¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Scan | g3n-h@ckm@n | V9_18.10.19.1 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ¤¤¤¤¤ XP | Vista | 7 | 8 - 32/64 bits ¤¤¤¤¤ - Start 12:31:48 03/29/2022 Updated 18/10/2019 | 07:30 (GMT) by g3n-h@ckm@n Contact : http://www.sosvirus.net/ Pre_scan Feedbacks : http://www.sosvirus.net/feedback-t74962.html [Jean Marie CARRIBON (Administrator)] - [DESKTOP-NA2IIKJ] SID = S-1-5-21-2982999039-1405869219-2042017926-1001 Boot: Normal boot System : Windows 10 Home (64 bits) Core ProcessorNameString : AMD E2-7110 APU with AMD Radeon R2 Graphics Identifier : AMD64 Family 22 Model 48 Stepping 1 CoreTemp : 30 Celsius - Max : 90 Celsius Memory RAM = Total (MB) : 3595 | Free (MB) : 1445 Pagefile = Total (MB) : 7128 | Free (MB) : 4754 Virtual = Total (MB) : 4194 | Free (MB) : 3958 ¤¤¤¤¤¤¤¤¤¤ # Components of starting up ¤¤¤¤¤¤¤¤¤¤¤ # Drives F:\-> [Removable] | [] | Total : 14.63 Go | Free : 0.13 Go -> FAT32 [USB] E:\-> [CDROM] | [WebPlus X7] | Total : 0.37 Go | Free : 0 Go -> CDFS [SATA] C:\-> [Fixed] | [WINDOWS 10 FAMILLE 64 BITS] | Total : 930.91 Go | Free : 770.62 Go -> NTFS [SATA] ¤¤¤¤¤¤¤¤¤¤ # Windows updates Windows Is Activated ¤¤¤¤¤¤¤¤¤¤ # Sessions C:\WINDOWS\system32\config\systemprofile C:\WINDOWS\ServiceProfiles\LocalService C:\WINDOWS\ServiceProfiles\NetworkService C:\Users\Jean Marie CARRIBON Registry saved , to restore : Shortcut on the desktop 'Pre_Scan_Restore' Restore the register (C:\Pre_Scan\Save\Registry [29.03.2022 @ 12_26_29]) To restore File or Folder : Shortcut on the desktop 'Pre_Scan_Restore' , select 'restore File - Folder' , select an Item and click on Restore ¤¤¤¤¤¤¤¤¤¤ # Browsers IE : 11.0.19041.1566 (© Microsoft Corporation.) GC : 99.0.4844.84 (Copyright 2022 Google LLC.) ¤¤¤¤¤¤¤¤¤¤ # FlashPlayer ActiveX : 11.6.602.168 ���������� # Security AV : COMODO Antivirus Disabled AS : Windows Defender Enabled FW : WMI : OK WU: Windows Update Service [Auto(2)] = Running AS: Windows Defender [Auto(2)] = Running FW: Windows FireWall Service [Auto(2)] = Running ¤¤¤¤¤¤¤¤¤¤ # Stopped processes 1936 | [Owner : |Parent : 904] - (.AMD - AMD External Events Service Module.) - (27.20.1034.6) = C:\Windows\System32\DriverStore\FileRepository\c0360470.inf_amd64_b06c374aee20d185\B360357\atiesrxx.exe 2140 | [Owner : |Parent : 1936] - (.AMD - AMD External Events Client Module.) - (27.20.1034.6) = C:\Windows\System32\DriverStore\FileRepository\c0360470.inf_amd64_b06c374aee20d185\B360357\atieclxx.exe 2808 | [Owner : |Parent : 904] - (.Realtek Semiconductor - Realtek Audio Service.) - (1.0.0.88) = C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe 2896 | [Owner : |Parent : 2808] - (.Realtek Semiconductor - HD Audio Background Process.) - (1.0.0.295) = C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe 2904 | [Owner : |Parent : 2808] - (.Realtek Semiconductor - HD Audio Background Process.) - (1.0.0.295) = C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe 1964 | [Owner : |Parent : 904] - (.Microsoft Corporation - Application sous-système spouleur.) - (10.0.19041.1566) = C:\Windows\System32\spoolsv.exe 3328 | [Owner : Système |Parent : 904] - (.Apple Inc. - Bonjour Service.) - (3.0.0.10) = C:\Program Files\Bonjour\mDNSResponder.exe 3380 | [Owner : Système |Parent : 904] - (.Seiko Epson