2017-03-22 22:11 - 05747600 _____ (Zemana Ltd. ) C:\Users\iNjeCtor\Downloads\setup.exe 2017-03-22 22:11 - 2017-03-22 22:11 - 00001981 _____ C:\Users\iNjeCtor\Desktop\Memory Cleaner.lnk 2017-03-22 22:11 - 2017-03-22 22:11 - 00000000 ____D C:\Users\iNjeCtor\AppData\Roaming\KoshyJohn.com 2017-03-22 22:11 - 2017-03-22 22:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KoshyJohn.com 2017-03-22 22:10 - 2017-03-22 22:11 - 00590208 _____ (KoshyJohn.com) C:\Users\iNjeCtor\Downloads\MemClean.exe 2017-03-22 21:50 - 2017-03-22 21:50 - 00001398 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk 2017-03-22 21:50 - 2017-03-22 21:50 - 00001386 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2017-03-22 21:50 - 2017-03-22 21:50 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking 2017-03-22 21:50 - 2017-03-22 21:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 2017-03-22 21:49 - 2017-03-22 21:53 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2017-03-22 21:49 - 2017-03-22 21:50 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2017-03-22 21:49 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe 2017-03-22 21:48 - 2017-03-22 21:48 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\iNjeCtor\Downloads\spybot-2.4.exe 2017-03-22 21:46 - 2017-03-23 15:08 - 00000000 ____D C:\AdwCleaner 2017-03-22 21:46 - 2017-03-22 21:46 - 04031440 _____ C:\Users\iNjeCtor\Downloads\adwcleaner_6.044.exe 2017-03-22 21:43 - 2017-03-22 21:45 - 00000000 ____D C:\ProgramData\SecTaskMan 2017-03-22 21:43 - 2017-03-22 21:43 - 02984912 _____ C:\Users\iNjeCtor\Downloads\SecurityTaskManager_Setup.exe 2017-03-22 21:43 - 2017-03-22 21:43 - 00001165 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spy Protector.lnk 2017-03-22 21:43 - 2017-03-22 21:43 - 00001154 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security Task Manager.lnk 2017-03-22 21:43 - 2017-03-22 21:43 - 00001142 _____ C:\Users\Public\Desktop\Security Task Manager.lnk 2017-03-22 21:43 - 2017-03-22 21:43 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2017-03-22 21:29 - 2017-03-22 21:40 - 138611937 _____ C:\Users\iNjeCtor\Desktop\720P_1500K_107646422.mp4 2017-03-22 19:48 - 2017-03-23 16:58 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-03-22 19:47 - 2017-03-22 19:47 - 22851472 _____ (Malwarebytes ) C:\Users\iNjeCtor\Downloads\mbam-setup-2.2.1.1043.exe 2017-03-22 19:47 - 2017-03-22 19:47 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2017-03-22 19:47 - 2017-03-22 19:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2017-03-22 19:47 - 2017-03-22 19:47 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-03-22 19:47 - 2017-03-22 19:47 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2017-03-22 19:47 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2017-03-22 19:47 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2017-03-22 19:47 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2017-03-22 19:32 - 2017-03-22 19:35 - 00000000 ____D C:\Users\iNjeCtor\Desktop\photo 2017-03-22 00:49 - 2017-03-22 21:22 - 00033946 _____ C:\Users\iNjeCtor\Desktop\Triangle wave.raw 