Aide pour appdata local temp rarsfx0
Fermé
cheplo
Messages postés
6
Statut
Membre
-
g3n-h@ckm@n Messages postés 14350 Statut Membre -
g3n-h@ckm@n Messages postés 14350 Statut Membre -
Bonjour,
bsr jais un problem appdata local temp rarsfx0 jais fait le scan adwcleaner le rap:
# AdwCleaner v2.301 - Rapport créé le 30/05/2013 à 19:02:58
# Mis à jour le 16/05/2013 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : frikh - FRIKH-PC
# Mode de démarrage : Normal
# Exécuté depuis : C:\Users\frikh\AppData\Local\Temp\Fichiers Internet temporaires\Content.IE5\HHTXJTTT\AdwCleaner.exe
# Option [Recherche]
***** [Services] *****
Présent : BrowserProtect
Présent : DefaultTabUpdate
Présent : Mp3Tube Toolbar Service
***** [Fichiers / Dossiers] *****
***** [Registre] *****
***** [Navigateurs] *****
-\\ Internet Explorer v9.0.8112.16483
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKCU\Software\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://www.22find.com/newtab?utm_source=b&utm_medium=mlv&from=mlv&uid=ST9500325AS_5VEFS3BRXXXX5VEFS3BR&ts=1362174728
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKCU\Software\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&st=home&tid=77
[HKCU\Software\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKCU\Software\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=38268&st=home&tid=77
[HKCU\Software\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&st=home&tid=77
[HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKCU\Software\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKCU\Software\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=38268&st=home&tid=77
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&st=home&tid=77
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - CustomizeSearch] = hxxp://search.22find.com/web/?utm_source=b&utm_medium=mlv&from=mlv&uid=ST9500325AS_5VEFS3BRXXXX5VEFS3BR&ts=1362174733
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://search.22find.com/web/?utm_source=b&utm_medium=mlv&from=mlv&uid=ST9500325AS_5VEFS3BRXXXX5VEFS3BR&ts=1362174733
[HKCU\Software\Microsoft\Internet Explorer\SearchUrl - (Default)] = hxxp://search.certified-toolbar.com?si=38268&st=bs&tid=77&q=%s
[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl - (Default)] = hxxp://search.certified-toolbar.com?si=38268&st=bs&tid=77&q=%s
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://www.22find.com/newtab?utm_source=b&utm_medium=mlv&from=mlv&uid=ST9500325AS_5VEFS3BRXXXX5VEFS3BR&ts=1362174728
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.22find.com/newtab?utm_source=b&utm_medium=mlv&from=mlv&uid=ST9500325AS_5VEFS3BRXXXX5VEFS3BR&ts=1362174728
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Search Page] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&st=home&tid=77
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
-\\ Mozilla Firefox v [Impossible d'obtenir la version]
Fichier : C:\Users\frikh\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js
Présente : user_pref("browser.search.defaultenginename", "Web Search");
Présente : user_pref("browser.search.defaultengine", "Web Search");
Présente : user_pref("browser.search.selectedEngine", "Web Search");
Présente : user_pref("browser.search.order.1", "Web Search");
Présente : user_pref("browser.startup.homepage", "hxxp://search.certified-toolbar.com?si=38268&st=home&tid=77")[...]
Présente : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=");
-\\ Google Chrome v26.0.1410.64
Fichier : C:\Users\frikh\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Le fichier ne contient aucune entrée illégitime.
*************************
AdwCleaner[R1].txt - [5140 octets] - [30/05/2013 19:02:58]
########## EOF - C:\AdwCleaner[R1].txt - [5200 octets] ##########
bsr jais un problem appdata local temp rarsfx0 jais fait le scan adwcleaner le rap:
# AdwCleaner v2.301 - Rapport créé le 30/05/2013 à 19:02:58
# Mis à jour le 16/05/2013 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : frikh - FRIKH-PC
# Mode de démarrage : Normal
# Exécuté depuis : C:\Users\frikh\AppData\Local\Temp\Fichiers Internet temporaires\Content.IE5\HHTXJTTT\AdwCleaner.exe
# Option [Recherche]
***** [Services] *****
Présent : BrowserProtect
Présent : DefaultTabUpdate
Présent : Mp3Tube Toolbar Service
***** [Fichiers / Dossiers] *****
***** [Registre] *****
***** [Navigateurs] *****
-\\ Internet Explorer v9.0.8112.16483
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKCU\Software\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://www.22find.com/newtab?utm_source=b&utm_medium=mlv&from=mlv&uid=ST9500325AS_5VEFS3BRXXXX5VEFS3BR&ts=1362174728
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKCU\Software\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&st=home&tid=77
[HKCU\Software\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKCU\Software\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=38268&st=home&tid=77
[HKCU\Software\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&st=home&tid=77
[HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKCU\Software\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKCU\Software\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Page] = hxxp://search.certified-toolbar.com?si=38268&st=home&tid=77
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&st=home&tid=77
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Bar] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - Search Page] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - CustomizeSearch] = hxxp://search.22find.com/web/?utm_source=b&utm_medium=mlv&from=mlv&uid=ST9500325AS_5VEFS3BRXXXX5VEFS3BR&ts=1362174733
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://search.22find.com/web/?utm_source=b&utm_medium=mlv&from=mlv&uid=ST9500325AS_5VEFS3BRXXXX5VEFS3BR&ts=1362174733
[HKCU\Software\Microsoft\Internet Explorer\SearchUrl - (Default)] = hxxp://search.certified-toolbar.com?si=38268&st=bs&tid=77&q=%s
[HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl - (Default)] = hxxp://search.certified-toolbar.com?si=38268&st=bs&tid=77&q=%s
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://www.22find.com/newtab?utm_source=b&utm_medium=mlv&from=mlv&uid=ST9500325AS_5VEFS3BRXXXX5VEFS3BR&ts=1362174728
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.22find.com/newtab?utm_source=b&utm_medium=mlv&from=mlv&uid=ST9500325AS_5VEFS3BRXXXX5VEFS3BR&ts=1362174728
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Search Page] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Default_Page_URL] = hxxp://search.certified-toolbar.com?si=38268&st=home&tid=77
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=
-\\ Mozilla Firefox v [Impossible d'obtenir la version]
Fichier : C:\Users\frikh\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js
Présente : user_pref("browser.search.defaultenginename", "Web Search");
Présente : user_pref("browser.search.defaultengine", "Web Search");
Présente : user_pref("browser.search.selectedEngine", "Web Search");
Présente : user_pref("browser.search.order.1", "Web Search");
Présente : user_pref("browser.startup.homepage", "hxxp://search.certified-toolbar.com?si=38268&st=home&tid=77")[...]
Présente : user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=38268&tid=77&st=bs&q=");
-\\ Google Chrome v26.0.1410.64
Fichier : C:\Users\frikh\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Le fichier ne contient aucune entrée illégitime.
*************************
AdwCleaner[R1].txt - [5140 octets] - [30/05/2013 19:02:58]
########## EOF - C:\AdwCleaner[R1].txt - [5200 octets] ##########
59 réponses
essaie de preciser au maximum je comprends rien là
qui ne veut pas se relancer ? qui te donne ce message ?
qui ne veut pas se relancer ? qui te donne ce message ?
quant je clic decu pour faire le scan il le di: unable to find locale data files. please reinstall je peux pas l'installe de nouveau es je peux pas le relance pour quil scan !!!!
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question/!\ ATTENTION SUIVRE A LA LETTRE CES INDICATIONS/!\
Desactive tes protections : https://forum.pcastuces.com/default.asp
clique droit sur ce lien : Combofix =>enregistrer la cible sous....=> sur ton bureau => du nom que tu veux
Avant d'utiliser ComboFix :
Utilise Defogger pour désactiver temporairement les logiciels d'emulation :
▶ Télécharge Defogger (de jpshortstuff) sur ton Bureau
▶ Lance le : clique sur "Disable" et fais redémarrer l'ordinateur si l'outil te le demande
Note : Quand nous aurons terminé la désinfection, tu pourras réactiver ces logiciels en relançant Defogger et en cliquant sur "Re-enable"
si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."
sur combofix renommé
¤¤¤¤¤¤¤¤¤¤ LAISSE-LE INSTALLER LA CONSOLE DE RECUPERATION S'IL TE LE DEMANDE ¤¤¤¤¤¤¤¤¤¤
▶ !!!!!NE TOUCHE A RIEN PENDANT LE TRAVAIL DE COMBOFIX (SOURIS/CLAVIER.....)!!!!!
▶ n'oublie pas de reactiver la garde de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.
▶▶ Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
▶▶▶ Si, après le redémarrage de votre pc par combofix, vous avez des erreurs "Clé marquée pour suppression" ou des soucis de connexion internet, redémarrez à nouveau votre ordinateur
▶ Téléchargez UsbFix (créé par El Desaparecido) sur votre Bureau.
▶ Si votre antivirus affiche une alerte, ignorez-la et désactivez l'antivirus temporairement.
▶ Branchez toutes vos sources de données externes à votre PC (clé USB, disque dur externe, etc...) sans les ouvrir.
▶ Double cliquez sur UsbFix.exe. (pour les utilisateurs de windows Vista , windows 7 , windows 8 , clique droit => executer en tant qu'administrateur"
▶ Cliquez sur Suppression.
▶ Laissez travailler l'outil.
▶ À la fin du scan, un rapport va s'afficher, postez-le dans votre prochaine réponse sur le forum.
▶ Le rapport est aussi sauvegardé à la racine du disque système ( C:\UsbFix.txt ).
▶ Tutoriel vidéo
▶ Si votre antivirus affiche une alerte, ignorez-la et désactivez l'antivirus temporairement.
▶ Branchez toutes vos sources de données externes à votre PC (clé USB, disque dur externe, etc...) sans les ouvrir.
▶ Double cliquez sur UsbFix.exe. (pour les utilisateurs de windows Vista , windows 7 , windows 8 , clique droit => executer en tant qu'administrateur"
▶ Cliquez sur Suppression.
▶ Laissez travailler l'outil.
▶ À la fin du scan, un rapport va s'afficher, postez-le dans votre prochaine réponse sur le forum.
▶ Le rapport est aussi sauvegardé à la racine du disque système ( C:\UsbFix.txt ).
▶ Tutoriel vidéo
le scan es arrete pour les raison suivant : erreur des dossiers compressés imposible de terminer lopération
C:\BigFishGamesCache\Upgrade\stub\millennium-secrets-le-collier-de-roxanne_s5_l4_gF6717T1L4_d1598823490[1].exe
C:\BigFishGamesCache\Upgrade\stub\mystery-case-files-dire-grove-collector_s5_l4_gF5260T1L4_d1598823790[1].exe
C:\BigFishGamesCache\Upgrade\stub\mystery-case-files-dire-grove-collector_s5_l4_gF5260T1L4_d1598824234.exe
C:\BigFishGamesCache\Upgrade\stub\timeless-the-forgotten-town_s1_l1_gF6697T1L1_d1554932803.exe
C:\Boonty\Components\tools\extract.exe
C:\Boot\memtest.exe
C:\eSupport\Manual\eManual.exe
C:\FPC\2.6.0\bin\i386-win32\program1.exe
C:\Installation Borland Database Engine\unins000.exe
C:\MSOCache\All Users\{90120000-0011-0000-0000-0000000FF1CE}-C\ose.exe
C:\MSOCache\All Users\{90120000-0011-0000-0000-0000000FF1CE}-C\setup.exe
C:\MSOCache\All Users\{90120000-006E-040C-0000-0000000FF1CE}-C\DW20.EXE
C:\MSOCache\All Users\{90120000-006E-040C-0000-0000000FF1CE}-C\dwtrig20.exe
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\ose.exe
C:\MSOCache\All Users\{90140000-006E-040C-0000-0000000FF1CE}-C\DW20.EXE
C:\MSOCache\All Users\{90140000-006E-040C-0000-0000000FF1CE}-C\dwtrig20.exe
C:\Program Files\Adobe\Adobe Photoshop CS4 (64 Bit)\Required\Droplet Template.exe
C:\Program Files\ASUS\Fast Boot\FastBoot.exe
C:\Program Files\ASUS\Fast Boot\FBAgent.exe
C:\Program Files\ASUS\Fast Boot\InstallTool.exe
C:\Program Files\ATI\CIM\Bin64\ATISetup.exe
C:\Program Files\ATI\CIM\Bin64\SetACL64.exe
C:\Program Files\ATI\CIM\Bin64\Setup.exe
C:\Program Files\CCleaner\uninst.exe
C:\Program Files\Common Files\Microsoft Shared\ink\ConvertInkStore.exe
C:\Program Files\Common Files\Microsoft Shared\ink\FlickLearningWizard.exe
C:\Program Files\Common Files\Microsoft Shared\ink\InkWatson.exe
C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe
C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe
C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe
C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLED.EXE
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE
C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe
C:\Program Files\Common Files\Microsoft Shared\WF\amd64\WorkflowDebugHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
C:\Program Files\DIFX\0169CE3A95F06636\dpinst.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Elantech\ETDMag.exe
C:\Program Files\Elantech\ETDUninst.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\epupdate.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\eputy48b.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\e_gppe06.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\e_gupa20.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\e_s40mtb.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\e_s40rnb.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\e_s40rpb.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\e_s8i0ab.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\e_siacsb.exe
C:\Program Files\IDT\setup.exe
C:\Program Files\IDT\WDM\idt64mp1.exe
C:\Program Files\IDT\WDM\idtpma64.exe
C:\Program Files\IDT\WDM\stacsv64.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\IDT\WDM\suhlp64.exe
C:\Program Files\Intel\TurboBoost\RegTbDrvCat_x64.exe
C:\Program Files\Intel\TurboBoost\TurboBoost.exe
C:\Program Files\Internet Explorer\iecleanup.exe
C:\Program Files\Internet Explorer\ieinstal.exe
C:\Program Files\Internet Explorer\ielowutil.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Games\FreeCell\FreeCell.exe
C:\Program Files\Microsoft Games\Hearts\Hearts.exe
C:\Program Files\Microsoft Games\Mahjong\Mahjong.exe
C:\Program Files\Microsoft Games\Minesweeper\MineSweeper.exe
C:\Program Files\Microsoft Games\Multiplayer\Backgammon\bckgzm.exe
C:\Program Files\Microsoft Games\Multiplayer\Checkers\chkrzm.exe
C:\Program Files\Microsoft Games\Multiplayer\Spades\shvlzm.exe
C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe
C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe
C:\Program Files\Microsoft Office\Office14\MSOHTMED.EXE
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\al.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\AxImp.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\CertMgr.Exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\gacutil.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\ildasm.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\lc.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\Mdbg.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\midl.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\midlc.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\mt.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\PEVerify.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\RC.Exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\ResGen.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\sgen.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\signtool.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\sn.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\SqlMetal.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\SvcUtil.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\TlbExp.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\TlbImp.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\wsdl.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\xsd.exe
C:\Program Files\Microsoft Silverlight\5.1.20125.0\agcp.exe
C:\Program Files\Microsoft Silverlight\5.1.20125.0\coregen.exe
C:\Program Files\Microsoft Silverlight\5.1.20125.0\Silverlight.Configuration.exe
C:\Program Files\Microsoft Silverlight\sllauncher.exe
C:\Program Files\Microsoft SQL Server\100\Shared\SqlDumper.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Microsoft Visual Studio 10.0\Common7\IDE\vsdiag_regwcf.exe
C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\mpishim.exe
C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\vsdiag_regwcf.exe
C:\Program Files\Microsoft Visual Studio 9.0\Microsoft Visual Studio 2008 Remote Debugger Light (x64) - FRA\install.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files\P4G\GadgetInstaller.exe
C:\Program Files\P4G\IntlDPST.exe
C:\Program Files\P4G\SetGadgetToDesktop.exe
C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
C:\Program Files\Trend Micro\AMSP\module\10008\1.5.1381\1.3.1036\bspatch.exe
C:\Program Files\Trend Micro\AMSP\module\10008\1.5.1381\1.3.1036\bzip2.exe
C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1381\6.5.1234\TmExtIns.exe
C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1381\6.5.1234\TmExtIns32.exe
C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1381\Helper\tdiins.exe
C:\Program Files\Trend Micro\AMSP\utilRollback.exe
C:\Program Files\Trend Micro\Titanium\OEMConsole.exe
C:\Program Files\Trend Micro\Titanium\PackageRemover.exe
C:\Program Files\Trend Micro\Titanium\plugin\TiPreAU.exe
C:\Program Files\Trend Micro\Titanium\plugin\TMAS\TMAS_OE\TMAS_OEImp.exe
C:\Program Files\Trend Micro\Titanium\plugin\TMAS\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Trend Micro\Titanium\plugin\TMAS\TMAS_OL\TMAS_OL.exe
C:\Program Files\Trend Micro\Titanium\plugin\TMAS\TMAS_OL\TMAS_OLImp.exe
C:\Program Files\Trend Micro\Titanium\plugin\TMAS\TMAS_OL\TMAS_OLSentry.exe
C:\Program Files\Trend Micro\Titanium\ShorcutLauncher.exe
C:\Program Files\Trend Micro\Titanium\TiMiniService.exe
C:\Program Files\Trend Micro\Titanium\TiResumeSrv.exe
C:\Program Files\Trend Micro\Titanium\UfIfAvIm.exe
C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe
C:\Program Files\Trend Micro\Titanium\WSCHandler.exe
C:\Program Files\Trend Micro\Titanium\WSCTool.exe
C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
C:\Program Files\Trend Micro\UniClient\UiFrmwrk\WSCStatusController.exe
C:\Program Files\Windows Defender\MpCmdRun.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Windows Journal\PDIALOG.exe
C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
C:\Program Files\Windows Live\Mesh\wlcrdpsystem.exe
C:\Program Files\Windows Live\Mesh\wlcrdpuser.exe
C:\Program Files\Windows Live\Mesh\WLRemoteClient.exe
C:\Program Files\Windows Mail\wab.exe
C:\Program Files\Windows Mail\wabmig.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Windows Media Player\wmlaunch.exe
C:\Program Files\Windows Media Player\wmpconfig.exe
C:\Program Files\Windows Media Player\wmpenc.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmprph.exe
C:\Program Files\Windows Media Player\wmpshare.exe
C:\Program Files\Windows Media Player\WMPSideShowGadget.exe
C:\Program Files\Windows Photo Viewer\ImagingDevices.exe
C:\Program Files\WinPcap\rpcapd.exe
C:\Program Files\WinPcap\uninstall.exe
C:\Program Files\WinRAR\Formats\ace32loader.exe
C:\Program Files\WinRAR\Rar.exe
C:\Program Files\WinRAR\Uninstall.exe
C:\Program Files\WinRAR\UnRAR.exe
C:\Program Files (x86)\7-Zip\7z.exe
C:\Program Files (x86)\7-Zip\7zFM.exe
C:\Program Files (x86)\7-Zip\7zG.exe
C:\Program Files (x86)\7-Zip\Uninstall.exe
C:\Program Files (x86)\Adobe Download Assistant\7z.exe
C:\Program Files (x86)\Adobe Download Assistant\Adobe Download Assistant.exe
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryBurner.exe
C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe
C:\Program Files (x86)\ASUS\AI Recovery\BurnHelper.exe
C:\Program Files (x86)\ASUS\AI Recovery\InstallTool.exe
C:\Program Files (x86)\ASUS\AI Recovery\oscdimg.exe
C:\Program Files (x86)\ASUS\AI Recovery\ServiceSimple2.exe
C:\Program Files (x86)\ASUS\AI Recovery\WinpeRestore.exe
C:\Program Files (x86)\ASUS\ASUS LifeFrame3\AutoPlayer.exe
C:\Program Files (x86)\ASUS\ASUS LifeFrame3\GameTmpl.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdt.exe
C:\Program Files (x86)\ASUS\Asus MultiFrame\MultiFrame32.exe
C:\Program Files (x86)\ASUS\Asus Vibe\Asus Vibe.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\BackupSetting.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\DMICFG.EXE
C:\Program Files (x86)\ASUS\ASUS WebStorage\EeeStorageUploader.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\gacutil.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\InstallAction.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\RegisterExtension.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\RegisterExtension_x64.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\RestartExplorer.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\uninst.exe
C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeCheckUpdate.exe
C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLiveUpdate.exe
C:\Program Files (x86)\ASUS\AsusVibe\uninst.exe
C:\Program Files (x86)\ASUS\AsusVibe\UninstallV1.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\askill.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AspScal.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\Atouch64.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\CypressTPCfg64.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ElanTPCfg64.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HCLaunMail64.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HCSup.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\InstASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SynptDis.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK0100\Win7_64\PNPINST64.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\InstGFNEXSrv.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckInstallUnistall.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
C:\Program Files (x86)\ASUS\ControlDeck\P4GCommunicator.exe
C:\Program Files (x86)\ASUS\Game Park\Hotel Dash Suite Success\Launch.exe
C:\Program Files (x86)\ASUS\Game Park\Hotel Dash Suite Success\Uninstall.exe
C:\Program Files (x86)\ASUS\Game Park\World of Goo\Launch.exe
C:\Program Files (x86)\ASUS\Game Park\World of Goo\Uninstall.exe
C:\Program Files (x86)\ASUS\SmartLogon\facemgr.exe
C:\Program Files (x86)\ASUS\SmartLogon\logonmgr.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe
C:\Program Files (x86)\ASUS\Splendid\ACEngSvr.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\Splendid\ACOVS.exe
C:\Program Files (x86)\ASUS\Splendid\Backache.exe
C:\Program Files (x86)\ASUS\Splendid\Backbone.exe
C:\Program Files (x86)\ASUS\VirtualCamera\VirCam.exe
C:\Program Files (x86)\ASUS\VirtualCamera\VirCamWS.exe
C:\Program Files (x86)\ASUS\WinFlash\WinFlash.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\WimaxConsole.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\CCCInstall.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\CLI.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Implementation\LOG.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atishlx.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCCInstall.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\installShell.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\installShell64.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Graphics-Full-Existing\MMLoadDrv.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Graphics-Previews-Common\CCCDsPreview.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Graphics-Previews-Common\MMACEPrev.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Graphics-Previews-Vista\cccprev.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\MOM-InstallProxy\MOM.InstallProxy.exe
C:\Program Files (x86)\AutoCAD 2004\AcSignApply.exe
C:\Program Files (x86)\AutoCAD 2004\addplwiz.exe
C:\Program Files (x86)\AutoCAD 2004\AdRefMan.exe
C:\Program Files (x86)\AutoCAD 2004\assist.exe
C:\Program Files (x86)\AutoCAD 2004\batchplt.exe
C:\Program Files (x86)\AutoCAD 2004\BrandSn.exe
C:\Program Files (x86)\AutoCAD 2004\DwgCheckStandards.exe
C:\Program Files (x86)\AutoCAD 2004\expand.exe
C:\Program Files (x86)\AutoCAD 2004\HPSETUP.exe
C:\Program Files (x86)\AutoCAD 2004\pc3exe.exe
C:\Program Files (x86)\AutoCAD 2004\senddmp.exe
C:\Program Files (x86)\AutoCAD 2004\sfxfe32.exe
C:\Program Files (x86)\AutoCAD 2004\slidelib.exe
C:\Program Files (x86)\AutoCAD 2004\styexe.exe
C:\Program Files (x86)\AutoCAD 2004\styshwiz.exe