Corporation - Epson Scanner Service (64bit).) - (1.1.0.1) = C:\Windows\System32\escsvc64.exe 3428 | [Owner : Système |Parent : 904] - (. - .) - (0.0.0.0) = C:\Program Files\MiniTool ShadowMaker\SchedulerService.exe 3436 | [Owner : Système |Parent : 904] - (. - .) - (0.0.0.0) = C:\Program Files\MiniTool ShadowMaker\AgentService.exe 3456 | [Owner : Système |Parent : 904] - (.Seiko Epson Corporation - MyEpson Portal Service.) - (1.0.3.3) = C:\Program Files (x86)\epson\MyEpson Portal\mepService.exe 3476 | [Owner : Système |Parent : 904] - (.Realtek Semiconductor Corp. - Realtek Bluetooth BTDevManager Service Application.) - (1.1.26.1) = C:\Windows\RtkBtManServ.exe 3756 | [Owner : Système |Parent : 904] - (.Nuance Communications, Inc. - Dragon NaturallySpeaking Service.) - (13.0.0.589) = C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe 4016 | [Owner : Système |Parent : 904] - (.Nuance Communications, Inc. - Dragon NaturallySpeaking Logging Service.) - (13.0.0.589) = C:\Program Files (x86)\Common Files\Nuance\loggerservice.exe 1292 | [Owner : Jean Marie CARRIBON |Parent : 3456] - (.Seiko Epson Corporation - MyEpson Portal.) - (1.1.3.6) = C:\Program Files (x86)\epson\MyEpson Portal\mep.exe 4520 | [Owner : Jean Marie CARRIBON |Parent : 1308] - (.Microsoft Corporation - Shell Infrastructure Host.) - (10.0.19041.746) = C:\Windows\System32\sihost.exe 1720 | [Owner : Jean Marie CARRIBON |Parent : 904] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.1566) = C:\Windows\System32\svchost.exe 4856 | [Owner : Jean Marie CARRIBON |Parent : 1308] - (.Microsoft Corporation - Processus hôte pour Tâches Windows.) - (10.0.19041.1503) = C:\Windows\System32\taskhostw.exe 1464 | [Owner : Jean Marie CARRIBON |Parent : 4452] - (.Microsoft Corporation - Explorateur Windows.) - (10.0.19041.1586) = C:\Windows\explorer.exe 5124 | [Owner : Jean Marie CARRIBON |Parent : 1344] - (.Microsoft Corporation - Chargeur CTF.) - (10.0.19041.1) = C:\Windows\System32\ctfmon.exe 5592 | [Owner : Aucun |Parent : 4888] - (.Microsoft Corporation - Outil de configuration du Planificateur de tâches.) - (10.0.19041.1503) = C:\Windows\System32\schtasks.exe 5600 | [Owner : Aucun |Parent : 5592] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.19041.1566) = C:\Windows\System32\conhost.exe 5708 | [Owner : Jean Marie CARRIBON |Parent : 904] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.1566) = C:\Windows\System32\svchost.exe 5300 | [Owner : Système |Parent : 4880] - (.Google LLC - Google Crash Handler.) - (1.3.36.121) = C:\Program Files (x86)\Google\Update\1.3.36.122\GoogleCrashHandler.exe 5216 | [Owner : Système |Parent : 4880] - (.Google LLC - Google Crash Handler.) - (1.3.36.121) = C:\Program Files (x86)\Google\Update\1.3.36.122\GoogleCrashHandler64.exe 5808 | [Owner : Jean Marie CARRIBON |Parent : 692] - (. - .) - (0.0.0.0) = C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe 5752 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe 6252 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe 6940 | [Owner : Aucun |Parent : 4956] - (. - .) - (0.0.0.0) = C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe 6884 | [Owner : Jean Marie CARRIBON |Parent : 1308] - (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) - (1.0.693.0) = C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe 6384 | [Owner : Jean Marie CARRIBON |Parent : 1464] - (.Microsoft Corporation - Windows Security notification icon.) - (10.0.19041.1) = C:\Windows\System32\SecurityHealthSystray.exe 6416 | [Owner : |Parent : 904] - (.Microsoft Corporation - Windows Security Health Service.) - (4.18.1907.16384) = C:\Windows\System32\SecurityHealthService.exe 6516 | [Owner : Jean Marie CARRIBON |Parent : 1464] - (.Acronis International GmbH - Acronis Scheduler Service Helper.) - (8.0.1.11450) = C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe 1884 | [Owner : Jean Marie CARRIBON |Parent : 1464] - (.Seiko Epson Corporation - Epson Software Updater.) - (1.0.0.0) = C:\Program Files (x86)\Epson Software\Download Navigator\EPSDNMON.EXE 8052 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Flexera Software LLC. - FLEXnet Connect Agent.) - (13.6.100.64627) = C:\ProgramData\FLEXnet\Connect\11\agent.exe 7868 | [Owner : Jean Marie CARRIBON |Parent : 1464] - (.ASIP SANTE - Gestionnaire de certificats CPS WIN 64 (Version Release).) - (3.13.0.0) = C:\Program Files\santesocial\CPS\CCM.exe 8244 | [Owner : Jean Marie CARRIBON |Parent : 7852] - (.SEIKO EPSON CORPORATION - Fax Reception.) - (3.0.2.1) = C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe 8264 | [Owner : Jean Marie CARRIBON |Parent : 7852] - (.SEIKO EPSON CORPORATION - Fax Transmission.) - (3.0.2.1) = C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe 8356 | [Owner : Jean Marie CARRIBON |Parent : 7852] - (.SEIKO EPSON CORPORATION - EEventManager Application.) - (3.2.0.0) = C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe 8432 | [Owner : Jean Marie CARRIBON |Parent : 7852] - (. - .) - (4.0.0.4) = C:\Ariane\Ariane\Ariane.exe 8460 | [Owner : Jean Marie CARRIBON |Parent : 7868] - (.GIE SESAM VITALE - ASIP SANTE - Serveur du Gestionnaire d'Acces au Lecteur WIN 64 sur NP (RELEASE) .) - (3.42.0.0) = C:\Program Files\santesocial\galss\galsvw64.exe 8544 | [Owner : Jean Marie CARRIBON |Parent : 1464] - (. - Outil de reconnexion pour le Vital'Act-3S.) - (1.1.1.0) = C:\Program Files (x86)\XIRING\V3S Reconnexion\V3S_Reconnexion.exe 2492 | [Owner : Jean Marie CARRIBON |Parent : 904] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.1566) = C:\Windows\System32\svchost.exe 8284 | [Owner : |Parent : 904] - (.Microsoft Corporation - Service Broker du moniteur d'exécution System Guard.) - (10.0.19041.546) = C:\Windows\System32\SgrmBroker.exe 6784 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Application Frame Host.) - (10.0.19041.746) = C:\Windows\System32\ApplicationFrameHost.exe 8656 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - .) - (121.9202.4105.0) = C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe 6636 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - User OOBE Broker.) - (10.0.19041.746) = C:\Windows\System32\oobe\UserOOBEBroker.exe 5604 | [Owner : |Parent : 904] - (.Microsoft Corporation - Antimalware Service Executable.) - (4.18.2202.4) = C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MsMpEng.exe 6448 | [Owner : Aucun |Parent : 1308] - (.Microsoft Corporation - Processus hôte pour Tâches Windows.) - (10.0.19041.1503) = C:\Windows\System32\taskhostw.exe 1320 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Explorateur