2017-03-21 23:38 - 2017-03-21 23:39 - 00000470 _____ C:\Users\iNjeCtor\Downloads\Triangle wave.net 2017-03-21 23:36 - 2017-03-22 00:52 - 00001586 _____ C:\Users\iNjeCtor\Desktop\Triangle wave.asc 2017-03-21 23:30 - 2017-03-21 23:39 - 00033950 _____ C:\Users\iNjeCtor\Downloads\Triangle wave.raw 2017-03-21 23:30 - 2017-03-21 23:30 - 00001662 _____ C:\Users\iNjeCtor\Downloads\Triangle wave.asc 2017-03-21 23:29 - 2017-03-21 23:29 - 00001901 _____ C:\Users\iNjeCtor\Downloads\partc.asc 2017-03-21 23:26 - 2017-03-21 23:26 - 00002240 _____ C:\Users\iNjeCtor\Downloads\projet.raw 2017-03-21 23:26 - 2017-03-21 23:26 - 00002128 _____ C:\Users\iNjeCtor\Downloads\projet.asc 2017-03-21 23:26 - 2017-03-21 23:26 - 00001970 _____ C:\Users\iNjeCtor\Downloads\projet.op.raw 2017-03-21 16:08 - 2017-03-23 16:06 - 00000000 ____D C:\Users\iNjeCtor\AppData\Local\Seed4Me 2017-03-21 16:08 - 2017-03-21 16:08 - 00000963 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seed4Me.lnk 2017-03-21 16:06 - 2017-03-21 16:08 - 00000000 ____D C:\Program Files\Seed4.Me VPN 2017-03-21 16:05 - 2017-03-21 16:05 - 02233768 _____ C:\Users\iNjeCtor\Downloads\SharewareOnSale_Giveaway_Seed4.Me_VPN_hub.exe 2017-03-20 19:58 - 2017-03-20 19:59 - 03533136 _____ C:\Users\iNjeCtor\Desktop\17417455_1866543940287751_7038532489891020800_n.mp4 2017-03-20 19:18 - 2017-03-20 20:20 - 00000000 ____D C:\Users\iNjeCtor\Documents\xqsd 2017-03-18 22:24 - 2017-03-19 22:34 - 00000000 ____D C:\Users\Pu\AppData\Roaming\Apple Computer 2017-03-18 22:23 - 2017-03-23 03:26 - 00000000 ____D C:\Users\Pu\AppData\LocalLow\Mozilla 2017-03-18 22:23 - 2017-03-18 22:28 - 00000000 ____D C:\Users\Pu\AppData\Local\Mozilla 2017-03-18 22:23 - 2017-03-18 22:23 - 00001420 _____ C:\Users\Pu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2017-03-18 22:23 - 2017-03-18 22:23 - 00000020 ___SH C:\Users\Pu\ntuser.ini 2017-03-18 22:23 - 2017-03-18 22:23 - 00000000 _SHDL C:\Users\Pu\My Documents 2017-03-18 22:23 - 2017-03-18 22:23 - 00000000 _SHDL C:\Users\Pu\Documents\My Videos 2017-03-18 22:23 - 2017-03-18 22:23 - 00000000 _SHDL C:\Users\Pu\Documents\My Pictures 2017-03-18 22:23 - 2017-03-18 22:23 - 00000000 _SHDL C:\Users\Pu\Documents\My Music 2017-03-18 22:23 - 2017-03-18 22:23 - 00000000 ____D C:\Users\Pu\AppData\Roaming\Mozilla 2017-03-18 22:23 - 2017-03-18 22:23 - 00000000 ____D C:\Users\Pu\AppData\Roaming\Intel 2017-03-18 22:23 - 2017-03-18 22:23 - 00000000 ____D C:\Users\Pu\AppData\Roaming\Adobe 2017-03-18 22:23 - 2017-03-18 22:23 - 00000000 ____D C:\Users\Pu\AppData\Local\VirtualStore 2017-03-18 22:23 - 2017-03-18 22:23 - 00000000 ____D C:\Users\Pu\AppData\Local\Google 2017-03-18 22:23 - 2017-03-18 22:23 - 00000000 ____D C:\Users\Pu 2017-03-18 22:23 - 2011-04-12 09:28 - 00000000 ____D C:\Users\Pu\AppData\Roaming\Media Center Programs 2017-03-17 18:32 - 2017-03-22 21:41 - 00004150 _____ C:\Users\iNjeCtor\AppData\Roaming\LTspiceXVII.ini 2017-03-17 18:18 - 2017-03-17 18:19 - 21629898 _____ C:\Users\iNjeCtor\Downloads\تحدي الفلكة.mp4 2017-03-17 18:16 - 2017-03-21 23:25 - 00001327 _____ C:\Users\iNjeCtor\AppData\Roaming\Microsoft\Windows\Start