Jump to content

Mishaan

Members
  • Posts

    15
  • Joined

  • Last visited

Reputation

0 Neutral
  1. Yep, it's a keylogger i installed for something personal but didn't uninstall it since that day i'm going to do this
  2. tional scan result of Farbar Recovery Scan Tool (x64) Version: 26-07-2014 Ran by Babakila at 2014-07-30 14:29:51 Running from C:\Users\Babakila\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C} AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) A Heart of Darkness (HKLM-x32\...\Victoria II - A Heart of Darkness_is1) (Version: 3.0.1 - Paradox Interactive) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.8.0.870 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.8.0.870 - Adobe Systems Incorporated) Hidden Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.4.980 - Adobe Systems Incorporated.) Adobe Community Help (x32 Version: 3.4.980 - Adobe Systems Incorporated.) Hidden Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.0.2 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.0.2 - Adobe Systems Incorporated) Hidden Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Photoshop CS5 (HKLM-x32\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Français (HKLM-x32\...\{AC76BA86-7AD7-1036-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.3.133 - Adobe Systems, Inc.) AION Free-To-Play (HKLM-x32\...\InstallShield_{6A9EF6CF-7630-4E33-AE22-7D70F3AF4B05}) (Version: 2.70.0000 - Gameforge) AION Free-To-Play (x32 Version: 2.70.0000 - Gameforge) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM-x32\...\{C6579A65-9CAE-4B31-8B6B-3306E0630A66}) (Version: 2.1.3.127 - Apple Inc.) Ardamax Keylogger 4.0.1 (HKCU\...\Ardamax Keylogger 4.0.1) (Version: - ) Audacity 2.0.2 (HKLM-x32\...\Audacity_is1) (Version: 2.0.2 - Audacity Team) avast! Free Antivirus (HKLM-x32\...\avast) (Version: 8.0.1489.0 - AVAST Software) AviSynth 2.5 (HKLM-x32\...\AviSynth) (Version: - ) AVS Screen Capture version 2.0.1 (HKLM-x32\...\AVS Screen Capture_is1) (Version: - Online Media Technologies Ltd.) AVS Update Manager 1.0 (HKLM-x32\...\AVS Update Manager_is1) (Version: - Online Media Technologies Ltd.) AVS Video Editor 6 (HKLM-x32\...\AVS Video Editor_is1) (Version: - Online Media Technologies Ltd.) AVS Video Recorder 2.4 (HKLM-x32\...\AVS Video Recorder_is1) (Version: - Online Media Technologies Ltd.) AVS4YOU Software Navigator 1.4 (HKLM-x32\...\AVS4YOU Software Navigator_is1) (Version: - Online Media Technologies Ltd.) Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) BubbleUPnP Server (HKLM-x32\...\BubbleUPnP Server) (Version: - ) CameraHelperMsi (x32 Version: 13.30.1395.0 - Logitech) Hidden CCleaner (HKLM\...\CCleaner) (Version: 3.11 - Piriform) Cheat Engine 6.1 (HKLM-x32\...\Cheat Engine 6.1_is1) (Version: - Dark Byte) Cheat Engine 6.2 (HKLM-x32\...\Cheat Engine 6.2_is1) (Version: - Dark Byte) Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Click to Call with Skype (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.6.8153 - Skype Technologies S.A.) Coffret de pilotes Logitech Webcam Software (HKLM\...\lvdrivers_12.10) (Version: 12.10.1110 - Logitech Inc.) CopyTrans Suite désinstallation uniquement (HKCU\...\CopyTrans Suite) (Version: 2.36 - WindSolutions) Crusader Kings II (HKLM-x32\...\Crusader Kings II_is1) (Version: - ) CrystalDiskInfo 5.4.2 Shizuku Edition (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 5.4.2 - Crystal Dew World) CyberGhost 5 (HKLM\...\CyberGhost VPN 5_is1) (Version: - CyberGhost S.R.L.) CyberLink DVD Suite Deluxe (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.2823 - CyberLink Corp.) CyberLink DVD Suite Deluxe (x32 Version: 7.0.2823 - CyberLink Corp.) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.40.2.0131 - DT Soft Ltd) Darkest Hour (HKLM-x32\...\{09D5819F-0F1A-4480-A112-B5CCA58D9773}_is1) (Version: - Darkest Hour Team) Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden DVD Menu Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}) (Version: 4.1.4030 - Hewlett-Packard) DVD Menu Pack for HP MediaSmart Video (x32 Version: 4.1.4030 - Hewlett-Packard) Hidden EA Sports FIFA World (HKLM-x32\...\{8F9AC744-EEF6-43DB-A4B6-FA1A18F1C640}) (Version: 5.3.0.40277 - Electronic Arts, Inc.) EA SPORTS Game Face Browser Plugin 1.8.0.0 (HKCU\...\EA SPORTS Game Face Browser Plugin) (Version: 1.8.0.0 - Electronic Arts) Easy Drive Data Recovery (HKLM-x32\...\Easy Drive Data Recovery) (Version: 3.0 - MunSoft) Emit version 1.11 (HKLM-x32\...\{91092771-7812-483E-A276-4D5977982BC5}_is1) (Version: 1.11 - Biokoda d.o.o.) erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) eSupport UndeletePlus 3.0.5.313 (HKLM-x32\...\eSupport UndeletePlus_is1) (Version: - Copyright © 2013 eSupport.com • All Rights Reserved) Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited) FATE (x32 Version: 2.2.0.95 - WildTangent) Hidden FIFA 2005 DEMO (HKLM-x32\...\{E4E3E62E-16D7-425E-009C-DCB5E64F5955}) (Version: - ) Flashtool (HKLM-x32\...\Flashtool) (Version: 0.9.10.1 - Androxyde) Free Video Converter V 3.0 (HKLM-x32\...\Free Video Converter_is1) (Version: 3.0.0.0 - Koyote Soft) Galerie de photos Windows Live (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden GameXN GO (HKCU\...\Game Organizer) (Version: - GameXN AS) GIMP 2.6.11 (HKLM-x32\...\WinGimp-2.0_is1) (Version: 2.6.11 - The GIMP Team) GmoteServer (HKLM-x32\...\DDA23392-9C73-4909-A221-BC12C6D2664D) (Version: 2.0.2 - Gmote.org) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.44 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Advisor (HKLM-x32\...\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.4.12850.3526 - Hewlett-Packard) HP Customer Experience Enhancements (x32 Version: 6.0.1.4 - Hewlett-Packard) Hidden HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.1.3 - WildTangent) HP MediaSmart DVD (HKLM-x32\...\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 4.1.4229 - Hewlett-Packard) HP MediaSmart DVD (x32 Version: 4.1.4229 - Hewlett-Packard) Hidden HP MediaSmart Music (HKLM-x32\...\InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}) (Version: 4.1.4301 - Hewlett-Packard) HP MediaSmart Music (x32 Version: 4.1.4301 - Hewlett-Packard) Hidden HP MediaSmart Photo (HKLM-x32\...\InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}) (Version: 4.1.4211 - Hewlett-Packard) HP MediaSmart Photo (x32 Version: 4.1.4211 - Hewlett-Packard) Hidden HP MediaSmart SmartMenu (HKLM\...\{5B08AF35-B699-4A44-BB89-3E51E70611E8}) (Version: 3.1.1.12 - Hewlett-Packard) HP MediaSmart Video (HKLM-x32\...\InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}) (Version: 4.1.4214 - Hewlett-Packard) HP MediaSmart Video (x32 Version: 4.1.4214 - Hewlett-Packard) Hidden HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard) HP Product Detection (HKLM-x32\...\{A436F67F-687E-4736-BD2B-537121A804CF}) (Version: 11.14.0001 - HP) HP Setup (HKLM-x32\...\{72D90DB3-A16A-4545-B555-868471101833}) (Version: 8.1.4186.3400 - Hewlett-Packard) HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company) HP Support Information (HKLM-x32\...\{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}) (Version: 10.1.0002 - Hewlett-Packard) HP Update (HKLM-x32\...\{DE77FE3F-A33D-499A-87AD-5FC406617B40}) (Version: 5.002.003.003 - Hewlett-Packard) HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.1.2.27173 - Hewlett-Packard) Index.dat Analyzer v2.5 (HKLM-x32\...\Index.dat Analyzer_is1) (Version: 2.5 - Systenance Software) Insaniquarium Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Installation Windows Live (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation) Installation Windows Live (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden Intel® Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2119 - Intel Corporation) iTunes (HKLM\...\{A04DCB25-7040-4935-A30D-8E0A893ABF2D}) (Version: 11.1.2.32 - Apple Inc.) Java 7 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.250 - Oracle) Java Auto Updater (x32 Version: 2.1.9.5 - Sun Microsystems, Inc.) Hidden Java 6 Update 30 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216020FF}) (Version: 6.0.300 - Sun Microsystems, Inc.) JavaFX 2.1.0 (HKLM-x32\...\{1111706F-666A-4037-7777-210328764D10}) (Version: 2.1.0 - Oracle Corporation) Jewel Quest II (x32 Version: 2.2.0.95 - WildTangent) Hidden Jewel Quest Solitaire (x32 Version: 2.2.0.95 - WildTangent) Hidden John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden Juniper Networks Setup Client (HKCU\...\Juniper_Setup_Client) (Version: 2.1.2.5973 - Juniper Networks) Juniper Networks Setup Client Activex Control (HKLM-x32\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks) Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2823 - CyberLink Corp.) LabelPrint (x32 Version: 2.5.2823 - CyberLink Corp.) Hidden Les Sims 2 (HKLM-x32\...\{6E7DD182-9FC6-4651-0095-2E666CC6AF35}) (Version: - ) Les Sims 2 : Nuits de Folie (HKLM-x32\...\{F7529650-B9DB-481B-0089-A2AC3C2821C1}) (Version: - ) Les Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.26.89 - Electronic Arts) Les Sims™ 3 Accès VIP (HKLM-x32\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts) Les Sims™ 3 Générations (HKLM-x32\...\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts) Les Sims™ 3 Destination Aventure (HKLM-x32\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts) Les Sims™ 3 Animaux & Cie (HKLM-x32\...\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts) LightScribe System Software (HKLM-x32\...\{46BA053F-57B3-4153-BDB6-D37EEC8B12D7}) (Version: 1.18.15.1 - LightScribe) LimeWire 5.6.2 (HKLM-x32\...\{77B6E212-9E3B-4D79-815D-EFBC2EBA14B3}_is1) (Version: 5.6.2 - HackWare,Inc) Logitech Vid HD (HKLM-x32\...\Logitech Vid) (Version: 7.2 (7259) - Logitech Inc..) Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.30 - Logitech Inc.) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.227 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.2.0.227 - LogMeIn, Inc.) Hidden LPEConnectFix 1.0 (HKLM-x32\...\LPEConnectFix_is1) (Version: - LOTR, Inc. lol www.gnutellaforums.com/) LWS Facebook (x32 Version: 13.30.1346.0 - Logitech) Hidden LWS Gallery (x32 Version: 13.30.1379.0 - Logitech) Hidden LWS Help_main (x32 Version: 13.30.1396.0 - Logitech) Hidden LWS Launcher (x32 Version: 13.30.1379.0 - Logitech) Hidden LWS Motion Detection (x32 Version: 13.30.1395.0 - Logitech) Hidden LWS Pictures And Video (x32 Version: 13.30.1395.0 - Logitech) Hidden LWS Twitter (x32 Version: 13.30.1346.0 - Logitech) Hidden LWS Video Mask Maker (x32 Version: 13.30.1379.0 - Logitech) Hidden LWS VideoEffects (Version: 13.30.1379.0 - Logitech) Hidden LWS Webcam Software (x32 Version: 13.30.1379.0 - Logitech) Hidden LWS WLM Plugin (x32 Version: 1.30.1201.0 - Logitech) Hidden LWS YouTube Plugin (x32 Version: 13.30.1346.0 - Logitech) Hidden Magic Desktop (HKLM-x32\...\EasyBits Magic Desktop) (Version: - EasyBits Software AS) Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) McAfee Security Scan Plus (HKLM-x32\...\McAfee Security Scan) (Version: 3.0.285.6 - McAfee, Inc.) Media Go (HKLM-x32\...\{7547239C-FA8A-4FA4-84A6-31EAC0777E1B}) (Version: 2.7.341 - Sony) Media Go Network Downloader (HKLM-x32\...\{73FA7631-3015-4EEC-A002-09488C47A07C}) (Version: 1.5.19.0 - Sony) Media Go Video Playback Engine 2.4.112.12050 (HKLM-x32\...\{7C5AEEE1-6D7C-8922-4548-7BF9096077EC}) (Version: 2.4.112.12050 - Sony) Microsoft .NET Framework 4.5.1 (FRA) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Français) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1036) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden Microsoft Office « Démarrer en un clic » 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4734.1000 - Microsoft Corporation) Microsoft Office « Démarrer en un clic » 2010 (Version: 14.0.4734.1000 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - Français (HKLM-x32\...\{90140011-0066-040C-0000-0000000FF1CE}) (Version: 14.0.4734.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden MotioninJoy DS3 driver version 0.6.0005 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.6.0005 - www.motioninjoy.com) Movie Theme Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}) (Version: 4.1.4030 - Hewlett-Packard) Movie Theme Pack for HP MediaSmart Video (x32 Version: 4.1.4030 - Hewlett-Packard) Hidden Mozilla Firefox 30.0 (x86 fr) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 fr)) (Version: 30.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MusicStation (HKLM-x32\...\MusicStationNetstaller) (Version: 1.0.1.5 - Hewlett-Packard) NC Launcher (GameForge) (HKLM-x32\...\NCLauncher_GameForge) (Version: - NCsoft) OpenOffice.org 3.3 (HKLM-x32\...\{05653DE1-6567-40C6-B930-39D399B64369}) (Version: 3.3.9567 - OpenOffice.org) Origin (HKLM-x32\...\Origin) (Version: 9.3.10.4710 - Electronic Arts, Inc.) Outil de téléchargement Windows Live (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) PDF Complete Special Edition (HKLM-x32\...\PDF Complete) (Version: 3.5.111 - PDF Complete, Inc) PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden PhotoFiltre (HKCU\...\PhotoFiltre) (Version: - ) PhotoFiltre Studio X (HKCU\...\PhotoFiltre Studio X) (Version: - ) PhotoNow! (HKLM-x32\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.6904 - CyberLink Corp.) PhotoNow! (x32 Version: 1.1.6904 - CyberLink Corp.) Hidden Plants vs. Zombies (x32 Version: 2.2.0.95 - WildTangent) Hidden PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) PlayStation®Network Downloader (HKLM-x32\...\{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}) (Version: 2.07.00849 - Sony Computer Entertainment Inc.) PlayStation®Store (HKLM-x32\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.16.2.15545 - Sony Computer Entertainment Inc.) Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.4022 - CyberLink Corp.) Power2Go (x32 Version: 6.1.4022 - CyberLink Corp.) Hidden PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.2906 - CyberLink Corp.) PowerDirector (x32 Version: 8.0.2906 - CyberLink Corp.) Hidden PowerISO (HKLM-x32\...\PowerISO) (Version: 5.5 - Power Software Ltd) PressReader (HKLM-x32\...\{912CED74-88D3-4C5B-ACB0-13231864975D}) (Version: 5.10.621.0 - NewspaperDirect Inc.) puush (HKLM-x32\...\{C3592426-531E-4110-911D-BFECE2CE284B}) (Version: 1.0.0.0 - Dean Herbert) QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6132 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.3025 - CyberLink Corp.) Hidden Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform) SAMSUNG Mobile Composite Device Software (HKLM\...\SAMSUNG Mobile Composite Device) (Version: - ) SAMSUNG Mobile Modem Driver Set (HKLM\...\SAMSUNG Mobile Modem) (Version: - ) Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version: - ) SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version: - ) SAMSUNG Mobile USB Modem Software (HKLM\...\SAMSUNG Mobile USB Modem) (Version: - ) Samsung PC Studio 3 (HKLM-x32\...\{C4A4722E-79F9-417C-BD72-8D359A090C97}) (Version: 3.2.2.80403 - Samsung Electronics Co., Ltd.) Samsung PC Studio 3 (x32 Version: 3.0.0.80403 - Samsung Electronics Co., Ltd.) Hidden SDFormatter (HKLM-x32\...\{A5355F15-F98B-4704-9BAE-E53B9FE48F48}) (Version: 3.1.0 - SD Association) SecurityKISS Tunnel v0.3.0 (HKLM\...\SecurityKISS Tunnel_is1) (Version: - ) SFR - Kit de connexion (HKLM-x32\...\SFR_Kit) (Version: 10.8.27.0 - SFR) Sid Meier's Civilization 4 - Beyond the Sword (HKLM-x32\...\{32E4F0D2-C135-475E-A841-1D59A0D22989}) (Version: 3.19 - Firaxis Games) Sid Meier's Civilization 4 - Warlords (HKLM-x32\...\{3E4B349F-10B5-4586-9D99-489A90A8B228}) (Version: 1.00.0000 - Firaxis Games) Sid Meier's Civilization 4 (HKLM-x32\...\{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}) (Version: 1.74 - Firaxis Games) Sid Meier's Civilization 4 (x32 Version: 1.00.0000 - Firaxis Games) Hidden Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.) Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Sony Ericsson Update Engine (HKLM-x32\...\Update Engine) (Version: 2.13.7.201306141231 - Sony Ericsson Communications AB) Sony Mobile Update Service (HKLM-x32\...\Update Service) (Version: 2.13.12.201310171455 - Sony Mobile Communications AB) Sony PC Companion 2.10.211 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.211 - Sony) Spotify (HKCU\...\Spotify) (Version: 0.9.10.14.g578d350b - Spotify AB) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden System Requirements Lab CYRI (HKLM-x32\...\{E5F05232-96B6-4552-A480-785A60A94B21}) (Version: 5.0.6.0 - Husdawg, LLC) TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - ) The Sims 2 University (HKLM-x32\...\{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}) (Version: - ) Undelete 360 (HKLM-x32\...\Undelete 360_is1) (Version: - File Recovery Ltd.) Uniblue DriverScanner (HKLM-x32\...\{C2F8CA82-2BD9-4513-B2D1-08A47914C1DA}_is1) (Version: 4.0.1.6 - Uniblue Systems Ltd) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Veetle TV (HKLM-x32\...\Veetle TV) (Version: 0.9.18 - Veetle, Inc) Victoria 2 (HKLM-x32\...\{9C3B7F54-C6E2-4A74-9937-9C6EBA10C4A2}) (Version: - ) Victoria II A House Divided 2.1 (HKLM-x32\...\Victoria II A House Divided 2.1) (Version: - ) Virtual Villagers - The Secret City (x32 Version: 2.2.0.95 - WildTangent) Hidden VLC media player 1.1.11 (HKLM-x32\...\VLC media player) (Version: 1.1.11 - VideoLAN) Wedding Dash (x32 Version: 2.2.0.95 - WildTangent) Hidden WildTangent Games App (HP Games) (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.5.36 - WildTangent) Windows Live Call (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden Windows Live FolderShare (HKLM-x32\...\{76810709-A7D3-468D-9167-A1780C1E766C}) (Version: 14.0.8117.416 - Microsoft Corporation) Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation) Windows Live Mail (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) Windows Phone app for desktop (HKLM-x32\...\{639E54EE-95CA-4CAE-9779-6BA32D5EAF48}) (Version: 1.1.2726.0 - Microsoft Corporation) WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.) WinRAR 4.00 (32 bits) (HKLM-x32\...\WinRAR archiver) (Version: 4.00.0 - win.rar GmbH) Wireshark 1.10.3 (64-bit) (HKLM-x32\...