Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

RegSvr32 module failed to load [Solved]


  • This topic is locked This topic is locked

#1
hubchau

hubchau

    New Member

  • Member
  • Pip
  • 4 posts

Hi, 

 

So everytime my Mom starts her PC up, she ends up with this message:

 

FQMOt5W.png

 

which says:

 

The module <path>/IcfgUsb32.dll failed to load.  Make sure the binary is stored at the specified path or debug it to check for problems with the binary or dependent .DLL files.  The specified module could not be found.

 

My mom thinks it appeared after I installed a legit version of Office 2016 on her PC a few weeks ago.

 

You'll find below the contents of  the FRST.txt and Addition.txt files.

 

I should add that the PC already had an issue/virus a few years ago, which lead the Start menu to have all its entries to be emptied. I think I solved it, but maybe I didn't.

 

The logs are in english, please tell me if it's issue and i'll try to swith the OS to English.

 

 

FRST.txt:

 

Résultats d'analyse de  Farbar Recovery Scan Tool (FRST) (x64) Version:16-05-2016
Exécuté par Laurence (administrateur) sur LAURENCE-TOSH (16-05-2016 16:33:24)
Exécuté depuis C:\Users\Laurence\Desktop
Profils chargés: Laurence (Profils disponibles: Laurence & admin & Administrateur)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Chrome)
Mode d'amorçage: Normal
Tutoriel pour Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processus (Avec liste blanche) =================
 
(Si un élément est inclus dans le fichier fixlist.txt, le processus sera arrêté. Le fichier ne sera pas déplacé.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Sony) C:\Program Files (x86)\Sony\Xperia Companion\XperiaCompanionAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\wbengine.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registre (Avec liste blanche) ===========================
 
(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé. Le fichier ne sera pas déplacé.)
 
HKLM\...\Run: [] => [X]
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1654400 2011-12-06] (Conexant Systems, Inc.)
HKLM\...\Run: [SRS Premium Sound HD] => C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe [2165120 2012-02-06] (SRS Labs, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2867984 2011-12-23] (Synaptics Incorporated)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [378968 2011-12-22] (Alcor Micro Corp.)
HKLM\...\Run: [ThpSrv] => C:\windows\system32\thpsrv /logon
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2012-01-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-05] (Intel Corporation)
HKLM-x32\...\Run: [TSleepSrv] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe [253312 2011-11-22] (TOSHIBA)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [90448 2011-11-02] (Research In Motion Limited)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [807392 2016-03-17] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [66328 2016-04-25] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\Run: [Dropbox Update] => C:\Users\Laurence\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-20] (Dropbox, Inc.)
HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\Run: [GoogleChromeAutoLaunch_286F20CF5057955FCE7A62896CED1F0A] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [881304 2016-05-11] (Google Inc.)
HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4290240 2016-03-01] (Disc Soft Ltd)
HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\Run: [Ukmedia] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\Laurence\AppData\Local\YTPack\IcfgUsb32.dll
HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8698584 2016-04-15] (Piriform Ltd)
HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\Run: [XperiaCompanionAgent] => C:\Program Files (x86)\Sony\Xperia Companion\XperiaCompanionAgent.exe [2033536 2016-04-11] (Sony)
HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\Run: [XperiaCompanion] => C:\Program Files (x86)\Sony\Xperia Companion\XperiaCompanionAgent.exe [2033536 2016-04-11] (Sony)
HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\Run: [RIMDeviceManager] => C:\Program Files (x86)\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe [2226776 2012-08-24] (Research In Motion Limited)
HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\MountPoints2: {1e4e9439-1289-11e6-b3e0-047d7bba8e3d} - E:\startme.exe
HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\MountPoints2: {c0d3280b-9df9-11e3-a262-047d7bba8e3d} - E:\LGAutoRun.exe
HKU\S-1-5-21-929901827-491967010-1845701030-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Mystify.scr [242688 2010-11-21] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-07] (Dropbox, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Avec liste blanche) ====================
 
(Si un élément est inclus dans le fichier fixlist.txt, s'il s'agit d'un élément du Registre, il sera supprimé ou restauré à la valeur par défaut.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{E8EFDA1D-2F57-4AA9-9FC5-97079DE34E92}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{FE9F17D7-81E9-405E-B263-668037FB2921}: [DhcpNameServer] 192.168.1.254
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-929901827-491967010-1845701030-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.avira.net/#web/result?source=art&q=
HKU\S-1-5-21-929901827-491967010-1845701030-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKU\S-1-5-21-929901827-491967010-1845701030-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
SearchScopes: HKLM -> {3A4B3C75-8496-473D-95D6-DB69101F7A27} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TEUA;
SearchScopes: HKLM-x32 -> DefaultScope la valeur est absente
SearchScopes: HKLM-x32 -> {3A4B3C75-8496-473D-95D6-DB69101F7A27} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TEUA;
SearchScopes: HKU\S-1-5-21-929901827-491967010-1845701030-1001 -> {3A4B3C75-8496-473D-95D6-DB69101F7A27} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TEUA_frFR491
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2016-04-29] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\root\Office16\URLREDIR.DLL [2016-04-29] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-04-29] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2016-04-29] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-17] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\URLREDIR.DLL [2016-04-29] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2016-04-29] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-17] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27] (Google Inc.)
Toolbar: HKU\S-1-5-21-929901827-491967010-1845701030-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/FR/Core/Player/2020PlayerAX_IKEA_Win32.cab
Handler-x32: http - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: http - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: https - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: https - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: ipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  Pas de fichier
Handler-x32: msdaipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-04-29] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-04-29] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-04-29] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-04-29] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-04-29] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-04-29] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-04-29] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-04-29] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
 
FireFox:
========
FF ProfilePath: C:\Users\Laurence\AppData\Roaming\Mozilla\Firefox\Profiles\1nmmifpe.default
FF Plugin: @microsoft.com/GENUINE -> disabled [Pas de fichier]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-04-29] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-17] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\new_plugin\npjp2.dll [Pas de fichier]
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-17] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Pas de fichier]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-04-29] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2016-04-29] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [Pas de fichier]
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2012-09-20] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-05-03] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.fr/
CHR StartupUrls: Default -> "hxxp://www.orange.fr/"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.102\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.102\ppGoogleNaClPluginChrome.dll => Pas de fichier
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.102\pdf.dll => Pas de fichier
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll => Pas de fichier
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll => Pas de fichier
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll => Pas de fichier
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL => Pas de fichier
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL => Pas de fichier
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\\npsitesafety.dll => Pas de fichier
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll => Pas de fichier
CHR Plugin: (Java™ Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => Pas de fichier
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll => Pas de fichier
CHR Profile: C:\Users\Laurence\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dropbox pour Gmail) - C:\Users\Laurence\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpdmhfocilnekecfjgimjdeckachfbec [2015-12-04]
CHR Extension: (Protection Web Avira) - C:\Users\Laurence\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-05-13]
CHR Extension: (AdBlock) - C:\Users\Laurence\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-05-15]
CHR Extension: (Paiements via le Chrome Web Store) - C:\Users\Laurence\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (20-20 3D Viewer for IKEA) - C:\Users\Laurence\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfhldcakmgpmglboaclpfdedehjblalp [2013-07-26]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-929901827-491967010-1845701030-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [begbnpffhnpedhocnobliippgejhjpfp] - C:\Users\Laurence\AppData\Roaming\Cool Mirage Ltd\gophotoit\1.8.29.5\gophotoit.crx <non trouvé(e)>
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Avec liste blanche) ========================
 
