Rapport de ZHPDiag v2013.5.13.114 par Nicolas Coolman, Update du 13/05/2013 Run by PC at 13/05/2013 22:52:00 State : Version à jour. WhiteList : Disable High Elevated Privileges : OK UAC : Deactivate by program ---\\ Web Browser MSIE: Internet Explorer v10.0.9200.16540 (Defaut) MFIE: Mozilla Firefox 20.0.1 ---\\ Windows Product Information ~ Langage: Français Windows 8 Home Premium Edition, 64-bit (Build 9200) Windows Server License Manager Script : OK ~ ion : Windows(R) Operating System, OEM_DM channel Windows ID Activation : OK ~ Windows Partial Key : 4F9VT Windows License : OK ~ Windows Remaining Initializations Number : 999 Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ System Protection Malwarebytes Anti-Malware version 1.75.0.1300 Norton Internet Security v20.3.1.22 Windows Defender W8 ---\\ System Optimizer ---\\ Peer To Peer (P2P) Vuze v4.9.0.0 =>P2P.Azureus ---\\ Software Update Adobe Flash Player 11 Plugin Java 7 Update 21 ---\\ System Information ~ Processor: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 3717 MB (17% free) System Restore: Activé (Enable) System drive C: has 43 GB (45%) free of 93 GB ---\\ Logged in mode ~ Computer Name: SAMSUNG ~ User Name: PC ~ All Users Names: PC, Administrateur, ~ Unselected Option: None Logged in as Administrator ---\\ Environnement Variables ~ System Unit : C:\ ~ %AppData% : C:\Users\PC\AppData\Roaming\ ~ %Desktop% : C:\Users\PC\Desktop\ ~ %Favorites% : C:\Users\PC\Favorites\ ~ %LocalAppData% : C:\Users\PC\AppData\Local\ ~ %StartMenu% : C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ DOS/Devices C:\ Hard drive, Flash drive, Thumb drive (Free 43 Go of 93 Go) D:\ Hard drive, Flash drive, Thumb drive (Free 442 Go of 466 Go) ---\\ Security Center & Tools Informations [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : Out Of Date ~ Security Center: 27 Scanned in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.E13A31D5254C25406A7946BDD9B06364] - (.Microsoft Corporation - Explorateur Windows.) (.11/10/2012 - 08:35:16.) -- C:\Windows\Explorer.exe [2380944] [MD5.FE9AB232B56A12224E8A3F3F9878C9A3] - (.Microsoft Corporation - Application de démarrage de Windows.) (.26/07/2012 - 04:08:50.) -- C:\Windows\System32\Wininit.exe [132608] [MD5.753C0848AE7872A3F59663078A517293] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.21/02/2013 - 11:15:07.) -- C:\Windows\System32\wininet.dll [2240512] [MD5.BCF2036A0DD579E47C008C133550283E] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.11/10/2012 - 06:46:58.) -- C:\Windows\System32\Winlogon.exe [517120] [MD5.9448F5740A037EC0C18F0E9177232DD0] - (.Microsoft Corporation - Bibliothèque de licences.) (.26/07/2012 - 04:07:20.) -- C:\Windows\System32\sppcomapi.dll [273408] [MD5.36D6A3201721558A8AFBCC09C2DA4C2C] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.06/11/2012 - 04:53:44.) -- C:\Windows\system32\Drivers\AFD.sys [560640] [MD5.A721FF570C2387E383BDDEA9632863C9] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.26/07/2012 - 06:00:48.) -- C:\Windows\system32\Drivers\atapi.sys [25840] [MD5.990B1BABE6E81FB18E65A87EBEFB1772] - (.Microsoft Corporation - CD-ROM File System Driver.) (.26/07/2012 - 03:30:10.) -- C:\Windows\system32\Drivers\Cdfs.sys [108544] [MD5.339BFF85D788268752DA8C9644B188EE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.26/07/2012 - 03:26:36.) -- C:\Windows\system32\Drivers\Cdrom.sys [174080] [MD5.09D9EB9E7898F8E6561473A20CC808B9] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.26/07/2012 - 03:26:53.) -- C:\Windows\system32\Drivers\DfsC.sys [118784] [MD5.7D87B5B6C7188D553E11B59DC7F0B111] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/09/2012 - 07:08:44.) -- C:\Windows\system32\Drivers\HDAudBus.sys [71168] [MD5.C9E9CBF73AFFBFE3E801EFB516787BA3] - (.Microsoft Corporation - Pilote de port i8042.) (.26/07/2012 - 03:28:51.) -- C:\Windows\system32\Drivers\i8042prt.sys [112640] [MD5.3969B9C218DD3FAA9F4ED2FFC3651C02] - (.Microsoft Corporation - IP Network Address Translator.) (.26/07/2012 - 03:23:01.) -- C:\Windows\system32\Drivers\IpNat.sys [145920] [MD5.93179D48066918323628CB016D8C94DC] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.05/02/2013 - 23:29:09.) -- C:\Windows\system32\Drivers\MRxSmb.sys [370688] [MD5.7CEC25C682D319D484630B3952C31A11] - (.Microsoft Corporation - MBT Transport driver.) (.26/07/2012 - 03:24:28.) -- C:\Windows\system32\Drivers\netBT.sys [331776] [MD5.76929F4A69E425911A63B407E26C2589] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.02/02/2013 - 11:54:54.) -- C:\Windows\system32\Drivers\ntfs.sys [1933544] [MD5.4563DAF8C6A740AD7F501E219BD10766] - (.Microsoft Corporation - Pilote de port parallèle.) (.26/07/2012 - 03:29:53.) -- C:\Windows\system32\Drivers\Parport.sys [105984] [MD5.A14D625C5AEE5FFE0F47D1A1D419FAAE] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.26/07/2012 - 03:23:17.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [124928] [MD5.B2A3AD74FF2E2FFA73AF2567108231B3] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.26/07/2012 - 03:25:18.) -- C:\Windows\system32\Drivers\rdpdr.sys [179712] [MD5.73DC722CE5DF26D7638CE2446F2655C7] - (.Microsoft Corporation - TDI Translation Driver.) (.26/07/2012 - 06:26:47.) -- C:\Windows\system32\Drivers\tdx.sys [117248] [MD5.2FB3CDFD5EAF4CD9D4AFAF96877D13AE] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.26/07/2012 - 05:57:09.) -- C:\Windows\system32\Drivers\volsnap.sys [332016] ~ Generic Processes: Scanned in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 2/59 ~ Mes musiques (My Musics) : 19/1316 ~ Mes Videos (My Videos) : 1/28 ~ Mes Favoris (My Favorites) : 1/3 ~ Mes Documents (My Documents) : 2/33 ~ Mon Bureau (My Desktop) : 1/18502 ~ Menu demarrer (Programs) : 1/22 ~ Hidden Files: Scanned in 00mn 06s ---\\ Processus lancés [MD5.D1D5DAB39DCB4BE0359943738D87409B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [532040] [PID.448] [MD5.4C124C8DB059000AD29C44C5E58CD407] - (.Samsung Electronics CO., LTD. - Settings.) -- C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2624200] [PID.3696] [MD5.0D8A2C637046E578EFC7F08EBE86555F] - (.Microsoft Corporation - Microsoft SkyDrive.) -- C:\Users\PC\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [256600] [PID.4660] [MD5.8E2A7F1F62467A7DCB8AB2C0642F47CA] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392] [PID.3964] [MD5.D63797E8E7781EE1500A810CB6194FA6] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816] [PID.4572] [MD5.4AC8041D25D3FB5BF9272D1968B5633F] - (.Microsoft Corporation - Microsoft Office Document Cache Sync Client.) -- C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.exe [78480] [PID.4860] [MD5.241BD3019FB31E812A51B31B06906335] - (.Symantec Corporation - Symantec Service Framework.) -- C:\Program Files (x86)\Norton Internet Security\Engine\20.3.1.22\ccSvcHst.exe [144520] [PID.416] [MD5.6F5386A655598F71BAAB2D6B63A69D6A] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [920472] [PID.384] [MD5.F834B06933E51E2266DC4858A0E9DD98] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe [17304] [PID.1540] [MD5.EB0EB16E7DC48C3D645B1E136346999B] - (.Adobe Systems, Inc. - Adobe Flash Player 11.6 r602.) -- C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_6_602_168.exe [1820016] [PID.5788] [MD5.8DEA9B1919CD66DD2B4D4B8C13B335EC] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [7335424] [PID.5284] ~ Processes Running: Scanned in 00mn 00s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\e1zinowv.default\prefs.js M3 - MFPP: Plugins - [PC] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\amazon-france.xml M3 - MFPP: Plugins - [PC] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\bing.xml M3 - MFPP: Plugins - [PC] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml M3 - MFPP: Plugins - [PC] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\eBay-france.xml M3 - MFPP: Plugins - [PC] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\google.xml M3 - MFPP: Plugins - [PC] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\wikipedia-fr.xml M3 - MFPP: Plugins - [PC] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\yahoo-france.xml P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\windows\system32\Macromed\Flash\NPSWF64_11_6_602_168.dll ~ Firefox Browser: 8 Scanned in 00mn 00s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://samsung13.msn.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://samsung13.msn.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (10.00.9200.16384 (win8_rtm.120725-1247)) -- C:\Windows\SysWOW64\ieframe.dll ~ IE Browser: 12 Scanned in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Redirection du fichier Hosts (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Hosts File: Scanned in 00mn 00s ~ Nombre de lignes (Lines number): 21 ---\\ Browser Helper Objects de navigateur (O2) O2 - BHO: Norton Identity Protection [64Bits] - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} . (.Symantec Corporation - coIEPlugIn.) -- C:\Program Files (x86)\Norton Internet Security\Engine\20.3.1.22\coIEPlg.dll O2 - BHO: Norton Vulnerability Protection [64Bits] - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} . (.Symantec Corporation - IPS Browser Helper DLL.) -- C:\Program Files (x86)\Norton Internet Security\Engine\20.3.1.22\IPS\IPSBHO.dll O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll ~ BHO: 5 Scanned in 00mn 00s ---\\ Applications démarrées par registre & par dossier (O4) O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\windows\system32\igfxpers.exe O4 - HKLM\..\Run: [Logitech Download Assistant] . (.Logitech, Inc. - Logitech Download Assistant.) -- C:\Windows\System32\LogiLDA.dll O4 - HKCU\..\Run: [SkyDrive] . (.Microsoft Corporation - Microsoft SkyDrive.) -- C:\Users\PC\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe O4 - HKUS\S-1-5-21-4087580524-408710073-2843193677-1001\..\Run: [SkyDrive] . (.Microsoft Corporation - Microsoft SkyDrive.) -- C:\Users\PC\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe ~ Application: Scanned in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\Desktop: Disque local (C) - Raccourci.lnk . (...) -- C:\ O4 - GS\Desktop: PhotoScape.lnk . (...) -- C:\Program Files (x86)\PhotoScape\PhotoScape.exe ~ Global Startup: Scanned in 00mn 00s ---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5) O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no ~ IE Control Panel: 1 Scanned in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: Se&nd to OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra button: Lync Click to Call [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\lync.exe (.not file.) O9 - Extra button: OneNote Lin&ked Notes [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll ~ IE Extra Buttons: Scanned in 00mn 00s ---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\windows\system32\napinsp.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\windows\system32\pnrpnsp.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\windows\system32\pnrpnsp.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\windows\system32\NLAapi.dll O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\windows\system32\mswsock.dll O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\windows\system32\winrnr.dll O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\windows\system32\wshbth.dll O10 - WLSP:\000000000008\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files (x86)\Bonjour\mdnsNSP.dll ~ Winsock: 8 Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{01ADFF8F-EE51-4ECD-BD48-0A6D55D7B286}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{0544A90B-79CB-4B75-9436-7494C48251BB}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{01ADFF8F-EE51-4ECD-BD48-0A6D55D7B286}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{0544A90B-79CB-4B75-9436-7494C48251BB}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll ~ Winlogon: Scanned in 00mn 00s ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. ~ SSODL: 1 Scanned in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: Intel® Centrino® Wireless Bluetooth® + H (AMPPALR3) . (.Intel Corporation - Intel® Centrino® Wireless Bluetooth® + High.) - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth (BTHSSecurityMgr) . (.Intel(R) Corporation - Intel(R) BlueTooth(R) HS Security Manager S.) - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe O23 - Service: (Easy Launcher) . (.Samsung Electronics CO., LTD. - EasyLauncher.) - C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) . (.Intel(R) Corporation - Intel(R) PROSet/Wireless Event Log Service.) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe O23 - Service: IntelliMemory (IntelliMemory) . (.Condusiv Technologies - IntelliMemory Service.) - C:\Program Files\Condusiv Technologies\IntelliMemory\IntelliMem.exe O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: Norton Internet Security (NIS) . (.Symantec Corporation - Symantec Service Framework.) - C:\Program Files (x86)\Norton Internet Security\Engine\20.3.1.22\ccSvcHst.exe O23 - Service: Intel(R) PROSet/Wireless Registry Servic (RegSrvc) . (.Intel(R) Corporation - Intel(R) PROSet/Wireless Registry Service.) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe O23 - Service: SW Update Service (SWUpdateService) . (.Samsung Electronics CO., LTD. - SW Update Agent.) - C:\Program Files (x86)\Samsung\SW Update\SWMAgent.exe O23 - Service: Intel(R) PROSet/Wireless Zero Configurat (ZeroConfigService) . (.Intel® Corporation - Intel® PROSet/Wireless Zero Configure Servi.) - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe ~ Services: 13 Scanned in 00mn 05s ---\\ Enumération Active Desktop & MHTML Editor (O24) O24 - Default MHTML Editor: Last - .(...) - (.not file.) ~ Desktop Component: 4 Scanned in 00mn 00s ---\\ BootExecute (O34) O34 - HKLM BootExecute: (autocheck autochk *) - File not found ~ BEX: 1 Scanned in 00mn 00s ---\\ Tâches planifiées en automatique (O39) [MD5.EAA2B8155272BC5789E81E7819518559] [APT] [Norton WSC Integration] (.Symantec Corporation.) -- C:\Program Files (x86)\Norton Internet Security\Engine\20.3.1.22\WSCStub.exe [163432] [MD5.4C124C8DB059000AD29C44C5E58CD407] [APT] [Settings] (.Samsung Electronics CO., LTD..) -- C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2624200] [MD5.3832D44C0811EED1338B34328EB493EB] [APT] [Norton Error Analyzer] (.Symantec Corporation.) -- C:\Program Files (x86)\Norton Internet Security\Engine\20.3.1.22\SymErr.exe [54096] [MD5.3832D44C0811EED1338B34328EB493EB] [APT] [Norton Error Processor] (.Symantec Corporation.) -- C:\Program Files (x86)\Norton Internet Security\Engine\20.3.1.22\SymErr.exe [54096] ~ Scheduled Task: 4 Scanned in 00mn 01s ---\\ Composants installés (ActiveSetup Installed Components) (O40) O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe O40 - ASIC: Browsing Enhancements [64Bits] - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll O40 - ASIC: Windows Desktop Update [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll ~ Active Setup: 9 Scanned in 00mn 00s ---\\ Pilotes lancés au démarrage (O41) O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) - C:\Windows\system32\drivers\afd.sys O41 - Driver: (BasicDisplay) . (.Microsoft Corporation - Microsoft Basic Display Driver.) - C:\Windows\system32\drivers\BasicDisplay.sys O41 - Driver: (BasicRender) . (.Microsoft Corporation - Microsoft Basic Render Driver.) - C:\Windows\system32\drivers\BasicRender.sys O41 - Driver: (BHDrvx64) . (.Symantec Corporation - BASH Driver.) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130502.001_60a\BHDrvx64.sys O41 - Driver: (ccSet_NIS) . (.Symantec Corporation - Common Client Settings Driver.) - C:\Windows\system32\drivers\NISx64\1403010.016\ccSetx64.sys O41 - Driver: cdrom.inf (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\drivers\cdrom.sys O41 - Driver: C:\Windows\System32\drivers\dam.sys (dam) . (.Microsoft Corporation - DAM Kernel Driver.) - C:\Windows\System32\drivers\dam.sys O41 - Driver: C:\Windows\System32\wkssvc.dll (Dfsc) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys O41 - Driver: (eeCtrl) . (.Symantec Corporation - Symantec Eraser Control Driver.) - C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys O41 - Driver: (IDSVia64) . (.Symantec Corporation - IDS Core Driver.) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130511.001\IDSvia64.sys O41 - Driver: (intmfs) . (.Condusiv Technologies - IntelliMemory Filesystem Filter Driver.) - C:\Windows\System32\DRIVERS\intmfs.sys O41 - Driver: mssmbios.inf (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys O41 - Driver: netnb.inf (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys O41 - Driver: npsvctrig.inf (npsvctrig) . (.Microsoft Corporation - Named pipe service triggers.) - C:\Windows\system32\drivers\npsvctrig.sys O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\system32\DRIVERS\pacer.sys O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys O41 - Driver: (SRTSPX) . (.Symantec Corporation - Symantec AutoProtect.) - C:\Windows\system32\drivers\NISx64\1403010.016\SRTSPX64.sys O41 - Driver: (SymIRON) . (.Symantec Corporation - Iron Driver.) - C:\Windows\system32\drivers\NISx64\1403010.016\Ironx64.sys O41 - Driver: (SymNetS) . (.Symantec Corporation - Network Security Driver.) - C:\Windows\system32\Drivers\NISx64\1403010.016\SYMNETS.sys O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\system32\DRIVERS\tdx.sys O41 - Driver: C:\Windows\System32\drivers\vwififlt.sys (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\system32\DRIVERS\vwififlt.sys O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\system32\DRIVERS\wanarp.sys ~ Drivers: 50 Scanned in 00mn 00s ---\\ Logiciels installés (O42) O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {A0087DDE-69D0-11E2-AD57-43CA6188709B} O42 - Logiciel: Adobe Flash Player 11 Plugin - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player Plugin O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM][64Bits] -- {45C56AA7-ED1B-4800-A97F-EDDF3F3520B1} O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM][64Bits] -- {2F72F540-1F60-4266-9506-952B21D6640D} O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM][64Bits] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] -- {6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D} O42 - Logiciel: Embird 2013 (64-bit) - (.© 1997-2013 BALARAD, s.r.o..) [HKLM][64Bits] -- Embird 2013 (64-bit) O42 - Logiciel: Fdrawcmd.sys 1.0.1.11 - (.Simon Owen.) [HKLM][64Bits] -- fdrawcmd O42 - Logiciel: Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed - (.Intel Corporation.) [HKLM][64Bits] -- {A94C50AA-21E8-4627-ADD0-E16A07030D7D} O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {3E29EE6C-963A-4aae-86C1-DC237C4A49FC} O42 - Logiciel: IntelliMemory - (.Condusiv Technologies.) [HKLM][64Bits] -- {E93403C5-8A91-4940-89DB-EED69DA6E82E} O42 - Logiciel: Intel® PROSet/Wireless WiFi Software - (.Intel Corporation.) [HKLM][64Bits] -- {DEF50764-F1A7-4DD4-B8BA-C81A4807631A} O42 - Logiciel: Java 7 Update 21 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83217017FF} O42 - Logiciel: Logiciel Intel® PROSet/Wireless - (.Intel Corporation.) [HKLM][64Bits] -- {e144fbd2-bf87-445f-b40b-93d61ca6bb7d} O42 - Logiciel: Mahjong Time EON (desktop version) - (.UNKNOWN.) [HKLM][64Bits] -- MTMahjongAIR.A08BAD4CD323DD6E08EB7713FBC9B2807D884B67.1 O42 - Logiciel: Mahjong Time EON (desktop version) - (.UNKNOWN.) [HKLM][64Bits] -- {78AAEEEE-7C96-EC01-1C0E-2673FD55109D} O42 - Logiciel: Malwarebytes Anti-Malware version 1.75.0.1300 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes' Anti-Malware_is1 O42 - Logiciel: Microsoft SkyDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- SkyDriveSetup.exe O42 - Logiciel: Mozilla Firefox 20.0.1 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 20.0.1 (x86 fr) O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService O42 - Logiciel: Norton Internet Security - (.Symantec Corporation.) [HKLM][64Bits] -- NIS O42 - Logiciel: Office 15 Click-to-Run Extensibility Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008C-0000-0000-0000000FF1CE} O42 - Logiciel: Office 15 Click-to-Run Licensing Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008F-0000-1000-0000000FF1CE} O42 - Logiciel: Office 15 Click-to-Run Localization Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008C-040C-0000-0000000FF1CE} O42 - Logiciel: PhotoScape - (...) [HKLM][64Bits] -- PhotoScape O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} O42 - Logiciel: S Agent - (.Samsung Electronics CO., LTD..) [HKLM][64Bits] -- {539A70A8-95EC-474A-BDDF-92AB7A53762C} O42 - Logiciel: SW Update - (.Samsung Electronics CO., LTD..) [HKLM][64Bits] -- {43C711D9-67C9-4793-80D4-E957D638D531} O42 - Logiciel: Settings - (.Samsung Electronics CO., LTD..) [HKLM][64Bits] -- {8CB5C357-12E5-41B1-A024-D57D4E6F32D9} O42 - Logiciel: Vuze - (.Azureus Software, Inc..) [HKLM][64Bits] -- 8461-7759-5462-8226 =>P2P.Azureus O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM][64Bits] -- {0225AD21-F3E2-4916-BFF3-65D3F9052582} ~ Logic: 74 Scanned in 00mn 00s ---\\ HKCU & HKLM Software Keys [HKCU\Software\AppDataLow\Software\JavaSoft] [HKCU\Software\AppDataLow] [HKCU\Software\Apple Computer, Inc.] [HKCU\Software\Apple Inc.] [HKCU\Software\Azureus] =>P2P.Azureus [HKCU\Software\Classes] [HKCU\Software\Clients] [HKCU\Software\Hewlett-Packard] [HKCU\Software\Intel] [HKCU\Software\JavaSoft] [HKCU\Software\LogiShrd] [HKCU\Software\Macromedia] [HKCU\Software\Malwarebytes' Anti-Malware] [HKCU\Software\Mine] [HKCU\Software\Mooii] [HKCU\Software\Mozilla] [HKCU\Software\Netscape] [HKCU\Software\Norton] [HKCU\Software\ODBC] [HKCU\Software\Policies] [HKCU\Software\RegisteredApplications] [HKCU\Software\Samsung] [HKCU\Software\Wow6432Node] [HKCU\Software\ZebHelpProcess Helper] [HKCU\Software\ej-technologies] [HKLM\Software\ATI Technologies] [HKLM\Software\Airplane] [HKLM\Software\Apple Computer, Inc.] [HKLM\Software\Apple Inc.] [HKLM\Software\Azureus] =>P2P.Azureus [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\Condusiv Technologies] [HKLM\Software\Diskeeper