virus disquees durs 2013-11-18T09:45:25+00:00
  • Auteur
    Messages
  • nadouche92
    Nombre d'articles : 0

    j’ai voulu désinfecter un disque dur que je ne pensais pas affecté, pourquoi le rapport dit que mon pc n’est pas vacciné alors que j’ai tt désinfecté hier?
    qu’est ce que je dois faire aprés ce rapport?
    ############################## | UsbFix V 7.150 | [Recherche]

    Utilisateur: Nadia (Administrateur) # NADIA-TOSH
    Mis à jour le 08/11/2013 par El Desaparecido – Team SosVirus
    Lancé à 10:29:33 | 18/11/2013

    Site Web : http://www.usbfix.net” onclick=”window.open(this.href);return false;
    Forum : https://www.sosvirus.net/” onclick=”window.open(this.href);return false;
    Upload Malware : upload_malware.php
    Contact : http://www.usbfix.net/contact/” onclick=”window.open(this.href);return false;

    PC: TOSHIBA (PWWAM)
    CPU: Pentium(R) Dual-Core CPU T4500 @ 2.30GHz
    RAM -> [Total : 3933 | Free : 2062]
    Bios: TOSHIBA
    Boot: Normal boot

    OS: Microsoft Windows 7 Édition Familiale Premium (6.1.7601 64-Bit) Service Pack 1
    WB: Windows Internet Explorer : 10.0.9200.16736
    WB: Google Chrome : 30.0.1599.101
    WB: Mozilla Firefox : 25.0.1

    SC: Security Center Service [Enabled]
    WU: Windows Update Service [Enabled]
    AV: avast! Antivirus [Enabled | Updated]
    AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
    FW: Windows FireWall Service [Enabled]

    C: (%systemdrive%) -> Disque fixe # 149 Go (56 Go libre(s) – 37%) [WINDOWS] # NTFS
    D: -> Disque fixe # 148 Go (140 Go libre(s) – 94%) [Data] # NTFS
    E: -> CD-ROM
    F: -> Disque fixe # 298 Go (83 Go libre(s) – 28%) [nadia dur1] # NTFS

    ################## | Processus Actif |

    C:Windowssystem32csrss.exe (ID: 472 |ParentID: 424)
    C:Windowssystem32wininit.exe (ID: 576 |ParentID: 424)
    C:Windowssystem32csrss.exe (ID: 592 |ParentID: 584)
    C:Windowssystem32services.exe (ID: 644 |ParentID: 576)
    C:Windowssystem32winlogon.exe (ID: 676 |ParentID: 584)
    C:Windowssystem32lsass.exe (ID: 692 |ParentID: 576)
    C:Windowssystem32lsm.exe (ID: 704 |ParentID: 576)
    C:Windowssystem32svchost.exe (ID: 824 |ParentID: 644)
    C:Windowssystem32svchost.exe (ID: 920 |ParentID: 644)
    C:WindowsSystem32svchost.exe (ID: 980 |ParentID: 644)
    C:WindowsSystem32svchost.exe (ID: 356 |ParentID: 644)
    C:Windowssystem32svchost.exe (ID: 508 |ParentID: 644)
    C:Windowssystem32svchost.exe (ID: 428 |ParentID: 644)
    C:WindowsservicingTrustedInstaller.exe (ID: 772 |ParentID: 644)
    C:Windowssystem32svchost.exe (ID: 1200 |ParentID: 644)
    C:Program FilesAVAST SoftwareAvastAvastSvc.exe (ID: 1280 |ParentID: 644)
    C:WindowsSystem32spoolsv.exe (ID: 1396 |ParentID: 644)
    C:Windowssystem32svchost.exe (ID: 1448 |ParentID: 644)
    C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe (ID: 1592 |ParentID: 644)
    C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe (ID: 1628 |ParentID: 644)
    C:Program FilesBonjourmDNSResponder.exe (ID: 1656 |ParentID: 644)
    C:Windowssystem32svchost.exe (ID: 1696 |ParentID: 644)
    C:Program Files (x86)RealtekRealtek USB 2.0 Card ReaderRIconMan.exe (ID: 1748 |ParentID: 644)
    C:Windowssystem32svchost.exe (ID: 1852 |ParentID: 644)
    C:Program Files (x86)TeamViewerVersion8TeamViewer_Service.exe (ID: 2004 |ParentID: 644)
    C:Windowssystem32TODDSrv.exe (ID: 240 |ParentID: 644)
    C:Program Files (x86)Tortor.exe (ID: 1320 |ParentID: 644)
    C:Program FilesTOSHIBAPower SaverTosCoSrv.exe (ID: 1296 |ParentID: 644)
    C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSVC.EXE (ID: 1036 |ParentID: 644)
    C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSvcM.exe (ID: 2084 |ParentID: 1036)
    C:Windowssystem32svchost.exe (ID: 2324 |ParentID: 644)
    C:Windowssystem32SearchIndexer.exe (ID: 2608 |ParentID: 644)
    C:Windowssystem32taskeng.exe (ID: 3204 |ParentID: 428)
    C:Windowssystem32taskhost.exe (ID: 3256 |ParentID: 644)
    C:Windowssystem32Dwm.exe (ID: 3372 |ParentID: 356)
    C:WindowsExplorer.EXE (ID: 3404 |ParentID: 3360)
    C:Program FilesTOSHIBABulletinBoardTosNcCore.exe (ID: 3580 |ParentID: 3404)
    C:Program FilesTOSHIBAReelTimeTosReelTimeMonitor.exe (ID: 3596 |ParentID: 3404)
    C:WindowsSystem32igfxtray.exe (ID: 3612 |ParentID: 3404)
    C:WindowsSystem32hkcmd.exe (ID: 3628 |ParentID: 3404)
    C:WindowsSystem32igfxpers.exe (ID: 3640 |ParentID: 3404)
    C:Program FilesRealtekAudioHDARAVCpl64.exe (ID: 3816 |ParentID: 3404)
    C:Program FilesRealtekAudioHDARAVBg64.exe (ID: 3908 |ParentID: 3404)
    C:Program FilesTOSHIBAPower SaverTPwrMain.exe (ID: 3964 |ParentID: 3404)
    C:Program FilesTOSHIBASmoothViewSmoothView.exe (ID: 4024 |ParentID: 3404)
    C:Program FilesSynapticsSynTPSynTPEnh.exe (ID: 4092 |ParentID: 3404)
    C:Program FilesWindows Media Playerwmpnetwk.exe (ID: 3588 |ParentID: 644)
    C:WindowsSystem32svchost.exe (ID: 3888 |ParentID: 644)
    C:Program Files (x86)Siber SystemsAI RoboFormrobotaskbaricon.exe (ID: 3480 |ParentID: 3404)
    C:Program FilesSynapticsSynTPSynTPHelper.exe (ID: 232 |ParentID: 4092)
    C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 3712 |ParentID: 3404)
    C:Program Files (x86)TOSHIBAUtilitiesKeNotify.exe (ID: 4212 |ParentID: 3320)
    C:Program Files (x86)TOSHIBATOSHIBA Service StationToshibaServiceStation.exe (ID: 4268 |ParentID: 3320)
    C:Program FilesAVAST SoftwareAvastAvastUI.exe (ID: 4304 |ParentID: 3320)
    C:Program Files (x86)TOSHIBAConfigFreeNDSTray.exe (ID: 4580 |ParentID: 3204)
    C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 4876 |ParentID: 3712)
    C:Windowssystem32DllHost.exe (ID: 4896 |ParentID: 824)
    C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 5016 |ParentID: 3712)
    C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 5048 |ParentID: 3712)
    C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 4076 |ParentID: 3712)
    C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 3380 |ParentID: 3712)
    C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 3720 |ParentID: 3712)
    C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 2160 |ParentID: 3712)
    C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 2356 |ParentID: 3712)
    C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 4120 |ParentID: 3712)
    C:Program Files (x86)Mozilla Firefoxfirefox.exe (ID: 4048 |ParentID: 3404)
    C:Program Files (x86)TOSHIBAConfigFreeCFSwMgr.exe (ID: 3484 |ParentID: 4580)
    C:Program Files (x86)TOSHIBAConfigFreeCFIWmxSvcs64.exe (ID: 5684 |ParentID: 644)
    C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe (ID: 5712 |ParentID: 644)
    C:Program Files (x86)TOSHIBATOSHIBA Service StationTMachInfo.exe (ID: 5972 |ParentID: 644)
    C:WindowsMicrosoft.NETFramework64v4.0.30319mscorsvw.exe (ID: 6044 |ParentID: 644)
    C:Program Files (x86)TOSHIBAConfigFreeCFSvcs.exe (ID: 5312 |ParentID: 644)
    c:Program Files (x86)NeroUpdateNASvc.exe (ID: 1888 |ParentID: 644)
    C:WindowsSystem32svchost.exe (ID: 5440 |ParentID: 644)
    C:Program FilesTOSHIBATOSHIBA HDD SSD AlertTosSmartSrv.exe (ID: 1160 |ParentID: 644)
    C:Program FilesTOSHIBATOSHIBA HDD SSD AlertTosSENotify.exe (ID: 4372 |ParentID: 4056)
    C:Windowssystem32wuauclt.exe (ID: 6136 |ParentID: 428)
    C:Program Files (x86)Mozilla Firefoxplugin-container.exe (ID: 4344 |ParentID: 4048)
    C:WindowsSysWOW64MacromedFlashFlashPlayerPlugin_11_7_700_224.exe (ID: 1524 |ParentID: 4344)
    C:WindowsSysWOW64MacromedFlashFlashPlayerPlugin_11_7_700_224.exe (ID: 760 |ParentID: 1524)
    C:UsbFixGo.exe (ID: 4960 |ParentID: 2524)
    C:Windowssystem32wbemwmiprvse.exe (ID: 5992 |ParentID: 824)

    ################## | Regedit Run |

    04 – HKLMSOFTWARE | Run : [HWSetup] – C:Program FilesTOSHIBAUtilitiesHWSetup.exe hwSetUP
    04 – HKLMSOFTWARE | Run : [SVPWUTIL] – C:Program Files (x86)TOSHIBAUtilitiesSVPWUTIL.exe SVPwUTIL
    04 – HKLMSOFTWARE | Run : [KeNotify] – “C:Program Files (x86)TOSHIBAUtilitiesKeNotify.exe” LPCM
    04 – HKLMSOFTWARE | Run : [ToshibaServiceStation] – C:Program Files (x86)TOSHIBATOSHIBA Service StationToshibaServiceStation.exe /hide:60
    04 – HKLMSOFTWARE | Run : [Adobe ARM] – “C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe”
    04 – HKLMSOFTWARE | Run : [AvastUI.exe] – “C:Program FilesAVAST SoftwareAvastAvastUI.exe” /nogui
    04 – HKLMSOFTWAREwow6432Node | Run : [HWSetup] – C:Program FilesTOSHIBAUtilitiesHWSetup.exe hwSetUP
    04 – HKLMSOFTWAREwow6432Node | Run : [SVPWUTIL] – C:Program Files (x86)TOSHIBAUtilitiesSVPWUTIL.exe SVPwUTIL
    04 – HKLMSOFTWAREwow6432Node | Run : [KeNotify] – “C:Program Files (x86)TOSHIBAUtilitiesKeNotify.exe” LPCM
    04 – HKLMSOFTWAREwow6432Node | Run : [ToshibaServiceStation] – C:Program Files (x86)TOSHIBATOSHIBA Service StationToshibaServiceStation.exe /hide:60
    04 – HKLMSOFTWAREwow6432Node | Run : [Adobe ARM] – “C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe”
    04 – HKLMSOFTWAREwow6432Node | Run : [AvastUI.exe] – “C:Program FilesAVAST SoftwareAvastAvastUI.exe” /nogui
    04 – HKLMSOFTWARE | RunOnce : [] –
    04 – HKLMSOFTWAREwow6432Node | RunOnce : [] –
    04 – HKUS-1-5-19SOFTWARE | Run : [Sidebar] – %ProgramFiles%Windows SidebarSidebar.exe /autoRun
    04 – HKUS-1-5-20SOFTWARE | Run : [Sidebar] – %ProgramFiles%Windows SidebarSidebar.exe /autoRun
    04 – HKUS-1-5-21-2945581834-3016043712-3197114360-1001SOFTWARE | Run : [swg] – “C:Program Files (x86)GoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe”
    04 – HKUS-1-5-21-2945581834-3016043712-3197114360-1001SOFTWARE | Run : [RoboForm] – “C:Program Files (x86)Siber SystemsAI RoboFormRoboTaskBarIcon.exe”
    04 – HKUS-1-5-18SOFTWARE | Run : [TOSHIBA Online Product Information] – C:Program Files (x86)TOSHIBATOSHIBA Online Product Informationtopi.exe
    04 – HKUS-1-5-19SOFTWARE | RunOnce : [mctadmin] – C:WindowsSystem32mctadmin.exe
    04 – HKUS-1-5-20SOFTWARE | RunOnce : [mctadmin] – C:WindowsSystem32mctadmin.exe
    04 – HKUS-1-5-18SOFTWARE | RunOnce : [SPReview] – “C:WindowsSystem32SPReviewSPReview.exe” /sp:1 /errorfwlink:”http://go.microsoft.com/fwlink/?LinkID=122915″ /build:7601

    ################## | Recherche générique |

    ################## | Registre |

    ################## | Vaccin |

    (!) Cet ordinateur n’est pas vacciné!

    ################## | E.O.F | http://www.usbfix.net” onclick=”window.open(this.href);return false; – https://www.sosvirus.net” onclick=”window.open(this.href);return false; |

  • Anonyme
    Nombre d'articles : 0

    Hello :hello: ,

    Bienvenue sur SosVirus :welcome:

    pourquoi le rapport dit que mon pc n’est pas vacciné alors que j’ai tt désinfecté hier?

    Car UsbFix n’a pas vu de clé usb connecté donc il n’a pas vacciné, je suis actuellement en train de travailler sur la fonction vaccin.