C:\Program Files (x86)\Autodesk\Autodesk Express Viewer\ExpressViewer.exe
C:\Program Files (x86)\Autodesk\Autodesk Express Viewer\Setup.exe
C:\Program Files (x86)\AviSynth 2.5\Uninstall.exe
C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\template.exe
C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\Program Files (x86)\Common Files\Autodesk Shared\AcHelp.exe
C:\Program Files (x86)\Common Files\Autodesk Shared\mtstack16.exe
C:\Program Files (x86)\Common Files\Autodesk Shared\WSCommCntr1.exe
C:\Program Files (x86)\Common Files\BOONTY Shared\Service\Boonty.exe
C:\Program Files (x86)\Common Files\Borland Shared\BDE\BDEADMIN.EXE
C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\BrowserHelpersInstaller.exe
C:\Program Files (x86)\Common Files\DVDVideoSoft\Dll\ffmpeg.exe
C:\Program Files (x86)\Common Files\DVDVideoSoft\Dll\lame.exe
C:\Program Files (x86)\Common Files\DVDVideoSoft\DvsService.exe
C:\Program Files (x86)\Common Files\DVDVideoSoft\DVSUpdate.exe
C:\Program Files (x86)\Common Files\DVDVideoSoft\FixComponentsSilent.exe
C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriver.exe
C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriver2.exe
C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\ISBEW64.exe
C:\Program Files (x86)\Common Files\InstallShield\Driver\7\Intel 32\IDriver.exe
C:\Program Files (x86)\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe
C:\Program Files (x86)\Common Files\InstallShield\Driver\8\Intel 32\IDriver2.exe
C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISDM.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jaucheck.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files (x86)\Common Files\Macrovision Shared\SafeCast\Install\CDAC13BA.EXE
C:\Program Files (x86)\Common Files\microsoft shared\DW\DW20.EXE
C:\Program Files (x86)\Common Files\microsoft shared\DW\DWTRIG20.EXE
C:\Program Files (x86)\Common Files\microsoft shared\EQUATION\EQNEDT32.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Help 9\dexplore.exe
C:\Program Files (x86)\Common Files\microsoft shared\ink\pipanel.exe
C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe
C:\Program Files (x86)\Common Files\microsoft shared\MODI\11.0\MSPVIEW.EXE
C:\Program Files (x86)\Common Files\microsoft shared\MSEnv\VSContentInstaller.exe
C:\Program Files (x86)\Common Files\microsoft shared\MSEnv\VSLauncher.exe
C:\Program Files (x86)\Common Files\microsoft shared\MSInfo\msinfo32.exe
C:\Program Files (x86)\Common Files\microsoft shared\MSInfo\OINFOP11.EXE
C:\Program Files (x86)\Common Files\microsoft shared\MSInfo\OINFOP12.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Office10\MSO7FTP.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Office10\MSO7FTPA.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Office10\MSO7FTPS.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Office10\MSOICONS.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE11\MSOICONS.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE11\MSOXMLED.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE11\SELFCERT.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\ACECNFLT.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSE7.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOICONS.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLED.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\ODSERV.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\Office Setup Controller\ODEPLOY.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\Office Setup Controller\SETUP.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\FLTLDR.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\LICLUA.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOICONS.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLED.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Oarpmany.exe
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Office Setup Controller\ODeploy.exe
C:\Program Files (x86)\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPREARM.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Smart Tag\SmartTagInstall.exe
C:\Program Files (x86)\Common Files\microsoft shared\Source Engine\OSE.EXE
C:\Program Files (x86)\Common Files\microsoft shared\VBA\VBA6\link.exe
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\C2RICONS.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHBS.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\MAPISERVER.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\VirtualOWSSuppHost.exe
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\VirtualOWSSuppManager.exe
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\VirtualSearchHost.exe
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\VirtualSearchProtocolHost.exe
C:\Program Files (x86)\Common Files\microsoft shared\VSTA\8.0\x86\vsta_ep32.exe
C:\Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe
C:\Program Files (x86)\Common Files\microsoft shared\Web Components\11\DFUICOM.EXE
C:\Program Files (x86)\Common Files\Oberon Media\OberonBroker\1.0.0.63\OberonBroker.exe
C:\Program Files (x86)\Common Files\System\MSMAPI\1036\CNFNOT32.EXE
C:\Program Files (x86)\Common Files\System\MSMAPI\1036\SCANOST.EXE
C:\Program Files (x86)\Common Files\System\MSMAPI\1036\SCANPST.EXE
C:\Program Files (x86)\Common Files\unins000.exe
C:\Program Files (x86)\Common Files\Windows Live\.cache\2e56cef61ccad0101\MeshBetaRemover.exe
C:\Program Files (x86)\Common Files\Windows Live\.cache\c545a62b1cd3d1701\DXSETUP.exe
C:\Program Files (x86)\Common Files\Windows Live\.cache\c6235f3a1cd3d1702\MeshBetaRemover.exe
C:\Program Files (x86)\Common Files\Windows Live\.cache\f16cc7fe1cbe1e904\DXSETUP.exe
C:\Program Files (x86)\Common Files\Windows Live\.cache\f1e3cccc1cbe1e905\DXSETUP.exe
C:\Program Files (x86)\CyberLink\LabelPrint\LabelPrint.exe
C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe
C:\Program Files (x86)\CyberLink\LabelPrint\OLRSubmission\OLRStateCheck.exe
C:\Program Files (x86)\CyberLink\LabelPrint\OLRSubmission\OLRSubmission.exe
C:\Program Files (x86)\CyberLink\Power2Go\BigBang\CLUpdater.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLDrvChk.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLInst.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLUninst.exe
C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe
C:\Program Files (x86)\CyberLink\Power2Go\OLRSubmission\OLRStateCheck.exe
C:\Program Files (x86)\CyberLink\Power2Go\OLRSubmission\OLRSubmission.exe
C:\Program Files (x86)\CyberLink\Power2Go\TaskScheduler.exe
C:\Program Files (x86)\Dofus2\app\Dofus.exe
C:\Program Files (x86)\Dofus2\app\reg\Reg.exe
C:\Program Files (x86)\Dofus2\uninstaller.exe
C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\asfbin.exe
C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\eWorker.exe
C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\rtmpdump.exe
C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\tsMuxeR.exe
C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\uninstall.exe
C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\videoplay.exe
C:\Program Files (x86)\epson\Creativity Suite\Attach To Email\AttachToEmail.exe
C:\Program Files (x86)\epson\Creativity Suite\Attach To Email\DspReadMe.exe
C:\Program Files (x86)\epson\Creativity Suite\Copy Utility\DspReadMe.exe
C:\Program Files (x86)\epson\Creativity Suite\Copy Utility\ECOPY.EXE
C:\Program Files (x86)\epson\Creativity Suite\Easy Photo Print\DspReadMe.exe
C:\Program Files (x86)\epson\Creativity Suite\Easy Photo Print\ECustomPrint.exe
C:\Program Files (x86)\epson\Creativity Suite\Easy Photo Print\EDPOFPrint.exe
C:\Program Files (x86)\epson\Creativity Suite\FaxAssistant\EFaxAssist.exe
C:\Program Files (x86)\epson\Creativity Suite\File Manager\DspReadMe.exe
C:\Program Files (x86)\epson\Creativity Suite\File Manager\EFileManager.exe
C:\Program Files (x86)\epson\Creativity Suite\File Manager\eppqcom.exe
C:\Program Files (x86)\epson\Creativity Suite\Scan Assistant\EScanAssist.exe
C:\Program Files (x86)\epson\escndv\escndv.exe
C:\Program Files (x86)\epson\escndv\setup\setup.exe
C:\Program Files (x86)\epson\TPMANUAL\CX4300_5500_DX4400\ENG\USE_G\DOCUNINS.EXE
C:\Program Files (x86)\Free Download Manager\etasks.exe
C:\Program Files (x86)\Free Download Manager\Updater.exe
C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\chrome_frame_helper.exe
C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\chrome_launcher.exe
C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\delegate_execute.exe
C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\chrome_frame_helper.exe
C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\chrome_launcher.exe
C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\delegate_execute.exe
C:\Program Files (x86)\Google\Chrome\Application\wow_helper.exe
C:\Program Files (x86)\Google\Google Earth Pro\googleearth.exe
C:\Program Files (x86)\Google\Google Earth Pro\gpsbabel.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleUpdate.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleUpdateBroker.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleUpdateOnDemand.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleUpdateSetup.exe
C:\Program Files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.145\GoogleUpdateSetup.exe
C:\Program Files (x86)\Google\Update\Download\{7420D410-6DF4-4991-B243-42A08FEBAFF0}\GoogleUpdateSetup.exe
C:\Program Files (x86)\Google\Update\Download\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\7.4.3607.2246\GoogleToolbarInstaller_updater_signed.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Installation Borland Database Engine\unins000.exe
C:\Program Files (x86)\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{40FEF622-6E0F-46B6-824B-A40C178FD4CD}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{5CA03ECF-B4A6-464B-9F5D-64D8B61B083F}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{671EC9B2-A0F0-4035-AA48-729EDC3C59EF}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{888F1505-C2B3-4FDE-835D-36353EBD4754}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{9D48531D-2135-49FC-BC29-ACCDA5396A76}\Setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{B66E665A-DF96-4C38-9422-C7F74BC1B4E5}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}\Setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{F4BF5F6B-F695-4762-AEB2-D095A4C34D89}\Setup.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\uninstall\Setup.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\uninstall\x64\Drv64.exe
C:\Program Files (x86)\Intel\Intel(R) Turbo Boost Technology Driver\uninstall\Setup.exe
C:\Program Files (x86)\Intel\Intel(R) Turbo Boost Technology Driver\uninstall\x64\Drv64.exe
C:\Program Files (x86)\Internet Download Manager\IDMGrHlp.exe
C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\Internet Download Manager\Uninstall.exe
C:\Program Files (x86)\Internet Explorer\ExtExport.exe
C:\Program Files (x86)\Internet Explorer\iecleanup.exe
C:\Program Files (x86)\Internet Explorer\iediagcmd.exe
C:\Program Files (x86)\Internet Explorer\ieinstal.exe
C:\Program Files (x86)\Internet Explorer\ielowutil.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Java\jre7\bin\java.exe
C:\Program Files (x86)\Java\jre7\bin\jp2launcher.exe
C:\Program Files (x86)\MarkAny\ContentSafer\MaAgent.exe
C:\Program Files (x86)\MarkAny\ContentSafer\MaCSMgr.exe
C:\Program Files (x86)\MarkAny\ContentSafer\MAWebControl.exe
C:\Program Files (x86)\MarkAny\ContentSafer\MPXBox.exe
C:\Program Files (x86)\MarkAny\ContentSafer\UpdateClient\MAUpdate.exe
C:\Program Files (x86)\MarkAny\ContentSafer\UpdateClient\MAUpdateBoot.exe
C:\Program Files (x86)\MarkAny\ContentSafer\UpdateClient\MaUpdateClient.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.318\mcuicnt.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
C:\Program Files (x86)\McAfee Security Scan\uninstall.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\mavinject32.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\mavinject64.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftdde.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlp.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlp64.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files (x86)\Microsoft Games for Windows - LIVE\Client\dotNetFx40_Client_setup.exe
C:\Program Files (x86)\Microsoft Games for Windows - LIVE\Client\GFWLClient.exe
C:\Program Files (x86)\Microsoft Games for Windows - LIVE\Client\GFWLive.exe
C:\Program Files (x86)\Microsoft Office\Office10\MAKECERT.EXE
C:\Program Files (x86)\Microsoft Office\Office10\SELFCERT.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\1036\MSOHELP.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\1036\UNPACK.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\DSSM.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\FINDER.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\MSOHTMED.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\MSTORDB.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\MSTORE.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\OIS.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\PROFLWIZ.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\WAVTOASF.EXE
C:\Program Files (x86)\Microsoft Office\Office12\CLVIEW.EXE
C:\Program Files (x86)\Microsoft Office\Office12\DSSM.EXE
C:\Program Files (x86)\Microsoft Office\Office12\MSOHTMED.EXE
C:\Program Files (x86)\Microsoft Office\Office12\MSQRY32.EXE
C:\Program Files (x86)\Microsoft Office\Office12\MSTORDB.EXE
C:\Program Files (x86)\Microsoft Office\Office12\MSTORE.EXE
C:\Program Files (x86)\Microsoft Office\Office12\OIS.EXE
C:\Program Files (x86)\Microsoft Office\Office12\REGFORM.EXE
C:\Program Files (x86)\Microsoft Office\Office12\SELFCERT.EXE
C:\Program Files (x86)\Microsoft Office\Office12\SETLANG.EXE
C:\Program Files (x86)\Microsoft Office\Office12\VPREVIEW.EXE
C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files (x86)\Microsoft Office\Office12\Wordconv.exe
C:\Program Files (x86)\Microsoft Office\Office14\1036\ONELEV.EXE
C:\Program Files (x86)\Microsoft Office\Office14\CLVIEW.EXE
C:\Program Files (x86)\Microsoft Office\Office14\CNFNOT32.EXE
C:\Program Files (x86)\Microsoft Office\Office14\IEContentService.exe
C:\Program Files (x86)\Microsoft Office\Office14\misc.exe
C:\Program Files (x86)\Microsoft Office\Office14\MSOHTMED.EXE
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files (x86)\Microsoft Office\Office14\MSOUC.EXE
C:\Program Files (x86)\Microsoft Office\Office14\MSQRY32.EXE
C:\Program Files (x86)\Microsoft Office\Office14\MSTORDB.EXE
C:\Program Files (x86)\Microsoft Office\Office14\MSTORE.EXE
C:\Program Files (x86)\Microsoft Office\Office14\NAMECONTROLSERVER.EXE
C:\Program Files (x86)\Microsoft Office\Office14\OIS.EXE
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Microsoft Office\Office14\SCANPST.EXE
C:\Program Files (x86)\Microsoft Office\Office14\SELFCERT.EXE
C:\Program Files (x86)\Microsoft Office\Office14\SETLANG.EXE
C:\Program Files (x86)\Microsoft Office\Office14\VPREVIEW.EXE
C:\Program Files (x86)\Microsoft Office\Office14\Wordconv.exe
C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\agcp.exe
C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\coregen.exe
C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\Silverlight.Configuration.exe
C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe
C:\Program Files (x86)\Microsoft SQL Server\100\COM\DISTRIB.exe
C:\Program Files (x86)\Microsoft SQL Server\100\COM\logread.exe
C:\Program Files (x86)\Microsoft SQL Server\100\COM\qrdrsvc.exe
C:\Program Files (x86)\Microsoft SQL Server\100\COM\replmerg.exe
C:\Program Files (x86)\Microsoft SQL Server\100\COM\snapshot.exe
C:\Program Files (x86)\Microsoft SQL Server\100\COM\tablediff.exe
C:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\DTExec.exe
C:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\dtshost.exe
C:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\DTSWizard.exe
C:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\dtutil.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Release\setup.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Release\x86\FixSqlRegistryKey_ia64.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Release\x86\FixSqlRegistryKey_x64.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Release\x86\FixSqlRegistryKey_x86.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Release\x86\LandingPage.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Release\x86\setup100.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Release\x86\SetupARP.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Shared\sqladhlp.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Shared\SqlDumper.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Shared\sqlsqm.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Shared\SqlWtsn.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\bcp.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\OSQL.EXE
C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE
C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SqlLogShip.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SQLPS.exe
C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\DatabaseMail.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\DCEXEC.EXE
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLIOSIM.EXE
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlmaint.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlstubss.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\xpadsi.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\MakeZipExe.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\mspdbsrv.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\UserControlTestContainer.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\VCExpress.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\Tools\errlook.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\Tools\makehm.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Microsoft Visual C++ 2008 Express Edition with SP1 - FRA\DeleteTemp.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Microsoft Visual C++ 2008 Express Edition with SP1 - FRA\setup.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\bscmake.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\cl.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\cvtres.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\dumpbin.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\editbin.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\lib.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\link.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\ml.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\nmake.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\undname.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\xdcmake.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\vcpackages\vcbuild.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\vcpackages\VCBuildHelper.exe
C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe
C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\fxreg.exe
C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\javacpl.exe
C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\javaws.exe
C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2launcher.exe
C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssvagent.exe
C:\Program Files (x86)\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe
C:\Program Files (x86)\PIXELA\Everio MediaBrowser\MEStarter.exe
C:\Program Files (x86)\Skype\Updater\Updater.exe
C:\Program Files (x86)\Soda PDF 5\ConversionService.exe
C:\Program Files (x86)\Soda PDF 5\PDFServerEngine.exe
C:\Program Files (x86)\Soda PDF 5\PreviewerSurrogate.exe
C:\Program Files (x86)\SuperCopier2\SC2Config.exe
C:\Program Files (x86)\SuperCopier2\SC2Uninst.exe
C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\java-rmi.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\java.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javacpl.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaws.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\jbroker.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\jp2launcher.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\jqs.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\jqsnotify.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\jucheck.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\jureg.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\jusched.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\keytool.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\kinit.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\klist.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\ktab.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\orbd.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\pack200.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\policytool.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\rmid.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\rmiregistry.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\servertool.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\ssvagent.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\tnameserv.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\unpack200.exe
C:\Program Files (x86)\syncables\syncables desktop\syncables.exe
C:\Program Files (x86)\syncables\syncables desktop\syncablesdesktop_Copy\Windows\syncablesUpdater.exe
C:\Program Files (x86)\syncables\syncables desktop\syncablesMAPI.exe
C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\SKIDROW.exe
C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\Resources\AssassinsCreedRevelations.exe
C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Program Files (x86)\Windows Live\Companion\companionuser.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe
C:\Program Files (x86)\Windows Live\Installer\defmgr.exe
C:\Program Files (x86)\Windows Live\Installer\LangSelector.exe
C:\Program Files (x86)\Windows Live\Installer\wlsettings.exe
C:\Program Files (x86)\Windows Live\Installer\wlstartup.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WindowsLivePhotoViewer.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXAlbumDownloadWizard.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXCodecHost.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGalleryRepair.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXQuickTimeControlHost.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXTranscode.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXVideoAcquireWizard.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXVideoCameraAutoPlayManager.exe
C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriter.exe
C:\Program Files (x86)\Windows Mail\wab.exe
C:\Program Files (x86)\Windows Mail\wabmig.exe
C:\Program Files (x86)\Windows Mail\WinMail.exe
C:\Program Files (x86)\Windows Media Player\wmlaunch.exe
C:\Program Files (x86)\Windows Media Player\wmpconfig.exe
C:\Program Files (x86)\Windows Media Player\WMPDMC.exe
C:\Program Files (x86)\Windows Media Player\wmpenc.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\Windows Media Player\wmprph.exe
C:\Program Files (x86)\Windows Media Player\wmpshare.exe
C:\Program Files (x86)\Windows Photo Viewer\ImagingDevices.exe
C:\Program Files (x86)\Word to Pdf Converter 3000\InstallPrinter.exe
C:\Program Files (x86)\Word to Pdf Converter 3000\unins000.exe
C:\Program Files (x86)\Xvid\AviC.exe
C:\Program Files (x86)\Xvid\CheckUpdate.exe
C:\Program Files (x86)\Xvid\MiniCalc.exe
C:\Program Files (x86)\Xvid\MiniConvert.exe
C:\Program Files (x86)\Xvid\OGMCalc.exe
C:\Program Files (x86)\Xvid\StatsReader.exe
C:\Program Files (x86)\Xvid\vidccleaner.exe
C:\Program Files (x86)\Xvid\xvid_encraw.exe
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
C:\ProgramData\Google\Google Toolbar\Update\gtb4F0C.tmp.exe
C:\ProgramData\Google\Google Toolbar\Update\gtb56BD.tmp.exe
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{1369BCF7-6667-147F-B44F-1612CE55B018}-temp50.exe
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{1D126D78-441A-FF15-F4AB-FE4282EDFD72}-temp50.exe
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{2A7310F2-2E1C-C533-7E34-1B75A423CA3F}-temp34.exe
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{77E581FE-A39A-D2DC-18B7-817A8B462AC8}-temp00.exe
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{7FE7AEEF-8450-E365-9C06-A4973CFA729D}-temp50.exe