Corporation] [HKLM\Software\GEAR Software] [HKLM\Software\Intel] [HKLM\Software\Khronos] [HKLM\Software\Logishrd] [HKLM\Software\Macromedia] [HKLM\Software\MozillaPlugins] [HKLM\Software\Mozilla] [HKLM\Software\NVIDIA Corporation] [HKLM\Software\Norton] [HKLM\Software\ODBC] [HKLM\Software\Policies] [HKLM\Software\RTLSetup] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\Samsung] [HKLM\Software\Symantec] [HKLM\Software\Wow6432Node\Adobe] [HKLM\Software\Wow6432Node\AdwCleaner] [HKLM\Software\Wow6432Node\Apple Computer, Inc.] [HKLM\Software\Wow6432Node\Apple Inc.] [HKLM\Software\Wow6432Node\Classes] [HKLM\Software\Wow6432Node\Clients] [HKLM\Software\Wow6432Node\Google] [HKLM\Software\Wow6432Node\InstallShield] [HKLM\Software\Wow6432Node\Intel] [HKLM\Software\Wow6432Node\JavaSoft] [HKLM\Software\Wow6432Node\JreMetrics] [HKLM\Software\Wow6432Node\Khronos] [HKLM\Software\Wow6432Node\Macromedia] [HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware (Trial)] [HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware] [HKLM\Software\Wow6432Node\Mooii] [HKLM\Software\Wow6432Node\MozillaPlugins] [HKLM\Software\Wow6432Node\Mozilla] [HKLM\Software\Wow6432Node\Norton] [HKLM\Software\Wow6432Node\ODBC] [HKLM\Software\Wow6432Node\Policies] [HKLM\Software\Wow6432Node\Realtek] [HKLM\Software\Wow6432Node\RegisteredApplications] [HKLM\Software\Wow6432Node\Samsung Electronics CO., LTD.] [HKLM\Software\Wow6432Node\Samsung] [HKLM\Software\Wow6432Node\Symantec] [HKLM\Software\Wow6432Node\Vittalia] [HKLM\Software\Wow6432Node\mozilla.org] [HKLM\Software\Wow6432Node] [HKLM\Software\ej-technologies] ~ Key Software: 123 Scanned in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 23/02/2013 - 21:56:37 - [0,079] ----D C:\Program Files (x86)\Adobe O43 - CFD: 24/02/2013 - 10:00:18 - [2,316] ----D C:\Program Files (x86)\Apple Software Update O43 - CFD: 24/02/2013 - 10:00:07 - [0,602] ----D C:\Program Files (x86)\Bonjour O43 - CFD: 28/03/2013 - 10:40:10 - [6,785] ----D C:\Program Files (x86)\Cisco O43 - CFD: 12/05/2013 - 15:24:10 - [237,116] ----D C:\Program Files (x86)\Common Files O43 - CFD: 12/05/2013 - 15:24:10 - [14,887] --H-D C:\Program Files (x86)\InstallShield Installation Information O43 - CFD: 12/05/2013 - 15:24:10 - [59,461] ----D C:\Program Files (x86)\Intel O43 - CFD: 17/04/2013 - 22:29:30 - [4,621] ----D C:\Program Files (x86)\Internet Explorer O43 - CFD: 24/02/2013 - 10:00:37 - [154,781] ----D C:\Program Files (x86)\iTunes O43 - CFD: 17/04/2013 - 18:17:05 - [122,344] ----D C:\Program Files (x86)\Java O43 - CFD: 22/04/2013 - 16:46:38 - [21,319] ----D C:\Program Files (x86)\Mahjong Time EON O43 - CFD: 13/05/2013 - 08:24:12 - [13,336] ----D C:\Program Files (x86)\Malwarebytes' Anti-Malware O43 - CFD: 23/02/2013 - 18:43:10 - [0,262] ----D C:\Program Files (x86)\Microsoft Office O43 - CFD: 23/02/2013 - 22:28:01 - [5,397] ----D C:\Program Files (x86)\Microsoft SkyDrive O43 - CFD: 23/02/2013 - 22:27:36 - [7,797] ----D C:\Program Files (x86)\Microsoft.NET O43 - CFD: 17/04/2013 - 22:29:30 - [46,181] ----D C:\Program Files (x86)\Mozilla Firefox O43 - CFD: 17/04/2013 - 22:29:28 - [0,212] ----D C:\Program Files (x86)\Mozilla Maintenance Service O43 - CFD: 07/08/2012 - 13:22:54 - [0,025] ----D C:\Program Files (x86)\MSBuild O43 - CFD: 23/02/2013 - 17:41:31 - [116,389] ----D C:\Program Files (x86)\Norton Internet Security O43 - CFD: 23/02/2013 - 17:41:08 - [13,571] ----D C:\Program Files (x86)\NortonInstaller O43 - CFD: 24/04/2013 - 21:48:51 - [25,405] ----D C:\Program Files (x86)\PhotoScape O43 - CFD: 24/08/2012 - 19:09:42 - [2,694] ----D C:\Program Files (x86)\Realtek O43 - CFD: 07/08/2012 - 13:22:54 - [36,536] ----D C:\Program Files (x86)\Reference Assemblies O43 - CFD: 28/03/2013 - 17:41:55 - [132,097] ----D C:\Program Files (x86)\Samsung O43 - CFD: 24/04/2013 - 18:42:04 - [0,479] ----D C:\Program Files (x86)\SoftwareUpdater =>PUP.Eorezo O43 - CFD: 24/03/2013 - 08:51:55 - [0,951] ----D C:\Program Files (x86)\Windows Defender O43 - CFD: 25/01/2013 - 04:27:36 - [5,466] ----D C:\Program Files (x86)\Windows Mail O43 - CFD: 15/02/2013 - 02:11:22 - [3,494] ----D C:\Program Files (x86)\Windows Media Player O43 - CFD: 26/07/2012 - 09:13:01 - [0,209] ----D C:\Program Files (x86)\Windows Multimedia Platform O43 - CFD: 26/07/2012 - 09:12:59 - [7,243] ----D C:\Program Files (x86)\Windows NT O43 - CFD: 25/01/2013 - 04:27:36 - [5,226] ----D C:\Program Files (x86)\Windows Photo Viewer O43 - CFD: 26/07/2012 - 09:13:01 - [0,209] ----D C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 26/07/2012 - 09:12:59 - [0] -SH-D C:\Program Files (x86)\Windows Sidebar O43 - CFD: 13/05/2013 - 22:52:10 - [22,129] ----D C:\Program Files (x86)\ZHPDiag O43 - CFD: 11/04/2013 - 07:19:38 - [45,606] ----D C:\Program Files (x86)\Common Files\Adobe AIR O43 - CFD: 24/02/2013 - 15:31:49 - [147,643] ----D C:\Program Files (x86)\Common Files\Apple O43 - CFD: 23/02/2013 - 22:27:37 - [0,013] ----D C:\Program Files (x86)\Common Files\DESIGNER O43 - CFD: 07/05/2013 - 12:54:50 - [0,173] ----D C:\Program Files (x86)\Common Files\Intel Corporation O43 - CFD: 17/04/2013 - 18:19:47 - [1,189] ----D C:\Program Files (x86)\Common Files\Java O43 - CFD: 17/04/2013 - 22:29:30 - [32,488] ----D C:\Program Files (x86)\Common Files\Microsoft Shared O43 - CFD: 07/05/2013 - 13:27:31 - [0] ----D C:\Program Files (x86)\Common Files\postureAgent O43 - CFD: 26/07/2012 - 09:13:01 - [0,003] ----D C:\Program Files (x86)\Common Files\Services O43 - CFD: 23/02/2013 - 18:26:57 - [0,595] ----D C:\Program Files (x86)\Common Files\Symantec Shared O43 - CFD: 25/01/2013 - 04:27:36 - [9,406] ----D C:\Program Files (x86)\Common Files\System O43 - CFD: 24/02/2013 - 10:00:37 - [2,774] ----D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 O43 - CFD: 23/02/2013 - 21:56:42 - [0] ----D C:\ProgramData\Adobe O43 - CFD: 24/02/2013 - 10:00:16 - [56,218] ----D C:\ProgramData\Apple O43 - CFD: 24/02/2013 - 10:00:27 - [58,854] ----D C:\ProgramData\Apple Computer O43 - CFD: 26/07/2012 - 08:22:08 - [0] --H-D C:\ProgramData\Application Data O43 - CFD: 28/03/2013 - 17:49:55 - [250,126] ----D C:\ProgramData\Condusiv Technologies O43 - CFD: 26/07/2012 - 08:22:08 - [0] --H-D C:\ProgramData\Desktop O43 - CFD: 26/07/2012 - 08:22:08 - [0] --H-D C:\ProgramData\Documents O43 - CFD: 31/03/2013 - 11:02:42 - [0,019] ----D C:\ProgramData\HP O43 - CFD: 12/05/2013 - 15:25:42 - [0,143] ----D C:\ProgramData\Intel O43 - CFD: 28/03/2013 - 10:40:09 - [0,000] ----D C:\ProgramData\Intel.sav O43 - CFD: 07/05/2013 - 07:53:08 - [1,311] ----D C:\ProgramData\ma-config.com O43 - CFD: 13/05/2013 - 08:24:12 - [6,212] ----D C:\ProgramData\Malwarebytes O43 - CFD: 08/04/2013 - 21:49:51 - [534,302] -S--D C:\ProgramData\Microsoft O43 - CFD: 23/02/2013 - 22:27:54 - [0] ----D C:\ProgramData\Microsoft SkyDrive O43 - CFD: 08/03/2013 - 09:25:59 - [0,007] ----D C:\ProgramData\Mozilla O43 - CFD: 23/02/2013 - 17:42:10 - [325,524] ----D C:\ProgramData\Norton O43 - CFD: 23/02/2013 - 17:41:13 - [3,428] ----D C:\ProgramData\NortonInstaller O43 - CFD: 28/03/2013 - 10:39:23 - [96,541] ----D C:\ProgramData\Package Cache O43 - CFD: 07/02/2013 - 07:01:14 - [0,041] ----D C:\ProgramData\PRICache O43 - CFD: 10/04/2013 - 22:32:24 - [0,004] ----D C:\ProgramData\regid.1991-06.com.microsoft O43 - CFD: 24/08/2012 - 19:07:02 - [0] ----D C:\ProgramData\Roaming O43 - CFD: 12/05/2013 - 09:08:18 - [363,914] ----D C:\ProgramData\Samsung O43 - CFD: 26/07/2012 - 08:22:08 - [0] --H-D C:\ProgramData\Start Menu O43 - CFD: 28/02/2013 - 21:06:03 - [0,000] ----D C:\ProgramData\Sun O43 - CFD: 26/07/2012 - 08:22:08 - [0] --H-D C:\ProgramData\Templates O43 - CFD: 12/05/2013 - 14:40:05 - [0,175] ----D C:\ProgramData\WinClon O43 - CFD: 23/02/2013 - 21:55:37 - [3,239] ----D C:\Users\PC\AppData\Roaming\Adobe O43 - CFD: 19/04/2013 - 13:54:37 - [-418,130] ----D C:\Users\PC\AppData\Roaming\Apple Computer O43 - CFD: 12/05/2013 - 15:27:32 - [27,518] ----D C:\Users\PC\AppData\Roaming\Azureus =>P2P.Azureus O43 - CFD: 12/05/2013 - 15:27:32 - [1,344] ----D C:\Users\PC\AppData\Roaming\EMBIRD64 O43 - CFD: 17/04/2013 - 22:29:17 - [0,005] ----D C:\Users\PC\AppData\Roaming\EMBIRD_STUDIO_(64-bit) O43 - CFD: 24/02/2013 - 20:20:12 - [0] ----D C:\Users\PC\AppData\Roaming\Identities O43 - CFD: 28/03/2013 - 17:46:59 - [0] ----D C:\Users\PC\AppData\Roaming\InstallShield O43 - CFD: 25/01/2013 - 04:04:36 - [0,001] ----D C:\Users\PC\AppData\Roaming\Intel O43 - CFD: 07/05/2013 - 12:54:07 - [0,001] ----D C:\Users\PC\AppData\Roaming\Intel Corporation O43 - CFD: 29/01/2013 - 09:51:36 - [0,063] ----D C:\Users\PC\AppData\Roaming\Macromedia O43 - CFD: 13/05/2013 - 08:24:23 - [0,002] ----D C:\Users\PC\AppData\Roaming\Malwarebytes O43 - CFD: 21/04/2013 - 08:44:53 - [26,739] -S--D C:\Users\PC\AppData\Roaming\Microsoft O43 - CFD: 23/02/2013 - 16:50:43 - [24,406] ----D C:\Users\PC\AppData\Roaming\Mozilla O43 - CFD: 23/02/2013 - 23:05:15 - [0,000] ----D C:\Users\PC\AppData\Roaming\MTMahjongAIR.A08BAD4CD323DD6E08EB7713FBC9B2807D884B67.1 O43 - CFD: 12/05/2013 - 15:27:32 - [0,032] ----D C:\Users\PC\AppData\Roaming\PhotoScape O43 - CFD: 23/02/2013 - 21:53:46 - [0,055] ----D C:\Users\PC\AppData\Local\Adobe O43 - CFD: 24/02/2013 - 10:00:19 - [0] ----D C:\Users\PC\AppData\Local\Apple O43 - CFD: 06/03/2013 - 19:44:44 - [46,268] ----D C:\Users\PC\AppData\Local\Apple Computer O43 - CFD: 25/01/2013 - 04:04:35 - [0] ----D C:\Users\PC\AppData\Local\Application Data O43 - CFD: 08/05/2013 - 13:01:08 - [8,473] ----D C:\Users\PC\AppData\Local\Diagnostics O43 - CFD: 11/05/2013 - 20:56:32 - [2,687] ----D C:\Users\PC\AppData\Local\ElevatedDiagnostics O43 - CFD: 25/01/2013 - 04:04:35 - [0] ----D C:\Users\PC\AppData\Local\Historique O43 - CFD: 06/05/2013 - 19:09:22 - [0,012] ----D C:\Users\PC\AppData\Local\HP O43 - CFD: 23/02/2013 - 21:53:12 - [0] ----D C:\Users\PC\AppData\Local\Macromedia O43 - CFD: 08/04/2013 - 21:49:51 - [245,263] ----D C:\Users\PC\AppData\Local\Microsoft O43 - CFD: 23/02/2013 - 16:50:24 - [6,729] ----D C:\Users\PC\AppData\Local\Mozilla O43 - CFD: 12/05/2013 - 15:25:51 - [295,208] ----D C:\Users\PC\AppData\Local\Packages O43 - CFD: 13/05/2013 - 08:23:40 - [0] ----D C:\Users\PC\AppData\Local\Programs O43 - CFD: 28/03/2013 - 11:10:50 - [0,000] ----D C:\Users\PC\AppData\Local\Samsung O43 - CFD: 13/05/2013 - 22:50:15 - [0,000] ----D C:\Users\PC\AppData\Local\Temp O43 - CFD: 25/01/2013 - 04:04:35 - [0] ----D C:\Users\PC\AppData\Local\Temporary Internet Files O43 - CFD: 25/01/2013 - 04:04:38 - [0] ----D C:\Users\PC\AppData\Local\VirtualStore O43 - CFD: 26/07/2012 - 09:13:00 - [0,004] R---D C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 26/07/2012 - 09:13:00 - [0,001] R---D C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 17/04/2013 - 22:29:17 - [0,000] R---D C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 07/03/2013 - 12:08:46 - [0] ----D C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games O43 - CFD: 26/07/2012 - 09:13:00 - [0,000] ----D C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 17/04/2013 - 22:29:17 - [0,000] R---D C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 26/07/2012 - 09:13:00 - [0,005] R---D C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools ~ Program Folder: 110 Scanned in 00mn 00s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.38C0D42540ADBAB7ACB2AE2D033538F4] - 13/05/2013 - 18:12:08 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1463448] O44 - LFC:[MD5.17E6FCC08D1C9211BB349890C7272EDE] - 13/05/2013 - 08:54:02 ---A- . (...) -- C:\Windows\SysNative\PerfStringBackup.INI [1793362] O44 - LFC:[MD5.6112AD483F3B8EB0BBF4180E72557E3F] - 13/05/2013 - 08:54:02 ---A- . (...) -- C:\Windows\SysNative\perfc009.dat [132614] O44 - LFC:[MD5.AAD97C2035BCB8847E808E6ED3A4FCEE] - 13/05/2013 - 08:54:02 ---A- . (...) -- C:\Windows\SysNative\perfc00C.dat [155650] O44 - LFC:[MD5.AC7F07AEA252F2954C1A01AB35758053] - 13/05/2013 - 08:54:02 ---A- . (...) -- C:\Windows\SysNative\perfh009.dat [710244] O44 - LFC:[MD5.663802563B7A0F044D034F1193E32EBE] - 13/05/2013 - 08:54:02 ---A- . (...) -- C:\Windows\SysNative\perfh00C.dat [800978] O44 - LFC:[MD5.17E6FCC08D1C9211BB349890C7272EDE] - 13/05/2013 - 08:54:02 RSHAD . (...) -- C:\Windows\System32\PerfStringBackup.INI [1793362] O44 - LFC:[MD5.6112AD483F3B8EB0BBF4180E72557E3F] - 13/05/2013 - 08:54:02 RSHAD . (...) -- C:\Windows\System32\perfc009.dat [132614] O44 - LFC:[MD5.AAD97C2035BCB8847E808E6ED3A4FCEE] - 13/05/2013 - 08:54:02 RSHAD . (...) -- C:\Windows\System32\perfc00C.dat [155650] O44 - LFC:[MD5.AC7F07AEA252F2954C1A01AB35758053] - 13/05/2013 - 08:54:02 RSHAD . (...) -- C:\Windows\System32\perfh009.dat [710244] O44 - LFC:[MD5.663802563B7A0F044D034F1193E32EBE] - 13/05/2013 - 08:54:02 RSHAD . (...) -- C:\Windows\System32\perfh00C.dat [800978] O44 - LFC:[MD5.F002E1722D67EBBFC300C4BE6B33E358] - 13/05/2013 - 08:48:41 -S-A- . (...) -- C:\Windows\bootstat.dat [67584] O44 - LFC:[MD5.0BB97D43299910CBFBA59C461B99B910] - 13/05/2013 - 08:24:11 RSHAD . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [25928] O44 - LFC:[MD5.B3080FE4A278B4BB25F69CE9B80A4C71] - 13/05/2013 - 07:05:59 ---A- . (...) -- C:\AdwCleaner[S1].txt [2909] O44 - LFC:[MD5.82ABACA08CC446E1C28553C5DEF66D18] - 12/05/2013 - 22:10:08 ---A- . (...) -- C:\AdwCleaner[R1].txt [2710] O44 - LFC:[MD5.E39C6CA5728F70C879CFAE941757422B] - 12/05/2013 - 16:35:35 ---A- . (...) -- C:\Windows\PFRO.log [15718] O44 - LFC:[MD5.DA63AFD6ED830F8C8F1719F7CA6F7ACD] - 12/05/2013 - 16:10:27 ---A- . (...) -- C:\Windows\password.klc [220] O44 - LFC:[MD5.A787C54A1515CEDB4C22E44A0D23C168] - 12/05/2013 - 14:54:09 ---A- . (...) -- C:\IFRToolLog.txt [7965] O44 - LFC:[MD5.44A98781564252A03C968DA19D915EB3] - 07/05/2013 - 14:04:07 ---A- . (...) -- C:\Windows\setupact.log [29822] ~ Files: 19 Scanned in 00mn 02s ---\\ Derniers fichiers créés dans Windows Prefetcher (O45) O45 - LFCP:[MD5.FE3EAE49A6D3AF584B71878D6887205A] - 12/05/2013 - 21:25:55 ---A- - C:\Windows\Prefetch\NOTEPAD.EXE-F0516D55.pf O45 - LFCP:[MD5.77205FDAFE296817D77ABE7710E678F6] - 12/05/2013 - 21:28:53 ---A- - C:\Windows\Prefetch\PCCONFIGX64.EXE-72046ADF.pf O45 - LFCP:[MD5.E52BA14E5373D4314D89E7D00FECF5BF] - 12/05/2013 - 21:31:36 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-1D955551.pf O45 - LFCP:[MD5.D20FB08A9659434270EF5488CEF44009] - 12/05/2013 - 21:31:36 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-9656C949.pf O45 - LFCP:[MD5.5D4E7686BFFD22A31D4A4DC540FDBDE5] - 12/05/2013 - 21:32:36 ---A- - C:\Windows\Prefetch\CHARGEPCCONFIG.EXE-9B606107.pf O45 - LFCP:[MD5.BAF565E2C58A25AF3F55E406235BA97C] - 12/05/2013 - 21:44:41 ---A- - C:\Windows\Prefetch\CHARGEPCCONFIG.EXE-2C8E374F.pf O45 - LFCP:[MD5.7716ED030F6637FC67682B48CF84AED1] - 12/05/2013 - 21:47:01 ---A- - C:\Windows\Prefetch\ZHPDIAG2.EXE-2B315FE5.pf O45 - LFCP:[MD5.479A6ACE632D58342F1E3E1C32F5D6AB] - 12/05/2013 - 21:47:01 ---A- - C:\Windows\Prefetch\ZHPDIAG2.TMP-9D21D372.pf O45 - LFCP:[MD5.05071731F3831EC33EC4CB58DEBA4FC6] - 12/05/2013 - 21:56:28 ---A- - C:\Windows\Prefetch\APPSUPDATER.EXE-C8083340.pf O45 - LFCP:[MD5.EA22D066677146CC428AC5FA1005F846] - 12/05/2013 - 22:23:36 ---A- - C:\Windows\Prefetch\DEFRAG.EXE-22AD8A37.pf O45 - LFCP:[MD5.8FEBEDF0146B50714746A0564483515E] - 12/05/2013 - 23:49:47 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-2F8F8529.pf O45 - LFCP:[MD5.DDAF7BA218AD19F9DFF3BCE5AA8C1128] - 12/05/2013 - 23:49:47 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-8FFE84E1.pf O45 - LFCP:[MD5.8A953BE8BEF9E980BEC6F4A2C1C4176F] - 13/05/2013 - 03:00:01 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-EBEFB068.pf O45 - LFCP:[MD5.3C2ABC41B09D77D295B80324B4F73EC1] - 13/05/2013 - 03:00:10 ---A- - C:\Windows\Prefetch\NGEN.EXE-383F81D5.pf O45 - LFCP:[MD5.31C754E7E43DD5ABCE380E63AE0DB4BF] - 13/05/2013 - 03:00:10 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-8C5E4517.pf O45 - LFCP:[MD5.89924312813834CA7BB5DE0136EAFAFD] - 13/05/2013 - 03:00:10 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-3C5D03F7.pf O45 - LFCP:[MD5.7AA5CA119D0C90FAAE2C87795B343E88] - 13/05/2013 - 03:00:11 ---A- - C:\Windows\Prefetch\NGEN.EXE-A8DBB043.pf O45 - LFCP:[MD5.9B1AB59ADCFF3F4947028DD4B1924F93] - 13/05/2013 - 03:00:12 ---A- - C:\Windows\Prefetch\NGENTASK.EXE-CD4E002C.pf O45 - LFCP:[MD5.4E347855703B8BC793A3F996DB7577BB] - 13/05/2013 - 03:00:13 ---A- - C:\Windows\Prefetch\NGENTASK.EXE-4DB88ADA.pf O45 - LFCP:[MD5.60930456A71D6868A692831CA01F65A0] - 13/05/2013 - 03:00:26 ---A- - C:\Windows\Prefetch\AITSTATIC.EXE-25CAEEE0.pf O45 - LFCP:[MD5.85925270FA34288B9101941CEC16CCB7] - 13/05/2013 - 07:05:57 ---A- - C:\Windows\Prefetch\ADWCLEANER.EXE-43E1F886.pf O45 - LFCP:[MD5.41D97295D87EE2241C46497B518C4D1E] - 13/05/2013 - 07:36:25 ---A- - C:\Windows\Prefetch\CONTROL.EXE-5BCB0217.pf O45 - LFCP:[MD5.334BD9DBBCC824B54992B77E4D8F723D] - 13/05/2013 - 07:36:25 ---A- - C:\Windows\Prefetch\Op-EXPLORER.EXE-03C49D11-000000F5.pf O45 - LFCP:[MD5.7F93F3B3442E4C6EE0B9D8C95D944C55] - 13/05/2013 - 07:36:38 ---A- - C:\Windows\Prefetch\MMC.EXE-17F9D1FC.pf O45 - LFCP:[MD5.BB09751DF766D9BD7AFA83496A50088A] - 13/05/2013 - 07:38:53 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-5D09CA10.pf O45 - LFCP:[MD5.DF324E9FBD9FF06B2DE1CB47B74E92FD] - 13/05/2013 - 07:39:55 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-42B82BF4.pf O45 - LFCP:[MD5.3C3CB94C6002393CEE3A0406B9BB0094] - 13/05/2013 - 07:44:26 ---A- - C:\Windows\Prefetch\PHOTOSCAPE.EXE-CCF5444F.pf O45 - LFCP:[MD5.040BF2E145610C54689535307D837CA2] - 13/05/2013 - 07:44:26 ---A- - C:\Windows\Prefetch\SPLWOW64.EXE-853292E2.pf O45 - LFCP:[MD5.6FF02D02BABE60798F83720C5382F5B8] - 13/05/2013 - 07:47:05 ---A- - C:\Windows\Prefetch\WINWORD.EXE-2437DA78.pf O45 - LFCP:[MD5.1C7E2574B2FDB9430EABA4F1B3A0B9BC] - 13/05/2013 - 07:47:08 ---A- - C:\Windows\Prefetch\RUNTIMEBROKER.EXE-17E2786F.pf O45 - LFCP:[MD5.7DCAFA51A59DB5CF0D054C2829F4C904] - 13/05/2013 - 07:49:01 ---A- - C:\Windows\Prefetch\EXCEL.EXE-FC85DF63.pf O45 - LFCP:[MD5.9D5706D61CD6D640FBC00A8AC4EB1637] - 13/05/2013 - 07:56:17 ---A- - C:\Windows\Prefetch\PCCONFIGX64.EXE-8984BAE7.pf O45 - LFCP:[MD5.AE0FCE5AADA4B661F5AE9E0180BD46E0] - 13/05/2013 - 08:00:57 ---A- - C:\Windows\Prefetch\IWRAP.EXE-93ABC663.pf O45 - LFCP:[MD5.250540F46E9690D8B21360D355A28A51] - 13/05/2013 - 08:10:17 ---A- - C:\Windows\Prefetch\MDNSRESPONDER.EXE-EC333707.pf O45 - LFCP:[MD5.E91AB2B29339FE22D2658496D199AB1D] - 13/05/2013 - 08:10:22 ---A- - C:\Windows\Prefetch\HELPPANE.EXE-5A92E3D5.pf O45 - LFCP:[MD5.B8F34E249C79A3F45321A7D8A20EDAC1] - 13/05/2013 - 08:10:47 ---A- - C:\Windows\Prefetch\USERACCOUNTCONTROLSETTINGS.EX-550E3008.pf O45 - LFCP:[MD5.B68FDEEBCFAC83826323AE5B0929DB8E] - 13/05/2013 - 08:10:52 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-7FA90189.pf O45 - LFCP:[MD5.4CF34FCE043AEBF29FA17C8B70DE0166] - 13/05/2013 - 08:10:52 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-ED34D77D.pf O45 - LFCP:[MD5.9EA9D8E523820DB559238A7B8B8CFE21] - 13/05/2013 - 08:12:02 ---A- - C:\Windows\Prefetch\APPLEMOBILEDEVICESERVICE.EXE-CDAEF2A9.pf O45 - LFCP:[MD5.74380C45419BB5D83E6C4103A19A3493] - 13/05/2013 - 08:12:02 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-D248379B.pf O45 - LFCP:[MD5.639319857C4A0E4A191917769C230974] - 13/05/2013 - 08:12:02 ---A- - C:\Windows\Prefetch\SPOOLSV.EXE-AC422BB0.pf O45 - LFCP:[MD5.B94F8174275E79B29F3EB4E7E16A2A9E] - 13/05/2013 - 08:12:02 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-9249A1CA.pf O45 - LFCP:[MD5.46F97682B6FC8DBC418834FA02B26646] - 13/05/2013 - 08:12:02 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-A2E8866A.pf O45 - LFCP:[MD5.D905B33EA33C2746E0FD35F3E4AF981C] - 13/05/2013 - 08:12:02 ---A- - C:\Windows\Prefetch\TASKHOSTEX.EXE-7356AAC0.pf O45 - LFCP:[MD5.CA0791DF4B9DB545D931470E33E2B3FC] - 13/05/2013 - 08:12:02 ---A- - C:\Windows\Prefetch\WLANEXT.EXE-AD1A4F51.pf O45 - LFCP:[MD5.4ACC6BF20F08AA13C64FA5D471AF439C] - 13/05/2013 - 08:14:05 ---A- - C:\Windows\Prefetch\PICKERHOST.EXE-03F09186.pf O45 - LFCP:[MD5.D6492BA6AACA92A1DCE1EEEA59F939E9] - 13/05/2013 - 08:16:27 ---A- - C:\Windows\Prefetch\APPLEPHOTOSTREAMS.EXE-F4825399.pf O45 - LFCP:[MD5.466269C7557575AB8F4A72F7852073CC] - 13/05/2013 - 08:17:22 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-E6E6216F.pf O45 - LFCP:[MD5.3647A4360AE2709913945500711801D7] - 13/05/2013 - 08:23:48 ---A- - C:\Windows\Prefetch\MBAM-SETUP-1.75.0.1300.EXE-87744B57.pf O45 - LFCP:[MD5.45378B121B9525809E05F19FE08157DE] - 13/05/2013 - 08:23:49 ---A- - C:\Windows\Prefetch\MBAM-SETUP-1.75.0.1300.TMP-6ED79E00.pf O45 - LFCP:[MD5.B0E3D57E02AA0DA6037BDFE8BDE47BB4] - 13/05/2013 - 08:24:11 ---A- - C:\Windows\Prefetch\REGSVR32.EXE-E1DBB6D8.pf O45 - LFCP:[MD5.DCF87DE5BB7EDB113BC60BA6B854B7E2] - 13/05/2013 - 08:24:42 ---A- - C:\Windows\Prefetch\MBAMSCHEDULER.EXE-E0C395DC.pf O45 - LFCP:[MD5.D36B91BA32B7475B14B62A94AAB7E0E7] - 13/05/2013 - 08:24:43 ---A- - C:\Windows\Prefetch\MBAMGUI.EXE-9FF23AE2.pf O45 - LFCP:[MD5.AC3C6EAD9D97F9299D5516AF2D9AE4E9] - 13/05/2013 - 08:24:43 ---A- - C:\Windows\Prefetch\MBAMSERVICE.EXE-5C46DB66.pf O45 - LFCP:[MD5.B10D54EA2A631BA585558BF0F8C9F24F] - 13/05/2013 - 08:25:27 ---A- - C:\Windows\Prefetch\REGSVR32.EXE-3290E8FC.pf O45 - LFCP:[MD5.BCA40E917CD6E004B993EF5B955ACA12] - 13/05/2013 - 08:25:37 ---A- - C:\Windows\Prefetch\MBAM.EXE-125A28F9.pf O45 - LFCP:[MD5.10C6F9E3A9593C53949902D2032187D2] - 13/05/2013 - 08:41:25 ---A- - C:\Windows\Prefetch\THUMBNAILEXTRACTIONHOST.EXE-D421C41C.pf O45 - LFCP:[MD5.3D53E25F3C2ECD292A0B3CA399B50B80] - 13/05/2013 - 08:44:48 ---A- - C:\Windows\Prefetch\NOTEPAD.EXE-1A4CC1C3.pf O45 - LFCP:[MD5.B6437E4CC99EC5F97FF218784DC3D8EB] - 13/05/2013 - 08:46:21 ---A- - C:\Windows\Prefetch\EASYSETTINGSCMDSERVER.EXE-1B8CA773.pf O45 - LFCP:[MD5.465E2657188C1D5465367F9731FFFD96] - 13/05/2013 - 08:46:22 ---A- - C:\Windows\Prefetch\PfSvPerfStats.bin O45 - LFCP:[MD5.6B39072CF20CBA9E1F198AFBA07CD86D] - 13/05/2013 - 08:47:29 ---A- - C:\Windows\Prefetch\IGFXSRVC.EXE-F41E6E8E.pf O45 - LFCP:[MD5.9F2C4121D330DA83C5A5E258088F488B] - 13/05/2013 - 08:47:29 ---A- - C:\Windows\Prefetch\MOBILEAPSET.EXE-2C67F0CE.pf O45 - LFCP:[MD5.BBF98059F80BFA68EB142BB86DC996FD] - 13/05/2013 - 08:47:29 ---A- - C:\Windows\Prefetch\SEARCHINDEXER.EXE-EF8503D3.pf O45 - LFCP:[MD5.1F1136B2B02F544AC6244F6CD272650E] - 13/05/2013 - 08:47:29 ---A- - C:\Windows\Prefetch\VENDORAPIRUN64.EXE-358606D0.pf O45 - LFCP:[MD5.A54C7A1338EF35F1ECEE4719E539852A] - 13/05/2013 - 08:47:31 ---A- - C:\Windows\Prefetch\APPVLP.EXE-69CCA9BE.pf O45 - LFCP:[MD5.2CE2050BB0E5B04274BDB5D77384C946] - 13/05/2013 - 08:47:41 ---A- - C:\Windows\Prefetch\CSISYNCCLIENT.EXE-5C0F4377.pf O45 - LFCP:[MD5.C50EFECB2726209B66324D417C309765] - 13/05/2013 - 08:47:42 ---A- - C:\Windows\Prefetch\MSOSYNC.EXE-B5BE2C92.pf O45 - LFCP:[MD5.8E2DDE22521FA7F17ACD045745F1CA93] - 13/05/2013 - 08:48:49 ---A- - C:\Windows\Prefetch\PCAUI.EXE-A64155AC.pf O45 - LFCP:[MD5.0D5F4D3A5FD4BF09809AE18A3A6D5533] - 13/05/2013 - 08:48:51 ---A- - C:\Windows\Prefetch\MPCMDRUN.EXE-6520183E.pf O45 - LFCP:[MD5.8E1214E93A736B34DE9AB377443E65E6] - 13/05/2013 - 08:48:59 ---A- - C:\Windows\Prefetch\BTHSAMPPALSERVICE.EXE-604575E6.pf O45 - LFCP:[MD5.BA41C313976FE9B060E4BA95374D28C5] - 13/05/2013 - 08:48:59 ---A- - C:\Windows\Prefetch\BTHSSECURITYMGR.EXE-76612BD0.pf O45 - LFCP:[MD5.8FB3C128939C1BEDF01DA26497950BC1] - 13/05/2013 - 08:50:20 ---A- - C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-10E4267C.pf O45 - LFCP:[MD5.A8B6BB54784AA95DA364248E1BAEC813] - 13/05/2013 - 08:50:58 ---A- - C:\Windows\Prefetch\WMIADAP.EXE-7D63BB4C.pf O45 - LFCP:[MD5.5CC0BB5C64B705C1E577E80E55C9FEDE] - 13/05/2013 - 09:12:38 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-F68363C4.pf O45 - LFCP:[MD5.4724306A447FE4AFA596B8AACB488D34] - 13/05/2013 - 09:13:37 ---A- - C:\Windows\Prefetch\SYMERR.EXE-601774F4.pf O45 - LFCP:[MD5.229B40C76B96E9BBE1903BAAA9D3C986] - 13/05/2013 - 09:15:41 ---A- - C:\Windows\Prefetch\ASOELNCH.EXE-D647F103.pf O45 - LFCP:[MD5.E900B596DDB76C0D044E74B457596A67] - 13/05/2013 - 09:16:58 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-D687BE54.pf O45 - LFCP:[MD5.552B543AC9C39AE534BA1785363B776A] - 13/05/2013 - 10:01:48 ---A- - C:\Windows\Prefetch\SCHTASKS.EXE-BA1E321E.pf O45 - LFCP:[MD5.D462153866A32929E9AF21093385609F] - 13/05/2013 - 10:32:01 ---A- - C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-C6CFE2A8.pf O45 - LFCP:[MD5.73349F870E0E1FDD2E5C59199D1A1F42] - 13/05/2013 - 12:11:17 ---A- - C:\Windows\Prefetch\CLTRT.EXE-45D70627.pf O45 - LFCP:[MD5.D28E37A6EBF535C81B3278C826A33F27] - 13/05/2013 - 12:11:32 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-29D61DAB.pf O45 - LFCP:[MD5.FFCE90C78BD49CB128963E709C98779D] - 13/05/2013 - 12:40:50 ---A- - C:\Windows\Prefetch\SNDVOL.EXE-276AC160.pf O45 - LFCP:[MD5.82A06A77E5BF6F19877B42C33C3E98D3] - 13/05/2013 - 13:25:44 ---A- - C:\Windows\Prefetch\INTELCOLORMODESET.EXE-B8538D59.pf O45 - LFCP:[MD5.F3ADD28550F93A337D7523C67854971D] - 13/05/2013 - 13:26:07 ---A- - C:\Windows\Prefetch\MSIEXEC.EXE-7D20CFB0.pf O45 - LFCP:[MD5.85A3BE5E66DA8F9994DCBF436C0836A2] - 13/05/2013 - 14:28:49 ---A- - C:\Windows\Prefetch\BLUETOOTHCONTROL64.EXE-103C6532.pf O45 - LFCP:[MD5.95AFD845BF2777B909D1AA39EEECDDE6] - 13/05/2013 - 14:28:49 ---A- - C:\Windows\Prefetch\SETTOUCHPADCONTROL64.EXE-CAF017E2.pf O45 - LFCP:[MD5.2E1B09A0EDB7EE6085A479D1BB314604] - 13/05/2013 - 14:28:49 ---A- - C:\Windows\Prefetch\SSETTINGS.EXE-2AC46236.pf O45 - LFCP:[MD5.576353194600D51A1B89BB36D7E9C6F0] - 13/05/2013 - 14:29:28 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-E41090C3.pf O45 - LFCP:[MD5.FB1C78129E436E6D56484E6FDF7B0042] - 13/05/2013 - 14:29:38 ---A- - C:\Windows\Prefetch\WWAHOST.EXE-AF977791.pf O45 - LFCP:[MD5.941F47969C441AD1A5F673E58BCB9A50] - 13/05/2013 - 14:31:18 ---A- - C:\Windows\Prefetch\TIWORKER.EXE-D3BFD41F.pf O45 - LFCP:[MD5.C0D79FB68EF9C8AFEC2F3F6FF296AE11] - 13/05/2013 - 14:31:18 ---A- - C:\Windows\Prefetch\TRUSTEDINSTALLER.EXE-B018CCBF.pf O45 - LFCP:[MD5.3443990DB03F994FAD3E9F47AC4F6CB0] - 13/05/2013 - 14:35:09 ---A- - C:\Windows\Prefetch\Layout.ini O45 - LFCP:[MD5.BE27D281FBEE372EFE66EADE494810EC] - 13/05/2013 - 14:47:00 ---A- - C:\Windows\Prefetch\THUMBNAILEXTRACTIONHOST.EXE-C3FB8861.pf O45 - LFCP:[MD5.FE0C97562324DA2CF1C188AFEF124537] - 13/05/2013 - 15:10:00 ---A- - C:\Windows\Prefetch\IGFXEXT.EXE-B04096D5.pf O45 - LFCP:[MD5.ADA761E47E1FD9404CCD9242137D1F70] - 13/05/2013 - 15:46:44 ---A- - C:\Windows\Prefetch\WMPLAYER.EXE-B0AD61F0.pf O45 - LFCP:[MD5.9444AEAD798D128117610FF6F203540D] - 13/05/2013 - 15:57:19 ---A- - C:\Windows\Prefetch\HOTFIX.EXE-4B2FE0BF.pf O45 - LFCP:[MD5.916CD553FAD46E5E9B4C2FC6BE0FB6A3] - 13/05/2013 - 15:58:27 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-47481F1B.pf O45 - LFCP:[MD5.225FAAFBB4BA2174C0DDCA821251CC91] - 13/05/2013 - 15:58:27 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-58294553.pf O45 - LFCP:[MD5.D2A104ED2F2DED20D32EF2A5B2776AEB] - 13/05/2013 - 16:46:49 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-05B3EDF6.pf O45 - LFCP:[MD5.6F413B252AAE161B16577F925F0DCBA5] - 13/05/2013 - 16:46:58 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-F2C7AEBC.pf O45 - LFCP:[MD5.562279F9E730C091563AC78227C6EAFD] - 13/05/2013 - 18:02:06 ---A- - C:\Windows\Prefetch\SETUP_WM.EXE-5D2609E7.pf O45 - LFCP:[MD5.DEFB9952EB4550A99EA6AFE6CD03BC66] - 13/05/2013 - 18:32:39 ---A- - C:\Windows\Prefetch\TASKENG.EXE-23205583.pf O45 - LFCP:[MD5.0C7A191F20D8D42B9C2EB522742781B1] - 13/05/2013 - 18:42:33 ---A- - C:\Windows\Prefetch\MAVINJECT32.EXE-A39D6437.pf O45 - LFCP:[MD5.586E9EF0E12A3D514B64603BA32564B6] - 13/05/2013 - 19:57:54 ---A- - C:\Windows\Prefetch\EXPLORER.EXE-03C49D11.pf O45 - LFCP:[MD5.AA918D6DE7C8632A6A269C8A1A83D1D5] - 13/05/2013 - 19:58:02 ---A- - C:\Windows\Prefetch\HOTFIX1.EXE-D12BC44B.pf O45 - LFCP:[MD5.9D9F3BBF11299951873B75AEF2C68544] - 13/05/2013 - 19:58:12 ---A- - C:\Windows\Prefetch\CCSVCHST.EXE-9D91D9EF.pf O45 - LFCP:[MD5.E80D039AF5C2D2698D6D79C64927AFE2] - 13/05/2013 - 19:58:12 ---A- - C:\Windows\Prefetch\CCSVCHST.EXE-9D91D9F0.pf O45 - LFCP:[MD5.69A3AB56FD740427DCC175AB925B6C64] - 13/05/2013 - 19:58:21 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-00AD1665.pf O45 - LFCP:[MD5.B80671CB6D5A848EF7CE04FD5A02D870] - 13/05/2013 - 20:04:10 ---A- - C:\Windows\Prefetch\CLTLMH.EXE-F83AE38E.pf O45 - LFCP:[MD5.F76FA7EDCA5ECE20329771BE75BFE76B] - 13/05/2013 - 20:04:10 ---A- - C:\Windows\Prefetch\CONHOST.EXE-F98A1078.pf O45 - LFCP:[MD5.187D62BD754924D9A4AEE6B8D066B4AF] - 13/05/2013 - 20:10:27 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-985C34E6.pf O45 - LFCP:[MD5.11C84DFCCD8F90D402DE5F00101BF3DF] - 13/05/2013 - 20:17:35 ---A- - C:\Windows\Prefetch\AUDIODG.EXE-9848A323.pf O45 - LFCP:[MD5.DA27E584760CE3D8E7D7D9B81E61B7AA] - 13/05/2013 - 20:51:20 ---A- - C:\Windows\Prefetch\BACKGROUNDTRANSFERHOST.EXE-E15DD0B7.pf O45 - LFCP:[MD5.DAC45321D4B5F13BDCD04F0E4C77CA7D] - 13/05/2013 - 20:57:41 ---A- - C:\Windows\Prefetch\MAHJONG TIME EON.EXE-7AA5E36D.pf O45 - LFCP:[MD5.3E1AADFF3825BA07A8DB2C53BC6E8CB1] - 13/05/2013 - 21:30:43 ---A- - C:\Windows\Prefetch\PING.EXE-167FE968.pf O45 - LFCP:[MD5.A5560C1C885CFEE1ACC7085859D52EBA] - 13/05/2013 - 22:05:22 ---A- - C:\Windows\Prefetch\SETTINGSYNCHOST.EXE-DD400067.pf O45 - LFCP:[MD5.CAE4A48810F6C863603A1BFE62FB65E5] - 13/05/2013 - 22:36:25 ---A- - C:\Windows\Prefetch\ZHPDIAG2.EXE-A81D648B.pf O45 - LFCP:[MD5.D6C86AA76186E2D875AF6F9973A9E432] - 13/05/2013 - 22:36:25 ---A- - C:\Windows\Prefetch\ZHPDIAG2.TMP-344298F2.pf O45 - LFCP:[MD5.45B68CB9AF74BE090256BC0F0D50D9BF] - 13/05/2013 - 22:36:32 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-CE99ACA7.pf O45 - LFCP:[MD5.3CA11804F36815CAB1A6EF68E4EB2246] - 13/05/2013 - 22:36:57 ---A- - C:\Windows\Prefetch\CMD.EXE-2EB3E6E2.pf O45 - LFCP:[MD5.7CC10429C168D98F3A51A74F655656E9] - 13/05/2013 - 22:36:59 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-210D3DBE.pf O45 - LFCP:[MD5.604AFC2D6C9D7A8B9CC5E3BB6D0EF68A] - 13/05/2013 - 22:37:06 ---A- - C:\Windows\Prefetch\SUBINACL.EXE-D08B2113.pf O45 - LFCP:[MD5.466314A96B8F0CFE83925A292CCD32C1] - 13/05/2013 - 22:45:50 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-E6B64B6C.pf O45 - LFCP:[MD5.C4202992EA819AE5DD481C3830163B34] - 13/05/2013 - 22:45:55 ---A- - C:\Windows\Prefetch\ZHPHEP.EXE-8162C2FA.pf O45 - LFCP:[MD5.0D37E8498144B2A40D01B4B6B37D2C55] - 13/05/2013 - 22:46:19 ---A- - C:\Windows\Prefetch\ZHPFIX.EXE-AFDB3DAC.pf O45 - LFCP:[MD5.4E40046AD7F2C071F2614A0AA84BDF92] - 13/05/2013 - 22:47:25 ---A- - C:\Windows\Prefetch\CMD.EXE-CD245F9E.pf O45 - LFCP:[MD5.51CF4AABC9DF3357B2CE9DB29123A665] - 13/05/2013 - 22:47:38 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-233DCAA0.pf O45 - LFCP:[MD5.CE1321C4D9860F9B793644552933EB65] - 13/05/2013 - 22:47:38 ---A- - C:\Windows\Prefetch\REGEDIT.EXE-FA6F6DA2.pf O45 - LFCP:[MD5.694AFE8FC7944093198522047954408F] - 13/05/2013 - 22:47:38 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-69B6023D.pf O45 - LFCP:[MD5.0C705DAF8BDC1188B043C3A1151C523C] - 13/05/2013 - 22:47:38 ---A- - C:\Windows\Prefetch\VSSVC.EXE-206E55B3.pf O45 - LFCP:[MD5.7EC05D04173EB695A98976CD37BC33E9] - 13/05/2013 - 22:47:42 ---A- - C:\Windows\Prefetch\SRTASKS.EXE-29C2E869.pf O45 - LFCP:[MD5.C4141BE11E05457F10C19950FF388DD6] - 13/05/2013 - 22:47:49 ---A- - C:\Windows\Prefetch\WMIAPSRV.EXE-CF150EEA.pf O45 - LFCP:[MD5.8181815019AE34A114B406B7EEE06DE4] - 13/05/2013 - 22:47:49 ---A- - C:\Windows\Prefetch\WMIPRVSE.EXE-BB49B536.pf O45 - LFCP:[MD5.8D29950A9DEB02391F7687B7C1958C6C] - 13/05/2013 - 22:48:11 ---A- - C:\Windows\Prefetch\FIREFOX.EXE-528BC649.pf O45 - LFCP:[MD5.262CE88D2C8CE67F9361A317178FEB47] - 13/05/2013 - 22:48:38 ---A- - C:\Windows\Prefetch\NOTEPAD.EXE-B28CC291.pf O45 - LFCP:[MD5.6A4C810E002C63A9B88CF170ED44E840] - 13/05/2013 - 22:50:25 ---A- - C:\Windows\Prefetch\FLASHPLAYERPLUGIN_11_6_602_16-246084F5.pf O45 - LFCP:[MD5.CABE41C3CED949CD3CF3EDC713C23E4F] - 13/05/2013 - 22:50:25 ---A- - C:\Windows\Prefetch\PLUGIN-CONTAINER.EXE-E510713D.pf O45 - LFCP:[MD5.A0123152AAA9FB3CD0B39ADEB73EBE17] - 13/05/2013 - 22:51:39 ---A- - C:\Windows\Prefetch\CONSENT.EXE-2D674CE4.pf O45 - LFCP:[MD5.4B3ADDBAA1DFE2C05D0187132B3ED6AC] - 13/05/2013 - 22:51:41 ---A- - C:\Windows\Prefetch\ZHPHEP.EXE-5F2753B1.pf O45 - LFCP:[MD5.4C50BD58C8C150737F49974507539240] - 13/05/2013 - 22:51:51 ---A- - C:\Windows\Prefetch\ZHPDIAG.EXE-C7289479.pf O45 - LFCP:[MD5.AAFF233EE0CFD80E33D3A6C2AABB6B18] - 13/05/2013 - 22:52:03 ---A- - C:\Windows\Prefetch\CSCRIPT.EXE-E9FF6526.pf O45 - LFCP:[MD5.2CACF83FC41EC1F1EF6BD58BD3203746] - 13/05/2013 - 22:52:09 ---A- - C:\Windows\Prefetch\PV.EXE-D9D90B9C.pf O45 - LFCP:[MD5.2DBE42F41167BB7951EBC49CC16A9286] - 13/05/2013 - 22:52:10 ---A- - C:\Windows\Prefetch\SPPSVC.EXE-7B160CA5.pf O45 - LFCP:[MD5.8E085DC79623D827E008812323E8AD78] - 13/05/2013 - 22:52:10 ---A- - C:\Windows\Prefetch\WMIPRVSE.EXE-0C8A533A.pf O45 - LFCP:[MD5.5C91CD84714CEF695709AE872F80257C] - 13/05/2013 - 22:52:18 ---A- - C:\Windows\Prefetch\SCHTASKS.EXE-0AD36442.pf O45 - LFCP:[MD5.A5AD8C8B1295E5D8B80C2E82D5DAE381] - 13/05/2013 - 22:52:19 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-5A956D1E.pf ~ Prefetcher: 146 Scanned in 00mn 00s ---\\ Déni du service (Local Security Authority) (O48) O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Fournisseur de sécurité TLS/SSL.) -- C:\Windows\System32\schannel.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Live Security Package.) -- C:\Windows\System32\livessp.dll ~ LSA: 9 Scanned in 00mn 00s ---\\ Contrôle du Safe Boot (CSB) (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\BasicDisplay.sys . (.Microsoft Corporation - Microsoft Basic Display Driver.) -- C:\Windows\System32\Drivers\BasicDisplay.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\BasicRender.sys . (.Microsoft Corporation - Microsoft Basic Render Driver.) -- C:\Windows\System32\Drivers\BasicRender.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dxgkrnl.sys . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\Drivers\dxgkrnl.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\FsDepends.sys . (.Microsoft Corporation - File System Dependency Manager Mini Filter Driver.) -- C:\Windows\System32\Drivers\FsDepends.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\BasicDisplay.sys . (.Microsoft Corporation - Microsoft Basic Display Driver.) -- C:\Windows\System32\Drivers\BasicDisplay.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\BasicRender.sys . (.Microsoft Corporation - Microsoft Basic Render Driver.) -- C:\Windows\System32\Drivers\BasicRender.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dxgkrnl.sys . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\Drivers\dxgkrnl.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\FsDepends.sys . (.Microsoft Corporation - File System Dependency Manager Mini Filter Driver.) -- C:\Windows\System32\Drivers\FsDepends.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (...) -- C:\Windows\System32\Drivers\rdpencdd.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys ~ CSB: 17 Scanned in 00mn 00s ---\\ Trojan Driver Search Data (HKLM) (O52) O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm ~ TDSD: 2 Scanned in 00mn 00s ---\\ Microsoft Control Security Providers (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll ~ MSCP: 2 Scanned in 00mn 00s ---\\ Microsoft Windows Policies System (O55) O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableCursorSuppression"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0 O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 17 Scanned in 00mn 00s ---\\ Microsoft Windows Policies Explorer (O56) O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1 ~ MWPE Keys: 3 Scanned in 00mn 00s ---\\ Liste des Drivers Système (O58) O58 - SDL:[MD5.4F18D4C7EA14F11A7211F60D553C03DB] - 26/07/2012 - 06:00:49 ---A- . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\Drivers\3ware.sys [106736] ~ Drivers: Scanned in 00mn 00s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC: 10/05/2013 - 00:29:23 ---A- C:\Users\PC\Videos\REVENGE Sason 1\revenge.117.recherche.amanda.desesperement.avi [368769508] O61 - LFC: 10/05/2013 - 01:00:02 ---A- C:\Users\PC\AppData\Roaming\Azureus\stats\2013\05\09.dat [27448] =>P2P.Azureus O61 - LFC: 10/05/2013 - 01:03:24 ---A- C:\Users\PC\Videos\REVENGE Sason 1\revenge.118.le.proces.avi [368143562] O61 - LFC: 10/05/2013 - 01:28:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\banips.config.bak [488] =>P2P.Azureus O61 - LFC: 10/05/2013 - 01:36:19 ---A- C:\Users\PC\Videos\REVENGE Sason 1\revenge.119.absolution.avi [368150094] O61 - LFC: 10/05/2013 - 02:08:18 ---A- C:\Users\PC\Videos\REVENGE Sason 1\revenge.120.heritage.avi [369179756] O61 - LFC: 10/05/2013 - 02:41:14 ---A- C:\Users\PC\Videos\REVENGE Sason 1\Revenge.S01E21.FRENCH.LD.DVDRiP.XViD-EPZ.avi [371504548] O61 - LFC: 10/05/2013 - 03:12:52 ---A- C:\Users\PC\Videos\REVENGE Sason 1\Revenge.S01E22.FINAL.FRENCH.LD.DVDRiP.XViD-EPZ.avi [372443292] O61 - LFC: 10/05/2013 - 07:33:53 ---A- C:\Users\PC\AppData\Roaming\Azureus\plugins\azemp\azemp_3.3.12.jar [476539] =>P2P.Azureus O61 - LFC: 10/05/2013 - 07:33:53 ---A- C:\Users\PC\AppData\Roaming\Azureus\plugins\azemp\libmprCanvas_1.3.6.jar [28430] =>P2P.Azureus O61 - LFC: 10/05/2013 - 07:33:53 ---A- C:\Users\PC\AppData\Roaming\Azureus\plugins\azemp\mplayer\config.bak [23] =>P2P.Azureus O61 - LFC: 10/05/2013 - 07:33:53 ---A- C:\Users\PC\AppData\Roaming\Azureus\plugins\azemp\vuzeplayer.exe.bak [4177856] =>P2P.Azureus O61 - LFC: 10/05/2013 - 11:43:54 ---A- C:\Users\PC\AppData\Roaming\Azureus\plugins\azemp\azemp_3.3.12.zip [4564144] =>P2P.Azureus O61 - LFC: 10/05/2013 - 11:43:54 ---A- C:\Users\PC\AppData\Roaming\Azureus\plugins\azemp\mplayer\config [23] =>P2P.Azureus O61 - LFC: 10/05/2013 - 11:43:54 ---A- C:\Users\PC\AppData\Roaming\Azureus\plugins\azemp\plugin.properties_3.3.12 [197] =>P2P.Azureus O61 - LFC: 10/05/2013 - 14:44:56 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\276159BC4FE990A6FEAF5E56AEE644290DFE076C.dat.bak [58953] =>P2P.Azureus O61 - LFC: 10/05/2013 - 14:44:56 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\6CE2451F9D221629FA8C4BFE7CB0520AF9C7D3B9.dat.bak [41780] =>P2P.Azureus O61 - LFC: 10/05/2013 - 14:49:56 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\D9A71DE28D455C1052EEE30D6C5DC19DD48B3E1B.dat.bak [59379] =>P2P.Azureus O61 - LFC: 10/05/2013 - 15:19:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\127D018A1948F00ECD6E30F7F04D8DFF9D3D68F2.dat.bak [58174] =>P2P.Azureus O61 - LFC: 10/05/2013 - 15:19:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\C177295A04F8D93624F5740DEDE37879DE2F7EBA.dat.bak [61496] =>P2P.Azureus O61 - LFC: 10/05/2013 - 15:24:59 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\DBD4CB933062D5533AB99E8A713B233A0A047C32.dat.bak [60934] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:51:01 ---A- C:\Users\PC\AppData\Roaming\Azureus\ipfilter.cache [0] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:52:35 ---A- C:\Users\PC\AppData\Roaming\Azureus\torrents\vampire-diaries-s04e22-vostfr-hdtv.torrent [29308] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:52:37 ---A- C:\Users\PC\AppData\Roaming\Azureus\dht\version.dat [20] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:52:44 ---A- C:\Users\PC\AppData\Roaming\Azureus\torrents\supernatural-s08e22-vostfr-hdtv.torrent [29394] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:52:46 ---A- C:\Users\PC\AppData\Roaming\Azureus\torrents\grey-s-anatomy-s09e23-vostfr-hdtv.torrent [29236] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:52:56 ---A- C:\Users\PC\AppData\Roaming\Azureus\plugins\azupnpav\cd.dat [24919] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\127D018A1948F00ECD6E30F7F04D8DFF9D3D68F2.dat [58174] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\25C8B2BE0E075CC3C15B8BED5CD69113152B5DF1.dat.bak [45384] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\26B8BA6176C2E6BF9CF90E071E2AD21D986E1A75.dat.bak [23038] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\276159BC4FE990A6FEAF5E56AEE644290DFE076C.dat [58953] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\3A4F8730B5B159C2879B7E149FE9A0F50C0E5A4C.dat.bak [45247] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\3BC91136CB1D3B18CDE89C4E6EE8BAD070F26ADD.dat.bak [44722] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\44894276C93E2A990B307FCA7E6DA72FFEAC9652.dat.bak [49549] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\632D9A8C0BD3A4E9691D5DE67B106CFC9141DD6F.dat.bak [43545] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\6CE2451F9D221629FA8C4BFE7CB0520AF9C7D3B9.dat [41781] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\95D1624AE2C134B92509B4A119D03C493A223834.dat.bak [61609] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\A775EF5B270A3E082AC9C212E3F5D5E04F694F5B.dat.bak [50368] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\A9D06881E661983CFAF376BC43958C640C6F3C76.dat.bak [48645] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\AF3C6773EAAB5EC81CAC90399E80F05B430C8647.dat.bak [44541] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\B289EF0CDD0E5428EC001EA0E2F5A7B7FCCA2175.dat.bak [40025] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\C177295A04F8D93624F5740DEDE37879DE2F7EBA.dat [61496] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\D9A71DE28D455C1052EEE30D6C5DC19DD48B3E1B.dat [59379] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\DBD4CB933062D5533AB99E8A713B233A0A047C32.dat [60934] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\E495BD89D16790405570E4925D622ECF278EFF73.dat.bak [39086] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\F01CCDE4CD04A4BA58A2E6305F2C8C808963C118.dat.bak [45862] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\F8DA5321A5FCCFD282155BE75CD32A35421BF643.dat.bak [61984] =>P2P.Azureus O61 - LFC: 10/05/2013 - 18:55:55 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\F93D772044474BDFB50E18A09DFD8E87660B673B.dat.bak [43679] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:27:27 ---A- C:\Users\PC\Videos\The.Vampire.Diaries.S04E22.FASTSUB.VOSTFR.HDTV.XviD-MiND.avi [366254846] O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\06398C61C2F984E05AEA754E90B5DBD00921CF5D.dat.bak [97808] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\0AA71E8AA9791F412C5D830904C7EE30177D4B1D.dat.bak [53585] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\1430DABC08BCC0BC64C4685AFEFD3F7F9867B0C9.dat.bak [41006] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\188667CC5656C9378006B05D3761228467C81F80.dat.bak [51482] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\1C9FCBB790A34B697EAB7DD18C70404F23084C2B.dat.bak [21163] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\26B8BA6176C2E6BF9CF90E071E2AD21D986E1A75.dat [23038] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\27D1B0BC0C76BA1BDC0FCC37543CE8D98871ED1A.dat.bak [42332] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\28554BBE4176285DE66D044B53674FC7BC8110B7.dat.bak [33145] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\299D4642A276496EC6359F6EEF2ED903D45EE70A.dat.bak [55462] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\2F7D10369BA2A8250D07A0F082A5D3C7D4DD1084.dat.bak [53742] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\3037423F264008BC186570F8832948ABBA9DF270.dat.bak [19846] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\34A4D7F9AE66DE031DC6952E5709072F897BD3F6.dat.bak [48035] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\3D49C59683E784C02B0DF70457A7C58A5430C70F.dat.bak [20789] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\4104BC53077E1A7D51E2CEE8DA8C79D7827AC12D.dat.bak [19210] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\44894276C93E2A990B307FCA7E6DA72FFEAC9652.dat [49549] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\46BA02250F40EDC5472DDF2146EEAA480B80B10A.dat.bak [43315] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\4B455799E4B01F1AF21EEA21667061DB071CA7F1.dat.bak [21889] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\4B681E7769D94131B565650000C91081FC31D476.dat.bak [56871] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\4D3B568F71BBE44F7960EDD2AAD08E6595859676.dat.bak [34130] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\66C52D09F24A136463C1CB4B9A6AFFC4751435C8.dat.bak [21649] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\6FC66D0AEF5A2D2FA988C329C23BBCD18901F63D.dat.bak [61089] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\70A2B8A67D5199C8D583C359FE3B7B542BA521EC.dat.bak [56661] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\898FC97AFC18282CC0494A10BB585FAB5913C01E.dat.bak [18254] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\9202ECDEF24A13B77BAE660BE2FA2B693B372053.dat.bak [42903] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\9953ED8D72A70D6EF62C39DEDF5748744AAF87E1.dat.bak [36786] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\A083CAE5A08BF3AA6FBAE12DFC1F9E9CB332CDD0.dat.bak [18325] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\B289EF0CDD0E5428EC001EA0E2F5A7B7FCCA2175.dat [40025] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\B6308469C2F73EB04436CED3B597FB0FFDFC4642.dat.bak [18658] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\B96BE9FBBCE953F7078E933A13AF5D7F1EA4E93A.dat.bak [52392] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\BC814CAC95C3E60DFE7772A57FB322A08C302189.dat.bak [57425] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\C919CDE344007E1469432AAC08767BA5B28660A2.dat.bak [20883] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\D0BEB87758211C897C606620DE570FFBB80E5349.dat.bak [58156] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\D5E8D2B458C5F749B1AE6EF8C8A50175B5DCAD51.dat.bak [60167] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\E24BDC91470B2D66A7D89A7E2BE839B5306C65F3.dat.bak [51267] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\E685BECAAAAA8D3ECE9AE6133451E6C6FF25252F.dat.bak [60601] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\E714D8BF3CD423C56DF69B36B41046B354BA7B8D.dat.bak [50178] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\F1D240BD6A0B1366629288B7139B3AD2E2A03498.dat.bak [37958] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:57 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\FA9826453585BB5ED24437F3EB52F2698E0EDDA5.dat.bak [23492] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\42C04824D3ECF6A03A23A5708A1E8927A14C53A5.dat.bak [37105] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\52FE4B16281A4F176DB1F4B5B057C1C6D182A488.dat.bak [42711] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\8F66498F3811D35D00844F472B790BA36E1A0EA5.dat.bak [203647] =>P2P.Azureus O61 - LFC: 10/05/2013 - 19:55:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\9EE61795994CC91DA222CFFB61A5176A77EBA6C7.dat.bak [41338] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:03:09 ---A- C:\Users\PC\Videos\Supernatural.S08E22.FASTSUB.VOSTFR.HDTV.XviD-F4ST.avi [367535190] O61 - LFC: 10/05/2013 - 20:10:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\25C8B2BE0E075CC3C15B8BED5CD69113152B5DF1.dat [45384] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:10:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\3A4F8730B5B159C2879B7E149FE9A0F50C0E5A4C.dat [45247] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:10:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\A775EF5B270A3E082AC9C212E3F5D5E04F694F5B.dat [50368] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:10:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\A9D06881E661983CFAF376BC43958C640C6F3C76.dat [48645] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:10:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\AF3C6773EAAB5EC81CAC90399E80F05B430C8647.dat [44541] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:10:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\E495BD89D16790405570E4925D622ECF278EFF73.dat [39086] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:10:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\F01CCDE4CD04A4BA58A2E6305F2C8C808963C118.dat [45862] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:10:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\F93D772044474BDFB50E18A09DFD8E87660B673B.dat [43679] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:30:58 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\3BC91136CB1D3B18CDE89C4E6EE8BAD070F26ADD.dat [44722] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:30:59 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\632D9A8C0BD3A4E9691D5DE67B106CFC9141DD6F.dat [43545] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:30:59 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\F8DA5321A5FCCFD282155BE75CD32A35421BF643.dat [61984] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:02 ---A- C:\Users\PC\Videos\Greys.Anatomy.S09E23.FASTSUB.VOSTFR.HDTV.XviD-MiND.avi [365687778] O61 - LFC: 10/05/2013 - 20:55:09 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\0AA71E8AA9791F412C5D830904C7EE30177D4B1D.dat [53585] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:09 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\188667CC5656C9378006B05D3761228467C81F80.dat [51482] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:09 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\299D4642A276496EC6359F6EEF2ED903D45EE70A.dat [55462] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:09 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\2F7D10369BA2A8250D07A0F082A5D3C7D4DD1084.dat [53742] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:09 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\34A4D7F9AE66DE031DC6952E5709072F897BD3F6.dat [48035] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:09 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\4B681E7769D94131B565650000C91081FC31D476.dat [56871] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:09 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\60061F31118340E7DD38AEDE518D9FC5E6FA89D3.dat.bak [50910] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:09 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\70A2B8A67D5199C8D583C359FE3B7B542BA521EC.dat [56661] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:09 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\B96BE9FBBCE953F7078E933A13AF5D7F1EA4E93A.dat [52392] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:09 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\BC814CAC95C3E60DFE7772A57FB322A08C302189.dat [57425] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:09 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\D5E8D2B458C5F749B1AE6EF8C8A50175B5DCAD51.dat [60167] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:09 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\E714D8BF3CD423C56DF69B36B41046B354BA7B8D.dat [50178] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\06398C61C2F984E05AEA754E90B5DBD00921CF5D.dat [97808] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\1430DABC08BCC0BC64C4685AFEFD3F7F9867B0C9.dat [41006] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\1C9FCBB790A34B697EAB7DD18C70404F23084C2B.dat [21163] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\27D1B0BC0C76BA1BDC0FCC37543CE8D98871ED1A.dat [42332] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\28554BBE4176285DE66D044B53674FC7BC8110B7.dat [33145] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\3037423F264008BC186570F8832948ABBA9DF270.dat [19846] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\3D49C59683E784C02B0DF70457A7C58A5430C70F.dat [20789] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\4104BC53077E1A7D51E2CEE8DA8C79D7827AC12D.dat [19210] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\42C04824D3ECF6A03A23A5708A1E8927A14C53A5.dat [37105] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\46BA02250F40EDC5472DDF2146EEAA480B80B10A.dat [43315] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\4B455799E4B01F1AF21EEA21667061DB071CA7F1.dat [21889] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\4D3B568F71BBE44F7960EDD2AAD08E6595859676.dat [34130] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\52FE4B16281A4F176DB1F4B5B057C1C6D182A488.dat [42711] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\66C52D09F24A136463C1CB4B9A6AFFC4751435C8.dat [21649] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\6FC66D0AEF5A2D2FA988C329C23BBCD18901F63D.dat [61089] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\898FC97AFC18282CC0494A10BB585FAB5913C01E.dat [18254] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\8F66498F3811D35D00844F472B790BA36E1A0EA5.dat [203647] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\9202ECDEF24A13B77BAE660BE2FA2B693B372053.dat [42903] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\95D1624AE2C134B92509B4A119D03C493A223834.dat [61609] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\9953ED8D72A70D6EF62C39DEDF5748744AAF87E1.dat [36786] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\9EE61795994CC91DA222CFFB61A5176A77EBA6C7.dat [41338] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\A083CAE5A08BF3AA6FBAE12DFC1F9E9CB332CDD0.dat [18324] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\B6308469C2F73EB04436CED3B597FB0FFDFC4642.dat [18658] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\C919CDE344007E1469432AAC08767BA5B28660A2.dat [20883] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\D0BEB87758211C897C606620DE570FFBB80E5349.dat [58156] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\E685BECAAAAA8D3ECE9AE6133451E6C6FF25252F.dat [60601] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\F1D240BD6A0B1366629288B7139B3AD2E2A03498.dat [37958] =>P2P.Azureus O61 - LFC: 10/05/2013 - 20:55:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\FA9826453585BB5ED24437F3EB52F2698E0EDDA5.dat [23492] =>P2P.Azureus O61 - LFC: 10/05/2013 - 21:11:02 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\E24BDC91470B2D66A7D89A7E2BE839B5306C65F3.dat [51267] =>P2P.Azureus O61 - LFC: 11/05/2013 - 00:42:13 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\AF78A0194F4AA1B13270C7BC29C96DA7227FC7BB.dat.bak [48593] =>P2P.Azureus O61 - LFC: 11/05/2013 - 00:42:17 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\B114ED11188B5FA45F2A6BF706D9A1A1736B13FA.dat.bak [50862] =>P2P.Azureus O61 - LFC: 11/05/2013 - 00:42:23 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\235D3617949EE96AC3C8CF33B34B53BE809F6F7A.dat.bak [59057] =>P2P.Azureus O61 - LFC: 11/05/2013 - 00:42:23 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\B114ED11188B5FA45F2A6BF706D9A1A1736B13FA.dat [50862] =>P2P.Azureus O61 - LFC: 11/05/2013 - 00:46:03 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\AF78A0194F4AA1B13270C7BC29C96DA7227FC7BB.dat [48593] =>P2P.Azureus O61 - LFC: 11/05/2013 - 00:46:12 ---A- C:\Users\PC\AppData\Roaming\Azureus\subs\38B243FB0DC547409457.vuze [2524] =>P2P.Azureus O61 - LFC: 11/05/2013 - 00:46:12 ---A- C:\Users\PC\AppData\Roaming\Azureus\subscriptions.config.bak [22372] =>P2P.Azureus O61 - LFC: 11/05/2013 - 00:51:03 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\235D3617949EE96AC3C8CF33B34B53BE809F6F7A.dat [59057] =>P2P.Azureus O61 - LFC: 11/05/2013 - 00:51:03 ---A- C:\Users\PC\AppData\Roaming\Azureus\active\60061F31118340E7DD38AEDE518D9FC5E6FA89D3.dat [50928] =>P2P.Azureus O61 - LFC: 11/05/2013 - 01:00:10 ---A- C:\Users\PC\AppData\Roaming\Azureus\stats\2013\05\10.dat [28797] =>P2P.Azureus O61 - LFC: 11/05/2013 - 07:43:49 ---A- C:\Users\PC\AppData\Roaming\Azureus\dht\addresses.dat [402] =>P2P.Azureus O61 - LFC: 11/05/2013 - 07:44:32 ---A- C:\Users\PC\AppData\Roaming\Azureus\dht\contacts.dat [548] =>P2P.Azureus O61 - LFC: 11/05/2013 - 07:44:32 ---A- C:\Users\PC\AppData\Roaming\Azureus\dht\diverse.dat [525] =>P2P.Azureus O61 - LFC: 11/05/2013 - 07:45:13 ---A- C:\Users\PC\AppData\Roaming\Azureus\net\pm_16058.dat [27838] =>P2P.Azureus O61 - LFC: 11/05/2013 - 07:46:34 ---A- C:\Users\PC\AppData\Roaming\Azureus\azureus.statistics [218] =>P2P.Azureus O61 - LFC: 11/05/2013 - 07:46:34 ---A- C:\Users\PC\AppData\Roaming\Azureus\azureus.statistics.bak [218] =>P2P.Azureus O61 - LFC: 11/05/2013 - 07:47:35 ---A- C:\Users\PC\AppData\Roaming\Azureus\devices.config.bak [6612] =>P2P.Azureus O61 - LFC: 11/05/2013 - 07:49:29 ---A- C:\Users\PC\AppData\Roaming\Azureus\downloads.config.bak [37076] =>P2P.Azureus O61 - LFC: 11/05/2013 - 07:49:34 ---A- C:\Users\PC\AppData\Roaming\Azureus\stats\2013\05\11.dat [1018] =>P2P.Azureus O61 - LFC: 11/05/2013 - 07:49:53 ---A- C:\Users\PC\AppData\Roaming\Azureus\rcm.config.bak [92411] =>P2P.Azureus O61 - LFC: 11/05/2013 - 07:49:56 ---A- C:\Users\PC\AppData\Roaming\Azureus\azureus.config.bak [10627] =>P2P.Azureus O61 - LFC: 11/05/2013 - 07:50:01 ---A- C:\Users\PC\AppData\Roaming\Azureus\sidebarauto.config.bak [422] =>P2P.Azureus O61 - LFC: 11/05/2013 - 07:50:01 ---A- C:\Users\PC\AppData\Roaming\Azureus\tables.config.bak [8264] =>P2P.Azureus O61 - LFC: 11/05/2013 - 08:37:37 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Les Rita Mitsouko\Les Rita Mitsouko\AlbumArtSmall.jpg [4722] O61 - LFC: 11/05/2013 - 08:37:37 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Les Rita Mitsouko\Les Rita Mitsouko\AlbumArt_{0903FEF7-E891-45B9-BB93-C5C1C2172896}_Large.jpg [17206] O61 - LFC: 11/05/2013 - 08:37:37 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Les Rita Mitsouko\Les Rita Mitsouko\AlbumArt_{0903FEF7-E891-45B9-BB93-C5C1C2172896}_Small.jpg [4722] O61 - LFC: 11/05/2013 - 08:37:37 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Les Rita Mitsouko\Les Rita Mitsouko\Folder.jpg [17206] O61 - LFC: 11/05/2013 - 08:38:14 ---A- C:\Users\PC\Music\iTunes\iTunes Media\Music\Les Rita Mitsouko\Les Rita Mitsouko\07 Marcia Baila (English_French exte.mp3 [9030163] O61 - LFC: 11/05/2013 - 12:52:32 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Michel Fugain\Unknown Album\AlbumArtSmall.jpg [2423] O61 - LFC: 11/05/2013 - 12:52:32 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Michel Fugain\Unknown Album\AlbumArt_{16A0D442-3C46-4501-9F20-F24118C9A336}_Small.jpg [2423] O61 - LFC: 11/05/2013 - 12:52:33 ---A- C:\Users\PC\Music\iTunes\iTunes Media\Music\Michel Fugain\Unknown Album\Une belle histoire.mp3 [3104768] O61 - LFC: 11/05/2013 - 12:52:33 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Michel Fugain\Unknown Album\AlbumArt_{16A0D442-3C46-4501-9F20-F24118C9A336}_Large.jpg [9482] O61 - LFC: 11/05/2013 - 12:52:33 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Michel Fugain\Unknown Album\Folder.jpg [9482] O61 - LFC: 11/05/2013 - 13:24:57 ---A- C:\Users\PC\Music\iTunes\iTunes Media\Music\Unknown Artist\Unknown Album\Alphaville Big In Japan.mp3 [6874201] O61 - LFC: 11/05/2013 - 13:24:58 ---A- C:\Users\PC\Music\100% clubbing party music 2012.mp3 [27186984] O61 - LFC: 11/05/2013 - 13:24:59 ---A- C:\Users\PC\Music\Can't Hold Us feat Ray Dalton Macklemore & Ryan Lewis.mp3 [4254710] O61 - LFC: 11/05/2013 - 13:24:59 ---A- C:\Users\PC\Music\Kanye West - Power Remix (feat. Swizz Beats and Jay-Z) - decentlydope.mp3 [10104512] O61 - LFC: 11/05/2013 - 13:25:00 ---A- C:\Users\PC\Music\la-fouine-telecharger-autopsie-5-de-la-fouine.mp3 [3271173] O61 - LFC: 11/05/2013 - 20:06:38 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051119.000\results.xsl [49097] O61 - LFC: 11/05/2013 - 20:06:43 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051119.000\55D5D34C-1B1C-45FD-8AF1-4669BF8E6FBF.Diagnose.0.etl [327680] O61 - LFC: 11/05/2013 - 20:06:44 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051119.000\NetworkConfiguration.cab [1665] O61 - LFC: 11/05/2013 - 20:06:59 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051119.000\55D5D34C-1B1C-45FD-8AF1-4669BF8E6FBF.Repair.1.etl [131072] O61 - LFC: 11/05/2013 - 20:07:22 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051119.000\55D5D34C-1B1C-45FD-8AF1-4669BF8E6FBF.Verify.2.etl [327680] O61 - LFC: 11/05/2013 - 20:07:25 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051119.000\2387C0D0-437E-44FD-A8B7-013C0A417D54.Diagnose.3.etl [327680] O61 - LFC: 11/05/2013 - 20:07:54 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051119.000\NetworkDiagnostics.debugreport.xml [154439] O61 - LFC: 11/05/2013 - 20:07:54 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051119.000\ResultReport.xml [51809] O61 - LFC: 11/05/2013 - 20:07:54 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051119.000\results.xml [263] O61 - LFC: 11/05/2013 - 20:38:01 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\2013051119.000\results.xsl [49097] O61 - LFC: 11/05/2013 - 20:38:25 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\2013051119.000\AppsDiagnostic.debugreport.xml [8059] O61 - LFC: 11/05/2013 - 20:38:25 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\2013051119.000\BITSDiagnostic.debugreport.xml [4398] O61 - LFC: 11/05/2013 - 20:38:25 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\2013051119.000\IEAudioPlaybackDiagnostic.debugreport.xml [2765] O61 - LFC: 11/05/2013 - 20:38:25 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\2013051119.000\ResultReport.xml [8344] O61 - LFC: 11/05/2013 - 20:38:25 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\2013051119.000\SRSP_KB2777760.debugreport.xml [2667] O61 - LFC: 11/05/2013 - 20:38:25 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\2013051119.000\results.xml [157] O61 - LFC: 11/05/2013 - 20:38:25 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.000\results.xsl [49097] O61 - LFC: 11/05/2013 - 20:38:31 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.000\_logAppsACL.txt [6296] O61 - LFC: 11/05/2013 - 20:39:07 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.000\AppsDiagnostic.debugreport.xml [17986] O61 - LFC: 11/05/2013 - 20:39:07 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.000\BITSDiagnostic.debugreport.xml [9820] O61 - LFC: 11/05/2013 - 20:39:07 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.000\IEAudioPlaybackDiagnostic.debugreport.xml [4120] O61 - LFC: 11/05/2013 - 20:39:07 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.000\ResultReport.xml [9138] O61 - LFC: 11/05/2013 - 20:39:07 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.000\SRSP_KB2777760.debugreport.xml [7243] O61 - LFC: 11/05/2013 - 20:39:07 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.000\results.xml [157] O61 - LFC: 11/05/2013 - 20:53:10 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\2013051119.001\results.xsl [49097] O61 - LFC: 11/05/2013 - 20:53:19 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\2013051119.001\AppsDiagnostic.debugreport.xml [8066] O61 - LFC: 11/05/2013 - 20:53:19 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\2013051119.001\BITSDiagnostic.debugreport.xml [4406] O61 - LFC: 11/05/2013 - 20:53:19 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\2013051119.001\IEAudioPlaybackDiagnostic.debugreport.xml [2773] O61 - LFC: 11/05/2013 - 20:53:19 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\2013051119.001\ResultReport.xml [8344] O61 - LFC: 11/05/2013 - 20:53:19 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\2013051119.001\SRSP_KB2777760.debugreport.xml [2675] O61 - LFC: 11/05/2013 - 20:53:19 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\2013051119.001\results.xml [157] O61 - LFC: 11/05/2013 - 20:53:20 ---A- C:\Users\PC\AppData\Local\Diagnostics\1508469439\latest.cab [10680] O61 - LFC: 11/05/2013 - 20:53:20 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.001\results.xsl [49097] O61 - LFC: 11/05/2013 - 20:53:43 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1612347604\2013051119.000\results.xsl [49097] O61 - LFC: 11/05/2013 - 20:53:52 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1612347604\2013051119.000\605F8B11-C26A-46EA-ACE0-2DD043606D96.Diagnose.Admin.0.etl [327680] O61 - LFC: 11/05/2013 - 20:53:53 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1612347604\2013051119.000\NetworkConfiguration.cab [1222] O61 - LFC: 11/05/2013 - 20:56:16 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1612347604\2013051119.000\605F8B11-C26A-46EA-ACE0-2DD043606D96.Repair.Admin.1.etl [196608] O61 - LFC: 11/05/2013 - 20:56:31 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1612347604\2013051119.000\605F8B11-C26A-46EA-ACE0-2DD043606D96.Verify.Admin.2.etl [327680] O61 - LFC: 11/05/2013 - 20:56:32 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1612347604\2013051119.000\4A4E0BDF-868D-45B6-ADCB-A4E14AA66DB0.Diagnose.Admin.3.etl [262144] O61 - LFC: 11/05/2013 - 20:58:07 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1612347604\2013051119.000\NetworkDiagnostics.debugreport.xml [152760] O61 - LFC: 11/05/2013 - 20:58:07 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1612347604\2013051119.000\ResultReport.xml [49656] O61 - LFC: 11/05/2013 - 20:58:07 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1612347604\2013051119.000\results.xml [412] O61 - LFC: 11/05/2013 - 20:58:07 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1612347604\latest.cab [43250] O61 - LFC: 11/05/2013 - 21:03:34 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.001\AppsDiagnostic.debugreport.xml [19082] O61 - LFC: 11/05/2013 - 21:03:34 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.001\BITSDiagnostic.debugreport.xml [9830] O61 - LFC: 11/05/2013 - 21:03:34 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.001\IEAudioPlaybackDiagnostic.debugreport.xml [4128] O61 - LFC: 11/05/2013 - 21:03:34 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.001\ResultReport.xml [8881] O61 - LFC: 11/05/2013 - 21:03:34 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.001\SRSP_KB2777760.debugreport.xml [7252] O61 - LFC: 11/05/2013 - 21:03:34 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\2013051119.001\results.xml [157] O61 - LFC: 11/05/2013 - 21:03:34 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\1508469439\latest.cab [11962] O61 - LFC: 11/05/2013 - 21:58:20 ---A- C:\Users\PC\AppData\Roaming\Intel Corporation\IAStorUtil\HelpWindowSettings.xml [682] O61 - LFC: 12/05/2013 - 08:16:53 ---A- C:\Users\PC\AppData\Roaming\Intel Corporation\IAStorUtil\MainWindowSettings.xml [682] O61 - LFC: 12/05/2013 - 09:38:16 ---A- C:\Users\PC\AppData\Roaming\Microsoft\HTML Help\hh.dat [8722] O61 - LFC: 12/05/2013 - 11:03:44 