    Y’a des adwares sur ton PC aussi :

    • Télécharges Adwcleaner (de Xplode) sur ton Bureau !
    • Fais clic droit dessus, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista
      1. Choisi l’option Scanner
      2. Choisi l’option Nettoyer
    • Accepte l’avertissement en cliquant sur OK

    • Acceptes les avertissements/informations en cliquant sur OK
    • Copie et Colle le contenu du rapport qui apparaît au redémarrage du PC
  • nadouche92
    Nombre d'articles : 0

    voici le rapport aprés sccan et redemarage
    # AdwCleaner v3.012 – Rapport créé le 18/11/2013 à 11:13:08
    # Mis à jour le 11/11/2013 par Xplode
    # Système d’exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Nom d’utilisateur : Nadia – NADIA-TOSH
    # Exécuté depuis : C:UsersNadiaDownloadsadwcleaner.exe
    # Option : Nettoyer

    ***** [ Services ] *****

    ***** [ Fichiers / Dossiers ] *****

    Dossier Supprimé : C:ProgramDataBabylon
    Dossier Supprimé : C:Program Files (x86)Conduit
    Dossier Supprimé : C:Program Files (x86)Supreme Savings
    Dossier Supprimé : C:Program Files (x86)tuguu sl
    Dossier Supprimé : C:UsersNadiaAppDataLocalConduit
    Dossier Supprimé : C:UsersNadiaAppDataLocalSupreme Savings
    Dossier Supprimé : C:UsersNadiaAppDataLocalLowConduit
    Dossier Supprimé : C:UsersNadiaAppDataLocalLowDelta
    Dossier Supprimé : C:UsersNadiaAppDataLocalLowPriceGong
    Dossier Supprimé : C:UsersNadiaAppDataLocalLowuTorrentBar_FR
    Dossier Supprimé : C:UsersNadiaAppDataRoamingBabylon
    Dossier Supprimé : C:UsersNadiaAppDataRoamingfile scout
    Dossier Supprimé : C:UsersNadiaAppDataLocalGoogleChromeUser DataDefaultExtensionspaoponfhfdfnjgddpnpjkambkcgdaaib
    [!] Dossier Supprimé : C:UsersNadiaAppDataLocalGoogleChromeUser DataDefaultExtensionspaoponfhfdfnjgddpnpjkambkcgdaaib

    ***** [ Raccourcis ] *****

    ***** [ Registre ] *****

    Clé Supprimée : HKCUSoftwareGoogleChromeExtensionspaoponfhfdfnjgddpnpjkambkcgdaaib
    Clé Supprimée : HKLMSOFTWAREGoogleChromeExtensionspaoponfhfdfnjgddpnpjkambkcgdaaib
    Clé Supprimée : HKLMSOFTWAREClassesAppID{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
    Clé Supprimée : HKLMSOFTWAREClassesProd.cap
    Clé Supprimée : HKLMSOFTWAREMicrosoftTracingBingBar_RASMANCS
    Clé Supprimée : HKLMSOFTWAREMicrosoftTracingMyBabylontb_RASAPI32
    Clé Supprimée : HKLMSOFTWAREMicrosoftTracingMyBabylontb_RASMANCS
    Clé Supprimée : HKLMSOFTWAREMicrosoftTracingoptimizerpro_rasapi32
    Clé Supprimée : HKLMSOFTWAREMicrosoftTracingoptimizerpro_rasmancs
    Clé Supprimée : HKLMSOFTWAREClassesCrossriderApp0019962.BHO
    Clé Supprimée : HKLMSOFTWAREClassesCrossriderApp0019962.BHO.1
    Clé Supprimée : HKLMSOFTWAREClassesCrossriderApp0019962.Sandbox
    Clé Supprimée : HKLMSOFTWAREClassesCrossriderApp0019962.Sandbox.1
    Clé Supprimée : HKCUSoftwarea55888ce53fec48
    Clé Supprimée : HKLMSOFTWAREClassesAppID{0A18A436-2A7A-49F3-A488-30538A2F6323}
    Clé Supprimée : HKLMSOFTWAREClassesCLSID{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
    Clé Supprimée : HKLMSOFTWAREClassesCLSID{22222222-2222-2222-2222-220122992262}
    Clé Supprimée : HKLMSOFTWAREClassesCLSID{3C471948-F874-49F5-B338-4F214A2EE0B1}
    Clé Supprimée : HKLMSOFTWAREClassesCLSID{11111111-1111-1111-1111-110111991162}
    Clé Supprimée : HKLMSOFTWAREClassesInterface{55555555-5555-5555-5555-550155995562}
    Clé Supprimée : HKLMSOFTWAREClassesInterface{66666666-6666-6666-6666-660166996662}
    Clé Supprimée : HKLMSOFTWAREClassesTypeLib{44444444-4444-4444-4444-440144994462}
    Clé Supprimée : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{11111111-1111-1111-1111-110111991162}
    Clé Supprimée : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{82E1477C-B154-48D3-9891-33D83C26BCD3}
    Clé Supprimée : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Clé Supprimée : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
    Clé Supprimée : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{11111111-1111-1111-1111-110111991162}
    Clé Supprimée : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExtPreApproved{11111111-1111-1111-1111-110111991162}
    Clé Supprimée : HKLMSOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{1c2b2612-9291-46d6-8e21-3e74c4583329}
    Clé Supprimée : HKLMSOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{40041302-aa25-4b1b-b030-dd894ae239af}
    Clé Supprimée : HKLMSOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{44eac34f-7317-4dd1-9ac8-f4ee73a40544}
    Clé Supprimée : HKLMSOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{6b1cc058-cd6b-479a-b1df-de24465bb229}
    Clé Supprimée : HKLMSOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{fc9fb302-01c3-46b6-8824-4e6a0d71d820}
    Clé Supprimée : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
    Clé Supprimée : [x64] HKLMSOFTWAREClassesInterface{55555555-5555-5555-5555-550155995562}
    Clé Supprimée : [x64] HKLMSOFTWAREClassesInterface{66666666-6666-6666-6666-660166996662}
    Valeur Supprimée : HKLMSOFTWAREPoliciesGoogleChromeExtensionInstallForcelist [1]
    Clé Supprimée : HKCUSoftwareBabSolution
    Clé Supprimée : HKCUSoftwareBabylonToolbar
    Clé Supprimée : HKCUSoftwareCr_Installer
    Clé Supprimée : HKCUSoftwareDataMngr
    Clé Supprimée : HKCUSoftwarefilescout
    Clé Supprimée : HKCUSoftwareinstalledbrowserextensions
    Clé Supprimée : HKCUSoftwareAppDataLowSoftwareConduit
    Clé Supprimée : HKCUSoftwareAppDataLowSoftwareConduitSearchScopes
    Clé Supprimée : HKCUSoftwareAppDataLowSoftwareCrossrider
    Clé Supprimée : HKCUSoftwareAppDataLowSoftwarePriceGong
    Clé Supprimée : HKCUSoftwareAppDataLowSoftwaresmartbar
    Clé Supprimée : HKCUSoftwareAppDataLowSoftwareSupreme Savings
    Clé Supprimée : HKLMSoftwareBabylon
    Clé Supprimée : HKLMSoftwareConduit
    Clé Supprimée : HKLMSoftwareDataMngr
    Clé Supprimée : HKLMSoftwareSupreme Savings
    Clé Supprimée : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{EBE677C0-CBCB-4EBF-8098-E27E1B5271CF}
    Clé Supprimée : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstallSupreme Savings
    Clé Supprimée : [x64] HKLMSOFTWAREDomaIQ
    Clé Supprimée : HKLMSoftwareClassesInstallerFeaturesC776EBEBCBCFBE408892EE7B12517FC
    Clé Supprimée : HKLMSoftwareClassesInstallerProductsC776EBEBCBCFBE408892EE7B12517FC

    ***** [ Navigateurs ] *****

    -\ Internet Explorer v10.0.9200.16736

    -\ Mozilla Firefox v25.0.1 (fr)

    [ Fichier : C:UsersNadiaAppDataRoamingMozillaFirefoxProfilesezo9ao19.defaultprefs.js ]

    -\ Google Chrome v30.0.1599.101

    [ Fichier : C:UsersNadiaAppDataLocalGoogleChromeUser DataDefaultpreferences ]

    *************************

    AdwCleaner[R0].txt – [7564 octets] – [18/11/2013 11:10:08]
    AdwCleaner[S0].txt – [6408 octets] – [18/11/2013 11:13:08]

    ########## EOF – C:AdwCleanerAdwCleaner[S0].txt – [6468 octets] ##########

  • Anonyme
    Nombre d'articles : 0

    On va faire un scan généraliste :

    • Télécharge Malwarebytes’ Anti-Malware et installe le.
    • Lance Malwarebytes’ Anti-Malware.
    • Clique sur l’onglet “Mises à jours” puis sur “Rechercher des mises à jours”.
    • Clique sur l’onglet “Recherche”, coche “éxécuter un examen rapide” puis clic sur Rechercher.

    A la fin de l’analyse, si MBAM n’a rien trouvé :

    • Clique sur OK, le rapport s’ouvre spontanément.

    Si des menaces ont été détectées :

    • Clique sur OK puis “Afficher les résultats”.
    • Coches toutes les cases.
    • Choisis l’option “Supprimer la sélection”.

    • Si MBAM demande le redémarrage de Windows : Clique sur “Oui”.
    • Une fois le PC redémarré, le rapport se trouve dans l’onglet “Rapports/Logs”.
    • Sinon le rapport s’ouvre automatiquement après la suppression.
    • Post le rapport dans ta prochaine réponse.
  • nadouche92
    Nombre d'articles : 0

    voici le rapport tt se que g supprimer c t des virus??
    Malwarebytes Anti-Malware (Essai) 1.75.0.1300
    http://www.malwarebytes.org

    Version de la base de données: v2013.11.18.03

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 10.0.9200.16736
    Nadia :: NADIA-TOSH [administrateur]

    Protection: Activé

    18/11/2013 11:38:29
    mbam-log-2013-11-18 (11-38-29).txt

    Type d’examen: Examen rapide
    Options d’examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
    Options d’examen désactivées: P2P
    Elément(s) analysé(s): 204413
    Temps écoulé: 4 minute(s), 26 seconde(s)

    Processus mémoire détecté(s): 0
    (Aucun élément nuisible détecté)

    Module(s) mémoire détecté(s): 0
    (Aucun élément nuisible détecté)

    Clé(s) du Registre détectée(s): 0
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre détectée(s): 0
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre détecté(s): 0
    (Aucun élément nuisible détecté)

    Dossier(s) détecté(s): 2
    C:UsersNadiaAppDataRoamingplayer (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimages (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.

    Fichier(s) détecté(s): 36
    C:UsersNadiaAppDataRoamingplayerplaylist.vpl (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerconfig.ini (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_103.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_11.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_120.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_121.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_122.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_123.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_124.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_125.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_126.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_127.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_136.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_137.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_140.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_141.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_149.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_150.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_160.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_165.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_181.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_191.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_193.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_199.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_200.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_201.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_204.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_221.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_224.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_28.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_34.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_37.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_49.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_57.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_86.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.
    C:UsersNadiaAppDataRoamingplayerimageschannel_ld_99.png (PUP.Optional.VPLMedia.A) -> Mis en quarantaine et supprimé avec succès.

    (fin)

  • nadouche92
    Nombre d'articles : 0

    par contre il y avait que mon disque dur branché lors de la recherche malware, fallait il que jbranche mes clé?

  • Anonyme
    Nombre d'articles : 0

    tt se que g supprimer c t des virus??

    Des adwares.PUP, des logiciels publiciels & indésirable.

    par contre il y avait que mon disque dur branché lors de la recherche malware, fallait il que jbranche mes clé?

    Non c’est Ok pour les clé 😉

    Nous allons éffectuer un diagnostic de ton ordinateur afin de voir si ton pc contient d’autres types d’infection ou pas.

    • Télécharge ZHPDiag (de Nicolas Coolman) sur ton bureau.
    • Installe le logiciel.
    • Lance ZHPDiag, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista

    • Clique sur Configurer
    • Clique sur l’icône représentant une loupe avec un + (« Lancer le diagnostic »)

      Note : Ne pas fermer le programme même si il est indiqué qu’il ne répond plus.

    • Une fois le scan terminé rends toi sur le bureau, le fichier ZHPDiag.txt à été créé.
    • Héberge le rapport ZHPDiag.txt sur SosUpload, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum
  • nadouche92
    Nombre d'articles : 0

    dit moi je comprend pas tous les mots: héberger ça veut dire copie/coller?

  • Anonyme
    Nombre d'articles : 0

    héberger

    Ca veut dire déposer le rapport sur un serveur dans ton cas, car il est souvent trop long pour le copier – coller directement sur le forum.

  • nadouche92
    Nombre d'articles : 0

    j’arrive pas a herberger le rapport quand je fais parcourir il ne voit pas le fichier qu’est ce que dois faire? je le copier sur word et peut l’heberger ou c obligatoirement sur bloc-note? je c pas si je suis clair?

  • nadouche92
    Nombre d'articles : 0

    attend je vais essayer de te le copier ici
    ~ Rapport de ZHPDiag v2013.11.17.37 – Nicolas Coolman (17/11/2013)
    ~ Lancé par Nadia (18/11/2013 11:57:41)
    ~ Adresse du Site Web http://nicolascoolman.webs.com” onclick=”window.open(this.href);return false;
    ~ Forums gratuits d’Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/” onclick=”window.open(this.href);return false;
    ~ Traduit par Nicolas Coolman
    ~ Etat de la version :
    ~ Liste blanche : Activée par le programme
    ~ Elévation des Privilèges : OK
    ~ User Account Control (UAC): Activate by user

    —\ Navigateurs Internet
    MSIE: Internet Explorer v10.0.9200.16736
    MFIE: Mozilla Firefox 25.0.1 (Defaut)
    GCIE: Google Chrome v30.0.1599.101

    —\ Informations sur les produits Windows
    ~ Langage: Français
    Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
    Windows Server License Manager Script : OK
    ~ Windows(R) 7, OEM_SLP channel
    System Locked Preinstallation (OEM_SLP) : OK
    Windows ID Activation : OK
    ~ Windows Partial Key : BWX77
    Windows License : OK
    ~ Windows Remaining Initializations Number : 4
    Software Protection Service (Protection logicielle) : OK
    Windows Automatic Updates : OK
    Windows Activation Technologies : OK

    —\ Logiciels de protection du système
    avast! Free Antivirus v9.0.2006
    Malwarebytes Anti-Malware version 1.75.0.1300
    Windows Defender W7

    —\ Logiciels d’optimisation du système
    CCleaner v4.07 =>Piriform Ltd

    —\ Logiciels de partage PeerToPeer

    —\ Surveillance de Logiciels
    Adobe Flash Player 11 Plugin
    Adobe Reader XI

    —\ Informations sur le système
    ~ Processor: Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
    ~ Operating System: 64 Bits
    Boot mode: Normal (Normal boot)
    Total RAM: 3932 MB (57% free)
    System Restore: Activé (Enable)
    System drive C: has 56 GB (37%) free of 149 GB

    —\ Mode de connexion au système
    ~ Computer Name: NADIA-TOSH
    ~ User Name: Nadia
    ~ All Users Names: Nadia, HomeGroupUser$, Administrateur,
    ~ Unselected Option: None
    Logged in as Administrator

    —\ Variables d’environnement
    ~ System Unit : C:
    ~ %AppZHP% : C:UsersNadiaAppDataRoamingZHP
    ~ %AppData% : C:UsersNadiaAppDataRoaming
    ~ %Desktop% : C:UsersNadiaDesktop
    ~ %Favorites% : C:UsersNadiaFavorites
    ~ %LocalAppData% : C:UsersNadiaAppDataLocal
    ~ %StartMenu% : C:UsersNadiaAppDataRoamingMicrosoftWindowsStart Menu
    ~ %Windir% : C:Windows
    ~ %System% : C:WindowsSystem32

    —\ Enumération des unités disques
    C: Hard drive, Flash drive, Thumb drive (Free 56 Go of 149 Go)
    D: Hard drive, Flash drive, Thumb drive (Free 140 Go of 148 Go)
    E: CD-ROM drive (Not Inserted)
    F: Hard drive, Flash drive, Thumb drive (Free 77 Go of 298 Go)

    —\ Etat du Centre de Sécurité Windows
    [HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorer] NoActiveDesktopChanges: Modified
    ~ Security Center: 46 Legitimates Filtered in 00mn 00s