Menu\LTspice XVII.lnk 2017-03-17 18:16 - 2017-03-18 02:42 - 00001057 _____ C:\Users\iNjeCtor\Desktop\LTspice XVII.lnk 2017-03-17 18:16 - 2017-03-17 18:32 - 00000000 ____D C:\Users\iNjeCtor\Documents\LTspiceXVII 2017-03-17 18:14 - 2017-03-17 18:14 - 00000000 ____D C:\Program Files\LTC 2017-03-17 18:09 - 2017-03-17 18:10 - 39533416 _____ (Linear Technology Corporation) C:\Users\iNjeCtor\Downloads\LTspiceXVII.exe 2017-03-16 22:59 - 2017-03-17 03:18 - 00000000 ____D C:\Users\iNjeCtor\Documents\pp 2017-03-16 22:41 - 2017-03-16 22:47 - 00000000 ____D C:\Users\iNjeCtor\Documents\Permue 2017-03-14 01:58 - 2017-03-14 01:58 - 00194726 _____ C:\Users\iNjeCtor\Desktop\Lettre de motivation-1.pdf 2017-03-14 01:55 - 2017-03-14 01:56 - 00393825 _____ C:\Users\iNjeCtor\Desktop\Relevé de ntoes.pdf 2017-03-14 01:52 - 2017-03-14 01:53 - 00171738 _____ C:\Users\iNjeCtor\Desktop\Doc1.pdf 2017-03-14 01:33 - 2017-03-14 02:20 - 00000000 ____D C:\Users\iNjeCtor\Desktop\candidature 2017-03-14 01:28 - 2017-03-14 01:28 - 00086531 _____ C:\Users\iNjeCtor\Downloads\sciences---master-2-images-et-systmes---spcialit-automatique-et-gnie-lectrique---st-jrme-765255.pdf 2017-03-14 00:45 - 2017-03-14 00:45 - 00543997 _____ C:\Users\iNjeCtor\Downloads\Passeport.pdf 2017-03-12 21:34 - 2017-03-12 23:35 - 00000000 ____D C:\Users\iNjeCtor\Documents\sdfsdfds 2017-03-12 21:31 - 2017-03-16 22:40 - 00000000 ____D C:\Program Files (x86)\CodeBlocks 2017-03-12 21:31 - 2017-03-16 22:39 - 00001098 _____ C:\Users\iNjeCtor\Desktop\CodeBlocks.lnk 2017-03-12 21:31 - 2017-03-12 21:32 - 00000000 ____D C:\Users\iNjeCtor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CodeBlocks 2017-03-12 21:24 - 2017-03-12 21:30 - 83783938 _____ (The Code::Blocks Team) C:\Users\iNjeCtor\Downloads\codeblocks-16.01mingw-setup.exe 2017-03-12 21:22 - 2017-03-12 21:23 - 34486727 _____ (The Code::Blocks Team) C:\Users\iNjeCtor\Downloads\codeblocks-16.01-setup(1).exe 2017-03-12 21:21 - 2017-03-12 21:22 - 00000000 ____D C:\Users\iNjeCtor\Documents\fsd 2017-03-12 21:15 - 2017-03-12 21:18 - 90574496 _____ (The Code::Blocks Team) C:\Users\iNjeCtor\Downloads\codeblocks-16.01mingw_fortran-setup.exe 2017-03-12 21:15 - 2017-03-12 21:17 - 00000000 ____D C:\Users\iNjeCtor\Documents\csdv 2017-03-12 21:14 - 2017-03-20 20:20 - 00000000 ____D C:\Users\iNjeCtor\AppData\Roaming\CodeBlocks 2017-03-12 21:14 - 2017-03-12 21:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CodeBlocks 2017-03-12 21:13 - 2017-03-12 21:14 - 34486727 _____ (The Code::Blocks Team) C:\Users\iNjeCtor\Downloads\codeblocks-16.01-setup.exe 2017-03-11 18:12 - 2017-03-11 18:12 - 00247033 _____ C:\Users\iNjeCtor\Desktop\CV et Lettre de Motivation(SALMI Mouad).zip 2017-03-10 22:37 - 2017-03-17 19:24 - 00004462 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2017-03-10 22:35 - 2017-03-10 22:36 - 01201256 _____ (Adobe Systems Incorporated) C:\Users\iNjeCtor\Downloads\flashplayer24pp_fa_install.exe 2017-03-10 16:25 - 2017-03-10 16:25 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01009.Wdf 2017-03-09 18:20 - 2017-03-09 18:22 - 00000000 ____D