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\3391462126\2013051210.000\results.xsl [49097] O61 - LFC: 12/05/2013 - 11:03:59 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\3391462126\2013051210.000\HomeGroupDiagnostic.debugreport.xml [2859] O61 - LFC: 12/05/2013 - 11:03:59 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\3391462126\2013051210.000\ResultReport.xml [13241] O61 - LFC: 12/05/2013 - 11:03:59 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\3391462126\2013051210.000\results.xml [292] O61 - LFC: 12/05/2013 - 11:03:59 ---A- C:\Users\PC\AppData\Local\ElevatedDiagnostics\3391462126\latest.cab [10206] O61 - LFC: 12/05/2013 - 15:07:37 ---A- C:\Users\PC\AppData\Local\resmon.resmoncfg [17] O61 - LFC: 12/05/2013 - 15:28:41 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\Content\8890A77645B73478F5B1DED18ACBF795_1E5D470765E0BE1964814B1F5A3581DC [471] O61 - LFC: 12/05/2013 - 15:28:41 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\Content\A3C4F17BF8CB09C3DF2A086B36306B5C_B5357B2EC71B0135E5CDF217962D8CE1 [471] O61 - LFC: 12/05/2013 - 15:28:43 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\Content\944E5B697BC46FE14AB888AE8A1EBB99_2269679B991E7B74D029ADC1DCE94782 [1499] O61 - LFC: 12/05/2013 - 15:28:43 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\Content\AC9005F5466BD463DF06D711B370595F [1176] O61 - LFC: 12/05/2013 - 15:28:44 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCookies\F963Y2XC.txt [159] O61 - LFC: 12/05/2013 - 15:29:11 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\8890A77645B73478F5B1DED18ACBF795_1E5D470765E0BE1964814B1F5A3581DC [426] O61 - LFC: 12/05/2013 - 15:29:11 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\944E5B697BC46FE14AB888AE8A1EBB99_2269679B991E7B74D029ADC1DCE94782 [482] O61 - LFC: 12/05/2013 - 15:29:11 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\A3C4F17BF8CB09C3DF2A086B36306B5C_B5357B2EC71B0135E5CDF217962D8CE1 [442] O61 - LFC: 12/05/2013 - 15:29:11 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\AFA2A5744430E65F42D3175FABFBE3E8 [222] O61 - LFC: 12/05/2013 - 15:31:46 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051214.000\results.xsl [49097] O61 - LFC: 12/05/2013 - 15:32:01 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051214.000\A6677278-E1C6-41DA-9EC2-3DC97358E01E.Diagnose.0.etl [327680] O61 - LFC: 12/05/2013 - 15:32:01 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051214.000\NetworkConfiguration.cab [1649] O61 - LFC: 12/05/2013 - 15:32:14 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051214.000\A6677278-E1C6-41DA-9EC2-3DC97358E01E.Repair.1.etl [196608] O61 - LFC: 12/05/2013 - 15:32:30 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051214.000\6B5C60E8-6A52-4E2E-8ED5-B08F14443ACC.Diagnose.3.etl [262144] O61 - LFC: 12/05/2013 - 15:32:30 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051214.000\A6677278-E1C6-41DA-9EC2-3DC97358E01E.Verify.2.etl [262144] O61 - LFC: 12/05/2013 - 15:32:39 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051214.000\NetworkDiagnostics.debugreport.xml [162113] O61 - LFC: 12/05/2013 - 15:32:39 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051214.000\ResultReport.xml [53968] O61 - LFC: 12/05/2013 - 15:32:39 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\2013051214.000\results.xml [299] O61 - LFC: 12/05/2013 - 15:32:39 ---A- C:\Users\PC\AppData\Local\Diagnostics\460911090\latest.cab [48676] O61 - LFC: 12/05/2013 - 15:34:48 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000247a_87222652e1ed9e.eml [10536] O61 - LFC: 12/05/2013 - 15:34:49 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000247b_f0d98ce3f8b662.eml [17684] O61 - LFC: 12/05/2013 - 15:34:50 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000247c_e19010ac39e378.eml [1309] O61 - LFC: 12/05/2013 - 15:34:50 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000247d_d6384653418eaa.eml [2894] O61 - LFC: 12/05/2013 - 15:34:51 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000247e_5b13c1d0485330.eml [8270] O61 - LFC: 12/05/2013 - 15:34:53 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000247f_edce8087115958.eml [14916] O61 - LFC: 12/05/2013 - 15:34:54 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002480_c88a9b52cb77d4.eml [30905] O61 - LFC: 12/05/2013 - 15:34:54 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002481_bfd3504617ca2.eml [5085] O61 - LFC: 12/05/2013 - 15:34:55 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002482_ea041e20876af7.eml [7753] O61 - LFC: 12/05/2013 - 15:34:55 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002483_720ababfea9c4a.eml [10565] O61 - LFC: 12/05/2013 - 15:34:55 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002484_e937a371baec9b.eml [13385] O61 - LFC: 12/05/2013 - 15:34:56 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002485_43b6a132524fff.eml [6353] O61 - LFC: 12/05/2013 - 15:34:56 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002486_1119d0fb9d24de.eml [12216] O61 - LFC: 12/05/2013 - 15:34:56 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002487_7da27755b47172.eml [16152] O61 - LFC: 12/05/2013 - 15:34:57 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002488_be3acc7cff37e2.eml [39575] O61 - LFC: 12/05/2013 - 15:34:57 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000006\20002523_57d97a08c1c92b.eml [1467] O61 - LFC: 12/05/2013 - 15:34:58 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000006\20002521_d888f64fb16024.eml [1455] O61 - LFC: 12/05/2013 - 15:34:58 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000006\20002522_f8a243b4f52837.eml [1446] O61 - LFC: 12/05/2013 - 15:34:59 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000006\20002520_9148edcca52a24.eml [2042] O61 - LFC: 12/05/2013 - 15:35:00 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002489_56ae1636418415.eml [34594] O61 - LFC: 12/05/2013 - 15:35:00 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000006\2000251f_2abce8c7af09d3.eml [6456] O61 - LFC: 12/05/2013 - 15:35:01 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000006\2000251d_55835171e8d28f.eml [1217] O61 - LFC: 12/05/2013 - 15:35:01 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000006\2000251e_e22ae7ad864923.eml [1459] O61 - LFC: 12/05/2013 - 15:35:02 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000006\2000251c_f08619d2f23bc9.eml [6505] O61 - LFC: 12/05/2013 - 15:35:03 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000005\2000251a_ab61ec83f845f2.eml [140341] O61 - LFC: 12/05/2013 - 15:35:03 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000005\2000251b_e499a7c39b9848.eml [14584] O61 - LFC: 12/05/2013 - 15:35:06 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002517_27a7669df8a43d.eml [5322] O61 - LFC: 12/05/2013 - 15:35:06 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002518_ffcbffdf2df1f6.eml [2993] O61 - LFC: 12/05/2013 - 15:35:06 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000005\20002519_3e295fbaa03b52.eml [11819] O61 - LFC: 12/05/2013 - 15:35:07 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000248a_3ed521d4c6f37f.eml [1288] O61 - LFC: 12/05/2013 - 15:35:07 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002515_5cbb18525eeef6.eml [2321] O61 - LFC: 12/05/2013 - 15:35:07 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002516_9d46947e977d3a.eml [2993] O61 - LFC: 12/05/2013 - 15:35:08 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002511_61a77a1d745bc1.eml [2993] O61 - LFC: 12/05/2013 - 15:35:08 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002512_6241a02fb3b5b6.eml [2993] O61 - LFC: 12/05/2013 - 15:35:08 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002513_75999723a95ef.eml [2993] O61 - LFC: 12/05/2013 - 15:35:08 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002514_4b751e03baf27b.eml [2993] O61 - LFC: 12/05/2013 - 15:35:09 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000248b_33ba6cecad9693.eml [28109] O61 - LFC: 12/05/2013 - 15:35:09 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\2000250f_2e045b9d2c1287.eml [11057] O61 - LFC: 12/05/2013 - 15:35:09 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002510_2163cc4bc8fc47.eml [2993] O61 - LFC: 12/05/2013 - 15:35:10 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\2000250b_9117ebf3ec43e8.eml [8483] O61 - LFC: 12/05/2013 - 15:35:10 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\2000250c_97969db727e242.eml [2369] O61 - LFC: 12/05/2013 - 15:35:10 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\2000250d_5cd92076d3b3b8.eml [4004] O61 - LFC: 12/05/2013 - 15:35:10 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\2000250e_8deb9c9771c9b8.eml [2292] O61 - LFC: 12/05/2013 - 15:35:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002508_70f5d417a302e2.eml [6127] O61 - LFC: 12/05/2013 - 15:35:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002509_e1db95f7f5298f.eml [58404] O61 - LFC: 12/05/2013 - 15:35:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\2000250a_c37c203d4aae5e.eml [4062] O61 - LFC: 12/05/2013 - 15:35:12 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000248c_74aa16187d9fa0.eml [1023] O61 - LFC: 12/05/2013 - 15:35:12 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002506_3cdce159b4b0f4.eml [2291] O61 - LFC: 12/05/2013 - 15:35:12 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002507_8824b4f7e0c411.eml [23240] O61 - LFC: 12/05/2013 - 15:35:13 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002503_e9594ee0e70d7f.eml [7322] O61 - LFC: 12/05/2013 - 15:35:13 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002504_395d7cc2873373.eml [2411] O61 - LFC: 12/05/2013 - 15:35:13 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002505_d75e14811cdf4.eml [6436] O61 - LFC: 12/05/2013 - 15:35:14 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002500_6190935df5b871.eml [7514] O61 - LFC: 12/05/2013 - 15:35:14 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002501_aae78b08797395.eml [8638] O61 - LFC: 12/05/2013 - 15:35:14 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002502_1d91f959b1b3ff.eml [2291] O61 - LFC: 12/05/2013 - 15:35:15 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000248d_e770a7d1d946d.eml [34109] O61 - LFC: 12/05/2013 - 15:35:15 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000248e_8852969ba5d0de.eml [18204] O61 - LFC: 12/05/2013 - 15:35:15 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024ff_dd6553ae207d15.eml [11674] O61 - LFC: 12/05/2013 - 15:35:16 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000248f_a81e13a5e0966b.eml [4706] O61 - LFC: 12/05/2013 - 15:35:16 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\2000244d_8c305c852316a.eml [3465] O61 - LFC: 12/05/2013 - 15:35:16 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024fe_6ed1a1508e2f62.eml [7490] O61 - LFC: 12/05/2013 - 15:35:17 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002490_410b457e7aea27.eml [6996] O61 - LFC: 12/05/2013 - 15:35:17 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\2000244e_c9a19ffde21a4.eml [6386] O61 - LFC: 12/05/2013 - 15:35:17 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024fd_d7b4fda214f3dc.eml [11856] O61 - LFC: 12/05/2013 - 15:35:18 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024f9_aa6312aba4fe3a.eml [15759] O61 - LFC: 12/05/2013 - 15:35:18 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024fa_dcbb4215408ebb.eml [11742] O61 - LFC: 12/05/2013 - 15:35:18 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024fb_fb48fe96beb9f.eml [11892] O61 - LFC: 12/05/2013 - 15:35:18 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024fc_161cb978539db1.eml [12115] O61 - LFC: 12/05/2013 - 15:35:19 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\2000244f_84ae3584ea155f.eml [7142] O61 - LFC: 12/05/2013 - 15:35:19 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024f8_5f4fdd1f21626.eml [11662] O61 - LFC: 12/05/2013 - 15:35:20 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002491_af0115423cbcc3.eml [12556] O61 - LFC: 12/05/2013 - 15:35:20 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024f5_1829e5508980b2.eml [6917] O61 - LFC: 12/05/2013 - 15:35:20 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024f6_15586c7e35f21b.eml [2283] O61 - LFC: 12/05/2013 - 15:35:20 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024f7_4c00672c455cab.eml [2283] O61 - LFC: 12/05/2013 - 15:35:21 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024f4_91e59aff940f17.eml [36279] O61 - LFC: 12/05/2013 - 15:35:22 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024f3_613f4e29c4429c.eml [14577] O61 - LFC: 12/05/2013 - 15:35:23 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002492_7005eee901b96.eml [8455] O61 - LFC: 12/05/2013 - 15:35:23 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024f1_d33c1bef6136d3.eml [1667] O61 - LFC: 12/05/2013 - 15:35:23 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024f2_c3bde544cda33.eml [43478] O61 - LFC: 12/05/2013 - 15:35:24 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\20002450_17593b02515842.eml [3471] O61 - LFC: 12/05/2013 - 15:35:24 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024ef_6b41a23c20ca6c.eml [22278] O61 - LFC: 12/05/2013 - 15:35:24 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024f0_605b62e4293057.eml [2283] O61 - LFC: 12/05/2013 - 15:35:25 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024ec_5f57fc587ba7f7.eml [2283] O61 - LFC: 12/05/2013 - 15:35:25 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024ed_18632e0e3c896d.eml [2283] O61 - LFC: 12/05/2013 - 15:35:25 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024ee_e4b54fb92d9156.eml [7764] O61 - LFC: 12/05/2013 - 15:35:26 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024ea_67473b2522eb8b.eml [2283] O61 - LFC: 12/05/2013 - 15:35:26 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024eb_62926152c2c585.eml [2283] O61 - LFC: 12/05/2013 - 15:35:27 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002493_9da05da280af64.eml [106202] O61 - LFC: 12/05/2013 - 15:35:27 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024e8_59de8be71716d1.eml [6455] O61 - LFC: 12/05/2013 - 15:35:27 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024e9_6d870ff84965c1.eml [2283] O61 - LFC: 12/05/2013 - 15:35:28 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\20002451_e83d2c3ebff4c.eml [6260] O61 - LFC: 12/05/2013 - 15:35:28 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024e6_c124cd9098742d.eml [6936] O61 - LFC: 12/05/2013 - 15:35:28 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024e7_b066aae9390322.eml [9994] O61 - LFC: 12/05/2013 - 15:35:29 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024e3_7d5cf700ce3473.eml [9016] O61 - LFC: 12/05/2013 - 15:35:29 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024e4_98d278fc793ee7.eml [10027] O61 - LFC: 12/05/2013 - 15:35:29 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024e5_e79dcb771af427.eml [1181] O61 - LFC: 12/05/2013 - 15:35:30 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024e0_663098725a4dad.eml [2235] O61 - LFC: 12/05/2013 - 15:35:30 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024e1_e80619e93539a.eml [11991] O61 - LFC: 12/05/2013 - 15:35:30 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024e2_9d9817f8c71aeb.eml [1909] O61 - LFC: 12/05/2013 - 15:35:31 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\20002452_25f84b252d0ab0.eml [1814] O61 - LFC: 12/05/2013 - 15:35:31 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024de_5dae815cedb0a4.eml [1488] O61 - LFC: 12/05/2013 - 15:35:31 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024df_2e5d78848f689c.eml [2477] O61 - LFC: 12/05/2013 - 15:35:32 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024db_cdb49a4ee12b0.eml [6098] O61 - LFC: 12/05/2013 - 15:35:32 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024dc_ccd23b7f6694.eml [1016] O61 - LFC: 12/05/2013 - 15:35:32 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024dd_275e0b37e20ce.eml [6637] O61 - LFC: 12/05/2013 - 15:35:33 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024d9_5065dad9ca915.eml [9880] O61 - LFC: 12/05/2013 - 15:35:33 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024da_368f580a4a985c.eml [7186] O61 - LFC: 12/05/2013 - 15:35:34 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024d6_17a5c15ff0ed66.eml [6871] O61 - LFC: 12/05/2013 - 15:35:34 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024d7_cead6b9f41e39b.eml [10000] O61 - LFC: 12/05/2013 - 15:35:34 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024d8_3053bc301f4886.eml [16084] O61 - LFC: 12/05/2013 - 15:35:35 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\20002453_7c1f9758737d76.eml [2917] O61 - LFC: 12/05/2013 - 15:35:35 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024d5_71420aefa04f0.eml [6871] O61 - LFC: 12/05/2013 - 15:35:36 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002494_3b6e27a3b46525.eml [29264] O61 - LFC: 12/05/2013 - 15:35:36 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024d4_cabbbbcce7332.eml [8420] O61 - LFC: 12/05/2013 - 15:35:37 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024d1_7a40f06672fd2e.eml [6682] O61 - LFC: 12/05/2013 - 15:35:37 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024d2_c0f759048d348.eml [6295] O61 - LFC: 12/05/2013 - 15:35:37 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024d3_252fcf45e95347.eml [32364] O61 - LFC: 12/05/2013 - 15:35:38 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024d0_7c333f18d35b2c.eml [90244] O61 - LFC: 12/05/2013 - 15:35:39 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024cf_da5df22f775eb1.eml [9786] O61 - LFC: 12/05/2013 - 15:35:40 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024cc_1051718433b5d7.eml [6707] O61 - LFC: 12/05/2013 - 15:35:40 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024cd_33ec52b2d02720.eml [7183] O61 - LFC: 12/05/2013 - 15:35:40 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024ce_1798b84f452081.eml [57954] O61 - LFC: 12/05/2013 - 15:35:41 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\20002454_4a4d8e3e41d462.eml [1615] O61 - LFC: 12/05/2013 - 15:35:42 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002495_f1e6aee3ea4e95.eml [34605] O61 - LFC: 12/05/2013 - 15:35:43 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\20002455_32913ba51174a5.eml [3492] O61 - LFC: 12/05/2013 - 15:35:43 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024ca_d216a2bf7e4a99.eml [11383] O61 - LFC: 12/05/2013 - 15:35:43 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024cb_ae825b494e3765.eml [9197] O61 - LFC: 12/05/2013 - 15:35:44 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024c8_6514d7875982b.eml [7467] O61 - LFC: 12/05/2013 - 15:35:44 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024c9_e2b670d4526420.eml [21253] O61 - LFC: 12/05/2013 - 15:35:45 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002496_85ffaabc48733.eml [34605] O61 - LFC: 12/05/2013 - 15:35:45 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024c6_46cdc2f3349e42.eml [6145] O61 - LFC: 12/05/2013 - 15:35:45 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024c7_c223ab22a41e1.eml [122455] O61 - LFC: 12/05/2013 - 15:35:46 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024c5_72f043e3ea6c38.eml [6025] O61 - LFC: 12/05/2013 - 15:35:47 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\20002456_e8c28ffc912352.eml [4114] O61 - LFC: 12/05/2013 - 15:35:47 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024c2_c2f9463c345869.eml [6057] O61 - LFC: 12/05/2013 - 15:35:47 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024c3_c4bdb0e5507781.eml [30224] O61 - LFC: 12/05/2013 - 15:35:47 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024c4_bc3e704bd0cf7a.eml [9146] O61 - LFC: 12/05/2013 - 15:35:48 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024bf_2c8007755bd29.eml [15879] O61 - LFC: 12/05/2013 - 15:35:48 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024c0_e68dacfc1a9cd8.eml [10031] O61 - LFC: 12/05/2013 - 15:35:48 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024c1_6ddf1746c1b32.eml [24066] O61 - LFC: 12/05/2013 - 15:35:49 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024bc_b84fdc131f47d.eml [7559] O61 - LFC: 12/05/2013 - 15:35:49 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024bd_88839dd2d6581.eml [9954] O61 - LFC: 12/05/2013 - 15:35:49 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024be_6d877e42c942c4.eml [53384] O61 - LFC: 12/05/2013 - 15:35:50 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002497_1c8081fd4b10ff.eml [34605] O61 - LFC: 12/05/2013 - 15:35:50 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024ba_33b202cbace5f7.eml [15883] O61 - LFC: 12/05/2013 - 15:35:50 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024bb_3beb81b42f4ec7.eml [87170] O61 - LFC: 12/05/2013 - 15:35:52 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\20002457_26fd8a35ec727.eml [27967] O61 - LFC: 12/05/2013 - 15:35:53 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024b7_4dbe440c881972.eml [9320] O61 - LFC: 12/05/2013 - 15:35:53 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024b8_82164845403a6c.eml [58393] O61 - LFC: 12/05/2013 - 15:35:53 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024b9_2b3ada7bdf9ab.eml [23939] O61 - LFC: 12/05/2013 - 15:35:54 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024b4_3fd2d3934996a4.eml [35110] O61 - LFC: 12/05/2013 - 15:35:54 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024b5_73bc0d5083baca.eml [23946] O61 - LFC: 12/05/2013 - 15:35:54 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024b6_1c14d5eb76c23.eml [52541] O61 - LFC: 12/05/2013 - 15:35:55 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024b2_2e2d6385b5c275.eml [123060] O61 - LFC: 12/05/2013 - 15:35:55 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024b3_4ad38778780895.eml [5674] O61 - LFC: 12/05/2013 - 15:35:57 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\20002458_b6ced5daebe34.eml [36486] O61 - LFC: 12/05/2013 - 15:35:57 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024b0_d56537e754e153.eml [15942] O61 - LFC: 12/05/2013 - 15:35:57 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024b1_cba5d1375a0849.eml [31847] O61 - LFC: 12/05/2013 - 15:35:59 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024af_84fbebfd14516f.eml [4027] O61 - LFC: 12/05/2013 - 15:36:00 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024ac_51e5b8cc67acd5.eml [9917] O61 - LFC: 12/05/2013 - 15:36:00 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024ad_11947a3c949eef.eml [10401] O61 - LFC: 12/05/2013 - 15:36:00 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024ae_9509d83792cc5b.eml [2582] O61 - LFC: 12/05/2013 - 15:36:01 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024a8_e37d68404bf2de.eml [4076] O61 - LFC: 12/05/2013 - 15:36:01 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024a9_83535022fe5cc5.eml [9862] O61 - LFC: 12/05/2013 - 15:36:01 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024aa_a37de8bf2bfdc9.eml [13749] O61 - LFC: 12/05/2013 - 15:36:01 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024ab_7c05651cbb6222.eml [2427] O61 - LFC: 12/05/2013 - 15:36:02 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002498_331952f6808264.eml [814] O61 - LFC: 12/05/2013 - 15:36:02 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024a6_eb896d4b7fc012.eml [35110] O61 - LFC: 12/05/2013 - 15:36:02 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024a7_7235de941b74db.eml [3514] O61 - LFC: 12/05/2013 - 15:36:03 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024a5_af1ce91cb1f6ce.eml [44044] O61 - LFC: 12/05/2013 - 15:36:04 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024a4_e9c55e4f8e4a51.eml [54543] O61 - LFC: 12/05/2013 - 15:36:05 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024a3_f57f9701991c0.eml [23914] O61 - LFC: 12/05/2013 - 15:36:06 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024a2_79e79e51438e91.eml [57644] O61 - LFC: 12/05/2013 - 15:36:07 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024a1_821befdb275fe0.eml [22021] O61 - LFC: 12/05/2013 - 15:36:08 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\20002459_d8d95e21167d4.eml [37777] O61 - LFC: 12/05/2013 - 15:36:08 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200024a0_82b92a1e511dc5.eml [10069] O61 - LFC: 12/05/2013 - 15:36:09 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002499_7d378583d0a5ae.eml [47353] O61 - LFC: 12/05/2013 - 15:36:09 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\2000249e_6bf9a9f4f5a7.eml [10138] O61 - LFC: 12/05/2013 - 15:36:09 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\2000249f_e26c8f56a0c73f.eml [10015] O61 - LFC: 12/05/2013 - 15:36:10 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\2000249b_5c2e92d369b865.eml [10435] O61 - LFC: 12/05/2013 - 15:36:10 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\2000249c_a4df74362410e1.eml [9945] O61 - LFC: 12/05/2013 - 15:36:10 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\2000249d_136324b727ba2c.eml [12329] O61 - LFC: 12/05/2013 - 15:36:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000249a_7fcd82901a81a1.eml [1218] O61 - LFC: 12/05/2013 - 15:36:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\2000245a_1b38ada155fcf8.eml [1858] O61 - LFC: 12/05/2013 - 15:36:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\2000245b_b7bfff9921c27b.eml [2012] O61 - LFC: 12/05/2013 - 15:36:12 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\2000245c_8380dcf7588aaf.eml [2578] O61 - LFC: 12/05/2013 - 15:36:14 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\2000245d_182b3e558fc7ee.eml [10289] O61 - LFC: 12/05/2013 - 15:36:20 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\2000245e_67f6e37e449e8.eml [2085] O61 - LFC: 12/05/2013 - 15:36:22 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\2000245f_b13a20aaa3d74c.eml [17462] O61 - LFC: 12/05/2013 - 15:36:23 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\20002460_be8bc70021a31f.eml [2739] O61 - LFC: 12/05/2013 - 15:43:34 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002478_40a906f1f32dd.eml [637] O61 - LFC: 12/05/2013 - 15:43:34 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002479_2bb908b399c60.eml [9328] O61 - LFC: 12/05/2013 - 15:43:36 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002477_e0d646cf72051d.eml [13203] O61 - LFC: 12/05/2013 - 15:43:37 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002475_280c76c09b4c7.eml [2301] O61 - LFC: 12/05/2013 - 15:43:37 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002476_d71d2c67e22789.eml [921] O61 - LFC: 12/05/2013 - 15:43:40 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002474_45b56b6473da6.eml [50194] O61 - LFC: 12/05/2013 - 15:43:42 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002473_f2321e005792ee.eml [15647] O61 - LFC: 12/05/2013 - 15:43:45 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002472_4527dd4f85a310.eml [6332] O61 - LFC: 12/05/2013 - 15:43:47 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002471_592d8024c6ae44.eml [23531] O61 - LFC: 12/05/2013 - 15:45:34 ---A- C:\Users\PC\AppData\Local\Packages\29982CsabaHarmath.UnCompress_pzm79av2szvm8\Settings\settings.dat [8192] O61 - LFC: 12/05/2013 - 15:45:34 ---A- C:\Users\PC\AppData\Local\Packages\AD2F1837.HPPrinterControl_v10z8vjag6ke6\Settings\settings.dat [8192] O61 - LFC: 12/05/2013 - 15:45:34 ---A- C:\Users\PC\AppData\Local\Packages\AD2F1837.HPScanandCapture_v10z8vjag6ke6\Settings\settings.dat [262144] O61 - LFC: 12/05/2013 - 15:45:34 ---A- C:\Users\PC\AppData\Local\Packages\BrowserChoice_cw5n1h2txyewy\Settings\settings.dat [8192] O61 - LFC: 12/05/2013 - 15:45:34 ---A- C:\Users\PC\AppData\Local\Packages\Microsoft.BingMaps_8wekyb3d8bbwe\Settings\settings.dat [8192] O61 - LFC: 12/05/2013 - 15:45:35 ---A- C:\Users\PC\AppData\Local\Packages\Microsoft.Camera_8wekyb3d8bbwe\Settings\settings.dat [262144] O61 - LFC: 12/05/2013 - 15:45:35 ---A- C:\Users\PC\AppData\Local\Packages\Microsoft.VCLibs.110.00_8wekyb3d8bbwe\Settings\settings.dat [8192] O61 - LFC: 12/05/2013 - 15:45:35 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.microsoftskydrive_8wekyb3d8bbwe\Settings\settings.dat [262144] O61 - LFC: 12/05/2013 - 15:45:43 ---A- C:\Users\PC\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Settings\settings.dat [8192] O61 - LFC: 12/05/2013 - 15:45:43 ---A- C:\Users\PC\AppData\Local\Packages\Microsoft.Reader_8wekyb3d8bbwe\Settings\settings.dat [262144] O61 - LFC: 12/05/2013 - 15:45:43 ---A- C:\Users\PC\AppData\Local\Packages\Microsoft.WinJS.1.0_8wekyb3d8bbwe\Settings\settings.dat [8192] O61 - LFC: 12/05/2013 - 15:45:43 ---A- C:\Users\PC\AppData\Local\Packages\Microsoft.XboxLIVEGames_8wekyb3d8bbwe\Settings\settings.dat [262144] O61 - LFC: 12/05/2013 - 15:45:49 ---A- C:\Users\PC\AppData\Local\Packages\WinStore_cw5n1h2txyewy\Settings\settings.dat [8192] O61 - LFC: 12/05/2013 - 15:45:49 ---A- C:\Users\PC\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat [8192] O61 - LFC: 12/05/2013 - 15:58:27 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\200024d3\675D990E-DB22-4DEF-993E-B8B3EBC1A9B62.gif [41297] O61 - LFC: 12/05/2013 - 15:58:28 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\200024d3\0286AE7B-6789-4609-B8A9-4320576165103.gif [34603] O61 - LFC: 12/05/2013 - 15:58:29 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\200024d3\girl_fr.gif [41297] O61 - LFC: 12/05/2013 - 15:58:30 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\200024d3\C9217EC1-4F82-49AB-BDF2-EF453ECF24D21.jpg [309111] O61 - LFC: 12/05/2013 - 15:58:31 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\200024ae\livraison offert.jpg [116883] O61 - LFC: 12/05/2013 - 15:58:32 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000246f_ff91750d1caf1.eml [1233] O61 - LFC: 12/05/2013 - 15:58:32 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002470_b6c9a77eb645de.eml [1495] O61 - LFC: 12/05/2013 - 15:58:33 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000246e_55b0b43b5ecc66.eml [1154] O61 - LFC: 12/05/2013 - 15:58:34 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000246d_6024081c6e0bb.eml [7833] O61 - LFC: 12/05/2013 - 15:58:35 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000246c_6480a15da5c9e.eml [106145] O61 - LFC: 12/05/2013 - 15:58:35 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\200024a8\image001.jpg [332] O61 - LFC: 12/05/2013 - 15:58:37 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000246a_2f36dadd2f94eb.eml [18290] O61 - LFC: 12/05/2013 - 15:58:37 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000246b_2477b6f241e426.eml [1180] O61 - LFC: 12/05/2013 - 15:58:38 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002469_f773f9575a66fc.eml [20218] O61 - LFC: 12/05/2013 - 15:58:39 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002467_9dfe15deecd577.eml [6408] O61 - LFC: 12/05/2013 - 15:58:39 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002468_75bae35acb1a6f.eml [15363] O61 - LFC: 12/05/2013 - 15:58:41 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002465_88e939d9bc9bfa.eml [13277] O61 - LFC: 12/05/2013 - 15:58:41 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002466_6b3b607daf3184.eml [19120] O61 - LFC: 12/05/2013 - 15:58:42 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002463_3c945a2c7b9442.eml [2786] O61 - LFC: 12/05/2013 - 15:58:42 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002464_257a881bacde91.eml [11615] O61 - LFC: 12/05/2013 - 15:58:43 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002462_af7cfa2f36317.eml [22593] O61 - LFC: 12/05/2013 - 15:58:45 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\20002461_8fddb4cfd99cf.eml [16160] O61 - LFC: 12/05/2013 - 15:58:58 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\2000249d\ATT00025.jpg [35849] O61 - LFC: 12/05/2013 - 15:58:58 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\200024a8\La soif.pps [4364800] O61 - LFC: 12/05/2013 - 15:58:59 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\2000249d\ATT00028.jpg [41833] O61 - LFC: 12/05/2013 - 15:59:00 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\2000249d\ATT00031.jpg [36497] O61 - LFC: 12/05/2013 - 15:59:01 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\2000249d\ATT00034.jpg [50514] O61 - LFC: 12/05/2013 - 15:59:01 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\2000249d\ATT00037.jpg [65869] O61 - LFC: 12/05/2013 - 15:59:02 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\2000249d\ATT00040.jpg [44930] O61 - LFC: 12/05/2013 - 15:59:03 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\2000249d\ATT00043.jpg [59690] O61 - LFC: 12/05/2013 - 15:59:04 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\2000249d\ATT00046.jpg [62626] O61 - LFC: 12/05/2013 - 15:59:05 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\2000249d\ATT00049.jpg [45540] O61 - LFC: 12/05/2013 - 15:59:05 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\2000249d\ATT00052.jpg [47356] O61 - LFC: 12/05/2013 - 16:01:43 ---A- C:\Users\PC\AppData\Local\Diagnostics\733862231\2013051215.000\results.xsl [49097] O61 - LFC: 12/05/2013 - 16:02:31 ---A- C:\Users\PC\AppData\Local\Diagnostics\733862231\2013051215.000\PCW.debugreport.xml [1839] O61 - LFC: 12/05/2013 - 16:02:31 ---A- C:\Users\PC\AppData\Local\Diagnostics\733862231\2013051215.000\ResultReport.xml [2099] O61 - LFC: 12/05/2013 - 16:02:31 ---A- C:\Users\PC\AppData\Local\Diagnostics\733862231\2013051215.000\results.xml [441] O61 - LFC: 12/05/2013 - 16:02:31 ---A- C:\Users\PC\AppData\Local\Diagnostics\733862231\latest.cab [8299] O61 - LFC: 12/05/2013 - 16:06:51 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\2000257c_8f1664b1df956b.eml [1451] O61 - LFC: 12/05/2013 - 16:07:00 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_FFE23A7C282C1690704B5AEA6161D1B8 [1891] O61 - LFC: 12/05/2013 - 16:07:00 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\Content\F063BF7EF604434CBE00FF198F0D9B10 [4148] O61 - LFC: 12/05/2013 - 16:07:00 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 [328] O61 - LFC: 12/05/2013 - 16:07:01 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\Content\B4378BD2E36B69DECED3E341BD654801_4D9B4B1875B131597137618324D6884A [1877] O61 - LFC: 12/05/2013 - 16:07:02 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\Content\7D1F03728133589A90656A87E482B21F [24904] O61 - LFC: 12/05/2013 - 16:07:02 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\7D1F03728133589A90656A87E482B21F [256] O61 - LFC: 12/05/2013 - 16:07:07 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000016\2000257d_2c39b71fb610be.eml [15767] O61 - LFC: 12/05/2013 - 16:07:31 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_FFE23A7C282C1690704B5AEA6161D1B8 [404] O61 - LFC: 12/05/2013 - 16:07:31 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\B4378BD2E36B69DECED3E341BD654801_4D9B4B1875B131597137618324D6884A [408] O61 - LFC: 12/05/2013 - 16:13:44 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000011\20002580_26689ca45c286f.eml [801] O61 - LFC: 12/05/2013 - 16:13:45 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000011\2000257f_9fd1b93d83b.eml [27240] O61 - LFC: 12/05/2013 - 16:13:46 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000011\2000257e_c50be8f29e0c99.eml [5323] O61 - LFC: 12/05/2013 - 16:14:00 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\20002591_fc09a51fcaa58f.eml [29996] O61 - LFC: 12/05/2013 - 16:14:01 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\People\Implicit\1e000001_4b81f121a787e2.eml [202] O61 - LFC: 12/05/2013 - 16:14:02 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\20002590_810369cd2e9b38.eml [5469] O61 - LFC: 12/05/2013 - 16:14:03 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\People\Implicit\1e0002c4_f57f782d89159f.eml [161] O61 - LFC: 12/05/2013 - 16:14:04 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\2000258e_7eef7b734e7edf.eml [11279] O61 - LFC: 12/05/2013 - 16:14:04 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\2000258f_9cc9651da7f042.eml [2546] O61 - LFC: 12/05/2013 - 16:14:05 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\2000258d_6e8227155cc026.eml [8385] O61 - LFC: 12/05/2013 - 16:14:06 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\2000258c_fb10bcae3c67cc.eml [5602] O61 - LFC: 12/05/2013 - 16:14:07 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\2000258b_cd6cb37edf7afe.eml [4176] O61 - LFC: 12/05/2013 - 16:14:08 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\2000258a_95604b1f3640a3.eml [11316] O61 - LFC: 12/05/2013 - 16:14:09 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\20002589_d414077e895f9c.eml [732] O61 - LFC: 12/05/2013 - 16:14:10 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\20002588_f8a9b145c548d.eml [2719] O61 - LFC: 12/05/2013 - 16:14:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\20002587_7442d6619b4f2.eml [23094] O61 - LFC: 12/05/2013 - 16:14:12 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\20002586_e554cec85fc930.eml [2758] O61 - LFC: 12/05/2013 - 16:14:13 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\20002585_57e95002bd314.eml [3043] O61 - LFC: 12/05/2013 - 16:14:14 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\20002584_6d976b3fb05614.eml [3910] O61 - LFC: 12/05/2013 - 16:14:15 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\20002583_878b72cc1fb517.eml [4100] O61 - LFC: 12/05/2013 - 16:14:16 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\20002582_7cb822b7505a4c.eml [12074] O61 - LFC: 12/05/2013 - 16:14:17 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\20002581_74d0afe573224f.eml [12943] O61 - LFC: 12/05/2013 - 16:48:58 ---A- C:\Users\PC\AppData\Local\Samsung\SysApps.stg [510] O61 - LFC: 12/05/2013 - 21:13:01 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200025e1_9182f87c644984.eml [3009] O61 - LFC: 12/05/2013 - 21:15:57 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200025e2_dad0bd688996ea.eml [3035] O61 - LFC: 12/05/2013 - 21:16:05 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\Content\7D266D9E1E69FA1EEFB9699B009B34C8_8CA7164968F366C9A94AC8E71C4BDD9B [1891] O61 - LFC: 12/05/2013 - 21:16:06 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\AL25JXQO\logo2[1].gif [1255] O61 - LFC: 12/05/2013 - 21:16:06 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\Content\CA7B2D59B4E9BC2D316D1AECDFC12F63_9129391668361A042AA696295EC7CBEC [1856] O61 - LFC: 12/05/2013 - 21:16:16 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000006\20002524_94f535283f563a.eml [1954] O61 - LFC: 12/05/2013 - 21:16:36 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\7D266D9E1E69FA1EEFB9699B009B34C8_8CA7164968F366C9A94AC8E71C4BDD9B [404] O61 - LFC: 12/05/2013 - 21:16:36 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\CA7B2D59B4E9BC2D316D1AECDFC12F63_9129391668361A042AA696295EC7CBEC [408] O61 - LFC: 13/05/2013 - 07:44:18 ---A- C:\Users\PC\AppData\Roaming\PhotoScape\intro.jpg [26713] O61 - LFC: 13/05/2013 - 07:44:19 --HA- C:\Users\PC\Pictures\photothumb.db [157696] O61 - LFC: 13/05/2013 - 07:45:03 ---A- C:\Users\PC\AppData\Roaming\PhotoScape\favorite.lst [0] O61 - LFC: 13/05/2013 - 07:45:03 ---A- C:\Users\PC\AppData\Roaming\PhotoScape\phoobj.cfg [1327] O61 - LFC: 13/05/2013 - 07:45:03 ---A- C:\Users\PC\AppData\Roaming\PhotoScape\photoscape.cfg [5711] O61 - LFC: 13/05/2013 - 07:47:02 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Office\15.0\f965efc4\Proofing\RoamingCustom.dic [50] O61 - LFC: 13/05/2013 - 07:47:12 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Bibliography Styles\TC102851216[[fn=apasixtheditionofficeonline]].xsl [333258] O61 - LFC: 13/05/2013 - 07:47:12 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Bibliography Styles\TC102851217[[fn=chicago]].xsl [343777] O61 - LFC: 13/05/2013 - 07:47:12 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Bibliography Styles\TC102851218[[fn=gb]].xsl [268317] O61 - LFC: 13/05/2013 - 07:47:12 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Bibliography Styles\TC102851219[[fn=gostname]].xsl [255948] O61 - LFC: 13/05/2013 - 07:47:12 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Bibliography Styles\TC102851220[[fn=gosttitle]].xsl [251032] O61 - LFC: 13/05/2013 - 07:47:12 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Bibliography Styles\TC102851221[[fn=harvardanglia2008officeonline]].xsl [284415] O61 - LFC: 13/05/2013 - 07:47:12 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Bibliography Styles\TC102851222[[fn=ieee2006officeonline]].xsl [294178] O61 - LFC: 13/05/2013 - 07:47:12 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Bibliography Styles\TC102851223[[fn=iso690]].xsl [270198] O61 - LFC: 13/05/2013 - 07:47:12 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Bibliography Styles\TC102851224[[fn=iso690nmerical]].xsl [217137] O61 - LFC: 13/05/2013 - 07:47:12 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Bibliography Styles\TC102851225[[fn=mlaseventheditionofficeonline]].xsl [254875] O61 - LFC: 13/05/2013 - 07:47:12 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Bibliography Styles\TC102851226[[fn=turabian]].xsl [344303] O61 - LFC: 13/05/2013 - 07:47:12 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Templates\LiveContent\15\Managed\Word Document Bibliography Styles\TC102851227[[fn=sist02]].xsl [250983] O61 - LFC: 13/05/2013 - 07:49:20 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Office\Recent\Mes documents.LNK [848] O61 - LFC: 13/05/2013 - 07:49:20 ---A- C:\Users\PC\Documents\prop.xlsx [105576] O61 - LFC: 13/05/2013 - 07:49:21 ---A- C:\Users\PC\AppData\Roaming\Microsoft\Office\Recent\prop.LNK [966] O61 - LFC: 13/05/2013 - 07:49:21 --H-- C:\Users\PC\AppData\Roaming\Microsoft\Office\Recent\index.dat [583] O61 - LFC: 13/05/2013 - 08:11:29 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\Content\FB788E090BC1F3AA2FBC9E8FB2859601 [909] O61 - LFC: 13/05/2013 - 08:11:39 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002646_5415b164d0d579.eml [3035] O61 - LFC: 13/05/2013 - 08:11:40 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\2000264a_7a0195be82f593.eml [2292] O61 - LFC: 13/05/2013 - 08:11:40 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\2000264b_a44b5c7f1da9f.eml [2857] O61 - LFC: 13/05/2013 - 08:11:41 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002647_1fb93de2ca8581.eml [3035] O61 - LFC: 13/05/2013 - 08:11:41 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002648_3b89609a89681.eml [11861] O61 - LFC: 13/05/2013 - 08:11:41 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002649_3127f53ab922b4.eml [3411] O61 - LFC: 13/05/2013 - 08:11:58 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\FB788E090BC1F3AA2FBC9E8FB2859601 [274] O61 - LFC: 13/05/2013 - 08:13:49 ---A- C:\Users\PC\Pictures\Pellicule\ping.JPG [156955] O61 - LFC: 13/05/2013 - 08:13:49 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\2000264d\photo.JPG [156955] O61 - LFC: 13/05/2013 - 08:14:37 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\2000264e_dddd9ffbe983fe.eml [725] O61 - LFC: 13/05/2013 - 08:14:38 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000007\2000264d_7c151c1b251c8.eml [1536] O61 - LFC: 13/05/2013 - 08:14:39 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000014\2000264c_b5b047eaf95596.eml [692] O61 - LFC: 13/05/2013 - 08:16:17 ---A- C:\Users\PC\AppData\Roaming\Apple Computer\MediaStream\local.db [55296] O61 - LFC: 13/05/2013 - 08:44:38 ---A- C:\Users\PC\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2013-05-13 (08-25-54).txt [2158] O61 - LFC: 13/05/2013 - 08:46:21 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveCommLast.etl [1179648] O61 - LFC: 13/05/2013 - 08:46:21 --HA- C:\Users\PC\AppData\Local\IconCache.db [37893] O61 - LFC: 13/05/2013 - 08:46:50 ---A- C:\Users\PC\AppData\Roaming\Intel\Wireless\WLANProfiles\Profiles.enc [48] O61 - LFC: 13/05/2013 - 08:47:05 -SHA- C:\Users\PC\AppData\Roaming\Microsoft\Protect\S-1-5-21-4087580524-408710073-2843193677-1001\288c827c-cd81-4f22-ae12-b121572aec95 [468] O61 - LFC: 13/05/2013 - 08:47:08 ----- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm.etl [0] O61 - LFC: 13/05/2013 - 08:47:11 -SHA- C:\Users\PC\AppData\Roaming\Microsoft\Protect\S-1-5-21-4087580524-408710073-2843193677-1001\1b624d3e-c7ef-4efd-974f-32a9077f4187 [468] O61 - LFC: 13/05/2013 - 08:47:14 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200026ab_bc81b8b7e5df7e.eml [1569] O61 - LFC: 13/05/2013 - 08:50:10 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\200026ac_804ceff1a5dbf8.eml [3035] O61 - LFC: 13/05/2013 - 09:01:45 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\200026ab\photo.JPG [156955] O61 - LFC: 13/05/2013 - 09:01:46 R---- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\Att\200026ab\ATT00001 [35] O61 - LFC: 13/05/2013 - 11:29:58 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Pierre Bachelet\Unknown Album\AlbumArtSmall.jpg [2320] O61 - LFC: 13/05/2013 - 11:29:58 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Pierre Bachelet\Unknown Album\AlbumArt_{A94DD898-0365-4D52-98AB-E1F77DC70CA0}_Large.jpg [8373] O61 - LFC: 13/05/2013 - 11:29:58 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Pierre Bachelet\Unknown Album\AlbumArt_{A94DD898-0365-4D52-98AB-E1F77DC70CA0}_Small.jpg [2320] O61 - LFC: 13/05/2013 - 11:29:58 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Pierre Bachelet\Unknown Album\Folder.jpg [8373] O61 - LFC: 13/05/2013 - 11:30:00 ---A- C:\Users\PC\Music\iTunes\iTunes Media\Music\Pierre Bachelet\Unknown Album\En l'an 2001.mp3 [5281160] O61 - LFC: 13/05/2013 - 11:30:19 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Sandra\Unknown Album\AlbumArtSmall.jpg [2001] O61 - LFC: 13/05/2013 - 11:30:19 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Sandra\Unknown Album\AlbumArt_{2D883220-A386-4EE9-AB93-26DE0256643F}_Small.jpg [2001] O61 - LFC: 13/05/2013 - 11:30:20 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Sandra\Unknown Album\AlbumArt_{2D883220-A386-4EE9-AB93-26DE0256643F}_Large.jpg [7014] O61 - LFC: 13/05/2013 - 11:30:20 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Sandra\Unknown Album\Folder.jpg [7014] O61 - LFC: 13/05/2013 - 11:30:27 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Stephanie De Monaco\Singles\AlbumArtSmall.jpg [3576] O61 - LFC: 13/05/2013 - 11:30:27 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Stephanie De Monaco\Singles\AlbumArt_{B1E8CC95-CBEC-4384-AC83-5D6218A532D0}_Large.jpg [15204] O61 - LFC: 13/05/2013 - 11:30:27 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Stephanie De Monaco\Singles\AlbumArt_{B1E8CC95-CBEC-4384-AC83-5D6218A532D0}_Small.jpg [3576] O61 - LFC: 13/05/2013 - 11:30:27 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\Stephanie De Monaco\Singles\Folder.jpg [15204] O61 - LFC: 13/05/2013 - 11:30:31 ---A- C:\Users\PC\Music\iTunes\iTunes Media\Music\Sandra\Unknown Album\Maria Magdalena.mp3 [2846720] O61 - LFC: 13/05/2013 - 11:30:31 ---A- C:\Users\PC\Music\iTunes\iTunes Media\Music\Stephanie De Monaco\Singles\Comme Un Ouragan.mp3 [4387647] O61 - LFC: 13/05/2013 - 11:31:41 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\YMCA\Unknown Album\AlbumArtSmall.jpg [3063] O61 - LFC: 13/05/2013 - 11:31:41 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\YMCA\Unknown Album\AlbumArt_{3AA0A8FE-C3A3-4E45-B2D2-6C5BB2731CFE}_Small.jpg [3063] O61 - LFC: 13/05/2013 - 11:31:42 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\YMCA\Unknown Album\AlbumArt_{3AA0A8FE-C3A3-4E45-B2D2-6C5BB2731CFE}_Large.jpg [13057] O61 - LFC: 13/05/2013 - 11:31:42 -SH-- C:\Users\PC\Music\iTunes\iTunes Media\Music\YMCA\Unknown Album\Folder.jpg [13057] O61 - LFC: 13/05/2013 - 11:32:01 ---A- C:\Users\PC\Music\iTunes\iTunes Media\Music\YMCA\Unknown Album\Village People.mp3 [3588677] O61 - LFC: 13/05/2013 - 11:32:42 -SH-- C:\Users\PC\Music\AlbumArt_{C7CE4C93-7DE2-4856-B64A-F11881C3234E}_Large.jpg [11828] O61 - LFC: 13/05/2013 - 11:32:42 -SH-- C:\Users\PC\Music\AlbumArt_{C7CE4C93-7DE2-4856-B64A-F11881C3234E}_Small.jpg [3050] O61 - LFC: 13/05/2013 - 11:33:14 -SH-- C:\Users\PC\Music\AlbumArt_{F2B8103F-2EFF-4DD8-9B7F-FE2A57013FA3}_Large.jpg [27295] O61 - LFC: 13/05/2013 - 11:33:14 -SH-- C:\Users\PC\Music\AlbumArt_{F2B8103F-2EFF-4DD8-9B7F-FE2A57013FA3}_Small.jpg [7408] O61 - LFC: 13/05/2013 - 11:34:17 -SH-- C:\Users\PC\Music\AlbumArt_{AD2DCCF4-CA37-4BAE-ACA0-6A784460DD35}_Small.jpg [2797] O61 - LFC: 13/05/2013 - 11:34:18 -SH-- C:\Users\PC\Music\AlbumArt_{AD2DCCF4-CA37-4BAE-ACA0-6A784460DD35}_Large.jpg [12204] O61 - LFC: 13/05/2013 - 11:34:44 -SH-- C:\Users\PC\Music\AlbumArt_{7153D037-8758-4795-9101-9C808DB1BFF5}_Small.jpg [2752] O61 - LFC: 13/05/2013 - 11:34:45 -SH-- C:\Users\PC\Music\AlbumArt_{7153D037-8758-4795-9101-9C808DB1BFF5}_Large.jpg [11359] O61 - LFC: 13/05/2013 - 11:35:46 -SH-- C:\Users\PC\Music\AlbumArt_{A40496ED-28C7-4E50-95E6-D3E8A3CB7354}_Small.jpg [2081] O61 - LFC: 13/05/2013 - 11:35:47 -SH-- C:\Users\PC\Music\AlbumArt_{A40496ED-28C7-4E50-95E6-D3E8A3CB7354}_Large.jpg [7813] O61 - LFC: 13/05/2013 - 11:36:07 -SH-- C:\Users\PC\Music\AlbumArt_{F9FE0E8E-A6C8-4E2C-AE61-4BE391F75D64}_Large.jpg [9921] O61 - LFC: 13/05/2013 - 11:36:07 -SH-- C:\Users\PC\Music\AlbumArt_{F9FE0E8E-A6C8-4E2C-AE61-4BE391F75D64}_Small.jpg [2646] O61 - LFC: 13/05/2013 - 11:36:28 -SH-- C:\Users\PC\Music\AlbumArt_{4DB2D0DB-9999-4514-A0B1-92818A40FA7E}_Large.jpg [42232] O61 - LFC: 13/05/2013 - 11:36:28 -SH-- C:\Users\PC\Music\AlbumArt_{4DB2D0DB-9999-4514-A0B1-92818A40FA7E}_Small.jpg [8004] O61 - LFC: 13/05/2013 - 11:36:49 -SH-- C:\Users\PC\Music\AlbumArtSmall.jpg [7631] O61 - LFC: 13/05/2013 - 11:36:49 -SH-- C:\Users\PC\Music\AlbumArt_{7206CD20-633A-439D-9679-CF822C3F2682}_Large.jpg [42534] O61 - LFC: 13/05/2013 - 11:36:49 -SH-- C:\Users\PC\Music\AlbumArt_{7206CD20-633A-439D-9679-CF822C3F2682}_Small.jpg [7631] O61 - LFC: 13/05/2013 - 11:36:49 -SH-- C:\Users\PC\Music\Folder.jpg [42534] O61 - LFC: 13/05/2013 - 11:36:58 ---A- C:\Users\PC\Music\iTunes\iTunes Media\Music\Patrick Hernandez\Unknown Album\Born to be alive.mp3 [3029935] O61 - LFC: 13/05/2013 - 11:37:14 ---A- C:\Users\PC\Music\Aha - Take On Me.mp3 [3686605] O61 - LFC: 13/05/2013 - 11:37:20 ---A- C:\Users\PC\Music\Barzotti_Claude_-_Le_Rital.mp3 [5040704] O61 - LFC: 13/05/2013 - 11:37:25 ---A- C:\Users\PC\Music\Joe Dassin - L' Ete Indien.mp3 [3268608] O61 - LFC: 13/05/2013 - 11:37:30 ---A- C:\Users\PC\Music\Kansas-CarryOnMyWaywardSon.mp3 [5146826] O61 - LFC: 13/05/2013 - 11:37:40 ---A- C:\Users\PC\Music\Marie Myriam - Comme un enfant.mp3 [4483141] O61 - LFC: 13/05/2013 - 11:37:44 ---A- C:\Users\PC\Music\Serge Lama - Je suis malade.mp3 [4038289] O61 - LFC: 13/05/2013 - 11:37:48 ---A- C:\Users\PC\Music\07 Harlem Shake.mp3 [7964155] O61 - LFC: 13/05/2013 - 11:37:52 ---A- C:\Users\PC\Music\Thrift-Shop-feat.-Wanz-www.Rapnaame.com_.mp3 [3902765] O61 - LFC: 13/05/2013 - 12:01:57 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000016\200026b0_123cd2d416883f.eml [22055] O61 - LFC: 13/05/2013 - 12:01:58 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000016\200026af_55b104704c8892.eml [19691] O61 - LFC: 13/05/2013 - 12:02:00 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000016\200026b1_aeb90608212433.eml [16313] O61 - LFC: 13/05/2013 - 12:16:54 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\200026b2_4c6e6471ab9e5.eml [24337] O61 - LFC: 13/05/2013 - 14:20:50 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\LiveComm\ec013506adbf814b\120712-0049\DBStore\edb.chk [8192] O61 - LFC: 13/05/2013 - 14:20:53 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000006\20002710_ed75d926198e28.eml [8291] O61 - LFC: 13/05/2013 - 14:20:53 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000006\20002711_c0fe4c717f02c3.eml [6418] O61 - LFC: 13/05/2013 - 14:29:24 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002712_fb5851d5a96787.eml [7797] O61 - LFC: 13/05/2013 - 14:29:25 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002713_b96e28b8819412.eml [7797] O61 - LFC: 13/05/2013 - 14:29:29 ----- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Microsoft.WindowsLive.Mail.etl [0] O61 - LFC: 13/05/2013 - 14:29:31 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\AL25JXQO\41560_711199276_6498_q[1].jpg [2196] O61 - LFC: 13/05/2013 - 14:29:31 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\ELBG7XX6\487557_10151573560839277_1480089011_s[1].jpg [5396] O61 - LFC: 13/05/2013 - 14:29:35 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\Content\A4C1370976EA5CBCD83ED4662793FEEA_68F3F21C366D5F2DA544EEDED42EA604 [1814] O61 - LFC: 13/05/2013 - 14:30:01 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\A4C1370976EA5CBCD83ED4662793FEEA_68F3F21C366D5F2DA544EEDED42EA604 [416] O61 - LFC: 13/05/2013 - 14:32:34 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002714_47743c2c8d4f1e.eml [6150] O61 - LFC: 13/05/2013 - 14:47:03 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000016\20002715_7bf210ce2f5e2b.eml [15910] O61 - LFC: 13/05/2013 - 15:11:02 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002716_c94ed39ca26e30.eml [10330] O61 - LFC: 13/05/2013 - 16:06:17 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\ELBG7XX6\ev[3].gif [42] O61 - LFC: 13/05/2013 - 16:17:00 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\16\1d00001d\20002718_8c723b1fbdf833.eml [6151] O61 - LFC: 13/05/2013 - 16:46:49 -S-A- C:\Users\PC\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\CA98213D205E542FD81528F8B9CAD5D5E1877C81 [1518] O61 - LFC: 13/05/2013 - 20:17:06 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\15\1d000010\2000271b_6428a7cb5bd137.eml [1158] O61 - LFC: 13/05/2013 - 20:51:10 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\AL25JXQO\ServicesDocument[1].xml [21377] O61 - LFC: 13/05/2013 - 20:51:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\AL25JXQO\Designs_03[2].jpg [4509] O61 - LFC: 13/05/2013 - 20:51:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\AL25JXQO\Home_01[1].jpg [9553] O61 - LFC: 13/05/2013 - 20:51:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\AL25JXQO\Mothers-Day_08[1].jpg [10388] O61 - LFC: 13/05/2013 - 20:51:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\AL25JXQO\New-Releases_02[1].jpg [5531] O61 - LFC: 13/05/2013 - 20:51:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\AL25JXQO\Projects_05[1].jpg [4186] O61 - LFC: 13/05/2013 - 20:51:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\AL25JXQO\Specials_04[1].jpg [4357] O61 - LFC: 13/05/2013 - 20:51:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\AL25JXQO\Supplies_06[1].jpg [5124] O61 - LFC: 13/05/2013 - 20:51:11 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\ELBG7XX6\Mothers-Day_09[1].jpg [12199] O61 - LFC: 13/05/2013 - 20:51:12 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\AL25JXQO\Mothers-Day_07[1].jpg [181039] O61 - LFC: 13/05/2013 - 20:51:12 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\ELBG7XX6\Mothers-Day_10[1].jpg [40781] O61 - LFC: 13/05/2013 - 20:51:12 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\INetCache\ELBG7XX6\Mothers-Day_11[1].jpg [28150] O61 - LFC: 13/05/2013 - 20:51:19 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\BackgroundTransferApi\854d5a50-b0ff-43f6-acc0-cfc941a87351.up_meta [89] O61 - LFC: 13/05/2013 - 20:51:19 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\bici\bi001000.sqm [814] O61 - LFC: 13/05/2013 - 20:51:20 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\BackgroundTransferApi\854d5a50-b0ff-43f6-acc0-cfc941a87351.6beb16a5-34ca-4b8a-af24-06f1d367f3c4.down_meta [426] O61 - LFC: 13/05/2013 - 20:51:20 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\BackgroundTransferApi\854d5a50-b0ff-43f6-acc0-cfc941a87351.down_data [0] O61 - LFC: 13/05/2013 - 20:57:32 ---A- C:\Users\PC\AppData\Roaming\Adobe\Flash Player\AssetCache\VVCVR24G\8F903698240FE799F61EEDA8595181137B996156.heu [150] O61 - LFC: 13/05/2013 - 20:57:32 ---A- C:\Users\PC\AppData\Roaming\Adobe\Flash Player\AssetCache\VVCVR24G\ABD49354324081CEBB8F60184CF5FEE81F0F9298.heu [150] O61 - LFC: 13/05/2013 - 20:57:41 ---A- C:\Users\PC\AppData\Roaming\Adobe\AIR\ELS\MTMahjongAIR.A08BAD4CD323DD6E08EB7713FBC9B2807D884B67.1\PrivateEncryptedDatai [24152] O61 - LFC: 13/05/2013 - 20:58:40 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000005\2000271c_61ec3def2eaac.eml [2675] O61 - LFC: 13/05/2013 - 20:58:41 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000005\2000271e_e70391d64fa468.eml [10264] O61 - LFC: 13/05/2013 - 20:58:42 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000005\2000271d_8801d0479ff27a.eml [6153] O61 - LFC: 13/05/2013 - 21:47:32 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\4309200C3DBAD0F6F0DFACE9165FD092 [264] O61 - LFC: 13/05/2013 - 21:47:32 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\E2EF7F0FB7284B9ACFD4F65D02218479 [264] O61 - LFC: 13/05/2013 - 22:02:32 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\AC9005F5466BD463DF06D711B370595F [316] O61 - LFC: 13/05/2013 - 22:20:31 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000006\2000271f_538f030bd2f629.eml [7089] O61 - LFC: 13/05/2013 - 22:34:18 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002720_3f7553061f197d.eml [3035] O61 - LFC: 13/05/2013 - 22:34:38 ---A- C:\Users\PC\AppData\Roaming\MTMahjongAIR.A08BAD4CD323DD6E08EB7713FBC9B2807D884B67.1\Local Store\#ApplicationUpdater\state.xml [243] O61 - LFC: 13/05/2013 - 22:43:54 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 [340] O61 - LFC: 13/05/2013 - 22:43:55 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002721_624be9dffad0af.eml [3035] O61 - LFC: 13/05/2013 - 22:44:24 -S-A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Microsoft\CryptnetUrlCache\MetaData\F063BF7EF604434CBE00FF198F0D9B10 [332] O61 - LFC: 13/05/2013 - 22:50:14 ---A- C:\Users\PC\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Indexed\LiveComm\ec013506adbf814b\120712-0049\Mail\1\1d000002\20002722_5ceb8f44a49f5d.eml [3035] ~ Files: 700 Scanned in 00mn 21s ---\\ Liste des outils de nettoyage (O63) O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 ~ ADS: Scanned in 00mn 00s ---\\ File Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- C:\EMBIRD64\EMBIRD.exe O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.bat> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe O67 - Shell Spawning: <.cmd> [HKCR\..\open\Command] (...) -- C:\EMBIRD64\EMBIRD.exe O67 - Shell Spawning: <.com> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKCR\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKCR\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O67 - Shell Spawning: <.js> [HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe ~ FASS Keys: 18 Scanned in 00mn 00s ---\\ Start Menu Internet (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Recherche des services démarrés par Svchost (O83) O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [190976] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [149504] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [149504] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [309248] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [1366016] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [1071104] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [99840] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à distance.) -- C:\Windows\System32\rasmans.dll [358400] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [107520] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [62976] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [438784] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [305664] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [3240448] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [826368] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [565760] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [894464] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [30720] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [69632] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [151552] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [105472] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1282560] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [219648] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [80896] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [134144] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [209920] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [291328] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84992] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [97792] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [190976] O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\Windows\System32\wlidsvc.dll [1964544] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [47104] O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\Windows\System32\DeviceSetupManager.dll [207872] O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Microsoft.) -- C:\Windows\System32\ncasvc.dll [161792] O83 - Search Svchost Services: SystemEventsBroker (SystemEventsBroker) . (.Microsoft Corporation - Service Broker pour les événements système.) -- C:\Windows\System32\SystemEventsBrokerServer.dll [180224] ~ Services: 34 Scanned in 00mn 00s ---\\ Recherche particuliere à la racine de certains dossiers (O84) [MD5.6EBA4DF7D38DA6FCD75D8FCF8F0FA99B] [SPRF][21/02/2013] (.Samsung Electronics - Samsung Marker.) -- C:\ProgramData\MakeMarkerFile.exe [2063240] [MD5.A95866BA166A09E360BB88DA72D4531D] [SPRF][12/05/2013] (...) -- C:\Users\PC\Desktop\adwcleaner.exe [628743] [MD5.683FDD3D773C58B262DC07CD0C6CE938] [SPRF][09/04/2013] (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Users\PC\Desktop\mbam-setup-1.75.0.1300.exe [10285040] [MD5.AF1E38B5593479C43B92939C5EAA3F22] [SPRF][12/05/2013] (.Pas de propriétaire - Configuration du PC.) -- C:\Users\PC\Desktop\PCConfigX64.exe [2355816] [MD5.3B3E5FD281D012859F83484A1253D851] [SPRF][27/12/2012] (.Mooii - PhotoScape Setup.) -- C:\Users\PC\Desktop\photoscape_photoscape_3.6.3_francais_41582.exe [21322864] [MD5.901CB66681C0CEB4CE5DD9F456875B81] [SPRF][09/05/2013] (.Pas de propriétaire - Nettoyage des fichiers temporaires.) -- C:\Users\PC\Desktop\SFTGC.exe [1038412] [MD5.7C8A098740D58F496C620A74F9A9A0E2] [SPRF][12/05/2013] (.Nicolas Coolman - ZHPDiag.) -- C:\Users\PC\Desktop\Zhpdiag2.exe [5647471] ~ Files: Scanned in 00mn 01s ---\\ Firewall Active Exception List (FirewallRules) (O87) O87 - FAEL: "vm-monitoring-rpc" | In - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "vm-monitoring-dcom" | In - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMP-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe O87 - FAEL: "WMP-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe O87 - FAEL: "WMP-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe O87 - FAEL: "SNMPTRAP-In-UDP" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Interruption SNMP.) -- C:\Windows\system32\snmptrap.exe O87 - FAEL: "SNMPTRAP-In-UDP-NoScope" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Interruption SNMP.) -- C:\Windows\system32\snmptrap.exe O87 - FAEL: "Wininit-Shutdown-In-Rule-TCP-RPC" | In - None - P6 - FALSE | .(.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\system32\wininit.exe O87 - FAEL: "Wininit-Shutdown-In-Rule-TCP-RPC-EPMapper" | In - None - P6 - FALSE | .(.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\system32\wininit.exe O87 - FAEL: "PNRPMNRS-PNRP-In-UDP" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "PNRPMNRS-PNRP-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "PNRPMNRS-SSDPSrv-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "PNRPMNRS-SSDPSrv-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteFwAdmin-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteFwAdmin-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteFwAdmin-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteFwAdmin-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "Netlogon-TCP-RPC-In" | In - None - P6 - FALSE | .(.Microsoft Corporation - Local Security Authority Process.) -- C:\Windows\System32\lsass.exe O87 - FAEL: "WMI-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMI-WINMGMT-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMI-WINMGMT-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMI-ASYNC-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Sink to receive asynchronous callbacks for WMI client application.) -- C:\Windows\system32\wbem\unsecapp.exe O87 - FAEL: "WMI-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMI-WINMGMT-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMI-WINMGMT-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMI-ASYNC-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Sink to receive asynchronous callbacks for WMI client application.) -- C:\Windows\system32\wbem\unsecapp.exe O87 - FAEL: "MsiScsi-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MsiScsi-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MsiScsi-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MsiScsi-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "ProximityUxHost-Sharing-In-TCP-NoScope" | In - None - P6 - TRUE | .(.Microsoft Corporation - Hôte UX de proximité.) -- C:\Windows\system32\proximityuxhost.exe O87 - FAEL: "ProximityUxHost-Sharing-Out-TCP-NoScope" | Out - None - P6 - TRUE | .(.Microsoft Corporation - Hôte UX de proximité.) -- C:\Windows\system32\proximityuxhost.exe O87 - FAEL: "FPS-SpoolSvc-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe O87 - FAEL: "FPS-SpoolSvc-In-TCP" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe O87 - FAEL: "FPS-LLMNR-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "FPS-LLMNR-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-UPnPHost-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-WSDEVNTS-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-WSDEVNT-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-SSDPSrv-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-SSDPSrv-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-UPnPHost-Out-TCP-Active" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-UPnP-Out-TCP-Active" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-FDPHOST-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-DAS-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Device Association Framework Provider Host.) -- C:\Windows\system32\dashost.exe O87 - FAEL: "NETDIS-FDPHOST-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-LLMNR-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-LLMNR-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-FDRESPUB-WSD-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-FDRESPUB-WSD-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-WSDEVNTS-Out-TCP-Active" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-WSDEVNT-Out-TCP-Active" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-SSDPSrv-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-SSDPSrv-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-UPnP-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-UPnPHost-Out-TCP" | Out - Public - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-FDPHOST-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-DAS-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Device Association Framework Provider Host.) -- C:\Windows\system32\dashost.exe O87 - FAEL: "NETDIS-FDPHOST-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-LLMNR-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-LLMNR-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-FDRESPUB-WSD-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-FDRESPUB-WSD-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-WSDEVNTS-Out-TCP" | Out - Public - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-WSDEVNT-Out-TCP" | Out - Public - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "Microsoft-Windows-HomeGroup-ProvSvc-TCP3587-In" | In - Private - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "Microsoft-Windows-HomeGroup-ProvSvc-TCP3587-Out" | Out - Private - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "Microsoft-Windows-HomeGroup-ProvSvc-UDP3540-In" | In - Private - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "Microsoft-Windows-HomeGroup-ProvSvc-UDP3540-Out" | Out - Private - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAssistance-In-TCP-EdgeScope" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe O87 - FAEL: "RemoteAssistance-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe O87 - FAEL: "RemoteAssistance-PnrpSvc-UDP-In-EdgeScope" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAssistance-PnrpSvc-UDP-OUT" | Out - Public - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAssistance-RAServer-In-TCP-NoScope-Active" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Serveur COM d’assistance à distance Windows.) -- C:\Windows\system32\raserver.exe O87 - FAEL: "RemoteAssistance-RAServer-Out-TCP-NoScope-Active" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Serveur COM d’assistance à distance Windows.) -- C:\Windows\system32\raserver.exe O87 - FAEL: "RemoteAssistance-DCOM-In-TCP-NoScope-Active" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAssistance-In-TCP-EdgeScope-Active" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe O87 - FAEL: "RemoteAssistance-Out-TCP-Active" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe O87 - FAEL: "RemoteAssistance-SSDPSrv-In-UDP-Active" | In - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAssistance-SSDPSrv-Out-UDP-Active" | Out - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAssistance-PnrpSvc-UDP-In-EdgeScope-Active" | In - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAssistance-PnrpSvc-UDP-OUT-Active" | Out - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MSDTC-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Service Microsoft Distributed Transaction Coordinator.) -- C:\Windows\system32\msdtc.exe O87 - FAEL: "MSDTC-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Service Microsoft Distributed Transaction Coordinator.) -- C:\Windows\system32\msdtc.exe O87 - FAEL: "MSDTC-KTMRM-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MSDTC-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MSDTC-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Service Microsoft Distributed Transaction Coordinator.) -- C:\Windows\system32\msdtc.exe O87 - FAEL: "MSDTC-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Service Microsoft Distributed Transaction Coordinator.) -- C:\Windows\system32\msdtc.exe O87 - FAEL: "MSDTC-KTMRM-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MSDTC-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-QWave-In-UDP-NoScope" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-QWave-Out-UDP-NoScope" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-QWave-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-QWave-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-WMP-In-UDP-NoScope" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe O87 - FAEL: "WMPNSS-WMP-Out-UDP-NoScope" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe O87 - FAEL: "WMPNSS-WMP-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe O87 - FAEL: "WMPNSS-In-UDP-NoScope" |In - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-Out-UDP-NoScope" |Out - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-QWave-In-UDP" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-QWave-Out-UDP" | Out - Public - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-QWave-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-QWave-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-SSDPSrv-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-SSDPSrv-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-WMP-In-UDP" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe O87 - FAEL: "WMPNSS-WMP-Out-UDP" | Out - Public - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe O87 - FAEL: "WMPNSS-WMP-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe O87 - FAEL: "WMPNSS-In-UDP" |In - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-Out-UDP" |Out - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) O87 - FAEL: "WMPNSS-UPnP-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteEventLogSvc-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteEventLogSvc-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteEventLogSvc-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteEventLogSvc-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "PlayTo-In-UDP-NoScope" | In - Domain - P17 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe O87 - FAEL: "PlayTo-In-UDP-LocalSubnetScope" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe O87 - FAEL: "PlayTo-In-UDP-PlayToScope" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe O87 - FAEL: "PlayTo-Out-UDP-NoScope" | Out - Domain - P17 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe O87 - FAEL: "PlayTo-Out-UDP-LocalSubnetScope" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe O87 - FAEL: "PlayTo-Out-UDP-PlayToScope" | Out - Public - P17 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe O87 - FAEL: "PlayTo-In-RTSP-NoScope" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe O87 - FAEL: "PlayTo-In-RTSP-LocalSubnetScope" | In - Private - P6 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe O87 - FAEL: "PlayTo-In-RTSP-PlayToScope" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe O87 - FAEL: "PlayTo-SSDP-Discovery-PlayToScope" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "PlayTo-QWave-In-UDP-PlayToScope" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "PlayTo-QWave-Out-UDP-PlayToScope" | Out - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "PlayTo-QWave-In-TCP-PlayToScope" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "PlayTo-QWave-Out-TCP-PlayToScope" | Out - Public - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "TPMVSCMGR-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "TPMVSCMGR-Server-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - TPM Virtual Smart Card Manager DCOM Server.) -- C:\Windows\system32\RmtTpmVscMgrSvr.exe O87 - FAEL: "TPMVSCMGR-Server-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - TPM Virtual Smart Card Manager DCOM Server.) -- C:\Windows\system32\RmtTpmVscMgrSvr.exe O87 - FAEL: "TPMVSCMGR-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "TPMVSCMGR-Server-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - TPM Virtual Smart Card Manager DCOM Server.) -- C:\Windows\system32\RmtTpmVscMgrSvr.exe O87 - FAEL: "TPMVSCMGR-Server-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - TPM Virtual Smart Card Manager DCOM Server.) -- C:\Windows\system32\RmtTpmVscMgrSvr.exe O87 - FAEL: "Collab-P2PHost-In-TCP" |In - None - P6 - TRUE | .(...) -- C:\Windows\system32\p2phost.exe (.not file.) O87 - FAEL: "Collab-P2PHost-Out-TCP" |Out - None - P6 - FALSE | .(...) -- C:\Windows\system32\p2phost.exe (.not file.) O87 - FAEL: "Collab-P2PHost-WSD-In-UDP" |In - None - P17 - FALSE | .(...) -- C:\Windows\system32\p2phost.exe (.not file.) O87 - FAEL: "Collab-P2PHost-WSD-Out-UDP" |Out - None - P17 - FALSE | .(...) -- C:\Windows\system32\p2phost.exe (.not file.) O87 - FAEL: "Collab-PNRP-In-UDP" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "Collab-PNRP-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "Collab-PNRP-SSDPSrv-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "Collab-PNRP-SSDPSrv-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteSvcAdmin-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\Windows\system32\services.exe O87 - FAEL: "RemoteSvcAdmin-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteSvcAdmin-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\Windows\system32\services.exe O87 - FAEL: "RemoteSvcAdmin-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "PerfLogsAlerts-PLASrv-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Performance Logs and Alerts DCOM Server.) -- C:\Windows\system32\plasrv.exe O87 - FAEL: "PerfLogsAlerts-DCOM-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "PerfLogsAlerts-PLASrv-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Performance Logs and Alerts DCOM Server.) -- C:\Windows\system32\plasrv.exe O87 - FAEL: "PerfLogsAlerts-DCOM-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-DHCP-In" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-DHCP-Out" | Out - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-DHCPV6-In" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-DHCPV6-Out" | Out - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-Teredo-In" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-Teredo-Out" | Out - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-IPHTTPS-Out" | Out - None - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-GP-Out-TCP" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-DNS-Out-UDP" | Out - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-GP-LSASS-Out-TCP" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Local Security Authority Process.) -- C:\Windows\system32\lsass.exe O87 - FAEL: "RVM-VDS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Service de disque virtuel.) -- C:\Windows\system32\vds.exe O87 - FAEL: "RVM-VDSLDR-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Virtual Disk Service Loader.) -- C:\Windows\system32\vdsldr.exe O87 - FAEL: "RVM-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RVM-VDS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Service de disque virtuel.) -- C:\Windows\system32\vds.exe O87 - FAEL: "RVM-VDSLDR-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Virtual Disk Service Loader.) -- C:\Windows\system32\vdsldr.exe O87 - FAEL: "RVM-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteTask-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteTask-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteTask-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteTask-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WPDMTP-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes.) -- C:\Windows\system32\wudfhost.exe O87 - FAEL: "WPDMTP-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes.) -- C:\Windows\system32\wudfhost.exe O87 - FAEL: "WPDMTP-SSDPSrv-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WPDMTP-SSDPSrv-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WPDMTP-UPnPHost-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WPDMTP-UPnP-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-SSDPSrv-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-SSDPSrv-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-In-TCP" |In - None - P6 - FALSE | .(...) -- C:\Windows\ehome\ehshell.exe (.not file.) O87 - FAEL: "MCX-Out-TCP" |Out - None - P6 - FALSE | .(...) -- C:\Windows\ehome\ehshell.exe (.not file.) O87 - FAEL: "MCX-QWave-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-QWave-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-QWave-In-TCP" | In - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-QWave-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-TERMSRV-In-TCP" | In - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-In-UDP" |In - None - P17 - FALSE | .(...) -- C:\Windows\ehome\ehshell.exe (.not file.) O87 - FAEL: "MCX-Out-UDP" |Out - None - P17 - FALSE | .(...) -- C:\Windows\ehome\ehshell.exe (.not file.) O87 - FAEL: "MCX-MCX2SVC-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-PlayTo-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-PlayTo-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-FDPHost-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{1EC62D5F-C8EC-429E-B6B4-2954EBCE3B5C}" | In - None - P6 - TRUE | .(.Microsoft Corporation - Microsoft SkyDrive.) -- C:\Users\PC\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe O87 - FAEL: "{76FCA511-6AE8-480B-8404-287080449DEA}" | In - None - P6 - TRUE | .(.Apple Inc. - WebKit2WebProcess.exe.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe O87 - FAEL: "{74C5F5F7-0DA4-4C24-9120-2AAB14B9EC21}" | In - Private - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe O87 - FAEL: "{C39500E4-B958-47B1-AC17-36689B023979}" | In - Private - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe O87 - FAEL: "{14F43D2E-A755-47F8-ACF7-41C735DA0DD9}" | In - Private - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe O87 - FAEL: "{ACEE24C1-862D-4008-BE3D-27FC6CBC0415}" | In - Private - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe O87 - FAEL: "{A61A4F52-6D0F-4594-8AD2-AFEFA87E2465}" | In - None - P17 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files (x86)\iTunes\iTunes.exe O87 - FAEL: "{B85DB6BE-2AFA-4195-B5CF-848E94F0B98E}" | In - Private - P6 - TRUE | .(.Azureus Software, Inc - Pas de description.) -- C:\Program Files\Vuze\Azureus.exe =>P2P.Azureus O87 - FAEL: "{457751F5-EF23-4704-9F17-745C713E2D11}" | In - Private - P17 - TRUE | .(.Azureus Software, Inc - Pas de description.) -- C:\Program Files\Vuze\Azureus.exe =>P2P.Azureus O87 - FAEL: "{CDCDF769-7FA4-4D86-80AC-09DD7A75976F}" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{E28E6993-22DE-482A-93D9-519989D83E00}" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{F8B61AA7-1177-4A46-8DFE-64697CF09A69}" | In - Private - P6 - TRUE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe O87 - FAEL: "{3F287906-717B-4288-B300-991227FDD45E}" | Out - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{3D07244C-A260-41B0-97F9-8EB7432E56E3}" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{3D731BB1-D93B-461F-9F45-78E820E71172}" | Out - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{5059EFFB-32FE-480E-B2C7-FC118B8FE241}" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{03499FAA-579A-4857-BF84-05C82A14CC46}" | Out - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{185384B2-3BC9-4544-AE85-FCFCA881645B}" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Device Association Framework Provider Host.) -- C:\Windows\system32\dashost.exe O87 - FAEL: "{5646B166-4D72-42AA-BC40-5C82E7A21285}" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{BA8C41BD-E369-45A9-A5AD-BF3E27B0648E}" | Out - Public - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{406F66B5-79CB-4D7B-942E-74E14BBFD98A}" | Out - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{CB8D5DEB-6107-49E5-993A-B98C5B516471}" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{585FD33C-A0B8-49A8-8416-15E46F734BF7}" | Out - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{AE71819B-47F1-4F7F-B689-C949D98020B3}" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{42F6AD76-1D28-406E-955C-3D473FB987CB}" | In - None - P17 - TRUE | .(.Pas de propriétaire - Wireless PAN DHCP and DNS Server.) -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe O87 - FAEL: "{E6D39097-7BFA-4353-94A2-B04F8E7B2974}" | In - Private - P6 - TRUE | .(.Condusiv Technologies - IntelliMemory Service.) -- C:\Program Files\Condusiv Technologies\IntelliMemory\IntelliMem.exe O87 - FAEL: "{D9D1FB29-A584-4F69-AD75-155623DD43B7}" | In - Private - P17 - TRUE | .(.Condusiv Technologies - IntelliMemory Service.) -- C:\Program Files\Condusiv Technologies\IntelliMemory\IntelliMem.exe ~ Firewall: 223 Scanned in 00mn 00s ---\\ Scan Additionnel (O88) Database Version : v2.12091 - (13/05/2013) Clés trouvées (Keys found) : 0 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 0 Fichiers trouvés (Files found) : 0 ~ Additionnel Scan: 159104 Items scanned in 00mn 10s ---\\ Product Upgrade Codes (O90) O90 - PUC: "045F27F206F16624596059B2126D46D0" . (.Apple Mobile Device Support.) -- C:\windows\Installer\{2F72F540-1F60-4266-9506-952B21D6640D}\Installer.ico O90 - PUC: "12DA52202E3F6194FB3F563D9F505228" . (.iTunes.) -- C:\windows\Installer\{0225AD21-F3E2-4916-BFF3-65D3F9052582}\Installer.ico O90 - PUC: "2B0163E6D0340BE4183EB2758E9BEDD8" . (.Bonjour.) -- C:\windows\Installer\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}\Bonjour.ico O90 - PUC: "46705FED7A1F4DD48BAB8CA1847036A1" . (.Intel® PROSet/Wireless WiFi Software.) -- C:\windows\Installer\{DEF50764-F1A7-4DD4-B8BA-C81A4807631A}\ARPPRODUCTICON.exe O90 - PUC: "46B5A9879DD95AB419A50FCFA0B1B7EF" . (.Apple Software Update.) -- C:\windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\Installer.ico O90 - PUC: "4B9DC6C7032B67E408AABF64F54FED92" . (.Intel(R) PROSet/Wireless WiFi Software Driver.) -- C:\windows\Installer\{7C6CD9B4-B230-4E76-80AA-FB465FF4DE29}\ARPPRODUCTICON.exe O90 - PUC: "4F42BC0DF480ED046B9B0A63626E280F" . (.iCloud.) -- C:\windows\Installer\{D0CB24F4-084F-40DE-B6B9-A03626E682F0}\ARP.ico O90 - PUC: "5C30439E19A8049498BDEE6DD96A8EE2" . (.IntelliMemory.) -- C:\windows\Installer\{E93403C5-8A91-4940-89DB-EED69DA6E82E}\ARPPRODUCTICON.exe O90 - PUC: "753C5BC85E211B140A425DD7E4F6239D" . (.Settings.) -- C:\windows\Installer\{8CB5C357-12E5-41B1-A024-D57D4E6F32D9}\_853F67D554F05449430E7E.exe O90 - PUC: "7AA65C54B1DE00849AF7DEFDF353021B" . (.Apple Application Support.) -- C:\windows\Installer\{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}\WinInstall.ico O90 - PUC: "9D117C349C763974084D9E756D835D13" . (.SW Update.) -- C:\windows\Installer\{43C711D9-67C9-4793-80D4-E957D638D531}\_853F67D554F05449430E7E.exe O90 - PUC: "AA05C49A8E127264DA0D1EA67030D0D7" . (.Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed.) -- C:\windows\Installer\{A94C50AA-21E8-4627-ADD0-E16A07030D7D}\IntelBluetoothICO ~ Update Products: 21 Scanned in 00mn 00s ---\\ MyComputer Name Space (O92) O92 - MNS: Flux de photos - {F0D63F85-37EC-4097-B30D-61B4A8917118} ~ MNS: 1 Scanned in 00mn 00s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SR - | Auto 13/02/2013 770528 | (AMPPALR3) . (.Intel Corporation.) - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe SR - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe SR - | Auto 12/09/2012 135984 | (BTHSSecurityMgr) . (.Intel(R) Corporation.) - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe SS - | Demand 14/12/2012 277616 | (cphs) . (.Intel Corporation.) - C:\Windows\SysWow64\IntelCpHeciSvc.exe SR - | Auto 03/01/2013 1594568 | (Easy Launcher) . (.Samsung Electronics CO., LTD..) - C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe SR - | Auto 08/02/2013 621296 | (EvtEng) . (.Intel(R) Corporation.) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe SR - | Auto 01/11/2012 55120 | (IntelliMemory) . (.Condusiv Technologies.) - C:\Program Files\Condusiv Technologies\IntelliMemory\IntelliMem.exe SR - | Demand 20/02/2013 641352 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe SR - | Auto 04/04/2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe SR - | Auto 04/04/2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe SS - | Demand 12/04/2013 115608 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe SS - | Demand 273136 | (MyWiFiDHCPDNS) . (...) - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe SR - | Auto 24/12/2012 144520 | (NIS) . (.Symantec Corporation.) - C:\Program Files (x86)\Norton Internet Security\Engine\20.3.1.22\ccSvcHst.exe SR - | Auto 08/02/2013 149744 | (RegSrvc) . (.Intel(R) Corporation.) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe SR - | Auto 09/04/2013 2921520 | (SWUpdateService) . (.Samsung Electronics CO., LTD..) - C:\Program Files (x86)\Samsung\SW Update\SWMAgent.exe SS - | Demand 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe SS - | Demand 20/09/2012 29696 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 08/02/2013 3386608 | (ZeroConfigService) . (.Intel® Corporation.) - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe ~ Services: Scanned in 00mn 00s ---\\ Recherche Master Boot Record Infection (MBR)(O80) Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net Run by PC at 13/05/2013 22:54:27 device: opened successfully user: error reading MBR Disk trace: error: Read Descripteur non valide kernel: error reading MBR ~ MBR: 9 Scanned in 00mn 02s ---\\ Recherche Master Boot Record Infection (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by PC at 13/05/2013 22:54:29 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 04s End of the scan (1967 lines in 02mn 29s)(0)