    —\ Recherche particulière de fichiers génériques
    [MD5.332FEAB1435662FC6C672E25BEB37BE3] – (.Microsoft Corporation – Explorateur Windows.) (.25/02/2011 – 07:19:30.) — C:WindowsExplorer.exe [2871808]
    [MD5.94355C28C1970635A31B3FE52EB7CEBA] – (.Microsoft Corporation – Application de démarrage de Windows.) (.14/07/2009 – 02:39:52.) — C:WindowsSystem32Wininit.exe [129024]
    [MD5.9706C99DAEBE3FEAC811B239617E98C4] – (.Microsoft Corporation – Extensions Internet pour Win32.) (.12/10/2013 – 09:45:20.) — C:WindowsSystem32wininet.dll [2241536]
    [MD5.1151B1BAA6F350B1DB6598E0FEA7C457] – (.Microsoft Corporation – Application d’ouverture de session Windows.) (.20/11/2010 – 14:25:30.) — C:WindowsSystem32Winlogon.exe [390656]
    [MD5.067FA52BFB59A56110A12312EF9AF243] – (.Microsoft Corporation – Bibliothèque de licences.) (.20/11/2010 – 14:27:26.) — C:WindowsSystem32sppcomapi.dll [232448]
    [MD5.79059559E89D06E8B80CE2944BE20228] – (.Microsoft Corporation – Ancillary Function Driver for WinSock.) (.28/09/2013 – 02:09:10.) — C:Windowssystem32DriversAFD.sys [497152]
    [MD5.02062C0B390B7729EDC9E69C680A6F3C] – (.Microsoft Corporation – ATAPI IDE Miniport Driver.) (.14/07/2009 – 02:52:21.) — C:Windowssystem32Driversatapi.sys [24128]
    [MD5.B8BD2BB284668C84865658C77574381A] – (.Microsoft Corporation – CD-ROM File System Driver.) (.14/07/2009 – 00:19:47.) — C:Windowssystem32DriversCdfs.sys [92160]
    [MD5.F036CE71586E93D94DAB220D7BDF4416] – (.Microsoft Corporation – SCSI CD-ROM Driver.) (.20/11/2010 – 10:19:21.) — C:Windowssystem32DriversCdrom.sys [147456]
    [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] – (.Microsoft Corporation – DFS Namespace Client Driver.) (.20/11/2010 – 10:26:32.) — C:Windowssystem32DriversDfsC.sys [102400]
    [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] – (.Microsoft Corporation – High Definition Audio Bus Driver.) (.20/11/2010 – 11:43:43.) — C:Windowssystem32DriversHDAudBus.sys [122368]
    [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] – (.Microsoft Corporation – Pilote de port i8042.) (.14/07/2009 – 00:19:57.) — C:Windowssystem32Driversi8042prt.sys [105472]
    [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] – (.Microsoft Corporation – IP Network Address Translator.) (.14/07/2009 – 01:10:03.) — C:Windowssystem32DriversIpNat.sys [116224]
    [MD5.A5D9106A73DC88564C825D317CAC68AC] – (.Microsoft Corporation – Windows NT SMB Minirdr.) (.27/04/2011 – 03:40:40.) — C:Windowssystem32DriversMRxSmb.sys [158208]
    [MD5.09594D1089C523423B32A4229263F068] – (.Microsoft Corporation – MBT Transport driver.) (.20/11/2010 – 10:23:20.) — C:Windowssystem32DriversnetBT.sys [261632]
    [MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] – (.Microsoft Corporation – Pilote du système de fichiers NT.) (.12/04/2013 – 15:45:08.) — C:Windowssystem32Driversntfs.sys [1656680]
    [MD5.0086431C29C35BE1DBC43F52CC273887] – (.Microsoft Corporation – Pilote de port parallèle.) (.14/07/2009 – 01:00:41.) — C:Windowssystem32DriversParport.sys [97280]
    [MD5.471815800AE33E6F1C32FB1B97C490CA] – (.Microsoft Corporation – RAS L2TP mini-port/call-manager driver.) (.20/11/2010 – 11:52:35.) — C:Windowssystem32DriversRasl2tp.sys [129536]
    [MD5.548260A7B8654E024DC30BF8A7C5BAA4] – (.Microsoft Corporation – SMB Transport driver.) (.14/07/2009 – 01:09:09.) — C:Windowssystem32Driverssmb.sys [93184]
    [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] – (.Microsoft Corporation – TDI Translation Driver.) (.20/11/2010 – 10:21:56.) — C:Windowssystem32Driverstdx.sys [119296]
    [MD5.0D08D2F3B3FF84E433346669B5E0F639] – (.Microsoft Corporation – Pilote de cliché instantané du volume.) (.20/11/2010 – 14:34:02.) — C:Windowssystem32Driversvolsnap.sys [295808]
    ~ Generic Processes: Scanned in 00mn 00s

    —\ Etat des fichiers cachés (Caché/Total)
    ~ Mes musiques (My Musics) : 1/84
    ~ Mes Favoris (My Favorites) : 1/47
    ~ Mes Documents (My Documents) : 1/16
    ~ Mon Bureau (My Desktop) : 1/1005
    ~ Menu demarrer (Programs) : 1/21
    ~ Hidden Files: Scanned in 00mn 02s

    —\ Processus lancés
    [MD5.07322C7B12AF81F00AC248190BBF69BE] – (.Siber Systems – RoboForm TaskBar Icon.) — C:Program Files (x86)Siber SystemsAI RoboFormrobotaskbaricon.exe [100200] [PID.4076]
    [MD5.1FAA54E9FFEA6FD3E0CEAD951CDDFEF6] – (.TOSHIBA CORPORATION – KeNotify MFC Application.) — C:Program Files (x86)TOSHIBAUtilitiesKeNotify.exe [34160] [PID.3268]
    [MD5.86E69581356CA45167EA6986B6E29087] – (.TOSHIBA CORPORATION – ConfigFree Task Tray Menu.) — C:Program Files (x86)TOSHIBAConfigFreeNDSTray.exe [304560] [PID.4232]
    [MD5.8A07221789D46B2EA7DFCA2BC807572A] – (.TOSHIBA CORPORATION – ConfigFree Switch Manager Process.) — C:Program Files (x86)TOSHIBAConfigFreeCFSwMgr.exe [62848] [PID.4368]
    [MD5.A12BAE32D24CB4960266DC8FFC45DE7E] – (.AVAST Software – avast! Antivirus.) — C:Program FilesAVAST SoftwareAvastAvastUI.exe [3568312] [PID.4404]
    [MD5.077D59BA0FD4007E841B6C670862B065] – (.Mozilla Corporation – Firefox.) — C:Program Files (x86)Mozilla Firefoxfirefox.exe [275568] [PID.1252]
    [MD5.D1D5DAB39DCB4BE0359943738D87409B] – (.Malwarebytes Corporation – Malwarebytes Anti-Malware.) — C:Program Files (x86)Malwarebytes’ Anti-Malwarembamgui.exe [532040] [PID.2696]
    [MD5.824512C3EAE3462388B8861986907E28] – (.Nicolas Coolman – ZHPDiag.) — C:Program Files (x86)ZHPDiagZHPDiag.exe [8227328] [PID.2824]
    [MD5.4BE7EC02133544CDE7A580875E130208] – (.AVAST Software – avast! Service.) — C:Program FilesAVAST SoftwareAvastAvastSvc.exe [50344] [PID.1272]
    [MD5.ADDA5E1951B90D3D23C56D3CF0622ADC] – (.Adobe Systems Incorporated – Adobe Acrobat Update Service.) — C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe [65640] [PID.1564]
    [MD5.4FE5C6D40664AE07BE5105874357D2ED] – (.Apple Inc. – MobileDeviceService.) — C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe [57008] [PID.1596]
    [MD5.4DE2EE2A5186D74BABC4E7F60D2AE989] – (.Realsil Microelectronics Inc. – Realtek Card Reader Icon Tool..) — C:Program Files (x86)RealtekRealtek USB 2.0 Card ReaderRIconMan.exe [1811456] [PID.1716]
    [MD5.F67C21CC4195F6AFC447418FE163E156] – (.TeamViewer GmbH – TeamViewer 8.) — C:Program Files (x86)TeamViewerVersion8TeamViewer_Service.exe [5087584] [PID.1864]
    [MD5.506B0B498216371D64ABB69145B70E4C] – (…) — C:Program Files (x86)Tortor.exe [3233806] [PID.2036]
    [MD5.CAB0EEAF5295FC96DDD3E19DCE27E131] – (.TOSHIBA CORPORATION – ConfigFree Service Process.) — C:Program Files (x86)TOSHIBAConfigFreeCFSvcs.exe [46448] [PID.5012]
    [MD5.9D1CCE440552500DED3A62F9D779CDB4] – (.Nero AG – NeroUpdate.) — c:Program Files (x86)NeroUpdateNASvc.exe [503080] [PID.1824]
    [MD5.65085456FD9A74D7F1A999520C299ECB] – (.Malwarebytes Corporation – Malwarebytes Anti-Malware.) — C:Program Files (x86)Malwarebytes’ Anti-Malwarembamscheduler.exe [418376] [PID.3984]
    [MD5.E0D7732F2D2E24B2DB3F67B6750295B8] – (.Malwarebytes Corporation – Malwarebytes Anti-Malware.) — C:Program Files (x86)Malwarebytes’ Anti-Malwarembamservice.exe [701512] [PID.4592]
    ~ Processes Running: Scanned in 00mn 02s

    —\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
    C:UsersNadiaAppDataLocalGoogleChromeUser DataDefaultPreferences
    G2 – GCE: Preference [User DataDefault] [paoponfhfdfnjgddpnpjkambkcgdaaib] uTorrentBar_FR v.10.20.101.5, (Désactivé) =>P2P.µTorrent
    ~ Google Browser: 15 Legitimates Filtered in 00mn 11s

    —\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
    C:UsersNadiaAppDataRoamingMozillaFirefoxProfilesezo9ao19.defaultprefs.js
    ~ Firefox Browser: 7 Legitimates Filtered in 00mn 00s

    —\ Internet Explorer, Proxy Management (R5)
    R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local
    R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = no key
    R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyEnable = 0
    R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,MigrateProxy = 1
    R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,EnableHttp1_1 = 1
    R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,AutoConfigProxy = wininet.dll
    ~ Proxy management: Scanned in 00mn 00s

    —\ Analyse des lignes F0, F1, F2, F3 – IniFiles, Autoloading programs
    F2 – REG:system.ini: USERINIT=C:Windowssystem32userinit.exe,
    F2 – REG:system.ini: Shell=C:Windowsexplorer.exe
    F2 – REG:system.ini: VMApplet=C:WindowsSystem32SystemPropertiesPerformance.exe
    ~ Keys: Scanned in 00mn 00s

    —\ Hosts file redirection (O1)
    ~ Le fichier hosts est sain (The hosts file is clean).
    ~ Hosts File: Scanned in 00mn 00s
    ~ Nombre de lignes (Lines number): 21

    —\ Browser Helper Objects de navigateur (O2)
    O2 – BHO: Adblock Plus for IE Browser Helper Object [64Bits] – {FFCB3198-32F3-4E8B-9539-4324694ED664} . (.Adblock Plus – Adblock Plus Module.) — C:Program FilesAdblock Plus for IEAdblockPlus32.dll
    O2 – BHO: McAfee Phishing Filter [64Bits] – {27B4851A-3207-45A2-B947-BE8AFE6163AB} . (…) — c:progra~1mcafeemskmskapbho.dll (.not file.)
    O2 – BHO: (no name) [64Bits] – {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Clé orpheline
    ~ BHO: 21 Legitimates Filtered in 00mn 00s

    —\ Internet Explorer Toolbars (O3)
    O3 – Toolbar: Google Toolbar [64Bits] – [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. – Google Toolbar.) — C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_32.dll =>Toolbar.Google
    O3 – Toolbar: (no name) [64Bits] – [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Clé orpheline
    O3 – Toolbar: avast! EasyPass Toolbar [64Bits] – [HKLM]{724d43a0-0d85-11d4-9908-00400523e39a} . (.AVAST Software – avast! EasyPass Main Module.) — C:Program Files (x86)Siber SystemsAI RoboFormroboform.dll
    O3 – ToolbarWebBrowser: (no name) [64Bits] – [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
    ~ Toolbar: Scanned in 00mn 00s

    —\ Autres liens utilisateurs (O4)
    O4 – GSDesktop [Public]: Google Chrome.lnk . (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe
    O4 – GSDesktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation – Firefox.) — C:Program Files (x86)Mozilla Firefoxfirefox.exe
    O4 – GSProgram [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation – Firefox.) — C:Program Files (x86)Mozilla Firefoxfirefox.exe
    O4 – GSQuickLaunch [Nadia]: Google Chrome.lnk . (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe
    O4 – GSQuickLaunch [Nadia]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation – Internet Explorer.) — C:Program Files (x86)Internet Exploreriexplore.exe
    O4 – GSTaskBar [Nadia]: Google Chrome.lnk . (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe
    O4 – GSTaskBar [Nadia]: Mozilla Firefox.lnk . (.Mozilla Corporation – Firefox.) — C:Program Files (x86)Mozilla Firefoxfirefox.exe
    O4 – GSSystemTools [Nadia]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation – Internet Explorer.) — C:Program Files (x86)Internet Exploreriexplore.exe
    O4 – GSDesktop [Nadia]: Ordinateur – Raccourci.lnk – Clé orpheline
    O4 – GSDesktop [Nadia]: SosVirus Forum Gratuit.lnk . (.Microsoft Corporation – Internet Explorer.) — C:Program Files (x86)Internet Exploreriexplore.exe https://www.sosvirus.net” onclick=”window.open(this.href);return false;
    O4 – GSDesktop [Nadia]: SosVirus sur Facebook.lnk . (.Microsoft Corporation – Internet Explorer.) — C:Program Files (x86)Internet Exploreriexplore.exe http://www.facebook.com” onclick=”window.open(this.href);return false;
    O4 – GSDesktop [Nadia]: Vidéos freebox.lnk . (…) — \FREEBOXDisque durVidéos
    ~ Global Startup: 69 Legitimates Filtered in 00mn 03s

    —\ Applications lancées au démarrage du sytème (O4)
    O4 – HKLM..Run: [TosNC] C:Program Files (x86)ToshibaBulletinBoardTosNcCore.exe (.not file.)
    O4 – HKLM..Run: [TosReelTimeMonitor] C:Program Files (x86)TOSHIBAReelTimeTosReelTimeMonitor.exe (.not file.)
    O4 – HKLM..Run: [IgfxTray] . (.Intel Corporation – igfxTray Module.) — C:Windowssystem32igfxtray.exe
    O4 – HKLM..Run: [HotKeysCmds] . (.Intel Corporation – hkcmd Module.) — C:Windowssystem32hkcmd.exe
    O4 – HKLM..Run: [Persistence] . (.Intel Corporation – persistence Module.) — C:Windowssystem32igfxpers.exe
    O4 – HKLM..Run: [RtHDVCpl] . (.Realtek Semiconductor – Gestionnaire audio HD Realtek.) — C:Program FilesRealtekAudioHDARAVCpl64.exe =>.Realtek Semiconductor Corp
    O4 – HKLM..Run: [RtHDVBg] . (.Realtek Semiconductor – HD Audio Background Process.) — C:Program FilesRealtekAudioHDARAVBg64.exe
    O4 – HKLM..Run: [TPwrMain] C:Program Files (x86)TOSHIBAPower SaverTPwrMain.exe (.not file.)
    O4 – HKLM..Run: [SmoothView] C:Program Files (x86)ToshibaSmoothViewSmoothView.exe (.not file.)
    O4 – HKLM..Run: [SynTPEnh] C:Program Files (x86)SynapticsSynTPSynTPEnh.exe (.not file.)
    O4 – HKLM..Run: [SmartFaceVWatcher] C:Program Files (x86)ToshibaSmartFaceVSmartFaceVWatcher.exe (.not file.)
    O4 – HKLM..Run: [TosSENotify] . (.TOSHIBA Corporation – Pas de description.) — C:Program FilesTOSHIBATOSHIBA HDD SSD AlertTosWaitSrv.exe
    O4 – HKLM..Run: [TosVolRegulator] . (.TOSHIBA Corporation – Toshiba Volume Regulator.) — C:Program FilesTOSHIBATosVolRegulatorTosVolRegulator.exe =>.Toshiba Corporation
    O4 – HKLM..Run: [iTunesHelper] . (.Microsoft Corporation – Microsoft ® Windows Based Script Host.) — C:WindowsSystem32wscript.exe
    O4 – HKLM..Run: [SergeLeLama] . (.Microsoft Corporation – Microsoft ® Windows Based Script Host.) — C:WindowsSystem32wscript.exe
    O4 – HKCU..Run: [swg] . (.Google Inc. – GoogleToolbarNotifier.) — C:Program Files (x86)GoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe =>Toolbar.Google
    O4 – HKCU..Run: [RoboForm] . (.Siber Systems – RoboForm TaskBar Icon.) — C:Program Files (x86)Siber SystemsAI RoboFormRoboTaskBarIcon.exe
    O4 – HKLM..Wow6432NodeRun: [HWSetup] . (.TOSHIBA Electronics, Inc. – HWSetup.) — C:Program FilesTOSHIBAUtilitiesHWSetup.exe
    O4 – HKLM..Wow6432NodeRun: [SVPWUTIL] . (.TOSHIBA – SVPWUTIL Application.) — C:Program Files (x86)TOSHIBAUtilitiesSVPWUTIL.exe
    O4 – HKLM..Wow6432NodeRun: [KeNotify] . (.TOSHIBA CORPORATION – KeNotify MFC Application.) — C:Program Files (x86)TOSHIBAUtilitiesKeNotify.exe
    O4 – HKLM..Wow6432NodeRun: [ToshibaServiceStation] . (.TOSHIBA Corporation – TOSHIBA Service Station.) — C:Program Files (x86)TOSHIBATOSHIBA Service StationToshibaServiceStation.exe =>.Toshiba Corporation
    O4 – HKLM..Wow6432NodeRun: [Adobe ARM] . (.Adobe Systems Incorporated – Adobe Reader and Acrobat Manager.) — C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe =>.Adobe Systems Incorporated
    O4 – HKLM..Wow6432NodeRun: [AvastUI.exe] . (.AVAST Software – avast! Antivirus.) — C:Program FilesAVAST SoftwareAvastAvastUI.exe
    O4 – HKLM..Wow6432NodeRunOnce: [Malwarebytes Anti-Malware] . (.Malwarebytes Corporation – Malwarebytes Anti-Malware.) — C:Program Files (x86)Malwarebytes’ Anti-Malwarembamgui.exe
    O4 – HKUSS-1-5-18..Run: [TOSHIBA Online Product Information] . (.TOSHIBA – TOSHIBA Online Product Information.) — C:Program Files (x86)TOSHIBATOSHIBA Online Product Informationtopi.exe =>.Toshiba Corporation
    O4 – HKUSS-1-5-19..Run: [Sidebar] . (.Microsoft Corporation – Gadgets du Bureau Windows.) — C:Program Files (x86)Windows SidebarSidebar.exe =>.Microsoft Corporation
    O4 – HKUSS-1-5-20..Run: [Sidebar] . (.Microsoft Corporation – Gadgets du Bureau Windows.) — C:Program Files (x86)Windows SidebarSidebar.exe =>.Microsoft Corporation
    O4 – HKUSS-1-5-18..RunOnce: [SPReview] . (.Microsoft Corporation – SP Reviewer.) — C:WindowsSystem32SPReviewSPReview.exe =>.Microsoft Corporation
    O4 – HKUSS-1-5-19..RunOnce: [mctadmin] . (.Microsoft Corporation – MCTAdmin.) — C:WindowsSystem32mctadmin.exe =>.Microsoft Corporation
    O4 – HKUSS-1-5-20..RunOnce: [mctadmin] . (.Microsoft Corporation – MCTAdmin.) — C:WindowsSystem32mctadmin.exe =>.Microsoft Corporation
    O4 – HKUSS-1-5-21-2945581834-3016043712-3197114360-1001..Run: [swg] . (.Google Inc. – GoogleToolbarNotifier.) — C:Program Files (x86)GoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe =>Toolbar.Google
    O4 – HKUSS-1-5-21-2945581834-3016043712-3197114360-1001..Run: [RoboForm] . (.Siber Systems – RoboForm TaskBar Icon.) — C:Program Files (x86)Siber SystemsAI RoboFormRoboTaskBarIcon.exe
    ~ Application: Scanned in 00mn 00s

