interpol virus 2013-10-28T21:48:27+00:00
  • Auteur
    Messages
  • scorpio44
    Participant
    Post count: 9

    Cet apres midi je me suis retrouve avec ce virus sur mon pc J’ai fait un demarrage sans echec avec restauration et surprise m’a page d’accueil est de nouveau accessible J’ai installe Malwarebytes Anti-Malware 1.75.0.1300 et fait un scan et effectivement il a mis en quarantaine ce fameux trojan ransom dont voici l’examen j’ai egalement fait un scan avec roguekiller ai je bien fait?
    http://www.malwarebytes.org

    Version de la base de données: v2013.10.28.09

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 10.0.9200.16721
    sadaik :: SADAIK-HP [administrateur]

    28/10/2013 21:11:59
    mbam-log-2013-10-28 (21-11-59).txt

    Type d’examen: Examen complet (C:|D:|G:|Q:|)
    Options d’examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
    Options d’examen désactivées: P2P
    Elément(s) analysé(s): 387127
    Temps écoulé: 55 minute(s), 47 seconde(s)

    Processus mémoire détecté(s): 0
    (Aucun élément nuisible détecté)

    Module(s) mémoire détecté(s): 0
    (Aucun élément nuisible détecté)

    Clé(s) du Registre détectée(s): 0
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre détectée(s): 0
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre détecté(s): 0
    (Aucun élément nuisible détecté)

    Dossier(s) détecté(s): 0
    (Aucun élément nuisible détecté)

    Fichier(s) détecté(s): 7
    C:UserssadaikDownloadsiLividSetup.exe (PUP.Optional.Bandoo) -> Mis en quarantaine et supprimé avec succès.
    C:UserssadaikDownloadsmovie1080p.mkv (1).zip (Trojan.Ransom) -> Mis en quarantaine et supprimé avec succès.
    C:UserssadaikDownloadsmovie1080p.mkv (2).zip (Trojan.Ransom) -> Mis en quarantaine et supprimé avec succès.
    C:UserssadaikDownloadsmovie1080p.mkv.zip (Trojan.Ransom) -> Mis en quarantaine et supprimé avec succès.
    C:UserssadaikDownloadsSweetImSetup (1).exe (PUP.Optional.SweetIM) -> Mis en quarantaine et supprimé avec succès.
    C:UserssadaikDownloadsSweetImSetup.exe (PUP.Optional.SweetIM) -> Mis en quarantaine et supprimé avec succès.
    C:UserssadaikDownloadsVLCMediaPlayerSetup-6Al3M50.exe (PUP.Optional.Somoto) -> Mis en quarantaine et supprimé avec succès.

    (fin)

  • H.A.W.X
    Participant
    Post count: 1704

    Bonsoir :)

    On va vérifier quelque chose quand même ;)

    • Télécharges RogueKiller (de Tigzy) sur ton Bureau.
    • Lance RogueKiller, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista

      Note : Attends que le PreScan ait fini.

    • Clique sur Scan.
    • Une fois le scan terminé rends toi sur le bureau, le rapport RKreport[X]¤S¤.txt à été créé.
    • Héberge le rapport RKreport[X]¤S¤.txt sur SosUpload, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum

    Bonne nuit :)

  • scorpio44
    Participant
    Post count: 9

    RogueKiller V8.7.6 [Oct 28 2013] par Tigzy
    mail : tigzyRKgmailcom
    Remontees : http://www.adlice.com/forum/” onclick=”window.open(this.href);return false;
    Site Web : http://www.sur-la-toile.com/RogueKiller/” onclick=”window.open(this.href);return false;
    Blog : http://tigzyrk.blogspot.com/” onclick=”window.open(this.href);return false;

    Systeme d’exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Demarrage : Mode normal
    Utilisateur : sadaik [Droits d’admin]
    Mode : Recherche — Date : 10/28/2013 23:46:05
    | ARK || FAK || MBR |

    ¤¤¤ Processus malicieux : 0 ¤¤¤

    ¤¤¤ Entrees de registre : 2 ¤¤¤
    [HJ DESK][PUM] HKLM[…]NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> TROUVÉ
    [HJ DESK][PUM] HKLM[…]NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ

    ¤¤¤ Tâches planifiées : 0 ¤¤¤

    ¤¤¤ Entrées Startup : 0 ¤¤¤

    ¤¤¤ Navigateurs web : 0 ¤¤¤

    ¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

    ¤¤¤ Driver : [NON CHARGE 0x0] ¤¤¤

    ¤¤¤ Ruches Externes: ¤¤¤

    ¤¤¤ Infection : ¤¤¤

    ¤¤¤ Fichier HOSTS: ¤¤¤
    –> %SystemRoot%System32driversetchosts

    ¤¤¤ MBR Verif: ¤¤¤

    +++++ PhysicalDrive0: (\.PHYSICALDRIVE0 @ SCSI) ST640LM000 HM641JI +++++
    — User —
    [MBR] 0d2748e3d967b06811bda8e8ab3c507f
    [BSP] 08ba16d7dc9b88ec66b36a31f3938cc9 : Windows 7/8 MBR Code
    Partition table:
    0 – [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo
    1 – [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 587742 Mo
    2 – [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1204105216 | Size: 22434 Mo
    3 – [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 1250050048 | Size: 103 Mo
    User = LL1 … OK!
    User = LL2 … OK!

    Termine : <>

    Je n’ai pas reussi a faire heberger le rapport sur sosupload

  • H.A.W.X
    Participant
    Post count: 1704

    Bonjour,

    Ok bon bonne nouvelle ;)

    Bon tu t’es fait infecté car tu n’étais pas à jour, donc on va y remédier ok ? :)

    • Télécharges SX Check&Update (de Igor51) sur ton Bureau !
    • Fermes toutes les applications en cours !
    • Fais clic droit dessus, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista
    • Clique sur Rapport
    • le rapport rapport_SX.txt va s’ouvrir copie/colle son contenue dans ta prochaine réponse

    ++

  • scorpio44
    Participant
    Post count: 9

    Voici le rapport et encore merci

    SX Check&Update
    Lien vers le tutoriel : http://forum.security-x.fr/tutoriels-317/tutoriel-sx-checkupdate/” onclick=”window.open(this.href);return false;

    Windows Version : Windows 7 64bits
    Service Pack : 1
    UserName : sadaik
    29/10/2013
    10:23:25
    version = v0.3.5

    Windows Update Information :
    AUOptions : 4
    Automatically, no notification


    Name : FlashPlayer ActiveX
    Version : 11.9.900.117
    Flash Player ActiveX est à jour

    Name : FlashPlayer Plugin FF
    Version : 11.9.900.117
    Flash Player Plugin FF est à jour

    Name : FlashPlayer Plugin
    Version : 11.9.900.117
    Flash Player Plugin est à jour

    Nom : Google Chrome
    Version : 30.0.1599.101

    Nom : Mozilla Firefox 18.0 (x86 fr)
    Version : 18.0

    Nom : Adobe Reader X (10.1.8) MUI
    Version : 10.1.8
    Adobe Reader est à jour

    Nom (svc) : Internet Explorer
    Version : 10.0.9200.16721

  • H.A.W.X
    Participant
    Post count: 1704

    Super ! ;)

    On corrige les traces d’infections que tuas et c’est fini ok ? :)

    1.

    • Télécharges Adwcleaner (de Xplode) sur ton Bureau !
    • Fais clic droit dessus, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista
      1. Choisi l’option Scanner
      2. Choisi l’option Nettoyer
    • Accepte l’avertissement en cliquant sur OK

    • Acceptes les avertissements/informations en cliquant sur OK
    • Copie et Colle le contenu du rapport qui apparaît au redémarrage du PC

    2.

    • Télécharge SFTGC (de Pierre13) sur ton Bureau et pas ailleurs !.
    • Lance SFTGC, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista
    • Clique sur GO

      Note : A la fin un rapport va s’ouvrir

    • Une fois le scan terminé rends toi sur le bureau, le fichier SFTGC.txt à été créé.
    • Héberge le rapport SFTGC.txt sur SosUpload, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum

    3.

    • Télécharge ZHPDiag (de Nicolas Coolman) sur ton bureau.
    • Installe le logiciel.
    • Lance ZHPDiag, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista
    • Clique sur Configurer
    • Clique sur l’icône représentant une loupe avec un + (« Lancer le diagnostic »)

      Note : Ne pas fermer le programme même si il est indiqué qu’il ne répond plus.

    • Une fois le scan terminé rends toi sur le bureau, le fichier ZHPDiag.txt à été créé.
    • Héberge le rapport ZHPDiag.txt sur SosUpload, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum

    J’attends donc 3 rapports ;)

  • scorpio44
    Participant
    Post count: 9

    1er rapport adwcleaner

    # AdwCleaner v3.010 – Rapport créé le 29/10/2013 à 12:47:33
    # Mis à jour le 20/10/2013 par Xplode
    # Système d’exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Nom d’utilisateur : sadaik – SADAIK-HP
    # Exécuté depuis : C:UserssadaikDownloadsadwcleaner.exe
    # Option : Scanner

    ***** [ Services ] *****

    ***** [ Fichiers / Dossiers ] *****

    Fichier Présent : C:UserssadaikAppDataRoamingMozillaFirefoxProfilesf54btgoa.defaultuser.js

    ***** [ Raccourcis ] *****

    ***** [ Registre ] *****

    Clé Présente : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{C9A6357B-25CC-4BCF-96C1-78736985D412}

    ***** [ Navigateurs ] *****

    -\ Internet Explorer v10.0.9200.16720

    -\ Mozilla Firefox v18.0 (fr)

    [ Fichier : C:UserssadaikAppDataRoamingMozillaFirefoxProfilesf54btgoa.defaultprefs.js ]

    -\ Google Chrome v30.0.1599.101

    [ Fichier : C:UserssadaikAppDataLocalGoogleChromeUser DataDefaultpreferences ]

    *************************

    AdwCleaner[R0].txt – [3548 octets] – [29/10/2013 10:04:17]
    AdwCleaner[R1].txt – [1076 octets] – [29/10/2013 12:47:33]
    AdwCleaner[S0].txt – [3283 octets] – [29/10/2013 10:05:38]

    ########## EOF – C:AdwCleanerAdwCleaner[R1].txt – [1196 octets] ##########

  • scorpio44
    Participant
    Post count: 9

    ~ Rapport de ZHPDiag v2013.10.28.74 – Nicolas Coolman (28/10/2013)
    ~ Lancé par sadaik (29/10/2013 13:05:53)
    ~ Adresse du Site Web http://nicolascoolman.webs.com” onclick=”window.open(this.href);return false;
    ~ Forums gratuits d’Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/” onclick=”window.open(this.href);return false;
    ~ Traduit par Nicolas Coolman
    ~ Etat de la version :
    ~ Liste blanche : Activée par le programme
    ~ Elévation des Privilèges : OK
    ~ User Account Control (UAC): Activate by user

    —\ Navigateurs Internet
    MSIE: Internet Explorer v10.0.9200.16721
    MFIE: Mozilla Firefox 18.0
    GCIE: Google Chrome v30.0.1599.101 (Defaut)

    —\ Informations sur les produits Windows
    ~ Langage: Français
    Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
    Windows Server License Manager Script : OK
    ~ Windows(R) 7, OEM_SLP channel
    System Locked Preinstallation (OEM_SLP) : OK
    Windows ID Activation : OK
    ~ Windows Partial Key : 3Q6C9
    Windows License : OK
    ~ Windows Remaining Initializations Number : 0
    Software Protection Service (Protection logicielle) : OK
    Windows Automatic Updates : OK
    Windows Activation Technologies : OK

    —\ Logiciels de protection du système
    avast! Free Antivirus v9.0.2006
    Trusteer Sécurité des points d’accès v3.5.1304.13
    Malwarebytes Anti-Malware version 1.75.0.1300
    Microsoft Security Client v4.3.0219.0
    Ad-Aware v8.0.0
    Windows Defender W7

    —\ Logiciels d’optimisation du système

    —\ Logiciels de partage PeerToPeer
    µTorrent v3.2.1.28086 =>P2P.µTorrent

    —\ Surveillance de Logiciels
    Adobe Flash Player 11 Plugin
    Adobe Reader X

    —\ Informations sur le système
    ~ Processor: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
    ~ Operating System: 64 Bits
    Boot mode: Normal (Normal boot)
    Total RAM: 3991 MB (57% free)
    System Restore: Activé (Enable)
    System drive C: has 514 GB (89%) free of 574 GB

    —\ Mode de connexion au système
    ~ Computer Name: SADAIK-HP
    ~ User Name: sadaik
    ~ All Users Names: UpdatusUser, sadaik, HomeGroupUser$, Administrateur,
    ~ Unselected Option: None
    Logged in as Administrator

    —\ Variables d’environnement
    ~ System Unit : C:
    ~ %AppZHP% : C:UserssadaikAppDataRoamingZHP
    ~ %AppData% : C:UserssadaikAppDataRoaming
    ~ %Desktop% : C:UserssadaikDesktop
    ~ %Favorites% : C:UserssadaikFavorites
    ~ %LocalAppData% : C:UserssadaikAppDataLocal
    ~ %StartMenu% : C:UserssadaikAppDataRoamingMicrosoftWindowsStart Menu
    ~ %Windir% : C:Windows
    ~ %System% : C:WindowsSystem32

    —\ Enumération des unités disques
    C: Hard drive, Flash drive, Thumb drive (Free 514 Go of 574 Go)
    D: Hard drive, Flash drive, Thumb drive (Free 2 Go of 22 Go)
    E: CD-ROM drive (Not Inserted)
    G: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)
    Q: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)

    —\ Etat du Centre de Sécurité Windows
    [HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorer] NoActiveDesktopChanges: Modified
    ~ Security Center: 41 Legitimates Filtered in 00mn 00s

    —\ Recherche particulière de fichiers génériques
    [MD5.332FEAB1435662FC6C672E25BEB37BE3] – (.Microsoft Corporation – Explorateur Windows.) (.24/02/2012 – 23:34:47.) — C:WindowsExplorer.exe [2871808]
    [MD5.94355C28C1970635A31B3FE52EB7CEBA] – (.Microsoft Corporation – Application de démarrage de Windows.) (.14/07/2009 – 02:39:52.) — C:WindowsSystem32Wininit.exe [129024]
    [MD5.D28B35DE88D27EFB27DF4B1E8319E3C0] – (.Microsoft Corporation – Extensions Internet pour Win32.) (.22/09/2013 – 23:55:10.) — C:WindowsSystem32wininet.dll [2241024]
    [MD5.1151B1BAA6F350B1DB6598E0FEA7C457] – (.Microsoft Corporation – Application d’ouverture de session Windows.) (.21/11/2010 – 04:24:29.) — C:WindowsSystem32Winlogon.exe [390656]
    [MD5.067FA52BFB59A56110A12312EF9AF243] – (.Microsoft Corporation – Bibliothèque de licences.) (.21/11/2010 – 04:24:16.) — C:WindowsSystem32sppcomapi.dll [232448]
    [MD5.314C17917AC8523EC77A710215012A65] – (.Microsoft Corporation – Ancillary Function Driver for WinSock.) (.14/09/2013 – 02:10:19.) — C:Windowssystem32DriversAFD.sys [497152]
    [MD5.02062C0B390B7729EDC9E69C680A6F3C] – (.Microsoft Corporation – ATAPI IDE Miniport Driver.) (.14/07/2009 – 02:52:21.) — C:Windowssystem32Driversatapi.sys [24128]
    [MD5.B8BD2BB284668C84865658C77574381A] – (.Microsoft Corporation – CD-ROM File System Driver.) (.14/07/2009 – 00:19:47.) — C:Windowssystem32DriversCdfs.sys [92160]
    [MD5.F036CE71586E93D94DAB220D7BDF4416] – (.Microsoft Corporation – SCSI CD-ROM Driver.) (.21/11/2010 – 04:23:47.) — C:Windowssystem32DriversCdrom.sys [147456]
    [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] – (.Microsoft Corporation – DFS Namespace Client Driver.) (.21/11/2010 – 04:24:32.) — C:Windowssystem32DriversDfsC.sys [102400]
    [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] – (.Microsoft Corporation – High Definition Audio Bus Driver.) (.21/11/2010 – 04:23:47.) — C:Windowssystem32DriversHDAudBus.sys [122368]
    [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] – (.Microsoft Corporation – Pilote de port i8042.) (.14/07/2009 – 00:19:57.) — C:Windowssystem32Driversi8042prt.sys [105472]
    [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] – (.Microsoft Corporation – IP Network Address Translator.) (.14/07/2009 – 01:10:03.) — C:Windowssystem32DriversIpNat.sys [116224]
    [MD5.A5D9106A73DC88564C825D317CAC68AC] – (.Microsoft Corporation – Windows NT SMB Minirdr.) (.24/02/2012 – 23:36:35.) — C:Windowssystem32DriversMRxSmb.sys [158208]
    [MD5.09594D1089C523423B32A4229263F068] – (.Microsoft Corporation – MBT Transport driver.) (.21/11/2010 – 04:23:51.) — C:Windowssystem32DriversnetBT.sys [261632]
    [MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] – (.Microsoft Corporation – Pilote du système de fichiers NT.) (.12/04/2013 – 15:45:08.) — C:Windowssystem32Driversntfs.sys [1656680]
    [MD5.0086431C29C35BE1DBC43F52CC273887] – (.Microsoft Corporation – Pilote de port parallèle.) (.14/07/2009 – 01:00:41.) — C:Windowssystem32DriversParport.sys [97280]
    [MD5.471815800AE33E6F1C32FB1B97C490CA] – (.Microsoft Corporation – RAS L2TP mini-port/call-manager driver.) (.21/11/2010 – 04:24:33.) — C:Windowssystem32DriversRasl2tp.sys [129536]
    [MD5.548260A7B8654E024DC30BF8A7C5BAA4] – (.Microsoft Corporation – SMB Transport driver.) (.14/07/2009 – 01:09:09.) — C:Windowssystem32Driverssmb.sys [93184]
    [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] – (.Microsoft Corporation – TDI Translation Driver.) (.21/11/2010 – 04:24:32.) — C:Windowssystem32Driverstdx.sys [119296]
    [MD5.DF8126BD41180351A093A3AD2FC8903B] – (.Microsoft Corporation – Pilote de cliché instantané du volume.) (.24/02/2012 – 23:33:12.) — C:Windowssystem32Driversvolsnap.sys [296320]
    ~ Generic Processes: Scanned in 00mn 09s

    —\ Etat des fichiers cachés (Caché/Total)
    ~ Mes images (My Pictures) : 1/5
    ~ Mes Favoris (My Favorites) : 1/12
    ~ Mes Documents (My Documents) : 1/927
    ~ Mon Bureau (My Desktop) : 1/8
    ~ Menu demarrer (Programs) : 1/29
    ~ Hidden Files: Scanned in 00mn 05s

