Vous pensez être infecté, des pubs s'affichent quand vous naviguez sur internet ?
Perte de données, ralentissement système, virus USB ?
Désinfectez votre ordinateur gratuitement !
  • Avatar du membre
  • Avatar du membre
Avatar du membre
par lcemegane
#18333
Merci beaucoup pour votre aide, voici le début du rapport OTL.txt ( je n'arrive pas à  le mettre sur sosupload)

OTL logfile created on: 21/11/2013 18:22:10 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Mégane\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16736)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

5,89 Gb Total Physical Memory | 4,36 Gb Available Physical Memory | 74,01% Memory free
6,83 Gb Paging File | 4,85 Gb Available in Paging File | 71,04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279,45 Gb Total Space | 212,66 Gb Free Space | 76,10% Space Free | Partition Type: NTFS
Drive D: | 397,87 Gb Total Space | 397,62 Gb Free Space | 99,94% Space Free | Partition Type: NTFS

Computer Name: PC-MEGANE | User Name: Mégane | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/11/20 22:41:02 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Mégane\Desktop\OTL.exe
PRC - [2013/11/14 12:29:33 | 000,863,184 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2013/10/10 18:24:51 | 000,621,448 | ---- | M] (Bitdefender) -- C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe
PRC - [2013/09/22 22:19:42 | 002,258,056 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe
PRC - [2013/09/22 22:19:42 | 000,369,800 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\Microsoft\BingDesktop\BDRuntimeHost.exe
PRC - [2013/09/22 22:19:42 | 000,207,496 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\Microsoft\BingDesktop\BDExtHost.exe
PRC - [2013/09/22 22:19:42 | 000,173,192 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
PRC - [2013/09/22 22:19:42 | 000,153,224 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\Microsoft\BingDesktop\BDAppHost.exe
PRC - [2013/09/05 15:04:00 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/04/16 17:25:30 | 000,020,792 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
PRC - [2013/02/26 11:08:24 | 000,176,240 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
PRC - [2013/02/14 10:14:08 | 001,260,320 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012/11/28 17:56:40 | 000,054,488 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
PRC - [2012/10/26 14:35:44 | 000,184,704 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
PRC - [2012/10/24 15:02:32 | 001,196,416 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe
PRC - [2012/10/17 19:08:40 | 000,205,184 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
PRC - [2012/10/05 15:55:50 | 000,110,976 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
PRC - [2012/09/18 12:51:54 | 001,124,032 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
PRC - [2012/09/14 13:14:16 | 000,328,064 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
PRC - [2012/08/31 19:27:20 | 000,590,208 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
PRC - [2012/08/22 09:24:28 | 001,559,936 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
PRC - [2012/07/17 14:57:22 | 000,365,376 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2012/07/17 14:57:20 | 000,277,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2012/06/27 12:47:02 | 000,129,856 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
PRC - [2012/06/25 10:57:14 | 000,166,720 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
PRC - [2012/05/28 10:04:48 | 000,113,312 | ---- | M] (ASUSTek Computer Inc.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
PRC - [2012/05/14 16:26:32 | 002,646,504 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe
PRC - [2012/04/24 14:37:56 | 000,169,752 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
PRC - [2012/04/13 10:14:00 | 000,277,120 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
PRC - [2012/03/28 18:34:30 | 000,091,432 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2011/11/21 14:19:50 | 000,096,896 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
PRC - [2011/03/09 13:21:54 | 000,107,816 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe


========== Modules (No Company Name) ==========

MOD - [2013/11/14 12:29:31 | 000,399,312 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppgooglenaclpluginchrome.dll
MOD - [2013/11/14 12:29:29 | 004,055,504 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll
MOD - [2013/11/14 12:28:37 | 000,702,416 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\libglesv2.dll
MOD - [2013/11/14 12:28:36 | 000,099,792 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\libegl.dll
MOD - [2013/11/14 12:28:34 | 001,619,408 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll
MOD - [2013/09/13 18:51:44 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2013/09/13 18:51:20 | 001,242,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2013/06/19 12:44:37 | 000,204,280 | ---- | M] () -- C:\Program Files\Bitdefender\Bitdefender\antispam32\txmlutil.dll
MOD - [2011/03/09 13:21:56 | 000,619,816 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
MOD - [2011/03/09 13:21:56 | 000,144,680 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLVistaAudioMixer.dll
MOD - [2011/03/09 13:21:48 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
MOD - [2010/10/11 17:15:28 | 001,873,192 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\Language\Fra\P2GRC.dll


========== Services (SafeList) ==========

SRV - [2013/09/22 22:19:42 | 000,173,192 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe -- (BingDesktopUpdate)
SRV - [2013/09/05 15:04:00 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/02/14 10:14:08 | 001,260,320 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012/12/13 23:14:24 | 000,277,616 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2012/11/27 13:56:51 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2012/10/05 15:55:50 | 000,110,976 | ---- | M] (ASUSTek Computer Inc.) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe -- (ASLDRService)
SRV - [2012/09/13 04:59:08 | 002,466,448 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)
SRV - [2012/07/26 04:20:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2012/07/17 14:57:22 | 000,365,376 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2012/07/17 14:57:20 | 000,277,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2012/06/27 12:47:02 | 000,129,856 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe -- (Intel(R)
SRV - [2012/06/25 10:57:14 | 000,166,720 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
SRV - [2012/04/24 14:37:56 | 000,169,752 | ---- | M] (Intel Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe -- (ICCS)
SRV - [2012/04/13 10:14:00 | 000,277,120 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe -- (ASUS InstantOn)
SRV - [2011/11/21 14:19:50 | 000,096,896 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv)


========== Driver Services (SafeList) ==========

DRV - [2011/09/07 09:55:04 | 000,017,536 | ---- | M] (ASUS) [Kernel | System | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys -- (ATKWMIACPIIO)
DRV - [2009/07/02 17:36:14 | 000,015,416 | ---- | M] (ASUS) [Kernel | Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys -- (ASMMAP64)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q=" onclick="window.open(this.href);return false;{searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-1305010613-2064220777-3922521960-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-1305010613-2064220777-3922521960-1001\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1305010613-2064220777-3922521960-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1305010613-2064220777-3922521960-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-1305010613-2064220777-3922521960-1002\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1305010613-2064220777-3922521960-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1305010613-2064220777-3922521960-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Bitdefender.com/PasswordManager;version=17.8: C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxnp.dll (Bitdefender)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ffpwdman@bitdefender.com: C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman\ [2013/10/17 18:47:05 | 000,000,000 | ---D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - Extension: Documents Google = C:\Users\Mégane\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google\u00A0Drive = C:\Users\Mégane\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Mégane\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Bitdefender Wallet = C:\Users\Mégane\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccahoghmggldkcdjiebjkidpfongdfbl\17.19.0_0\
CHR - Extension: Recherche Google = C:\Users\Mégane\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google\u00A0Wallet = C:\Users\Mégane\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0\
CHR - Extension: Gmail = C:\Users\Mégane\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_5\

O1 HOSTS File: ([2012/07/26 06:26:49 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O2 - BHO: (Bitdefender Wallet) - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll (Bitdefender)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ASUSPRP] C:\Program Files (x86)\ASUS\APRP\APRP.EXE (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe (ASUS Cloud Corporation)
O4 - HKLM..\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (Microsoft Corp.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKU\.DEFAULT..\Run: [Bitdefender Agent de l'application Wallet] C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe (Bitdefender)
O4 - HKU\.DEFAULT..\Run: [Bitdefender Wallet] C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe (Bitdefender)
O4 - HKU\.DEFAULT..\Run: [Bitdefender Wallet Agent] C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe (Bitdefender)
O4 - HKU\S-1-5-18..\Run: [Bitdefender Agent de l'application Wallet] C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe (Bitdefender)
O4 - HKU\S-1-5-18..\Run: [Bitdefender Wallet] C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe (Bitdefender)
O4 - HKU\S-1-5-18..\Run: [Bitdefender Wallet Agent] C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe (Bitdefender)
O4 - HKU\S-1-5-21-1305010613-2064220777-3922521960-1002..\Run: [Bitdefender Agent de l'application Wallet] C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe (Bitdefender)
O4 - HKU\S-1-5-21-1305010613-2064220777-3922521960-1002..\Run: [Bitdefender Wallet] C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe (Bitdefender)
O4 - HKU\S-1-5-21-1305010613-2064220777-3922521960-1002..\Run: [Bitdefender Wallet Agent] C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe (Bitdefender)
O4 - HKU\S-1-5-21-1305010613-2064220777-3922521960-1002..\Run: [Power2GoExpress] C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe (CyberLink Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-1305010613-2064220777-3922521960-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.188.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{126EF352-55B9-459E-B6EA-65454DEC9394}: DhcpNameServer = 127.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F109431D-AF75-40B1-8A24-12D4CA0EC0F9}: DhcpNameServer = 10.188.0.1
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)



SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MCODS - Reg Error: Value error.
SafeBootMin: mcpltsvc -
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: TBS - Service
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootMin: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: MCODS - Reg Error: Value error.
SafeBootNet: mcpltsvc -
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdpencdd.sys - Driver
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: SmartcardSimulator - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TBS - Service
SafeBootNet: TDI - Driver Group
SafeBootNet: VirtualSmartcardReader - Driver
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootNet: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {3A8403F3-90B5-35DC-8926-EB9B907209F9} - .NET Framework
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP

Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/11/20 22:41:19 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Mégane\Desktop\OTL.exe
[2013/11/14 14:40:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/11/14 14:40:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2013/11/14 14:40:07 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/11/13 22:32:41 | 000,000,000 | ---D | C] -- C:\Users\Mégane\AppData\Local\Temp
[2013/11/13 12:06:04 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/11/13 12:04:30 | 001,034,531 | ---- | C] (Thisisu) -- C:\Users\Mégane\Desktop\JRT.exe
[2013/11/13 09:15:25 | 000,694,232 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/11/13 09:15:25 | 000,078,296 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/11/12 23:27:32 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013/11/12 23:27:31 | 001,711,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll
[2013/11/12 23:26:43 | 002,035,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2013/11/12 21:54:01 | 000,000,000 | ---D | C] -- C:\Users\Mégane\AppData\Roaming\Malwarebytes
[2013/11/12 21:52:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/11/12 21:52:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/11/12 21:52:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/11/12 21:52:20 | 000,000,000 | ---D | C] -- C:\Users\Mégane\AppData\Local\Programs
[2013/11/12 21:51:58 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Mégane\Desktop\mbam-setup-1.75.0.1300.exe
[2013/11/12 16:25:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
[2013/11/12 16:23:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ZHPDiag
[2013/11/12 16:23:00 | 000,000,000 | ---D | C] -- C:\Users\Mégane\AppData\Roaming\ZHP
[2013/11/12 16:19:06 | 006,848,936 | ---- | C] (Nicolas Coolman ) -- C:\Users\Mégane\Desktop\ZHPDiag2.exe
[2013/11/12 15:56:52 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013/11/09 17:06:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/11/09 17:05:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2013/11/09 17:00:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2013/11/09 17:00:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2013/11/09 16:48:22 | 000,000,000 | ---D | C] -- C:\history
[2013/11/09 16:48:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bing Bureau
[2013/11/09 16:47:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft
[2013/11/09 16:30:18 | 010,799,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Xaml.dll
[2013/11/09 16:30:15 | 000,914,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAutomationCore.dll
[2013/11/09 16:30:14 | 000,628,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapi.dll
[2013/11/09 16:30:13 | 000,247,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ubpm.dll
[2013/11/09 16:30:12 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wudriver.dll
[2013/11/09 16:30:11 | 000,126,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuwebv.dll
[2013/11/09 16:30:11 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapp.exe
[2013/11/09 14:44:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender
[2013/11/09 14:44:24 | 000,000,000 | ---D | C] -- C:\ProgramData\BDLogging
[2013/11/09 14:42:48 | 000,511,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\capicom.dll
[2013/11/09 14:18:23 | 000,000,000 | ---D | C] -- C:\Users\Mégane\AppData\Roaming\Bitdefender
[2013/11/09 14:10:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Bitdefender
[2013/11/09 14:09:23 | 000,000,000 | ---D | C] -- C:\Users\Mégane\AppData\Roaming\QuickScan
[2013/11/08 21:06:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/11/07 21:05:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2013/11/07 21:03:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2013/11/07 21:03:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013/11/07 21:03:27 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013/11/07 21:03:15 | 000,096,168 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/11/07 21:03:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2013/11/07 21:03:14 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013/11/07 21:03:14 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013/11/07 21:03:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java

========== Files - Modified Within 30 Days ==========

[2013/11/21 18:15:00 | 000,001,088 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/11/21 16:09:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/11/21 10:53:58 | 000,019,999 | ---- | M] () -- C:\Users\Mégane\Documents\Littérature 21 novembre.odt
[2013/11/21 06:44:10 | 000,000,062 | ---- | M] () -- C:\Users\Mégane\AppData\Roaming\sp_data.sys
[2013/11/21 06:43:58 | 000,001,084 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/11/20 22:51:04 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2013/11/20 22:51:03 | 763,097,087 | -HS- | M] () -- C:\hiberfil.sys
[2013/11/20 22:41:02 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Mégane\Desktop\OTL.exe
[2013/11/20 15:50:50 | 000,021,355 | ---- | M] () -- C:\Users\Mégane\Documents\Sans nom 1.odt
[2013/11/19 15:26:44 | 000,023,147 | ---- | M] () -- C:\Users\Mégane\Documents\Civilisation Britannique 19 novembre.odt
[2013/11/19 14:19:39 | 000,018,319 | ---- | M] () -- C:\Users\Mégane\Documents\Civilisation Américaine TD 19 novembre.odt
[2013/11/18 22:30:40 | 000,028,023 | ---- | M] () -- C:\Users\Mégane\Documents\Research paper.odt
[2013/11/18 15:57:34 | 000,020,970 | ---- | M] () -- C:\Users\Mégane\Documents\Academic writing pour le 19 novembre.odt
[2013/11/15 18:07:05 | 000,031,874 | ---- | M] () -- C:\Users\Mégane\Documents\Américaine civi.odt
[2013/11/15 18:06:14 | 000,034,874 | ---- | M] () -- C:\Users\Mégane\Documents\Research paper TEXTS.odt
[2013/11/15 15:27:02 | 000,002,183 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/11/14 14:40:38 | 000,001,785 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013/11/14 12:27:24 | 000,025,253 | ---- | M] () -- C:\Users\Mégane\Documents\Littérature 14 Novembre.odt
[2013/11/13 15:57:30 | 000,021,555 | ---- | M] () -- C:\Users\Mégane\Documents\Civilisation britannique 13nov TD.odt
[2013/11/13 13:27:27 | 000,000,512 | ---- | M] () -- C:\PhysicalDisk0_MBR.bin
[2013/11/13 12:04:15 | 001,034,531 | ---- | M] (Thisisu) -- C:\Users\Mégane\Desktop\JRT.exe
[2013/11/12 21:52:44 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/11/12 21:49:14 | 010,285,040 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Mégane\Desktop\mbam-setup-1.75.0.1300.exe
[2013/11/12 16:25:42 | 000,001,993 | ---- | M] () -- C:\Users\Mégane\Desktop\ZHPFix.lnk
[2013/11/12 16:25:42 | 000,001,866 | ---- | M] () -- C:\Users\Mégane\Desktop\ZHPDiag.lnk
[2013/11/12 16:18:06 | 006,848,936 | ---- | M] (Nicolas Coolman ) -- C:\Users\Mégane\Desktop\ZHPDiag2.exe
[2013/11/12 15:48:00 | 001,085,542 | ---- | M] () -- C:\Users\Mégane\Desktop\adwcleaner.exe
[2013/11/12 15:26:06 | 000,026,324 | ---- | M] () -- C:\Users\Mégane\Documents\Civilisation Britannique CM 12 novembre.odt
[2013/11/12 10:58:52 | 000,026,066 | ---- | M] () -- C:\Users\Mégane\Documents\Civilisation Américaine CM 12 Novembre.odt
[2013/11/10 19:04:32 | 000,022,406 | ---- | M] () -- C:\Users\Mégane\Documents\POEM LANGUE ORALE.odt
[2013/11/09 17:00:23 | 000,002,021 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2013/11/09 15:07:14 | 001,142,527 | ---- | M] () -- C:\ProgramData\1384002564.bdinstall.bin
[2013/11/09 14:44:27 | 000,002,192 | ---- | M] () -- C:\Users\Public\Desktop\Bitdefender Safepay.lnk
[2013/11/09 14:44:27 | 000,002,148 | ---- | M] () -- C:\Users\Public\Desktop\Bitdefender Antivirus Plus.lnk
[2013/11/09 10:35:47 | 000,002,285 | ---- | M] () -- C:\Users\Mégane\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/11/07 21:03:06 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013/11/07 21:03:06 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013/11/07 21:03:06 | 000,174,504 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013/11/07 21:03:06 | 000,096,168 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/11/06 16:41:09 | 000,020,947 | ---- | M] () -- C:\Users\Mégane\Documents\AW cours 05 nov.odt
[2013/11/06 15:56:47 | 000,022,030 | ---- | M] () -- C:\Users\Mégane\Documents\Cours civi brit TD.odt
[2013/11/05 23:58:57 | 000,694,232 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/11/05 23:58:57 | 000,078,296 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/11/05 20:25:35 | 000,014,619 | ---- | M] () -- C:\Users\Mégane\Documents\Academic Writing Mégane Delesalle LCE 2 intro synthèse.odt
[2013/11/05 15:27:24 | 000,025,030 | ---- | M] () -- C:\Users\Mégane\Documents\Civi UK 05 nov.odt
[2013/11/05 14:25:48 | 000,013,002 | ---- | M] () -- C:\Users\Mégane\Documents\Civilisation Américaine TD 05 novembre.odt
[2013/11/05 10:49:32 | 000,023,150 | ---- | M] () -- C:\Users\Mégane\Documents\Civilisation Américaine CM 05 novembre.odt
[2013/11/01 15:26:51 | 000,018,947 | ---- | M] () -- C:\Users\Mégane\Documents\The Dormouse and the Doctor.odt
[2013/10/24 11:30:46 | 000,030,024 | ---- | M] () -- C:\Users\Mégane\Documents\Littérature 24 octobre.odt
[2013/10/23 13:38:05 | 260,773,880 | ---- | M] () -- C:\Users\Mégane\Documents\IMG_1173.MOV
[2013/10/23 13:20:42 | 823,969,867 | ---- | M] () -- C:\Users\Mégane\Documents\IMG_1171.MOV