    —\ Boutons situés sur la barre d’outils principale d’Internet Explorer (O9)
    O9 – Extra button: &Envoyer à OneNote [64Bits] – {2670000A-7350-4f3c-8081-5663EE0C6C49} — C:Program Files (x86)MICROS~2Office15ONBttnIE.dll (.not file.)
    O9 – Extra button: Cliquer pour appeler Lync [64Bits] – {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} . (.Microsoft Corporation – Microsoft Lync.) — C:Program FilesMicrosoft OfficeOffice15lync.exe
    O9 – Extra button: Remplir les formulaires [64Bits] – {320AF880-6646-11D3-ABEE-C5DBF3571F46} . (.AVAST Software – avast! EasyPass Main Module.) — C:Program Files (x86)Siber SystemsAI RoboFormroboform.dll
    O9 – Extra button: Enregistrer les formulaires [64Bits] – {320AF880-6646-11D3-ABEE-C5DBF3571F49} . (.AVAST Software – avast! EasyPass Main Module.) — C:Program Files (x86)Siber SystemsAI RoboFormroboform.dll
    O9 – Extra button: Barre avast! EasyPass [64Bits] – {724d43aa-0d85-11d4-9908-00400523e39a} . (.AVAST Software – avast! EasyPass Main Module.) — C:Program Files (x86)Siber SystemsAI RoboFormroboform.dll
    O9 – Extra button: Notes &liées OneNote [64Bits] – {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} — C:Program Files (x86)MICROS~2Office15ONBTTN~1.dll (.not file.)
    ~ IE Extra Buttons: Scanned in 00mn 00s

    —\ Modification Domaine/Adresses DNS (O17)
    O17 – HKLMSystemCCSServicesTcpip..{3CBE77E5-1AFD-41A4-912A-D72F32C997FC}: DhcpNameServer = 192.168.1.254
    O17 – HKLMSystemCCSServicesTcpip..{690DB7D7-44A1-47F6-9621-861436D7D04A}: DhcpNameServer = 192.168.1.254
    O17 – HKLMSystemCS1ServicesTcpip..{3CBE77E5-1AFD-41A4-912A-D72F32C997FC}: DhcpNameServer = 192.168.1.254
    O17 – HKLMSystemCS1ServicesTcpip..{690DB7D7-44A1-47F6-9621-861436D7D04A}: DhcpNameServer = 192.168.1.254
    O17 – HKLMSystemCS2ServicesTcpip..{3CBE77E5-1AFD-41A4-912A-D72F32C997FC}: DhcpNameServer = 192.168.1.254
    O17 – HKLMSystemCS2ServicesTcpip..{690DB7D7-44A1-47F6-9621-861436D7D04A}: DhcpNameServer = 192.168.1.254
    O17 – HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 192.168.1.254
    ~ Domain: Scanned in 00mn 00s

    —\ Protocole additionnel (O18)
    O18 – Handler: wlpg [64Bits] – {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (…) —
    O18 – Filter: text/xml [64Bits] – {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation – Microsoft Office XML MIME Filter.) — C:Program FilesCommon FilesMicrosoft SharedOFFICE15MSOXMLMF.dll =>.Microsoft Corporation
    ~ Protocole Additionnel: Scanned in 00mn 00s

    —\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
    O20 – Winlogon Notify: igfxcui . (.Intel Corporation – igfxdev Module.) — C:WindowsSystem32igfxdev.dll
    ~ Winlogon: Scanned in 00mn 00s

    —\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
    O20 – AppInit_DLLs: . (…) – c:progra~3bitguard271769~1.27{c16c1~1loader.dll (.not file.) =>PUP.BitGuard
    ~ AppInit DLL: Scanned in 00mn 00s

    —\ Liste des services NT non Microsoft et non désactivés (O23)
    O23 – Service: Tor Win32 Service (tor) . (…) – C:Program Files (x86)Tortor.exe
    O23 – Service: TOSHIBA Power Saver (TosCoSrv) . (.TOSHIBA Corporation – TOSHIBA Power Saver.) – C:Program FilesTOSHIBAPower SaverTosCoSrv.exe
    ~ Services: 16 Legitimates Filtered in 00mn 12s

    —\ Tâches planifiées en automatique (O39)
    [MD5.D4F602B1F775B5827932D3C5B04A3FD2] [APT] [AutoKMS] (…) — C:WindowsAutoKMSAutoKMS.exe [3372032] =>Trojan.Keygen
    [MD5.00000000000000000000000000000000] [APT] [Updater19962.exe] (…) — C:UsersNadiaAppDataLocalUpdater19962Updater19962.exe (.not file.) [0] =>PUP.CrossRider
    [MD5.00000000000000000000000000000000] [APT] [{F615774C-9B19-43C8-B2AF-D280FEBC64C0}] (…) — C:Program Files (x86)InstallShield Installation Information{5E6F6CF3-BACC-4144-868C-E14622C658F3}setup.exe (.not file.) [0]
    ~ Scheduled Task: 18 Legitimates Filtered in 00mn 06s

    —\ HKCU & HKLM Software Keys
    [HKLMSoftwareSergeLeLama]
    ~ Key Software: 182 Legitimates Filtered in 00mn 00s

    —\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
    O44 – LFC:[MD5.04583E2BAAB18EE73C85F417AD7D8CA7] – 11/11/2013 – 18:38:47 —A- . (…) — C:Windowsvbaddin.ini [13]
    O44 – LFC:[MD5.9DA0D0278B74C2EAED053B836C4E552C] – 17/11/2013 – 20:38:52


    . (…) — C:UsbFix [Scan 1] NADIA-TOSH.txt [16183]
    O44 – LFC:[MD5.1F4FC90C5DF353A9A69EF9872F7F19FD] – 17/11/2013 – 21:21:46


    . (…) — C:UsbFix [Clean 3] NADIA-TOSH.txt [12861]
    O44 – LFC:[MD5.A5C2F9BA6722DB1CB03F0202A87C6143] – 17/11/2013 – 21:58:43


    . (…) — C:UsbFix [Scan 2] NADIA-TOSH.txt [11259]
    O44 – LFC:[MD5.AEA2C834E364BED58A1808F16C47A0F0] – 17/11/2013 – 22:03:07


    . (…) — C:UsbFix [Clean 5] NADIA-TOSH.txt [15002]
    O44 – LFC:[MD5.0023EFEF3293306C4B6762F11977E94E] – 17/11/2013 – 22:12:47


    . (…) — C:UsbFix [Scan 3] NADIA-TOSH.txt [13825]
    O44 – LFC:[MD5.1F26922E30E21274BFAA99AC37F8021E] – 17/11/2013 – 22:18:27


    . (…) — C:UsbFix [Clean 7] NADIA-TOSH.txt [22258]
    O44 – LFC:[MD5.9D80BAE9374EE3078891E1EFD8405C47] – 17/11/2013 – 22:26:20


    . (…) — C:UsbFix [Scan 4] NADIA-TOSH.txt [6284]
    O44 – LFC:[MD5.5177D99F4A65DE182185EDFA50D47237] – 17/11/2013 – 22:28:40


    . (…) — C:UsbFix [Clean 9] NADIA-TOSH.txt [12790]
    O44 – LFC:[MD5.95D2CF5C682F1D3800DD77B437D52527] – 17/11/2013 – 22:36:22


    . (…) — C:UsbFix [Clean 10] NADIA-TOSH.txt [15471]
    O44 – LFC:[MD5.38D52FB9F0703D7CBBA1F88D6A184412] – 17/11/2013 – 23:02:37


    . (…) — C:UsbFix [Scan 5] NADIA-TOSH.txt [6027]
    O44 – LFC:[MD5.45567AB4059C04902816813F89393325] – 17/11/2013 – 23:05:18


    . (…) — C:UsbFix [Clean 11] NADIA-TOSH.txt [8621]
    O44 – LFC:[MD5.31B2A4D3D175AB430AE209F7AE0286A1] – 18/11/2013 – 09:37:25 —A- . (…) — C:Windowswin.ini [499]
    O44 – LFC:[MD5.3DB047FAFDAE124930E3DF14EF7B5D74] – 18/11/2013 – 10:29:49


    . (…) — C:UsbFix [Scan 6] NADIA-TOSH.txt [10100]
    O44 – LFC:[MD5.F32E3F62D2D4AF603E4ACA37835E77E5] – 18/11/2013 – 10:36:15 —A- . (…) — C:UsbFix [Clean 12] NADIA-TOSH.txt [15766]
    ~ Files: 112 Legitimates Filtered in 00mn 38s

    —\ Derniers fichiers créés dans Windows Prefetcher (O45)
    O45 – LFCP:[MD5.307683270C2373B0C321DC06AE2C22B4] – 18/11/2013 – 11:08:30 —A- – C:WindowsPrefetchGO.EXE-0A7DE786.pf
    O45 – LFCP:[MD5.C75BE3B6455AE4E2E7DA6F4B1E12FDD1] – 18/11/2013 – 11:17:37 —A- – C:WindowsPrefetchROBOTASKBARICON.EXE-20C79AF5.pf
    ~ Prefetcher: 83 Legitimates Filtered in 00mn 00s

    —\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
    O55 – MWPS:[HKLM…PoliciesSystem] – “EnableUIADesktopToggle”=0
    O55 – MWPS:[HKLM…PoliciesSystem] – “PromptOnSecureDesktop”=0
    O55 – MWPS:[HKLM…PoliciesSystem] – “FilterAdministratorToken”=0
    O55 – MWPS:[HKLM…PoliciesSystem] – “EnableLinkedConnections”=1
    ~ MWPS: 17 Legitimates Filtered in 00mn 00s

    —\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
    O56 – MWPE:[HKLM…policiesExplorer] – “NoActiveDesktopChanges”=1
    ~ MWPE Keys: 3 Legitimates Filtered in 00mn 00s

    —\ Liste des pilotes du système (SDL) (O58)
    O58 – SDL:[MD5.C04F7B373881009D7994D9BF55D24AB4] – 11/11/2013 – 18:57:54 —A- . (…) — C:WindowsSystem32DriversaswRvrt.sys [65776]
    ~ Drivers: 17 Legitimates Filtered in 00mn 00s

    —\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
    O61 – LFC: 17/11/2013 – 11:59:44 —A- . (…) — C:UsersNadiaAppDataLocalMozillaupdatesE7CF176E110C211Bactive-update.xml [57]
    O61 – LFC: 17/11/2013 – 11:59:44 —A- . (…) — C:UsersNadiaAppDataLocalMozillaupdatesE7CF176E110C211Bupdates.xml [1517]
    O61 – LFC: 17/11/2013 – 11:59:49 —A- . (…) — C:UsersNadiaAppDataRoamingMicrosoftTemplatesNormal.dotm [17871]
    O61 – LFC: 17/11/2013 – 11:59:53 —A- . (…) — C:UsersNadiaDocumentsMy Avast EasyPass DataDefault Profilecache.rfo [14]
    O61 – LFC: 17/11/2013 – 11:59:53 —A- . (…) — C:UsersNadiaDocumentsMy Avast EasyPass DataDefault Profilelicense.rfo [96]
    O61 – LFC: 17/11/2013 – 11:59:53 —A- . (…) — C:UsersNadiaDocumentsMy Avast EasyPass DataDefault Profilemru.rfo [63]
    O61 – LFC: 17/11/2013 – 11:59:53 —A- . (…) — C:UsersNadiaDocumentsusbfix rapport.txt [16183]
    O61 – LFC: 18/11/2013 – 11:59:37 —A- . (…) — C:UsersNadiaAppDataLocalGoogleChromeUser DataCertificate Revocation Lists [263418]
    O61 – LFC: 18/11/2013 – 11:59:42 —A- . (…) — C:UsersNadiaAppDataLocalGoogleChromeUser DataLocal State [46134]
    O61 – LFC: 18/11/2013 – 11:59:42 —A- . (…) — C:UsersNadiaAppDataLocalGoogleChromeUser Datafr-FR-3-0.bdic [1074744]
    O61 – LFC: 18/11/2013 – 11:59:53 —A- . (…) — C:UsersNadiaAppDataRoamingZHPLog.txt [22542] =>.Nicolas Coolman
    O61 – LFC: 18/11/2013 – 11:59:53 —A- . (…) — C:UsersNadiaAppDataRoamingZHPTestsZHPDiag.txt [2861] =>.Nicolas Coolman
    O61 – LFC: 18/11/2013 – 11:59:53 —A- . (…) — C:UsersNadiaDocumentsMy Avast EasyPass DataDefault Profileoptions.rfo [552]
    O61 – LFC: 18/11/2013 – 11:59:53 —A- . (…) — C:UsersNadiaDownloadsadwcleaner.exe [1085542]
    ~ 1 Fichiers temporaires (Temporary files)
    ~ Files: 127 Legitimates Filtered in 00mn 17s

    —\ Liste des outils de désinfection (LATC) (O63)
    O63 – Logiciel: UsbFix By El Desaparecido – (.El Desaparecido – http://www.usbfix.net.) [HKLM] — Usbfix
    O63 – Logiciel: ZHPDiag 2013 – (.Nicolas Coolman.) [HKLM] — ZHPDiag_is1 =>.Nicolas Coolman
    ~ ADS: Scanned in 00mn 00s

    —\ Menu de démarrage Internet (SMI) (O68)
    O68 – StartMenuInternet: [HKLM..ShellopenCommand] (.Mozilla Corporation – Firefox.) — C:Program Files (x86)Mozilla Firefoxfirefox.exe
    O68 – StartMenuInternet: [HKLM..ShellopenCommand] (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe
    O68 – StartMenuInternet: [HKLM..ShellopenCommand] (.Microsoft Corporation – Internet Explorer.) — C:Program FilesInternet Exploreriexplore.exe
    O68 – StartMenuInternet: [HKLM..ShellopenCommand] (…) — C:Program Files (x86)OperaOpera.exe (.not file.)
    ~ Keys: Scanned in 00mn 00s