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
 
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [955736 2016-03-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [466504 2016-03-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [466504 2016-03-17] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1424880 2016-03-17] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [280008 2016-04-25] (Avira Operations GmbH & Co. KG)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2911464 2016-04-29] (Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1444544 2016-03-01] (Disc Soft Ltd)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [Fichier non signé]
S3 ose64; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [242736 2016-04-28] (Microsoft Corporation) [Fichier non signé]
R2 Thpsrv; C:\windows\system32\ThpSrv.exe [558592 2011-04-21] (TOSHIBA Corporation) [Fichier non signé]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Pilotes (Avec liste blanche) ==========================
 
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
 
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [154816 2016-03-17] (Avira Operations GmbH & Co. KG)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [50464 2014-04-28] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [133168 2016-03-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-08-15] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [69888 2016-03-17] (Avira Operations GmbH & Co. KG)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2016-04-03] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2016-04-03] (Disc Soft Ltd)
R3 dvdfab; C:\Windows\System32\drivers\dvdfab.sys [79232 2011-08-15] (Fengtao Software Inc.)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [74752 2011-07-25] (Research In Motion Limited)
R3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44032 2011-07-20] (Research in Motion Ltd)
R3 SmbDrv; C:\Windows\System32\DRIVERS\Smb_driver.sys [21264 2011-12-23] (Synaptics Incorporated)
S2 SSPORT; C:\windows\SysWOW64\Drivers\SSPORT.sys [11576 2009-09-10] (Samsung Electronics)
S3 Tosrfcom; pas de ImagePath
S2 DgiVecp; \??\C:\windows\system32\Drivers\DgiVecp.sys [X]
 
==================== NetSvcs (Avec liste blanche) ===================
 
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
 
 
==================== Un mois - Créés - fichiers et dossiers ========
 
(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)
 
2016-05-16 16:33 - 2016-05-16 16:33 - 00028496 _____ C:\Users\Laurence\Desktop\FRST.txt
2016-05-16 16:25 - 2016-05-16 16:25 - 05200384 _____ (AVAST Software) C:\Users\Laurence\Desktop\aswmbr.exe
2016-05-16 16:22 - 2016-05-16 16:33 - 00000000 ____D C:\FRST
2016-05-16 16:13 - 2016-05-16 16:13 - 03651136 _____ C:\Users\Laurence\Downloads\adwcleaner_5.117.exe
2016-05-16 16:11 - 2016-05-16 16:11 - 00000000 ____D C:\_OTL
2016-05-16 15:51 - 2016-05-16 15:51 - 02382336 _____ (Farbar) C:\Users\Laurence\Desktop\FRST64.exe
2016-05-16 15:50 - 2016-05-16 15:50 - 00602112 _____ (OldTimer Tools) C:\Users\Laurence\Desktop\OTL.exe
2016-05-14 09:38 - 2016-05-14 09:38 - 00000000 ____D C:\Users\Laurence\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-05-08 09:18 - 2016-05-08 09:18 - 00083811 _____ C:\Users\Laurence\Downloads\Bouyguestelecom_Facture_20160502.pdf
2016-05-07 15:37 - 2016-05-07 15:37 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2016-05-05 19:30 - 2016-05-05 19:30 - 00002669 _____ C:\Users\Public\Desktop\Xperia Companion.lnk
2016-05-05 19:30 - 2016-05-05 19:30 - 00000000 ____D C:\Users\Laurence\Searches\Documents\Sony
2016-05-05 19:30 - 2016-05-05 19:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2016-05-05 19:30 - 2016-05-05 19:30 - 00000000 ____D C:\Program Files (x86)\Sony
2016-05-05 18:56 - 2016-05-05 18:58 - 42304896 _____ (Sony) C:\Users\Laurence\AppData\Local\pcc.exe
2016-05-01 16:36 - 2016-05-01 16:36 - 00002391 _____ C:\Users\Laurence\Desktop\Outlook 2016.lnk
2016-05-01 16:26 - 2016-05-01 16:38 - 00000000 ____D C:\Users\Laurence\Searches\Documents\Fichiers Outlook
2016-05-01 15:17 - 2016-05-01 15:17 - 00492830 _____ C:\Users\Laurence\Searches\Documents\cc_20160501_151701.reg
2016-05-01 12:45 - 2016-05-01 12:45 - 00002806 _____ C:\windows\System32\Tasks\CCleanerSkipUAC
2016-05-01 12:45 - 2016-05-01 12:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-05-01 12:45 - 2016-05-01 12:45 - 00000000 ____D C:\Program Files\CCleaner
2016-05-01 12:44 - 2016-05-01 12:44 - 06882192 _____ (Piriform Ltd) C:\Users\Laurence\Downloads\ccsetup517.exe
2016-04-29 17:59 - 2016-04-29 18:00 - 00000000 ____D C:\Users\Laurence\Downloads\The.Five.UK.S01E03.HDTV.x264-TLA[ettv]
2016-04-24 19:55 - 2016-04-24 19:56 - 00000000 ____D C:\Users\Laurence\Downloads\The.Blacklist.S03E19.WEB-DL.x264-FUM[Talamasca32]
 
==================== Un mois - Modifiés - fichiers et dossiers ========
 
(Si un élément est inclus dans le fichier fixlist.txt, le fichier/dossier sera déplacé.)
 