\Wireshark) (Version: 1.10.3 - The Wireshark developer community, http://www.wireshark.org) Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 27-07-2014 12:37:19 Fin de désinfection 27-07-2014 12:53:26 zoek.exe restore point 29-07-2014 09:27:41 Windows Update 29-07-2014 15:06:02 Installed Windows Phone app for desktop ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2014-07-27 20:14 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {08E27D3A-D6DA-4D43-8AA9-01BD25FE75FA} - System32\Tasks\{8CC5F7C7-A631-4DEA-AAA2-8F9F1EB2AD63} => C:\Users\Babakila\Downloads\LimeWirePirateEdition.exe Task: {0B8414EA-2FCB-407C-8E30-796890A96BFF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-04] (Google Inc.) Task: {20106230-2C2C-4DEB-95B0-7227E497508C} - System32\Tasks\{884B4866-E50A-464C-A3D3-DFE372B5F85B} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.) Task: {246DC990-FA43-4131-9643-5FBA5B7402FA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-04] (Google Inc.) Task: {2688D54C-CAE3-4C5B-AE7F-A25AE376301C} - System32\Tasks\{893377C6-DDA6-4056-A05D-423ED7F313BB} => C:\Program Files (x86)\Electronic Arts\Les Sims 3 Générations\Game\Bin\Sims3Launcher.exe [2011-03-21] (Electronic Arts, Inc.) Task: {2F5535FD-B3DF-41A6-8450-8DC6AE5B7232} - System32\Tasks\{6AEDE296-644E-42BF-A188-0DB469688805} => Firefox.exe http://www.skype.com/go/downloading?source=lightinstaller&ver=6.14.0.104&LastError=-9 Task: {345F3BAE-C7D2-49B6-96A4-91F66F3D5D30} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {35174E2A-D14A-4BFF-AB5D-29B6CB0E2099} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {44CEE5EA-A934-40D3-9705-54B096AAD822} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-816315366-518852455-1505757675-1000Core => C:\Users\Babakila\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.) Task: {50400DB8-1507-4F15-9932-59CC37EAF1AD} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {54132CA0-3F6A-4CF0-B729-EDDC4918264C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company) Task: {625C6660-1433-4CF3-9CFB-ED8BB1D5B5A3} - System32\Tasks\{CCD40395-D46C-495A-A20B-5626629BF428} => Firefox.exe http://ui.skype.com/ui/0/5.8.0.158/en/abandoninstall?page=tsMain Task: {656E60CD-1BF7-4584-A635-13F4759DA864} - System32\Tasks\HPCeeScheduleForFAMILLEBABAKILA$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05] (Hewlett-Packard) Task: {903F5605-32FB-4350-A47C-55330257CBA2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08] (Adobe Systems Incorporated) Task: {96F048A4-4C37-40E9-939A-042CFF6C8D99} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {9E6D7C79-6537-46F2-B171-DD44FDD03C73} - System32\Tasks\{C8A0844F-A53E-4D49-9B74-E4F10E82B38F} => Firefox.exe http://ui.skype.com/ui/0/6.0.60.126/fr/abandoninstall?page=tsProgressBar Task: {C63679E6-3A55-44E1-8E03-21F37D90D9CC} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation) Task: {C8E73DCA-0146-45D9-93C6-72F089933EA2} - System32\Tasks\{C32F4FB8-E096-47F1-99F6-418C4EC28666} => Firefox.exe http://ui.skype.com/ui/0/5.5.0.114/fr/go/help.faq.installer?LastError=1618 Task: {D0268835-0C6E-419A-9F3E-38FA66AA4BC8} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-25] () Task: {D84A3B7A-5042-4F2A-8076-B487AC4FE73F} - System32\Tasks\HPCeeScheduleForBabakila => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05] (Hewlett-Packard) Task: {D9CAC4FB-8FF3-427B-B910-EC2FD1B69419} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe <==== ATTENTION Task: {DB70B02F-5267-4EFA-A51C-BDD664FAA19C} - System32\Tasks\{8FF38A09-61D7-4BB7-A061-5E98AFDACE55} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.) Task: {DC4B2878-471B-4731-AE45-43BAF2C45498} - System32\Tasks\ServicePlan => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-25] () Task: {E50EDD85-2381-421E-9702-61695DCCAD65} - System32\Tasks\{11E67E3B-9A4B-4CC5-A74F-0E84DF9A55CB} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.) Task: {E70C2B1A-EDC1-47C4-83F8-E8652363AE25} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-816315366-518852455-1505757675-1000UA => C:\Users\Babakila\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.) Task: {E9C37490-BBE0-4D1B-BC70-963AFD0EFAEE} - System32\Tasks\{C5DD9B20-7E48-42CB-91A6-10A5011842FA} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.) Task: {EA0775ED-8C78-46E2-B5EF-4D71DAEC2D68} - System32\Tasks\{71AC89EE-A001-45FA-8074-E083C56D3ECE} => C:\Program Files (x86)\Electronic Arts\Les Sims 3 Générations\Game\Bin\Sims3Launcher.exe [2011-03-21] (Electronic Arts, Inc.) Task: {F13C4E60-F40D-4552-8208-FE5A4CF423B4} - System32\Tasks\DriverScanner => C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe [2011-05-16] (Uniblue Systems Limited) Task: {FF766965-615B-49FB-ABFF-5B954936D6C4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-03-21] (Hewlett-Packard) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DriverScanner.job => C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-816315366-518852455-1505757675-1000Core.job => C:\Users\Babakila\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-816315366-518852455-1505757675-1000UA.job => C:\Users\Babakila\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HPCeeScheduleForBabakila.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\Windows\Tasks\HPCeeScheduleForFAMILLEBABAKILA$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Loaded Modules (whitelisted) ============= 2012-10-30 22:42 - 2013-10-31 12:35 - 00070880 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe 2012-01-10 14:41 - 2014-05-11 13:38 - 00567880 _____ () C:\Program Files (x86)\puush\puush.exe 2014-07-29 15:29 - 2014-07-29 10:29 - 02822144 _____ () C:\Program Files\AVAST Software\Avast\defs\14072900\algo.dll 2011-09-27 07:23 - 2011-09-27 07:23 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2011-09-27 07:22 - 2011-09-27 07:22 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2012-10-30 22:42 - 2012-04-30 11:57 - 00039936 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\TMonitorAPI.dll 2012-10-30 22:42 - 2013-09-13 11:02 - 00208896 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\MExplorer.dll 2011-07-07 14:54 - 2011-07-07 14:54 - 00233984 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\Report.dll 2012-10-05 04:51 - 2013-05-20 12:58 - 00620718 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\sqlite3.dll 2012-10-30 22:42 - 2010-01-11 16:44 - 00053248 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\VObject.dll 2012-11-27 16:13 - 2012-11-27 16:13 - 00585728 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PhoneUpdate.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 02145304 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtCore4.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 07956504 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtGui4.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 00342552 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtXml4.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 00029208 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QGif4.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 00128536 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll 2011-01-17 16:19 - 2012-05-08 12:06 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll 2010-09-28 14:00 - 2010-09-28 14:00 - 00061440 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll 2010-09-28 14:00 - 2010-09-28 14:00 - 00131072 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\ECenter\ECLibrary.dll 2010-09-28 14:00 - 2010-09-28 14:00 - 00028672 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll 2014-06-18 14:47 - 2014-06-18 14:47 - 03852912 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-07-08 22:19 - 2014-07-08 22:19 - 17029808 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\rkfree:cfg ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background ==================== Faulty Device Manager Devices ============= Name: avast! Firewall NDIS Filter Miniport Description: avast! Firewall NDIS Filter Miniport Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: ALWIL Software Service: aswNdis Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19) Resolution: A registry problem was detected. This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options: On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver. ==================== Event log errors: ========================= Application errors: ================== Error: (07/30/2014 00:01:41 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9719 Error: (07/30/2014 00:01:41 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9719 Error: (07/30/2014 00:01:41 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/29/2014 10:49:26 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9797 Error: (07/29/2014 10:49:26 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9797 Error: (07/29/2014 10:49:26 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/29/2014 10:44:52 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: La création du contexte d’activation a échoué pour « C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1 ». Erreur dans le fichier de manifeste ou de stratégie « C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 » à la ligne C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Une version de composant nécessaire à l’application est en conflit avec une autre version de composant déjà active. Les composants en conflit sont : Composant 1 : C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Composant 2 : C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (07/29/2014 09:37:22 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: La création du contexte d’activation a échoué pour « C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1 ». Erreur dans le fichier de manifeste ou de stratégie « C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2 » à la ligne C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Une version de composant nécessaire à l’application est en conflit avec une autre version de composant déjà active. Les composants en conflit sont : Composant 1 : C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Composant 2 : C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (07/29/2014 07:46:26 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9813 Error: (07/29/2014 07:46:26 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9813 System errors: ============= Error: (07/29/2014 05:41:19 PM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (07/29/2014 05:41:16 PM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (07/29/2014 11:29:27 AM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (07/29/2014 11:29:24 AM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (07/29/2014 11:22:04 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Le pilote de démarrage système ou d’amorçage suivant n’a pas pu se charger : StarOpen Error: (07/29/2014 11:20:33 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Le service Connaissance des emplacements réseau n’a pas pu démarrer en raison de l’erreur : %%1053 Error: (07/29/2014 11:20:33 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Le dépassement de délai (30000 millisecondes) a été atteint lors de l’attente de la réponse transactionnelle du service NlaSvc. Error: (07/29/2014 11:20:03 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Le service LMIGuardianSvc n’a pas pu démarrer en raison de l’erreur : %%1053 Error: (07/29/2014 11:20:03 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Le dépassement de délai (30000 millisecondes) a été atteint lors de l’attente de la connexion du service LMIGuardianSvc. Error: (07/29/2014 11:19:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Le service Freemake Improver n’a pas pu démarrer en raison de l’erreur : %%1053 Microsoft Office Sessions: ========================= Error: (07/30/2014 00:01:41 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9719 Error: (07/30/2014 00:01:41 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9719 Error: (07/30/2014 00:01:41 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/29/2014 10:49:26 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9797 Error: (07/29/2014 10:49:26 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9797 Error: (07/29/2014 10:49:26 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/29/2014 10:44:52 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe Error: (07/29/2014 09:37:22 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Babakila\Downloads\esetsmartinstaller_enu.exe Error: (07/29/2014 07:46:26 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9813 Error: (07/29/2014 07:46:26 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9813 CodeIntegrity Errors: =================================== Date: 2014-07-27 20:10:28.221 Description: Windows ne peut pas vérifier l’intégrité d’image du fichier \Device\HarddiskVolume2\ComboFix\catchme.sys, car le fichier à hacher est introuvable sur le système. Une modification matérielle ou logicielle récente a peut-être installé un fichier incorrectement signé ou endommagé ou il s’agit éventuellement d’un logiciel malveillant d’une source inconnue. Date: 2014-07-27 20:10:27.800 Description: Windows ne peut pas vérifier l’intégrité d’image du fichier \Device\HarddiskVolume2\ComboFix\catchme.sys, car le fichier à hacher est introuvable sur le système. Une modification matérielle ou logicielle récente a peut-être installé un fichier incorrectement signé ou endommagé ou il s’agit éventuellement d’un logiciel malveillant d’une source inconnue. Date: 2014-05-15 20:05:49.466 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.3\f0260952_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:05:48.782 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.3\f0260952_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:05:48.028 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.3\f0260952_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:05:34.504 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.2\f0238120_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:05:33.965 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.2\f0238120_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:05:33.402 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.2\f0238120_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:04:59.166 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.1\f0208272_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:04:58.413 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.1\f0208272_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. ==================== Memory info =========================== Percentage of memory in use: 55% Total physical RAM: 4061.24 MB Available physical RAM: 1801.8 MB Total Pagefile: 8120.66 MB Available Pagefile: 4859.67 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:582.75 GB) (Free:227.02 GB) NTFS Drive d: (HP_RECOVERY) (Fixed) (Total:13.32 GB) (Free:1.64 GB) NTFS ==>[system with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 596 GB) (Disk ID: 34FC3F15) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=583 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=13 GB) - (Type=07 NTFS) ==================== End Of Log ============================ I want to add that I own the TV serie Misfits in a immaterial form (bought on the tv) so if I'm right this isn't piracy, correct me if i'm wrong Thanks
  3. Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-07-2014 Ran by Babakila (administrator) on FAMILLEBABAKILA on 30-07-2014 14:26:41 Running from C:\Users\Babakila\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Français (France) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Uniblue Systems Limited) C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (CyberGhost S.R.L) C:\Program Files\CyberGhost 5\Service.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (SFR) C:\Program Files (x86)\SFR\Kit\9props.exe (EasyBits Software AS) C:\ProgramData\GameXN\GameXNGO.exe (Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe (Spotify Ltd) C:\Users\Babakila\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (CyberGhost S.R.L.) C:\Program Files\CyberGhost 5\CyberGhost.exe () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe () C:\Program Files (x86)\puush\puush.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe (Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Power Software Ltd) C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Easybits) C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe (Farbar) C:\Users\Babakila\Downloads\FRST64(1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [563736 2009-10-15] (PDF Complete Inc) HKLM-x32\...\Run: [HP Software Update] => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2008-12-09] (Hewlett-Packard) HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2010-04-25] (EasyBits Software AS) HKLM-x32\...\Run: [switchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-08-12] (Logitech Inc.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [avast] => C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [superVigil] => C:\ProgramData\SuperVigil\SyScript\SysPlug.exe [984680 2012-10-03] () HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [337432 2013-01-27] (Power Software Ltd) HKLM-x32\...\Run: [sunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [Magic Desktop for HP notification] => C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1238016 2013-07-27] (Easybits) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-23] (Apple Inc.) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3816784 2014-07-21] (LogMeIn Inc.) HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-07-23] (Hewlett-Packard) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [HPAdvisorDock] => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1715768 2010-09-28] (Hewlett-Packard) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [Connexion SFR 9props.exe] => C:\Program Files (x86)\SFR\Kit\9props.exe [976192 2010-07-19] (SFR) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [DriverScanner] => C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe [338296 2011-05-16] (Uniblue Systems Limited) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [GameXN GO] => C:\ProgramData\GameXN\GameXNGO.exe [347008 2011-09-09] (EasyBits Software AS) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [466656 2014-05-23] (Sony) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [spotify Web Helper] => C:\Users\Babakila\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-05-18] (Spotify Ltd) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [CyberGhost] => C:\Program Files\CyberGhost 5\CyberGhost.EXE [404080 2014-06-12] (CyberGhost S.R.L.) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21444224 2014-05-08] (Skype Technologies S.A.) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [puush] => C:\Program Files (x86)\puush\puush.exe [567880 2014-05-11] () HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Policies\system: [DisableChangePassword] 0 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Babakila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {3FE5B696-1B72-40A9-A02E-12A93A7977A1} URL = http://fr.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM - {DF8CD4F7-1BA3-4EFB-B022-AC83C6314BAA} URL = http://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {3FE5B696-1B72-40A9-A02E-12A93A7977A1} URL = http://fr.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM-x32 - {DF8CD4F7-1BA3-4EFB-B022-AC83C6314BAA} URL = http://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF SearchScopes: HKCU - DefaultScope yandex.ru-221635 URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=tele1202&cd=2XzuyEtN2Y1L1Qzu0DyEzzyDyCyE0AyE0FtDzyyD0B0CtAtBtN0D0Tzu0CyBtByCtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1877437213&ir= SearchScopes: HKCU - URL http://search.conduit.com/Results.aspx?gd=&ctid=CT3319415&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=58&CUI=&UM=5&UP=SP61DD3E74-C39D-43DF-BE1F-AF5F42EBE4D7&q={searchTerms}&SSPV= SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} SearchScopes: HKCU - yandex.ru-221635 URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=tele1202&cd=2XzuyEtN2Y1L1Qzu0DyEzzyDyCyE0AyE0FtDzyyD0B0CtAtBtN0D0Tzu0CyBtByCtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1877437213&ir= SearchScopes: HKCU - {3FE5B696-1B72-40A9-A02E-12A93A7977A1} URL = http://fr.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKCU - {DF8CD4F7-1BA3-4EFB-B022-AC83C6314BAA} URL = http://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF BHO: avast! Online Security -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO: No Name -> {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} -> No File BHO-x32: Objet d'aide à la navigation SFR -> {0F6E720A-1A6B-40E1-A294-1D4D19F156C8} -> C:\Program Files (x86)\SFR\Kit\SFRNavErrorHelper.dll (SFR) BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2010-11-23] (EasyBits Software Corp.) Tcpip\..