========== Files Created - No Company Name ==========

[2013/11/21 09:36:10 | 000,019,999 | ---- | C] () -- C:\Users\Mégane\Documents\Littérature 21 novembre.odt
[2013/11/20 15:50:48 | 000,021,355 | ---- | C] () -- C:\Users\Mégane\Documents\Sans nom 1.odt
[2013/11/19 14:25:23 | 000,023,147 | ---- | C] () -- C:\Users\Mégane\Documents\Civilisation Britannique 19 novembre.odt
[2013/11/19 13:39:18 | 000,018,319 | ---- | C] () -- C:\Users\Mégane\Documents\Civilisation Américaine TD 19 novembre.odt
[2013/11/15 18:06:11 | 000,034,874 | ---- | C] () -- C:\Users\Mégane\Documents\Research paper TEXTS.odt
[2013/11/14 14:40:38 | 000,001,785 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013/11/14 10:48:54 | 000,025,253 | ---- | C] () -- C:\Users\Mégane\Documents\Littérature 14 Novembre.odt
[2013/11/13 15:07:22 | 000,021,555 | ---- | C] () -- C:\Users\Mégane\Documents\Civilisation britannique 13nov TD.odt
[2013/11/12 21:52:44 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/11/12 21:06:51 | 000,028,023 | ---- | C] () -- C:\Users\Mégane\Documents\Research paper.odt
[2013/11/12 16:32:50 | 000,000,512 | ---- | C] () -- C:\PhysicalDisk0_MBR.bin
[2013/11/12 16:25:42 | 000,001,993 | ---- | C] () -- C:\Users\Mégane\Desktop\ZHPFix.lnk
[2013/11/12 16:25:42 | 000,001,866 | ---- | C] () -- C:\Users\Mégane\Desktop\ZHPDiag.lnk
[2013/11/12 15:56:36 | 001,085,542 | ---- | C] () -- C:\Users\Mégane\Desktop\adwcleaner.exe
[2013/11/12 14:33:29 | 000,026,324 | ---- | C] () -- C:\Users\Mégane\Documents\Civilisation Britannique CM 12 novembre.odt
[2013/11/12 14:31:44 | 000,031,874 | ---- | C] () -- C:\Users\Mégane\Documents\Américaine civi.odt
[2013/11/12 12:25:26 | 000,020,970 | ---- | C] () -- C:\Users\Mégane\Documents\Academic writing pour le 19 novembre.odt
[2013/11/12 10:04:00 | 000,026,066 | ---- | C] () -- C:\Users\Mégane\Documents\Civilisation Américaine CM 12 Novembre.odt
[2013/11/10 19:04:29 | 000,022,406 | ---- | C] () -- C:\Users\Mégane\Documents\POEM LANGUE ORALE.odt
[2013/11/09 17:00:23 | 000,002,021 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2013/11/09 17:00:22 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013/11/09 15:07:14 | 001,142,527 | ---- | C] () -- C:\ProgramData\1384002564.bdinstall.bin
[2013/11/09 14:44:27 | 000,002,192 | ---- | C] () -- C:\Users\Public\Desktop\Bitdefender Safepay.lnk
[2013/11/09 14:44:27 | 000,002,148 | ---- | C] () -- C:\Users\Public\Desktop\Bitdefender Antivirus Plus.lnk
[2013/11/08 21:06:17 | 000,002,285 | ---- | C] () -- C:\Users\Mégane\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/11/08 21:06:17 | 000,002,183 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/11/08 21:05:17 | 000,001,088 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/11/08 21:05:16 | 000,001,084 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/11/06 16:41:07 | 000,020,947 | ---- | C] () -- C:\Users\Mégane\Documents\AW cours 05 nov.odt
[2013/11/06 14:18:24 | 000,022,030 | ---- | C] () -- C:\Users\Mégane\Documents\Cours civi brit TD.odt
[2013/11/05 20:25:33 | 000,014,619 | ---- | C] () -- C:\Users\Mégane\Documents\Academic Writing Mégane Delesalle LCE 2 intro synthèse.odt
[2013/11/05 15:27:22 | 000,025,030 | ---- | C] () -- C:\Users\Mégane\Documents\Civi UK 05 nov.odt
[2013/11/05 14:15:49 | 000,013,002 | ---- | C] () -- C:\Users\Mégane\Documents\Civilisation Américaine TD 05 novembre.odt
[2013/11/05 10:45:37 | 000,023,150 | ---- | C] () -- C:\Users\Mégane\Documents\Civilisation Américaine CM 05 novembre.odt
[2013/11/01 15:26:48 | 000,018,947 | ---- | C] () -- C:\Users\Mégane\Documents\The Dormouse and the Doctor.odt
[2013/10/24 09:05:57 | 000,030,024 | ---- | C] () -- C:\Users\Mégane\Documents\Littérature 24 octobre.odt
[2013/10/23 16:45:31 | 260,773,880 | ---- | C] () -- C:\Users\Mégane\Documents\IMG_1173.MOV
[2013/10/23 16:43:16 | 823,969,867 | ---- | C] () -- C:\Users\Mégane\Documents\IMG_1171.MOV
[2013/09/28 20:31:37 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
[2013/09/28 18:29:43 | 000,000,062 | ---- | C] () -- C:\Users\Mégane\AppData\Roaming\sp_data.sys
[2013/04/24 04:36:10 | 000,598,384 | ---- | C] () -- C:\Windows\SysWow64\igvpkrng700.bin
[2013/04/24 04:36:09 | 000,064,512 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2013/04/24 04:36:08 | 000,754,652 | ---- | C] () -- C:\Windows\SysWow64\igcodeckrng700.bin
[2012/11/27 05:08:26 | 000,024,576 | ---- | C] () -- C:\ProgramData\SetStretch.exe
[2012/11/27 05:08:26 | 000,000,256 | ---- | C] () -- C:\ProgramData\SetStretch.cmd
[2012/11/27 05:08:26 | 000,000,103 | ---- | C] () -- C:\ProgramData\SetStretch.VBS
[2012/07/26 09:13:10 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2012/07/26 09:13:09 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2012/07/26 08:21:26 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2012/07/26 02:17:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2012/07/25 21:37:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2012/07/25 21:28:31 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2012/07/25 21:22:56 | 000,267,284 | ---- | C] () -- C:\Windows\SysWow64\igvpkrng600.bin
[2012/07/25 21:22:54 | 000,963,376 | ---- | C] () -- C:\Windows\SysWow64\igcodeckrng600.bin
[2012/06/02 15:31:19 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2012/04/20 13:59:44 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll

========== ZeroAccess Check ==========
Avatar du membre
par lcemegane
#18335
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/08/02 07:28:20 | 019,758,080 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/08/02 06:08:10 | 017,561,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012/07/26 04:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2012/07/26 04:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012/07/26 04:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/09/28 18:35:23 | 000,000,000 | ---D | M] -- C:\Users\Mégane\AppData\Roaming\ASUS
[2013/09/28 18:32:17 | 000,000,000 | ---D | M] -- C:\Users\Mégane\AppData\Roaming\ASUS WebStorage
[2013/11/09 14:18:23 | 000,000,000 | ---D | M] -- C:\Users\Mégane\AppData\Roaming\Bitdefender
[2013/09/28 23:09:31 | 000,000,000 | ---D | M] -- C:\Users\Mégane\AppData\Roaming\OpenOffice
[2013/11/09 14:09:23 | 000,000,000 | ---D | M] -- C:\Users\Mégane\AppData\Roaming\QuickScan
[2013/10/12 23:30:26 | 000,000,000 | ---D | M] -- C:\Users\Mégane\AppData\Roaming\Windows Live Writer
[2013/11/13 17:47:23 | 000,000,000 | ---D | M] -- C:\Users\Mégane\AppData\Roaming\ZHP

========== Purity Check ==========



========== Custom Scans ==========

< MD5 for: AFD.SYS >
[2013/11/20 19:21:47 | 000,085,417 | ---- | M] () MD5=26E4F2C0C82200E7A3554167BFB8AEE6 -- C:\Windows\WinSxS\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.2.9200.20814_none_31873dce01162616\afd.sys
[2013/09/04 04:11:23 | 000,576,512 | ---- | M] (Microsoft Corporation) MD5=7C0E0EDF18D6CC565D7BFBB451709FA5 -- C:\Windows\SysNative\drivers\afd.sys
[2013/09/04 04:11:23 | 000,576,512 | ---- | M] (Microsoft Corporation) MD5=7C0E0EDF18D6CC565D7BFBB451709FA5 -- C:\Windows\WinSxS\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.2.9200.16706_none_310a7182e7ee9d09\afd.sys
[2013/10/28 15:07:15 | 000,000,196 | ---- | M] () MD5=8259BE7D5467EE9A12912403CD4CBDD7 -- C:\Windows\WinSxS\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.2.9200.20555_none_315cf8b60135b7bc\afd.sys
[2013/10/28 15:07:14 | 000,015,446 | ---- | M] () MD5=84C557D1F4CBCBD9957AD04DF5852980 -- C:\Windows\WinSxS\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.2.9200.16384_none_30b1e9f6e8315547\afd.sys
[2013/11/20 19:21:46 | 000,085,445 | ---- | M] () MD5=91ADF1647280F9109E7D650197C3923B -- C:\Windows\WinSxS\amd64_microsoft-windows-winsock-core_31bf3856ad364e35_6.2.9200.16451_none_30cf5ac2e81bb296\afd.sys

< MD5 for: EXPLORER.EXE >
[2013/06/01 12:34:21 | 002,391,280 | ---- | M] (Microsoft Corporation) MD5=0E8E6463F81C80AFBED533E0F1F8895D -- C:\Windows\explorer.exe
[2013/06/01 12:34:21 | 002,391,280 | ---- | M] (Microsoft Corporation) MD5=0E8E6463F81C80AFBED533E0F1F8895D -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16628_none_aac334d9034c59e1\explorer.exe
[2013/10/28 15:33:28 | 000,191,911 | ---- | M] () MD5=14DF6DB9658B54BBDF09B3A27CA4A19C -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_b5080a0137b9becc\explorer.exe
[2013/10/28 15:33:35 | 000,191,929 | ---- | M] () MD5=1A89BE62066FC5EBCCEA2EF02735F493 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_b592a71650d677ed\explorer.exe
[2013/10/28 15:33:22 | 000,193,351 | ---- | M] () MD5=3A672801A2E6EE81B17629B7E17D4BF3 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_b4d2f8c937e166b1\explorer.exe
[2013/10/27 13:58:25 | 000,217,360 | ---- | M] () MD5=3EDEBD7CE52E816C56D444233C485D93 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20733_none_ab3d00461c7696e9\explorer.exe
[2013/10/27 13:58:21 | 000,220,321 | ---- | M] () MD5=5D93D7A80DD6E75DF7158FED1360A65E -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_ab3dfcc41c75b5f2\explorer.exe
[2013/10/27 13:58:18 | 000,220,310 | ---- | M] () MD5=75F5916475E2AAE30322A207A4A9D86F -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_aab35faf0358fcd1\explorer.exe
[2013/10/28 15:33:40 | 000,190,101 | ---- | M] () MD5=A51EC65E784E2ADF4DB6945D255B964B -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20733_none_b591aa9850d758e4\explorer.exe
[2013/06/01 11:24:46 | 002,106,176 | ---- | M] (Microsoft Corporation) MD5=EAFE46B0292D2BD2467835E2ACF717CC -- C:\Windows\SysWOW64\explorer.exe
[2013/06/01 11:24:46 | 002,106,176 | ---- | M] (Microsoft Corporation) MD5=EAFE46B0292D2BD2467835E2ACF717CC -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16628_none_b517df2b37ad1bdc\explorer.exe
[2013/10/27 13:58:14 | 000,221,955 | ---- | M] () MD5=F9182F71A0738369A6671DA82DA5D499 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_aa7e4e770380a4b6\explorer.exe

< MD5 for: I8042PRT.SYS >
[2012/07/26 03:28:51 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=C9E9CBF73AFFBFE3E801EFB516787BA3 -- C:\Windows\SysNative\drivers\i8042prt.sys
[2012/07/26 03:28:51 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=C9E9CBF73AFFBFE3E801EFB516787BA3 -- C:\Windows\SysNative\DriverStore\FileRepository\keyboard.inf_amd64_1a7f16d14b82baf1\i8042prt.sys
[2012/07/26 03:28:51 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=C9E9CBF73AFFBFE3E801EFB516787BA3 -- C:\Windows\SysNative\DriverStore\FileRepository\keyboard.inf_amd64_886e23df8a6acdc0\i8042prt.sys
[2012/07/26 03:28:51 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=C9E9CBF73AFFBFE3E801EFB516787BA3 -- C:\Windows\SysNative\DriverStore\FileRepository\msmouse.inf_amd64_df79823e0a537e57\i8042prt.sys
[2012/07/26 03:28:51 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=C9E9CBF73AFFBFE3E801EFB516787BA3 -- C:\Windows\SysNative\DriverStore\FileRepository\msmouse.inf_amd64_f105fedfe75017ad\i8042prt.sys
[2012/07/26 03:28:51 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=C9E9CBF73AFFBFE3E801EFB516787BA3 -- C:\Windows\WinSxS\amd64_keyboard.inf_31bf3856ad364e35_6.2.9200.16384_none_f018153d62bd2275\i8042prt.sys
[2012/07/26 03:28:51 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=C9E9CBF73AFFBFE3E801EFB516787BA3 -- C:\Windows\WinSxS\amd64_keyboard.inf_31bf3856ad364e35_6.2.9200.16548_none_f04759e16299125b\i8042prt.sys
[2012/07/26 03:28:51 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=C9E9CBF73AFFBFE3E801EFB516787BA3 -- C:\Windows\WinSxS\amd64_keyboard.inf_31bf3856ad364e35_6.2.9200.20652_none_f0c025047bc4360c\i8042prt.sys
[2012/07/26 03:28:51 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=C9E9CBF73AFFBFE3E801EFB516787BA3 -- C:\Windows\WinSxS\amd64_msmouse.inf_31bf3856ad364e35_6.2.9200.16384_none_a6fdb2e15c1f6949\i8042prt.sys
[2012/07/26 03:28:51 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=C9E9CBF73AFFBFE3E801EFB516787BA3 -- C:\Windows\WinSxS\amd64_msmouse.inf_31bf3856ad364e35_6.2.9200.16548_none_a72cf7855bfb592f\i8042prt.sys
[2012/07/26 03:28:51 | 000,112,640 | ---- | M] (Microsoft Corporation) MD5=C9E9CBF73AFFBFE3E801EFB516787BA3 -- C:\Windows\WinSxS\amd64_msmouse.inf_31bf3856ad364e35_6.2.9200.20652_none_a7a5c2a875267ce0\i8042prt.sys

< MD5 for: LSASS.EXE >
[2013/10/27 19:35:14 | 000,002,767 | ---- | M] () MD5=84505846DDE8FD8406B07E83F0E0DD74 -- C:\Windows\WinSxS\amd64_microsoft-windows-lsa-minwin_31bf3856ad364e35_6.2.9200.16384_none_963549021c129d16\lsass.exe
[2013/10/27 19:35:15 | 000,000,552 | ---- | M] () MD5=D5FD6314BD84FEFC07B69727682D3A3F -- C:\Windows\WinSxS\amd64_microsoft-windows-lsa-minwin_31bf3856ad364e35_6.2.9200.20521_none_96fcc65d3502465c\lsass.exe
[2012/11/27 13:56:51 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=F702AB6181513303AB0FC8D59E52708B -- C:\Windows\SysNative\lsass.exe
[2012/11/27 13:56:51 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=F702AB6181513303AB0FC8D59E52708B -- C:\Windows\WinSxS\amd64_microsoft-windows-lsa-minwin_31bf3856ad364e35_6.2.9200.16420_none_967229481be58d3b\lsass.exe

< MD5 for: NETBT.SYS >
[2012/07/26 03:24:28 | 000,331,776 | ---- | M] (Microsoft Corporation) MD5=7CEC25C682D319D484630B3952C31A11 -- C:\Windows\SysNative\drivers\netbt.sys
[2012/07/26 03:24:28 | 000,331,776 | ---- | M] (Microsoft Corporation) MD5=7CEC25C682D319D484630B3952C31A11 -- C:\Windows\WinSxS\amd64_microsoft-windows-netbt-minwin_31bf3856ad364e35_6.2.9200.16384_none_447628a661a3fbd5\netbt.sys