2016-05-16 16:33 - 2015-06-20 13:22 - 00001208 _____ C:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-929901827-491967010-1845701030-1001UA.job
2016-05-16 16:33 - 2012-02-26 21:20 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2016-05-16 16:28 - 2009-07-14 06:45 - 00024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-05-16 16:28 - 2009-07-14 06:45 - 00024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-05-16 16:20 - 2012-02-26 21:24 - 00001066 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-16 16:19 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-05-16 16:18 - 2014-06-01 11:41 - 00000000 ____D C:\AdwCleaner
2016-05-16 15:49 - 2012-02-26 21:24 - 00001070 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-16 15:17 - 2013-01-07 23:31 - 00000000 ____D C:\Users\Laurence\AppData\Roaming\uTorrent
2016-05-16 15:17 - 2009-07-14 05:20 - 00000000 ____D C:\windows\inf
2016-05-16 14:29 - 2013-01-27 13:18 - 00057344 _____ C:\Users\Laurence\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-05-16 14:25 - 2011-07-05 16:04 - 00747250 _____ C:\windows\system32\perfh00C.dat
2016-05-16 14:25 - 2011-07-05 16:04 - 00149742 _____ C:\windows\system32\perfc00C.dat
2016-05-16 14:25 - 2009-07-14 07:13 - 01667292 _____ C:\windows\system32\PerfStringBackup.INI
2016-05-16 14:20 - 2013-08-30 19:41 - 00000000 ____D C:\Users\Laurence\Desktop\François
2016-05-16 11:48 - 2013-02-09 17:53 - 00000000 ____D C:\Users\Laurence\Searches\Documents\ECOLE
2016-05-16 11:39 - 2016-02-08 12:38 - 00017920 _____ C:\windows\SysWOW64\rpcnetp.dll
2016-05-16 11:38 - 2016-02-08 12:38 - 00017920 _____ C:\windows\SysWOW64\rpcnetp.exe
2016-05-16 11:38 - 2016-02-08 12:38 - 00017920 _____ C:\windows\system32\rpcnetp.exe
2016-05-15 19:19 - 2015-06-20 13:22 - 00001156 _____ C:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-929901827-491967010-1845701030-1001Core.job
2016-05-15 15:21 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\NDF
2016-05-14 22:39 - 2012-12-02 23:39 - 00000206 _____ C:\windows\Tasks\AutoKMSDaily.job
2016-05-14 09:38 - 2012-11-13 00:34 - 00000000 ____D C:\Users\Laurence\AppData\Roaming\Dropbox
2016-05-13 23:17 - 2012-10-09 22:26 - 00000000 ____D C:\Users\Laurence\AppData\Roaming\vlc
2016-05-13 18:48 - 2014-12-26 12:13 - 00003886 _____ C:\windows\System32\Tasks\Adobe Acrobat Update Task
2016-05-13 18:47 - 2015-11-05 20:26 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-05-12 20:33 - 2012-02-26 21:20 - 00797376 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2016-05-12 20:33 - 2012-02-26 21:20 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-05-12 20:33 - 2012-02-26 21:20 - 00003768 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2016-05-12 19:47 - 2014-09-07 20:54 - 00000000 ____D C:\ProgramData\Package Cache
2016-05-12 19:47 - 2014-09-07 20:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2016-05-10 22:44 - 2012-02-26 21:24 - 00004066 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-05-10 22:44 - 2012-02-26 21:24 - 00003814 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-05-07 15:38 - 2016-04-05 19:59 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-05-07 15:37 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2016-05-07 15:34 - 2016-04-05 19:50 - 00000000 ____D C:\Program Files\Microsoft Office
2016-05-02 10:07 - 2009-07-14 07:08 - 00032482 _____ C:\windows\Tasks\SCHEDLGU.TXT
2016-05-01 16:38 - 2013-01-27 15:42 - 00000000 ____D C:\Users\Laurence\Searches\Documents\Outlook Files
2016-05-01 15:09 - 2016-04-03 14:32 - 00000000 ____D C:\Users\Laurence\AppData\Roaming\DAEMON Tools Lite
2016-05-01 15:09 - 2015-09-26 22:51 - 00000000 ____D C:\Users\Laurence\AppData\Local\PDFCreator
2016-05-01 15:09 - 2015-04-21 22:22 - 00000000 ____D C:\Program Files\PDFCreator
2016-05-01 15:09 - 2013-01-04 19:04 - 00000000 ____D C:\Users\Laurence\AppData\Roaming\TeamViewer
2016-05-01 15:08 - 2015-09-04 06:24 - 00000000 ____D C:\windows\Minidump
2016-05-01 15:08 - 2012-12-21 22:53 - 00000000 ___DC C:\Users\Laurence\AppData\Local\MigWiz
2016-05-01 15:08 - 2012-02-27 04:54 - 00000000 ____D C:\windows\Panther
2016-05-01 15:08 - 2009-07-14 05:20 - 00000000 ____D C:\windows\ModemLogs
2016-04-27 09:18 - 2012-11-13 00:35 - 00000000 ___RD C:\Users\Laurence\Dropbox
2016-04-26 09:21 - 2014-11-17 20:23 - 00000000 ____D C:\Users\Laurence\AppData\Local\Popcorn-Time
2016-04-16 09:13 - 2016-04-14 19:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-04-16 09:13 - 2015-02-16 22:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
 
==================== Fichiers à la racine de certains dossiers =======
 
2013-01-27 16:10 - 2013-01-27 16:10 - 0038464 _____ () C:\Users\Laurence\AppData\Roaming\Comma Separated Values (Windows).ADR
2012-07-07 14:58 - 2016-05-16 14:37 - 0001232 _____ () C:\Users\Laurence\AppData\Roaming\Rim.Desktop.Exception.log
2012-07-07 14:57 - 2012-07-07 14:57 - 0001153 _____ () C:\Users\Laurence\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2012-07-07 14:58 - 2016-05-16 14:36 - 0001232 _____ () C:\Users\Laurence\AppData\Roaming\Rim.DesktopHelper.Exception.log
2012-07-07 14:58 - 2016-05-16 14:37 - 0001232 _____ () C:\Users\Laurence\AppData\Roaming\Rim.Transcoder.Exception.log
2013-01-27 13:18 - 2016-05-16 14:29 - 0057344 _____ () C:\Users\Laurence\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-05-05 18:56 - 2016-05-05 18:58 - 42304896 _____ (Sony) C:\Users\Laurence\AppData\Local\pcc.exe
2014-09-14 14:30 - 2014-09-14 14:30 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-10-10 19:28 - 2012-10-10 20:11 - 0000303 _____ () C:\ProgramData\hpzinstall.log
 
Fichiers à déplacer ou supprimer:
====================
C:\Users\Laurence\Apache_OpenOffice_4.1.1_Win_x86_install_en-US.exe
C:\Users\Laurence\Setup.x64.fr-FR_ProPlusRetail_DRN4R-XQ7DK-9QTH6-WY3PM-JK83V_act_1_.exe
 
 
Certains fichiers dans TEMP:
====================
C:\Users\admin\AppData\Local\Temp\avgnt.exe
C:\Users\Laurence\AppData\Local\Temp\avgnt.exe
 
 
==================== Bamital & volsnap =================
 
(Il n'y a pas de correction automatique pour les fichiers qui ne satisfont pas à la vérification.)
 
C:\windows\system32\winlogon.exe => Le fichier est signé numériquement
C:\windows\system32\wininit.exe => Le fichier est signé numériquement
C:\windows\SysWOW64\wininit.exe => Le fichier est signé numériquement
C:\windows\explorer.exe => Le fichier est signé numériquement
C:\windows\SysWOW64\explorer.exe => Le fichier est signé numériquement
C:\windows\system32\svchost.exe => Le fichier est signé numériquement
C:\windows\SysWOW64\svchost.exe => Le fichier est signé numériquement
C:\windows\system32\services.exe => Le fichier est signé numériquement
C:\windows\system32\User32.dll => Le fichier est signé numériquement
C:\windows\SysWOW64\User32.dll => Le fichier est signé numériquement
C:\windows\system32\userinit.exe => Le fichier est signé numériquement
C:\windows\SysWOW64\userinit.exe => Le fichier est signé numériquement
C:\windows\system32\rpcss.dll => Le fichier est signé numériquement
C:\windows\system32\dnsapi.dll => Le fichier est signé numériquement
C:\windows\SysWOW64\dnsapi.dll => Le fichier est signé numériquement
C:\windows\system32\Drivers\volsnap.sys => Le fichier est signé numériquement
 
 
LastRegBack: 2016-05-08 12:38
 
==================== Fin de FRST.txt ============================
 

 

Addition.txt:

 

Résultats de l'Analyse supplémentaire de Farbar Recovery Scan Tool (x64) Version:16-05-2016
Exécuté par Laurence (2016-05-16 16:34:12)
Exécuté depuis C:\Users\Laurence\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-07-06 16:35:08)
Mode d'amorçage: Normal
==========================================================
 
 
==================== Comptes: =============================
 
admin (S-1-5-21-929901827-491967010-1845701030-1003 - Administrator - Enabled) => C:\Users\admin
Administrateur (S-1-5-21-929901827-491967010-1845701030-500 - Administrator - Disabled) => C:\Users\Administrateur
HomeGroupUser$ (S-1-5-21-929901827-491967010-1845701030-1002 - Limited - Enabled)
Invité (S-1-5-21-929901827-491967010-1845701030-501 - Limited - Enabled)
Laurence (S-1-5-21-929901827-491967010-1845701030-1001 - Administrator - Enabled) => C:\Users\Laurence
 
==================== Centre de sécurité ========================
 
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé.)
 
AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Programmes installés ======================
 
(Seuls les logiciels publicitaires ('adware') avec la marque 'caché' ('Hidden') sont susceptibles d'être ajoutés au fichier fixlist.txt pour qu'ils ne soient plus masqués. Les programmes publicitaires devront être désinstallés manuellement.)
 
µTorrent (HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\uTorrent) (Version: 3.4.2.32239 - BitTorrent Inc.)
Adobe Acrobat Reader DC - Français (HKLM-x32\...\{AC76BA86-7AD7-1036-7B44-AC0F074E4100}) (Version: 15.016.20039 - Adobe Systems Incorporated)
Adobe Digital Editions 2.0 (HKLM-x32\...\Adobe Digital Editions 2.0) (Version: 2.0 - Adobe Systems Incorporated)
Adobe Flash Player 21 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 21.0.0.242 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 4.3.17.00279 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 4.3.17.00279 - Alcor Micro Corp.) Hidden
AMD Catalyst Install Manager (HKLM\...\{F856881A-D370-B1A7-2AFF-128F4AA93558}) (Version: 3.0.859.0 - Advanced Micro Devices, Inc.)
Apple Application Support (32 bits) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Application Support (64 bits) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Bluetooth Filter Driver Package (HKLM\...\{65486209-5C54-439C-8383-8AC9BBE25932}) (Version: 1.0.0.12 - Atheros Communications)
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.0.12.13 - Atheros Communications Inc.)
Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros)
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.16.282 - Avira Operations GmbH & Co. KG)
Avira Launcher (HKLM-x32\...\{bfb60b68-92b8-481b-b416-7e05b4ea01c9}) (Version: 1.1.61.18979 - Avira Operations GmbH & Co. KG)
Avira Launcher (x32 Version: 1.1.61.18979 - Avira Operations GmbH & Co. KG) Hidden
BlackBerry Desktop Software 7.0 (HKLM-x32\...\BlackBerry_Desktop) (Version: 7.0.0.59 - Research In Motion Ltd.)
BlackBerry Desktop Software 7.0 (x32 Version: 7.0.0.59 - Research In Motion Ltd.) Hidden
BlackBerry Device Manager 7.0 (HKLM-x32\...\BlackBerry_HandheldManager) (Version: 7.0.0.43 - Research In Motion Ltd.)
BlackBerry Device Manager 7.0 (x32 Version: 7.0.0.43 - Research In Motion Ltd.) Hidden
BlackBerry Device Software Updater (HKLM-x32\...\{38676C9C-270F-43D1-926A-E45DE8820A6B}) (Version: 7.1.0.34 - Research In Motion Ltd)
Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v9.00.00(T) - TOSHIBA CORPORATION)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Canon PIXMA iP4000 (HKLM\...\CANONBJ_Deinstall_CNMCP64.DLL) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 5.17 - Piriform)
CD-LabelPrint (HKLM-x32\...\MediaNavigation.CDLabelPrint) (Version:  - )
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.51.2.63 - Conexant)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.3.0.0152 - Disc Soft Ltd)
Deezer (HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\DeezerDrive) (Version: 1.0.769.677 - Deezer)
Dropbox (HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\Dropbox) (Version: 3.20.1 - Dropbox, Inc.)
Garmin USB Drivers (HKLM-x32\...\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries)
Garmin WebUpdater (HKLM-x32\...\{00FE2935-FB56-4410-AB5F-D6E70C1771D2}) (Version: 2.5.6 - Garmin Ltd or its subsidiaries)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 50.0.2661.102 - Google Inc.)
Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7619.1252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.1.1399 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.1.209 - Intel Corporation)
iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
Kobo (HKLM-x32\...\Kobo) (Version: 3.19.3765 - Rakuten Kobo Inc.)
Logiciel de base du périphérique HP Photosmart 6520 series (HKLM\...\{B04E95AD-CBEB-443A-989F-9E9F9170907F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 365 ProPlus - fr-fr (HKLM\...\O365ProPlusRetail - fr-fr) (Version: 16.0.6868.2060 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\OneDriveSetup.exe) (Version: 17.3.6281.1202 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Module linguistique Microsoft Visual Studio 2010 Tools pour Office Runtime (x64) - FRA (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - FRA) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 45.0.2 (x86 fr) (HKLM-x32\...\Mozilla Firefox 45.0.2 (x86 fr)) (Version: 45.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 45.0.2.5941 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
myCANAL (HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\3504603462.player.canalplus.fr) (Version:  - player.canalplus.fr)
Office 16 Click-to-Run Extensibility Component (Version: 16.0.6828.1015 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.6828.1015 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (Version: 16.0.6828.1015 - Microsoft Corporation) Hidden
OpenOffice 4.1.1 (HKLM-x32\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
OpenOffice 4.1.1 Language Pack (French) (HKLM-x32\...\{2319074D-5C2A-433D-91C6-16587FDFDC1D}) (Version: 4.11.9775 - Apache Software Foundation)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.1.1 - pdfforge)
Popcorn Time (HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\Popcorn Time) (Version:  - Popcorn Official) <==== ATTENTION
Premium Sound HD (HKLM\...\{439A73C2-8CFA-4630-8484-36BCA2AEBB0A}) (Version: 1.12.0300 - SRS Labs, Inc.)
QuickTime 7 (HKLM-x32\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Secure Download Manager (HKLM-x32\...\{60232A95-0B96-4BBB-9798-85A6AB6F8210}) (Version: 3.1.60 - Kivuto Solutions Inc.)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.39.0 - Synaptics Incorporated)
TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.13852 - TeamViewer)
Tesseract-OCR - open source OCR engine (HKLM-x32\...\Tesseract-OCR) (Version: 3.02.02 - Tesseract-OCR community)
TOSHIBA HDD Protection (HKLM\...\{94A90C69-71C1-470A-88F5-AA47ECC96B40}) (Version: 2.2.2.15 - TOSHIBA Corporation)
TOSHIBA Sleep Utility (HKLM-x32\...\{654F7484-88C5-46DC-AB32-C66BCB0E2102}) (Version: 1.4.0022.000104 - TOSHIBA Corporation)
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Windows Driver Package - Garmin (grmnusb) GARMIN Devices  (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin)
Xperia Companion (HKLM-x32\...\{69fb49e3-2848-40e8-9fdd-8f02e02c327a}) (Version: 1.1.24.0 - Sony)
Xperia Companion (x32 Version: 1.1.24.0 - Sony) Hidden
 
==================== Personnalisé CLSID (Avec liste blanche): ==========================
 
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
 
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{00000001-4544-5A45-4552-2D4452495645}\InprocServer32 -> C:\Users\Laurence\AppData\Roaming\DeezerDrive\DeezerDrive.Native.x64.dll (Deezer)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{00000004-4544-5A45-4552-2D4452495645}\InprocServer32 -> C:\Users\Laurence\AppData\Roaming\DeezerDrive\DeezerDrive.Native.x64.dll (Deezer)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{00000005-4544-5A45-4552-2D4452495645}\InprocServer32 -> C:\Users\Laurence\AppData\Roaming\DeezerDrive\DeezerDrive.Native.x64.dll (Deezer)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{00000006-4544-5A45-4552-2D4452495645}\InprocServer32 -> C:\Users\Laurence\AppData\Roaming\DeezerDrive\DeezerDrive.Native.x64.dll (Deezer)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Laurence\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Laurence\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64\FileCoAuthLib64.dll ()
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Laurence\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-929901827-491967010-1845701030-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Laurence\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll (Dropbox, Inc.)
 