    —\ Processus lancés
    [MD5.292C1E04626EED84C668E7714DD6DB66] – (.AuthenTec Inc. – TouchControl.) — C:Program Files (x86)HP SimplePassTouchControl.exe [3695912] [PID.2276]
    [MD5.254E94A9FC2B491F6F619F9A5F5DC578] – (.Trusteer Ltd. – RapportService.) — C:Program Files (x86)TrusteerRapportbinRapportService.exe [2480408] [PID.2432]
    [MD5.66295B0D0FB2292C6D62904F5C3DE0B2] – (…) — C:Program Files (x86)OrangeOrange InstallerOrangeInstaller.exe [561320] [PID.3048]
    [MD5.BB4CEE22CFE1C259F5C4279349EB879C] – (.Orange – Assistance Livebox.) — C:Program Files (x86)OrangeAssistance LiveboxAssistanceLivebox.exe [149824] [PID.2544]
    [MD5.6E81310512F5D2FA908ABC76CCCADED4] – (.Orange – Executable Orange Inside.) — C:UserssadaikAppDataRoamingOrangeOrangeInsideoneOrangeInside.exe [1526272] [PID.3064]
    [MD5.A7035C7D3AAA24C5D71D6B5506F2D704] – (.Lavasoft – Ad-Aware Tray Application.) — C:Program Files (x86)LavasoftAd-AwareAAWTray.exe [515416] [PID.5128]
    [MD5.7E4E3EE20FF5D10A60E6267A8EE67786] – (.Intel Corporation – Intel(R) USB 3.0 Monitor.) — C:Program Files (x86)IntelIntel(R) USB 3.0 eXtensible Host Controller DriverApplicationiusb3mon.exe [291096] [PID.5840]
    [MD5.B7F55E2AE978D3D34F7876EE5D689AAE] – (.CyberLink – YouCam Mirage.) — C:Program Files (x86)CyberLinkYouCamYCMMirage.exe [136488] [PID.924]
    [MD5.8A3B69683E63808719D24E1C68C21CC7] – (.Hewlett-Packard Development Company, L.P. – HP On Screen Display.) — C:Program Files (x86)Hewlett-PackardHP On Screen DisplayHPOSD.exe [379960] [PID.6132]
    [MD5.8192B2E274607D1D530F5C191698C544] – (.Hewlett-Packard Development Company, L.P. – HP Message Service.) — C:Program Files (x86)Hewlett-PackardHP Quick LaunchHPMSGSVC.exe [578944] [PID.2364]
    [MD5.7C0704D4523BA671AFE6D028399942D3] – (.AVAST Software – avast! Antivirus.) — C:Program FilesAVAST SoftwareAvastavastui.exe [3567800] [PID.5580]
    [MD5.0737D18842CE3C65FC0D04DA0D4875B1] – (.Pas de propriétaire – IEWebSiteLogon.) — C:Program Files (x86)HP SimplePassIEWebSiteLogon.exe [4073768] [PID.6152]
    [MD5.51138BEEA3E2C21EC44D0932C71762A8] – (…) — ysWOW64RunDll32.exe [0] [PID.6648]
    [MD5.9EDFB86FAA07BFED3C3D00211FAB6D82] – (.Orange – Assistance Livebox.) — C:Program Files (x86)OrangeAssistance LiveboxdistST2.exe [13446464] [PID.6084]
    [MD5.3E399A1328181C2A352472369DE2A93A] – (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe [844752] [PID.3260]
    [MD5.3B605772669BDFD6DC266B9320E87B45] – (.Nicolas Coolman – ZHPDiag.) — C:Program Files (x86)ZHPDiagZHPDiag.exe [8143872] [PID.2752]
    [MD5.60BCE8BBD1C515007BB335ACEFBFC246] – (.HP – HP Service.) — C:Program Files (x86)HP SimplePassTrueSuiteService.exe [1641768] [PID.744]
    [MD5.02396BD77121751A738444325E1F14E8] – (.Trusteer Ltd. – RapportMgmtService.) — C:Program Files (x86)TrusteerRapportbinRapportMgmtService.exe [1444120] [PID.1112]
    [MD5.4BE7EC02133544CDE7A580875E130208] – (.AVAST Software – avast! Service.) — C:Program FilesAVAST SoftwareAvastAvastSvc.exe [50344] [PID.1744]
    [MD5.4BFD99EF6CC3AF080808D55AB2778195] – (.Lavasoft – Ad-Aware Service Application.) — C:Program Files (x86)LavasoftAd-AwareAAWService.exe [951632] [PID.2076]
    [MD5.ADDA5E1951B90D3D23C56D3CF0622ADC] – (.Adobe Systems Incorporated – Adobe Acrobat Update Service.) — C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe [65640] [PID.2856]
    [MD5.9D519AAA21E622DF7DF27041E0917499] – (.Pas de propriétaire – DedicarzService.) — C:Program Files (x86)OrangeAssistance LiveboxdedicarzDedicarzService.exe [1966960] [PID.3032]
    [MD5.CA793DCC1D5F619021EF1D37CC7A831E] – (.EasyBits Software AS – Shared EasyBits services for Windows.) — C:WindowsSysWOW64ezSharedSvcHost.exe [514232] [PID.3068]
    [MD5.2BEC76BDCD1BC080210325E7B5094834] – (.Hewlett-Packard Development Company, L.P. – HP Quick Launch WMI Service.) — C:Program Files (x86)Hewlett-PackardHP Quick LaunchHPWMISVC.exe [35200] [PID.3168]
    [MD5.C9DCE1CB628AEED3C0C30ABBF4F1E718] – (…) — C:Program Files (x86)IntelIntel(R) Management Engine ComponentsFWServiceIntelMeFWService.exe [128280] [PID.3492]
    [MD5.3628933AF5305EAB8173949BFF912F04] – (.Intel Corporation – Intel(R) Dynamic Application Loader Host In.) — C:Program Files (x86)IntelIntel(R) Management Engine ComponentsDALjhi_service.exe [161560] [PID.3516]
    [MD5.39B1D0A636A400304565D4521FAD6D77] – (.Microsoft Corporation – Microsoft Application Virtualization Virtua.) — C:Program Files (x86)Microsoft Application Virtualization Clientsftvsa.exe [207528] [PID.3880]
    [MD5.77C5A741A7452812F278EF2C18478862] – (.Microsoft Corporation – Microsoft Application Virtualization Client.) — C:Program Files (x86)Microsoft Application Virtualization Clientsftlist.exe [523944] [PID.3288]
    [MD5.FD557A50A65E44041CD2FCEF4BEB04DB] – (.Microsoft Corporation – Microsoft Office Client Virtualization Serv.) — C:Program Files (x86)Common FilesMicrosoft SharedVirtualization HandlerCVHSVC.exe [822504] [PID.4568]
    [MD5.9B7EDD3FE7C211C36E921D34D18A3A0A] – (.Hewlett-Packard Company – HP Software Framework WMI Service.) — C:Program Files (x86)Hewlett-PackardSharedhpqWmiEx.exe [1001376] [PID.5232]
    [MD5.7D4B9A48430ED57ACA6373B71D5904CA] – (.Intel Corporation – IAStorDataSvc.) — C:Program Files (x86)IntelIntel(R) Rapid Storage TechnologyIAStorDataMgrSvc.exe [13592] [PID.3828]
    [MD5.BF22ACF4CF3734D61357E67F0521BC03] – (.Intel Corporation – Local Manageability Service.) — C:Program Files (x86)IntelIntel(R) Management Engine ComponentsLMSLMS.exe [277784] [PID.1468]
    [MD5.B097EBA0E3FEB020BB65FE43AF5ECCFF] – (.Intel Corporation – User Notification Service.) — C:Program Files (x86)IntelIntel(R) Management Engine ComponentsUNSUNS.exe [363800] [PID.4520]
    ~ Processes Running: Scanned in 00mn 02s

    —\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
    C:UserssadaikAppDataLocalGoogleChromeUser DataDefaultPreferences
    ~ Google Browser: 17 Legitimates Filtered in 00mn 12s

    —\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
    C:UserssadaikAppDataRoamingMozillaFirefoxProfilesf54btgoa.defaultprefs.js
    C:UserssadaikAppDataRoamingMozillaFirefoxProfilesf54btgoa.defaultuser.js
    ~ Firefox Browser: 7 Legitimates Filtered in 00mn 00s

    —\ Internet Explorer, Proxy Management (R5)
    R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = no key
    R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyEnable = 0
    R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,MigrateProxy = 1
    R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,EnableHttp1_1 = 1
    R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,AutoConfigProxy = wininet.dll
    ~ Proxy management: Scanned in 00mn 00s

    —\ Analyse des lignes F0, F1, F2, F3 – IniFiles, Autoloading programs
    F2 – REG:system.ini: USERINIT=C:Windowssystem32userinit.exe,
    F2 – REG:system.ini: Shell=C:Windowsexplorer.exe
    F2 – REG:system.ini: VMApplet=C:WindowsSystem32SystemPropertiesPerformance.exe
    ~ Keys: Scanned in 00mn 00s

    —\ Hosts file redirection (O1)
    ~ Le fichier hosts est sain (The hosts file is clean).
    ~ Hosts File: Scanned in 00mn 00s
    ~ Nombre de lignes (Lines number): 21

    —\ Internet Explorer Toolbars (O3)
    O3 – Toolbar: (no name) [64Bits] – [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Clé orpheline
    O3 – ToolbarWebBrowser: (no name) [64Bits] – [HKCU]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} Clé orpheline
    ~ Toolbar: Scanned in 00mn 00s

    —\ Autres liens utilisateurs (O4)
    O4 – GSDesktop [Public]: Ad-Aware.lnk . (.Lavasoft – Ad-Aware GUI.) — C:Program Files (x86)LavasoftAd-AwareAd-Aware.exe
    O4 – GSDesktop [Public]: HP Support Assistant.lnk . (.Hewlett-Packard Company – HP Support Assistant.) — C:Program Files (x86)Hewlett-PackardHP Support FrameworkHPSF.exe =>.Hewlett-Packard Co
    O4 – GSDesktop [Public]: HP+.lnk . (…) — C:Program Files (x86)Hewlett-PackardSharedWizLink.exe
    O4 – GSDesktop [Public]: Magic Desktop.lnk . (.EasyBits Software AS – EasyBits Security Shield.) — C:Program Files (x86)EasyBits For KidsezSecShield.exe =>.EasyBits Software AS
    O4 – GSDesktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation – Firefox.) — C:Program Files (x86)Mozilla Firefoxfirefox.exe
    O4 – GSDesktop [Public]: rara Music.lnk . (…) — C:Program Files (x86)Hewlett-PackardSharedWizLink.exe
    O4 – GSDesktop [Public]: µTorrent.lnk . (.BitTorrent Inc. – µTorrent.) — C:Program Files (x86)uTorrentuTorrent.exe =>P2P.BitTorrent
    O4 – GSProgram [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation – Firefox.) — C:Program Files (x86)Mozilla Firefoxfirefox.exe
    O4 – GSQuickLaunch [sadaik]: Ad-Aware.lnk . (.Lavasoft – Ad-Aware GUI.) — C:Program Files (x86)LavasoftAd-AwareAd-Aware.exe
    O4 – GSQuickLaunch [sadaik]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation – Internet Explorer.) — C:Program Files (x86)Internet Exploreriexplore.exe
    O4 – GSQuickLaunch [sadaik]: µTorrent.lnk . (.BitTorrent Inc. – µTorrent.) — C:Program Files (x86)uTorrentuTorrent.exe =>P2P.BitTorrent
    O4 – GSTaskBar [sadaik]: Google Chrome.lnk . (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe
    O4 – GSTaskBar [sadaik]: HP Recommended.LNK . (…) — C:Program Files (x86)Hewlett-PackardHP LaunchBoxHPTaskBar1.exe (.not file.)
    O4 – GSTaskBar [sadaik]: Internet Explorer.lnk . (.Microsoft Corporation – Internet Explorer.) — C:Program Files (x86)Internet Exploreriexplore.exe
    O4 – GSProgram [sadaik]: Internet Explorer.lnk . (.Microsoft Corporation – Internet Explorer.) — C:Program Files (x86)Internet Exploreriexplore.exe
    O4 – GSSystemTools [sadaik]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation – Internet Explorer.) — C:Program Files (x86)Internet Exploreriexplore.exe
    O4 – GSDesktop [sadaik]: Assistance Livebox.lnk . (.Orange – Assistance Livebox.) — C:Program Files (x86)OrangeAssistance LiveboxAssistanceLivebox.exe
    O4 – GSDesktop [sadaik]: Google Chrome.lnk . (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe
    O4 – GSDesktop [sadaik]: MediaCoder.lnk . (.Broad Intelligence – MediaCoder.) — C:Program Files (x86)MediaCodermediacoder.exe
    ~ Global Startup: 77 Legitimates Filtered in 00mn 02s

    —\ Applications lancées au démarrage du sytème (O4)
    O4 – GSStartup [Public]: Bluetooth.lnk . (…) — C:Program Files (x86)WIDCOMMBluetooth SoftwareBTTray.exe (.not file.)
    O4 – HKLM..Run: [SynTPEnh] C:Program Files (x86)SynapticsSynTPSynTPEnh.exe (.not file.)
    O4 – HKLM..Run: [SetDefault] . (.Hewlett-Packard Development Company, L.P. – SetDefault.) — C:Program FilesHewlett-PackardHP LaunchBoxSetDefault.exe
    O4 – HKLM..Run: [MSC] . (.Microsoft Corporation – Microsoft Security Client User Interface.) — c:Program FilesMicrosoft Security Clientmsseces.exe
    O4 – HKLM..Run: [SysTrayApp] . (.IDT, Inc. – IDT PC Audio.) — C:Program FilesIDTWDMsttray64.exe
    O4 – HKLM..Run: [IgfxTray] . (.Intel Corporation – igfxTray Module.) — C:Windowssystem32igfxtray.exe
    O4 – HKLM..Run: [HotKeysCmds] . (.Intel Corporation – hkcmd Module.) — C:Windowssystem32hkcmd.exe
    O4 – HKLM..Run: [Persistence] . (.Intel Corporation – persistence Module.) — C:Windowssystem32igfxpers.exe
    O4 – HKCU..Run: [Sidebar] . (.Microsoft Corporation – Gadgets du Bureau Windows.) — C:Program FilesWindows Sidebarsidebar.exe =>.Microsoft Corporation
    O4 – HKCU..Run: [Orange Installer] . (…) — C:Program Files (x86)OrangeOrange InstallerOrangeInstaller.exe
    O4 – HKCU..Run: [OrangeInside] . (.Orange – Executable Orange Inside.) — C:UserssadaikAppDataRoamingOrangeOrangeInsideoneOrangeInside.exe
    O4 – HKLM..Wow6432NodeRun: [USB3MON] . (.Intel Corporation – Intel(R) USB 3.0 Monitor.) — C:Program Files (x86)IntelIntel(R) USB 3.0 eXtensible Host Controller DriverApplicationiusb3mon.exe
    O4 – HKLM..Wow6432NodeRun: [Easybits Recovery] . (.EasyBits Software AS – Pas de description.) — C:Program Files (x86)EasyBits For KidsezRecover.exe =>.EasyBits Software AS
    O4 – HKLM..Wow6432NodeRun: [Adobe ARM] . (.Adobe Systems Incorporated – Adobe Reader and Acrobat Manager.) — C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe =>.Adobe Systems Incorporated
    O4 – HKLM..Wow6432NodeRun: [HPOSD] . (.Hewlett-Packard Development Company, L.P. – HP On Screen Display.) — C:Program Files (x86)Hewlett-PackardHP On Screen DisplayHPOSD.exe
    O4 – HKLM..Wow6432NodeRun: [HP CoolSense] . (.Hewlett-Packard Development Company, L.P. – HP CoolSense.) — C:Program Files (x86)Hewlett-PackardHP CoolSenseCoolSense.exe
    O4 – HKLM..Wow6432NodeRun: [HP Quick Launch] . (.Hewlett-Packard Development Company, L.P. – HP Message Service.) — C:Program Files (x86)Hewlett-PackardHP Quick LaunchHPMSGSVC.exe
    O4 – HKLM..Wow6432NodeRun: [Ad-Watch] . (.Lavasoft – Ad-Aware Tray Application.) — C:Program Files (x86)LavasoftAd-AwareAAWTray.exe
    O4 – HKLM..Wow6432NodeRun: [AvastUI.exe] . (.AVAST Software – avast! Antivirus.) — C:Program FilesAVAST SoftwareAvastAvastUI.exe
    O4 – HKUSS-1-5-19..Run: [Sidebar] . (.Microsoft Corporation – Gadgets du Bureau Windows.) — C:Program Files (x86)Windows SidebarSidebar.exe =>.Microsoft Corporation
    O4 – HKUSS-1-5-20..Run: [Sidebar] . (.Microsoft Corporation – Gadgets du Bureau Windows.) — C:Program Files (x86)Windows SidebarSidebar.exe =>.Microsoft Corporation
    O4 – HKUSS-1-5-19..RunOnce: [mctadmin] . (.Microsoft Corporation – MCTAdmin.) — C:WindowsSystem32mctadmin.exe =>.Microsoft Corporation
    O4 – HKUSS-1-5-20..RunOnce: [mctadmin] . (.Microsoft Corporation – MCTAdmin.) — C:WindowsSystem32mctadmin.exe =>.Microsoft Corporation
    O4 – HKUSS-1-5-21-3690416426-1796864196-2923006020-1001..Run: [Sidebar] . (.Microsoft Corporation – Gadgets du Bureau Windows.) — C:Program FilesWindows Sidebarsidebar.exe =>.Microsoft Corporation
    O4 – HKUSS-1-5-21-3690416426-1796864196-2923006020-1001..Run: [Orange Installer] . (…) — C:Program Files (x86)OrangeOrange InstallerOrangeInstaller.exe
    O4 – HKUSS-1-5-21-3690416426-1796864196-2923006020-1001..Run: [OrangeInside] . (.Orange – Executable Orange Inside.) — C:UserssadaikAppDataRoamingOrangeOrangeInsideoneOrangeInside.exe
    ~ Application: Scanned in 00mn 00s

    —\ Modification Domaine/Adresses DNS (O17)
    O17 – HKLMSystemCCSServicesTcpip..{7D69DC7B-32BA-4DB3-84B4-3FFD12878258}: DhcpNameServer = 192.168.1.1 192.168.1.1
    O17 – HKLMSystemCCSServicesTcpip..{E909151F-2F83-48DE-9419-E15605E75C34}: DhcpNameServer = 172.168.31.32
    O17 – HKLMSystemCS1ServicesTcpip..{7D69DC7B-32BA-4DB3-84B4-3FFD12878258}: DhcpNameServer = 192.168.1.1 192.168.1.1
    O17 – HKLMSystemCS1ServicesTcpip..{E909151F-2F83-48DE-9419-E15605E75C34}: DhcpNameServer = 172.168.31.32
    O17 – HKLMSystemCS2ServicesTcpip..{7D69DC7B-32BA-4DB3-84B4-3FFD12878258}: DhcpNameServer = 192.168.1.1 192.168.1.1
    O17 – HKLMSystemCS2ServicesTcpip..{E909151F-2F83-48DE-9419-E15605E75C34}: DhcpNameServer = 172.168.31.32
    O17 – HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 192.168.1.1 192.168.1.1
    ~ Domain: Scanned in 00mn 00s

    —\ Protocole additionnel (O18)
    O18 – Handler: wlpg [64Bits] – {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (…) —
    O18 – Filter: application/x-msdownload [64Bits] – {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation – Microsoft .NET Runtime Execution Engine.) — C:WindowsSystem32mscoree.dll =>.Microsoft Corporation
    ~ Protocole Additionnel: Scanned in 00mn 00s

    —\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
    O20 – Winlogon Notify: igfxcui . (.Intel Corporation – igfxdev Module.) — C:WindowsSystem32igfxdev.dll
    ~ Winlogon: Scanned in 00mn 00s

    —\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
    O20 – AppInit_DLLs: . (.NVIDIA Corporation – NVIDIA shim initialization dll, Version 314.) – C:Windowssystem32nvinitx.dll
    ~ AppInit DLL: Scanned in 00mn 00s

    —\ Liste des services NT non Microsoft et non désactivés (O23)
    O23 – Service: Dedicarz Service (Dedicarz Service) . (.Pas de propriétaire – DedicarzService.) – C:Program Files (x86)OrangeAssistance LiveboxdedicarzDedicarzService.exe
    O23 – Service: Intel(R) Management and Security Applica (UNS) . (.Intel Corporation – User Notification Service.) – C:Program Files (x86)IntelIntel(R) Management Engine ComponentsUNSUNS.exe
    ~ Services: 25 Legitimates Filtered in 00mn 09s

    —\ Enumère les données de BootExecute (BEX) (O34)
    O34 – HKLM BootExecute: (lsdelete) – File not found
    ~ BEX: 2 Legitimates Filtered in 00mn 00s

    —\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
    O43 – CFD: 29/08/2013 – 10:47:23 – [9,927] –H-D C:ProgramData{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
    ~ 23 Dossiers CLSID vides (CLSID Empty Folders)
    ~ Program Folder: 181 Legitimates Filtered in 00mn 53s

    —\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
    O44 – LFC:[MD5.092C1E09F1AFBF0E60DA6832D65EB32B] – 29/10/2013 – 10:07:17 —A- . (…) — C:aaw7boot.log [28220]
    ~ Files: 31 Legitimates Filtered in 00mn 28s

    —\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
    O55 – MWPS:[HKLM…PoliciesSystem] – “EnableUIADesktopToggle”=0
    O55 – MWPS:[HKLM…PoliciesSystem] – “FilterAdministratorToken”=0
    ~ MWPS: 16 Legitimates Filtered in 00mn 00s

    —\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
    O56 – MWPE:[HKLM…policiesExplorer] – “NoActiveDesktopChanges”=1
    ~ MWPE Keys: 4 Legitimates Filtered in 00mn 00s

    —\ Liste des pilotes du système (SDL) (O58)
    O58 – SDL:[MD5.C04F7B373881009D7994D9BF55D24AB4] – 29/10/2013 – 00:43:33 —A- . (…) — C:WindowsSystem32DriversaswRvrt.sys [65776]
    ~ Drivers: 16 Legitimates Filtered in 00mn 00s