< MD5 for: SVCHOST.EXE >
[2013/10/29 22:39:18 | 000,003,208 | ---- | M] () MD5=0573DD9D68773C131A9FAA5704A06F27 -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.16384_none_b2666581d6b482a6\svchost.exe
[2013/10/29 22:39:18 | 000,000,583 | ---- | M] () MD5=456068B215A420BADA87E81FFFB796D5 -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.20521_none_b32de2dcefa42bec\svchost.exe
[2012/11/27 13:57:03 | 000,023,040 | ---- | M] (Microsoft Corporation) MD5=A46DC432F81473F526E3994AA483E366 -- C:\Windows\SysWOW64\svchost.exe
[2012/11/27 13:57:03 | 000,023,040 | ---- | M] (Microsoft Corporation) MD5=A46DC432F81473F526E3994AA483E366 -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.16420_none_b2a345c7d68772cb\svchost.exe
[2013/04/04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2013/10/28 13:54:26 | 000,000,609 | ---- | M] () MD5=DD1936725249DCAE1CE0320E28861FFD -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.20521_none_0f4c7e60a8019d22\svchost.exe
[2012/11/27 13:56:51 | 000,029,696 | ---- | M] (Microsoft Corporation) MD5=EDE27EACE742EE2888C5DD36400A2EC0 -- C:\Windows\SysNative\svchost.exe
[2012/11/27 13:56:51 | 000,029,696 | ---- | M] (Microsoft Corporation) MD5=EDE27EACE742EE2888C5DD36400A2EC0 -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.16420_none_0ec1e14b8ee4e401\svchost.exe
[2013/10/28 13:54:26 | 000,002,873 | ---- | M] () MD5=F38BADCA4357B1627D9FD36184D2E52D -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.16384_none_0e8501058f11f3dc\svchost.exe

< MD5 for: TCPIP.SYS >
[2013/10/28 14:10:12 | 000,370,088 | ---- | M] () MD5=071815CBB272BCB402454DD8F875B42F -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.2.9200.20623_none_0cb1398c09185008\tcpip.sys
[2013/10/28 14:09:39 | 000,373,137 | ---- | M] () MD5=22E730340EB813AAB528C07D9AAA0419 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.2.9200.16384_none_0be7b9b6f02a76ed\tcpip.sys
[2013/10/28 14:10:26 | 000,362,050 | ---- | M] () MD5=37CD2D458F8DA6D7FBEF99FC18E72209 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.2.9200.20767_none_0c89fcea0935224f\tcpip.sys
[2013/08/01 11:41:31 | 002,233,688 | ---- | M] (Microsoft Corporation) MD5=37D85E873C9531A2F88DD9C63D3F8A9E -- C:\Windows\SysNative\drivers\tcpip.sys
[2013/08/01 11:41:31 | 002,233,688 | ---- | M] (Microsoft Corporation) MD5=37D85E873C9531A2F88DD9C63D3F8A9E -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.2.9200.16679_none_0bf790c6f01dd124\tcpip.sys
[2013/10/28 14:09:44 | 000,375,242 | ---- | M] () MD5=569C571354EA25FFF495C95C904DD745 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.2.9200.16420_none_0c2499fceffd6712\tcpip.sys
[2013/10/28 14:09:49 | 000,370,080 | ---- | M] () MD5=947C04F67CD3370DE1DFB00341068556 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.2.9200.16518_none_0c376e1eefee1300\tcpip.sys
[2013/10/28 14:10:31 | 000,358,445 | ---- | M] () MD5=A095166E7CE9FC6A31D9ADC66B637EEE -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.2.9200.20787_none_0c745d1209455a31\tcpip.sys
[2013/10/28 14:09:58 | 000,239,494 | ---- | M] () MD5=D225229DBDE93E116F2961E84359F3F8 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.2.9200.16628_none_0c2ca018eff62c18\tcpip.sys
[2013/10/28 14:10:21 | 000,365,875 | ---- | M] () MD5=DE5B5B8DAB653634316D80708F245180 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.2.9200.20733_none_0ca66b8609206920\tcpip.sys
[2013/10/28 14:10:16 | 000,371,879 | ---- | M] () MD5=DF03C7D2E96D5EFC6803DF7B448B7A28 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.2.9200.20652_none_0c8fc97e09318a84\tcpip.sys
[2013/10/28 14:09:54 | 000,264,299 | ---- | M] () MD5=E361B462D244BCB7D80B13AF3B3BC9AD -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.2.9200.16548_none_0c16fe5af00666d3\tcpip.sys
[2013/10/28 14:10:02 | 000,236,109 | ---- | M] () MD5=F237AA210E578D7DF47A69068FB951CE -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.2.9200.16659_none_0c0d309ef00d9942\tcpip.sys
[2013/10/28 14:10:07 | 000,375,206 | ---- | M] () MD5=F5A057C11CF3AE861E65D5BB2C163598 -- C:\Windows\WinSxS\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.2.9200.20521_none_0caf3712091a2033\tcpip.sys

< MD5 for: USERINIT.EXE >
[2012/07/26 04:08:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E925F7BA032920D58DD284B6181A247 -- C:\Windows\SysNative\userinit.exe
[2012/07/26 04:08:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E925F7BA032920D58DD284B6181A247 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.2.9200.16384_none_34f2617a5b742e02\userinit.exe
[2012/07/26 04:21:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=9F6289D194A04A09671FEED4B6CB6EF7 -- C:\Windows\SysWOW64\userinit.exe
[2012/07/26 04:21:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=9F6289D194A04A09671FEED4B6CB6EF7 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.2.9200.16384_none_d8d3c5f6a316bccc\userinit.exe

< MD5 for: VOLSNAP.SYS >
[2013/06/01 13:06:28 | 000,332,032 | ---- | M] (Microsoft Corporation) MD5=0548F5D3282A91B69F9D39EE771307F7 -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.2.9200.20733_none_6f3f10b49ecf22f7\volsnap.sys
[2012/07/26 05:57:09 | 000,332,016 | ---- | M] (Microsoft Corporation) MD5=2FB3CDFD5EAF4CD9D4AFAF96877D13AE -- C:\Windows\SysNative\DriverStore\FileRepository\volume.inf_amd64_9d78abd6ac3df11c\volsnap.sys
[2012/07/26 05:57:09 | 000,332,016 | ---- | M] (Microsoft Corporation) MD5=2FB3CDFD5EAF4CD9D4AFAF96877D13AE -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.2.9200.16384_none_6e805ee585d930c4\volsnap.sys
[2013/06/01 12:26:33 | 000,327,936 | ---- | M] (Microsoft Corporation) MD5=78A5BBA3819FFFC62FFEC3E2220D102D -- C:\Windows\SysNative\drivers\volsnap.sys
[2013/06/01 12:26:33 | 000,327,936 | ---- | M] (Microsoft Corporation) MD5=78A5BBA3819FFFC62FFEC3E2220D102D -- C:\Windows\SysNative\DriverStore\FileRepository\volume.inf_amd64_84c99cb521dc4714\volsnap.sys
[2013/06/01 12:26:33 | 000,327,936 | ---- | M] (Microsoft Corporation) MD5=78A5BBA3819FFFC62FFEC3E2220D102D -- C:\Windows\WinSxS\amd64_volume.inf_31bf3856ad364e35_6.2.9200.16628_none_6ec5454785a4e5ef\volsnap.sys

< MD5 for: WININIT.EXE >
[2012/07/26 04:08:50 | 000,132,608 | ---- | M] (Microsoft Corporation) MD5=FE9AB232B56A12224E8A3F3F9878C9A3 -- C:\Windows\SysNative\wininit.exe
[2012/07/26 04:08:50 | 000,132,608 | ---- | M] (Microsoft Corporation) MD5=FE9AB232B56A12224E8A3F3F9878C9A3 -- C:\Windows\WinSxS\amd64_microsoft-windows-wininit_31bf3856ad364e35_6.2.9200.16384_none_89bc60338e14dc99\wininit.exe

< MD5 for: WINLOGON.EXE >
[2013/10/28 15:06:56 | 000,053,889 | ---- | M] () MD5=6AF441311CCF9608BA772D345D8BCEDC -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16384_none_c88ca87b5eb5b1ec\winlogon.exe
[2013/10/28 15:06:57 | 000,053,884 | ---- | M] () MD5=862ECFA441ACF89AFB9C73C749CD7296 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20521_none_c95425d677a55b32\winlogon.exe
[2013/10/28 15:06:58 | 000,001,620 | ---- | M] () MD5=99BAFD1D6569CF375EC0972DF3C64835 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20534_none_c94c56c877aac328\winlogon.exe
[2013/10/28 15:06:56 | 000,053,876 | ---- | M] () MD5=A2E6FF103E376E28D34DA274FE1F638A -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16420_none_c8c988c15e88a211\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2012/10/11 06:46:58 | 000,517,120 | ---- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E -- C:\Windows\SysNative\winlogon.exe
[2012/10/11 06:46:58 | 000,517,120 | ---- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16433_none_c8c1b9b35e8e0a07\winlogon.exe

< %APPDATA%\*.exe /s >

< %APPDATA%\Adobe\Update\*.* >

< %APPDATA%\Update\*.* >

< %APPDATA%\Microsoft\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %ALLUSERSPROFILE%\*.* >
[2013/11/09 15:07:14 | 001,142,527 | ---- | M] () -- C:\ProgramData\1384002564.bdinstall.bin
[2012/09/07 12:40:44 | 000,000,256 | ---- | M] () -- C:\ProgramData\SetStretch.cmd
[2009/07/22 11:04:00 | 000,024,576 | ---- | M] () -- C:\ProgramData\SetStretch.exe
[2012/09/07 12:37:49 | 000,000,103 | ---- | M] () -- C:\ProgramData\SetStretch.VBS
[2013/09/28 18:47:46 | 000,000,105 | ---- | M] () -- C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2013/09/28 18:45:13 | 000,000,107 | ---- | M] () -- C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log

< %SYSTEMDRIVE%\*.* >
[2013/11/13 21:53:31 | 000,005,923 | ---- | M] () -- C:\bdlog.txt
[2012/07/26 04:44:30 | 000,398,156 | RHS- | M] () -- C:\bootmgr
[2012/06/02 15:30:55 | 000,000,001 | -HS- | M] () -- C:\BOOTNXT
[2013/11/20 22:51:03 | 763,097,087 | -HS- | M] () -- C:\hiberfil.sys
[2013/11/20 22:51:03 | 1006,632,960 | -HS- | M] () -- C:\pagefile.sys
[2013/11/13 13:27:27 | 000,000,512 | ---- | M] () -- C:\PhysicalDisk0_MBR.bin
[2013/11/20 22:51:04 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2013/04/01 07:53:21 | 006,293,504 | RH-- | M] () -- C:\X550CA.BIN
[2013/04/07 09:06:02 | 006,293,504 | RH-- | M] () -- C:\X550CC.BIN
[2013/04/07 07:58:18 | 006,293,504 | RH-- | M] () -- C:\X550VB.BIN
[2013/04/07 09:12:38 | 006,293,504 | RH-- | M] () -- C:\X550VC.BIN

< %PROGRAMFILES%\*.* >
[2012/07/26 09:11:35 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini

< %PROGRAMFILES%\Internet Explorer\*.* >
[2012/07/26 04:20:46 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\ExtExport.exe
[2012/07/26 04:18:34 | 000,051,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\hmmapi.dll
[2012/10/17 21:34:28 | 000,002,843 | ---- | M] () -- C:\Program Files (x86)\Internet Explorer\ie9props.propdesc
[2012/07/26 04:18:36 | 000,697,344 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\iedvtool.dll
[2012/07/26 04:20:47 | 000,467,456 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\ieinstal.exe
[2012/07/26 04:20:47 | 000,222,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\ielowutil.exe
[2013/10/12 08:02:29 | 000,257,536 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\ieproxy.dll
[2013/08/01 09:36:05 | 000,236,032 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\IEShims.dll
[2013/02/21 12:28:11 | 000,770,608 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012/07/26 04:18:47 | 000,440,320 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\jsdbgui.dll
[2013/04/28 23:30:12 | 000,108,032 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\jsdebuggeride.dll
[2012/07/26 04:18:47 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\JSProfilerCore.dll
[2012/07/26 04:18:47 | 000,147,456 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\jsprofilerui.dll
[2012/06/21 20:03:37 | 000,285,080 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\msdbg2.dll
[2012/07/26 04:19:24 | 000,294,400 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\networkinspection.dll
[2012/06/21 20:03:37 | 000,392,080 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\pdm.dll
[2012/06/21 20:03:37 | 000,070,568 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\pdmproxy100.dll
[2012/07/26 04:19:56 | 000,219,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\sqmapi.dll

< %USERPROFILE%\*.* >
[2013/11/20 23:20:38 | 001,835,008 | -HS- | M] () -- C:\Users\Mégane\NTUSER.DAT
[2013/09/28 18:27:32 | 000,208,896 | -HS- | M] () -- C:\Users\Mégane\ntuser.dat.LOG1
[2013/09/28 18:27:32 | 000,000,000 | -HS- | M] () -- C:\Users\Mégane\ntuser.dat.LOG2
[2013/09/28 18:48:34 | 000,065,536 | -HS- | M] () -- C:\Users\Mégane\NTUSER.DAT{c62ccdc3-d701-11e1-9f13-782bcb37b9d5}.TM.blf
[2013/09/28 18:48:34 | 000,524,288 | -HS- | M] () -- C:\Users\Mégane\NTUSER.DAT{c62ccdc3-d701-11e1-9f13-782bcb37b9d5}.TMContainer00000000000000000001.regtrans-ms
[2013/09/28 18:27:43 | 000,524,288 | -HS- | M] () -- C:\Users\Mégane\NTUSER.DAT{c62ccdc3-d701-11e1-9f13-782bcb37b9d5}.TMContainer00000000000000000002.regtrans-ms
[2013/09/28 18:27:32 | 000,000,020 | -HS- | M] () -- C:\Users\Mégane\ntuser.ini

< %Temp%\smtmp\1\*.* >

< %Temp%\smtmp\2\*.* >

< %Temp%\smtmp\3\*.* >

< %Temp%\smtmp\4\*.* >

< %USERPROFILE%\Local Settings\Temp\*.exe >

< %USERPROFILE%\Local Settings\Temp\*.dll >

< %USERPROFILE%\Application Data\*.exe >

< %systemroot%\system32\DBBK\*.* /s >

< %systemroot%\system32\config\systemprofile\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\*.exe /90 >

< %systemroot%\system32\*.dll /lockedfiles >
[2012/07/26 04:19:52 | 000,156,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\scrrun.dll

< %systemroot%\system32\*.dll /90 >
[2013/10/02 00:37:53 | 002,035,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\authui.dll
[2013/10/02 00:37:57 | 001,569,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\crypt32.dll
[2013/10/01 23:22:19 | 001,022,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\gdi32.dll
[2013/10/12 08:02:28 | 013,761,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ieframe.dll
[2013/10/12 08:02:29 | 002,049,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\iertutil.dll
[2013/10/12 08:02:33 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\jscript.dll
[2013/10/12 08:02:33 | 002,877,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\jscript9.dll
[2013/10/12 08:02:48 | 000,493,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\msfeeds.dll
[2013/10/12 08:02:49 | 014,355,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\mshtml.dll
[2013/09/23 23:30:03 | 000,323,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\schannel.dll
[2013/09/13 23:36:14 | 000,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ubpm.dll
[2013/08/30 00:48:12 | 000,914,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\UIAutomationCore.dll
[2013/10/12 08:03:41 | 001,138,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\urlmon.dll
[2013/11/07 21:03:06 | 000,096,168 | ---- | M] (Oracle Corporation) -- C:\Windows\system32\WindowsAccessBridge-32.dll
[2013/10/12 08:03:50 | 001,767,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wininet.dll
[2013/09/13 23:36:23 | 000,628,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wuapi.dll
[2013/09/13 23:36:23 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wudriver.dll
[2013/09/13 23:36:23 | 000,126,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wuwebv.dll

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\system32\drivers\*.sys /90 >

< %systemroot%\system32\*.exe /90 >
[2013/11/05 23:58:57 | 000,694,232 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\system32\FlashPlayerApp.exe
[2013/11/07 21:03:06 | 000,174,504 | ---- | M] (Oracle Corporation) -- C:\Windows\system32\java.exe
[2013/11/07 21:03:06 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\system32\javaw.exe
[2013/11/07 21:03:06 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\Windows\system32\javaws.exe
[2013/09/13 23:36:37 | 000,035,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\wuapp.exe

< %systemroot%\system32\config\*.sav >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\assembly\tmp\*.* /S /MD5 >