==================== Tâches planifiées (Avec liste blanche) =============
 
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
 
Task: {2A0D2B32-DB71-4361-B39D-9046AB51E1B2} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2016-04-29] (Microsoft Corporation)
Task: {2A5FA210-A9CF-4D3F-88D3-891AD191306E} - System32\Tasks\$dMM6KqyKu+JyN+{$ => C:\Users\Laurence\AppData\Roaming\playnowradio\playnowradio\1.3.4.8\playnowradio.exe
Task: {348B246E-632B-4515-BB89-F202C78834D0} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-929901827-491967010-1845701030-1001Core => C:\Users\Laurence\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20] (Dropbox, Inc.)
Task: {56498E98-E166-4397-A120-172581790C41} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-04-29] (Microsoft Corporation)
Task: {58C35AE2-5A6A-436B-B587-86498598867B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-04-22] (Adobe Systems Incorporated)
Task: {7FE18FFE-E784-425D-B4C7-0AFED9E26E1F} - System32\Tasks\AutoKMSDaily => C:\windows\AutoKMS.exe
Task: {87D5C29B-65CC-4056-A1F4-60AD174937CF} - System32\Tasks\{47DBFE36-9431-4C21-95DE-41E11D1FB5EB} => pcalua.exe -a C:\Users\Laurence\AppData\Roaming\playnowradio\playnowradio\1.3.4.8\playnowradio.exe -c /uninstl
Task: {A24981E6-618F-4A7A-AE16-1031A0A94654} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-05-12] (Adobe Systems Incorporated)
Task: {AA856EB5-A6C2-494E-85D6-C7864E7699DF} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-04-29] (Microsoft Corporation)
Task: {B9E07515-7F06-41FE-A56B-E6BFFB883DF1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {C17EC07F-001D-4479-88B2-12246B33C6AE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {C2CCC787-D7E7-4DEA-8DE0-48069F253A4F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2016-04-29] (Microsoft Corporation)
Task: {C73CDDB0-AB7A-44A9-9BAE-0DB8653A9448} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {DEA27C5A-9F67-487D-95E8-10C0535BAAF6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2016-04-29] (Microsoft Corporation)
Task: {F2146FC3-2CCB-473A-A378-DCB94A64BCC1} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-04-15] (Piriform Ltd)
Task: {FBD990CA-5231-4515-A3D2-3FFAA72124CC} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-929901827-491967010-1845701030-1001UA => C:\Users\Laurence\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-20] (Dropbox, Inc.)
 
(Si un élément est inclus dans le fichier fixlist.txt, le fichier tâche (.job) sera déplacé. Le fichier exécuté par la tâche ne sera pas déplacé.)
 
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\AutoKMSDaily.job => C:\windows\AutoKMS.exe
Task: C:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-929901827-491967010-1845701030-1001Core.job => C:\Users\Laurence\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-929901827-491967010-1845701030-1001UA.job => C:\Users\Laurence\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Raccourcis =============================
 
(Les éléments sont susceptibles d'être inscrits dans le fichier fixlist.txt afin d'être supprimés ou restaurés.)
 
==================== Modules chargés (Avec liste blanche) ==============
 
2011-06-21 08:42 - 2011-06-21 08:42 - 00034304 _____ () C:\windows\System32\sst3cl6.dll
2015-02-13 05:20 - 2015-02-13 05:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-05-15 16:26 - 2015-05-15 16:26 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-04-05 22:24 - 2016-04-29 07:29 - 00417472 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll
2012-07-07 19:08 - 2011-02-28 08:39 - 00211456 _____ () C:\Program Files (x86)\IZArc\IZArcCM64.dll
2016-04-15 20:07 - 2016-04-15 20:07 - 00069632 _____ () C:\Program Files\CCleaner\lang\lang-1036.dll
2012-01-20 13:13 - 2012-01-20 13:13 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2011-11-09 18:55 - 2011-11-09 18:55 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2016-05-13 18:51 - 2016-05-11 13:48 - 01738904 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.102\libglesv2.dll
2016-05-13 18:51 - 2016-05-11 13:48 - 00086168 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.102\libegl.dll
2016-05-13 18:51 - 2016-05-11 13:48 - 17565848 _____ () C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.102\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (Avec liste blanche) =========
 
(Si un élément est inclus dans le fichier fixlist.txt, seul le flux de données additionnel (ADS - Alternate Data Stream) sera supprimé.)
 
 
==================== Mode sans échec (Avec liste blanche) ===================
 
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le "AlternateShell" sera restauré.)
 
 
==================== Association (Avec liste blanche) ===============
 
(Si un élément est inclus dans le fichier fixlist.txt, l'élément de Registre sera restauré à la valeur par défaut ou supprimé.)
 
 
==================== Internet Explorer sites de confiance/sensibles ===============
 
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre.)
 
IE trusted site: HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\ge.com -> hxxps://spo-mydrivefiles.ge.com
IE trusted site: HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\samsungsetup.com -> hxxp://www.samsungsetup.com
 
==================== Hosts contenu: ===============================
 
(Si nécessaire, la commande Hosts: peut être incluse dans le fichier fixlist.txt afin de réinitialiser le fichier hosts.)
 
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
 
 
==================== Autres zones ============================
 
(Actuellement, il n'y a pas de correction automatique pour cette section.)
 
HKU\S-1-5-21-929901827-491967010-1845701030-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Laurence\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Le Pare-feu est activé.
 
==================== MSCONFIG/TASK MANAGER éléments désactivés ==
 
(Actuellement, il n'y a pas de correction automatique pour cette section.)
 
MSCONFIG\startupreg: Toshiba Registration => C:\Program Files\Toshiba\Registration\ToshibaReminder.exe
 
==================== RèglesPare-feu (Avec liste blanche) ===============
 
(Si un élément est inclus dans le fichier fixlist.txt, il sera supprimé du Registre. Le fichier ne sera pas déplacé, sauf s'il est inscrit séparément.)
 