    —\ Recherche d’infection sur les navigateurs internet (SBI) (O69)
    O69 – SBI: SearchScopes [HKCU] {0645124B-D4B6-4D92-A067-42291E184AC2} – (eBay) – http://rover.ebay.com” onclick=”window.open(this.href);return false; =>Toolbar.eBay
    O69 – SBI: SearchScopes [HKCU] {380B0270-B697-4A6E-B099-9FAF49B78FBC} – (Google) – http://www.google.com” onclick=”window.open(this.href);return false;
    O69 – SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} – (Google) – http://www.google.com” onclick=”window.open(this.href);return false;
    O69 – SBI: SearchScopes [HKCU] {BDCF80F9-36B8-4930-8FAA-DDDDE251315F} – (uTorrentBar_FR Customized Web Search) – http://search.conduit.com” onclick=”window.open(this.href);return false; =>P2P.µTorrent
    ~ Keys: Scanned in 00mn 00s

    —\ Recherche particulière à la racine du système (SPRF) (O84)
    [MD5.378189889438568FEF3D98588283B3A5] [SPRF][11/11/2013] (…) — C:UsersNadiaAppDataLocalTempQuarantine.exe [350377]
    ~ Files: 1 Legitimates Filtered in 00mn 00s

    —\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
    [MD5.41EB61D8D9A936DDDCF51B064A081881] [WIS][18/09/2012] (.Skype Technologies S.A. – Skype.) — C:WindowsInstaller42c386.msi [19337216]
    ~ WIS: 133 Legitimates Filtered in 00mn 05s

    —\ Etat général des services not Microsoft (EGS) (SR=Running, SS=Stopped)
    SR – | Auto 05/09/2013 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) – C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe
    SR – | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) – C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe
    SR – | Auto 11/11/2013 50344 | (avast! Antivirus) . (.AVAST Software.) – C:Program FilesAVAST SoftwareAvastAvastSvc.exe
    SR – | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) – C:Program FilesBonjourmDNSResponder.exe
    SR – | Auto 28/01/2010 249200 | (cfWiMAXService) . (.TOSHIBA CORPORATION.) – C:Program Files (x86)TOSHIBAConfigFreeCFIWmxSvcs64.exe
    SR – | Auto 10/03/2009 46448 | (ConfigFree Service) . (.TOSHIBA CORPORATION.) – C:Program Files (x86)TOSHIBAConfigFreeCFSvcs.exe
    SS – | Demand 28/07/2010 246520 | (GameConsoleService) . (.WildTangent, Inc..) – C:Program Files (x86)TOSHIBA GamesTOSHIBA Game ConsoleGameConsoleService.exe
    SS – | Auto 04/09/2012 116648 | (gupdate) . (.Google Inc..) – C:Program Files (x86)GoogleUpdateGoogleUpdate.exe
    SS – | Demand 04/09/2012 116648 | (gupdatem) . (.Google Inc..) – C:Program Files (x86)GoogleUpdateGoogleUpdate.exe
    SS – | Demand 04/09/2012 194032 | (gusvc) . (.Google.) – C:Program Files (x86)GoogleCommonGoogle UpdaterGoogleUpdaterService.exe
    SR – | Auto 27/08/2010 1811456 | (IconMan_R) . (.Realsil Microelectronics Inc..) – C:Program Files (x86)RealtekRealtek USB 2.0 Card ReaderRIconMan.exe
    SS – | Demand 20/02/2013 641352 | (iPod Service) . (.Apple Inc..) – C:Program FilesiPodbiniPodService.exe
    SR – | Auto 04/04/2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) – C:Program Files (x86)Malwarebytes’ Anti-Malwarembamscheduler.exe
    SR – | Auto 04/04/2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) – C:Program Files (x86)Malwarebytes’ Anti-Malwarembamservice.exe
    SS – | Demand 17/11/2013 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) – C:Program Files (x86)Mozilla Maintenance Servicemaintenanceservice.exe
    SR – | Auto 04/05/2010 503080 | (NAUpdate) . (.Nero AG.) – c:Program Files (x86)NeroUpdateNASvc.exe
    SS – | Auto 13/07/2012 160944 | (SkypeUpdate) . (.Skype Technologies.) – C:Program Files (x86)SkypeUpdaterUpdater.exe
    SR – | Auto 01/10/2013 5087584 | (TeamViewer8) . (.TeamViewer GmbH.) – C:Program Files (x86)TeamViewerVersion8TeamViewer_Service.exe
    SS – | Demand 11/05/2010 124368 | (TemproMonitoringService) . (.Toshiba Europe GmbH.) – C:Program Files (x86)Toshiba TEMPROTemproSvc.exe =>.Toshiba Corporation
    SR – | Demand 06/10/2009 51512 | (TMachInfo) . (.TOSHIBA Corporation.) – C:Program Files (x86)TOSHIBATOSHIBA Service StationTMachInfo.exe =>.Toshiba Corporation
    SR – | Auto 28/07/2009 140632 | (TODDSrv) . (.TOSHIBA Corporation.) – C:Windowssystem32TODDSrv.exe
    SR – | Auto 06/09/2013 3233806 | (tor) . (…) – C:Program Files (x86)Tortor.exe
    SR – | Auto 28/09/2010 489384 | (TosCoSrv) . (.TOSHIBA Corporation.) – C:Program FilesTOSHIBAPower SaverTosCoSrv.exe
    SR – | Demand 05/02/2010 137560 | (TOSHIBA HDD SSD Alert Service) . (.TOSHIBA Corporation.) – C:Program FilesTOSHIBATOSHIBA HDD SSD AlertTosSmartSrv.exe
    SR – | Auto 14/07/2009 27136 | C:Program Files (x86)Windows Defendermpsvc.dll (WinDefend) . (.Microsoft Corporation.) – C:WindowsSystem32svchost.exe
    SR – | Auto 10/07/1658 0 | (WMPNetworkSvc) . (…) – C:Program Files (x86)Windows Media Playerwmpnetwk.exe =>.Microsoft Corporation
    SR – | Auto 14/07/2009 27136 | C:WindowsSystem32wuaueng.dll (wuauserv) . (.Microsoft Corporation.) – C:WindowsSystem32svchost.exe
    ~ Services: Scanned in 00mn 07s

    —\ Recherche d’infection sur le Master Boot Record (MBR)(O80)
    Run by Nadia at 18/11/2013 12:00:44
    ~ OS 64 not supported by MBR tool
    ~ MBR: 0 Legitimates Filtered in 00mn 00s

    —\ Recherche d’infection sur le Master Boot Record (MBRCheck)(O80)
    Written by ad13, http://ad13.geekstog” onclick=”window.open(this.href);return false;
    Run by Nadia at 18/11/2013 12:00:46

    ********* Dump file Name *********
    C:PhysicalDisk0_MBR.bin
    ~ MBR: Scanned in 00mn 02s

    —\ Scan Additionnel (O88)
    Database Version : 12996 – (17/11/2013)
    Clés trouvées (Keys found) : 13
    Valeurs trouvées (Values found) : 2
    Dossiers trouvés (Folders found) : 1
    Fichiers trouvés (Files found) : 1

    [HKLMSoftwareGoogleChromeExtensionspaoponfhfdfnjgddpnpjkambkcgdaaib] =>P2P.µTorrent^
    [HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E}] =>Toolbar.Conduit
    [HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{D6533F74-218B-41BE-9D91-5BD471FECFFD}] =>Toolbar.Conduit
    [HKCUSoftwareAppDataLowSoftwareuTorrentBar_FR] =>Toolbar.Conduit
    [HKLMSoftwareWow6432NodeMicrosoftWindowsCurrentVersionUninstall{FDE58148-57E7-43BF-879A-29CCE818C078}] =>Toolbar.eBay
    [HKLMSoftwareWow6432NodeMicrosoftTracingBingBar_RASAPI32] =>Toolbar.Bing
    [HKLMSoftwareClassesInstallerFeatures84185EDF7E75FB3478A992CC8E810C87] =>Toolbar.eBay
    [HKLMSoftwareClassesInstallerProducts84185EDF7E75FB3478A992CC8E810C87] =>Toolbar.eBay
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Products84185EDF7E75FB3478A992CC8E810C87] =>Toolbar.eBay
    [HKLMSoftwareWow6432NodeClassesInstallerFeatures84185EDF7E75FB3478A992CC8E810C87] =>Toolbar.eBay
    [HKLMSoftwareWow6432NodeClassesInstallerProducts84185EDF7E75FB3478A992CC8E810C87] =>Toolbar.eBay
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ProductsC776EBEBCBCFBE408892EE7B12517FC] =>PUP.VAFPlayer
    [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsC776EBEBCBCFBE408892EE7B12517FC] =>PUP.VAFPlayer
    [HKLMSoftwareMicrosoftInternet ExplorerToolbar]:{2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google^
    [HKCUSOFTWAREMicrosoftWindowsCurrentVersionRun]:swg =>Toolbar.Google^
    C:UsersNadiaAppDataLocalGoogleChromeUser DataDefaultExtensionspaoponfhfdfnjgddpnpjkambkcgdaaib =>P2P.µTorrent^
    C:WindowsAutoKMSAutoKMS.exe =>Trojan.Keygen^
    ~ Additionnel Scan: 294459 Items scanned in 00mn 36s

    —\ Récapitulatif des détections trouvées sur votre station
    ~ http://nicolascoolman.webs.com/apps/blog/show/32979753-pup-bitguard” onclick=”window.open(this.href);return false; =>PUP.BitGuard
    ~ http://nicolascoolman.webs.com/apps/blog/show/27583526-pup-crossrider” onclick=”window.open(this.href);return false; =>PUP.CrossRider
    ~ http://nicolascoolman.webs.com/apps/blog/show/29507721-toolbar-conduit” onclick=”window.open(this.href);return false; =>Toolbar.Conduit
    ~ http://nicolascoolman.webs.com/apps/blog/show/30392620-pup-vafplayer” onclick=”window.open(this.href);return false; =>PUP.VAFPlayer
    ~ MSI: 4 link(s) detected in 00mn 36s

    ~ 1410 Legitimates filtered by white list
    End of the scan (508 lines in 03mn 42s)(0)

  • Anonyme
    Nombre d'articles : 0

    T’as de la chance, il est passé en entier 🙂

    • Séléctionne et copie le script suivant :

      Script ZHPFix
      O2 - BHO: McAfee Phishing Filter [64Bits] - {27B4851A-3207-45A2-B947-BE8AFE6163AB} . (...) -- c:progra~1mcafeemskmskapbho.dll (.not file.)
      O2 - BHO: (no name) [64Bits] - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Clé orpheline
      O3 - Toolbar: (no name) [64Bits] - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Clé orpheline
      O3 - ToolbarWebBrowser: (no name) [64Bits] - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
      O4 - HKLM..Run: [TosNC] C:Program Files (x86)ToshibaBulletinBoardTosNcCore.exe (.not file.)
      O4 - HKLM..Run: [TosReelTimeMonitor] C:Program Files (x86)TOSHIBAReelTimeTosReelTimeMonitor.exe (.not file.)
      O4 - HKLM..Run: [TPwrMain] C:Program Files (x86)TOSHIBAPower SaverTPwrMain.exe (.not file.)
      O4 - HKLM..Run: [SmoothView] C:Program Files (x86)ToshibaSmoothViewSmoothView.exe (.not file.)
      O4 - HKLM..Run: [SynTPEnh] C:Program Files (x86)SynapticsSynTPSynTPEnh.exe (.not file.)
      O4 - HKLM..Run: [SmartFaceVWatcher] C:Program Files (x86)ToshibaSmartFaceVSmartFaceVWatcher.exe (.not file.)
      [MD5.00000000000000000000000000000000] [APT] [Updater19962.exe] (...) -- C:UsersNadiaAppDataLocalUpdater19962Updater19962.exe (.not file.) [0] =>PUP.CrossRider
      [MD5.00000000000000000000000000000000] [APT] [{F615774C-9B19-43C8-B2AF-D280FEBC64C0}] (...) -- C:Program Files (x86)InstallShield Installation Information{5E6F6CF3-BACC-4144-868C-E14622C658F3}setup.exe (.not file.) [0]
      O56 - MWPE:[HKLM...policiesExplorer] - "NoActiveDesktopChanges"=1
      O69 - SBI: SearchScopes [HKCU] {BDCF80F9-36B8-4930-8FAA-DDDDE251315F} - (uTorrentBar_FR Customized Web Search) - http://search.conduit.com =>P2P.µTorrent
      [HKLMSoftwareGoogleChromeExtensionspaoponfhfdfnjgddpnpjkambkcgdaaib] =>P2P.µTorrent^
      [HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E}] =>Toolbar.Conduit
      [HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{D6533F74-218B-41BE-9D91-5BD471FECFFD}] =>Toolbar.Conduit
      [HKCUSoftwareAppDataLowSoftwareuTorrentBar_FR] =>Toolbar.Conduit
      [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ProductsC776EBEBCBCFBE408892EE7B12517FC] =>PUP.VAFPlayer
      [HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsC776EBEBCBCFBE408892EE7B12517FC] =>PUP.VAFPlayer
      C:UsersNadiaAppDataLocalGoogleChromeUser DataDefaultExtensionspaoponfhfdfnjgddpnpjkambkcgdaaib =>P2P.µTorrent^
      O20 - AppInit_DLLs: . (...) - c:progra~3bitguard271769~1.27{c16c1~1loader.dll (.not file.) =>PUP.BitGuard
      EmptyCLSID
      Emptytemp
      EmptyFlash
      ShortcutFix
    • Lances ZHPFix, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista

      1. Clique sur Importer
      2. Les lignes précedemment copiées doivent être collées dans le cadre
      3. Si c’est le cas, Clic sur “GO

    • Confirmes les nettoyages des données en cliquant sur “Oui
    • Une fois le scan terminé rends toi sur le bureau, le fichier ZHPFixReport à été crée.
    • Héberge le rapport ZHPFixReport sur SosUpload, puis copie/colle le lien fourni dans ta prochaine réponse.
  • nadouche92
    Nombre d'articles : 0

    sa passe pas sur sosupload donc le voici:
    Rapport de ZHPFix 2013.11.14.5 par Nicolas Coolman, Update du 14/11/2013
    Fichier d’export Registre :
    Run by Nadia at 18/11/2013 12:27:21
    High Elevated Privileges : OK
    Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)

    Corbeille vidée (00mn 05s)
    Réparation des raccourcis navigateur

    ========== Clés du Registre ==========
    SUPPRIMÉ: CLSID BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB}
    SUPPRIMÉ: [HKLMSOFTWAREClassesCLSID{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
    SUPPRIMÉ: [HKLMSOFTWAREClassesCLSID{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
    SUPPRIMÉ: SearchScopes :{BDCF80F9-36B8-4930-8FAA-DDDDE251315F}
    SUPPRIMÉ: HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E}
    SUPPRIMÉ: HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{D6533F74-218B-41BE-9D91-5BD471FECFFD}
    SUPPRIMÉ: HKCUSoftwareAppDataLowSoftwareuTorrentBar_FR
    SUPPRIMÉ:* HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ProductsC776EBEBCBCFBE408892EE7B12517FC
    SUPPRIMÉ:* HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsC776EBEBCBCFBE408892EE7B12517FC

    ========== Valeurs du Registre ==========
    SUPPRIMÉ: Toolbar: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5}
    SUPPRIMÉ: Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F}
    SUPPRIMÉ RunValue: TosNC
    SUPPRIMÉ RunValue: TosReelTimeMonitor
    SUPPRIMÉ RunValue: TPwrMain
    SUPPRIMÉ RunValue: SmoothView
    SUPPRIMÉ RunValue: SynTPEnh
    SUPPRIMÉ RunValue: SmartFaceVWatcher
    SUPPRIMÉ MWPE Value: NoActiveDesktopChanges

    ========== Eléments de donnée du Registre ==========
    SUPPRIMÉ AppInit: progra~3bitguard271769~1.27{c16c1~1loader.dll

    ========== Dossiers ==========
    Aucun dossiers CLSID Local utilisateur vide
    SUPPRIMÉS Temporaires Windows (14)
    SUPPRIMÉS Flash Cookies (0)

    ========== Fichiers ==========
    SUPPRIMÉS Temporaires Windows (14) (6 163 007 octets)
    SUPPRIMÉS Flash Cookies (0) (0 octets)

    ========== Tache planifiée ==========
    SUPPRIMÉ: Updater19962.exe
    SUPPRIMÉ: {F615774C-9B19-43C8-B2AF-D280FEBC64C0}

    ========== Récapitulatif ==========
    9 : Clés du Registre
    9 : Valeurs du Registre
    1 : Eléments de donnée du Registre
    3 : Dossiers
    2 : Fichiers
    2 : Tache planifiée

    End of clean in 00mn 14s

    ========== Chemin de fichier rapport ==========
    C:UsersNadiaAppDataRoamingZHPZHPFix[R1].txt – 18/11/2013 12:27:27 [2344]

  • Anonyme
    Nombre d'articles : 0

    Ok, on termine , comment va ton pc ?