C:\Users\iNjeCtor\AppData\Roaming\Apple Computer 2017-03-09 18:20 - 2017-03-09 18:20 - 00001760 _____ C:\Users\Public\Desktop\iTunes.lnk 2017-03-09 18:20 - 2017-03-09 18:20 - 00000000 ____D C:\Users\iNjeCtor\AppData\Local\Apple Computer 2017-03-09 18:20 - 2017-03-09 18:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2017-03-09 18:18 - 2017-03-09 18:20 - 00000000 ____D C:\Program Files\iTunes 2017-03-09 18:18 - 2017-03-09 18:18 - 00000000 ____D C:\ProgramData\Apple Computer 2017-03-09 18:18 - 2017-03-09 18:18 - 00000000 ____D C:\Program Files\iPod 2017-03-09 18:14 - 2017-03-09 18:14 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2017-03-09 18:14 - 2017-03-09 18:14 - 00000000 ____D C:\Windows\System32\Tasks\Apple 2017-03-09 18:14 - 2017-03-09 18:14 - 00000000 ____D C:\Users\iNjeCtor\AppData\Local\Apple 2017-03-09 18:14 - 2017-03-09 18:14 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2017-03-09 18:12 - 2017-03-09 18:18 - 00000000 ____D C:\Program Files\Common Files\Apple 2017-03-09 18:11 - 2017-03-09 18:14 - 00000000 ____D C:\ProgramData\Apple 2017-03-07 17:04 - 2017-03-07 17:04 - 00002409 _____ C:\Users\iNjeCtor\Desktop\Ticket.htm 2017-03-07 17:04 - 2017-03-07 17:04 - 00000000 ____D C:\Users\iNjeCtor\Desktop\Ticket_fichiers 2017-03-05 18:48 - 2017-03-01 20:47 - 00000000 ____D C:\Users\iNjeCtor\Desktop\Notes 2017-03-05 18:48 - 2009-10-25 19:15 - 02292806 _____ C:\Users\iNjeCtor\Desktop\Windows 7 Loader.exe 2017-03-05 18:48 - 2009-10-25 16:43 - 00002582 _____ C:\Users\iNjeCtor\Desktop\Keys.ini 2017-03-05 18:47 - 2017-03-05 18:47 - 00205098 __RSH C:\HUBNV 2017-03-05 18:47 - 2017-03-05 18:47 - 00000020 __RSH C:\winx.ld 2017-03-05 17:36 - 2017-03-05 17:36 - 00032384 _____ C:\Users\iNjeCtor\Downloads\simple-blogger-templates.zip 2017-03-05 17:36 - 2016-12-25 05:44 - 00146496 _____ C:\Users\iNjeCtor\Desktop\simple-blogger-templates.xml 2017-03-05 17:23 - 2016-07-06 11:10 - 00112102 _____ C:\Users\iNjeCtor\Desktop\template-8051602698618030272.xml 2017-03-05 17:21 - 2017-03-05 17:21 - 00024089 _____ C:\Users\iNjeCtor\Downloads\قالب بلوغر مخصص للسيو.zip 2017-03-04 23:29 - 2017-03-04 23:29 - 01128960 _____ (Disk Wipe) C:\Users\iNjeCtor\Downloads\DiskWipe.exe 2017-03-04 22:07 - 2017-03-04 22:07 - 00000000 ____D C:\Windows\pss 2017-03-03 23:43 - 2017-03-03 23:43 - 00000000 ____D C:\Users\iNjeCtor\Tracing 2017-03-03 23:42 - 2017-03-04 22:09 - 00000000 ____D C:\Users\iNjeCtor\AppData\Roaming\Skype 2017-03-03 23:42 - 2017-03-03 23:42 - 00002697 _____ C:\Users\Public\Desktop\Skype.lnk 2017-03-03 23:42 - 2017-03-03 23:42 - 00000000 ___RD C:\Program Files (x86)\Skype 2017-03-03 23:42 - 2017-03-03 23:42 - 00000000 ____D C:\ProgramData\Skype 2017-03-03 23:42 - 2017-03-03 23:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2017-03-03 23:41 - 2017-03-03 23:41 - 00000000 ____D C:\ProgramData\Package Cache 2017-03-03 23:40 - 2017-03-03 23:40 - 01631200 _____ (Skype Technologies S.A.) C:\Users\iNjeCtor\Downloads\SkypeSetup.exe 2017-03-03 20:20 - 2017-03-03 20:20 - 00002243 _____ C:\Users\iNjeCtor\Downloads\num_PrePlainte.html 2017-03-02 16:16 - 2017-03-02 