\Interfaces\{F1B2815C-7CD4-44B1-AD5C-7894E67B8C18}: [NameServer]95.169.183.219,89.41.60.38 FireFox: ======== FF ProfilePath: C:\Users\Babakila\AppData\Roaming\Mozilla\Firefox\Profiles\df63j430.default-1378308598723 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) FF Plugin-x32: @real.com/nppl3260;version=6.0.12.69 - C:\Program Files (x86)\Video Convert Master\codec\real\browser\plugins\nppl3260.dll No File FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.69 - C:\Program Files (x86)\Video Convert Master\codec\real\browser\plugins\nprpjplug.dll No File FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.18 - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin-x32: @videolan.org/vlc,version=1.1.11 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Babakila\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: electronicarts.com/GameFacePlugin - C:\Users\Babakila\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts) FF Plugin HKCU: sony.com/MediaGoDetector - C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC) FF user.js: detected! => C:\Users\Babakila\AppData\Roaming\Mozilla\Firefox\Profiles\df63j430.default-1378308598723\user.js FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazon-france.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\cnrtl-tlfi-fr.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-france.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-france.xml FF Extension: iMacros for Firefox - C:\Users\Babakila\AppData\Roaming\Mozilla\Firefox\Profiles\df63j430.default-1378308598723\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2014-05-28] FF Extension: Adblock Plus - C:\Users\Babakila\AppData\Roaming\Mozilla\Firefox\Profiles\df63j430.default-1378308598723\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-20] FF Extension: Greasemonkey - C:\Users\Babakila\AppData\Roaming\Mozilla\Firefox\Profiles\df63j430.default-1378308598723\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2013-12-21] FF Extension: Click to call with Skype - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-06-18] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-01-25] Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.44\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.44\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.44\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Media Go Detector) - C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC) CHR Plugin: (PlayStation®Network Downloader Check Plug-in) - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc) CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc) CHR Plugin: (VLC Multimedia Plug-in) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Unity Player) - C:\Users\Babakila\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Babakila\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) CHR Plugin: (Game Face Plugin) - C:\Users\Babakila\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts) CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Windows Activation Technologies) - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File CHR Extension: (Google Docs) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-08-04] CHR Extension: (Google Drive) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-04] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-07-18] CHR Extension: (YouTube) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-04] CHR Extension: (Google Search) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-04] CHR Extension: (JV Chat Loader) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikeiebaphjpheeemfjnfchlpochgipdd [2013-08-05] CHR Extension: (Skype Click to Call) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-08-04] CHR Extension: (Google Wallet) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-04] CHR Extension: (No Name) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-04] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-08-16] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) S2 BubbleUPnP Server; C:\Program Files (x86)\BubbleUPnP Server\BubbleUPnPServer.exe [196608 2011-11-16] () [File not signed] R2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64624 2014-06-12] (CyberGhost S.R.L) R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed] S2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [74752 2011-11-24] (Freemake) [File not signed] R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed] R2 LightScribeService; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-05-19] (Hewlett-Packard Company) [File not signed] R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-07-16] (LogMeIn, Inc.) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe [234776 2012-09-05] (McAfee, Inc.) S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [4903312 2011-02-23] (INCA Internet Co., Ltd.) [File not signed] R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [635416 2009-10-15] (PDF Complete Inc) S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [21136 2012-10-31] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-07-21] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-07-21] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-07-21] () R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-04-11] (DT Soft Ltd) S3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] () R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited) S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed] S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-24] (Anchorfree Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfoX64.sys [X] S3 dump_wmimmc; \??\C:\Program Files\DBO_CT_TW\GameGuard\dump_wmimmc.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-07-30 14:26 - 2014-07-30 14:26 - 02093568 _____ (Farbar) C:\Users\Babakila\Downloads\FRST64(1).exe 2014-07-30 14:24 - 2014-07-30 14:24 - 159808878 _____ () C:\Users\Babakila\Downloads\misfits.s02e01.french.dvdrip.xvid-jmt.avi.part 2014-07-30 14:24 - 2014-07-30 14:24 - 00000000 _____ () C:\Users\Babakila\Downloads\misfits.s02e01.french.dvdrip.xvid-jmt.avi 2014-07-29 17:08 - 2014-07-29 17:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Phone 2014-07-29 17:07 - 2014-07-29 17:08 - 00000000 ____D () C:\Program Files (x86)\Windows Phone 2014-07-29 17:05 - 2014-07-29 17:05 - 00000000 ____D () C:\ProgramData\Applications 2014-07-29 16:47 - 2014-07-29 16:47 - 06745792 _____ (Microsoft Corporation) C:\Users\Babakila\Downloads\WindowsPhone.exe 2014-07-28 22:31 - 2014-07-28 22:31 - 01007216 _____ (Juniper Networks) C:\Users\Babakila\Downloads\JuniperSetupClientInstaller(1).exe 2014-07-28 22:30 - 2014-07-28 22:31 - 01007216 _____ (Juniper Networks) C:\Users\Babakila\Downloads\JuniperSetupClientInstaller.exe 2014-07-28 16:16 - 2014-07-28 16:28 - 366176973 _____ () C:\Users\Babakila\Downloads\Misfits.S01E06.FiNAL.FRENCH.DVDRip.XviD-JMT-www.Zone-Telechargement.com.avi 2014-07-28 14:38 - 2014-07-28 14:51 - 366312723 _____ () C:\Users\Babakila\Downloads\Misfits.S01E05.FRENCH.DVDRip.XviD-JMT-www.Zone-Telechargement.com.avi 2014-07-28 13:31 - 2014-07-28 13:44 - 366239326 _____ () C:\Users\Babakila\Downloads\Misfits.S01E04.FRENCH.DVDRip.XviD-JMT-www.Zone-Telechargement.com.avi 2014-07-28 12:08 - 2014-07-28 12:20 - 366100254 _____ () C:\Users\Babakila\Downloads\Misfits.S01E03.FRENCH.DVDRip.XviD-JMT-www.Zone-Telechargement.com.avi 2014-07-28 00:40 - 2014-07-28 00:52 - 366130674 _____ () C:\Users\Babakila\Downloads\Misfits.S01E02.FRENCH.DVDRip.XviD-JMT-www.Zone-Telechargement.com.avi 2014-07-28 00:09 - 2014-07-28 00:22 - 366144967 _____ () C:\Users\Babakila\Downloads\Misfits.S01E01.FRENCH.DVDRip.XviD-JMT-www.Zone-Telechargement.com.avi 2014-07-27 21:55 - 2014-07-27 21:55 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-07-27 21:53 - 2014-07-27 21:53 - 00001248 _____ () C:\Users\Babakila\Desktop\malware.txt 2014-07-27 21:25 - 2014-07-27 21:25 - 02347384 _____ (ESET) C:\Users\Babakila\Downloads\esetsmartinstaller_enu.exe 2014-07-27 20:32 - 2014-07-27 20:32 - 00023178 _____ () C:\ComboFix.txt 2014-07-27 19:56 - 2014-07-27 20:33 - 00000000 ____D () C:\Qoobox 2014-07-27 19:56 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-07-27 19:56 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-07-27 19:56 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-07-27 19:56 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-07-27 19:56 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-07-27 19:56 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-07-27 19:56 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-07-27 19:56 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-07-27 19:55 - 2014-07-27 20:27 - 00000000 ____D () C:\Windows\erdnt 2014-07-27 18:22 - 2014-07-27 18:22 - 05563277 ____R (Swearware) C:\Users\Babakila\Downloads\ComboFix.exe 2014-07-27 15:40 - 2014-07-27 15:42 - 00048114 _____ () C:\Users\Babakila\Downloads\Addition.txt 2014-07-27 15:39 - 2014-07-30 14:28 - 00030239 _____ () C:\Users\Babakila\Downloads\FRST.txt 2014-07-27 15:39 - 2014-07-30 14:26 - 00000000 ____D () C:\FRST 2014-07-27 15:38 - 2014-07-27 15:38 - 02093568 _____ (Farbar) C:\Users\Babakila\Downloads\FRST64.exe 2014-07-27 15:09 - 2014-07-27 15:00 - 00016434 _____ () C:\zoek-results2014-07-27-130039.log 2014-07-27 15:07 - 2014-07-27 15:07 - 01287168 _____ () C:\Users\Babakila\Downloads\zoek.exe 2014-07-27 14:53 - 2014-07-27 15:13 - 00019554 _____ () C:\zoek-results.log 2014-07-27 14:47 - 2014-07-27 14:47 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Babakila\Downloads\tdsskiller.exe 2014-07-27 14:47 - 2014-07-27 14:47 - 00000000 ____D () C:\zoek_backup 2014-07-27 14:37 - 2014-07-27 14:38 - 00001057 _____ () C:\DelFix.txt 2014-07-27 13:57 - 2014-07-27 14:36 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-07-27 13:51 - 2014-07-27 13:51 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Babakila\Downloads\mbar-1.07.0.1012.exe 2014-07-26 23:23 - 2014-07-27 21:25 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-26 23:23 - 2014-07-26 23:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-07-26 23:22 - 2014-07-27 13:54 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-26 23:22 - 2014-07-26 23:22 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-07-26 23:22 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-25 18:29 - 2014-07-25 18:29 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\GameXN 2014-07-25 18:29 - 2014-07-25 18:29 - 00000000 ____D () C:\Users\Babakila\AppData\Local\GameXN 2014-07-22 18:36 - 2014-07-22 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2014-07-22 18:36 - 2014-07-22 18:36 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi 2014-07-18 22:56 - 2014-07-18 22:56 - 00000000 ____D () C:\Users\Babakila\Desktop\rouss 2014-07-16 23:16 - 2014-07-25 03:00 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\Users\Public\Documents\Sports Interactive 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\Users\Babakila\Documents\Sports Interactive 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\Users\Babakila\AppData\Local\Sports Interactive 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\ProgramData\Steam 2014-07-09 20:07 - 2014-07-29 12:14 - 00000000 ____D () C:\Program Files (x86)\Football Manager 2014 2014-07-09 09:48 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-07-09 09:48 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-09 09:48 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-09 09:48 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-09 09:48 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-07-09 09:48 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-09 09:48 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-09 09:48 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-09 09:48 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-07-09 09:48 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-07-09 09:48 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-09 09:48 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-09 09:48 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-09 09:48 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-09 09:48 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-07-09 09:48 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-07-09 09:48 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-09 09:48 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-07-09 09:48 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-09 09:48 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-07-09 09:48 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-09 09:48 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-09 09:48 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-09 09:48 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-09 09:48 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-09 09:48 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-09 09:48 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-07-09 09:48 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-07-09 09:48 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-07-09 09:48 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-07-09 09:48 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-09 09:48 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-09 09:48 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-09 09:48 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-07-09 09:48 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-09 09:48 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-07-09 09:48 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-07-09 09:48 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-07-09 09:48 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-07-09 09:48 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-09 09:48 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-07-09 09:48 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-07-09 09:48 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-09 09:48 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-09 09:48 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-09 09:48 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-09 09:48 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-09 09:48 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-09 09:48 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-07-09 09:48 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-09 09:48 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-09 09:48 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-09 09:48 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-07-09 09:48 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-09 09:48 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-09 09:48 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-07-09 09:48 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-07-09 09:48 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-07-09 09:48 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-09 09:48 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-09 09:48 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-07-09 09:48 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-07-09 09:48 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-07-09 09:48 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-07-09 09:48 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-07-09 09:48 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-07-09 09:48 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-07-09 09:48 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-07-09 09:48 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-07-09 09:48 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-07-09 09:48 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-07-09 09:48 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2014-07-09 09:48 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-07-09 09:48 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-07-09 09:48 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-07-09 09:48 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-09 09:47 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-07-09 09:47 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-07-09 09:47 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-07-08 22:18 - 2014-07-08 22:18 - 11204096 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-07-08 15:46 - 2014-07-08 16:21 - 2162077696 _____ () C:\Users\Babakila\Downloads\Football+Manager+2014.iso 2014-07-06 21:31 - 2014-07-06 21:31 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\Juniper Networks ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-07-30 14:28 - 2014-07-27 15:39 - 00030239 _____ () C:\Users\Babakila\Downloads\FRST.txt 2014-07-30 14:26 - 2014-07-30 14:26 - 02093568 _____ (Farbar) C:\Users\Babakila\Downloads\FRST64(1).exe 2014-07-30 14:26 - 2014-07-27 15:39 - 00000000 ____D () C:\FRST 2014-07-30 14:25 - 2011-09-09 17:00 - 00000000 ____D () C:\ProgramData\GameXN 2014-07-30 14:19 - 2014-06-18 14:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-07-30 14:18 - 2012-05-31 19:02 - 00001002 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-30 13:35 - 2013-08-04 23:21 - 00001072 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-30 12:46 - 2011-12-08 16:36 - 00001108 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-816315366-518852455-1505757675-1000UA.job 2014-07-30 12:46 - 2011-12-08 16:36 - 00001086 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-816315366-518852455-1505757675-1000Core.job 2014-07-30 12:29 - 2013-07-25 10:09 - 00101943 _____ () C:\Windows\setupact.log 2014-07-30 12:15 - 2011-06-28 20:39 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\Skype 2014-07-30 12:15 - 2010-11-23 22:10 - 01471816 _____ () C:\Windows\WindowsUpdate.log 2014-07-30 10:35 - 2013-08-04 23:21 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-30 09:39 - 2011-09-08 15:45 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\go 2014-07-29 21:46 - 2012-08-15 21:28 - 00000000 ____D () C:\Users\Babakila\Documents\i-pod fias 2014-07-29 17:08 - 2014-07-29 17:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Phone 2014-07-29 17:08 - 2014-07-29 17:07 - 00000000 ____D () C:\Program Files (x86)\Windows Phone 2014-07-29 17:05 - 2014-07-29 17:05 - 00000000 ____D () C:\ProgramData\Applications 2014-07-29 16:47 - 2014-07-29 16:47 - 06745792 _____ (Microsoft Corporation) C:\Users\Babakila\Downloads\WindowsPhone.exe 2014-07-29 16:14 - 2009-07-14 06:45 - 00015792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-29 16:14 - 2009-07-14 06:45 - 00015792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-29 12:33 - 2010-11-23 22:44 - 00748104 _____ () C:\Windows\system32\perfh00C.dat 2014-07-29 12:33 - 2010-11-23 22:44 - 00150370 _____ () C:\Windows\system32\perfc00C.dat 2014-07-29 12:33 - 2009-07-14 07:13 - 01671168 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-29 11:23 - 2013-03-31 21:20 - 00000000 ____D () C:\Users\Babakila\AppData\Local\LogMeIn Hamachi 2014-07-29 11:18 - 2011-08-18 00:15 - 00000346 _____ () C:\Windows\Tasks\DriverScanner.job 2014-07-29 11:18 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-29 10:41 - 2014-06-21 17:25 - 00000344 _____ () C:\Windows\Tasks\HPCeeScheduleForBabakila.job 2014-07-29 10:40 - 2013-07-25 10:09 - 00259640 _____ () C:\Windows\PFRO.log 2014-07-29 01:43 - 2013-11-13 18:45 - 00000000 ____D () C:\Program Files (x86)\BubbleUPnP Server 2014-07-29 01:10 - 2014-06-21 17:25 - 00003204 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForBabakila 2014-07-29 00:26 - 2010-11-23 22:17 - 00000000 ____D () C:\ProgramData\PDFC 2014-07-29 00:22 - 2011-04-11 18:39 - 00000000 ____D () C:\Windows\PCHEALTH 2014-07-29 00:17 - 2011-05-18 13:57 - 00000000 ____D () C:\Users\Babakila\AppData\Local\CrashDumps 2014-07-28 22:31 - 2014-07-28 22:31 - 01007216 _____ (Juniper Networks) C:\Users\Babakila\Downloads\JuniperSetupClientInstaller(1).exe 2014-07-28 22:31 - 2014-07-28 22:30 - 01007216 _____ (Juniper Networks) C:\Users\Babakila\Downloads\JuniperSetupClientInstaller.exe 