    —\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
    O61 – LFC: 28/10/2013 – 13:09:37 —A- . (…) — C:UserssadaikDocumentsroguekiller.txt [1941]
    O61 – LFC: 28/10/2013 – 13:09:48 —A- . (…) — C:UserssadaikDownloadsRogueKiller.exe [3538944]
    O61 – LFC: 29/10/2013 – 13:09:01 —A- . (…) — C:UserssadaikAppDataLocalGoogleChromeUser DataLocal State [46202]
    O61 – LFC: 29/10/2013 – 13:09:08 —A- . (…) — C:UserssadaikAppDataRoamingfr.orange.assistanceliveboxLocal StoreALB.db [9216] =>.Orange Corporation
    O61 – LFC: 29/10/2013 – 13:09:14 —A- . (…) — C:UserssadaikAppDataRoamingZHPLog.txt [18469] =>.Nicolas Coolman
    O61 – LFC: 29/10/2013 – 13:09:14 —A- . (…) — C:UserssadaikAppDataRoamingZHPTestsZHPDiag.txt [2884] =>.Nicolas Coolman
    O61 – LFC: 29/10/2013 – 13:09:39 —A- . (…) — C:UserssadaikDownloadsadwcleaner (1).exe [1060070]
    O61 – LFC: 29/10/2013 – 13:09:39 —A- . (…) — C:UserssadaikDownloadsadwcleaner.exe [1060070]
    O61 – LFC: 29/10/2013 – 13:09:48 —A- . (…) — C:UserssadaikDownloadsSFTGC.exe [1064060]
    O61 – LFC: 29/10/2013 – 13:09:48 —A- . (…) — C:UserssadaikDownloadsrapport_SX.txt [849]
    O61 – LFC: 29/10/2013 – 13:09:49 —A- . (…) — C:UserssadaikDownloadsSXCU (1).exe [362496]
    O61 – LFC: 29/10/2013 – 13:09:49 —A- . (…) — C:UserssadaikDownloadsSXCU.exe [362496]
    ~ Files: 265 Legitimates Filtered in 01mn 01s

    —\ Liste des outils de désinfection (LATC) (O63)
    O63 – Logiciel: ZHPDiag 2013 – (.Nicolas Coolman.) [HKLM] — ZHPDiag_is1 =>.Nicolas Coolman
    ~ ADS: Scanned in 00mn 00s

    —\ Associations Shell Spawning (O67)
    O67 – Shell Spawning: [HKCU..openCommand] (.Not Key.)
    ~ FASS Keys: 19 Legitimates Filtered in 00mn 00s

    —\ Menu de démarrage Internet (SMI) (O68)
    O68 – StartMenuInternet: [HKLM..ShellopenCommand] (.Mozilla Corporation – Firefox.) — C:Program Files (x86)Mozilla Firefoxfirefox.exe
    O68 – StartMenuInternet: [HKLM..ShellopenCommand] (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe
    O68 – StartMenuInternet: [HKLM..ShellopenCommand] (.Microsoft Corporation – Internet Explorer.) — C:Program FilesInternet Exploreriexplore.exe
    ~ Keys: Scanned in 00mn 00s

    —\ Recherche d’infection sur les navigateurs internet (SBI) (O69)
    O69 – SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} – (Bing) – http://www.bing.com” onclick=”window.open(this.href);return false;
    O69 – SBI: SearchScopes [HKCU] {814C76CB-2623-43F4-AAD0-58A0E5190A20} [DefaultScope] – (Orange) – http://r.orange.fr” onclick=”window.open(this.href);return false;
    O69 – SBI: SearchScopes [HKCU] {D944BB61-2E34-4DBF-A683-47E505C587DC} – (eBay) – http://rover.ebay.com” onclick=”window.open(this.href);return false;
    O69 – SBI: SearchScopes [HKCU] {DFADA26B-5C52-412C-8B52-F2CACB6B014B} – (Propositions de recherche Amazon.fr) – http://www.amazon.fr” onclick=”window.open(this.href);return false;
    ~ Keys: Scanned in 00mn 00s

    —\ Enumère les codes produits des logiciels (PUC) (O90)
    O90 – PUC: “3E9A223DB85706D47A4C568CF83D870D” . (.Bing Bar.) — C:WindowsInstaller{D322A9E3-758B-4D60-A7C4-65C88FD378D0}icon_installer_ico =>Toolbar.Bing
    ~ Update Products: 104 Legitimates Filtered in 00mn 00s

    —\ Etat général des services not Microsoft (EGS) (SR=Running, SS=Stopped)
    SR – | Auto 09/05/2013 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) – C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe
    SS – | Demand 08/10/2013 257416 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) – C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe
    SR – | Auto 29/10/2013 50344 | (avast! Antivirus) . (.AVAST Software.) – C:Program FilesAVAST SoftwareAvastAvastSvc.exe
    SS – | Auto 23/07/2013 193696 | (BBSvc) . (.Microsoft Corporation..) – C:Program Files (x86)MicrosoftBingBar7.2.241.0BBSvc.exe
    SR – | Demand 23/07/2013 240288 | (BBUpdate) . (.Microsoft Corporation..) – C:Program Files (x86)MicrosoftBingBar7.2.241.0SeaPort.exe
    SR – | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) – C:Program FilesBonjourmDNSResponder.exe
    SR – | Auto 06/12/2012 1005944 | (btwdins) . (.Broadcom Corporation..) – C:Program FilesWIDCOMMBluetooth Softwarebtwdins.exe
    SS – | Demand 23/05/2013 276248 | (cphs) . (.Intel Corporation.) – C:WindowsSysWow64IntelCpHeciSvc.exe
    SR – | Auto 10/06/2013 1966960 | (Dedicarz Service) . (…) – C:Program Files (x86)OrangeAssistance LiveboxdedicarzDedicarzService.exe
    SR – | Auto 10/07/1658 0 | (ezSharedSvc) . (.EasyBits Software AS.) – C:WindowsSystem32ezSharedSvcHost.exe =>.EasyBits Software AS
    SR – | Auto 07/06/2013 1641768 | (FPLService) . (.HP.) – C:Program Files (x86)HP SimplePassTrueSuiteService.exe
    SS – | Demand 12/10/2010 206072 | (GamesAppService) . (.WildTangent, Inc..) – C:Program Files (x86)WildTangent GamesAppGamesAppService.exe
    SS – | Auto 23/10/2012 116648 | (gupdate) . (.Google Inc..) – C:Program Files (x86)GoogleUpdateGoogleUpdate.exe
    SS – | Demand 23/10/2012 116648 | (gupdatem) . (.Google Inc..) – C:Program Files (x86)GoogleUpdateGoogleUpdate.exe
    SR – | Auto 27/09/2012 86528 | (HP Support Assistant Service) . (.Hewlett-Packard Company.) – C:Program Files (x86)Hewlett-PackardHP Support Frameworkhpsa_service.exe =>.Hewlett-Packard Co
    SR – | Auto 16/02/2011 682040 | (HPAuto) . (.Hewlett-Packard.) – C:Program FilesHewlett-PackardHP AutoHPAuto.exe
    SR – | Auto 11/10/2010 346168 | (HPClientSvc) . (.Hewlett-Packard Company.) – C:Program FilesHewlett-PackardHP Client ServicesHPClientServices.exe
    SR – | Demand 10/08/2012 1001376 | (hpqwmiex) . (.Hewlett-Packard Company.) – C:Program Files (x86)Hewlett-PackardSharedhpqWmiEx.exe
    SR – | Auto 24/09/2012 31040 | (hpsrv) . (.Hewlett-Packard Company.) – C:WindowsSystem32Hpservice.exe
    SR – | Auto 05/03/2012 35200 | (HPWMISVC) . (.Hewlett-Packard Development Company, L.P..) – C:Program Files (x86)Hewlett-PackardHP Quick LaunchHPWMISVC.exe
    SR – | Auto 30/11/2011 13592 | (IAStorDataMgrSvc) . (.Intel Corporation.) – C:Program Files (x86)IntelIntel(R) Rapid Storage TechnologyIAStorDataMgrSvc.exe
    SR – | Auto 08/12/2011 607456 | (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) – C:Program FilesInteliCLS ClientHeciServer.exe
    SR – | Auto 16/12/2011 128280 | (Intel(R) ME Service) . (…) – C:Program Files (x86)IntelIntel(R) Management Engine ComponentsFWServiceIntelMeFWService.exe
    SR – | Auto 16/12/2011 161560 | (jhi_service) . (.Intel Corporation.) – C:Program Files (x86)IntelIntel(R) Management Engine ComponentsDALjhi_service.exe
    SR – | Auto 09/03/2009 951632 | (Lavasoft Ad-Aware Service) . (.Lavasoft.) – C:Program Files (x86)LavasoftAd-AwareAAWService.exe
    SR – | Auto 16/12/2011 277784 | (LMS) . (.Intel Corporation.) – C:Program Files (x86)IntelIntel(R) Management Engine ComponentsLMSLMS.exe
    SS – | Demand 05/01/2013 115760 | (MozillaMaintenance) . (.Mozilla Foundation.) – C:Program Files (x86)Mozilla Maintenance Servicemaintenanceservice.exe
    SR – | Auto 15/03/2013 877856 | (nvsvc) . (.NVIDIA Corporation.) – C:Windowssystem32nvvsvc.exe
    SS – | Auto 15/03/2013 1266464 | (nvUpdatusService) . (.NVIDIA Corporation.) – C:Program Files (x86)NVIDIA CorporationNVIDIA Update Coredaemonu.exe
    SS – | Auto 29/08/2013 1073160 | (Orange update Core Service) . (.Orange SA.) – C:Program Files (x86)OrangeOrangeUpdateServiceOUCore.exe
    SR – | Auto 17/10/2013 1444120 | (RapportMgmtService) . (.Trusteer Ltd..) – C:Program Files (x86)TrusteerRapportbinRapportMgmtService.exe
    SS – | Auto 01/03/2013 161384 | (SkypeUpdate) . (.Skype Technologies.) – C:Program Files (x86)SkypeUpdaterUpdater.exe
    SR – | Auto 23/05/2013 321536 | (STacSV) . (.IDT, Inc..) – C:Program FilesIDTWDMSTacSV64.exe
    SS – | Demand 07/01/2013 401856 | (TrueService) . (.AuthenTec, Inc..) – C:Program FilesCommon FilesAuthenTecTrueService.exe
    SR – | Auto 16/12/2011 363800 | (UNS) . (.Intel Corporation.) – C:Program Files (x86)IntelIntel(R) Management Engine ComponentsUNSUNS.exe
    SS – | Demand 14/07/2009 27136 | C:Program Files (x86)Windows Defendermpsvc.dll (WinDefend) . (.Microsoft Corporation.) – C:WindowsSystem32svchost.exe
    SR – | Auto 10/07/1658 0 | (WMPNetworkSvc) . (…) – C:Program Files (x86)Windows Media Playerwmpnetwk.exe =>.Microsoft Corporation
    SR – | Auto 14/07/2009 27136 | C:WindowsSystem32wuaueng.dll (wuauserv) . (.Microsoft Corporation.) – C:WindowsSystem32svchost.exe
    ~ Services: Scanned in 00mn 18s

    —\ Recherche d’infection sur le Master Boot Record (MBR)(O80)
    Run by sadaik at 29/10/2013 13:11:41
    ~ OS 64 not supported by MBR tool
    ~ MBR: 0 Legitimates Filtered in 00mn 00s

    —\ Recherche d’infection sur le Master Boot Record (MBRCheck)(O80)
    Written by ad13, http://ad13.geekstog” onclick=”window.open(this.href);return false;
    Run by sadaik at 29/10/2013 13:11:43

    ********* Dump file Name *********
    C:PhysicalDisk0_MBR.bin
    ~ MBR: Scanned in 00mn 02s

    —\ Scan Additionnel (O88)
    Database Version : 12960 – (28/10/2013)
    Clés trouvées (Keys found) : 5
    Valeurs trouvées (Values found) : 2
    Dossiers trouvés (Folders found) : 0
    Fichiers trouvés (Files found) : 1

    [HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{C9A6357B-25CC-4BCF-96C1-78736985D412}] =>Toolbar.Orange
    [HKLMSoftwareWow6432NodeMicrosoftTracingBingBar_RASAPI32] =>Toolbar.Bing
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components464AA55239C100F32AF2D438EDDC0F47] =>Adware.IMBooster
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components5652BA3D5FB98AE31B337BF0AF939856] =>Adware.IMBooster
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components86EB95E1AFCBABE3DB9ECCC669B99494] =>Adware.IMBooster
    C:UserssadaikDownloadscacaoweb.exe =>PUP.CacaoWeb
    ~ Additionnel Scan: 271193 Items scanned in 00mn 25s

    —\ Récapitulatif des détections trouvées sur votre station
    ~ http://nicolascoolman.webs.com/apps/blog/show/31536787-toolbar-bing” onclick=”window.open(this.href);return false; =>Toolbar.Bing
    ~ http://nicolascoolman.webs.com/apps/blog/show/26684723-adware-imbooster” onclick=”window.open(this.href);return false; =>Adware.IMBooster
    ~ http://nicolascoolman.webs.com/apps/blog/show/27566847-pup-cacaoweb” onclick=”window.open(this.href);return false; =>PUP.CacaoWeb
    ~ MSI: 3 link(s) detected in 00mn 25s

    ~ 1442 Legitimates filtered by white list
    End of the scan (476 lines in 06mn 15s)(0)

  • scorpio44
    Participant
    Post count: 9

    Ce rapport est en 2 parties car trop volumineux +de 8000 caracteres

    Rapport de SFTGC (Pierre13) du Mardi 29 Octobre 2013 à 12:51:47 version : 2.0.0.55
    Mis à jour le 12/09/2013
    Outil lancé en Mode normal et En tant qu’administrateur
    Windows 7 Home Premium Service Pack 1 64 bits

    Tool start in C:UserssadaikDownloads

    1435 éléments supprimés => 1.16 Go libérés. (58 s)