16:16 - 33087411 _____ C:\Users\iNjeCtor\Downloads\WA3.Abo3rab-V3.00.apk 2017-03-02 16:16 - 2017-03-02 16:16 - 33072800 _____ C:\Users\iNjeCtor\Downloads\WA2.Abo3rab-V3.00.apk 2017-03-02 16:16 - 2017-03-02 16:16 - 33070764 _____ C:\Users\iNjeCtor\Downloads\WA.Abo3rab-V3.00.apk 2017-03-02 03:11 - 2017-03-02 03:11 - 00000000 ____D C:\Users\iNjeCtor\Desktop\WhatsApp 2017-03-02 03:10 - 2017-03-02 03:10 - 00000000 ____D C:\Users\iNjeCtor\Desktop\ORG 2017-03-02 03:09 - 2017-03-02 03:10 - 00000000 ____D C:\Users\iNjeCtor\Desktop\GBWhatsApp3 2017-03-02 03:08 - 2017-03-02 03:08 - 00000000 ____D C:\Users\iNjeCtor\Desktop\GBWhatsapp 2017-03-02 03:07 - 2017-03-22 19:35 - 00000000 ____D C:\Users\iNjeCtor\Desktop\Facebook 2017-03-02 03:05 - 2017-03-02 03:05 - 00000000 ____D C:\Users\iNjeCtor\Desktop\DCIM 2017-03-02 03:02 - 2017-03-02 03:07 - 00000000 ____D C:\Users\iNjeCtor\Desktop\Camera 2017-03-02 03:02 - 2017-03-02 03:02 - 00000000 ____D C:\Users\iNjeCtor\Desktop\100AVIARY 2017-03-01 18:46 - 2017-03-01 18:46 - 00203673 _____ C:\Users\iNjeCtor\Desktop\biceps serie 1.pdf 2017-03-01 16:10 - 2017-03-01 16:10 - 00002085 _____ C:\Users\Public\Desktop\ImTOO Video Editor 2.lnk 2017-03-01 16:10 - 2017-03-01 16:10 - 00000000 ____D C:\Users\iNjeCtor\AppData\Roaming\ImTOO 2017-03-01 16:10 - 2017-03-01 16:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImTOO 2017-03-01 16:09 - 2017-03-01 16:09 - 00000000 ____D C:\ProgramData\ImTOO 2017-03-01 16:09 - 2017-03-01 16:09 - 00000000 ____D C:\Program Files (x86)\ImTOO 2017-03-01 16:05 - 2017-03-01 16:08 - 26094536 _____ C:\Users\iNjeCtor\Downloads\video-editor2.exe 2017-02-27 02:48 - 2017-02-27 02:52 - 334833913 _____ C:\Users\iNjeCtor\Desktop\10000000_1770296536621142_2883589588826193920_n.mp4 2017-02-26 00:05 - 2017-02-26 00:05 - 00616365 _____ C:\Users\iNjeCtor\Desktop\SDER + legs.pdf 2017-02-25 18:47 - 2017-02-25 18:48 - 00000000 ____D C:\Users\iNjeCtor\AppData\Roaming\Paltalk 2017-02-25 18:47 - 2017-02-25 18:47 - 00001994 _____ C:\Users\iNjeCtor\Desktop\Paltalk Messenger.lnk 2017-02-25 18:47 - 2017-02-25 18:47 - 00001232 _____ C:\Users\iNjeCtor\Desktop\Upgrade to Paltalk Extreme.lnk 2017-02-25 18:47 - 2017-02-25 18:47 - 00000000 ____D C:\Users\iNjeCtor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Paltalk Messenger 2017-02-25 18:47 - 2017-02-25 18:47 - 00000000 ____D C:\Program Files (x86)\Paltalk Messenger 2017-02-25 16:11 - 2017-02-25 16:11 - 00225237 _____ C:\Users\iNjeCtor\Desktop\(746899103) SALMI+Mouad+CV.pdf 2017-02-25 16:11 - 2017-02-25 16:11 - 00000000 ____D C:\Users\iNjeCtor\Documents\Modèles Office personnalisés 2017-02-25 15:54 - 2017-02-25 15:54 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform 2017-02-25 15:53 - 2017-02-25 15:53 - 00002883 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive Entreprise.lnk 2017-02-25 15:53 - 2017-02-25 15:53 - 00002862 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk 2017-02-25 15:53 - 2017-02-25 15:53 - 00002857 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype Entreprise 2016.lnk 2017-02-25 15:53 - 2017-02-25 15:53 - 00002833 