Windows.) - (10.0.19041.1586) = C:\Windows\explorer.exe 8968 | [Owner : Jean Marie CARRIBON |Parent : 904] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.1566) = C:\Windows\System32\svchost.exe 5896 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe 5052 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - System Settings Broker.) - (10.0.19041.746) = C:\Windows\System32\SystemSettingsBroker.exe 2844 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Paramètres.) - (10.0.19041.1566) = C:\Windows\ImmersiveControlPanel\SystemSettings.exe 8992 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe 7812 | [Owner : |Parent : 5604] - (.Microsoft Corporation - Microsoft Malware Protection Copy Accelerator Utility.) - (4.18.2202.4) = C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2202.4-0\MpCopyAccelerator.exe 4328 | [Owner : Jean Marie CARRIBON |Parent : 904] - (.Microsoft Corporation - Processus hôte pour les services Windows.) - (10.0.19041.1566) = C:\Windows\System32\svchost.exe 6692 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Explorateur Windows.) - (10.0.19041.1586) = C:\Windows\explorer.exe 5316 | [Owner : Jean Marie CARRIBON |Parent : 9080] - (.Flexera Software LLC. - Common Software Manager.) - (13.6.0.62600) = C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe 2472 | [Owner : Système |Parent : 692] - (.Microsoft Corporation - MoUSO Core Worker Process.) - (10.0.19041.1503) = C:\Windows\System32\MoUsoCoreWorker.exe 7368 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Component Package Support Server.) - (10.0.19041.746) = C:\Windows\System32\CompPkgSrv.exe 3732 | [Owner : Aucun |Parent : 8292] - (.Piriform Software Ltd - CCleaner.) - (5.91.0.9537) = C:\Program Files\CCleaner\CCleaner64.exe 5288 | [Owner : Jean Marie CARRIBON |Parent : 692] - (. - .) - (10.22011.1003.0) = C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.22011.10031.0_x64__8wekyb3d8bbwe\Video.UI.exe 6360 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe 9976 | [Owner : Jean Marie CARRIBON |Parent : 4336] - (.Mozilla Corporation - Firefox.) - (98.0.1.8107) = C:\Program Files\Mozilla Firefox\tobedeleted\rep6c4dcc7f-32e9-4815-a3df-1209e157a0ac 1412 | [Owner : Système |Parent : 904] - (.Adobe Inc. - Adobe Acrobat Update Service.) - (1.824.45.8876) = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 9940 | [Owner : LogonSessionId_0_525631817 |Parent : 904] - (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - (7.0.19041.1566) = C:\Windows\System32\SearchIndexer.exe 6064 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - .) - (1.22022.147.0) = C:\Program Files\WindowsApps\Microsoft.YourPhone_1.22022.147.0_x64__8wekyb3d8bbwe\YourPhone.exe 7992 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe 2440 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Cortana.) - (3.2202.10603.0) = C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2202.10603.0_x64__8wekyb3d8bbwe\Cortana.exe 2708 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Runtime Broker.) - (10.0.19041.746) = C:\Windows\System32\RuntimeBroker.exe 9936 | [Owner : Jean Marie CARRIBON |Parent : 7228] - (.Microsoft Corporation - Microsoft Edge.) - (99.0.1150.55) = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe 6284 | [Owner : Jean Marie CARRIBON |Parent : 9936] - (.Microsoft