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{B23976F2-471D-E29E-CDB0-A9F9E2AF98F7}-temp00.exe
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{E74EF458-827C-138E-CDF8-16E3BD141D7F}-temp50.exe
C:\ProgramData\OberonGameConsole\Asus\download\bricks_of_atlantis-setup.exe
C:\ProgramData\OberonGameConsole\Asus\download\diner_dash_flo_through_time-setup.exe
C:\ProgramData\OberonGameConsole\Asus\download\Family_Flights-setup.exe
C:\ProgramData\OberonGameConsole\Asus\download\Professor_Fizzwizzle-setup.exe
C:\ProgramData\OberonGameConsole\Asus\download\Turbo_Fiesta-setup.exe
C:\ProgramData\OberonGameConsole\Asus\download\Yummy_Drink_Factory-setup.exe
C:\ProgramData\SuperVigil\SyScript\SysPlug.exe
C:\Python25\UNWISE.EXE
C:\Users\All Users\EPSON\EPW!3 SSRP\E_S40RPB.EXE
C:\Users\All Users\Google\Google Toolbar\Update\gtb4F0C.tmp.exe
C:\Users\All Users\Google\Google Toolbar\Update\gtb56BD.tmp.exe
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\{1369BCF7-6667-147F-B44F-1612CE55B018}-temp50.exe
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\{1D126D78-441A-FF15-F4AB-FE4282EDFD72}-temp50.exe
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\{2A7310F2-2E1C-C533-7E34-1B75A423CA3F}-temp34.exe
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\{77E581FE-A39A-D2DC-18B7-817A8B462AC8}-temp00.exe
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\{7FE7AEEF-8450-E365-9C06-A4973CFA729D}-temp50.exe
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\{B23976F2-471D-E29E-CDB0-A9F9E2AF98F7}-temp00.exe
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\{E74EF458-827C-138E-CDF8-16E3BD141D7F}-temp50.exe
C:\Users\All Users\OberonGameConsole\Asus\download\bricks_of_atlantis-setup.exe
C:\Users\All Users\OberonGameConsole\Asus\download\diner_dash_flo_through_time-setup.exe
C:\Users\All Users\OberonGameConsole\Asus\download\Family_Flights-setup.exe
C:\Users\All Users\OberonGameConsole\Asus\download\Professor_Fizzwizzle-setup.exe
C:\Users\All Users\OberonGameConsole\Asus\download\Turbo_Fiesta-setup.exe
C:\Users\All Users\OberonGameConsole\Asus\download\Yummy_Drink_Factory-setup.exe
C:\Users\All Users\SuperVigil\SyScript\SysPlug.exe
C:\Users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
C:\Users\frikh\AppData\Local\Adobe\Updater6\Install\AdobeUpdater\AdobeUpdaterInstallMgr.exe
C:\Users\frikh\AppData\Local\Apps\2.0\A5JPD9D7.LLM\WLEVCBEW.3E0\clic...exe_4fe91ede9f9bdca3_0001.0003_none_81523b6764d98a8a\GoogleUpdateSetup.exe
C:\Users\frikh\AppData\Local\Apps\2.0\A5JPD9D7.LLM\WLEVCBEW.3E0\google.app_4fe91ede9f9bdca3_0001.0003_2d9846fbef24274a\clickonce_bootstrap.exe
C:\Users\frikh\AppData\Local\Apps\2.0\A5JPD9D7.LLM\WLEVCBEW.3E0\google.app_4fe91ede9f9bdca3_0001.0003_2d9846fbef24274a\GoogleUpdateSetup.exe
C:\Users\frikh\AppData\Local\Apps\2.0\A5JPD9D7.LLM\WLEVCBEW.3E0\unit...app_3ba2843229693745_0001.0000_88a324fdb122f223\UnityWebPlayerBootstrap.exe
C:\Users\frikh\AppData\Local\Apps\2.0\Data\1DET3916.1MM\HMOMLV0P.K6M\unit...app_3ba2843229693745_0001.0000_88a324fdb122f223\Data\UnityWebPlayer.exe
C:\Users\frikh\AppData\Local\BabylonToolbar.exe
C:\Users\frikh\AppData\Local\e-academy Inc\SecureDownloadManager\SecureDownloadManager.exe
C:\Users\frikh\AppData\Local\Facebook\Update\1.2.203.0\FacebookCrashHandler.exe
C:\Users\frikh\AppData\Local\Facebook\Update\1.2.203.0\FacebookUpdate.exe
C:\Users\frikh\AppData\Local\Facebook\Update\FacebookUpdate.exe
C:\Users\frikh\AppData\Local\Unity\WebPlayer\Uninstall.exe
C:\Users\frikh\AppData\LocalLow\Unity\WebPlayer\UnityBugReporter.exe
C:\Users\frikh\AppData\LocalLow\Unity\WebPlayer\UnityWebPlayerUpdate.exe
C:\Users\frikh\AppData\Roaming\Asus WebStorage\EeeStorageUpdate.EXE
C:\Users\frikh\AppData\Roaming\Asus WebStorage\Update\ASUSWebStorage3.0.143.296.exe
C:\Users\frikh\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
C:\Users\frikh\AppData\Roaming\Microsoft\Installer\{0848DFF5-C123-4E34-800C-FE1D3AFD4EB9}\_112D608FD02CD87FDC7735.exe
C:\Users\frikh\AppData\Roaming\Microsoft\Installer\{0848DFF5-C123-4E34-800C-FE1D3AFD4EB9}\_58CFC9BA8A872032F313E4.exe
C:\Users\frikh\AppData\Roaming\Microsoft\Installer\{0848DFF5-C123-4E34-800C-FE1D3AFD4EB9}\_853F67D554F05449430E7E.exe
C:\Users\frikh\AppData\Roaming\Microsoft\Installer\{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}\ARPPRODUCTICON.exe
C:\Users\frikh\AppData\Roaming\Microsoft\Installer\{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}\Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe
C:\Users\frikh\AppData\Roaming\Mining\rcrlab.com_yandex.ru.exe
C:\Users\frikh\AppData\Roaming\PunkBuster\pbsetup\pbsvc.exe
C:\Users\frikh\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentInstaller.exe
C:\Users\frikh\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentUpdate.exe
C:\Users\frikh\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\KiesPDLR.exe
C:\Users\frikh\AppData\Roaming\Samsung\Kies\UpdateTemp\Temp\Kies.Update.exe
C:\Users\frikh\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe
C:\Users\frikh\Desktop\java\JavaRa.exe
C:\Users\frikh\Desktop\jheb\JhebergUploader.exe
C:\Users\frikh\Desktop\JhebergUploader.exe
C:\Users\frikh\Desktop\jre-6u29-windows-i586-iftw.exe
C:\Users\frikh\Desktop\msicuu2.exe
C:\Users\frikh\Desktop\OTL.exe
C:\Users\frikh\Documents\APNSetup.exe
C:\Users\frikh\Documents\DVDVideoSoft\DVSUninstall.exe
C:\Users\frikh\Downloads\Avira_Premium_Security_Suite_10_New_2012_Keys_[Ghayyurious]_secure.exe
C:\Users\frikh\Downloads\chromeinstall-7u21 (1).exe
C:\Users\frikh\Downloads\chromeinstall-7u21 (2).exe
C:\Users\frikh\Downloads\chromeinstall-7u21 (3).exe
C:\Users\frikh\Downloads\chromeinstall-7u21 (4).exe
C:\Users\frikh\Downloads\chromeinstall-7u21 (5).exe
C:\Users\frikh\Downloads\chromeinstall-7u21 (6).exe
C:\Users\frikh\Downloads\chromeinstall-7u21.exe
C:\Users\frikh\Downloads\Far_Cry_3_SKIDROWCRACK.exe
C:\Users\frikh\Downloads\flash demo\GN1000-5500_V2.20_2012_12-3\IPBOX.exe
C:\Users\frikh\Downloads\flash demo\GN1000-5500_V2.20_2012_12-3\MultiHeader.exe
C:\Users\frikh\Downloads\flash demo\GN1000-5500_V2.20_2012_12-3\STBEditor.exe
C:\Users\frikh\Downloads\Haihaisoft_PDF_Reader.exe
C:\Users\frikh\Downloads\install_reader11_fr_mssd_aih.exe
C:\Users\frikh\Downloads\OTL.exe
C:\Users\frikh\Downloads\SkypeSetupFull [1].exe
C:\Users\frikh\Downloads\SkypeSetupFull.exe
C:\Users\frikh\Downloads\SoftonicDownloader_pour_avidemux.exe
C:\Users\frikh\Downloads\SoftonicDownloader_pour_guitar-guru.exe
C:\Users\frikh\Downloads\SoftonicDownloader_pour_handbrake.exe
C:\Users\frikh\Downloads\SoftonicDownloader_pour_javara.exe
C:\Users\frikh\Downloads\SoftonicDownloader_pour_tuxguitar.exe
C:\Users\frikh\Downloads\SoftonicDownloader_pour_windows-installer-cleanup.exe
C:\Users\frikh\Downloads\word-to-pdf-converter.exe
C:\Users\Public\Pictures\Sample Pictures\impromerie\atube catcher.exe
C:\Windows\ABLKSR\ABLKSR.exe
C:\Windows\assembly\GAC_32\ehexthost32\6.1.0.0__31bf3856ad364e35\ehexthost32.exe
C:\Windows\assembly\GAC_32\MSBuild\3.5.0.0__b03f5f7f11d50a3a\MSBuild.exe
C:\Windows\assembly\GAC_64\mcupdate\6.1.0.0__31bf3856ad364e35\mcupdate.exe
C:\Windows\assembly\GAC_64\MSBuild\3.5.0.0__b03f5f7f11d50a3a\MSBuild.exe
C:\Windows\assembly\GAC_MSIL\CCC\2.0.0.0__90ba9c70f846762e\CCC.EXE
C:\Windows\assembly\GAC_MSIL\CLI\2.0.0.0__90ba9c70f846762e\CLI.EXE
C:\Windows\assembly\GAC_MSIL\ComSvcConfig\3.0.0.0__b03f5f7f11d50a3a\ComSvcConfig.exe
C:\Windows\assembly\GAC_MSIL\dfsvc\2.0.0.0__b03f5f7f11d50a3a\dfsvc.exe
C:\Windows\assembly\GAC_MSIL\ehexthost\6.1.0.0__31bf3856ad364e35\ehexthost.exe
C:\Windows\assembly\GAC_MSIL\loadmxf\6.1.0.0__31bf3856ad364e35\loadmxf.exe
C:\Windows\assembly\GAC_MSIL\LOG\2.0.3602.28243__90ba9c70f846762e\LOG.EXE
C:\Windows\assembly\GAC_MSIL\MOM\2.0.0.0__90ba9c70f846762e\MOM.EXE
C:\Windows\assembly\GAC_MSIL\PresentationFontCache\3.0.0.0__31bf3856ad364e35\PresentationFontCache.exe
C:\Windows\assembly\GAC_MSIL\SMSvcHost\3.0.0.0__b03f5f7f11d50a3a\SMSvcHost.exe
C:\Windows\assembly\GAC_MSIL\WsatConfig\3.0.0.0__b03f5f7f11d50a3a\WsatConfig.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\58196a9215d9ed7453d4da854cd40581\ComSvcConfig.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\dfsvc\09c2fc2e6fb391b9b68b220a4ca9a83e\dfsvc.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\d712c6e3c66d6d14434fc9365c5319f0\ehExtHost32.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\MSBuild\68d7de90f7a20fdcc7bed5f513ff5a5f\MSBuild.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\4887489f50210be650432a982d01800f\PresentationFontCache.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\405750446c2533817879ccad7b30dc54\SMSvcHost.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\SQLPS\d1ee00e0f189802071ac8102552ce141\SQLPS.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\8025f27cad4633d9afefd37c11a13bf1\WindowsLiveWriter.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\4aa9a083362ad7a5bf3b126745c69a74\WsatConfig.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig\fdb14e50d68f95342dc03c610c19d809\ComSvcConfig.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\dfsvc\0c0332e0630632b7d4ebe502bb38f4a0\dfsvc.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\5734b0852b8e71796f7c248da2eff7af\ehExtHost.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\LoadMxf\e2cfbaa9293dbc1cd6f6528f85d06d59\LoadMxf.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\mcupdate\16b1d1ce01275dbddf1a964c2d542bd9\mcupdate.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\MSBuild\94db84eb2d96fbeb8d5e33bbfd414848\MSBuild.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\39d46439b9a28783911227cb0af99358\PresentationFontCache.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost\6fb4d4415f90e7895a985570ad1d7dad\SMSvcHost.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPAA06.tmp\MSBuild.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\WsatConfig\021d15f8a9ff41bdada8a84fa6c37628\WsatConfig.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_32\ComSvcConfig\21d957900261194008e7167481e0861e\ComSvcConfig.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_32\dfsvc\eb7718a354f813cbdc8c9d0381d79564\dfsvc.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Workflow.#\77050b55da5617dd7b6c2efeaf731be7\Microsoft.Workflow.Compiler.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_32\MSBuild\f62cdac275a32e6f5a0035cdb608f0e7\MSBuild.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost\7a13a0fa1c1b9efb3c3ccd64ca71c0e3\SMSvcHost.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_32\WsatConfig\45d7592752244f31fe05a8a1a7c29c25\WsatConfig.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\ComSvcConfig\34a6ccf3eb6ed7d286174e5737e867ae\ComSvcConfig.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\dfsvc\9232741c621db3f1792c12e6211207b3\dfsvc.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Workflow.#\82dfca65b326c881614f9a12a43784d5\Microsoft.Workflow.Compiler.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\MSBuild\5b59ba7d223ca5f0a8459bcd16fc4df2\MSBuild.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\MSBuild\d2a3f23074983c5941161dab34a2ffe7\MSBuild.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost\9f884d67367c5fd09bf42e70d5c2b507\SMSvcHost.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\WsatConfig\90b07af68150d31ca95c9875b9bf1851\WsatConfig.ni.exe
C:\Windows\ASUS\PRELOAD.EXE
C:\Windows\bfsvc.exe
C:\Windows\Boot\PCAT\memtest.exe
C:\Windows\Downloaded Program Files\dwusplay.exe
C:\Windows\ehome\ehexthost.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\ehome\ehprivjob.exe
C:\Windows\ehome\ehrec.exe
C:\Windows\ehome\ehrecvr.exe
C:\Windows\ehome\ehsched.exe
C:\Windows\ehome\ehshell.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehvid.exe
C:\Windows\ehome\loadmxf.exe
C:\Windows\ehome\mcGlidHost.exe
C:\Windows\ehome\McrMgr.exe
C:\Windows\ehome\mcspad.exe
C:\Windows\ehome\mcupdate.exe
C:\Windows\ehome\Mcx2Prov.exe
C:\Windows\ehome\McxTask.exe
C:\Windows\ehome\MediaCenterWebLauncher.exe
C:\Windows\ehome\RegisterMCEApp.exe
C:\Windows\ehome\wow\ehexthost32.exe
C:\Windows\ehome\WTVConverter.exe
C:\Windows\erdnt\cache64\ctfmon.exe
C:\Windows\erdnt\cache64\lsass.exe
C:\Windows\erdnt\cache64\services.exe
C:\Windows\erdnt\cache64\spoolsv.exe
C:\Windows\erdnt\cache64\svchost.exe
C:\Windows\erdnt\cache64\userinit.exe
C:\Windows\erdnt\cache64\wininit.exe
C:\Windows\erdnt\cache64\winlogon.exe
C:\Windows\erdnt\cache64\wuauclt.exe
C:\Windows\erdnt\cache86\ctfmon.exe
C:\Windows\erdnt\cache86\iexplore.exe
C:\Windows\erdnt\cache86\regedit.exe
C:\Windows\erdnt\cache86\svchost.exe
C:\Windows\erdnt\cache86\userinit.exe
C:\Windows\erdnt\cache86\wininit.exe
C:\Windows\erdnt\Hiv-backup\ERDNT.EXE
C:\Windows\erdnt\subs\ERDNT.EXE
C:\Windows\fveupdate.exe
C:\Windows\grep.exe
C:\Windows\HelpPane.exe
C:\Windows\hh.exe
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\ACECNFLT.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\CLVIEW.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\DSSM.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\DWTRIG20.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\MSE7.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\MSOHTMED.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\MSQRY32.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\MSTORDB.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\MSTORE.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\ODEPLOY.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\OIS.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\OSE.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\REGFORM.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\SELFCERT.EXE
C:\Windows\Installer\$PatchCache$\Managed\00
C:\BigFishGamesCache\Upgrade\stub\mystery-case-files-dire-grove-collector_s5_l4_gF5260T1L4_d1598823790[1].exe
C:\BigFishGamesCache\Upgrade\stub\mystery-case-files-dire-grove-collector_s5_l4_gF5260T1L4_d1598824234.exe
C:\BigFishGamesCache\Upgrade\stub\timeless-the-forgotten-town_s1_l1_gF6697T1L1_d1554932803.exe
C:\Boonty\Components\tools\extract.exe
C:\Boot\memtest.exe
C:\eSupport\Manual\eManual.exe
C:\FPC\2.6.0\bin\i386-win32\program1.exe
C:\Installation Borland Database Engine\unins000.exe
C:\MSOCache\All Users\{90120000-0011-0000-0000-0000000FF1CE}-C\ose.exe
C:\MSOCache\All Users\{90120000-0011-0000-0000-0000000FF1CE}-C\setup.exe
C:\MSOCache\All Users\{90120000-006E-040C-0000-0000000FF1CE}-C\DW20.EXE
C:\MSOCache\All Users\{90120000-006E-040C-0000-0000000FF1CE}-C\dwtrig20.exe
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\ose.exe
C:\MSOCache\All Users\{90140000-006E-040C-0000-0000000FF1CE}-C\DW20.EXE
C:\MSOCache\All Users\{90140000-006E-040C-0000-0000000FF1CE}-C\dwtrig20.exe
C:\Program Files\Adobe\Adobe Photoshop CS4 (64 Bit)\Required\Droplet Template.exe
C:\Program Files\ASUS\Fast Boot\FastBoot.exe
C:\Program Files\ASUS\Fast Boot\FBAgent.exe
C:\Program Files\ASUS\Fast Boot\InstallTool.exe
C:\Program Files\ATI\CIM\Bin64\ATISetup.exe
C:\Program Files\ATI\CIM\Bin64\SetACL64.exe
C:\Program Files\ATI\CIM\Bin64\Setup.exe
C:\Program Files\CCleaner\uninst.exe
C:\Program Files\Common Files\Microsoft Shared\ink\ConvertInkStore.exe
C:\Program Files\Common Files\Microsoft Shared\ink\FlickLearningWizard.exe
C:\Program Files\Common Files\Microsoft Shared\ink\InkWatson.exe
C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe
C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe
C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe
C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLED.EXE
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE
C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe
C:\Program Files\Common Files\Microsoft Shared\WF\amd64\WorkflowDebugHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
C:\Program Files\DIFX\0169CE3A95F06636\dpinst.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Elantech\ETDMag.exe
C:\Program Files\Elantech\ETDUninst.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\epupdate.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\eputy48b.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\e_gppe06.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\e_gupa20.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\e_s40mtb.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\e_s40rnb.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\e_s40rpb.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\e_s8i0ab.exe
C:\Program Files\EPSON\PrinterDriverTemp\SCX4300\COMMON\e_siacsb.exe
C:\Program Files\IDT\setup.exe
C:\Program Files\IDT\WDM\idt64mp1.exe
C:\Program Files\IDT\WDM\idtpma64.exe
C:\Program Files\IDT\WDM\stacsv64.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\IDT\WDM\suhlp64.exe
C:\Program Files\Intel\TurboBoost\RegTbDrvCat_x64.exe
C:\Program Files\Intel\TurboBoost\TurboBoost.exe
C:\Program Files\Internet Explorer\iecleanup.exe
C:\Program Files\Internet Explorer\ieinstal.exe
C:\Program Files\Internet Explorer\ielowutil.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Games\FreeCell\FreeCell.exe
C:\Program Files\Microsoft Games\Hearts\Hearts.exe
C:\Program Files\Microsoft Games\Mahjong\Mahjong.exe
C:\Program Files\Microsoft Games\Minesweeper\MineSweeper.exe
C:\Program Files\Microsoft Games\Multiplayer\Backgammon\bckgzm.exe
C:\Program Files\Microsoft Games\Multiplayer\Checkers\chkrzm.exe
C:\Program Files\Microsoft Games\Multiplayer\Spades\shvlzm.exe
C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe
C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe
C:\Program Files\Microsoft Office\Office14\MSOHTMED.EXE
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\al.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\AxImp.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\CertMgr.Exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\gacutil.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\ildasm.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\lc.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\Mdbg.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\midl.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\midlc.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\mt.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\PEVerify.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\RC.Exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\ResGen.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\sgen.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\signtool.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\sn.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\SqlMetal.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\SvcUtil.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\TlbExp.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\TlbImp.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\wsdl.exe
C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\xsd.exe
C:\Program Files\Microsoft Silverlight\5.1.20125.0\agcp.exe
C:\Program Files\Microsoft Silverlight\5.1.20125.0\coregen.exe
C:\Program Files\Microsoft Silverlight\5.1.20125.0\Silverlight.Configuration.exe
C:\Program Files\Microsoft Silverlight\sllauncher.exe
C:\Program Files\Microsoft SQL Server\100\Shared\SqlDumper.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Microsoft Visual Studio 10.0\Common7\IDE\vsdiag_regwcf.exe
C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\mpishim.exe
C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\vsdiag_regwcf.exe
C:\Program Files\Microsoft Visual Studio 9.0\Microsoft Visual Studio 2008 Remote Debugger Light (x64) - FRA\install.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files\P4G\GadgetInstaller.exe
C:\Program Files\P4G\IntlDPST.exe
C:\Program Files\P4G\SetGadgetToDesktop.exe
C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
C:\Program Files\Trend Micro\AMSP\module\10008\1.5.1381\1.3.1036\bspatch.exe
C:\Program Files\Trend Micro\AMSP\module\10008\1.5.1381\1.3.1036\bzip2.exe
C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1381\6.5.1234\TmExtIns.exe
C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1381\6.5.1234\TmExtIns32.exe
C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1381\Helper\tdiins.exe
C:\Program Files\Trend Micro\AMSP\utilRollback.exe
C:\Program Files\Trend Micro\Titanium\OEMConsole.exe
C:\Program Files\Trend Micro\Titanium\PackageRemover.exe
C:\Program Files\Trend Micro\Titanium\plugin\TiPreAU.exe
C:\Program Files\Trend Micro\Titanium\plugin\TMAS\TMAS_OE\TMAS_OEImp.exe
C:\Program Files\Trend Micro\Titanium\plugin\TMAS\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Trend Micro\Titanium\plugin\TMAS\TMAS_OL\TMAS_OL.exe
C:\Program Files\Trend Micro\Titanium\plugin\TMAS\TMAS_OL\TMAS_OLImp.exe
C:\Program Files\Trend Micro\Titanium\plugin\TMAS\TMAS_OL\TMAS_OLSentry.exe
C:\Program Files\Trend Micro\Titanium\ShorcutLauncher.exe
C:\Program Files\Trend Micro\Titanium\TiMiniService.exe
C:\Program Files\Trend Micro\Titanium\TiResumeSrv.exe
C:\Program Files\Trend Micro\Titanium\UfIfAvIm.exe
C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe
C:\Program Files\Trend Micro\Titanium\WSCHandler.exe
C:\Program Files\Trend Micro\Titanium\WSCTool.exe
C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
C:\Program Files\Trend Micro\UniClient\UiFrmwrk\WSCStatusController.exe
C:\Program Files\Windows Defender\MpCmdRun.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Windows Journal\PDIALOG.exe
C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
C:\Program Files\Windows Live\Mesh\wlcrdpsystem.exe
C:\Program Files\Windows Live\Mesh\wlcrdpuser.exe
C:\Program Files\Windows Live\Mesh\WLRemoteClient.exe
C:\Program Files\Windows Mail\wab.exe
C:\Program Files\Windows Mail\wabmig.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Windows Media Player\wmlaunch.exe
C:\Program Files\Windows Media Player\wmpconfig.exe
C:\Program Files\Windows Media Player\wmpenc.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmprph.exe
C:\Program Files\Windows Media Player\wmpshare.exe
C:\Program Files\Windows Media Player\WMPSideShowGadget.exe
C:\Program Files\Windows Photo Viewer\ImagingDevices.exe
C:\Program Files\WinPcap\rpcapd.exe
C:\Program Files\WinPcap\uninstall.exe
C:\Program Files\WinRAR\Formats\ace32loader.exe
C:\Program Files\WinRAR\Rar.exe
C:\Program Files\WinRAR\Uninstall.exe
C:\Program Files\WinRAR\UnRAR.exe
C:\Program Files (x86)\7-Zip\7z.exe
C:\Program Files (x86)\7-Zip\7zFM.exe
C:\Program Files (x86)\7-Zip\7zG.exe
C:\Program Files (x86)\7-Zip\Uninstall.exe
C:\Program Files (x86)\Adobe Download Assistant\7z.exe
C:\Program Files (x86)\Adobe Download Assistant\Adobe Download Assistant.exe
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryBurner.exe
C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe
C:\Program Files (x86)\ASUS\AI Recovery\BurnHelper.exe
C:\Program Files (x86)\ASUS\AI Recovery\InstallTool.exe
C:\Program Files (x86)\ASUS\AI Recovery\oscdimg.exe
C:\Program Files (x86)\ASUS\AI Recovery\ServiceSimple2.exe
C:\Program Files (x86)\ASUS\AI Recovery\WinpeRestore.exe
C:\Program Files (x86)\ASUS\ASUS LifeFrame3\AutoPlayer.exe
C:\Program Files (x86)\ASUS\ASUS LifeFrame3\GameTmpl.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdt.exe
C:\Program Files (x86)\ASUS\Asus MultiFrame\MultiFrame32.exe
C:\Program Files (x86)\ASUS\Asus Vibe\Asus Vibe.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\BackupSetting.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\DMICFG.EXE
C:\Program Files (x86)\ASUS\ASUS WebStorage\EeeStorageUploader.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\gacutil.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\InstallAction.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\RegisterExtension.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\RegisterExtension_x64.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\RestartExplorer.exe
C:\Program Files (x86)\ASUS\ASUS WebStorage\uninst.exe
C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeCheckUpdate.exe
C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLiveUpdate.exe
C:\Program Files (x86)\ASUS\AsusVibe\uninst.exe
C:\Program Files (x86)\ASUS\AsusVibe\UninstallV1.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\askill.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AspScal.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\Atouch64.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\CypressTPCfg64.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ElanTPCfg64.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HCLaunMail64.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HCSup.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\InstASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SynptDis.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK0100\Win7_64\PNPINST64.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\InstGFNEXSrv.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckInstallUnistall.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