    • Télécharge SFTGC (de Pierre13) sur ton Bureau et pas ailleurs !.
    • Lance SFTGC, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista
    • Clique sur GO

      Note : A la fin un rapport va s’ouvrir

    • Une fois le scan terminé rends toi sur le bureau, le fichier SFTGC.txt à été créé.
    • Héberge le rapport SFTGC.txt sur SosUpload, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum
  • nadouche92
    Nombre d'articles : 0

    me dis pas qu’il faudra ke je refasse tt ca sur mon autre pc???

    Rapport de SFTGC (Pierre13) du Lundi 18 Novembre 2013 à 12:36:23 version : 2.0.0.55
    Mis à jour le 12/09/2013
    Outil lancé en Mode normal et En tant qu’administrateur
    Windows 7 Home Premium Service Pack 1 64 bits

    Tool start in C:UsersNadiaDownloads

    505 éléments supprimés => 124.17 Mo libérés. (47 s)

    C:UsersNadiaAppDataLocalTempacro_rd_dir
    C:UsersNadiaAppDataLocalTempNadia NBAgent.nji
    C:UsersNadiaAppDataLocalTempplugtmp
    C:UsersNadiaAppDataLocalTemp{3378b390-7570-4528-8b36-6c85f690f897}
    C:UsersNadiaAppDataLocalLowAdblock Plus for IE
    C:UsersNadiaAppDataLocalLowTempLogs
    C:UsersNadiaAppDataLocalLowSiber SystemsRoboFormUserData
    C:UsersNadiaAppDataLocalLowSiber SystemsRoboFormUserDatacache.rfo
    C:UsersNadiaAppDataLocalLowSiber SystemsRoboFormUserDatalicense.rfo
    C:UsersNadiaAppDataLocalLowSiber SystemsRoboFormUserDatamru.rfo
    C:UsersNadiaAppDataLocalLowSiber SystemsRoboFormUserDataoptions.rfo
    C:UsersNadiaAppDataLocalLowSiber SystemsRoboFormUserDataRoboFormDataHere.txt
    C:UsersNadiaAppDataLocalLowMicrosoftIME12
    C:UsersNadiaAppDataLocalLowMicrosoftIMJP12
    C:UsersNadiaAppDataLocalLowMicrosoftIMJP8_1
    C:UsersNadiaAppDataLocalLowMicrosoftIMJP9_0
    C:UsersNadiaAppDataLocalMicrosoftWindowsHistorydesktop.ini
    C:UsersNadiaAppDataLocalMicrosoftWindowsHistoryLowdesktop.ini
    C:UsersNadiaAppDataLocalMicrosoftWindowsHistoryLowHistory.IE5
    C:UsersNadiaAppDataLocalMicrosoftWindowsHistoryLowHistory.IE5desktop.ini
    C:UsersNadiaAppDataLocalMicrosoftWindowsHistoryHistory.IE5container.dat
    C:UsersNadiaAppDataLocalMicrosoftWindowsHistoryHistory.IE5desktop.ini
    C:UsersNadiaAppDataLocalMicrosoftWindowsHistoryHistory.IE5MSHist012013111120131118
    C:UsersNadiaAppDataLocalMicrosoftWindowsHistoryHistory.IE5MSHist012013111820131119
    C:UsersNadiaAppDataLocalMicrosoftWindowsHistoryHistory.IE5MSHist012013111820131119container.dat
    C:UsersNadiaAppDataLocalMicrosoftWindowsHistoryHistory.IE5MSHist012013111120131118container.dat
    C:UsersNadiaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.MSO
    C:UsersNadiaAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.Word
    C:UsersNadiaAppDataLocalMicrosoftWindowsTemporary Internet FilesSqm
    C:UsersNadiaAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCUsersNadiaAppDataRoamingMicrosoftWindowsPrivacIELow
    C:UsersNadiaAppDataLocalMicrosoftWindowsTemporary Internet FilesVirtualizedCUsersNadiaAppDataRoamingMacromediaFlash Player#SharedObjects7E8M5X4Xsupremesa-a.akamaihd.netitemse6a00storage.swf
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentAutomaticDestinations
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentAziz.lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentCustomDestinations
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentdesktop.ini
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentdicredico.lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentDocuments.lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentdroit des usagers.lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentImane BOURASS.lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentjec oct 2013.lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentlettre direction.lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentMaude.lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentNADIA ASH 4 (F).lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentNADIA CHANS (F).lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentSAM_0236.lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentusbfix rapport.lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentUsbFix [Clean 3] NADIA-TOSH.lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentWINDOWS (C).lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentZHPDiag.lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentZHPFixReport.lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentécrit.lnk
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentCustomDestinations16ec093b8f51508f.customDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentCustomDestinations28c8b86deab549a1.customDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentCustomDestinations337ed59af273c758.customDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentCustomDestinations5473d7b19198511f.customDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentCustomDestinations5afe4de1b92fc382.customDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentCustomDestinations5d696d521de238c3.customDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentCustomDestinations74d7f43c1561fc1e.customDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentCustomDestinations81BCHR2BVGNPRN91WFKA.temp
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentCustomDestinations83b03b46dcd30a0e.customDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentCustomDestinations969252ce11249fdd.customDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentCustomDestinationsc68f1b2d5666494d.customDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentCustomDestinationsccc0fa1b9f86f7b3.customDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentAutomaticDestinations146b792ff47a0f72.automaticDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentAutomaticDestinations16ec093b8f51508f.automaticDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentAutomaticDestinations1b4dd67f29cb1962.automaticDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentAutomaticDestinations47bb2136fda3f1ed.automaticDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentAutomaticDestinations7e4dca80246863e3.automaticDestinations-ms
    C:UsersNadiaAppDataRoamingMicrosoftWindowsRecentAutomaticDestinations9b9cdc69c1c24e2b.automaticDestinations-ms
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData30DBCEADC67EA14BE9A74D5A32FAF83
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData4AFA8793E5CDC4A81C6CD4554A30707
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData130ADF60D1B7B3CF82CC6CA82D961601_12C50190AA5922E6D711F2DEE84C1EB9
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData130ADF60D1B7B3CF82CC6CA82D961601_2FFE778CED2FD9BBAB74B5314F3440CA
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData130ADF60D1B7B3CF82CC6CA82D961601_3722A7817B153CAC96BEA5D2AB2FB31E
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData130ADF60D1B7B3CF82CC6CA82D961601_BFF3E82445C199812E8EC4CC74EA6FD4
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData130ADF60D1B7B3CF82CC6CA82D961601_EC2B8F0C530DA57B6BD72F9ED19E4B95
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData130ADF60D1B7B3CF82CC6CA82D961601_F3F138DDA4E72F849B7E03101CED9406
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData15C9B775FA7F2C683FD76888C21180E6_E27DFEC191FB94181AFA36FA5A594D4D
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData17704B7A99D010A5658DCB9355B65471_5FEA55F2BCB4685A54058A290E2CED24
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData1DAF2884EC4DFA96BA4A58D4DBC9C406
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData21253908F3CB05D51B1C2DA8B681A785
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData23B523C9E7746F715D33C6527C18EB9D
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData26AD01F9C002FAD37427E734302383D8_E1DF8F31180BEED965CA2CD894B8B7B4
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData27371171D8BBA336302695C6CEB04833
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData2E980CF7BB84455884A2F90C0668C729_13D1F45DD9F256533B0C06DE47C918A9
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData2E980CF7BB84455884A2F90C0668C729_2817DADA27860DDBAA5B75DC24D8F7CB
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData2E980CF7BB84455884A2F90C0668C729_8C1CE3349DC87E0D9A75F7C83AA6AA4D
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData2E980CF7BB84455884A2F90C0668C729_E64A865E6157E47C4D58BD172CB0A346
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData30F7B429BB1DACA9B591B41E016BED66_F6024CD0767F1B4C9F060C7479C6DC83
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData3130B1871A126520A8C47861EFE3ED4D
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData3781B4A3713292956206932165FA4132_247C447D981AB87548C17087CA562739
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData37C951188967C8EB88D99893D9D191FE
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData3B143EDBBE87DD7AF4242621D50150C8_795C6FEE4F635805518880099C60193C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData3B6E683A7A45CC59BF035C9BA8C7AB9D
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData3C3948BE6E525B8A8CEE9FAC91C9E392_5C199D58691AAA2282032FF3781E4BA5
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData3C3948BE6E525B8A8CEE9FAC91C9E392_C8FA2A733FE2A95A8ABEB57315278F81
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData4302E4BD4246B8416A3626782DD3C8B9_471689C5672B5D4E16234BF7D920804C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData4302E4BD4246B8416A3626782DD3C8B9_5EEBB180DF6B081EF421E7B1C7DE0754
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData4309200C3DBAD0F6F0DFACE9165FD092
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData45781A86D7D79A4E3FE6F4DF8CDF171D_E0B7CDE0B6AB7ABECB214E5A7A028B64
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData49514950C94E8026A2B06312597DFF49_569BD946168DB279A65378F7D088CFD0
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData49514950C94E8026A2B06312597DFF49_AFC22B77ED08EE3E2B28B6DE75CADDF5
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData4DD39726D4B55AC3B4119B35A893323C_102B4A98EBC3FA5C6B2B8B6FA5322E3B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData4DD39726D4B55AC3B4119B35A893323C_5C3A8346A3889E0A80292D7D1539C3F1
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData5457A8CE4B2A7499F8299A013B6E1C7C_4BDA944235F1446F185236D493959297
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData5457A8CE4B2A7499F8299A013B6E1C7C_7DCDC9B86C5DA37FEB2732F7D1A586E5
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData5457A8CE4B2A7499F8299A013B6E1C7C_BD1446EE1580F7EA207C073F7ABA5015
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData5495C2E4531B22B3185CE59F8E73C447
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData57C8EDB95DF3F0AD4EE2DC2B8CFD4157
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData5BF987767EE121EB773E3E93D13C2F30_EF26754C41825C23E00A83FE50225A1A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData5C45AD19E3530EC4218F560AFC04C3F7
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData60E31627FDA0A46932B0E5948949F2A5
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData696F3DE637E6DE85B458996D49D759AD
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData6C05FF55E66434DC351985A3C60541B2_305471F92FEBDAC55C5F5411833A3468
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData6F0788892ECB795F56E658EDB1CA93AA_D57CC30C337AC7E9B9D1EF68CA4F2B29
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData724BA1E3D2C377A06FA5FA54F984881F_204A0CEAE21E503F798B2869C9756D5D
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7396C420A8E1BC1DA97F1AF0D10BAD21
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7423F88C7F265F0DEFC08EA88C3BDE45_11D7BA58D75E54D622A3AD9CDF9905BB
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData74BFD122C0875EC75DBE5C6DB4C59019
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData77EC63BDA74BD0D0E0426DC8F8008506
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData783DF2F5A7C9BC04C36663632D14B993_09A85C5418FB163D61A6CDA83D9C0B2C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B2238AACCEDC3F1FFE8E7EB5F575EC9
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_5C25CBC044F014C00B0BA9E7FEE400D7
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_96E18C6F7F11D436D50EB658BB37DA57
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_AE80968B09655437A4C6DA8671FF8BB7
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7B8944BA8AD0EFDF0E01A43EF62BECD0_E46661FBBE406EC01508EFCD5698836C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7C1B7BA2D0A4C1307F3A4A532F819AA1_49C1796B52BB2D4C90E15ABC693FBA62
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7D1F03728133589A90656A87E482B21F
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7D266D9E1E69FA1EEFB9699B009B34C8_1D5A876A9113EC07224C45E5A870E3BD
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7D266D9E1E69FA1EEFB9699B009B34C8_8CA7164968F366C9A94AC8E71C4BDD9B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData7D266D9E1E69FA1EEFB9699B009B34C8_FFE23A7C282C1690704B5AEA6161D1B8
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_209F4928FBDA7542CD726D289AEFA279
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_2F1BD5B4F9DBD26AB429C868029F876C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_52D163C71C0A45313122DB0337F6BD08
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_56F6CE74E651601224311261B6D1523A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_602DEDB8C7D6326D5C8D775461CB2C26
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_6F2F7960AAA8F8616CDE8AF3EC245868
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_72A8A3227555B8D9D0FEB7CED8B1BFBF
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_79CE80F3BB362DAA9837C94F6900C92A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_8A4ABE81D0B05920BC2AAF871936BF40
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_918340BA089892122B5626AE042DBBDE
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_9338BC338B6B38FF71A77A73A6496574
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_95BE0E24685C739E0287588432223979
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_B0BD9BAA9237E6406EC04FE996EA7710
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_B313A6AEB91DC2BE7A8547095314EC1C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_BD18A0CBF4C6463B2960D3E513AB6C7F
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_CAED40D1E29B0CF7BFCE055DDE63B150
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_D47B0351FE4289C5C14A4B1359D31F2A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_DB803DFCBAD45E1B55051EE70C257C5B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_E4DFCF5325A7B2A17D0E55108E8A34A8
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_EC9834D79F6FC380DD6205AD8CA74CEB
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_F0D84CB7919AFA8EDA0C1950AA5534A1
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_F2EFD568D6CA72D7BC802424E3F92B9A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8059E9A0D314877E40FE93D8CCFB3C69_F9758F0CEE4021D579BC2D754B77BF07
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8850665FA6436A99CD7432C30BBA9688_D6E65A57AC9D98B7C0DDA234DBE11864
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8850665FA6436A99CD7432C30BBA9688_EDE9EB77DBBEC01C325C4EF6EF79E79B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8890A77645B73478F5B1DED18ACBF795_1E5D470765E0BE1964814B1F5A3581DC
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8890A77645B73478F5B1DED18ACBF795_D3DB95C0E7608ACC9AA10ACCCCEBBDF5
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8890A77645B73478F5B1DED18ACBF795_E1EDEF0C21AE75D448F7327475DF4C9E
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8EA86C033C277996C7EE317E0F0E3B25_9B5183AE2014375207A1884853E4E799
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8EBFACB3A66359F9514D044C86BA4794
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData8F0B8CB0B32F751A2A9BFB4C6342C8CA
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData91ECFED5143F7F4F4576655D8EFAB51C_1521FDA318EDFEBCCDD7DD7DD752E274
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData91ECFED5143F7F4F4576655D8EFAB51C_4ACE605C7B17D38B8C1930042514D240
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData91ECFED5143F7F4F4576655D8EFAB51C_FD610691E11595AEA69D65A65E1A4374
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData94308059B57B3142E455B38A6EB92015
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData944E5B697BC46FE14AB888AE8A1EBB99_1A5D9298CC0735F34DA1CFF6ECB2443A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData944E5B697BC46FE14AB888AE8A1EBB99_C0035FF38E2228D8D803FC8213995A28
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData955CAB6FF6A24D5820D50B5BA1CF79C7_0D0504E280D4BC90041F089A5D901106
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData955CAB6FF6A24D5820D50B5BA1CF79C7_1A9CEF0D6BDBEE31E5C2CF9955E61B89
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData969F6872C062F51ACB119B46DFBDDA7D_B6A78665305B1848AE7D26E778D2B09B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaData9DB5D4FD0574EF300D1CF597CD7FECD0_77E75AC05F50F025C961015BFF770537
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataA3C4F17BF8CB09C3DF2A086B36306B5C_2C05E41C96EFDC884611C5187A819B15
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataA3C4F17BF8CB09C3DF2A086B36306B5C_4F52D381AC684F1C862E58E2340C9AAE
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataA3C4F17BF8CB09C3DF2A086B36306B5C_B5975426F3F347F59480D4E3DF5E3B86
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataA3C4F17BF8CB09C3DF2A086B36306B5C_C1C0B5D167C066A750AF361DC97F90F6
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataA470BE7C5A2476DEFEF6D7D0D0898D02_8AD7C343D4F560D789C538216F0CA9C1
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataA470BE7C5A2476DEFEF6D7D0D0898D02_99736A17001914AD89DD994D38ADB58E
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataA8FABA189DB7D25FBA7CAC806625FD30
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataA92F33496848CFF4F115ED04BCDD933A_6C14F82F698E40985D569864739DB21B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataAABBA64FEAC30FC78B82B9115CBA4569_1983EA3188848689F475FC595EEDFB14
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataAC9005F5466BD463DF06D711B370595F
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataB3BB9C1BA2D19E090AE305B2683903A0_3A991EF068DA80925661324DEEB3A2FC
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataB4378BD2E36B69DECED3E341BD654801_2E8B7E39650FDD1C192A93EED7A00EE1
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataB4378BD2E36B69DECED3E341BD654801_C9BF1C51982C7B3022E5C0637BE5600A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataB8CC409ACDBF2A2FE04C56F2875B1FD6
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataBBB768C456D9E2DCD3EF595C400D483D_64C05B9EB32FC3D0CE6CB126561EEBFF
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataBD8A14C7C024625432CC03FE72E47EF0_6FD1BEFD298F4FD3EE4B4EE2E6631CC7
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataBD8A14C7C024625432CC03FE72E47EF0_BC4EC46B2A6D9424FFBAF3A0C035586C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataBD8A14C7C024625432CC03FE72E47EF0_C8B74D9B1792BE9EC319F25CEE42586E
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataBD8A14C7C024625432CC03FE72E47EF0_CE8FCC7861C3AD5B2C06B958AD7EFCBD
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataC0AF5F80AA0D55CA55AD4471DD73D761
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataC3B4324B100AA32F7BE995E7E34E0AA5_15C23806E36E1233F1A79C3B11377E1C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataC5C16E8B8D126375C32C54465617D152_208DEAF681F30C26434D6DDCE91246CE
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataC5C16E8B8D126375C32C54465617D152_E89BE6285BCA3816E41A2C36E7E420A5
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataC8E7EC0C85688F4738F3BE49B104BA67
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataCA7B2D59B4E9BC2D316D1AECDFC12F63_1C9A6512958C3A4690AB2C96A34FEA6F
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataCA7B2D59B4E9BC2D316D1AECDFC12F63_68E0BD50FB6728A2D6BF5880FD8775B3
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataCA7B2D59B4E9BC2D316D1AECDFC12F63_79D3546DEED35444160AFB1E5947D1D8
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataCA7B2D59B4E9BC2D316D1AECDFC12F63_A0D7D7DB6C50D45B91F564D07E4A9405
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataCA7B2D59B4E9BC2D316D1AECDFC12F63_A79F1256921C9233349147CB3AA52673
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataCA7B2D59B4E9BC2D316D1AECDFC12F63_D0A92AAB15AA0E4211995849EF098D1E
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataCA7B2D59B4E9BC2D316D1AECDFC12F63_DE54C4FA15BBC43BAFB240D0C3799849
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataCA7B2D59B4E9BC2D316D1AECDFC12F63_E8FFB3D833ACBBA2A753BCE3F81C274B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataCA7B2D59B4E9BC2D316D1AECDFC12F63_F7A4D5E143E9D5D55CB49AA007B72044
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataCED209487D21B905304C249DD63B49BA_763EF36FA92455C61C561841DEEE7EE8
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataCF8F81142E45FB23D354F9018CD9473D_8CDBBB84D14526E38B4F7DDD8F66A4F9
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataCF8F81142E45FB23D354F9018CD9473D_AF5099BD6DC57AC8062EAE72507D5449
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataD0197CD123129A6D466C5F0FC1584EA2_3C6C7459D4DE3406C1DF8350D5E28578
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataD0197CD123129A6D466C5F0FC1584EA2_C16FC2E785F35E8D8B7475368877978A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataD1D88DE21ADA9AD70F84C0C44CF3BFE4
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataE2EF7F0FB7284B9ACFD4F65D02218479
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataE5F99F8CA677C9C5793DF9906EE2DCB6_6BF524492A7D8EFF897E6AF01BCBE61A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataE5F99F8CA677C9C5793DF9906EE2DCB6_78A3FDFEAF0CB6269293DC6B4406F98B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataE63A640A06A2B005AB42F3250BC98D9E_6020995806BF99A1FBC324A7B889F612
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataEE44ECA143B76F2B9F2A5AA75B5D1EC6_847118BE2683F0C241D1D702F3A3F5F9
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataF063BF7EF604434CBE00FF198F0D9B10
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataF30B1DAC467EEB5A0EB57E5457CD952D_5FB0DDB3AA79F9EDA9226B63C372B406