2014-07-27 21:55 - 2014-07-27 21:55 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-07-27 21:53 - 2014-07-27 21:53 - 00001248 _____ () C:\Users\Babakila\Desktop\malware.txt 2014-07-27 21:25 - 2014-07-27 21:25 - 02347384 _____ (ESET) C:\Users\Babakila\Downloads\esetsmartinstaller_enu.exe 2014-07-27 21:25 - 2014-07-26 23:23 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-27 20:33 - 2014-07-27 19:56 - 00000000 ____D () C:\Qoobox 2014-07-27 20:33 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-07-27 20:32 - 2014-07-27 20:32 - 00023178 _____ () C:\ComboFix.txt 2014-07-27 20:27 - 2014-07-27 19:55 - 00000000 ____D () C:\Windows\erdnt 2014-07-27 20:15 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-07-27 18:22 - 2014-07-27 18:22 - 05563277 ____R (Swearware) C:\Users\Babakila\Downloads\ComboFix.exe 2014-07-27 15:42 - 2014-07-27 15:40 - 00048114 _____ () C:\Users\Babakila\Downloads\Addition.txt 2014-07-27 15:38 - 2014-07-27 15:38 - 02093568 _____ (Farbar) C:\Users\Babakila\Downloads\FRST64.exe 2014-07-27 15:13 - 2014-07-27 14:53 - 00019554 _____ () C:\zoek-results.log 2014-07-27 15:07 - 2014-07-27 15:07 - 01287168 _____ () C:\Users\Babakila\Downloads\zoek.exe 2014-07-27 15:00 - 2014-07-27 15:09 - 00016434 _____ () C:\zoek-results2014-07-27-130039.log 2014-07-27 14:47 - 2014-07-27 14:47 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Babakila\Downloads\tdsskiller.exe 2014-07-27 14:47 - 2014-07-27 14:47 - 00000000 ____D () C:\zoek_backup 2014-07-27 14:38 - 2014-07-27 14:37 - 00001057 _____ () C:\DelFix.txt 2014-07-27 14:36 - 2014-07-27 13:57 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-07-27 13:54 - 2014-07-26 23:22 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-27 13:51 - 2014-07-27 13:51 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Babakila\Downloads\mbar-1.07.0.1012.exe 2014-07-26 23:27 - 2014-05-23 23:04 - 00000000 ____D () C:\Users\Babakila\Documents\FIFA World 2014-07-26 23:27 - 2013-10-27 09:22 - 00139264 ___SH () C:\Users\Babakila\Documents\Thumbs.db 2014-07-26 23:23 - 2014-07-26 23:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-07-26 23:23 - 2012-01-08 19:53 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-07-26 23:23 - 2011-10-24 15:14 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\Malwarebytes 2014-07-26 23:22 - 2014-07-26 23:22 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-07-26 23:22 - 2011-10-24 15:14 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-25 18:29 - 2014-07-25 18:29 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\GameXN 2014-07-25 18:29 - 2014-07-25 18:29 - 00000000 ____D () C:\Users\Babakila\AppData\Local\GameXN 2014-07-25 18:22 - 2012-06-15 23:10 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-25 18:22 - 2012-06-15 23:10 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-07-25 03:03 - 2012-06-15 23:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-25 03:00 - 2014-07-16 23:16 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-07-24 22:26 - 2013-08-04 23:22 - 00002143 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-24 12:27 - 2012-03-28 17:48 - 00003216 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForFAMILLEBABAKILA$ 2014-07-24 12:27 - 2012-03-28 17:48 - 00000358 _____ () C:\Windows\Tasks\HPCeeScheduleForFAMILLEBABAKILA$.job 2014-07-23 17:21 - 2011-11-02 14:12 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-07-23 17:21 - 2011-04-13 21:11 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-07-22 18:36 - 2014-07-22 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2014-07-22 18:36 - 2014-07-22 18:36 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi 2014-07-22 14:05 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-07-18 22:56 - 2014-07-18 22:56 - 00000000 ____D () C:\Users\Babakila\Desktop\rouss 2014-07-18 10:11 - 2011-04-11 18:38 - 00000000 ____D () C:\Users\Babakila 2014-07-16 23:16 - 2013-03-17 20:52 - 00001884 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-07-16 23:16 - 2011-06-11 13:30 - 00000000 _____ () C:\Windows\SysWOW64\config.nt 2014-07-16 23:15 - 2009-07-14 07:08 - 00032482 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-16 23:12 - 2014-05-11 13:37 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\puush 2014-07-16 23:12 - 2013-10-19 14:46 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\Spotify 2014-07-16 23:12 - 2013-08-14 23:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-07-16 23:12 - 2013-08-04 23:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-07-16 23:12 - 2012-01-01 14:10 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-07-16 23:12 - 2011-10-13 21:12 - 00000000 ____D () C:\Users\Babakila\Documents\Xilisoft Corporation 2014-07-16 23:12 - 2011-09-27 18:20 - 00000000 ____D () C:\Users\Babakila\Documents\My Art 2014-07-16 23:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-07-16 23:10 - 2014-05-28 15:00 - 00000000 ____D () C:\Users\Babakila\Documents\iMacros 2014-07-16 23:10 - 2013-03-14 15:22 - 00000000 ____D () C:\Users\Babakila\Documents\My Games 2014-07-16 23:10 - 2012-10-30 13:26 - 00000000 ____D () C:\Users\Babakila\Documents\EA Games 2014-07-16 23:10 - 2012-06-25 20:23 - 00000000 ____D () C:\Users\Babakila\Documents\Fax 2014-07-16 23:10 - 2012-05-14 16:40 - 00000000 ____D () C:\Users\Babakila\Documents\LimeWire 2014-07-16 23:10 - 2011-04-11 23:27 - 00000000 ____D () C:\Users\Babakila\Documents\Electronic Arts 2014-07-15 14:57 - 2013-10-19 14:46 - 00000000 ____D () C:\Users\Babakila\AppData\Local\Spotify 2014-07-14 19:42 - 2011-09-19 12:06 - 00000000 ____D () C:\Users\Babakila\Documents\Galy ecole 2014-07-11 11:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-07-10 09:51 - 2011-04-11 21:51 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite 2014-07-10 09:48 - 2009-07-14 06:45 - 04865032 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-10 03:14 - 2009-07-14 09:45 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-10 03:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2014-07-10 03:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism 2014-07-10 03:07 - 2013-07-25 22:11 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-10 03:03 - 2011-11-28 19:41 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\Users\Public\Documents\Sports Interactive 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\Users\Babakila\Documents\Sports Interactive 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\Users\Babakila\AppData\Local\Sports Interactive 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\ProgramData\Steam 2014-07-09 20:06 - 2011-04-11 21:51 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\DAEMON Tools Lite 2014-07-08 22:19 - 2012-05-31 19:02 - 00003940 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-07-08 22:19 - 2012-05-30 14:37 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-07-08 22:19 - 2012-02-04 10:40 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-07-08 22:18 - 2014-07-08 22:18 - 11204096 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-07-06 21:31 - 2014-07-06 21:31 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\Juniper Networks ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-29 14:25 ==================== End Of Log ============================ There's no problem actually
  4. Sorry wasn't aware of this being installed, I'm deleting all of this Sorry again
  5. ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=c838c7d6adc6b0448b916d4c0eb7f5bb # engine=19379 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2014-07-28 03:51:01 # local_time=2014-07-28 05:51:01 ) # country="France" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=777 16777213 100 100 1017343 183268933 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 290600 158192511 0 0 # scanned=527934 # found=26 # cleaned=0 # scan_time=24675 sh=42641E6015220DB5095B28606C82C003E2DB097B ft=1 fh=aff2050af91a0498 vn="a variant of Win32/HackTool.CheatEngine.AB potentially unsafe application" ac=I fn="C:\Program Files (x86)\Cheat Engine 6.1\cheatengine-i386.exe" sh=88F07DB216F388A603179649D83BF1FC9AC8CB06 ft=1 fh=b538b1f51b2210a0 vn="a variant of Win32/HackTool.CheatEngine.AB potentially unsafe application" ac=I fn="C:\Program Files (x86)\Cheat Engine 6.2\cheatengine-i386.exe" sh=CA3F51EC1897756636232998193325B830F22F26 ft=1 fh=3702c3e3af3ccb17 vn="a variant of Win32/HackTool.CheatEngine.AF potentially unsafe application" ac=I fn="C:\Program Files (x86)\Cheat Engine 6.2\standalonephase1.dat" sh=7B57C2E98A52C5104F1A995D3ACEEC86F8323563 ft=1 fh=586cc1657f347032 vn="a variant of Win32/HackTool.Crack.BL potentially unsafe application" ac=I fn="C:\Program Files (x86)\Football Manager 2014\steam_api.dll" sh=BFD5B993F7932EFB6589090F4606E53F56A5B988 ft=1 fh=6290f236502f5883 vn="a variant of Win32/KeyLogger.Ardamax.NBG application" ac=I fn="C:\ProgramData\IPB\AKV.exe" sh=BFD5B993F7932EFB6589090F4606E53F56A5B988 ft=1 fh=6290f236502f5883 vn="a variant of Win32/KeyLogger.Ardamax.NBG application" ac=I fn="C:\Users\All Users\IPB\AKV.exe" sh=442985568DA94C0E874F416001F8BA846EF362F7 ft=1 fh=28fc657a40578013 vn="a variant of Win32/AdWare.MultiPlug.AQ application" ac=I fn="C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Cache\f_001426" sh=442985568DA94C0E874F416001F8BA846EF362F7 ft=1 fh=28fc657a40578013 vn="a variant of Win32/AdWare.MultiPlug.AQ application" ac=I fn="C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\File System\006\t\00\00000000" sh=F9A9E4359278D945DD10EE6C3456383B16493B64 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2011-3544.AW trojan" ac=I fn="C:\Users\Babakila\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\12a9bf7b-79a8ccc2" sh=573A43817F0310ABE662F7DFC97A78ED348BC1EA ft=1 fh=cffc82aa069b8de9 vn="Win32/OpenCandy potentially unsafe application" ac=I fn="C:\Users\Babakila\Downloads\CheatEngine62.exe" sh=87A72B063BB6DD52C98DA7F766B68D8DFA45F9E8 ft=0 fh=0000000000000000 vn="a variant of Win32/HackTool.Crack.BL potentially unsafe application" ac=I fn="C:\Users\Babakila\Downloads\Football+Manager+2014.iso" sh=A9472E497C42CD91866472FE9869C276662B5FE4 ft=1 fh=5df048d54c7d811b vn="Win32/D2Surf.A potentially unsafe application" ac=I fn="C:\Users\Babakila\Downloads\setup.exe" sh=9FE17338D2F275070EF6650E1F6426BCC0450C1B ft=1 fh=93af1575eec2c726 vn="Win32/KeyLogger.Ardamax potentially unsafe application" ac=I fn="C:\Users\Babakila\Downloads\setup_akl.exe" sh=B453000199B9E50FA9055FAC266163C5BC4ACE70 ft=1 fh=0922b47c4196a923 vn="a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application" ac=I fn="C:\Users\Babakila\Music\Nouveau dossier\avira_antivirus_personal_fr.exe" sh=A8A37E54DB53B64808D4DE3DDBB505859E9F4269 ft=1 fh=b799c6fdeb2be9bc vn="Win32/Bundled.Toolbar.Google.E potentially unsafe application" ac=I fn="C:\Users\Babakila\Music\Nouveau dossier\ccsetup311.exe" sh=F82BA0F478BAF34CBF5F13ADB22A72B8829135A9 ft=1 fh=65fc87673ce8ba03 vn="a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application" ac=I fn="C:\Users\Babakila\Music\Nouveau dossier\pf-setup-fr-652.exe" sh=FC204D22EB99DF6505E8AC916E166B3F07CE463E ft=1 fh=d9677f7f8890f1ba vn="Win32/Toolbar.SearchSuite potentially unwanted application" ac=I fn="C:\Users\Babakila\Music\Nouveau dossier\Setup_FreeVideoConverter(1).exe" sh=5F71467BF54C260FD6CFD44A6EBF49BAED54964F ft=1 fh=1988af5f4f490573 vn="Win32/Toolbar.SearchSuite potentially unwanted application" ac=I fn="C:\Users\Babakila\Music\Nouveau dossier\Setup_FreeVideoConverter.exe" sh=85C2E758DADB8A93064CA5CEDF96BC69C021B84C ft=1 fh=1f9bbc275addc6d3 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application" ac=I fn="C:\Users\Babakila\Pictures\Jeff\Jeff 2\01net_Recuva\rcsetup151.exe" sh=7B57C2E98A52C5104F1A995D3ACEEC86F8323563 ft=1 fh=586cc1657f347032 vn="a variant of Win32/HackTool.Crack.BL potentially unsafe application" ac=I fn="C:\Users\Babakila\Pictures\Jeff\Mishaan\steam_api.dll" sh=E62D5D2D0C316F5818AF5204B9430FDD53913458 ft=1 fh=f42cb0ef0c3bfaeb vn="Win32/OpenCandy potentially unsafe application" ac=I fn="C:\Users\Babakila\Pictures\Jeff\Mishaan\ty\CrystalDiskInfo5_4_2Shizuku-en.exe" sh=5A51B7120F85728CF3EAB6DEDBE70BA8EBC3CE6D ft=0 fh=0000000000000000 vn="a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application" ac=I fn="C:\Windows\Installer\cf6665.msi" sh=B5B41E946960F17050C00A4891CFF46B08486A4D ft=1 fh=79895fd74f1827db vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application" ac=I fn="C:\Windows\System32\Adobe\Shockwave 12\gt.exe" sh=93AB339299C0CF9A4DD56383876EA81303BFCDAB ft=0 fh=0000000000000000 vn="a variant of Win32/Adware.OneStep.AT application" ac=I fn="C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M\upgrade[1].cab" sh=B5B41E946960F17050C00A4891CFF46B08486A4D ft=1 fh=79895fd74f1827db vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application" ac=I fn="C:\Windows\SysWOW64\Adobe\Shockwave 12\gt.exe" sh=93AB339299C0CF9A4DD56383876EA81303BFCDAB ft=0 fh=0000000000000000 vn="a variant of Win32/Adware.OneStep.AT application" ac=I fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M\upgrade[1].cab"
  6. It's been running for almost 7 hours and it's only at 31%, is it normal?
  7. Woke up and saw that Eset have been closed, I don't know why so I launched another scan
  8. It's been 1h16 and Eset's scan is still at 18%, it seems that i'll let the computer run this night and post the result when I wake up...
  9. First Malware result: Malwarebytes Anti-Malware www.malwarebytes.org Date de l'examen: 27/07/2014 Heure de l'examen: 21:25:01 Fichier journal: malware.txt Administrateur: Oui Version: 2.00.2.1012 Base de données Malveillants: v2014.07.27.07 Base de données Rootkits: v2014.07.17.01 Licence: Gratuite Protection contre les malveillants: Désactivé(e) Protection contre les sites Web malveillants: Désactivé(e) Self-protection: Désactivé(e) Système d'exploitation: Windows 7 Service Pack 1 Processeur: x64 Système de fichiers: NTFS Utilisateur: Babakila Type d'examen: Examen "Menaces" Résultat: Terminé Objets analysés: 323711 Temps écoulé: 19 min, 0 sec Mémoire: Activé(e) Démarrage: Activé(e) Système de fichiers: Activé(e) Archives: Activé(e) Rootkits: Activé(e) Heuristics: Activé(e) PUP: Avertir PUM: Activé(e) Processus: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Clés du Registre: 0 (No malicious items detected) Valeurs du Registre: 0 (No malicious items detected) Données du Registre: 0 (No malicious items detected) Dossiers: 0 (No malicious items detected) Fichiers: 0 (No malicious items detected) Secteurs physiques: 0 (No malicious items detected) (end)
  10. I've just saw your reply so I'm doing it but I have to add that there's no longer alerts from avast
  11. There is the result: ComboFix 14-07-25.01 - Babakila 27/07/2014 19:58:23.1.2 - x64 Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.33.1036.18.4061.2451 [GMT 2:00] Lancé depuis: c:\users\Babakila\Downloads\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Autres suppressions )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\END c:\programdata\1349264738.bdinstall.bin c:\programdata\1349265079.bdinstall.bin c:\programdata\eee0e59a97827a23604c0113a1216970_c c:\users\Babakila\AppData\Roaming\chrtmp c:\users\Babakila\Documents\~WRL1950.tmp c:\windows\SysWow64\6ffdbcaf-f6c1-42d3-a4a9-c7957224a70b.dll . . ((((((((((((((((((((((((((((( Fichiers créés du 2014-06-27 au 2014-07-27 )))))))))))))))))))))))))))))))))))) . . 2014-07-27 18:14 . 2014-07-27 18:14 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-07-27 13:39 . 2014-07-27 13:41 -------- d-----w- C:\FRST 2014-07-27 12:47 . 2014-07-27 12:47 -------- d-----w- C:\zoek_backup 2014-07-27 11:57 . 2014-07-27 12:36 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable) 2014-07-26 22:59 . 2014-07-26 22:59 79064 ----a-w- c:\windows\system32\drivers\tgcremv.sys 2014-07-26 21:23 . 2014-07-27 14:21 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-07-26 21:22 . 2014-07-27 11:54 92888 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-07-26 21:22 . 2014-05-12 05:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys 2014-07-26 21:22 . 2014-07-26 21:22 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware 2014-07-25 16:29 . 2014-07-25 16:29 -------- d-----w- c:\users\Babakila\AppData\Roaming\GameXN 2014-07-25 16:29 . 2014-07-25 16:29 -------- d-----w- c:\users\Babakila\AppData\Local\GameXN 2014-07-25 07:07 . 2014-07-14 02:12 10924376 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{83E01FC4-3D32-4843-8188-A17667DF5AD5}\mpengine.dll 2014-07-22 16:36 . 2014-07-22 16:36 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi 2014-07-09 18:36 . 2014-07-09 18:36 -------- d-----w- c:\users\Babakila\AppData\Local\Sports Interactive 2014-07-09 18:36 . 2014-07-09 18:36 -------- d-----w- c:\programdata\Steam 2014-07-09 18:07 . 2014-07-09 18:43 -------- d-----w- c:\program files (x86)\Football Manager 2014 2014-07-09 07:49 . 2014-06-03 10:02 1719296 ----a-w- c:\program files\Windows Journal\NBDoc.DLL 2014-07-09 07:49 . 2014-06-03 10:02 1389568 ----a-w- c:\program files\Windows Journal\JNWDRV.dll 2014-07-09 07:49 . 2014-06-03 10:02 1380864 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll 2014-07-09 07:49 . 2014-06-03 10:02 1354240 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2014-07-09 07:49 . 2014-06-03 09:29 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2014-07-09 07:47 . 2014-06-05 14:45 1460736 ----a-w- c:\windows\system32\lsasrv.dll 2014-07-09 07:47 . 2014-06-05 14:26 22016 ----a-w- c:\windows\SysWow64\secur32.dll 2014-07-09 07:47 . 2014-06-05 14:25 96768 ----a-w- c:\windows\SysWow64\sspicli.dll 2014-07-08 20:18 . 2014-07-08 20:18 11204096 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2014-07-06 19:31 . 2014-07-06 19:31 -------- d-----w- c:\users\Babakila\AppData\Roaming\Juniper Networks . . . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2014-07-10 01:03 . 2011-11-28 17:41 96441528 ----a-w- c:\windows\system32\MRT.exe 2014-07-08 20:19 . 2012-05-30 12:37 699056 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-07-08 20:19 . 2012-02-04 08:40 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-05-12 05:25 . 2011-10-24 13:13 25816 ----a-w- c:\windows\system32\drivers\mbam.sys 2014-05-09 06:14 . 2014-05-15 10:35 477184 ----a-w- c:\windows\system32\aepdu.dll 2014-05-09 06:11 . 2014-05-15 10:35 424448 ----a-w- c:\windows\system32\aeinv.dll . . ((((((((((((((((((((((((((((((((( Points de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}] 2010-07-19 16:32 165184 ----a-w- c:\program files (x86)\SFR\Kit\SFRNavErrorHelper.