C:\Program Files (x86)\ASUS\ControlDeck\P4GCommunicator.exe
C:\Program Files (x86)\ASUS\Game Park\Hotel Dash Suite Success\Launch.exe
C:\Program Files (x86)\ASUS\Game Park\Hotel Dash Suite Success\Uninstall.exe
C:\Program Files (x86)\ASUS\Game Park\World of Goo\Launch.exe
C:\Program Files (x86)\ASUS\Game Park\World of Goo\Uninstall.exe
C:\Program Files (x86)\ASUS\SmartLogon\facemgr.exe
C:\Program Files (x86)\ASUS\SmartLogon\logonmgr.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe
C:\Program Files (x86)\ASUS\Splendid\ACEngSvr.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\Splendid\ACOVS.exe
C:\Program Files (x86)\ASUS\Splendid\Backache.exe
C:\Program Files (x86)\ASUS\Splendid\Backbone.exe
C:\Program Files (x86)\ASUS\VirtualCamera\VirCam.exe
C:\Program Files (x86)\ASUS\VirtualCamera\VirCamWS.exe
C:\Program Files (x86)\ASUS\WinFlash\WinFlash.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\WimaxConsole.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\CCCInstall.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\CLI.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Implementation\LOG.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atishlx.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCCInstall.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\installShell.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\installShell64.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Graphics-Full-Existing\MMLoadDrv.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Graphics-Previews-Common\CCCDsPreview.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Graphics-Previews-Common\MMACEPrev.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Graphics-Previews-Vista\cccprev.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\MOM-InstallProxy\MOM.InstallProxy.exe
C:\Program Files (x86)\AutoCAD 2004\AcSignApply.exe
C:\Program Files (x86)\AutoCAD 2004\addplwiz.exe
C:\Program Files (x86)\AutoCAD 2004\AdRefMan.exe
C:\Program Files (x86)\AutoCAD 2004\assist.exe
C:\Program Files (x86)\AutoCAD 2004\batchplt.exe
C:\Program Files (x86)\AutoCAD 2004\BrandSn.exe
C:\Program Files (x86)\AutoCAD 2004\DwgCheckStandards.exe
C:\Program Files (x86)\AutoCAD 2004\expand.exe
C:\Program Files (x86)\AutoCAD 2004\HPSETUP.exe
C:\Program Files (x86)\AutoCAD 2004\pc3exe.exe
C:\Program Files (x86)\AutoCAD 2004\senddmp.exe
C:\Program Files (x86)\AutoCAD 2004\sfxfe32.exe
C:\Program Files (x86)\AutoCAD 2004\slidelib.exe
C:\Program Files (x86)\AutoCAD 2004\styexe.exe
C:\Program Files (x86)\AutoCAD 2004\styshwiz.exe
C:\Program Files (x86)\Autodesk\Autodesk Express Viewer\ExpressViewer.exe
C:\Program Files (x86)\Autodesk\Autodesk Express Viewer\Setup.exe
C:\Program Files (x86)\AviSynth 2.5\Uninstall.exe
C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\template.exe
C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\Program Files (x86)\Common Files\Autodesk Shared\AcHelp.exe
C:\Program Files (x86)\Common Files\Autodesk Shared\mtstack16.exe
C:\Program Files (x86)\Common Files\Autodesk Shared\WSCommCntr1.exe
C:\Program Files (x86)\Common Files\BOONTY Shared\Service\Boonty.exe
C:\Program Files (x86)\Common Files\Borland Shared\BDE\BDEADMIN.EXE
C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\BrowserHelpersInstaller.exe
C:\Program Files (x86)\Common Files\DVDVideoSoft\Dll\ffmpeg.exe
C:\Program Files (x86)\Common Files\DVDVideoSoft\Dll\lame.exe
C:\Program Files (x86)\Common Files\DVDVideoSoft\DvsService.exe
C:\Program Files (x86)\Common Files\DVDVideoSoft\DVSUpdate.exe
C:\Program Files (x86)\Common Files\DVDVideoSoft\FixComponentsSilent.exe
C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriver.exe
C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriver2.exe
C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\ISBEW64.exe
C:\Program Files (x86)\Common Files\InstallShield\Driver\7\Intel 32\IDriver.exe
C:\Program Files (x86)\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe
C:\Program Files (x86)\Common Files\InstallShield\Driver\8\Intel 32\IDriver2.exe
C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISDM.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jaucheck.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files (x86)\Common Files\Macrovision Shared\SafeCast\Install\CDAC13BA.EXE
C:\Program Files (x86)\Common Files\microsoft shared\DW\DW20.EXE
C:\Program Files (x86)\Common Files\microsoft shared\DW\DWTRIG20.EXE
C:\Program Files (x86)\Common Files\microsoft shared\EQUATION\EQNEDT32.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Help 9\dexplore.exe
C:\Program Files (x86)\Common Files\microsoft shared\ink\pipanel.exe
C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe
C:\Program Files (x86)\Common Files\microsoft shared\MODI\11.0\MSPVIEW.EXE
C:\Program Files (x86)\Common Files\microsoft shared\MSEnv\VSContentInstaller.exe
C:\Program Files (x86)\Common Files\microsoft shared\MSEnv\VSLauncher.exe
C:\Program Files (x86)\Common Files\microsoft shared\MSInfo\msinfo32.exe
C:\Program Files (x86)\Common Files\microsoft shared\MSInfo\OINFOP11.EXE
C:\Program Files (x86)\Common Files\microsoft shared\MSInfo\OINFOP12.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Office10\MSO7FTP.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Office10\MSO7FTPA.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Office10\MSO7FTPS.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Office10\MSOICONS.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE11\MSOICONS.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE11\MSOXMLED.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE11\SELFCERT.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\ACECNFLT.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSE7.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOICONS.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLED.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\ODSERV.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\Office Setup Controller\ODEPLOY.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\Office Setup Controller\SETUP.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\FLTLDR.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\LICLUA.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOICONS.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLED.EXE
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Oarpmany.exe
C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Office Setup Controller\ODeploy.exe
C:\Program Files (x86)\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPREARM.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Smart Tag\SmartTagInstall.exe
C:\Program Files (x86)\Common Files\microsoft shared\Source Engine\OSE.EXE
C:\Program Files (x86)\Common Files\microsoft shared\VBA\VBA6\link.exe
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\C2RICONS.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHBS.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\MAPISERVER.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\VirtualOWSSuppHost.exe
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\VirtualOWSSuppManager.exe
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\VirtualSearchHost.exe
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\VirtualSearchProtocolHost.exe
C:\Program Files (x86)\Common Files\microsoft shared\VSTA\8.0\x86\vsta_ep32.exe
C:\Program Files (x86)\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe
C:\Program Files (x86)\Common Files\microsoft shared\Web Components\11\DFUICOM.EXE
C:\Program Files (x86)\Common Files\Oberon Media\OberonBroker\1.0.0.63\OberonBroker.exe
C:\Program Files (x86)\Common Files\System\MSMAPI\1036\CNFNOT32.EXE
C:\Program Files (x86)\Common Files\System\MSMAPI\1036\SCANOST.EXE
C:\Program Files (x86)\Common Files\System\MSMAPI\1036\SCANPST.EXE
C:\Program Files (x86)\Common Files\unins000.exe
C:\Program Files (x86)\Common Files\Windows Live\.cache\2e56cef61ccad0101\MeshBetaRemover.exe
C:\Program Files (x86)\Common Files\Windows Live\.cache\c545a62b1cd3d1701\DXSETUP.exe
C:\Program Files (x86)\Common Files\Windows Live\.cache\c6235f3a1cd3d1702\MeshBetaRemover.exe
C:\Program Files (x86)\Common Files\Windows Live\.cache\f16cc7fe1cbe1e904\DXSETUP.exe
C:\Program Files (x86)\Common Files\Windows Live\.cache\f1e3cccc1cbe1e905\DXSETUP.exe
C:\Program Files (x86)\CyberLink\LabelPrint\LabelPrint.exe
C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe
C:\Program Files (x86)\CyberLink\LabelPrint\OLRSubmission\OLRStateCheck.exe
C:\Program Files (x86)\CyberLink\LabelPrint\OLRSubmission\OLRSubmission.exe
C:\Program Files (x86)\CyberLink\Power2Go\BigBang\CLUpdater.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLDrvChk.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLInst.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLUninst.exe
C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe
C:\Program Files (x86)\CyberLink\Power2Go\OLRSubmission\OLRStateCheck.exe
C:\Program Files (x86)\CyberLink\Power2Go\OLRSubmission\OLRSubmission.exe
C:\Program Files (x86)\CyberLink\Power2Go\TaskScheduler.exe
C:\Program Files (x86)\Dofus2\app\Dofus.exe
C:\Program Files (x86)\Dofus2\app\reg\Reg.exe
C:\Program Files (x86)\Dofus2\uninstaller.exe
C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\asfbin.exe
C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\eWorker.exe
C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\rtmpdump.exe
C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\tsMuxeR.exe
C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\uninstall.exe
C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\videoplay.exe
C:\Program Files (x86)\epson\Creativity Suite\Attach To Email\AttachToEmail.exe
C:\Program Files (x86)\epson\Creativity Suite\Attach To Email\DspReadMe.exe
C:\Program Files (x86)\epson\Creativity Suite\Copy Utility\DspReadMe.exe
C:\Program Files (x86)\epson\Creativity Suite\Copy Utility\ECOPY.EXE
C:\Program Files (x86)\epson\Creativity Suite\Easy Photo Print\DspReadMe.exe
C:\Program Files (x86)\epson\Creativity Suite\Easy Photo Print\ECustomPrint.exe
C:\Program Files (x86)\epson\Creativity Suite\Easy Photo Print\EDPOFPrint.exe
C:\Program Files (x86)\epson\Creativity Suite\FaxAssistant\EFaxAssist.exe
C:\Program Files (x86)\epson\Creativity Suite\File Manager\DspReadMe.exe
C:\Program Files (x86)\epson\Creativity Suite\File Manager\EFileManager.exe
C:\Program Files (x86)\epson\Creativity Suite\File Manager\eppqcom.exe
C:\Program Files (x86)\epson\Creativity Suite\Scan Assistant\EScanAssist.exe
C:\Program Files (x86)\epson\escndv\escndv.exe
C:\Program Files (x86)\epson\escndv\setup\setup.exe
C:\Program Files (x86)\epson\TPMANUAL\CX4300_5500_DX4400\ENG\USE_G\DOCUNINS.EXE
C:\Program Files (x86)\Free Download Manager\etasks.exe
C:\Program Files (x86)\Free Download Manager\Updater.exe
C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\chrome_frame_helper.exe
C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\chrome_launcher.exe
C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\delegate_execute.exe
C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\chrome_frame_helper.exe
C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\chrome_launcher.exe
C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\delegate_execute.exe
C:\Program Files (x86)\Google\Chrome\Application\wow_helper.exe
C:\Program Files (x86)\Google\Google Earth Pro\googleearth.exe
C:\Program Files (x86)\Google\Google Earth Pro\gpsbabel.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleUpdate.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleUpdateBroker.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleUpdateOnDemand.exe
C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleUpdateSetup.exe
C:\Program Files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.145\GoogleUpdateSetup.exe
C:\Program Files (x86)\Google\Update\Download\{7420D410-6DF4-4991-B243-42A08FEBAFF0}\GoogleUpdateSetup.exe
C:\Program Files (x86)\Google\Update\Download\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\7.4.3607.2246\GoogleToolbarInstaller_updater_signed.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Installation Borland Database Engine\unins000.exe
C:\Program Files (x86)\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{40FEF622-6E0F-46B6-824B-A40C178FD4CD}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{5CA03ECF-B4A6-464B-9F5D-64D8B61B083F}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{671EC9B2-A0F0-4035-AA48-729EDC3C59EF}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{888F1505-C2B3-4FDE-835D-36353EBD4754}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{9D48531D-2135-49FC-BC29-ACCDA5396A76}\Setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{B66E665A-DF96-4C38-9422-C7F74BC1B4E5}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}\Setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}\setup.exe
C:\Program Files (x86)\InstallShield Installation Information\{F4BF5F6B-F695-4762-AEB2-D095A4C34D89}\Setup.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\uninstall\Setup.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\uninstall\x64\Drv64.exe
C:\Program Files (x86)\Intel\Intel(R) Turbo Boost Technology Driver\uninstall\Setup.exe
C:\Program Files (x86)\Intel\Intel(R) Turbo Boost Technology Driver\uninstall\x64\Drv64.exe
C:\Program Files (x86)\Internet Download Manager\IDMGrHlp.exe
C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\Internet Download Manager\Uninstall.exe
C:\Program Files (x86)\Internet Explorer\ExtExport.exe
C:\Program Files (x86)\Internet Explorer\iecleanup.exe
C:\Program Files (x86)\Internet Explorer\iediagcmd.exe
C:\Program Files (x86)\Internet Explorer\ieinstal.exe
C:\Program Files (x86)\Internet Explorer\ielowutil.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Java\jre7\bin\java.exe
C:\Program Files (x86)\Java\jre7\bin\jp2launcher.exe
C:\Program Files (x86)\MarkAny\ContentSafer\MaAgent.exe
C:\Program Files (x86)\MarkAny\ContentSafer\MaCSMgr.exe
C:\Program Files (x86)\MarkAny\ContentSafer\MAWebControl.exe
C:\Program Files (x86)\MarkAny\ContentSafer\MPXBox.exe
C:\Program Files (x86)\MarkAny\ContentSafer\UpdateClient\MAUpdate.exe
C:\Program Files (x86)\MarkAny\ContentSafer\UpdateClient\MAUpdateBoot.exe
C:\Program Files (x86)\MarkAny\ContentSafer\UpdateClient\MaUpdateClient.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.318\mcuicnt.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
C:\Program Files (x86)\McAfee Security Scan\uninstall.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\mavinject32.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\mavinject64.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftdde.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlp.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlp64.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files (x86)\Microsoft Games for Windows - LIVE\Client\dotNetFx40_Client_setup.exe
C:\Program Files (x86)\Microsoft Games for Windows - LIVE\Client\GFWLClient.exe
C:\Program Files (x86)\Microsoft Games for Windows - LIVE\Client\GFWLive.exe
C:\Program Files (x86)\Microsoft Office\Office10\MAKECERT.EXE
C:\Program Files (x86)\Microsoft Office\Office10\SELFCERT.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\1036\MSOHELP.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\1036\UNPACK.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\DSSM.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\FINDER.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\MSOHTMED.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\MSTORDB.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\MSTORE.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\OIS.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\PROFLWIZ.EXE
C:\Program Files (x86)\Microsoft Office\OFFICE11\WAVTOASF.EXE
C:\Program Files (x86)\Microsoft Office\Office12\CLVIEW.EXE
C:\Program Files (x86)\Microsoft Office\Office12\DSSM.EXE
C:\Program Files (x86)\Microsoft Office\Office12\MSOHTMED.EXE
C:\Program Files (x86)\Microsoft Office\Office12\MSQRY32.EXE
C:\Program Files (x86)\Microsoft Office\Office12\MSTORDB.EXE
C:\Program Files (x86)\Microsoft Office\Office12\MSTORE.EXE
C:\Program Files (x86)\Microsoft Office\Office12\OIS.EXE
C:\Program Files (x86)\Microsoft Office\Office12\REGFORM.EXE
C:\Program Files (x86)\Microsoft Office\Office12\SELFCERT.EXE
C:\Program Files (x86)\Microsoft Office\Office12\SETLANG.EXE
C:\Program Files (x86)\Microsoft Office\Office12\VPREVIEW.EXE
C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files (x86)\Microsoft Office\Office12\Wordconv.exe
C:\Program Files (x86)\Microsoft Office\Office14\1036\ONELEV.EXE
C:\Program Files (x86)\Microsoft Office\Office14\CLVIEW.EXE
C:\Program Files (x86)\Microsoft Office\Office14\CNFNOT32.EXE
C:\Program Files (x86)\Microsoft Office\Office14\IEContentService.exe
C:\Program Files (x86)\Microsoft Office\Office14\misc.exe
C:\Program Files (x86)\Microsoft Office\Office14\MSOHTMED.EXE
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files (x86)\Microsoft Office\Office14\MSOUC.EXE
C:\Program Files (x86)\Microsoft Office\Office14\MSQRY32.EXE
C:\Program Files (x86)\Microsoft Office\Office14\MSTORDB.EXE
C:\Program Files (x86)\Microsoft Office\Office14\MSTORE.EXE
C:\Program Files (x86)\Microsoft Office\Office14\NAMECONTROLSERVER.EXE
C:\Program Files (x86)\Microsoft Office\Office14\OIS.EXE
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Microsoft Office\Office14\SCANPST.EXE
C:\Program Files (x86)\Microsoft Office\Office14\SELFCERT.EXE
C:\Program Files (x86)\Microsoft Office\Office14\SETLANG.EXE
C:\Program Files (x86)\Microsoft Office\Office14\VPREVIEW.EXE
C:\Program Files (x86)\Microsoft Office\Office14\Wordconv.exe
C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\agcp.exe
C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\coregen.exe
C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\Silverlight.Configuration.exe
C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe
C:\Program Files (x86)\Microsoft SQL Server\100\COM\DISTRIB.exe
C:\Program Files (x86)\Microsoft SQL Server\100\COM\logread.exe
C:\Program Files (x86)\Microsoft SQL Server\100\COM\qrdrsvc.exe
C:\Program Files (x86)\Microsoft SQL Server\100\COM\replmerg.exe
C:\Program Files (x86)\Microsoft SQL Server\100\COM\snapshot.exe
C:\Program Files (x86)\Microsoft SQL Server\100\COM\tablediff.exe
C:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\DTExec.exe
C:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\dtshost.exe
C:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\DTSWizard.exe
C:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\dtutil.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Release\setup.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Release\x86\FixSqlRegistryKey_ia64.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Release\x86\FixSqlRegistryKey_x64.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Release\x86\FixSqlRegistryKey_x86.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Release\x86\LandingPage.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Release\x86\setup100.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Setup Bootstrap\Release\x86\SetupARP.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Shared\sqladhlp.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Shared\SqlDumper.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Shared\sqlsqm.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Shared\SqlWtsn.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\bcp.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\OSQL.EXE
C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE
C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SqlLogShip.exe
C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\SQLPS.exe
C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\DatabaseMail.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\DCEXEC.EXE
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLIOSIM.EXE
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlmaint.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlstubss.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\xpadsi.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\MakeZipExe.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\mspdbsrv.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\UserControlTestContainer.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\VCExpress.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\Tools\errlook.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\Tools\makehm.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Microsoft Visual C++ 2008 Express Edition with SP1 - FRA\DeleteTemp.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\Microsoft Visual C++ 2008 Express Edition with SP1 - FRA\setup.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\bscmake.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\cl.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\cvtres.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\dumpbin.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\editbin.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\lib.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\link.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\ml.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\nmake.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\undname.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\bin\xdcmake.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\vcpackages\vcbuild.exe
C:\Program Files (x86)\Microsoft Visual Studio 9.0\VC\vcpackages\VCBuildHelper.exe
C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe
C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\fxreg.exe
C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\javacpl.exe
C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\javaws.exe
C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2launcher.exe
C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssvagent.exe
C:\Program Files (x86)\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe
C:\Program Files (x86)\PIXELA\Everio MediaBrowser\MEStarter.exe
C:\Program Files (x86)\Skype\Updater\Updater.exe
C:\Program Files (x86)\Soda PDF 5\ConversionService.exe
C:\Program Files (x86)\Soda PDF 5\PDFServerEngine.exe
C:\Program Files (x86)\Soda PDF 5\PreviewerSurrogate.exe
C:\Program Files (x86)\SuperCopier2\SC2Config.exe
C:\Program Files (x86)\SuperCopier2\SC2Uninst.exe
C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\java-rmi.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\java.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javacpl.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaws.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\jbroker.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\jp2launcher.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\jqs.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\jqsnotify.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\jucheck.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\jureg.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\jusched.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\keytool.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\kinit.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\klist.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\ktab.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\orbd.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\pack200.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\policytool.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\rmid.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\rmiregistry.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\servertool.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\ssvagent.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\tnameserv.exe
C:\Program Files (x86)\syncables\syncables desktop\jre\bin\unpack200.exe
C:\Program Files (x86)\syncables\syncables desktop\syncables.exe