< %systemroot%\assembly\GAC_32\*.* /S /MD5 >
[2013/09/28 23:00:40 | 000,064,512 | ---- | M] () MD5=D3BCB3507FC6FCE55514BDD786826858 -- C:\Windows\assembly\GAC_32\cli_cppuhelper\1.0.22.0__ce2cb7e279207b9e\cli_cppuhelper.dll
[2012/07/26 11:07:31 | 000,069,120 | ---- | M] (Microsoft Corporation) MD5=2FCC6FAEFA0148BEDD4AE0920822DE06 -- C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
[2012/07/26 11:07:31 | 000,072,192 | ---- | M] (Microsoft Corporation) MD5=AEB7F131417C3D92E2672B1D6F6DB3E8 -- C:\Windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
[2012/07/26 04:35:58 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=AC32B98EC555DD4C8EC20D470EAF9C37 -- C:\Windows\assembly\GAC_32\Microsoft.Ink\6.1.0.0__31bf3856ad364e35\Microsoft.Ink.dll
[2012/07/26 04:33:07 | 000,077,824 | ---- | M] ( ) MD5=1D9787D7A38F8696ACABA7B474B751B5 -- C:\Windows\assembly\GAC_32\Microsoft.Interop.Security.AzRoles\2.0.0.0__31bf3856ad364e35\Microsoft.Interop.Security.AzRoles.dll
[2012/07/26 11:07:31 | 000,163,840 | ---- | M] (Microsoft Corporation) MD5=C852020936B347DE9520E33F3EC92FC9 -- C:\Windows\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
[2012/07/26 11:07:31 | 000,088,648 | ---- | M] (Microsoft Corporation) MD5=26546FCB401ACEE13CC9258DCB2479DF -- C:\Windows\assembly\GAC_32\MSBuild\3.5.0.0__b03f5f7f11d50a3a\MSBuild.exe
[2012/07/26 11:07:31 | 000,001,581 | ---- | M] () MD5=1EA3E30080C0E256C2EF0C621E91C345 -- C:\Windows\assembly\GAC_32\MSBuild\3.5.0.0__b03f5f7f11d50a3a\msbuild.exe.config
[2012/07/26 11:07:31 | 000,066,728 | ---- | M] () MD5=C01B81BB10AD14DBC5C4ECD350638096 -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\big5.nlp
[2012/07/26 11:07:31 | 000,082,172 | ---- | M] () MD5=EE1F60F8774D74BED8B13498F3FE737A -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bopomofo.nlp
[2012/07/26 11:07:31 | 000,116,756 | ---- | M] () MD5=F6DFDA5A31162D848634504565F6D321 -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\ksc.nlp
[2013/04/22 23:08:36 | 004,554,752 | ---- | M] (Microsoft Corporation) MD5=917174B2C503F870134F2573D8A080B1 -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
[2012/06/02 15:34:41 | 000,059,342 | ---- | M] () MD5=DA5748A89E22A3932387E65694B25BBB -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normidna.nlp
[2012/07/26 11:07:31 | 000,045,794 | ---- | M] () MD5=3831A5E217D6FA828CCE1011DA26E677 -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfc.nlp
[2012/07/26 11:07:31 | 000,039,284 | ---- | M] () MD5=DBDE664E0BA4BACD0A6A04AE2232B205 -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfd.nlp
[2012/07/26 11:07:31 | 000,066,384 | ---- | M] () MD5=C9B88B759FE81D59CE8EBF5A0A8EB75A -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfkc.nlp
[2012/07/26 11:07:31 | 000,060,294 | ---- | M] () MD5=3CAB6AB66759FCDF73B61EE262C9ACF4 -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\normnfkd.nlp
[2012/07/26 11:07:31 | 000,083,748 | ---- | M] () MD5=54144F43EDF5AA8F504A30E7C1D1A7B5 -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\prc.nlp
[2012/07/26 11:07:31 | 000,083,748 | ---- | M] () MD5=901863C68E6523336CAC602FE9320ABC -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\prcp.nlp
[2012/07/26 11:07:31 | 000,262,148 | ---- | M] () MD5=FB59D247F7143C3B9683A547E808A88B -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
[2012/07/26 11:07:31 | 000,020,320 | ---- | M] () MD5=FF13BA175F0013D2311827E0D438C60B -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
[2012/07/26 11:07:31 | 000,028,288 | ---- | M] () MD5=09E420F90A329BDA68477FA4AF43CB28 -- C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\xjis.nlp
[2013/09/28 23:00:58 | 000,000,382 | ---- | M] () MD5=5B5249684E45C53333ACB2703BC03AB3 -- C:\Windows\assembly\GAC_32\policy.1.0.cli_cppuhelper\22.0.0.0__ce2cb7e279207b9e\cli_cppuhelper.config
[2013/09/28 23:00:58 | 000,003,072 | ---- | M] () MD5=1FF8B0F021D111AE9086BB8C523C415E -- C:\Windows\assembly\GAC_32\policy.1.0.cli_cppuhelper\22.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_cppuhelper.dll
[2013/04/15 23:06:09 | 004,218,880 | ---- | M] (Microsoft Corporation) MD5=0937AB1E040F230B8E6B62AAC2A2466F -- C:\Windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
[2012/07/26 11:07:31 | 000,000,161 | ---- | M] () MD5=C0856EC51C8C75B8FDF02C1BBCFE7B93 -- C:\Windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationFontCache.exe.config
[2013/04/19 23:05:22 | 001,737,888 | ---- | M] (Microsoft Corporation) MD5=E8D5378C39F5E29ADA63731E84D4E1DE -- C:\Windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
[2012/07/26 11:07:31 | 000,487,424 | ---- | M] (Microsoft Corporation) MD5=4527346262FDD0C69A576D371EE8CB64 -- C:\Windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
[2012/07/26 11:07:31 | 002,972,672 | ---- | M] (Microsoft Corporation) MD5=618228D67A57FB200B9A7BD2C209D79E -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
[2012/07/26 11:07:31 | 000,258,048 | ---- | M] (Microsoft Corporation) MD5=2659B71D13230829087077B68BA830BE -- C:\Windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
[2012/07/26 11:07:31 | 000,113,664 | ---- | M] (Microsoft Corporation) MD5=9671883E8186BA39239DC5898FD37A8F -- C:\Windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
[2013/04/15 23:06:10 | 000,368,640 | ---- | M] (Microsoft Corporation) MD5=C103356DCF724945D8C433FBD30AB4FB -- C:\Windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
[2012/07/26 11:07:31 | 000,261,632 | ---- | M] (Microsoft Corporation) MD5=81B8522AD3919354ADCABDFE9DE67507 -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
[2013/07/01 23:08:23 | 005,283,840 | ---- | M] (Microsoft Corporation) MD5=43AD57997F6FC967115C9B5682F5CA33 -- C:\Windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll

< %systemroot%\assembly\GAC_64\*.* /S /MD5 >
[2012/07/26 11:07:31 | 000,080,896 | ---- | M] (Microsoft Corporation) MD5=0D3A2740C6FDDAA77F59064BF067EE14 -- C:\Windows\assembly\GAC_64\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
[2012/07/26 11:07:31 | 000,089,600 | ---- | M] (Microsoft Corporation) MD5=5DDE7B014A187A2FC30188AD9E938593 -- C:\Windows\assembly\GAC_64\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
[2012/07/26 05:57:15 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=A3FFC426D703E43F3CB900E6E37FB259 -- C:\Windows\assembly\GAC_64\Microsoft.Ink\6.1.0.0__31bf3856ad364e35\Microsoft.Ink.dll
[2012/07/26 05:51:28 | 000,077,824 | ---- | M] ( ) MD5=3706F6F41747E9B3DAA21CC5A61B3454 -- C:\Windows\assembly\GAC_64\Microsoft.Interop.Security.AzRoles\2.0.0.0__31bf3856ad364e35\Microsoft.Interop.Security.AzRoles.dll
[2012/07/06 03:02:29 | 000,163,840 | ---- | M] (Microsoft Corporation) MD5=17D61C19D5E1A4FC7750A5EC8EE4FC84 -- C:\Windows\assembly\GAC_64\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
[2012/07/26 11:07:31 | 000,084,552 | ---- | M] (Microsoft Corporation) MD5=B43FDCDFC40BC5EFD272CF73FEC94D5F -- C:\Windows\assembly\GAC_64\MSBuild\3.5.0.0__b03f5f7f11d50a3a\MSBuild.exe
[2012/07/26 11:07:31 | 000,001,581 | ---- | M] () MD5=1EA3E30080C0E256C2EF0C621E91C345 -- C:\Windows\assembly\GAC_64\MSBuild\3.5.0.0__b03f5f7f11d50a3a\msbuild.exe.config
[2012/07/26 11:07:31 | 000,066,728 | ---- | M] () MD5=C01B81BB10AD14DBC5C4ECD350638096 -- C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\big5.nlp
[2012/07/26 11:07:31 | 000,082,172 | ---- | M] () MD5=EE1F60F8774D74BED8B13498F3FE737A -- C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\bopomofo.nlp
[2012/07/26 11:07:31 | 000,116,756 | ---- | M] () MD5=F6DFDA5A31162D848634504565F6D321 -- C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\ksc.nlp
[2013/04/22 23:08:48 | 004,571,136 | ---- | M] (Microsoft Corporation) MD5=626A1631844751737C565DA9ED550000 -- C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
[2012/06/02 15:33:37 | 000,059,342 | ---- | M] () MD5=DA5748A89E22A3932387E65694B25BBB -- C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\normidna.nlp
[2012/07/26 11:07:31 | 000,045,794 | ---- | M] () MD5=3831A5E217D6FA828CCE1011DA26E677 -- C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\normnfc.nlp
[2012/07/26 11:07:31 | 000,039,284 | ---- | M] () MD5=DBDE664E0BA4BACD0A6A04AE2232B205 -- C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\normnfd.nlp
[2012/07/26 11:07:31 | 000,066,384 | ---- | M] () MD5=C9B88B759FE81D59CE8EBF5A0A8EB75A -- C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\normnfkc.nlp
[2012/07/26 11:07:31 | 000,060,294 | ---- | M] () MD5=3CAB6AB66759FCDF73B61EE262C9ACF4 -- C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\normnfkd.nlp
[2012/07/26 11:07:31 | 000,083,748 | ---- | M] () MD5=54144F43EDF5AA8F504A30E7C1D1A7B5 -- C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\prc.nlp
[2012/07/26 11:07:31 | 000,083,748 | ---- | M] () MD5=901863C68E6523336CAC602FE9320ABC -- C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\prcp.nlp
[2012/07/26 11:07:31 | 000,262,148 | ---- | M] () MD5=FB59D247F7143C3B9683A547E808A88B -- C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
[2012/07/26 11:07:31 | 000,020,320 | ---- | M] () MD5=FF13BA175F0013D2311827E0D438C60B -- C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
[2012/07/26 11:07:31 | 000,028,288 | ---- | M] () MD5=09E420F90A329BDA68477FA4AF43CB28 -- C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\xjis.nlp
[2013/04/15 23:08:00 | 003,999,232 | ---- | M] (Microsoft Corporation) MD5=4A88998AA8C740A6FAEAD7F6C2F14127 -- C:\Windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
[2012/07/26 11:07:31 | 000,000,161 | ---- | M] () MD5=C0856EC51C8C75B8FDF02C1BBCFE7B93 -- C:\Windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationFontCache.exe.config
[2013/04/19 23:05:48 | 002,256,032 | ---- | M] (Microsoft Corporation) MD5=234DA4E47055B32DD833FBD0F4FA4D8B -- C:\Windows\assembly\GAC_64\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
[2012/07/26 11:07:31 | 000,503,296 | ---- | M] (Microsoft Corporation) MD5=5A25DE07B2D2BE53AEA6E08B50F8E197 -- C:\Windows\assembly\GAC_64\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
[2012/07/26 11:07:31 | 003,145,216 | ---- | M] (Microsoft Corporation) MD5=9CBB1B96CF309000C3ABBFC12464D74D -- C:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
[2012/07/26 11:07:31 | 000,245,760 | ---- | M] (Microsoft Corporation) MD5=A6302FCEB4495D9EE7BB94A597081C94 -- C:\Windows\assembly\GAC_64\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
[2012/07/26 11:07:31 | 000,133,120 | ---- | M] (Microsoft Corporation) MD5=1B2A8DA0CAE0D8B8818ED70FF23591DA -- C:\Windows\assembly\GAC_64\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
[2013/04/15 23:08:00 | 000,357,888 | ---- | M] (Microsoft Corporation) MD5=AE9897E5790B23A18E82D6BB8ECA143B -- C:\Windows\assembly\GAC_64\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
[2012/07/26 11:07:31 | 000,283,136 | ---- | M] (Microsoft Corporation) MD5=05B1D09454ACA804B286964CCF556E04 -- C:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
[2013/07/01 23:08:45 | 005,292,032 | ---- | M] (Microsoft Corporation) MD5=0162FF86E799F25BAFE532194975A11F -- C:\Windows\assembly\GAC_64\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll

< %windir%\ServiceProfiles\LocalService\AppData\Local\Temp\*.* >
[2013/11/20 22:54:19 | 000,739,756 | ---- | M] () -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\MpCmdRun.log
[2013/11/21 09:56:58 | 000,145,504 | ---- | M] () -- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\winstore.log

< %windir%\ServiceProfiles\NetworkService\AppData\Local\Temp\*.* >
[2013/11/09 14:18:26 | 000,002,098 | ---- | M] () -- C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\MpCmdRun.log

< %windir%\temp*.* >

< "%WinDir%\$NtUninstallKB*$." /30 >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections >
"DefaultConnectionSettings" = 46 00 00 00 E5 00 00 00 09 00 00 00 00 00 00 00 07 00 00 00 2A 2E 6C 6F 63 61 6C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 00 00 00 0A BC 7A 16 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 17 00 00 00 00 00 00 00 20 01 00 00 5E F5 79 FD 14 8D 14 9C D1 3E 59 39 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [Binary data over 200 bytes]
"SavedLegacySettings" = 46 00 00 00 5A 03 00 00 09 00 00 00 00 00 00 00 07 00 00 00 2A 2E 6C 6F 63 61 6C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 00 00 00 0A BC 7A 16 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 17 00 00 00 00 00 00 00 20 01 00 00 5E F5 79 FD 14 8D 14 9C D1 3E 59 39 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [Binary data over 200 bytes]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< C:\Program Files\Common Files\ComObjects\*.* / >
Invalid Switch:

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< End of report >
Avatar du membre
par lcemegane
#18337
Voici le rapport extras.txt

OTL Extras logfile created on: 21/11/2013 18:22:10 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Mégane\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16736)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

5,89 Gb Total Physical Memory | 4,36 Gb Available Physical Memory | 74,01% Memory free
6,83 Gb Paging File | 4,85 Gb Available in Paging File | 71,04% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279,45 Gb Total Space | 212,66 Gb Free Space | 76,10% Space Free | Partition Type: NTFS
Drive D: | 397,87 Gb Total Space | 397,62 Gb Free Space | 99,94% Space Free | Partition Type: NTFS