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataF4B372709D6C2AD766C34D274501DC76_C08D897FBCD7D5D638FCD154D1404CBE
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataFB788E090BC1F3AA2FBC9E8FB2859601
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheMetaDataFCEA474F228C13CD0DAD678431D0ACFC
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent30DBCEADC67EA14BE9A74D5A32FAF83
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent4AFA8793E5CDC4A81C6CD4554A30707
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent130ADF60D1B7B3CF82CC6CA82D961601_12C50190AA5922E6D711F2DEE84C1EB9
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent130ADF60D1B7B3CF82CC6CA82D961601_2FFE778CED2FD9BBAB74B5314F3440CA
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent130ADF60D1B7B3CF82CC6CA82D961601_3722A7817B153CAC96BEA5D2AB2FB31E
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent130ADF60D1B7B3CF82CC6CA82D961601_BFF3E82445C199812E8EC4CC74EA6FD4
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent130ADF60D1B7B3CF82CC6CA82D961601_EC2B8F0C530DA57B6BD72F9ED19E4B95
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent130ADF60D1B7B3CF82CC6CA82D961601_F3F138DDA4E72F849B7E03101CED9406
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent15C9B775FA7F2C683FD76888C21180E6_E27DFEC191FB94181AFA36FA5A594D4D
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent17704B7A99D010A5658DCB9355B65471_5FEA55F2BCB4685A54058A290E2CED24
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent1DAF2884EC4DFA96BA4A58D4DBC9C406
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent21253908F3CB05D51B1C2DA8B681A785
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent23B523C9E7746F715D33C6527C18EB9D
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent26AD01F9C002FAD37427E734302383D8_E1DF8F31180BEED965CA2CD894B8B7B4
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent27371171D8BBA336302695C6CEB04833
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent2E980CF7BB84455884A2F90C0668C729_13D1F45DD9F256533B0C06DE47C918A9
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent2E980CF7BB84455884A2F90C0668C729_2817DADA27860DDBAA5B75DC24D8F7CB
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent2E980CF7BB84455884A2F90C0668C729_8C1CE3349DC87E0D9A75F7C83AA6AA4D
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent2E980CF7BB84455884A2F90C0668C729_E64A865E6157E47C4D58BD172CB0A346
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent30F7B429BB1DACA9B591B41E016BED66_F6024CD0767F1B4C9F060C7479C6DC83
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent3130B1871A126520A8C47861EFE3ED4D
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent3781B4A3713292956206932165FA4132_247C447D981AB87548C17087CA562739
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent37C951188967C8EB88D99893D9D191FE
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent3B143EDBBE87DD7AF4242621D50150C8_795C6FEE4F635805518880099C60193C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent3B6E683A7A45CC59BF035C9BA8C7AB9D
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent3C3948BE6E525B8A8CEE9FAC91C9E392_5C199D58691AAA2282032FF3781E4BA5
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent3C3948BE6E525B8A8CEE9FAC91C9E392_C8FA2A733FE2A95A8ABEB57315278F81
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent4302E4BD4246B8416A3626782DD3C8B9_471689C5672B5D4E16234BF7D920804C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent4302E4BD4246B8416A3626782DD3C8B9_5EEBB180DF6B081EF421E7B1C7DE0754
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent4309200C3DBAD0F6F0DFACE9165FD092
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent45781A86D7D79A4E3FE6F4DF8CDF171D_E0B7CDE0B6AB7ABECB214E5A7A028B64
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent49514950C94E8026A2B06312597DFF49_569BD946168DB279A65378F7D088CFD0
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent49514950C94E8026A2B06312597DFF49_AFC22B77ED08EE3E2B28B6DE75CADDF5
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent4DD39726D4B55AC3B4119B35A893323C_102B4A98EBC3FA5C6B2B8B6FA5322E3B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent4DD39726D4B55AC3B4119B35A893323C_5C3A8346A3889E0A80292D7D1539C3F1
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent5457A8CE4B2A7499F8299A013B6E1C7C_4BDA944235F1446F185236D493959297
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent5457A8CE4B2A7499F8299A013B6E1C7C_7DCDC9B86C5DA37FEB2732F7D1A586E5
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent5457A8CE4B2A7499F8299A013B6E1C7C_BD1446EE1580F7EA207C073F7ABA5015
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent5495C2E4531B22B3185CE59F8E73C447
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent57C8EDB95DF3F0AD4EE2DC2B8CFD4157
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent5BF987767EE121EB773E3E93D13C2F30_EF26754C41825C23E00A83FE50225A1A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent5C45AD19E3530EC4218F560AFC04C3F7
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent60E31627FDA0A46932B0E5948949F2A5
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent696F3DE637E6DE85B458996D49D759AD
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent6C05FF55E66434DC351985A3C60541B2_305471F92FEBDAC55C5F5411833A3468
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent6F0788892ECB795F56E658EDB1CA93AA_D57CC30C337AC7E9B9D1EF68CA4F2B29
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent724BA1E3D2C377A06FA5FA54F984881F_204A0CEAE21E503F798B2869C9756D5D
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent7396C420A8E1BC1DA97F1AF0D10BAD21
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent7423F88C7F265F0DEFC08EA88C3BDE45_11D7BA58D75E54D622A3AD9CDF9905BB
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent74BFD122C0875EC75DBE5C6DB4C59019
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent77EC63BDA74BD0D0E0426DC8F8008506
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent783DF2F5A7C9BC04C36663632D14B993_09A85C5418FB163D61A6CDA83D9C0B2C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B2238AACCEDC3F1FFE8E7EB5F575EC9
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_5C25CBC044F014C00B0BA9E7FEE400D7
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_96E18C6F7F11D436D50EB658BB37DA57
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_AE80968B09655437A4C6DA8671FF8BB7
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent7B8944BA8AD0EFDF0E01A43EF62BECD0_E46661FBBE406EC01508EFCD5698836C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent7C1B7BA2D0A4C1307F3A4A532F819AA1_49C1796B52BB2D4C90E15ABC693FBA62
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent7D1F03728133589A90656A87E482B21F
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent7D266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent7D266D9E1E69FA1EEFB9699B009B34C8_1D5A876A9113EC07224C45E5A870E3BD
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent7D266D9E1E69FA1EEFB9699B009B34C8_8CA7164968F366C9A94AC8E71C4BDD9B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent7D266D9E1E69FA1EEFB9699B009B34C8_FFE23A7C282C1690704B5AEA6161D1B8
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_209F4928FBDA7542CD726D289AEFA279
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_2F1BD5B4F9DBD26AB429C868029F876C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_52D163C71C0A45313122DB0337F6BD08
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_56F6CE74E651601224311261B6D1523A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_602DEDB8C7D6326D5C8D775461CB2C26
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_6F2F7960AAA8F8616CDE8AF3EC245868
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_72A8A3227555B8D9D0FEB7CED8B1BFBF
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_79CE80F3BB362DAA9837C94F6900C92A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_8A4ABE81D0B05920BC2AAF871936BF40
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_918340BA089892122B5626AE042DBBDE
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_9338BC338B6B38FF71A77A73A6496574
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_95BE0E24685C739E0287588432223979
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_B0BD9BAA9237E6406EC04FE996EA7710
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_B313A6AEB91DC2BE7A8547095314EC1C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_BD18A0CBF4C6463B2960D3E513AB6C7F
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_CAED40D1E29B0CF7BFCE055DDE63B150
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_D47B0351FE4289C5C14A4B1359D31F2A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_DB803DFCBAD45E1B55051EE70C257C5B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_E4DFCF5325A7B2A17D0E55108E8A34A8
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_EC9834D79F6FC380DD6205AD8CA74CEB
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_F0D84CB7919AFA8EDA0C1950AA5534A1
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_F2EFD568D6CA72D7BC802424E3F92B9A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8059E9A0D314877E40FE93D8CCFB3C69_F9758F0CEE4021D579BC2D754B77BF07
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8850665FA6436A99CD7432C30BBA9688_D6E65A57AC9D98B7C0DDA234DBE11864
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8850665FA6436A99CD7432C30BBA9688_EDE9EB77DBBEC01C325C4EF6EF79E79B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8890A77645B73478F5B1DED18ACBF795_1E5D470765E0BE1964814B1F5A3581DC
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8890A77645B73478F5B1DED18ACBF795_D3DB95C0E7608ACC9AA10ACCCCEBBDF5
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8890A77645B73478F5B1DED18ACBF795_E1EDEF0C21AE75D448F7327475DF4C9E
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8EA86C033C277996C7EE317E0F0E3B25_9B5183AE2014375207A1884853E4E799
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8EBFACB3A66359F9514D044C86BA4794
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent8F0B8CB0B32F751A2A9BFB4C6342C8CA
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent91ECFED5143F7F4F4576655D8EFAB51C_1521FDA318EDFEBCCDD7DD7DD752E274
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent91ECFED5143F7F4F4576655D8EFAB51C_4ACE605C7B17D38B8C1930042514D240
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent91ECFED5143F7F4F4576655D8EFAB51C_FD610691E11595AEA69D65A65E1A4374
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent94308059B57B3142E455B38A6EB92015
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent944E5B697BC46FE14AB888AE8A1EBB99_1A5D9298CC0735F34DA1CFF6ECB2443A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent944E5B697BC46FE14AB888AE8A1EBB99_C0035FF38E2228D8D803FC8213995A28
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent955CAB6FF6A24D5820D50B5BA1CF79C7_0D0504E280D4BC90041F089A5D901106
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent955CAB6FF6A24D5820D50B5BA1CF79C7_1A9CEF0D6BDBEE31E5C2CF9955E61B89
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent969F6872C062F51ACB119B46DFBDDA7D_B6A78665305B1848AE7D26E778D2B09B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContent9DB5D4FD0574EF300D1CF597CD7FECD0_77E75AC05F50F025C961015BFF770537
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentA3C4F17BF8CB09C3DF2A086B36306B5C_2C05E41C96EFDC884611C5187A819B15
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentA3C4F17BF8CB09C3DF2A086B36306B5C_4F52D381AC684F1C862E58E2340C9AAE
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentA3C4F17BF8CB09C3DF2A086B36306B5C_B5975426F3F347F59480D4E3DF5E3B86
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentA3C4F17BF8CB09C3DF2A086B36306B5C_C1C0B5D167C066A750AF361DC97F90F6
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentA470BE7C5A2476DEFEF6D7D0D0898D02_8AD7C343D4F560D789C538216F0CA9C1
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentA470BE7C5A2476DEFEF6D7D0D0898D02_99736A17001914AD89DD994D38ADB58E
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentA8FABA189DB7D25FBA7CAC806625FD30
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentA92F33496848CFF4F115ED04BCDD933A_6C14F82F698E40985D569864739DB21B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentAABBA64FEAC30FC78B82B9115CBA4569_1983EA3188848689F475FC595EEDFB14
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentAC9005F5466BD463DF06D711B370595F
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentB3BB9C1BA2D19E090AE305B2683903A0_3A991EF068DA80925661324DEEB3A2FC
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentB4378BD2E36B69DECED3E341BD654801_2E8B7E39650FDD1C192A93EED7A00EE1
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentB4378BD2E36B69DECED3E341BD654801_C9BF1C51982C7B3022E5C0637BE5600A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentB8CC409ACDBF2A2FE04C56F2875B1FD6
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentBBB768C456D9E2DCD3EF595C400D483D_64C05B9EB32FC3D0CE6CB126561EEBFF
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentBD8A14C7C024625432CC03FE72E47EF0_6FD1BEFD298F4FD3EE4B4EE2E6631CC7
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentBD8A14C7C024625432CC03FE72E47EF0_BC4EC46B2A6D9424FFBAF3A0C035586C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentBD8A14C7C024625432CC03FE72E47EF0_C8B74D9B1792BE9EC319F25CEE42586E
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentBD8A14C7C024625432CC03FE72E47EF0_CE8FCC7861C3AD5B2C06B958AD7EFCBD
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentC0AF5F80AA0D55CA55AD4471DD73D761
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentC3B4324B100AA32F7BE995E7E34E0AA5_15C23806E36E1233F1A79C3B11377E1C
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentC5C16E8B8D126375C32C54465617D152_208DEAF681F30C26434D6DDCE91246CE
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentC5C16E8B8D126375C32C54465617D152_E89BE6285BCA3816E41A2C36E7E420A5
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentC8E7EC0C85688F4738F3BE49B104BA67
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentCA7B2D59B4E9BC2D316D1AECDFC12F63_1C9A6512958C3A4690AB2C96A34FEA6F
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentCA7B2D59B4E9BC2D316D1AECDFC12F63_68E0BD50FB6728A2D6BF5880FD8775B3
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentCA7B2D59B4E9BC2D316D1AECDFC12F63_79D3546DEED35444160AFB1E5947D1D8
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentCA7B2D59B4E9BC2D316D1AECDFC12F63_A0D7D7DB6C50D45B91F564D07E4A9405
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentCA7B2D59B4E9BC2D316D1AECDFC12F63_A79F1256921C9233349147CB3AA52673
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentCA7B2D59B4E9BC2D316D1AECDFC12F63_D0A92AAB15AA0E4211995849EF098D1E
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentCA7B2D59B4E9BC2D316D1AECDFC12F63_DE54C4FA15BBC43BAFB240D0C3799849
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentCA7B2D59B4E9BC2D316D1AECDFC12F63_E8FFB3D833ACBBA2A753BCE3F81C274B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentCA7B2D59B4E9BC2D316D1AECDFC12F63_F7A4D5E143E9D5D55CB49AA007B72044
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentCED209487D21B905304C249DD63B49BA_763EF36FA92455C61C561841DEEE7EE8
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentCF8F81142E45FB23D354F9018CD9473D_8CDBBB84D14526E38B4F7DDD8F66A4F9
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentCF8F81142E45FB23D354F9018CD9473D_AF5099BD6DC57AC8062EAE72507D5449
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentD0197CD123129A6D466C5F0FC1584EA2_3C6C7459D4DE3406C1DF8350D5E28578
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentD0197CD123129A6D466C5F0FC1584EA2_C16FC2E785F35E8D8B7475368877978A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentD1D88DE21ADA9AD70F84C0C44CF3BFE4
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentE2EF7F0FB7284B9ACFD4F65D02218479
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentE5F99F8CA677C9C5793DF9906EE2DCB6_6BF524492A7D8EFF897E6AF01BCBE61A
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentE5F99F8CA677C9C5793DF9906EE2DCB6_78A3FDFEAF0CB6269293DC6B4406F98B
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentE63A640A06A2B005AB42F3250BC98D9E_6020995806BF99A1FBC324A7B889F612
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentEE44ECA143B76F2B9F2A5AA75B5D1EC6_847118BE2683F0C241D1D702F3A3F5F9
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentF063BF7EF604434CBE00FF198F0D9B10
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentF30B1DAC467EEB5A0EB57E5457CD952D_5FB0DDB3AA79F9EDA9226B63C372B406
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentF4B372709D6C2AD766C34D274501DC76_C08D897FBCD7D5D638FCD154D1404CBE
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentFB788E090BC1F3AA2FBC9E8FB2859601
    C:UsersNadiaAppDataLocalLowMicrosoftCryptnetUrlCacheContentFCEA474F228C13CD0DAD678431D0ACFC
    C:WindowsTEMPchrome_installer.log
    C:WindowsTEMPCR_B2F72.tmp
    C:WindowsTEMPfwtsqmfile00.sqm
    C:WindowsTEMPfwtsqmfile01.sqm
    C:WindowsTEMPfwtsqmfile02.sqm
    C:WindowsTEMPfwtsqmfile03.sqm
    C:WindowsTEMPfwtsqmfile04.sqm
    C:WindowsTEMPGoogleToolbarInstaller1.log
    C:WindowsTEMPMpCmdRun.log
    C:WindowsTEMPMpSigStub.log
    C:WindowsTEMPMSI4a573.LOG
    C:WindowsTEMPScheduledHeartbeat.log
    C:WindowsTEMP{6C457916-30A1-46AD-A531-719EFBBBAB2A}
    C:WindowsTEMP{6C457916-30A1-46AD-A531-719EFBBBAB2A}fpi.tmp
    C:WindowsTEMPCR_B2F72.tmpCHROME_PATCH.PACKED.7Z
    C:WindowsTEMPCR_B2F72.tmpsetup.exe
    C:WindowsTEMPavast_ashMozilla Firefox
    C:WindowsTEMPavast_ashMozilla Firefoxupdate.xml
    C:WindowsPrefetchACRORD32.EXE-D066635E.pf
    C:WindowsPrefetchAgAppLaunch.db
    C:WindowsPrefetchAgCx_S1_S-1-5-21-2945581834-3016043712-3197114360-1001.snp.db
    C:WindowsPrefetchAgCx_SC1.db
    C:WindowsPrefetchAgCx_SC1.db.trx
    C:WindowsPrefetchAgCx_SC2.db
    C:WindowsPrefetchAgCx_SC4.db
    C:WindowsPrefetchAgGlFaultHistory.db
    C:WindowsPrefetchAgGlFgAppHistory.db
    C:WindowsPrefetchAgGlGlobalHistory.db
    C:WindowsPrefetchAgGlUAD_P_S-1-5-21-2945581834-3016043712-3197114360-1001.db
    C:WindowsPrefetchAgGlUAD_S-1-5-21-2945581834-3016043712-3197114360-1001.db
    C:WindowsPrefetchAgRobust.db
    C:WindowsPrefetchAPPLEMOBILEDEVICESERVICE.EXE-100BA47F.pf
    C:WindowsPrefetchAVASTEMUPDATE.EXE-6EF4B603.pf
    C:WindowsPrefetchCFIWMXSVCS64.EXE-E079CBBA.pf
    C:WindowsPrefetchCFSVCS.EXE-35E839CF.pf
    C:WindowsPrefetchCMD.EXE-4A81B364.pf
    C:WindowsPrefetchCMD.EXE-AC113AA8.pf
    C:WindowsPrefetchCONHOST.EXE-1F3E9D7E.pf
    C:WindowsPrefetchCONSENT.EXE-531BD9EA.pf
    C:WindowsPrefetchCSC.EXE-BE9AC2DF.pf
    C:WindowsPrefetchCSCRIPT.EXE-0FB3F22C.pf
    C:WindowsPrefetchCVTRES.EXE-2B9D810D.pf
    C:WindowsPrefetchDEVICEDISPLAYOBJECTPROVIDER.E-17410B90.pf
    C:WindowsPrefetchDLLHOST.EXE-40DD444D.pf
    C:WindowsPrefetchDLLHOST.EXE-5E46FA0D.pf
    C:WindowsPrefetchDLLHOST.EXE-766398D2.pf
    C:WindowsPrefetchDLLHOST.EXE-76936ED5.pf
    C:WindowsPrefetchDLLHOST.EXE-A8DE6D5B.pf
    C:WindowsPrefetchDLLHOST.EXE-E7777CC4.pf
    C:WindowsPrefetchEXPLORER.EXE-A80E4F97.pf
    C:WindowsPrefetchFIREFOX.EXE-18ACFCFF.pf
    C:WindowsPrefetchFLASHPLAYERPLUGIN_11_7_700_22-4CA03018.pf
    C:WindowsPrefetchGO.EXE-0A7DE786.pf
    C:WindowsPrefetchGOOGLETOOLBARNOTIFIER.EXE-7AE0A20E.pf
    C:WindowsPrefetchGOOGLEUPDATE.EXE-B95715F5.pf
    C:WindowsPrefetchGREP.COM-A0F2EC80.pf
    C:WindowsPrefetchLADS.EXE-046BC4A8.pf
    C:WindowsPrefetchLayout.ini
    C:WindowsPrefetchMBAM-SETUP-1.75.0.1300.EXE-588B4BDC.pf
    C:WindowsPrefetchMBAM-SETUP-1.75.0.1300.TMP-3F54AD88.pf
    C:WindowsPrefetchMBAM-SETUP-1.75.0.1300.TMP-7D5F7E0E.pf
    C:WindowsPrefetchMBAM.EXE-80210E2F.pf
    C:WindowsPrefetchMBAMGUI.EXE-1CA97248.pf
    C:WindowsPrefetchMBAMSCHEDULER.EXE-7473DE22.pf
    C:WindowsPrefetchMBAMSERVICE.EXE-B55DB80C.pf
    C:WindowsPrefetchMBRCHECK.EXE-2CA9EB2F.pf
    C:WindowsPrefetchMPCMDRUN.EXE-F401FBB4.pf
    C:WindowsPrefetchMSCORSVW.EXE-57D17DAF.pf
    C:WindowsPrefetchMSCORSVW.EXE-C3C515BD.pf
    C:WindowsPrefetchNASVC.EXE-B158719F.pf
    C:WindowsPrefetchNBAGENT.EXE-74069EAC.pf
    C:WindowsPrefetchNBCORE.EXE-68D662B6.pf
    C:WindowsPrefetchNOTEPAD.EXE-1605FA5B.pf
    C:WindowsPrefetchNOTEPAD.EXE-D8414F97.pf
    C:WindowsPrefetchNSLOOKUP.EXE-8DBC12C3.pf
    C:WindowsPrefetchNTOSBOOT-B00DFAAD.pf
    C:WindowsPrefetchPfSvPerfStats.bin
    C:WindowsPrefetchPLUGIN-CONTAINER.EXE-F1B02F03.pf
    C:WindowsPrefetchPV.EXE-34B75B82.pf
    C:WindowsPrefetchReadyBoot
    C:WindowsPrefetchREG.EXE-4978446A.pf
    C:WindowsPrefetchREGEDIT.EXE-2023FAA8.pf
    C:WindowsPrefetchREGSVR32.EXE-8461DBEE.pf
    C:WindowsPrefetchREGSVR32.EXE-D5170E12.pf
    C:WindowsPrefetchROBOTASKBARICON.EXE-20C79AF5.pf
    C:WindowsPrefetchRUNDLL32.EXE-0505915D.pf
    C:WindowsPrefetchRUNDLL32.EXE-A3E35360.pf
    C:WindowsPrefetchSCHTASKS.EXE-AD598958.pf
    C:WindowsPrefetchSEARCHFILTERHOST.EXE-77482212.pf
    C:WindowsPrefetchSEARCHINDEXER.EXE-4A6353B9.pf
    C:WindowsPrefetchSEARCHPROTOCOLHOST.EXE-0CB8CADE.pf
    C:WindowsPrefetchSFTGC.EXE-D17D7310.pf
    C:WindowsPrefetchSPOOLSV.EXE-D1F6B8B6.pf
    C:WindowsPrefetchSPPSVC.EXE-B0F8131B.pf
    C:WindowsPrefetchSUBINACL.EXE-AB0CE9D9.pf
    C:WindowsPrefetchSVCHOST.EXE-05F624AB.pf
    C:WindowsPrefetchSVCHOST.EXE-80F4A784.pf
    C:WindowsPrefetchSYNTPHELPER.EXE-0A20AAC4.pf
    C:WindowsPrefetchTASKENG.EXE-48D4E289.pf
    C:WindowsPrefetchTASKHOST.EXE-7238F31D.pf
    C:WindowsPrefetchTMACHINFO.EXE-2FCB5A05.pf
    C:WindowsPrefetchTOSSENOTIFY.EXE-BC36C1CB.pf
    C:WindowsPrefetchTOSSMARTSRV.EXE-BCFE7888.pf
    C:WindowsPrefetchTOSVOLREGULATOR.EXE-99D29444.pf
    C:WindowsPrefetchTOSWAITSRV.EXE-4901C686.pf
    C:WindowsPrefetchTRUSTEDINSTALLER.EXE-3CC531E5.pf
    C:WindowsPrefetchUSBFIX.EXE-63300B32.pf
    C:WindowsPrefetchWERMGR.EXE-0F2AC88C.pf
    C:WindowsPrefetchWLIDSVC.EXE-5514E75E.pf
    C:WindowsPrefetchWMIADAP.EXE-F8DFDFA2.pf
    C:WindowsPrefetchWMIPRVSE.EXE-1628051C.pf
    C:WindowsPrefetchWMIPRVSE.EXE-6768A320.pf
    C:WindowsPrefetchWMPNETWK.EXE-D9F2A96F.pf
    C:WindowsPrefetchWSCRIPT.EXE-52CF1F0C.pf
    C:WindowsPrefetchWUAUCLT.EXE-70318591.pf
    C:WindowsPrefetchZHPDIAG.EXE-0D117CAF.pf
    C:WindowsPrefetchZHPDIAG2.EXE-C0657B9A.pf
    C:WindowsPrefetchZHPDIAG2.TMP-3C65F7AB.pf
    C:WindowsPrefetchZHPDIAG2.TMP-C6CB9745.pf
    C:WindowsPrefetchZHPFIX.EXE-32786FC2.pf
    C:WindowsPrefetchZHPHEP.EXE-03FFF510.pf
    C:WindowsPrefetchZHPHEP.EXE-EBD3B8D7.pf
    C:WindowsPrefetchReadyBootTrace1.fx
    C:WindowsPrefetchReadyBootTrace2.fx
    C:WindowsPrefetchReadyBootTrace3.fx
    C:WindowsPrefetchReadyBootTrace4.fx
    C:WindowsPrefetchReadyBootTrace5.fx