    C:UserssadaikAppDataLocalTemp1764_13976
    C:UserssadaikAppDataLocalTemp1764_22598
    C:UserssadaikAppDataLocalTemp2952_23974
    C:UserssadaikAppDataLocalTemp3148_3662
    C:UserssadaikAppDataLocalTemp3276_6922
    C:UserssadaikAppDataLocalTemp4308_26063
    C:UserssadaikAppDataLocalTemp5000_11308
    C:UserssadaikAppDataLocalTemp5344_10677
    C:UserssadaikAppDataLocalTemp5424_12628
    C:UserssadaikAppDataLocalTemp5956_25946
    C:UserssadaikAppDataLocalTemp6260_10592
    C:UserssadaikAppDataLocalTemp6260_2969
    C:UserssadaikAppDataLocalTemp6804_2550
    C:UserssadaikAppDataLocalTemp6824_2110
    C:UserssadaikAppDataLocalTemp6936_7709
    C:UserssadaikAppDataLocalTemp7116_24146
    C:UserssadaikAppDataLocalTemp7128_22080
    C:UserssadaikAppDataLocalTempAdobeARM.log
    C:UserssadaikAppDataLocalTempAdwCleaner.jpg
    C:UserssadaikAppDataLocalTempAuthLog
    C:UserssadaikAppDataLocalTempchrome_installer.log
    C:UserssadaikAppDataLocalTempCleaning.ico
    C:UserssadaikAppDataLocalTempDonate.ico
    C:UserssadaikAppDataLocalTempExtract.exe
    C:UserssadaikAppDataLocalTempHP Support Framework
    C:UserssadaikAppDataLocalTempHPSAActionItems.xml
    C:UserssadaikAppDataLocalTempIDauthenticator281198164918475603txt
    C:UserssadaikAppDataLocalTempJSaHCMAPI_2.2.506022111406453252349.dll
    C:UserssadaikAppDataLocalTempnsbBC.tmp
    C:UserssadaikAppDataLocalTempntdll_dump.dll
    C:UserssadaikAppDataLocalTempQuarantine.exe
    C:UserssadaikAppDataLocalTempReport.ico
    C:UserssadaikAppDataLocalTempScan.ico
    C:UserssadaikAppDataLocalTempSP63224.exe
    C:UserssadaikAppDataLocalTempUninstall.ico
    C:UserssadaikAppDataLocalTempwmplog00.sqm
    C:UserssadaikAppDataLocalTempwmplog01.sqm
    C:UserssadaikAppDataLocalTempwmplog02.sqm
    C:UserssadaikAppDataLocalTempwmplog03.sqm
    C:UserssadaikAppDataLocalTempwmplog04.sqm
    C:UserssadaikAppDataLocalTempwmplog05.sqm
    C:UserssadaikAppDataLocalTempWPDNSE
    C:UserssadaikAppDataLocalTemp_avast_
    C:UserssadaikAppDataLocalTemp~DF289EC409C9BB598B.TMP
    C:UserssadaikAppDataLocalTemp{D327D99E-08AB-4305-BC4F-05400C8C6953}{383F9CA1-4E49-44DA-BB6B-F8DD5CD7F21C}
    C:UserssadaikAppDataLocalTemp{D327D99E-08AB-4305-BC4F-05400C8C6953}{383F9CA1-4E49-44DA-BB6B-F8DD5CD7F21C}HP64msi.log
    C:UserssadaikAppDataLocalTempupdater_temp_truesuiterollback
    C:UserssadaikAppDataLocalTempnsbBC.tmpnsExec.dll
    C:UserssadaikAppDataLocalTempnsbBC.tmpversion.dll
    C:UserssadaikAppDataLocalTempHPWarrantyCheckerHPWarrantyCheckHPWarrantyChecker.exe
    C:UserssadaikAppDataLocalTempHPWarrantyCheckerHPWarrantyCheckInterop.TaskScheduler.dll
    C:UserssadaikAppDataLocalTempHPWarrantyCheckerHPWarrantyCheckResourcesImagesHwUpgrades
    C:UserssadaikAppDataLocalTempHPWarrantyCheckerHPWarrantyCheckResourcesImagesHwUpgradesUpgrade_CPC.png
    C:UserssadaikAppDataLocalTempHP Support FrameworkHPSF_Config1.dll
    C:UserssadaikAppDataLocalTempAdobeAcrobat10.0
    C:UserssadaikAppDataLocalTemp7128_22080crl-set
    C:UserssadaikAppDataLocalTemp7128_22080manifest.fingerprint
    C:UserssadaikAppDataLocalTemp7128_22080manifest.json
    C:UserssadaikAppDataLocalTemp7116_24146crl-set
    C:UserssadaikAppDataLocalTemp7116_24146manifest.fingerprint
    C:UserssadaikAppDataLocalTemp7116_24146manifest.json
    C:UserssadaikAppDataLocalTemp6936_7709crl-set
    C:UserssadaikAppDataLocalTemp6936_7709manifest.fingerprint
    C:UserssadaikAppDataLocalTemp6936_7709manifest.json
    C:UserssadaikAppDataLocalTemp6824_2110crl-set
    C:UserssadaikAppDataLocalTemp6824_2110manifest.fingerprint
    C:UserssadaikAppDataLocalTemp6824_2110manifest.json
    C:UserssadaikAppDataLocalTemp6804_2550crl-set
    C:UserssadaikAppDataLocalTemp6804_2550manifest.fingerprint
    C:UserssadaikAppDataLocalTemp6804_2550manifest.json
    C:UserssadaikAppDataLocalTemp6260_2969crl-set
    C:UserssadaikAppDataLocalTemp6260_2969manifest.fingerprint
    C:UserssadaikAppDataLocalTemp6260_2969manifest.json
    C:UserssadaikAppDataLocalTemp6260_10592crl-set
    C:UserssadaikAppDataLocalTemp6260_10592manifest.fingerprint
    C:UserssadaikAppDataLocalTemp6260_10592manifest.json
    C:UserssadaikAppDataLocalTemp5956_25946crl-set
    C:UserssadaikAppDataLocalTemp5956_25946manifest.fingerprint
    C:UserssadaikAppDataLocalTemp5956_25946manifest.json
    C:UserssadaikAppDataLocalTemp5424_12628crl-set
    C:UserssadaikAppDataLocalTemp5424_12628manifest.fingerprint
    C:UserssadaikAppDataLocalTemp5424_12628manifest.json
    C:UserssadaikAppDataLocalTemp5344_10677crl-set
    C:UserssadaikAppDataLocalTemp5344_10677manifest.fingerprint
    C:UserssadaikAppDataLocalTemp5344_10677manifest.json
    C:UserssadaikAppDataLocalTemp5000_11308crl-set
    C:UserssadaikAppDataLocalTemp5000_11308manifest.fingerprint
    C:UserssadaikAppDataLocalTemp5000_11308manifest.json
    C:UserssadaikAppDataLocalTemp4308_26063crl-set
    C:UserssadaikAppDataLocalTemp4308_26063manifest.fingerprint
    C:UserssadaikAppDataLocalTemp4308_26063manifest.json
    C:UserssadaikAppDataLocalTemp3276_6922crl-set
    C:UserssadaikAppDataLocalTemp3276_6922manifest.fingerprint
    C:UserssadaikAppDataLocalTemp3276_6922manifest.json
    C:UserssadaikAppDataLocalTemp3148_3662crl-set
    C:UserssadaikAppDataLocalTemp3148_3662manifest.fingerprint
    C:UserssadaikAppDataLocalTemp3148_3662manifest.json
    C:UserssadaikAppDataLocalTemp2952_23974crl-set
    C:UserssadaikAppDataLocalTemp2952_23974manifest.fingerprint
    C:UserssadaikAppDataLocalTemp2952_23974manifest.json
    C:UserssadaikAppDataLocalTemp1764_22598crl-set
    C:UserssadaikAppDataLocalTemp1764_22598manifest.fingerprint
    C:UserssadaikAppDataLocalTemp1764_22598manifest.json
    C:UserssadaikAppDataLocalTemp1764_13976crl-set
    C:UserssadaikAppDataLocalTemp1764_13976manifest.fingerprint
    C:UserssadaikAppDataLocalTemp1764_13976manifest.json
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFRTLBConfiguration.conf
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13OrangeStats
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13Server
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13Styles
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13UpgradeInfo.xml
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13VersionDefinition.xml
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13StylesOrangeToolbar.isl
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ServerOrangeTLBSync.exe
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ServerOrangeToolbarRemotingObject.dll
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13Resourcesarrow.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ResourcesarrowRollover.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ResourcesauthentButton.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13Resourcesbackground.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13Resourcesbutton.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ResourcesbuttonIcon.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13Resourceschevrons.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ResourceschevronsRollover.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13Resourcesloader.gif
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ResourceslogoutButton.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ResourcesokButton.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ResourcesOrangeLogo.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ResourcessearchMenu_Annuaire.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ResourcessearchMenu_Bookmark.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ResourcessearchMenu_Desktop.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ResourcessearchMenu_FrenchWeb.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ResourcessearchMenu_Images.png
    C:UserssadaikAppDataLocalLowOrangeOrangeToolbarFR13ResourcessearchMenu_MagGlass.png
    C:UserssadaikAppDataLocalMicrosoftWindowsHistorydesktop.ini
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryLowdesktop.ini
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryLowHistory.IE5container.dat
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryLowHistory.IE5desktop.ini
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryLowHistory.IE5MSHist012013051620130517
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryLowHistory.IE5MSHist012013051620130517container.dat
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryHistory.IE5container.dat
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryHistory.IE5desktop.ini
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryHistory.IE5MSHist012013101420131021
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryHistory.IE5MSHist012013102120131028
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryHistory.IE5MSHist012013102820131029
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryHistory.IE5MSHist012013102920131030
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryHistory.IE5MSHist012013102920131030container.dat
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryHistory.IE5MSHist012013102820131029container.dat
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryHistory.IE5MSHist012013102120131028container.dat
    C:UserssadaikAppDataLocalMicrosoftWindowsHistoryHistory.IE5MSHist012013101420131021container.dat
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.MSO
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.Word
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet Filesdesktop.ini
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesSqm
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCUserssadaikAppDataRoamingMicrosoftWindowsPrivacIELow
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCUserssadaikAppDataLocalGDIPFONTCACHEV1.DAT
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCUserssadaikAppDataLocalTrusteerRapportuserlogs
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCUserssadaikAppDataLocalTrusteerRapportuserlogsgp_iexplore.4544.log
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCUserssadaikAppDataLocalTrusteerRapportuserlogsgp_IEXPLORE.4940.log
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCUserssadaikAppDataLocalTrusteerRapportuserlogsgp_IEXPLORE.8036.log
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCUserssadaikAppDataLocalTrusteerRapportuserlogskoan.4544.log
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCUserssadaikAppDataLocalTrusteerRapportuserlogskoan.4940.log
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCUserssadaikAppDataLocalTrusteerRapportuserlogskoan.8036.log
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCUserssadaikAppDataLocalTrusteerRapportuserlogskoanlight.4544.log
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCUserssadaikAppDataLocalTrusteerRapportuserlogskoanlight.4940.log
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCUserssadaikAppDataLocalTrusteerRapportuserlogskoanlight.8036.log
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCProgramDataNVIDIA CorporationDrs
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCProgramDataNVIDIA CorporationDrsnvAppTimestamps
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCProgramDataNVIDIA CorporationDrsnvdrssel.bin
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesSqmiesqmdata0.sqm
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesLowAntiPhishing
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesLowContent.IE5
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesLowdesktop.ini
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesLowMSIMGSIZ.DAT
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesLowContent.IE5container.dat
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesLowAntiPhishing7A7E08C8-3FF5-45F2-873D-A84D669DC82F.dat
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesLowAntiPhishingED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5container.dat
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5K3FKQ73R
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5S6AU4Y0E
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5SDKAN2Z6
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5T4Y9AC91
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5ZRAK4F0Z
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5ZRAK4F0Z62342[1]
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5ZRAK4F0ZDefault[2].aspx
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5ZRAK4F0ZGetContent[1].jpg
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5ZRAK4F0ZGetMDRCDPOSTURL[1].aspx
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5ZRAK4F0Zie8[1].htm
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5ZRAK4F0ZserviceinfoMusic[1].xml
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5ZRAK4F0ZVersion[1].txt
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5ZRAK4F0ZVersion[2].txt
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5ZRAK4F0Zwebslice[1].htm
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5ZRAK4F0ZWMP1a334016-a271-4007-a5e8-e0b8e0b268bf[1]..jpg
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5ZRAK4F0Z__utm[1].gif
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5T4Y9AC91configW7[1].xml
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5T4Y9AC91data[1].xml
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5SDKAN2Z613526[1]
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5SDKAN2Z68918[1]
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5SDKAN2Z6configW7[1].xml
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5SDKAN2Z6fwlink[1].htm
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5SDKAN2Z6fwlink[2].htm
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5SDKAN2Z6ie8[1].htm
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5SDKAN2Z6rdr[1].htm
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5SDKAN2Z6VersionSFT[1].txt
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5SDKAN2Z6WMP8b2d9f12-8fa1-4f7c-a474-e1d06cb1c24a[1]..jpg
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5SDKAN2Z6__utm[1].gif
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5SDKAN2Z6__utm[2].gif
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5SDKAN2Z6__utm[3].gif
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5S6AU4Y0E28016ffcbe8a1939af038a0db8cfb2f471a00311[1].htm
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5S6AU4Y0Edata[1].xml
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5S6AU4Y0Edata[2].xml
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5S6AU4Y0EGetContent[1].xml
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5S6AU4Y0EGetContent[2].xml
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5S6AU4Y0EMenuURLMusic[1].png
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5S6AU4Y0EServiceLargeURL12[1].png
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5S6AU4Y0EWMP27df5056-31de-486c-9786-7be983887fb2[1]..jpg
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5S6AU4Y0EWMP88bb25f1-696f-45ab-8077-66b182e745f7[1]..jpg
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5S6AU4Y0E__utm[1].gif
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5S6AU4Y0E__utm[2].gif
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5K3FKQ73R48543[1]
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5K3FKQ73RAllServices[1].xml
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5K3FKQ73RGetContent[1].png
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5K3FKQ73RGetMDRCDPOSTURL[1].aspx
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5K3FKQ73Rie8[1].htm
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5K3FKQ73Rie8[2].htm
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5K3FKQ73RServiceSmallURL[1].png
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5K3FKQ73Rwm_com_v_rgb_15x15[1].png
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5K3FKQ73R__utm[1].gif
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5K3FKQ73R__utm[2].gif
    C:UserssadaikAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5K3FKQ73R__utm[3].gif
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecent01.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecent2013-06-28.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecent2013-07-04 doc.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecent2013-08-06 20.13.42.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecent4-BNE 9 septembre 2013-Motion retraites votée.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentA3 Formation DB3 – Volume 2.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentABERKANE Sadaik.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentanzar-kafir_alexander-splendor_large.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentAttachments_2012_10_26.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentAttachments_2012_11_19.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentAttachments_2012_11_22.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentAttachments_2012_11_23.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentAutomaticDestinations
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentBienvenue.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentBoîte de réception.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentbrains1 001.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentCahier d’exercices – Enrichir les observations V1.0.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentCirculaire 2013-01.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentCirculaire échelon 2 ans.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentCommission de Réforme.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentcrp.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentCustomDestinations
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentDallas.2012.S02E15.FASTSUB.VOSTFR.720p.HDTV.x264-F4ST.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentDallas.2012.S02E15.FASTSUB.VOSTFR.720p.HDTV.x264-F4ST.mkv.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentDemande de paiement des Heures Supplémentaires.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentdesktop.ini
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentdessaux.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentdoc 001 (1).lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentdoc 001.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentDocuments numérisés.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentDocuments.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentedf 001.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentexpress.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentfax-0244840245-0170557515-20130922104301-1379839381.2333 (1).lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentFichiers.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentfr-fr.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentgdf.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentImages.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentimgres.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentimpot 2013(revenus 2012).lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentInformation Auto Direct Assurance (1).lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentlettre de resiliation.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentLettre Type.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentLogs.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentMalette – Detention – Vestiaire.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentMaverickMen – Straight Boy Cherry Pop – Hunter, Cole & Tommy.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentmbam-log-2013-10-28 (21-11-59).lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentMes images.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentMr & Mme ABERKANE.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentNouvelles vidéos bandantes.lnk
    C:UserssadaikAppDataRoamingMicrosoftWindowsRecentorleans_mag111.lnk
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData130ADF60D1B7B3CF82CC6CA82D961601_2FFE778CED2FD9BBAB74B5314F3440CA
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData130ADF60D1B7B3CF82CC6CA82D961601_BFF3E82445C199812E8EC4CC74EA6FD4
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData130ADF60D1B7B3CF82CC6CA82D961601_F3F138DDA4E72F849B7E03101CED9406
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData1DAF2884EC4DFA96BA4A58D4DBC9C406
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData1F39B5CFACECFDE48DB25BCA2231FAC6_0A6205079491C9BB3442CCD0C01A26DB
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData1F39B5CFACECFDE48DB25BCA2231FAC6_135A427F1ED873A4BF5097F7A809FA2A
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData1F39B5CFACECFDE48DB25BCA2231FAC6_659E8B339CB5D4A3440EE573BB1175E7
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData1F39B5CFACECFDE48DB25BCA2231FAC6_AF0C2EE105FB75E951BD399797433878
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData207B9FD92391B9B2A60A89B4C965D5DF
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData21253908F3CB05D51B1C2DA8B681A785
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData23B523C9E7746F715D33C6527C18EB9D
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData3130B1871A126520A8C47861EFE3ED4D
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData37C951188967C8EB88D99893D9D191FE
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData3C3948BE6E525B8A8CEE9FAC91C9E392_5BEB6C6453DB87D996BDBC5D90D34AE1
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData3C3948BE6E525B8A8CEE9FAC91C9E392_70EBAAE68A2949E536A14CEB79290052
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData3C3948BE6E525B8A8CEE9FAC91C9E392_C8FA2A733FE2A95A8ABEB57315278F81
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData4309200C3DBAD0F6F0DFACE9165FD092
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData4DD39726D4B55AC3B4119B35A893323C_558346C9EC433D7E0C0E40884A0BF603
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData5457A8CE4B2A7499F8299A013B6E1C7C_4BDA944235F1446F185236D493959297
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData57C8EDB95DF3F0AD4EE2DC2B8CFD4157
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData5C45AD19E3530EC4218F560AFC04C3F7
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData60E31627FDA0A46932B0E5948949F2A5
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData62B5AF9BE9ADC1085C3C56EC07A82BF6
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData696F3DE637E6DE85B458996D49D759AD
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData6AA3321A15A787985201D7A6820782F0_4E35DE6F4FCFB7BE2C045F6B5ED89FC8
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData6B7AED56F69397028F35E77E6DD681FC
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7396C420A8E1BC1DA97F1AF0D10BAD21
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData74BFD122C0875EC75DBE5C6DB4C59019
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData77EC63BDA74BD0D0E0426DC8F8008506
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData783DF2F5A7C9BC04C36663632D14B993_09A85C5418FB163D61A6CDA83D9C0B2C
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B2238AACCEDC3F1FFE8E7EB5F575EC9
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_28B92C2A450B05C41EFDAC42E08BE299
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_355DF12EAABE3F04A4C1AF592920E175
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_37A2EE06120A6ADAF05DDF491177BB3A
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_4E77F136D5A7E8FBC05E0674B32314AD