Computer Name: PC-MEGANE | User Name: Mégane | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-1305010613-2064220777-3922521960-1002\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{4C1789D6-621D-4F17-9943-42622DA203BA}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{E09C51D2-1F9F-41A6-BEA7-8B93DB621409}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04481ECC-55C2-41CD-A11C-2B0613905FAF}" = dir=out | name=pinball fx2 |
"{06EEF38E-CA01-4E5A-A1C7-E57922EF2ABE}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{19998B2A-C3C0-4894-9183-DF97D56495E3}" = dir=out | name=@{codeblenders.horscopodiario_1.1.0.0_neutral__e1fj52hy2zdf6?ms-resource://codeblenders.horscopodiario/resources/appname} |
"{19A1FC0B-CB14-4FF3-B28D-00D86FA24C1D}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{1A202387-7AEE-4302-A19E-03B78B27197F}" = dir=out | name=adera |
"{20D66489-2B03-4FE7-9FB5-E8CBCCDA4390}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{223673DB-27B0-4D58-BE35-4D8AE4879B0B}" = dir=out | name=mytf1 |
"{244E2A9A-D92A-4975-A86E-E1C7D0D91719}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{282A0477-787B-4C9E-A9A0-07BE7DEB4991}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{323A3B21-6DFB-4FC2-A605-4D80484ABEB4}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{33907CBA-EF85-4B9B-92FE-42599538FEDA}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{37CDA6EA-BB92-4512-B494-38F63AF1DFFE}" = dir=out | name=@{aheadsolutions.hangmandeluxepremium_1.0.0.18_x64__dyv241ra4wh74?ms-resource://aheadsolutions.hangmandeluxepremium/resources/appname} |
"{386D5EFE-B53B-4446-964D-6B2600664AAF}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{3BE61E84-5913-4603-9858-F414A7788EE2}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{41A58919-84C1-42D2-A031-926A1562DA5F}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{456FBF2A-AF29-4E1E-B2D2-E4C74DDFE161}" = dir=out | name=taptiles |
"{49D88D91-8886-4771-91AE-762AE6FFBA64}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{4E5DB9CC-470A-4726-BB2A-1BABFB33A3A5}" = dir=out | name=windows_ie_ac_001 |
"{518991F3-59CA-410F-A53F-2B8B34A2BB1A}" = dir=out | name=@{microsoft.zunemusic_1.5.146.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{57C0F666-E390-4EA9-A1C4-F5B25AC7673B}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{5A5DC8C7-17DE-4ABA-8242-8914677BA8C9}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{5A88D716-4169-41AF-A558-D5CB53E0AC7A}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{727FE76E-EE93-4622-B39F-D2F5154FB042}" = dir=out | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{7AB74C4D-79D6-4C3A-B984-FE703D5B58C6}" = dir=out | name=fresh paint |
"{7AFE8FEE-2281-4F5F-89CC-20BB59250CB2}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7CD29738-74EC-48C1-AC8D-D2087A1ED9AC}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{83364510-BC22-402E-8F38-0FF207CB4227}" = dir=out | name=@{microsoft.skypeapp_1.0.0.266_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} |
"{8604A0FF-DB31-4A24-B07F-4368D2706231}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} |
"{863251B7-EE78-4CF0-925C-6261A0159C07}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{945D9678-51F8-4FCC-9520-818455886723}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} |
"{94A6CC64-68AF-48EE-A747-582936D755ED}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{967E2A47-828B-42F1-9994-E30081710B32}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{AB58B4D8-7B1C-4752-8379-5D4A3C3A9C44}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd cinema\powerdvdcinema10.exe |
"{ABF2F8C9-AE85-4B78-9C98-3F705819B82B}" = dir=in | name=pinball fx2 |
"{AE0AD75A-CBB0-4D6E-B608-B1D3A32B86F5}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{BB0A1068-4D31-4C90-9AAB-213E8C5D99F4}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{BB820669-85E8-4DEC-A118-26B762566434}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{C4C7D0F2-F5ED-4D80-AA2F-8C53FB8A950C}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{C6B1742C-68F0-488F-BD22-19900F51D440}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{C72B7DB9-571F-44E3-9484-D865DCD0276C}" = dir=out | name=météo-france |
"{CB85612C-7287-48C5-9FA7-81739FC2A9A5}" = dir=in | name=@{microsoft.skypeapp_1.0.0.266_x86__kzf8qxf38zg5c?ms-resource://microsoft.skypeapp/resources/manifest_display_name} |
"{D11E040F-3350-45C7-94D8-A66FEB69F093}" = dir=out | name=microsoft solitaire collection |
"{D2320122-572B-4394-9097-A943F0FFC441}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe |
"{D585DFF9-AC83-47A0-BB37-D6FC5F468A1C}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\platform\mcsvchost\mcsvhost.exe |
"{DA3E476E-4C95-4E86-BC07-ACBDFC51DBF9}" = dir=in | name=@{browserchoice_6.2.0.0_neutral_neutral_cw5n1h2txyewy?ms-resource://browserchoice/resources/displayname} |
"{DA99D871-481D-44B7-AEFB-1E4B5B744D04}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{DADAFDC4-54FE-4415-961A-5CB18F825CD9}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{EB0B3F5A-43CB-4F63-98E9-8A98D58A3C8F}" = dir=in | name=météo-france |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03D562B5-C4E2-4846-A920-33178788BE00}" = Windows Live Communications Platform
"{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
"{0F929651-F516-4956-90F2-FFBD2CD5D30E}" = Photo Gallery
"{0FD2B9C6-DB91-48EA-9518-AB5B68CA1E28}" = Movie Maker
"{0FD66C6F-4023-4C74-AF8E-9B8B2053868E}" = Fotogalerie
"{0FF9CC94-EF23-401E-BDBD-37403D1A2B38}" = Windows Live SOXE Definitions
"{10640F6D-6AB0-401E-9FC6-A94D19C580BC}" = Windows Live UX Platform Language Pack
"{119A44B5-6237-4D56-8424-5DAE70ED3F4E}" = Windows Live UX Platform Language Pack
"{147FBA18-A6BB-4AD5-8F0A-37380AAABD76}" = Photo Common
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
"{1EFB835F-DD75-48EC-BB3D-1A71CF604457}" = Windows Live Writer
"{2020C08E-74F5-4E9F-BD2A-41F8CB6EBA10}" = Photo Gallery
"{22C58DA3-FA02-4DD3-8C5B-23570411E95B}" = Windows Live Writer Resources
"{23B93929-FAD4-40E5-96C6-0E977BB87204}" = Windows Live Essentials
"{26A24AE4-039D-4CA4-87B4-2F83217045FF}" = Java 7 Update 45
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Qualcomm Atheros Client Installation Program
"{356BAE2E-3A48-4A6F-8BC6-AC62D50ECFA3}" = Windows Live Messenger
"{3BD8FD6A-D36D-45D9-BB5C-CD39404C222F}" = Windows Live Writer Resources
"{3C5F91EF-5C0B-4D13-BCBE-0FC6FC3ED7F9}" = Movie Maker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{45898170-E68C-4F02-AA35-C2186BF347A3}" = Movie Maker
"{46F044A5-CE8B-4196-984E-5BD6525E361D}" = Apple Application Support
"{49DC9658-D26A-4AAB-A83A-2655B8033056}" = Photo Common
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AB9FFAB-FFA5-49AF-9712-68B7B859B1F3}" = Windows Live Writer
"{4D3286A6-F6AB-498A-82A4-E4F040529F3D}" = ASUS Smart Gesture
"{4F8C9861-DDCF-4EE8-978C-35B691C406B3}" = OpenOffice 4.0.0
"{5172E572-C175-4F80-A6D5-5CB45826AD61}" = SceneSwitch
"{58172D66-2F69-4215-9AEC-ED8196023736}" = ASUS Tutor
"{5A0EE0F0-E909-4F3B-B437-AAD9252427CB}" = Windows Live Installer
"{5C601EA8-D519-4010-8CD0-BD3B94A6DD58}" = Photo Common
"{6066D3FE-3692-4449-A3C8-D1EAA2C0E9E7}" = Movie Maker
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{6B6923B9-8719-425B-916C-CD2908F31AAF}" = Windows Live SOXE
"{6BA68C11-0B63-4192-B880-0B5E3F7949F9}" = Windows Live UX Platform Language Pack
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{749F674B-2674-47E8-879C-5626A06B2A91}" = ASUS InstantOn
"{7693587D-5D66-4208-ABEA-C370217D1D9B}" = Movie Maker
"{7881716A-5DA3-4B3F-A3CC-E63676E5CF78}" = Windows Live Messenger
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78DF4802-2B2B-4333-99AF-363C2F93D476}" = Windows Live Writer Resources
"{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}" = Bing Bureau
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}" = ASUS Instant Connect
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{8BC85D25-AF2D-40DA-BD04-016B64D384BF}" = Windows Live Mail
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash
"{90150000-0138-0409-0000-0000000FF1CE}" = Microsoft Office
"{91D59688-8209-4569-B581-B870BDC74EAB}" = Windows Live Messenger
"{936D4074-6A57-45ED-AF5A-F7CF5A56DE6F}" = Windows Live Essentials
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A52DB080-D445-49EB-90D2-03B9CD794511}" = Photo Common
"{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}" = ASUS USB Charger Plus
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA806DB1-E882-4834-8102-B5F256BE9A2F}" = Windows Live Essentials
"{AAA94EAA-40A4-458C-9D86-D1DA765B51D5}" = Windows Live Writer
"{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package
"{AC76BA86-7AD7-1036-7B44-AB0000000001}" = Adobe Reader XI (11.0.05) - Français
"{AEFAF1CC-9688-402B-A3E3-7E8F2043874C}" = Windows Live Writer
"{B286BAC3-CBE6-4854-BF68-EB72A34CEA56}" = Windows Live Messenger
"{BBFCB394-78EB-45D4-BAC6-809AB1DF5F83}" = Windows Live Mail
"{BDDC2D1F-092F-476F-A7D7-819AA5F434DF}" = Windows Live UX Platform Language Pack
"{C0018D63-C33C-4515-9CE8-3BC8830F79A1}" = Photo Gallery
"{C156E7D3-D8B1-4303-BE38-99CE675C393D}" = Windows Live Writer
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint 2.5
"{C6B0EE9E-2128-4448-B7AE-5E2B46E0F0E7}" = Windows Live Photo Common
"{CCC7C18E-1BEA-409F-B7A9-6C9740B99119}" = Windows Live UX Platform Language Pack
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D29B0575-C3DE-4746-A893-4FDF0F7D68B2}" = Windows Live Mail
"{D604900F-A275-416C-AF9D-CDEDF58B72DB}" = Windows Live Mail
"{DE7D8CF9-9C52-4BE0-B3E0-D4F116C524A8}" = Windows Live
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = ASUSDVD
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E13497F0-4C28-47A0-B994-4D5E6D0F64A2}" = Windows Live Mail
"{E169436E-49D8-419B-A5C0-D245EAF99611}" = Movie Maker
"{E3445598-4424-4EE2-B71C-C23325F7FB71}" = Windows Live PIMT Platform
"{E3E8006D-3DD9-40DF-9171-1EDE1023E57C}" = Windows Live Mail
"{EC5E0CAF-BC28-401C-B8BE-89C496D6D66F}" = Windows Live Essentials
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{ECD07D50-05C3-40E6-A10E-A371AC7E4B8A}" = Windows Live Writer
"{EFBCA571-617D-484A-9ECA-E301BB6D0750}" = Windows Live Writer
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F0E58739-2B4C-498F-9B0D-FF0F2FD52B61}" = Windows Live UX Platform
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1A79BDD-A47F-441B-954D-EE045C379EBB}" = Windows Live Writer Resources
"{F4D99A13-F63A-4FC1-8799-CFFDB78DDFB3}" = Galerie de photos
"{F6F30C28-38AA-4DBA-AE0B-7E30238E61BB}" = Junk Mail filter update
"{F875E135-31C5-4C4D-929F-D49E6332E7F1}" = Photo Common
"{F9B9F5AA-D604-47A7-9238-22A664DBED16}" = Windows Live Messenger
"{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}" = ASUS Live Update
"{FA6BC7A5-85B3-4DC2-825C-D508E386151A}" = Raccolta foto
"{FC5F20C5-C44E-40DE-927C-4C7D7994912F}" = Windows Live Messenger
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel(R) SDK for OpenCL - CPU Only Runtime Package
"{FFCF82EC-895F-4AC8-925E-3412FE25EF62}" = Windows Live Writer Resources
"Asus Vibe2.0" = AsusVibe2.0
"ASUS WebStorage" = ASUS WebStorage Sync Agent
"Google Chrome" = Google Chrome
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint 2.5
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = ASUSDVD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"MyBitCast" = MyBitCast 2.0
"WinLiveSuite" = Windows Live
"ZHPDiag_is1" = ZHPDiag 2013

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1305010613-2064220777-3922521960-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SkyDriveSetup.exe" = Microsoft SkyDrive

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 20/11/2013 09:45:59 | Computer Name = PC-Megane | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1110

Error - 20/11/2013 09:45:59 | Computer Name = PC-Megane | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1110

Error - 20/11/2013 10:02:17 | Computer Name = PC-Megane | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 20/11/2013 10:02:17 | Computer Name = PC-Megane | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 979688

Error - 20/11/2013 10:02:17 | Computer Name = PC-Megane | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 979688

Error - 20/11/2013 10:51:31 | Computer Name = PC-Megane | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 20/11/2013 10:51:31 | Computer Name = PC-Megane | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1187

Error - 20/11/2013 10:51:31 | Computer Name = PC-Megane | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1187

Error - 21/11/2013 01:43:18 | Computer Name = PC-Megane | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 21/11/2013 11:46:49 | Computer Name = PC-Megane | Source = Customer Experience Improvement Program | ID = 1008
Description =

[ System Events ]
Error - 19/11/2013 10:17:17 | Computer Name = PC-Megane | Source = Schannel | ID = 36884
Description = Le certificat reçu à  partir du serveur distant ne contient par le
nom attendu. Il n&#130;est par conséquent pas possible de déterminer si nous sommes connecté
au serveur correct. Le nom de serveur attendu est client.wns.windows.com. La demande
de connexion SSL a échoué. Les données jointes contiennent le certificat du serveur.

Error - 19/11/2013 10:17:40 | Computer Name = PC-Megane | Source = Schannel | ID = 36888
Description = Une alerte irrécupérable a été générée et envoyée au point de terminaison
distant. Ceci peut entraîner l&#130;arrêt de la connexion. Le code d&#130;erreur irrécupérable
défini par le protocole TLS est 43. L&#130;état d&#130;erreur de Windows SChannel est 552.

Error - 19/11/2013 10:17:40 | Computer Name = PC-Megane | Source = Schannel | ID = 36884
Description = Le certificat reçu à  partir du serveur distant ne contient par le
nom attendu. Il n&#130;est par conséquent pas possible de déterminer si nous sommes connecté
au serveur correct. Le nom de serveur attendu est client.wns.windows.com. La demande
de connexion SSL a échoué. Les données jointes contiennent le certificat du serveur.

Error - 19/11/2013 10:18:08 | Computer Name = PC-Megane | Source = Schannel | ID = 36888
Description = Une alerte irrécupérable a été générée et envoyée au point de terminaison
distant. Ceci peut entraîner l&#130;arrêt de la connexion. Le code d&#130;erreur irrécupérable
défini par le protocole TLS est 43. L&#130;état d&#130;erreur de Windows SChannel est 552.

Error - 19/11/2013 10:18:08 | Computer Name = PC-Megane | Source = Schannel | ID = 36884
Description = Le certificat reçu à  partir du serveur distant ne contient par le
nom attendu. Il n&#130;est par conséquent pas possible de déterminer si nous sommes connecté
au serveur correct. Le nom de serveur attendu est client.wns.windows.com. La demande
de connexion SSL a échoué. Les données jointes contiennent le certificat du serveur.

Error - 19/11/2013 10:18:40 | Computer Name = PC-Megane | Source = Schannel | ID = 36888
Description = Une alerte irrécupérable a été générée et envoyée au point de terminaison
distant. Ceci peut entraîner l&#130;arrêt de la connexion. Le code d&#130;erreur irrécupérable
défini par le protocole TLS est 43. L&#130;état d&#130;erreur de Windows SChannel est 552.

Error - 19/11/2013 10:18:40 | Computer Name = PC-Megane | Source = Schannel | ID = 36884
Description = Le certificat reçu à  partir du serveur distant ne contient par le
nom attendu. Il n&#130;est par conséquent pas possible de déterminer si nous sommes connecté
au serveur correct. Le nom de serveur attendu est client.wns.windows.com. La demande
de connexion SSL a échoué. Les données jointes contiennent le certificat du serveur.

Error - 20/11/2013 17:51:37 | Computer Name = PC-Megane | Source = EventLog | ID = 6008
Description = L&#130;arrêt système précédant à  22:23:20 le ?20/?11/?2013 n&#130;était pas
prévu.

Error - 21/11/2013 04:34:33 | Computer Name = PC-Megane | Source = Schannel | ID = 36888
Description = Une alerte irrécupérable a été générée et envoyée au point de terminaison
distant. Ceci peut entraîner l&#130;arrêt de la connexion. Le code d&#130;erreur irrécupérable
défini par le protocole TLS est 43. L&#130;état d&#130;erreur de Windows SChannel est 552.

Error - 21/11/2013 04:34:33 | Computer Name = PC-Megane | Source = Schannel | ID = 36884
Description = Le certificat reçu à  partir du serveur distant ne contient par le
nom attendu. Il n&#130;est par conséquent pas possible de déterminer si nous sommes connecté
au serveur correct. Le nom de serveur attendu est client.wns.windows.com. La demande
de connexion SSL a échoué. Les données jointes contiennent le certificat du serveur.


< End of report >
Avatar du membre
par billmaxime
#18387
:hello: lcemegane,

ok, fais ceci et poste le rapport s'il te plaît
  • Télécharge SFTGC (de Pierre13) sur ton Bureau et pas ailleurs !.
  • Lance SFTGC, exécuter en tant qu'administrateur sous Windows : 7/8 et Vista
  • Clique sur GO

    Image

    Note : A la fin un rapport va s'ouvrir
  • Une fois le scan terminé rends toi sur le bureau, le fichier SFTGC.txt à  été créé.
  • Héberge le rapport SFTGC.txt sur SosUpload, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum
dis moi comment va le pc s'il te plaît

:merci2:
Avatar du membre
par lcemegane
#18508
Voici le début du rapport :

Rapport de SFTGC (Pierre13) du Vendredi 22 Novembre 2013 à  16:46:46 version : 2.0.0.55
Mis à  jour le 12/09/2013
Outil lancé en Mode normal et En tant qu'administrateur
Windows 8 64 bits

Tool start in C:\Users\Mégane\Desktop

717 éléments supprimés => 50.63 Mo libérés. (28 s)