    Corbeille vidée.

    Fin du rapport.

  • Anonyme
    Nombre d'articles : 0

    me dis pas qu’il faudra ke je refasse tt ca sur mon autre pc???

    Y’a des chances 🙁 Pour le second PC, il te faudra ouvrir un nouveau sujet ( 1PC = 1 sujet )

    Quoiqu’il en soit on a terminé avec celui ci 🙂

    • Pour supprimer les outils de désinfections utilisés :
    • Télécharges Delfix sur ton Bureau.
    • Lance Delfix, exécuter en tant qu’administrateur sous Windows : 7/8 et Vista
    • Coche la case suivantes :
      • Supprimer les outils de désinfection
      • Purger la restauration système

    [hr:3vn5c8d4]

    [fin2desinf:3vn5c8d4][/fin2desinf:3vn5c8d4]

  • nadouche92
    Nombre d'articles : 0

    est ce qu’il faudra que j’efface tous les logiciels que tu ma fait installé ou je dois les garder?

  • nadouche92
    Nombre d'articles : 0

    merci beaucoup pour ton aide
    a bientot pour mon autre pc

  • Anonyme
    Nombre d'articles : 0

    est ce qu’il faudra que j’efface tous les logiciels que tu ma fait installé ou je dois les garder?

    Delfix le fera pour toi 😉

    A bientôt pour le second PC 😉

Le sujet ‘virus disquees durs’ est fermé à de nouvelles réponses.