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_5442B1CAC753FE77C0664BB0A0BCD11E
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_8102C2D9BECD09FCBB2BC1857DCCAD50
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_96E18C6F7F11D436D50EB658BB37DA57
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_AE80968B09655437A4C6DA8671FF8BB7
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_B2087E0B670B77412221B4DDD6EED487
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_B6BE63DC850D81A0F76BAF35804A5109
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_DBEBBB72D7CF896A67503824FF19F0BB
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_E5F52F44EFEA601D95BF7714E6B3781D
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_EC757EE2334DC15F8EC7D6598BA39F24
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_FC9386660504DD089A3224FBCF3C0610
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7D1F03728133589A90656A87E482B21F
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7D266D9E1E69FA1EEFB9699B009B34C8_1D5A876A9113EC07224C45E5A870E3BD
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7D266D9E1E69FA1EEFB9699B009B34C8_8CA7164968F366C9A94AC8E71C4BDD9B
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8890A77645B73478F5B1DED18ACBF795_1E5D470765E0BE1964814B1F5A3581DC
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8DFDF057024880D7A081AFBF6D26B92F
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData94308059B57B3142E455B38A6EB92015
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData955CAB6FF6A24D5820D50B5BA1CF79C7_AD9E7615297A3A83320AACE5801A04F9
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataA1377F7115F1F126A15360369B165211
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataAC9005F5466BD463DF06D711B370595F
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataB3BB9C1BA2D19E090AE305B2683903A0_6F0A84CE2BA99BD19D42C92610275852
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataB8CC409ACDBF2A2FE04C56F2875B1FD6
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataBD8A14C7C024625432CC03FE72E47EF0_35DB72DF5C829F76FA820993F2C82D80
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataBD8A14C7C024625432CC03FE72E47EF0_3A5F651392150CF214ACD12CFF48904C
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataBD8A14C7C024625432CC03FE72E47EF0_6FD1BEFD298F4FD3EE4B4EE2E6631CC7
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataBD8A14C7C024625432CC03FE72E47EF0_9A7E95AFAD37DF8C0CB08A3AAB34052E
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataCA7B2D59B4E9BC2D316D1AECDFC12F63_8D3B1392CF242E665F2C60EC4734C971
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataCA7B2D59B4E9BC2D316D1AECDFC12F63_E8FFB3D833ACBBA2A753BCE3F81C274B
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataE2EF7F0FB7284B9ACFD4F65D02218479
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataE48DDEA3BF68DF580551FA0F27950B54
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataE63A640A06A2B005AB42F3250BC98D9E_6020995806BF99A1FBC324A7B889F612
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataE76BF8706526FBFA546EB1718F852E85_9BDA1A7A25F2B5C32A9083C3BEFB69F1
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataF72943F1E01540BBACB5396C76DD6AAA
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataF90F18257CBB4D84216AC1E1F3BB2C76
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataFB788E090BC1F3AA2FBC9E8FB2859601
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent130ADF60D1B7B3CF82CC6CA82D961601_2FFE778CED2FD9BBAB74B5314F3440CA
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent130ADF60D1B7B3CF82CC6CA82D961601_BFF3E82445C199812E8EC4CC74EA6FD4
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent130ADF60D1B7B3CF82CC6CA82D961601_F3F138DDA4E72F849B7E03101CED9406
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent1DAF2884EC4DFA96BA4A58D4DBC9C406
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent1F39B5CFACECFDE48DB25BCA2231FAC6_0A6205079491C9BB3442CCD0C01A26DB
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent1F39B5CFACECFDE48DB25BCA2231FAC6_135A427F1ED873A4BF5097F7A809FA2A
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent1F39B5CFACECFDE48DB25BCA2231FAC6_659E8B339CB5D4A3440EE573BB1175E7
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent1F39B5CFACECFDE48DB25BCA2231FAC6_AF0C2EE105FB75E951BD399797433878
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent207B9FD92391B9B2A60A89B4C965D5DF
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent21253908F3CB05D51B1C2DA8B681A785
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent23B523C9E7746F715D33C6527C18EB9D
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent3130B1871A126520A8C47861EFE3ED4D
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent37C951188967C8EB88D99893D9D191FE
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent3C3948BE6E525B8A8CEE9FAC91C9E392_5BEB6C6453DB87D996BDBC5D90D34AE1
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent3C3948BE6E525B8A8CEE9FAC91C9E392_70EBAAE68A2949E536A14CEB79290052
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent3C3948BE6E525B8A8CEE9FAC91C9E392_C8FA2A733FE2A95A8ABEB57315278F81
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent4309200C3DBAD0F6F0DFACE9165FD092
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent4DD39726D4B55AC3B4119B35A893323C_558346C9EC433D7E0C0E40884A0BF603
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent5457A8CE4B2A7499F8299A013B6E1C7C_4BDA944235F1446F185236D493959297
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent57C8EDB95DF3F0AD4EE2DC2B8CFD4157
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent5C45AD19E3530EC4218F560AFC04C3F7
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent60E31627FDA0A46932B0E5948949F2A5
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent62B5AF9BE9ADC1085C3C56EC07A82BF6
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent696F3DE637E6DE85B458996D49D759AD
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent6AA3321A15A787985201D7A6820782F0_4E35DE6F4FCFB7BE2C045F6B5ED89FC8
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent6B7AED56F69397028F35E77E6DD681FC
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7396C420A8E1BC1DA97F1AF0D10BAD21
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent74BFD122C0875EC75DBE5C6DB4C59019
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent77EC63BDA74BD0D0E0426DC8F8008506
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent783DF2F5A7C9BC04C36663632D14B993_09A85C5418FB163D61A6CDA83D9C0B2C
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B2238AACCEDC3F1FFE8E7EB5F575EC9
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_28B92C2A450B05C41EFDAC42E08BE299
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_355DF12EAABE3F04A4C1AF592920E175
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_37A2EE06120A6ADAF05DDF491177BB3A
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_4E77F136D5A7E8FBC05E0674B32314AD
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_5442B1CAC753FE77C0664BB0A0BCD11E
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_8102C2D9BECD09FCBB2BC1857DCCAD50
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_96E18C6F7F11D436D50EB658BB37DA57
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_AE80968B09655437A4C6DA8671FF8BB7
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_B2087E0B670B77412221B4DDD6EED487
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_B6BE63DC850D81A0F76BAF35804A5109
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_DBEBBB72D7CF896A67503824FF19F0BB
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_E5F52F44EFEA601D95BF7714E6B3781D
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_EC757EE2334DC15F8EC7D6598BA39F24
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_FC9386660504DD089A3224FBCF3C0610
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7D1F03728133589A90656A87E482B21F
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7D266D9E1E69FA1EEFB9699B009B34C8_1D5A876A9113EC07224C45E5A870E3BD
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent7D266D9E1E69FA1EEFB9699B009B34C8_8CA7164968F366C9A94AC8E71C4BDD9B
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent8890A77645B73478F5B1DED18ACBF795_1E5D470765E0BE1964814B1F5A3581DC
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent8DFDF057024880D7A081AFBF6D26B92F
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent94308059B57B3142E455B38A6EB92015
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContent955CAB6FF6A24D5820D50B5BA1CF79C7_AD9E7615297A3A83320AACE5801A04F9
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentA1377F7115F1F126A15360369B165211
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentAC9005F5466BD463DF06D711B370595F
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentB3BB9C1BA2D19E090AE305B2683903A0_6F0A84CE2BA99BD19D42C92610275852
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentB8CC409ACDBF2A2FE04C56F2875B1FD6
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentBD8A14C7C024625432CC03FE72E47EF0_35DB72DF5C829F76FA820993F2C82D80
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentBD8A14C7C024625432CC03FE72E47EF0_3A5F651392150CF214ACD12CFF48904C
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentBD8A14C7C024625432CC03FE72E47EF0_6FD1BEFD298F4FD3EE4B4EE2E6631CC7
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentBD8A14C7C024625432CC03FE72E47EF0_9A7E95AFAD37DF8C0CB08A3AAB34052E
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentCA7B2D59B4E9BC2D316D1AECDFC12F63_8D3B1392CF242E665F2C60EC4734C971
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentCA7B2D59B4E9BC2D316D1AECDFC12F63_E8FFB3D833ACBBA2A753BCE3F81C274B
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentE2EF7F0FB7284B9ACFD4F65D02218479
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentE48DDEA3BF68DF580551FA0F27950B54
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentE63A640A06A2B005AB42F3250BC98D9E_6020995806BF99A1FBC324A7B889F612
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentE76BF8706526FBFA546EB1718F852E85_9BDA1A7A25F2B5C32A9083C3BEFB69F1
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentF72943F1E01540BBACB5396C76DD6AAA
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentF90F18257CBB4D84216AC1E1F3BB2C76
    C:UserssadaikAppDataLocalLowMicrosoftCryptnetUrlCacheContentFB788E090BC1F3AA2FBC9E8FB2859601
    C:UserssadaikAppDataLocalTempupdater_temp_truesuite
    C:UserssadaikAppDataLocalTemp{D327D99E-08AB-4305-BC4F-05400C8C6953}
    C:UserssadaikAppDataLocalTempHPWarrantyCheckerHPWarrantyCheckResourcesImages
    C:UserssadaikAppDataLocalTempAdobeAcrobat
    C:WindowsTEMP3376.tmp
    C:WindowsTEMP83B3.tmp
    C:WindowsTEMPaawB228.tmp
    C:WindowsTEMPACLM
    C:WindowsTEMPACLM_GeneratedProxy.cs
    C:WindowsTEMPAdobeARM.log
    C:WindowsTEMPASPNETSetup_00000.log
    C:WindowsTEMPASPNETSetup_00001.log
    C:WindowsTEMPASPNETSetup_00002.log
    C:WindowsTEMPASPNETSetup_00003.log
    C:WindowsTEMPASPNETSetup_00004.log
    C:WindowsTEMPASPNETSetup_00005.log
    C:WindowsTEMPASPNETSetup_00006.log
    C:WindowsTEMPASPNETSetup_00007.log
    C:WindowsTEMPASPNETSetup_00008.log
    C:WindowsTEMPASPNETSetup_00009.log
    C:WindowsTEMPASPNETSetup_00010.log
    C:WindowsTEMPASPNETSetup_00011.log
    C:WindowsTEMPASPNETSetup_00012.log
    C:WindowsTEMPASPNETSetup_00013.log
    C:WindowsTEMPASPNETSetup_00014.log
    C:WindowsTEMPASPNETSetup_00015.log
    C:WindowsTEMPASPNETSetup_00016.log
    C:WindowsTEMPASPNETSetup_00017.log
    C:WindowsTEMPASPNETSetup_00018.log
    C:WindowsTEMPASPNETSetup_00019.log
    C:WindowsTEMPC1278489-2329-4E46-8F69-86DFA4B1BC5C-Sigs
    C:WindowsTEMPcab_3264_2
    C:WindowsTEMPcab_3264_3
    C:WindowsTEMPcab_3264_4
    C:WindowsTEMPcab_3264_5
    C:WindowsTEMPcab_3264_6
    C:WindowsTEMPcab_3264_7
    C:WindowsTEMPcab_3264_8
    C:WindowsTEMPchrome_installer.log
    C:WindowsTEMPCR_BB2A0.tmp
    C:WindowsTEMPdd_clwireg.txt
    C:WindowsTEMPdd_dotNetFx40LP_Client_x86_x64fr_decompression_log.txt
    C:WindowsTEMPdd_dotNetFx40_Client_x86_x64_decompression_log.txt
    C:WindowsTEMPdd_NDP40-KB2468871-v2-x64_decompression_log.txt
    C:WindowsTEMPdd_SetupUtility.txt
    C:WindowsTEMPdd_vcredistMSI15E8.txt
    C:WindowsTEMPdd_vcredistMSI2BBE.txt
    C:WindowsTEMPdd_vcredistMSI2C24.txt
    C:WindowsTEMPdd_vcredistUI15E8.txt
    C:WindowsTEMPdd_vcredistUI2BBE.txt
    C:WindowsTEMPdd_vcredistUI2C24.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130606_210828_982.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130606_210836_093.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130606_211129_184.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130606_211130_954.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130606_212315_182.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130606_212316_879.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130606_212739_520.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130606_212740_590.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130606_213024_736.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130606_213025_533.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130607_210217_566.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130607_210220_649.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130607_210637_539.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130607_210639_041.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130713_211019_201.txt
    C:WindowsTEMPdd_wcf_CA_smci_20130713_211023_108.txt
    C:WindowsTEMPdd_wcf_CA_smci_20131010_211205_640.txt
    C:WindowsTEMPdd_wcf_CA_smci_20131010_211214_959.txt
    C:WindowsTEMPdd_wcf_CA_smci_20131010_212244_517.txt
    C:WindowsTEMPdd_wcf_CA_smci_20131010_212245_952.txt
    C:WindowsTEMPdefaultCache.reg
    C:WindowsTEMPDMI4D35.tmp
    C:WindowsTEMPDMI4E4E.tmp
    C:WindowsTEMPDMI5C13.tmp
    C:WindowsTEMPDMI7925.tmp
    C:WindowsTEMPdmiwu
    C:WindowsTEMPfwtsqmfile00.sqm
    C:WindowsTEMPfwtsqmfile01.sqm
    C:WindowsTEMPfwtsqmfile02.sqm
    C:WindowsTEMPfwtsqmfile03.sqm
    C:WindowsTEMPfwtsqmfile04.sqm
    C:WindowsTEMPfwtsqmfile05.sqm
    C:WindowsTEMPfwtsqmfile06.sqm
    C:WindowsTEMPfwtsqmfile07.sqm
    C:WindowsTEMPfwtsqmfile08.sqm
    C:WindowsTEMPfwtsqmfile09.sqm
    C:WindowsTEMPfwtsqmfile10.sqm
    C:WindowsTEMPfwtsqmfile11.sqm
    C:WindowsTEMPfwtsqmfile12.sqm
    C:WindowsTEMPfwtsqmfile13.sqm
    C:WindowsTEMPfwtsqmfile14.sqm
    C:WindowsTEMPfwtsqmfile15.sqm
    C:WindowsTEMPfwtsqmfile16.sqm
    C:WindowsTEMPfwtsqmfile17.sqm
    C:WindowsTEMPfwtsqmfile18.sqm
    C:WindowsTEMPfwtsqmfile19.sqm
    C:WindowsTEMPFXSAPIDebugLogFile.txt
    C:WindowsTEMPFXSTIFFDebugLogFile.txt
    C:WindowsTEMPHealthCheckAC.xml
    C:WindowsTEMPHFIAF4D.tmp.html
    C:WindowsTEMPIEA19E.tmp
    C:WindowsTEMPIEBA8B.tmp
    C:WindowsTEMPIEBF7A.tmp
    C:WindowsTEMPKB2468871v2_10.0.30319
    C:WindowsTEMPKB2468871v2_20121029_065121072-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2468871v2_20121029_065121072.html
    C:WindowsTEMPKB2468871v2_20130606_232443605-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2468871v2_20130606_232443605-Microsoft .NET Framework 4 Extended-MSP1.txt
    C:WindowsTEMPKB2468871v2_20130606_232443605.html
    C:WindowsTEMPKB2487367_10.0.30319
    C:WindowsTEMPKB2487367_20130607_230114119-Microsoft .NET Framework 4 Extended-MSP0.txt
    C:WindowsTEMPKB2487367_20130607_230114119.html
    C:WindowsTEMPKB2533523_10.0.30319
    C:WindowsTEMPKB2533523_20121028_224724256-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2533523_20121028_224724256.html
    C:WindowsTEMPKB2533523_20130606_231048129-Microsoft .NET Framework 4 Client Profile-MSP1.txt
    C:WindowsTEMPKB2533523_20130606_231048129-Microsoft .NET Framework 4 Extended-MSP0.txt
    C:WindowsTEMPKB2533523_20130606_231048129.html
    C:WindowsTEMPKB2600217_10.0.30319
    C:WindowsTEMPKB2600217_20121028_224351768-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2600217_20121028_224351768.html
    C:WindowsTEMPKB2600217_20130606_230114021-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2600217_20130606_230114021-Microsoft .NET Framework 4 Extended-MSP1.txt
    C:WindowsTEMPKB2600217_20130606_230114021.html
    C:WindowsTEMPKB2604121_10.0.30319
    C:WindowsTEMPKB2604121_20121028_225116181-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2604121_20121028_225116181.html
    C:WindowsTEMPKB2656351_10.0.30319
    C:WindowsTEMPKB2656351_20121028_224959148-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2656351_20121028_224959148.html
    C:WindowsTEMPKB2656351_20130606_231807951-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2656351_20130606_231807951-Microsoft .NET Framework 4 Extended-MSP1.txt
    C:WindowsTEMPKB2656351_20130606_231807951.html
    C:WindowsTEMPKB2656368v2_10.0.30319
    C:WindowsTEMPKB2656368v2_20121029_065658654-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2656368v2_20121029_065658654.html
    C:WindowsTEMPKB2656405_10.0.30319
    C:WindowsTEMPKB2656405_20121028_225518294-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2656405_20121028_225518294.html
    C:WindowsTEMPKB2656405_20121029_064757358-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2656405_20121029_064757358.html
    C:WindowsTEMPKB2686827_10.0.30319
    C:WindowsTEMPKB2686827_20121028_225340684-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2686827_20121028_225340684.html
    C:WindowsTEMPKB2729449_10.0.30319
    C:WindowsTEMPKB2729449_20121116_065210810-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2729449_20121116_065210810.html
    C:WindowsTEMPKB2736428_10.0.30319
    C:WindowsTEMPKB2736428_20130607_230332849-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2736428_20130607_230332849-Microsoft .NET Framework 4 Extended-MSP1.txt
    C:WindowsTEMPKB2736428_20130607_230332849.html
    C:WindowsTEMPKB2737019_10.0.30319
    C:WindowsTEMPKB2737019_20121116_065614155-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2737019_20121116_065614155.html
    C:WindowsTEMPKB2742595_10.0.30319
    C:WindowsTEMPKB2742595_20130109_233158500-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2742595_20130109_233158500.html
    C:WindowsTEMPKB2742595_20130606_232826466-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2742595_20130606_232826466-Microsoft .NET Framework 4 Extended-MSP1.txt
    C:WindowsTEMPKB2742595_20130606_232826466.html
    C:WindowsTEMPKB2789642_10.0.30319
    C:WindowsTEMPKB2789642_20130213_230332930-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2789642_20130213_230332930.html
    C:WindowsTEMPKB2804576_10.0.30319
    C:WindowsTEMPKB2804576_20130515_230253116-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2804576_20130515_230253116.html
    C:WindowsTEMPKB2835393_10.0.30319
    C:WindowsTEMPKB2835393_20130711_063358380-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2835393_20130711_063358380.html
    C:WindowsTEMPKB2836939v3_10.0.30319
    C:WindowsTEMPKB2836939v3_20131010_230524624-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2836939v3_20131010_230524624-Microsoft .NET Framework 4 Extended-MSP1.txt
    C:WindowsTEMPKB2836939v3_20131010_230524624.html
    C:WindowsTEMPKB2836939_10.0.30319
    C:WindowsTEMPKB2836939_20130713_230226052-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2836939_20130713_230226052-Microsoft .NET Framework 4 Extended-MSP1.txt
    C:WindowsTEMPKB2836939_20130713_230226052.html
    C:WindowsTEMPKB2840628v2_10.0.30319
    C:WindowsTEMPKB2840628v2_20130813_230527019-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2840628v2_20130813_230527019.html
    C:WindowsTEMPKB2840628_10.0.30319
    C:WindowsTEMPKB2840628_20130711_064123214-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2840628_20130711_064123214.html
    C:WindowsTEMPKB2858302v2_10.0.30319
    C:WindowsTEMPKB2858302v2_20131010_231750099-Microsoft .NET Framework 4 Client Profile-MSP0.txt
    C:WindowsTEMPKB2858302v2_20131010_231750099-Microsoft .NET Framework 4 Extended-MSP1.txt
    C:WindowsTEMPKB2858302v2_20131010_231750099.html
    C:WindowsTEMPlpksetup-20121028-235231-0.log
    C:WindowsTEMPlpksetup-20121029-064350-0.log
    C:WindowsTEMPlpksetup-20121029-122409-0.log
    C:WindowsTEMPlpksetup-20121029-210107-0.log
    C:WindowsTEMPlpksetup-20121029-223848-0.log
    C:WindowsTEMPlpksetup-20121030-060346-0.log
    C:WindowsTEMPlpksetup-20121030-193743-0.log
    C:WindowsTEMPlpksetup-20121031-080424-0.log
    C:WindowsTEMPlpksetup-20121101-103310-0.log
    C:WindowsTEMPlpksetup-20121102-064928-0.log
    C:WindowsTEMPlpksetup-20121102-205628-0.log
    C:WindowsTEMPlpksetup-20121103-064907-0.log
    C:WindowsTEMPlpksetup-20121103-201811-0.log
    C:WindowsTEMPlpksetup-20121104-063325-0.log
    C:WindowsTEMPlpksetup-20121104-202430-0.log
    C:WindowsTEMPlpksetup-20121105-093246-0.log
    C:WindowsTEMPlpksetup-20121106-124833-0.log
    C:WindowsTEMPlpksetup-20121107-063437-0.log
    C:WindowsTEMPlpksetup-20121107-210621-0.log
    C:WindowsTEMPlpksetup-20121108-054255-0.log
    C:WindowsTEMPlpksetup-20121108-194729-0.log
    C:WindowsTEMPlpksetup-20121109-090720-0.log
    C:WindowsTEMPlpksetup-20121110-102029-0.log
    C:WindowsTEMPlpksetup-20121111-070149-0.log
    C:WindowsTEMPlpksetup-20121111-201701-0.log
    C:WindowsTEMPlpksetup-20121112-092559-0.log
    C:WindowsTEMPlpksetup-20121113-060011-0.log
    C:WindowsTEMPlpksetup-20121113-194320-0.log
    C:WindowsTEMPlpksetup-20121114-080300-0.log
    C:WindowsTEMPlpksetup-20121114-205931-0.log
    C:WindowsTEMPlpksetup-20121115-105152-0.log
    C:WindowsTEMPlpksetup-20121115-192809-0.log
    C:WindowsTEMPlpksetup-20121116-060337-0.log
    C:WindowsTEMPlpksetup-20121116-195932-0.log
    C:WindowsTEMPlpksetup-20121117-103601-0.log
    C:WindowsTEMPlpksetup-20121118-201242-0.log
    C:WindowsTEMPlpksetup-20121121-055006-0.log
    C:WindowsTEMPlpksetup-20121121-194618-0.log
    C:WindowsTEMPlpksetup-20121122-054934-0.log
    C:WindowsTEMPlpksetup-20121122-194246-0.log
    C:WindowsTEMPlpksetup-20121123-161231-0.log
    C:WindowsTEMPlpksetup-20121124-122641-0.log
    C:WindowsTEMPlpksetup-20121124-182504-0.log
    C:WindowsTEMPlpksetup-20121125-104957-0.log
    C:WindowsTEMPlpksetup-20121126-070242-0.log
    C:WindowsTEMPlpksetup-20121126-212331-0.log
    C:WindowsTEMPlpksetup-20121127-194606-0.log
    C:WindowsTEMPlpksetup-20121128-172017-0.log
    C:WindowsTEMPlpksetup-20121129-190858-0.log
    C:WindowsTEMPlpksetup-20121130-060825-0.log
    C:WindowsTEMPlpksetup-20121130-192044-0.log
    C:WindowsTEMPlpksetup-20121201-064405-0.log
    C:WindowsTEMPlpksetup-20121201-201902-0.log
    C:WindowsTEMPlpksetup-20121202-063638-0.log
    C:WindowsTEMPlpksetup-20121202-203658-0.log
    C:WindowsTEMPlpksetup-20121203-110615-0.log
    C:WindowsTEMPlpksetup-20121204-121409-0.log
    C:WindowsTEMPlpksetup-20121204-173529-0.log
    C:WindowsTEMPlpksetup-20121205-060158-0.log
    C:WindowsTEMPlpksetup-20121205-194057-0.log
    C:WindowsTEMPlpksetup-20121206-064145-0.log
    C:WindowsTEMPlpksetup-20121206-212647-0.log
    C:WindowsTEMPlpksetup-20121207-182902-0.log
    C:WindowsTEMPlpksetup-20121208-101447-0.log
    C:WindowsTEMPlpksetup-20121208-174903-0.log
    C:WindowsTEMPlpksetup-20121209-113218-0.log
    C:WindowsTEMPlpksetup-20121209-170722-0.log
    C:WindowsTEMPlpksetup-20121210-193034-0.log
    C:WindowsTEMPlpksetup-20121211-053751-0.log
    C:WindowsTEMPlpksetup-20121211-205741-0.log
    C:WindowsTEMPlpksetup-20121212-171812-0.log
    C:WindowsTEMPlpksetup-20121213-151043-0.log