C:\Users\Mégane\AppData\Local\Temp\1696_1043
C:\Users\Mégane\AppData\Local\Temp\2552_1374
C:\Users\Mégane\AppData\Local\Temp\2964_6218
C:\Users\Mégane\AppData\Local\Temp\3436_27413
C:\Users\Mégane\AppData\Local\Temp\3676_117
C:\Users\Mégane\AppData\Local\Temp\4092_5777
C:\Users\Mégane\AppData\Local\Temp\5020_15993
C:\Users\Mégane\AppData\Local\Temp\5076_27818
C:\Users\Mégane\AppData\Local\Temp\5176_29947
C:\Users\Mégane\AppData\Local\Temp\5184_2680
C:\Users\Mégane\AppData\Local\Temp\5248_8083
C:\Users\Mégane\AppData\Local\Temp\5468_25926
C:\Users\Mégane\AppData\Local\Temp\5992_10438
C:\Users\Mégane\AppData\Local\Temp\6884_6830
C:\Users\Mégane\AppData\Local\Temp\7324_30931
C:\Users\Mégane\AppData\Local\Temp\7672_2150
C:\Users\Mégane\AppData\Local\Temp\7864_28754
C:\Users\Mégane\AppData\Local\Temp\acrord32_sbx
C:\Users\Mégane\AppData\Local\Temp\AdobeARM.log
C:\Users\Mégane\AppData\Local\Temp\chrome_installer.log
C:\Users\Mégane\AppData\Local\Temp\hsperfdata_Mégane
C:\Users\Mégane\AppData\Local\Temp\InsOnMode.ini
C:\Users\Mégane\AppData\Local\Temp\JavaDeployReg.log
C:\Users\Mégane\AppData\Local\Temp\jusched.log
C:\Users\Mégane\AppData\Local\Temp\Low
C:\Users\Mégane\AppData\Local\Temp\SetupAdminA54.log
C:\Users\Mégane\AppData\Local\Temp\winstore.log
C:\Users\Mégane\AppData\Local\Temp\7864_28754\crl-set
C:\Users\Mégane\AppData\Local\Temp\7864_28754\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\7864_28754\manifest.json
C:\Users\Mégane\AppData\Local\Temp\7672_2150\crl-set
C:\Users\Mégane\AppData\Local\Temp\7672_2150\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\7672_2150\manifest.json
C:\Users\Mégane\AppData\Local\Temp\7324_30931\crl-set
C:\Users\Mégane\AppData\Local\Temp\7324_30931\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\7324_30931\manifest.json
C:\Users\Mégane\AppData\Local\Temp\6884_6830\crl-set
C:\Users\Mégane\AppData\Local\Temp\6884_6830\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\6884_6830\manifest.json
C:\Users\Mégane\AppData\Local\Temp\5992_10438\crl-set
C:\Users\Mégane\AppData\Local\Temp\5992_10438\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\5992_10438\manifest.json
C:\Users\Mégane\AppData\Local\Temp\5468_25926\crl-set
C:\Users\Mégane\AppData\Local\Temp\5468_25926\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\5468_25926\manifest.json
C:\Users\Mégane\AppData\Local\Temp\5248_8083\crl-set
C:\Users\Mégane\AppData\Local\Temp\5248_8083\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\5248_8083\manifest.json
C:\Users\Mégane\AppData\Local\Temp\5184_2680\crl-set
C:\Users\Mégane\AppData\Local\Temp\5184_2680\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\5184_2680\manifest.json
C:\Users\Mégane\AppData\Local\Temp\5176_29947\crl-set
C:\Users\Mégane\AppData\Local\Temp\5176_29947\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\5176_29947\manifest.json
C:\Users\Mégane\AppData\Local\Temp\5076_27818\crl-set
C:\Users\Mégane\AppData\Local\Temp\5076_27818\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\5076_27818\manifest.json
C:\Users\Mégane\AppData\Local\Temp\5020_15993\crl-set
C:\Users\Mégane\AppData\Local\Temp\5020_15993\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\5020_15993\manifest.json
C:\Users\Mégane\AppData\Local\Temp\4092_5777\crl-set
C:\Users\Mégane\AppData\Local\Temp\4092_5777\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\4092_5777\manifest.json
C:\Users\Mégane\AppData\Local\Temp\3676_117\crl-set
C:\Users\Mégane\AppData\Local\Temp\3676_117\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\3676_117\manifest.json
C:\Users\Mégane\AppData\Local\Temp\3436_27413\crl-set
C:\Users\Mégane\AppData\Local\Temp\3436_27413\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\3436_27413\manifest.json
C:\Users\Mégane\AppData\Local\Temp\2964_6218\crl-set
C:\Users\Mégane\AppData\Local\Temp\2964_6218\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\2964_6218\manifest.json
C:\Users\Mégane\AppData\Local\Temp\2552_1374\crl-set
C:\Users\Mégane\AppData\Local\Temp\2552_1374\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\2552_1374\manifest.json
C:\Users\Mégane\AppData\Local\Temp\1696_1043\crl-set
C:\Users\Mégane\AppData\Local\Temp\1696_1043\manifest.fingerprint
C:\Users\Mégane\AppData\Local\Temp\1696_1043\manifest.json
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\10 - Over Again.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\21571_Calendrier_universitaire_FLSH_13-14.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\22337_DS_SEM1.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\541511_10151928236165581_281842771_n.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\823WGTMA.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\860OKMZO.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Academic writing cours mardi 05.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Academic writing pour le 19 novembre.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AdwCleaner.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AdwCleaner[S0].lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AdwCleaner[S1].lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Américaine civi.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AW cours 05 nov.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Can French People Speak English. BonjourLovelies.com.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Civi USA cours 2.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Civilisation Américaine TD 19 novembre.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Civilisation Britannique 19 novembre.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Disque amovible (F).lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Documents.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Downloads.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\FAC.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\facebook.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Fashion inspiration-tumblr.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\FILMS.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\https--connect.wifirst.net-redirect_method=GET&redirect_url=http%3A%2F%2Fwww.msftncsi.com%2Fredirect.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\https--secure.skype.com-login-ssononce=648rrj8LO79SAsAtiK6A&go=myaccount&intsrc=client-_-windows8_9-_-1.0-_-go-my-account.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\IMG_0841.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\IMG_1107.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Jason Derulo -Marry Me- Official Lyrics Video-[www_flvto_com].lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Jason Derulo.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Langue Orale ( the good one ).lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Langue Orale (2).lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Langue Orale.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\LCE 2.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Lesson 5 .lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Littérature 21 novembre.odt.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\mbar-1.01.0.1022.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\nrd-hangover2.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Olly Murs- This Song Is About You (Lyrics)-[www_flvto_com].lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\OTL.Txt.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Research paper TEXTS.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Research paper.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Sans nom 1.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Shooting.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Sport represented as a grand event.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Terminaisons faibles phonétique.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\The News.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\TUMBLR NON POSTES NON TRIE.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\tumblr_m1r9ygFRFf1rovmado1_500.jpg.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\tumblr_m27ah8ug411r4grpqo1_500.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\tumblr_m2cc8rAINY1qb9k3go1_500.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\tumblr_m2w3jzyRZP1qij5oho1_500.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\tumblr_m8gk0lgeif1qg22hlo1_500_large.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\tumblr_m8m9abB01u1r2unmto1_500.jpg.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\tumblr_mj19roxtFr1qfwkrao1_500.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\tumblr_mjtfdnYORG1qejm4fo1_500.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\tumblr_mn7lngwKp61rswt5eo1_500.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\tumblr_mo19g0ZQCJ1rkfanfo1_1280.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\tumblr_mutvfjDCPW1rd6cj9o1_250.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\tumblr_mve8hfikTj1qctsgko1_1280.jpg.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Téléchargements.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\VINTED.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Vocabulaire clothes.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\Your Girl.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\zhp.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\ZHPDiag.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\ZHPFIX.EXE-AFDB3DAC.pf.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\[www.Cpasbien.com] Jane.By.Design.S01E13.FASTSUB.VOSTFR.HDTV.XviD-Xtrem (2).lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\[www.Cpasbien.com] Jane.By.Design.S01E13.FASTSUB.VOSTFR.HDTV.XviD-Xtrem.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\[www.Cpasbien.com] One Direction - Take Me Home - [2012-Album] Mp3-320Kbps.lnk
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\25039900b9bba50b.customDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\28c8b86deab549a1.customDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\484d0d7daee6eded.customDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\74d7f43c1561fc1e.customDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7e4dca80246863e3.customDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\83b03b46dcd30a0e.customDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9645f58513b1a821.customDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\bd249197a6faeff2.customDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\f01b4d95cf55d32a.customDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\26bfbdac8c66cb7d.automaticDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\4cb9c5750d51c07f.automaticDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\4d939776340f1d18.automaticDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\5d696d521de238c3.automaticDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\74d7f43c1561fc1e.automaticDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\7a8db574299c8568.automaticDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\7e4dca80246863e3.automaticDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\83b03b46dcd30a0e.automaticDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\9b9cdc69c1c24e2b.automaticDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\a2b95ca27b6c33d9.automaticDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\ae6df75df512bd06.automaticDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f3c90dec42360729.automaticDestinations-ms
C:\Users\Mégane\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\ff103e2cc310d0d.automaticDestinations-ms
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\03C2624375988154FBF20373B7D495E8_4CE1399DE4CEDD0087BBFC0689796C3F
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\04AFA8793E5CDC4A81C6CD4554A30707
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_1E562C75E6CFA21DBFA4413069869356
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\086C252C05DBB672D245CC31A72A2E67
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0B1B84E1509125064E3D44331C3817C2_3E6BB635115BB4A3C7C9DF5009227113
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\130ADF60D1B7B3CF82CC6CA82D961601_2FFE778CED2FD9BBAB74B5314F3440CA
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\130ADF60D1B7B3CF82CC6CA82D961601_3722A7817B153CAC96BEA5D2AB2FB31E
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\130ADF60D1B7B3CF82CC6CA82D961601_54F461E341AC92480E0EB583C80AB528
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\130ADF60D1B7B3CF82CC6CA82D961601_83653FB4B566DAD9C63D2C31D4C9715C
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\130ADF60D1B7B3CF82CC6CA82D961601_91579693C2D8584E3FFB75C581EC5E8B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\130ADF60D1B7B3CF82CC6CA82D961601_BFF3E82445C199812E8EC4CC74EA6FD4
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\130ADF60D1B7B3CF82CC6CA82D961601_EC2B8F0C530DA57B6BD72F9ED19E4B95
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\130ADF60D1B7B3CF82CC6CA82D961601_F3F138DDA4E72F849B7E03101CED9406
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\161B1C6D9CDC22FEB7269E395DF82F33_ACE2C216192F681278D474D3F3FB331A
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1DAF2884EC4DFA96BA4A58D4DBC9C406
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1F39B5CFACECFDE48DB25BCA2231FAC6_135A427F1ED873A4BF5097F7A809FA2A
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\219976D61D72B43A8A9F6916F467E10F_376E88BBCF4E0F0C2D6E36DC7206916B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\219976D61D72B43A8A9F6916F467E10F_51EFD2D60ADD1881AF594C1F47629221
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\23B523C9E7746F715D33C6527C18EB9D
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2439BE688C04EC10EE2B724361DFB2CA_C520C54E784EC869C630392026CE9925
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2E980CF7BB84455884A2F90C0668C729_FCFF5DBC182D9C0A4C50FA1AE3576B84
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\30F7B429BB1DACA9B591B41E016BED66_F6024CD0767F1B4C9F060C7479C6DC83
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\3F9CAA0497A0877CE21ECD947E7238B5_E1F0919A92865CED77950400693A532F
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4309200C3DBAD0F6F0DFACE9165FD092
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_232288A20D63375EAC649186251E5D74
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_569BD946168DB279A65378F7D088CFD0
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_AFC22B77ED08EE3E2B28B6DE75CADDF5
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4E29C7E9E83048EFCCC5C3D57B6818DB
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4E921787B7D7C838D920938DFC6D122E_79F029B769AAE8010337F77D683CB533
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5457A8CE4B2A7499F8299A013B6E1C7C_4BDA944235F1446F185236D493959297
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5457A8CE4B2A7499F8299A013B6E1C7C_A6B2237C23668D872C46152358A3FB3E
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5457A8CE4B2A7499F8299A013B6E1C7C_D734EC3DD00546F46D368325396086B0
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\566A973C3ADBC70963C072413659C1CB_39482AEE62881116513CBB19A044403F
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AA3321A15A787985201D7A6820782F0_0AB46376AFB6F40B0426680E3025D384
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AA3321A15A787985201D7A6820782F0_35BFA9D40D21E81B408449EB9D85CCA4
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6AA3321A15A787985201D7A6820782F0_4E35DE6F4FCFB7BE2C045F6B5ED89FC8
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6B7AED56F69397028F35E77E6DD681FC
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_11D7BA58D75E54D622A3AD9CDF9905BB
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\74BFD122C0875EC75DBE5C6DB4C59019
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\783DF2F5A7C9BC04C36663632D14B993_09A85C5418FB163D61A6CDA83D9C0B2C
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\783DF2F5A7C9BC04C36663632D14B993_09E6BFC8958A4903B51F28C3DF0B32CC
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\783DF2F5A7C9BC04C36663632D14B993_169DE3439FD2D9FE0AE07883B5A27A1B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\783DF2F5A7C9BC04C36663632D14B993_6C67FC20D6E627EA8FBFF0B449CB060B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_36E3207A43A87A281983E8D0B4D7BCDF
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_5AE6F9C328F80F504A42447CD464EEC0
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_82A6E25B79E891F34987BD4C93317D0A
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_96E18C6F7F11D436D50EB658BB37DA57
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_AE80968B09655437A4C6DA8671FF8BB7
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_B2DB1CC4B5F2D2A802D56AAED525802D
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_C9B190D3A0B2283820B6C33764149AA6
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_CD4662E1A7F15144990B9C9F03164C3A
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_D120C285892F736A029B7FDC0C33E264
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_D7F0806A9FAA0922F41F59F20EB11D5C
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7C44AA84A5CFEC3289884F54A088297E_C9E46D66912637334CBAD07207DBA517
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D1F03728133589A90656A87E482B21F
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_1D5A876A9113EC07224C45E5A870E3BD
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_8CA7164968F366C9A94AC8E71C4BDD9B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_2E4BCCAAA8B52E99AC2D8241A872DD77
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_2F1BD5B4F9DBD26AB429C868029F876C
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_3B544D333012FB463337A933E27FA00D
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_602DEDB8C7D6326D5C8D775461CB2C26
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_6F2F7960AAA8F8616CDE8AF3EC245868
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_918340BA089892122B5626AE042DBBDE
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_95BE0E24685C739E0287588432223979
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_B313A6AEB91DC2BE7A8547095314EC1C
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_CAED40D1E29B0CF7BFCE055DDE63B150
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_D47B0351FE4289C5C14A4B1359D31F2A
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_E4DFCF5325A7B2A17D0E55108E8A34A8
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_EC9834D79F6FC380DD6205AD8CA74CEB
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_F2EFD568D6CA72D7BC802424E3F92B9A
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8059E9A0D314877E40FE93D8CCFB3C69_F9758F0CEE4021D579BC2D754B77BF07
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\855CF405355328EC482A28D56A44CFB0_120F73EDCEB7A42DFB7C70F56DD38B42
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8890A77645B73478F5B1DED18ACBF795_1E5D470765E0BE1964814B1F5A3581DC
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8890A77645B73478F5B1DED18ACBF795_D3DB95C0E7608ACC9AA10ACCCCEBBDF5
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EBFACB3A66359F9514D044C86BA4794
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\91ECFED5143F7F4F4576655D8EFAB51C_17392CB0F1D8BCBED3814699659DFF76
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94C0DD15E1E10CFC94461B254088DA63_E28BA5D0B90D87A2CBA70A99B6D6E3A5
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\955CAB6FF6A24D5820D50B5BA1CF79C7_0D0504E280D4BC90041F089A5D901106
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\955CAB6FF6A24D5820D50B5BA1CF79C7_CFEA3385E24D822B0027B3D9A091B242
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A3C4F17BF8CB09C3DF2A086B36306B5C_C1C0B5D167C066A750AF361DC97F90F6
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\AC9005F5466BD463DF06D711B370595F
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B3BB9C1BA2D19E090AE305B2683903A0_3A991EF068DA80925661324DEEB3A2FC
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B3BB9C1BA2D19E090AE305B2683903A0_5864DDF0697688952ACDB52C47E0933E
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B3BB9C1BA2D19E090AE305B2683903A0_6F0A84CE2BA99BD19D42C92610275852
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B90B117906B8A74C79D1BC450C2B94B1_A54F26A8A41DE52C237D54D67F12793F
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BBB768C456D9E2DCD3EF595C400D483D_64C05B9EB32FC3D0CE6CB126561EEBFF
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BD8A14C7C024625432CC03FE72E47EF0_35DB72DF5C829F76FA820993F2C82D80
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BD8A14C7C024625432CC03FE72E47EF0_6FD1BEFD298F4FD3EE4B4EE2E6631CC7
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BD8A14C7C024625432CC03FE72E47EF0_BC4EC46B2A6D9424FFBAF3A0C035586C
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C25FBC9FE17D1C30FF964815C35F0AB3
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C3B4324B100AA32F7BE995E7E34E0AA5_15C23806E36E1233F1A79C3B11377E1C
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C437972632A488222EA069E1572887C7_9AD1C6A04DF1BBA89E35E1142E44AE70
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C5C16E8B8D126375C32C54465617D152_E89BE6285BCA3816E41A2C36E7E420A5
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CA7B2D59B4E9BC2D316D1AECDFC12F63_AE3FE875193DBB7C9EC575C998F19368
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CA7B2D59B4E9BC2D316D1AECDFC12F63_B9385197A2757B8FEC32C5C94631DF12
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CA7B2D59B4E9BC2D316D1AECDFC12F63_E8FFB3D833ACBBA2A753BCE3F81C274B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D0F063B6B88A2B8BFE21C3993A613447
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E63A640A06A2B005AB42F3250BC98D9E_6020995806BF99A1FBC324A7B889F612
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F30B1DAC467EEB5A0EB57E5457CD952D_5196DDA6F3358FF603DC5010CA4ED54B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F4B372709D6C2AD766C34D274501DC76_C08D897FBCD7D5D638FCD154D1404CBE
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F4D9C889B7AEBCF4E1A2DAABC5C3628A_45372F968036A3D8F01EF13C820C17D1
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F4D9C889B7AEBCF4E1A2DAABC5C3628A_AD67B42F526068C7A09A14203543DAE9
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F72943F1E01540BBACB5396C76DD6AAA
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F99CAC852E278659C1E715225DD11A14_A941BBEE5E39237968E8808A19F1998B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\FB788E090BC1F3AA2FBC9E8FB2859601
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\FCEA474F228C13CD0DAD678431D0ACFC
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\03C2624375988154FBF20373B7D495E8_4CE1399DE4CEDD0087BBFC0689796C3F
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\04AFA8793E5CDC4A81C6CD4554A30707
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_1E562C75E6CFA21DBFA4413069869356
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\086C252C05DBB672D245CC31A72A2E67
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0B1B84E1509125064E3D44331C3817C2_3E6BB635115BB4A3C7C9DF5009227113
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\130ADF60D1B7B3CF82CC6CA82D961601_2FFE778CED2FD9BBAB74B5314F3440CA
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\130ADF60D1B7B3CF82CC6CA82D961601_3722A7817B153CAC96BEA5D2AB2FB31E
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\130ADF60D1B7B3CF82CC6CA82D961601_54F461E341AC92480E0EB583C80AB528
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\130ADF60D1B7B3CF82CC6CA82D961601_83653FB4B566DAD9C63D2C31D4C9715C