C:\Program Files (x86)\syncables\syncables desktop\syncablesdesktop_Copy\Windows\syncablesUpdater.exe
C:\Program Files (x86)\syncables\syncables desktop\syncablesMAPI.exe
C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\SKIDROW.exe
C:\Program Files (x86)\Ubisoft\Assassin's Creed Revelations\Resources\AssassinsCreedRevelations.exe
C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Program Files (x86)\Windows Live\Companion\companionuser.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe
C:\Program Files (x86)\Windows Live\Installer\defmgr.exe
C:\Program Files (x86)\Windows Live\Installer\LangSelector.exe
C:\Program Files (x86)\Windows Live\Installer\wlsettings.exe
C:\Program Files (x86)\Windows Live\Installer\wlstartup.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WindowsLivePhotoViewer.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXAlbumDownloadWizard.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXCodecHost.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoAcquireWizard.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGalleryRepair.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXQuickTimeControlHost.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXTranscode.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXVideoAcquireWizard.exe
C:\Program Files (x86)\Windows Live\Photo Gallery\WLXVideoCameraAutoPlayManager.exe
C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriter.exe
C:\Program Files (x86)\Windows Mail\wab.exe
C:\Program Files (x86)\Windows Mail\wabmig.exe
C:\Program Files (x86)\Windows Mail\WinMail.exe
C:\Program Files (x86)\Windows Media Player\wmlaunch.exe
C:\Program Files (x86)\Windows Media Player\wmpconfig.exe
C:\Program Files (x86)\Windows Media Player\WMPDMC.exe
C:\Program Files (x86)\Windows Media Player\wmpenc.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\Windows Media Player\wmprph.exe
C:\Program Files (x86)\Windows Media Player\wmpshare.exe
C:\Program Files (x86)\Windows Photo Viewer\ImagingDevices.exe
C:\Program Files (x86)\Word to Pdf Converter 3000\InstallPrinter.exe
C:\Program Files (x86)\Word to Pdf Converter 3000\unins000.exe
C:\Program Files (x86)\Xvid\AviC.exe
C:\Program Files (x86)\Xvid\CheckUpdate.exe
C:\Program Files (x86)\Xvid\MiniCalc.exe
C:\Program Files (x86)\Xvid\MiniConvert.exe
C:\Program Files (x86)\Xvid\OGMCalc.exe
C:\Program Files (x86)\Xvid\StatsReader.exe
C:\Program Files (x86)\Xvid\vidccleaner.exe
C:\Program Files (x86)\Xvid\xvid_encraw.exe
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
C:\ProgramData\Google\Google Toolbar\Update\gtb4F0C.tmp.exe
C:\ProgramData\Google\Google Toolbar\Update\gtb56BD.tmp.exe
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{1369BCF7-6667-147F-B44F-1612CE55B018}-temp50.exe
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{1D126D78-441A-FF15-F4AB-FE4282EDFD72}-temp50.exe
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{2A7310F2-2E1C-C533-7E34-1B75A423CA3F}-temp34.exe
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{77E581FE-A39A-D2DC-18B7-817A8B462AC8}-temp00.exe
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{7FE7AEEF-8450-E365-9C06-A4973CFA729D}-temp50.exe
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{B23976F2-471D-E29E-CDB0-A9F9E2AF98F7}-temp00.exe
C:\ProgramData\Microsoft\Windows Defender\LocalCopy\{E74EF458-827C-138E-CDF8-16E3BD141D7F}-temp50.exe
C:\ProgramData\OberonGameConsole\Asus\download\bricks_of_atlantis-setup.exe
C:\ProgramData\OberonGameConsole\Asus\download\diner_dash_flo_through_time-setup.exe
C:\ProgramData\OberonGameConsole\Asus\download\Family_Flights-setup.exe
C:\ProgramData\OberonGameConsole\Asus\download\Professor_Fizzwizzle-setup.exe
C:\ProgramData\OberonGameConsole\Asus\download\Turbo_Fiesta-setup.exe
C:\ProgramData\OberonGameConsole\Asus\download\Yummy_Drink_Factory-setup.exe
C:\ProgramData\SuperVigil\SyScript\SysPlug.exe
C:\Python25\UNWISE.EXE
C:\Users\All Users\EPSON\EPW!3 SSRP\E_S40RPB.EXE
C:\Users\All Users\Google\Google Toolbar\Update\gtb4F0C.tmp.exe
C:\Users\All Users\Google\Google Toolbar\Update\gtb56BD.tmp.exe
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\{1369BCF7-6667-147F-B44F-1612CE55B018}-temp50.exe
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\{1D126D78-441A-FF15-F4AB-FE4282EDFD72}-temp50.exe
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\{2A7310F2-2E1C-C533-7E34-1B75A423CA3F}-temp34.exe
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\{77E581FE-A39A-D2DC-18B7-817A8B462AC8}-temp00.exe
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\{7FE7AEEF-8450-E365-9C06-A4973CFA729D}-temp50.exe
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\{B23976F2-471D-E29E-CDB0-A9F9E2AF98F7}-temp00.exe
C:\Users\All Users\Microsoft\Windows Defender\LocalCopy\{E74EF458-827C-138E-CDF8-16E3BD141D7F}-temp50.exe
C:\Users\All Users\OberonGameConsole\Asus\download\bricks_of_atlantis-setup.exe
C:\Users\All Users\OberonGameConsole\Asus\download\diner_dash_flo_through_time-setup.exe
C:\Users\All Users\OberonGameConsole\Asus\download\Family_Flights-setup.exe
C:\Users\All Users\OberonGameConsole\Asus\download\Professor_Fizzwizzle-setup.exe
C:\Users\All Users\OberonGameConsole\Asus\download\Turbo_Fiesta-setup.exe
C:\Users\All Users\OberonGameConsole\Asus\download\Yummy_Drink_Factory-setup.exe
C:\Users\All Users\SuperVigil\SyScript\SysPlug.exe
C:\Users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
C:\Users\frikh\AppData\Local\Adobe\Updater6\Install\AdobeUpdater\AdobeUpdaterInstallMgr.exe
C:\Users\frikh\AppData\Local\Apps\2.0\A5JPD9D7.LLM\WLEVCBEW.3E0\clic...exe_4fe91ede9f9bdca3_0001.0003_none_81523b6764d98a8a\GoogleUpdateSetup.exe
C:\Users\frikh\AppData\Local\Apps\2.0\A5JPD9D7.LLM\WLEVCBEW.3E0\google.app_4fe91ede9f9bdca3_0001.0003_2d9846fbef24274a\clickonce_bootstrap.exe
C:\Users\frikh\AppData\Local\Apps\2.0\A5JPD9D7.LLM\WLEVCBEW.3E0\google.app_4fe91ede9f9bdca3_0001.0003_2d9846fbef24274a\GoogleUpdateSetup.exe
C:\Users\frikh\AppData\Local\Apps\2.0\A5JPD9D7.LLM\WLEVCBEW.3E0\unit...app_3ba2843229693745_0001.0000_88a324fdb122f223\UnityWebPlayerBootstrap.exe
C:\Users\frikh\AppData\Local\Apps\2.0\Data\1DET3916.1MM\HMOMLV0P.K6M\unit...app_3ba2843229693745_0001.0000_88a324fdb122f223\Data\UnityWebPlayer.exe
C:\Users\frikh\AppData\Local\BabylonToolbar.exe
C:\Users\frikh\AppData\Local\e-academy Inc\SecureDownloadManager\SecureDownloadManager.exe
C:\Users\frikh\AppData\Local\Facebook\Update\1.2.203.0\FacebookCrashHandler.exe
C:\Users\frikh\AppData\Local\Facebook\Update\1.2.203.0\FacebookUpdate.exe
C:\Users\frikh\AppData\Local\Facebook\Update\FacebookUpdate.exe
C:\Users\frikh\AppData\Local\Unity\WebPlayer\Uninstall.exe
C:\Users\frikh\AppData\LocalLow\Unity\WebPlayer\UnityBugReporter.exe
C:\Users\frikh\AppData\LocalLow\Unity\WebPlayer\UnityWebPlayerUpdate.exe
C:\Users\frikh\AppData\Roaming\Asus WebStorage\EeeStorageUpdate.EXE
C:\Users\frikh\AppData\Roaming\Asus WebStorage\Update\ASUSWebStorage3.0.143.296.exe
C:\Users\frikh\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
C:\Users\frikh\AppData\Roaming\Microsoft\Installer\{0848DFF5-C123-4E34-800C-FE1D3AFD4EB9}\_112D608FD02CD87FDC7735.exe
C:\Users\frikh\AppData\Roaming\Microsoft\Installer\{0848DFF5-C123-4E34-800C-FE1D3AFD4EB9}\_58CFC9BA8A872032F313E4.exe
C:\Users\frikh\AppData\Roaming\Microsoft\Installer\{0848DFF5-C123-4E34-800C-FE1D3AFD4EB9}\_853F67D554F05449430E7E.exe
C:\Users\frikh\AppData\Roaming\Microsoft\Installer\{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}\ARPPRODUCTICON.exe
C:\Users\frikh\AppData\Roaming\Microsoft\Installer\{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}\Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe
C:\Users\frikh\AppData\Roaming\Mining\rcrlab.com_yandex.ru.exe
C:\Users\frikh\AppData\Roaming\PunkBuster\pbsetup\pbsvc.exe
C:\Users\frikh\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentInstaller.exe
C:\Users\frikh\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\AgentUpdate.exe
C:\Users\frikh\AppData\Roaming\Samsung\Kies\FirmwareUpdateTemp\AGENT\KiesPDLR.exe
C:\Users\frikh\AppData\Roaming\Samsung\Kies\UpdateTemp\Temp\Kies.Update.exe
C:\Users\frikh\AppData\Roaming\Samsung\Kies\UpdateTemp\Updater\Kies.Update.exe
C:\Users\frikh\Desktop\java\JavaRa.exe
C:\Users\frikh\Desktop\jheb\JhebergUploader.exe
C:\Users\frikh\Desktop\JhebergUploader.exe
C:\Users\frikh\Desktop\jre-6u29-windows-i586-iftw.exe
C:\Users\frikh\Desktop\msicuu2.exe
C:\Users\frikh\Desktop\OTL.exe
C:\Users\frikh\Documents\APNSetup.exe
C:\Users\frikh\Documents\DVDVideoSoft\DVSUninstall.exe
C:\Users\frikh\Downloads\Avira_Premium_Security_Suite_10_New_2012_Keys_[Ghayyurious]_secure.exe
C:\Users\frikh\Downloads\chromeinstall-7u21 (1).exe
C:\Users\frikh\Downloads\chromeinstall-7u21 (2).exe
C:\Users\frikh\Downloads\chromeinstall-7u21 (3).exe
C:\Users\frikh\Downloads\chromeinstall-7u21 (4).exe
C:\Users\frikh\Downloads\chromeinstall-7u21 (5).exe
C:\Users\frikh\Downloads\chromeinstall-7u21 (6).exe
C:\Users\frikh\Downloads\chromeinstall-7u21.exe
C:\Users\frikh\Downloads\Far_Cry_3_SKIDROWCRACK.exe
C:\Users\frikh\Downloads\flash demo\GN1000-5500_V2.20_2012_12-3\IPBOX.exe
C:\Users\frikh\Downloads\flash demo\GN1000-5500_V2.20_2012_12-3\MultiHeader.exe
C:\Users\frikh\Downloads\flash demo\GN1000-5500_V2.20_2012_12-3\STBEditor.exe
C:\Users\frikh\Downloads\Haihaisoft_PDF_Reader.exe
C:\Users\frikh\Downloads\install_reader11_fr_mssd_aih.exe
C:\Users\frikh\Downloads\OTL.exe
C:\Users\frikh\Downloads\SkypeSetupFull [1].exe
C:\Users\frikh\Downloads\SkypeSetupFull.exe
C:\Users\frikh\Downloads\SoftonicDownloader_pour_avidemux.exe
C:\Users\frikh\Downloads\SoftonicDownloader_pour_guitar-guru.exe
C:\Users\frikh\Downloads\SoftonicDownloader_pour_handbrake.exe
C:\Users\frikh\Downloads\SoftonicDownloader_pour_javara.exe
C:\Users\frikh\Downloads\SoftonicDownloader_pour_tuxguitar.exe
C:\Users\frikh\Downloads\SoftonicDownloader_pour_windows-installer-cleanup.exe
C:\Users\frikh\Downloads\word-to-pdf-converter.exe
C:\Users\Public\Pictures\Sample Pictures\impromerie\atube catcher.exe
C:\Windows\ABLKSR\ABLKSR.exe
C:\Windows\assembly\GAC_32\ehexthost32\6.1.0.0__31bf3856ad364e35\ehexthost32.exe
C:\Windows\assembly\GAC_32\MSBuild\3.5.0.0__b03f5f7f11d50a3a\MSBuild.exe
C:\Windows\assembly\GAC_64\mcupdate\6.1.0.0__31bf3856ad364e35\mcupdate.exe
C:\Windows\assembly\GAC_64\MSBuild\3.5.0.0__b03f5f7f11d50a3a\MSBuild.exe
C:\Windows\assembly\GAC_MSIL\CCC\2.0.0.0__90ba9c70f846762e\CCC.EXE
C:\Windows\assembly\GAC_MSIL\CLI\2.0.0.0__90ba9c70f846762e\CLI.EXE
C:\Windows\assembly\GAC_MSIL\ComSvcConfig\3.0.0.0__b03f5f7f11d50a3a\ComSvcConfig.exe
C:\Windows\assembly\GAC_MSIL\dfsvc\2.0.0.0__b03f5f7f11d50a3a\dfsvc.exe
C:\Windows\assembly\GAC_MSIL\ehexthost\6.1.0.0__31bf3856ad364e35\ehexthost.exe
C:\Windows\assembly\GAC_MSIL\loadmxf\6.1.0.0__31bf3856ad364e35\loadmxf.exe
C:\Windows\assembly\GAC_MSIL\LOG\2.0.3602.28243__90ba9c70f846762e\LOG.EXE
C:\Windows\assembly\GAC_MSIL\MOM\2.0.0.0__90ba9c70f846762e\MOM.EXE
C:\Windows\assembly\GAC_MSIL\PresentationFontCache\3.0.0.0__31bf3856ad364e35\PresentationFontCache.exe
C:\Windows\assembly\GAC_MSIL\SMSvcHost\3.0.0.0__b03f5f7f11d50a3a\SMSvcHost.exe
C:\Windows\assembly\GAC_MSIL\WsatConfig\3.0.0.0__b03f5f7f11d50a3a\WsatConfig.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\58196a9215d9ed7453d4da854cd40581\ComSvcConfig.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\dfsvc\09c2fc2e6fb391b9b68b220a4ca9a83e\dfsvc.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\ehExtHost32\d712c6e3c66d6d14434fc9365c5319f0\ehExtHost32.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\MSBuild\68d7de90f7a20fdcc7bed5f513ff5a5f\MSBuild.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\4887489f50210be650432a982d01800f\PresentationFontCache.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\405750446c2533817879ccad7b30dc54\SMSvcHost.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\SQLPS\d1ee00e0f189802071ac8102552ce141\SQLPS.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\8025f27cad4633d9afefd37c11a13bf1\WindowsLiveWriter.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\4aa9a083362ad7a5bf3b126745c69a74\WsatConfig.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\ComSvcConfig\fdb14e50d68f95342dc03c610c19d809\ComSvcConfig.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\dfsvc\0c0332e0630632b7d4ebe502bb38f4a0\dfsvc.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\ehExtHost\5734b0852b8e71796f7c248da2eff7af\ehExtHost.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\LoadMxf\e2cfbaa9293dbc1cd6f6528f85d06d59\LoadMxf.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\mcupdate\16b1d1ce01275dbddf1a964c2d542bd9\mcupdate.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\MSBuild\94db84eb2d96fbeb8d5e33bbfd414848\MSBuild.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\PresentationFontCac#\39d46439b9a28783911227cb0af99358\PresentationFontCache.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\SMSvcHost\6fb4d4415f90e7895a985570ad1d7dad\SMSvcHost.ni.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPAA06.tmp\MSBuild.exe
C:\Windows\assembly\NativeImages_v2.0.50727_64\WsatConfig\021d15f8a9ff41bdada8a84fa6c37628\WsatConfig.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_32\ComSvcConfig\21d957900261194008e7167481e0861e\ComSvcConfig.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_32\dfsvc\eb7718a354f813cbdc8c9d0381d79564\dfsvc.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Workflow.#\77050b55da5617dd7b6c2efeaf731be7\Microsoft.Workflow.Compiler.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_32\MSBuild\f62cdac275a32e6f5a0035cdb608f0e7\MSBuild.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_32\SMSvcHost\7a13a0fa1c1b9efb3c3ccd64ca71c0e3\SMSvcHost.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_32\WsatConfig\45d7592752244f31fe05a8a1a7c29c25\WsatConfig.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\ComSvcConfig\34a6ccf3eb6ed7d286174e5737e867ae\ComSvcConfig.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\dfsvc\9232741c621db3f1792c12e6211207b3\dfsvc.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Workflow.#\82dfca65b326c881614f9a12a43784d5\Microsoft.Workflow.Compiler.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\MSBuild\5b59ba7d223ca5f0a8459bcd16fc4df2\MSBuild.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\MSBuild\d2a3f23074983c5941161dab34a2ffe7\MSBuild.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\SMSvcHost\9f884d67367c5fd09bf42e70d5c2b507\SMSvcHost.ni.exe
C:\Windows\assembly\NativeImages_v4.0.30319_64\WsatConfig\90b07af68150d31ca95c9875b9bf1851\WsatConfig.ni.exe
C:\Windows\ASUS\PRELOAD.EXE
C:\Windows\bfsvc.exe
C:\Windows\Boot\PCAT\memtest.exe
C:\Windows\Downloaded Program Files\dwusplay.exe
C:\Windows\ehome\ehexthost.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\ehome\ehprivjob.exe
C:\Windows\ehome\ehrec.exe
C:\Windows\ehome\ehrecvr.exe
C:\Windows\ehome\ehsched.exe
C:\Windows\ehome\ehshell.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehvid.exe
C:\Windows\ehome\loadmxf.exe
C:\Windows\ehome\mcGlidHost.exe
C:\Windows\ehome\McrMgr.exe
C:\Windows\ehome\mcspad.exe
C:\Windows\ehome\mcupdate.exe
C:\Windows\ehome\Mcx2Prov.exe
C:\Windows\ehome\McxTask.exe
C:\Windows\ehome\MediaCenterWebLauncher.exe
C:\Windows\ehome\RegisterMCEApp.exe
C:\Windows\ehome\wow\ehexthost32.exe
C:\Windows\ehome\WTVConverter.exe
C:\Windows\erdnt\cache64\ctfmon.exe
C:\Windows\erdnt\cache64\lsass.exe
C:\Windows\erdnt\cache64\services.exe
C:\Windows\erdnt\cache64\spoolsv.exe
C:\Windows\erdnt\cache64\svchost.exe
C:\Windows\erdnt\cache64\userinit.exe
C:\Windows\erdnt\cache64\wininit.exe
C:\Windows\erdnt\cache64\winlogon.exe
C:\Windows\erdnt\cache64\wuauclt.exe
C:\Windows\erdnt\cache86\ctfmon.exe
C:\Windows\erdnt\cache86\iexplore.exe
C:\Windows\erdnt\cache86\regedit.exe
C:\Windows\erdnt\cache86\svchost.exe
C:\Windows\erdnt\cache86\userinit.exe
C:\Windows\erdnt\cache86\wininit.exe
C:\Windows\erdnt\Hiv-backup\ERDNT.EXE
C:\Windows\erdnt\subs\ERDNT.EXE
C:\Windows\fveupdate.exe
C:\Windows\grep.exe
C:\Windows\HelpPane.exe
C:\Windows\hh.exe
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\ACECNFLT.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\CLVIEW.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\DSSM.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\DWTRIG20.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\MSE7.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\MSOHTMED.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\MSQRY32.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\MSTORDB.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\MSTORE.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\ODEPLOY.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\OIS.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\OSE.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\REGFORM.EXE
C:\Windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.4518\SELFCERT.EXE
C:\Windows\Installer\$PatchCache$\Managed\00
############################## | UsbFix V 7.126 | [Suppression]
Utilisateur: frikh (Administrateur) # FRIKH-PC
Mis à jour le 13/05/2013 par El Desaparecido
Lancé à 22:20:17 | 30/05/2013
Site Web: https://www.sosvirus.net/
Upload Malware: http://upload.sosvirus.org/
Contact: contact@sosvirus.org
PC: ASUSTeK Computer Inc. (K72Jr) (x64-based PC)
CPU: Intel(R) Core(TM) i5 CPU M 460 @ 2.53GHz (2534)
RAM -> [Total : 3949 | Free : 876]
BIOS: BIOS Date: 10/30/09 15:13:23 Ver: 08.00.10
BOOT: Normal boot
OS: Microsoft Windows 7 Édition Familiale Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 9.0.8112.16421
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Trend Micro Titanium Internet Security [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 116 Go (42 Go libre(s) - 36%) [OS] # NTFS
D:\ -> Disque fixe # 328 Go (31 Go libre(s) - 9%) [DATA] # NTFS
E:\ -> CD-ROM
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [UpdateLBPShortCut] - "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
HKLM\SOFTWARE | Run : [UpdateP2GoShortCut] - "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
HKLM\SOFTWARE | Run : [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
HKLM\SOFTWARE | Run : [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
HKLM\SOFTWARE | Run : [SuperVigil] - "C:\ProgramData\SuperVigil\SyScript\SysPlug.exe" C:\ProgramData\SuperVigil\SuperVigil\SuperVigil.spg
HKLM\SOFTWARE | Run : [] -
HKLM\SOFTWARE | Run : [ISUSScheduler] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
HKLM\SOFTWARE | Run : [Regedit32] - C:\Windows\system32\regedit.exe
HKLM\SOFTWARE\wow6432Node | Run : [UpdateLBPShortCut] - "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
HKLM\SOFTWARE\wow6432Node | Run : [UpdateP2GoShortCut] - "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE\wow6432Node | Run : [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
HKLM\SOFTWARE\wow6432Node | Run : [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
HKLM\SOFTWARE\wow6432Node | Run : [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
HKLM\SOFTWARE\wow6432Node | Run : [SuperVigil] - "C:\ProgramData\SuperVigil\SyScript\SysPlug.exe" C:\ProgramData\SuperVigil\SuperVigil\SuperVigil.spg
HKLM\SOFTWARE\wow6432Node | Run : [] -
HKLM\SOFTWARE\wow6432Node | Run : [ISUSScheduler] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
HKLM\SOFTWARE\wow6432Node | Run : [Regedit32] - C:\Windows\system32\regedit.exe
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Facebook Update] - "C:\Users\frikh\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Free Download Manager] - "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [SuperCopier2.exe] - C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Skype] - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [ISUSPM Startup] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Xvid] - C:\Program Files (x86)\Xvid\CheckUpdate.exe
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Regedit32] - C:\Windows\system32\regedit.exe
HKU\S-1-5-18\SOFTWARE | RunOnce : [Del83836934] - cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del"
################## | Processus Stoppés |
Stoppé! C:\Windows\system32\atiesrxx.exe (856)
Stoppé! C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_38986e29a8b510a2\STacSV64.exe (416)
Stoppé! C:\Windows\system32\atieclxx.exe (1228)
Stoppé! C:\Windows\system32\FBAgent.exe (1304)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (1364)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (1408)
Stoppé! C:\Windows\System32\spoolsv.exe (1568)
Stoppé! C:\Windows\SysWOW64\drivers\CDAC11BA.EXE (1812)
Stoppé! C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (1860)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (1892)
Stoppé! C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (1980)
Stoppé! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2348)
Stoppé! C:\Program Files (x86)\Soda PDF 5\HelperService.exe (2396)
Stoppé! C:\Program Files (x86)\Soda PDF 5\ConversionService.exe (2428)
Stoppé! C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (2460)
Stoppé! C:\Program Files\Trend Micro\Titanium\TiMiniService.exe (2540)
Stoppé! C:\Program Files\Trend Micro\Titanium\TiResumeSrv.exe (2612)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2676)
Stoppé! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (2740)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (2992)
Stoppé! C:\Windows\AsScrPro.exe (3192)
Stoppé! C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (3300)
Stoppé! C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (3648)
Stoppé! C:\Windows\System32\alg.exe (3708)
Stoppé! C:\Program Files\IDT\WDM\sttray64.exe (3836)
Stoppé! C:\Program Files (x86)\Free Download Manager\fdm.exe (3224)
Stoppé! C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe (3212)
Stoppé! C:\Program Files (x86)\Skype\Phone\Skype.exe (3220)
Stoppé! C:\Program Files (x86)\Xvid\CheckUpdate.exe (1128)
Stoppé! C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (4116)
Stoppé! C:\Program Files (x86)\Xvid\autoupdate-windows.exe (4172)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (4248)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (4256)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (4264)
Stoppé! C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (4280)
Stoppé! C:\Windows\SysWOW64\regedit.exe (4288)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (3784)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (2288)
Stoppé! C:\Windows\system32\notepad.exe (4076)
Stoppé! C:\Program Files (x86)\Internet Explorer\iexplore.exe (4484)
Stoppé! C:\Program Files (x86)\Internet Explorer\iexplore.exe (4716)
Stoppé! C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE (3464)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (4244)
Stoppé! C:\Windows\splwow64.exe (2244)
Stoppé! C:\Program Files (x86)\Internet Explorer\iexplore.exe (2392)
################## | Éléments infectieux |
Supprimé! C:\Users\frikh\AppData\Roaming\Temp
(!) Fichiers temporaires supprimés.
################## | Registre |
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Regedit32
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Regedit32
################## | Mountpoints2 |
################## | Listing |
[30/05/2013 - 22:03:45 | D ] C:\$RECYCLE.BIN
[30/05/2013 - 19:03:12 | N | 5269] C:\AdwCleaner[R1].txt
[30/05/2013 - 19:11:56 | N | 6292] C:\AdwCleaner[S1].txt
[26/05/2012 - 02:04:21 | D ] C:\AeriaGames
[30/03/2012 - 12:13:10 | N | 2006] C:\aqua_bitmap.cpp
[02/07/2011 - 16:55:20 | D ] C:\ASUS.DAT
[14/03/2011 - 01:01:15 | D ] C:\AsusVibeData
[06/12/2011 - 18:38:15 | D ] C:\BigFishGamesCache
[06/12/2011 - 18:30:06 | D ] C:\Boonty
[27/11/2011 - 11:21:34 | D ] C:\Boot
[20/11/2010 - 11:40:07 | RASH | 383786] C:\bootmgr
[29/07/2009 - 05:03:37 | N | 8192] C:\BOOTSECT.BAK
[23/11/2012 - 18:23:31 | N | 94] C:\ChromeHPLog.txt
[30/05/2013 - 22:10:02 | N | 31526] C:\ComboFix.txt
[30/05/2013 - 09:54:19 | D ] C:\Config.Msi
[14/03/2011 - 01:33:23 | N | 14862] C:\devlist.txt
[13/10/2012 - 11:07:20 | D ] C:\DOA
[14/07/2009 - 04:08:56 | SHD ] C:\Documents and Settings
[27/02/2013 - 18:19:17 | D ] C:\Downloads
[14/03/2011 - 01:20:33 | D ] C:\eSupport
[01/03/2013 - 20:52:09 | D ] C:\extensions
[01/03/2013 - 20:52:09 | N | 0] C:\extensions.sqlite
[14/03/2011 - 01:33:23 | N | 9] C:\Finish.log
[18/01/2013 - 20:32:25 | D ] C:\found.002
[31/10/2012 - 10:25:51 | D ] C:\found.003
[18/01/2013 - 20:32:25 | D ] C:\found.004
[12/05/2012 - 18:08:46 | D ] C:\FPC
[14/12/2012 - 19:38:09 | D ] C:\Games