Corporation - Microsoft Edge.) - (99.0.1150.55) = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe 7564 | [Owner : Jean Marie CARRIBON |Parent : 9936] - (.Microsoft Corporation - Microsoft Edge.) - (99.0.1150.55) = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe 6100 | [Owner : Jean Marie CARRIBON |Parent : 9936] - (.Microsoft Corporation - Microsoft Edge.) - (99.0.1150.55) = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe 6772 | [Owner : Jean Marie CARRIBON |Parent : 9936] - (.Microsoft Corporation - Microsoft Edge.) - (99.0.1150.55) = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe 7984 | [Owner : Jean Marie CARRIBON |Parent : 6700] - (.Mozilla Corporation - Firefox.) - (98.0.2.8116) = C:\Program Files\Mozilla Firefox\firefox.exe 3416 | [Owner : Jean Marie CARRIBON |Parent : 7984] - (.Mozilla Corporation - Firefox.) - (98.0.2.8116) = C:\Program Files\Mozilla Firefox\firefox.exe 3048 | [Owner : Jean Marie CARRIBON |Parent : 7984] - (.Mozilla Corporation - Firefox.) - (98.0.2.8116) = C:\Program Files\Mozilla Firefox\firefox.exe 10684 | [Owner : SERVICE LOCAL |Parent : 904] - (.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes en mode utilisateur.) - (10.0.19041.1466) = C:\Windows\System32\WUDFHost.exe 10932 | [Owner : Aucun |Parent : 7984] - (.Akeo Consulting - Rufus.) - (3.18.1877.0) = C:\Users\Jean Marie CARRIBON\Downloads\rufus-3.18.exe 2792 | [Owner : Aucun |Parent : 1084] - (. - Usb Anti-Malware.) - (11.0.4.2) = C:\Program Files (x86)\UsbFix\UsbFix.exe 7856 | [Owner : Aucun |Parent : 1308] - (. - Real Time Protection for UsbFix Anti-Malware Professionnal.) - (10.0.3.3) = C:\Program Files (x86)\UsbFix\Modules\UsbFixMonitor.exe 2268 | [Owner : Aucun |Parent : 2792] - (.Microsoft Corporation - Bloc-notes.) - (10.0.19041.1) = C:\Windows\System32\notepad.exe 9816 | [Owner : Jean Marie CARRIBON |Parent : 7984] - (.Mozilla Corporation - Firefox.) - (98.0.2.8116) = C:\Program Files\Mozilla Firefox\firefox.exe 7388 | [Owner : Aucun |Parent : 7984] - (.Lavasoft Limited - AdAware Installer.) - (10.5.3.4405) = C:\Users\Jean Marie CARRIBON\Downloads\ad-aware-free-10-5-3-es-en-win.exe 11720 | [Owner : Jean Marie CARRIBON |Parent : 7984] - (.Mozilla Corporation - Firefox.) - (98.0.2.8116) = C:\Program Files\Mozilla Firefox\firefox.exe 12164 | [Owner : Jean Marie CARRIBON |Parent : 7984] - (.Mozilla Corporation - Firefox.) - (98.0.2.8116) = C:\Program Files\Mozilla Firefox\firefox.exe 2508 | [Owner : Jean Marie CARRIBON |Parent : 1464] - (.Microsoft Corporation - Windows PowerShell.) - (10.0.19041.546) = C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 4380 | [Owner : Jean Marie CARRIBON |Parent : 2508] - (.Microsoft Corporation - Hôte de la fenêtre de la console.) - (10.0.19041.1566) = C:\Windows\System32\conhost.exe 2332 | [Owner : Jean Marie CARRIBON |Parent : 1464] - (. - .) - (3.80.0.0) = C:\Program Files (x86)\WinRAR\WinRAR.exe 2160 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Explorateur Windows.) - (10.0.19041.1586) = C:\Windows\explorer.exe 10492 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Windows Defender application.) - (10.0.19041.1566) = C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe 8132 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Windows Security Health