  • scorpio44
    Participant
    Post count: 9

    C:WindowsTEMPlpksetup-20121214-121425-0.log
    C:WindowsTEMPlpksetup-20121214-193340-0.log
    C:WindowsTEMPlpksetup-20121215-063444-0.log
    C:WindowsTEMPlpksetup-20121215-202100-0.log
    C:WindowsTEMPlpksetup-20121216-064318-0.log
    C:WindowsTEMPlpksetup-20121216-202306-0.log
    C:WindowsTEMPlpksetup-20121217-102542-0.log
    C:WindowsTEMPlpksetup-20121218-100253-0.log
    C:WindowsTEMPlpksetup-20121218-172043-0.log
    C:WindowsTEMPlpksetup-20121219-060309-0.log
    C:WindowsTEMPlpksetup-20121219-193656-0.log
    C:WindowsTEMPlpksetup-20121220-060556-0.log
    C:WindowsTEMPlpksetup-20121220-193842-0.log
    C:WindowsTEMPlpksetup-20121221-055653-0.log
    C:WindowsTEMPlpksetup-20121221-200311-0.log
    C:WindowsTEMPlpksetup-20121222-105721-0.log
    C:WindowsTEMPlpksetup-20121223-064715-0.log
    C:WindowsTEMPlpksetup-20121223-202520-0.log
    C:WindowsTEMPlpksetup-20121223-203654-0.log
    C:WindowsTEMPlpksetup-20121224-065630-0.log
    C:WindowsTEMPlpksetup-20121224-202447-0.log
    C:WindowsTEMPlpksetup-20121225-063557-0.log
    C:WindowsTEMPlpksetup-20121225-202556-0.log
    C:WindowsTEMPlpksetup-20121226-081029-0.log
    C:WindowsTEMPlpksetup-20121227-090623-0.log
    C:WindowsTEMPlpksetup-20121227-192425-0.log
    C:WindowsTEMPlpksetup-20121228-100702-0.log
    C:WindowsTEMPlpksetup-20121228-194502-0.log
    C:WindowsTEMPlpksetup-20121229-184826-0.log
    C:WindowsTEMPlpksetup-20121230-082414-0.log
    C:WindowsTEMPlpksetup-20121230-104056-0.log
    C:WindowsTEMPlpksetup-20121230-153622-0.log
    C:WindowsTEMPlpksetup-20121231-112425-0.log
    C:WindowsTEMPlpksetup-20121231-174623-0.log
    C:WindowsTEMPlpksetup-20130101-094129-0.log
    C:WindowsTEMPlpksetup-20130101-174834-0.log
    C:WindowsTEMPlpksetup-20130102-093024-0.log
    C:WindowsTEMPlpksetup-20130104-093043-0.log
    C:WindowsTEMPlpksetup-20130104-195556-0.log
    C:WindowsTEMPlpksetup-20130105-100425-0.log
    C:WindowsTEMPlpksetup-20130106-091450-0.log
    C:WindowsTEMPlpksetup-20130107-131637-0.log
    C:WindowsTEMPlpksetup-20130108-144223-0.log
    C:WindowsTEMPlpksetup-20130109-065326-0.log
    C:WindowsTEMPlpksetup-20130109-210641-0.log
    C:WindowsTEMPlpksetup-20130110-054933-0.log
    C:WindowsTEMPlpksetup-20130110-192558-0.log
    C:WindowsTEMPlpksetup-20130111-110309-0.log
    C:WindowsTEMPlpksetup-20130112-110227-0.log
    C:WindowsTEMPlpksetup-20130113-095056-0.log
    C:WindowsTEMPlpksetup-20130114-055607-0.log
    C:WindowsTEMPlpksetup-20130114-195102-0.log
    C:WindowsTEMPlpksetup-20130115-065809-0.log
    C:WindowsTEMPlpksetup-20130115-210147-0.log
    C:WindowsTEMPlpksetup-20130116-101200-0.log
    C:WindowsTEMPlpksetup-20130117-092901-0.log
    C:WindowsTEMPlpksetup-20130118-054701-0.log
    C:WindowsTEMPlpksetup-20130118-195444-0.log
    C:WindowsTEMPlpksetup-20130118-200217-0.log
    C:WindowsTEMPlpksetup-20130119-064303-0.log
    C:WindowsTEMPlpksetup-20130120-202136-0.log
    C:WindowsTEMPlpksetup-20130121-101245-0.log
    C:WindowsTEMPlpksetup-20130122-093546-0.log
    C:WindowsTEMPlpksetup-20130123-065557-0.log
    C:WindowsTEMPlpksetup-20130123-210429-0.log
    C:WindowsTEMPlpksetup-20130124-053602-0.log
    C:WindowsTEMPlpksetup-20130124-193135-0.log
    C:WindowsTEMPlpksetup-20130125-093420-0.log
    C:WindowsTEMPlpksetup-20130126-094315-0.log
    C:WindowsTEMPlpksetup-20130127-094048-0.log
    C:WindowsTEMPlpksetup-20130128-054709-0.log
    C:WindowsTEMPlpksetup-20130128-194324-0.log
    C:WindowsTEMPlpksetup-20130129-064811-0.log
    C:WindowsTEMPlpksetup-20130129-210730-0.log
    C:WindowsTEMPlpksetup-20130130-085519-0.log
    C:WindowsTEMPlpksetup-20130131-090802-0.log
    C:WindowsTEMPlpksetup-20130131-174038-0.log
    C:WindowsTEMPlpksetup-20130201-194309-0.log
    C:WindowsTEMPlpksetup-20130202-062827-0.log
    C:WindowsTEMPlpksetup-20130202-200431-0.log
    C:WindowsTEMPlpksetup-20130203-064742-0.log
    C:WindowsTEMPlpksetup-20130203-201238-0.log
    C:WindowsTEMPlpksetup-20130204-084531-0.log
    C:WindowsTEMPlpksetup-20130205-103802-0.log
    C:WindowsTEMPlpksetup-20130206-081424-0.log
    C:WindowsTEMPlpksetup-20130207-055853-0.log
    C:WindowsTEMPlpksetup-20130207-193510-0.log
    C:WindowsTEMPlpksetup-20130208-093849-0.log
    C:WindowsTEMPlpksetup-20130209-092802-0.log
    C:WindowsTEMPlpksetup-20130210-100532-0.log
    C:WindowsTEMPlpksetup-20130211-060421-0.log
    C:WindowsTEMPlpksetup-20130211-202703-0.log
    C:WindowsTEMPlpksetup-20130212-073122-0.log
    C:WindowsTEMPlpksetup-20130212-210224-0.log
    C:WindowsTEMPlpksetup-20130213-081616-0.log
    C:WindowsTEMPlpksetup-20130213-232737-0.log
    C:WindowsTEMPlpksetup-20130214-080839-0.log
    C:WindowsTEMPlpksetup-20130215-055007-0.log
    C:WindowsTEMPlpksetup-20130215-193324-0.log
    C:WindowsTEMPlpksetup-20130216-063906-0.log
    C:WindowsTEMPlpksetup-20130216-202240-0.log
    C:WindowsTEMPlpksetup-20130217-063900-0.log
    C:WindowsTEMPlpksetup-20130217-201322-0.log
    C:WindowsTEMPlpksetup-20130218-083130-0.log
    C:WindowsTEMPlpksetup-20130218-122420-0.log
    C:WindowsTEMPlpksetup-20130219-085854-0.log
    C:WindowsTEMPlpksetup-20130219-092016-0.log
    C:WindowsTEMPlpksetup-20130220-054619-0.log
    C:WindowsTEMPlpksetup-20130220-193114-0.log
    C:WindowsTEMPlpksetup-20130221-062751-0.log
    C:WindowsTEMPlpksetup-20130221-205902-0.log
    C:WindowsTEMPlpksetup-20130222-085715-0.log
    C:WindowsTEMPlpksetup-20130223-082825-0.log
    C:WindowsTEMPlpksetup-20130223-183313-0.log
    C:WindowsTEMPlpksetup-20130224-092828-0.log
    C:WindowsTEMPlpksetup-20130225-063435-0.log
    C:WindowsTEMPlpksetup-20130225-205608-0.log
    C:WindowsTEMPlpksetup-20130226-054646-0.log
    C:WindowsTEMPlpksetup-20130226-200114-0.log
    C:WindowsTEMPlpksetup-20130227-080146-0.log
    C:WindowsTEMPlpksetup-20130227-232108-0.log
    C:WindowsTEMPlpksetup-20130228-082339-0.log
    C:WindowsTEMPlpksetup-20130301-061718-0.log
    C:WindowsTEMPlpksetup-20130301-210320-0.log
    C:WindowsTEMPlpksetup-20130302-064619-0.log
    C:WindowsTEMPlpksetup-20130302-202110-0.log
    C:WindowsTEMPlpksetup-20130303-064633-0.log
    C:WindowsTEMPlpksetup-20130303-203409-0.log
    C:WindowsTEMPlpksetup-20130304-111122-0.log
    C:WindowsTEMPlpksetup-20130304-170809-0.log
    C:WindowsTEMPlpksetup-20130305-082129-0.log
    C:WindowsTEMPlpksetup-20130306-064648-0.log
    C:WindowsTEMPlpksetup-20130306-210244-0.log
    C:WindowsTEMPlpksetup-20130307-054822-0.log
    C:WindowsTEMPlpksetup-20130307-195509-0.log
    C:WindowsTEMPlpksetup-20130308-081504-0.log
    C:WindowsTEMPlpksetup-20130309-081258-0.log
    C:WindowsTEMPlpksetup-20130310-101220-0.log
    C:WindowsTEMPlpksetup-20130311-054655-0.log
    C:WindowsTEMPlpksetup-20130311-193033-0.log
    C:WindowsTEMPlpksetup-20130312-062942-0.log
    C:WindowsTEMPlpksetup-20130312-211630-0.log
    C:WindowsTEMPlpksetup-20130313-080412-0.log
    C:WindowsTEMPlpksetup-20130314-080804-0.log
    C:WindowsTEMPlpksetup-20130315-055930-0.log
    C:WindowsTEMPlpksetup-20130315-194244-0.log
    C:WindowsTEMPlpksetup-20130316-064842-0.log
    C:WindowsTEMPlpksetup-20130316-202340-0.log
    C:WindowsTEMPlpksetup-20130317-063542-0.log
    C:WindowsTEMPlpksetup-20130317-202051-0.log
    C:WindowsTEMPlpksetup-20130318-112139-0.log
    C:WindowsTEMPlpksetup-20130321-224950-0.log
    C:WindowsTEMPlpksetup-20130322-085049-0.log
    C:WindowsTEMPlpksetup-20130322-085525-0.log
    C:WindowsTEMPlpksetup-20130322-194412-0.log
    C:WindowsTEMPlpksetup-20130323-092549-0.log
    C:WindowsTEMPlpksetup-20130323-194542-0.log
    C:WindowsTEMPlpksetup-20130324-094128-0.log
    C:WindowsTEMPlpksetup-20130324-101637-0.log
    C:WindowsTEMPlpksetup-20130324-102613-0.log
    C:WindowsTEMPlpksetup-20130324-211051-0.log
    C:WindowsTEMPlpksetup-20130325-065612-0.log
    C:WindowsTEMPlpksetup-20130325-122227-0.log
    C:WindowsTEMPlpksetup-20130325-162142-0.log
    C:WindowsTEMPlpksetup-20130325-232254-0.log
    C:WindowsTEMPlpksetup-20130326-081209-0.log
    C:WindowsTEMPlpksetup-20130326-144522-0.log
    C:WindowsTEMPlpksetup-20130326-144623-0.log
    C:WindowsTEMPlpksetup-20130327-075354-0.log
    C:WindowsTEMPlpksetup-20130327-184830-0.log
    C:WindowsTEMPlpksetup-20130328-202714-0.log
    C:WindowsTEMPlpksetup-20130329-080611-0.log
    C:WindowsTEMPlpksetup-20130330-082446-0.log
    C:WindowsTEMPlpksetup-20130402-201651-0.log
    C:WindowsTEMPlpksetup-20130403-232944-0.log
    C:WindowsTEMPlpksetup-20130410-134055-0.log
    C:WindowsTEMPlpksetup-20130410-232541-0.log
    C:WindowsTEMPlpksetup-20130411-083748-0.log
    C:WindowsTEMPlpksetup-20130414-064844-0.log
    C:WindowsTEMPlpksetup-20130415-101934-0.log
    C:WindowsTEMPlpksetup-20130416-083233-0.log
    C:WindowsTEMPlpksetup-20130417-090438-0.log
    C:WindowsTEMPlpksetup-20130418-074635-0.log
    C:WindowsTEMPlpksetup-20130418-180149-0.log
    C:WindowsTEMPlpksetup-20130419-081004-0.log
    C:WindowsTEMPlpksetup-20130421-203505-0.log
    C:WindowsTEMPlpksetup-20130422-130550-0.log
    C:WindowsTEMPlpksetup-20130422-163454-0.log
    C:WindowsTEMPlpksetup-20130422-200750-0.log
    C:WindowsTEMPlpksetup-20130423-085839-0.log
    C:WindowsTEMPlpksetup-20130423-200447-0.log
    C:WindowsTEMPlpksetup-20130424-090126-0.log
    C:WindowsTEMPlpksetup-20130424-185129-0.log
    C:WindowsTEMPlpksetup-20130425-074025-0.log
    C:WindowsTEMPlpksetup-20130425-083521-0.log
    C:WindowsTEMPlpksetup-20130425-133334-0.log
    C:WindowsTEMPlpksetup-20130425-180136-0.log
    C:WindowsTEMPlpksetup-20130426-080504-0.log
    C:WindowsTEMPlpksetup-20130426-102851-0.log
    C:WindowsTEMPlpksetup-20130426-163852-0.log
    C:WindowsTEMPlpksetup-20130427-090531-0.log
    C:WindowsTEMPlpksetup-20130427-195114-0.log
    C:WindowsTEMPlpksetup-20130428-104129-0.log
    C:WindowsTEMPlpksetup-20130428-120948-0.log
    C:WindowsTEMPlpksetup-20130428-154308-0.log
    C:WindowsTEMPlpksetup-20130428-154541-0.log
    C:WindowsTEMPlpksetup-20130428-183900-0.log
    C:WindowsTEMPlpksetup-20130428-184420-0.log
    C:WindowsTEMPlpksetup-20130428-185706-0.log
    C:WindowsTEMPlpksetup-20130428-191816-0.log
    C:WindowsTEMPlpksetup-20130429-074240-0.log
    C:WindowsTEMPlpksetup-20130429-084837-0.log
    C:WindowsTEMPlpksetup-20130429-201754-0.log
    C:WindowsTEMPlpksetup-20130430-054819-0.log
    C:WindowsTEMPlpksetup-20130430-200830-0.log
    C:WindowsTEMPlpksetup-20130501-065839-0.log
    C:WindowsTEMPlpksetup-20130501-203341-0.log
    C:WindowsTEMPlpksetup-20130502-060407-0.log
    C:WindowsTEMPlpksetup-20130503-074149-0.log
    C:WindowsTEMPlpksetup-20130504-072058-0.log
    C:WindowsTEMPlpksetup-20130505-103839-0.log
    C:WindowsTEMPlpksetup-20130506-070803-0.log
    C:WindowsTEMPlpksetup-20130507-054940-0.log
    C:WindowsTEMPlpksetup-20130508-084341-0.log
    C:WindowsTEMPlpksetup-20130509-092616-0.log
    C:WindowsTEMPlpksetup-20130511-091706-0.log
    C:WindowsTEMPlpksetup-20130512-091916-0.log
    C:WindowsTEMPlpksetup-20130513-082351-0.log
    C:WindowsTEMPlpksetup-20130513-140514-0.log
    C:WindowsTEMPlpksetup-20130514-094445-0.log
    C:WindowsTEMPlpksetup-20130515-084743-0.log
    C:WindowsTEMPlpksetup-20130515-232841-0.log
    C:WindowsTEMPlpksetup-20130516-074134-0.log
    C:WindowsTEMPlpksetup-20130516-120257-0.log
    C:WindowsTEMPlpksetup-20130517-083931-0.log
    C:WindowsTEMPlpksetup-20130518-075252-0.log
    C:WindowsTEMPlpksetup-20130518-082234-0.log
    C:WindowsTEMPlpksetup-20130519-102009-0.log
    C:WindowsTEMPlpksetup-20130519-102619-0.log
    C:WindowsTEMPlpksetup-20130520-075518-0.log
    C:WindowsTEMPlpksetup-20130521-092448-0.log
    C:WindowsTEMPlpksetup-20130521-184406-0.log
    C:WindowsTEMPlpksetup-20130522-091353-0.log
    C:WindowsTEMPlpksetup-20130522-193436-0.log
    C:WindowsTEMPlpksetup-20130523-085714-0.log
    C:WindowsTEMPlpksetup-20130523-125405-0.log
    C:WindowsTEMPlpksetup-20130523-190144-0.log
    C:WindowsTEMPlpksetup-20130523-213855-0.log
    C:WindowsTEMPlpksetup-20130524-085829-0.log
    C:WindowsTEMPlpksetup-20130524-195530-0.log
    C:WindowsTEMPlpksetup-20130524-233810-0.log
    C:WindowsTEMPlpksetup-20130525-092655-0.log
    C:WindowsTEMPlpksetup-20130525-191040-0.log
    C:WindowsTEMPlpksetup-20130526-084853-0.log
    C:WindowsTEMPlpksetup-20130527-084402-0.log
    C:WindowsTEMPlpksetup-20130527-215805-0.log
    C:WindowsTEMPlpksetup-20130528-085655-0.log
    C:WindowsTEMPlpksetup-20130528-154340-0.log
    C:WindowsTEMPlpksetup-20130528-191706-0.log
    C:WindowsTEMPlpksetup-20130529-083615-0.log
    C:WindowsTEMPlpksetup-20130530-153001-0.log
    C:WindowsTEMPlpksetup-20130531-095555-0.log
    C:WindowsTEMPlpksetup-20130601-084844-0.log
    C:WindowsTEMPlpksetup-20130602-015609-0.log
    C:WindowsTEMPlpksetup-20130602-094432-0.log
    C:WindowsTEMPlpksetup-20130603-062829-0.log
    C:WindowsTEMPlpksetup-20130603-212854-0.log
    C:WindowsTEMPlpksetup-20130604-061358-0.log
    C:WindowsTEMPlpksetup-20130604-192243-0.log
    C:WindowsTEMPlpksetup-20130605-070541-0.log
    C:WindowsTEMPlpksetup-20130606-111039-0.log
    C:WindowsTEMPlpksetup-20130607-054920-0.log
    C:WindowsTEMPlpksetup-20130608-065853-0.log
    C:WindowsTEMPlpksetup-20130608-203922-0.log
    C:WindowsTEMPlpksetup-20130609-065159-0.log
    C:WindowsTEMPlpksetup-20130610-115623-0.log
    C:WindowsTEMPlpksetup-20130611-165734-0.log
    C:WindowsTEMPlpksetup-20130612-064619-0.log
    C:WindowsTEMPlpksetup-20130612-211002-0.log
    C:WindowsTEMPlpksetup-20130612-232809-0.log
    C:WindowsTEMPlpksetup-20130613-054858-0.log
    C:WindowsTEMPlpksetup-20130613-194620-0.log
    C:WindowsTEMPlpksetup-20130614-101411-0.log
    C:WindowsTEMPlpksetup-20130615-090111-0.log
    C:WindowsTEMPlpksetup-20130615-194736-0.log
    C:WindowsTEMPlpksetup-20130616-115022-0.log
    C:WindowsTEMPlpksetup-20130617-063726-0.log
    C:WindowsTEMPlpksetup-20130618-053710-0.log
    C:WindowsTEMPlpksetup-20130618-145217-0.log
    C:WindowsTEMPlpksetup-20130618-170821-0.log
    C:WindowsTEMPlpksetup-20130619-200922-0.log
    C:WindowsTEMPlpksetup-20130620-123508-0.log
    C:WindowsTEMPlpksetup-20130621-060655-0.log
    C:WindowsTEMPlpksetup-20130621-200108-0.log
    C:WindowsTEMPlpksetup-20130622-064614-0.log
    C:WindowsTEMPlpksetup-20130622-202727-0.log
    C:WindowsTEMPlpksetup-20130623-061054-0.log
    C:WindowsTEMPlpksetup-20130623-203501-0.log
    C:WindowsTEMPlpksetup-20130624-101607-0.log
    C:WindowsTEMPlpksetup-20130625-071816-0.log
    C:WindowsTEMPlpksetup-20130626-053958-0.log
    C:WindowsTEMPlpksetup-20130626-193143-0.log
    C:WindowsTEMPlpksetup-20130627-064437-0.log
    C:WindowsTEMPlpksetup-20130627-211046-0.log
    C:WindowsTEMPlpksetup-20130628-055908-0.log
    C:WindowsTEMPlpksetup-20130628-195811-0.log
    C:WindowsTEMPlpksetup-20130629-112511-0.log
    C:WindowsTEMPlpksetup-20130630-131249-0.log
    C:WindowsTEMPlpksetup-20130701-063130-0.log
    C:WindowsTEMPlpksetup-20130701-210015-0.log
    C:WindowsTEMPlpksetup-20130702-054900-0.log
    C:WindowsTEMPlpksetup-20130702-195350-0.log
    C:WindowsTEMPlpksetup-20130704-115327-0.log
    C:WindowsTEMPlpksetup-20130705-053105-0.log
    C:WindowsTEMPlpksetup-20130705-192544-0.log
    C:WindowsTEMPlpksetup-20130706-071341-0.log
    C:WindowsTEMPlpksetup-20130707-063544-0.log
    C:WindowsTEMPlpksetup-20130707-202802-0.log
    C:WindowsTEMPlpksetup-20130708-115119-0.log
    C:WindowsTEMPlpksetup-20130709-084234-0.log
    C:WindowsTEMPlpksetup-20130710-104355-0.log
    C:WindowsTEMPlpksetup-20130711-053743-0.log
    C:WindowsTEMPlpksetup-20130711-195140-0.log
    C:WindowsTEMPlpksetup-20130712-101226-0.log
    C:WindowsTEMPlpksetup-20130712-172253-0.log
    C:WindowsTEMPlpksetup-20130712-192238-0.log
    C:WindowsTEMPlpksetup-20130713-091335-0.log
    C:WindowsTEMPlpksetup-20130713-140428-0.log
    C:WindowsTEMPlpksetup-20130714-084043-0.log
    C:WindowsTEMPlpksetup-20130714-092251-0.log
    C:WindowsTEMPlpksetup-20130715-054701-0.log
    C:WindowsTEMPlpksetup-20130715-193207-0.log
    C:WindowsTEMPlpksetup-20130716-064753-0.log
    C:WindowsTEMPlpksetup-20130716-211651-0.log
    C:WindowsTEMPlpksetup-20130717-084041-0.log
    C:WindowsTEMPlpksetup-20130718-090024-0.log
    C:WindowsTEMPlpksetup-20130719-055909-0.log
    C:WindowsTEMPlpksetup-20130719-194819-0.log
    C:WindowsTEMPlpksetup-20130720-064645-0.log
    C:WindowsTEMPlpksetup-20130720-202447-0.log
    C:WindowsTEMPlpksetup-20130721-064746-0.log
    C:WindowsTEMPlpksetup-20130721-203918-0.log
    C:WindowsTEMPlpksetup-20130722-090534-0.log
    C:WindowsTEMPlpksetup-20130723-100400-0.log
    C:WindowsTEMPlpksetup-20130724-060511-0.log
    C:WindowsTEMPlpksetup-20130724-194407-0.log
    C:WindowsTEMPlpksetup-20130725-064520-0.log
    C:WindowsTEMPlpksetup-20130725-210500-0.log
    C:WindowsTEMPlpksetup-20130726-083427-0.log
    C:WindowsTEMPlpksetup-20130727-071227-0.log
    C:WindowsTEMPlpksetup-20130728-093253-0.log
    C:WindowsTEMPlpksetup-20130729-064813-0.log
    C:WindowsTEMPlpksetup-20130729-212834-0.log
    C:WindowsTEMPlpksetup-20130730-054856-0.log
    C:WindowsTEMPlpksetup-20130730-193648-0.log
    C:WindowsTEMPlpksetup-20130731-110719-0.log
    C:WindowsTEMPlpksetup-20130731-190820-0.log
    C:WindowsTEMPlpksetup-20130801-094002-0.log
    C:WindowsTEMPlpksetup-20130801-191756-0.log
    C:WindowsTEMPlpksetup-20130802-064551-0.log
    C:WindowsTEMPlpksetup-20130802-210510-0.log
    C:WindowsTEMPlpksetup-20130803-065825-0.log
    C:WindowsTEMPlpksetup-20130803-203114-0.log
    C:WindowsTEMPlpksetup-20130804-065559-0.log
    C:WindowsTEMPlpksetup-20130804-203812-0.log
    C:WindowsTEMPlpksetup-20130805-094945-0.log
    C:WindowsTEMPlpksetup-20130806-084839-0.log
    C:WindowsTEMPlpksetup-20130806-120605-0.log
    C:WindowsTEMPlpksetup-20130806-223128-0.log
    C:WindowsTEMPlpksetup-20130807-064709-0.log
    C:WindowsTEMPlpksetup-20130807-211736-0.log
    C:WindowsTEMPlpksetup-20130808-060033-0.log
    C:WindowsTEMPlpksetup-20130808-193304-0.log
    C:WindowsTEMPlpksetup-20130809-123105-0.log
    C:WindowsTEMPlpksetup-20130809-185702-0.log
    C:WindowsTEMPlpksetup-20130809-225644-0.log
    C:WindowsTEMPlpksetup-20130810-082939-0.log