FirewallRules: [{8FCAFA3E-08A4-450A-8802-ABD1B8AAB817}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{EE41A122-227B-439E-8B48-4FC2BD4261E6}] => (Allow) C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe
FirewallRules: [{D72820A3-DBB2-430A-85BD-CFAA56E4D400}] => (Allow) C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe
FirewallRules: [{88C03786-9AA6-4B04-ADFD-0732771F17D2}] => (Allow) LPort=4481
FirewallRules: [{BF321633-E382-4543-B618-F72CC658EBD4}] => (Allow) LPort=4481
FirewallRules: [{B96B4C8B-A029-40D4-827D-42A04757A33A}] => (Allow) LPort=4482
FirewallRules: [{0AAA6978-9756-40F5-89B6-D988860CD0C6}] => (Allow) LPort=4482
FirewallRules: [{C865EB18-3B28-45D5-8E5D-1C38592F9533}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
FirewallRules: [{86D69742-8A2C-4207-AA93-565180443342}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
FirewallRules: [{B7BA9CBE-D7B0-43A3-9552-1928612C52B5}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
FirewallRules: [{176674F2-C97E-4719-828E-C2AFAC47310C}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
FirewallRules: [{A06CC188-8D23-4B78-BBDD-FD1B9F65BB15}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{4CCDF4EF-CCCB-4C32-83EC-39A94296A408}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{72D658A2-7EBF-4857-A5F7-347AF5945863}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C5F94803-342B-4DD5-A48E-2F9CB2931E59}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{3271A57A-DB60-4AAD-BD92-BF39CC1160C6}] => (Allow) C:\Users\Laurence\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{52561B62-F40B-41B2-88DB-F95285EFBCE1}] => (Allow) C:\Users\Laurence\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [TCP Query User{1C4F8072-D293-4F99-9471-E1FBD3C9010E}C:\users\laurence\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\laurence\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{50143EF4-AF4B-4B7D-9673-AFC1F74673D0}C:\users\laurence\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\laurence\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{A550E66A-DBC1-418F-A089-FE14F6748A0B}] => (Allow) C:\Users\Laurence\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{DAE8E4CE-EF77-4A2D-BD23-CCCB405B66D7}] => (Allow) C:\Users\Laurence\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{1556A51E-B49B-4FE6-87FA-F76944034DFD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{ACD1C923-DEBC-4D2B-A9F7-8A34BECF9E2F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{F32C2E0B-C321-4900-9C8E-C87E101F8DCE}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\DeviceSetup.exe
FirewallRules: [{B6132620-CEF7-4E39-B182-DD0056F2B063}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{F3DAF037-9C58-4B02-8E25-5C06A1A44EAB}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{6AA516DA-CF00-40CA-97C0-97AFD7BEBF98}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{8B38944E-AF4F-4EC4-B4C1-4ACB5FB43B64}C:\users\laurence\appdata\local\popcorn time\nw.exe] => (Block) C:\users\laurence\appdata\local\popcorn time\nw.exe
FirewallRules: [UDP Query User{B54823AA-CCE6-43B1-8287-CDCA44E034D9}C:\users\laurence\appdata\local\popcorn time\nw.exe] => (Block) C:\users\laurence\appdata\local\popcorn time\nw.exe
FirewallRules: [TCP Query User{7B5F043E-98DE-4226-8710-4E409E31F285}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{7337E48A-9824-4A3A-A6B6-806C19077B10}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{62F9CABC-4E15-4576-B5B5-50FB36120244}C:\users\laurence\appdata\local\popcorn time\nw.exe] => (Allow) C:\users\laurence\appdata\local\popcorn time\nw.exe
FirewallRules: [UDP Query User{0B7A1BCA-B50D-416B-A035-8C649CCB5E74}C:\users\laurence\appdata\local\popcorn time\nw.exe] => (Allow) C:\users\laurence\appdata\local\popcorn time\nw.exe
FirewallRules: [{2DFC3942-2E81-4C49-8E5F-EB34D30A1D3E}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{8BDF9945-2B01-4919-BFD2-5FB4E81C30AE}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{E8F4F867-8834-418E-8F94-1F7E43BE8DAA}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{8BC2E6B5-EFDC-40C7-928E-209300E68BBB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{3D47354C-BAAA-41B0-A082-DF2923EE1166}] => (Allow) C:\Program Files (x86)\Sony\Xperia Companion\XperiaCompanion.exe
FirewallRules: [{CCDD472F-5B61-4CB1-B418-BB3DDC164A8C}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{A5B46B35-3E83-4711-874F-D5929FB7A41C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Points de restauration =========================
 
02-05-2016 11:36:11 Point de contrôle planifié
05-05-2016 19:29:37 Xperia Companion
15-05-2016 14:49:24 Installed BlackBerry Desktop Software.
 
==================== Éléments en erreur du Gestionnaire de périphériques =============
 
 
==================== Erreurs du Journal des événements: =========================
 
Erreurs Application:
==================
Error: (05/16/2016 04:20:36 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/16/2016 04:20:03 PM) (Source: ESENT) (EventID: 455) (User: )
Description: taskhost (2568) WebCacheLocal: L'Erreur -1811 s'est produite lors de l'ouverture du fichier journal C:\Users\Laurence\AppData\Local\Microsoft\Windows\WebCache\V0100743.log.
 
Error: (05/16/2016 02:20:26 PM) (Source: Microsoft Office 16) (EventID: 2011) (User: )
Description: Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {CA19643E-F5FA-4BEC-B461-CF6E0FDEA5C9}
 
Error: (05/16/2016 02:20:26 PM) (Source: Microsoft Office 16) (EventID: 2011) (User: )
Description: Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {CA19643E-F5FA-4BEC-B461-CF6E0FDEA5C9}
 
Error: (05/16/2016 11:39:31 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/15/2016 03:03:00 PM) (Source: MsiInstaller) (EventID: 11311) (User: Laurence-TOSH)
Description: Produit : BlackBerry Desktop Software 7.1 -- Erreur 1311. Fichier source introuvable(cabinet) : C:\Users\Laurence\AppData\Local\Temp\WZSE0.TMP\Data1.cab. Vérifiez que ce fichier existe et que vous êtes autorisé à y accéder.
 
Error: (05/15/2016 02:51:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 12807
 
Error: (05/15/2016 02:51:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 12807
 
Error: (05/15/2016 02:51:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (05/15/2016 02:50:30 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Le programme sllauncher.exe version 5.1.41212.0 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans le Centre de maintenance.
 
ID de processus : 1158
 
Heure de début : 01d1aea30c76cb6b
 
Heure de fin : 31
 
Chemin d’accès de l’application : C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe
 
ID de rapport : 8efe0f8f-1a9b-11e6-9d6b-047d7bba8e3d
 
 
Erreurs système:
=============
Error: (05/16/2016 04:19:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Le service SSPORT n’a pas pu démarrer en raison de l’erreur : 
%%2
 
Error: (05/16/2016 04:19:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Le service DgiVecp n’a pas pu démarrer en raison de l’erreur : 
%%2
 
Error: (05/16/2016 04:18:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Le service Apple Mobile Device Service n’a pas pu démarrer en raison de l’erreur : 
%%109
 
Error: (05/16/2016 04:18:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Le service Spouleur d’impression n’a pas pu démarrer en raison de l’erreur : 
%%1069
 
Error: (05/16/2016 04:18:53 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Le service Spooler n’a pas pu ouvrir de session en tant que NT AUTHORITY\SYSTEM avec le mot de passe actuellement configuré en raison de l’erreur suivante : 
%%50
 
Pour vous assurer que le service est configuré correctement, utilisez le composant logiciel enfichable Services dans Microsoft Management Console (MMC).
 
Error: (05/16/2016 04:18:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Le service Windows Search n’a pas pu démarrer en raison de l’erreur : 
%%1069
 
Error: (05/16/2016 04:18:40 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Le service WSearch n’a pas pu ouvrir de session en tant que NT AUTHORITY\SYSTEM avec le mot de passe actuellement configuré en raison de l’erreur suivante : 
%%50
 
Pour vous assurer que le service est configuré correctement, utilisez le composant logiciel enfichable Services dans Microsoft Management Console (MMC).
 