[13/10/2012 - 11:07:20 | D ] C:\Help
[30/05/2013 - 22:03:05 | ASH | 3105259520] C:\hiberfil.sys
[13/10/2012 - 11:07:20 | D ] C:\include
[13/10/2012 - 11:28:41 | D ] C:\Installation Borland Database Engine
[14/03/2011 - 01:05:33 | D ] C:\Intel
[05/01/2010 - 08:42:12 | N | 19] C:\K72JR_WIN7.20
[13/10/2012 - 11:07:20 | D ] C:\lib
[24/07/2012 - 02:04:24 | D ] C:\Microgaming
[04/07/2011 - 22:35:29 | RD ] C:\MSOCache
[12/01/2013 - 02:18:50 | D ] C:\nfs
[17/04/2013 - 08:15:28 | D ] C:\Output Files
[13/10/2012 - 10:45:38 | N | 4] C:\OVBCMSOC.ITM
[30/05/2013 - 22:03:07 | ASH | 4140347392] C:\pagefile.sys
[13/03/2011 - 12:47:29 | N | 233] C:\Pass.txt
[14/07/2009 - 02:20:08 | D ] C:\PerfLogs
[30/05/2013 - 21:17:39 | D ] C:\Pre_Scan
[30/05/2013 - 19:11:40 | D ] C:\Program Files
[30/05/2013 - 22:01:07 | D ] C:\Program Files (x86)
[30/05/2013 - 22:01:01 | D ] C:\ProgramData
[23/11/2012 - 17:35:37 | D ] C:\Python25
[30/05/2013 - 22:10:04 | D ] C:\Qoobox
[02/07/2011 - 16:51:34 | D ] C:\Recovery
[05/01/2010 - 08:42:12 | N | 7] C:\RECOVERY.DAT
[11/02/2013 - 19:02:02 | N | 202] C:\SetSearchAndHomepageInBrowserLog.txt
[14/03/2011 - 01:23:20 | N | 193] C:\setup.log
[13/05/2006 - 15:22:24 | N | 5] C:\store.log
[30/05/2013 - 21:56:50 | SHD ] C:\System Volume Information
[10/04/2013 - 23:30:06 | D ] C:\Temp
[14/10/2012 - 09:08:03 | N | 0] C:\testDefBrow.html
[30/05/2013 - 22:22:15 | D ] C:\UsbFix
[30/05/2013 - 22:22:24 | A | 11404] C:\UsbFix [Clean 2] FRIKH-PC.txt
[28/06/2012 - 10:09:32 | D ] C:\Users
[30/05/2013 - 22:10:04 | D ] C:\Windows
[28/06/2012 - 10:10:09 | DC ] D:\$RECYCLE.BIN
[26/12/2012 - 16:33:18 | DC ] D:\0e176c0dade1fbf01d6291deeb6fae
[13/05/2013 - 04:46:54 | DC ] D:\0efbbff2d14dfa2d6f48715f5c9efd
[23/11/2012 - 04:43:50 | DC ] D:\227e13e4d6fd8b343229b7
[06/11/2012 - 19:47:05 | DC ] D:\29f3eec80f44bd0dbe3c
[20/12/2012 - 10:15:57 | DC ] D:\3cfa5db312262695aa18c7f0d4
[22/12/2012 - 18:19:58 | DC ] D:\444fcfe1f922fbd3f2fcf0122a
[01/05/2013 - 23:47:59 | DC ] D:\508c12a60818f7b1d9
[05/12/2011 - 21:17:59 | DC ] D:\64f0f7dbb3f4cb5aba302f5648
[30/10/2012 - 12:05:21 | DC ] D:\71c53df984ed5bda4fd5
[25/04/2013 - 11:50:17 | DC ] D:\9c12c024c1049bea13e48baf54
[28/01/2013 - 14:33:01 | DC ] D:\9dccac17e8661de0d60b0e0f9b71
[16/08/2003 - 00:40:00 | C | 3612862] D:\A2561404.CAB
[16/08/2003 - 00:40:52 | C | 6658289] D:\A3561404.CAB
[16/08/2003 - 00:41:30 | C | 3134238] D:\A4561404.CAB
[29/09/2011 - 05:39:31 | DC ] D:\a90207c72b06473183b6
[15/04/2003 - 22:57:44 | C | 276] D:\acad1.reg
[15/04/2003 - 23:56:18 | C | 276] D:\acad2.reg
[19/03/2003 - 15:59:18 | C | 310] D:\acadcd.mid
[07/11/2012 - 19:56:08 | DC ] D:\af035c009f6055c4c8b5be3f2881d953
[16/08/2003 - 00:41:50 | C | 2407957] D:\AV561404.CAB
[24/02/2013 - 16:48:24 | DC ] D:\b99fd03af446dc2db85b
[25/04/2013 - 22:54:26 | DC ] D:\Bin
[21/03/2013 - 00:47:15 | DC ] D:\bureau
[21/12/2012 - 08:39:45 | DC ] D:\c5a40c867c1253de8e3cda6c8718
[02/11/2012 - 00:05:36 | DC ] D:\c99af7fc688746c1fea1
[15/08/2003 - 09:05:52 | C | 1681457] D:\CC561401.CAB
[15/08/2003 - 09:05:56 | C | 323898] D:\CD561401.CAB
[15/08/2003 - 09:06:12 | C | 2071027] D:\CF561401.CAB
[15/08/2003 - 09:06:20 | C | 706243] D:\CL561401.CAB
[15/08/2003 - 09:06:32 | C | 1232028] D:\CM561401.CAB
[05/11/2012 - 19:21:31 | DC ] D:\Config.Msi
[15/08/2003 - 09:06:44 | C | 2487448] D:\CP561401.CAB
[15/08/2003 - 09:06:54 | C | 2306744] D:\CR561401.CAB
[01/03/2013 - 22:06:11 | DC ] D:\crack
[15/08/2003 - 09:07:00 | C | 611657] D:\CS561401.CAB
[16/08/2003 - 00:42:58 | C | 5503414] D:\E2561404.CAB
[16/08/2003 - 00:43:36 | C | 3728516] D:\E3561404.CAB
[16/08/2003 - 00:43:48 | C | 614809] D:\E4561404.CAB
[16/08/2003 - 00:44:10 | C | 2517595] D:\EV561404.CAB
[15/10/2011 - 02:50:02 | DC ] D:\f6c83ad819af1d7bde1412e468c7de
[13/04/2013 - 12:23:55 | DC ] D:\FFOutput
[25/04/2013 - 23:09:49 | DC ] D:\FILES
[26/05/2013 - 21:51:09 | DC ] D:\film
[16/08/2003 - 00:44:26 | C | 1840628] D:\G3561404.CAB
[23/08/2012 - 13:07:22 | DC ] D:\GTA
[16/08/2003 - 00:42:38 | C | 502881] D:\GV561402.CAB
[15/08/2003 - 09:03:32 | C | 107046] D:\IJ561401.CAB
[15/08/2003 - 09:03:34 | C | 38260] D:\IS561401.CAB
[15/08/2003 - 09:05:16 | C | 13650283] D:\IU561401.CAB
[16/08/2003 - 00:46:28 | C | 10646583] D:\L2561404.CAB
[16/08/2003 - 00:47:00 | C | 2224184] D:\L3561405.CAB
[16/08/2003 - 00:47:20 | C | 1058289] D:\L4561405.CAB
[16/08/2003 - 00:44:08 | C | 300748] D:\L9561402.CAB
[08/06/2003 - 21:20:26 | C | 48747] D:\license.exe
[30/05/2013 - 20:33:35 | DC ] D:\limac
[16/08/2003 - 00:47:38 | C | 1115417] D:\LV561405.CAB
[16/08/2003 - 00:29:06 | C | 51050] D:\M2561403.CAB
[16/08/2003 - 00:29:34 | C | 5209361] D:\M3561403.CAB
[16/08/2003 - 00:30:34 | C | 12878142] D:\M4561403.CAB
[15/08/2003 - 09:09:52 | C | 2301053] D:\M9561401.CAB
[16/08/2003 - 00:46:36 | C | 630316] D:\MA561405.CAB
[13/04/2013 - 23:09:37 | DC ] D:\Mariage
[16/08/2003 - 00:45:16 | C | 2336284] D:\MC561403.CAB
[16/08/2003 - 00:30:10 | C | 917002] D:\MG561403.CAB
[15/08/2003 - 09:11:30 | C | 2374394] D:\MH561401.CAB
[16/08/2003 - 00:49:26 | C | 887039] D:\MO561404.CAB
[25/04/2013 - 23:10:21 | DC ] D:\MSDE2000
[28/11/2012 - 21:08:57 | DC ] D:\msdownld.tmp
[25/04/2013 - 11:50:33 | DC ] D:\MSI8da4b.tmp
[15/10/2011 - 19:51:53 | RDC ] D:\MSOCache
[16/08/2003 - 00:45:58 | C | 2532195] D:\MT561403.CAB
[15/08/2003 - 09:06:14 | C | 30137] D:\O0561401.CAB
[18/08/2003 - 14:46:28 | C | 12582960] D:\O1561407.CAB
[16/08/2003 - 00:46:44 | C | 195326] D:\O9561402.CAB
[18/08/2003 - 14:44:46 | C | 562688] D:\OWC10.MSI
[18/08/2003 - 14:45:04 | C | 607232] D:\OWC11.MSI
[16/08/2003 - 00:54:24 | C | 29758389] D:\P2561404.CAB
[16/08/2003 - 00:55:44 | C | 5405691] D:\P3561405.CAB
[16/08/2003 - 00:55:58 | C | 456919] D:\P4561405.CAB
[15/08/2003 - 08:53:16 | C | 1740699] D:\PA561401.CAB
[02/06/2012 - 17:50:27 | DC ] D:\PFiles
[15/08/2003 - 10:22:34 | C | 754496] D:\PR102593.CAB
[15/08/2003 - 12:42:44 | C | 12137368] D:\PR103196.CAB
[15/08/2003 - 09:11:26 | C | 5755051] D:\PR103369.CAB
[16/08/2003 - 00:34:32 | C | 8381104] D:\PR103601.CAB
[16/08/2003 - 00:32:44 | C | 3519473] D:\PR104301.CAB
[15/08/2003 - 09:11:50 | C | 7645762] D:\PR308246.CAB
[18/08/2003 - 15:05:30 | C | 5842944] D:\PRO11.MSI
[16/08/2003 - 00:56:50 | C | 1436775] D:\PV561405.CAB
[16/08/2003 - 00:57:34 | C | 2174890] D:\PW561405.CAB
[16/08/2003 - 00:58:00 | C | 3060871] D:\Q2561405.CAB
[16/08/2003 - 00:58:32 | C | 2556851] D:\Q3561405.CAB
[16/08/2003 - 00:58:42 | C | 562402] D:\Q4561405.CAB
[16/08/2003 - 00:58:58 | C | 1424358] D:\QV561405.CAB
[31/07/2003 - 09:49:12 | C | 7160] D:\README.HTM
[02/02/2012 - 16:06:37 | DC ] D:\recycl.bin
[17/04/2013 - 08:03:20 | DC ] D:\salim sport
[17/05/2013 - 10:36:20 | DC ] D:\salim travail
[11/07/2003 - 14:06:08 | C | 22397] D:\SETUP.HTM
[11/03/2003 - 10:36:12 | C | 519] D:\setup.ini
[16/08/2003 - 00:59:38 | C | 6922159] D:\SKU011.CAB
[18/08/2003 - 15:00:20 | C | 399529] D:\SKU011.XML
[16/08/2003 - 00:28:08 | C | 163932] D:\SKU026.CAB
[18/08/2003 - 14:44:30 | C | 3534146] D:\SKU0A4.CAB
[15/07/2012 - 13:47:11 | SHDC ] D:\System Volume Information
[16/08/2003 - 00:35:00 | C | 323620] D:\TA561401.CAB
[15/08/2003 - 13:04:08 | C | 1986770] D:\TR102537.CAB
[15/08/2003 - 13:07:52 | C | 2372548] D:\TR103113.CAB
[15/08/2003 - 09:14:40 | C | 2056750] D:\TR308222.CAB
[16/08/2003 - 00:48:34 | C | 2060804] D:\V3561402.CAB
[16/08/2003 - 01:00:42 | C | 6339729] D:\W2561405.CAB
[16/08/2003 - 01:01:14 | C | 3027025] D:\W3561405.CAB
[16/08/2003 - 01:01:30 | C | 791064] D:\W4561405.CAB
[16/08/2003 - 01:01:56 | C | 3228915] D:\WV561405.CAB
[16/08/2003 - 01:02:58 | C | 9621215] D:\X2561405.CAB
[16/08/2003 - 01:03:06 | C | 1164555] D:\X3561405.CAB
[16/08/2003 - 00:28:56 | C | 8436971] D:\YA561403.CAB
[16/08/2003 - 00:29:40 | C | 8530949] D:\YB561403.CAB
[16/08/2003 - 00:35:56 | C | 635769] D:\YC561403.CAB
[16/08/2003 - 00:49:46 | C | 4713330] D:\YH561402.CAB
[15/08/2003 - 09:13:56 | C | 1440029] D:\YI561401.CAB
[16/08/2003 - 01:01:56 | C | 1562651] D:\YL561403.CAB
[15/08/2003 - 09:14:52 | C | 63208] D:\YM561403.CAB
[16/08/2003 - 00:36:04 | C | 1259551] D:\YO561402.CAB
[15/08/2003 - 09:14:12 | C | 14446] D:\YT561401.CAB
[15/08/2003 - 10:39:32 | C | 192632] D:\ZA561401.CAB
[16/08/2003 - 00:50:02 | C | 2679261] D:\ZC561402.CAB
[16/08/2003 - 00:29:12 | C | 1733140] D:\ZD561403.CAB
[16/08/2003 - 00:50:18 | C | 768200] D:\ZE561402.CAB
[15/08/2003 - 09:14:46 | C | 2248811] D:\ZF561402.CAB
[15/08/2003 - 09:14:48 | C | 47824] D:\ZG561401.CAB
[16/08/2003 - 00:36:16 | C | 243499] D:\ZH561403.CAB
[16/08/2003 - 00:50:28 | C | 84052] D:\ZI561402.CAB
[15/08/2003 - 09:15:00 | C | 103723] D:\ZJ561401.CAB
[15/08/2003 - 09:16:32 | C | 147457] D:\ZK561401.CAB
[15/08/2003 - 08:52:44 | C | 107454] D:\ZM561401.CAB
[15/08/2003 - 08:52:54 | C | 274001] D:\ZN561401.CAB
[16/08/2003 - 01:03:18 | C | 315297] D:\ZO561403.CAB
[15/08/2003 - 08:53:00 | C | 668276] D:\ZQ561401.CAB
[16/08/2003 - 00:36:24 | C | 33325] D:\ZR561402.CAB
[15/08/2003 - 08:53:04 | C | 441429] D:\ZS561401.CAB
[15/08/2003 - 09:15:48 | C | 353051] D:\ZT561401.CAB
[16/08/2003 - 01:04:16 | C | 16808] D:\ZU561405.CAB
[15/08/2003 - 08:53:14 | C | 91858] D:\ZV561401.CAB
[16/08/2003 - 00:29:32 | C | 483564] D:\ZY561403.CAB
[15/08/2003 - 08:53:26 | C | 6291] D:\ZZ561401.CAB
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
Utilisateur: frikh (Administrateur) # FRIKH-PC
Mis à jour le 13/05/2013 par El Desaparecido
Lancé à 22:20:17 | 30/05/2013
Site Web: https://www.sosvirus.net/
Upload Malware: http://upload.sosvirus.org/
Contact: contact@sosvirus.org
PC: ASUSTeK Computer Inc. (K72Jr) (x64-based PC)
CPU: Intel(R) Core(TM) i5 CPU M 460 @ 2.53GHz (2534)
RAM -> [Total : 3949 | Free : 876]
BIOS: BIOS Date: 10/30/09 15:13:23 Ver: 08.00.10
BOOT: Normal boot
OS: Microsoft Windows 7 Édition Familiale Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 9.0.8112.16421
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Trend Micro Titanium Internet Security [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 116 Go (42 Go libre(s) - 36%) [OS] # NTFS
D:\ -> Disque fixe # 328 Go (31 Go libre(s) - 9%) [DATA] # NTFS
E:\ -> CD-ROM
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [UpdateLBPShortCut] - "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
HKLM\SOFTWARE | Run : [UpdateP2GoShortCut] - "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
HKLM\SOFTWARE | Run : [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
HKLM\SOFTWARE | Run : [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
HKLM\SOFTWARE | Run : [SuperVigil] - "C:\ProgramData\SuperVigil\SyScript\SysPlug.exe" C:\ProgramData\SuperVigil\SuperVigil\SuperVigil.spg
HKLM\SOFTWARE | Run : [] -
HKLM\SOFTWARE | Run : [ISUSScheduler] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
HKLM\SOFTWARE | Run : [Regedit32] - C:\Windows\system32\regedit.exe
HKLM\SOFTWARE\wow6432Node | Run : [UpdateLBPShortCut] - "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
HKLM\SOFTWARE\wow6432Node | Run : [UpdateP2GoShortCut] - "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE\wow6432Node | Run : [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
HKLM\SOFTWARE\wow6432Node | Run : [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
HKLM\SOFTWARE\wow6432Node | Run : [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
HKLM\SOFTWARE\wow6432Node | Run : [SuperVigil] - "C:\ProgramData\SuperVigil\SyScript\SysPlug.exe" C:\ProgramData\SuperVigil\SuperVigil\SuperVigil.spg
HKLM\SOFTWARE\wow6432Node | Run : [] -
HKLM\SOFTWARE\wow6432Node | Run : [ISUSScheduler] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
HKLM\SOFTWARE\wow6432Node | Run : [Regedit32] - C:\Windows\system32\regedit.exe
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Facebook Update] - "C:\Users\frikh\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Free Download Manager] - "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [SuperCopier2.exe] - C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Skype] - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [ISUSPM Startup] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Xvid] - C:\Program Files (x86)\Xvid\CheckUpdate.exe
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Regedit32] - C:\Windows\system32\regedit.exe
HKU\S-1-5-18\SOFTWARE | RunOnce : [Del83836934] - cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del"
################## | Processus Stoppés |
Stoppé! C:\Windows\system32\atiesrxx.exe (856)
Stoppé! C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_38986e29a8b510a2\STacSV64.exe (416)
Stoppé! C:\Windows\system32\atieclxx.exe (1228)
Stoppé! C:\Windows\system32\FBAgent.exe (1304)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (1364)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (1408)
Stoppé! C:\Windows\System32\spoolsv.exe (1568)
Stoppé! C:\Windows\SysWOW64\drivers\CDAC11BA.EXE (1812)
Stoppé! C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (1860)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (1892)
Stoppé! C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (1980)
Stoppé! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2348)
Stoppé! C:\Program Files (x86)\Soda PDF 5\HelperService.exe (2396)
Stoppé! C:\Program Files (x86)\Soda PDF 5\ConversionService.exe (2428)
Stoppé! C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (2460)
Stoppé! C:\Program Files\Trend Micro\Titanium\TiMiniService.exe (2540)
Stoppé! C:\Program Files\Trend Micro\Titanium\TiResumeSrv.exe (2612)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2676)
Stoppé! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (2740)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (2992)
Stoppé! C:\Windows\AsScrPro.exe (3192)
Stoppé! C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (3300)
Stoppé! C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (3648)
Stoppé! C:\Windows\System32\alg.exe (3708)
Stoppé! C:\Program Files\IDT\WDM\sttray64.exe (3836)
Stoppé! C:\Program Files (x86)\Free Download Manager\fdm.exe (3224)
Stoppé! C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe (3212)
Stoppé! C:\Program Files (x86)\Skype\Phone\Skype.exe (3220)
Stoppé! C:\Program Files (x86)\Xvid\CheckUpdate.exe (1128)
Stoppé! C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (4116)
Stoppé! C:\Program Files (x86)\Xvid\autoupdate-windows.exe (4172)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (4248)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (4256)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (4264)
Stoppé! C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (4280)
Stoppé! C:\Windows\SysWOW64\regedit.exe (4288)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (3784)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (2288)
Stoppé! C:\Windows\system32\notepad.exe (4076)
Stoppé! C:\Program Files (x86)\Internet Explorer\iexplore.exe (4484)
Stoppé! C:\Program Files (x86)\Internet Explorer\iexplore.exe (4716)
Stoppé! C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE (3464)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (4244)
Stoppé! C:\Windows\splwow64.exe (2244)
Stoppé! C:\Program Files (x86)\Internet Explorer\iexplore.exe (2392)
################## | Éléments infectieux |
Supprimé! C:\Users\frikh\AppData\Roaming\Temp
(!) Fichiers temporaires supprimés.
################## | Registre |
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Regedit32
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Regedit32
################## | Mountpoints2 |
################## | Listing |
[30/05/2013 - 22:03:45 | D ] C:\$RECYCLE.BIN
[30/05/2013 - 19:03:12 | N | 5269] C:\AdwCleaner[R1].txt
[30/05/2013 - 19:11:56 | N | 6292] C:\AdwCleaner[S1].txt
[26/05/2012 - 02:04:21 | D ] C:\AeriaGames
[30/03/2012 - 12:13:10 | N | 2006] C:\aqua_bitmap.cpp
[02/07/2011 - 16:55:20 | D ] C:\ASUS.DAT
[14/03/2011 - 01:01:15 | D ] C:\AsusVibeData
[06/12/2011 - 18:38:15 | D ] C:\BigFishGamesCache
[06/12/2011 - 18:30:06 | D ] C:\Boonty
[27/11/2011 - 11:21:34 | D ] C:\Boot
[20/11/2010 - 11:40:07 | RASH | 383786] C:\bootmgr
[29/07/2009 - 05:03:37 | N | 8192] C:\BOOTSECT.BAK
[23/11/2012 - 18:23:31 | N | 94] C:\ChromeHPLog.txt
[30/05/2013 - 22:10:02 | N | 31526] C:\ComboFix.txt
[30/05/2013 - 09:54:19 | D ] C:\Config.Msi
[14/03/2011 - 01:33:23 | N | 14862] C:\devlist.txt
[13/10/2012 - 11:07:20 | D ] C:\DOA
[14/07/2009 - 04:08:56 | SHD ] C:\Documents and Settings
[27/02/2013 - 18:19:17 | D ] C:\Downloads
[14/03/2011 - 01:20:33 | D ] C:\eSupport
[01/03/2013 - 20:52:09 | D ] C:\extensions
[01/03/2013 - 20:52:09 | N | 0] C:\extensions.sqlite
[14/03/2011 - 01:33:23 | N | 9] C:\Finish.log
[18/01/2013 - 20:32:25 | D ] C:\found.002
[31/10/2012 - 10:25:51 | D ] C:\found.003
[18/01/2013 - 20:32:25 | D ] C:\found.004
[12/05/2012 - 18:08:46 | D ] C:\FPC
[14/12/2012 - 19:38:09 | D ] C:\Games
[13/10/2012 - 11:07:20 | D ] C:\Help
[30/05/2013 - 22:03:05 | ASH | 3105259520] C:\hiberfil.sys
[13/10/2012 - 11:07:20 | D ] C:\include
[13/10/2012 - 11:28:41 | D ] C:\Installation Borland Database Engine
[14/03/2011 - 01:05:33 | D ] C:\Intel
[05/01/2010 - 08:42:12 | N | 19] C:\K72JR_WIN7.20
[13/10/2012 - 11:07:20 | D ] C:\lib
[24/07/2012 - 02:04:24 | D ] C:\Microgaming
[04/07/2011 - 22:35:29 | RD ] C:\MSOCache
[12/01/2013 - 02:18:50 | D ] C:\nfs
[17/04/2013 - 08:15:28 | D ] C:\Output Files
[13/10/2012 - 10:45:38 | N | 4] C:\OVBCMSOC.ITM
[30/05/2013 - 22:03:07 | ASH | 4140347392] C:\pagefile.sys
[13/03/2011 - 12:47:29 | N | 233] C:\Pass.txt
[14/07/2009 - 02:20:08 | D ] C:\PerfLogs
[30/05/2013 - 21:17:39 | D ] C:\Pre_Scan
[30/05/2013 - 19:11:40 | D ] C:\Program Files
[30/05/2013 - 22:01:07 | D ] C:\Program Files (x86)
[30/05/2013 - 22:01:01 | D ] C:\ProgramData
[23/11/2012 - 17:35:37 | D ] C:\Python25
[30/05/2013 - 22:10:04 | D ] C:\Qoobox
[02/07/2011 - 16:51:34 | D ] C:\Recovery
[05/01/2010 - 08:42:12 | N | 7] C:\RECOVERY.DAT
[11/02/2013 - 19:02:02 | N | 202] C:\SetSearchAndHomepageInBrowserLog.txt
[14/03/2011 - 01:23:20 | N | 193] C:\setup.log
[13/05/2006 - 15:22:24 | N | 5] C:\store.log
[30/05/2013 - 21:56:50 | SHD ] C:\System Volume Information
[10/04/2013 - 23:30:06 | D ] C:\Temp
[14/10/2012 - 09:08:03 | N | 0] C:\testDefBrow.html
[30/05/2013 - 22:22:15 | D ] C:\UsbFix
[30/05/2013 - 22:22:24 | A | 11404] C:\UsbFix [Clean 2] FRIKH-PC.txt
[28/06/2012 - 10:09:32 | D ] C:\Users
[30/05/2013 - 22:10:04 | D ] C:\Windows
[28/06/2012 - 10:10:09 | DC ] D:\$RECYCLE.BIN
[26/12/2012 - 16:33:18 | DC ] D:\0e176c0dade1fbf01d6291deeb6fae
[13/05/2013 - 04:46:54 | DC ] D:\0efbbff2d14dfa2d6f48715f5c9efd
[23/11/2012 - 04:43:50 | DC ] D:\227e13e4d6fd8b343229b7
[06/11/2012 - 19:47:05 | DC ] D:\29f3eec80f44bd0dbe3c
[20/12/2012 - 10:15:57 | DC ] D:\3cfa5db312262695aa18c7f0d4
[22/12/2012 - 18:19:58 | DC ] D:\444fcfe1f922fbd3f2fcf0122a
[01/05/2013 - 23:47:59 | DC ] D:\508c12a60818f7b1d9
[05/12/2011 - 21:17:59 | DC ] D:\64f0f7dbb3f4cb5aba302f5648
[30/10/2012 - 12:05:21 | DC ] D:\71c53df984ed5bda4fd5
[25/04/2013 - 11:50:17 | DC ] D:\9c12c024c1049bea13e48baf54
[28/01/2013 - 14:33:01 | DC ] D:\9dccac17e8661de0d60b0e0f9b71
[16/08/2003 - 00:40:00 | C | 3612862] D:\A2561404.CAB
[16/08/2003 - 00:40:52 | C | 6658289] D:\A3561404.CAB
[16/08/2003 - 00:41:30 | C | 3134238] D:\A4561404.CAB
[29/09/2011 - 05:39:31 | DC ] D:\a90207c72b06473183b6
[15/04/2003 - 22:57:44 | C | 276] D:\acad1.reg
[15/04/2003 - 23:56:18 | C | 276] D:\acad2.reg
[19/03/2003 - 15:59:18 | C | 310] D:\acadcd.mid
[07/11/2012 - 19:56:08 | DC ] D:\af035c009f6055c4c8b5be3f2881d953
[16/08/2003 - 00:41:50 | C | 2407957] D:\AV561404.CAB
[24/02/2013 - 16:48:24 | DC ] D:\b99fd03af446dc2db85b
[25/04/2013 - 22:54:26 | DC ] D:\Bin
[21/03/2013 - 00:47:15 | DC ] D:\bureau
[21/12/2012 - 08:39:45 | DC ] D:\c5a40c867c1253de8e3cda6c8718
[02/11/2012 - 00:05:36 | DC ] D:\c99af7fc688746c1fea1
[15/08/2003 - 09:05:52 | C | 1681457] D:\CC561401.CAB
[15/08/2003 - 09:05:56 | C | 323898] D:\CD561401.CAB
[15/08/2003 - 09:06:12 | C | 2071027] D:\CF561401.CAB
[15/08/2003 - 09:06:20 | C | 706243] D:\CL561401.CAB
[15/08/2003 - 09:06:32 | C | 1232028] D:\CM561401.CAB
[05/11/2012 - 19:21:31 | DC ] D:\Config.Msi
[15/08/2003 - 09:06:44 | C | 2487448] D:\CP561401.CAB
[15/08/2003 - 09:06:54 | C | 2306744] D:\CR561401.CAB
[01/03/2013 - 22:06:11 | DC ] D:\crack
[15/08/2003 - 09:07:00 | C | 611657] D:\CS561401.CAB
[16/08/2003 - 00:42:58 | C | 5503414] D:\E2561404.CAB
[16/08/2003 - 00:43:36 | C | 3728516] D:\E3561404.CAB
[16/08/2003 - 00:43:48 | C | 614809] D:\E4561404.CAB
[16/08/2003 - 00:44:10 | C | 2517595] D:\EV561404.CAB
[15/10/2011 - 02:50:02 | DC ] D:\f6c83ad819af1d7bde1412e468c7de
[13/04/2013 - 12:23:55 | DC ] D:\FFOutput
[25/04/2013 - 23:09:49 | DC ] D:\FILES
[26/05/2013 - 21:51:09 | DC ] D:\film
[16/08/2003 - 00:44:26 | C | 1840628] D:\G3561404.CAB
[23/08/2012 - 13:07:22 | DC ] D:\GTA
[16/08/2003 - 00:42:38 | C | 502881] D:\GV561402.CAB
[15/08/2003 - 09:03:32 | C | 107046] D:\IJ561401.CAB
[15/08/2003 - 09:03:34 | C | 38260] D:\IS561401.CAB
[15/08/2003 - 09:05:16 | C | 13650283] D:\IU561401.CAB
[16/08/2003 - 00:46:28 | C | 10646583] D:\L2561404.CAB
[16/08/2003 - 00:47:00 | C | 2224184] D:\L3561405.CAB
[16/08/2003 - 00:47:20 | C | 1058289] D:\L4561405.CAB
[16/08/2003 - 00:44:08 | C | 300748] D:\L9561402.CAB
[08/06/2003 - 21:20:26 | C | 48747] D:\license.exe
[30/05/2013 - 20:33:35 | DC ] D:\limac
[16/08/2003 - 00:47:38 | C | 1115417] D:\LV561405.CAB
[16/08/2003 - 00:29:06 | C | 51050] D:\M2561403.CAB
[16/08/2003 - 00:29:34 | C | 5209361] D:\M3561403.CAB
[16/08/2003 - 00:30:34 | C | 12878142] D:\M4561403.CAB
[15/08/2003 - 09:09:52 | C | 2301053] D:\M9561401.CAB
[16/08/2003 - 00:46:36 | C | 630316] D:\MA561405.CAB
[13/04/2013 - 23:09:37 | DC ] D:\Mariage
[16/08/2003 - 00:45:16 | C | 2336284] D:\MC561403.CAB
[16/08/2003 - 00:30:10 | C | 917002] D:\MG561403.CAB
[15/08/2003 - 09:11:30 | C | 2374394] D:\MH561401.CAB
[16/08/2003 - 00:49:26 | C | 887039] D:\MO561404.CAB
[25/04/2013 - 23:10:21 | DC ] D:\MSDE2000
[28/11/2012 - 21:08:57 | DC ] D:\msdownld.tmp
[25/04/2013 - 11:50:33 | DC ] D:\MSI8da4b.tmp
[15/10/2011 - 19:51:53 | RDC ] D:\MSOCache
[16/08/2003 - 00:45:58 | C | 2532195] D:\MT561403.CAB
[15/08/2003 - 09:06:14 | C | 30137] D:\O0561401.CAB
[18/08/2003 - 14:46:28 | C | 12582960] D:\O1561407.CAB
[16/08/2003 - 00:46:44 | C | 195326] D:\O9561402.CAB
[18/08/2003 - 14:44:46 | C | 562688] D:\OWC10.MSI
[18/08/2003 - 14:45:04 | C | 607232] D:\OWC11.MSI
[16/08/2003 - 00:54:24 | C | 29758389] D:\P2561404.CAB
[16/08/2003 - 00:55:44 | C | 5405691] D:\P3561405.CAB
[16/08/2003 - 00:55:58 | C | 456919] D:\P4561405.CAB
[15/08/2003 - 08:53:16 | C | 1740699] D:\PA561401.CAB
[02/06/2012 - 17:50:27 | DC ] D:\PFiles
[15/08/2003 - 10:22:34 | C | 754496] D:\PR102593.CAB
[15/08/2003 - 12:42:44 | C | 12137368] D:\PR103196.CAB
[15/08/2003 - 09:11:26 | C | 5755051] D:\PR103369.CAB
[16/08/2003 - 00:34:32 | C | 8381104] D:\PR103601.CAB
[16/08/2003 - 00:32:44 | C | 3519473] D:\PR104301.CAB
[15/08/2003 - 09:11:50 | C | 7645762] D:\PR308246.CAB
[18/08/2003 - 15:05:30 | C | 5842944] D:\PRO11.MSI
[16/08/2003 - 00:56:50 | C | 1436775] D:\PV561405.CAB
[16/08/2003 - 00:57:34 | C | 2174890] D:\PW561405.CAB
[16/08/2003 - 00:58:00 | C | 3060871] D:\Q2561405.CAB
[16/08/2003 - 00:58:32 | C | 2556851] D:\Q3561405.CAB
[16/08/2003 - 00:58:42 | C | 562402] D:\Q4561405.CAB
[16/08/2003 - 00:58:58 | C | 1424358] D:\QV561405.CAB
[31/07/2003 - 09:49:12 | C | 7160] D:\README.HTM
[02/02/2012 - 16:06:37 | DC ] D:\recycl.bin
[17/04/2013 - 08:03:20 | DC ] D:\salim sport
[17/05/2013 - 10:36:20 | DC ] D:\salim travail
[11/07/2003 - 14:06:08 | C | 22397] D:\SETUP.HTM
[11/03/2003 - 10:36:12 | C | 519] D:\setup.ini
[16/08/2003 - 00:59:38 | C | 6922159] D:\SKU011.CAB
[18/08/2003 - 15:00:20 | C | 399529] D:\SKU011.XML
[16/08/2003 - 00:28:08 | C | 163932] D:\SKU026.CAB
[18/08/2003 - 14:44:30 | C | 3534146] D:\SKU0A4.CAB
[15/07/2012 - 13:47:11 | SHDC ] D:\System Volume Information
[16/08/2003 - 00:35:00 | C | 323620] D:\TA561401.CAB
[15/08/2003 - 13:04:08 | C | 1986770] D:\TR102537.CAB
[15/08/2003 - 13:07:52 | C | 2372548] D:\TR103113.CAB
[15/08/2003 - 09:14:40 | C | 2056750] D:\TR308222.CAB
[16/08/2003 - 00:48:34 | C | 2060804] D:\V3561402.CAB
[16/08/2003 - 01:00:42 | C | 6339729] D:\W2561405.CAB
[16/08/2003 - 01:01:14 | C | 3027025] D:\W3561405.CAB
[16/08/2003 - 01:01:30 | C | 791064] D:\W4561405.CAB
[16/08/2003 - 01:01:56 | C | 3228915] D:\WV561405.CAB
[16/08/2003 - 01:02:58 | C | 9621215] D:\X2561405.CAB
[16/08/2003 - 01:03:06 | C | 1164555] D:\X3561405.CAB
[16/08/2003 - 00:28:56 | C | 8436971] D:\YA561403.CAB
[16/08/2003 - 00:29:40 | C | 8530949] D:\YB561403.CAB