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HPAdvisorDock"="c:\program files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe" [2010-09-28 1715768] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408] "Connexion SFR 9props.exe"="c:\program files (x86)\SFR\Kit\9props.exe" [2010-07-19 976192] "DriverScanner"="c:\program files (x86)\Uniblue\DriverScanner\launcher.exe" [2011-05-16 338296] "GameXN GO"="c:\programdata\GameXN\GameXNGO.exe" [2011-09-09 347008] "Sony PC Companion"="c:\program files (x86)\Sony\Sony PC Companion\PCCompanion.exe" [2014-05-23 466656] "Spotify Web Helper"="c:\users\Babakila\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2014-05-18 1176632] "CyberGhost"="c:\program files\CyberGhost 5\CyberGhost.EXE" [2014-06-12 404080] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-05-08 21444224] "puush"="c:\program files (x86)\puush\puush.exe" [2014-05-11 567880] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "PDF Complete"="c:\program files (x86)\PDF Complete\pdfsty.exe" [2009-10-14 563736] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576] "Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2010-04-25 61112] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992] "LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2011-08-12 205336] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968] "SuperVigil"="c:\programdata\SuperVigil\SyScript\SysPlug.exe" [2012-10-03 984680] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] "PWRISOVM.EXE"="c:\program files (x86)\PowerISO\PWRISOVM.EXE" [2013-01-27 337432] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888] "Magic Desktop for HP notification"="c:\programdata\Easybits Magic Desktop for HP\mdhpSUN.exe" [2013-07-27 1238016] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-10-23 152392] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2014-07-21 3816784] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "Malwarebytes Anti-Malware (cleanup)"="c:\programdata\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe" [2014-05-12 54072] . c:\users\Babakila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe [2012-9-5 271808] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "HideFastUserSwitching"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) . [hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R2 BubbleUPnP Server;BubbleUPnP Server;c:\program files (x86)\BubbleUPnP Server\BubbleUPnPServer.exe;c:\program files (x86)\BubbleUPnP Server\BubbleUPnPServer.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 Freemake Improver;Freemake Improver;c:\programdata\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe;c:\programdata\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [x] R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 dump_wmimmc;dump_wmimmc;c:\program files\DBO_CT_TW\GameGuard\dump_wmimmc.sys;c:\program files\DBO_CT_TW\GameGuard\dump_wmimmc.sys [x] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys;c:\windows\SYSNATIVE\DRIVERS\ggflt.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x] R3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys;c:\windows\SYSNATIVE\DRIVERS\LVPr2M64.sys [x] R3 LVUVC64;Logitech Webcam C100(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe;c:\program files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe [x] R3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys;c:\windows\SYSNATIVE\DRIVERS\MijXfilt.sys [x] R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys;c:\windows\SYSNATIVE\DRIVERS\netaapl64.sys [x] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x] R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S1 aswKbd;aswKbd; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 CGVPNCliService;CyberGhost VPN 5 Client Service;c:\program files\CyberGhost 5\Service.exe;c:\program files\CyberGhost 5\Service.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 ezSharedSvc;Easybits Services for Windows;c:\windows\System32\ezSharedSvcHost.exe;c:\windows\SYSNATIVE\ezSharedSvcHost.exe [x] S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x] S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x] S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe;c:\program files (x86)\PDF Complete\pdfsvc.exe [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] . . --- Autres Services/Pilotes en mémoire --- . *NewlyCreated* - 40522219 *NewlyCreated* - 42467388 *NewlyCreated* - MBAMWEBACCESSCONTROL *Deregistered* - 40522219 *Deregistered* - 42467388 *Deregistered* - MBAMWebAccessControl . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-07-24 20:21 1096520 ----a-w- c:\program files (x86)\Google\Chrome\Application\37.0.2062.44\Installer\chrmstp.exe . Contenu du dossier 'Tâches planifiées' . 2014-07-27 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-30 20:19] . 2014-07-25 c:\windows\Tasks\DriverScanner.job - c:\program files (x86)\Uniblue\DriverScanner\dsmonitor.exe [2011-08-17 09:22] . 2014-07-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-816315366-518852455-1505757675-1000Core.job - c:\users\Babakila\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-12-08 10:41] . 2014-07-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-816315366-518852455-1505757675-1000UA.job - c:\users\Babakila\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-12-08 10:41] . 2014-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-04 21:21] . 2014-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-04 21:21] . 2014-07-27 c:\windows\Tasks\HPCeeScheduleForBabakila.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 11:53] . 2014-07-24 c:\windows\Tasks\HPCeeScheduleForFAMILLEBABAKILA$.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 11:53] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-05-09 08:58 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "NCPluginUpdater"="c:\program files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" [2014-07-23 21720] . ------- Examen supplémentaire ------- . uStart Page = hxxp://www.google.com uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local TCP: Interfaces\{F1B2815C-7CD4-44B1-AD5C-7894E67B8C18}: NameServer = 95.169.183.219,89.41.60.38 FF - ProfilePath - c:\users\Babakila\AppData\Roaming\Mozilla\Firefox\Profiles\df63j430.default-1378308598723\ . - - - - ORPHELINS SUPPRIMES - - - - . Wow6432Node-HKCU-Run-AdobeBridge - (no file) Wow6432Node-HKLM-Run-<NO NAME> - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start BHO-{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - (no file) AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe AddRemove-Update Service - c:\users\Babakila\Desktop\Update Service\uninst.exe AddRemove-{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE} - c:\program files (x86)\InstallShield Installation Information\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}\setup.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher] "ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- CLES DE REGISTRE BLOQUEES --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.14" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Heure de fin: 2014-07-27 20:32:21 ComboFix-quarantined-files.txt 2014-07-27 18:32 . Avant-CF: 245 002 698 752 octets libres Après-CF: 246 777 044 992 octets libres . - - End Of File - - D13D8B96E2070AB234336BE1417D317B D6A87DFE60244F737228E24C39A3D2C6
  12. And there's addition.txt: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-07-2014 Ran by Babakila at 2014-07-27 15:40:55 Running from C:\Users\Babakila\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C} AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKLM-x32\...\uTorrent) (Version: 3.2.1.28086 - BitTorrent Inc.) A Heart of Darkness (HKLM-x32\...\Victoria II - A Heart of Darkness_is1) (Version: 3.0.1 - Paradox Interactive) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.8.0.870 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.8.0.870 - Adobe Systems Incorporated) Hidden Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.4.980 - Adobe Systems Incorporated.) Adobe Community Help (x32 Version: 3.4.980 - Adobe Systems Incorporated.) Hidden Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.0.2 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.0.2 - Adobe Systems Incorporated) Hidden Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Photoshop CS5 (HKLM-x32\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Français (HKLM-x32\...\{AC76BA86-7AD7-1036-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.3.133 - Adobe Systems, Inc.) AION Free-To-Play (HKLM-x32\...\InstallShield_{6A9EF6CF-7630-4E33-AE22-7D70F3AF4B05}) (Version: 2.70.0000 - Gameforge) AION Free-To-Play (x32 Version: 2.70.0000 - Gameforge) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM-x32\...\{C6579A65-9CAE-4B31-8B6B-3306E0630A66}) (Version: 2.1.3.127 - Apple Inc.) Ardamax Keylogger 4.0.1 (HKCU\...\Ardamax Keylogger 4.0.1) (Version: - ) Audacity 2.0.2 (HKLM-x32\...\Audacity_is1) (Version: 2.0.2 - Audacity Team) avast! Free Antivirus (HKLM-x32\...\avast) (Version: 8.0.1489.0 - AVAST Software) AviSynth 2.5 (HKLM-x32\...\AviSynth) (Version: - ) AVS Screen Capture version 2.0.1 (HKLM-x32\...\AVS Screen Capture_is1) (Version: - Online Media Technologies Ltd.) AVS Update Manager 1.0 (HKLM-x32\...\AVS Update Manager_is1) (Version: - Online Media Technologies Ltd.) AVS Video Editor 6 (HKLM-x32\...\AVS Video Editor_is1) (Version: - Online Media Technologies Ltd.) AVS Video Recorder 2.4 (HKLM-x32\...\AVS Video Recorder_is1) (Version: - Online Media Technologies Ltd.) AVS4YOU Software Navigator 1.4 (HKLM-x32\...\AVS4YOU Software Navigator_is1) (Version: - Online Media Technologies Ltd.) Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) BubbleUPnP Server (HKLM-x32\...\BubbleUPnP Server) (Version: - ) CameraHelperMsi (x32 Version: 13.30.1395.0 - Logitech) Hidden CCleaner (HKLM\...\CCleaner) (Version: 3.11 - Piriform) Cheat Engine 6.1 (HKLM-x32\...\Cheat Engine 6.1_is1) (Version: - Dark Byte) Cheat Engine 6.2 (HKLM-x32\...\Cheat Engine 6.2_is1) (Version: - Dark Byte) Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Click to Call with Skype (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.6.8153 - Skype Technologies S.A.) Coffret de pilotes Logitech Webcam Software (HKLM\...\lvdrivers_12.10) (Version: 12.10.1110 - Logitech Inc.) CopyTrans Suite désinstallation uniquement (HKCU\...\CopyTrans Suite) (Version: 2.36 - WindSolutions) Crusader Kings II (HKLM-x32\...\Crusader Kings II_is1) (Version: - ) CrystalDiskInfo 5.4.2 Shizuku Edition (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 5.4.2 - Crystal Dew World) CyberGhost 5 (HKLM\...\CyberGhost VPN 5_is1) (Version: - CyberGhost S.R.L.) CyberLink DVD Suite Deluxe (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.2823 - CyberLink Corp.) CyberLink DVD Suite Deluxe (x32 Version: 7.0.2823 - CyberLink Corp.) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.40.2.0131 - DT Soft Ltd) Darkest Hour (HKLM-x32\...\{09D5819F-0F1A-4480-A112-B5CCA58D9773}_is1) (Version: - Darkest Hour Team) Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden DVD Menu Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}) (Version: 4.1.4030 - Hewlett-Packard) DVD Menu Pack for HP MediaSmart Video (x32 Version: 4.1.4030 - Hewlett-Packard) Hidden EA Sports FIFA World (HKLM-x32\...\{8F9AC744-EEF6-43DB-A4B6-FA1A18F1C640}) (Version: 5.3.0.40277 - Electronic Arts, Inc.) EA SPORTS Game Face Browser Plugin 1.8.0.0 (HKCU\...\EA SPORTS Game Face Browser Plugin) (Version: 1.8.0.0 - Electronic Arts) Easy Drive Data Recovery (HKLM-x32\...\Easy Drive Data Recovery) (Version: 3.0 - MunSoft) Emit version 1.11 (HKLM-x32\...\{91092771-7812-483E-A276-4D5977982BC5}_is1) (Version: 1.11 - Biokoda d.o.o.) erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden eSupport UndeletePlus 3.0.5.313 (HKLM-x32\...\eSupport UndeletePlus_is1) (Version: - Copyright © 2013 eSupport.com • All Rights Reserved) Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited) FATE (x32 Version: 2.2.0.95 - WildTangent) Hidden FIFA 2005 DEMO (HKLM-x32\...\{E4E3E62E-16D7-425E-009C-DCB5E64F5955}) (Version: - ) Flashtool (HKLM-x32\...\Flashtool) (Version: 0.9.10.1 - Androxyde) Football Manager 2014 (HKLM-x32\...\Rm9vdGJhbGxNYW5hZ2VyMjAxNA==_is1) (Version: 1 - ) Free Video Converter V 3.0 (HKLM-x32\...\Free Video Converter_is1) (Version: 3.0.0.0 - Koyote Soft) Galerie de photos Windows Live (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden GameXN GO (HKCU\...\Game Organizer) (Version: - GameXN AS) GIMP 2.6.11 (HKLM-x32\...\WinGimp-2.0_is1) (Version: 2.6.11 - The GIMP Team) GmoteServer (HKLM-x32\...\DDA23392-9C73-4909-A221-BC12C6D2664D) (Version: 2.0.2 - Gmote.org) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.44 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Advisor (HKLM-x32\...\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.4.12850.3526 - Hewlett-Packard) HP Customer Experience Enhancements (x32 Version: 6.0.1.4 - Hewlett-Packard) Hidden HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.1.3 - WildTangent) HP MediaSmart DVD (HKLM-x32\...\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 4.1.4229 - Hewlett-Packard) HP MediaSmart DVD (x32 Version: 4.1.4229 - Hewlett-Packard) Hidden HP MediaSmart Music (HKLM-x32\...\InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}) (Version: 4.1.4301 - Hewlett-Packard) HP MediaSmart Music (x32 Version: 4.1.4301 - Hewlett-Packard) Hidden HP MediaSmart Photo (HKLM-x32\...\InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}) (Version: 4.1.4211 - Hewlett-Packard) HP MediaSmart Photo (x32 Version: 4.1.4211 - Hewlett-Packard) Hidden HP MediaSmart SmartMenu (HKLM\...\{5B08AF35-B699-4A44-BB89-3E51E70611E8}) (Version: 3.1.1.12 - Hewlett-Packard) HP MediaSmart Video (HKLM-x32\...\InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}) (Version: 4.1.4214 - Hewlett-Packard) HP MediaSmart Video (x32 Version: 4.1.4214 - Hewlett-Packard) Hidden HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard) HP Product Detection (HKLM-x32\...\{A436F67F-687E-4736-BD2B-537121A804CF}) (Version: 11.14.0001 - HP) HP Setup (HKLM-x32\...\{72D90DB3-A16A-4545-B555-868471101833}) (Version: 8.1.4186.3400 - Hewlett-Packard) HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company) HP Support Information (HKLM-x32\...\{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}) (Version: 10.1.0002 - Hewlett-Packard) HP Update (HKLM-x32\...\{DE77FE3F-A33D-499A-87AD-5FC406617B40}) (Version: 5.002.003.003 - Hewlett-Packard) HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.1.2.27173 - Hewlett-Packard) Index.dat Analyzer v2.5 (HKLM-x32\...\Index.dat Analyzer_is1) (Version: 2.5 - Systenance Software) Insaniquarium Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Installation Windows Live (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation) Installation Windows Live (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden Intel® Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2119 - Intel Corporation) iTunes (HKLM\...\{A04DCB25-7040-4935-A30D-8E0A893ABF2D}) (Version: 11.1.2.32 - Apple Inc.) Java 7 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.250 - Oracle) Java Auto Updater (x32 Version: 2.1.9.5 - Sun Microsystems, Inc.) Hidden Java 6 Update 30 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216020FF}) (Version: 6.0.300 - Sun Microsystems, Inc.) JavaFX 2.1.0 (HKLM-x32\...\{1111706F-666A-4037-7777-210328764D10}) (Version: 2.1.0 - Oracle Corporation) Jewel Quest II (x32 Version: 2.2.0.95 - WildTangent) Hidden Jewel Quest Solitaire (x32 Version: 2.2.0.95 - WildTangent) Hidden John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden Juniper Networks Setup Client (HKCU\...\Juniper_Setup_Client) (Version: 2.1.2.5973 - Juniper Networks) Juniper Networks Setup Client Activex Control (HKLM-x32\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks) Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2823 - CyberLink Corp.) LabelPrint (x32 Version: 2.5.2823 - CyberLink Corp.) Hidden Les Sims 2 (HKLM-x32\...\{6E7DD182-9FC6-4651-0095-2E666CC6AF35}) (Version: - ) Les Sims 2 : Nuits de Folie (HKLM-x32\...\{F7529650-B9DB-481B-0089-A2AC3C2821C1}) (Version: - ) Les Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.26.89 - Electronic Arts) Les Sims™ 3 Accès VIP (HKLM-x32\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts) Les Sims™ 3 Générations (HKLM-x32\...\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts) Les Sims™ 3 Destination Aventure (HKLM-x32\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts) Les Sims™ 3 Animaux & Cie (HKLM-x32\...\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts) LightScribe System Software (HKLM-x32\...\{46BA053F-57B3-4153-BDB6-D37EEC8B12D7}) (Version: 1.18.15.1 - LightScribe) LimeWire 5.6.2 (HKLM-x32\...\{77B6E212-9E3B-4D79-815D-EFBC2EBA14B3}_is1) (Version: 5.6.2 - HackWare,Inc) Logitech Vid HD (HKLM-x32\...\Logitech Vid) (Version: 7.2 (7259) - Logitech Inc..) Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.30 - Logitech Inc.) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.227 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.2.0.227 - LogMeIn, Inc.) Hidden LPEConnectFix 1.0 (HKLM-x32\...\LPEConnectFix_is1) (Version: - LOTR, Inc. lol www.gnutellaforums.com/) LWS Facebook (x32 Version: 13.30.1346.0 - Logitech) Hidden LWS Gallery (x32 Version: 13.30.1379.0 - Logitech) Hidden LWS Help_main (x32 Version: 13.30.1396.0 - Logitech) Hidden LWS Launcher (x32 Version: 13.30.1379.0 - Logitech) Hidden LWS Motion Detection (x32 Version: 13.30.1395.0 - Logitech) Hidden LWS Pictures And Video (x32 Version: 13.30.1395.0 - Logitech) Hidden LWS Twitter (x32 Version: 13.30.1346.0 - Logitech) Hidden LWS Video Mask Maker (x32 Version: 13.30.1379.0 - Logitech) Hidden LWS VideoEffects (Version: 13.30.1379.0 - Logitech) Hidden LWS Webcam Software (x32 Version: 13.30.1379.0 - Logitech) Hidden LWS WLM Plugin (x32 Version: 1.30.1201.0 - Logitech) Hidden LWS YouTube Plugin (x32 Version: 13.30.1346.0 - Logitech) Hidden Magic Desktop (HKLM-x32\...\EasyBits Magic Desktop) (Version: - EasyBits Software AS) Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) McAfee Security Scan Plus (HKLM-x32\...\McAfee Security Scan) (Version: 3.0.285.6 - McAfee, Inc.) Media Go (HKLM-x32\...\{7547239C-FA8A-4FA4-84A6-31EAC0777E1B}) (Version: 2.7.341 - Sony) Media Go Network Downloader (HKLM-x32\...\{73FA7631-3015-4EEC-A002-09488C47A07C}) (Version: 1.5.19.0 - Sony) Media Go Video Playback Engine 2.4.112.12050 (HKLM-x32\...\{7C5AEEE1-6D7C-8922-4548-7BF9096077EC}) (Version: 2.4.112.12050 - Sony) Microsoft .NET Framework 4.5.1 (FRA) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Français) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1036) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden Microsoft Office « Démarrer en un clic » 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4734.1000 - Microsoft Corporation) Microsoft Office « Démarrer en un clic » 2010 (Version: 14.0.4734.1000 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - Français (HKLM-x32\...\{90140011-0066-040C-0000-0000000FF1CE}) (Version: 14.0.4734.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden MotioninJoy DS3 driver version 0.6.0005 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.6.0005 - www.motioninjoy.com) Movie Theme Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}) (Version: 4.1.4030 - Hewlett-Packard) Movie Theme Pack for HP MediaSmart Video (x32 Version: 4.1.4030 - Hewlett-Packard) Hidden Mozilla Firefox 30.0 (x86 fr) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 fr)) (Version: 30.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MusicStation (HKLM-x32\...\MusicStationNetstaller) (Version: 1.0.1.5 - Hewlett-Packard) NC Launcher (GameForge) (HKLM-x32\...\NCLauncher_GameForge) (Version: - NCsoft) OpenOffice.org 3.3 (HKLM-x32\...\{05653DE1-6567-40C6-B930-39D399B64369}) (Version: 3.3.9567 - OpenOffice.org) Origin (HKLM-x32\...\Origin) (Version: 9.3.10.4710 - Electronic Arts, Inc.) Outil de téléchargement Windows Live (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) PDF Complete Special Edition (HKLM-x32\...\PDF Complete) (Version: 3.5.111 - PDF Complete, Inc) PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden PhotoFiltre (HKCU\...\PhotoFiltre) (Version: - ) PhotoFiltre Studio X (HKCU\...\PhotoFiltre Studio X) (Version: - ) PhotoNow! (HKLM-x32\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.6904 - CyberLink Corp.) PhotoNow! (x32 Version: 1.1.6904 - CyberLink Corp.) Hidden Plants vs. Zombies (x32 Version: 2.2.0.95 - WildTangent) Hidden PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) PlayStation®Network Downloader (HKLM-x32\...\{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}) (Version: 2.07.00849 - Sony Computer Entertainment Inc.) PlayStation®Store (HKLM-x32\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.16.2.15545 - Sony Computer Entertainment Inc.) Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.4022 - CyberLink Corp.) Power2Go (x32 Version: 6.1.4022 - CyberLink Corp.) Hidden PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.2906 - CyberLink Corp.) PowerDirector (x32 Version: 8.0.2906 - CyberLink Corp.) Hidden PowerISO (HKLM-x32\...\PowerISO) (Version: 5.5 - Power Software Ltd) PressReader (HKLM-x32\...\{912CED74-88D3-4C5B-ACB0-13231864975D}) (Version: 5.10.621.0 - NewspaperDirect Inc.) puush (HKLM-x32\...\{C3592426-531E-4110-911D-BFECE2CE284B}) (Version: 1.0.0.0 - Dean Herbert) QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6132 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.3025 - CyberLink Corp.) Hidden Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform) SAMSUNG Mobile Composite Device Software (HKLM\...\SAMSUNG Mobile Composite Device) (Version: - ) SAMSUNG Mobile Modem Driver Set (HKLM\...\SAMSUNG Mobile Modem) (Version: - ) Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version: - ) SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version: - ) SAMSUNG Mobile USB Modem Software (HKLM\...\SAMSUNG Mobile USB Modem) (Version: - ) Samsung PC Studio 3 (HKLM-x32\...\{C4A4722E-79F9-417C-BD72-8D359A090C97}) (Version: 3.2.2.80403 - Samsung Electronics Co., Ltd.) Samsung PC Studio 3 (x32 Version: 3.0.0.80403 - Samsung Electronics Co., Ltd.) Hidden SDFormatter (HKLM-x32\...\{A5355F15-F98B-4704-9BAE-E53B9FE48F48}) (Version: 3.1.0 - SD Association) SecurityKISS Tunnel v0.3.0 (HKLM\...\SecurityKISS Tunnel_is1) (Version: - ) SFR - Kit de connexion (HKLM-x32\...\SFR_Kit) (Version: 10.8.27.0 - SFR) Sid Meier's Civilization 4 - Beyond the Sword (HKLM-x32\...\{32E4F0D2-C135-475E-A841-1D59A0D22989}) (Version: 3.19 - Firaxis Games) Sid Meier's Civilization 4 - Warlords (HKLM-x32\...\{3E4B349F-10B5-4586-9D99-489A90A8B228}) (Version: 1.00.0000 - Firaxis Games) Sid Meier's Civilization 4 (HKLM-x32\...\{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}) (Version: 1.74 - Firaxis Games) Sid Meier's Civilization 4 (x32 Version: 1.00.0000 - Firaxis Games) Hidden Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.) Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Sony Ericsson Update Engine (HKLM-x32\...\Update Engine) (Version: 2.13.7.201306141231 - Sony Ericsson Communications AB) Sony Mobile Update Service (HKLM-x32\...\Update Service) (Version: 2.13.12.201310171455 - Sony Mobile Communications AB) Sony PC Companion 2.10.211 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.211 - Sony) Spotify (HKCU\...\Spotify) (Version: 0.9.10.14.g578d350b - Spotify AB) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden System Requirements Lab CYRI (HKLM-x32\...\{E5F05232-96B6-4552-A480-785A60A94B21}) (Version: 5.0.6.0 - Husdawg, LLC) TAP-Windows 9.9.2 (HKLM\...\TAP-Windows) (Version: 9.9.2 - ) The Sims 2 University (HKLM-x32\...\{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}) (Version: - ) Undelete 360 (HKLM-x32\...\Undelete 360_is1) (Version: - File Recovery Ltd.) Uniblue DriverScanner (HKLM-x32\...\{C2F8CA82-2BD9-4513-B2D1-08A47914C1DA}_is1) (Version: 4.0.1.6 - Uniblue Systems Ltd) Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Veetle TV (HKLM-x32\...\Veetle TV) (Version: 0.9.18 - Veetle, Inc) Victoria 2 (HKLM-x32\...\{9C3B7F54-C6E2-4A74-9937-9C6EBA10C4A2}) (Version: - ) Victoria II A House Divided 2.1 (HKLM-x32\...\Victoria II A House Divided 2.1) (Version: - ) Virtual Villagers - The Secret City (x32 Version: 2.2.0.95 - WildTangent) Hidden VLC media player 1.1.11 (HKLM-x32\...\VLC media player) (Version: 1.1.11 - VideoLAN) Wedding Dash (x32 Version: 2.2.0.95 - WildTangent) Hidden WildTangent Games App (HP Games) (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.5.36 - WildTangent) Windows Live Call (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden Windows Live FolderShare (HKLM-x32\...\{76810709-A7D3-468D-9167-A1780C1E766C}) (Version: 14.0.8117.416 - Microsoft Corporation) Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation) Windows Live Mail (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.) WinRAR 4.00 (32 bits) (HKLM-x32\...\WinRAR archiver) (Version: 4.00.0 - win.rar GmbH) Wireshark 1.10.3 (64-bit) (HKLM-x32\...\Wireshark) (Version: 1.10.3 - The Wireshark developer community, http://www.wireshark.org) Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 27-07-2014 12:37:19 Fin de désinfection 27-07-2014 12:53:26 zoek.exe restore point ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2012-10-02 21:30 - 00003470 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {08E27D3A-D6DA-4D43-8AA9-01BD25FE75FA} - System32\Tasks\{8CC5F7C7-A631-4DEA-AAA2-8F9F1EB2AD63} => C:\Users\Babakila\Downloads\LimeWirePirateEdition.exe Task: {0B8414EA-2FCB-407C-8E30-796890A96BFF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-04] (Google Inc.) Task: {20106230-2C2C-4DEB-95B0-7227E497508C} - System32\Tasks\{884B4866-E50A-464C-A3D3-DFE372B5F85B} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.) Task: {246DC990-FA43-4131-9643-5FBA5B7402FA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-04] (Google Inc.) Task: {2688D54C-CAE3-4C5B-AE7F-A25AE376301C} - System32\Tasks\{893377C6-DDA6-4056-A05D-423ED7F313BB} => C:\Program Files (x86)\Electronic Arts\Les Sims 3 Générations\Game\Bin\Sims3Launcher.exe [2011-03-21] (Electronic Arts, Inc.) Task: {2F5535FD-B3DF-41A6-8450-8DC6AE5B7232} - System32\Tasks\{6AEDE296-644E-42BF-A188-0DB469688805} => Firefox.exe http://www.skype.com/go/downloading?source=lightinstaller&ver=6.14.0.104&LastError=-9 Task: {345F3BAE-C7D2-49B6-96A4-91F66F3D5D30} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {35174E2A-D14A-4BFF-AB5D-29B6CB0E2099} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {44CEE5EA-A934-40D3-9705-54B096AAD822} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-816315366-518852455-1505757675-1000Core => C:\Users\Babakila\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.) Task: {50400DB8-1507-4F15-9932-59CC37EAF1AD} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {54132CA0-3F6A-4CF0-B729-EDDC4918264C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company) Task: {625C6660-1433-4CF3-9CFB-ED8BB1D5B5A3} - System32\Tasks\{CCD40395-D46C-495A-A20B-5626629BF428} => Firefox.exe http://ui.skype.com/ui/0/5.8.0.158/en/abandoninstall?page=tsMain Task: {656E60CD-1BF7-4584-A635-13F4759DA864} - System32\Tasks\HPCeeScheduleForFAMILLEBABAKILA$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05] (Hewlett-Packard) Task: {903F5605-32FB-4350-A47C-55330257CBA2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08] (Adobe Systems Incorporated) Task: {96F048A4-4C37-40E9-939A-042CFF6C8D99} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {9E6D7C79-6537-46F2-B171-DD44FDD03C73} - System32\Tasks\{C8A0844F-A53E-4D49-9B74-E4F10E82B38F} => Firefox.exe http://ui.skype.com/ui/0/6.0.60.126/fr/abandoninstall?page=tsProgressBar Task: {C63679E6-3A55-44E1-8E03-21F37D90D9CC} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation) Task: {C8E73DCA-0146-45D9-93C6-72F089933EA2} - System32\Tasks\{C32F4FB8-E096-47F1-99F6-418C4EC28666} => Firefox.exe http://ui.skype.com/ui/0/5.5.0.114/fr/go/help.faq.installer?LastError=1618 Task: {D0268835-0C6E-419A-9F3E-38FA66AA4BC8} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-25] () Task: {D9CAC4FB-8FF3-427B-B910-EC2FD1B69419} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe <==== ATTENTION Task: {DB70B02F-5267-4EFA-A51C-BDD664FAA19C} - System32\Tasks\{8FF38A09-61D7-4BB7-A061-5E98AFDACE55} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.) Task: {DC4B2878-471B-4731-AE45-43BAF2C45498} - System32\Tasks\ServicePlan => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-25] () Task: {E50EDD85-2381-421E-9702-61695DCCAD65} - System32\Tasks\{11E67E3B-9A4B-4CC5-A74F-0E84DF9A55CB} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.) Task: {E70C2B1A-EDC1-47C4-83F8-E8652363AE25} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-816315366-518852455-1505757675-1000UA => C:\Users\Babakila\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.) Task: {E9C37490-BBE0-4D1B-BC70-963AFD0EFAEE} - System32\Tasks\{C5DD9B20-7E48-42CB-91A6-10A5011842FA} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.) Task: {EA0775ED-8C78-46E2-B5EF-4D71DAEC2D68} - System32\Tasks\{71AC89EE-A001-45FA-8074-E083C56D3ECE} => C:\Program Files (x86)\Electronic Arts\Les Sims 3 Générations\Game\Bin\Sims3Launcher.exe [2011-03-21] (Electronic Arts, Inc.) Task: {F13C4E60-F40D-4552-8208-FE5A4CF423B4} - System32\Tasks\DriverScanner => C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe [2011-05-16] (Uniblue Systems Limited) Task: {F88C5F9D-F23E-4876-AD1F-5B35BB651598} - System32\Tasks\HPCeeScheduleForBabakila => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05] (Hewlett-Packard) Task: {FF766965-615B-49FB-ABFF-5B954936D6C4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-03-21] (Hewlett-Packard) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DriverScanner.job => C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-816315366-518852455-1505757675-1000Core.job => C:\Users\Babakila\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-816315366-518852455-1505757675-1000UA.job => C:\Users\Babakila\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HPCeeScheduleForBabakila.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\Windows\Tasks\HPCeeScheduleForFAMILLEBABAKILA$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Loaded Modules (whitelisted) ============= 2011-04-11 22:23 - 2011-03-02 12:40 - 00164864 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll 2011-11-16 16:52 - 2011-11-16 16:52 - 00196608 _____ () C:\Program Files (x86)\BubbleUPnP Server\BubbleUPnPServer.exe 2012-10-30 22:42 - 2013-10-31 12:35 - 00070880 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe 2012-01-10 14:41 - 2014-05-11 13:38 - 00567880 _____ () C:\Program Files (x86)\puush\puush.exe 2014-07-27 14:00 - 2014-07-27 10:34 - 02822144 _____ () C:\Program Files\AVAST Software\Avast\defs\14072700\algo.dll 2011-09-27 07:23 - 2011-09-27 07:23 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2011-09-27 07:22 - 2011-09-27 07:22 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2012-10-30 22:42 - 2012-04-30 11:57 - 00039936 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\TMonitorAPI.dll 2012-10-30 22:42 - 2013-09-13 11:02 - 00208896 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\MExplorer.dll 2011-07-07 14:54 - 2011-07-07 14:54 - 00233984 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\Report.dll 2012-10-05 04:51 - 2013-05-20 12:58 - 00620718 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\sqlite3.dll 2012-10-30 22:42 - 2010-01-11 16:44 - 00053248 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\VObject.dll 2012-11-27 16:13 - 2012-11-27 16:13 - 00585728 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PhoneUpdate.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 02145304 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtCore4.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 07956504 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtGui4.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 00342552 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtXml4.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 00029208 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QGif4.dll 2011-08-12 12:18 - 2011-08-12 12:18 - 00128536 _____ () C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll 2011-01-17 16:19 - 2012-05-08 12:06 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll 2010-09-28 14:00 - 2010-09-28 14:00 - 00061440 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll 2010-09-28 14:00 - 2010-09-28 14:00 - 00131072 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\ECenter\ECLibrary.dll 2010-09-28 14:00 - 2010-09-28 14:00 - 00028672 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll 2014-06-18 14:47 - 2014-06-18 14:47 - 03852912 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\rkfree:cfg ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background ==================== Faulty Device Manager Devices ============= Name: avast! Firewall NDIS Filter Miniport Description: avast! Firewall NDIS Filter Miniport Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: ALWIL Software Service: aswNdis Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19) Resolution: A registry problem was detected. This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options: On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver. ==================== Event log errors: ========================= Application errors: ================== Error: (07/27/2014 02:16:58 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Pour information uniquement. (Patch task for {90140011-0066-040C-0000-0000000FF1CE}): DownloadLatest Failed: Error: (07/27/2014 10:16:11 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 11185 Error: (07/27/2014 10:16:11 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 11185 Error: (07/27/2014 10:16:11 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/27/2014 10:16:10 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 10140 Error: (07/27/2014 10:16:10 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 10140 Error: (07/27/2014 10:16:10 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/27/2014 10:16:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 8408 Error: (07/27/2014 10:16:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 8408 Error: (07/27/2014 10:16:08 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second System errors: ============= Error: (07/27/2014 02:59:44 PM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (07/27/2014 02:59:42 PM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (07/27/2014 02:53:03 PM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (07/27/2014 02:53:00 PM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (07/27/2014 02:52:27 PM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (07/27/2014 02:52:24 PM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (07/27/2014 02:51:33 PM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (07/27/2014 02:51:30 PM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (07/27/2014 02:51:10 PM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Error: (07/27/2014 02:51:07 PM) (Source: Disk) (EventID: 7) (User: ) Description: Le périphérique \Device\Harddisk0\DR0 comporte un bloc défectueux. Microsoft Office Sessions: ========================= Error: (07/27/2014 02:16:58 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: (Patch task for {90140011-0066-040C-0000-0000000FF1CE}): DownloadLatest Failed: Error: (07/27/2014 10:16:11 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 11185 Error: (07/27/2014 10:16:11 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 11185 Error: (07/27/2014 10:16:11 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/27/2014 10:16:10 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 10140 Error: (07/27/2014 10:16:10 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 10140 Error: (07/27/2014 10:16:10 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/27/2014 10:16:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 8408 Error: (07/27/2014 10:16:09 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 8408 Error: (07/27/2014 10:16:08 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second CodeIntegrity Errors: =================================== Date: 2014-05-15 20:05:49.466 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.3\f0260952_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:05:48.782 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.3\f0260952_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:05:48.028 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.3\f0260952_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:05:34.504 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.2\f0238120_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:05:33.965 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.2\f0238120_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:05:33.402 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.2\f0238120_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:04:59.166 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.1\f0208272_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:04:58.413 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.1\f0208272_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 20:04:57.420 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\Users\Babakila\Documents\recup_dir.1\f0208272_aswKbd.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. Date: 2014-05-15 18:16:22.162 Description: Le module d’intégrité du code ne peut pas vérifier l’intégrité image du fichier \Device\HarddiskVolume2\$RECYCLE.BIN\S-1-5-21-816315366-518852455-1505757675-1000\$RUE64JJ.10\f1016576_aswSP.sys car le jeu de hachages d’images par page n’a pas été trouvé sur le système. ==================== Memory info =========================== Percentage of memory in use: 70% Total physical RAM: 4061.24 MB Available physical RAM: 1200.14 MB Total Pagefile: 8120.66 MB Available Pagefile: 4617.12 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:582.75 GB) (Free:228.49 GB) NTFS Drive d: (HP_RECOVERY) (Fixed) (Total:13.32 GB) (Free:1.64 GB) NTFS ==>[system with boot components (obtained from reading drive)] Drive g: (FOOTBALL MANAGER) (CDROM) (Total:2.01 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 596 GB) (Disk ID: 34FC3F15) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=583 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=13 GB) - (Type=07 NTFS) ==================== End Of Log ============================