Error: (05/16/2016 04:18:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Le service Service Partage réseau du Lecteur Windows Media n’a pas pu démarrer en raison de l’erreur : 
%%1069
 
Error: (05/16/2016 04:18:40 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Le service WMPNetworkSvc n’a pas pu ouvrir de session en tant que NT AUTHORITY\NetworkService avec le mot de passe actuellement configuré en raison de l’erreur suivante : 
%%50
 
Pour vous assurer que le service est configuré correctement, utilisez le composant logiciel enfichable Services dans Microsoft Management Console (MMC).
 
Error: (05/16/2016 04:18:10 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Le service Service Partage réseau du Lecteur Windows Media s’est terminé de manière inattendue. Ceci s’est produit 1 fois. L’action corrective suivante va être effectuée dans 30000 millisecondes : Redémarrer le service.
 
 
CodeIntegrity:
===================================
  Date: 2012-09-01 11:45:40.676
  Description: Windows ne peut pas vérifier l’intégrité d’image du fichier \Device\HarddiskVolume2\Users\Laurence\Downloads\iP4000\cnmpar21.sys, car le fichier à hacher est introuvable sur le système. Une modification matérielle ou logicielle récente a peut-être installé un fichier incorrectement signé ou endommagé ou il s’agit éventuellement d’un logiciel malveillant d’une source inconnue.
 
  Date: 2012-09-01 11:45:40.645
  Description: Windows ne peut pas vérifier l’intégrité d’image du fichier \Device\HarddiskVolume2\Users\Laurence\Downloads\iP4000\cnmpar21.sys, car le fichier à hacher est introuvable sur le système. Une modification matérielle ou logicielle récente a peut-être installé un fichier incorrectement signé ou endommagé ou il s’agit éventuellement d’un logiciel malveillant d’une source inconnue.
 
 
==================== Infos Mémoire =========================== 
 
Processeur: Intel® Core™ i3-2367M CPU @ 1.40GHz
Pourcentage de mémoire utilisée: 69%
Mémoire physique - RAM - totale: 4066.36 MB
Mémoire physique - RAM - disponible: 1246.94 MB
Mémoire virtuelle totale: 8130.92 MB
Mémoire virtuelle disponible: 5059.6 MB
 
==================== Lecteurs ================================
 
Drive c: (TI30876700A) (Fixed) (Total:448.5 GB) (Free:302.13 GB) NTFS ==>[système avec composants d'amorçage (obtenu depuis lecteur)]
 
==================== MBR & Table des partitions ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 0F7FB6CC)
Partition 1: (Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Not Active) - (Size=448.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=15.8 GB) - (Type=17)
 
==================== Fin de Addition.txt ============================
 
 
Thanks a lot!!!

Attached Files


Edited by hubchau, 16 May 2016 - 08:54 AM.

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there, let me know what problems remain after this

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

CreateRestorePoint:
HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\Run: [Ukmedia] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\Laurence\AppData\Local\YTPack\IcfgUsb32.dll
Task: {2A5FA210-A9CF-4D3F-88D3-891AD191306E} - System32\Tasks\$dMM6KqyKu+JyN+{$ => C:\Users\Laurence\AppData\Roaming\playnowradio\playnowradio\1.3.4.8\playnowradio.exe
Task: {87D5C29B-65CC-4056-A1F4-60AD174937CF} - System32\Tasks\{47DBFE36-9431-4C21-95DE-41E11D1FB5EB} => pcalua.exe -a C:\Users\Laurence\AppData\Roaming\playnowradio\playnowradio\1.3.4.8\playnowradio.exe -c /uninstl
C:\Users\Laurence\AppData\Roaming\playnowradio
C:\Users\Laurence\AppData\Local\YTPack
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.

  • 0

#3
hubchau

hubchau

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Hi,

Thanks a lot for your quick answer. I'll do that remotely this evening and I'll post everything you ask.

Regards,
  • 0

#4
hubchau

hubchau

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts

Hi,

 

here are the two logs you asked.

 

Let me know if you need me to translate them :)

 

Thank you so much!

 

 

Fixlog.txt:

 

 

 

Résultats de correction de Farbar Recovery Scan Tool (x64) Version:16-05-2016
Exécuté par Laurence (2016-05-18 19:10:05) Run:1
Exécuté depuis C:\Users\Laurence\Desktop
Profils chargés: Laurence (Profils disponibles: Laurence & admin & Administrateur)
Mode d'amorçage: Normal
==============================================

fixlist contenu:
*****************
CreateRestorePoint:
HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\Run: [Ukmedia] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\Laurence\AppData\Local\YTPack\IcfgUsb32.dll
Task: {2A5FA210-A9CF-4D3F-88D3-891AD191306E} - System32\Tasks\$dMM6KqyKu+JyN+{$ => C:\Users\Laurence\AppData\Roaming\playnowradio\playnowradio\1.3.4.8\playnowradio.exe
Task: {87D5C29B-65CC-4056-A1F4-60AD174937CF} - System32\Tasks\{47DBFE36-9431-4C21-95DE-41E11D1FB5EB} => pcalua.exe -a C:\Users\Laurence\AppData\Roaming\playnowradio\playnowradio\1.3.4.8\playnowradio.exe -c /uninstl
C:\Users\Laurence\AppData\Roaming\playnowradio
C:\Users\Laurence\AppData\Local\YTPack
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:s
CMD: bitsadmin /reset /allusers
*****************

Le Point de restauration a été créé avec succès.
HKU\S-1-5-21-929901827-491967010-1845701030-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Ukmedia => valeur supprimé(es) avec succès
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2A5FA210-A9CF-4D3F-88D3-891AD191306E}" => clé supprimé(es) avec succès
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A5FA210-A9CF-4D3F-88D3-891AD191306E}" => clé supprimé(es) avec succès
C:\windows\System32\Tasks\$dMM6KqyKu+JyN+{$ => déplacé(es) avec succès
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\$dMM6KqyKu+JyN+{$" => clé supprimé(es) avec succès
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{87D5C29B-65CC-4056-A1F4-60AD174937CF}" => clé supprimé(es) avec succès
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87D5C29B-65CC-4056-A1F4-60AD174937CF}" => clé supprimé(es) avec succès
C:\windows\System32\Tasks\{47DBFE36-9431-4C21-95DE-41E11D1FB5EB} => déplacé(es) avec succès
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{47DBFE36-9431-4C21-95DE-41E11D1FB5EB}" => clé supprimé(es) avec succès
"C:\Users\Laurence\AppData\Roaming\playnowradio" => non trouvé(e).
"C:\Users\Laurence\AppData\Local\YTPack" => non trouvé(e).

========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========

L'opération a réussi.


========= Fin de Reg: =========


========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========

L'opération a réussi.