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\130ADF60D1B7B3CF82CC6CA82D961601_91579693C2D8584E3FFB75C581EC5E8B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\130ADF60D1B7B3CF82CC6CA82D961601_BFF3E82445C199812E8EC4CC74EA6FD4
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\130ADF60D1B7B3CF82CC6CA82D961601_EC2B8F0C530DA57B6BD72F9ED19E4B95
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\130ADF60D1B7B3CF82CC6CA82D961601_F3F138DDA4E72F849B7E03101CED9406
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\161B1C6D9CDC22FEB7269E395DF82F33_ACE2C216192F681278D474D3F3FB331A
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1DAF2884EC4DFA96BA4A58D4DBC9C406
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1F39B5CFACECFDE48DB25BCA2231FAC6_135A427F1ED873A4BF5097F7A809FA2A
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\219976D61D72B43A8A9F6916F467E10F_376E88BBCF4E0F0C2D6E36DC7206916B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\219976D61D72B43A8A9F6916F467E10F_51EFD2D60ADD1881AF594C1F47629221
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\23B523C9E7746F715D33C6527C18EB9D
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2439BE688C04EC10EE2B724361DFB2CA_C520C54E784EC869C630392026CE9925
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2E980CF7BB84455884A2F90C0668C729_FCFF5DBC182D9C0A4C50FA1AE3576B84
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\30F7B429BB1DACA9B591B41E016BED66_F6024CD0767F1B4C9F060C7479C6DC83
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\3F9CAA0497A0877CE21ECD947E7238B5_E1F0919A92865CED77950400693A532F
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4309200C3DBAD0F6F0DFACE9165FD092
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_232288A20D63375EAC649186251E5D74
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_569BD946168DB279A65378F7D088CFD0
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_AFC22B77ED08EE3E2B28B6DE75CADDF5
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4E29C7E9E83048EFCCC5C3D57B6818DB
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4E921787B7D7C838D920938DFC6D122E_79F029B769AAE8010337F77D683CB533
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5457A8CE4B2A7499F8299A013B6E1C7C_4BDA944235F1446F185236D493959297
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5457A8CE4B2A7499F8299A013B6E1C7C_A6B2237C23668D872C46152358A3FB3E
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5457A8CE4B2A7499F8299A013B6E1C7C_D734EC3DD00546F46D368325396086B0
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\566A973C3ADBC70963C072413659C1CB_39482AEE62881116513CBB19A044403F
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AA3321A15A787985201D7A6820782F0_0AB46376AFB6F40B0426680E3025D384
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AA3321A15A787985201D7A6820782F0_35BFA9D40D21E81B408449EB9D85CCA4
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6AA3321A15A787985201D7A6820782F0_4E35DE6F4FCFB7BE2C045F6B5ED89FC8
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6B7AED56F69397028F35E77E6DD681FC
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_11D7BA58D75E54D622A3AD9CDF9905BB
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\74BFD122C0875EC75DBE5C6DB4C59019
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\783DF2F5A7C9BC04C36663632D14B993_09A85C5418FB163D61A6CDA83D9C0B2C
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\783DF2F5A7C9BC04C36663632D14B993_09E6BFC8958A4903B51F28C3DF0B32CC
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\783DF2F5A7C9BC04C36663632D14B993_169DE3439FD2D9FE0AE07883B5A27A1B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\783DF2F5A7C9BC04C36663632D14B993_6C67FC20D6E627EA8FBFF0B449CB060B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_36E3207A43A87A281983E8D0B4D7BCDF
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_5AE6F9C328F80F504A42447CD464EEC0
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_82A6E25B79E891F34987BD4C93317D0A
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_96E18C6F7F11D436D50EB658BB37DA57
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_AE80968B09655437A4C6DA8671FF8BB7
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_B2DB1CC4B5F2D2A802D56AAED525802D
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_C9B190D3A0B2283820B6C33764149AA6
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_CD4662E1A7F15144990B9C9F03164C3A
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_D120C285892F736A029B7FDC0C33E264
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_D7F0806A9FAA0922F41F59F20EB11D5C
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7C44AA84A5CFEC3289884F54A088297E_C9E46D66912637334CBAD07207DBA517
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D1F03728133589A90656A87E482B21F
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_1D5A876A9113EC07224C45E5A870E3BD
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_8CA7164968F366C9A94AC8E71C4BDD9B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_2E4BCCAAA8B52E99AC2D8241A872DD77
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_2F1BD5B4F9DBD26AB429C868029F876C
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_3B544D333012FB463337A933E27FA00D
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_602DEDB8C7D6326D5C8D775461CB2C26
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_6F2F7960AAA8F8616CDE8AF3EC245868
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_918340BA089892122B5626AE042DBBDE
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_95BE0E24685C739E0287588432223979
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_B313A6AEB91DC2BE7A8547095314EC1C
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_CAED40D1E29B0CF7BFCE055DDE63B150
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_D47B0351FE4289C5C14A4B1359D31F2A
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_E4DFCF5325A7B2A17D0E55108E8A34A8
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_EC9834D79F6FC380DD6205AD8CA74CEB
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_F2EFD568D6CA72D7BC802424E3F92B9A
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8059E9A0D314877E40FE93D8CCFB3C69_F9758F0CEE4021D579BC2D754B77BF07
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\855CF405355328EC482A28D56A44CFB0_120F73EDCEB7A42DFB7C70F56DD38B42
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8890A77645B73478F5B1DED18ACBF795_1E5D470765E0BE1964814B1F5A3581DC
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8890A77645B73478F5B1DED18ACBF795_D3DB95C0E7608ACC9AA10ACCCCEBBDF5
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EBFACB3A66359F9514D044C86BA4794
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\91ECFED5143F7F4F4576655D8EFAB51C_17392CB0F1D8BCBED3814699659DFF76
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94C0DD15E1E10CFC94461B254088DA63_E28BA5D0B90D87A2CBA70A99B6D6E3A5
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\955CAB6FF6A24D5820D50B5BA1CF79C7_0D0504E280D4BC90041F089A5D901106
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\955CAB6FF6A24D5820D50B5BA1CF79C7_CFEA3385E24D822B0027B3D9A091B242
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A3C4F17BF8CB09C3DF2A086B36306B5C_C1C0B5D167C066A750AF361DC97F90F6
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\AC9005F5466BD463DF06D711B370595F
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B3BB9C1BA2D19E090AE305B2683903A0_3A991EF068DA80925661324DEEB3A2FC
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B3BB9C1BA2D19E090AE305B2683903A0_5864DDF0697688952ACDB52C47E0933E
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B3BB9C1BA2D19E090AE305B2683903A0_6F0A84CE2BA99BD19D42C92610275852
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B90B117906B8A74C79D1BC450C2B94B1_A54F26A8A41DE52C237D54D67F12793F
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BBB768C456D9E2DCD3EF595C400D483D_64C05B9EB32FC3D0CE6CB126561EEBFF
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BD8A14C7C024625432CC03FE72E47EF0_35DB72DF5C829F76FA820993F2C82D80
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BD8A14C7C024625432CC03FE72E47EF0_6FD1BEFD298F4FD3EE4B4EE2E6631CC7
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BD8A14C7C024625432CC03FE72E47EF0_BC4EC46B2A6D9424FFBAF3A0C035586C
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C25FBC9FE17D1C30FF964815C35F0AB3
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C3B4324B100AA32F7BE995E7E34E0AA5_15C23806E36E1233F1A79C3B11377E1C
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C437972632A488222EA069E1572887C7_9AD1C6A04DF1BBA89E35E1142E44AE70
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C5C16E8B8D126375C32C54465617D152_E89BE6285BCA3816E41A2C36E7E420A5
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CA7B2D59B4E9BC2D316D1AECDFC12F63_AE3FE875193DBB7C9EC575C998F19368
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CA7B2D59B4E9BC2D316D1AECDFC12F63_B9385197A2757B8FEC32C5C94631DF12
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CA7B2D59B4E9BC2D316D1AECDFC12F63_E8FFB3D833ACBBA2A753BCE3F81C274B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D0F063B6B88A2B8BFE21C3993A613447
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E63A640A06A2B005AB42F3250BC98D9E_6020995806BF99A1FBC324A7B889F612
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F30B1DAC467EEB5A0EB57E5457CD952D_5196DDA6F3358FF603DC5010CA4ED54B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F4B372709D6C2AD766C34D274501DC76_C08D897FBCD7D5D638FCD154D1404CBE
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F4D9C889B7AEBCF4E1A2DAABC5C3628A_45372F968036A3D8F01EF13C820C17D1
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F4D9C889B7AEBCF4E1A2DAABC5C3628A_AD67B42F526068C7A09A14203543DAE9
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F72943F1E01540BBACB5396C76DD6AAA
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F99CAC852E278659C1E715225DD11A14_A941BBEE5E39237968E8808A19F1998B
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\FB788E090BC1F3AA2FBC9E8FB2859601
C:\Users\Mégane\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\FCEA474F228C13CD0DAD678431D0ACFC
C:\Users\Mégane\AppData\Local\Microsoft\Sqm\WindowsLL\WindowsLL.wns.0.sqm
C:\Users\Mégane\AppData\Local\Microsoft\Sqm\WindowsLL\WindowsLL.wns.1.sqm
Avatar du membre
par lcemegane
#18510
C:\Windows\TEMP\AEIC437.tmp
C:\Windows\TEMP\ASPNETSetup_00000.log
C:\Windows\TEMP\ASPNETSetup_00001.log
C:\Windows\TEMP\Atheros_Wlan_setup.log
C:\Windows\TEMP\Audio_Realtek_setup.log
C:\Windows\TEMP\BCDSAVE
C:\Windows\TEMP\BCDSAVE.LOG
C:\Windows\TEMP\BCDSAVE.LOG1
C:\Windows\TEMP\BCDSAVE.LOG2
C:\Windows\TEMP\Cardreader_RTL8411.log
C:\Windows\TEMP\changeID.txt
C:\Windows\TEMP\chrome_installer.log
C:\Windows\TEMP\CreateISRT.exe
C:\Windows\TEMP\DMI9FBA.tmp
C:\Windows\TEMP\DMIA1BF.tmp
C:\Windows\TEMP\DMIA2F8.tmp
C:\Windows\TEMP\DMIAC2E.tmp
C:\Windows\TEMP\DMIAE13.tmp
C:\Windows\TEMP\DMIB15E.tmp
C:\Windows\TEMP\DMIB2D6.tmp
C:\Windows\TEMP\DMIB325.tmp
C:\Windows\TEMP\DMIB355.tmp
C:\Windows\TEMP\DMID2FF.tmp
C:\Windows\TEMP\ElectroLyrics-1Installer_1381937345.log
C:\Windows\TEMP\FXSAPIDebugLogFile.txt
C:\Windows\TEMP\FXSTIFFDebugLogFile.txt
C:\Windows\TEMP\HDIFAC3.cmd
C:\Windows\TEMP\LOCAL.cmd
C:\Windows\TEMP\LOCAL1.cmd
C:\Windows\TEMP\LOCAL1.VBS
C:\Windows\TEMP\lpksetup-20130929-144251-0.log
C:\Windows\TEMP\lpksetup-20131001-070853-0.log
C:\Windows\TEMP\lpksetup-20131001-072216-0.log
C:\Windows\TEMP\lpksetup-20131002-092652-0.log
C:\Windows\TEMP\lpksetup-20131004-094906-0.log
C:\Windows\TEMP\lpksetup-20131004-101334-0.log
C:\Windows\TEMP\lpksetup-20131010-131849-0.log
C:\Windows\TEMP\lpksetup-20131010-212329-0.log
C:\Windows\TEMP\lpksetup-20131011-080733-0.log
C:\Windows\TEMP\lpksetup-20131012-235243-0.log
C:\Windows\TEMP\lpksetup-20131014-070633-0.log
C:\Windows\TEMP\lpksetup-20131015-161340-0.log
C:\Windows\TEMP\lpksetup-20131016-123303-0.log
C:\Windows\TEMP\lpksetup-20131028-192732-0.log
C:\Windows\TEMP\lpksetup-20131109-153555-0.log
C:\Windows\TEMP\lpksetup-20131109-165133-0.log
C:\Windows\TEMP\lpksetup-20131112-160347-0.log
C:\Windows\TEMP\lpksetup-20131112-161119-0.log
C:\Windows\TEMP\lpksetup-20131112-231732-0.log
C:\Windows\TEMP\lpksetup-20131113-091504-0.log
C:\Windows\TEMP\lpksetup-20131113-215446-0.log
C:\Windows\TEMP\lpksetup-20131120-225202-0.log
C:\Windows\TEMP\mcafee_1xxVqhXBZcqnYJa
C:\Windows\TEMP\mcafee_8E8lqePv8oJtwmK
C:\Windows\TEMP\MpCmdRun.log
C:\Windows\TEMP\NvidiaLogs
C:\Windows\TEMP\OOBEClear.cmd
C:\Windows\TEMP\OOBERun.cmd
C:\Windows\TEMP\OOBERun2.cmd
C:\Windows\TEMP\OOBERun3.cmd
C:\Windows\TEMP\Plus-HD-3.5Installer_1382984892.log
C:\Windows\TEMP\Realtek_LAN_setup.log
C:\Windows\TEMP\report.dat
C:\Windows\TEMP\rstcli.exe
C:\Windows\TEMP\rstcli64.exe
C:\Windows\TEMP\SEP940E.tmp
C:\Windows\TEMP\SetREML.exe
C:\Windows\TEMP\Silverlight0.log
C:\Windows\TEMP\SilverlightMSI.log
C:\Windows\TEMP\TempEnumAll.txt
C:\Windows\TEMP\TempFindGUID.txt
C:\Windows\TEMP\TempProc.log
C:\Windows\TEMP\TilesData
C:\Windows\TEMP\tmp000043b0
C:\Windows\TEMP\TS_7C4F.tmp
C:\Windows\TEMP\TS_8048.tmp
C:\Windows\TEMP\TS_8B19.tmp
C:\Windows\TEMP\TS_8D4C.tmp
C:\Windows\TEMP\winstore.log
C:\Windows\TEMP\~bdE6B6.tmp
C:\Windows\TEMP\tmp000043b0\tmp00000000
C:\Windows\TEMP\TilesData\AsSmartPin.exe
C:\Windows\TEMP\TilesData\P4GHybrid.ini
C:\Windows\TEMP\TilesData\SmartPin.ini
C:\Windows\TEMP\NvidiaLogs\LOG.DBInstaller.exe.log
C:\Windows\TEMP\NvidiaLogs\LOG.DrvInst.exe.log
C:\Windows\TEMP\NvidiaLogs\LOG.NVCPLSetupInt.exe.log
C:\Windows\TEMP\NvidiaLogs\LOG.nvtray.exe.log
C:\Windows\TEMP\NvidiaLogs\LOG.nvvsvc.exe.log
C:\Windows\TEMP\NvidiaLogs\LOG.nvxdsync.exe.log
C:\Windows\TEMP\NvidiaLogs\LOG.RunDll32.EXE.log
C:\Windows\TEMP\NvidiaLogs\LOG.setup.exe.log
C:\Windows\Prefetch\ACRORD32.EXE-153662D3.pf
C:\Windows\Prefetch\ACRORD32.EXE-4E288B88.pf
C:\Windows\Prefetch\ADOBEARM.EXE-813E932C.pf
C:\Windows\Prefetch\ADWCLEANER.EXE-DDE79D9C.pf
C:\Windows\Prefetch\AgAppLaunch.db
C:\Windows\Prefetch\AgCx_SC1.db
C:\Windows\Prefetch\AgCx_SC1.db.trx
C:\Windows\Prefetch\AgCx_SC2.db
C:\Windows\Prefetch\AgCx_SC4.db
C:\Windows\Prefetch\AgCx_SC5.db
C:\Windows\Prefetch\AgGlFaultHistory.db
C:\Windows\Prefetch\AgGlFgAppHistory.db
C:\Windows\Prefetch\AgGlGlobalHistory.db
C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-1305010613-2064220777-3922521960-1002.db
C:\Windows\Prefetch\AgGlUAD_S-1-5-21-1305010613-2064220777-3922521960-1002.db
C:\Windows\Prefetch\AgRobust.db
C:\Windows\Prefetch\APPLEMOBILEDEVICEHELPER.EXE-B90BEA1C.pf
C:\Windows\Prefetch\APRP.EXE-189CFE39.pf
C:\Windows\Prefetch\ASUSTPCFG64.EXE-7A0C8A89.pf
C:\Windows\Prefetch\ATH.EXE-216631C3.pf
C:\Windows\Prefetch\ATKOSD2.EXE-830E1513.pf
C:\Windows\Prefetch\AUDIODG.EXE-9848A323.pf
C:\Windows\Prefetch\AUTHHOST.EXE-44C90B62.pf
C:\Windows\Prefetch\AU_.EXE-1B98730A.pf
C:\Windows\Prefetch\AVCENTER.EXE-6D852881.pf
C:\Windows\Prefetch\AVGNT.EXE-97FED619.pf
C:\Windows\Prefetch\AVIRA_FREE_ANTIVIRUS [1].EXE-720C7F00.pf
C:\Windows\Prefetch\AVIRA_FREE_ANTIVIRUS.EXE-51A360EB.pf
C:\Windows\Prefetch\AVNOTIFY.EXE-A7994A59.pf
C:\Windows\Prefetch\AVRESTART.EXE-304BDA5D.pf
C:\Windows\Prefetch\AVSCAN.EXE-8C830A05.pf
C:\Windows\Prefetch\AVWEBLOADER.EXE-89F8203C.pf
C:\Windows\Prefetch\BACKGROUNDTRANSFERHOST.EXE-7DDF8CD2.pf
C:\Windows\Prefetch\BDADDMTASK.EXE-35FD799F.pf
C:\Windows\Prefetch\BDAGENT.EXE-6B62F545.pf
C:\Windows\Prefetch\BDAPPHOST.EXE-3F03D4E8.pf
C:\Windows\Prefetch\BDEXTHOST.EXE-46A5DBB8.pf
C:\Windows\Prefetch\BDRUNTIMEHOST.EXE-686E0807.pf
C:\Windows\Prefetch\BINGDESKTOP.EXE-8D000461.pf
C:\Windows\Prefetch\BITDEFENDER_AV_64B.EXE-6559A4F5.pf
C:\Windows\Prefetch\BUBBLES.SCR-55ABA833.pf
C:\Windows\Prefetch\CALC.EXE-0FE8F3A9.pf
C:\Windows\Prefetch\CHROME.EXE-9812FE60.pf
C:\Windows\Prefetch\CHROME.EXE-CCF9F3F4.pf
C:\Windows\Prefetch\CHROMEINSTALL-7U45.EXE-4BFC94E6.pf
C:\Windows\Prefetch\CLUPDATER.EXE-82A90891.pf
C:\Windows\Prefetch\CMD.EXE-2EB3E6E2.pf
C:\Windows\Prefetch\CMD.EXE-CD245F9E.pf
C:\Windows\Prefetch\CONHOST.EXE-F98A1078.pf
C:\Windows\Prefetch\CONSENT.EXE-2D674CE4.pf
C:\Windows\Prefetch\CSRSS.EXE-A7A2B218.pf
C:\Windows\Prefetch\DELEGATE_EXECUTE.EXE-8869DDC1.pf
C:\Windows\Prefetch\DFSVC.EXE-AD35CBCB.pf
C:\Windows\Prefetch\DISPLAYSWITCH.EXE-4D432882.pf
C:\Windows\Prefetch\DISTNOTED.EXE-DE72C2C6.pf
C:\Windows\Prefetch\DLLHOST.EXE-38926D07.pf
C:\Windows\Prefetch\DLLHOST.EXE-50AF0BCC.pf
C:\Windows\Prefetch\DLLHOST.EXE-6AA5D6C5.pf
C:\Windows\Prefetch\DLLHOST.EXE-716E1264.pf
C:\Windows\Prefetch\DLLHOST.EXE-C1C2EFBE.pf
C:\Windows\Prefetch\DOWNLOADER.EXE-1E5B7B87.pf
C:\Windows\Prefetch\DWM.EXE-F29FE9E2.pf
C:\Windows\Prefetch\dynreservedpri.db
C:\Windows\Prefetch\ERUNT.EXE-13EE2BE2.pf
C:\Windows\Prefetch\EULA.EXE-0C63FE43.pf
C:\Windows\Prefetch\EULA.EXE-185A99EE.pf
C:\Windows\Prefetch\EXPLORER.EXE-03C49D11.pf
C:\Windows\Prefetch\FIRSTRUN.EXE-3834855C.pf
C:\Windows\Prefetch\FIRSTRUN.EXE-ED4F9EAB.pf
C:\Windows\Prefetch\GLCND.EXE-DD45F588.pf
C:\Windows\Prefetch\GOOGLEUPDATE.EXE-05D9223F.pf
C:\Windows\Prefetch\GOOGLEUPDATE.EXE-296EF55A.pf
C:\Windows\Prefetch\GOOGLEUPDATE.EXE-62E5E10F.pf
C:\Windows\Prefetch\GOOGLEUPDATE.EXE-8F25D5F9.pf
C:\Windows\Prefetch\HCONTROL.EXE-752ABE5C.pf
C:\Windows\Prefetch\HKCMD.EXE-15DC91D5.pf
C:\Windows\Prefetch\HOROSCOPE.EXE-39F22478.pf
C:\Windows\Prefetch\IEXPLORE.EXE-7A9337F2.pf
C:\Windows\Prefetch\IEXPLORE.EXE-F4FB5D2F.pf
C:\Windows\Prefetch\IGFXSRVC.EXE-F41E6E8E.pf
C:\Windows\Prefetch\IGFXTRAY.EXE-21BDFE68.pf
C:\Windows\Prefetch\INSONWMI.EXE-D024CEF9.pf
C:\Windows\Prefetch\INSTALL.EXE-168BA674.pf
C:\Windows\Prefetch\INSTALLER.EXE-166619CC.pf
C:\Windows\Prefetch\INSTALLER.EXE-2463F9E4.pf
C:\Windows\Prefetch\INSTALLERPACKAGE.EXE-C9871E88.pf
C:\Windows\Prefetch\INSTALL_READER11_FR_MSSD_AAA_-B4A67C9F.pf
C:\Windows\Prefetch\ITUNES.EXE-07AC1693.pf
C:\Windows\Prefetch\ITUNES64SETUP.EXE-17113D82.pf
C:\Windows\Prefetch\ITUNESHELPER.EXE-722A54DB.pf
C:\Windows\Prefetch\JUSCHED.EXE-4B303C70.pf
C:\Windows\Prefetch\LAUNCHER.EXE-925A5160.pf
C:\Windows\Prefetch\Layout.ini
C:\Windows\Prefetch\LIVECOMM.EXE-32EE8CFF.pf
C:\Windows\Prefetch\LOGONUI.EXE-E35F76FB.pf
C:\Windows\Prefetch\LSDRIVEDETECT.EXE-CE98813C.pf
C:\Windows\Prefetch\MBAM-SETUP-1.75.0.1300.TMP-9BAA085B.pf
C:\Windows\Prefetch\MBAM-SETUP-1.75.0.1300.TMP-C9983A51.pf
C:\Windows\Prefetch\MBAM.EXE-125A28F9.pf
C:\Windows\Prefetch\MCUICNT.EXE-D0E68351.pf
C:\Windows\Prefetch\MDCRASHREPORTTOOL.EXE-3BC35FEE.pf
C:\Windows\Prefetch\MOVIEMAKER.EXE-A6401490.pf
C:\Windows\Prefetch\MPCMDRUN.EXE-6520183E.pf
C:\Windows\Prefetch\MSCORSVW.EXE-55FE3087.pf
C:\Windows\Prefetch\MSCORSVW.EXE-D593A5D9.pf
C:\Windows\Prefetch\MSDT.EXE-A16F1692.pf
C:\Windows\Prefetch\MSIEXEC.EXE-BAE57A74.pf
C:\Windows\Prefetch\MSNMSGR.EXE-424B3DE6.pf
C:\Windows\Prefetch\MSOOBE.EXE-AE41C2E0.pf
C:\Windows\Prefetch\NGEN.EXE-383F81D5.pf
C:\Windows\Prefetch\NGEN.EXE-A8DBB043.pf
C:\Windows\Prefetch\NGENTASK.EXE-4DB88ADA.pf
C:\Windows\Prefetch\NGENTASK.EXE-CD4E002C.pf
C:\Windows\Prefetch\NOTEPAD.EXE-1A4CC1C3.pf
C:\Windows\Prefetch\NOTEPAD.EXE-B28CC291.pf
C:\Windows\Prefetch\NOTEPAD.EXE-F0516D55.pf
C:\Windows\Prefetch\NVTRAY.EXE-981FA625.pf
C:\Windows\Prefetch\NVVSVC.EXE-D5489D80.pf
C:\Windows\Prefetch\NVXDSYNC.EXE-7855AED2.pf
C:\Windows\Prefetch\OBK.EXE-DCF2DD96.pf
C:\Windows\Prefetch\ODSCANUI.EXE-899461D2.pf
C:\Windows\Prefetch\ODSLV.EXE-1ECDDD1C.pf
C:\Windows\Prefetch\ODSW.EXE-983DD055.pf
C:\Windows\Prefetch\Op-EXPLORER.EXE-03C49D11-000000F5.pf
C:\Windows\Prefetch\OPENWITH.EXE-BA0DC300.pf
C:\Windows\Prefetch\OTL.EXE-A732DED9.pf
C:\Windows\Prefetch\PDVD10SERV.EXE-99C8A7B5.pf
C:\Windows\Prefetch\PfSvPerfStats.bin
C:\Windows\Prefetch\PING.EXE-167FE968.pf
C:\Windows\Prefetch\POWER2GOEXPRESS.EXE-F5293CA2.pf
C:\Windows\Prefetch\POWERCFG.EXE-C4097EFB.pf
C:\Windows\Prefetch\RAVBG64.EXE-B555701F.pf
C:\Windows\Prefetch\RAVCPL64.EXE-C0BB540D.pf
C:\Windows\Prefetch\READER_SL.EXE-BC0A991D.pf
C:\Windows\Prefetch\ReadyBoot
C:\Windows\Prefetch\RECOVERYDRIVE.EXE-0EE8638F.pf
C:\Windows\Prefetch\RUNDLL32.EXE-00972AFF.pf
C:\Windows\Prefetch\RUNDLL32.EXE-346952CF.pf
C:\Windows\Prefetch\RUNDLL32.EXE-405FEB5D.pf
C:\Windows\Prefetch\RUNDLL32.EXE-6999291C.pf
C:\Windows\Prefetch\RUNDLL32.EXE-6BFEE589.pf
C:\Windows\Prefetch\RUNDLL32.EXE-719E97F9.pf
C:\Windows\Prefetch\RUNDLL32.EXE-9E940D77.pf
C:\Windows\Prefetch\RUNDLL32.EXE-AC024951.pf
C:\Windows\Prefetch\RUNDLL32.EXE-EA0A52C8.pf
C:\Windows\Prefetch\RUNTIMEBROKER.EXE-17E2786F.pf
C:\Windows\Prefetch\SC.EXE-443D0E78.pf
C:\Windows\Prefetch\SDIAGNHOST.EXE-D8BC1DC6.pf
C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-10E4267C.pf
C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-C6CFE2A8.pf
C:\Windows\Prefetch\SECCENTER.EXE-B7787518.pf
C:\Windows\Prefetch\SETTINGSYNCHOST.EXE-DD400067.pf
C:\Windows\Prefetch\SETUP.EXE-8238713E.pf
C:\Windows\Prefetch\SETUP.EXE-8A9CE894.pf
C:\Windows\Prefetch\SETUP.EXE-A61F6D06.pf
C:\Windows\Prefetch\SETUP.EXE-C1C3DD17.pf
C:\Windows\Prefetch\SETUP.EXE-D5D45E0A.pf
C:\Windows\Prefetch\SETUPDOWNLOADER.EXE-3304E9C0.pf
C:\Windows\Prefetch\SETUP_WM.EXE-5D2609E7.pf
C:\Windows\Prefetch\SFTGC.EXE-1155E149.pf
C:\Windows\Prefetch\SIMUSEREXEC.EXE-5BCC1EE0.pf
C:\Windows\Prefetch\SKYDRIVESETUP.EXE-ACD69350.pf
C:\Windows\Prefetch\SMSS.EXE-81AD91F0.pf
C:\Windows\Prefetch\SNDVOL.EXE-276AC160.pf
C:\Windows\Prefetch\SOFFICE.BIN-4DEC791F.pf
C:\Windows\Prefetch\SVCHOST.EXE-5511E724.pf
C:\Windows\Prefetch\SYNCSERVER.EXE-261E368E.pf
C:\Windows\Prefetch\SYSTEMSETTINGS.EXE-D8CC3B5E.pf
C:\Windows\Prefetch\TASKENG.EXE-23205583.pf
C:\Windows\Prefetch\TASKHOST.EXE-29D61DAB.pf
C:\Windows\Prefetch\TASKHOST.EXE-3C5D03F7.pf
C:\Windows\Prefetch\TASKHOST.EXE-86081325.pf
C:\Windows\Prefetch\TASKHOST.EXE-882A5176.pf
C:\Windows\Prefetch\TASKHOST.EXE-D687BE54.pf
C:\Windows\Prefetch\TASKHOST.EXE-F2C7AEBC.pf
C:\Windows\Prefetch\TASKHOSTEX.EXE-7356AAC0.pf
C:\Windows\Prefetch\TASKKILL.EXE-3D8A2F61.pf
C:\Windows\Prefetch\TASKLIST.EXE-74FDEEA1.pf
C:\Windows\Prefetch\TASKMGR.EXE-39AABA37.pf
C:\Windows\Prefetch\THE WORLD CLOCK.EXE-1030EBBF.pf
C:\Windows\Prefetch\THUMBNAILEXTRACTIONHOST.EXE-C3FB8861.pf
C:\Windows\Prefetch\TIWORKER.EXE-375F3D59.pf
C:\Windows\Prefetch\TRUSTEDINSTALLER.EXE-B018CCBF.pf
C:\Windows\Prefetch\UNINS000.EXE-1CF61FE7.pf
C:\Windows\Prefetch\UPDATESRV.EXE-9AD36E5A.pf
C:\Windows\Prefetch\VCREDIST_X86.EXE-F7C89C6A.pf
C:\Windows\Prefetch\VSSERV.EXE-33A15939.pf
C:\Windows\Prefetch\W32TM.EXE-78C041DB.pf
C:\Windows\Prefetch\WAJAM_DOWNLOAD.EXE-85DB3B14.pf
C:\Windows\Prefetch\WAJAM_INSTALL.EXE-D8D8BE0A.pf
C:\Windows\Prefetch\WERFAULT.EXE-94CE7668.pf
C:\Windows\Prefetch\WINLOGON.EXE-0D9AB72B.pf
C:\Windows\Prefetch\WLMAIL.EXE-A89F57F3.pf
C:\Windows\Prefetch\WLSETUP-WEB.EXE-B5407236.pf
C:\Windows\Prefetch\WLSTARTUP.EXE-9F0A892A.pf
C:\Windows\Prefetch\WLXPHOTOGALLERY.EXE-55FF63A1.pf
C:\Windows\Prefetch\WMIPRVSE.EXE-BB49B536.pf
C:\Windows\Prefetch\WMPLAYER.EXE-8A348205.pf
C:\Windows\Prefetch\WMPLAYER.EXE-B0AD61F0.pf
C:\Windows\Prefetch\WUDFHOST.EXE-0D78D366.pf
C:\Windows\Prefetch\WWAHOST.EXE-08E78623.pf
C:\Windows\Prefetch\WWAHOST.EXE-349FF887.pf
C:\Windows\Prefetch\WWAHOST.EXE-4C1933AC.pf
C:\Windows\Prefetch\WWAHOST.EXE-6132DF3D.pf
C:\Windows\Prefetch\WWAHOST.EXE-9178D9A9.pf
C:\Windows\Prefetch\WWAHOST.EXE-917C29EF.pf
C:\Windows\Prefetch\WWAHOST.EXE-DAF4E5BB.pf
C:\Windows\Prefetch\WWAHOST.EXE-DBA9DFF9.pf
C:\Windows\Prefetch\WWAHOST.EXE-EABC9C04.pf
C:\Windows\Prefetch\WWAHOST.EXE-F7FB8768.pf
C:\Windows\Prefetch\ZHPDIAG.EXE-C7289479.pf
C:\Windows\Prefetch\ZHPDIAG2.TMP-174AEA90.pf
C:\Windows\Prefetch\ZHPDIAG2.TMP-1EF80010.pf
C:\Windows\Prefetch\ZHPDIAG2.TMP-81AC398A.pf
C:\Windows\Prefetch\ZHPFIX.EXE-AFDB3DAC.pf
C:\Windows\Prefetch\ZHPHEP.EXE-5F2753B1.pf
C:\Windows\Prefetch\ZHPHEP.EXE-8162C2FA.pf
C:\Windows\Prefetch\_IU14D2N.TMP-A8098D0F.pf
C:\Windows\Prefetch\ReadyBoot\rblayout.xin
C:\Windows\Prefetch\ReadyBoot\Trace1.fx
C:\Windows\Prefetch\ReadyBoot\Trace10.fx
C:\Windows\Prefetch\ReadyBoot\Trace7.fx
C:\Windows\Prefetch\ReadyBoot\Trace8.fx
C:\Windows\Prefetch\ReadyBoot\Trace9.fx