    C:WindowsTEMPlpksetup-20130810-192520-0.log
    C:WindowsTEMPlpksetup-20130811-134239-0.log
    C:WindowsTEMPlpksetup-20130812-055226-0.log
    C:WindowsTEMPlpksetup-20130812-195824-0.log
    C:WindowsTEMPlpksetup-20130813-065415-0.log
    C:WindowsTEMPlpksetup-20130813-210548-0.log
    C:WindowsTEMPlpksetup-20130813-233247-0.log
    C:WindowsTEMPlpksetup-20130814-093114-0.log
    C:WindowsTEMPlpksetup-20130815-094404-0.log
    C:WindowsTEMPlpksetup-20130817-090205-0.log
    C:WindowsTEMPlpksetup-20130817-135843-0.log
    C:WindowsTEMPlpksetup-20130817-184012-0.log
    C:WindowsTEMPlpksetup-20130818-193646-0.log
    C:WindowsTEMPlpksetup-20130820-172421-0.log
    C:WindowsTEMPlpksetup-20130820-172701-0.log
    C:WindowsTEMPlpksetup-20130821-055610-0.log
    C:WindowsTEMPlpksetup-20130821-194922-0.log
    C:WindowsTEMPlpksetup-20130822-064817-0.log
    C:WindowsTEMPlpksetup-20130822-210553-0.log
    C:WindowsTEMPlpksetup-20130823-091614-0.log
    C:WindowsTEMPlpksetup-20130824-121122-0.log
    C:WindowsTEMPlpksetup-20130825-095158-0.log
    C:WindowsTEMPlpksetup-20130826-060004-0.log
    C:WindowsTEMPlpksetup-20130826-193643-0.log
    C:WindowsTEMPlpksetup-20130827-065440-0.log
    C:WindowsTEMPlpksetup-20130827-205841-0.log
    C:WindowsTEMPlpksetup-20130828-115403-0.log
    C:WindowsTEMPlpksetup-20130829-104414-0.log
    C:WindowsTEMPlpksetup-20130829-115121-0.log
    C:WindowsTEMPlpksetup-20130829-190721-0.log
    C:WindowsTEMPlpksetup-20130830-055613-0.log
    C:WindowsTEMPlpksetup-20130830-193954-0.log
    C:WindowsTEMPlpksetup-20130831-065446-0.log
    C:WindowsTEMPlpksetup-20130831-202811-0.log
    C:WindowsTEMPlpksetup-20130901-065736-0.log
    C:WindowsTEMPlpksetup-20130901-203403-0.log
    C:WindowsTEMPlpksetup-20130902-102515-0.log
    C:WindowsTEMPlpksetup-20130903-094148-0.log
    C:WindowsTEMPlpksetup-20130904-064811-0.log
    C:WindowsTEMPlpksetup-20130904-211436-0.log
    C:WindowsTEMPlpksetup-20130905-055408-0.log
    C:WindowsTEMPlpksetup-20130905-192908-0.log
    C:WindowsTEMPlpksetup-20130905-200238-0.log
    C:WindowsTEMPlpksetup-20130905-200740-0.log
    C:WindowsTEMPlpksetup-20130906-083828-0.log
    C:WindowsTEMPlpksetup-20130907-193105-0.log
    C:WindowsTEMPlpksetup-20130908-040554-0.log
    C:WindowsTEMPlpksetup-20130908-115702-0.log
    C:WindowsTEMPlpksetup-20130909-065803-0.log
    C:WindowsTEMPlpksetup-20130909-210318-0.log
    C:WindowsTEMPlpksetup-20130910-055425-0.log
    C:WindowsTEMPlpksetup-20130910-192652-0.log
    C:WindowsTEMPlpksetup-20130911-054831-0.log
    C:WindowsTEMPlpksetup-20130911-190838-0.log
    C:WindowsTEMPlpksetup-20130911-191114-0.log
    C:WindowsTEMPlpksetup-20130912-132809-0.log
    C:WindowsTEMPlpksetup-20130913-130618-0.log
    C:WindowsTEMPlpksetup-20130914-085206-0.log
    C:WindowsTEMPlpksetup-20130914-192407-0.log
    C:WindowsTEMPlpksetup-20130915-103727-0.log
    C:WindowsTEMPlpksetup-20130915-194415-0.log
    C:WindowsTEMPlpksetup-20130916-093656-0.log
    C:WindowsTEMPlpksetup-20130916-130720-0.log
    C:WindowsTEMPlpksetup-20130916-201802-0.log
    C:WindowsTEMPlpksetup-20130917-100152-0.log
    C:WindowsTEMPlpksetup-20130917-193659-0.log
    C:WindowsTEMPlpksetup-20130918-085113-0.log
    C:WindowsTEMPlpksetup-20130918-193141-0.log
    C:WindowsTEMPlpksetup-20130919-083829-0.log
    C:WindowsTEMPlpksetup-20130919-111415-0.log
    C:WindowsTEMPlpksetup-20130919-185815-0.log
    C:WindowsTEMPlpksetup-20130920-090938-0.log
    C:WindowsTEMPlpksetup-20130920-202609-0.log
    C:WindowsTEMPlpksetup-20130921-091008-0.log
    C:WindowsTEMPlpksetup-20130921-131444-0.log
    C:WindowsTEMPlpksetup-20130921-195356-0.log
    C:WindowsTEMPlpksetup-20130922-183501-0.log
    C:WindowsTEMPlpksetup-20130923-090817-0.log
    C:WindowsTEMPlpksetup-20130923-204121-0.log
    C:WindowsTEMPlpksetup-20130924-085339-0.log
    C:WindowsTEMPlpksetup-20130924-150943-0.log
    C:WindowsTEMPlpksetup-20130924-194315-0.log
    C:WindowsTEMPlpksetup-20130925-092659-0.log
    C:WindowsTEMPlpksetup-20130925-195300-0.log
    C:WindowsTEMPlpksetup-20130926-084545-0.log
    C:WindowsTEMPlpksetup-20130926-114807-0.log
    C:WindowsTEMPlpksetup-20130926-193341-0.log
    C:WindowsTEMPlpksetup-20130927-093439-0.log
    C:WindowsTEMPlpksetup-20130927-185953-0.log
    C:WindowsTEMPlpksetup-20130928-114852-0.log
    C:WindowsTEMPlpksetup-20130928-183611-0.log
    C:WindowsTEMPlpksetup-20130929-135437-0.log
    C:WindowsTEMPlpksetup-20130930-074112-0.log
    C:WindowsTEMPlpksetup-20130930-173754-0.log
    C:WindowsTEMPlpksetup-20131001-132906-0.log
    C:WindowsTEMPlpksetup-20131002-170822-0.log
    C:WindowsTEMPlpksetup-20131003-065530-0.log
    C:WindowsTEMPlpksetup-20131003-210714-0.log
    C:WindowsTEMPlpksetup-20131004-095621-0.log
    C:WindowsTEMPlpksetup-20131005-120211-0.log
    C:WindowsTEMPlpksetup-20131006-114514-0.log
    C:WindowsTEMPlpksetup-20131006-121330-0.log
    C:WindowsTEMPlpksetup-20131006-211625-0.log
    C:WindowsTEMPlpksetup-20131007-064702-0.log
    C:WindowsTEMPlpksetup-20131007-205534-0.log
    C:WindowsTEMPlpksetup-20131008-060254-0.log
    C:WindowsTEMPlpksetup-20131008-200234-0.log
    C:WindowsTEMPlpksetup-20131009-103851-0.log
    C:WindowsTEMPlpksetup-20131010-092348-0.log
    C:WindowsTEMPlpksetup-20131010-233747-0.log
    C:WindowsTEMPlpksetup-20131011-063230-0.log
    C:WindowsTEMPlpksetup-20131011-205736-0.log
    C:WindowsTEMPlpksetup-20131012-064230-0.log
    C:WindowsTEMPlpksetup-20131012-203356-0.log
    C:WindowsTEMPlpksetup-20131013-064255-0.log
    C:WindowsTEMPlpksetup-20131013-202116-0.log
    C:WindowsTEMPlpksetup-20131013-220927-0.log
    C:WindowsTEMPlpksetup-20131014-095651-0.log
    C:WindowsTEMPlpksetup-20131014-211109-0.log
    C:WindowsTEMPlpksetup-20131015-111152-0.log
    C:WindowsTEMPlpksetup-20131016-055932-0.log
    C:WindowsTEMPlpksetup-20131016-145649-0.log
    C:WindowsTEMPlpksetup-20131017-064748-0.log
    C:WindowsTEMPlpksetup-20131017-070005-0.log
    C:WindowsTEMPlpksetup-20131017-211451-0.log
    C:WindowsTEMPlpksetup-20131018-092801-0.log
    C:WindowsTEMPlpksetup-20131018-204210-0.log
    C:WindowsTEMPlpksetup-20131019-095352-0.log
    C:WindowsTEMPlpksetup-20131020-093424-0.log
    C:WindowsTEMPlpksetup-20131021-065302-0.log
    C:WindowsTEMPlpksetup-20131021-210837-0.log
    C:WindowsTEMPlpksetup-20131022-054702-0.log
    C:WindowsTEMPlpksetup-20131022-195210-0.log
    C:WindowsTEMPlpksetup-20131023-094548-0.log
    C:WindowsTEMPlpksetup-20131024-095754-0.log
    C:WindowsTEMPlpksetup-20131024-180331-0.log
    C:WindowsTEMPlpksetup-20131024-185829-0.log
    C:WindowsTEMPlpksetup-20131025-063151-0.log
    C:WindowsTEMPlpksetup-20131025-210810-0.log
    C:WindowsTEMPlpksetup-20131026-070457-0.log
    C:WindowsTEMPlpksetup-20131026-201411-0.log
    C:WindowsTEMPlpksetup-20131027-064658-0.log
    C:WindowsTEMPlpksetup-20131027-202652-0.log
    C:WindowsTEMPlpksetup-20131028-095247-0.log
    C:WindowsTEMPlpksetup-20131028-173155-0.log
    C:WindowsTEMPlpksetup-20131028-200811-0.log
    C:WindowsTEMPlpksetup-20131028-201421-0.log
    C:WindowsTEMPlpksetup-20131028-201904-0.log
    C:WindowsTEMPlpksetup-20131028-205305-0.log
    C:WindowsTEMPlpksetup-20131028-225041-0.log
    C:WindowsTEMPlpksetup-20131029-093828-0.log
    C:WindowsTEMPlpksetup-20131029-100805-0.log
    C:WindowsTEMPmavcperf-setup.log
    C:WindowsTEMPMicrosoft .NET Framework 4 Client Profile Setup_20121027_094516147-MSI_netfx_Core_x64.msi.txt
    C:WindowsTEMPMicrosoft .NET Framework 4 Client Profile Setup_20121027_094516147.html
    C:WindowsTEMPMicrosoft .NET Framework 4 Client Profile Setup_4.0.30319
    C:WindowsTEMPMicrosoft .NET Framework Client Profile Language Pack Setup_20121027_094956123-MSI_netfx_CoreLP_x64.msi.txt
    C:WindowsTEMPMicrosoft .NET Framework Client Profile Language Pack Setup_20121027_094956123.html
    C:WindowsTEMPMicrosoft .NET Framework Client Profile Language Pack Setup_4.0.30319
    C:WindowsTEMPMicrosoft Visual C++ 2010 x64 Redistributable Setup_10.0.30319
    C:WindowsTEMPMicrosoft Visual C++ 2010 x64 Redistributable Setup_20121026_100523591-Microsoft Visual C++ 2010 x64 Redistributable – 10.0.30319-MSP0.txt
    C:WindowsTEMPMicrosoft Visual C++ 2010 x64 Redistributable Setup_20121026_100523591-MSI_vc_red.msi.txt
    C:WindowsTEMPMicrosoft Visual C++ 2010 x64 Redistributable Setup_20121026_100523591.html
    C:WindowsTEMPMicrosoft Visual C++ 2010 x86 Redistributable Setup_10.0.30319
    C:WindowsTEMPMicrosoft Visual C++ 2010 x86 Redistributable Setup_20121026_100531956-Microsoft Visual C++ 2010 x86 Redistributable – 10.0.30319-MSP0.txt
    C:WindowsTEMPMicrosoft Visual C++ 2010 x86 Redistributable Setup_20121026_100531956-MSI_vc_red.msi.txt
    C:WindowsTEMPMicrosoft Visual C++ 2010 x86 Redistributable Setup_20121026_100531956.html
    C:WindowsTEMPMicrosoft Visual C++ 2010 x86 Redistributable Setup_20130719_060429837-MSI_vc_red.msi.txt
    C:WindowsTEMPMicrosoft Visual C++ 2010 x86 Redistributable Setup_20130719_060429837.html
    C:WindowsTEMPMpCmdRun.log
    C:WindowsTEMPMPInstrumentation
    C:WindowsTEMPMpSigStub.log
    C:WindowsTEMPMPTelemetrySubmit
    C:WindowsTEMPnss974.tmp
    C:WindowsTEMPnsxE74.tmp
    C:WindowsTEMPNVIDIA
    C:WindowsTEMPpatch.js
    C:WindowsTEMPRGI13B3.tmp
    C:WindowsTEMPRGI13B3.tmp-tmp
    C:WindowsTEMPRGI4AD9.tmp
    C:WindowsTEMPRGI4AD9.tmp-tmp
    C:WindowsTEMPRGI884F.tmp
    C:WindowsTEMPRGI884F.tmp-tmp
    C:WindowsTEMPRGI934.tmp
    C:WindowsTEMPRGI934.tmp-tmp
    C:WindowsTEMPRGI9C1E.tmp
    C:WindowsTEMPRGI9C1E.tmp-tmp
    C:WindowsTEMPRGIA39D.tmp
    C:WindowsTEMPRGIA39D.tmp-tmp
    C:WindowsTEMPRGIA968.tmp
    C:WindowsTEMPRGIA968.tmp-tmp
    C:WindowsTEMPRGIC31A.tmp
    C:WindowsTEMPRGIC31A.tmp-tmp
    C:WindowsTEMPRGIF7E3.tmp
    C:WindowsTEMPRGIF7E3.tmp-tmp
    C:WindowsTEMPRGIFC56.tmp
    C:WindowsTEMPRGIFC56.tmp-tmp
    C:WindowsTEMPSilverlight0.log
    C:WindowsTEMPSilverlightMSI.log
    C:WindowsTEMPSYMEVENT.LOG
    C:WindowsTEMPTMP00000006BD712EDEA2D0768A
    C:WindowsTEMPTMP000000099363D50AA9ADE98C
    C:WindowsTEMPTMP0000000E9FC09AB9881FD8CE
    C:WindowsTEMPTMP00000030B752A88BDB83F55A
    C:WindowsTEMPTMP0000005481EFB192F395826F
    C:WindowsTEMPTMP000010DE1ECC20F29835584E
    C:WindowsTEMPTS_C909.tmp
    C:WindowsTEMPTS_CE67.tmp
    C:WindowsTEMPTS_CFA0.tmp
    C:WindowsTEMPTS_D896.tmp
    C:WindowsTEMPTS_D9B0.tmp
    C:WindowsTEMPTS_DA9B.tmp
    C:WindowsTEMPTS_F171.tmp
    C:WindowsTEMPTS_F23D.tmp
    C:WindowsTEMPTS_FAF1.tmp
    C:WindowsTEMPUDDE64.tmp
    C:WindowsTEMPwificonfig
    C:WindowsTEMP{32ACC2FF-7802-490E-9CB5-55942375BAA5}
    C:WindowsTEMP{32ACC2FF-7802-490E-9CB5-55942375BAA5}fpi.tmp
    C:WindowsTEMPIEBF7A.tmpWindows6.1-KB2729094-v2-x64.cab
    C:WindowsTEMPIEBA8B.tmpWindows6.1-KB2670838-x64.cab
    C:WindowsTEMPIEA19E.tmpWindows6.1-KB2533623-x64.cab
    C:WindowsTEMPCR_BB2A0.tmpSETUP_PATCH.PACKED.7Z
    C:WindowsTEMPavast_ashMozilla Firefox
    C:WindowsTEMPavast_ashMozilla Firefoxupdate.xml
    C:WindowsTEMPACLMACLMLog.txt
    C:WindowsTEMPACLMCPSSMasterCatalog.ini
    C:WindowsPrefetchAD-AWAREADMIN.EXE-BD669D86.pf
    C:WindowsPrefetchAgAppLaunch.db
    C:WindowsPrefetchAgCx_S2_S-1-5-21-3690416426-1796864196-2923006020-1001.snp.db
    C:WindowsPrefetchAgCx_SC1.db
    C:WindowsPrefetchAgCx_SC1.db.trx
    C:WindowsPrefetchAgCx_SC2.db
    C:WindowsPrefetchAgCx_SC3_B08931B31546BA10.db
    C:WindowsPrefetchAgCx_SC4.db
    C:WindowsPrefetchAgGlFaultHistory.db
    C:WindowsPrefetchAgGlFgAppHistory.db
    C:WindowsPrefetchAgGlGlobalHistory.db
    C:WindowsPrefetchAgGlUAD_P_S-1-5-21-3690416426-1796864196-2923006020-1001.db
    C:WindowsPrefetchAgGlUAD_S-1-5-21-3690416426-1796864196-2923006020-1001.db
    C:WindowsPrefetchAgRobust.db
    C:WindowsPrefetchAM_DELTA_PATCH_1.161.244.0.EX-72BC3E9A.pf
    C:WindowsPrefetchAM_DELTA_PATCH_1.161.299.0.EX-28F226C4.pf
    C:WindowsPrefetchAM_DELTA_PATCH_1.161.365.0.EX-786EBB8E.pf
    C:WindowsPrefetchAM_DELTA_PATCH_1.161.524.0.EX-4BAE746F.pf
    C:WindowsPrefetchASSISTANCELIVEBOX.EXE-650EC96F.pf
    C:WindowsPrefetchATBROKER.EXE-2E15A492.pf
    C:WindowsPrefetchAUDIODG.EXE-BDFD3029.pf
    C:WindowsPrefetchBIOMONITOR.EXE-A54E55F8.pf
    C:WindowsPrefetchBTSTACKSERVER.EXE-917D6126.pf
    C:WindowsPrefetchBTTRAY.EXE-6D2138AD.pf
    C:WindowsPrefetchCHROME.EXE-D999B1BA.pf
    C:WindowsPrefetchCONHOST.EXE-1F3E9D7E.pf
    C:WindowsPrefetchCONSENT.EXE-531BD9EA.pf
    C:WindowsPrefetchCSC.EXE-A3B8D95D.pf
    C:WindowsPrefetchCSC.EXE-BE9AC2DF.pf
    C:WindowsPrefetchCVTRES.EXE-069169FB.pf
    C:WindowsPrefetchCVTRES.EXE-2B9D810D.pf
    C:WindowsPrefetchDEFRAG.EXE-588F90AD.pf
    C:WindowsPrefetchDETECTION_COUNTRYCODE.EXE-8E06A8BC.pf
    C:WindowsPrefetchDETECTION_NETWORKCHECK.EXE-AD645CC9.pf
    C:WindowsPrefetchDETECT_LOWDISKSPACE_EX_US.EXE-B835F65F.pf
    C:WindowsPrefetchDETECT_LOWDISKSPACE_US.EXE-333F976B.pf
    C:WindowsPrefetchDETECT_REVGENCOUNTRY.EXE-A1C3912A.pf
    C:WindowsPrefetchDEVICEDISPLAYOBJECTPROVIDER.E-17410B90.pf
    C:WindowsPrefetchDLLHOST.EXE-40DD444D.pf
    C:WindowsPrefetchDLLHOST.EXE-5E46FA0D.pf
    C:WindowsPrefetchDLLHOST.EXE-766398D2.pf
    C:WindowsPrefetchDLLHOST.EXE-A8DE6D5B.pf
    C:WindowsPrefetchDLLHOST.EXE-B2EB1806.pf
    C:WindowsPrefetchDLLHOST.EXE-E7777CC4.pf
    C:WindowsPrefetchDLLHOST.EXE-ECB71776.pf
    C:WindowsPrefetchDOWNLOADAD.EXE-458F8347.pf
    C:WindowsPrefetchDRVINST.EXE-4CB4314A.pf
    C:WindowsPrefetchDWM.EXE-6FFD3DA8.pf
    C:WindowsPrefetchEXPLORER.EXE-A80E4F97.pf
    C:WindowsPrefetchEZRECOVER.EXE-E7109CC0.pf
    C:WindowsPrefetchFLASHPLAYERUPDATESERVICE.EXE-216D9C35.pf
    C:WindowsPrefetchGOOGLEUPDATE.EXE-B95715F5.pf
    C:WindowsPrefetchHPASSET.EXE-64C2897D.pf
    C:WindowsPrefetchHPCEE.EXE-6A33E4FB.pf
    C:WindowsPrefetchHPDOBJECT.EXE-BC6F451E.pf
    C:WindowsPrefetchHPMSGSVC.EXE-673FC6EC.pf
    C:WindowsPrefetchHPOSD.EXE-EAAD9E22.pf
    C:WindowsPrefetchHPQWMIEX.EXE-FAAC8C6F.pf
    C:WindowsPrefetchHPRESOURCES.EXE-A7537576.pf
    C:WindowsPrefetchHPSACIPDETECTION4.EXE-0849DE02.pf
    C:WindowsPrefetchHPSACOMMANDER.EXE-0CAADAA5.pf
    C:WindowsPrefetchHPSA_SERVICE.EXE-AD6579F0.pf
    C:WindowsPrefetchHPSF.EXE-C90ABEF1.pf
    C:WindowsPrefetchHPSFREPORT.EXE-F3375220.pf
    C:WindowsPrefetchHPTASKBAR3.EXE-A6188DE5.pf
    C:WindowsPrefetchIASTORDATAMGRSVC.EXE-C086B157.pf
    C:WindowsPrefetchIEWEBSITELOGON.EXE-CBA4CE5E.pf
    C:WindowsPrefetchIGFXSRVC.EXE-96A493A4.pf
    C:WindowsPrefetchIGFXTRAY.EXE-C444237E.pf
    C:WindowsPrefetchISBEW64.EXE-37453E32.pf
    C:WindowsPrefetchISBEW64.EXE-E7C9C034.pf
    C:WindowsPrefetchIUSB3MON.EXE-A44D03E8.pf
    C:WindowsPrefetchLayout.ini
    C:WindowsPrefetchLIVEBOXMANAGER.EXE-CF39284A.pf
    C:WindowsPrefetchLMS.EXE-8C70F87D.pf
    C:WindowsPrefetchLOGONUI.EXE-09140401.pf
    C:WindowsPrefetchLOWDISKSPACEDETECTION.EXE-6D00DF33.pf
    C:WindowsPrefetchMPCMDRUN.EXE-6AA90EA5.pf
    C:WindowsPrefetchMPSIGSTUB.EXE-6CB27A06.pf
    C:WindowsPrefetchMSCORSVW.EXE-57D17DAF.pf
    C:WindowsPrefetchMSCORSVW.EXE-C3C515BD.pf
    C:WindowsPrefetchMSIEXEC.EXE-A2D55CB6.pf
    C:WindowsPrefetchMSIEXEC.EXE-E09A077A.pf
    C:WindowsPrefetchNGEN.EXE-AE594A6B.pf
    C:WindowsPrefetchNISSRV.EXE-78BBD390.pf
    C:WindowsPrefetchNTOSBOOT-B00DFAAD.pf
    C:WindowsPrefetchNVTRAY.EXE-DB83881B.pf
    C:WindowsPrefetchOUINDICATOR.EXE-648863BA.pf
    C:WindowsPrefetchOUNOTIFICATION.EXE-107BB686.pf
    C:WindowsPrefetchOUSOFTWAREMANAGER.EXE-D8DB207F.pf
    C:WindowsPrefetchPfSvPerfStats.bin
    C:WindowsPrefetchPING.EXE-7E94E73E.pf
    C:WindowsPrefetchPLUGINLIVEBOX.EXE-B6F50B66.pf
    C:WindowsPrefetchPRESENTATIONFONTCACHE.EXE-73BE9E78.pf
    C:WindowsPrefetchPRODUCTCONFIG.EXE-29BD970A.pf
    C:WindowsPrefetchRAPPORTINJSERVICE_X64.EXE-48AF38F9.pf
    C:WindowsPrefetchRAPPORTSERVICE.EXE-B9BE0E79.pf
    C:WindowsPrefetchReadyBoot
    C:WindowsPrefetchREGSVR32.EXE-8461DBEE.pf
    C:WindowsPrefetchREGSVR32.EXE-D5170E12.pf
    C:WindowsPrefetchRESOURCE.EXE-E971D367.pf
    C:WindowsPrefetchRUNDLL32.EXE-3981F465.pf
    C:WindowsPrefetchRUNDLL32.EXE-411A328D.pf
    C:WindowsPrefetchRUNDLL32.EXE-61C085F4.pf
    C:WindowsPrefetchRUNDLL32.EXE-A3E35360.pf
    C:WindowsPrefetchRUNDLL32.EXE-DE9673F9.pf
    C:WindowsPrefetchRUNONCE.EXE-0E293DD6.pf
    C:WindowsPrefetchSCHTASKS.EXE-5CA45734.pf
    C:WindowsPrefetchSDIAGNHOST.EXE-8D72177C.pf
    C:WindowsPrefetchSEAPORT.EXE-24954F00.pf
    C:WindowsPrefetchSEARCHFILTERHOST.EXE-77482212.pf
    C:WindowsPrefetchSEARCHINDEXER.EXE-4A6353B9.pf
    C:WindowsPrefetchSEARCHPROTOCOLHOST.EXE-0CB8CADE.pf
    C:WindowsPrefetchSETDEFAULT.EXE-2B7FB0EB.pf
    C:WindowsPrefetchSETUP.EXE-EBD4A06F.pf
    C:WindowsPrefetchSPPSVC.EXE-B0F8131B.pf
    C:WindowsPrefetchST2.EXE-6A187731.pf
    C:WindowsPrefetchSVCHOST.EXE-6168E4A3.pf
    C:WindowsPrefetchSVCHOST.EXE-7AC6742A.pf
    C:WindowsPrefetchSVCHOST.EXE-7CFEDEA3.pf
    C:WindowsPrefetchSVCHOST.EXE-80F4A784.pf
    C:WindowsPrefetchSVCHOST.EXE-C871F054.pf
    C:WindowsPrefetchSYNTPENH.EXE-E6DC1353.pf
    C:WindowsPrefetchSYNTPHELPER.EXE-0A20AAC4.pf
    C:WindowsPrefetchTASKENG.EXE-48D4E289.pf
    C:WindowsPrefetchTASKHOST.EXE-7238F31D.pf
    C:WindowsPrefetchTASKKILL.EXE-E0105477.pf
    C:WindowsPrefetchTOUCHCONTROL.EXE-C358135A.pf
    C:WindowsPrefetchTRUESUITESERVICE.EXE-F9EC0995.pf
    C:WindowsPrefetchTRUSTEDINSTALLER.EXE-3CC531E5.pf
    C:WindowsPrefetchUNS.EXE-E6E49771.pf
    C:WindowsPrefetchUNZIP.EXE-EAF733B0.pf
    C:WindowsPrefetchUSERINIT.EXE-2257A3E7.pf
    C:WindowsPrefetchUTORRENT.EXE-AE62E46F.pf
    C:WindowsPrefetchVSSVC.EXE-B8AFC319.pf
    C:WindowsPrefetchW32TM.EXE-1101AF41.pf
    C:WindowsPrefetchWERMGR.EXE-0F2AC88C.pf
    C:WindowsPrefetchWIRELESSOFFMSG.EXE-286C32A5.pf
    C:WindowsPrefetchWMIADAP.EXE-F8DFDFA2.pf
    C:WindowsPrefetchWMIPRVSE.EXE-1628051C.pf
    C:WindowsPrefetchWMPLAYER.EXE-26C72A86.pf
    C:WindowsPrefetchWMPNETWK.EXE-D9F2A96F.pf
    C:WindowsPrefetchWMPNSCFG.EXE-FC0D39BF.pf
    C:WindowsPrefetchWUAUCLT.EXE-70318591.pf
    C:WindowsPrefetchYCMMIRAGE.EXE-5E0FEA70.pf
    C:WindowsPrefetchReadyBootTrace5.fx
    C:WindowsPrefetchReadyBootTrace6.fx
    C:WindowsPrefetchReadyBootTrace7.fx
    C:WindowsPrefetchReadyBootTrace8.fx
    C:WindowsPrefetchReadyBootTrace9.fx