[16/08/2003 - 00:35:56 | C | 635769] D:\YC561403.CAB
[16/08/2003 - 00:49:46 | C | 4713330] D:\YH561402.CAB
[15/08/2003 - 09:13:56 | C | 1440029] D:\YI561401.CAB
[16/08/2003 - 01:01:56 | C | 1562651] D:\YL561403.CAB
[15/08/2003 - 09:14:52 | C | 63208] D:\YM561403.CAB
[16/08/2003 - 00:36:04 | C | 1259551] D:\YO561402.CAB
[15/08/2003 - 09:14:12 | C | 14446] D:\YT561401.CAB
[15/08/2003 - 10:39:32 | C | 192632] D:\ZA561401.CAB
[16/08/2003 - 00:50:02 | C | 2679261] D:\ZC561402.CAB
[16/08/2003 - 00:29:12 | C | 1733140] D:\ZD561403.CAB
[16/08/2003 - 00:50:18 | C | 768200] D:\ZE561402.CAB
[15/08/2003 - 09:14:46 | C | 2248811] D:\ZF561402.CAB
[15/08/2003 - 09:14:48 | C | 47824] D:\ZG561401.CAB
[16/08/2003 - 00:36:16 | C | 243499] D:\ZH561403.CAB
[16/08/2003 - 00:50:28 | C | 84052] D:\ZI561402.CAB
[15/08/2003 - 09:15:00 | C | 103723] D:\ZJ561401.CAB
[15/08/2003 - 09:16:32 | C | 147457] D:\ZK561401.CAB
[15/08/2003 - 08:52:44 | C | 107454] D:\ZM561401.CAB
[15/08/2003 - 08:52:54 | C | 274001] D:\ZN561401.CAB
[16/08/2003 - 01:03:18 | C | 315297] D:\ZO561403.CAB
[15/08/2003 - 08:53:00 | C | 668276] D:\ZQ561401.CAB
[16/08/2003 - 00:36:24 | C | 33325] D:\ZR561402.CAB
[15/08/2003 - 08:53:04 | C | 441429] D:\ZS561401.CAB
[15/08/2003 - 09:15:48 | C | 353051] D:\ZT561401.CAB
[16/08/2003 - 01:04:16 | C | 16808] D:\ZU561405.CAB
[15/08/2003 - 08:53:14 | C | 91858] D:\ZV561401.CAB
[16/08/2003 - 00:29:32 | C | 483564] D:\ZY561403.CAB
[15/08/2003 - 08:53:26 | C | 6291] D:\ZZ561401.CAB
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
############################## | UsbFix V 7.126 | [Suppression]
Utilisateur: frikh (Administrateur) # FRIKH-PC
Mis à jour le 13/05/2013 par El Desaparecido
Lancé à 22:33:46 | 30/05/2013
Site Web: https://www.sosvirus.net/
Upload Malware: http://upload.sosvirus.org/
Contact: contact@sosvirus.org
PC: ASUSTeK Computer Inc. (K72Jr) (x64-based PC)
CPU: Intel(R) Core(TM) i5 CPU M 460 @ 2.53GHz (2534)
RAM -> [Total : 3949 | Free : 2138]
BIOS: BIOS Date: 10/30/09 15:13:23 Ver: 08.00.10
BOOT: Normal boot
OS: Microsoft Windows 7 Édition Familiale Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 9.0.8112.16421
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Trend Micro Titanium Internet Security [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 116 Go (42 Go libre(s) - 36%) [OS] # NTFS
D:\ -> Disque fixe # 328 Go (31 Go libre(s) - 9%) [DATA] # NTFS
E:\ -> CD-ROM
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [UpdateLBPShortCut] - "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
HKLM\SOFTWARE | Run : [UpdateP2GoShortCut] - "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
HKLM\SOFTWARE | Run : [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
HKLM\SOFTWARE | Run : [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
HKLM\SOFTWARE | Run : [SuperVigil] - "C:\ProgramData\SuperVigil\SyScript\SysPlug.exe" C:\ProgramData\SuperVigil\SuperVigil\SuperVigil.spg
HKLM\SOFTWARE | Run : [] -
HKLM\SOFTWARE | Run : [ISUSScheduler] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
HKLM\SOFTWARE\wow6432Node | Run : [UpdateLBPShortCut] - "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
HKLM\SOFTWARE\wow6432Node | Run : [UpdateP2GoShortCut] - "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE\wow6432Node | Run : [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
HKLM\SOFTWARE\wow6432Node | Run : [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
HKLM\SOFTWARE\wow6432Node | Run : [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
HKLM\SOFTWARE\wow6432Node | Run : [SuperVigil] - "C:\ProgramData\SuperVigil\SyScript\SysPlug.exe" C:\ProgramData\SuperVigil\SuperVigil\SuperVigil.spg
HKLM\SOFTWARE\wow6432Node | Run : [] -
HKLM\SOFTWARE\wow6432Node | Run : [ISUSScheduler] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Facebook Update] - "C:\Users\frikh\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Free Download Manager] - "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [SuperCopier2.exe] - C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Skype] - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [ISUSPM Startup] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Xvid] - C:\Program Files (x86)\Xvid\CheckUpdate.exe
HKU\S-1-5-18\SOFTWARE | RunOnce : [Del83836934] - cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del"
################## | Processus Stoppés |
Stoppé! C:\Windows\system32\atiesrxx.exe (848)
Stoppé! C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_38986e29a8b510a2\STacSV64.exe (368)
Stoppé! C:\Windows\system32\atieclxx.exe (1224)
Stoppé! C:\Windows\system32\FBAgent.exe (1300)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (1328)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (1428)
Stoppé! C:\Windows\System32\spoolsv.exe (1544)
Stoppé! C:\Windows\SysWOW64\drivers\CDAC11BA.EXE (1744)
Stoppé! C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (1792)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (1824)
Stoppé! C:\Windows\system32\msiexec.exe (1900)
Stoppé! C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (1948)
Stoppé! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2584)
Stoppé! C:\Program Files (x86)\Soda PDF 5\HelperService.exe (2632)
Stoppé! C:\Program Files (x86)\Soda PDF 5\ConversionService.exe (2668)
Stoppé! C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (2696)
Stoppé! C:\Program Files\Trend Micro\Titanium\TiMiniService.exe (2780)
Stoppé! C:\Program Files\Trend Micro\Titanium\TiResumeSrv.exe (2824)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2868)
Stoppé! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (2932)
Stoppé! C:\Windows\AsScrPro.exe (3160)
Stoppé! C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (3248)
Stoppé! C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (3324)
Stoppé! C:\Program Files\Elantech\ETDCtrl.exe (3504)
Stoppé! C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe (3512)
Stoppé! C:\Windows\System32\alg.exe (3548)
Stoppé! C:\Program Files\IDT\WDM\sttray64.exe (3720)
Stoppé! C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (3756)
Stoppé! C:\Program Files (x86)\Free Download Manager\fdm.exe (3948)
Stoppé! C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe (3968)
Stoppé! C:\Program Files (x86)\Skype\Phone\Skype.exe (4008)
Stoppé! C:\Program Files (x86)\Xvid\CheckUpdate.exe (4056)
Stoppé! C:\Program Files (x86)\Xvid\autoupdate-windows.exe (3216)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (3764)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (3784)
Stoppé! C:\Program Files (x86)\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe (3956)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (3616)
Stoppé! C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (1184)
Stoppé! C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (1464)
Stoppé! C:\Program Files (x86)\ASUS\ASUS WebStorage\EeeStorageUploader.exe (1120)
Stoppé! C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (4428)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (12140)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (13064)
Stoppé! C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE (19136)
Stoppé! C:\Program Files (x86)\Internet Explorer\iexplore.exe (12372)
Stoppé! C:\Program Files (x86)\Internet Explorer\iexplore.exe (18588)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (18760)
Stoppé! C:\Windows\splwow64.exe (1852)
Stoppé! C:\Program Files (x86)\Internet Explorer\iexplore.exe (17880)
################## | Éléments infectieux |
(!) Fichiers temporaires supprimés.
################## | Registre |
################## | Mountpoints2 |
################## | Listing |
[30/05/2013 - 22:03:45 | D ] C:\$RECYCLE.BIN
[30/05/2013 - 19:03:12 | N | 5269] C:\AdwCleaner[R1].txt
[30/05/2013 - 19:11:56 | N | 6292] C:\AdwCleaner[S1].txt
[26/05/2012 - 02:04:21 | D ] C:\AeriaGames
[30/03/2012 - 12:13:10 | N | 2006] C:\aqua_bitmap.cpp
[02/07/2011 - 16:55:20 | D ] C:\ASUS.DAT
[14/03/2011 - 01:01:15 | D ] C:\AsusVibeData
[30/05/2013 - 22:22:24 | RASHD ] C:\Autorun.inf
[06/12/2011 - 18:38:15 | D ] C:\BigFishGamesCache
[06/12/2011 - 18:30:06 | D ] C:\Boonty
[27/11/2011 - 11:21:34 | D ] C:\Boot
[20/11/2010 - 11:40:07 | RASH | 383786] C:\bootmgr
[29/07/2009 - 05:03:37 | N | 8192] C:\BOOTSECT.BAK
[23/11/2012 - 18:23:31 | N | 94] C:\ChromeHPLog.txt
[30/05/2013 - 22:10:02 | N | 31526] C:\ComboFix.txt
[30/05/2013 - 09:54:19 | D ] C:\Config.Msi
[14/03/2011 - 01:33:23 | N | 14862] C:\devlist.txt
[13/10/2012 - 11:07:20 | D ] C:\DOA
[14/07/2009 - 04:08:56 | SHD ] C:\Documents and Settings
[27/02/2013 - 18:19:17 | D ] C:\Downloads
[14/03/2011 - 01:20:33 | D ] C:\eSupport
[01/03/2013 - 20:52:09 | D ] C:\extensions
[01/03/2013 - 20:52:09 | N | 0] C:\extensions.sqlite
[14/03/2011 - 01:33:23 | N | 9] C:\Finish.log
[18/01/2013 - 20:32:25 | D ] C:\found.002
[31/10/2012 - 10:25:51 | D ] C:\found.003
[18/01/2013 - 20:32:25 | D ] C:\found.004
[12/05/2012 - 18:08:46 | D ] C:\FPC
[14/12/2012 - 19:38:09 | D ] C:\Games
[13/10/2012 - 11:07:20 | D ] C:\Help
[30/05/2013 - 22:24:17 | ASH | 3105259520] C:\hiberfil.sys
[13/10/2012 - 11:07:20 | D ] C:\include
[13/10/2012 - 11:28:41 | D ] C:\Installation Borland Database Engine
[14/03/2011 - 01:05:33 | D ] C:\Intel
[05/01/2010 - 08:42:12 | N | 19] C:\K72JR_WIN7.20
[13/10/2012 - 11:07:20 | D ] C:\lib
[24/07/2012 - 02:04:24 | D ] C:\Microgaming
[04/07/2011 - 22:35:29 | RD ] C:\MSOCache
[12/01/2013 - 02:18:50 | D ] C:\nfs
[17/04/2013 - 08:15:28 | D ] C:\Output Files
[13/10/2012 - 10:45:38 | N | 4] C:\OVBCMSOC.ITM
[30/05/2013 - 22:24:19 | ASH | 4140347392] C:\pagefile.sys
[13/03/2011 - 12:47:29 | N | 233] C:\Pass.txt
[14/07/2009 - 02:20:08 | D ] C:\PerfLogs
[30/05/2013 - 21:17:39 | D ] C:\Pre_Scan
[30/05/2013 - 19:11:40 | D ] C:\Program Files
[30/05/2013 - 22:01:07 | D ] C:\Program Files (x86)
[30/05/2013 - 22:01:01 | D ] C:\ProgramData
[23/11/2012 - 17:35:37 | D ] C:\Python25
[30/05/2013 - 22:10:04 | D ] C:\Qoobox
[02/07/2011 - 16:51:34 | D ] C:\Recovery
[05/01/2010 - 08:42:12 | N | 7] C:\RECOVERY.DAT
[11/02/2013 - 19:02:02 | N | 202] C:\SetSearchAndHomepageInBrowserLog.txt
[14/03/2011 - 01:23:20 | N | 193] C:\setup.log
[13/05/2006 - 15:22:24 | N | 5] C:\store.log
[30/05/2013 - 21:56:50 | SHD ] C:\System Volume Information
[10/04/2013 - 23:30:06 | D ] C:\Temp
[14/10/2012 - 09:08:03 | N | 0] C:\testDefBrow.html
[30/05/2013 - 22:22:24 | N | 22] C:\Upload_UsbFix.zip
[30/05/2013 - 22:34:57 | D ] C:\UsbFix
[30/05/2013 - 22:22:24 | N | 19697] C:\UsbFix [Clean 2] FRIKH-PC.txt
[30/05/2013 - 22:35:06 | A | 11370] C:\UsbFix [Clean 3] FRIKH-PC.txt
[28/06/2012 - 10:09:32 | D ] C:\Users
[30/05/2013 - 22:10:04 | D ] C:\Windows
[28/06/2012 - 10:10:09 | DC ] D:\$RECYCLE.BIN
[26/12/2012 - 16:33:18 | DC ] D:\0e176c0dade1fbf01d6291deeb6fae
[13/05/2013 - 04:46:54 | DC ] D:\0efbbff2d14dfa2d6f48715f5c9efd
[23/11/2012 - 04:43:50 | DC ] D:\227e13e4d6fd8b343229b7
[06/11/2012 - 19:47:05 | DC ] D:\29f3eec80f44bd0dbe3c
[20/12/2012 - 10:15:57 | DC ] D:\3cfa5db312262695aa18c7f0d4
[22/12/2012 - 18:19:58 | DC ] D:\444fcfe1f922fbd3f2fcf0122a
[01/05/2013 - 23:47:59 | DC ] D:\508c12a60818f7b1d9
[05/12/2011 - 21:17:59 | DC ] D:\64f0f7dbb3f4cb5aba302f5648
[30/10/2012 - 12:05:21 | DC ] D:\71c53df984ed5bda4fd5
[25/04/2013 - 11:50:17 | DC ] D:\9c12c024c1049bea13e48baf54
[28/01/2013 - 14:33:01 | DC ] D:\9dccac17e8661de0d60b0e0f9b71
[16/08/2003 - 00:40:00 | C | 3612862] D:\A2561404.CAB
[16/08/2003 - 00:40:52 | C | 6658289] D:\A3561404.CAB
[16/08/2003 - 00:41:30 | C | 3134238] D:\A4561404.CAB
[29/09/2011 - 05:39:31 | DC ] D:\a90207c72b06473183b6
[15/04/2003 - 22:57:44 | C | 276] D:\acad1.reg
[15/04/2003 - 23:56:18 | C | 276] D:\acad2.reg
[19/03/2003 - 15:59:18 | C | 310] D:\acadcd.mid
[07/11/2012 - 19:56:08 | DC ] D:\af035c009f6055c4c8b5be3f2881d953
[30/05/2013 - 22:22:24 | RASHDC ] D:\Autorun.inf
[16/08/2003 - 00:41:50 | C | 2407957] D:\AV561404.CAB
[24/02/2013 - 16:48:24 | DC ] D:\b99fd03af446dc2db85b
[25/04/2013 - 22:54:26 | DC ] D:\Bin
[21/03/2013 - 00:47:15 | DC ] D:\bureau
[21/12/2012 - 08:39:45 | DC ] D:\c5a40c867c1253de8e3cda6c8718
[02/11/2012 - 00:05:36 | DC ] D:\c99af7fc688746c1fea1
[15/08/2003 - 09:05:52 | C | 1681457] D:\CC561401.CAB
[15/08/2003 - 09:05:56 | C | 323898] D:\CD561401.CAB
[15/08/2003 - 09:06:12 | C | 2071027] D:\CF561401.CAB
[15/08/2003 - 09:06:20 | C | 706243] D:\CL561401.CAB
[15/08/2003 - 09:06:32 | C | 1232028] D:\CM561401.CAB
[05/11/2012 - 19:21:31 | DC ] D:\Config.Msi
[15/08/2003 - 09:06:44 | C | 2487448] D:\CP561401.CAB
[15/08/2003 - 09:06:54 | C | 2306744] D:\CR561401.CAB
[01/03/2013 - 22:06:11 | DC ] D:\crack
[15/08/2003 - 09:07:00 | C | 611657] D:\CS561401.CAB
[16/08/2003 - 00:42:58 | C | 5503414] D:\E2561404.CAB
[16/08/2003 - 00:43:36 | C | 3728516] D:\E3561404.CAB
[16/08/2003 - 00:43:48 | C | 614809] D:\E4561404.CAB
[16/08/2003 - 00:44:10 | C | 2517595] D:\EV561404.CAB
[15/10/2011 - 02:50:02 | DC ] D:\f6c83ad819af1d7bde1412e468c7de
[13/04/2013 - 12:23:55 | DC ] D:\FFOutput
[25/04/2013 - 23:09:49 | DC ] D:\FILES
[26/05/2013 - 21:51:09 | DC ] D:\film
[16/08/2003 - 00:44:26 | C | 1840628] D:\G3561404.CAB
[23/08/2012 - 13:07:22 | DC ] D:\GTA
[16/08/2003 - 00:42:38 | C | 502881] D:\GV561402.CAB
[15/08/2003 - 09:03:32 | C | 107046] D:\IJ561401.CAB
[15/08/2003 - 09:03:34 | C | 38260] D:\IS561401.CAB
[15/08/2003 - 09:05:16 | C | 13650283] D:\IU561401.CAB
[16/08/2003 - 00:46:28 | C | 10646583] D:\L2561404.CAB
[16/08/2003 - 00:47:00 | C | 2224184] D:\L3561405.CAB
[16/08/2003 - 00:47:20 | C | 1058289] D:\L4561405.CAB
[16/08/2003 - 00:44:08 | C | 300748] D:\L9561402.CAB
[08/06/2003 - 21:20:26 | C | 48747] D:\license.exe
[30/05/2013 - 20:33:35 | DC ] D:\limac
[16/08/2003 - 00:47:38 | C | 1115417] D:\LV561405.CAB
[16/08/2003 - 00:29:06 | C | 51050] D:\M2561403.CAB
[16/08/2003 - 00:29:34 | C | 5209361] D:\M3561403.CAB
[16/08/2003 - 00:30:34 | C | 12878142] D:\M4561403.CAB
[15/08/2003 - 09:09:52 | C | 2301053] D:\M9561401.CAB
[16/08/2003 - 00:46:36 | C | 630316] D:\MA561405.CAB
[13/04/2013 - 23:09:37 | DC ] D:\Mariage
[16/08/2003 - 00:45:16 | C | 2336284] D:\MC561403.CAB
[16/08/2003 - 00:30:10 | C | 917002] D:\MG561403.CAB
[15/08/2003 - 09:11:30 | C | 2374394] D:\MH561401.CAB
[16/08/2003 - 00:49:26 | C | 887039] D:\MO561404.CAB
[25/04/2013 - 23:10:21 | DC ] D:\MSDE2000
[28/11/2012 - 21:08:57 | DC ] D:\msdownld.tmp
[25/04/2013 - 11:50:33 | DC ] D:\MSI8da4b.tmp
[15/10/2011 - 19:51:53 | RDC ] D:\MSOCache
[16/08/2003 - 00:45:58 | C | 2532195] D:\MT561403.CAB
[15/08/2003 - 09:06:14 | C | 30137] D:\O0561401.CAB
[18/08/2003 - 14:46:28 | C | 12582960] D:\O1561407.CAB
[16/08/2003 - 00:46:44 | C | 195326] D:\O9561402.CAB
[18/08/2003 - 14:44:46 | C | 562688] D:\OWC10.MSI
[18/08/2003 - 14:45:04 | C | 607232] D:\OWC11.MSI
[16/08/2003 - 00:54:24 | C | 29758389] D:\P2561404.CAB
[16/08/2003 - 00:55:44 | C | 5405691] D:\P3561405.CAB
[16/08/2003 - 00:55:58 | C | 456919] D:\P4561405.CAB
[15/08/2003 - 08:53:16 | C | 1740699] D:\PA561401.CAB
[02/06/2012 - 17:50:27 | DC ] D:\PFiles
[15/08/2003 - 10:22:34 | C | 754496] D:\PR102593.CAB
[15/08/2003 - 12:42:44 | C | 12137368] D:\PR103196.CAB
[15/08/2003 - 09:11:26 | C | 5755051] D:\PR103369.CAB
[16/08/2003 - 00:34:32 | C | 8381104] D:\PR103601.CAB
[16/08/2003 - 00:32:44 | C | 3519473] D:\PR104301.CAB
[15/08/2003 - 09:11:50 | C | 7645762] D:\PR308246.CAB
[18/08/2003 - 15:05:30 | C | 5842944] D:\PRO11.MSI
[16/08/2003 - 00:56:50 | C | 1436775] D:\PV561405.CAB
[16/08/2003 - 00:57:34 | C | 2174890] D:\PW561405.CAB
[16/08/2003 - 00:58:00 | C | 3060871] D:\Q2561405.CAB
[16/08/2003 - 00:58:32 | C | 2556851] D:\Q3561405.CAB
[16/08/2003 - 00:58:42 | C | 562402] D:\Q4561405.CAB
[16/08/2003 - 00:58:58 | C | 1424358] D:\QV561405.CAB
[31/07/2003 - 09:49:12 | C | 7160] D:\README.HTM
[02/02/2012 - 16:06:37 | DC ] D:\recycl.bin
[17/04/2013 - 08:03:20 | DC ] D:\salim sport
[17/05/2013 - 10:36:20 | DC ] D:\salim travail
[11/07/2003 - 14:06:08 | C | 22397] D:\SETUP.HTM
[11/03/2003 - 10:36:12 | C | 519] D:\setup.ini
[16/08/2003 - 00:59:38 | C | 6922159] D:\SKU011.CAB
[18/08/2003 - 15:00:20 | C | 399529] D:\SKU011.XML
[16/08/2003 - 00:28:08 | C | 163932] D:\SKU026.CAB
[18/08/2003 - 14:44:30 | C | 3534146] D:\SKU0A4.CAB
[15/07/2012 - 13:47:11 | SHDC ] D:\System Volume Information
[16/08/2003 - 00:35:00 | C | 323620] D:\TA561401.CAB
[15/08/2003 - 13:04:08 | C | 1986770] D:\TR102537.CAB
[15/08/2003 - 13:07:52 | C | 2372548] D:\TR103113.CAB
[15/08/2003 - 09:14:40 | C | 2056750] D:\TR308222.CAB
[16/08/2003 - 00:48:34 | C | 2060804] D:\V3561402.CAB
[16/08/2003 - 01:00:42 | C | 6339729] D:\W2561405.CAB
[16/08/2003 - 01:01:14 | C | 3027025] D:\W3561405.CAB
[16/08/2003 - 01:01:30 | C | 791064] D:\W4561405.CAB
[16/08/2003 - 01:01:56 | C | 3228915] D:\WV561405.CAB
[16/08/2003 - 01:02:58 | C | 9621215] D:\X2561405.CAB
[16/08/2003 - 01:03:06 | C | 1164555] D:\X3561405.CAB
[16/08/2003 - 00:28:56 | C | 8436971] D:\YA561403.CAB
[16/08/2003 - 00:29:40 | C | 8530949] D:\YB561403.CAB
[16/08/2003 - 00:35:56 | C | 635769] D:\YC561403.CAB
[16/08/2003 - 00:49:46 | C | 4713330] D:\YH561402.CAB
[15/08/2003 - 09:13:56 | C | 1440029] D:\YI561401.CAB
[16/08/2003 - 01:01:56 | C | 1562651] D:\YL561403.CAB
[15/08/2003 - 09:14:52 | C | 63208] D:\YM561403.CAB
[16/08/2003 - 00:36:04 | C | 1259551] D:\YO561402.CAB
[15/08/2003 - 09:14:12 | C | 14446] D:\YT561401.CAB
[15/08/2003 - 10:39:32 | C | 192632] D:\ZA561401.CAB
[16/08/2003 - 00:50:02 | C | 2679261] D:\ZC561402.CAB
[16/08/2003 - 00:29:12 | C | 1733140] D:\ZD561403.CAB
[16/08/2003 - 00:50:18 | C | 768200] D:\ZE561402.CAB
[15/08/2003 - 09:14:46 | C | 2248811] D:\ZF561402.CAB
[15/08/2003 - 09:14:48 | C | 47824] D:\ZG561401.CAB
[16/08/2003 - 00:36:16 | C | 243499] D:\ZH561403.CAB
[16/08/2003 - 00:50:28 | C | 84052] D:\ZI561402.CAB
[15/08/2003 - 09:15:00 | C | 103723] D:\ZJ561401.CAB
[15/08/2003 - 09:16:32 | C | 147457] D:\ZK561401.CAB
[15/08/2003 - 08:52:44 | C | 107454] D:\ZM561401.CAB
[15/08/2003 - 08:52:54 | C | 274001] D:\ZN561401.CAB
[16/08/2003 - 01:03:18 | C | 315297] D:\ZO561403.CAB
[15/08/2003 - 08:53:00 | C | 668276] D:\ZQ561401.CAB
[16/08/2003 - 00:36:24 | C | 33325] D:\ZR561402.CAB
[15/08/2003 - 08:53:04 | C | 441429] D:\ZS561401.CAB
[15/08/2003 - 09:15:48 | C | 353051] D:\ZT561401.CAB
[16/08/2003 - 01:04:16 | C | 16808] D:\ZU561405.CAB
[15/08/2003 - 08:53:14 | C | 91858] D:\ZV561401.CAB
[16/08/2003 - 00:29:32 | C | 483564] D:\ZY561403.CAB
[15/08/2003 - 08:53:26 | C | 6291] D:\ZZ561401.CAB
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
Utilisateur: frikh (Administrateur) # FRIKH-PC
Mis à jour le 13/05/2013 par El Desaparecido
Lancé à 22:33:46 | 30/05/2013
Site Web: https://www.sosvirus.net/
Upload Malware: http://upload.sosvirus.org/
Contact: contact@sosvirus.org
PC: ASUSTeK Computer Inc. (K72Jr) (x64-based PC)
CPU: Intel(R) Core(TM) i5 CPU M 460 @ 2.53GHz (2534)
RAM -> [Total : 3949 | Free : 2138]
BIOS: BIOS Date: 10/30/09 15:13:23 Ver: 08.00.10
BOOT: Normal boot
OS: Microsoft Windows 7 Édition Familiale Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 9.0.8112.16421
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Trend Micro Titanium Internet Security [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 116 Go (42 Go libre(s) - 36%) [OS] # NTFS
D:\ -> Disque fixe # 328 Go (31 Go libre(s) - 9%) [DATA] # NTFS
E:\ -> CD-ROM
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [UpdateLBPShortCut] - "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
HKLM\SOFTWARE | Run : [UpdateP2GoShortCut] - "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
HKLM\SOFTWARE | Run : [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
HKLM\SOFTWARE | Run : [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
HKLM\SOFTWARE | Run : [SuperVigil] - "C:\ProgramData\SuperVigil\SyScript\SysPlug.exe" C:\ProgramData\SuperVigil\SuperVigil\SuperVigil.spg
HKLM\SOFTWARE | Run : [] -
HKLM\SOFTWARE | Run : [ISUSScheduler] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
HKLM\SOFTWARE\wow6432Node | Run : [UpdateLBPShortCut] - "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
HKLM\SOFTWARE\wow6432Node | Run : [UpdateP2GoShortCut] - "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE\wow6432Node | Run : [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
HKLM\SOFTWARE\wow6432Node | Run : [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
HKLM\SOFTWARE\wow6432Node | Run : [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
HKLM\SOFTWARE\wow6432Node | Run : [SuperVigil] - "C:\ProgramData\SuperVigil\SyScript\SysPlug.exe" C:\ProgramData\SuperVigil\SuperVigil\SuperVigil.spg
HKLM\SOFTWARE\wow6432Node | Run : [] -
HKLM\SOFTWARE\wow6432Node | Run : [ISUSScheduler] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Facebook Update] - "C:\Users\frikh\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Free Download Manager] - "C:\Program Files (x86)\Free Download Manager\fdm.exe" -autorun
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [SuperCopier2.exe] - C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Skype] - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [ISUSPM Startup] - "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
HKU\S-1-5-21-1690438275-548386926-3050949732-1000\SOFTWARE | Run : [Xvid] - C:\Program Files (x86)\Xvid\CheckUpdate.exe
HKU\S-1-5-18\SOFTWARE | RunOnce : [Del83836934] - cmd.exe /Q /D /c del "C:\Windows\TEMP\0.del"
################## | Processus Stoppés |
Stoppé! C:\Windows\system32\atiesrxx.exe (848)
Stoppé! C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_38986e29a8b510a2\STacSV64.exe (368)
Stoppé! C:\Windows\system32\atieclxx.exe (1224)
Stoppé! C:\Windows\system32\FBAgent.exe (1300)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (1328)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (1428)
Stoppé! C:\Windows\System32\spoolsv.exe (1544)
Stoppé! C:\Windows\SysWOW64\drivers\CDAC11BA.EXE (1744)
Stoppé! C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (1792)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (1824)
Stoppé! C:\Windows\system32\msiexec.exe (1900)
Stoppé! C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe (1948)
Stoppé! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2584)
Stoppé! C:\Program Files (x86)\Soda PDF 5\HelperService.exe (2632)
Stoppé! C:\Program Files (x86)\Soda PDF 5\ConversionService.exe (2668)
Stoppé! C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (2696)
Stoppé! C:\Program Files\Trend Micro\Titanium\TiMiniService.exe (2780)
Stoppé! C:\Program Files\Trend Micro\Titanium\TiResumeSrv.exe (2824)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2868)
Stoppé! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (2932)
Stoppé! C:\Windows\AsScrPro.exe (3160)
Stoppé! C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (3248)
Stoppé! C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (3324)
Stoppé! C:\Program Files\Elantech\ETDCtrl.exe (3504)
Stoppé! C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe (3512)
Stoppé! C:\Windows\System32\alg.exe (3548)
Stoppé! C:\Program Files\IDT\WDM\sttray64.exe (3720)
Stoppé! C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (3756)
Stoppé! C:\Program Files (x86)\Free Download Manager\fdm.exe (3948)
Stoppé! C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe (3968)
Stoppé! C:\Program Files (x86)\Skype\Phone\Skype.exe (4008)
Stoppé! C:\Program Files (x86)\Xvid\CheckUpdate.exe (4056)
Stoppé! C:\Program Files (x86)\Xvid\autoupdate-windows.exe (3216)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (3764)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (3784)
Stoppé! C:\Program Files (x86)\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe (3956)
Stoppé! C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (3616)
Stoppé! C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (1184)
Stoppé! C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (1464)
Stoppé! C:\Program Files (x86)\ASUS\ASUS WebStorage\EeeStorageUploader.exe (1120)
Stoppé! C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (4428)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (12140)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (13064)
Stoppé! C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE (19136)
Stoppé! C:\Program Files (x86)\Internet Explorer\iexplore.exe (12372)
Stoppé! C:\Program Files (x86)\Internet Explorer\iexplore.exe (18588)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (18760)
Stoppé! C:\Windows\splwow64.exe (1852)
Stoppé! C:\Program Files (x86)\Internet Explorer\iexplore.exe (17880)
################## | Éléments infectieux |
(!) Fichiers temporaires supprimés.