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk 2017-02-25 15:53 - 2017-02-25 15:53 - 00002811 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk 2017-02-25 15:53 - 2017-02-25 15:53 - 00002805 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk 2017-02-25 15:53 - 2017-02-25 15:53 - 00002785 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk 2017-02-25 15:53 - 2017-02-25 15:53 - 00002777 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk 2017-02-25 15:53 - 2017-02-25 15:53 - 00002769 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk 2017-02-25 15:53 - 2017-02-25 15:53 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outils Microsoft Office 2016 2017-02-25 15:50 - 2017-02-25 15:50 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-02-25 15:48 - 2017-02-25 15:48 - 00000000 ____D C:\Program Files\Common Files\DESIGNER 2017-02-25 15:48 - 2017-02-25 15:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-02-25 15:47 - 2017-02-25 15:47 - 00000000 ____D C:\Windows\PCHEALTH 2017-02-25 15:47 - 2017-02-25 15:47 - 00000000 ____D C:\Program Files\Microsoft SQL Server 2017-02-25 15:47 - 2017-02-25 15:47 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server 2017-02-25 15:44 - 2017-02-25 15:52 - 00000000 ____D C:\Windows\SHELLNEW 2017-02-25 15:43 - 2017-02-25 15:43 - 00000000 ____D C:\Program Files\Microsoft Analysis Services 2017-02-25 15:43 - 2017-02-25 15:43 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services 2017-02-25 15:42 - 2017-02-25 15:47 - 00000000 ____D C:\Program Files\Microsoft Office 2017-02-25 15:42 - 2017-02-25 15:42 - 00000000 ____D C:\Users\iNjeCtor\AppData\Local\Microsoft Help 2017-02-25 15:42 - 2017-02-25 15:42 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-02-25 15:41 - 2017-02-25 15:59 - 00000000 ____D C:\Users\iNjeCtor\Desktop\تفعيل اوفيس 2016 2017-02-25 15:41 - 2017-02-25 15:41 - 00000000 __RHD C:\MSOCache 2017-02-25 15:39 - 2017-02-25 15:41 - 00000000 ____D C:\Users\iNjeCtor\Desktop\SW_DVD5_Office_Professional_Plus_2016_64Bit_French_MLF_X20-42435 2017-02-25 15:38 - 2015-10-09 19:30 - 1046243328 _____ C:\Users\iNjeCtor\Desktop\SW_DVD5_Office_Professional_Plus_2016_64Bit_French_MLF_X20-42435.ISO 2017-02-23 20:39 - 2017-03-10 00:16 - 00000000 ____D C:\Users\iNjeCtor\Desktop\Biceps Triceps 2017-02-23 20:11 - 2017-02-23 20:33 - 00000000 ____D C:\Users\iNjeCtor\Desktop\épaules 2017-02-23 19:58 - 2017-02-23 20:07 - 00000000 ____D C:\Users\iNjeCtor\Desktop\SDER 2017-02-21 21:46 - 2017-02-21 21:54 - 00000000 ____D C:\Users\iNjeCtor\AppData\Roaming\TeamViewer 2017-02-21 21:46 - 2017-02-21 21:46 - 00001050 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk 2017-02-21 21:46 - 2017-02-21 21:46 - 00001038 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk 2017-02-21 21:46 - 2017-02-21 21:46 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2017-02-21 21:45 - 2017-02-21 21:45 - 12972920 _____ (TeamViewer GmbH) C:\Users\iNjeCtor\Downloads\TeamViewer_Setup_fr.exe ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-03-23 16:57 - 2009-07-14 05:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-03-23 