    Corbeille vidée.

    Fin du rapport.

  • H.A.W.X
    Participant
    Post count: 1704

    Bonjour,

    Je poste dan la soirée car j’ai du travail pour le moment :shame:

    Bonne journée

  • H.A.W.X
    Participant
    Post count: 1704

    Bonsoir !

    Après une longue journée de travail :secretsmile:

    • Copie les lignes ci dessous :


    Script ZHPFix
    Sysrestore

    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components464AA55239C100F32AF2D438EDDC0F47] =>Adware.IMBooster
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components5652BA3D5FB98AE31B337BF0AF939856] =>Adware.IMBooster
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components86EB95E1AFCBABE3DB9ECCC669B99494] =>Adware.IMBooster
    C:UserssadaikDownloadscacaoweb.exe =>PUP.CacaoWeb
    O3 - Toolbar: (no name) [64Bits] - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Clé orpheline
    O3 - ToolbarWebBrowser: (no name) [64Bits] - [HKCU]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} Clé orpheline
    O90 - PUC: "3E9A223DB85706D47A4C568CF83D870D" . (.Bing Bar.) -- C:WindowsInstaller{D322A9E3-758B-4D60-A7C4-65C88FD378D0}icon_installer_ico =>Toolbar.Bing
    [HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{C9A6357B-25CC-4BCF-96C1-78736985D412}] =>Toolbar.Orange
    [HKLMSoftwareWow6432NodeMicrosoftTracingBingBar_RASAPI32] =>Toolbar.Bing

    FirewallRaz
    EmptyCLSID
    EmptyFlash

    • Lances ZHPFix, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista

      1. Clique sur Importer
      2. Puis Clic sur “GO

    • Confirmes les nettoyages des données en cliquant sur “Oui
    • Une fois le scan terminé rends toi sur le bureau, le fichier ZHPFixReport à été crée.
    • Héberge le rapport ZHPFixReport sur SosUpload, puis copie/colle le lien fourni dans ta prochaine réponse.

    Bonne soirée :)

  • scorpio44
    Participant
    Post count: 9

    Rapport de ZHPFix 2013.10.21.17 par Nicolas Coolman, Update du 21/10/2013
    Fichier d’export Registre :
    Run by sadaik at 30/10/2013 22:21:36
    High Elevated Privileges : OK
    Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)

    Corbeille vidée (00mn 29s)

    ========== Processus mémoire ==========
    SUPPRIMÉ: Memory Process: C:UserssadaikDownloadscacaoweb.exe

    ========== Clés du Registre ==========
    SUPPRIMÉ:* HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components464AA55239C100F32AF2D438EDDC0F47
    SUPPRIMÉ:* HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components5652BA3D5FB98AE31B337BF0AF939856
    SUPPRIMÉ:* HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components86EB95E1AFCBABE3DB9ECCC669B99494
    SUPPRIMÉ: [HKLMSOFTWAREClassesCLSID{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
    SUPPRIMÉ: [HKLMSoftwareClassesInstallerProducts\3E9A223DB85706D47A4C568CF83D870D]
    SUPPRIMÉ: [HKLMSoftwareClassesInstallerFeatures3E9A223DB85706D47A4C568CF83D870D]
    SUPPRIMÉ: HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{C9A6357B-25CC-4BCF-96C1-78736985D412}
    SUPPRIMÉ: HKLMSoftwareWow6432NodeMicrosoftTracingBingBar_RASAPI32

    ========== Valeurs du Registre ==========
    SUPPRIMÉ: Toolbar: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5}
    SUPPRIMÉ: Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
    Aucune Valeur Standard Profile: FirewallRaz :
    Aucune Valeur Domain Profile: FirewallRaz :
    SUPPRIMÉ: FirewallRaz (None) : {576A048B-525B-48AA-BF1F-8D0C47A3E6FC}
    SUPPRIMÉ: FirewallRaz (Domain) : NetPres-In-TCP-NoScope
    SUPPRIMÉ: FirewallRaz (Domain) : NetPres-Out-TCP-NoScope
    SUPPRIMÉ: FirewallRaz (None) : NetPres-WSD-In-UDP
    SUPPRIMÉ: FirewallRaz (None) : NetPres-WSD-Out-UDP
    SUPPRIMÉ: FirewallRaz (Public) : NetPres-In-TCP
    SUPPRIMÉ: FirewallRaz (Public) : NetPres-Out-TCP
    SUPPRIMÉ: FirewallRaz (None) : {2C5B9520-3AE4-4001-BE46-9862C1DAC76A}
    SUPPRIMÉ: FirewallRaz (None) : {C3A994B8-7BD7-4606-8626-54F540CB1EC8}

    ========== Dossiers ==========
    SUPPRIMÉ: C:UserssadaikAppDataLocal{00815597-34CF-46A7-9BEC-B85A5982254C}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{0DFB6AE7-E94E-4812-A5DB-3900522FEDFB}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{1B7643D6-247F-41FE-A18E-511805E37D79}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{28832CB3-C9B7-4F23-9CFC-AEDB9933FE7D}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{3F7016FA-28F7-41B2-90FE-5A55DC6E6A2A}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{53444EDD-3533-49B3-82CC-8A1FAE620A70}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{6216017F-DD93-409C-82BB-21C6116856F6}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{63514CF1-4B5C-4FCF-87E6-BC0B3E32A508}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{6BAF7884-87BE-401A-B206-DA2CA3C64A7C}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{6C4E62D8-F456-4A98-81FB-18E67DE31331}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{801D8681-DF5A-4488-A2B4-0289339F412F}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{8231CACF-5A11-4441-BD3A-C6AD29C93F34}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{8364383B-E1E5-4E19-AF31-0C8A76783B2D}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{8E341275-B840-439E-B837-9FA18A07692D}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{C8B97C7D-AE79-4692-8CD0-3D832E9AA6C4}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{D1FDBF74-ACE4-4B4C-879D-8F4DCECD3CF7}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{D963A35D-E90F-4710-A7EA-C200D4796C61}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{DD573BA7-D0EA-4E9E-B243-DEF271D561A3}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{E1197284-B85A-4CC9-8E25-BBA9EC6DF4BD}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{E1F44C0F-BC61-4834-BF0A-97D422005F92}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{E8AD86E0-9AB2-4F9F-BE21-3F0DD8182EC7}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{EE8B783B-20EA-404A-B69A-64419C59AAEA}
    SUPPRIMÉ: C:UserssadaikAppDataLocal{FE93A336-D117-499C-B24C-AFBF9B7C31DD}
    SUPPRIMÉS Flash Cookies (0) (0 octets)

    ========== Fichiers ==========
    SUPPRIMÉS Flash Cookies (0) (0 octets)

    ========== Restauration Système ==========
    Point de restauration du système créé avec succès

    ========== Récapitulatif ==========
    1 : Processus mémoire
    8 : Clés du Registre
    13 : Valeurs du Registre
    24 : Dossiers
    1 : Fichiers
    1 : Restauration Système

    End of clean in 01mn 10s

    ========== Chemin de fichier rapport ==========
    C:UserssadaikAppDataRoamingZHPZHPFix[R1].txt – 30/10/2013 22:22:06 [4370]

  • H.A.W.X
    Participant
    Post count: 1704

    Bonjour :)

    Ok ton PC est clean :secretsmile:

    As tu des questions ? Des demandes avant de finaliser ? :)

    Veux tu des conseils sur comment te protéger efficacement ?

    Bonne journée :)

  • scorpio44
    Participant
    Post count: 9

    ce type de virus ou de trojan est il possible qu’il soit detecte par une alerte des lors qu’il s’incruste dans le pc par les logiciels type malware adaware ou les antivirus parce c’est en ouvrant un fichier contamine et que j’ai ete envahi
    voila sinon merci de votre attention et de l’aide que vous m’avez apporte en tant normal je fais attention et ce que je telecharge mais comme bcp d’entre nous il a suffi d’une fois le plus important c’est de m’en etre debarasse

  • H.A.W.X
    Participant
    Post count: 1704

    Bonjour,

    Oui effectivement cela n’est pas venu via une faille puisque tes mises à jour étaient toutes ok !

    Aurais tu encore le fichier infecté ?

    Malheureusement Avast est un très bon antivirus gratuit de nos jours, je parle de la version gratuite et non payante ;)

    Les antivirus ne connaissent pas tout, même les payant très bon malheureusement :( Je peux te conseiller de garder Malwarebytes qui aura lui aussi une protection en temps réel en plus d’avast. Bien faire attention au fichiers que tu ouvres, vérifier que la source qui te l’envoie soit fiable !

    Le risque est partout, il faut une bonne protection, ce que je t’ai proposé au dessus et être responsable lors de tes recherche sur le net :)

    Es ce que cela t’aide ? Veux tu plus de précisions ?

    Je reste à ton écoute si tu as besoins, la procédure pour supprimer tout les outils de désinfection est ci dessous ;) :

    • Télécharges Delfix sur ton Bureau.
    • Lance Delfix, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista
    • Coche la case suivantes :
      • Réactiver l’UAC
      • Supprimer les outils de désinfection
      • Effectuer une sauvegarde du registre
      • Purger la restauration système
      • Réinitialisation des paramètres système

    ++

  • scorpio44
    Participant
    Post count: 9

    # DelFix v10.5 – Rapport créé le 02/11/2013 à 15:36:23
    # Mis à jour le 17/10/2013 par Xplode
    # Nom d’utilisateur : sadaik – SADAIK-HP
    # Système d’exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)

    ~ Activation de l’UAC … OK

    ~ Suppression des outils de désinfection …

    Supprimé : C:AdwCleaner
    Supprimé : C:ProgramDataMicrosoftWindowsStart MenuProgramsZHP
    Supprimé : C:Program Files (x86)ZHPDiag
    Supprimé : C:PhysicalDisk0_MBR.bin
    Supprimé : C:UserssadaikDesktopZHPDiag.lnk
    Supprimé : C:UserssadaikDesktopZHPDiag.txt
    Supprimé : C:UserssadaikDesktopZHPFix.lnk
    Supprimé : C:UserssadaikDesktopZHPFixReport.txt
    Supprimé : C:UserssadaikDownloadsadwcleaner (1).exe
    Supprimé : C:UserssadaikDownloadsadwcleaner.exe
    Supprimé : C:UserssadaikDownloadsrapport_SX.txt
    Supprimé : C:UserssadaikDownloadsRogueKiller.exe
    Supprimé : C:UserssadaikDownloadsSXCU (1).exe
    Supprimé : C:UserssadaikDownloadsSXCU.exe
    Supprimé : C:UserssadaikDownloadsZHPDiag2.exe
    Supprimée : HKLMSOFTWAREAdwCleaner
    Supprimée : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstallZHPDiag_is1

    ~ Sauvegarde de la base de registre … OK

    ~ Purge de la restauration système …

    Supprimé : RP #143 [Windows Update | 10/16/2013 04:23:31]
    Supprimé : RP #144 [Windows Update | 10/19/2013 08:05:05]
    Supprimé : RP #145 [Windows Update | 10/23/2013 07:57:00]
    Supprimé : RP #146 [HPSF Applying updates | 10/24/2013 17:12:22]
    Supprimé : RP #147 [HPSF Applying updates | 10/24/2013 17:12:22]
    Supprimé : RP #148 [Windows Update | 10/27/2013 05:57:27]
    Supprimé : RP #149 [Installed Rapport | 10/28/2013 08:54:05]
    Supprimé : RP #150 [Installed Rapport | 10/28/2013 21:52:04]
    Supprimé : RP #151 [avast! antivirus system restore point | 10/28/2013 23:42:50]
    Supprimé : RP #152 [Windows Update | 10/30/2013 06:00:31]
    Supprimé : RP #153 [Point de restauration ZHPFix | 10/30/2013 21:20:57]
    Supprimé : RP #154 [HPSF Applying updates | 10/31/2013 19:18:41]
    Supprimé : RP #155 [HPSF Applying updates | 10/31/2013 19:18:41]

    Nouveau point de restauration créé !

    ~ Réinitialisation des paramètres système … OK

    ########## – EOF – ##########

Le sujet ‘interpol virus’ est fermé à de nouvelles réponses.