################## | Registre |
################## | Mountpoints2 |
################## | Listing |
[30/05/2013 - 22:03:45 | D ] C:\$RECYCLE.BIN
[30/05/2013 - 19:03:12 | N | 5269] C:\AdwCleaner[R1].txt
[30/05/2013 - 19:11:56 | N | 6292] C:\AdwCleaner[S1].txt
[26/05/2012 - 02:04:21 | D ] C:\AeriaGames
[30/03/2012 - 12:13:10 | N | 2006] C:\aqua_bitmap.cpp
[02/07/2011 - 16:55:20 | D ] C:\ASUS.DAT
[14/03/2011 - 01:01:15 | D ] C:\AsusVibeData
[30/05/2013 - 22:22:24 | RASHD ] C:\Autorun.inf
[06/12/2011 - 18:38:15 | D ] C:\BigFishGamesCache
[06/12/2011 - 18:30:06 | D ] C:\Boonty
[27/11/2011 - 11:21:34 | D ] C:\Boot
[20/11/2010 - 11:40:07 | RASH | 383786] C:\bootmgr
[29/07/2009 - 05:03:37 | N | 8192] C:\BOOTSECT.BAK
[23/11/2012 - 18:23:31 | N | 94] C:\ChromeHPLog.txt
[30/05/2013 - 22:10:02 | N | 31526] C:\ComboFix.txt
[30/05/2013 - 09:54:19 | D ] C:\Config.Msi
[14/03/2011 - 01:33:23 | N | 14862] C:\devlist.txt
[13/10/2012 - 11:07:20 | D ] C:\DOA
[14/07/2009 - 04:08:56 | SHD ] C:\Documents and Settings
[27/02/2013 - 18:19:17 | D ] C:\Downloads
[14/03/2011 - 01:20:33 | D ] C:\eSupport
[01/03/2013 - 20:52:09 | D ] C:\extensions
[01/03/2013 - 20:52:09 | N | 0] C:\extensions.sqlite
[14/03/2011 - 01:33:23 | N | 9] C:\Finish.log
[18/01/2013 - 20:32:25 | D ] C:\found.002
[31/10/2012 - 10:25:51 | D ] C:\found.003
[18/01/2013 - 20:32:25 | D ] C:\found.004
[12/05/2012 - 18:08:46 | D ] C:\FPC
[14/12/2012 - 19:38:09 | D ] C:\Games
[13/10/2012 - 11:07:20 | D ] C:\Help
[30/05/2013 - 22:24:17 | ASH | 3105259520] C:\hiberfil.sys
[13/10/2012 - 11:07:20 | D ] C:\include
[13/10/2012 - 11:28:41 | D ] C:\Installation Borland Database Engine
[14/03/2011 - 01:05:33 | D ] C:\Intel
[05/01/2010 - 08:42:12 | N | 19] C:\K72JR_WIN7.20
[13/10/2012 - 11:07:20 | D ] C:\lib
[24/07/2012 - 02:04:24 | D ] C:\Microgaming
[04/07/2011 - 22:35:29 | RD ] C:\MSOCache
[12/01/2013 - 02:18:50 | D ] C:\nfs
[17/04/2013 - 08:15:28 | D ] C:\Output Files
[13/10/2012 - 10:45:38 | N | 4] C:\OVBCMSOC.ITM
[30/05/2013 - 22:24:19 | ASH | 4140347392] C:\pagefile.sys
[13/03/2011 - 12:47:29 | N | 233] C:\Pass.txt
[14/07/2009 - 02:20:08 | D ] C:\PerfLogs
[30/05/2013 - 21:17:39 | D ] C:\Pre_Scan
[30/05/2013 - 19:11:40 | D ] C:\Program Files
[30/05/2013 - 22:01:07 | D ] C:\Program Files (x86)
[30/05/2013 - 22:01:01 | D ] C:\ProgramData
[23/11/2012 - 17:35:37 | D ] C:\Python25
[30/05/2013 - 22:10:04 | D ] C:\Qoobox
[02/07/2011 - 16:51:34 | D ] C:\Recovery
[05/01/2010 - 08:42:12 | N | 7] C:\RECOVERY.DAT
[11/02/2013 - 19:02:02 | N | 202] C:\SetSearchAndHomepageInBrowserLog.txt
[14/03/2011 - 01:23:20 | N | 193] C:\setup.log
[13/05/2006 - 15:22:24 | N | 5] C:\store.log
[30/05/2013 - 21:56:50 | SHD ] C:\System Volume Information
[10/04/2013 - 23:30:06 | D ] C:\Temp
[14/10/2012 - 09:08:03 | N | 0] C:\testDefBrow.html
[30/05/2013 - 22:22:24 | N | 22] C:\Upload_UsbFix.zip
[30/05/2013 - 22:34:57 | D ] C:\UsbFix
[30/05/2013 - 22:22:24 | N | 19697] C:\UsbFix [Clean 2] FRIKH-PC.txt
[30/05/2013 - 22:35:06 | A | 11370] C:\UsbFix [Clean 3] FRIKH-PC.txt
[28/06/2012 - 10:09:32 | D ] C:\Users
[30/05/2013 - 22:10:04 | D ] C:\Windows
[28/06/2012 - 10:10:09 | DC ] D:\$RECYCLE.BIN
[26/12/2012 - 16:33:18 | DC ] D:\0e176c0dade1fbf01d6291deeb6fae
[13/05/2013 - 04:46:54 | DC ] D:\0efbbff2d14dfa2d6f48715f5c9efd
[23/11/2012 - 04:43:50 | DC ] D:\227e13e4d6fd8b343229b7
[06/11/2012 - 19:47:05 | DC ] D:\29f3eec80f44bd0dbe3c
[20/12/2012 - 10:15:57 | DC ] D:\3cfa5db312262695aa18c7f0d4
[22/12/2012 - 18:19:58 | DC ] D:\444fcfe1f922fbd3f2fcf0122a
[01/05/2013 - 23:47:59 | DC ] D:\508c12a60818f7b1d9
[05/12/2011 - 21:17:59 | DC ] D:\64f0f7dbb3f4cb5aba302f5648
[30/10/2012 - 12:05:21 | DC ] D:\71c53df984ed5bda4fd5
[25/04/2013 - 11:50:17 | DC ] D:\9c12c024c1049bea13e48baf54
[28/01/2013 - 14:33:01 | DC ] D:\9dccac17e8661de0d60b0e0f9b71
[16/08/2003 - 00:40:00 | C | 3612862] D:\A2561404.CAB
[16/08/2003 - 00:40:52 | C | 6658289] D:\A3561404.CAB
[16/08/2003 - 00:41:30 | C | 3134238] D:\A4561404.CAB
[29/09/2011 - 05:39:31 | DC ] D:\a90207c72b06473183b6
[15/04/2003 - 22:57:44 | C | 276] D:\acad1.reg
[15/04/2003 - 23:56:18 | C | 276] D:\acad2.reg
[19/03/2003 - 15:59:18 | C | 310] D:\acadcd.mid
[07/11/2012 - 19:56:08 | DC ] D:\af035c009f6055c4c8b5be3f2881d953
[30/05/2013 - 22:22:24 | RASHDC ] D:\Autorun.inf
[16/08/2003 - 00:41:50 | C | 2407957] D:\AV561404.CAB
[24/02/2013 - 16:48:24 | DC ] D:\b99fd03af446dc2db85b
[25/04/2013 - 22:54:26 | DC ] D:\Bin
[21/03/2013 - 00:47:15 | DC ] D:\bureau
[21/12/2012 - 08:39:45 | DC ] D:\c5a40c867c1253de8e3cda6c8718
[02/11/2012 - 00:05:36 | DC ] D:\c99af7fc688746c1fea1
[15/08/2003 - 09:05:52 | C | 1681457] D:\CC561401.CAB
[15/08/2003 - 09:05:56 | C | 323898] D:\CD561401.CAB
[15/08/2003 - 09:06:12 | C | 2071027] D:\CF561401.CAB
[15/08/2003 - 09:06:20 | C | 706243] D:\CL561401.CAB
[15/08/2003 - 09:06:32 | C | 1232028] D:\CM561401.CAB
[05/11/2012 - 19:21:31 | DC ] D:\Config.Msi
[15/08/2003 - 09:06:44 | C | 2487448] D:\CP561401.CAB
[15/08/2003 - 09:06:54 | C | 2306744] D:\CR561401.CAB
[01/03/2013 - 22:06:11 | DC ] D:\crack
[15/08/2003 - 09:07:00 | C | 611657] D:\CS561401.CAB
[16/08/2003 - 00:42:58 | C | 5503414] D:\E2561404.CAB
[16/08/2003 - 00:43:36 | C | 3728516] D:\E3561404.CAB
[16/08/2003 - 00:43:48 | C | 614809] D:\E4561404.CAB
[16/08/2003 - 00:44:10 | C | 2517595] D:\EV561404.CAB
[15/10/2011 - 02:50:02 | DC ] D:\f6c83ad819af1d7bde1412e468c7de
[13/04/2013 - 12:23:55 | DC ] D:\FFOutput
[25/04/2013 - 23:09:49 | DC ] D:\FILES
[26/05/2013 - 21:51:09 | DC ] D:\film
[16/08/2003 - 00:44:26 | C | 1840628] D:\G3561404.CAB
[23/08/2012 - 13:07:22 | DC ] D:\GTA
[16/08/2003 - 00:42:38 | C | 502881] D:\GV561402.CAB
[15/08/2003 - 09:03:32 | C | 107046] D:\IJ561401.CAB
[15/08/2003 - 09:03:34 | C | 38260] D:\IS561401.CAB
[15/08/2003 - 09:05:16 | C | 13650283] D:\IU561401.CAB
[16/08/2003 - 00:46:28 | C | 10646583] D:\L2561404.CAB
[16/08/2003 - 00:47:00 | C | 2224184] D:\L3561405.CAB
[16/08/2003 - 00:47:20 | C | 1058289] D:\L4561405.CAB
[16/08/2003 - 00:44:08 | C | 300748] D:\L9561402.CAB
[08/06/2003 - 21:20:26 | C | 48747] D:\license.exe
[30/05/2013 - 20:33:35 | DC ] D:\limac
[16/08/2003 - 00:47:38 | C | 1115417] D:\LV561405.CAB
[16/08/2003 - 00:29:06 | C | 51050] D:\M2561403.CAB
[16/08/2003 - 00:29:34 | C | 5209361] D:\M3561403.CAB
[16/08/2003 - 00:30:34 | C | 12878142] D:\M4561403.CAB
[15/08/2003 - 09:09:52 | C | 2301053] D:\M9561401.CAB
[16/08/2003 - 00:46:36 | C | 630316] D:\MA561405.CAB
[13/04/2013 - 23:09:37 | DC ] D:\Mariage
[16/08/2003 - 00:45:16 | C | 2336284] D:\MC561403.CAB
[16/08/2003 - 00:30:10 | C | 917002] D:\MG561403.CAB
[15/08/2003 - 09:11:30 | C | 2374394] D:\MH561401.CAB
[16/08/2003 - 00:49:26 | C | 887039] D:\MO561404.CAB
[25/04/2013 - 23:10:21 | DC ] D:\MSDE2000
[28/11/2012 - 21:08:57 | DC ] D:\msdownld.tmp
[25/04/2013 - 11:50:33 | DC ] D:\MSI8da4b.tmp
[15/10/2011 - 19:51:53 | RDC ] D:\MSOCache
[16/08/2003 - 00:45:58 | C | 2532195] D:\MT561403.CAB
[15/08/2003 - 09:06:14 | C | 30137] D:\O0561401.CAB
[18/08/2003 - 14:46:28 | C | 12582960] D:\O1561407.CAB
[16/08/2003 - 00:46:44 | C | 195326] D:\O9561402.CAB
[18/08/2003 - 14:44:46 | C | 562688] D:\OWC10.MSI
[18/08/2003 - 14:45:04 | C | 607232] D:\OWC11.MSI
[16/08/2003 - 00:54:24 | C | 29758389] D:\P2561404.CAB
[16/08/2003 - 00:55:44 | C | 5405691] D:\P3561405.CAB
[16/08/2003 - 00:55:58 | C | 456919] D:\P4561405.CAB
[15/08/2003 - 08:53:16 | C | 1740699] D:\PA561401.CAB
[02/06/2012 - 17:50:27 | DC ] D:\PFiles
[15/08/2003 - 10:22:34 | C | 754496] D:\PR102593.CAB
[15/08/2003 - 12:42:44 | C | 12137368] D:\PR103196.CAB
[15/08/2003 - 09:11:26 | C | 5755051] D:\PR103369.CAB
[16/08/2003 - 00:34:32 | C | 8381104] D:\PR103601.CAB
[16/08/2003 - 00:32:44 | C | 3519473] D:\PR104301.CAB
[15/08/2003 - 09:11:50 | C | 7645762] D:\PR308246.CAB
[18/08/2003 - 15:05:30 | C | 5842944] D:\PRO11.MSI
[16/08/2003 - 00:56:50 | C | 1436775] D:\PV561405.CAB
[16/08/2003 - 00:57:34 | C | 2174890] D:\PW561405.CAB
[16/08/2003 - 00:58:00 | C | 3060871] D:\Q2561405.CAB
[16/08/2003 - 00:58:32 | C | 2556851] D:\Q3561405.CAB
[16/08/2003 - 00:58:42 | C | 562402] D:\Q4561405.CAB
[16/08/2003 - 00:58:58 | C | 1424358] D:\QV561405.CAB
[31/07/2003 - 09:49:12 | C | 7160] D:\README.HTM
[02/02/2012 - 16:06:37 | DC ] D:\recycl.bin
[17/04/2013 - 08:03:20 | DC ] D:\salim sport
[17/05/2013 - 10:36:20 | DC ] D:\salim travail
[11/07/2003 - 14:06:08 | C | 22397] D:\SETUP.HTM
[11/03/2003 - 10:36:12 | C | 519] D:\setup.ini
[16/08/2003 - 00:59:38 | C | 6922159] D:\SKU011.CAB
[18/08/2003 - 15:00:20 | C | 399529] D:\SKU011.XML
[16/08/2003 - 00:28:08 | C | 163932] D:\SKU026.CAB
[18/08/2003 - 14:44:30 | C | 3534146] D:\SKU0A4.CAB
[15/07/2012 - 13:47:11 | SHDC ] D:\System Volume Information
[16/08/2003 - 00:35:00 | C | 323620] D:\TA561401.CAB
[15/08/2003 - 13:04:08 | C | 1986770] D:\TR102537.CAB
[15/08/2003 - 13:07:52 | C | 2372548] D:\TR103113.CAB
[15/08/2003 - 09:14:40 | C | 2056750] D:\TR308222.CAB
[16/08/2003 - 00:48:34 | C | 2060804] D:\V3561402.CAB
[16/08/2003 - 01:00:42 | C | 6339729] D:\W2561405.CAB
[16/08/2003 - 01:01:14 | C | 3027025] D:\W3561405.CAB
[16/08/2003 - 01:01:30 | C | 791064] D:\W4561405.CAB
[16/08/2003 - 01:01:56 | C | 3228915] D:\WV561405.CAB
[16/08/2003 - 01:02:58 | C | 9621215] D:\X2561405.CAB
[16/08/2003 - 01:03:06 | C | 1164555] D:\X3561405.CAB
[16/08/2003 - 00:28:56 | C | 8436971] D:\YA561403.CAB
[16/08/2003 - 00:29:40 | C | 8530949] D:\YB561403.CAB
[16/08/2003 - 00:35:56 | C | 635769] D:\YC561403.CAB
[16/08/2003 - 00:49:46 | C | 4713330] D:\YH561402.CAB
[15/08/2003 - 09:13:56 | C | 1440029] D:\YI561401.CAB
[16/08/2003 - 01:01:56 | C | 1562651] D:\YL561403.CAB
[15/08/2003 - 09:14:52 | C | 63208] D:\YM561403.CAB
[16/08/2003 - 00:36:04 | C | 1259551] D:\YO561402.CAB
[15/08/2003 - 09:14:12 | C | 14446] D:\YT561401.CAB
[15/08/2003 - 10:39:32 | C | 192632] D:\ZA561401.CAB
[16/08/2003 - 00:50:02 | C | 2679261] D:\ZC561402.CAB
[16/08/2003 - 00:29:12 | C | 1733140] D:\ZD561403.CAB
[16/08/2003 - 00:50:18 | C | 768200] D:\ZE561402.CAB
[15/08/2003 - 09:14:46 | C | 2248811] D:\ZF561402.CAB
[15/08/2003 - 09:14:48 | C | 47824] D:\ZG561401.CAB
[16/08/2003 - 00:36:16 | C | 243499] D:\ZH561403.CAB
[16/08/2003 - 00:50:28 | C | 84052] D:\ZI561402.CAB
[15/08/2003 - 09:15:00 | C | 103723] D:\ZJ561401.CAB
[15/08/2003 - 09:16:32 | C | 147457] D:\ZK561401.CAB
[15/08/2003 - 08:52:44 | C | 107454] D:\ZM561401.CAB
[15/08/2003 - 08:52:54 | C | 274001] D:\ZN561401.CAB
[16/08/2003 - 01:03:18 | C | 315297] D:\ZO561403.CAB
[15/08/2003 - 08:53:00 | C | 668276] D:\ZQ561401.CAB
[16/08/2003 - 00:36:24 | C | 33325] D:\ZR561402.CAB
[15/08/2003 - 08:53:04 | C | 441429] D:\ZS561401.CAB
[15/08/2003 - 09:15:48 | C | 353051] D:\ZT561401.CAB
[16/08/2003 - 01:04:16 | C | 16808] D:\ZU561405.CAB
[15/08/2003 - 08:53:14 | C | 91858] D:\ZV561401.CAB
[16/08/2003 - 00:29:32 | C | 483564] D:\ZY561403.CAB
[15/08/2003 - 08:53:26 | C | 6291] D:\ZZ561401.CAB
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
les deux dernier se trouve dans Quarantine , vus que jais relance le scan sa dois etre pour sa !! on tt cas je vous es donne tt ce que jais trouve dans cest dossier