  13. Just saw that I forgot something in my first post so sorry and Hi everyone! There's FRST.txt Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-07-2014 Ran by Babakila (administrator) on FAMILLEBABAKILA on 27-07-2014 15:39:23 Running from C:\Users\Babakila\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Français (France) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Uniblue Systems Limited) C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe () C:\Program Files (x86)\BubbleUPnP Server\BubbleUPnPServer.exe (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (SFR) C:\Program Files (x86)\SFR\Kit\9props.exe (Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe (Spotify Ltd) C:\Users\Babakila\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe () C:\Program Files (x86)\puush\puush.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe (Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (Power Software Ltd) C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Easybits) C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (EasyBits Software AS) C:\ProgramData\GameXN\GameXNGO.exe (CyberGhost S.R.L.) C:\Program Files\CyberGhost 5\CyberGhost.exe (CyberGhost S.R.L) C:\Program Files\CyberGhost 5\Service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [563736 2009-10-15] (PDF Complete Inc) HKLM-x32\...\Run: [HP Software Update] => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2008-12-09] (Hewlett-Packard) HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2010-04-25] (EasyBits Software AS) HKLM-x32\...\Run: [switchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-08-12] (Logitech Inc.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [avast] => C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [superVigil] => C:\ProgramData\SuperVigil\SyScript\SysPlug.exe [984680 2012-10-03] () HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [337432 2013-01-27] (Power Software Ltd) HKLM-x32\...\Run: [sunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [Magic Desktop for HP notification] => C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1238016 2013-07-27] (Easybits) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-23] (Apple Inc.) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3816784 2014-07-21] (LogMeIn Inc.) HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-07-23] (Hewlett-Packard) HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2014-05-12] (Malwarebytes Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-19\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation) HKU\S-1-5-20\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [HPAdvisorDock] => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1715768 2010-09-28] (Hewlett-Packard) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [Connexion SFR 9props.exe] => C:\Program Files (x86)\SFR\Kit\9props.exe [976192 2010-07-19] (SFR) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [DriverScanner] => C:\Program Files (x86)\Uniblue\DriverScanner\launcher.exe [338296 2011-05-16] (Uniblue Systems Limited) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [Facebook Update] => C:\Users\Babakila\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-12] (Facebook Inc.) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [GameXN GO] => C:\ProgramData\GameXN\GameXNGO.exe [347008 2011-09-09] (EasyBits Software AS) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [466656 2014-05-23] (Sony) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [spotify Web Helper] => C:\Users\Babakila\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-05-18] (Spotify Ltd) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [CyberGhost] => C:\Program Files\CyberGhost 5\CyberGhost.EXE [404080 2014-06-12] (CyberGhost S.R.L.) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21444224 2014-05-08] (Skype Technologies S.A.) HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Run: [puush] => C:\Program Files (x86)\puush\puush.exe [567880 2014-05-11] () HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\Policies\system: [DisableChangePassword] 0 HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\MountPoints2: K - K:\Startme.exe HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\MountPoints2: L - L:\Startme.exe HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\MountPoints2: M - M:\Startme.exe HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\MountPoints2: {1b01b238-50d5-11e2-b73a-d48564a4f095} - M:\Startme.exe HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\MountPoints2: {5c4f02d6-2125-11e2-a73b-d48564a4f095} - K:\Startme.exe HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\MountPoints2: {60c71fbc-8eeb-11e0-acf6-d48564a4f095} - L:\iStudio.exe HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\MountPoints2: {843b4152-8977-11e0-9f24-d48564a4f095} - I:\RunGame.exe HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\MountPoints2: {cd065443-fb20-11e0-a49b-d48564a4f095} - F:\Autorun.exe HKU\S-1-5-21-816315366-518852455-1505757675-1000\...\MountPoints2: {f45d3b01-6459-11e0-9c38-d48564a4f095} - G:\setup.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe (McAfee, Inc.) Startup: C:\Users\Babakila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/HPDSK/3 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.microsoft.com/access/allinone.asp HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {3FE5B696-1B72-40A9-A02E-12A93A7977A1} URL = http://fr.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM - {DF8CD4F7-1BA3-4EFB-B022-AC83C6314BAA} URL = http://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {3FE5B696-1B72-40A9-A02E-12A93A7977A1} URL = http://fr.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM-x32 - {DF8CD4F7-1BA3-4EFB-B022-AC83C6314BAA} URL = http://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF SearchScopes: HKCU - DefaultScope yandex.ru-221635 URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=tele1202&cd=2XzuyEtN2Y1L1Qzu0DyEzzyDyCyE0AyE0FtDzyyD0B0CtAtBtN0D0Tzu0CyBtByCtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1877437213&ir= SearchScopes: HKCU - URL http://search.conduit.com/Results.aspx?gd=&ctid=CT3319415&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=58&CUI=&UM=5&UP=SP61DD3E74-C39D-43DF-BE1F-AF5F42EBE4D7&q={searchTerms}&SSPV= SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} SearchScopes: HKCU - yandex.ru-221635 URL = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=tele1202&cd=2XzuyEtN2Y1L1Qzu0DyEzzyDyCyE0AyE0FtDzyyD0B0CtAtBtN0D0Tzu0CyBtByCtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=1877437213&ir= SearchScopes: HKCU - {3FE5B696-1B72-40A9-A02E-12A93A7977A1} URL = http://fr.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKCU - {DF8CD4F7-1BA3-4EFB-B022-AC83C6314BAA} URL = http://fr.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF BHO: avast! Online Security -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO: No Name -> {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} -> No File BHO-x32: Objet d'aide à la navigation SFR -> {0F6E720A-1A6B-40E1-A294-1D4D19F156C8} -> C:\Program Files (x86)\SFR\Kit\SFRNavErrorHelper.dll (SFR) BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2010-11-23] (EasyBits Software Corp.) Tcpip\..\Interfaces\{F1B2815C-7CD4-44B1-AD5C-7894E67B8C18}: [NameServer]95.169.183.219,89.41.60.38 FireFox: ======== FF ProfilePath: C:\Users\Babakila\AppData\Roaming\Mozilla\Firefox\Profiles\df63j430.default-1378308598723 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) FF Plugin-x32: @real.com/nppl3260;version=6.0.12.69 - C:\Program Files (x86)\Video Convert Master\codec\real\browser\plugins\nppl3260.dll No File FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.69 - C:\Program Files (x86)\Video Convert Master\codec\real\browser\plugins\nprpjplug.dll No File FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.18 - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin-x32: @videolan.org/vlc,version=1.1.11 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Babakila\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: electronicarts.com/GameFacePlugin - C:\Users\Babakila\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts) FF Plugin HKCU: sony.com/MediaGoDetector - C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC) FF user.js: detected! => C:\Users\Babakila\AppData\Roaming\Mozilla\Firefox\Profiles\df63j430.default-1378308598723\user.js FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazon-france.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\cnrtl-tlfi-fr.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-france.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-france.xml FF Extension: iMacros for Firefox - C:\Users\Babakila\AppData\Roaming\Mozilla\Firefox\Profiles\df63j430.default-1378308598723\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2014-05-28] FF Extension: Adblock Plus - C:\Users\Babakila\AppData\Roaming\Mozilla\Firefox\Profiles\df63j430.default-1378308598723\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-20] FF Extension: Greasemonkey - C:\Users\Babakila\AppData\Roaming\Mozilla\Firefox\Profiles\df63j430.default-1378308598723\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2013-12-21] FF Extension: Click to call with Skype - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-06-18] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-01-25] Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.44\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.44\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.44\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Media Go Detector) - C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC) CHR Plugin: (PlayStation®Network Downloader Check Plug-in) - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) CHR Plugin: (Veetle TV Player) - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc) CHR Plugin: (Veetle TV Core) - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc) CHR Plugin: (VLC Multimedia Plug-in) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team) CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Unity Player) - C:\Users\Babakila\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Babakila\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) CHR Plugin: (Game Face Plugin) - C:\Users\Babakila\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts) CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Windows Activation Technologies) - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File CHR Extension: (Google Docs) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-08-04] CHR Extension: (Google Drive) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-04] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-07-18] CHR Extension: (YouTube) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-04] CHR Extension: (Google Search) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-04] CHR Extension: (JV Chat Loader) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikeiebaphjpheeemfjnfchlpochgipdd [2013-08-05] CHR Extension: (Skype Click to Call) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-08-04] CHR Extension: (Google Wallet) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-04] CHR Extension: (No Name) - C:\Users\Babakila\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-04] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-08-16] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 BubbleUPnP Server; C:\Program Files (x86)\BubbleUPnP Server\BubbleUPnPServer.exe [196608 2011-11-16] () [File not signed] R2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64624 2014-06-12] (CyberGhost S.R.L) R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed] R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [74752 2011-11-24] (Freemake) [File not signed] R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed] R2 LightScribeService; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-05-19] (Hewlett-Packard Company) [File not signed] R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-07-16] (LogMeIn, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe [234776 2012-09-05] (McAfee, Inc.) S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [4903312 2011-02-23] (INCA Internet Co., Ltd.) [File not signed] R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [635416 2009-10-15] (PDF Complete Inc) S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [21136 2012-10-31] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-07-21] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-07-21] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-07-21] () R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-04-11] (DT Soft Ltd) U0 eqhbdq; C:\Windows\System32\drivers\tgcremv.sys [79064 2014-07-27] (Malwarebytes Corporation) S3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-07] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-27] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited) S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed] S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2013-04-24] (Anchorfree Inc.) S3 CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfoX64.sys [X] S3 dump_wmimmc; \??\C:\Program Files\DBO_CT_TW\GameGuard\dump_wmimmc.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-07-27 15:39 - 2014-07-27 15:40 - 00032622 _____ () C:\Users\Babakila\Downloads\FRST.txt 2014-07-27 15:39 - 2014-07-27 15:39 - 00000000 ____D () C:\FRST 2014-07-27 15:38 - 2014-07-27 15:38 - 02093568 _____ (Farbar) C:\Users\Babakila\Downloads\FRST64.exe 2014-07-27 15:09 - 2014-07-27 15:00 - 00016434 _____ () C:\zoek-results2014-07-27-130039.log 2014-07-27 15:07 - 2014-07-27 15:07 - 01287168 _____ () C:\Users\Babakila\Downloads\zoek.exe 2014-07-27 14:53 - 2014-07-27 15:13 - 00019554 _____ () C:\zoek-results.log 2014-07-27 14:47 - 2014-07-27 14:47 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Babakila\Downloads\tdsskiller.exe 2014-07-27 14:47 - 2014-07-27 14:47 - 00000000 ____D () C:\zoek_backup 2014-07-27 14:37 - 2014-07-27 14:38 - 00001057 _____ () C:\DelFix.txt 2014-07-27 13:57 - 2014-07-27 14:36 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-07-27 13:51 - 2014-07-27 13:51 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Babakila\Downloads\mbar-1.07.0.1012.exe 2014-07-27 00:59 - 2014-07-27 00:59 - 00079064 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\tgcremv.sys 2014-07-26 23:23 - 2014-07-27 09:56 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-26 23:23 - 2014-07-26 23:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-07-26 23:22 - 2014-07-27 13:54 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-26 23:22 - 2014-07-26 23:22 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-07-26 23:22 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-25 18:29 - 2014-07-25 18:29 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\GameXN 2014-07-25 18:29 - 2014-07-25 18:29 - 00000000 ____D () C:\Users\Babakila\AppData\Local\GameXN 2014-07-22 18:36 - 2014-07-22 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2014-07-22 18:36 - 2014-07-22 18:36 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi 2014-07-18 22:56 - 2014-07-18 22:56 - 00000000 ____D () C:\Users\Babakila\Desktop\rouss 2014-07-16 23:16 - 2014-07-25 03:00 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\Users\Public\Documents\Sports Interactive 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\Users\Babakila\Documents\Sports Interactive 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\Users\Babakila\AppData\Local\Sports Interactive 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\ProgramData\Steam 2014-07-09 20:12 - 2014-07-09 20:12 - 00000862 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Football Manager 2014.lnk 2014-07-09 20:07 - 2014-07-09 20:43 - 00000000 ____D () C:\Program Files (x86)\Football Manager 2014 2014-07-09 09:48 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-07-09 09:48 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-09 09:48 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-09 09:48 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-09 09:48 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-07-09 09:48 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-09 09:48 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-09 09:48 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-09 09:48 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-07-09 09:48 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-07-09 09:48 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-09 09:48 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-09 09:48 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-09 09:48 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-09 09:48 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-07-09 09:48 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-07-09 09:48 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-09 09:48 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-07-09 09:48 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-09 09:48 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-07-09 09:48 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-09 09:48 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-09 09:48 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-09 09:48 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-09 09:48 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-09 09:48 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-09 09:48 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-07-09 09:48 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-07-09 09:48 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-07-09 09:48 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-07-09 09:48 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-09 09:48 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-09 09:48 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-09 09:48 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-07-09 09:48 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-09 09:48 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-07-09 09:48 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-07-09 09:48 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-07-09 09:48 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-07-09 09:48 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-09 09:48 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-07-09 09:48 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-07-09 09:48 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-09 09:48 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-09 09:48 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-09 09:48 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-09 09:48 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-09 09:48 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-09 09:48 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-07-09 09:48 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-09 09:48 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-09 09:48 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-09 09:48 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-07-09 09:48 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-09 09:48 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-09 09:48 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-07-09 09:48 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-07-09 09:48 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-07-09 09:48 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-09 09:48 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-09 09:48 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-07-09 09:48 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-07-09 09:48 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-07-09 09:48 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-07-09 09:48 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-07-09 09:48 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-07-09 09:48 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-07-09 09:48 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-07-09 09:48 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-07-09 09:48 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-07-09 09:48 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-07-09 09:48 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2014-07-09 09:48 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-07-09 09:48 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-07-09 09:48 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-07-09 09:48 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-09 09:47 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-07-09 09:47 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-07-09 09:47 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-07-08 22:18 - 2014-07-08 22:18 - 11204096 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-07-08 15:46 - 2014-07-08 16:21 - 2162077696 _____ () C:\Users\Babakila\Downloads\Football+Manager+2014.iso 2014-07-06 21:31 - 2014-07-06 21:31 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\Juniper Networks ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-07-27 15:40 - 2014-07-27 15:39 - 00032622 _____ () C:\Users\Babakila\Downloads\FRST.txt 2014-07-27 15:39 - 2014-07-27 15:39 - 00000000 ____D () C:\FRST 2014-07-27 15:38 - 2014-07-27 15:38 - 02093568 _____ (Farbar) C:\Users\Babakila\Downloads\FRST64.exe 