16:57 - 2009-07-14 05:45 - 00026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-03-23 16:06 - 2017-02-04 04:50 - 00000000 ____D C:\Users\iNjeCtor\AppData\LocalLow\Mozilla 2017-03-23 16:04 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-03-23 14:59 - 2017-02-04 04:40 - 00003266 _____ C:\Windows\System32\Tasks\Driver Booster Scheduler 2017-03-23 14:59 - 2017-02-04 04:40 - 00002283 _____ C:\Users\Public\Desktop\Driver Booster 4.lnk 2017-03-23 14:59 - 2017-02-04 04:40 - 00000000 ____D C:\ProgramData\IObit 2017-03-23 14:58 - 2017-02-04 04:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 4 2017-03-21 16:10 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries 2017-03-21 16:07 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf 2017-03-20 16:48 - 2009-07-14 06:08 - 00032636 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2017-03-18 18:33 - 2017-02-05 18:03 - 00000000 ____D C:\Program Files\Mozilla Firefox 2017-03-18 18:33 - 2017-02-05 18:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-03-18 05:36 - 2017-02-04 05:27 - 00000000 ____D C:\Users\iNjeCtor\AppData\Roaming\vlc 2017-03-17 19:24 - 2017-02-04 05:06 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-03-17 19:24 - 2017-02-04 05:06 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-03-17 19:24 - 2017-02-04 05:06 - 00004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-03-17 19:24 - 2017-02-04 05:05 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-03-17 19:24 - 2017-02-04 05:05 - 00000000 ____D C:\Windows\system32\Macromed 2017-03-12 21:13 - 2017-02-09 03:18 - 00000000 ____D C:\Users\iNjeCtor\AppData\Roaming\DMCache 2017-03-10 22:37 - 2017-02-04 05:00 - 00000000 ____D C:\Users\iNjeCtor\AppData\Local\Adobe 2017-03-05 17:37 - 2017-02-10 22:51 - 00000000 ____D C:\Program Files\Opera 2017-03-03 23:43 - 2017-02-04 04:25 - 00000000 ____D C:\Users\iNjeCtor 2017-03-02 16:13 - 2017-02-10 22:52 - 00003840 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1486763538 2017-02-26 17:17 - 2016-06-20 06:53 - 00713824 _____ C:\Windows\system32\perfh019.dat 2017-02-26 17:17 - 2016-06-20 06:53 - 00148866 _____ C:\Windows\system32\perfc019.dat 2017-02-26 17:17 - 2009-07-14 06:13 - 01640642 _____ C:\Windows\system32\PerfStringBackup.INI 2017-02-26 15:35 - 2009-07-14 05:45 - 00425048 _____ C:\Windows\system32\FNTCACHE.DAT 2017-02-25 15:58 - 2017-02-04 04:39 - 00111128 _____ C:\Users\iNjeCtor\AppData\Local\GDIPFONTCACHEV1.DAT 2017-02-25 15:52 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2017-02-25 15:44 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\System 2017-02-25 15:44 - 2009-07-14 03:34 - 00000478 _____ C:\Windows\win.ini 2017-02-21 02:40 - 2017-02-09 03:18 - 00000000 ____D C:\Users\iNjeCtor\Downloads\Compressed ==================== Files in the root of some directories ======= 2017-03-17 18:32 - 2017-03-22 21:41 - 0004150 _____ () C:\Users\iNjeCtor\AppData\Roaming\LTspiceXVII.ini 2017-02-04 05:51 - 2017-02-04 05:51 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-03-16 23:50 ==================== End of FRST.txt ============================