Corbeille vidée.


Fin du rapport.


mon ordinateur semble débarassé de ce virus !
Avatar du membre
par billmaxime
#18512
re lcemegane,

dis moi comment va le pc s'il te plaît

fais ceci et poste le rapport

dans delfix, vérifie que ces cases soient cochées

réactiver l'uac

supprimer les outils de désinfection (case pre-cochée par défault)

purger la restauration système

clique sur exécuter


  • Télécharges Delfix sur ton Bureau.
  • Lance Delfix, exécuter en tant qu'administrateur sous Windows : 7/8 et Vista
  • Coche la case suivantes :
    • Réactiver l'UAC

      Image
:merci2:
Avatar du membre
par lcemegane
#18516
Je n'arrive pas à  exécuter ce logiciel, il disparait au moment o๠je veux exécuter, je l'ai retélécharger par 2 fois et ça ne marche toujours pas
Avatar du membre
par lcemegane
#18523
J'avais déjà  essayé la dernière fois le mode sans échec sans y parvenir, c'est un nouvel ordinateur je ne trouvais du tout avec windows 8... y a-t-il une autre solution ?

bonsoir oki pour la fermeture je m'en charge car[…]

how to clean junk files

Hello don't use this program , it's a bullshit :)

Bonjour https://www.aht.li/3213847/AdsFix.exe b[…]

De rien Bon WE :)