2014-07-27 15:36 - 2013-08-04 23:21 - 00001072 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-27 15:31 - 2011-09-09 17:00 - 00000000 ____D () C:\ProgramData\GameXN 2014-07-27 15:18 - 2012-05-31 19:02 - 00001002 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-27 15:13 - 2014-07-27 14:53 - 00019554 _____ () C:\zoek-results.log 2014-07-27 15:07 - 2014-07-27 15:07 - 01287168 _____ () C:\Users\Babakila\Downloads\zoek.exe 2014-07-27 15:00 - 2014-07-27 15:09 - 00016434 _____ () C:\zoek-results2014-07-27-130039.log 2014-07-27 14:47 - 2014-07-27 14:47 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Babakila\Downloads\tdsskiller.exe 2014-07-27 14:47 - 2014-07-27 14:47 - 00000000 ____D () C:\zoek_backup 2014-07-27 14:38 - 2014-07-27 14:37 - 00001057 _____ () C:\DelFix.txt 2014-07-27 14:36 - 2014-07-27 13:57 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-07-27 13:54 - 2014-07-26 23:22 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-27 13:51 - 2014-07-27 13:51 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Babakila\Downloads\mbar-1.07.0.1012.exe 2014-07-27 12:46 - 2011-12-08 16:36 - 00001108 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-816315366-518852455-1505757675-1000UA.job 2014-07-27 12:46 - 2011-12-08 16:36 - 00001086 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-816315366-518852455-1505757675-1000Core.job 2014-07-27 12:32 - 2013-08-04 23:21 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-27 12:32 - 2010-11-23 22:10 - 01387727 _____ () C:\Windows\WindowsUpdate.log 2014-07-27 10:11 - 2009-07-14 06:45 - 00015792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-27 10:11 - 2009-07-14 06:45 - 00015792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-27 09:56 - 2014-07-26 23:23 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-27 09:56 - 2011-09-08 15:45 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\go 2014-07-27 01:00 - 2011-06-28 20:39 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\Skype 2014-07-27 00:59 - 2014-07-27 00:59 - 00079064 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\tgcremv.sys 2014-07-27 00:59 - 2011-04-11 18:39 - 00000000 ____D () C:\Windows\PCHEALTH 2014-07-26 23:27 - 2014-05-23 23:04 - 00000000 ____D () C:\Users\Babakila\Documents\FIFA World 2014-07-26 23:27 - 2013-10-27 09:22 - 00139264 ___SH () C:\Users\Babakila\Documents\Thumbs.db 2014-07-26 23:23 - 2014-07-26 23:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-07-26 23:23 - 2012-01-08 19:53 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-07-26 23:23 - 2011-10-24 15:14 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\Malwarebytes 2014-07-26 23:22 - 2014-07-26 23:22 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-07-26 23:22 - 2011-10-24 15:14 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-26 23:22 - 2011-10-24 15:13 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-07-26 14:09 - 2013-07-25 10:09 - 00100647 _____ () C:\Windows\setupact.log 2014-07-25 18:31 - 2013-03-31 21:20 - 00000000 ____D () C:\Users\Babakila\AppData\Local\LogMeIn Hamachi 2014-07-25 18:29 - 2014-07-25 18:29 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\GameXN 2014-07-25 18:29 - 2014-07-25 18:29 - 00000000 ____D () C:\Users\Babakila\AppData\Local\GameXN 2014-07-25 18:24 - 2013-11-13 18:45 - 00000000 ____D () C:\Program Files (x86)\BubbleUPnP Server 2014-07-25 18:23 - 2011-08-18 00:15 - 00000346 _____ () C:\Windows\Tasks\DriverScanner.job 2014-07-25 18:22 - 2014-06-21 17:25 - 00000344 _____ () C:\Windows\Tasks\HPCeeScheduleForBabakila.job 2014-07-25 18:22 - 2012-06-15 23:10 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-07-25 18:22 - 2012-06-15 23:10 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-07-25 18:22 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-25 03:03 - 2012-06-15 23:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-07-25 03:00 - 2014-07-16 23:16 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-07-24 22:26 - 2013-08-04 23:22 - 00002143 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-24 12:27 - 2012-03-28 17:48 - 00003216 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForFAMILLEBABAKILA$ 2014-07-24 12:27 - 2012-03-28 17:48 - 00000358 _____ () C:\Windows\Tasks\HPCeeScheduleForFAMILLEBABAKILA$.job 2014-07-23 17:22 - 2014-06-21 17:25 - 00003204 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForBabakila 2014-07-23 17:21 - 2011-11-02 14:12 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-07-23 17:21 - 2011-04-13 21:11 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-07-22 18:36 - 2014-07-22 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi 2014-07-22 18:36 - 2014-07-22 18:36 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi 2014-07-22 14:05 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-07-22 00:30 - 2010-11-23 22:17 - 00000000 ____D () C:\ProgramData\PDFC 2014-07-21 12:01 - 2012-08-15 21:28 - 00000000 ____D () C:\Users\Babakila\Documents\i-pod fias 2014-07-18 22:56 - 2014-07-18 22:56 - 00000000 ____D () C:\Users\Babakila\Desktop\rouss 2014-07-18 13:20 - 2013-07-25 10:09 - 00253214 _____ () C:\Windows\PFRO.log 2014-07-18 10:11 - 2011-04-11 18:38 - 00000000 ____D () C:\Users\Babakila 2014-07-17 00:23 - 2010-11-23 22:44 - 00748104 _____ () C:\Windows\system32\perfh00C.dat 2014-07-17 00:23 - 2010-11-23 22:44 - 00150370 _____ () C:\Windows\system32\perfc00C.dat 2014-07-17 00:23 - 2009-07-14 07:13 - 01671168 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-16 23:16 - 2013-03-17 20:52 - 00001884 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-07-16 23:16 - 2011-06-11 13:30 - 00000000 _____ () C:\Windows\SysWOW64\config.nt 2014-07-16 23:15 - 2009-07-14 07:08 - 00032482 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-16 23:12 - 2014-06-18 14:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-07-16 23:12 - 2014-05-11 13:37 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\puush 2014-07-16 23:12 - 2013-10-19 14:46 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\Spotify 2014-07-16 23:12 - 2013-08-14 23:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-07-16 23:12 - 2013-08-04 23:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-07-16 23:12 - 2012-01-01 14:10 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-07-16 23:12 - 2011-10-13 21:12 - 00000000 ____D () C:\Users\Babakila\Documents\Xilisoft Corporation 2014-07-16 23:12 - 2011-09-27 18:20 - 00000000 ____D () C:\Users\Babakila\Documents\My Art 2014-07-16 23:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-07-16 23:10 - 2014-05-28 15:00 - 00000000 ____D () C:\Users\Babakila\Documents\iMacros 2014-07-16 23:10 - 2013-03-14 15:22 - 00000000 ____D () C:\Users\Babakila\Documents\My Games 2014-07-16 23:10 - 2012-10-30 13:26 - 00000000 ____D () C:\Users\Babakila\Documents\EA Games 2014-07-16 23:10 - 2012-06-25 20:23 - 00000000 ____D () C:\Users\Babakila\Documents\Fax 2014-07-16 23:10 - 2012-05-14 16:40 - 00000000 ____D () C:\Users\Babakila\Documents\LimeWire 2014-07-16 23:10 - 2011-04-11 23:27 - 00000000 ____D () C:\Users\Babakila\Documents\Electronic Arts 2014-07-15 14:57 - 2013-10-19 14:46 - 00000000 ____D () C:\Users\Babakila\AppData\Local\Spotify 2014-07-14 19:42 - 2011-09-19 12:06 - 00000000 ____D () C:\Users\Babakila\Documents\Galy ecole 2014-07-11 11:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-07-10 09:51 - 2011-04-11 21:51 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite 2014-07-10 09:48 - 2009-07-14 06:45 - 04865032 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-10 03:14 - 2009-07-14 09:45 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-10 03:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2014-07-10 03:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism 2014-07-10 03:07 - 2013-07-25 22:11 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-10 03:03 - 2011-11-28 19:41 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-07-09 20:43 - 2014-07-09 20:07 - 00000000 ____D () C:\Program Files (x86)\Football Manager 2014 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\Users\Public\Documents\Sports Interactive 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\Users\Babakila\Documents\Sports Interactive 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\Users\Babakila\AppData\Local\Sports Interactive 2014-07-09 20:36 - 2014-07-09 20:36 - 00000000 ____D () C:\ProgramData\Steam 2014-07-09 20:12 - 2014-07-09 20:12 - 00000862 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Football Manager 2014.lnk 2014-07-09 20:06 - 2011-04-11 21:51 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\DAEMON Tools Lite 2014-07-08 22:19 - 2012-05-31 19:02 - 00003940 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-07-08 22:19 - 2012-05-30 14:37 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-07-08 22:19 - 2012-02-04 10:40 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-07-08 22:18 - 2014-07-08 22:18 - 11204096 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-07-08 16:21 - 2014-07-08 15:46 - 2162077696 _____ () C:\Users\Babakila\Downloads\Football+Manager+2014.iso 2014-07-06 21:31 - 2014-07-06 21:31 - 00000000 ____D () C:\Users\Babakila\AppData\Roaming\Juniper Networks 2014-06-29 20:38 - 2013-11-10 15:25 - 00000000 ____D () C:\Users\Babakila\AppData\Local\CyberGhost Some content of TEMP: ==================== C:\Users\Babakila\AppData\Local\Temp\74178uninstall.exe C:\Users\Babakila\AppData\Local\Temp\install_reader11_fr_mssa_aaa_aih.exe C:\Users\Babakila\AppData\Local\Temp\OfficeSetup.exe C:\Users\Babakila\AppData\Local\Temp\Setup.X86.fr-FR_O365HomePremRetail_c6db9c75-ac9c-4f31-bd22-27c6e9b8b844_TX_DB_.exe C:\Users\Babakila\AppData\Local\Temp\SkypeSetup.exe C:\Users\Babakila\AppData\Local\Temp\sp64126.exe C:\Users\Babakila\AppData\Local\Temp\Sqlite3.dll C:\Users\Babakila\AppData\Local\Temp\UninstallHPSA.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-18 10:54 ==================== End Of Log ============================
  14. Hmm, sorry but where can i have the avast logs?
  15. I have a problem with my PC, first excuse my english it's not my native language My sister seems to have downloaded something bad on some site and since that avast is going crazy with 5-6 alerts every 5 minutes about dangerous files I've searched on google and there was someone with the same problem, I've done everything that he had to do And now the last thing I've done after using Malware Rootkit and TDSS Killer was using zoek.exe with the script svchost.exe;z And there's the results MD5: DECE352416436AAEF18E8CB2C0D1279D SHA1: 42D6028E882CD8028CDB68AA6350C707CC504DD3 --- C:\Windows\Prefetch\SVCHOST.EXE-C871F054.pf --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 25366 Created time: 2014-07-25 16:27:43 Modified time: 2014-07-25 16:27:43 MD5: AEE621E474613531731A27CB509E1014 SHA1: 0C1AB3D2D187B6B27CA6097B36534DEEA54488A9 --- C:\Windows\System32\svchost.exe --- Company: Microsoft Corporation File Description: Processus hôte pour les services Windows File Version: 6.1.7600.16385 (win7_rtm.090713-1255) Product Name: Système d’exploitation Microsoft® Windows® Copyright: © Microsoft Corporation. Tous droits réservés. Original Filename: svchost.exe.mui File type: ----a-w- File size: 20992 Created time: 2009-07-13 23:19:28 Modified time: 2009-07-14 01:14:41 MD5: 54A47F6B5E09A77E61649109C6A08866 SHA1: 4AF001B3C3816B860660CF2DE2C0FD3C1DFB4878 --- C:\Windows\System32\fr-FR\svchost.exe.mui --- Company: Microsoft Corporation File Description: Processus hôte pour les services Windows File Version: 6.1.7600.16385 (win7_rtm.090713-1255) Product Name: Système d’exploitation Microsoft® Windows® Copyright: © Microsoft Corporation. Tous droits réservés. Original Filename: svchost.exe.mui File type: ----a-w- File size: 2048 Created time: 2010-11-23 20:43:29 Modified time: 2010-11-23 20:43:29 MD5: 0A963D5DFB4245BF19B7B4AB0D83560E SHA1: 4E91CFBE5EE0BDF860DE430DBB38FC8269CDC759 --- C:\Windows\SysWOW64\ezSharedSvcHost.exe --- Company: EasyBits Software AS File Description: Shared EasyBits services for Windows File Version: 5.0.0.101 Product Name: Copyright: EasyBits Software AS Original Filename: File type: ----a-w- File size: 514232 Created time: 2010-11-23 20:39:35 Modified time: 2010-04-23 20:00:00 MD5: CA793DCC1D5F619021EF1D37CC7A831E SHA1: C8E33F65FFF39C010F6AA6C64314D56267D94196 --- C:\Windows\SysWOW64\svchost.exe --- Company: Microsoft Corporation File Description: Processus hôte pour les services Windows File Version: 6.1.7600.16385 (win7_rtm.090713-1255) Product Name: Système d’exploitation Microsoft® Windows® Copyright: © Microsoft Corporation. Tous droits réservés. Original Filename: svchost.exe.mui File type: ----a-w- File size: 20992 Created time: 2009-07-13 23:19:28 Modified time: 2009-07-14 01:14:41 MD5: 54A47F6B5E09A77E61649109C6A08866 SHA1: 4AF001B3C3816B860660CF2DE2C0FD3C1DFB4878 --- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\CrashDumps\ezSharedSvcHost.exe.1332.dmp --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 566197 Created time: 2014-07-14 20:08:56 Modified time: 2014-07-14 20:08:56 MD5: 01CF162E52887417221E78B45D8B865F SHA1: 95856C72F91DB843E35928BE0FA0D806087F866F --- C:\Windows\SysWOW64\fr-FR\svchost.exe.mui --- Company: Microsoft Corporation File Description: Processus hôte pour les services Windows File Version: 6.1.7600.16385 (win7_rtm.090713-1255) Product Name: Système d’exploitation Microsoft® Windows® Copyright: © Microsoft Corporation. Tous droits réservés. Original Filename: svchost.exe.mui File type: ----a-w- File size: 2048 Created time: 2010-11-23 20:43:29 Modified time: 2010-11-23 20:43:29 MD5: 0A963D5DFB4245BF19B7B4AB0D83560E SHA1: 4E91CFBE5EE0BDF860DE430DBB38FC8269CDC759 --- C:\Windows\winsxs\amd64_microsoft-windows-s..s-svchost.resources_31bf3856ad364e35_6.1.7600.16385_fr-fr_4fc0b563b423b21e\svchost.exe.mui --- Company: Microsoft Corporation File Description: Processus hôte pour les services Windows File Version: 6.1.7600.16385 (win7_rtm.090713-1255) Product Name: Système d’exploitation Microsoft® Windows® Copyright: © Microsoft Corporation. Tous droits réservés. Original Filename: svchost.exe.mui File type: ----a-w- File size: 2048 Created time: 2010-11-23 20:43:25 Modified time: 2010-11-23 20:43:25 MD5: 0F5AF281B79F91D782FAE3230FF90288 SHA1: 43AFF858A5042047BE70EEC28E166E12D76C9C49 --- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe --- Company: Microsoft Corporation File Description: Processus hôte pour les services Windows File Version: 6.1.7600.16385 (win7_rtm.090713-1255) Product Name: Système d’exploitation Microsoft® Windows® Copyright: © Microsoft Corporation. Tous droits réservés. Original Filename: svchost.exe.mui File type: ----a-w- File size: 27136 Created time: 2009-07-13 23:31:13 Modified time: 2009-07-14 01:39:46 MD5: C78655BC80301D76ED4FEF1C1EA40A7D SHA1: 619652B42AFE5FB0E3719D7AEDA7A5494AB193E8 --- C:\Windows\winsxs\amd64_wcf-m_smsvchost_exe_cnf_31bf3856ad364e35_6.1.7600.16385_none_50a8efa432beeea2\SMSvcHost.exe.config --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 1951 Created time: 2009-07-14 01:01:53 Modified time: 2009-06-10 20:30:46 MD5: 757BC33428B870035A16FD96B9DDB7FA SHA1: 1807228029AC16B20CF77A02D2059AADA5F0A08C --- C:\Windows\winsxs\amd64_wcf-smsvchost_b03f5f7f11d50a3a_6.1.7600.16385_none_c7f13af70ac77b22\SMSvcHost.exe --- Company: Microsoft Corporation File Description: SMSvcHost.exe File Version: 3.0.4506.4926 (NetFXw7.030729-4900) Product Name: Microsoft® .NET Framework Copyright: © Microsoft Corporation. All rights reserved. Original Filename: SMSvcHost.exe File type: ----a-w- File size: 116560 Created time: 2009-07-14 01:01:53 Modified time: 2009-06-10 20:30:46 MD5: 3E5A36127E201DDF663176B66828FAFE SHA1: FC57F6847125BF31D23AF9580994514E24E0461E --- C:\Windows\winsxs\amd64_wcf-smsvchost_b03f5f7f11d50a3a_6.1.7601.22126_none_b0f9770f24c56a09\SMSvcHost.exe --- Company: Microsoft Corporation File Description: SMSvcHost.exe File Version: 3.0.4506.5846 (QFE.030729-5800) Product Name: Microsoft® .NET Framework Copyright: © Microsoft Corporation. All rights reserved. Original Filename: SMSvcHost.exe File type: ----a-w- File size: 117344 Created time: 2013-01-09 19:07:52 Modified time: 2012-10-05 10:56:11 MD5: A86CCDC27CDB60D21066622DC775DEB0 SHA1: EF8A2C1B18DC6A05F258CEBB8983CAF256B4C900 --- C:\Windows\winsxs\msil_smsvchost_b03f5f7f11d50a3a_6.1.7600.16385_none_e6e1153910bdcce8\SMSvcHost.exe --- Company: Microsoft Corporation File Description: SMSvcHost.exe File Version: 3.0.4506.4926 (NetFXw7.030729-4900) Product Name: Microsoft® .NET Framework Copyright: © Microsoft Corporation. All rights reserved. Original Filename: SMSvcHost.exe File type: ----a-w- File size: 128848 Created time: 2009-07-14 00:36:26 Modified time: 2009-06-10 21:14:05 MD5: FE2AA5A684B0DD9B1FAE57B7817C198B SHA1: CAE75C4414900CF83F28E07A61EBFC18149B2163 --- C:\Windows\winsxs\msil_smsvchost_b03f5f7f11d50a3a_6.1.7601.17514_none_e6b622bd1115139e\SMSvcHost.exe --- Company: Microsoft Corporation File Description: SMSvcHost.exe File Version: 3.0.4506.5420 (Win7SP1.030729-5400) Product Name: Microsoft® .NET Framework Copyright: © Microsoft Corporation. All rights reserved. Original Filename: SMSvcHost.exe File type: ----a-w- File size: 128848 Created time: 2011-11-22 12:03:58 Modified time: 2010-11-05 01:52:39 MD5: F476EC40033CDB91EFBE73EB99B8362D SHA1: 949A482B241CEB37AC4CF22EEBF8DA5188D50A8F --- C:\Windows\winsxs\msil_smsvchost_b03f5f7f11d50a3a_6.1.7601.22126_none_cfe951512abbbbcf\SMSvcHost.exe --- Company: Microsoft Corporation File Description: SMSvcHost.exe File Version: 3.0.4506.5846 (QFE.030729-5800) Product Name: Microsoft® .NET Framework Copyright: © Microsoft Corporation. All rights reserved. Original Filename: SMSvcHost.exe File type: ----a-w- File size: 129648 Created time: 2013-01-09 19:07:52 Modified time: 2012-10-05 10:56:07 MD5: 6D27597EF1D8FBA6420BBC3EA994F097 SHA1: C1C2D4794AEB61E88B035CE32E686E15E881515F --- C:\Windows\winsxs\x86_microsoft-windows-s..s-svchost.resources_31bf3856ad364e35_6.1.7600.16385_fr-fr_f3a219dffbc640e8\svchost.exe.mui --- Company: Microsoft Corporation File Description: Processus hôte pour les services Windows File Version: 6.1.7600.16385 (win7_rtm.090713-1255) Product Name: Système d’exploitation Microsoft® Windows® Copyright: © Microsoft Corporation. Tous droits réservés. Original Filename: svchost.exe.mui File type: ----a-w- File size: 2048 Created time: 2010-11-23 20:43:29 Modified time: 2010-11-23 20:43:29 MD5: 0A963D5DFB4245BF19B7B4AB0D83560E SHA1: 4E91CFBE5EE0BDF860DE430DBB38FC8269CDC759 --- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe --- Company: Microsoft Corporation File Description: Processus hôte pour les services Windows File Version: 6.1.7600.16385 (win7_rtm.090713-1255) Product Name: Système d’exploitation Microsoft® Windows® Copyright: © Microsoft Corporation. Tous droits réservés. Original Filename: svchost.exe.mui File type: ----a-w- File size: 20992 Created time: 2009-07-13 23:19:28 Modified time: 2009-07-14 01:14:41 MD5: 54A47F6B5E09A77E61649109C6A08866 SHA1: 4AF001B3C3816B860660CF2DE2C0FD3C1DFB4878 --- C:\Windows\winsxs\x86_wcf-m_smsvchost_exe_cnf_31bf3856ad364e35_6.1.7600.16385_none_f48a54207a617d6c\SMSvcHost.exe.config --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File type: ----a-w- File size: 1951 Created time: 2009-07-14 00:36:26 Modified time: 2009-06-10 21:14:05 MD5: 757BC33428B870035A16FD96B9DDB7FA SHA1: 1807228029AC16B20CF77A02D2059AADA5F0A08C ==== C:\zoek_backup content ====================== C:\zoek_backup (files=0 folders=0 0 bytes) ==== EOF on 27/07/2014 at 15:13:30,59 ====================== If you can explain me I don't really understand it, thanks in advance
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.