Host.) - (4.18.1907.16384) = C:\Windows\System32\SecurityHealthHost.exe 7496 | [Owner : Jean Marie CARRIBON |Parent : 692] - (.Microsoft Corporation - Windows Defender SmartScreen.) - (10.0.19041.1566) = C:\Windows\System32\smartscreen.exe 1996 | [Owner : Aucun |Parent : 692] - (.Microsoft Corporation - Windows Security Health Host.) - (4.18.1907.16384) = C:\Windows\System32\SecurityHealthHost.exe 11096 | [Owner : Système |Parent : 9940] - (.Microsoft Corporation - Microsoft Windows Search Protocol Host.) - (7.0.19041.1566) = C:\Windows\System32\SearchProtocolHost.exe ¤¤¤¤¤¤¤¤¤¤ # Winlogon user ¤¤¤¤¤¤¤¤¤¤ # Winlogon machine ¤¤¤¤¤¤¤¤¤¤ # SafeBoot Safeboot Keys are O.K Alternate shell is OK ! � ¤¤¤¤¤¤¤¤¤¤ | Winsock ¤¤¤¤¤¤¤¤¤¤ # IFEO ¤¤¤¤¤¤¤¤¤¤ # Mountpoints2 ¤¤¤¤¤¤¤¤¤¤ # Windows [HKLM\Software\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot]~[Shell] : SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\Software\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini]~[winlogon] : SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot]~[Shell] : SYS:Microsoft\Windows NT\CurrentVersion\Winlogon ¤¤¤¤¤¤¤¤¤¤ # Security center ¤¤¤¤¤¤¤¤¤¤ # Services Repaired : [HKLM\SYSTEM\CurrentControlSet\Services\Bits]~[Start] : 3 -> 2 ¤¤¤¤¤¤¤¤¤¤ # Internet Explorer ¤¤¤¤¤¤¤¤¤¤ # reparsepoint ¤¤¤¤¤¤¤¤¤¤ # Offsets ¤¤¤¤¤¤¤¤¤¤ # Files | Folders | Registry Moved to quarantine successfully : C:\$Recycle.bin\S-1-5-21-2982999039-1405869219-2042017926-1001\$IIW7TRV.dll Moved to quarantine successfully : C:\$Recycle.bin\S-1-5-21-2982999039-1405869219-2042017926-1001\$IO7YFT7.exe Moved to quarantine successfully : C:\$Recycle.bin\S-1-5-21-2982999039-1405869219-2042017926-1001\$IOH13W5.exe Moved to quarantine successfully : C:\$Recycle.bin\S-1-5-21-2982999039-1405869219-2042017926-1001\$IOZPX6D.exe Moved to quarantine successfully : C:\$Recycle.bin\S-1-5-21-2982999039-1405869219-2042017926-1001\$RIW7TRV.dll Moved to quarantine successfully : C:\$Recycle.bin\S-1-5-21-2982999039-1405869219-2042017926-1001\$RO7YFT7.exe Moved to quarantine successfully : C:\$Recycle.bin\S-1-5-21-2982999039-1405869219-2042017926-1001\$ROH13W5.exe Moved to quarantine successfully : C:\$Recycle.bin\S-1-5-21-2982999039-1405869219-2042017926-1001\$ROZPX6D.exe Deleted : [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]~[MTPW] : "C:\Program Files\MiniTool Partition Wizard 12\updatechecker.exe" Moved to quarantine successfully : F:\Wireshark-win64-3.4.4.exe Moved to quarantine successfully : F:\pdf-bates.exe Moved to quarantine successfully : F:\css_installer.exe Moved to quarantine successfully : F:\QuickDiag.exe Moved to quarantine successfully : F:\OTM.exe Moved to quarantine successfully : F:\quickdiag_V5_29.10.19.1.exe Moved to quarantine successfully : F:\DriverPack-17-Online.exe Will be moved in quarantine at reboot : C:\DumpStack.log.tmp Will be moved in quarantine at reboot : C:\DumpStack.log.tmp ¤¤¤¤¤¤¤¤¤¤ # ADS Deleted : C:\ProgramData\Temp:0FF263E8 ¤¤¤¤¤¤¤¤¤¤ # Prefetch cleaned ¤¤¤¤¤¤¤¤¤¤ | Hidden files ~ [Drive C:] : Hidden : 3 | Restored : 2 ~ [Program Files] : Hidden : 62 | Restored : 62 ~ [Pictures] : Hidden : 1 | Restored : 1 ~ [Windows] : Hidden : 13 | Restored : 10 ~ [AppData] : Hidden : 3 | Restored : 3 End : 13:58:53 ¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤ - 260