========= Fin de Reg: =========


========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => valeur supprimé(es) avec succès
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => valeur supprimé(es) avec succès
HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => valeur supprimé(es) avec succès
HKU\S-1-5-21-929901827-491967010-1845701030-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => valeur supprimé(es) avec succès
HKU\S-1-5-21-929901827-491967010-1845701030-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => valeur supprimé(es) avec succès


========= Fin de RemoveProxy: =========


=========  bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Unable to cancel {76EFECDF-091A-4B06-BED1-05F0B4D080F9}.
Unable to cancel {A332BB15-EA35-4E7C-AB6D-840DC2606C15}.
Unable to cancel {ACB8739D-9BC8-40F0-A029-695BB6DC345D}.
Unable to cancel {CC85982C-7910-4FBC-AEC7-8745FD676187}.
Unable to cancel {FFF87744-2B87-4982-A471-DD90E60AED2D}.
Unable to cancel {42FCFEE3-9513-4FA5-B49C-8FCE8160EBBA}.
Unable to cancel {64E21EF5-1ABB-4274-B4FD-7C10774A62F6}.
Unable to cancel {F55B3848-7C77-48B7-A3A1-F2771CA38C5B}.
Unable to cancel {BAFCC195-B6E0-43F0-9046-30CA8B687E42}.
Unable to cancel {127F74F6-1D6F-4BBF-933B-1B00D5599A16}.
Unable to cancel {556067A5-ED61-46E5-ACE0-141594C94806}.
Unable to cancel {2867BAB8-AF2A-4161-B7F1-158A51942860}.
Unable to cancel {97DB21FC-C4E3-4808-9109-81EE3B5324E1}.
Unable to cancel {3262641B-F58C-42A6-BCF0-375EC3BBCF90}.
Unable to cancel {2D1FB72B-97AB-4DCE-BA9D-01CC8C6981AE}.
Unable to cancel {2270F6D7-02D6-44AC-8581-4AC5617B6B32}.
Unable to cancel {81E8CB01-DF18-4C8A-8224-2D8F24D1C1B5}.
Unable to cancel {78147F7E-71CA-4E2F-BAC8-32CBF41EF857}.
Unable to cancel {6B892300-B25C-48F0-8B13-E4ECAA3D06BD}.
Unable to cancel {1609CB11-F30B-4EC6-B2C5-3C980BA7EC46}.
Unable to cancel {B061CD4A-38C9-4CED-986D-5977F2A43672}.
Unable to cancel {207B2B05-F73E-4293-B30E-222667492CEE}.
Unable to cancel {3300D57F-E2EA-4C6C-98B9-2A14A38CE53A}.
Unable to cancel {71BFFB89-4169-4C70-8292-5D159822BF6D}.
0 out of 24 jobs canceled.

========= Fin de CMD: =========

EmptyTemp: => 228.1 MB données temporaires supprimées.


Le système a dû redémarrer.

==== Fin de Fixlog 19:11:15 ====

 

AdwCleaner: As I already did a scan and clean two days ago and some way before, the logs don't have the same name.

 

After reboot, the file [C2] was displayed :

 

 

 

# AdwCleaner v5.117 - Rapport créé le 18/05/2016 à 19:23:34# Mis à jour le 15/05/2016 par Xplode
# Base de données : 2016-05-15.2 [Serveur]
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (X64)
# Nom d'utilisateur : Laurence - LAURENCE-TOSH
# Exécuté depuis : C:\Users\Laurence\Downloads\adwcleaner_5.117.exe
# Option : Nettoyer
# Support : http://toolslib.net/forum


***** [ Services ] *****




***** [ Dossiers ] *****


[-] Dossier supprimé : C:\Users\Laurence\AppData\Local\Popcorn Time
[x] Dossier Non supprimé : C:\Users\Laurence\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time


***** [ Fichiers ] *****




***** [ DLLs ] *****




***** [ WMI ] *****




***** [ Raccourcis ] *****




***** [ Tâches planifiées ] *****




***** [ Registre ] *****




***** [ Navigateurs ] *****




*************************


:: Clés "Tracing" supprimées
:: Paramètres Winsock réinitialisés


*************************


C:\AdwCleaner\AdwCleaner[C1].txt - [4964 octets] - [16/05/2016 16:18:02]
C:\AdwCleaner\AdwCleaner[C2].txt - [1070 octets] - [18/05/2016 19:23:34]
C:\AdwCleaner\AdwCleaner[R0].txt - [16419 octets] - [01/06/2014 11:42:18]
C:\AdwCleaner\AdwCleaner[R1].txt - [1068 octets] - [01/06/2014 11:46:29]
C:\AdwCleaner\AdwCleaner[S0].txt - [15367 octets] - [01/06/2014 11:43:40]
C:\AdwCleaner\AdwCleaner[S1].txt - [6118 octets] - [01/06/2014 11:48:02]
C:\AdwCleaner\AdwCleaner[S2].txt - [1401 octets] - [18/05/2016 19:18:17]


########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1516 octets] ##########

 

I also have the [S2] if needed:

 

 

 

# AdwCleaner v5.117 - Rapport créé le 18/05/2016 à 19:18:17# Mis à jour le 15/05/2016 par Xplode
# Base de données : 2016-05-15.2 [Serveur]
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (X64)
# Nom d'utilisateur : Laurence - LAURENCE-TOSH
# Exécuté depuis : C:\Users\Laurence\Downloads\adwcleaner_5.117.exe
# Option : Scanner
# Support : http://toolslib.net/forum


***** [ Services ] *****




***** [ Dossiers ] *****


Dossier trouvé : C:\Users\Laurence\AppData\Local\Popcorn Time
Dossier trouvé : C:\Users\Laurence\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time


***** [ Fichiers ] *****




***** [ DLL ] *****




***** [ WMI ] *****




***** [ Raccourcis ] *****




***** [ Tâches planifiées ] *****




***** [ Registre ] *****




***** [ Navigateurs ] *****




*************************


C:\AdwCleaner\AdwCleaner[C1].txt - [4964 octets] - [16/05/2016 16:18:02]
C:\AdwCleaner\AdwCleaner[R0].txt - [16419 octets] - [01/06/2014 11:42:18]
C:\AdwCleaner\AdwCleaner[R1].txt - [1068 octets] - [01/06/2014 11:46:29]
C:\AdwCleaner\AdwCleaner[S0].txt - [15367 octets] - [01/06/2014 11:43:40]
C:\AdwCleaner\AdwCleaner[S1].txt - [6118 octets] - [01/06/2014 11:48:02]
C:\AdwCleaner\AdwCleaner[S2].txt - [1247 octets] - [18/05/2016 19:18:17]


########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1321 octets] ##########

 


Edited by hubchau, 18 May 2016 - 11:43 AM.

  • 0

#5
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

What problems if any are you experiencing now ?


  • 0

#6
hubchau

hubchau

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Well it seems the message is now gone!

1) Thanks a lot!

2) Did you find something specific in my logs then delete it, or did you simply delete everything that looked unfamiliar?

Thanks again!
  • 0

#7
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

It was this run key

HKU\S-1-5-21-929901827-491967010-1845701030-1001\...\Run: [Ukmedia] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\Laurence\AppData\Local\YTPack\IcfgUsb32.dll

 

Which is apparently part of youtube Pakistan... And as you are in France I was a tad suspicious :)

 

Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Remove tools

Download and run Delfix
Select the options as shown
delfix.JPG

: Keep Java Updated :

WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article

I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser and How to unplug Java from the browser)

If you do need to keep Java then download JavaRa
Run the programme and select  Remove Java Runtime.  Uninstall all versions of Java present
Once done then run it again and select Update Java runtime > Download and install Latest version
javara.JPG

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent install this programme to lock down and prevent crypto ransome ware

CryptoPrevent.JPG

Malwarebytes

Update and run weekly to keep your system clean

Unchecky

Click on the link above to be taken to Unchecky.com
click the very large Download button.
click Save
Click Open folder
Right click on the Unchecky_setup and choose to Run as Administrator
Once open click the Install button.
Then click on Finish
Unchecky is now installed and will help you keep unwanted check boxes unchecked, this is a fire and forget programme  ;)

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read this little guide  Best security practices Keep safe  :wave:


  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP